作者: Marc Fischlin , Tommaso Gagliardoni , Özgür Dagdelen
DOI:
关键词:
摘要: The Fiat-Shamir transformation is a famous technique to turn identification schemes into signature schemes. derived scheme provably secure in the random-oracle model against classical adversaries. Still, has also been suggested be used connection with quantum-immune schemes, order get However, recent paper by Boneh et al. (Asiacrypt 2011) raised issue that results may not immediately applicable quantum adversaries, because such adversaries should allowed query random oracle superposition. It unclear if still this (QROM). Here, we discuss giving proofs for QROM presumably hard. We show there cannot black-box extractors, as long underlying active and first message of prover independent its witness. Most are type. then some one able resurrect result modifying protocol first. particular version Lyubashevsky which QROM.