The standard model security of the Fiat-Shamir transform has been an active research area for many years. In breakthrough results, Canetti et al. (STOC’19) and Peikert-Shiehian (Crypto’19) showed that, under the Learning-With-Errors (LWE ) assumption, it provides soundness by applying correlation-intractable (CI) hash functions to so-called trapdoor Σ -protocols. In order to be compatible with CI hash functions based on standard LWE assumptions with polynomial approximation factors, all known such protocols have been obtained via parallel repetitions of a basic protocol with binary challenges. In this paper, we consider languages related to Paillier’s composite residuosity assumption (DCR ) for which we give the first trapdoor Σ -protocols ...
Deniable ring signature can be regarded as group signature without group manager, in which a singer ...
International audienceThe Fiat-Shamir paradigm for transforming identification schemes into signatur...
Ring signature schemes provide a way to sign a message without exposing the identity of authentic si...
International audienceThe standard model security of the Fiat-Shamir transform has been an active re...
The Fiat–Shamir (FS) transformation (Fiat and Shamir, Crypto ‘86) is a popular paradigm for construc...
We provide a positive result about the Fiat-Shamir (FS) transform in the standard model, showing how...
The Fiat-Shamir transform is a well studied paradigm for removing interaction from public-coin proto...
www-cse.ucsd.edu/users/sshoup Abstract. We provide a positive result about the Fiat-Shamir (FS) tran...
Ring signatures make it possible for a signer to anonymously and, yet, convincingly leak a secret by...
We describe an adaptation of Schnorr\u27s signature to the lattice setting, which relies on Gaussian...
International audienceBasing signature schemes on strong lattice problems has been a long standing o...
The Fiat-Shamir (FS) transform is a popular technique for obtaining practical zero-knowledge argumen...
We construct efficient ring signatures (RS) from isogeny and lattice assumptions. Our ring signature...
Deniable ring signature can be regarded as group signature without group manager, in which a singer ...
International audienceThe Fiat-Shamir paradigm for transforming identification schemes into signatur...
Ring signature schemes provide a way to sign a message without exposing the identity of authentic si...
International audienceThe standard model security of the Fiat-Shamir transform has been an active re...
The Fiat–Shamir (FS) transformation (Fiat and Shamir, Crypto ‘86) is a popular paradigm for construc...
We provide a positive result about the Fiat-Shamir (FS) transform in the standard model, showing how...
The Fiat-Shamir transform is a well studied paradigm for removing interaction from public-coin proto...
www-cse.ucsd.edu/users/sshoup Abstract. We provide a positive result about the Fiat-Shamir (FS) tran...
Ring signatures make it possible for a signer to anonymously and, yet, convincingly leak a secret by...
We describe an adaptation of Schnorr\u27s signature to the lattice setting, which relies on Gaussian...
International audienceBasing signature schemes on strong lattice problems has been a long standing o...
The Fiat-Shamir (FS) transform is a popular technique for obtaining practical zero-knowledge argumen...
We construct efficient ring signatures (RS) from isogeny and lattice assumptions. Our ring signature...
Deniable ring signature can be regarded as group signature without group manager, in which a singer ...
International audienceThe Fiat-Shamir paradigm for transforming identification schemes into signatur...
Ring signature schemes provide a way to sign a message without exposing the identity of authentic si...