Threshold and Multi-Signature Schemes from Linear Hash Functions

Threshold and Multi-Signature Schemes from Linear Hash Functions
复制标题

DOI:
10.1007/978-3-031-30589-4_22
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Stefano Tessaro;Chenzhi Zhu
Stefano Tessaro;Chenzhi Zhu
中科院分区:
其他
文献类型:
--
作者:
Stefano Tessaro;Chenzhi Zhu

文献摘要

相似文献

本文给出了新的两轮多重签名和门限签名的构造,其安全性仅依赖于(普通)离散对数问题的困难性或RSA的困难性,并假设了随机预言机。它们的签名协议是部分非交互式的,即,第一轮的签名协议是独立的消息被签署。我们通过推广最有效的离散对数为基础的计划,(尼克,Ruffing,和Seurin,NPTO '21)和(Komlo和Goldberg,SAC '20),我们的结构,工作与适当定义的线性散列函数。虽然原来的计划依赖于更强,更有争议的一个离散对数假设,我们表明,适当的实例化的哈希函数,使安全的基础上,无论是简单的离散对数假设或RSA。我们的方案所产生的签名等价于Okamoto的身份识别方案(NIPPTO '92)。更抽象地说,我们的结果提供了一个一般框架,将OMDL下的安全方案转化为在普通DL假设下的安全方案,并在一定的限制下,转化为RSA下的安全方案。
This paper gives new constructions of two-round multi-signa-tures and threshold signatures for which security relies solely on either the hardness of the (plain) discrete logarithm problem or the hardness of RSA, in addition to assuming random oracles. Their signing protocol is partially non-interactive, i.e., the first round of the signing protocol is independent of the message being signed.We obtain our constructions by generalizing the most efficient discrete-logarithm based schemes,(Nick, Ruffing, and Seurin, CRYPTO ’21) and(Komlo and Goldberg, SAC ’20), to work with suitably defined linear hash functions. While the original schemes rely on the stronger and more controversial one-more discrete logarithm assumption, we show that suitable instantiations of the hash functions enable security to be based on either the plain discrete logarithm assumption or on RSA. The signatures produced by our schemes are equivalent to those obtained from Okamoto’s identification schemes (CRYPTO ’92).More abstractly, our results suggest a general framework to transform schemes secure under OMDL into ones secure under the plain DL assumption and, with some restrictions, under RSA.