[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84014-en":3,"doc-seo-84014-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84014,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Withdrawability in Fiat–Shamir with aborts constructions","This paper extends withdrawable signatures from the Liu, Baek and Susilo (LBS23) line of work to the Fiat–Shamir with aborts paradigm. It introduces an abstract construction and provides security proofs for the proposal. It then instantiates the result with a concrete withdrawable signature scheme derived from a no-hint, full-t Dilithium-style Fiat–Shamir-with-aborts construction. Adapting the design to production ML-DSA with hints introduces a small εzk term.","arXiv :2607 .0583 1v 1 [ cs .CR] 7 Jul 2026  \nWithdrawability in Fiat–Shamir with aborts  \nconstructions  \nRamses Fernandez   \nFairgate Labs  \nAbstract. This article presents an extension of the work performed by Liu, Baek and Susilo [LBS23] on withdrawable signatures to the Fiat–Shamir with aborts paradigm.  \nWe introduce an abstract construction, and provide security proofs for this proposal.  \nAs an instantiation, we provide a concrete withdrawable signature scheme based on a no-hint, full-t Dilithium-style Fiat–Shamir-with-aborts construction [DLL+ 18];  \nadapting to production ML-DSA (with hints) introduces a small εzk term.  \nKeywords: Withdrawability · Digital signatures · Module Learning with Errors  \n1 Introduction  \nDigital signatures serve as a fundamental cryptographic mechanism that enables entities to bind their identities to pieces of information. The essential purpose of a digital signature is to allow a signer, who has established a public key pk, to sign messages using their private key sk in a way that enables anyone knowing pk to verify both the message’s origin and its integrity during transit.  \nAn important paradigm for the creation of digital signatures is the Fiat–Shamir transform, which converts interactive identification protocols into non-interactive digital signature schemes. Starting with a three-move identification protocol, where a prover demonstrates knowledge to a verifier through commitment, challenge, and response steps, the transform replaces the verifier’s random challenge with a hash function applied to both the commitment and the message. This creates a digital signature scheme where the signing algorithm computes a commitment, generates a challenge by hashing the commitment with the message, and produces a response using the secret key.  \nThe Schnorr signature scheme is perhaps the most well-known application of the Fiat– Shamir transform, which has gained particular attention due to its security characteristics and its valuable properties, such as signature aggregation. These advantages make Schnorr signatures especially attractive for blockchain applications where transaction size reduction and privacy enhancement are crucial considerations.  \nThe impact of digital signatures is particularly important in blockchain technology, where this primitive extends beyond basic transaction authentication, enabling sophisticated smart contract interactions, multi-signature schemes for enhanced security, and threshold signature systems for distributed key management. Furthermore, innovations in signature aggregation and batch verification techniques have contributed significantly to blockchainscalability solutions.  \nE-mail: [ramses.fernandez@fairgate.io](ramses.fernandez@fairgate.io) (Ramses Fernandez)  \nCurrent public-key cryptographic algorithms serve as the foundation for protecting sensitive electronic information from unauthorized access. These algorithms have successfully withstood attacks from conventional computing systems for decades, due to the hardness of their underlying mathematical problems, prime factorization and the computation of discrete logarithms. However, the emergence of quantum computing presents a significant challenge to this security paradigm, as Shor’s algorithm demonstrates the potential to solve both the prime factorization and the computation of discrete logarithms efficiently. This means that quantum computers possess computational capabilities that could potentially compromise current cryptographic methods, exposing vulnerable data and information.  \nTo address this impending challenge, new cryptographic approaches are being designed to withstand attacks from both traditional computers and future quantum systems. These methods rely on problems, such as lattices, error-correcting codes or isogenies of elliptic curves, which have enhanced mathematical structure, leading to computational problems assumed to be hard both for classical and quantum computers. This fram","cbCaigMTjCAVz9HO","https://ap.wps.com/l/cbCaigMTjCAVz9HO","pdf",702146,2,1,24,"English","en",105,"# Abstract\n# Introduction\n## Digital signatures and Fiat–Shamir transform\n## Post-quantum cryptography context\n## Fiat–Shamir with aborts and lattice-based constructions\n## Dilithium and HAETAE overview","[{\"question\":\"What problem does the paper address regarding withdrawable signatures?\",\"answer\":\"The paper extends existing withdrawable-signature work to the Fiat–Shamir with aborts paradigm, enabling a new construction with formal security arguments.\"},{\"question\":\"How does the Fiat–Shamir with aborts paradigm generate signatures non-interactively?\",\"answer\":\"It replaces the verifier’s challenge with a hash function (random-oracle treatment) and uses controlled rejection sampling where the signing algorithm aborts and restarts if a potential signature would leak information about the secret key.\"},{\"question\":\"What schemes are used as instantiations or references for the construction?\",\"answer\":\"The paper instantiates the approach using a no-hint, full-t Dilithium-style Fiat–Shamir-with-aborts construction, and discusses adapting to production ML-DSA with hints, which adds a small εzk term.\"}]",1784192017,60,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"withdrawability-in-fiatshamir-with-aborts-constructions","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/withdrawability-in-fiatshamir-with-aborts-constructions/84014/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the paper address regarding withdrawable signatures?","Question",{"text":75,"@type":76},"The paper extends existing withdrawable-signature work to the Fiat–Shamir with aborts paradigm, enabling a new construction with formal security arguments.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the Fiat–Shamir with aborts paradigm generate signatures non-interactively?",{"text":80,"@type":76},"It replaces the verifier’s challenge with a hash function (random-oracle treatment) and uses controlled rejection sampling where the signing algorithm aborts and restarts if a potential signature would leak information about the secret key.",{"name":82,"@type":73,"acceptedAnswer":83},"What schemes are used as instantiations or references for the construction?",{"text":84,"@type":76},"The paper instantiates the approach using a no-hint, full-t Dilithium-style Fiat–Shamir-with-aborts construction, and discusses adapting to production ML-DSA with hints, which adds a small εzk term.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,109,114,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":29,"slug":108},5,"Comic","comic",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]