Threshold Signatures with Private Accountability
Dan Boneh, Chelsea Komlo
Abstract
Existing threshold signature schemes come in two flavors: (i) fully private, where the signature reveals nothing about the set of signers that generated the signature, and (ii) accountable, where the signature completely identifies the set of signers. In this paper we propose a new type of threshold signature, called TAPS, that is a hybrid of privacy and accountability. A TAPS signature is fully private from the public's point of view. However, an entity that has a secret tracing key can trace a signature to the threshold of signers that generated it. A TAPS makes it possible for an organization to keep its inner workings private, while ensuring that signers are accountable for their actions. We construct a number of TAPS schemes. First, we present a generic construction that builds a TAPS from any accountable threshold signature. This generic construction is not efficient, and we next focus on efficient schemes based on standard assumptions. We build two efficient TAPS schemes (in the random oracle model) based on the Schnorr signature scheme. We conclude with a number of open problems relating to efficient TAPS.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext df3d7c7c-5f31-4454-a97c-df5f79423ed8Cited by top-tier papers3
- An Extended Hierarchy of Security Notions for Threshold Signature Schemes and Automated Analysis of Protocols That Use ThemCas Cremers, Aleksi Peltonen, Mang ZhaoCCS 2026 · 4 citations
- Breaking Omertà: On Threshold Cryptography, Smart Collusion, and WhistleblowingMahimna Kelkar, Aadityan Ganesh, Aditi Partap, Joseph Bonneau et al.CCS 2025 · 1 citation
- Vitārit: Paying for Threshold Services on Bitcoin and FriendsSri Aravinda Krishnan Thyagarajan, Easwar Vivek Mangipudi, Lucjan Hanzlik, Aniket Kate et al.S&P 2025
Builds on4
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 147 citations
- Compressed -Protocol Theory and Practical Application to Plug & Play Secure AlgorithmicsThomas Attema, Ronald CramerCRYPTO 2020 · 73 citations
- Traceable Secret Sharing and ApplicationsVipul Goyal, Yifan Song, Akshayaram SrinivasanCRYPTO 2021 · 29 citations
Related papers
- Multimodal Private SignaturesKhoa Nguyen, Fuchun Guo, Willy Susilo, Guomin YangCRYPTO 2022 · 19 citations
- A Plausible Attack on the Adaptive Security of Threshold Schnorr SignaturesElizabeth C. Crites, Alistair StewartCRYPTO 2025 · 11 citations
- hinTS: Threshold Signatures with Silent SetupSanjam Garg, Abhishek Jain, Pratyay Mukherjee, Rohit Sinha et al.S&P 2024 · 48 citations
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Membership Privacy for Fully Dynamic Group SignaturesMichael Backes, Lucjan Hanzlik, Jonas Schneider-BenschCCS 2019 · 30 citations
