Compact Lattice Gadget and Its Applications to Hash-and-Sign Signatures

05/21/2023
by   Yang Yu, et al.
0

This work aims to improve the practicality of gadget-based cryptosystems, with a focus on hash-and-sign signatures. To this end, we develop a compact gadget framework in which the used gadget is a square matrix instead of the short and fat one used in previous constructions. To work with this compact gadget, we devise a specialized gadget sampler, called semi-random sampler, to compute the approximate preimage. It first deterministically computes the error and then randomly samples the preimage. We show that for uniformly random targets, the preimage and error distributions are simulatable without knowing the trapdoor. This ensures the security of the signature applications. Compared to the Gaussian-distributed errors in previous algorithms, the deterministic errors have a smaller size, which lead to a substantial gain in security and enables a practically working instantiation. As the applications, we present two practically efficient gadget-based signature schemes based on NTRU and Ring-LWE respectively. The NTRU-based scheme offers comparable efficiency to Falcon and Mitaka and a simple implementation without the need of generating the NTRU trapdoor. The LWE-based scheme also achieves a desirable overall performance. It not only greatly outperforms the state-of-the-art LWE-based hash-and-sign signatures, but also has an even smaller size than the LWE-based Fiat-Shamir signature scheme Dilithium. These results fill the long-term gap in practical gadget-based signatures.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/16/2018

Wave: A New Code-Based Signature Scheme

We present here Wave the first 'hash-and-sign' code-based signature sche...
research
02/18/2020

Security analysis of the W-OTS^+ signature scheme: Updating security bounds

In this work, we discuss in detail a flaw in the original security proof...
research
05/25/2023

Ring Signature from Bonsai Tree: How to Preserve the Long-Term Anonymity

Signer-anonymity is the central feature of ring signatures, which enable...
research
05/30/2019

Proof-of-forgery for hash-based signatures

In the present work, a peculiar property of hash-based signatures allowi...
research
01/20/2023

Key-and-Signature Compact Multi-Signatures for Blockchain: A Compiler with Realizations

Multi-signature is a protocol where a set of signatures jointly sign a m...
research
01/02/2019

Accountable Tracing Signatures from Lattices

Group signatures allow users of a group to sign messages anonymously in ...
research
12/11/2021

A Note on the Post-Quantum Security of (Ring) Signatures

This work revisits the security of classical signatures and ring signatu...

Please sign up or login with your details

Forgot password? Click here to reset