Member-only story
Casanova and A Post Quantum World
Well, we’ve all seen the signs that say “The Best Coffee Ever!”, but when it comes to a post-quantum world of digital signatures, a paper that promises the shortest signature ever just grabs your attention [here]:
It uses a multivariate method [here]. There are a number of multivariate methods including UOV [here] and Rainbow [here]. The shortest ever signature is used in the GeMSS (Great Multivariate Short Signature) method. It was created by Casanova et al uses the HFEv- method [here]:
We can see in Figure 1 that GeMSS has the smallest private key (16 bytes), and the smallest signature size (33 bytes) for 128-bit security. The downside is that large public key size, and which rivals the other multivariant method: Rainbow:
Unfortunately, GeMSS just needs too much memory, and failed to reach the final round of the NIST PCQ standard…