Dates are inconsistent

Dates are inconsistent

222 results sorted by ID

2026/1607 (PDF) Last updated: 2026-08-04
UFOs: A Very Efficient Multivariate Public Key Signature Scheme
Gilles Macario-Rat
Public-key cryptography

We present UFOs, a multivariate public-key signature scheme in the Unbalanced Oil and Vinegar (UOV) family. The scheme replaces generic quadratic polynomials with a structured subclass based on Frobenius-type quadratic forms, yielding a compressed public-key representation while retaining the efficient UOV signing procedure. We describe the key-generation, signing, and verification algorithms, and we detail the derivation of the public system from a compact secret description. We discuss...

2026/1576 (PDF) Last updated: 2026-08-05
A Systematic Literature Review on Optimising CRYSTALS-Dilithium (ML-DSA) Performance for IoT Devices via Lightweight Hashing
Ceasar Njuguna Ngunu, Edward Ombui
Implementation

Background: The migration to post-quantum cryptography confronts resource-constrained Internet of Things (IoT) devices with a material performance cost. CRYSTALS-Dilithium, standardised as the Module-Lattice-Based Digital Signature Algorithm (ML-DSA) in FIPS 204, fixes the Keccak-based SHAKE functions as its only symmetric primitives, and profiling on embedded platforms identifies hashing as the largest single contributor to the scheme’s software cost. This review synthesises the performance...

2026/1567 (PDF) Last updated: 2026-07-30
Zero Knowledge Barcode Decoding with Application to Private Online Attribute Verification
Kelsey Merrill, Anna Woo, Wenting Zheng, Sarah Scheffler
Applications

Online attribute checking (e.g. proving age, residency) is increasingly common, yet standard implementations reveal far more personal information than necessary (e.g. all ID contents). Privacy-preserving alternatives exist but require digital inputs: anonymous-credentials or zero-knowledge (ZK) proofs of signature possession over a bitstring. However, it is challenging to gain integrity guarantees on the bitstring itself. C2PA offers a partial solution: C2PA-enabled cameras...

2026/1508 (PDF) Last updated: 2026-08-04
ZKPoSP: Post-Quantum Zero-Knowledge Proofs for Hierarchical Deterministic Wallets
Vincenzo Botta, Michal Pospieszalski, Emanuele Ragnoli, Justus Ranvier
Cryptographic protocols

Recent advances in quantum hardware, including Google's Willow processor, have substantially narrowed the timeline to cryptographically relevant quantum computers. In the blockchain setting, where addresses and key derivation standards such as BIP32, BIP44, and SLIP-10 are the dominant infrastructure for wallet management, a quantum computer running Shor's algorithm can recover any elliptic-curve private key from the corresponding public key, threatening every wallet in production today....

2026/1452 (PDF) Last updated: 2026-07-16
Labeled Multi-Key Batched IBE
Guru-Vamsi Policharla
Cryptographic protocols

We study Batched IBE through the lens of Multi-Message Signatures -- a natural extension of standard digital signatures in which a single signing operation signs an entire vector of messages at once. A public open algorithm then derives an opening for each message, allowing anyone to verify that an individual message was signed. First we show that Multi-Message Signatures are essential by constructing a Multi-Message Signature scheme from every Batched IBE scheme with a sufficiently large...

2026/1448 (PDF) Last updated: 2026-07-16
Improving Skipping Fault Correction Attacks on Randomized Dilithium via MILP
Haobo Ouyang, Chaoran Wang, Guowei Liu, Lixuan Wu, Meiqin Wang, Yanhong Fan
Attacks and cryptanalysis

Dilithium, as a quantum-secure digital signature standard in FIPS 204, has received widespread attention for its physical implementation security. NIST selected Dilithium's randomized signing mode as the default, which can mitigate the severe physical attacks that exploit the deterministic signing mode. However, the physical attack resilience of randomized signing mode is currently an open question. In 2024, Krahmer et al. demonstrated a key-recovery attack against randomized Dilithium by...

2026/1422 (PDF) Last updated: 2026-07-11
LESS on the Cortex-M4: Characterizing the Speed–Memory Design Space of Code-Equivalence Signatures
Minwoo Lee, Minjoo Sim, Subeen Cho, Yulim Hyoung, Hwajeong Seo
Implementation

LESS is a code-based signature scheme built on the linear equivalence problem and, in its v2.0 round-2 form, a candidate in the NIST call for additional post-quantum signatures. No microcontroller implementation of it has been reported: the official benchmarking effort for the additional signatures excluded it on memory grounds, and an x86-massif cross-check puts the reference's peak stack at up to $\approx 836$~KB---beyond the SRAM of even the largest mainstream Cortex-M4. This paper...

2026/1333 (PDF) Last updated: 2026-07-06
Apples, Oranges, and Signatures: Pitfalls and Methodology in ML-DSA Benchmarking
Sebastien Riou, Jong-Yeon Park, Liga Anwar, Axel Poschmann, Michael Hutter
Implementation

Cryptographic migration, particularly in the post-quantum setting, poses significant practical challenges and requires reliable performance data to support sound engineering decisions. For ML-DSA, however, existing benchmarking practices often produce misleading or non-comparable results, complicating migration and cryptographic agility efforts. This paper analyzes common pitfalls in benchmarking ML-DSA signature operations, including subtle inconsistencies when comparing security levels. We...

2026/1332 (PDF) Last updated: 2026-06-28
A Differentiated Approach for Post-Quantum DNSSEC
Marc Espie, Hugo Mayer, Ludovic Perret
Applications

Post-quantum signature algorithms pose significant challenges for DNSSEC migration: their larger keys and signatures exceed DNS over UDP transport limits, making TCP fallback unavoidable even for the most compact schemes. We propose a differentiated algorithm selection, assigning distinct signature algorithms to the Zone Signing Key (ZSK) and Key Signing Key (KSK) roles. This approach expands the space of deployable post-quantum configurations beyond what undifferentiated selection permits,...

2026/1327 (PDF) Last updated: 2026-06-26
Fault assisted Man-In-The-Middle Attack on MAYO
Siddhesh Shinde, Sayandeep Saha
Attacks and cryptanalysis

Multivariate quadratic (MQ) signature schemes such as MAYO are among the leading candidates for post-quantum digital signatures, with security relying on the hardness of solving systems of multivariate quadratic equations. In this paper, we present a fault-assisted man-in-the-middle attack targeting the key-generation procedure of MAYO. Specifically, we target the computation of the public key, which is represented as a system of $m$ quadratic polynomials. Following the MAYO specification,...

2026/1305 (PDF) Last updated: 2026-07-08
Auxiliary Isogeny Freedom in SQIsign's Two-Dimensional Representation
Dustin Ray
Public-key cryptography

SQIsign encodes its response isogeny via a two-dimensional representation on a product of elliptic curves, using the Kani construction. We analyze the algebraic structure of this encoding in detail, with a focus on the role of the auxiliary isogeny and its implications for strong unforgeability. We show that the anti-isometry $\psi$ determining the Kani kernel is publicly computable from the torsion-point images of the component and auxiliary isogenies alone, that the...

2026/1304 (PDF) Last updated: 2026-06-22
Security Analysis of One Lightweight Certificateless Mutual Authentication Scheme Based on Signatures for IIoT
Zhengjun Cao, Lihua Liu
Attacks and cryptanalysis

We show that the certificateless signature scheme [IEEE ITJ, 26852-26865, 2024] is insecure against public key replacement attack. An adversary can forge signatures for any message by replacing the signer's public key. We find the two components $\delta_A$ and $T_A$ of signature $\sigma_A=(m_A, ID_A, \delta_A, T_A)$ are not tightly bound to the target message $m_A$ and the singer's identity $ID_A$. The inherent flaw results in that the adversary can find an efficient signing algorithm...

2026/1300 (PDF) Last updated: 2026-07-10
Thresholdizing Standardized FALCON Signatures
Radhika Garg, Daniel Escudero, Antigoni Polychroniadou, Akira Takahashi, Xiao Wang
Cryptographic protocols

Threshold signatures allow a quorum of parties to jointly produce a signature while preventing any smaller subset from doing so. Following NIST's post-quantum standardization, designing threshold schemes compatible with the newly selected primitives is a pressing task. In particular, no prior threshold signature scheme produces signatures verifiable under the unmodified FALCON verification algorithm - the NIST-selected post-quantum scheme with the smallest signatures and keys. In this...

2026/1210 (PDF) Last updated: 2026-06-08
Uncloneable Cryptography in Linear Quantum Memory
Andrew Huang, Omri Shmueli, Vinod Vaikuntanathan, Mark Zhandry
Foundations

Quantum cryptography is a rapidly developing area which leverages quantum information to accomplish classically impossible tasks. In many of these protocols, quantum states are used as long-term cryptographic keys, relying on the quantum no-cloning theorem to ensure that the keys cannot be copied by an adversary. Unfortunately, quantum state tend to decohere, and hence, persistent quantum memory is and will remain one of the most valuable and challenging resources for quantum computers. As...

2026/1067 (PDF) Last updated: 2026-05-27
GATOR: Group Action AdapTOR Signatures via MPC-in-the-Head
Nico Döttling, Manar Mohamed, Riccardo Zanotto
Cryptographic protocols

Adaptor signatures are a foundational fairness primitive for blockchain applications. They enhance blockchain functionality by enabling applications such as atomic swaps, payment channels, and other fair-exchange protocols. At a high level, they allow a buyer to produce a pre-signature tied to a public statement, which a seller holding a corresponding witness can adapt into a valid signature. Once this signature is posted on-chain, the seller obtains payment, while the buyer can extract the...

2026/1031 (PDF) Last updated: 2026-08-06
Compact Quaternion Algorithms for SQIsign
Won Kim, Changmin Lee, Hyunwoo Yoo
Public-key cryptography

SQIsign is an isogeny-based post-quantum signature scheme whose public keys and signatures are remarkably compact. However, since SQIsign relies on arithmetic in quaternion algebras over the field of rational numbers, no fixed-precision integer arithmetic for SQIsign had been established until recently, hindering constant-time implementation and deployment on memory-constrained devices. Recent work by Kim et al. instantiated an SQIsign implementation with fixed-precision integer arithmetic...

2026/979 (PDF) Last updated: 2026-05-26
Improved Dual Attack and Trapdoor Sampling via Quantum Rejection Sampling
Cong Ling, Hao Yan, Nicholas Zhao
Attacks and cryptanalysis

In this work, we revisit the dual attack and GPV trapdoor sampling, focusing on the lattice Gaussian sampling term, which can be a significant bottleneck in the overall complexity. We show that this sampling step can be quantumly accelerated by combining the lower bound underlying Wang and Ling's analysis of Klein's algorithm with the quantum rejection sampling (QRS) framework proposed by Ozols et al. Specifically, this lower bound gives precisely the pointwise domination condition required...

2026/968 (PDF) Last updated: 2026-05-17
Frobenius-UOV: A Very Efficient Multivariate Public Key Signature Scheme
Gilles Macario-Rat
Public-key cryptography

We present Frobenius-UOV, a multivariate public-key signature scheme in the Unbalanced Oil and Vinegar (UOV) family. The scheme replaces generic quadratic polynomials with a structured subclass based on Frobenius-type quadratic forms, yielding a compressed public-key representation while retaining the efficient UOV signing procedure. We describe the key-generation, signing, and verification algorithms, and we detail the derivation of the public system from a compact secret description. We...

2026/929 (PDF) Last updated: 2026-05-11
On the Statistical vs. Computational Security of the DKLs23 Multiparty ECDSA Protocol
Gil Segev
Cryptographic protocols

The DKLs23 protocol (Doerner, Kondi, Lee and shelat, IEEE S&P '24) is a state-of-the-art multiparty ECDSA signing protocol. Due to its exceptional combination of simplicity, efficiency, and statistical UC security within an elegant hybrid model providing access to standard ideal functionalities, it is rapidly seeing widespread adoption. We provide a comprehensive security analysis of the DKLs23 protocol, showing that although it is not statistically secure as originally claimed, it is...

2026/827 (PDF) Last updated: 2026-06-02
A Post-Quantum Accountable Sanitizable Signature Scheme Based on Unbalanced Oil and Vinegar
Zhiwei Wang
Public-key cryptography

Sanitizable signature schemes~(SSS) allow a designated sanitizer to modify admissible portions of a signed message while preserving the validity of the original signer's authorisation. All existing SSS constructions satisfying the Brzuska et~al.\ security framework rely on classical number-theoretic assumptions broken by Shor's algorithm. We present \textsf{UOV-San}, a sanitizable signature scheme based entirely on multivariate cryptography. The construction employs a...

2026/817 (PDF) Last updated: 2026-04-25
SOLMAE: Lightweight Post-Quantum Signature based on NTRU lattices with Hybrid Sampling
Kwangjo Kim
Public-key cryptography

The paper introduces SOLMAE, a lightweight post-quantum signature scheme that follows the traditional hash-and-sign paradigm of Gentry–Peikert–Vaikuntanathan and is instantiated over NTRU lattices using hybrid Gaussian samplers. As a natural successor to earlier designs including Falcon, Mitaka and Antrag, SOLMAE combines the strengths of these approaches. In particular, SOLMAE positions itself as offering a unified framework that achieves improved efficiency and security trade-offs over...

2026/710 (PDF) Last updated: 2026-04-15
Optimizing and Implementing Threshold MAYO
Diego F. Aranha, Giacomo Borin, Sofia Celi, Guilhem Niot
Public-key cryptography

Threshold signatures distribute trust across multiple parties, eliminating single points of failure and reducing insider and key-exfiltration risks—properties that are increasingly important for high-assurance deployments and recently emphasized by NIST’s Multi-Party Threshold Cryptography (MPTC) initiative. We present a practical t-out-of-n threshold variant and emulation of MAYO, a post-quantum signature candidate to NIST’s call for additional signatures. Our proposal builds upon the...

2026/685 (PDF) Last updated: 2026-04-08
Efficient e = 3 Threshold RSA via Integer Coordinates for Intel SGX
Sam Ng, Jason Lau
Cryptographic protocols

Threshold RSA signatures face a fundamental obstacle: reconstructing the private exponent from Shamir shares requires Lagrange coefficients whose computation involves modular division by values tied to $\phi(N)$, which must remain hidden. This obstacle is particularly acute for critical deployments such as Intel SGX code signing, which mandates $e=3$. Existing $e=3$-compatible approaches incur substantial overhead, increased share sizes, or sacrifice security properties such as perfect...

2026/638 (PDF) Last updated: 2026-05-07
THED: Threshold Dilithium from FHE
Jai Hyun Park, Alain Passelègue, Damien Stehlé
Cryptographic protocols

We describe THED, a threshold version of the Dilithium signature scheme (ML-DSA), whose issued signatures are valid for the genuine Dilithium verification algorithm. The signing protocol has two rounds of communication, one of which that lends itself to preprocessing. The scheme supports arbitrary number of users and threshold parameter. The construction consists in running Dilithium's signing algorithm under Threshold Fully Homomorphic Encryption (ThFHE), except for the computation of...

2026/620 (PDF) Last updated: 2026-03-30
AHAB: Asynchronous, High-throughput, Adaptively-secure, Batched Threshold Schnorr Signatures
Victor Shoup
Cryptographic protocols

We present AHAB, a suite of protocols for threshold Schnorr signatures in the asynchronous communication setting with guaranteed output delivery (robustness). We build on the AVSS and GoAVSS protocols of Shoup–Smart and Groth–Shoup, which allow t < n/3 static corruptions. First, we provide protocol enhancements and a full security proof in the adaptive corruption model with erasures. Second, we introduce a signature production pipeline with a player elimination framework that bounds the...

2026/617 (PDF) Last updated: 2026-07-16
Scaling of Memory and Bandwidth Requirements of Post-Quantum Signatures with Message Size
Falko Strenzke
Cryptographic protocols

In this work we analyse the qualitative memory and bandwidth efficiency properties of the currently standardised post-quantum signatures as such and of their protocol integrations mainly in the X.509 context. The term “qualitative” in this respect refers to how memory and bandwidth requirements scale with the size of the signed message. Specifically, we address the question in how far the algorithms support online-computations, a.k.a streaming, with respect to the signed message in the...

2026/442 (PDF) Last updated: 2026-03-04
Memory-Efficient Implementation of SMAUG-T and HAETAE
Yulim Hyoung, Subeen Cho, Uijae Kim, Minwoo Lee, Hwajeong Seo, Minjoo Sim
Implementation

SMAUG-T and HAETAE, designated as target algorithms for national standardization via the Korean Post-Quantum Cryptography (KpqC) competition, run efficiently on general-purpose platforms. On ARM Cortex-M4 class microcontrollers, however, peak stack usage becomes a key constraint: while SMAUG-T can be executed on typical Cortex-M4 boards, the baseline HAETAE implementation exceeds the available SRAM (e.g., 91{,}176\,B stack for signing), motivating dedicated memory optimization. To address...

2026/419 (PDF) Last updated: 2026-05-26
Hermine: An Efficient Lattice-based FROST-like Threshold Signature
Giacomo Borin, Sofía Celi, Rafael del Pino, Thomas Espitau, Shuichi Katsumata, Guilhem Niot, Thomas Prest, Kaoru Takemure
Public-key cryptography

Threshold signatures have regained a strong interest recently, driven by applications in cryptocurrencies and NIST's ongoing call for threshold schemes. Among them, FROST - a classical threshold Schnorr signature scheme already in real-world deployment - stands out. Its appeal lies in three core features: partially non-interactive signing, non-interactive identifiable abort (IA), and proactive security. In contrast, while post-quantum (PQ) threshold signatures have seen significant advances...

2026/394 (PDF) Last updated: 2026-07-13
SQISign on ARM
Luca De Feo, Li-Jie Jian, Ting-Yuan Wang, Bo-Yin Yang
Implementation

We present the first vectorized implementation of SQIsign for high-performance Arm architectures. SQIsign is a promising candidate in the NIST On-Ramp Digital Signatures Call Round 2 to its most compact key and signature sizes. However, its signing performance remains a primary bottleneck, particularly the ideal-to-isogeny conversion. The conversion requires a large number of operations on elliptic curves and Abelian varieties, which depend on finite field arithmetic. Despite recent...

2026/312 (PDF) Last updated: 2026-05-06
RISQrypt: Fast, Secure and Agile Hardware-Software Co-Design for Post-Quantum Cryptography
Tolun Tosun, Atıl Utku Ay, Quinten Norga, Suparna Kundu, Melik Yazıcı, Erkay Savaş, Ingrid Verbauwhede
Implementation

In this paper, we present RISQrypt, the first unified architecture in the literature that implements Kyber (ML-KEM) and Dilithium (ML-DSA), standardized lattice-based Post-Quantum Cryptography (PQC) algorithms, with masking. RISQrypt is a hardware–software co-design framework that integrates dedicated cryptographic accelerators to speed up polynomial arithmetic, hashing, and mask-conversion operations, the latter being one of the primary bottlenecks in masked implementations of lattice-based...

2026/235 (PDF) Last updated: 2026-04-28
Optimized Implementations of Keccak, Kyber, and Dilithium on the MSP430 Microcontroller
DongHyun Shin, YoungBeom Kim, Ayesha Khalid, Máire O'Neill, Seog Chung Seo
Implementation

Post-Quantum cryptography (PQC) typically requires more memory and computational power than conventional public-key cryptography. Until now, most active research in PQC optimization for embedded devices has focused on 32-bit and 64-bit ARM architectures, specifically Cortex-M0/M3/M4 and ARMv8. To enable a smooth migration of PQC algorithms in Internet of Things environments, optimization research is also required for devices with lower computational capabilities. To address this gap, we...

2026/228 (PDF) Last updated: 2026-02-11
SCA-MQDSA: Side-Channel Analysis of Multivariate Digital Signature Implementations
N.K. Vishwaajith, Anindya Ganguly, Debranjan Pal, Trevor Yap, Puja Mondal, Suparna Kundu, Sayandeep Saha, Shivam Bhasin, Ingrid Verbauwhede, Angshuman Karmakar
Attacks and cryptanalysis

The rapid progress of Internet-of-Things (IoT) systems and network protocols has strengthened the demand for digital signature schemes with compact signatures and low computational overhead. However, standardized post-quantum signature schemes, such as ML-DSA, SLH-DSA, and Falcon, incur relatively large signature sizes, which limit their practicality on resource-constrained devices (RCD). To address this challenge, NIST recalled the post-quantum digital signature standardization process. It...

2026/187 (PDF) Last updated: 2026-06-07
Hardness of hinted ISIS from the space-time hardness of lattice problems
Martin R. Albrecht, Russell W. F. Lai, Eamonn W. Postlethwaite
Public-key cryptography

We initiate the study of basing the hardness of hinted ISIS problems (i.e. with trapdoor information, or ‘hints’) on the previously conjectured space-time hardness of lattice problems without hints. We present two main results. 1. If there exists an efficient algorithm for hinted ISIS that outputs solutions a constant factor longer than the hints, then there exists a single-exponential time and polynomial memory zero-centred spherical Gaussian sampler solving hinted SIS with norm a...

2026/048 (PDF) Last updated: 2026-01-12
Masked Solving of Linear Equations System and Application to UOV Signatures
Jean-Sébastien Coron, François Gérard, Bowen Zhang
Implementation

In response to the looming quantum threat, NIST has selected four algorithms for standardization (i.e., ML-KEM, ML-DSA, SLH-DSA, and FN-DSA), yet three of the four schemes are based on Euclidean lattices, which raises concerns about the mathematical diversity of post-quantum algorithms. NIST has therefore announced an additional call for post-quantum signatures with a preference for schemes constructed from assumptions other than lattices. Among such candidates, the Unbalanced Oil and...

2026/013 (PDF) Last updated: 2026-01-05
Efficient Threshold ML-DSA
Sofía Celi, Rafaël del Pino, Thomas Espitau, Guilhem Niot, Thomas Prest
Public-key cryptography

Threshold signature schemes allow a group of users to jointly generate a digital signature, providing resilience against faults and enhancing decentralization. With the advent of post-quantum cryptography, lattice-based threshold signatures have gained attention as viable PQ-threshold solutions. Nevertheless, existing constructions are limited in terms of their scalability, robustness. Worse, none is compatible with standardized schemes, particularly with the NIST-selected and standardized...

2025/2337 (PDF) Last updated: 2025-12-30
ML-DSA-OSH: An Efficient, Open-Source Hardware Implementation of ML-DSA
Quinten Norga, Suparna Kundu, Ingrid Verbauwhede
Implementation

ML-DSA is a post-quantum lattice-based digital signature algorithm (DSA) that the National Institute of Standards and Technology (NIST) recently standardized as FIPS 204. Remarkably, there are only a handful of published hardware designs and no open-source hardware implementations of complete ML-DSA. In this work, we present an efficient open-source hardware (OSH) design of ML-DSA, based on a Dilithium implementation by Beckwith et al. (FPT 2021). We discuss the required modifications for...

2025/2273 (PDF) Last updated: 2025-12-18
Benchmarking SLH-DSA: A Comparative Hardware Analysis Against Classical Digital Signatures for Post-Quantum Security
Jayalaxmi H, H M Brunda, Sumith Subraya Nayak, Sathya M, Anirudh S Hegde
Implementation

The advent of large-scale quantum computers poses a fundamental threat to widely deployed public-key cryptographic schemes such as RSA and elliptic curve digital signatures. In response, the National Institute of Standards and Technology has standardized several post-quantum cryptographic algorithms, including the Stateless Hash-Based Digital Signature Algorithm (SLH-DSA) specified in FIPS 205. While SLH-DSA offers strong, conservative security guarantees based solely on cryptographic hash...

2025/2192 (PDF) Last updated: 2026-01-07
Constant-time Quaternion Algorithms for SQIsign
Andrea Basso, Chenfeng He, David Jacquemin, Fatna Kouider, Péter Kutas, Anisha Mukherjee, Sina Schaeffler, Sujoy Sinha Roy
Implementation

SQIsign, the only isogeny-based signature competing in the ongoing NIST call for additional signatures, offers the most compact key and signature sizes among all other candidates. It combines isogenies with quaternion arithmetic for its signing procedure. In this work, we address a gap in the current implementation of SQIsign: the absence of constant-time algorithms for quaternion arithmetic. We propose constant-time algorithmic formulations for three fundamental routines in SQIsign's...

2025/2163 (PDF) Last updated: 2026-05-22
Splitting the MAYO: A Component-Wise Fault Injection Attack on Randomized MAYO
Mohamed Abdelmonem, Lejla Batina, Durba Chatterjee, Vincent Dankbaar, Håvard Raddum
Attacks and cryptanalysis

We present a practical component-wise fault injection attack against randomized MAYO implementations. The attack targets the final addition of oil and vinegar components during signing. Depending on compiler optimization, a fault may expose either oil coefficients directly or vinegar coefficients that can be used to recover the oil coefficient via the public verification algorithm. By accumulating partial coefficient-wise information across multiple faulty signatures and exploiting the...

2025/2159 (PDF) Last updated: 2025-11-27
One Fell Swoop: A Single-Trace Key-Recovery Attack on the Falcon Signing Algorithm
Kang Li, Shouran Ma, Haochen Dou, Qian Guo
Attacks and cryptanalysis

Falcon, a lattice-based signature scheme selected for NIST post-quantum standardization, is notable for its compact signature size alongside a complex signing procedure involving extensive floating-point arithmetic. Prior side-channel attacks on Falcon, while demonstrating vulnerabilities, have consistently required a large number of power traces for successful key recovery; this critical efficiency gap means previously reported attacks are often impractical in real-world scenarios where...

2025/2101 (PDF) Last updated: 2025-11-15
Fault Attacks against UOV-based Signatures
Sven Bauer, Fabrizio De Santis, Kristjane Koleci
Attacks and cryptanalysis

The Unbalanced Oil and Vinegar (UOV) construction is the foundation of several post-quantum digital signature algorithms currently under consideration in NIST's standardization process for additional post-quantum digital signature schemes. This paper introduces new single fault injection attacks against the signing procedure of deterministic variants of signature schemes based on the UOV construction. We show how these attacks can be applied to attack MAYO and PROV, two signature schemes...

2025/2096 (PDF) Last updated: 2025-11-14
Laser Fault Injection Attack on the eXtended Merkle Signature Scheme
Alexander Wagner, Marc Schink, Silvan Streit, Dominik Klein, Sven Freud
Attacks and cryptanalysis

The interest in hash-based signatures (HBS) has increased since the need for post-quantum cryptography (PQC) emerged that could withstand attacks by quantum computers. Since their standardization, stateful HBS algorithms have been deployed in several products ranging from embedded devices up to servers. In practice, they are most applicable to verify the integrity and authenticity of data that rarely changes, such as the firmware of embedded devices. The verification procedure then takes...

2025/2076 (PDF) Last updated: 2025-11-10
Non-Interactive Blind Signatures from RSA Assumption and More
Lucjan Hanzlik, Eugenio Paracucchi, Riccardo Zanotto
Public-key cryptography

Blind signatures have received increased attention from researchers and practitioners. They allow users to obtain a signature under a message without revealing it to the signer. One of the most popular applications of blind signatures is to use them as one-time tokens, where the issuing is not linkable to the redeeming phase, and the signature under a random identifier forms a valid token. This concept is the backbone of the Privacy Pass system, which uses it to identify honest but anonymous...

2025/2069 (PDF) Last updated: 2026-06-17
Shorter Hash-Based Signatures Using Forced Pruning
Mehdi Abri, Jonathan Katz
Public-key cryptography

The stateless hash-based digital signature algorithm (SLH-DSA) is a post-quantum signature scheme based on the SPHINCS$^+$ framework that was recently standardized by NIST. Although it offers many benefits, a drawback of SLH-DSA is that it has relatively large signatures. Several techniques have been proposed to reduce the signature size of SPHINCS-like schemes, and NIST is actively evaluating variants with shorter signatures for possible future standardization. We explore using forced...

2025/2007 (PDF) Last updated: 2026-07-09
k-Anonymous Group Signatures
Shalini Banerjee, Andrey Bozhko, Andy Rupp
Cryptographic protocols

We review $k$-anonymity in authentication schemes, group signatures, and ring signatures. Existing constructions either require a signer to maintain state across interactions, or admit tracing algorithms that cost $O(n^k)$ in the number $n$ of signatures. We introduce $k$-anonymous group signatures ($k$-AGS), that achieves stateless signing with a tracing cost $O(n+k)$, while necessarily sacrificing unlinkability. We present a generic construction of $k$-AGS together with an efficient...

2025/1929 (PDF) Last updated: 2025-10-15
Cryptanalysis of a Post-Quantum Signature Scheme Based on Number-Theoretic Assumptions
Agha Aghayev, Nour-eddine Rahmani
Attacks and cryptanalysis

The asymmetric cryptographic constructions upon on number- theoretic hardness assumptions have become insecure, due to Shor’s quantum algorithm and they will be vulnerable to large scale quantum computers. Hence, the adaption to quantum-resistant cryptosystems is a major task. Digital signatures, being a fundamental primitive in nu- merous applications. Recently, a new approach by Nguyen et al. [9] has claimed post-quantum security by basing the signature algorithm’s se- curity on a...

2025/1878 (PDF) Last updated: 2025-10-08
MIRANDA: short signatures from a leakage-free full-domain-hash scheme
Alain Couvreur, Thomas Debris-Alazard, Philippe Gaborit, Adrien Vinçotte
Public-key cryptography

We present Miranda, the first family of full-domain-hash signatures based on matrix codes. This signature scheme fulfils the paradigm of Gentry, Peikert and Vaikuntanathan (GPV), which gives strong security guarantees. Our trapdoor is very simple and generic: if we propose it with matrix codes, it can actually be instantiated in many other ways since it only involves a subcode of a decodable code (or lattice) in a unique decoding regime of parameters. Though Miranda signing algorithm relies...

2025/1808 (PDF) Last updated: 2026-05-02
Variables for Free: Fault Injection Attack on MAYO via Valid Solutions
Yadi Zhong
Attacks and cryptanalysis

Abstract. Multivariate quadratic problem over a finite field, a NP-hard problem, is also considered as one of the hard problems for cryptanalytic-relevant quantum computers. It is the foundation of multivariate quadratic-based cryptography and several post-quantum digital signature schemes initially proposed in 1990s. Patarin’s unbalanced Oil-and-Vinegar (UOV) scheme is the oldest MQ signature algorithm that remain secure against large-scale cryptanalytic-relevant quantum computers. UOV has...

2025/1737 (PDF) Last updated: 2026-02-23
WaterSQI and PRISMO: Quaternion Signatures for Supersingular Isogeny Group Actions
Tako Boris Fouotsa
Public-key cryptography

Isogeny group action based signatures are obtained from a sigma protocol with high soundness error, say $\frac{1}{2}$ for its most basic variant. One needs to independently repeat the sigma protocol $O(\lambda)$ times to reduce the soundness error to negligible (with $\lambda$ being the security parameter). These repetitions come with a considerable efficiency and size overhead. On the other hand, quaternion isogeny-based signatures such as SQIsign and PRISM are directly obtained from a...

2025/1696 (PDF) Last updated: 2026-01-14
Threshold ECDSA in Two Rounds
Yingjie Lyu, Zengpeng Li, Hong-Sheng Zhou, Xudong Deng
Cryptographic protocols

We propose the first two-round multi-party signing protocol for the Elliptic Curve Digital Signature Algorithm (ECDSA) in the threshold-optimal setting, reducing the number of rounds by one compared to the state of the art (Doerner et al., S&P '24). We also resolve the security issue of presigning pointed out by Groth and Shoup (Eurocrypt '22), evading a security loss that increases with the number of pre-released, unused presignatures, for the first time among threshold-optimal...

2025/1680 (PDF) Last updated: 2025-09-19
ChipmunkRing: A Practical Post-Quantum Ring Signature Scheme for Blockchain Applications
Dmitrii A. Gerasimov
Cryptographic protocols

We introduce ChipmunkRing, a practical post-quantum ring signature construction tailored for blockchain environments. Building on our Chipmunk lattice-based cryptographic framework, this implementation delivers compact digital signatures ranging from 20.5 to 279.7KB, with rapid signing operations completing in 1.1-15.1ms and efficient validation processes requiring only 0.4-4.5ms for participant groups of 2-64 members. The cornerstone of our approach is Acorn Verification—a streamlined...

2025/1596 (PDF) Last updated: 2025-09-04
On GPU acceleration of PQC algorithms
Daniel Römer, Gero Knoblauch, Alexander Wiesmaier
Implementation

The rise of quantum computers results in many cryptographic systems being no longer considered sufficiently secure. Algorithms from the field of post-quantum cryptography promise to provide security against the new systems. However, PQC algorithms are generally more computationally intensive than classical cryptography. In order to increase suitability of PQC for everyday use, this paper investigates their acceleration using GPUs. For this purpose, we analyzed research in the field and...

2025/1424 (PDF) Last updated: 2025-08-05
LESS is Even More: Optimizing Digital Signatures from Code Equivalence
Luke Beckwith, Andre Esser, Edoardo Persichetti, Paolo Santini, Floyd Zweydinger
Public-key cryptography

LESS is a signature scheme based on the code equivalence problem that has advanced to the second round of the NIST PQC standardization process. While promising, the scheme suffers from relatively large signatures and moderate to slow signing and verification times. Chou, Santini, and Persichetti recently introduced a variant of LESS relying on canonical forms to significantly reduce signature sizes. However, the overall performance impact of this approach remained largely unclear. In this...

2025/1163 (PDF) Last updated: 2026-01-28
Quorus: Efficient, Scalable Threshold ML-DSA Signatures from MPC
Alexander Bienstock, Leo de Castro, Daniel Escudero, Antigoni Polychroniadou, Akira Takahashi
Cryptographic protocols

A threshold signature protocol divides a secret signing key among multiple parties, enabling any subset above a threshold to jointly create a signature. While post-quantum (PQ) threshold signatures are being studied, especially following NIST's call for threshold schemes, most solutions focus on specially designed, threshold-friendly signature schemes. However, real-world applications like distributed certificate authorities and digital currencies require signatures verifiable under existing...

2025/999 (PDF) Last updated: 2025-05-30
Insecurity of One Ring Signature Scheme with Batch Verification for Applications in VANETs
Zhengjun Cao, Lihua Liu
Attacks and cryptanalysis

We show that the Negi-Kumar certificateless ring signature scheme [Wirel. Pers. Commun. 134(4): 1987-2011 (2024)] is insecure against forgery attack. The signer's public key $PK_j$ and secret key $PSK_j$ are simply invoked to compute the hash value $H_{2_j}=h_5(m_j\|PSK_j\|PK_j\|t_j)$, which cannot be retrieved by the verifier for checking their dependency. The explicit dependency between the public key and secret key is not properly used to construct some intractable problems, such...

2025/939 (PDF) Last updated: 2025-05-23
On the security of one certificateless aggregate signature scheme with dynamic revocation in vehicular ad-hoc networks
Zhengjun Cao, Lihua Liu
Attacks and cryptanalysis

We show that the certificateless signature scheme [Veh. Commun. 47: 100763 (2024)] is insecure, because an adversary can launch forgery attack for any message. The signer's certificateless public key is not tightly bound to the system public key. The inherent flaw results in that the adversary can find an efficient signing algorithm functionally equivalent to the valid signing algorithm. The findings in this note could be helpful for newcomers who are not familiar with the designing...

2025/834 (PDF) Last updated: 2025-05-10
A Note on ``CABC: A Cross-Domain Authentication Method Combining Blockchain with Certificateless Signature for IIoT''
Zhengjun Cao, Lihua Liu
Attacks and cryptanalysis

We show that the authentication method [Future Gener. Comput. Syst. 158: 516-529 (2024)] cannot be practically implemented, because the signature scheme is insecure against certificateless public key replacement forgery attack. The explicit dependency between the certificateless public key and secret key is not properly used to construct some intractable problems, such as Elliptic Curve Discrete Logarithm (ECDL). An adversary can find an efficient signing algorithm functionally...

2025/830 (PDF) Last updated: 2025-05-09
Simple Power Analysis Attack on SQIsign
Anisha Mukherjee, Maciej Czuprynko, David Jacquemin, Péter Kutas, Sujoy Sinha Roy
Attacks and cryptanalysis

The isogeny-based post-quantum digital signature algorithm SQIsign offers the most compact key and signature sizes among all candidates in the ongoing NIST call for additional post-quantum signature algorithms. To the best of our knowledge, we present the first Simple Power Analysis (SPA) side-channel attack on SQIsign, demonstrating its feasibility for key recovery. Our attack specifically targets secret-dependent computations within Cornacchia's algorithm, a fundamental component of...

2025/796 (PDF) Last updated: 2025-05-04
Unified MEDS Accelerator
Sanjay Deshpande, Yongseok Lee, Mamuri Nawan, Kashif Nawaz, Ruben Niederhagen, Yunheung Paek, Jakub Szefer
Implementation

The Matrix Equivalence Digital Signature (MEDS) scheme a code-based candidate in the first round of NIST’s Post-Quantum Cryptography (PQC) standardization process, offers competitively small signature sizes but incurs high computational costs for signing and verification. This work explores how a high-performance FPGA-based hardware implementation can enhance MEDS performance by leveraging the inherent parallelism of its computations, while examining the trade-offs between performance gains...

2025/755 (PDF) Last updated: 2025-04-28
A Note on "CB-DA: Lightweight and Escrow-Free Certificate-Based Data Aggregation for Smart Grid"
Zhengjun Cao, Lihua Liu
Attacks and cryptanalysis

We show that the data aggregation scheme [IEEE TDSC, 2023, 20(3), 2011-2024] is flawed, because the signer only signs a part of data, not the whole data. An adversary can replace the unsigned component to cheat the verifier. To frustrate this attack, all components of the target data should be concatenated together and then be hashed and signed, so as to ensure that the signature verification can prove the whole message integrity.

2025/621 (PDF) Last updated: 2025-04-05
SPHINCSLET: An Area-Efficient Accelerator for the Full SPHINCS+ Digital Signature Algorithm
Sanjay Deshpande, Yongseok Lee, Cansu Karakuzu, Jakub Szefer, Yunheung Paek
Implementation

This work presents SPHINCSLET, the first fully standard-compliant and area-efficient hardware implementation of the SLH-DSA algorithm, formerly known as SPHINCS+, a post-quantum digital signature scheme. SPHINCSLET is designed to be parameterizable across different security levels and hash functions, offering a balanced trade-off between area efficiency and performance. Existing hardware implementations either feature a large area footprint to achieve fast signing and verification or adopt a...

2025/599 (PDF) Last updated: 2025-04-02
Insecurity of One Decentralized Attribute-based Signature Scheme for Social Co-governance