Skip to main content
QUICK REVIEW

[论文解读] Tight quantum security of the Fiat-Shamir transform for commit-and-open identification schemes with applications to post-quantum signature schemes

André Chailloux|arXiv (Cornell University)|Jun 12, 2019
Quantum Computing Algorithms and Architecture被引用 4
一句话总结

本文為適用於承諾並開啟認證方案的Fiat-Shamir變換提出了緊緻的量子安全歸約,進而實現了後量子數位簽章方案的具體安全界。透過利用特殊聲音性質與一種新型的量子歸約技術,該方法在無漸近損失的情況下實現緊緻性,可直接應用於NIST後量子密碼學候選演算法,如MQDSS、PICNIC與Stern的方案。

ABSTRACT

Applying the Fiat-Shamir transform on identification schemes is one of the main ways of constructing signature schemes. While the classical security of this transformation is well understood, it is only very recently that generic results for the quantum case have been proposed [DFMS19,LZ19]. These results are asymptotic and therefore can't be used to derive the concrete security of these signature schemes without a significant loss in parameters. In this paper, we show that if we start from a commit-and-open identification scheme, where the prover first commits to several strings and then as a second message opens a subset of them depending on the verifier's message, then there is a tight quantum reduction for the the Fiat-Shamir transform to special soundness notions. Our work applies to most 3 round schemes of this form and can be used immediately to derive quantum concrete security of signature schemes. We apply our techniques to several identification schemes that lead to signature schemes such as Stern's identification scheme based on coding problems, the [KTX08] identification scheme based on lattice problems, the [SSH11] identification schemes based on multivariate problems, closely related to the NIST candidate MQDSS, and the PICNIC scheme based on multiparty computing problems, which is also a NIST candidate.

研究动机与目标

  • 解決在量子隨機Oracle模型中,基於Fiat-Shamir的後量子數位簽章方案缺乏緊緻量子安全歸約的問題。
  • 克服目前因漸近與非緊緻安全界所導致的參數過度估計問題,例如在MQDSS與PICNIC等方案中所見。
  • 針對三回合承諾並開啟認證方案,提出使用特殊聲音性質的具體、緊緻量子安全歸約。
  • 實現可在實際應用中優化參數的後量子數位簽章方案,並在現實假設下提供可證明的安全性。
  • 將緊緻歸約的適用範圍擴展至主要的NIST後量子密碼學候選方案,包括基於編碼、格、多變數與多方計算問題的方案。

提出的方法

  • 提出一種承諾並開啟認證方案模型,其中證明者對多個字串進行承諾,並根據驗證者的挑戰開啟其中一部分。
  • 定義一種新的量子安全概念,稱為γ-sp+(特殊聲音性質),專為量子隨機Oracle模型所設計。
  • 設計一個量子攻擊者模擬器,利用原始攻擊者的查詢來高概率提取出有效的偽造。
  • 使用一種精心設計的挑戰集,結合量子重播技術,以模擬量子隨機Oracle並提取衝突。
  • 證明緊緻的安全界:破壞簽章方案的優勢被限制在破壞底層認證方案的優勢加上一個與查詢次數和挑戰空間大小相關的可忽略項。
  • 將歸約應用於方案的平行重複,進一步緊緻化多回合變體的安全界。

实验结果

研究问题

  • RQ1在量子隨機Oracle模型中,Fiat-Shamir變換能否針對承諾並開啟認證方案實現緊緻的量子歸約?
  • RQ2在先前研究僅提供漸近歸約的情況下,從此類方案衍生出的簽章方案的具體量子安全界為何?
  • RQ3如何使量子安全歸約足夠緊緻,以避免在後量子數位簽章方案中出現過度參數化?
  • RQ4現有NIST後量子密碼學候選方案(例如MQDSS、PICNIC、Stern的方案)在多大程度上能從緊緻的量子安全歸約中受益?
  • RQ5所提出的技術能否延伸至超過三回合的多回合承諾並開啟方案?

主要发现

  • 本文為Fiat-Shamir變換在承諾並開啟認證方案上的應用建立了緊緻的量子安全歸約,其界為 $ QADV_{\text{FS}}(t,q_{\text{H}}) \\nleq QADV_{\text{IS}}^{\text{γ-sp+}}(t+nr+|C|r,q_{\text{H}}) + O\big(\frac{q_{\text{H}}^2(\text{γ}-1)^r}{|C|^r}\big) $,確保可忽略的損失。
  • 對於 $ \text{λ} = 64 $ 位安全,方案需滿足 $ r \geq 219 $ 且 $ |M| \geq 192 $;而對於 $ \text{λ} = 128 $,則需 $ r \geq 438 $ 且 $ |M| \geq 384 $,基於條件 $ 2^{2\lambda}(2/3)^r < 1 $。
  • 研究成果可直接應用於主要的NIST後量子密碼學候選方案,包括Stern的方案、KTX08(格)、SSH11(多變數)、MQDSS與PICNIC,進而實現具體的安全性主張。
  • 分析顯示,目前使用 $ \text{SHAKE}_{256} $ 作為承諾函數(輸出512位)的方案,可透過減少 $ |M| $ 來優化,進而提升效率。
  • 該方法解決了先前對MQDSS與PICNIC證明中非緊緻性問題,這些方案因重播機制導致歸約損失分別達 $ q^2 $ 與 $ q^6 $ 因子。
  • 該框架可延伸至多回合方案如Pigroast/Legroast,但需進一步研究以完全將緊緻性擴展至此類協議。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。