Ellipsoidal G+G Signature over NTRU Lattices
Huiwen Jia, Yuchu Wu, Lishan Ke, Jingting Xu, Chunming Tang, Momeng LiuG+G constructs Fiat–Shamir lattice signatures by Gaussian convolution, with fresh Gaussian randomness sampled both before and after the challenge is fixed. Its NTRU instantiation uses a spherical public response distribution. In this paper, we apply ellipsoidal Gaussian techniques to G+G over NTRU lattices to reduce the signature size. We combine a fixed Hamming weight ternary secret with a discrete Gaussian secret and assign different Gaussian parameters to the two response components. A matrix Gaussian decomposition and the associated spectral condition bound the distance between the response distribution and a public ellipsoidal Gaussian. These bounds yield honest-verifier zero-knowledge and, under the stated sufficient conditions and the NTRU short integer solution (SIS) assumption for the conditioned key distribution, existential unforgeability of the basic signature in the classical random oracle model. For concrete parameters in dimensions 512 and 1024, we compare the spherical and ellipsoidal constructions using G+G’s signature truncation and a common size-estimation method. The signature sizes decrease from 1001 to 940 bytes and from 1728 to 1548 bytes, corresponding to reductions of 6.09% and 10.42%, respectively.