Gedankenexperiment Forgery

Eventually, the adversary outputs a forgery: it outputs public keys pk1, ..., pkn, a message m ∈ M, and a multi-signature σ.

The adversary has broken security if it did not issue a signature query for m and

outputs accept.

Last updated