On One-Shot Signatures, Quantum vs. Classical Binding, and Obfuscating Permutations
Omri Shmueli, Mark Zhandry
Abstract
One-shot signatures (OSS) were defined by Amos, Georgiou, Kiayias, and Zhandry (STOC'20). These allow for signing exactly one message, after which the signing key self-destructs, preventing a second message from ever being signed. While such an object is impossible classically, Amos et al observe that OSS may be possible using quantum signing keys by leveraging the no-cloning principle. OSS has since become an important conceptual tool with many applications in decentralized settings and for quantum cryptography with classical communication. OSS are also closely related to separations between classical-binding and collapse-binding for post-quantum hashing and commitments. Unfortunately, the only known OSS construction due to Amos et al. was only justified in a classical oracle model, and moreover their justification was ultimately found to contain a fatal bug. Thus, the existence of OSS, even in a classical idealized model, has remained open. We give the first standard-model OSS, with provable security assuming (sub-exponential) indistinguishability obfuscation (iO) and LWE. This also gives the first standard-model separation between classical and collapse-binding post-quantum commitments/hashing, solving a decade-old open problem. Along the way, we also give the first construction with unconditional security relative to a classical oracle. To achieve our standard-model construction, we develop a notion of permutable pseudorandom permutations (permutable PRPs), and show how they are useful for translating oracle proofs involving random permutations into obfuscation-based proofs. In particular, obfuscating permutable PRPs gives a trapdoor one-way permutation that is full-domain, solving another decade-old-problem of constructing this object from (sub-exponential) iO and one-way functions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8f4d0017-6f12-40ba-b07b-568cc32a0e0fCited by top-tier papers3
- On the Cryptographic Futility of Non-collapsing MeasurementsAlper Çakan, Dakshita Khurana, Tomoyuki Morimae, Yuki Shirakawa et al.EUROCRYPT 2026 · 1 citation
- On the Cryptographic Foundations of Interactive Quantum AdvantageKabir Tomer, Mark ZhandrySTOC 2026 · 1 citation
- Public-Key Quantum Fire and Key-Fire From Classical OraclesAlper Çakan, Vipul Goyal, Omri ShmueliCRYPTO 2026
Builds on10
- Puncturable Pseudorandom Sets and Private Information Retrieval with Near-Optimal Online Bandwidth and TimeElaine Shi, Waqar Aqeel, Balakrishnan Chandrasekaran, Bruce M. MaggsCRYPTO 2021 · 38 citations
- Cryptography with Certified DeletionJames Bartusek, Dakshita KhuranaCRYPTO 2023 · 25 citations
- Another Round of Breaking and Making Quantum Money: - How to Not Build It from Lattices, and MoreJiahui Liu, Hart Montgomery, Mark ZhandryEUROCRYPT 2023 · 21 citations
- Public-key Quantum money with a classical bankOmri ShmueliSTOC 2022 · 20 citations
- Semi-quantum Tokenized SignaturesOmri ShmueliCRYPTO 2022 · 15 citations
Related papers
- One-shot signatures and applications to hybrid quantum/classical authenticationRyan Amos, Marios Georgiou, Aggelos Kiayias, Mark ZhandrySTOC 2020 · 6 citations
- Uncloneable Cryptography in Linear Quantum MemoryAndrew Huang, Omri Shmueli, Vinod Vaikuntanathan, Mark ZhandryCRYPTO 2026 · 2 citations
- New Constructions of Collapsing HashesMark ZhandryCRYPTO 2022 · 7 citations
- Quantum Commitments and Signatures Without One-Way FunctionsTomoyuki Morimae, Takashi YamakawaCRYPTO 2022 · 74 citations
- Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only IndifferentiabilityMihir Bellare, Hannah Davis, Felix GüntherEUROCRYPT 2020 · 35 citations
