2
organizing roles
3
collaborators
2019–2022
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
5 Talks
| Title | Conference | Type | Co-authors |
|---|---|---|---|
| Online-Extractability in the Quantum Random-Oracle Model | QCRYPT 2022 | regular | Serge Fehr, Christian Majenz, Christian Schaffner |
| Online-Extractability in the Quantum Random-Oracle Model | QIP 2022 | regular | Serge Fehr, ▸Christian Majenz, Christian Schaffner |
| The Measure-and-Reprogram Technique 2.0: Multi-Round Fiat-Shamir and More | QCRYPT 2020 | regular | Serge Fehr, Christian Majenz |
We revisit recent works by Don, Fehr, Majenz and Schaffner and by Liu and Zhandry on the security of the Fiat-Shamir transformation of sigma-protocols in the quantum random oracle model (QROM). Two natural questions that arise in this context are: (1) whether the results extend to the Fiat-Shamir transformation of *multi-round* interactive proofs, and (2) whether Don et al.'s O(q^2) loss in security is optimal. Firstly, we answer question (1) in the affirmative. As a byproduct of solving a technical difficulty in proving this result, we slightly improve the result of Don et al., equipping it with a cleaner bound and an even simpler proof. We apply our result to digital signature schemes showing that it can be used to prove strong security for schemes like MQDSS in the QROM. As another application we prove QROM-security of a non-interactive OR proof by Liu, Wei and Wong. As for question (2), we show via a Grover-search based attack that Don et al.'s quadratic security loss for the Fiat-Shamir transformation of sigma-protocols is optimal up to a small constant factor. This extends to our new multi-round result, proving it tight up to a factor that depends on the number of rounds only, i.e. is constant for any constant-round interactive proof. |
|||
| Security of the Fiat-Shamir Transformation in the Quantum Random-Oracle Model | QIP 2020 | regular | Serge Fehr, Christian Majenz, Christian Schaffner |
| Security of the Fiat-Shamir transformation in the quantum random-oracle model | QCRYPT 2019 | regular | Serge Fehr, Christian Majenz, Christian Schaffner |
The famous Fiat-Shamir transformation turns any public-coin three-round interactive proof, i.e., any so-called sigma-protocol, into a non-interactive proof in the random-oracle model. We study this transformation in the setting of a quantum adversary that in particular may query the random oracle in quantum superposition. Our main result is a generic reduction that transforms any quantum dishonest prover attacking the Fiat-Shamir transformation in the quantum random-oracle model into a similarly successful quantum dishonest prover attacking the underlying sigma-protocol (in the standard model). Applied to the standard soundness and proof-of-knowledge definitions, our reduction implies that both these security properties, in both the computational and the statistical variant, are preserved under the Fiat-Shamir transformation even when allowing quantum attacks. Our result improves and completes the partial results that have been known so far, but it also proves wrong certain claims made in the literature. In the context of post-quantum secure signature schemes, our results imply that for any sigma-protocol that is a proof-of-knowledge against quantum dishonest provers (and that satisfies some additional natural properties), the corresponding Fiat-Shamir signature scheme is secure in the quantum random-oracle model. For example, we can conclude that the non-optimized version of Fish, which is the bare Fiat-Shamir variant of the NIST candidate Picnic, is secure in the quantum random-oracle model. |
|||
1 Poster
| Title | Conference | Co-authors |
|---|---|---|
| Efficient NIZKs and Signatures from Commit-and-Open Protocols in the QROM | QCRYPT 2022 | Serge Fehr, Christian Majenz, Christian Schaffner |
Committee service
| Conference | Committee | Position | Title |
|---|---|---|---|
| QCRYPT 2021 | organizing | member | — |
| QCRYPT 2020 | organizing | member | — |
Collaborators
| Co-author | Joint talks |
|---|---|
| Christian Majenz | 6 |
| Serge Fehr | 6 |
| Christian Schaffner | 5 |