[Resource Topic] 2024/710: BUFFing FALCON without Increasing the Signature Size

2024/710

BUFFing FALCON without Increasing the Signature Size

Authors: Samed Düzlü, Rune Fiedler, Marc Fischlin


This work shows how FALCON can achieve the Beyond UnForgeability Features (BUFF) introduced by Cremers et al. (S&P’21) more efficiently than by applying the generic BUFF transform. Specifically, we show that applying a transform of Pornin and Stern (ACNS’05), dubbed PS-3 transform, already suffices for FALCON to achieve BUFF security. For FALCON, this merely means to include the public key in the hashing step in signature generation and verification, instead of hashing only the nonce and the message; the other signature computation steps and the signature output remain untouched. In comparison to the BUFF transform, which appends a hash value to the final signature, the PS-3 transform therefore achieves shorter signature sizes, without incurring additional computations.

ePrint: https://eprint.iacr.org/2024/710

