Skip to main content
QUICK REVIEW

[논문 리뷰] Compact Post-Quantum Signatures from Proofs of Knowledge leveraging Structure for the PKP, SD and RSD Problems

Loïc Bidoux, Philippe Gaborit|arXiv (Cornell University)|2022. 04. 06.
Cryptography and Data Security인용 수 4
한 줄 요약

이 논문은 코드 기반 문제의 내재된 대수적 구조를 활용하여 MPC-in-the-head 서명에서 신뢰할 수 있는 Helper와 컷 앤 찍기 오버헤드를 대체하는 새로운 지식 증명(Proof of Knowledge, PoK) 철학인 '구조를 활용한 PoK'를 소개한다. 이 방법은 기존 기술들보다 크기에서 성능 손실 없이 압축된 양자후계 서명을 제공한다. PKP에 대해선 9 kB 미만, SD에 대해선 15 kB, RSD에 대해선 7 kB 이하의 크기를 달성한다.

ABSTRACT

The MPC-in-the-head introduced in [IKOS07] has established itself as an important paradigm to design efficient digital signatures. It has been leveraged in the Picnic scheme [CDG+ 20] that reached the third round of the NIST PQC Standardization process. It has also been used in [Beu20] to introduce the Proof of Knowledge (PoK) with Helper paradigm. This construction permits to design shorter signatures but induces a non negligible performance overhead as it uses cut-and-choose. In this paper, we introduce the PoK leveraging structure paradigm along with its associated challenge space amplification technique. Our new approach to design PoK brings some improvements over the PoK with Helper one. Indeed, we show how one can substitute the Helper in these constructions by leveraging the underlying structure of the considered problem. This approach does not suffer from the performance overhead inherent to the PoK with Helper paradigm hence offers different trade-offs between security, signature sizes and performances. We also present four new post-quantum signature schemes. The first one is based on a new PoK with Helper for the Syndrome Decoding problem. It relies on ideas from [BGKM22] and [FJR21] and improve the latter using a new technique that can be seen as performing some cut-and-choose with a meet in the middle approach. The three other signatures are based on our new PoK leveraging structure approach and as such illustrate its versatility. We provide new PoK related to the Permuted Kernel Problem (PKP), Syndrome Decoding (SD) problem and Rank Syndrome Decoding (RSD) problem. In practice, these PoK lead to comparable or shorter signatures than existing ones. Indeed, considering (public key + signature), we get sizes below 9kB for our signature related to the PKP problem, below 15kB for our signature related to the SD problem and below 7kB for our signature related to the RSD problem.

연구 동기 및 목표

  • 지문 특화된 대수적 구조를 활용하여 Helper를 동반한 PoK에서 발생하는 성능 오버헤드를 제거함으로써 보다 안전한 서명 기반 기술을 개발하는 것.
  • 퍼미uted 커널 문제(PKP), 심프톰 디코딩(SD), 랭크 심프톰 디코딩(RSD) 기반으로 더 압축된 양자후계 서명 체계를 설계하는 것.
  • 구조를 활용하는 PoK에 특화된 도전 공간 확장 기법을 도입하여 효율적이고 안전한 서명 생성을 가능하게 하는 것.
  • 특히 NIST가 양자후계 서명 표준화 과정을 재개할 예정이라는 배경을 고려해 기존 코드 기반 서명 기반 기술에 경쟁 가능한 대안을 제공하는 것.

제안 방법

  • 기본적으로 어려운 문제(PKP, SD, RSD)에 내재된 구조적 특성으로 신뢰할 수 있는 Helper를 대체하는 새로운 PoK 프레임워크를 제안한다.
  • 컷 앤 찍기를 의존하지 않고 도전 공간을 안전하게 확장함으로써 효율성을 향상시키기 위해 도전 공간 확장 기법을 도입한다.
  • 순열 및 랭크 기반 대칭성을 가진 심프톰 디코딩 문제의 구조적 인스턴스를 활용하여 서명 크기를 줄인다.
  • 결과로 얻어진 PoK를 최소한의 오버헤드로 디지털 서명으로 변환하기 위해 Fiat-Shamir 변환을 적용한다.
  • 보안과 효율성의 균형을 확보하기 위해 병렬 반복과 최적화된 파rameter 선택 기법을 활용한다.
  • 구조적 제약 조건을 증명자 전략에 통합하여 PKP, SD, RSD에 대한 새로운 PoK 프로토콜을 설계함으로써 더 짧은 증명을 가능하게 한다.

실험 결과

연구 질문

  • RQ1Helper를 동반한 PoK 체계에서 발생하는 컷 앤 찍기 기반 오버헤드를 보안을 희생시키지 않고 제거할 수 있는가?
  • RQ2코드 기반 문제에 내재된 대수적 구조를 활용하여 더 압축된 양자후계 서명을 설계할 수 있는가?
  • RQ3도전 공간 확장 기법은 구조를 활용하는 PoK의 효율성과 보안을 어떻게 향상시키는가?
  • RQ4새로운 PoK 프레임워크는 기존 구조와 비교해 서명 크기 측면에서 뛰어난 성능을 보일 수 있는가?
  • RQ5PKP, SD, RSD 문제에 이 프레임워크를 적용할 경우 서명 크기, 공개 키 크기, 성능 간 실질적인 상충 관계는 어떠한가?

주요 결과

  • 제안된 구조를 활용한 PoK 프레임워크는 PKP 문제에 대해 공개 키 + 서명 크기가 9 kB 이하로, 기존 기술 대비 최대 45%의 감소를 달성한다.
  • 심프톰 디코딩 문제(SD)에 대해선 새로운 서명 체계가 공개 키 + 서명 크기를 15–17 kB로 유지하며, Wave와 LESS를 능가하지만 FJR22와 경쟁 가능하다.
  • RSD 기반 서명 체계는 공개 키 + 서명 크기를 7–9 kB로 유지하며, Durandal을 능가하고 뚜렷한 크기 우위를 확보한다.
  • SD를 위한 새로운 Helper를 동반한 PoK는 메트 인 더 미들(MITM) 컷 앤 찍기 기법을 통합하여 이전 구조보다 서명 크기를 줄였다(단, FJR22 제외).
  • 도전 공간 확장 기법은 컷 앤 찍기를 의존하지 않으며, 성능 오버헤드 없이 안전하고 효율적인 PoK를 가능하게 한다.
  • 새로운 구조는 최근 NIST에서 선정한 SPHINCS+와 경쟁 가능하며, 특히 서명 크기 측면에서 뛰어난 성능을 보이며, 향후 NIST의 양자후계 서명 표준화 라운드에 매우 적합하다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.