Lattice-based extended withdrawability

arXiv:2607.14690 · cs.CR · Submitted 2026-07-16 · Read on arXiv

Ramses Fernandez-Valencia

cs.CR

Submitted: 2026-07-16

License: http://creativecommons.org/licenses/by/4.0/

The gist: We extend the extended withdrawable signatures of Liu, Susilo and Baek to lattice-based constructions built on the Fiat-Shamir with aborts paradigm.

Terminology

Abstract

We extend the extended withdrawable signatures of Liu, Susilo and Baek to lattice-based constructions built on the Fiat-Shamir with aborts paradigm. Departing from an earlier draft that transported a per-signer shift in the clear, which leaks the signer, we realise extended withdrawable signatures as a claimable ring signature: signer ambiguity is provided by a one-out-of-N signature used as a black box (anonymity under full key exposure), and confirmation is the signer's claim, a binding signature together with the opening of a hiding index commitment bound into the transcript. No signer-derived value is published in the clear. We give complete proofs of correctness, extended withdrawability (as anonymity-until-claim), unforgeability under insider corruption, and claimability soundness, reducing to decisional MLWE (commitment hiding), MSIS (commitment binding), the anonymity of the one-out-of- N scheme, and the EUF-CMA security of the base signature, in the (quantum) random-oracle model. We instantiate the base signature with a no-hint, full- t Dilithium-style scheme and the one-out-of- N layer with an established lattice one-out-of-many proof.

Sources

Related papers