Paper 2026/1991

Towards Practical Iterative Rejection Sampling: A Compact and Efficient Signature over Module Lattices

Yifan Ming, Institute of Software, Chinese Academy of Sciences
Jipeng Zhang, National University of Singapore
Zihan Liu, Institute of Software, Chinese Academy of Sciences
Guofeng Tang, Singapore Management University
Pengfei Chen, Zhejiang University
Yutao Sun, Beijing Electronic Science and Technology Institute
Si Gao, Institute of Software, Chinese Academy of Sciences
Cong Zhang, Zhejiang University
Long Chen, Institute of Software, Chinese Academy of Sciences
Abstract

Lattice signatures face a strict trade-off among compactness, implementation simplicity, and reliance on standard lattice assumptions: ML-DSA-44 requires a 2420-byte signature (3732 bytes combined) and HAETAE-120 takes 1474 bytes (2466 bytes combined), while Falcon-512 achieves 555 bytes but relies on complex floating-point arithmetic. We propose SHUTTLE, a compact Fiat–Shamir signature built on a standard MLWE public-key structure with unforgeability bound to MSIS in the random oracle model. At NIST Level I, SHUTTLE achieves a signature size of 1175 bytes (and 2167 bytes combined)—a 51% reduction in signature size over ML-DSA-44 and 20% smaller than HAETAE-120 using purely integer arithmetic. SHUTTLE resolves prior compact schemes’ limitations via three core techniques: (1) replacing secret-dependent rejection in the iterative sampling loop with a deterministic transition bounded by Rényi divergence, relegating restarts solely to public bounds and encoding checks (occurring with negligible probability $\approx 2^{-30}$); (2) reformulating transition logic in the logarithmic domain into simple integer interval comparisons; and (3) employing an asymmetric stretch-and-compress mechanism to offset MLWE parameter expansion. By eliminating secret-dependent rejection from the inner loop, SHUTTLE achieves constant-time execution with fast signing (1406k cycles, about $3\times$ faster than HAETAE-120) and verification faster than ML-DSA-44.

Note: This is the full version of our paper accepted at ASIACRYPT 2026 (paper ID 806), including the proofs and additional implementation details omitted from the proceedings version.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A major revision of an IACR publication in ASIACRYPT 2026
Keywords
lattice-based signaturesiterative rejection samplingpost-quantum cryptographyRényi divergence
Contact author(s)
mingyifan2024 @ iscas ac cn
jp-zhang @ outlook com
liuzihan2024 @ iscas ac cn
tang guofeng789 @ gmail com
chenpengfei155 @ gmail com
sun_yutao @ foxmail com
gaosi @ iscas ac cn
congresearch @ zju edu cn
chenlong @ iscas ac cn
History
2026-09-14: approved
2026-09-12: received
See all versions
Short URL
https://ia.cr/2026/1991
License
Creative Commons Attribution-NonCommercial-NoDerivs
CC BY-NC-ND

BibTeX

@misc{cryptoeprint:2026/1991,
      author = {Yifan Ming and Jipeng Zhang and Zihan Liu and Guofeng Tang and Pengfei Chen and Yutao Sun and Si Gao and Cong Zhang and Long Chen},
      title = {Towards Practical Iterative Rejection Sampling: A Compact and Efficient Signature over Module Lattices},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1991},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1991}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.