Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Computer Science editorial

Open AccessOA2026

Prefix Puncturable Signatures with Smaller Signing Key from HIBS

A generic construction from hierarchical identity-based signatures achieving O(lQ^{Punc}) punctured signing key size
Masayuki Tezuka; Keisuke Tanakaยท 2026ยท DOI 10.48550/arXiv.2609.24503

The core problem

Puncturable signatures, introduced by Bellare et al. at EUROCRYPT 2016, allow a signing key to be punctured (updated) so that it loses the ability to sign particular messages while retaining the ability to sign all others. Halevi et al. (ASIACRYPT 2017) introduced prefix puncturable signatures, in which the signing key can be punctured with respect to a target prefix so that it cannot sign messages whose prefixes match the target prefix.

Several generic constructions of prefix puncturable signature schemes have been proposed, including constructions based on identity-based signatures (IBS) (ESORICS 2022) and delegated constrained signatures (IEEE Trans. Inf. Forensics Secure. 2024). However, these constructions suffer from drawbacks in terms of key size. When the prefix space is the set of all -bit strings, the former construction requires a signing key consisting of IBS signing keys. The latter construction, when instantiated with a lattice-based delegated constrained signature scheme, yields a punctured signing key whose size grows quadratically with the number of puncturing operations .

This paper addresses the key-size problem by presenting a gener

Innovation

The main result is a generic construction of prefix puncturable signatures from HIBS with significantly reduced signing key size. Specifically, for prefix space , the punctured signing key size is bounded by , where is the number of puncturing operations.

This improves upon prior constructions:

- The IBS-based construction (ESORICS 2022) requires a signing key of size IBS signing keys, which is exponential in the prefix length.
- The delegated constrained signature construction (IEEE Trans. Inf. Forensics Secure. 2024), when instantiated with a lattice-based scheme, yields a punctured signing key whose size grows quadratically with , i.e., .

In contrast, the proposed HIBS-based construction achieves linear growth in both and . When instantiated with HIBS, the scheme remains secure under standard lattice assumptions and is post-quantum secure.

The paper provides a formal security proof showing that the constructed prefix puncturable signature scheme is existentially unforgeable under chosen-message attacks (EUF-CMA) if the underlying HIBS schem

Puncturable signatures, introduced by Bellare et al. at EUROCRYPT 2016, allow a signing key to be punctured (updated) so that it loses the ability to sign particular messages while retaining the ability to sign all others. Halevi et al. (ASIACRYPT 2017) introduced prefix puncturable signatures, in which the signing key can be punctured with respect to a target prefix so that it cannot sign messages whose prefixes match the target prefix.
Several generic constructions of prefix puncturable signature schemes have been proposed, including constructions based on identity-based signatures (IBS) (ESORICS 2022) and delegated constrained signatures (IEEE Trans. Inf. Forensics Secure. 2024). However, these constructions suffer from drawbacks in terms of key size. When the prefix space is the set of all -bit strings, the former construction requires a signing key consisting of IBS signing keys. The latter construction, when instantiated with a lattice-based delegated constrained signature scheme, yields a punctured signing key whose size grows quadratically with the number of puncturing operations .

Why it matters

The proposed construction offers a substantial improvement in key size for prefix puncturable signatures, making them more practical for deployment in resource-constrained environments. The use of HIBS as a building block is natural: the hierarchical structure of identities aligns well with prefix puncturing, as a prefix can be viewed as an identity at a certain level, and puncturing corresponds to deriving a key for that identity.

The key-size bound is optimal in the sense that each puncturing operation must at least add some information proportional to the prefix length to prevent signing under that prefix. The construction is generic and can be instantiated with any secure HIBS scheme, including post-quantum ones like HIBS.

A potential limitation is that the signing key grows linearly with the number of puncturing operations, which may be undesirable for applications requiring many punctures. However, this is inherent to the prefix puncturing model, and the linear growth is a significant improvement over quadratic or exponential growth.

Future work could explore further optimizations, such as aggregating punctured keys or using more efficient HIBS schemes. Additionally, the construction could be extended to support other puncturing policies, such as puncturing on arbitrary sets of messages.

Overall, this work provides a practical and efficient solution for prefix puncturable signatures, with strong security guarantees and post-quantum resistance when instantiated with lattice-based HIBS.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ