Paper 2026/1103

Jevil: A Catastrophic-Failure-by-Design Signature Scheme

Nadim Kobeissi, Symbolic Software
Abstract

Few-time signatures cap how many signatures a signer can safely issue. Jevil is, to our knowledge, the first post-quantum and transparent (setup-free) few-time signature scheme with a sharp key-recovery cliff: its cap is enforced by a single sharp threshold rather than a slow slope. Signatures one through $n^{\star}$ are existentially unforgeable at approximately $124$-bit classical security; at the $(n^{\star}{+}1)$-th the entire secret polynomial becomes publicly recoverable, achieving catastrophic failure as a key design requirement. The cap is founded on a secret polynomial together with the degree-binding of a polynomial commitment, and is intrinsic to any accepted public key: even a malicious signer who chooses $\mathsf{pk}$ adversarially cannot construct one that lets them keep signing past the cliff without the same polynomial becoming publicly recoverable. All prior post-quantum few-time schemes (HORS, FORS, PORS, HORSIC$^{+}$, eBiBa, Syrga$_2$) degrade softly as $(nK/T)^K$. Every prior cliff-style construction misses at least one of post-quantum, transparent, sharp, and count-triggered: one-time Schnorr/ECDSA nonce reuse is neither post-quantum nor a designed property; polynomial-witness key-extraction signatures (notably DSKE) over KZG or IPA commitments are sharp but neither post-quantum nor transparent, while DSKE's hash-based variant is post-quantum and transparent but degrades softly; and double-authentication-preventing signatures (DAPS), post-quantum and transparent in their lattice form, fire a sharp key-recovery cliff on a message predicate (signing conflicting messages) rather than on a signature count, so they are not few-time schemes. Concretely, Jevil provides $68$-byte public keys, $32$-byte secret keys, and $\sim 40$~KB to $\sim 500$~KB signatures across the recommended signing budgets $n^{\star} \in \{1, 3, 7, 15, \ldots, 2^{14} - 1\}$, the range admitted by the working field's $2$-adicity. All primitives are believed to be post-quantum.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Few-time signatureswhirpolynomial commitmentspost-quantum cryptography
Contact author(s)
nadim @ symbolic software
History
2026-06-01: last of 4 revisions
2026-05-29: received
See all versions
Short URL
https://ia.cr/2026/1103
License
Creative Commons Attribution-NonCommercial-ShareAlike
CC BY-NC-SA

BibTeX

@misc{cryptoeprint:2026/1103,
      author = {Nadim Kobeissi},
      title = {Jevil: A Catastrophic-Failure-by-Design Signature Scheme},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1103},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1103}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.