G+G: A Fiat-Shamir Lattice Signature Based on Convolved Gaussians

Julien Devevey, École Normale Supérieure de Lyon
Alain Passelègue, French Institute for Research in Computer Science and Automation, École Normale Supérieure de Lyon, CryptoLab, Inc.
Damien Stehlé, École Normale Supérieure de Lyon, CryptoLab, Inc.

We describe an adaptation of Schnorr's signature to the lattice setting, which relies on Gaussian convolution rather than flooding or rejection sampling as previous approaches. It does not involve any abort, can be proved secure in the ROM and QROM using existing analyses of the Fiat-Shamir transform, and enjoys smaller signature sizes (both asymptotically and for concrete security levels).

Note: Fixed parameter sizes. Fixed minor editorial mistakes.

A minor revision of an IACR publication in ASIACRYPT 2023
