Threshold Ring Signatures: From DualRing to the \(t+1\) Rings
摘要
A t-out-of-n threshold ring signature allows t signers to sign a message while anonymizing themselves within a set of n public keys. One of the key research directions is to build a practical threshold ring signature with a short signature size, which is logarithmic to the parameters (t, n). In this paper, we extend the DualRing architecture (using one R-ring and one C-ring) for ring signatures (CRYPTO ’21) to a new architecture for threshold ring signatures. We propose a generic construction of threshold ring signatures using one R-ring and t C-rings. We show that the t C-rings are constructed securely and efficiently. In order to compress the n elements in the C-rings in the elliptic curve setting, we propose a new argument of knowledge for matrix multiplication. The proof size is \(O(\log n)\) . When combined with the generic threshold ring signature, we obtain the first practical threshold ring signature with size \(O(\log n)\) only (independent to t).