Lune

CCS2026顶会

Practical Silent Threshold Signatures and Silent Threshold Encryption for Dynamic Committees

Yifei He, Zheng Zhou, Yu Chen, Zhi Guan, Zhong Chen

出版方
2026年份

摘要

Silent threshold signatures (STS) and encryption (STE) enable threshold cryptography without interactive distributed key generation, allowing a group of NN parties to non-interactively generate a joint public signature verification key or an encryption key. However, modern distributed systems (such as Ethereum) rely on small, dynamically changing committees of size n≪Nn \ll N for efficiency, and existing silent threshold schemes either fail to support this dynamic setting or suffer from severe scalability issues. To the best of our knowledge, the only prior STS construction for dynamic committees, Dyna-hinTS, requires an aggregation time of O(Nlog⁡N)O(N\log N) per epoch, tightly coupling the cost to the global system size rather than the small active committee. Furthermore, no STE scheme for dynamic committees has been proposed yet.

In this work, we present practical silent threshold signature and encryption schemes for dynamic committees, reducing the aggregation cost so that it depends only on the committee size nn. For signatures, we redesign the Dyna-hinTS framework by replacing its Plonk-style SNARKs with linear pairing checks and a new polynomial commitment for representing the committee, yielding an aggregation time of O(nlog⁡2n)O(n\log^2n). We also introduce the first silent threshold encryption scheme for dynamic committees with matching efficiency. We further significantly optimize the silent setup phase common to prior STS and STE schemes, reducing each party’s one-time setup (i.e., generating the setup data, referred to as a "hint") cost from O(N2)O(N^2) to O(N)O(N).

We implement our schemes in Rust, and the results demonstrate practicality at scale. For a system parameterized with N=220N = 2^{20} and n=210n = 2^{10}, the per-party hint generation takes 197 seconds, and signature aggregation takes 0.153 seconds, achieving a >1900×>1900\times improvement over Dyna-hinTS. At the same time, our aggregated signature size, verification key size, and verification time (with access to the epoch committee representation) remain constant.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖