Publicly Verifiable Secret Sharing Over Class Groups and Applications to DKG and YOSO
Ignacio Cascudo, Bernardo David
Abstract
. Publicly Verifiable Secret Sharing (PVSS) allows a dealer to publish encrypted shares of a secret so that parties holding the corresponding decryption keys may later reconstruct it. Both dealing and reconstruction are non-interactive and any verifier can check their validity. PVSS finds applications in randomness beacons, distributed key generation (DKG) and in YOSO MPC (Gentry et al. CRYPTO’21), when endowed with suitable publicly verifiable re-sharing as in YOLO YOSO (Cascudo et al. ASIACRYPT’22). We introduce a PVSS scheme over class groups that achieves similar efficiency to state-of-the art schemes that only allow for reconstructing a function of the secret, while our scheme allows the reconstruction of the original secret. Our construction generalizes the DDH-based scheme of YOLO YOSO to operate over class groups, which poses technical challenges in adapting the necessary NIZKs in face of the unknown group order and the fact that efficient NIZKs of knowledge are not as simple to construct in this setting. Building on our PVSS scheme’s ability to recover the original secret, we propose two DKG protocols for discrete logarithm key pairs: a biasable 1-round protocol, which improves on the concrete communication/computational complexities of previous works; and a 2-round unbiasable protocol, which improves on the round complexity of previous works. We also add publicly verifiable resharing towards anonymous committees to our PVSS, so that it can be used to efficiently transfer state among committees in the YOSO setting. Together with a recent construction of MPC in the YOSO model based on class groups (Braun et al. CRYPTO’23), this results in the most efficient full realization ( i.e. without assuming receiver anonymous channels) of YOSO MPC based on the CDN framework with transparent setup.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8b2a89bc-27ae-47e4-9820-93389f2c7c24Cited by top-tier papers9
- Distributed Randomness Using Weighted VUFsSourav Das, Benny Pinkas, Alin Tomescu, Zhuolun XiangEUROCRYPT 2025 · 7 citations
- sfOPA: One-Shot Private Aggregation with Single Client Interaction and Its Applications to Federated LearningHarish Karthikeyan, Antigoni PolychroniadouCRYPTO 2025 · 1 citation
- Practical Mempool Privacy via One-time Setup Batched Threshold EncryptionArka Rai Choudhuri, Sanjam Garg, Guru-Vamsi Policharla, Mingyuan WangUSENIX Security 2025
- Secure Multiparty Computation of Threshold Signatures Made More EfficientHarry W. H. Wong, Jack P. K. Ma, Sherman S. M. ChowNDSS 2024
- NFSA: Non-Forward Secure Aggregation with One Server via Two Layer Secret SharingYufei ZhouCCS 2026
Related papers
- Adaptively Secure (Aggregatable) PVSS from Standard AssumptionsRenas Bacho, Yanbo Chen, Julian LossCRYPTO 2026
- Adaptively Secure (Aggregatable) PVSS and Application to Distributed Randomness BeaconsRenas Bacho, Julian LossCCS 2023 · 7 citations
- Practical Non-interactive Publicly Verifiable Secret Sharing with Thousands of PartiesCraig Gentry, Shai Halevi, Vadim LyubashevskyEUROCRYPT 2022 · 65 citations
- Non-interactive VSS using Class Groups and Application to DKGAniket Kate, Easwar Vivek Mangipudi, Pratyay Mukherjee, Hamza Saleem et al.CCS 2024 · 13 citations
- Secure Multiparty Computation from Threshold Encryption Based on Class GroupsLennart Braun, Ivan Damgård, Claudio OrlandiCRYPTO 2023 · 47 citations
