Download presentation
Presentation is loading. Please wait.
1
Post-Quantum Security of Fiat-Shamir
Dominique Unruh University of Tartu
2
Fiat-Shamir (overview)
Non-interactive proof system: Zero-knowledge proof of knowledge Signature scheme (Signer proves knowledge of sk) Quantum secure? Prover πππ,π» πππ ,πππ π Verifier statement witness statement Verifier learns βnothingβ Prover must know witness Quantum Fiat-Shamir
3
Understanding FS: Sigma protocols
Interactive proof system Honest-verifier zero-knowledge Interaction πβπ efficiently simulated Special soundness Given: πππ π for two πβπππ (same πππ) Get: Witness P V commitment challenge response Quantum Fiat-Shamir
4
Understanding FS: The construction
Verifier Prover Prover sends simulated sigma-proto interaction ο Soundness of sigma-protocol carries over P V πππ πβπππβ π»(πππ) πππ,πβπππ,πππ π πβπππ πππ π Quantum Fiat-Shamir
5
Breaking FS soundness (quantum)
Artificial sigma-protocol [Ambainis,Rosmanis,U14] (relative to specific oracles) P Can give πππ π for any πβπππ (using |Ξ¨βͺ) Only once (|Ξ¨βͺ used up) FS insecure (soundness) But: sigma-protocol has special soundness ππππ |Ξ¨βͺ πβπππ πππ π Quantum Fiat-Shamir
6
Breaking FS soundness (quantum)
FS not secure in general For quantum attackers Relative to specific oracles Ways out: Non-relativizing proofs? Doubtful. Other protocols? Yes. Extra conditions on sigma-protocol? This talk. [U15] [Dagdelen, Fischlin,Gagliardoni13] Quantum Fiat-Shamir
7
Main result Sigma protocol Fiat-Shamir Statistical soundness
Reduction to quantum search Simulation soundness Stronger than classical Weaker than classical Honest verifier ZK Adaptive RO reprogramming Zero knowledge Unpredictable commitments Complete Complete Quantum Fiat-Shamir
8
P V P V Soundness proof Sigma protocol
Def: πβπππ is βpromisingβ if β πππ π P V πππ πβπππ πππ π statistical soundness βΉ For any πππ, few promising πβπππ Hard to find: πππ with π»(π₯,πππ) promising Fiat-Shamir Hard to break Fiat-Shamir soundness: Finding valid πππ,π» π₯,πππ ,πππ π P πππ,π» π₯,πππ ,πππ π V Quantum Fiat-Shamir
9
Simulation sound extractability
What about signatures? Quantum Classical approach: Sigma protocol Fiat-Shamir (as proof) Statistical Special soundness Simulation sound extractability β ? Fiat-Shamir (as signature) Unforgeability Honest verifier ZK Zero knowledge Hard instances Dual-mode Hard to guess π π from ππ ππ indistinguishable from ππ without π π Quantum Fiat-Shamir
10
Open problems Suitable sigma protocols [Kiltz,Lyubashevsky,Schaffner]?
Stronger guarantees: Extractability? Weaker assms: Computational soundness? Tightness of reductions Quantum Fiat-Shamir
11
I thank you for your attention
This research was supported by European Social Fundβs Doctoral Studies and Internationalisation Programme DoRa
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.