Post-quantum Security of Fiat-Shamir

被引:39
|
作者
Unruh, Dominique [1 ]
机构
[1] Univ Tartu, Tartu, Estonia
关键词
Post-quantum security; Fiat-Shamir; Non-interactive proof systems; Signatures; SIGNATURES; PROOFS;
D O I
10.1007/978-3-319-70694-8_3
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The Fiat-Shamir construction (Crypto 1986) is an efficient transformation in the random oracle model for creating non-interactive proof systems and signatures from sigma-protocols. In classical cryptography, Fiat-Shamir is a zero-knowledge proof of knowledge assuming that the underlying sigma-protocol has the zero-knowledge and special soundness properties. Unfortunately, Ambainis, Rosmanis, and Unruh (FOCS 2014) ruled out non-relativizing proofs under those conditions in the quantum setting. In this paper, we show under which strengthened conditions the Fiat-Shamir proof system is still post-quantum secure. Namely, we show that if we require the sigma-protocol to have computational zero-knowledge and statistical soundness, then Fiat-Shamir is a zero-knowledge simulation-sound proof system (but not a proof of knowledge!). Furthermore, we show that Fiat-Shamir leads to a post-quantum secure unforgeable signature scheme when additionally assuming a "dual-mode hard instance generator" for generating key pairs.
引用
收藏
页码:65 / 95
页数:31
相关论文
共 50 条
  • [1] Revisiting Post-quantum Fiat-Shamir
    Liu, Qipeng
    Zhandry, Mark
    ADVANCES IN CRYPTOLOGY - CRYPTO 2019, PT II, 2019, 11693 : 326 - 355
  • [2] On the (in)security of the Fiat-Shamir paradigm
    Goldwasser, S
    Kalai, YT
    44TH ANNUAL IEEE SYMPOSIUM ON FOUNDATIONS OF COMPUTER SCIENCE, PROCEEDINGS, 2003, : 102 - 113
  • [3] Security of the extended Fiat-Shamir schemes
    Ohta, K
    Okamoto, T
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 1998, E81A (01): : 65 - 71
  • [4] The Fiat-Shamir Transformation in a Quantum World
    Dagdelen, Ozgur
    Fischlin, Marc
    Gagliardoni, Tommaso
    ADVANCES IN CRYPTOLOGY - ASIACRYPT 2013, PT II, 2013, 8270 : 62 - 81
  • [5] Fiat-Shamir Security of FRI and Related SNARKs
    Block, Alexander R.
    Garreta, Albert
    Katz, Jonathan
    Thaler, Justin
    Tiwari, Pratyush Ranjan
    Zajac, Michal
    ADVANCES IN CRYPTOLOGY, ASIACRYPT 2023, PT II, 2023, 14439 : 3 - 40
  • [6] From obfuscation to the security of fiat-shamir for proofs
    Microsoft Research, Cambridge, United States
    不详
    不详
    Lect. Notes Comput. Sci., 1600, (224-251):
  • [7] Forward Security of Fiat-Shamir Lattice Signatures
    Tao, Yang
    Zhang, Rui
    Ji, Yunfeng
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, PT I, ACNS 2023, 2023, 13905 : 607 - 633
  • [8] Security of the Fiat-Shamir Transformation in the Quantum Random-Oracle Model
    Don, Jelle
    Fehr, Serge
    Majenz, Christian
    Schaffner, Christian
    ADVANCES IN CRYPTOLOGY - CRYPTO 2019, PT II, 2019, 11693 : 356 - 383
  • [9] From Obfuscation to the Security of Fiat-Shamir for Proofs
    Kalai, Yael Tauman
    Rothblum, Guy N.
    Rothblum, Ron D.
    ADVANCES IN CRYPTOLOGY - CRYPTO 2017, PART II, 2017, 10402 : 224 - 251
  • [10] AN ALTERNATIVE TO THE FIAT-SHAMIR PROTOCOL
    STERN, J
    LECTURE NOTES IN COMPUTER SCIENCE, 1990, 434 : 173 - 180