Lune

S&P2026Top-tier venue

GoSSamer: Lightweight and Linear-Communication Asynchronous (Dynamic Proactive) Secret Sharing and the Applications

Xinxin Xing, Yizhong Liu, Boyang Liao, Jianwei Liu, Bin Hu, Xun Lin, Yuan Lu, Tianwei Zhang

2026Year
2Citations
1Top-tier citations

Abstract

Asynchronous complete secret sharing (ACSS) and asynchronous dynamic proactive secret sharing (ADPSS) are fundamental primitives for secret sharing and resharing in modern threshold systems, such as multi-party computation, distributed key management, and blockchain. However, existing ACSS constructions that employ homomorphic commitments incur notable computational overhead, while the lightweightcomputation constructions require quadratic per-secret communication, limiting scalability as the number of parties grows. ADPSS constructions inevitably inherit these inefficiencies due to their tight coupling to the commitment-based ACSS and requiring at least quadratic cross-committee communication. To break these bottlenecks, we design GoSSamer, a concretely and asymptotically efficient protocol suite, where both our ACSS and ADPSS achieve (1) lightweight computation with only hash function and symmetric encryption; (2) asymptotically optimal, linear per-secret communication; (3) optimal resilience in asynchronous networks; and (4) postquantum security. In GoSSamer-ACSS, we propose an originalevaluation propagation paradigm for linear communication without commitment-requiring interpolation, which further unlocks our lightweight bivariate-polynomial-based degree checking for share verification. Building on this foundation, GoSSamer-ADPSS contributes two further techniques: a consistency verification technique that decouples the ADPSS framework from the commitment-based ACSS, and a dualcommittee reconstruction technique that yields linear per-secret communication. When deployed in distributed AWS instances, GoSSamer-ACSS reduces the runtime by 95.6 % compared to the linear-communication scheme hbACSS (NDSS'22) and 45.8%\mathbf{4 5. 8} \boldsymbol{\%} compared to lightweight SS24 (JoC'24). GoSSamerADPSS reduces the runtime by at least 67.7 % compared to LongLive (Usenix Security'23). Moreover, when applied to practical distributed key management systems, the GoSSamer-ACSS-based distributed key generation is 7−11×\mathbf{7}-\mathbf{1 1} \times faster than DXK+23 (Usenix Security'23), and GoSSamer-ADPSS-based key resharing reaches a throughput of 1994keys/s1994 \text{keys} / \mathrm{s} across 10 -node committees, compared to 85keys/s85 \text{keys} / \mathrm{s} in LongLive.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 095aee29-3bd4-4135-9011-89cfd055b744

Cited by top-tier papers1

Ask how each one uses it

Builds on19

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines