Cryptanalysis of Short and Provable Secure Lattice-Based Signature Scheme
摘要
Fenghe and Zhenhua proposed a short and provable secure lattice-based signature scheme in the standard model in 2016. Their aim was to construct a short signature without using any lattice delegation technique. They claimed that their scheme is strongly unforgeable under the hardness of the shortest integer solution (SIS) problem. In this article, we highlight a flaw in the signature scheme proposed by Fenghe and Zhenhua. We show that an adversary can generate a valid message-signature pair by solving a linear system of equations. We also show that the design of the scheme leaks some information about the secret key.