Diogenes: Lightweight Scalable RSA Modulus Generation with a Dishonest Majority
Megan Chen, Carmit Hazay, Yuval Ishai, Yuriy Kashnikov, Daniele Micciancio, Tarik Riviere, Abhi Shelat, Muthuramakrishnan Venkitasubramaniam, Ruihan Wang
Abstract
In this work, we design and implement the first protocol for distributed generation of an RSA modulus that can support thousands of parties and offers security against active corruption of an arbitrary number of parties. In a nutshell, we first design a highly optimized protocol for this scale that is secure against passive corruptions, and then amplify its security to withstand active corruptions using lightweight succinct zero-knowledge proofs. Our protocol achieves security with "identifiable abort," where a corrupted party is identified whenever the protocol aborts, and supports public verifiability.Our protocol against passive corruptions extends the recent work of Chen et al. (CRYPTO 2020) that, in turn, is based on the blueprint introduced in the original work of Boneh-Franklin protocol (CRYPTO 1997, J. ACM, 2001). Specifically, we reduce the task of sampling a modulus to secure distributed multiplication, which we implement via an efficient threshold additively homomorphic encryption scheme based on the Ring-LWE assumption. This results in a protocol where the (amortized) per-party communication cost grows logarithmically in the number of parties. In order to minimize the work done by the parties, we employ a "publicly verifiable" coordinator that is connected to all parties and only performs computations on public data.We implemented both the passive and the active variants of our protocol and ran experiments using 2 to 4,000 parties. This is the first implementation of any MPC protocol that can scale to more than 1,000 parties. For generating a 2048-bit modulus among 1,000 parties, our passive protocol executed in under 6 minutes and the active variant ran in under 25 minutes.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 2e7094f1-ff3e-41c7-a7e8-773cac8c7a90Cited by top-tier papers4
- Secure Distributed RSA Modulus Generation Revisited: A Faster and More Communication-Efficient ConstructionShaojing Zhang, Chengliang Tian, Ruixue Wang, Hequn Xian et al.USENIX Security 2026
- hbACSS: How to Robustly Share Many SecretsThomas Yurek, Licheng Luo, Jaiden Fairoze, Aniket Kate et al.NDSS 2022
- Threshold ECDSA in Two RoundsYingjie Lyu, Zengpeng Li, Hong-Sheng Zhou, Xudong DengCCS 2025
- Curve Trees: Practical and Transparent Zero-Knowledge AccumulatorsMatteo Campanelli, Mathias Hall-Andersen, Simon Holmgaard KampUSENIX Security 2023
Related papers
- Trout: Two-Round Threshold ECDSA from Class GroupsHila Dahari-Garbian, Ariel Nof, Luke ParkerCCS 2025
- Improved Distributed RSA Key Generation Using the Miller-Rabin TestJakob Burkhardt, Ivan Damgård, Tore Kasper Frederiksen, Satrajit Ghosh et al.CCS 2023 · 10 citations
- The Return of Eratosthenes: Secure Generation of RSA Moduli using Distributed SievingCyprien Delpech de Saint Guilhem, Eleftheria Makri, Dragos Rotaru, Titouan TanguyCCS 2021 · 1 citation
- Multiparty Generation of an RSA ModulusMegan Chen, Ran Cohen, Jack Doerner, Yashvanth Kondi et al.CRYPTO 2020 · 24 citations
- Fast Fully Secure Multi-Party Computation over Any Ring with Two-Thirds Honest MajorityAnders P. K. Dalskov, Daniel Escudero, Ariel NofCCS 2022 · 17 citations
