Paper 2022/839

Threshold Structure-Preserving Signatures

Elizabeth Crites, University of Edinburgh, Edinburgh, UK
Markulf Kohlweiss, University of Edinburgh, Edinburgh, UK, IOG
Bart Preneel, imec-COSIC, KU Leuven, Leuven, Belgium
Mahdi Sedaghat, imec-COSIC, KU Leuven, Leuven, Belgium
Daniel Slamanig, AIT Austrian Institute of Technology, Vienna, Austria
Abstract

Structure-preserving signatures (SPS) are an important building block for privacy-preserving cryptographic primitives, such as electronic cash, anonymous credentials, and delegatable anonymous credentials. In this work, we introduce the first threshold structure-preserving signature scheme (TSPS). This enables multiple parties to jointly sign a message, resulting in a standard, single-party SPS signature, and can thus be used as a replacement for applications based on SPS. We begin by defining and constructing SPS for indexed messages, which are messages defined relative to a unique index. We prove its security in the random oracle model under a variant of the generalized Pointcheval-Sanders assumption (PS). Moreover, we generalize this scheme to an indexed multi-message SPS for signing vectors of indexed messages, which we prove secure under the same assumption. We then formally define the notion of a TSPS and propose a construction based on our indexed multi-message SPS. Our TSPS construction is fully non-interactive, meaning that signers simply output partial signatures without communicating with the other signers. Additionally, signatures are short: they consist of 2 group elements and require 2 pairing product equations to verify. We prove the security of our TSPS under the security of our indexed multi-message SPS scheme. Finally, we show that our TSPS may be used as a drop-in replacement for UC-secure Threshold-Issuance Anonymous Credential (TIAC) schemes, such as Coconut, without the overhead of the Fischlin transform.

Note: Major revision.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
A major revision of an IACR publication in ASIACRYPT 2023
Keywords
Threshold SignaturesStructure-Preserving Signatures
Contact author(s)
ecrites @ ed ac uk
mkohlwei @ inf ed ac uk
bart preneel @ esat kuleuven be
ssedagha @ esat kuleuven be
daniel slamanig @ ait ac at
History
2023-09-21: last of 2 revisions
2022-06-24: received
See all versions
Short URL
https://ia.cr/2022/839
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2022/839,
      author = {Elizabeth Crites and Markulf Kohlweiss and Bart Preneel and Mahdi Sedaghat and Daniel Slamanig},
      title = {Threshold Structure-Preserving Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2022/839},
      year = {2022},
      url = {https://eprint.iacr.org/2022/839}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.