Threshold Signatures in the Multiverse

被引:3
|
作者
Baird, Leemon [3 ]
Garg, Sanjam [1 ,4 ]
Jain, Abhishek [2 ]
Mukherjee, Pratyay [5 ]
Sinha, Rohit [3 ,6 ]
Wang, Mingyuan [1 ]
Zhang, Yinuo [1 ]
机构
[1] Univ Calif Berkeley, Berkeley, CA USA
[2] Johns Hopkins Univ, Baltimore, MD 21218 USA
[3] Swirlds Labs, College Stn, TX 77845 USA
[4] NTT Res, Sunnyvale, CA USA
[5] Supra Oracles, Berkeley, CA USA
[6] Meta, Cambridge, MA USA
关键词
SECURE;
D O I
10.1109/SP46215.2023.10179436
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We introduce a new notion of multiverse threshold signatures (MTS). In an MTS scheme, multiple universes - each defined by a set of (possibly overlapping) signers, their weights, and a specific security threshold can co-exist. A universe can be (adaptively) created via a non-interactive asynchronous setup. Crucially, each party in the multiverse holds constant-sized keys and releases compact signatures with size and computation time both independent of the number of universes. Given sufficient partial signatures over a message from the members of a specific universe, an aggregator can produce a short aggregate signature relative to that universe. We construct an MTS scheme building on BLS signatures. Our scheme is practical, and can be used to reduce bandwidth complexity and computational costs in decentralized oracle networks. As an example data point, consider a multiverse containing 2000 nodes and 100 universes (parameters inspired by Chainlink's use in the wild), each of which contains arbitrarily large subsets of nodes and arbitrary thresholds. Each node computes and outputs 1 group element as its partial signature; the aggregator performs under 0.7 seconds of work for each aggregate signature, and the final signature of size 192 bytes takes 6.4 ms (or 198K EVM gas units) to verify. For this setting, prior approaches, when used to construct MTS, yield schemes that have one of the following drawbacks: (i) partial signatures that are 48x larger, (ii) have aggregation times 311x worse, or (iii) have signature size 39x and verification gas costs 3.38x larger. We also provide an opensource implementation and a detailed evaluation.
引用
下载
收藏
页码:1454 / 1470
页数:17
相关论文
共 50 条
  • [21] multiverse
    Johnson, Will
    POETRY WALES, 2012, 48 (03): : 52 - 52
  • [22] THE MULTIVERSE
    Cochrane, Harry
    TLS-THE TIMES LITERARY SUPPLEMENT, 2019, (6053): : 27 - 27
  • [23] INTO THE MULTIVERSE
    Halpern, Sue
    NATION, 2017, 305 (10) : 32 - 34
  • [24] The Multiverse
    Louis, Adrian C.
    SOUTH DAKOTA REVIEW, 2016, 52 (3-4): : 94 - 94
  • [25] 'THE MULTIVERSE'
    GOLDBARTH, A
    POETRY, 1988, 151 (04) : 329 - 332
  • [26] 'Multiverse'
    Burrows, W
    POETRY WALES, 2001, 37 (01): : 70 - 71
  • [27] Multiverse
    Rose-Shapiro, Annette
    ARTNEWS, 2014, 113 (05): : 102 - 102
  • [28] Multiverse
    Dooley, Terence
    AGENDA, 2015, 49 (02): : 57 - 57
  • [29] Extendable Threshold Ring Signatures with Enhanced Anonymity
    Avitabile, Gennaro
    Botta, Vincenzo
    Fiore, Dario
    PUBLIC-KEY CRYPTOGRAPHY - PKC 2023, PT I, 2023, 13940 : 281 - 311
  • [30] Efficient Forward-Secure Threshold Signatures
    Kurek, Rafael
    ADVANCES IN INFORMATION AND COMPUTER SECURITY (IWSEC 2020), 2020, 12231 : 239 - 260