Post-quantum Security of Fiat-Shamir

被引:39
|
作者
Unruh, Dominique [1 ]
机构
[1] Univ Tartu, Tartu, Estonia
关键词
Post-quantum security; Fiat-Shamir; Non-interactive proof systems; Signatures; SIGNATURES; PROOFS;
D O I
10.1007/978-3-319-70694-8_3
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The Fiat-Shamir construction (Crypto 1986) is an efficient transformation in the random oracle model for creating non-interactive proof systems and signatures from sigma-protocols. In classical cryptography, Fiat-Shamir is a zero-knowledge proof of knowledge assuming that the underlying sigma-protocol has the zero-knowledge and special soundness properties. Unfortunately, Ambainis, Rosmanis, and Unruh (FOCS 2014) ruled out non-relativizing proofs under those conditions in the quantum setting. In this paper, we show under which strengthened conditions the Fiat-Shamir proof system is still post-quantum secure. Namely, we show that if we require the sigma-protocol to have computational zero-knowledge and statistical soundness, then Fiat-Shamir is a zero-knowledge simulation-sound proof system (but not a proof of knowledge!). Furthermore, we show that Fiat-Shamir leads to a post-quantum secure unforgeable signature scheme when additionally assuming a "dual-mode hard instance generator" for generating key pairs.
引用
收藏
页码:65 / 95
页数:31
相关论文
共 50 条
  • [21] Fiat-Shamir for highly sound protocols is instantiable
    Mittelbach, Arno
    Venturi, Daniele
    THEORETICAL COMPUTER SCIENCE, 2018, 740 : 28 - 62
  • [22] AN IMPROVEMENT OF THE FIAT-SHAMIR IDENTIFICATION AND SIGNATURE SCHEME
    MICALI, S
    SHAMIR, A
    LECTURE NOTES IN COMPUTER SCIENCE, 1990, 403 : 244 - 247
  • [23] Fiat-Shamir for Highly Sound Protocols Is Instantiable
    Mittelbach, Arno
    Venturi, Daniele
    SECURITY AND CRYPTOGRAPHY FOR NETWORKS, SCN 2016, 2016, 9841 : 198 - 215
  • [24] Why "Fiat-Shamir for Proofs" Lacks a Proof
    Bitansky, Nir
    Dachman-Soled, Dana
    Garg, Sanjam
    Jain, Abhishek
    Kalai, Yael Tauman
    Lopez-Alt, Adriana
    Wichs, Daniel
    THEORY OF CRYPTOGRAPHY (TCC 2013), 2013, 7785 : 182 - 201
  • [25] On the Security of Lattice-Based Fiat-Shamir Signatures in the Presence of Randomness Leakage
    Liu, Yuejun
    Zhou, Yongbin
    Sun, Shuo
    Wang, Tianyu
    Zhang, Rui
    Ming, Jingdian
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 1868 - 1879
  • [26] A Concrete Treatment of Fiat-Shamir Signatures in the Quantum Random-Oracle Model
    Kiltz, Eike
    Lyubashevsky, Vadim
    Schaffner, Christian
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2018, PT III, 2018, 10822 : 552 - 586
  • [27] The Fiat-Shamir Transform for Group and Ring Signature Schemes
    Lee, Ming Feng
    Smart, Nigel P.
    Warinschi, Bogdan
    SECURITY AND CRYPTOGRAPHY FOR NETWORKS, 2010, 6280 : 363 - 380
  • [28] On the Insecurity of the Fiat-Shamir Signatures with Iterative Hash Functions
    Fujisaki, Eiichiro
    Nishimaki, Ryo
    Tanaka, Keisuke
    PROVABLE SECURITY, PROCEEDINGS, 2009, 5848 : 118 - +
  • [29] A SMART CARD IMPLEMENTATION OF THE FIAT-SHAMIR IDENTIFICATION SCHEME
    KNOBLOCH, HJ
    LECTURE NOTES IN COMPUTER SCIENCE, 1988, 330 : 87 - 95
  • [30] Weak Fiat-Shamir Attacks on Modern Proof Systems
    Dao, Quang
    Miller, Jim
    Wright, Opal
    Grubbs, Paul
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 199 - 216