Multiplicative Forward-Secure Threshold Signature Scheme
Sherman S. M. Chow, H. W. Go, Lucas C. K. Hui, Siu-Ming Yiu · 2008
Abstract. The devastating consequence of secret key exposure in digital signature is that any signature can be forged and cannot be trusted. To mitigate the damage of secret key exposure, forward-secure signature schemes and threshold signature schemes are devised. Forward-secure signature schemes address the key exposure problem by dividing the usage life time of the public key into discrete time periods and using different secret keys in different periods, such that all signatures generated in previous time periods with old secret keys are still considered valid even if the current secret key is compromised. Threshold signature schemes lower the chance of complete exposure of the secret by sharing it among different entities. Combining these properties enhances the security of the whole scheme and is particularly useful in an ad-hoc network environment where the security and the availability of a single certificate authority is not guaranteed. In this paper, we propose a robust forward-secure threshold signature scheme based on multiplicative secret sharing. When compared to the existing schemes, our scheme is more efficient in key updates and use fewer communication rounds in signing. The security of our threshold scheme is reducible to the security of the scheme in single user settings, which has been already proven to be secure under the random oracle model.