Lune

EUROCRYPT2024顶会

SPRINT: High-Throughput Robust Distributed Schnorr Signatures

Fabrice Benhamouda, Shai Halevi, Hugo Krawczyk, Yiping Ma, Tal Rabin

2024年份
25被引次数
5顶会引用

摘要

We describe high-throughput threshold protocols with guaranteed output delivery for generating Schnorr-type signatures. The protocols run a single message-independent interactive ephemeral randomness generation procedure (e.g., DKG) followed by a non-interactive multi-message signature generation procedure. The protocols offer significant increase in throughput already for as few as ten parties while remaining highly-efficient for many hundreds of parties with thousands of signatures generated per minute (and over 10,000 in normal optimistic case).

These protocols extend seamlessly to the dynamic/proactive setting, where each run of the protocol uses a new committee, and they support sub-sampling the committees from among an effectively unbounded number of nodes. The protocols work over a broadcast channel in both synchronous and asynchronous networks.

The combination of these features makes our protocols a good match for implementing a signature service over an (asynchronous) public blockchain with many validators, where guaranteed output delivery is an absolute must. In that setting, there is a system-wide public key, where the corresponding secret signature key is distributed among the validators. Clients can submit messages (under suitable controls, e.g. smart contracts), and authorized messages are signed relative to the global public key.

Asymptotically, when running with committees of nn parties, our protocols can generate Ω(n2)\Omega(n^2) signatures per run, while providing resilience against Ω(n)\Omega(n) corrupted nodes, and using broadcast bandwidth of only O(n2)O(n^2) group elements and scalars. For example, we can sign about n2/16n^2/16 messages using just under 2n22n^2 total bandwidth while supporting resilience against n/4n/4 corrupted parties, or sign n2/8n^2/8 messages using just over 2n22n^2 total bandwidth with resilience against n/5n/5 corrupted parties.

We prove security of our protocols by reduction to the hardness of the discrete logarithm problem in the random-oracle model.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

lune papers get b59bae33-e34f-4e5f-b298-5584dfdd705a

引用它的顶会 Paper5

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖