Compact Lattice Signatures via Iterative Rejection Sampling
Joel Gärtner
Abstract
One of the primary approaches for constructing lattice-based signature schemes is through the “Fiat-Shamir with aborts” methodology. Schemes constructed using this approach may abort and restart during signing, corresponding to rejection sampling produced signatures in order to ensure that they follow a distribution that is independent of the secret key. This rejection sampling is only feasible when the output distribution is sufficiently wide, limiting how compact this type of signature schemes can be. In this work, we develop a new method to construct lattice signatures with the “Fiat-Shamir with aborts” approach. By constructing signatures in a way that is influenced by the rejection condition, we can significantly lower the rejection probability. This allows our scheme to use an iterative rejection sampling to target narrower output distributions than previous methods, resulting in much more compact signatures. In the most compact variant of our new signature scheme, the combined size of a signature and a verification key is less than half of that for ML-DSA and comparable to that of compact hash-and-sign lattice signature schemes, such as Falcon. Alternatively, by targeting a somewhat wider distribution, the rejection condition of the scheme can be securely ignored. This non-aborting variant of our scheme still retains a notable size advantage over previous lattice-based Fiat-Shamir schemes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 281cea66-a777-4cd8-a661-0c5bbced0f39Builds on2
- Shorter Hash-and-Sign Lattice-Based SignaturesThomas Espitau, Mehdi Tibouchi, Alexandre Wallet, Yang YuCRYPTO 2022 · 38 citations
- Fixing and Mechanizing the Security Proof of Fiat-Shamir with Aborts and DilithiumManuel Barbosa, Gilles Barthe, Christian Doczkal, Jelle Don et al.CRYPTO 2023 · 33 citations
Related papers
- DualMS 2.0: Practical Lattice-Based Two-Round Fiat-Shamir Multi-Signature with Better EfficiencyQiqi Lai, Chongshen Chen, Feng Hao Liu, Tianyu Zhao et al.CCS 2026
- Compact Lattice Gadget and Its Applications to Hash-and-Sign SignaturesYang Yu, Huiwen Jia, Xiaoyun WangCRYPTO 2023 · 35 citations
- Polytopes in the Fiat-Shamir with Aborts ParadigmHenry Bambury, Hugo Beguinet, Thomas Ricosset, Éric SageloliCRYPTO 2024 · 5 citations
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi et al.EUROCRYPT 2022 · 67 citations
- High-Order Masking of Lattice Signatures in Quasilinear TimeRafaël del Pino, Thomas Prest, Mélissa Rossi, Markku-Juhani O. SaarinenS&P 2023
