김성광 교수팀, 정보보호 분야 세계 최고 권위 학회 ACM CCS 2026 논문 발표 선정
정보보호대학원 2026-09-09

○ 정보보호대학원 소속 김성광 교수팀 논문이 2026년 11월 15일-19일에 네덜란드 헤이그에서 개최되는 ACM CCS 2026 발표 논문으로 선정됨. 이번에 선정된 논문은 삼성SDS 이병학 연구원, KAIST 손민철 박사과정과 공동으로 수행되었음.

 - 논문제목: Shorter VOLE-in-the-Head-based Signatures from Vector Semi-Commitment

 - 저자 정보: 김성광 (고려대학교), 이병학 (삼성SDS), 손민철 (KAIST)

 - 학회 홈페이지: https://www.sigsac.org/ccs/CCS2026/


CCS(ACM Conference on Computer and Communications Security)는 IEEE S&P, USENIX Security, NDSS와 더불어 정보보호 분야 세계 최고 권위의 4대 학술대회로 널리 인정받고 있으며, 국내에서도 BK21 Computer Science 분야 우수 국제학술대회 목록에서 최우수 등급(인정 IF 최고 등급인 4)으로 분류되어 있음


CCS 2026은 두 차례의 제출 사이클로 운영됨. 먼저 마감된 1차 사이클(Cycle A)에는 총 1,206편이 제출되어 이 중 78편만 즉시 채택되고 113편이 수정 후 재심(minor revision, shepherding) 대상으로 분류되었음(예비 채택 191편, 제출 대비 약 15.8%; 학회 공식 투명성 보고서 기준, 2차 사이클 통계는 미공개). 본 논문은 2차 사이클(Cycle B)에 제출되어 재심없이 즉시 채택되었음


VOLE-in-the-Head(VOLEitH)는 VOLE 기반 영지식 증명을 공개 검증 가능한 양자내성 전자서명으로 변환하는 패러다임으로, 미국 NIST 추가 양자내성 전자서명 표준화 공모 후보인 FAEST의 기반 기술임. VOLEitH 서명에서는 GGM 트리 기반 vector commitment가 서명 크기의 대부분을 차지함. 본 연구는 연구팀이 Eurocrypt 2025에서 MPC-in-the-Head 기법을 위해 제안한 vector semi-commitment(VSC)를 VOLEitH에 적용하여 서명 크기를 줄이고, 그 안전성을 random oracle, Davies-Meyer, counter mode, PRG 모델에 공통으로 적용되는 하나의 증명으로 보였음. 제안 기법을 FAEST v2.0에 적용한 rFAEST는 128-bit 보안 수준의 4개 parameter set 중 3개에서 서명 크기를 최대 5.1% 줄였고, 4개 모두에서 서명 속도를 27.7-124.2%, 검증 속도를 28.3-115.3% 향상시켰음. 또한 leaf별 commitment를 전체 leaf commitment의 최소·최대값만 남기는 MinMax commitment로 대체한 Huth-Joux(Asiacrypt 2025)의 VOLEitH-SBC 변형에 대해, 서명 질의 없이 약 2^86.5-2^94 연산으로 서명을 위조하는 공격을 제시하여 VSC가 유지하는 leaf commitment 구조가 왜 필요한지 보여주었음


논문 초록 : The VOLE-in-the-Head (VOLEitH) paradigm compiles VOLE-based zero-knowledge proofs into publicly verifiable post-quantum signature schemes. A central component of VOLEitH is a GGM-style tree used to realize a vector commitment, whose size dominates the signature.

In this work, we adapt vector semi-commitment (VSC)---previously developed for MPC-in-the-Head (MPCitH) by Kim et al. (Eurocrypt 2025)---to the VOLEitH paradigm and prove its security. While prior MPCitH analyses relied on assumption-specific, fragmented security proofs, we give a unified treatment that characterizes which abstract property the underlying tree must satisfy, and instantiate it under the random oracle, Davies--Meyer, counter (CTR), and pseudorandom generator (PRG) models. 

Building on this, we construct reduced VOLE-in-the-Head (rVOLEitH) and apply it to FAEST, one of the NIST additional post-quantum signature candidates, obtaining signature sizes comparable to those of FAEST v2.0, ranging from 94.9% to 102.8% of the corresponding FAEST v2.0 sizes, while attaining 27.7-124.2% faster signing and 28.3-115.3% faster verification for 128-bit parameters.

Finally, we present a practical attack on a recently proposed VOLEitH variant of the subfield bilinear collision (SBC) signature scheme by Huth and Joux (Asiacrypt 2025) which replaces leaf commitments with a single global commitment, demonstrating the necessity of the commitment structure retained by VSC.


841e7c8e666fb258e1bbd4cd865ba019_1788945643_5249.png


닫기