Beijing Institute of Mathematical Sciences and Applications Beijing Institute of Mathematical Sciences and Applications

  • About
    • President
    • Governance
    • Partner Institutions
    • Visit
  • People
    • Management
    • Faculty
    • Postdocs
    • Visiting Scholars
    • Administration
    • Academic Support
  • Research
    • Research Groups
    • Courses
    • Seminars
    • Journals
  • Join Us
    • Faculty
    • Postdocs
    • Students
  • Events
    • Conferences
    • Workshops
    • Forum
  • Life @ BIMSA
    • Accommodation
    • Transportation
    • Facilities
    • Tour
  • News
    • News
    • Announcement
    • Downloads
About
President
Governance
Partner Institutions
Visit
People
Management
Faculty
Postdocs
Visiting Scholars
Administration
Academic Support
Research
Research Groups
Courses
Seminars
Journals
Join Us
Faculty
Postdocs
Students
Events
Conferences
Workshops
Forum
Life @ BIMSA
Accommodation
Transportation
Facilities
Tour
News
News
Announcement
Downloads
Qiuzhen College, Tsinghua University
Yau Mathematical Sciences Center, Tsinghua University (YMSC)
Tsinghua Sanya International  Mathematics Forum (TSIMF)
Shanghai Institute for Mathematics and  Interdisciplinary Sciences (SIMIS)
Hetao Institute of Mathematics and Interdisciplinary Sciences
BIMSA > Cryptography and Its Applications Cryptography and Its Applications A Compact Rank-Metric Signature Scheme from Double-Circulant LRPC Codes
A Compact Rank-Metric Signature Scheme from Double-Circulant LRPC Codes
Organizer
Yingjie Zhang
Speaker
Babindamana Régis Freguin
Time
Wednesday, September 23, 2026 2:00 PM - 3:00 PM
Venue
A7-301
Online
Zoom 442 374 5045 (BIMSA)
Abstract
Stern-Véron identification protocols give code-based signatures with small keys, provided the public generator matrix is random, which is what makes it costly to store. In this work, we show that the systematic generator matrix of a double-circulant LRPC code works just as well and costs a single circulant row. Combined with the rank-metric Véron protocol and the Fiat-Shamir transform, this gives a signature whose public key is that row plus one noisy codeword. The protocol never decodes, so the low-rank trapdoor stays hidden and security reduces to rank syndrome decoding for ideal codes, the assumption behind ROLLO and Durandal. We prove completeness, soundness and zero-knowledge, give size formulas, a worked example over $\mathbb{F}_{2^5}$ and a comparison with Wave, Durandal and rank-metric CVE.
Beijing Institute of Mathematical Sciences and Applications
CONTACT

No. 544, Hefangkou Village Huaibei Town, Huairou District Beijing 101408

北京市怀柔区 河防口村544号
北京雁栖湖应用数学研究院 101408

Tel. 010-60661855 Tel. 010-60661855
Email. administration@bimsa.cn

Copyright © Beijing Institute of Mathematical Sciences and Applications

京ICP备2022029550号-1

京公网安备11011602001060 京公网安备11011602001060