MuSig-DN: Schnorr Multi-Signatures with Verifiably Deterministic Nonces
Jonas Nick, Tim Ruffing, Yannick Seurin, Pieter Wuille
摘要
MuSig is a multi-signature scheme for Schnorr signatures, which supports key aggregation and is secure in the plain public key model. Standard derandomization techniques for discrete logarithm-based signatures such as RFC 6979, which make the signing procedure immune to catastrophic failures in the randomness generation, are not applicable to multi-signatures as an attacker could trick an honest user into producing two different partial signatures with the same randomness, which would reveal the user's secret key. In this paper, we propose a variant of MuSig in which signers generate their nonce deterministically as a pseudorandom function of the message and all signers' public keys and prove that they did so by providing a non-interactive zero-knowledge proof to their cosigners. The resulting scheme, which we call MuSig-DN, is the first Schnorr multi-signature scheme with deterministic signing. Therefore its signing protocol is robust against failures in the randomness generation as well as attacks trying to exploit the statefulness of the signing procedure, e.g., virtual machine rewinding attacks. As an additional benefit, a signing session in MuSig-DN requires only two rounds instead of three as required by all previous Schnorr multi-signatures including MuSig. To instantiate our construction, we identify a suitable algebraic pseudorandom function and provide an efficient implementation of this function as an arithmetic circuit. This makes it possible to realize MuSig-DN efficiently using zero-knowledge proof frameworks for arithmetic circuits which support inputs given in Pedersen commitments, e.g., Bulletproofs. We demonstrate the practicality of our technique by implementing it for the secp256k1 elliptic curve used in Bitcoin.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- MuSig-L: Lattice-Based Multi-signature with Single-Round Online PhaseCecilia Boschini, Akira Takahashi, Mehdi TibouchiCRYPTO 2022 · 被引用 54 次
- ROAST: Robust Asynchronous Schnorr Threshold SignaturesTim Ruffing, Viktoria Ronge, Elliott Jin, Jonas Schneider-Bensch 等CCS 2022 · 被引用 50 次
- Threshold and Multi-signature Schemes from Linear Hash FunctionsStefano Tessaro, Chenzhi ZhuEUROCRYPT 2023 · 被引用 48 次
- Threshold Schnorr with Stateless Deterministic Signing from Standard AssumptionsFrançois Garillot, Yashvanth Kondi, Payman Mohassel, Valeria NikolaenkoCRYPTO 2021 · 被引用 39 次
- Tight State-Restoration Soundness in the Algebraic Group ModelAshrujit Ghoshal, Stefano TessaroCRYPTO 2021 · 被引用 27 次
它引用的顶会 Paper4
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra 等S&P 2018 · 被引用 1,285 次
- On the Security of Two-Round Multi-SignaturesManu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz 等S&P 2019 · 被引用 126 次
- A Formal Treatment of Deterministic WalletsPoulami Das, Sebastian Faust, Julian LossCCS 2019 · 被引用 62 次
- Succinct Arguments for Bilinear Group Arithmetic: Practical Structure-Preserving CryptographyRussell W. F. Lai, Giulio Malavolta, Viktoria RongeCCS 2019 · 被引用 50 次
相关 Paper
- Schnorr Signatures and MuSig2 are Jointly Secure, Even in Deterministic WalletsRenas Bacho, Yanbo Chen, Poulami Das, Julian Loss 等CCS 2026
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 被引用 147 次
- Two-Round Stateless Deterministic Two-Party Schnorr Signatures from Pseudorandom Correlation FunctionsYashvanth Kondi, Claudio Orlandi, Lawrence RoyCRYPTO 2023 · 被引用 19 次
- Concurrently Secure Blind Schnorr SignaturesGeorg Fuchsbauer, Mathias WolfEUROCRYPT 2024 · 被引用 25 次
- On the Multi-user Security of Short Schnorr Signatures with PreprocessingJeremiah Blocki, Seunghoon LeeEUROCRYPT 2022 · 被引用 8 次
