arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

基于格的扩展可撤销性

Lattice-based extended withdrawability

Ramses Fernandez-Valencia

arXiv 2607.14690首次发表:更新:

AI 中文总结

该研究将扩展可撤销签名扩展到基于格的构造,实现为可认领环签名,给出正确性等证明,归结为相关安全性,并用特定方案实例化基础签名及N选1层。

AI 中文摘要

我们将Liu、Susilo和Baek的扩展可撤销签名扩展到基于格的构造,该构造建立在带中止的菲亚特-沙米尔范式之上。与早期草案不同,早期草案以明文传输每个签名者的偏移量,从而泄露签名者信息,我们将扩展可撤销签名实现为可认领的环签名:签名者的模糊性由用作黑盒的N选1签名提供(完全密钥暴露下的匿名性),确认是签名者的声明,即一个具有约束力的签名以及绑定到抄本中的隐藏索引承诺的公开。没有明文发布任何签名者派生的值。我们给出了正确性、扩展可撤销性(作为声明前的匿名性)、内部人员腐败下的不可伪造性和声明可健全性的完整证明,在(量子)随机预言模型中,这些证明归结为判定性MLWE(承诺隐藏)、MSIS(承诺绑定)、N选1方案的匿名性以及基础签名的EUF-CMA安全性。我们用无提示、全t的Dilithium风格方案实例化基础签名,并用已建立的基于格的多中选一证明实例化N选1层。

英文摘要

We extend the extended withdrawable signatures of Liu, Susilo and Baek to lattice-based constructions built on the Fiat-Shamir with aborts paradigm. Departing from an earlier draft that transported a per-signer shift in the clear, which leaks the signer, we realise extended withdrawable signatures as a claimable ring signature: signer ambiguity is provided by a one-out-of-N signature used as a black box (anonymity under full key exposure), and confirmation is the signer's claim, a binding signature together with the opening of a hiding index commitment bound into the transcript. No signer-derived value is published in the clear. We give complete proofs of correctness, extended withdrawability (as anonymity-until-claim), unforgeability under insider corruption, and claimability soundness, reducing to decisional MLWE (commitment hiding), MSIS (commitment binding), the anonymity of the one-out-of-$N$ scheme, and the EUF-CMA security of the base signature, in the (quantum) random-oracle model. We instantiate the base signature with a no-hint, full-$t$ Dilithium-style scheme and the one-out-of-$N$ layer with an established lattice one-out-of-many proof.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑