Paper 2025/1841

Fast Post-Quantum Ring Signature from Power Residue PRFs with QROM Security

Xinyu Zhang, Monash University
Ziyi Li, Hong Kong Polytechnic University
Ron Steinfeld, Monash University
Raymond K. Zhao, ExeQuantum
Joseph K. Liu, Monash University
Tsz Hon Yuen, Monash University
Abstract

Ring signatures enable a user to sign anonymously on behalf of a group, providing a fundamental building block for privacy-preserving applications such as anonymous credentials and private transactions. Existing post-quantum constructions, however, face a persistent tension between efficiency and rigorous quantum security: practical schemes are typically analysed only in the classical random oracle model (ROM), whereas schemes with proofs in the quantum random oracle model (QROM) either incur multi-megabyte signatures, lack implementations, or rely on reductions too loose to support concrete parameter selection. We present PegaRing, the first post-quantum ring signature to combine practical performance with concretely parameterised security in QROM. At the 128-bit security level and a ring size of 1024, PegaRing produces 28KB signatures, reducing signature size by a factor of 88 relative to the smallest prior concretely parameterised QROM-secure construction. Our implementation signs in 4.325 ms and verifies in 3.074 ms. Compared with the state-of-the-art VOLE-in-the-head ring signature, which is proven secure only in classical ROM, PegaRing reduces signing and verification latency by factors of 2.65 and 3.80, respectively, while providing security in QROM. Finally, when using the first message-dependent Fiat-Shamir challenge as the boundary between offline and online computation, PegaRing's online signing phase takes 0.018 ms, compared with 7.611 ms for VOLE-in-the-head construction, achieving a reduction of more than 400 times. These results substantially narrow the gap between rigorous quantum security and practical performance for post-quantum ring signatures and make QROM-secure anonymous authentication feasible for various anonymity sets.

Note: Major Revision. This version updates the key contribution of the paper and revised analysis of beta-approximate PRF relation with respect to arithmetic progression list. We also updated the implementation and experiment results.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Legendre and Power Residue PRFsSigma ProtocolPost-QuantumSignatureRing SignatureQROM
Contact author(s)
xinyu zhang2 @ monash edu
zycal li @ polyu edu hk
ron steinfeld @ monash edu
raymond @ exequantum com
Joseph Liu @ monash edu
john tszhonyuen @ monash edu
History
2026-08-28: last of 3 revisions
2025-10-06: received
See all versions
Short URL
https://ia.cr/2025/1841
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1841,
      author = {Xinyu Zhang and Ziyi Li and Ron Steinfeld and Raymond K. Zhao and Joseph K. Liu and Tsz Hon Yuen},
      title = {Fast Post-Quantum Ring Signature from Power Residue {PRFs} with {QROM} Security},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1841},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1841}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.