From 5-pass MQ-based identification to MQ-based signatures

M.S. Chen, A. Hülsing, J. Rijneveld, S. Samardjiska, P. Schwabe

This paper presents MQDSS, the first signature scheme with a security reduction based on the problem of solving a multivariate system of quadratic equations (MQ problem). In order to construct this scheme we give a new security reduction for the Fiat-Shamir transform from a large class of 5-pass identification schemes and show that a previous attempt from the literature to obtain such a proof does not achieve the desired goal. We give concrete parameters for MQDSS and provide a detailed security analysis showing that the resulting instantiation MQDSS-31-64 achieves 128 bits of post-quantum security. Finally, we describe an optimized implementation of MQDSS-31-64 for recent Intel processors with full protection against timing attacks and report benchmarks of this implementation.

Advances in Cryptology - ASIACRYPT 2016
Published - 2016
22nd International Conference on the Theory and Application of Cryptology and Information Security, ASIACRYPT 2016
Duration: 4 Dec 2016 → 8 Dec 2016
Conference number: 22

22nd International Conference on the Theory and Application of Cryptology and Information Security, ASIACRYPT 2016
ASIACRYPT 2016
