arrow
Return

Efficient Lattice-Based Threshold Signatures With Functional Interchangeability

delete2023-01-01
delete5
PRE
AI
G
Guofeng Tang
B
Bo Pang
L
Long Chen
Z
Zhenfeng Zhang *
DOI:10.1109/TIFS.2023.3293408delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
A threshold signature scheme distributes the ability to generate signatures through distributed key generation and signing protocols. A threshold signature scheme should be functionally interchangeable, meaning that a signature produced by a threshold scheme should be verifiable by the same algorithm used for non-threshold signatures. To resist future attacks from quantum adversaries, lattice-based threshold signatures are desirable. However, the performance of existing lattice-based threshold signing protocols is still far from practical. This paper presents the first lattice-based t-out-of-n threshold signature scheme with functional interchangeability that has been implemented. To build an t-out-of-n access structure for arbitrary t <= n, we first present a novel t-out-of-n version of the SPDZ MPC protocol. We avoid using the MPC protocol to evaluate hash operations for high concrete efficiency. Moreover, we design an efficient distributed rejection sampling protocol. Consequently, the online phase of our distributed signing protocol takes only 0.5 seconds in the two-party setting and 7.3 seconds in the 12-party setting according to our implementation. As a byproduct, our scheme also presents a periodic key refreshment mechanism and offers proactive security.
Keywords:
Threshold signatures
lattice-based signatures
rejection sampling

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

I
institute of software, cas
Scholars:
445
Papers: 387
Citations: 0
C
chinese academy of sciences
Scholars:
55.7W
Papers: 44.7W
Citations: 704