Threshold signatures (TS) have been widely used in digital wallets and blockchain ecosystems. In a (t, n) threshold signature scheme, at least \(t+1\) signers are required to produce a valid signature. The state-of-the-art TS schemes compromise either the security model or incur at least linear-size reduction loss. Designing a fully adaptive and tightly secure TS scheme without algebraic group model (AGM) is still challenging. In this work, we propose a new security model, \(\textsf{EUF}\text {-}\textsf{CMA}\text {-}\textsf{FC}\) , making an enhancement in randomness guarantee and capturing fully adaptive security. We also propose \(\textsf{Glitter}\) , a fully adaptive and tightly secure five-round threshold signature scheme without pairing. \(\textsf{Glitter}\) has a comparable signature size and verification time with the state-of-the-art works. We prove the tight security of \(\textsf{Glitter}\) in the \(\textsf{EUF}\text {-}\textsf{CMA}\text {-}\textsf{FC}\) model in the random oracle model via security reduction. Without AGM, the security of \(\textsf{Glitter}\) can be reduced to t-algebraic translation resistance of tagged linear function (which implies DDH) with reduction loss \(L=2\) .

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

\(\textsf{Glitter}\) : A Fully Adaptive and Tightly Secure Threshold Signature

  • Shaolong Tang,
  • Peng Jiang,
  • Liehuang Zhu

摘要

Threshold signatures (TS) have been widely used in digital wallets and blockchain ecosystems. In a (t, n) threshold signature scheme, at least \(t+1\) signers are required to produce a valid signature. The state-of-the-art TS schemes compromise either the security model or incur at least linear-size reduction loss. Designing a fully adaptive and tightly secure TS scheme without algebraic group model (AGM) is still challenging. In this work, we propose a new security model, \(\textsf{EUF}\text {-}\textsf{CMA}\text {-}\textsf{FC}\) , making an enhancement in randomness guarantee and capturing fully adaptive security. We also propose \(\textsf{Glitter}\) , a fully adaptive and tightly secure five-round threshold signature scheme without pairing. \(\textsf{Glitter}\) has a comparable signature size and verification time with the state-of-the-art works. We prove the tight security of \(\textsf{Glitter}\) in the \(\textsf{EUF}\text {-}\textsf{CMA}\text {-}\textsf{FC}\) model in the random oracle model via security reduction. Without AGM, the security of \(\textsf{Glitter}\) can be reduced to t-algebraic translation resistance of tagged linear function (which implies DDH) with reduction loss \(L=2\) .