Paper 2024/1256

Concrete Analysis of Schnorr-type Signatures with Aborts

Theo Fanuela Prabowo, National University of Singapore
Chik How Tan, National University of Singapore
Abstract

Lyubashevsky’s signature can be viewed as a lattice-based adapation of the Schnorr signature, with the core difference being the use of aborts during signature generation process. Since the proposal of Lyubashevsky’s signature, a number of other variants of Schnorr-type signatures with aborts have been proposed, both in lattice-based and code-based setting. In this paper, we examine the security of Schnorr-type signature schemes with aborts. We give a detailed analysis of when the expected value of the signature is correlated to the secret key, and when it is not. Our analysis shows that even when abort condition is employed, it is crucial to set the parameters carefully in order to defend against statistical attack. In particular, we recommend to set δ ≥ β (where δ, β are public parameters) as in this case we prove that the signature does not reveal any information about the secret key. On the other hand, if this condition is not satisfied, then some information about the secret key are leaked, making the scheme susceptible to statistical attacks. For completeness, we also analyze the security of Schnorr-type signatures without aborts. In particular, we present a detailed key recovery attack via statistical method on the EagleSign signature, which is one of the submission to the NIST call for Additional PQC Signature. Moreover, we give a formula for determining the number of required signatures to successfully launch the statistical attack.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
statistical attackkey recovery attackLyubashevsky's signaturesignature with abortsSchnorr-type signatures
Contact author(s)
tsltfp @ nus edu sg
tsltch @ nus edu sg
History
2024-08-09: approved
2024-08-08: received
See all versions
Short URL
https://ia.cr/2024/1256
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/1256,
      author = {Theo Fanuela Prabowo and Chik How Tan},
      title = {Concrete Analysis of Schnorr-type Signatures with Aborts},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/1256},
      year = {2024},
      url = {https://eprint.iacr.org/2024/1256}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.