DualRing: Generic Construction of Ring Signatures with Efficient Instantiations
Tsz Hon Yuen, Muhammed F. Esgin, Joseph K. Liu, Man Ho Au, Zhimin Ding
Abstract
We introduce a novel generic ring signature construction, called DualRing, which can be built from several canonical identification schemes (such as Schnorr identification). DualRing differs from the classical ring signatures by its formation of two rings: a ring of commitments and a ring of challenges. It has a structural difference from the common ring signature approaches based on accumulators or zero-knowledge proofs of the signer index. Comparatively, DualRing has a number of unique advantages.
Considering the DL-based setting by using Schnorr identification scheme, our DualRing structure allows the signature size to be compressed into logarithmic size via an argument of knowledge system such as Bulletproofs. We further improve on the Bulletproofs argument system to eliminate about half of the computation while maintaining the same proof size. We call this Sum Argument and it can be of independent interest. This DL-based construction, named DualRing-EC, using Schnorr identification with Sum Argument has the shortest ring signature size in the literature without using trusted setup.
Considering the lattice-based setting, we instantiate DualRing by a canonical identification based on M-LWE and M-SIS. In practice, we achieve the shortest lattice-based ring signature, named DualRing-LB, when the ring size is between 4 and 2000. DualRing-LB is also 5x faster in signing and verification than the fastest lattice-based scheme by Esgin et al. (CRYPTO'19).
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 90824fe6-0df4-44c0-9451-6f623e7a801eCited by top-tier papers7
- K-Waay: Fast and Deniable Post-Quantum X3DH without Ring SignaturesDaniel Collins, Loïs Huguenin-Dumittan, Ngoc Khanh Nguyen, Nicolas Rolin et al.USENIX Security 2024 · 12 citations
- Posterior Security: Anonymity and Message Hiding of Standard SignaturesTsz Hon Yuen, Ying-Teng Chen, Shimin Pan, Jiangshan Yu et al.CCS 2025 · 2 citations
- Shadowfax: Hybrid Security and Deniability for AKEMsPhillip Gajland, Vincent Hwang, Jonas JanneckUSENIX Security 2026
- Efficient Constant-Size Linkable Ring Signatures for Ad-Hoc Rings via Pairing-Based Set Membership ArgumentsMin Xie, Zhengzhou Tu, Man Ho Au, Junbin Fang et al.CCS 2025
- Comprehensive Deniability Analysis of Signal Handshake Protocols: X3DH, PQXDH to Fully Post-Quantum with Deniable Ring SignaturesShuichi Katsumata, Guilhem Niot, Ida Tucker, Thom WiggersUSENIX Security 2025
Related papers
- Compact Ring Signatures from Learning with ErrorsRohit Chatterjee, Sanjam Garg, Mohammad Hajiabadi, Dakshita Khurana et al.CRYPTO 2021 · 22 citations
- Ring Signatures for Deniable AKEM: Gandalf's FellowshipPhillip Gajland, Jonas Janneck, Eike KiltzCRYPTO 2024 · 8 citations
- Group Signatures and More from Isogenies and Lattices: Generic, Simple, and EfficientWard Beullens, Samuel Dobson, Shuichi Katsumata, Yi-Fu Lai et al.EUROCRYPT 2022 · 51 citations
- Just One Bit Vector: Complement-Free Ring Confidential Transactions with Transparent SetupHao Gao, Qianhong Wu, Bo Qin, Fudong Wu et al.USENIX Security 2026
- DualMS 2.0: Practical Lattice-Based Two-Round Fiat-Shamir Multi-Signature with Better EfficiencyQiqi Lai, Chongshen Chen, Feng Hao Liu, Tianyu Zhao et al.CCS 2026
