Linearly Homomorphic Signature with Tight Security on Lattice

Heng Guo,Kun Tian,Feng Liu,Zhiyong Zheng
2024-12-02
Abstract:At present, in lattice-based linearly homomorphic signature schemes, especially under the standard model, there are very few schemes with tight security. This paper constructs the first lattice-based linearly homomorphic signature scheme that achieves tight security against existential unforgeability under chosen-message attacks (EUF-CMA) in the standard model. Furthermore, among existing schemes, the scheme proposed in this paper also offers certain advantages in terms of public key size, signature length, and computational cost.
Cryptography and Security,Information Theory
What problem does this paper attempt to address?
The problem that this paper attempts to solve is to construct a lattice - based linear homomorphic signature scheme with tight security under the standard model. Specifically: 1. **Current problems**: - At present, among lattice - based linear homomorphic signature schemes, especially under the standard model, only a few schemes can achieve tight security. - Existing schemes have room for improvement in terms of public key size, signature length, and computational cost. 2. **Paper's goals**: - To construct the first lattice - based linear homomorphic signature scheme that achieves tight security under the standard model and can resist existential forgery attacks under chosen - message attacks (EUF - CMA). - Based on existing schemes, optimize the public key size, signature length, and computational cost. 3. **Main contributions**: - Propose a new lattice - based linear homomorphic signature scheme, which not only achieves tight security but also has a shorter signature length than previous schemes. - By introducing new technical means (such as the random orthogonal matrix generation algorithm OtrGen), improve the efficiency and security of the signature scheme. 4. **Security models**: - This scheme can achieve tight security under two security models, namely EUF - CMA (Existential Unforgeability under Chosen - Message Attacks) and U - ST - SCMA (Unforgeability under Selective - Tag Static Chosen - Message Attack). In summary, this paper aims to fill the gap in tight security of lattice - based linear homomorphic signature schemes under the standard model and provide a more efficient and secure solution.