An Efficient Threshold Ring Signature from G+G Identification Protocol
摘要
Threshold ring signature confirms that t signers are participating in the signature and keep them anonymous. It is a generalization of ring signature, and has many important applications such as whistleblower, e-voting and blockchain et al. In this paper, an improved lattice-based ring signature and threshold ring signature scheme from Fiat-Shamir heuristic are proposed. The schemes eliminte the dependence on Stern-like identification protocols and have much shorter signature sizes. We also use the Gaussian convolution technique (G+G) presented by Devevey et al. in Asiacrypt 2023 to remove the reject-sampling in BLISS. This allows the threshold ring signature to overcome the proof issue caused by “abort” and achieve higher computation efficiency than previous ones.