Analysis of NTRUSign signature scheme

  • Sungjun Min (Information and Communications University (ICU)) ;
  • Go Yamamoto (NTT, Information Sharing Platform Laboratories) ;
  • Kim, Kwangjo (Information and Communications University (ICU))
  • Published : 2003.12.01

Abstract

A new type of signature scheme, called NTRUSign, based on solving the approximately closest vector problem in an NTRU lattice was proposed in[7],[8]. However no security proof against chosen messages attack has been made for this scheme. In this paper, we show that NTRUSign signature scheme contains the weakness of malleability. From this, one can derive new valid signatures from any previous message-signature pair which means that NTRUSign is not secure against strongly existential forgery.

Keywords