{"id":{"repo_id":"trento","oai_identifier":"oai:iris.unitn.it:11572/449630"},"canonical_url":"https://search.dev.ndltd.org/etd/trento/oai:iris.unitn.it:11572/449630","repository":{"repo_id":"trento","name":"Università degli Studi di Trento","base_url":"https://iris.unitn.it/oai/request"},"display":{"title":"Code-Based Digital Signature Schemes: Construction, Cryptanalysis and Theoretical Foundations","abstract":"In recent decades, numerous code-based digital signature schemes following the hash&amp;sign paradigm have been proposed, often turning out to be insecure and demonstrating that the cryptographic community still seems far from a satisfactory solution in this area. The first major question we pose in this thesis is whether it is possible to construct, in this regard, a signature scheme that enjoys a solid security reduction and is also efficient. We discuss a proposal that combines some new ideas, but we anticipate that it suffered a severe attack two years ago, making it unusable. The second question we pose is the possibility to say something about the security of other schemes. According to this, we leave the constructive side and explore the cryptanalytic one, analyzing HWQCS. We break its security assumptions and violate the EUF-CMA security. Other than by following the hash&amp;sign paradigm, an alternative approach to obtain digital signatures is to rely on interactive protocols, making them non-interactive using the Fiat-Shamir transform. Recently, numerous optimizations to the basic paradigm have been introduced, including the well-known fixed-weight optimization. Although this technique is widely used, its underlying security assumptions are still not well understood, and the formal security of these schemes has not yet been proven. With the intention of laying a first brick in this direction, we prove that the underlying interactive protocol still enjoys knowledge soundness. These are the main questions targeted by this thesis, forming the fil rouge that guides the narrative. In the process of addressing them, several secondary questions will naturally arise, which will be described and explored throughout the discussion.","abstract_html":"In recent decades, numerous code-based digital signature schemes following the hash&amp;amp;sign paradigm have been proposed, often turning out to be insecure and demonstrating that the cryptographic community still seems far from a satisfactory solution in this area. The first major question we pose in this thesis is whether it is possible to construct, in this regard, a signature scheme that enjoys a solid security reduction and is also efficient. We discuss a proposal that combines some new ideas, but we anticipate that it suffered a severe attack two years ago, making it unusable. The second question we pose is the possibility to say something about the security of other schemes. According to this, we leave the constructive side and explore the cryptanalytic one, analyzing HWQCS. We break its security assumptions and violate the EUF-CMA security. Other than by following the hash&amp;amp;sign paradigm, an alternative approach to obtain digital signatures is to rely on interactive protocols, making them non-interactive using the Fiat-Shamir transform. Recently, numerous optimizations to the basic paradigm have been introduced, including the well-known fixed-weight optimization. Although this technique is widely used, its underlying security assumptions are still not well understood, and the formal security of these schemes has not yet been proven. With the intention of laying a first brick in this direction, we prove that the underlying interactive protocol still enjoys knowledge soundness. These are the main questions targeted by this thesis, forming the fil rouge that guides the narrative. In the process of addressing them, several secondary questions will naturally arise, which will be described and explored throughout the discussion.","abstract_has_math":false,"creators":["Tognolini, Giovanni"],"institution":"Università degli studi di Trento","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Murru, Nadir","Meneghetti, Alessio"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-03-28","date_published":"2025-03-28","updated_at":"2026-07-24T05:04:43Z","subjects":["Post-Quantum","Digital Signatures","Cryptanalysis","Code-Based","Theoretical Foundations","Cryptography"],"languages":["eng"],"rights":["info:eu-repo/semantics/openAccess","license:Tutti i diritti riservati (All rights reserved)","license uri:iris.PRI01"],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["http://dx.doi.org/10.15168/11572_449630","10.15168/11572_449630"],"render_values":[{"text":"http://dx.doi.org/10.15168/11572_449630","href":"http://dx.doi.org/10.15168/11572_449630","code":true},{"text":"10.15168/11572_449630","href":"https://doi.org/10.15168/11572_449630","code":true}]}]},"links":{"outbound_url":"https://hdl.handle.net/11572/449630","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Tognolini, Giovanni","Murru, Nadir","Meneghetti, Alessio"]},{"key":"dc:creator","label":"Author","values":["Tognolini, Giovanni"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2025-03-28"]},{"key":"dc:publisher","label":"Institution","values":["Università degli studi di Trento","place:TRENTO"]},{"key":"dc:relation","label":"Dc Relation","values":["firstpage:1","lastpage:140","numberofpages:140"]},{"key":"dc:type","label":"Dc Type","values":["info:eu-repo/semantics/doctoralThesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Post-Quantum","Digital Signatures","Cryptanalysis","Code-Based","Theoretical Foundations","Cryptography"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["info:eu-repo/semantics/openAccess","license:Tutti i diritti riservati (All rights reserved)","license uri:iris.PRI01"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/11572/449630","http://dx.doi.org/10.15168/11572_449630","10.15168/11572_449630"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["In recent decades, numerous code-based digital signature schemes following the hash&amp;sign paradigm have been proposed, often turning out to be insecure and demonstrating that the cryptographic community still seems far from a satisfactory solution in this area. The first major question we pose in this thesis is whether it is possible to construct, in this regard, a signature scheme that enjoys a solid security reduction and is also efficient. We discuss a proposal that combines some new ideas, but we anticipate that it suffered a severe attack two years ago, making it unusable. The second question we pose is the possibility to say something about the security of other schemes. According to this, we leave the constructive side and explore the cryptanalytic one, analyzing HWQCS. We break its security assumptions and violate the EUF-CMA security. Other than by following the hash&amp;sign paradigm, an alternative approach to obtain digital signatures is to rely on interactive protocols, making them non-interactive using the Fiat-Shamir transform. Recently, numerous optimizations to the basic paradigm have been introduced, including the well-known fixed-weight optimization. Although this technique is widely used, its underlying security assumptions are still not well understood, and the formal security of these schemes has not yet been proven. With the intention of laying a first brick in this direction, we prove that the underlying interactive protocol still enjoys knowledge soundness. These are the main questions targeted by this thesis, forming the fil rouge that guides the narrative. In the process of addressing them, several secondary questions will naturally arise, which will be described and explored throughout the discussion."]},{"key":"dc:title","label":"Title","values":["Code-Based Digital Signature Schemes: Construction, Cryptanalysis and Theoretical Foundations"]}]}],"canonical_facts":{"dc:contributor":["Tognolini, Giovanni","Murru, Nadir","Meneghetti, Alessio"],"dc:creator":["Tognolini, Giovanni"],"dc:date":["2025-03-28"],"dc:description":["In recent decades, numerous code-based digital signature schemes following the hash&amp;sign paradigm have been proposed, often turning out to be insecure and demonstrating that the cryptographic community still seems far from a satisfactory solution in this area. The first major question we pose in this thesis is whether it is possible to construct, in this regard, a signature scheme that enjoys a solid security reduction and is also efficient. We discuss a proposal that combines some new ideas, but we anticipate that it suffered a severe attack two years ago, making it unusable. The second question we pose is the possibility to say something about the security of other schemes. According to this, we leave the constructive side and explore the cryptanalytic one, analyzing HWQCS. We break its security assumptions and violate the EUF-CMA security. Other than by following the hash&amp;sign paradigm, an alternative approach to obtain digital signatures is to rely on interactive protocols, making them non-interactive using the Fiat-Shamir transform. Recently, numerous optimizations to the basic paradigm have been introduced, including the well-known fixed-weight optimization. Although this technique is widely used, its underlying security assumptions are still not well understood, and the formal security of these schemes has not yet been proven. With the intention of laying a first brick in this direction, we prove that the underlying interactive protocol still enjoys knowledge soundness. These are the main questions targeted by this thesis, forming the fil rouge that guides the narrative. In the process of addressing them, several secondary questions will naturally arise, which will be described and explored throughout the discussion."],"dc:identifier":["https://hdl.handle.net/11572/449630","http://dx.doi.org/10.15168/11572_449630","10.15168/11572_449630"],"dc:language":["eng"],"dc:publisher":["Università degli studi di Trento","place:TRENTO"],"dc:relation":["firstpage:1","lastpage:140","numberofpages:140"],"dc:rights":["info:eu-repo/semantics/openAccess","license:Tutti i diritti riservati (All rights reserved)","license uri:iris.PRI01"],"dc:subject":["Post-Quantum","Digital Signatures","Cryptanalysis","Code-Based","Theoretical Foundations","Cryptography"],"dc:title":["Code-Based Digital Signature Schemes: Construction, Cryptanalysis and Theoretical Foundations"],"dc:type":["info:eu-repo/semantics/doctoralThesis"]},"updated_at":"2026-07-24T05:04:43Z"}