Paper 2024/358

Stateless Deterministic Multi-Party EdDSA Signatures with Low Communication

Qi Feng, Wuhan University
Kang Yang, State Key Laboratory of Cryptology
Kaiyi Zhang, Shanghai Jiao Tong University
Xiao Wang, Northwestern University
Yu Yu, Shanghai Jiao Tong University, Shanghai Qi Zhi Institute
Xiang Xie, Primus Labs, Shanghai Qi Zhi Institute
Abstract

EdDSA is a standardized signing algorithm, by both the IRTF and NIST, that is widely used in blockchain, e.g., Hyperledger, Cardano, Zcash, etc. It is a variant of the well-known Schnorr signature scheme that leverages Edwards curves. It features stateless and deterministic nonce generation, meaning it does not rely on a reliable source of randomness or state continuity. Recently, NIST issued a call for multi-party threshold EdDSA signatures, with one approach verifying nonce generation through zero-knowledge (ZK) proofs. In this paper, we propose a new stateless and deterministic multi-party EdDSA protocol in the full-threshold setting, capable of tolerating all-but-one malicious corruption. Compared to the state-of-the-art multi-party EdDSA protocol by Garillot et al. (Crypto’21), our protocol reduces communication cost by a factor of 56x while maintaining the same three-round structure, albeit with a roughly 2.25x increase in computational cost. We utilize information-theoretic message authentication codes (IT-MACs) in a multi-verifier setting to authenticate values and transform them from the Boolean domain to the arithmetic domain by refining multi-verifier extended doubly-authenticated bits (mv-edabits). Additionally, we employ pseudorandom correlation functions (PCF) to generate IT-MACs in a stateless and deterministic manner. Combining these elements, we design a multi-verifier zero-knowledge (MVZK) protocol for stateless and deterministic nonce generation. Our protocol can be used to build secure blockchain wallets and custody solutions, enhancing key protection.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published by the IACR in PKC 2025
Keywords
Multi-Party EdDSA SigningMulti-Verifier Zero-Knowledge ProofThreshold Signature and Key Protection.
Contact author(s)
fengqi whu @ whu edu cn
yangk @ sklc org
kzoacn @ sjtu edu cn
wangxiao @ northwestern edu
yuyu @ yuyu hk
xiexiangiscas @ gmail com
History
2025-02-23: last of 2 revisions
2024-02-28: received
See all versions
Short URL
https://ia.cr/2024/358
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/358,
      author = {Qi Feng and Kang Yang and Kaiyi Zhang and Xiao Wang and Yu Yu and Xiang Xie},
      title = {Stateless Deterministic Multi-Party {EdDSA} Signatures with Low Communication},
      howpublished = {Cryptology {ePrint} Archive, Paper 2024/358},
      year = {2024},
      url = {https://eprint.iacr.org/2024/358}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.