Research Article

A Fuzzy Identity-Based Signature Scheme from Lattices in the Standard Model

Table 1

Performance comparison with the scheme of [21].

Length of PP Length of MK Length of skID Length of

[21]
Ours

Sign cost Verify cost Unforgeability Model

[21] ()<
+ + ()

Ours SSS MVP ()
+ ()+ SMP ()
+ PS ()+ ()

Note. The units of public parameters size, master secret key size, private key of identity size, and signature size are bits. The base of the logarithm function is 2; denotes Shamir secret sharing operation; denotes preimage sampling algorithm; denotes matrix and vector product (where the matrix form is and the vector form is -row); denotes scalar multiplication; denotes existential unforgeability; denotes random oracle model; DGS denotes discrete Gaussian sampling algorithm; denotes matrix and matrix addition; denotes strong unforgeability; denotes the standard model. The () and () denote modules that are used in the corresponding operations.