Two-Round n-out-of-n and Multi-Signatures and Trapdoor Commitment from Lattices∗
  syRljlCB1Ygs 2023年11月02日 35 0

Abstract. Although they have been studied for a long time, distributed signature protocols have garnered renewed interest in recent years in view of novel applications

to topics like blockchains. Most recent works have focused on distributed versions of

ECDSA or variants of Schnorr signatures; however, and in particular, little attention has

been given to constructions based on post-quantum secure assumptions like the hardness of lattice problems. A few lattice-based threshold signature and multi-signature

schemes have been proposed in the literature, but they either rely on hash-and-sign

lattice signatures (which tend to be comparatively inefficient), use expensive generic transformations, or only come with incomplete security proofs. In this paper, we

construct several lattice-based distributed signing protocols with low round complexity

following the Fiat–Shamir with Aborts (FSwA) paradigm of Lyubashevsky (Asiacrypt

2009). Our protocols can be seen as distributed variants of the fast Dilithium-G signature scheme and the full security proof can be made assuming the hardness of module

SIS and LWE problems. A key step to achieving security (unexplained in some earlier papers) is to prevent the leakage that can occur when parties abort after their first

message—which can inevitably happen in the Fiat–Shamir with Aborts setting. We

manage to do so using homomorphic commitments. Exploiting the similarities between

FSwA and Schnorr-style signatures, our approach makes the most of observations from

recent advancements in the discrete log setting, such as Drijvers et al.’s seminal work

on two-round multi-signatures (S&P 2019). In particular, we observe that the use of

commitment not only resolves the subtle issue with aborts, but also makes it possible

to realize secure two-round n-out-of-n distributed signing and multi-signature in the

plain public key model, by equipping the commitment with a trapdoor feature. The construction of suitable trapdoor commitment from lattices is a side contribution of this

paper.

【版权声明】本文内容来自摩杜云社区用户原创、第三方投稿、转载,内容版权归原作者所有。本网站的目的在于传递更多信息,不拥有版权,亦不承担相应法律责任。如果您发现本社区中有涉嫌抄袭的内容,欢迎发送邮件进行举报,并提供相关证据,一经查实,本社区将立刻删除涉嫌侵权内容,举报邮箱: cloudbbs@moduyun.com

上一篇: IP协议报字段 下一篇: BUUCTF--Web篇详细wp
  1. 分享:
最后一次编辑于 2023年11月08日 0

暂无评论

推荐阅读
  4i8hCvzXKbg6   2023年11月30日   38   0   0 StandardciTime
  4i8hCvzXKbg6   2023年11月24日   45   0   0 IPideTCP
  syRljlCB1Ygs   2023年11月26日   43   0   0 sedciide
  4i8hCvzXKbg6   2023年12月10日   28   0   0 StandardciTime
  PUL2Nb3n9wqa   2023年11月22日   30   0   0 自定义cibundle
  4i8hCvzXKbg6   2023年12月02日   32   0   0 StandardciTime
syRljlCB1Ygs