Efficient NIZKs and Signatures from Commit-and-Open Protocols in the QROM

02/28/2022
by   Jelle Don, et al.
0

Commit-and-open Sigma-protocols are a popular class of protocols for constructing non-interactive zero-knowledge arguments and digital-signature schemes via the Fiat-Shamir transformation. Instantiated with hash-based commitments, the resulting non-interactive schemes enjoy tight online-extractability in the random oracle model. Online extractability improves the tightness of security proofs for the resulting digital-signature schemes by avoiding lossy rewinding or forking-lemma based extraction. In this work, we prove tight online extractability in the quantum random oracle model (QROM), showing that the construction supports post-quantum security. First, we consider the default case where committing is done by element-wise hashing. In a second part, we extend our result to Merkle-tree based commitments. Our results yield a significant improvement of the provable post-quantum security of the digital-signature scheme Picnic. Our analysis makes use of a recent framework by Chung et al. [arXiv:2010.11658] for analysing quantum algorithms in the QROM using purely classical reasoning. Therefore, our results can to a large extent be understood and verified without prior knowledge of quantum information science.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/23/2021

Quantum-access security of the Winternitz one-time signature scheme

Quantum-access security, where an attacker is granted superposition acce...
research
03/11/2020

The Measure-and-Reprogram Technique 2.0: Multi-Round Fiat-Shamir and More

We revisit recent works by Don, Fehr, Majenz and Schaffner and by Liu an...
research
03/23/2022

Winternitz stack protocols

This paper proposes and evaluates a new bipartite post-quantum digital s...
research
03/04/2021

Online-Extractability in the Quantum Random-Oracle Model

We show the following generic result. Whenever a quantum query algorithm...
research
07/12/2021

Weakened Random Oracle Models with Target Prefix

Weakened random oracle models (WROMs) are variants of the random oracle ...
research
10/28/2020

Tight adaptive reprogramming in the QROM

The random oracle model (ROM) enjoys widespread popularity, mostly becau...
research
05/03/2021

A Tight Parallel Repetition Theorem for Partially Simulatable Interactive Arguments via Smooth KL-Divergence

Hardness amplification is a central problem in the study of interactive ...

Please sign up or login with your details

Forgot password? Click here to reset