Paper 2025/1813

Two-party ECDSA Signing at Constant Communication Overhead

Yashvanth Kondi, Silence Laboratories
Abstract

In this work, we investigate whether the cost of two-party ECDSA signing can be brought within the realm of plain ECDSA signing. We answer the question in the affirmative for the case of communication complexity, by means of a new signing protocol. Our protocol consumes bandwidth linear in the security parameter, and hence the size of an ECDSA signature. Our scheme makes only blackbox use of generic tools---Oblivious Transfer during key generation, and any Pseudorandom Function when signing. While computation complexity is not asymptotically optimal, benchmarks of our protocol confirm that concrete costs are the lowest known for ECDSA signing. Our protocol is therefore the most concretely efficient in the literature on all fronts: bandwidth, computation, and rounds. On a technical level, our protocol is enabled by a novel Pseudorandom Correlation Function (PCF) for the Vector Oblivious Linear Evaluation correlation over a large ring. The PCF relies on one-way functions alone, and may be of independent interest. Our scheme supports standard extensions, such as pre-signing, and including backup servers for key shares in a $(2,n)$ configuration.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
MPCECDSAThreshold ECDSATwo party ECDSA2 of n ECDSA
Contact author(s)
yash @ ykondi net
History
2025-10-08: approved
2025-10-03: received
See all versions
Short URL
https://ia.cr/2025/1813
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1813,
      author = {Yashvanth Kondi},
      title = {Two-party {ECDSA} Signing at Constant Communication Overhead},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1813},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1813}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.