On the Security of Two-Round Multi-Signatures
Manu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz, Julian Loss, Gregory Neven, Igors Stepanovs
Abstract
A multi-signature scheme allows a group of signers to collaboratively sign a message, creating a single signature that convinces a verifier that every individual signer approved the message. The increased interest in technologies to decentralize trust has triggered the proposal of highly efficient two-round Schnorr-based multi-signature schemes designed to scale up to thousands of signers, namely BCJ by Bagherzandi et al. (CCS 2008), MWLD by Ma et al. (DCC 2010), CoSi by Syta et al. (S&P 2016), and MuSig by Maxwell et al. (ePrint 2018). In this work, we point out serious security issues in all currently known two-round multi-signature schemes (without pairings). First, we prove that none of the schemes can be proved secure without radically departing from currently known techniques. Namely, we show that if the one-more discrete-logarithm problem is hard, then no algebraic reduction exists that proves any of these schemes secure under the discrete-logarithm or one-more discrete-logarithm problem. We point out subtle flaws in the published security proofs of the above schemes (except CoSi, which was not proved secure) to clarify the contradiction between our result and the existing proofs. Next, we describe practical sub-exponential attacks on all schemes, providing further evidence to their insecurity. Being left without two-round multi-signature schemes, we present mBCJ, a variant of the BCJ scheme that we prove secure under the discrete-logarithm assumption in the random-oracle model. Our experiments show that mBCJ barely affects scalability compared to CoSi, allowing 16384 signers to collaboratively sign a message in about 2 seconds, making it a highly practical and provably secure alternative for large-scale deployments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0b9541e7-c8d5-445d-95f0-fb54291a218fCited by top-tier papers14
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Verifiable Timed Signatures Made PracticalSri Aravinda Krishnan Thyagarajan, Adithya Bhat, Giulio Malavolta, Nico Döttling et al.CCS 2020 · 58 citations
- MuSig-L: Lattice-Based Multi-signature with Single-Round Online PhaseCecilia Boschini, Akira Takahashi, Mehdi TibouchiCRYPTO 2022 · 54 citations
- ROAST: Robust Asynchronous Schnorr Threshold SignaturesTim Ruffing, Viktoria Ronge, Elliott Jin, Jonas Schneider-Bensch et al.CCS 2022 · 50 citations
- Threshold and Multi-signature Schemes from Linear Hash FunctionsStefano Tessaro, Chenzhi ZhuEUROCRYPT 2023 · 48 citations
Builds on5
- OmniLedger: A Secure, Scale-Out, Decentralized Ledger via ShardingEleftherios Kokoris-Kogias, Philipp Jovanovic, Linus Gasser, Nicolas Gailly et al.S&P 2018 · 1,145 citations
- Enhancing Bitcoin Security and Performance with Strong Consistency via Collective SigningEleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly, Ismail Khoffi et al.USENIX Security 2016 · 769 citations
- Scalable Bias-Resistant Distributed RandomnessEwa Syta, Philipp Jovanovic, Eleftherios Kokoris-Kogias, Nicolas Gailly et al.S&P 2017 · 327 citations
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky et al.S&P 2016 · 285 citations
- CHAINIAC: Proactive Software-Update Transparency via Collectively Signed Skipchains and Verified BuildsKirill Nikitin, Eleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly et al.USENIX Security 2017 · 144 citations
Related papers
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 147 citations
- Two-Round Trip Schnorr Multi-signatures via Delinearized WitnessesHandan Kilinç Alper, Jeffrey BurdgesCRYPTO 2021 · 53 citations
- Chopsticks: Fork-Free Two-Round Multi-signatures from Non-interactive AssumptionsJiaxin Pan, Benedikt WagnerEUROCRYPT 2023 · 24 citations
- MuSig-DN: Schnorr Multi-Signatures with Verifiably Deterministic NoncesJonas Nick, Tim Ruffing, Yannick Seurin, Pieter WuilleCCS 2020 · 2 citations
- Two-Round Threshold Signature from Algebraic One-More Learning with ErrorsThomas Espitau, Shuichi Katsumata, Kaoru TakemureCRYPTO 2024 · 25 citations
