Post-quantum digital signature schemes have recently received increased attention due to the NIST standardization effort. MPC-in-the-Head and VOLE-in-the-Head are general techniques for constructing such signatures from zero-knowledge proof systems. A common theme between the two is an all-but-one vector commitment scheme which internally uses GGM trees. This primitive is responsible for a significant part of the computational time during signing and verification. A more efficient technique for constructing GGM trees is the half-tree technique, introduced by Guo et al. (Eurocrypt 2023). Our work builds an all-but-one vector commitment scheme from the half-tree technique, and further generalizes it to an all-but- \(\tau \) vector commitment scheme. Crucially, our work avoids the use of the random oracle assumption in an important step, which means our binding proof is non-trivial and instead relies on the random permutation oracle. Since this oracle can be instantiated using fixed-key AES which has hardware support, we achieve faster signing and verification times. We integrate our vector commitment scheme into FAEST ( faest.info ), a round one candidate in the NIST standardization process, and demonstrates its performance with a prototype implementation. Our implementation is between \(1.11 \times \) and \(1.57 \times \) faster across all parameter sets.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Faster VOLEitH Signatures from All-But-One Vector Commitment and Half-Tree

  • Dung Bui,
  • Kelong Cong,
  • Cyprien Delpech de Saint Guilhem

摘要

Post-quantum digital signature schemes have recently received increased attention due to the NIST standardization effort. MPC-in-the-Head and VOLE-in-the-Head are general techniques for constructing such signatures from zero-knowledge proof systems. A common theme between the two is an all-but-one vector commitment scheme which internally uses GGM trees. This primitive is responsible for a significant part of the computational time during signing and verification. A more efficient technique for constructing GGM trees is the half-tree technique, introduced by Guo et al. (Eurocrypt 2023). Our work builds an all-but-one vector commitment scheme from the half-tree technique, and further generalizes it to an all-but- \(\tau \) vector commitment scheme. Crucially, our work avoids the use of the random oracle assumption in an important step, which means our binding proof is non-trivial and instead relies on the random permutation oracle. Since this oracle can be instantiated using fixed-key AES which has hardware support, we achieve faster signing and verification times. We integrate our vector commitment scheme into FAEST ( faest.info ), a round one candidate in the NIST standardization process, and demonstrates its performance with a prototype implementation. Our implementation is between \(1.11 \times \) and \(1.57 \times \) faster across all parameter sets.