On the Security of KZG Commitment for VSS

On the Security of KZG Commitment for VSS
复制标题

DOI:
10.1145/3576915.3623127
复制
发表时间:
2023-11
期刊:
Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Atsuki Momose;Sourav Das;Ling Ren
Atsuki Momose;Sourav Das;Ling Ren
中科院分区:
其他
文献类型:
--
作者:
Atsuki Momose;Sourav Das;Ling Ren

文献摘要

相似文献

Kate、Zaverucha 和 Goldberg 提出的恒定大小多项式承诺方案 (Asiscrypt 2010),也称为 KZG 承诺,是设计带宽高效的可验证秘密共享 (VSS) 协议的重要组成部分。然而,我们指出,KZG 承诺缺少对 VSS 协议至关重要的两个重要属性。首先,在没有理想化群体假设的情况下,KZG 承诺尚未被证明在标准对手模型中具有程度约束力。换句话说,提交的多项式不能保证具有所要求的次数,而该次数应该是 VSS 的重构阈值。如果没有此属性,VSS 的股东最终可能会根据使用的份额重建不同的秘密。其次,KZG 承诺不支持通过单一设置同时使用不同次数的多项式。如果底层 VSS 协议的重建阈值发生变化,协议必须重新进行设置,这涉及昂贵的多方计算,称为 tau 设置的幂。在这项工作中,我们增强了 KZG 致力于解决这两个限制的承诺。在强 Diffie-Hellman (SDH) 假设下,我们的方案在标准模型中具有度约束力。它支持 tau 幂公共参考串下的任何度数 0 < d ≤ m,其中 m+ 1 个群元素由一次性设置生成。
The constant-sized polynomial commitment scheme by Kate, Zaverucha, and Goldberg (Asiscrypt 2010), also known as the KZG commitment, is an essential component in designing bandwidth-efficient verifiable secret-sharing (VSS) protocols. We point out, however, that the KZG commitment is missing two important properties that are crucial for VSS protocols. First, the KZG commitment has not been proven to be degree binding in the standard adversary model without idealized group assumptions. In other words, the committed polynomial is not guaranteed to have the claimed degree, which is supposed to be the reconstruction threshold of VSS. Without this property, shareholders in VSS may end up reconstructing different secrets depending on which shares are used. Second, the KZG commitment does not support polynomials with different degrees at once with a single setup. If the reconstruction threshold of the underlying VSS protocol changes, the protocol must redo the setup, which involves an expensive multi-party computation known as the powers of tau setup. In this work, we augment the KZG commitment to address both of these limitations. Our scheme is degree-binding in the standard model under the strong Diffie-Hellman (SDH) assumption. It supports any degree 0 < d ≤ m under a powers-of-tau common reference string with m+ 1 group elements generated by a one-time setup.