<p>A <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10623_2025_1660_Article_IEq1.gif" Format="GIF" Height="15" Rendition="HTML" Resolution="72" Type="Linedraw" Width="71" /> </InlineMediaObject> <EquationSource Format="TEX">\(t{\text {-}\textsf{out}\text {-}\textsf{of}\text {-}}n\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>t</mi> <mrow> <mtext>-</mtext> <mi mathvariant="sans-serif">out</mi> <mtext>-</mtext> <mi mathvariant="sans-serif">of</mi> <mtext>-</mtext> </mrow> <mi>n</mi> </mrow> </math></EquationSource> </InlineEquation> threshold ring signature allows <i>t</i> parties to jointly sign a message on behalf of <i>n</i> parties without revealing the identities of the signers. In this paper, we introduce a new generic construction for threshold ring signature, called <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10623_2025_1660_Article_IEq2.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="59" /> </InlineMediaObject> <EquationSource Format="TEX">\(\mathsf {GC\text {-}TRS}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">GC</mi> <mtext mathvariant="sans-serif">-</mtext> <mi mathvariant="sans-serif">TRS</mi> </mrow> </math></EquationSource> </InlineEquation>, which can be built on top of a selection on identification schemes, commitment schemes, and a new primitive called <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10623_2025_1660_Article_IEq1.gif" Format="GIF" Height="15" Rendition="HTML" Resolution="72" Type="Linedraw" Width="71" /> </InlineMediaObject> <EquationSource Format="TEX">\(t{\text {-}\textsf{out}\text {-}\textsf{of}\text {-}}n\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>t</mi> <mrow> <mtext>-</mtext> <mi mathvariant="sans-serif">out</mi> <mtext>-</mtext> <mi mathvariant="sans-serif">of</mi> <mtext>-</mtext> </mrow> <mi>n</mi> </mrow> </math></EquationSource> </InlineEquation> proof protocol which is a special type of zero-knowledge proof. In general, our design enables a group of <i>t</i> signers to first generate an aggregated signature by interacting with each other; then they are able to compute a <InlineEquation ID="IEq4"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10623_2025_1660_Article_IEq1.gif" Format="GIF" Height="15" Rendition="HTML" Resolution="72" Type="Linedraw" Width="71" /> </InlineMediaObject> <EquationSource Format="TEX">\(t{\text {-}\textsf{out}\text {-}\textsf{of}\text {-}}n\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>t</mi> <mrow> <mtext>-</mtext> <mi mathvariant="sans-serif">out</mi> <mtext>-</mtext> <mi mathvariant="sans-serif">of</mi> <mtext>-</mtext> </mrow> <mi>n</mi> </mrow> </math></EquationSource> </InlineEquation> proof to convince the verifier that the aggregated signature is indeed produced by <i>t</i> individuals among a particular set. The signature is succinct, as it contains only one aggregated signature and one proof in the final signature. We define all the properties required for the building blocks to capture the security of the <InlineEquation ID="IEq5"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10623_2025_1660_Article_IEq2.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="59" /> </InlineMediaObject> <EquationSource Format="TEX">\(\mathsf {GC\text {-}TRS}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">GC</mi> <mtext mathvariant="sans-serif">-</mtext> <mi mathvariant="sans-serif">TRS</mi> </mrow> </math></EquationSource> </InlineEquation> and provide a detailed security proof. Furthermore, we propose two lattice-based instantiations for the <InlineEquation ID="IEq6"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10623_2025_1660_Article_IEq2.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="59" /> </InlineMediaObject> <EquationSource Format="TEX">\(\mathsf {GC\text {-}TRS}\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi mathvariant="sans-serif">GC</mi> <mtext mathvariant="sans-serif">-</mtext> <mi mathvariant="sans-serif">TRS</mi> </mrow> </math></EquationSource> </InlineEquation>, named <Emphasis FontCategory="SansSerif">LTRS</Emphasis> and <Emphasis FontCategory="SansSerif">CTRS</Emphasis>, respectively. Notably, the <Emphasis FontCategory="SansSerif">CTRS</Emphasis> scheme is the first scheme that has a logarithmic signature size relative to the ring size. Additionally, during the instantiation process, we construct two <InlineEquation ID="IEq7"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10623_2025_1660_Article_IEq1.gif" Format="GIF" Height="15" Rendition="HTML" Resolution="72" Type="Linedraw" Width="71" /> </InlineMediaObject> <EquationSource Format="TEX">\(t{\text {-}\textsf{out}\text {-}\textsf{of}\text {-}}n\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mi>t</mi> <mrow> <mtext>-</mtext> <mi mathvariant="sans-serif">out</mi> <mtext>-</mtext> <mi mathvariant="sans-serif">of</mi> <mtext>-</mtext> </mrow> <mi>n</mi> </mrow> </math></EquationSource> </InlineEquation> proof protocols, which may be of independent interest.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Generic construction of threshold ring signatures and lattice-based instantiations

  • Hao Lin,
  • Mingqiang Wang,
  • Weiqiang Wen,
  • Shi-Feng Sun,
  • Kaitai Liang

摘要

A \(t{\text {-}\textsf{out}\text {-}\textsf{of}\text {-}}n\) t - out - of - n threshold ring signature allows t parties to jointly sign a message on behalf of n parties without revealing the identities of the signers. In this paper, we introduce a new generic construction for threshold ring signature, called \(\mathsf {GC\text {-}TRS}\) GC - TRS , which can be built on top of a selection on identification schemes, commitment schemes, and a new primitive called \(t{\text {-}\textsf{out}\text {-}\textsf{of}\text {-}}n\) t - out - of - n proof protocol which is a special type of zero-knowledge proof. In general, our design enables a group of t signers to first generate an aggregated signature by interacting with each other; then they are able to compute a \(t{\text {-}\textsf{out}\text {-}\textsf{of}\text {-}}n\) t - out - of - n proof to convince the verifier that the aggregated signature is indeed produced by t individuals among a particular set. The signature is succinct, as it contains only one aggregated signature and one proof in the final signature. We define all the properties required for the building blocks to capture the security of the \(\mathsf {GC\text {-}TRS}\) GC - TRS and provide a detailed security proof. Furthermore, we propose two lattice-based instantiations for the \(\mathsf {GC\text {-}TRS}\) GC - TRS , named LTRS and CTRS, respectively. Notably, the CTRS scheme is the first scheme that has a logarithmic signature size relative to the ring size. Additionally, during the instantiation process, we construct two \(t{\text {-}\textsf{out}\text {-}\textsf{of}\text {-}}n\) t - out - of - n proof protocols, which may be of independent interest.