Paper 2025/2134

Non-Interactive Threshold Mercurial Signatures with Applications to Threshold DAC

Scott Griffy, Brown University
Nicholas Jankovic, Brown University
Anna Lysyanskaya, Brown University
Arup Mondal, Ashoka University
Abstract

In a mercurial signature, a signer signs a representative $m$ of an equivalence class of messages on behalf of a representative $\mathsf{pk}$ of an equivalence class of public keys, receiving the signature $\sigma$. One can then transform $\sigma$ into a signature $\sigma'$ on an equivalent (to $m$) message $m'$ under an equivalent (to $\mathsf{pk}$) public key $\mathsf{pk}'$. Mercurial signatures are helpful in constructing delegatable anonymous credentials: their privacy properties enable straightforward randomization of a credential chain, hiding the identity of each signer while preserving the authenticity of the overall credential. Unfortunately, without trusted setup, known constructions of mercurial signatures satisfy only a weak form of this privacy property. Specifically, an adversary who is responsible for a link in a delegation chain—and thus knows its corresponding secret key—will be able to recognize this link even after the chain has been randomized. To address this issue, Abe et al. (Asiacrypt 2024) proposed (interactive) threshold mercurial signatures (TMS), which remove the reliance on a single trusted signer by distributing the signing capability among multiple parties, none of whom knows the signing key. However, this contribution was far from practical, as it required the signers to interact with each other during the signing process. In this work, we define and realize non-interactive TMS, where each participant non-interactively computes its contribution to the threshold mercurial signature. Our construction also substantially reduces the overall communication complexity. It uses the mercurial signature scheme of Mir et al. (CCS 2023) as a starting point. Further, we introduce threshold delegatable anonymous credentials (TDAC) and use a non-interactive TMS to construct them.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
anonymous credentialsdelegatable anonymous credentialsmercurial signaturesthreshold signaturessignature schemes
Contact author(s)
scott_griffy @ brown edu
nicholas_jankovic @ brown edu
anna_lysyanskaya @ brown edu
arup24mondal @ gmail com
History
2025-11-22: approved
2025-11-21: received
See all versions
Short URL
https://ia.cr/2025/2134
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2134,
      author = {Scott Griffy and Nicholas Jankovic and Anna Lysyanskaya and Arup Mondal},
      title = {Non-Interactive Threshold Mercurial Signatures with Applications to Threshold {DAC}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2134},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2134}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.