Generalized Quantum-assisted Digital Signature
Alberto Tarable, Rudi Paolo Paganelli, Elisabetta Storelli, Alberto Gatto, Marco Ferrari
TL;DR
This work addresses the challenge of IT-secure digital signatures by leveraging QKD-derived keys to support a quantum-assisted framework. It generalizes prior QaDS to GQaDS, introduces Carter-Wegman MACs to drastically shorten signatures, and develops a semi-analytical optimization of protocol parameters that balance forgery and repudiation risks, including a deterministic variant when a second verifier is trusted. The authors derive nuanced, regime-dependent expressions for repudiation and forging probabilities and show how to tune parameters (such as the fraction of shared key blocks and thresholds) to meet stringent security targets (e.g., $P_R<10^{-24}$ and $P_F<10^{-40}$) with realistic key lengths. The Carter-Wegman MAC implementation reduces signature length while preserving IT security, and the deterministic GQaDS variant further lowers requirements by enabling parallel verification and arbitration. Overall, GQaDS offers a practically realizable, QKD-backed digital signature paradigm with scalable security guarantees and flexible deployment options including a highly compact deterministic mode.
Abstract
This paper introduces Generalized Quantum-assisted Digital Signature (GQaDS), an improved version of a recently proposed scheme whose information theoretic security is inherited by adopting QKD keys for digital signature purposes. Its security against forging is computed considering a trial-and-error approach taken by the malicious forger and GQaDS parameters are optimized via an analytical approach balancing between forgery and repudiation probabilities. The hash functions of the previous implementation are replaced with Carter-Wegman Message Authentication Codes (MACs), strengthening the scheme security and reducing the signature length. For particular scenarios where the second verifier has a safe reputation, a simplified version of GQaDS, namely deterministic GQaDS, can further reduce the required signature length, keeping the desired security strength.
