Digital Signatures Using Error Polynomials for Quantum Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital signature schemes may become insecure with the advent of higher capacity computing, such as quantum computing, and are often inefficient in practice, lacking robustness against forgery attempts.

Innovation Solution

The use of digital signatures that incorporate error polynomials for generating verification keys, where coefficients are limited and computed using randomization techniques, providing a signing key to produce message signatures and a verification key to authenticate messages, leveraging the hardness of the learning with errors problem to secure the verification process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing digital signature schemes are used, then implementation is straightforward, but security becomes vulnerable to quantum computing and higher capacity computing

Engineering Contradiction:
ImprovesecurityVSAvoidresistance to quantum computing
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the mathematical parameters and structure of digital signature schemes by incorporating error polynomials and lattice-based cryptography. This transforms traditional signature schemes into quantum-resistant variants by fundamentally altering the underlying mathematical problems from discrete logarithm-based to lattice-based hardness assumptions, thereby improving security against quantum computing while maintaining functional versatility

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent combines multiple cryptographic elements (error polynomials, lattice structures, and traditional signature components) into a composite cryptographic system. This hybrid approach integrates the hardness of lattice problems with polynomial error terms to create a multi-layered security structure that resists both classical and quantum attacks while preserving digital signature functionality

Inventive Principle:
Principle #40Composite materials

2Reliability

If traditional digital signature schemes are used, then computational efficiency is acceptable, but robustness against forgery attempts is insufficient

Engineering Contradiction:
Improverobustness against forgeryVSAvoidcomplexity of verification key generation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-generating verification keys with embedded error polynomials and lattice structures before actual signing operations. This advance preparation ensures that the cryptographic structure is already optimized for forgery resistance, allowing verification processes to rely on pre-established hardness assumptions rather than computing them in real-time, thus balancing robustness with manageable complexity

Inventive Principle:
Principle #10Preliminary action

3Power

If quantum computing becomes feasible, then computing power increases, but existing digital signature schemes become insecure

Engineering Contradiction:
Improvecomputing powerVSAvoidsecurity
Core Design Contradiction:
PowerVSReliability

Solution Approach 1:

The patent converts the potential harm of quantum computing into a benefit by designing signature schemes based on lattice problems that are believed to be hard for both classical and quantum computers. Instead of trying to prevent quantum computing, the invention embraces it by selecting mathematical problems whose hardness is preserved even against quantum algorithms, effectively turning the quantum threat into an opportunity for more robust cryptography

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS8677135B2Digital signatures with error polynomials
Publication Date: 2014.03.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8677135B2 patent drawing
  • US8677135B2 patent drawing
  • US8677135B2 patent drawing

AI summary

Representations of polynomials a, s, t, e—1 and e—2 can be provided. Values of coefficients of the polynomials can be limited, and can be computed using randomization techniques. A verification key can be generated to include representations of polynomials a, b, and c. Computation of b can include computing a product using a and s, and adding e—1. Computation of c can include computing a product using a and t, and adding e—2. A signing key can represent s and t. The signing key can be used to produce a message signature that can represent a sum of t and a product of s and m, with m being derived from a message to be signed. The verification key can be used to verify the signature by checking coefficient sizes of a polynomial represented by the signature, and of a checking polynomial derived from the verification key and the signature.