An accountable threshold signature (ATS) is a threshold signature scheme where every signature identifies the quorum of signers who generated that signature. They are widely used in financial settings where signers need to be held accountable for threshold signatures they generate. In this work we construct the first accountable threshold signature schemes that support a proactive refresh. Proactive refresh is a protocol that lets the group of signers refresh their shares of the secret key, without changing the public key or the threshold. It is an important security mechanism that helps protect a secret key from a gradual exposure of key shares. However, until now, no ATS scheme supported a proactive refresh. We begin by giving several definitions for this new concept that achieve different levels of security. We then construct three types of ATS schemes with proactive refresh. The first is a generic construction that is efficient when the number of signers is small. The second is a collection of very practical constructions derived from ATS versions of the Schnorr and BLS signature schemes; however these practical constructions only satisfy our weaker notion of security. The third is a hybrid construction that performs well for a large number of signers and satisfies our strongest security definition.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Proactive Refresh for Accountable Threshold Signatures

  • Dan Boneh,
  • Aditi Partap,
  • Lior Rotem

摘要

An accountable threshold signature (ATS) is a threshold signature scheme where every signature identifies the quorum of signers who generated that signature. They are widely used in financial settings where signers need to be held accountable for threshold signatures they generate. In this work we construct the first accountable threshold signature schemes that support a proactive refresh. Proactive refresh is a protocol that lets the group of signers refresh their shares of the secret key, without changing the public key or the threshold. It is an important security mechanism that helps protect a secret key from a gradual exposure of key shares. However, until now, no ATS scheme supported a proactive refresh. We begin by giving several definitions for this new concept that achieve different levels of security. We then construct three types of ATS schemes with proactive refresh. The first is a generic construction that is efficient when the number of signers is small. The second is a collection of very practical constructions derived from ATS versions of the Schnorr and BLS signature schemes; however these practical constructions only satisfy our weaker notion of security. The third is a hybrid construction that performs well for a large number of signers and satisfies our strongest security definition.