Lune

CRYPTO2025顶会

Traceable Verifiable Random Functions

Dan Boneh, Aditi Partap, Lior Rotem

2025年份
7被引次数

摘要

A threshold verifiable random function (threshold VRF) is a VRF where the evaluation key is secret shared among nn parties, and a quorum of tt parties is needed to evaluate the VRF. Threshold VRFs are used widely in practice in applications such as randomness beacons and deterministic wallets. Despite their long history, the question of accountability for leaking key shares in a threshold VRF has not been studied. Specifically, consider a set of ff parties who use their key shares to create an evaluation box EE that lets anyone evaluate the VRF at any point in the domain of the VRF. When ff is less than the threshold tt, this box EE must also take as input t−ft-f additional evaluation shares. Our goal is to design a threshold VRF where there is a tracing algorithm that can trace any such box EE to the coalition of ff parties that created it, using only blackbox access to EE. The risk of tracing should deter the coalition from selling such a box. Questions in this vein were previously explored in the context of threshold decryption and secret sharing. Here we define and study traceability for a threshold VRF.

Our traceable threshold VRF is built from a VRF based on Paillier encryption. The starting point for our tracing algorithm is the tracing technique of Boneh-Partap-Rotem (Crypto 2024) designed for tracing leaks in the context of secret sharing. However, there are multiple technical challenges in making this approach work, and we develop the necessary tools to overcome all these challenges. The end result is a threshold VRF with a provably secure tracing algorithm.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖