Compressed Σ-Protocols for Bilinear Group Arithmetic Circuits and Application to Logarithmic Transparent Threshold Signatures

被引:14
作者
Attema, Thomas [1 ,2 ,4 ]
Cramer, Ronald [1 ,2 ]
Rambaud, Matthieu [3 ]
机构
[1] CWI, Cryptol Grp, Amsterdam, Netherlands
[2] Leiden Univ, Math Inst, Leiden, Netherlands
[3] Inst Polytech Paris, Telecom Paris, Palaiseau, France
[4] TNO, Cyber Secur & Robustness, The Hague, Netherlands
来源
ADVANCES IN CRYPTOLOGY - ASIACRYPT 2021, PT IV | 2021年 / 13093卷
关键词
Zero-knowledge; Bilinear groups; Pairings; Compressed; Sigma-Protocol Theory; Threshold signature schemes;
D O I
10.1007/978-3-030-92068-5_18
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Lai et al. (CCS 2019) have shown how Bulletproof's arithmetic circuit zero-knowledge protocol (Bootle et al., EUROCRYPT 2016 and Bunz et al., S&P 2018) can be generalized to work for bilinear group arithmetic circuits directly, i.e., without requiring these circuits to be translated into arithmetic circuits. In a nutshell, a bilinear group arithmetic circuit is a standard arithmetic circuit augmented with special gates capturing group exponentiations or pairings. Such circuits are highly relevant, e.g., in the context of zero-knowledge statements over pairing-based languages. As expressing these special gates in terms of a standard arithmetic circuit results in a significant overhead in circuit size, an approach to zero-knowledge via standard arithmetic circuits may incur substantial additional costs. The approach due to Lai et al. shows how to avoid this by integrating additional zero-knowledge techniques into the Bulletproof framework so as to handle the special gates very efficiently. We take a different approach by generalizing Compressed S-Protocol Theory (CRYPTO 2020) from arithmetic circuit relations to bilinear group arithmetic circuit relations. Besides its conceptual simplicity, our approach has the practical advantage of reducing the communication costs of Lai et al.'s protocol by roughly a multiplicative factor 3. Finally, we show an application of our results which may be of independent interest. We construct the first k-out-of-n threshold signature scheme (TSS) that allows for transparent setup and that yields threshold signatures of size logarithmic in n. The threshold signature hides the identities of the k signers and the threshold k can be dynamically chosen at aggregation time.
引用
收藏
页码:526 / 556
页数:31
相关论文
共 42 条
[1]   Structure-Preserving Signatures and Commitments to Group Elements [J].
Abe, Masayuki ;
Fuchsbauer, Georg ;
Groth, Jens ;
Haralambiev, Kristiyan ;
Ohkubo, Miyako .
JOURNAL OF CRYPTOLOGY, 2016, 29 (02) :363-421
[2]  
Ateniese G., 2005, 2005385 IACR
[3]  
Attema T., 2020, 2020753 IACR
[4]   A Compressed Σ-Protocol Theory for Lattices [J].
Attema, Thomas ;
Cramer, Ronald ;
Kohl, Lisa .
ADVANCES IN CRYPTOLOGY - CRYPTO 2021, PT II, 2021, 12826 :549-579
[5]   Compressed Σ-Protocol Theory and Practical Application to Plug & Play Secure Algorithmics [J].
Attema, Thomas ;
Cramer, Ronald .
ADVANCES IN CRYPTOLOGY - CRYPTO 2020, PT III, 2020, 12172 :513-543
[6]   Presumed Asymptomatic Carrier Transmission of COVID-19 [J].
Bai, Yan ;
Yao, Lingsheng ;
Wei, Tao ;
Tian, Fei ;
Jin, Dong-Yan ;
Chen, Lijuan ;
Wang, Meiyun .
JAMA-JOURNAL OF THE AMERICAN MEDICAL ASSOCIATION, 2020, 323 (14) :1406-1407
[7]  
Ballard L., 2005, 2005417 IACR
[8]  
Bellare M., 1993, P 1 ACM C COMP COMM, P62
[9]  
Boldyreva A, 2003, LECT NOTES COMPUT SC, V2567, P31
[10]  
Boneh D., 2001, INT C THEOR APPL CRY, P514