错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Password Protected Universal Thresholdizer

  • Sabyasachi Dutta,
  • Partha Sarathi Roy,
  • Reihaneh Safavi-Naini,
  • Willy Susilo

摘要

The Universal Thresholdizer ( \(\textsf{UT}\) ), introduced by Boneh et al. in CRYPTO 2018, offers an elegant method for converting non-threshold cryptographic primitives into threshold ones. However, \(\textsf{UT}\) lacks user authentication, making threshold functionalities vulnerable to impersonation attacks through fraudulent requests. To address this issue, we introduce a general framework called the Password Protected Universal Thresholdizer ( \({\textsf{PPUT}}\) ). This framework enhances the capabilities of \(\textsf{UT}\) by integrating password-based user authentication while preserving threshold security guarantees. It ensures that only a legitimate user having the correct password can compute the final output, without requiring persistent secret storage beyond the initial setup phase. We formalize simulation-based security for \({\textsf{PPUT}}\) in the stand-alone model against malicious adversaries, ensuring the security of the user’s password, the secret states of the user and servers, and all intermediate computations. We then demonstrate a generic construction of \({\textsf{PPUT}}\) , which integrates \(\textsf{UT}\) with a threshold password authenticated key exchange ( \(\textsf{TPAKE}\) ). For \(\textsf{TPAKE}\) , we introduce a simulation-based security definition and provide a generic construction. As an application of the proposed \({\textsf{PPUT}}\) , we present a password protected threshold signature scheme that simultaneously provides authentication of the user, robustness, and unforgeability, making it suitable for distributed key management systems, such as cryptocurrency wallets. All the generic constructions proposed in this work are proven secure in the standard model and can be instantiated from lattices, ensuring security against quantum adversaries.