VOLE-in-the-Head and the�FAEST Post-Quantum Signature Scheme
Peter Scholl
ZKProof, 2 August 2023
Based on
Peter Scholl
2
Publicly Verifiable Zero-Knowledge and Post-Quantum Signatures From VOLE-in-the-Head
with Carsten Baum, Lennart Braun, Cyprien Delpech de Saint Guilhem, Michael Klooß,
Emmanuela Orsini, Lawrence Roy
CRYPTO 2023
FAEST Digital Signature Scheme
+ Christian Majenz, Shibam Mukherjee, Sebastian Ramacher, Christian Rechberger
Submission to NIST PQC Standardization process
Zero-knowledge proofs
Peter Scholl
3
Prover
Verifier
I believe you
Families of ZK Proofs
4
Proof size
Prover runtime
Groth16
STARKs
Ligero
MPC-in-the-head
VOLE-ZK
Succinct
Linear
VOLE-in-the-Head: a general tool for making VOLE-ZK proofs publicly verifiable
5
Simplicity
Speed
Application: FAEST
Post-quantum signature based on AES
Submitted to NIST PQC Standardization Call
VOLE-in-the-Head: a general tool for making VOLE-ZK proofs publicly verifiable
Application: FAEST post-quantum
signature scheme
6
Speed
Simplicity
Security
AES/SHA
Linear size
7
VOLE-ZK
in the designated verifier setting
Background: VOLE�(vector oblivious linear evaluation)
Peter Scholl
8
VOLE
Prover
Verifier
Can be instantiated with OT, HE, LPN…
ZK from VOLE (designated verifier)
Peter Scholl
9
[BMRS 21, WYKW 21]
ZK from VOLE via Commit-and-Prove
Peter Scholl
10
[BMRS 21, WYKW 21]
Multiplication gates in VOLE-ZK
Peter Scholl
11
[DIO 21, YSWW 21]
Cost analysis for VOLE-ZK
Peter Scholl
12
13
VOLE-in-the-Head
Adding public verifiability
MPC-in-the-Head vs VOLE-in-the-head:�high-level differences
Peter Scholl
14
challenge
MPC-in-the-Head vs VOLE-in-the-head:�high-level differences
Peter Scholl
15
VOLE
How to do VOLE-in-the-head?
Peter Scholl
16
All-but-one
vector commitment
Convert to VOLE
Run VOLE-ZK proof
How to do VOLE? Warm-up: using OT
Peter Scholl
17
How to do VOLE-in-the-head? Just commit!
Peter Scholl
18
Postpone until after VOLE-ZK proof
VOLE-in-the-head: some details
Peter Scholl
19
Needs consistency check
More details: consistency checking
Peter Scholl
20
Application to�Post-Quantum Signatures
Peter Scholl
21
Call for Additional Digital Signature Schemes
Paradigm for ZK-based signatures
Peter Scholl
22
AES: a ZK-friendly OWF?
Peter Scholl
23
Proving AES-128 in FAEST
Peter Scholl
24
S-Box
Proving the AES S-Box
Peter Scholl
25
S-Box
Peter Scholl
26
Mult. check
VOLE consistency check
Open VOLE outputs
S-Box
FAEST performance
Peter Scholl
27
| Sign (ms) | Verify (ms) | |sig| (bytes) |
FAEST-128s | 57.4 | 54.7 | 5 006 |
FAEST-128f | 10.6 | 8.7 | 6 336 |
FAEST-256s | 192.8 | 172.8 | 22 100 |
FAEST-256f | 53.3 | 38.6 | 28 400 |
FAEST: example performance
Peter Scholl
28
| Sign/Verify | Size |
FAEST-128s | | 5 006 B |
FAEST-128f | | 6 336 B |
FAEST-256s | | 22 100 B |
FAEST-256f | | 28 400 B |
Conclusion
VOLE-ZK proofs:
FAEST signature:
Resources:
Paper: https://ia.cr/2023/996
PQ signature: https://faest.info
Peter Scholl
29
Thank you!