Thomas Debris-Alazard, Pierre Loisel, Inria Saclay, Laboratoire LIX, Ecole Polytechnique, France; Valentin Vasseur, Thales, France
Session:
Post-quantum Cryptography
Track:
5: Cryptography
Location:
Ballroom II & III
Presentation Time:
Fri, 12 Jul, 10:45 - 11:05
Session Chair:
Jens Zumbraegel,
Abstract
Enhanced pqsigRM is a code-based hash-and-sign scheme proposed to the second National Institute of Standards and Technology call for post-quantum signatures. The scheme is based on the (U,U+V)-construction and it enjoys remarkably small signature lengths, about 1KBytes for a security level of 128 bits. Unfortunately we will show that signatures leak information about the underlying (U,U+V)-structure. It allows to retrieve the private-key with 100, 000 signatures.