Aggregating Falcon Signatures with LaBRADOR
Marius A. Aardal, Diego F. Aranha, Katharina Boudgoust, Sebastian Kolby, Akira Takahashi
Abstract
Several prior works have suggested to use non-interactive arguments of knowledge with short proofs to aggregate signatures of Falcon, which is part of the first post-quantum signatures selected for standardization by NIST. Especially LaBRADOR, based on standard structured lattice assumptions and published at CRYPTO’23, seems promising to realize this task. However, no prior work has tackled this idea in a rigorous way. In this paper, we thoroughly prove how to aggregate Falcon signatures using LaBRADOR. We start by providing the first complete knowledge soundness analysis for the non-interactive version of LaBRADOR. Here, the multi-round and recursive nature of LaBRADOR requires a complex and thorough analysis. For this purpose, we introduce the notion of predicate special soundness (PSS). This is a general framework for evaluating the knowledge error of complex Fiat-Shamir arguments of knowledge protocols in a modular fashion, which we believe to be of independent interest. We then explain the exact steps to take in order to adapt the non-interactive LaBRADOR proof system for aggregating Falcon signatures and provide concrete proof size estimates. Additionally, we formalize the folklore approach of obtaining aggregate signatures from the class of hash-then-sign signatures through arguments of knowledge.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b8e325cc-e233-41dc-9fc0-7dd40187b2eaCited by top-tier papers3
- Unmasking TRaccoon: A Lattice-Based Threshold Signature with An Efficient Identifiable Abort ProtocolRafaël Del Pino, Shuichi Katsumata, Guilhem Niot, Michael Reichle et al.CRYPTO 2025 · 8 citations
- Leftover Hash Lemma(s) Over Cyclotomic RingsKatharina Boudgoust, Oleksandra LapihaEUROCRYPT 2026 · 3 citations
- KZH-Fold: Accountable Voting from Sublinear AccumulationGeorge Kadianakis, Arantxa Zapico, Hossein Hafezi, Benedikt BünzCCS 2025 · 1 citation
Builds on15
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- Lattice-Based Zero-Knowledge Proofs and Applications: Shorter, Simpler, and More GeneralVadim Lyubashevsky, Ngoc Khanh Nguyen, Maxime PlançonCRYPTO 2022 · 125 citations
- Lattice-Based SNARKs: Publicly Verifiable, Preprocessing, and Recursively Composable - (Extended Abstract)Martin R. Albrecht, Valerio Cini, Russell W. F. Lai, Giulio Malavolta et al.CRYPTO 2022 · 73 citations
- Practical Non-interactive Publicly Verifiable Secret Sharing with Thousands of PartiesCraig Gentry, Shai Halevi, Vadim LyubashevskyEUROCRYPT 2022 · 65 citations
- Practical Product Proofs for Lattice CommitmentsThomas Attema, Vadim Lyubashevsky, Gregor SeilerCRYPTO 2020 · 60 citations
Related papers
- A Closer Look at FalconPierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck et al.EUROCRYPT 2026 · 15 citations
- Orthus: Practical Sublinear Batch-Verification of Lattice Relations from Standard AssumptionsMadalina Bolboceanu, Jonathan Bootle, Vadim Lyubashevsky, Antonio Merino-Gallardo et al.CRYPTO 2026 · 1 citation
- A Toolkit for Succinct Lattice-Based Zero Knowledge ProofsBeatrice Biasioli, Madalina Bolboceanu, Vadim Lyubashevsky, Antonio Merino-Gallardo et al.CCS 2026 · 1 citation
- Loquat: A SNARK-Friendly Post-quantum Signature Based on the Legendre PRF with Applications in Ring and Aggregate SignaturesXinyu Zhang, Ron Steinfeld, Muhammed F. Esgin, Joseph K. Liu et al.CRYPTO 2024 · 6 citations
- LaBRADOR: Compact Proofs for R1CS from Module-SISWard Beullens, Gregor SeilerCRYPTO 2023 · 59 citations
