Paper 2026/397

Bittersweet Signatures: Bringing LWR to a Picnic for Hardware-Friendly MPC-in-the-Head

Brieuc Balon, Université catholique de Louvain
Gianluca Brian, Technische Universität Darmstadt
Sebastian Faust, Technische Universität Darmstadt
Carmit Hazay, Bar-Ilan University
Elena Micheli, Technische Universität Darmstadt
François-Xavier Standaert, Université catholique de Louvain
Abstract

Post-quantum signature schemes are becoming increasingly important due to the threat of quantum computers to classical cryptographic schemes. Among the approaches considered in the literature, the MPC-in-the-head paradigm introduced by Ishai et al. (STOC'07) provides an innovative solution for constructing zero-knowledge proofs by exploiting Multi-Party Computation (MPC). This technique has proven to be a versatile tool in order to design efficient cryptographic schemes, including post-quantum signatures. Building on the MPC-in-the-head paradigm, we introduce Bittersweet signatures, a new class of signature schemes based on the Learning With Rounding (LWR) assumption. Their main advantage is conceptual simplicity: by exploiting (almost) key-homomorphic pseudorandom functions (PRFs), a cryptographic object that preserves pseudorandomness while allowing linear operations on keys, we obtain a very regular design offering nice opportunities for parallel implementations. Theoretically, analyzing Bittersweet signatures requires addressing significant challenges related to the (carry) leakage that almost key-homomorphic operations lead to. Concretely, Bittersweet signatures natively lead to competitive signature sizes, trading moderate software performance overheads for hardware performance gains when compared to state-of-the-art MPC-in-the-head schemes (e.g., relying on code-based assumptions), while admittedly lagging a bit behind recent algorithms based on the VOLE-in-the-head or Threshold-Computation-in-the-head frameworks. Besides, their scalability and algebraic structure makes them promising candidates for leakage-resilient implementations. The new abstractions we introduce additionally suggest interesting research directions towards further optimization and generalization.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
Post-Quantum SignatureMultiparty ComputationLearning with Rounding
Contact author(s)
brieuc balon @ uclouvain be
gianluca brian @ tu-darmstadt de
sebastian faust @ tu-darmstadt de
carmit hazay @ biu ac il
elena micheli @ tu-darmstadt de
francois-xavier standaert @ uclouvain be
History
2026-03-01: approved
2026-02-26: received
See all versions
Short URL
https://ia.cr/2026/397
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/397,
      author = {Brieuc Balon and Gianluca Brian and Sebastian Faust and Carmit Hazay and Elena Micheli and François-Xavier Standaert},
      title = {Bittersweet Signatures: Bringing {LWR} to a Picnic for Hardware-Friendly {MPC}-in-the-Head},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/397},
      year = {2026},
      url = {https://eprint.iacr.org/2026/397}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.