首页> 外文会议>International Conference on the Theory and Application of Cryptology and Information Security >SQISign: Compact Post-quantum Signatures from Quaternions and Isogenies
【24h】

SQISign: Compact Post-quantum Signatures from Quaternions and Isogenies

机译:SQISIGN:四季度和异构化的压缩后量子签名

获取原文

摘要

We introduce a new signature scheme, SQISign, (for Short Quaternion and Isogeny Signature) from isogeny graphs of supersingular elliptic curves. The signature scheme is derived from a new one-round, high soundness, interactive identification protocol. Targeting the post-quantum NIST-1 level of security, our implementation results in signatures of 204 bytes, secret keys of 16 bytes and public keys of 64 bytes. In particular, the signature and public key sizes combined are an order of magnitude smaller than all other post-quantum signature schemes. On a modern workstation, our implementation in C takes 0.6 s for key generation, 2.5 s for signing, and 50 ms for verification. While the soundness of the identification protocol follows from classical assumptions, the zero-knowledge property relies on the second main contribution of this paper. We introduce a new algorithm to find an isogeny path connecting two given supersingular elliptic curves of known endomorphism rings. A previous algorithm to solve this problem, due to Kohel, Lauter, Petit and Tignol, systematically reveals paths from the input curves to a 'special' curve. This leakage would break the zero-knowledge property of the protocol. Our algorithm does not directly reveal such a path, and subject to a new computational assumption, we prove that the resulting identification protocol is zero-knowledge.
机译:我们介绍了一种新的签名计划,SQIsign,(对于短四季度和短期和源性签名),来自超椭圆曲线的isogeny图。签名方案源自新的单轮,高声,交互式识别协议。针对Quantum NIST-1安全性的安全性,我们的实现导致204个字节的签名,秘密键16个字节和64字节的公钥。特别地,组合的签名和公钥尺寸是小于所有其他后量子签名方案的数量级。在现代化的工作站上,我们在C中的实施需要0.6秒,用于签名2.5秒,验证50毫秒。虽然识别协议的声音遵循古典假设,但零知识属性依赖于本文的第二个主要贡献。我们介绍了一种新的算法,找到了连接两个给定的已知内骨形环的两个给定的椭圆形曲线的基因发生路径。通过Kohel,Lauter,Petit和Tignol来解决这个问题的先前算法,系统地揭示了从输入曲线到“特殊”曲线的路径。此泄漏将破坏协议的零知识属性。我们的算法没有直接揭示这样的路径,并且受到新的计算假设的影响,我们证明了结果的识别协议是零知识。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号