Shorter Signatures Based on Tailor-Made Minimalist Symmetric-Key Crypto
Christoph Dobraunig, Daniel Kales, Christian Rechberger, Markus Schofnegger, Greg Zaverucha
Abstract
Signature schemes based on the MPC-in-the-head approach (MPCitH) have either been designed by taking a proof system and selecting a suitable symmetric-key primitive (Picnic, CCS16), or starting with an existing primitive such as AES and trying to find the most suitable proof system (BBQ, SAC19 or Banquet, PKC21). In this work we do both: we improve certain symmetric-key primitives to better fit existing signature schemes, and we also propose a new signature scheme that combines a new, minimalist one-way function with changes to a proof system to make their combination even more efficient. Our concrete results are as follows. First, we show how to provably remove the need to include the key schedule of block ciphers. This simplifies schemes like Picnic and it also leads to the fastest and smallest AES-based signatures, where we achieve signature sizes of around 10.8 to 14.2 KB using AES-128, on average 10% shorter than Banquet and 15% faster. Second, we investigate a variant of AES with larger S-boxes we call LSAES, for which we argue that it is likely to be at least as strong as AES, further reducing the size of AES-based signatures to 9.9 KB. Finally, we present a new signature scheme, Rainier, combining a new one-way function called Rain with a Banquet-like proof system. To the best of our knowledge, it is the first MPCitH-based signature scheme which can produce signatures that are less than 5 KB in size; it also outperforms previous Picnic and Banquet instances in all performance metrics. Contributions. In this work, we investigate three methods of reducing MPCitH signature sizes further, while simultaneously improving the performance of signing and verification. Our results cover a range of options from more conservative (but less performant), to more performant (but with stronger assumptions). • We investigate the use of AES as a public permutation in a single-key Even-Mansour construction. The use of a public constant for the AES key removes the need to calculate the AES key schedule as part of the MPC protocol, reducing the number of S-boxes (and therefore inversions) from 200 to 160 for AES-128, which leads to smaller signatures using the Banquet proof system. • In Banquet, the in-and outputs to the inverse functions are lifted from the AES field F 2 8 to a larger field F 2 8λ to reduce the soundness error of the protocol. This step leads to an increase in signature size, since elements
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c1502add-ee2b-4615-a61b-dabd6b99313cCited by top-tier papers4
- Publicly Verifiable Zero-Knowledge and Post-Quantum Signatures from VOLE-in-the-HeadCarsten Baum, Lennart Braun, Cyprien Delpech de Saint Guilhem, Michael Klooß et al.CRYPTO 2023 · 75 citations
- Coefficient Grouping for Complex Affine LayersFukang Liu, Lorenzo Grassi, Clémence Bouvier, Willi Meier et al.CRYPTO 2023 · 10 citations
- Proof-of-Possession for KEM Certificates using Verifiable GenerationTim Güneysu, Philip W. Hodges, Georg Land, Mike Ounsworth et al.CCS 2022 · 7 citations
- Concretely Efficient Blind Signatures Based on VOLE-in-the-Head Proofs and the MAYO TrapdoorCarsten Baum, Marvin Beckmann, Ward Beullens, Shibam Mukherjee et al.USENIX Security 2026 · 1 citation
Builds on10
- The SPHINCS+ Signature FrameworkDaniel J. Bernstein, Andreas Hülsing, Stefan Kölbl, Ruben Niederhagen et al.CCS 2019 · 385 citations
- Post-Quantum Zero-Knowledge and Signatures from Symmetric-Key PrimitivesMelissa Chase, David Derler, Steven Goldfeder, Claudio Orlandi et al.CCS 2017 · 316 citations
- ZKBoo: Faster Zero-Knowledge for Boolean CircuitsIrene Giacomelli, Jesper Madsen, Claudio OrlandiUSENIX Security 2016 · 287 citations
- Improved Non-Interactive Zero Knowledge with Applications to Post-Quantum SignaturesJonathan Katz, Vladimir Kolesnikov, Xiao WangCCS 2018 · 257 citations
- Implementing Grover Oracles for Quantum Key Search on AES and LowMCSamuel Jaques, Michael Naehrig, Martin Roetteler, Fernando VirdiaEUROCRYPT 2020 · 226 citations
Related papers
- Limbo: Efficient Zero-knowledge MPCitH-based ArgumentsCyprien Delpech de Saint Guilhem, Emmanuela Orsini, Titouan TanguyCCS 2021 · 4 citations
- Shorter, Tighter, FAESTer: Optimizations and Improved (QROM) Analysis for VOLE-in-the-Head SignaturesCarsten Baum, Ward Beullens, Lennart Braun, Cyprien Delpech de Saint Guilhem et al.CRYPTO 2025 · 2 citations
- Improved Alternating-Moduli PRFs and Post-quantum SignaturesNavid Alamati, Guru-Vamsi Policharla, Srinivasan Raghuraman, Peter RindalCRYPTO 2024 · 16 citations
- AIM: Symmetric Primitive for Shorter Signatures with Stronger SecuritySeongkwang Kim, Jincheol Ha, Mincheol Son, ByeongHak Lee et al.CCS 2023 · 19 citations
- Magic Pot: Cryptanalysis of Full AIM2 in the Standard and Related-/reused-Key Settings Using New Elimination FrameworkAlex Biryukov, Pablo García Fernández, Aleksei UdovenkoEUROCRYPT 2026 · 1 citation
