MIRANDA: short signatures from a leakage-free full-domain-hash scheme
cs.CR, cs.IT, math.IT
Submitted: 2025-10-08
Updated: 2026-09-23
License: http://creativecommons.org/licenses/by/4.0/
The gist: We present, the first family of full-domain-hash signatures based on matrix codes.
Terminology
Abstract
We present, the first family of full-domain-hash signatures based on matrix codes. This signature scheme fulfils the paradigm of Gentry, Peikert and Vaikuntanathan, which gives strong security guarantees. Our trapdoor is very simple and generic: if we propose it with matrix codes, it can actually be instantiated in many other ways since it only involves a subcode of a decodable code (or lattice) in a unique decoding regime of parameters. Though signing algorithm relies on a decoding task where there is exactly one solution, there are many possible signatures given a message to sign and we ensure that signatures are not leaking information on their underlying trapdoor by means of a very simple procedure involving the drawing of a small number of uniform bits. In particular does not use a rejection sampling procedure which makes its implementation a very simple task contrary to other-like signatures schemes such as or even. We instantiate with the famous family of Gabidulin codes represented as spaces of matrices and we study thoroughly its security (in the EUF-CMA security model). For 128 bits of classical security, the signature sizes are as low as 90 bytes and the public key sizes are in the order of 2.6 megabytes.
Sources
- Revisiting Algebraic Attacks on MinRank and on the Rank Decoding Problem
- Code-based Cryptography: Lecture Notes
- The problem with the SURF scheme
- Polynomial-Time Key Recovery Attack on the Lau-Tan Cryptosystem Based on Gabidulin Codes
- Properties of codes in rank metric
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs