Practical, Round-Optimal Lattice-Based Blind Signatures

43Citations
Citations of this article
15Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Blind signatures are a fundamental cryptographic primitive with numerous practical applications. While there exist many practical blind signatures from number-theoretic assumptions, the situation is far less satisfactory from post-quantum assumptions. In this work, we provide the first overall practical, lattice-based blind signature, supporting an unbounded number of signature queries and additionally enjoying optimal round complexity. We provide a detailed estimate of parameters achieved-we obtain a signature of size slightly above 45KB, for a core-SVP hardness of 109 bits. The run-times of the signer, user and verifier are also very small. Our scheme relies on the Gentry, Peikert and Vaikuntanathan signature [STOC'08] and non-interactive zero-knowledge proofs for linear relations with small unknowns, which are significantly more efficient than their general purpose counterparts. Its security stems from a new and arguably natural assumption which we introduce, called the one-more-ISIS assumption. This assumption can be seen as a lattice analogue of the one-more-RSA assumption by Bellare et al [JoC'03]. To gain confidence in our assumption, we provide a detailed analysis of diverse attack strategies.

Cite

CITATION STYLE

APA

Agrawal, S., Kirshanova, E., Stehlé, D., & Yadav, A. (2022). Practical, Round-Optimal Lattice-Based Blind Signatures. In Proceedings of the ACM Conference on Computer and Communications Security (pp. 39–53). Association for Computing Machinery. https://doi.org/10.1145/3548606.3560650

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free