Paper 2026/629

Towards Formal Security Proofs of MQOM

Haruhisa Kosuge, NTT (Japan)
Keita Xagawa, Technology Innovation Institute
Abstract

Recent MPC-in-the-Head (MPCitH) signatures increasingly rely on aggressive GGM-tree optimizations to reduce signature size and cost, culminating in secret-key-root correlated GGM trees as used in SBC (Huth and Joux, CRYPTO 2024), MQOM (NIST PQC Standardization for Additional Signature Round-2, 2024), and rBN++ (Kim, Lee, and Son, EUROCRYPT 2025). While this technique yields substantial compression, it introduces a dependency loop in the proof (Kosuge and Xagawa, ePrint 2025/1999). We analyze MQOM and resolve this circularity by providing EUF-CMA security proofs for a slightly modified variant. The modifications consist of incorporating a salt into the input of a hash function and modifying the evaluation domain to ensure that all evaluation points are nonzero. For the resulting variant of MQOM, we prove EUF-CMA security for the GF(2) parameter sets in the random-oracle plus ideal-cipher model, assuming EUF-NMA security, standard one-wayness, and a heuristic conjecture on matrices. Our proof combines the H-coefficient technique with one-wayness, which may be of independent interest. We also prove EUF-CMA security in the (quantum) random-oracle model, where block-cipher-based hash functions are modeled as random oracles. The proof relies on EUF-NMA security and partial-guessing one-wayness (Feneuil and Rivain, ASIACRYPT 2026), which can be reduced classically to partial-domain one-wayness and, in the quantum setting, to a new notion introduced in this work called domain-extension one-wayness.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A minor revision of an IACR publication in ASIACRYPT 2026
Keywords
MQOMMPC-in-the-Head signaturesecret-key-root correlated GGM tree
Contact author(s)
hrhs kosuge @ ntt com
keita xagawa @ tii ae
History
2026-09-28: revised
2026-03-31: received
See all versions
Short URL
https://ia.cr/2026/629
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/629,
      author = {Haruhisa Kosuge and Keita Xagawa},
      title = {Towards Formal Security Proofs of {MQOM}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/629},
      year = {2026},
      url = {https://eprint.iacr.org/2026/629}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.