Signcryption from NTRU Lattices Without Random Oracles
Ziyuan Liu, Raylin Tso, Yi‐Fan Tseng, Masahiro Mambo · 2019
A signcryption scheme provides both the function of digital signature and encryption scheme at the same time. Additionally, it has lower cost than traditional sign-then-encrypt or encrypt-then-sign approaches. Many useful applications have been found where confidentiality and non-repudiation are both required. On the other hand, with the current development of rapid quantum computing, currently schemes based on traditional numerical assumptions (e.g., decisional Diffie-Hellman assumption) are more likely to be attacked by quantum computers. Therefore, lattice-based signcryption schemes have been extensively studied in recent years. However, most of them are either inefficient or secure-proved under the assumptions of random oracles. Although some of them are proved in the standard model, they are not practical in low-cost devices. Since the security is based on "Learning with Errors" (LWE) or "Short Integer Solution" problems, it will result in extremely large size of keys. In this paper, we propose an efficient NTRU-based signcryption scheme, which is inspired from Pion et al.'s key encapsulation mechanism. We provide rigorous security proofs for the confidentiality and unforgeability under NTRU-based assumptions in the standard model. Compared with other schemes, we conclude that our scheme is more efficient and secure.