A New Lattice-Based Post-Quantum Digital Signature from Compact Rejection Sampling
Abstract
1. Introduction
1.1. Our Contribution
- On the Difficulty of Constructing CRS Schemes. Although it would seem that centered binomial distributions have been used to extract the secret key coefficients in lattice-based key exchanges [23] for a long time, it is far from being enough to build a rejection sampling for a FSwA signature scheme. The main difficulty is how to compute bounded but small enough repetitions of M to meet the rejection sampling conditions, as centered binomial distributions hardly have known and related geometric properties in previous works. This prevented previous schemes from using centered binomial distributions to construct the FSwA signatures. In this work, we discuss several very important properties of the centered binomial distributions, and prove that there exists a small enough M to achieve an efficient centered binomial-based rejection sampling.
- Compact Rejection Sampling with High-Precision and Semi-Uniform Operation. This work describes a construction of the compact rejection sampling. It not only has high-precision sampling as Gaussian distribution, but also has the property of semi-uniform operation similar to uniform distribution, which are highly associated with the performance of our proposed FSwA signature scheme. Unlike the rejection samplings in previous works are based on Gaussian or uniform distributions, this work develops a new rejection sampling from centered binomial distribution. A sampling from a centered binomial distribution is defined as follows:
- –
- Sample ,
- –
- Output
It only consists of a uniform random sampling and addition and subtraction operations. This is why we name “semi-uniform operation” in this work. Therefore it is simple to resist against timing attacks, as no large tables or data-dependent branches are required [23]. - An Efficient Lattice-Based FSwA Signature Scheme from Centered Binomial Distribution. This work focuses on the lattice-based FSwA signatures, and proposes the use of centered binomial distribution in Lyubashevsky’s signature [8] scheme. Our goal is to attempt to construct a lattice-based FSwA signature by a new probability distribution, rather than Gaussian or uniform distribution. The main technique is our compact rejection sampling from centered binomial distribution, which is the essential building block to design FSwA signature in lattices. To some extent, the proposed scheme combines the advantages of both GRS and URS schemes, while preventing the disadvantages of both. Therefore, our construction may be seen as a new and alternative approach to construct efficient lattice-based signature schemes.
- Minimize the Sizes of Signature and Public Key. The fact that our proposed scheme has short signature and public key sizes is an inherent result. Centered binomial distribution not only has the property of semi-uniform operation but also owns the bell-shaped characteristic and high-precision sampling as Gaussian distribution. This intuitively gives us the desirable parameters for our scheme as the output of the signatures follows the centered binomial distribution. Concretely, the combination of signature and public key sizes of our proposed scheme is slightly larger than those of GRS schemes but smaller than those of URS signature schemes.
1.2. Organization
2. Preliminaries
2.1. Notations
2.2. Digital Signature
- KeyGen: The key generation algorithm takes as input the system parameter, and returns a public/secret key pair .
- Sign: The sign algorithm takes as the message μ and the secret key . It returns a signature ϱ of μ.
- Verify: The verify algorithm takes as input the pair and the public key . It returns “Accept” if ϱ is a valid signature of message μ; otherwise, it returns “Reject”.
- Setup: The challenger runs the KeyGen algorithm to get the key pair , sends public key to the adversary, and keeps the secret key in private.
- Query: The adversary adaptively chooses messages and makes signature queries on these messages. For each signature query on the message , the challenger runs the signing algorithm and sends the signature to the adversary.
- Forgery: The adversary returns a forged signature on some message and wins the game if
- is a valid signature of the message .
- The signature of has not been queried.
2.3. Hardness Assumptions in Lattices
2.4. Generic Rejection Sampling
- 1.
- , , output with probability .
- 2.
- , , output with probability .
3. Centered Binomial Distribution and Rejection Sampling
3.1. Centered Binomial Distribution
- Sample , and
- Output
3.2. The Proposed Rejection Sampling
- 1.
- .
- 2.
- .
- 3.
- Output with probability .
- is within statistical distance of the distribution of the following algorithm :
- 1.
- .
- 2.
- .
- 3.
- Output with probability .
4. The Construction
4.1. High-Level Description of the Scheme
4.2. Formal Description
- KeyGen: Input security parameter, output public key and secret key .
- Choose where every coefficient of is chosen uniformly and independently from .
- Uniformly random sample .
- Compute .
- Return public key and secret key .
- Sign: Input the public and secret key pair and the message , output a signature of .
- Sample .
- Compute .
- Compute .
- Output with probability , where , and .
- If , then restart.
- Return a signature .
- Verify: Input public key, signature and message , output “Accept” or “Reject”.
- If , return “Reject”.
- If , return “Reject”.
- If , return “Reject”.
- Otherwise, return “Accept”.
- RejectionSampling :
- Let .
- Let .
- With probability , output 1, else output 0.
- Sign: Input the public and secret key pair and message , output a signature .
- Sample .
- Compute .
- Compute .
- .
- If , then restart.
- If , then restart.
- Return a signature .
4.3. Concrete Parameters
4.4. Security Evaluation
- Primal SIS Attack. This attack targets the primal lattice of dimension , directly searching for the short signature vector. The estimator finds the optimal BKZ block size for our present parameters. The resulting classical attack cost is operations, and the quantum cost is , both exceeding the target 128-bit security. In addition, the Euclidean norm bound of our signature is larger than the lattice’s heuristic shortest vector, adding extra enumeration overhead for adversaries.
- Dual SIS Attack. This attack works on the smaller dual lattice of dimension . To offset the smaller lattice dimension, the optimal BKZ block size rises to . The dual attack costs classical operations and quantum gates, which are both higher than the primal attack costs. The tight bound of secret key coefficients removes weak exploitable lattice structures. As the primal attack is computationally cheaper, we use its security bounds as our conservative 128-bit security lower bound.
- Shortest Vector Problem (SVP) Baseline. We take SVP as the core hardness baseline for SIS attacks under our parameters. The primal SIS lattice has volume , and the norm of the shortest non-zero lattice vector is , which exactly matches the Euclidean norm upper bound of our signature, meaning adversaries cannot exploit substantially shorter vectors to weaken the problem. All primal and dual SIS attacks boil down to SVP solved via BKZ lattice sieving, both surpassing 128-bit security by the above discussion.
4.5. Efficiency Comparison
4.6. The Compactness and Simple Implementation
5. Security Proof
- Hybridsign :
- Uniformly random sample .
- Sample .
- Output with probability where .
- Program .
- Return .
- Hybridsign* :
- Sample .
- . That is, it samples a random and then reprograms H consistently.
- Compute .
- Output with probability , where .
- If , then restart.
- Return .
- Hybridsign** :
- Sample .
- Sample .
- Compute .
- Output with probability , where .
- If , then restart.
- Program .
- Return .
- The Hybridsign* and Hybridsign** differ only in the order of sampling c and programming the random oracle. We invoke Theorem 3 from reference [30], in which the statistical distance between the Hybridsign* and the Hybridsign** is only related to the security parameter , independent of query counts. Therefore, this result is still valid here, and it proves that reordering uniform sampling of c and lazy RO programming introduces only a negligible statistical distance in the random oracle model.
6. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Ducas, L.; Kiltz, E.; Lepoint, T.; Lyubashevsky, V.; Schwabe, P.; Seiler, G.; Stehlé, D. Module-Lattice-Based Digital Signature Standard. Available online: https://csrc.nist.gov/Projects/post-quantum-cryptography (accessed on 11 December 2025).
- Ducas, L.; Kiltz, E.; Lepoint, T.; Lyubashevsky, V.; Schwabe, P.; Seiler, G.; Stehlé, D. CRYSTALS-Dilithium: A lattice-based digital. Signature scheme. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2018, 1, 238–268. [Google Scholar] [CrossRef] [Scilit]
- Prest, T.; Fouque, P.; Hoffstein, J.; Kirchner, P.; Lyubashevsky, V.; Pornin, T.; Ricosset, T.; Seiler, G.; Whyte, W.; Zhang, Z. Falcon. Available online: https://csrc.nist.gov/Projects/post-quantum-cryptography/post-quantum-cryptography-standardization/selected-algorithms (accessed on 11 December 2025).
- Gentry, C.; Peikert, C.; Vaikuntanathan, V. Trapdoors for hard lattices and new cryptographic constructions. In Proceedings of the Fortieth Annual ACM Symposium on Theory of Computing–STOC 08, Victoria, BC, Canada, 17–20 May 2008; pp. 197–206. [Google Scholar]
- Yu, Y.; Jia, H.; Wang, X. Compact lattice gadget and its applications to hash-and-sign signatures. In Proceedings of the Advances in Cryptology–CRYPTO 2023, 43rd Annual International Cryptology Conference, Santa Barbara, CA, USA, 20–24 August 2023; pp. 390–420. [Google Scholar]
- Schnorr, C.P. Efficient identification and signatures for smart cards. In Proceedings of the Advances in Cryptology–CRYPTO 1989, Annual International Cryptology Conference, New York, NY, USA, 20–24 August 1989; Volume 435, pp. 239–252. [Google Scholar]
- Lyubashevsky, V. Fiat-Shamir with aborts: Applications to lattice and factoring-based signatures. In Proceedings of the Advances in Cryptology–ASIACRYPT 2009, 15th International Conference on the Theory and Application of Cryptology and Information Security, Tokyo, Japan, 6–10 December 2009; pp. 598–616. [Google Scholar]
- Lyubashevsky, V. Lattice signatures without trapdoors. In Proceedings of the Advances in Cryptology–EUROCRYPT 2012, 31st Annual International Conference on the Theory and Applications of Cryptographic Techniques, Cambridge, UK, 15–19 April 2012; pp. 738–755. [Google Scholar]
- Bambury, H.; Beguinet, H.; Ricosset, T.; Sageloli, É. Polytopes in the Fiat-Shamir with aborts paradigm. In Proceedings of the Advances in Cryptology–CRYPTO 2024, 44th Annual International Cryptology Conference, Santa Barbara, CA, USA, 18–22 August 2024; pp. 339–372. [Google Scholar]
- Cheon, J.H.; Choe, H.; Devevey, J.; Guüneysu, T.; Hong, D.; Krausz, M.; Land, G.; Möller, M.; Stehlé, D.; Yi, M. Haetae: Shorter lattice-based fiat-shamir signatures. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2024, 7, 25–75. [Google Scholar] [CrossRef] [Scilit]
- Ducas, L.; Durmus, A.; Lepoint, T.; Lyubashevsky, V. Lattice signatures and bimodal Gaussians. In Proceedings of the Advances in Cryptology–CRYPTO 2013, 33rd Annual Cryptology Conference, Santa Barbara, CA, USA, 18–22 August 2013; pp. 40–56. [Google Scholar]
- Bai, S.; Galbraith, S.D. An improved compression technique for signatures based on learning with errors. In Proceedings of the Topics in Cryptology–CT-RSA 2014, The Cryptographer’s Track at the RSA Conference, San Francisco, CA, USA, 25–28 February 2014; pp. 28–47. [Google Scholar]
- Espitau, T.; Fouque, P.; Gérard, B.; Tibouchi, M. Side-channel attacks on BLISS lattice-based signatures: Exploiting branch tracing against strongswan and electromagnetic emanations in microcontrollers. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security–CCS 17, Dallas, TX, USA, 30 October–3 November 2017; pp. 1857–1874. [Google Scholar]
- Bootle, J.; Delaplace, C.; Espitau, T.; Fouque, P.; Tibouchi, M. LWE without modular reduction and improved side-channel attacks against BLISS. In Proceedings of the Advances in Cryptography–ASIACRYPT 2018, 24th International Conference on the Theory and Application of Cryptology and Information Security, Brisbane, QLD, Australia, 2–6 December 2018; pp. 494–524. [Google Scholar]
- Pessl, P. Analyzing the shuffling side-channel countermeasure for lattice-based signatures. In Proceedings of the Progress in Cryptology–INDOCRYPT 2016, 17th International Conference on Cryptology in India, Kolkata, India, 11–14 December 2016; pp. 153–170. [Google Scholar]
- Micciancio, D.; Walter, M. Gaussian sampling over the integers: Efficient, generic, constant-time. In Proceedings of the Advances in Cryptography–CRYPTO 2017, 37th Annual International Cryptology Conference, Santa Barbara, CA, USA, 20–24 August 2017; pp. 455–485. [Google Scholar]
- Guüneysu, T.; Lyubashevsky, V.; Pöppelmann, T. Practical lattice-based cryptography: A signature scheme for embedded systems. In Proceedings of the International Conference on Cryptographic Hardware and Embedded Systems–CHES 2012, Leuven, Belgium, 9–12 September 2012; pp. 530–547. [Google Scholar]
- Alkim, E.; Bindel, N.; Buchmann, J.; Dagdelen, Ö.; Eaton, E.; Gutoski, G.; Krämer, J.; Pawlega, F. Revisiting TESLA in the quantum random oracle model. In Proceedings of the 8th International Conference on Post-Quantum Cryptography–PQCrypto 2017, Utrecht, The Netherlands, 26–28 June 2017; pp. 143–162. [Google Scholar]
- Zhang, J.; Yu, Y.; Fan, S.; Zhang, Z.; Yang, K. Tweaking the asymmetry of asymmetric-key cryptography on lattices: KEMs and signatures of smaller sizes. In Proceedings of the 23rd IACR International Conference on Practice and Theory of Public-Key Cryptography, Edinburgh, UK, 4–7 May 2020; pp. 37–65. [Google Scholar]
- Liu, Y.; Zhou, Y.; Sun, S.; Wang, T.; Zhang, R.; Ming, J. On the security of lattice-based Fiat-Shamir signatures in the presence of randomness leakage. IEEE Trans. Inf. Forensics Secur. 2021, 16, 1868–1879. [Google Scholar] [CrossRef] [Scilit]
- Gong, B.; Cheng, L.; Zhao, Y. SKCN: Practical and flexible digital signature from module lattice. In Proceedings of the 25th Australasian Conference on Information Security and Privacy, Perth, WA, Australia, 30 November–2 December 2020; pp. 62–81. [Google Scholar]
- Zhang, P.; Yang, H.; Zhu, L.; Zhang, Y.; Wang, H.; Xu, Q. A new lattice-based online/offline signatures framework for low-power devices. Theor. Comput. Sci. 2023, 962, 113942. [Google Scholar] [CrossRef] [Scilit]
- Alkim, E.; Ducas, L.; Pöppelmann, T.; Schwabe, P. Post-quantum key exchange-a new hope. In Proceedings of the 25th USENIX Security Symposium, Vancouver, BC, Canada, 10–12 August 2016; pp. 327–343. [Google Scholar]
- Micciancio, D.; Peikert, C. Hardness of SIS and LWE with small parameters. In Proceedings of the Advances in Cryptography–CRYPTO 2013, 33rd Annual Cryptology Conference, Santa Barbara, CA, USA, 18–22 August 2013; pp. 21–39. [Google Scholar]
- Lesigne, E. Heads or Tails: An Introduction to Limit Theorems in Probability; American Mathematical Society Press: Providence, RI, USA, 2005. [Google Scholar]
- Albrecht, M.R. Lattice-Estimator. v2025, GitHub. 2025. Available online: https://github.com/malb/lattice-estimator (accessed on 30 July 2026).
- Albrecht, M.R.; Player, R.; Scott, S. On the concrete hardness of Learning with Errors. J. Math. Cryptol. 2015, 9, 169–203. [Google Scholar] [CrossRef] [Scilit]
- Das, D.; Hoffstein, J.; Pipher, J.; Whyte, W.; Zhang, Z. Modular lattice signatures, revisited. Des. Codes Cryptogr. 2020, 88, 505–532. [Google Scholar] [CrossRef] [Scilit]
- Bos, J.W.; Costello, C.; Naehrig, M.; Stebila, D. Post-quantum key exchange for the TLS protocol from the ring learning with errors problem. In Proceedings of the IEEE Symposium on Security and Privacy, San Jose, CA, USA, 17–21 May 2015; pp. 553–570. [Google Scholar]
- Barbosa, M.; Barthe, G.; Doczkal, C.; Don, J.; Fehr, S.; Grégoire, B.; Huang, Y.; Hülsing, A.; Lee, Y.; Wu, X. Fixing and mechanizing the security proof of Fiat-Shamir with aborts and Dilithium. In Proceedings of the Advances in Cryptology–CRYPTO 2023, 43rd Annual International Cryptology Conference, Santa Barbara, CA, USA, 20–24 August 2023; pp. 358–389. [Google Scholar]
- Devevey, J.; Fawzi, O.; Passele‘gue, A.; Stehlé, D. On rejection sampling in Lyubashevsky’s signature scheme. In Proceedings of the Advances in Cryptology-ASIACRYPT 2022, 28th International Conference on the Theory and Application of Cryptology and Information Security, Taipei, Taiwan, 5–9 December 2022; pp. 34–64. [Google Scholar]
- Devevey, J.; Fallahpour, P.; Passelègue, A.; Stehlé, D. A detailed analysis of Fiat-Shamir with aborts. In Proceedings of the Advances in Cryptology–CRYPTO 2023, 43rd Annual International Cryptology Conference, Santa Barbara, CA, USA, 20–24 August 2023; pp. 327–357. [Google Scholar]
- Bellare, M.; Neven, G. Multi-signatures in the plain public-key model and a general forking lemma. In Proceedings of the 13th ACM Conference on Computer and Communications Security, Alexandria, VA, USA, 30 October–3 November 2006; pp. 390–399. [Google Scholar]
- Lyubashevsky, V. Digital signatures based on the hardness of ideal lattice problems in all rings. In Proceedings of the Advances in Cryptology–ASIACRYPT, 22th International Conference on the Theory and Application of Cryptology and Information Security, Hanoi, Vietnam, 4–8 December 2016; pp. 196–214. [Google Scholar]
- del Pino, R.; Lyubashevsky, V.; Seiler, G. Lattice-based group signatures and zero-knowledge proofs of automorphism stability. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, ON, Canada, 15–19 October 2018; pp. 574–591. [Google Scholar]
- Gao, W.; Jin, S.; Fu, T.; Ren, S.; Dong, X.; Qin, B.; Wang, B. Logarithmic certificate-less linkable ring signature over lattices and application in electronic voting systems. Comput. Stand. Interfaces 2026, 96, 104081. [Google Scholar] [CrossRef] [Scilit]

| The Approach | The Sampling | High-Precision |
|---|---|---|
| GRS (BLISS) | Gaussian | Yes |
| URS (ML-DSA) | Uniform | No |
| CRS (this work) | Semi-uniform | Yes |
| Notations | Meaning |
|---|---|
| The integer set | |
| Module q residue class ring for a prime number q | |
| Polynomial ring | |
| Transpose vector of the vector | |
| The -norm | |
| The -norm | |
| The -norm | |
| Centered binomial sampling centered at 0 | |
| Centered binomial sampling centered at v, shifting by the value v | |
| The n-dimension vector set | |
| For a finite set , s is sampled uniformly from | |
| For a probability distribution , d is sampled according to |
| Name | Definition | I | II |
|---|---|---|---|
| Target security level | - | 128-bit | 128-bit |
| Optimized for | - | Signature size | Repetitions |
| n | Power of two | 512 | 512 |
| q | Security reduction | 12,289 | 12,289 |
| m | 1024 | 1024 | |
| d | 1 | 1 | |
| 60 | 60 | ||
| 8.2 | 10 | ||
| l | 16 | 16 | |
| M | 7 | 4.9 | |
| Expected repetitions | 7 | 4.9 | |
| Public key size | 896 | 896 | |
| Secret key size | 256 | 256 | |
| Signature size | 1486 | 1536 | |
| Signing time (ms) | - | 14.87 | 12.34 |
| Parameters Set | Theoretical Acceptance Rate | Actual Acceptance Rate | Standard Deviation |
|---|---|---|---|
| I | |||
| II |
| Parameter I | Parameter I | |
|---|---|---|
| BKZ block size for primal attack | 348 | 349 |
| BKZ block size for dual attack | 355 | 357 |
| Classical cost against primal attack | ||
| Classical cost against dual attack | ||
| Quantum cost against primal attack | ||
| Quantum cost against dual attack |
| Scheme | Distribution | Repetitions | Acceptance Rate | Public Key Size | Signature Size |
|---|---|---|---|---|---|
| ML-DSA [1] | Uniform | 6.6 | 1300 | 2400 | |
| BLISS [11] | Gaussian | 2.18 | 875 | 625 | |
| Patronus [9] | Uniform in polytope | 3 | 832 | 2070 | |
| HAETAE [10] | Uniform in hyperball | 6 | 992 | 1474 | |
| Our scheme | Centered binomial | 4.9 | 896 | 1536 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Zhang, P.; Wang, L. A New Lattice-Based Post-Quantum Digital Signature from Compact Rejection Sampling. Computers 2026, 15, 541. https://doi.org/10.3390/computers15080541
Zhang P, Wang L. A New Lattice-Based Post-Quantum Digital Signature from Compact Rejection Sampling. Computers. 2026; 15(8):541. https://doi.org/10.3390/computers15080541
Chicago/Turabian StyleZhang, Pingyuan, and Limin Wang. 2026. "A New Lattice-Based Post-Quantum Digital Signature from Compact Rejection Sampling" Computers 15, no. 8: 541. https://doi.org/10.3390/computers15080541
APA StyleZhang, P., & Wang, L. (2026). A New Lattice-Based Post-Quantum Digital Signature from Compact Rejection Sampling. Computers, 15(8), 541. https://doi.org/10.3390/computers15080541
