Toothpicks: More Efficient Fork-Free Two-Round Multi-signatures
Jiaxin Pan, Benedikt Wagner
Abstract
Tightly secure cryptographic schemes can be implemented with standardized parameters, while still having a sufficiently high security level backed up by their analysis. In a recent work, Pan and Wagner (Eurocrypt 2023) presented the first tightly secure two-round multi-signature scheme without pairings, called Chopsticks. While this is an interesting first theoretical step, Chopsticks is much less efficient than its non-tight counterparts.
In this work, we close this gap by proposing a new tightly secure two-round multi-signature scheme that is as efficient as non-tight schemes. Our scheme is based on the DDH assumption without pairings. Compared to Chopsticks, we reduce the signature size by more than a factor of 3 and the communication complexity by more than a factor of 2.
Technically, we achieve this as follows: (1) We develop a new pseudorandom path technique, as opposed to the pseudorandom matching technique in Chopsticks. (2) We construct a more efficient commitment scheme with suitable properties, which is an important primitive in both our scheme and Chopsticks. Surprisingly, we observe that the commitment scheme does not have to be binding, enabling our efficient construction.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers2
- Pairing-Free Blind Signatures from CDH AssumptionsRutchathon Chairattana-Apirom, Stefano Tessaro, Chenzhi ZhuCRYPTO 2024 · 18 citations
- Adaptively-Secure Three-Round Threshold Schnorr from DLGuilhem Niot, Michael Reichle, Kaoru TakemureEUROCRYPT 2026
Related papers
- Chopsticks: Fork-Free Two-Round Multi-signatures from Non-interactive AssumptionsJiaxin Pan, Benedikt WagnerEUROCRYPT 2023 · 24 citations
- Earpicks: Tightly Secure Two-Round Multi and Threshold SignaturesRenas Bacho, Yanbo ChenEUROCRYPT 2026 · 1 citation
- T-Spoon: Tightly Secure Two-Round Multi-signatures with Key AggregationRenas Bacho, Benedikt WagnerCRYPTO 2025 · 6 citations
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 147 citations
- Adaptively Secure Three-Round Threshold Schnorr Signatures from DDHRenas Bacho, Sourav Das, Julian Loss, Ling RenCRYPTO 2025 · 12 citations
