REVIEW 1 minor 30 references
Two code-based schemes turn restricted-error decoding and code equivalence into post-quantum digital signatures.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · grok-4.3
2026-07-01 04:48 UTC pith:SVU3XD5D
load-bearing objection This is a clear expository overview of CROSS and LESS with no new technical results or analyses.
Digital signature schemes based on code equivalence and syndrome decoding from restricted errors
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
The Fiat-Shamir transform applied to sigma protocols for the syndrome decoding problem with restricted errors and for the code equivalence problem produces digital signature schemes believed to remain secure against quantum adversaries.
What carries the argument
Sigma protocols for syndrome decoding from restricted errors and for code equivalence, converted to signatures by the Fiat-Shamir transform.
Load-bearing premise
The problems of syndrome decoding from restricted errors and of deciding code equivalence stay computationally hard for both classical and quantum algorithms.
What would settle it
An efficient algorithm, classical or quantum, that solves the restricted-error syndrome decoding problem or the code equivalence problem for the parameter sizes used in the schemes would falsify their security.
If this is right
- The signatures can be used wherever data authenticity must survive quantum attacks.
- The two schemes rest on distinct hardness assumptions from many other post-quantum methods.
- The explicit reduction from the underlying problems to signature forgery supplies a clear security argument.
Where Pith is reading between the lines
- Similar sigma-protocol constructions could be attempted on other variants of coding-theory problems to produce additional signature families.
- Concrete efficiency measurements of signature size and verification time for these schemes would clarify their practical trade-offs relative to other post-quantum options.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript is an expository overview of two NIST second-round post-quantum signature candidates, CROSS and LESS. It describes the underlying problems (syndrome decoding from restricted errors and code equivalence), reviews sigma protocols, explains the Fiat-Shamir transform, and states that the resulting signatures are believed to be post-quantum secure on the basis of those pre-existing hardness assumptions. No new constructions, reductions, or parameter analyses are claimed.
Significance. As a review paper the work has moderate significance: it supplies a structured account of existing schemes and explicitly ties security to standard assumptions rather than new derivations. This may aid accessibility for researchers following the NIST process. No machine-checked proofs, reproducible code, or falsifiable predictions are provided.
minor comments (1)
- [Abstract] Abstract: the phrasing 'explain how this procedure yields code-based digital signatures believed to be post-quantum secure' could be tightened to make clearer that security rests entirely on prior hardness assumptions for the two problems, with no new analysis supplied in the manuscript.
Simulated Author's Rebuttal
We thank the referee for their positive recommendation to accept the manuscript. The review correctly identifies the paper as an expository overview of the CROSS and LESS schemes, their underlying hardness assumptions, and the sigma-protocol plus Fiat-Shamir construction, without claiming new results.
Circularity Check
No significant circularity; expository review without derivations
full rationale
The manuscript is an overview of the existing CROSS and LESS signature schemes. It describes the syndrome decoding and code equivalence problems, sigma protocols, and the Fiat-Shamir transform, but introduces no new equations, predictions, security reductions, or parameter derivations. The claim of post-quantum security is attributed solely to the pre-existing hardness assumptions on those problems rather than any internal derivation chain. No load-bearing steps reduce to self-definition, fitted inputs, or self-citations.
Axiom & Free-Parameter Ledger
read the original abstract
Digital signature schemes are an important cryptographic tool to ensure data authenticity and integrity in many applications that must be resilient to attacks, including those facilitated by quantum computers. We consider the two digital signature schemes based on error-correcting codes that are second-round candidates in NIST's call for Additional Signature Schemes, which is part of the Post-Quantum Cryptography Standardization Process. Specifically, we provide an overview of the Codes and Restricted Objects Signature Scheme (CROSS) and the Linear Equivalence Signature Scheme (LESS). We describe their underlying problems of syndrome decoding from restricted errors and code equivalence. We review sigma protocols and how they can be transformed into digital signature schemes via the Fiat-Shamir transform. Finally, we explain how this procedure yields code-based digital signatures believed to be post-quantum secure.
Figures
Reference graph
Works this paper leans on
-
[1]
M. R. Albrecht, D. J. Bernstein, T. Chou, C. Cid, J. Gilcher, T. Lange, V . Maram, I. von Maurich, R. Mis- oczki, R. Niederhagen, K. G. Paterson, E. Persichetti, C. Peters, P. Schwabe, N. Sendrier, J. Szefer, C. J. Tjhai, M. Tomlinson, and W. Wang. Classic McEliece, 2020. NIST PQC Round 3 submission
work page 2020
- [2]
-
[3]
T. Attema and S. Fehr. Parallel repetition of (k1, . . . , kµ)- special-sound multi-round interactive proofs. In Y . Dodis and T. Shrimpton, editors, Advances in Cryptology – 11 CRYPTO 2022, volume 13507 of Lecture Notes in Com- puter Science, pages 415–443. Springer, 2022
work page 2022
-
[4]
L. Babai. Graph isomorphism in quasipolynomial time. In Proceedings of the 48th Annual ACM Symposium on Theory of Computing (STOC) , pages 684–697. ACM, 2016
work page 2016
-
[5]
M. Baldi, A. Barenghi, M. Battagliola, S. Bitzer, M. Gi- anvecchio, P. Karl, F. Manganiello, A. Pavoni, G. Pelosi, F. Pintore, P. Santini, J. Schupp, E. Signorini, F. Slaugh- ter, A. Wachter-Zeh, and V . Weger. CROSS: Codes and restricted objects signature scheme, 2023. NIST PQC Additional Digital Signature Schemes submission
work page 2023
-
[6]
E. Berlekamp, R. McEliece, and H. van Tilborg. On the inherent intractability of certain coding problems (corresp.). IEEE Transactions on Information Theory , 24(3):384–386, 1978
work page 1978
- [7]
- [8]
- [9]
- [10]
-
[11]
T. Chou, R. Niederhagen, E. Persichetti, T. H. Ran- drianarisoa, K. Reijnders, S. Samardjiska, and M. Tri- moska. Take your MEDS: Digital signatures from ma- trix code equivalence. In N. El Mrabet, L. De Feo, and S. Duquesne, editors, AFRICACRYPT 2023, volume 14064 of LNCS, pages 28–52. Springer, Cham, July 2023
work page 2023
-
[12]
W. Diffie and M. Hellman. New directions in cryp- tography. IEEE Transactions on Information Theory , 22(6):644–654, 1976
work page 1976
- [13]
-
[14]
A. Fiat and A. Shamir. How to prove yourself: Practical solutions to identification and signature problems. In A. M. Odlyzko, editor, CRYPTO ’86, pages 186–194. Springer Berlin Heidelberg, 1987
work page 1987
-
[15]
M. J. E. Golay. Notes on Digital Coding. Proceedings of the IRE , 37(6):657, 1949
work page 1949
-
[16]
E. Gorla and F. Salizzoni. MacWilliams’ extension theorem for rank-metric codes. Journal of Symbolic Computation, 122:102263, 2024
work page 2024
-
[17]
L. K. Grover. A fast quantum mechanical algorithm for database search. In Proceedings of the Twenty- Eighth Annual ACM Symposium on Theory of Computing, STOC ’96, page 212–219, New York, NY , USA, 1996. Association for Computing Machinery
work page 1996
-
[18]
R. W. Hamming. Error detecting and error correcting codes. The Bell System Technical Journal , 29(2):147– 160, 1950
work page 1950
-
[19]
F. J. MacWilliams. Combinatorial Problems of Ele- mentary Abelian Groups . PhD dissertation, Harvard University, 1962
work page 1962
-
[20]
R. J. McEliece. A public-key cryptosystem based on algebraic coding theory. Deep Space Network Progress Report, 44:114–116, Jan. 1978
work page 1978
-
[21]
C. A. Melchor, N. Aragon, S. Bettaieb, L. Bidoux, O. Blazy, J. Bos, J. Deneuville, A. Dion, P. Gaborit, J. La- can, E. Persichetti, J. Robert, P. V ´eron, and G. Z ´emor. HQC: Hamming quasi-cyclic. NIST PQC Submission, 2025
work page 2025
- [22]
-
[23]
Post-quantum cryptography standardization
National Institute of Standards and Technology. Post-quantum cryptography standardization. https://csrc.nist.gov/projects/post-quantum-cryptography/ post-quantum-cryptography-standardization, 2017. Updated December 2025
work page 2017
-
[24]
National Institute of Standards and Technology. Status report on the first round of the additional digital signature schemes for the NIST post-quantum cryptography stan- dardization process. Technical Report NIST IR 8528, National Institute of Standards and Technology, Oct. 2024
work page 2024
-
[25]
H. Niederreiter. Knapsack-type cryptosystems and alge- braic coding theory. Problems of Control and Information Theory, 15(2):157–166, 1986
work page 1986
-
[26]
E. Petrank and R. M. Roth. Is code equivalence easy to decide? IEEE Transactions on Information Theory , 43(5):1602–1604, 1997
work page 1997
- [27]
-
[28]
R. L. Rivest, A. Shamir, and L. Adleman. A method for obtaining digital signatures and public-key cryptosys- tems. Commun. ACM, 21(2):120–126, Feb. 1978
work page 1978
-
[29]
C.-P. Schnorr. Efficient signature generation by smart cards. Journal of Cryptology , 4(3):161–174, Jan. 1991
work page 1991
-
[30]
P. Shor. Algorithms for quantum computation: Discrete logarithms and factoring. In Proceedings 35th Annual Symposium on Foundations of Computer Science , pages 124–134, 1994. 12 SHORT BIOS Sarah Arpin (sarpin@vt.edu) is an Assistant Professor in the Department of Mathematics at Virginia Tech. She earned an M.A. in Pure Mathematics from CUNY Hunter College...
work page 1994
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.