Indian Institute of Science
The machinery of oracle replay attack of Pointcheval and Stern [PS00] plays a pivotal role in the security argument of a large class of signature schemes [ElG85, Sch91, Oka93]. In the basic version of replay attack, one runs the adversary twice on related inputs in order to solve the underlying hard problem. The probability of success of the replay attack is bounded by the forking lemma of [PS00]. However, observed that the \"Forking Lemma is something purely probabilistic, not about signatures\" and proposed a more abstract version called the General Forking Lemma (GF).