Threshold Signatures from Inner Product Argument: Succinct, Weighted, and Multi-threshold

Threshold Signatures from Inner Product Argument: Succinct, Weighted, and Multi-threshold
复制标题

DOI:
10.1145/3576915.3623096
复制
发表时间:
2023-11
期刊:
Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Sourav Das;Philippe Camacho;Zhuolun Xiang;Javier Nieto;Benedikt Bünz;Ling Ren
Sourav Das;Philippe Camacho;Zhuolun Xiang;Javier Nieto;Benedikt Bünz;Ling Ren
中科院分区:
其他
文献类型:
--
作者:
Sourav Das;Philippe Camacho;Zhuolun Xiang;Javier Nieto;Benedikt Bünz;Ling Ren

文献摘要

被引文献

相似文献

阈值签名通过在一组签名者之间共享签名密钥来保护签名密钥,因此攻击者必须破坏一个阈值数量的签名者才能伪造签名。如果签名者的权值不同,现有的签名简洁且验证次数不变的阈值签名将不起作用。这种加权设置在去中心化系统中越来越重要,尤其是在权益证明区块链中。本文提出了一种新的基于配对和离散对数密码系统的阈值签名范式。该方案具有一个仅由7个群元素组成的紧凑验证密钥和一个由8个群元素组成的签名。验证签名需要8次幂运算和8次双线性配对。我们的方案支持签名者之间的任意权重分布和任意阈值。它需要在通用功率设置之后进行非交互式预处理。在代数群模型中证明了该方案的安全性,并用Golang实现了该方案。我们的评估表明,我们的方案实现了与标准(未加权)阈值签名相当的签名大小和验证时间。与现有的多重签名方案相比,我们的方案具有更小的公共验证密钥。
Threshold signatures protect the signing key by sharing it among a group of signers so that an adversary must corrupt a threshold number of signers to be able to forge signatures. Existing threshold signatures with succinct signatures and constant verification times do not work if signers have different weights. Such weighted settings are seeing increasing importance in decentralized systems, especially in the Proof-of-Stake blockchains. This paper presents a new paradigm for threshold signatures for pairing and discrete logarithm-based cryptosystems. Our scheme has a compact verification key consisting of only 7 group elements, and a signature consisting of 8 group elements. Verifying the signature requires 8 exponentiations and 8 bilinear pairings. Our scheme supports arbitrary weight distributions among signers and arbitrary thresholds. It requires non-interactive preprocessing after a universal powers-of-tau setup. We prove the security of our scheme in the Algebraic Group Model and implement it using Golang. Our evaluation shows that our scheme achieves a comparable signature size and verification time to a standard (unweighted) threshold signature. Compared to existing multisignature schemes, our scheme has a much smaller public verification key.