\(\textsf{Glitter}\) : A Fully Adaptive and Tightly Secure Threshold Signature
摘要
Threshold signatures (TS) have been widely used in digital wallets and blockchain ecosystems. In a (t, n) threshold signature scheme, at least \(t+1\) signers are required to produce a valid signature. The state-of-the-art TS schemes compromise either the security model or incur at least linear-size reduction loss. Designing a fully adaptive and tightly secure TS scheme without algebraic group model (AGM) is still challenging. In this work, we propose a new security model, \(\textsf{EUF}\text {-}\textsf{CMA}\text {-}\textsf{FC}\) , making an enhancement in randomness guarantee and capturing fully adaptive security. We also propose \(\textsf{Glitter}\) , a fully adaptive and tightly secure five-round threshold signature scheme without pairing. \(\textsf{Glitter}\) has a comparable signature size and verification time with the state-of-the-art works. We prove the tight security of \(\textsf{Glitter}\) in the \(\textsf{EUF}\text {-}\textsf{CMA}\text {-}\textsf{FC}\) model in the random oracle model via security reduction. Without AGM, the security of \(\textsf{Glitter}\) can be reduced to t-algebraic translation resistance of tagged linear function (which implies DDH) with reduction loss \(L=2\) .