Paper 2026/557

On Post-Quantum Signature with Message Recovery from Hash-and-Sign in QROM

Bohang Chen, Shanghai Jiao Tong University
Shuai Han, Shanghai Jiao Tong University
Shengli Liu, Shanghai Jiao Tong University
Abstract

Post-quantum signatures have been suffering from their inefficiency compared to traditional signatures. To reduce space consumption, a promising approach is to design signature schemes with message recovery, which can embed part of the message into the signature without increasing its length. A notable example is the PSS-R signature scheme (probabilistic signature scheme with recovery) proposed by Bellare and Rogaway (EUROCRYPT 1996) in the classical ROM (random oracle model). However, there were few works considering post-quantum signature schemes with message recovery. In this work, we study the design of post-quantum signature scheme with message recovery in the QROM (quantum ROM). Specifically, we adapt the classic PSS-R signature scheme to the post-quantum setting and prove its security in the QROM. Our security proof is conceptually similar to the original proof of PSS-R, but faces challenges in QROM when we need to reprogram two random oracles with correlated inputs/outputs. To address these issues, we extend the tight adaptive reprogramming theorem (Grilo et al., ASIACRYPT 2021) and the measure-and-reprogram theorem (Don et al., CRYPTO 2020) to our setting, to support reprogramming two oracles successively, where the input to one oracle depends on the other oracle's output. With these extended proof techniques, we provide the first security proof of a PSS-R-like signature scheme with message recovery in the QROM.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A minor revision of an IACR publication in PKC 2026
Keywords
Post-quantum SecurityDigital SignatureMessage RecoveryQROM
Contact author(s)
bohang0918 @ sjtu edu cn
dalen17 @ sjtu edu cn
slliu @ sjtu edu cn
History
2026-05-21: revised
2026-03-20: received
See all versions
Short URL
https://ia.cr/2026/557
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/557,
      author = {Bohang Chen and Shuai Han and Shengli Liu},
      title = {On Post-Quantum Signature with Message Recovery from Hash-and-Sign in {QROM}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/557},
      year = {2026},
      url = {https://eprint.iacr.org/2026/557}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.