Schnorr Signatures and MuSig2 are Jointly Secure, Even in Deterministic Wallets
Renas Bacho, Yanbo Chen, Poulami Das, Julian Loss, Tim Ruffing, Benedikt Wagner
Abstract
Modern cryptocurrency wallets use Schnorr signatures together with public, deterministic key derivation: by repeatedly rerandomizing a single master public key, an unlimited number of public keys for incoming payments can be derived without access to secret data. Moreover, some wallets support multi-signature schemes such as MuSig2 for optionally aggregating derived public keys from distinct parties into "-of-" public keys, so that funds received on such aggregated keys can be spent only when authorized by all parties. However, these advanced key-management techniques stretch the underlying cryptographic schemes beyond the guarantees provided by existing security proofs. Although deterministic Schnorr wallets and MuSig2 have each been proven secure in isolation, the provable security of their composition---despite its deployment in wallets---has not been established thus far.
The goal of this work is to narrow this gap between theory and practice. We provide the first formal security analysis of the joint use of single-signer Schnorr signatures and MuSig2, both under rerandomization and in deterministic wallets. First, we introduce the notion of a (rerandomizable) joint-signature scheme, in which an honest signer uses the same secret key for single-signer signatures and multi-signatures. Within this model, we prove tight security of Schnorr signatures plus MuSig2 under the algebraic one-more discrete logarithm (AOMDL) assumption in the combination of the algebraic group model (AGM) and the random oracle model (ROM). Finally, we provide a formal model of deterministic wallets with joint-signature schemes and show that Schnorr plus MuSig2 remains secure under public, deterministic key derivation.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- MuSig-DN: Schnorr Multi-Signatures with Verifiably Deterministic NoncesJonas Nick, Tim Ruffing, Yannick Seurin, Pieter WuilleCCS 2020 · 2 citations
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 147 citations
- Deterministic Wallets in a Quantum WorldNabil Alkeilani Alkadri, Poulami Das, Andreas Erwig, Sebastian Faust et al.CCS 2020 · 6 citations
- A Formal Treatment of Deterministic WalletsPoulami Das, Sebastian Faust, Julian LossCCS 2019 · 62 citations
- MuSig-L: Lattice-Based Multi-signature with Single-Round Online PhaseCecilia Boschini, Akira Takahashi, Mehdi TibouchiCRYPTO 2022 · 54 citations
