On the Security of ECDSA with Additive Key Derivation and Presignatures
Jens Groth, Victor Shoup
摘要
Two common variations of ECDSA signatures are additive key derivation and presignatures. Additive key derivation is a simple mechanism for deriving many subkeys from a single master key, and is already widely used in cryptocurrency applications with the Hierarchical Deterministic Wallet mechanism standardized in Bitcoin Improvement Proposal 32 (BIP32). Because of its linear nature, additive key derivation is also amenable to efficient implementation in the threshold setting. With presignatures, the secret and public nonces used in the ECDSA signing algorithm are precomputed. In the threshold setting, using presignatures along with other precomputed data allows for an extremely efficient "online phase" of the protocol. Recent works have advocated for both of these variations, sometimes combined together. However, somewhat surprisingly, we are aware of no prior security proof for additive key derivation, let alone for additive key derivation in combination with presignatures.
In this paper, we provide a thorough analysis of these variations, both in isolation and in combination. Our analysis is in the generic group model (GGM). Importantly, we do not modify ECDSA or weaken the standard notion of security in any way. Of independent interest, we also present a version of the GGM that is specific to elliptic curves. This EC-GGM better models some of the idiosyncrasies (such as the conversion function and malleability) of ECDSA. In addition to this analysis, we report security weaknesses in these variations that apparently have not been previously reported. For example, we show that when both variations are combined, there is a cube-root attack on ECDSA, which is much faster than the best known, square-root attack on plain ECDSA. We also present two mitigations against these weaknesses: re-randomized presignatures and homogeneous key derivation. Each of these mitigations is very lightweight, and when used in combination, the security is essentially the same as that of plain ECDSA (in the EC-GGM).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Low-Bandwidth Threshold ECDSA via Pseudorandom Correlation GeneratorsDamiano Abram, Ariel Nof, Claudio Orlandi, Peter Scholl 等S&P 2022 · 被引用 51 次
- Decentralized and Stateful Serverless Computing on the Internet Computer BlockchainMaksym Arutyunyan, Andriy Berestovskyy, Adam Bratschi-Kaye, Ulan Degenbaev 等USENIX ATC 2023 · 被引用 10 次
- Demystifying and Detecting Cryptographic Defects in Ethereum Smart ContractsJiashuo Zhang, Yiming Shen, Jiachi Chen, Jianzhong Su 等ICSE 2025 · 被引用 2 次
- Accountable authentication with privacy protection: The Larch system for universal loginEmma Dauterman, Danny Lin, Henry Corrigan-Gibbs, David MazièresOSDI 2023 · 被引用 2 次
- Threshold ECDSA in Two RoundsYingjie Lyu, Zengpeng Li, Hong-Sheng Zhou, Xudong DengCCS 2025
它引用的顶会 Paper2
相关 Paper
- Secure Two-party Threshold ECDSA from ECDSA AssumptionsJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2018 · 被引用 171 次
- Robust Threshold ECDSA with Online-Friendly Design in Three RoundsGuofeng Tang, Haiyang XueS&P 2025
- Efficient Online-friendly Two-Party ECDSA SignatureHaiyang Xue, Man Ho Au, Xiang Xie, Tsz Hon Yuen 等CCS 2021 · 被引用 31 次
- Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency CustodyYehuda Lindell, Ariel NofCCS 2018 · 被引用 220 次
- UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable AbortsRan Canetti, Rosario Gennaro, Steven Goldfeder, Nikolaos Makriyannis 等CCS 2020 · 被引用 135 次
