Shorter Hash-and-Sign Lattice-Based Signatures
Thomas Espitau, Mehdi Tibouchi, Alexandre Wallet, Yang Yu
Abstract
Lattice-based digital signature schemes following the hashand-sign design paradigm of Gentry, Peikert and Vaikuntanathan (GPV) tend to offer an attractive level of efficiency, particularly when instantiated with structured compact trapdoors. In particular, NIST postquantum finalist Falcon is both quite fast for signing and verification and quite compact: NIST notes that it has the smallest bandwidth (as measured in combined size of public key and signature) of all round 2 digital signature candidates. Nevertheless, while Falcon-512, for instance, compares favorably to ECDSA-384 in terms of speed, its signatures are well over 10 times larger. For applications that store large number of signatures, or that require signatures to fit in prescribed packet sizes, this can be a critical limitation.
In this paper, we explore several approaches to further improve the size of hash-and-sign lattice-based signatures, particularly instantiated over NTRU lattices like Falcon and its recent variant Mitaka. In particular, while GPV signatures are usually obtained by sampling lattice points according to some spherical discrete Gaussian distribution, we show that it can be beneficial to sample instead according to a suitably chosen ellipsoidal discrete Gaussian: this is because only half of the sampled Gaussian vector is actually output as the signature, while the other half is recovered during verification. Making the half that actually occurs in signatures shorter reduces signature size at essentially no security loss (in a suitable range of parameters). Similarly, we show that reducing the modulus q with respect to which signatures are computed can improve signature size as well as verification key size almost "for free"; this is particularly true for constructions like Falcon and Mitaka that do not make substantial use of NTT-based multiplication (and rely instead on transcendental FFT). Finally, we show that the Gaussian vectors in signatures can be represented in a more compact way with appropriate coding-theoretic techniques, improving signature size by an additional 7 to 14%. All in all, we manage to reduce the size of, e.g., Falcon signatures by 30-40% at the cost of only 4-6 bits of Core-SVP security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3828d3ab-cd79-406e-a4b4-253924be2e0fCited by top-tier papers8
- Practical, Round-Optimal Lattice-Based Blind SignaturesShweta Agrawal, Elena Kirshanova, Damien Stehlé, Anshu YadavCCS 2022 · 52 citations
- Compact Lattice Gadget and Its Applications to Hash-and-Sign SignaturesYang Yu, Huiwen Jia, Xiaoyun WangCRYPTO 2023 · 35 citations
- Finding Short Integer Solutions When the Modulus Is SmallLéo Ducas, Thomas Espitau, Eamonn W. PostlethwaiteCRYPTO 2023 · 18 citations
- Practical Post-Quantum Signatures for PrivacySven Argo, Tim Güneysu, Corentin Jeudy, Georg Land et al.CCS 2024 · 11 citations
- Leap: A Fast, Lattice-Based OPRF with Application to Private Set IntersectionLena Heimberger, Daniel Kales, Riccardo Lolato, Omid Mir et al.EUROCRYPT 2025 · 9 citations
Builds on5
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 972 citations
- Improved Cryptanalysis of UOV and RainbowWard BeullensEUROCRYPT 2021 · 96 citations
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi et al.EUROCRYPT 2022 · 67 citations
- The rank of sparse random matricesAmin Coja-Oghlan, Alperen Ali Ergür, Pu Gao, Samuel Hetterich et al.SODA 2020 · 19 citations
- Fast Reduction of Algebraic Lattices over Cyclotomic FieldsPaul Kirchner, Thomas Espitau, Pierre-Alain FouqueCRYPTO 2020 · 12 citations
Related papers
- Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU LatticesPierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet et al.EUROCRYPT 2020 · 19 citations
- Compact Lattice Signatures via Iterative Rejection SamplingJoel GärtnerCRYPTO 2025 · 2 citations
- DualMS 2.0: Practical Lattice-Based Two-Round Fiat-Shamir Multi-Signature with Better EfficiencyQiqi Lai, Chongshen Chen, Feng Hao Liu, Tianyu Zhao et al.CCS 2026
- TACHYON: Fast Signatures from Compact KnapsackRouzbeh Behnia, Muslum Ozgur Ozmen, Attila A. Yavuz, Mike RosulekCCS 2018 · 12 citations
- A Closer Look at FalconPierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck et al.EUROCRYPT 2026 · 15 citations
