Presentation is loading. Please wait.

Presentation is loading. Please wait.

Multivariate Signature Scheme using Quadratic Forms Takanori Yasuda (ISIT) Joint work with Tsuyoshi Takagi (Kyushu Univ.), Kouichi Sakurai (Kyushu Univ.)

Similar presentations


Presentation on theme: "Multivariate Signature Scheme using Quadratic Forms Takanori Yasuda (ISIT) Joint work with Tsuyoshi Takagi (Kyushu Univ.), Kouichi Sakurai (Kyushu Univ.)"— Presentation transcript:

1 Multivariate Signature Scheme using Quadratic Forms Takanori Yasuda (ISIT) Joint work with Tsuyoshi Takagi (Kyushu Univ.), Kouichi Sakurai (Kyushu Univ.) 2013/3/3 Workshop on Solving Multivariate Polynomial Systems and Related Topics

2 Contents 1.Multivariate Signature Schemes 2.Quadratic Forms 3.Multivariate System defined by Quadratic Forms 4.Application to Signature Scheme 5.Comparison with Rainbow 1.Efficiency of Signature Generation 2.Key Sizes 3.Security 6.Conclusion 1

3 MPKC Signature Signature Message 6 For any message M, there must exist the corresponding signature. F is surjective.

4 New Multivariate Polynomial Map We introduce a multivariate polynomial map not surjective, and apply it to signature. 2 For a symmetric matrix A,

5 Problems of G 3 Is G applicable to signature or not? Problems

6 Quadratic Forms

7

8 How to compute the inverse map 5 Simple case Problem 1’ is equivalent to

9 Real field Case Gram-Schmidt orthonormalization provides an efficient algorithm to solve Problem 1’’. Definition: We want to apply Gram-Schmidt orthonormalization technique to the case of finite fields.

10 Finite Field Case However, we can extend Gram-Schmidt orthonormalization by inserting a step: We cannot apply Gram-Schmidt orthonormalization directly. Solve Problem 1’

11 Problem 2 7

12 Classification Theorem

13 Application to MPKC Signature Scheme

14 Signature Generation

15 Property of Our Scheme 14

16 Property of Our Scheme Multivariate Polynomial Maps Rainbow UOV HFE MI Proposal Surjective Not Surjective 4

17 Security of Our Scheme There are several attacks of MPKC signature schemes which depend on the structure of central map. For example, UOV attack is an attack which transforms public key into a form of central map of UOV scheme. o Central maps of UOV ara surjective. o The public key of our scheme cannot be transformed into any surjective map. These attacks is not applicable against our scheme. ( Other example: Rainbow-band-separation attack, UOV-Reconciliation attack ) However, attacks which is independent of scheme, like direct attacks, are applicable to our scheme. 15

18 Comparison with Rainbow 16

19 Conclusion We propose a new MPKC signature scheme using quadtaci forms. The multivariate polynomial map used in the scheme is not surjective. Signature generation uses an extended Gram-Schmidt orthonormalization. It is 8 or 9 times more efficient than that of Rainbow at the level of 88-bit security. Future Work Security analysis Application to encryption scheme 17


Download ppt "Multivariate Signature Scheme using Quadratic Forms Takanori Yasuda (ISIT) Joint work with Tsuyoshi Takagi (Kyushu Univ.), Kouichi Sakurai (Kyushu Univ.)"

Similar presentations


Ads by Google