On the Adaptive Security of the Threshold BLS Signature Scheme
Renas Bacho, Julian Loss
Abstract
Threshold signatures are a crucial tool for many distributed protocols. As shown by Cachin, Kursawe, and Shoup (PODC '00), schemes with unique signatures are of particular importance, as they allow to implement distributed coin flipping very efficiently and without any timing assumptions. This makes them an ideal building block for (inherently randomized) asynchronous consensus protocols. The threshold-BLS signature of Boldyreva (PKC '03) is both unique and very compact, but unfortunately lacks a security proof against adaptive adversaries. Thus, current consensus protocols either rely on less efficient alternatives or are not adaptively secure. In this work, we revisit the security of the threshold BLS signature by showing the following results, assuming t adaptive corruptions: - We give a modular security proof that follows a two-step approach: 1) We introduce a new security notion for distributed key generation protocols (DKG). We show that it is satisfied by several protocols that previously only had a static security proof. 2) Assuming any DKG protocol with this property, we then prove unforgeability of the threshold BLS scheme. Our reductions are tight and can be used to substantiate real-world parameter choices. - To justify our use of strong assumptions such as the algebraic group model (AGM) and the hardness of one-more-discrete logarithm (OMDL), we prove an impossibility result: Even in the AGM, a strong interactive assumption is required in order to prove the scheme secure.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 2015fc4d-d9cd-4d6d-94da-b07ae1339471Cited by top-tier papers14
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Bingo: Adaptivity and Asynchrony in Verifiable Secret Sharing and Distributed Key GenerationIttai Abraham, Philipp Jovanovic, Mary Maller, Sarah Meiklejohn et al.CRYPTO 2023 · 33 citations
- FlexiRand: Output Private (Distributed) VRFs and Application to BlockchainsAniket Kate, Easwar Vivek Mangipudi, Siva Maradana, Pratyay MukherjeeCCS 2023 · 11 citations
- Unmasking TRaccoon: A Lattice-Based Threshold Signature with An Efficient Identifiable Abort ProtocolRafaël Del Pino, Shuichi Katsumata, Guilhem Niot, Michael Reichle et al.CRYPTO 2025 · 8 citations
- An Extended Hierarchy of Security Notions for Threshold Signature Schemes and Automated Analysis of Protocols That Use ThemCas Cremers, Aleksi Peltonen, Mang ZhaoCCS 2026 · 4 citations
Related papers
- Adaptively Secure BLS Threshold Signatures from DDH and co-CDHSourav Das, Ling RenCRYPTO 2024 · 40 citations
- On the Adaptive Security of Key-Unique Threshold SignaturesMichele Ciampi, Elizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2026
- Adaptively Secure Partially Non-interactive Threshold Schnorr Signatures in the AGMRenas Bacho, Yanbo Chen, Julian Loss, Stefano Tessaro et al.EUROCRYPT 2026 · 5 citations
- On the Adaptive Security of FROSTElizabeth C. Crites, Jonathan Katz, Chelsea Komlo, Stefano Tessaro et al.CRYPTO 2025 · 9 citations
- Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDHPaul Gerhart, Davide Li Calsi, Luigi Russo, Dominique SchröderEUROCRYPT 2026 · 1 citation
