UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable Aborts
Ran Canetti, Rosario Gennaro, Steven Goldfeder, Nikolaos Makriyannis, Udi Peled
Abstract
Building on the Gennaro & Goldfeder and Lindell & Nof protocols (CCS '18), we present two threshold ECDSA protocols, for any number of signatories and any threshold, that improve as follows over the state of the art: -- For both protocols, only the last round requires knowledge of the message, and the other rounds can take place in a preprocessing stage, lending to a non-interactive threshold ECDSA protocol. -- Both protocols withstand adaptive corruption of signatories. Furthermore, they include a periodic refresh mechanism and offer full proactive security. -- Both protocols realize an ideal threshold signature functionality within the UC framework, in the global random oracle model, assuming Strong RSA, DDH, semantic security of the Paillier encryption, and a somewhat enhanced variant of existential unforgeability of ECDSA. -- Both protocols achieve accountability by identifying corrupted parties in case of failure to generate a valid signature. The two protocols are distinguished by the round-complexity and the identification process for detecting cheating parties. Namely: -- For the first protocol, signature generation takes only 4 rounds (down from the current state of the art of 8 rounds), but the identification process requires computation and communication that is quadratic in the number of parties. -- For the second protocol, the identification process requires computation and communication that is only linear in the number of parties, but signature generation takes 7 rounds. These properties (low latency, compatibility with cold-wallet architectures, proactive security, identifiable abort and composable security) make the two protocols ideal for threshold wallets for ECDSA-based cryptocurrencies.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e5db2fa9-1731-45b3-b4dc-fecbf69f7da2Cited by top-tier papers18
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Better than Advertised Security for Non-interactive Threshold SignaturesMihir Bellare, Elizabeth C. Crites, Chelsea Komlo, Mary Maller et al.CRYPTO 2022 · 71 citations
- ROAST: Robust Asynchronous Schnorr Threshold SignaturesTim Ruffing, Viktoria Ronge, Elliott Jin, Jonas Schneider-Bensch et al.CCS 2022 · 50 citations
- Practical Schnorr Threshold Signatures Without the Algebraic Group ModelHien Chu, Paul Gerhart, Tim Ruffing, Dominique SchröderCRYPTO 2023 · 38 citations
- PEReDi: Privacy-Enhanced, Regulated and Distributed Central Bank Digital CurrenciesAggelos Kiayias, Markulf Kohlweiss, Amirreza SarenchehCCS 2022 · 33 citations
Related papers
- Threshold ECDSA from ECDSA Assumptions: The Multiparty CaseJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2019 · 167 citations
- Secure Two-party Threshold ECDSA from ECDSA AssumptionsJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2018 · 171 citations
- Low-Bandwidth Threshold ECDSA via Pseudorandom Correlation GeneratorsDamiano Abram, Ariel Nof, Claudio Orlandi, Peter Scholl et al.S&P 2022 · 51 citations
- Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency CustodyYehuda Lindell, Ariel NofCCS 2018 · 220 citations
- Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDHPaul Gerhart, Davide Li Calsi, Luigi Russo, Dominique SchröderEUROCRYPT 2026 · 1 citation
