MQQ-SIG - An Ultra-Fast and Provably CMA Resistant Digital Signature Scheme
نویسندگان
چکیده
We present MQQ-SIG, a signature scheme based on “Multivariate Quadratic Quasigroups”. The MQQ-SIG signature scheme has a public key consisting of n 2 quadratic polynomials in n variables where n = 160, 192, 224 or 256. Under the assumption that solving systems of n 2 MQQ’s equations in n variables is as hard as solving systems of random quadratic equations, we prove that in the random oracle model our signature scheme is CMA (Chosen-Message Attack) resistant. From efficiency point of view, the signing and verification processes of MQQ-SIG are three orders of magnitude faster than RSA or ECDSA. Compared with other MQ signing schemes, MQQ-SIG has both advantages and disadvantages. Advantages are that it has more than three times smaller private keys (from 401 to 593 bytes), and the signing process is an order of magnitude faster than other MQ schemes. That makes it very suitable for implementation in smart cards and other embedded systems. However, MQQ-SIG has a big public key (from 125 to 512 Kb) and it is not suitable for systems where the size of the public key has to be small.
منابع مشابه
A Polynomial-Time Key-Recovery Attack on MQQ Cryptosystems
We investigate the security of the family of MQQ public key cryptosystems using multivariate quadratic quasigroups (MQQ). These cryptosystems show especially good performance properties. In particular, the MQQ-SIG signature scheme is the fastest scheme in the ECRYPT benchmarking of cryptographic systems (eBACS). We show that both the signature scheme MQQ-SIG and the encryption scheme MQQ-ENC, a...
متن کاملCertificate-Based Secure Three-Party Signcryption Scheme with Low Costs
A signcryption scheme combining public key encryption and digital signatures can simultaneously satisfy the security requirements of confidentiality, integrity, authenticity and non-repudiation. In a three-party communication environment, a message signcrypted by one party might have to be securely delivered to the other two and they usually independently decrypt the ciphertext and verify recov...
متن کاملOptimal Parameters for XMSS
We introduce Multi Tree XMSS (XMSS ), a hash-based signature scheme that can be used to sign a virtually unlimited number of messages. It is provably forward and hence EU-CMA secure in the standard model and improves key and signature generation times compared to previous schemes. XMSS has — like all practical hash-based signature schemes — a lot of parameters that control different trade-offs ...
متن کاملOn Provably Secure Code-Based Signature and Signcryption Scheme
Signcryption is a cryptographic protocol that provides authentication and confidentiality as a single primitive at a cost lower than the combined cost of sign and encryption. Due to the improved efficiency, signcryption schemes have found significant applications in areas related to E-commerce. Shor’s algorithm [22] poses a threat to number-theoretic algorithms, as it can solve the number-theor...
متن کاملA New Digital Signature Scheme and its Application to aPractical
This paper introduces a new digital signature scheme that is provably secure against adaptive chosen message attacks provided the so-called Strong RSA Assumption holds. This signature scheme leads to a new coalition-resistant group signature scheme that is signiicantly more eecient than the previously known schemes with the same security properties .
متن کامل