<p>We present a new lattice-based signature scheme, called ‘<InlineEquation ID="IEq1"> <EquationSource Format="TEX">\(\textsf{NTRU}+ \textsf{Sign}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">NTRU</mi> <mo>+</mo> <mi mathvariant="sans-serif">Sign</mi> </mrow> </math></EquationSource> </InlineEquation>’, using the Fiat-Shamir with Aborts framework. The proposed scheme is designed based on a novel NTRU-based key structure that fits well with bimodal distributions, enabling efficiency improvements compared to its predecessor, <InlineEquation ID="IEq2"> <EquationSource Format="TEX">\(\textsf{BLISS}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">BLISS</mi> </math></EquationSource> </InlineEquation>. The novel NTRU-based key structure is characterized by: (1) effectively changing a modulus from 2<i>q</i> to <i>q</i>, which is different from the existing usage of 2<i>q</i> for bimodal distributions, and (2) drastically reducing the magnitude of a secret key, which directly leads to compactness of signature sizes. We provide two concrete parameter sets for <InlineEquation ID="IEq3"> <EquationSource Format="TEX">\(\textsf{NTRU}+ \textsf{Sign}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">NTRU</mi> <mo>+</mo> <mi mathvariant="sans-serif">Sign</mi> </mrow> </math></EquationSource> </InlineEquation>, supporting 93-bit and 211-bit security levels. Using the technique from <InlineEquation ID="IEq4"> <EquationSource Format="TEX">\(\textsf{GALACTICS}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">GALACTICS</mi> </math></EquationSource> </InlineEquation> (that was suggested as the constant-time implementation of <InlineEquation ID="IEq5"> <EquationSource Format="TEX">\(\textsf{BLISS}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">BLISS</mi> </math></EquationSource> </InlineEquation>), our analysis shows that <InlineEquation ID="IEq6"> <EquationSource Format="TEX">\(\textsf{NTRU}+ \textsf{Sign}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">NTRU</mi> <mo>+</mo> <mi mathvariant="sans-serif">Sign</mi> </mrow> </math></EquationSource> </InlineEquation> achieves a good balance between computational efficiency and signature compactness, with constant-time implementation. For instance, at the NIST-3 security level, <InlineEquation ID="IEq7"> <EquationSource Format="TEX">\(\textsf{NTRU}+ \textsf{Sign}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">NTRU</mi> <mo>+</mo> <mi mathvariant="sans-serif">Sign</mi> </mrow> </math></EquationSource> </InlineEquation> produces signatures that are significantly smaller than <InlineEquation ID="IEq8"> <EquationSource Format="TEX">\(\textsf{Dilithium}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">Dilithium</mi> </math></EquationSource> </InlineEquation> and <InlineEquation ID="IEq9"> <EquationSource Format="TEX">\(\textsf{HAETAE}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">HAETAE</mi> </math></EquationSource> </InlineEquation>, while providing faster verification speeds. These advantages position <InlineEquation ID="IEq10"> <EquationSource Format="TEX">\(\textsf{NTRU}+ \textsf{Sign}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">NTRU</mi> <mo>+</mo> <mi mathvariant="sans-serif">Sign</mi> </mrow> </math></EquationSource> </InlineEquation> as a competitive and practical solution for real-world deployments.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

NTRU+Sign: compact NTRU-based signatures using bimodal distributions

  • Joo Woo,
  • Jonghyun Kim,
  • Ga Hee Hong,
  • Seungwoo Lee,
  • Minkyu Kim,
  • Hochang Lee,
  • Jong Hwan Park

摘要

We present a new lattice-based signature scheme, called ‘ \(\textsf{NTRU}+ \textsf{Sign}\) NTRU + Sign ’, using the Fiat-Shamir with Aborts framework. The proposed scheme is designed based on a novel NTRU-based key structure that fits well with bimodal distributions, enabling efficiency improvements compared to its predecessor, \(\textsf{BLISS}\) BLISS . The novel NTRU-based key structure is characterized by: (1) effectively changing a modulus from 2q to q, which is different from the existing usage of 2q for bimodal distributions, and (2) drastically reducing the magnitude of a secret key, which directly leads to compactness of signature sizes. We provide two concrete parameter sets for \(\textsf{NTRU}+ \textsf{Sign}\) NTRU + Sign , supporting 93-bit and 211-bit security levels. Using the technique from \(\textsf{GALACTICS}\) GALACTICS (that was suggested as the constant-time implementation of \(\textsf{BLISS}\) BLISS ), our analysis shows that \(\textsf{NTRU}+ \textsf{Sign}\) NTRU + Sign achieves a good balance between computational efficiency and signature compactness, with constant-time implementation. For instance, at the NIST-3 security level, \(\textsf{NTRU}+ \textsf{Sign}\) NTRU + Sign produces signatures that are significantly smaller than \(\textsf{Dilithium}\) Dilithium and \(\textsf{HAETAE}\) HAETAE , while providing faster verification speeds. These advantages position \(\textsf{NTRU}+ \textsf{Sign}\) NTRU + Sign as a competitive and practical solution for real-world deployments.