Aggregatable Distributed Key Generation
Kobi Gurkan, Philipp Jovanovic, Mary Maller, Sarah Meiklejohn, Gilad Stern, Alin Tomescu
Abstract
In this paper, we introduce a distributed key generation (DKG) protocol with aggregatable and publicly-verifiable transcripts. Compared with prior publicly-verifiable approaches, our DKG reduces the size of the final transcript and the time to verify it from O(n 2 ) to O(n log n), where n denotes the number of parties. As compared with prior non-publicly-verifiable approaches, our DKG leverages gossip rather than all-to-all communication to reduce verification and communication complexity. We also revisit existing DKG security definitions, which are quite strong, and propose new and natural relaxations. As a result, we can prove the security of our aggregatable DKG as well as that of several existing DKGs, including the popular Pedersen variant. We show that, under these new definitions, these existing DKGs can be used to yield secure threshold variants of popular cryptosystems such as El-Gamal encryption and BLS signatures. We also prove that our DKG can be securely combined with a new efficient verifiable unpredictable function (VUF), whose security we prove in the random oracle model. Finally, we experimentally evaluate our DKG and show that the perparty overheads scale linearly and are practical. For 64 parties, it takes 71 ms to share and 359 ms to verify the overall transcript, while for 8192 parties, it takes 8 s and 42.2 s respectively. cLabs, Ethereum Foundation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers12
- Practical Asynchronous Distributed Key GenerationSourav Das, Thomas Yurek, Zhuolun Xiang, Andrew Miller et al.S&P 2022 · 136 citations
- Spurt: Scalable Distributed Randomness Beacon with Transparent SetupSourav Das, Vinith Krishnan, Irene Miriam Isaac, Ling RenS&P 2022 · 80 citations
- Bingo: Adaptivity and Asynchrony in Verifiable Secret Sharing and Distributed Key GenerationIttai Abraham, Philipp Jovanovic, Mary Maller, Sarah Meiklejohn et al.CRYPTO 2023 · 33 citations
- Distributed Randomness Using Weighted VUFsSourav Das, Benny Pinkas, Alin Tomescu, Zhuolun XiangEUROCRYPT 2025 · 7 citations
- Scalable and Adaptively Secure Any-Trust Distributed Key Generation and All-hands CheckpointingHanwen Feng, Tiancheng Mai, Qiang TangCCS 2024 · 4 citations
Builds on4
- Scalable Bias-Resistant Distributed RandomnessEwa Syta, Philipp Jovanovic, Eleftherios Kokoris-Kogias, Nicolas Gailly et al.S&P 2017 · 327 citations
- Asynchronous Distributed Key Generation for Computationally-Secure Randomness, Consensus, and Threshold SignaturesEleftherios Kokoris-Kogias, Dahlia Malkhi, Alexander SpiegelmanCCS 2020 · 107 citations
- Towards Scalable Threshold CryptosystemsAlin Tomescu, Robert Chen, Yiming Zheng, Ittai Abraham et al.S&P 2020 · 102 citations
- On the (in)security of ROSFabrice Benhamouda, Tancrède Lepoint, Julian Loss, Michele Orrù et al.EUROCRYPT 2021 · 74 citations
Related papers
- Golden: Lightweight Non-interactive Distributed Key GenerationBenedikt Bünz, Kevin Choi, Chelsea KomloCRYPTO 2026
- On the Adaptive Security of the Threshold BLS Signature SchemeRenas Bacho, Julian LossCCS 2022 · 75 citations
- Practical Asynchronous High-threshold Distributed Key Generation and Distributed Polynomial SamplingSourav Das, Zhuolun Xiang, Lefteris Kokoris-Kogias, Ling RenUSENIX Security 2023
- Exponent-VRFs and Their ApplicationsDan Boneh, Iftach Haitner, Yehuda Lindell, Gil SegevEUROCRYPT 2025 · 11 citations
- Network-Agnostic Security Comes (Almost) for Free in DKG and MPCRenas Bacho, Daniel Collins, Chen-Da Liu-Zhang, Julian LossCRYPTO 2023 · 19 citations
