Group Signatures and More from Isogenies and Lattices: Generic, Simple, and Efficient
Ward Beullens, Samuel Dobson, Shuichi Katsumata, Yi-Fu Lai, Federico Pintore
Abstract
We construct an efficient dynamic group signature (or more generally an accountable ring signature) from isogeny and lattice assumptions. Our group signature is based on a simple generic construction that can be instantiated by cryptographically hard group actions such as the CSIDH group action or an MLWE-based group action. The signature is of size O(log N ), where N is the number of users in the group. Our idea builds on the recent efficient OR-proof by Beullens, Katsumata, and Pintore (Asiacrypt'20), where we efficiently add a proof of valid ciphertext to their OR-proof and further show that the resulting non-interactive zero-knowledge proof system is online extractable.
Our group signatures satisfy more ideal security properties compared to previously known constructions, while simultaneously having an attractive signature size. The signature size of our isogeny-based construction is an order of magnitude smaller than all previously known post-quantum group signatures (e.g., 6.6 KB for 64 members). In comparison, our lattice-based construction has a larger signature size (e.g., either 126 KB or 89 KB for 64 members depending on the satisfied security property). However, since the O(•)-notation hides a very small constant factor, it remains small even for very large group sizes, say 2 20 .
- 128 bits of classical security and 60 bits of quantum security [Pei20].
malicious group manager can frame any honest members in the group by simply replacing the output of the opening algorithm. In contrast, our scheme remains secure even against malicious group managers since the validity of the output of the opening algorithm is verifiable. That is, even the group manager is held accountable in our group signature.
Not only our group signatures satisfy more ideal security properties compared to previous constructions, Tab. 1 shows that our signature size remains competitive. Our isogeny-based group signature based on CSIDH provides the smallest signature size among all post-quantum group signatures, which is 0.6 log 2 (N )+3 KB. In contrast, our lattice signature is larger; the scheme in the second (resp. third) row has signature size 0.5 log 2 (N ) + 123.5 KB (resp. 0.5 log 2 (N ) + 85.9 KB). It is smaller compared to [KKW18], while larger compared to [ESZ22]. Compared to the two constructions, our signature size grows much slower with the group size N (see also Footnote 1) and also satisfies stronger security. We thus leave it as an interesting open problem to lower the constants in our construction.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bbf6f591-d5f2-4cca-80ad-0c8576c6cb10Cited by top-tier papers5
- Lattice-Based Zero-Knowledge Proofs and Applications: Shorter, Simpler, and More GeneralVadim Lyubashevsky, Ngoc Khanh Nguyen, Maxime PlançonCRYPTO 2022 · 125 citations
- A New Framework for More Efficient Round-Optimal Lattice-Based (Partially) Blind Signature via Trapdoor SamplingRafaël del Pino, Shuichi KatsumataCRYPTO 2022 · 50 citations
- Practical Lattice-Based Zero-Knowledge Proofs for Integer RelationsVadim Lyubashevsky, Ngoc Khanh Nguyen, Gregor SeilerCCS 2020 · 41 citations
- CSI -Otter: Isogeny-Based (Partially) Blind Signatures from the Class Group Action with a TwistShuichi Katsumata, Yi-Fu Lai, Jason T. LeGrow, Ling QinCRYPTO 2023 · 22 citations
- Exploring How to Authenticate Application Messages in MLS: More Efficient, Post-Quantum, and Anonymous BlocklistableKeitaro Hashimoto, Shuichi Katsumata, Guillermo Pascual-PerezUSENIX Security 2025
Builds on12
- Improved Non-Interactive Zero Knowledge with Applications to Post-Quantum SignaturesJonathan Katz, Vladimir Kolesnikov, Xiao WangCCS 2018 · 257 citations
- He Gives C-Sieves on the CSIDHChris PeikertEUROCRYPT 2020 · 120 citations
- MatRiCT: Efficient, Scalable and Post-Quantum Blockchain Confidential Transactions ProtocolMuhammed F. Esgin, Raymond K. Zhao, Ron Steinfeld, Joseph K. Liu et al.CCS 2019 · 104 citations
- Quantum Security Analysis of CSIDHXavier Bonnetain, André SchrottenloherEUROCRYPT 2020 · 103 citations
- Lattice-Based Group Signatures and Zero-Knowledge Proofs of Automorphism StabilityRafaël del Pino, Vadim Lyubashevsky, Gregor SeilerCCS 2018 · 84 citations
Related papers
- Practical, Round-Optimal Lattice-Based Blind SignaturesShweta Agrawal, Elena Kirshanova, Damien Stehlé, Anshu YadavCCS 2022 · 52 citations
- Compact Ring Signatures from Learning with ErrorsRohit Chatterjee, Sanjam Garg, Mohammad Hajiabadi, Dakshita Khurana et al.CRYPTO 2021 · 22 citations
- Post-Quantum Blind Signature from Standard Group Action Assumptions and MoreLucjan Hanzlik, Yi-Fu Lai, Eugenio Paracucchi, Edoardo PersichettiEUROCRYPT 2026 · 1 citation
- SQIsignHD: New Dimensions in CryptographyPierrick Dartois, Antonin Leroux, Damien Robert, Benjamin WesolowskiEUROCRYPT 2024 · 69 citations
- Lattice Signature with Efficient Protocols, Application to Anonymous CredentialsCorentin Jeudy, Adeline Roux-Langlois, Olivier SandersCRYPTO 2023 · 29 citations
