Paper 2024/1628

Glacius: Threshold Schnorr Signatures from DDH with Full Adaptive Security

Renas Bacho, CISPA Helmholtz Center for Information Security, Saarbrücken, Germany, Saarland University, Saarbrücken, Germany
Sourav Das, University of Illinois at Urbana Champaign
Julian Loss, CISPA Helmholtz Center for Information Security, Saarbrücken, Germany
Ling Ren, University of Illinois at Urbana Champaign
Abstract

Threshold signatures are one of the most important cryptographic primitives in distributed systems. The threshold Schnorr signature scheme, an efficient and pairing-free scheme, is a popular choice and is included in NIST's standards and recent call for threshold cryptography. Despite its importance, most threshold Schnorr signature schemes assume a static adversary in their security proof. A recent scheme proposed by Katsumata et al. (Crypto 2024) addresses this issue. However, it requires linear-sized signing keys and lacks the identifiable abort property, which makes it vulnerable to denial-of-service attacks. Other schemes with adaptive security either have reduced corruption thresholds or rely on non-standard assumptions such as the algebraic group model (AGM) or hardness of the algebraic one-more discrete logarithm (AOMDL) problem. In this work, we present Glacius, the first threshold Schnorr signature scheme that overcomes all these issues. Glacius is adaptively secure based on the hardness of decisional Diffie-Hellman (DDH) in the random oracle model (ROM), and it supports a full corruption threshold $t<n$, where $n$ is the total number of signers and $t$ is the signing threshold. Additionally, Glacius provides constant-sized signing keys and identifiable abort, meaning signers can detect misbehavior. We also give a formal game-based definition of identifiable abort, addressing certain subtle issues present in existing definitions, which may be of independent interest.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Threshold SignaturesSchnorr SignaturesAdaptive Security
Contact author(s)
renas bacho @ cispa de
souravd2 @ illinois edu
loss @ cispa de
renling @ illinois edu
History
2024-10-14: approved
2024-10-11: received
See all versions
Short URL
https://ia.cr/2024/1628
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2024/1628,
      author = {Renas Bacho and Sourav Das and Julian Loss and Ling Ren},
      title = {Glacius: Threshold Schnorr Signatures from {DDH} with Full Adaptive Security},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/1628},
      year = {2024},
      url = {https://eprint.iacr.org/2024/1628}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.