Tight Reductions

Security reductions whose loss is a constant rather than growing with the adversary’s resources.

Status Statement Tags
1+1 adaptively secure lattice threshold signature
Resolved. Oriole (Jiang, Wee, Zhu, ePrint 2026/793, posted April 2026, a month after Tweed) gives a lattice-based threshold signature with exactly this shape – two rounds, only the second message-dependent, adaptive security against T-1 corruptions with no erasures, from MSIS and MLWE in the ROM – verified here directly against the paper’s PDF (Definition of adp-TS-sUF-4 in its Figure 4, and the Theorem 2 + Theorem 3 reduction chain to MSIS), not just its abstract. The proof is human-written and published, but not yet independently re-verified line-by-line by this site, nor formalized in Lean.
Learning With ErrorsThreshold SignaturesTight Reductionsromseparationresearch-solved
Three moves from DL, ROM only
Open: three moves, black-box in the group, ROM only, from DL alone. Three moves is achieved from DDH in the ROM and from DL in AGM+ROM; four moves is achieved from DL in the ROM. 5 open
Blind SignaturesRandom Oracle ModelSignature SchemesTight Reductionsromassumption
Single-session lattice Chevallier-Mames tightness
Open: whether the one-session lattice translation of the Chevallier-Mames signature has a tight SUF-CMA reduction to search Module-LWE, or whether the paper’s two-fold parallel repetition (which doubles signature size and signing time) is inherent to a tight proof of this shape. 4 open
Learning With ErrorsSignature SchemesTight Reductionsromtight-bound
No matching items