Compact Lattice Gadget and Its Applications to Hash-and-Sign Signatures
Yang Yu, Huiwen Jia, Xiaoyun Wang
摘要
Lattice gadgets and the associated algorithms are the essential building blocks of lattice-based cryptography. In the past decade, they have been applied to build versatile and powerful cryptosystems. However, the practical optimizations and designs of gadget-based schemes generally lag their theoretical constructions. For example, the gadgetbased signatures have elegant design and capability of extending to more advanced primitives, but they are far less efficient than other latticebased signatures. This work aims to improve the practicality of gadget-based cryptosystems, with a focus on hash-and-sign signatures. To this end, we develop a compact gadget framework in which the used gadget is a square matrix instead of the short and fat one used in previous constructions. To work with this compact gadget, we devise a specialized gadget sampler, called semi-random sampler, to compute the approximate preimage. It first deterministically computes the error and then randomly samples the preimage. We show that for uniformly random targets, the preimage and error distributions are simulatable without knowing the trapdoor. This ensures the security of the signature applications. Compared to the Gaussian-distributed errors in previous algorithms, the deterministic errors have a smaller size, which lead to a substantial gain in security and enables a practically working instantiation. As the applications, we present two practically efficient gadget-based signature schemes based on NTRU and Ring-LWE respectively. The NTRUbased scheme offers comparable efficiency to Falcon and Mitaka and a simple implementation without the need of generating the NTRU trapdoor. The LWE-based scheme also achieves a desirable overall perfor-mance. It not only greatly outperforms the state-of-the-art LWE-based hash-and-sign signatures, but also has an even smaller size than the LWE-based Fiat-Shamir signature scheme Dilithium. These results fill the long-term gap in practical gadget-based signatures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- A Closer Look at FalconPierre-Alain Fouque, Phillip Gajland, Hubert de Groote, Jonas Janneck 等EUROCRYPT 2026 · 被引用 15 次
- Plover: Masking-Friendly Hash-and-Sign Lattice SignaturesMuhammed F. Esgin, Thomas Espitau, Guilhem Niot, Thomas Prest 等EUROCRYPT 2024 · 被引用 14 次
- Lattice-Based Threshold Blind SignaturesSebastian Faller, Guilhem Niot, Michael ReichleS&P 2026 · 被引用 2 次
它引用的顶会 Paper4
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 被引用 972 次
- On the Lattice Isomorphism Problem, Quadratic Forms, Remarkable Lattices, and CryptographyLéo Ducas, Wessel P. J. van WoerdenEUROCRYPT 2022 · 被引用 67 次
- Shorter Hash-and-Sign Lattice-Based SignaturesThomas Espitau, Mehdi Tibouchi, Alexandre Wallet, Yang YuCRYPTO 2022 · 被引用 38 次
- Integral Matrix Gram Root and Lattice Gaussian Sampling Without FloatsLéo Ducas, Steven D. Galbraith, Thomas Prest, Yang YuEUROCRYPT 2020 · 被引用 22 次
相关 Paper
- Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconThomas Espitau, Pierre-Alain Fouque, François Gérard, Mélissa Rossi 等EUROCRYPT 2022 · 被引用 67 次
- Compact Lattice Signatures via Iterative Rejection SamplingJoel GärtnerCRYPTO 2025 · 被引用 2 次
- Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU LatticesPierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet 等EUROCRYPT 2020 · 被引用 19 次
- DualMS 2.0: Practical Lattice-Based Two-Round Fiat-Shamir Multi-Signature with Better EfficiencyQiqi Lai, Chongshen Chen, Feng Hao Liu, Tianyu Zhao 等CCS 2026
- Tight Lattice-Based Signatures Without Trapdoors from Search LWERutchathon Chairattana-Apirom, Nico Döttling, Julian Loss, Stefano Tessaro 等CRYPTO 2026
