Syndrome Decoding in the Head: Shorter Signatures from Zero-Knowledge Proofs
Thibauld Feneuil, Antoine Joux, Matthieu Rivain
Abstract
. Zero-knowledge proofs of knowledge are useful tools to design signature schemes. The on-going effort to build a quantum computer urges the cryptography community to develop new secure cryptographic protocols based on quantum-hard cryptographic problems. One of the few directions is code-based cryptography for which the strongest problem is the syndrome decoding (SD) for random linear codes. This problem is known to be NP -hard and the cryptanalysis state of the art has been stable for many years. A zero-knowledge protocol for this problem was pioneered by Stern in 1993. Since its publication, many articles proposed optimizations, implementation, or variants. In this paper, we introduce a new zero-knowledge proof for the syndrome decoding problem on random linear codes. Instead of using permutations like most of the existing protocols, we rely on the MPC-in-the-head paradigm in which we reduce the task of proving the low Hamming weight of the SD solution to proving some relations between specific polynomials. Specifically, we propose a 5-round zero-knowledge protocol that proves the knowledge of a vector x such that y = Hx and wt( x ) ≤ w and which achieves a soundness error closed to 1 /N for an arbitrary N . While turning this protocol into a signature scheme, we achieve a signature size of 11-12 KB for 128-bit security when relying on the hardness of the SD problem on binary fields. Using larger fields (like F 2 8 ), we can produce fast signatures of around 8 KB. This allows us to outperform Picnic3 and to be competitive with SPHINCS + , both post-quantum signature candidates in the ongoing NIST standardization effort. Moreover, our scheme outperforms all the existing code-based signature schemes for the common “signature size + public key size” metric.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext de961de8-8506-4b22-adf6-28f7f68e1ff1Cited by top-tier papers4
- Publicly Verifiable Zero-Knowledge and Post-Quantum Signatures from VOLE-in-the-HeadCarsten Baum, Lennart Braun, Cyprien Delpech de Saint Guilhem, Michael Klooß et al.CRYPTO 2023 · 75 citations
- Short Signatures from Regular Syndrome Decoding in the HeadEliana Carozza, Geoffroy Couteau, Antoine JouxEUROCRYPT 2023 · 25 citations
- Reduction from Sparse LPN to LPN, Dual Attack 3.0Kévin Carrier, Thomas Debris-Alazard, Charles Meyer-Hilfiger, Jean-Pierre TillichEUROCRYPT 2024 · 13 citations
- Amortizing Randomness Cost: Efficient Masked Implementation of SDitH Signatures with Common SharesGuowei Liu, Weijia Wang, Lixuan Wu, Chaoran Wang et al.USENIX Security 2026
Builds on2
Related papers
- The Return of the SDitHCarlos Aguilar Melchor, Nicolas Gama, James Howe, Andreas Hülsing et al.EUROCRYPT 2023 · 40 citations
- Improved Non-Interactive Zero Knowledge with Applications to Post-Quantum SignaturesJonathan Katz, Vladimir Kolesnikov, Xiao WangCCS 2018 · 257 citations
- The LaZer Library: Lattice-Based Zero Knowledge and Succinct Proofs for Quantum-Safe PrivacyVadim Lyubashevsky, Gregor Seiler, Patrick SteuerCCS 2024 · 13 citations
- Practical Post-Quantum Signature Schemes from Isomorphism Problems of Trilinear FormsGang Tang, Dung Hoang Duong, Antoine Joux, Thomas Plantard et al.EUROCRYPT 2022 · 36 citations
- Message-Recovery Laser Fault Injection Attack on the Classic McEliece CryptosystemPierre-Louis Cayrel, Brice Colombier, Vlad-Florin Dragoi, Alexandre Menu et al.EUROCRYPT 2021 · 28 citations
