Towards Tightly Secure Strongly Unforgeable Short Lattice Signatures
摘要
An strongly unforgeable signature scheme means that the adversary can’t produce a new message-signature pair (m, s), even if he or she is able to get a different signature \(s'\) from m. The concept of strong unforgeability plays an important role in theory and practice of signature schemes. In addition, the tight security of a cryptographic scheme is another important concept. In Asiacrypt’16, Boyen and Li proposed an almost tightly secure short signature scheme based on pseudorandom function and the hardness assumption of short integer solution (SIS). Their based-lattice signature scheme is existentially unforgeable in the standard model. How to construct a based-lattice signature scheme that is strongly unforgeable and (almost) tightly secure? In this paper, we solve this problem. We propose the first based-lattice signature which is strongly unforgeable and almost tightly secure.