Threshold-optimal DSA/ECDSA signatures and an application to Bitcoin wallet security

Rosario Gennaro and Steven Goldfeder and Arvind Narayanan

Abstract: While threshold signature schemes have been presented before, there has never been an optimal threshold signature algorithm for DSA. Due to the properties of DSA, it is far more difficult to create a threshold scheme for it than for other signature algorithms. In this paper, we present a breakthrough scheme that provides a threshold DSA algorithm that is efficient and optimal. We also present a compelling application to use our scheme: securing Bitcoin wallets. Bitcoin thefts are on the rise, and threshold DSA is necessary to secure Bitcoin wallets. Our scheme is the first general threshold DSA scheme that does not require an honest majority and is useful for securing Bitcoin wallets.

Category / Keywords: cryptographic protocols / DSA, ECDSA, threshold signatures, threshold cryptography, Bitcoin

Date: received 6 Jan 2016, last revised 26 Jan 2016

