Shorter Hash-and-Sign Lattice-Based Signatures
Thomas Espitau, Mehdi Tibouchi, Alexandre Wallet, Yang Yu
摘要
Lattice-based digital signature schemes following the hashand-sign design paradigm of Gentry, Peikert and Vaikuntanathan (GPV) tend to offer an attractive level of efficiency, particularly when instantiated with structured compact trapdoors. In particular, NIST postquantum finalist Falcon is both quite fast for signing and verification and quite compact: NIST notes that it has the smallest bandwidth (as measured in combined size of public key and signature) of all round 2 digital signature candidates. Nevertheless, while Falcon-512, for instance, compares favorably to ECDSA-384 in terms of speed, its signatures are well over 10 times larger. For applications that store large number of signatures, or that require signatures to fit in prescribed packet sizes, this can be a critical limitation.
In this paper, we explore several approaches to further improve the size of hash-and-sign lattice-based signatures, particularly instantiated over NTRU lattices like Falcon and its recent variant Mitaka. In particular, while GPV signatures are usually obtained by sampling lattice points according to some spherical discrete Gaussian distribution, we show that it can be beneficial to sample instead according to a suitably chosen ellipsoidal discrete Gaussian: this is because only half of the sampled Gaussian vector is actually output as the signature, while the other half is recovered during verification. Making the half that actually occurs in signatures shorter reduces signature size at essentially no security loss (in a suitable range of parameters). Similarly, we show that reducing the modulus q with respect to which signatures are computed can improve signature size as well as verification key size almost "for free"; this is particularly true for constructions like Falcon and Mitaka that do not make substantial use of NTT-based multiplication (and rely instead on transcendental FFT). Finally, we show that the Gaussian vectors in signatures can be represented in a more compact way with appropriate coding-theoretic techniques, improving signature size by an additional 7 to 14%. All in all, we manage to reduce the size of, e.g., Falcon signatures by 30-40% at the cost of only 4-6 bits of Core-SVP security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Practical, Round-Optimal Lattice-Based Blind SignaturesShweta Agrawal, Elena Kirshanova, Damien Stehlé, Anshu YadavCCS 2022 · 被引用 52 次
- Compact Lattice Gadget and Its Applications to Hash-and-Sign SignaturesYang Yu, Huiwen Jia, Xiaoyun WangCRYPTO 2023 · 被引用 35 次
- Finding Short Integer Solutions When the Modulus Is SmallLéo Ducas, Thomas Espitau, Eamonn W. PostlethwaiteCRYPTO 2023 · 被引用 18 次
- Practical Post-Quantum Signatures for PrivacySven Argo, Tim Güneysu, Corentin Jeudy, Georg Land 等CCS 2024 · 被引用 11 次
- Leap: A Fast, Lattice-Based OPRF with Application to Private Set IntersectionLena Heimberger, Daniel Kales, Riccardo Lolato, Omid Mir 等EUROCRYPT 2025 · 被引用 9 次
它引用的顶会 Paper5
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 被引用 972 次
- Improved Cryptanalysis of UOV and RainbowWard BeullensEUROCRYPT 2021 · 被引用 96 次
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi 等EUROCRYPT 2022 · 被引用 67 次
- The rank of sparse random matricesAmin Coja-Oghlan, Alperen Ali Ergür, Pu Gao, Samuel Hetterich 等SODA 2020 · 被引用 19 次
- Fast Reduction of Algebraic Lattices over Cyclotomic FieldsPaul Kirchner, Thomas Espitau, Pierre-Alain FouqueCRYPTO 2020 · 被引用 12 次
相关 Paper
- Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU LatticesPierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet 等EUROCRYPT 2020 · 被引用 19 次
- Compact Lattice Signatures via Iterative Rejection SamplingJoel GärtnerCRYPTO 2025 · 被引用 2 次
- DualMS 2.0: Practical Lattice-Based Two-Round Fiat-Shamir Multi-Signature with Better EfficiencyQiqi Lai, Chongshen Chen, Feng Hao Liu, Tianyu Zhao 等CCS 2026
- TACHYON: Fast Signatures from Compact KnapsackRouzbeh Behnia, Muslum Ozgur Ozmen, Attila A. Yavuz, Mike RosulekCCS 2018 · 被引用 12 次
- A Closer Look at FalconPierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck 等EUROCRYPT 2026 · 被引用 15 次
