The Algebraic One-More MISIS Problem and Applications to Threshold Signatures
Chenzhi Zhu, Stefano Tessaro
Abstract
This paper introduces a new one-more computational problem for lattice-based cryptography, which we refer to as the Algebraic One-More MISIS problem, or AOM-MISIS for short. It is a modification of the AOM-MLWE problem recently introduced by Espitau et al. (CRYPTO '24) to prove security of new two-round threshold signatures.
Our first main result establishes that the hardness of AOM-MISIS is implied by the hardness of MSIS and MLWE (with suitable parameters), both of which are standard assumptions for efficient lattice-based cryptography. We prove this result via a new generalization of a technique by Tessaro and Zhu (EUROCRYPT '23) used to prove hardness of a one-more problem for linear hash functions assuming their collision resistance, for which no clear lattice analogue was known. Since the hardness of AOM-MISIS implies the hardness of AOM-MLWE, our result resolves the main open question from the work of Espitau et al., who only provided a similar result for AOM-MLWE restricted to selective adversaries, a class which does not cover the use for threshold signatures.
Furthermore, we show that our novel formulation of AOM-MISIS offers a better interface to develop tighter security bounds for state-of-the-art two-round threshold signatures. We exemplify this by providing new proofs of security, assuming the hardness of MLWE and MSIS, for two threshold signatures, the one proposed in the same work by Espitau et al., as well as a recent construction by Chairattana-Apirom et al. (ASIACRYPT 2024). For the former scheme, we also show that it satisfies the strongest security notion (TS-UF-4) in the security hierarchy of Bellare et al. (CRYPTO '22), as a result of independent interest.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 43f08602-e2a5-4ecf-8629-301c646d5513Cited by top-tier papers3
- Quorus: Efficient, Scalable Threshold ML-DSA Signatures from MPCAlexander Bienstock, Leo de Castro, Daniel Escudero, Antigoni Polychroniadou et al.USENIX Security 2026 · 1 citation
- Olingo: Threshold Lattice Signatures with DKG and Identifiable AbortKamil Doruk Gur, Patrick Hough, Jonathan Katz, Caroline Sandsbråten et al.CCS 2026
- A Full Threshold NIST PQC-Compliant Framework for Distributed Trust in Federal Public Key InfrastructureKiarash Sedghighadikolaei, Changqi Sun, Thang Hoang, Bechir Hamdaoui et al.S&P 2026
Related papers
- Two-Round Threshold Signature from Algebraic One-More Learning with ErrorsThomas Espitau, Shuichi Katsumata, Kaoru TakemureCRYPTO 2024 · 25 citations
- Tweed: Adaptively Secure Lattice-Based Two-Round Threshold SignaturesKaijie Jiang, Stefano Tessaro, Hoeteck Wee, Chenzhi ZhuEUROCRYPT 2026 · 1 citation
- Adaptively Secure Partially Non-interactive Threshold Schnorr Signatures in the AGMRenas Bacho, Yanbo Chen, Julian Loss, Stefano Tessaro et al.EUROCRYPT 2026 · 5 citations
- Threshold and Multi-signature Schemes from Linear Hash FunctionsStefano Tessaro, Chenzhi ZhuEUROCRYPT 2023 · 48 citations
- Adaptively Secure 5 Round Threshold Signatures from MLWE/MSIS and DL with RewindingShuichi Katsumata, Michael Reichle, Kaoru TakemureCRYPTO 2024 · 34 citations
