Cryptanalysis of a Lattice-based Multi-signature Scheme

Ramakant Kumar,Sahadeo Padhye
DOI: https://doi.org/10.1007/s40009-024-01583-1
2024-12-07
National Academy Science Letters
Abstract:Kansal and Dutta proposed a lattice-based round optimal multi-signature scheme in AFRICA-CRYPT 2020. They achieved signature compression and public key aggregation with only one round of signature generation. They showed that their scheme is unforgeable under the hardness of the short integer solution problem. In 2023, Liu et al. showed that forgery is possible in this scheme. They showed that an adversary with sufficient message-signature pairs could find the signer's secret key in polynomial time. In this paper, we propose a flaw in the design of the Kansal-Dutta multi-signature scheme. We show that with the help of only one valid message-signature pair, an adversary can generate forged multi-signature even without computing the secret keys of the signers. We also give suggestions to overcome the proposed attack.
multidisciplinary sciences
What problem does this paper attempt to address?