USENIX Security2024Top-tier venue
Pixel+ and Pixel++: Compact and Efficient Forward-Secure Multi-Signatures for PoS Blockchain Consensus
Jianghong Wei, Guohua Tian, Ding Wang, Fuchun Guo, Willy Susilo, Xiaofeng Chen
Abstract
Multi-signature schemes have attracted considerable attention in recent years due to their popular applications in PoS blockchains. However, the use of general multi-signature schemes poses a critical threat to the security of PoS blockchains once signing keys get corrupted. That is, after an adversary obtains enough signing keys, it can break the immutable nature of PoS blockchains by forking the chain and modifying the history from some point in the past. Forwardsecure multi-signature (FS-MS) schemes can overcome this issue by periodically updating signing keys. The only FS-MS construction currently available is Drijvers et al's Pixel, which builds on pairing groups and only achieves forward security at the time period level. In this work, we present new FS-MS constructions that either are free from pairing or capture forward security at the individual message level (i.e., fine-grained forward security). Our first construction Pixel+ works for a maximum number of time periods T . Pixel+ signatures consist of only one group element, and can be verified using two exponentiations. It is the first FS-MS from RSA assumption, and has 3.5x and 22.8x faster signing and verification than Pixel, respectively. Our second FS-MS construction Pixel++ is a pairing-based one. It immediately revokes the signing key's capacity of re-signing the message after creating a signature on this message, rather than at the end of the current time period. Thus, it provides more practical forward security than Pixel. On the other hand, Pixel++ is almost as efficient as Pixel in terms of signing and verification. Both Pixel+ and Pixel++ allow for non-interactive aggregation of signatures from independent signers and are proven to be secure in the random oracle model. In addition, they also support the aggregation of public keys, significantly reducing the storage overhead on PoS blockchains. We demonstrate how to integrate Pixel+ and Pixel++ into PoS blockchains. As a proof-of-concept, we provide implementations of Pixel+ and Pixel++, and conduct several representative experiments to show that Pixel+ and Pixel++ have good concrete efficiency and are practical.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- On the Limits of Consensus under Dynamic Availability and ReconfigurationJavier Nieto, Joachim Neu, Ling RenCCS 2026 · 2 citations
- Differential Trust: Dynamic Multi-Authority Anonymous Credentials with Epoch-Weighted UpdatesChen Li, Jianting Ning, Xiulong Liu, Yulin LiuUSENIX Security 2026
Builds on12
- Scalable Bias-Resistant Distributed RandomnessEwa Syta, Philipp Jovanovic, Eleftherios Kokoris-Kogias, Nicolas Gailly et al.S&P 2017 · 327 citations
- Ouroboros Genesis: Composable Proof-of-Stake Blockchains with Dynamic AvailabilityChristian Badertscher, Peter Gazi, Aggelos Kiayias, Alexander Russell et al.CCS 2018 · 306 citations
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky et al.S&P 2016 · 285 citations
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 147 citations
- On the Security of Two-Round Multi-SignaturesManu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz et al.S&P 2019 · 126 citations
Related papers
- Pixel: Multi-signatures for ConsensusManu Drijvers, Sergey Gorbunov, Gregory Neven, Hoeteck WeeUSENIX Security 2020
- Earpicks: Tightly Secure Two-Round Multi and Threshold SignaturesRenas Bacho, Yanbo ChenEUROCRYPT 2026 · 1 citation
- DahLIAS: Discrete Logarithm-Based Interactive Aggregate SignaturesJonas Nick, Tim Ruffing, Yannick SeurinEUROCRYPT 2026
- Chopsticks: Fork-Free Two-Round Multi-signatures from Non-interactive AssumptionsJiaxin Pan, Benedikt WagnerEUROCRYPT 2023 · 24 citations
- Putting Multi Into Multi-signatures: Tight Security for Multiple SignersAnja Lehmann, Cavit ÖzbayEUROCRYPT 2026
