Technische Universitat Darmstadt
In this paper, the authors extend this scheme to a threshold ring identification and signature scheme. Their scheme is the first multivariate scheme of this type and generally the first multivariate signature scheme with special properties. Despite the fact that they need more rounds to achieve given levels of security, the signatures are at least twice shorter than those obtained by other post-quantum (e.g. code based) constructions. Furthermore, their scheme offers provable security, which is quite a rare fact in multivariate cryptography.