A Detailed Analysis of Fiat-Shamir with Aborts
Julien Devevey, Pouria Fallahpour, Alain Passelègue, Damien Stehlé
Abstract
Lyubashevky's signatures are based on the Fiat-Shamir with Aborts paradigm. It transforms an interactive identification protocol that has a non-negligible probability of aborting into a signature by repeating executions until a loop iteration does not trigger an abort. Interaction is removed by replacing the challenge of the verifier by the evaluation of a hash function, modeled as a random oracle in the analysis. The access to the random oracle is classical (ROM), resp. quantum (QROM), if one is interested in security against classical, resp. quantum, adversaries. Most analyses in the literature consider a setting with a bounded number of aborts (i.e., signing fails if no signature is output within a prescribed number of loop iterations), while practical instantiations (e.g., Dilithium) run until a signature is output (i.e., loop iterations are unbounded).
In this work, we emphasize that combining random oracles with loop iterations induces numerous technicalities for analyzing correctness, run-time, and security of the resulting schemes, both in the bounded and unbounded case. As a first contribution, we put light on errors in all existing analyses. We then provide two detailed analyses in the QROM for the bounded case, adapted from Kiltz, Lyubashevsky, and Shaffner [EUROCRYPT'18] and from Grilo, Hövelmanns, Hülsing, and Majenz [ASIACRYPT'21]. In the process, we prove the underlying -protocol to achieve a stronger zero-knowledge property than usually considered for -protocols with aborts, which enables a corrected analysis. A further contribution is a detailed analysis in the case of unbounded aborts, the latter inducing several additional subtleties.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 7a0802b1-6abd-4ca6-a7a0-42db8394839fCited by top-tier papers3
- Evaluating the Security of CRYSTALS-Dilithium in the Quantum Random Oracle ModelKelsey A. Jackson, Carl A. Miller, Daochen WangEUROCRYPT 2024 · 14 citations
- Tighter Quantum Security for Fiat-Shamir-with-Aborts and Hash-and-Sign-with-Retry SignaturesPouria Fallahpour, Serge Fehr, Yu-Hsuan HuangCRYPTO 2026 · 3 citations
- Quorus: Efficient, Scalable Threshold ML-DSA Signatures from MPCAlexander Bienstock, Leo de Castro, Daniel Escudero, Antigoni Polychroniadou et al.USENIX Security 2026 · 1 citation
Related papers
- Fixing and Mechanizing the Security Proof of Fiat-Shamir with Aborts and DilithiumManuel Barbosa, Gilles Barthe, Christian Doczkal, Jelle Don et al.CRYPTO 2023 · 33 citations
- The Measure-and-Reprogram Technique 2.0: Multi-round Fiat-Shamir and MoreJelle Don, Serge Fehr, Christian MajenzCRYPTO 2020 · 61 citations
- Efficient NIZKs and Signatures from Commit-and-Open Protocols in the QROMJelle Don, Serge Fehr, Christian Majenz, Christian SchaffnerCRYPTO 2022 · 15 citations
- Aborting Random Oracles: How to Build Them, How to Use ThemGottfried Herold, Dmitry Khovratovich, Mikhail A. Kudinov, Stefano Tessaro et al.CRYPTO 2026
- Polytopes in the Fiat-Shamir with Aborts ParadigmHenry Bambury, Hugo Beguinet, Thomas Ricosset, Éric SageloliCRYPTO 2024 · 5 citations
