Paper 2022/241

Coalition and Threshold Hash-Based Signatures

John Kelsey
Stefan Lucks
Nathalie Lang
Abstract

We introduce techniques to transform existing stateful hash based signature (HBS) schemes, such as LMS or XMSS, into efficient threshold and distributed signature schemes. Our approach requires a trusted dealer for setup, and uses a large (up to a few GiB, typically) common reference value for each new public key. The dealer generates the keypair and distributes shares of the signing key to the trustees, while creating the CRV. Signing involves an untrusted aggregator communicating point-to-point with a set of trustees. Only the aggregator needs access to the CRV; the trustees need only a PRF key and enough space to remember which one-time keys they have helped to sign with so far. Signing requires two round trips between the aggregator and each participating trustee, and only a little more computation from the trustees and aggregator than is done when signing with the underlying HBS scheme. We reduce the security of our scheme to that of the underlying HBS scheme, assuming the availability of a secure PRF. A dishonest aggregator or tampered CRV can prevent valid signatures from being constructed, but does not allow forgeries. Our techniques offer a powerful practical defense against accidental reuse of a one-time key in stateful HBS schemes by requiring multiple trustees to fail in the same way in order for key reuse to occur.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Published by the IACR in CIC 2025
Keywords
threshold cryptographyhash functionshash-based signatures
Contact author(s)
stefan lucks @ uni-weimar de
nathalie lang @ uni-weimar de
History
2025-07-01: last of 3 revisions
2022-02-25: received
See all versions
Short URL
https://ia.cr/2022/241
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2022/241,
      author = {John Kelsey and Stefan Lucks and Nathalie Lang},
      title = {Coalition and Threshold Hash-Based Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2022/241},
      year = {2022},
      url = {https://eprint.iacr.org/2022/241}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.