Exponent-VRFs and Their Applications
Dan Boneh, Iftach Haitner, Yehuda Lindell, Gil Segev
Abstract
Verifiable random functions (VRFs) are pseudorandom functions where the function owner can prove that a generated output is correct relative to a committed key. In this paper we introduce the notion of an exponent-VRF (eVRF): a VRF that does not provide its output explicitly, but instead provides , where is a generator of some finite cyclic group (or in multiplicative notation). We construct eVRFs from the Paillier encryption scheme and from DDH, both in the random-oracle model. We then show that an eVRF is a powerful tool that has many important applications in threshold cryptography. In particular, we construct (1) a one-round fully simulatable distributed key-generation protocol (after a single two-round initialization phase), (2) a two-round fully simulatable signing protocol for multiparty Schnorr with a deterministic variant, (3) a two-party ECDSA protocol that has a deterministic variant, (4) a threshold Schnorr signing protocol where the parties can later prove that they signed without being able to frame another group, and (5) an MPC-friendly and verifiable HD-derivation. All these applications are derived from this single new eVRF abstraction, and the resulting protocols are concretely efficient.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get d6119cdb-8a38-48d6-b0f5-789a9dede432Cited by top-tier papers5
- Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDHPaul Gerhart, Davide Li Calsi, Luigi Russo, Dominique SchröderEUROCRYPT 2026 · 1 citation
- Threshold ECDSA in Two RoundsYingjie Lyu, Zengpeng Li, Hong-Sheng Zhou, Xudong DengCCS 2025
- Adaptively-Secure Three-Round Threshold Schnorr from DLGuilhem Niot, Michael Reichle, Kaoru TakemureEUROCRYPT 2026
- Trout: Two-Round Threshold ECDSA from Class GroupsHila Dahari-Garbian, Ariel Nof, Luke ParkerCCS 2025
- Succinct Two-Round Two-Party Signing from PCFsLennart Braun, Geoffroy Couteau, Kelsey Melissaris, Mahshid Riahinia et al.CRYPTO 2026
Related papers
- Golden: Lightweight Non-interactive Distributed Key GenerationBenedikt Bünz, Kevin Choi, Chelsea KomloCRYPTO 2026
- High-throughput Verifiable Distributed OPRF from Gold PRFNan Cheng, Yohei Watanabe, Yugo Kasashima, Ioannis Katis et al.CCS 2026
- Two-Round Stateless Deterministic Two-Party Schnorr Signatures from Pseudorandom Correlation FunctionsYashvanth Kondi, Claudio Orlandi, Lawrence RoyCRYPTO 2023 · 19 citations
- Traceable Verifiable Random FunctionsDan Boneh, Aditi Partap, Lior RotemCRYPTO 2025 · 7 citations
- The Rise of Paillier: Homomorphic Secret Sharing and Public-Key Silent OTClaudio Orlandi, Peter Scholl, Sophia YakoubovEUROCRYPT 2021 · 85 citations
