Lune

CRYPTO2026Top-tier venue

Golden: Lightweight Non-interactive Distributed Key Generation

Benedikt Bünz, Kevin Choi, Chelsea Komlo

2026Year

Abstract

We present Golden, a non-interactive Distributed Key Generation (DKG) protocol. Golden achieves public verifiability in a lightweight, non-interactive manner, outputting Shamir secret shares of a field element sk∈Zp\mathsf{sk} \in \mathbb{Z}_p to all participants, and a public key PK=gsk\mathsf{PK}= g^{\mathsf{sk}} that is a discrete-logarithm commitment to sk.

Golden avoids the overhead of public-key encryption schemes like ElGamal, Pallier, or class groups by using a novel building block: a two-party exponent Verifiable Random Function (two-party eVRF), which may be of independent interest. We present a concretely efficient construction based on the Diffie-Hellman non-interactive key exchange and an efficient zero-knowledge proof. DKG participants use this two-party eVRF in a pairwise manner to generate a one-time pad to encrypt shares, while maintaining public verifiability. Golden can be securely instantiated in the random oracle model over any elliptic curve for which the discrete logarithm assumption holds.

Golden drastically improves efficiency, compared to other non-interactive DKGs. For 50 participants, Golden requires only 223 kb bandwidth and 13.5 seconds of total runtime for each participant, in comparison to ElGamal-based non-interactive DKG, which requires 27.8 MB bandwidth and 40.5 seconds runtime per participant.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get af9d63d8-4675-4d2b-8024-a405fa19cca1

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines