That's Not My Signature! Fail-Stop Signatures for a Post-quantum World
Cecilia Boschini, Hila Dahari, Moni Naor, Eyal Ronen
摘要
In this work we present Fail-Stop Signatures (FSS), which are digital signatures enhanced with a forgery detection mechanism. Such mechanism allows to extract from a forgery a proof that the hardness assumption underlying the signature scheme has been broken, without the need for extensive cryptanalysis. This capability allows for the rapid deprecation of insecure signature schemes and their consequent replacement with more secure alternatives. We argue that a standardization process should prefer signatures that allow for a fail-stop mechanism whenever reasonable, as FSS make large, undiscriminating exploits of an undisclosed vulnerability a high stakes game for an agency. To prove that fail-stop mechanisms are practical we present FSS.SPHINCS, that is, SPHINCS + (now standardized as SLH-DSA) augmented with a fail-stop mechanism. We show that the fail-stop mechanism does not have a big impact on the efficiency of SPHINCS + . Using Lamport's signature as running example, we illustrate how to go from SPHINCS + to FSS.SPHINCS and give an intuition behind our proposed security model.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper2
相关 Paper
- Machine-Checked Security for rmXMSS as in RFC 8391 and Manuel Barbosa, François Dupressoir, Benjamin Grégoire, Andreas Hülsing 等CRYPTO 2023 · 被引用 3 次
- Shorter Hash-Based Signatures Using Forced PruningMehdi Abri, Jonathan KatzCRYPTO 2026
- SPHINCS+C: Compressing SPHINCS+ With (Almost) No CostAndreas Hülsing, Mikhail A. Kudinov, Eyal Ronen, Eylon YogevS&P 2023
- On the Security of the PKCS#1 v1.5 Signature SchemeTibor Jager, Saqib A. Kakvi, Alexander MayCCS 2018 · 被引用 19 次
- Accelerating SLH-DSA by Two Orders of Magnitude with a Single Hash UnitMarkku-Juhani O. SaarinenCRYPTO 2024 · 被引用 18 次
