We implement a new scheme of the short digital signature which is different from schemes based on multivariate public keys. The scheme started from inverse twisted Diffie-Hellman protocol based on two Eulerian endomorphisms Gi, i=1,2 of Z2s [x1,x2,…., xn] moving each xi to a monomial term with coefficient from Z*2s and acting on (Z*2s)n as bijective maps. So correspondents Alice and Bob elaborate mutually inverse transformations X and Y the space of hash values (Z*2s)n. Another twisted Diffie Hellman protocol is used for safe delivery from Alice to Bob of bijective affine transformation A of space (Z2s)n preserving (Z*2s)n. Bob uses his combination YAY for the verification of digital signature of Alice on hash value h from (Z*2s)n Alice sends the tuple XA−1 X(h) as her signature. For practical use (Z*2s)n can be identified with the n-dimensional vector space over the finite field Fq, q=2s−1 or affine space (Zq)n. The cost of the single protocol is O(n3) and the cost of the computation of the reimage of the used nonlinear map is O(n2). So the verification of nt, t≥1 signatures takes time O(nt+2). We present several other cryptographic algorithms based on Eulerian transformations and endomorphisms of Z2s [x1, x2,…., xn].

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

On the Postquantum Protocol-Based Short Digital Signatures with Multivariate Maps Over Arithmetical Rings

  • Vasyl Ustimenko,
  • Oleksandr Pustovit

摘要

We implement a new scheme of the short digital signature which is different from schemes based on multivariate public keys. The scheme started from inverse twisted Diffie-Hellman protocol based on two Eulerian endomorphisms Gi, i=1,2 of Z2s [x1,x2,…., xn] moving each xi to a monomial term with coefficient from Z*2s and acting on (Z*2s)n as bijective maps. So correspondents Alice and Bob elaborate mutually inverse transformations X and Y the space of hash values (Z*2s)n. Another twisted Diffie Hellman protocol is used for safe delivery from Alice to Bob of bijective affine transformation A of space (Z2s)n preserving (Z*2s)n. Bob uses his combination YAY for the verification of digital signature of Alice on hash value h from (Z*2s)n Alice sends the tuple XA−1 X(h) as her signature. For practical use (Z*2s)n can be identified with the n-dimensional vector space over the finite field Fq, q=2s−1 or affine space (Zq)n. The cost of the single protocol is O(n3) and the cost of the computation of the reimage of the used nonlinear map is O(n2). So the verification of nt, t≥1 signatures takes time O(nt+2). We present several other cryptographic algorithms based on Eulerian transformations and endomorphisms of Z2s [x1, x2,…., xn].