Compact Lattice Gadget and Its Applications to Hash-and-Sign Signatures
Yang Yu, Huiwen Jia, Xiaoyun Wang
Abstract
Lattice gadgets and the associated algorithms are the essential building blocks of lattice-based cryptography. In the past decade, they have been applied to build versatile and powerful cryptosystems. However, the practical optimizations and designs of gadget-based schemes generally lag their theoretical constructions. For example, the gadgetbased signatures have elegant design and capability of extending to more advanced primitives, but they are far less efficient than other latticebased signatures. This work aims to improve the practicality of gadget-based cryptosystems, with a focus on hash-and-sign signatures. To this end, we develop a compact gadget framework in which the used gadget is a square matrix instead of the short and fat one used in previous constructions. To work with this compact gadget, we devise a specialized gadget sampler, called semi-random sampler, to compute the approximate preimage. It first deterministically computes the error and then randomly samples the preimage. We show that for uniformly random targets, the preimage and error distributions are simulatable without knowing the trapdoor. This ensures the security of the signature applications. Compared to the Gaussian-distributed errors in previous algorithms, the deterministic errors have a smaller size, which lead to a substantial gain in security and enables a practically working instantiation. As the applications, we present two practically efficient gadget-based signature schemes based on NTRU and Ring-LWE respectively. The NTRUbased scheme offers comparable efficiency to Falcon and Mitaka and a simple implementation without the need of generating the NTRU trapdoor. The LWE-based scheme also achieves a desirable overall perfor-mance. It not only greatly outperforms the state-of-the-art LWE-based hash-and-sign signatures, but also has an even smaller size than the LWE-based Fiat-Shamir signature scheme Dilithium. These results fill the long-term gap in practical gadget-based signatures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 91d2f340-02c7-4f69-97a5-322065a3d624Cited by top-tier papers3
- A Closer Look at FalconPierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck et al.EUROCRYPT 2026 · 15 citations
- Plover: Masking-Friendly Hash-and-Sign Lattice SignaturesMuhammed F. Esgin, Thomas Espitau, Guilhem Niot, Thomas Prest et al.EUROCRYPT 2024 · 14 citations
- Lattice-Based Threshold Blind SignaturesSebastian Faller, Guilhem Niot, Michael ReichleS&P 2026 · 2 citations
Builds on4
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 972 citations
- On the Lattice Isomorphism Problem, Quadratic Forms, Remarkable Lattices, and CryptographyLéo Ducas, Wessel P. J. van WoerdenEUROCRYPT 2022 · 67 citations
- Shorter Hash-and-Sign Lattice-Based SignaturesThomas Espitau, Mehdi Tibouchi, Alexandre Wallet, Yang YuCRYPTO 2022 · 38 citations
- Integral Matrix Gram Root and Lattice Gaussian Sampling Without FloatsLéo Ducas, Steven D. Galbraith, Thomas Prest, Yang YuEUROCRYPT 2020 · 22 citations
Related papers
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi et al.EUROCRYPT 2022 · 67 citations
- Compact Lattice Signatures via Iterative Rejection SamplingJoel GärtnerCRYPTO 2025 · 2 citations
- Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU LatticesPierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet et al.EUROCRYPT 2020 · 19 citations
- DualMS 2.0: Practical Lattice-Based Two-Round Fiat-Shamir Multi-Signature with Better EfficiencyQiqi Lai, Chongshen Chen, Feng Hao Liu, Tianyu Zhao et al.CCS 2026
- Tight Lattice-Based Signatures Without Trapdoors from Search LWERutchathon Chairattana-Apirom, Nico Döttling, Julian Loss, Stefano Tessaro et al.CRYPTO 2026
