跳到主要內容

簡易檢索 / 詳目顯示

研究生: 蔡汶璋
Tsai, Wen-Chang
論文名稱: 基於模組晶格之門檻身分基礎簽章
Threshold Identity-Based Signatures from Module Lattices
指導教授: 曾一凡
Tseng, Yi-Fan
口試委員: 劉子源
Liu, Zi-Yuan
黃政嘉
Huang, Jheng-Jia
學位類別: 碩士
Master
系所名稱: 資訊學院 - 資訊科學系
Department of Computer Science
論文出版年: 2026
畢業學年度: 115
語文別: 英文
論文頁數: 52
中文關鍵詞: 門檻簽章身分基礎簽章模組晶格
外文關鍵詞: Threshold Signatures, dentity-Based Signatures, Module Lattices, PostQuantum Cryptography
相關次數: 點閱:9下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 本論文提出 TRaccoon-IBS,一個基於模組晶格的門檻身分基礎簽章(threshold
    identity-based signature) 方 案。 此 方 案 將 TRaccoon 的 三 輪、 無 rejection sampling門檻簽章流程調整到身分基礎設定。受信任的 Private Key Generator 透過 gadget trapdoor 與 preimage sampling 產生身分簽章金鑰,再以 Shamir secret sharing 分給簽署者。任意 T 位簽署者可共同產生簽章 Σ = (c, z);驗證者只需系統公開參數與身分字串,不必取得個別公開金鑰憑證。由於簽章流程不採用 rejection sampling,增加門檻參與者數量不會帶來額外的 rejection-sampling abort 機率。
    本 論 文 以 精 確 的 MSIS 關 係 As = Hid(ID) 取 代 TRaccoon 帶 有 error term 的MLWE 公開 簽 章 關係, 因 此 驗 證不 需 要 rounding、bit-dropping 或 hint 元件。 此改 動 也使 原 有的 Hint-MLWE 洩漏 分析 不再 適 用。我 們改 以 Rényi divergence 分析 noise flooding,並以 pairwise one-time additive masks 消除 Lagrange 係數造成的share leakage。在隨機預言機模型下,我們針對 adaptive identity/message queries 與最多 T − 1 位簽署者的 static corruption 證明 EUF-CMA 安全性。證明使用 decisional MLWE 替換 TrapGen 公開矩陣,經過十個 hybrid games,最後將成功偽造轉換為normal-form MSIS(nf-MSIS)的解。
    本論文另提出一組參考參數,並使用 C 語言原型實作,在 n = 2048 參數組下
    進行初步的大小與執行時間量測。


    We present TRaccoon-IBS, a module-lattice threshold identity-based signature scheme based on TRaccoon’s three-round, rejection-free signing protocol. A trusted Private Key Generator uses a gadget trapdoor and preimage sampling to derive an identity signing key, then shares it among N signers with Shamir secret sharing. Any T signers can jointly
    produce a signature Σ = (c, z). Verification uses the system public parameters and the identity string without a separate public-key certificate. Since signing uses no rejection sampling, a larger threshold adds no rejection-sampling abort probability.
    The construction replaces TRaccoon’s noisy MLWE signing relation with the exact MSIS relation As = Hid(ID), so verification needs no rounding, bit-dropping, or hint values. Since the Hint-MLWE leakage argument no longer applies, we analyze noise flooding with Rényi divergence and use pairwise one-time masks to cancel leakage from Lagrange coefficients. In the random oracle model, we prove EUF-CMA security for adaptive identity and message queries under static corruption of up to T − 1 signers. The proof replaces the TrapGen public matrix under decisional MLWE, proceeds through ten hybrid games, and reduces a successful forgery to normal-form MSIS (nf-MSIS).
    We also present a reference parameter set and report preliminary size and timing measurements at n = 2048 using a prototype implementation written in C.

    致謝 i
    摘要 ii
    Abstract iii
    Contents iv
    List of Figures vi
    List of Tables vii
    List of Definitions viii
    List of Abbreviations ix
    List of Notations x

    1 Introduction 1
    1.1 Our Contributions 2
    1.2 Related Work and Considerations 3
    1.3 Paper Organization 4

    2 Preliminaries 6
    2.1 Notation 6
    2.2 Lattice Background 6
    2.3 Hardness Assumption 8
    2.4 Cryptographic Building Blocks 9
    2.5 Syntax and Security Definitions 13

    3 Construction 17
    3.1 Public Parameters 18
    3.2 Setup 19
    3.3 Threshold Extraction 19
    3.4 Three-Round Threshold Signing 21
    3.5 Combine 23
    3.6 Verify 23
    3.7 Correctness 23

    4 Security 26
    4.1 Main Theorem 26
    4.2 Proof of Theorem 4.1 via Hybrid Games 28

    5 Parameters and Measurements 36
    5.1 Parameter Summary 36
    5.2 Parameter Reference 37
    5.3 Experimental Measurements 37
    5.4 Comparison with Prior Lattice-Based Threshold Schemes 39

    6 Conclusion 41
    6.1 Future Work 41

    Bibliography 42

    A Deferred Proofs 46
    A.1 Commitment Regularity Lemma 46
    A.2 Extraction Simulation Lemma 47

    B Rényi Divergence Background and Detailed Calculations 49
    B.1 Rényi Divergence for Noise Flooding 49
    B.2 Definition and Properties 50
    B.3 Shifted Gaussian Bound 50
    B.4 Multi-Session Leakage Bound (Hybrid 8 Calculation) 51
    B.5 From Rényi Divergence to Advantage Bound 52

    [ADP24] N. A. Alkadri, N. Döttling, and S. Pu, “Practical lattice-based distributed signatures for a small number of signers,” in International Conference on Applied Cryptography and Network Security, Springer, 2024, pp. 376–402 (cit. p. 4).

    [ASY22] S. Agrawal, D. Stehlé, and A. Yadav, “Round-optimal lattice-based threshold signatures, revisited,” Cryptology ePrint Archive, 2022 (cit. p. 3).

    [Ata23] S. Atapoor, “Identity-based threshold signatures from isogenies,” in IMA International Conference on Cryptography and Coding, Springer, 2023, pp. 220–240 (cit. p. 3).

    [BEP+21] P. Bert, G. Eberhart, L. Prabel, A. Roux-Langlois, and M. Sabt, “Implementation of lattice trapdoors on modules and applications,” in International Conference on Post-Quantum Cryptography, Springer, 2021, pp. 195–214 (cit. pp. 2, 10, 11, 37, 47, 48).

    [BGG+18] D. Boneh, R. Gennaro, S. Goldfeder, et al., “Threshold cryptosystems from threshold fully homomorphic encryption,” in Annual International Cryptology Conference, Springer, 2018, pp. 565–596 (cit. p. 3).

    [BKL+25] C. Boschini, D. Kaviani, R. W. Lai, et al., “Ringtail: Practical two-round threshold signatures from learning with errors,” in 2025 IEEE Symposium on Security and Privacy (SP), IEEE, 2025, pp. 149–164 (cit. p. 4).

    [BKP13] R. Bendlin, S. Krehbiel, and C. Peikert, “How to share a lattice trapdoor: Threshold protocols for signatures and (h) ibe,” in International Conference on Applied Cryptography and Network Security, Springer, 2013, pp. 218–236 (cit. p. 3).

    [BLR+18] S. Bai, T. Lepoint, A. Roux-Langlois, et al., “Improved security proofs in lattice-based cryptography: Using the rényi divergence rather than the statistical distance,” Journal of Cryptology, vol. 31, no. 2, pp. 610–640, 2018 (cit. pp. 37, 50, 52).

    [BLS01] D. Boneh, B. Lynn, and H. Shacham, “Short signatures from the weil pairing,” in International Conference on the Theory and Application of Cryptology and Information Security, Springer, 2001, pp. 514–532 (cit. p. 3).

    [BN06] M. Bellare and G. Neven, “Multi-signatures in the plain public-key model and a general forking lemma,” in Proceedings of the 13th ACM Conference on Computer and Communications Security, 2006, pp. 390–399 (cit. p. 27).

    [Bol02] A. Boldyreva, “Threshold signatures, multisignatures and blind signatures based on the gap-diffie-hellman-group signature scheme,” in International Workshop on Public Key Cryptography, Springer, 2002, pp. 31–46 (cit. p. 3).

    [BTT22] C. Boschini, A. Takahashi, and M. Tibouchi, “Musig-l: Lattice-based multisignature with single-round online phase,” in Annual International Cryptology Conference, Springer, 2022, pp. 276–305 (cit. p. 4).

    [Che23] Y. Chen, “: Efficient lattice-based two-round multi-signature with trapdoor-free simulation,” in Annual International Cryptology Conference, Springer, 2023, pp. 716–747 (cit. p. 4).

    [CS19] D. Cozzo and N. P. Smart, “Sharing the luov: Threshold post-quantum signatures,” in IMA International Conference on Cryptography and Coding, Springer, 2019, pp. 128–153 (cit. p. 3).

    [DEN+25] R. Del Pino, T. Espitau, G. Niot, and T. Prest, “Simple and efficient lattice threshold signatures with identifiable aborts,” Cryptology ePrint Archive, 2025 (cit. p. 4).

    [DKM+24] R. Del Pino, S. Katsumata, M. Maller, et al., “Threshold raccoon: Practical threshold signatures from standard lattice assumptions,” in Annual International Conference on the Theory and Applications of Cryptographic Techniques, Springer, 2024, pp. 219–248 (cit. pp. 4, 19, 22, 28, 37, 39).

    [DN25] R. Del Pino and G. Niot, “Finally! a compact lattice-based threshold signature,” in IACR International Conference on Public-Key Cryptography, Springer, 2025, pp. 169–199 (cit. pp. 4, 39).

    [DOT+21] I. Damgård, C. Orlandi, A. Takahashi, and M. Tibouchi, “Two-round n-out-of-n and multi-signatures and trapdoor commitment from lattices,” in IACR International Conference on Public-Key Cryptography, Springer, 2021, pp. 99–130 (cit. p. 4).

    [EKT25] T. Espitau, S. Katsumata, and K. Takemure, “Two-round threshold signature from algebraic one-more learning with errors,” Journal of Cryptology, vol. 38, no. 4, p. 31, 2025 (cit. p. 4).

    [ENP24] T. Espitau, G. Niot, and T. Prest, “Flood and submerse: Distributed key generation and robust threshold signature from lattices,” in Annual International Cryptology Conference, Springer, 2024, pp. 425–458 (cit. p. 4).

    [GM18] N. Genise and D. Micciancio, “Faster gaussian sampling for trapdoor lattices with arbitrary modulus,” in Annual International Conference on the Theory and Applications of Cryptographic Techniques, Springer, 2018, pp. 174–203 (cit. pp. 47, 48).

    [KG20] C. Komlo and I. Goldberg, “Frost: Flexible round-optimized schnorr threshold signatures,” in International Conference on Selected Areas in Cryptography, Springer, 2020, pp. 34–65 (cit. p. 3).

    [KRT24] S. Katsumata, M. Reichle, and K. Takemure, “Adaptively secure 5 round threshold signatures from mlwe/msis and dl with rewinding,” in Annual International Cryptology Conference, Springer, 2024, pp. 459–491 (cit. p. 4).

    [LS15] A. Langlois and D. Stehlé, “Worst-case to average-case reductions for module lattices,” Designs, Codes and Cryptography, vol. 75, no. 3, pp. 565–599, 2015 (cit. p. 8).

    [Lyu09] V. Lyubashevsky, “Fiat-shamir with aborts: Applications to lattice and factoring-based signatures,” in International Conference on the Theory and Application of Cryptology and Information Security, Springer, 2009, pp. 598–616 (cit. p. 4).

    [MP12] D. Micciancio and C. Peikert, “Trapdoors for lattices: Simpler, tighter, faster, smaller,” in Annual International Conference on the Theory and Applications of Cryptographic Techniques, Springer, 2012, pp. 700–718 (cit. pp. 2, 3, 10, 37).

    [MR07] D. Micciancio and O. Regev, “Worst-case to average-case reductions based on gaussian measures,” SIAM Journal on Computing, vol. 37, no. 1, pp. 267–302, 2007 (cit. pp. 8, 37, 46, 48).

    [Pei10] C. Peikert, “An efficient and parallel gaussian sampler for lattices,” in Annual Cryptology Conference, Springer, 2010, pp. 80–97 (cit. pp. 37, 48).

    [Pei16] C. Peikert, “A decade of lattice cryptography,” Foundations and Trends in Theoretical Computer Science, vol. 10, no. 4, pp. 283–424, 2016 (cit. p. 10).

    [Rén61] A. Rényi, “On measures of entropy and information,” in Proceedings of the Fourth Berkeley Symposium on Mathematical Statistics and Probability, Volume 1: Contributions to the Theory of Statistics, University of California Press, vol. 4, 1961, pp. 547–562 (cit. p. 50).

    [RRJ+22] T. Ruffing, V. Ronge, E. Jin, J. Schneider-Bensch, and D. Schröder, “Roast: Robust asynchronous schnorr threshold signatures,” in Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, 2022, pp. 2551–2564 (cit. p. 3).

    [Rüc10] M. Rückert, “Strongly unforgeable signatures and hierarchical identity-based signatures from lattices without random oracles,” in International Workshop on Post-Quantum Cryptography, Springer, 2010, pp. 182–200 (cit. p. 3).

    [TH14] M. Tian and L. Huang, “Efficient identity-based signature from lattices,” in IFIP International Information Security Conference, Springer, 2014, pp. 321–329 (cit. p. 3).

    [TPC+23] G. Tang, B. Pang, L. Chen, and Z. Zhang, “Efficient lattice-based threshold signatures with functional interchangeability,” IEEE Transactions on Information Forensics and Security, vol. 18, pp. 4173–4187, 2023 (cit. p. 3).

    無法下載圖示 全文公開日期 2031/07/28
    QR CODE
    :::