Lattice-based threshold signature method

A lattice-based threshold signature scheme addresses post-quantum cryptography challenges by employing three-round commitment and response generation, ensuring secure and efficient post-quantum threshold signatures.

GB2629629BActive Publication Date: 2025-06-25PQSHIELD LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
GB2023006626
Authority / Receiving Office
GB · GB
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-05-04
Publication Date
2025-06-25
Estimated Expiration
2043-05-04

AI Technical Summary

Technical Problem

Existing threshold signature schemes are not effectively adapted for post-quantum cryptography, particularly under Module Learning with Errors (MLWE) and Module Short Integer Solution (MSIS) assumptions, and face challenges in maintaining security and practicality in distributed environments.

Method used

A lattice-based threshold signature method involving three rounds of commitment, response generation, and signature combination using Learning with Errors samples and public key components, with noise and blinding techniques to ensure security and efficiency.

Benefits of technology

The method provides secure and practical post-quantum threshold signatures resistant to quantum computers, ensuring authenticity and non-repudiation in electronic communications, while maintaining computational efficiency and security against direct forgery attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000001_0000
    Figure 00000001_0000
  • Figure 00000003_0000
    Figure 00000003_0000
Patent Text Reader

Abstract

A lattice-based threshold signature scheme which operates in three rounds and is secure under Module Learning with Errors (MLWE) and Module Short integer Solution (MSIS) assumptions. A public matrix,
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field The present invention relates to a threshold signature method and one or more information processing apparatus for applying a threshold signature method. Background A threshold signature scheme is a special type of multiparty computation that aims to generate a digital signature. A threshold signature assumes that there are N signers, and that any threshold T of the N signers can sign a message but T - 1 cannot. In a world without quantum computers there are threshold signature solutions that are both practical and secure in highly adversarial environments. Examples of pre-quantum threshold signature schemes include implementations of e.g. the Schnorr, ECDSA, RSA, or BLS signature schemes. These signature schemes are well developed and include security features such as robustness, identifiable aborts, small round complexity and backward compatibility with existing applications. In a world with sufficiently powerful quantum computers, cryptographic techniques need to be modified because the problems on which pre-quantum cryptographic algorithms are based will become solvable. There are challenges with designing threshold signature schemes for postquantum cryptography that prior works have struggled to address. Currently there are five common classes of assumptions that are conjectured resistant against quantum computers: multivariate equations, one-way functions, error correcting codes, isogenies, and lattice type assumptions. Nonetheless, there has to date been limited success in building threshold signature schemes based on these assumptions. Accordingly, there is a desire to formulate a post-quantum threshold signature scheme. Summary According to a first aspect of the present invention, there is provided a threshold signature method performed by one or more information processing apparatus for generating a signature using a threshold number, T, out of a number N of secret shares generated from a secret, s, wherein the number of secret shares, N, is greater than the threshold number, T, the method comprising: generating a public matrix, A, and the secret, s; generating a small noise, e, and a public key, vk = (A, t) including a portion of the public key, t, that is a sum of the small noise, e, with a product of the public matrix, A, and the secret, s; generating N secret shares, Si, from the secret, s; for each of the threshold number T of secret shares: generating a learning with errors sample, wj; generating a commitment, cmtj, that is a hash of at least the generated learning with error sample, Wj, and making the commitment, cmti, available in a first round of the signature method and making the learning with errors sample, Wj, available in a second round of the signature method; for each of the T secret shares in a third round of the signature method: generating an aggregated commitment, w, by summing the learning with errors samples, Wj, across the T secret shares; generating a challenge, c, that is a hash of the public key, vk, a message to be signed, msg, and the aggregated commitment, w; generating an individual response, Zj, based on the challenge, c, the secret share, Sj, and an ephemeral randomness used to generate the learning with errors sample, q; and making the individual response, Zj, available in the third round; combining the contributions in respect of the T secret shares in the first, second and third rounds to generate a signature by: generating an aggregated commitment, w, by summing the learning with errors samples, Wj across the T secret shares; generating an aggregated response, z, by summing the individual responses, zj; generating a global challenge, c, by hashing the public key, vk, the message to be signed, msg, and the aggregated commitment, w; generating a hint, h, by: determining a noisy commitment, y, by subtracting a product of the global challenge, c, and the portion of the public key, t, from a product of the aggregated response, z, and the public matrix, A; and subtracting the noisy commitment, y, from the aggregated commitment, w, to generate the hint, h; and outputting a signature comprising the global challenge, c, the aggregated response, z, and the hint, h. According to a second aspect of the invention there is provided one or more information processing apparatus, each comprising a processor and a storage medium storing computer-readable instructions, wherein the computer-readable instructions are configured to cause the one or more information processing apparatus to perform a method according to the first aspect. According to a third aspect of the invention there is provided one or more programs that, when executed on one or more information processing apparatus cause the one or more information processing apparatus to perform a method according to the first aspect. Further features and advantages of the invention will become apparent from the following description of preferred embodiments of the invention, given by way of example only, which is made with reference to the accompanying drawings. Brief Description of the Drawings Figure 1 is a schematic diagram of components of an example information processing apparatus; Figure 2 illustrates steps of a key generation method performed by a central actor; Figure 3 shows the relationship between seeds, signers, and blinders in an example in which there are three signers; Figure 4a illustrates steps of first and second rounds of a threshold signature method; Figure 4b illustrates steps of a third round of a threshold signature method and steps for combining the contributions from three rounds of the threshold signature method to generate a signature; Figure 5 illustrates steps for verifying a signature; Figure 6a illustrates steps of first and second rounds of a threshold signature method according to a further embodiment; and Figure 6b illustrates steps of a third round of a threshold signature method and steps for combining the contributions from three rounds of the threshold signature method to generate a signature according to a further embodiment. Detailed Description Digital signatures are a method of ensuring the authenticity and non-repudiation of electronic documents and messages. They are an important component of secure electronic communication and are widely used in applications such as electronic contracts, financial transactions, and email communication. The use of digital signatures offers several advantages over traditional paperbased signatures. First, they provide a higher level of security, and it is much more difficult to forge a digital signature than a handwritten signature. Second, they provide a greater level of assurance regarding the authenticity and integrity of the signed document or message, as any changes made to the original document will result in a different signature and thus an invalid signature. Typically digital signatures may be verified by anyone with access to the signer's public key, the message to which the signature was applied, and the signature. A threshold signature scheme based on lattice assumptions will be described below. Prior signature schemes relying on lattice-based techniques have a feature that the response may depend on the signing key and may thus leak information about signing key. To alleviate this dependency, a commonly used method is the rejectionsampling method, that drops some potential signatures so that the resulting distribution of responses doesn’t depend upon secret information. However, rejection sampling methods aren’t practical for distributing the computation in a threshold scheme. This is because none of the signers knows the complete signature and the signers are therefore unable to perform the check to reject a signature. More precisely, performing a rejection check in a distributed manner on a signature that is not yet public is a highly complicated task. The following threshold signature scheme assumes that the Module Learning with Errors (MLWE) problem is hard to solve and that the Module Short Integer Solution (MSIS) problem is hard to solve. Preliminaries The signature scheme described below may be performed on one or more information processing apparatus such as a server, computer, and / or mobile device. A central actor will be described below. The central actor may be a separate information processing apparatus, such as a server or cloud service, and other steps of the signature scheme may be performed on user devices associated with different signers in the signature scheme. In one example a group of signers in a group may wish to be able to sign a message as long as a threshold number T of the signers in the group contribute to the signature process. The signers may participate in the signature scheme using separate user devices. In other implementations all the processing may be performed on a single information processing apparatus and there may be a single user. For example, a user may have a signing key associated with a cryptographic asset, such as an asset on a blockchain. The user may wish to keep the signing key secure and resistant to loss. Accordingly, the user may generate shares of the signing key and store them on different storage devices. In this case, the user may sign a document using the storage devices as long as the user has access to at least a threshold number of the devices. Similarly, a malicious actor would need access to a threshold number of the storage devices to apply the signature. In some implementations the storage devices may be drives, such as solidstate drives or the like. All steps of the method in this case could be performed on a single information processing apparatus based on information relating to the key shares stored on the storage devices. The description below will describe potential signers. However, the term ‘potential signer’ or ‘signer’ may be used interchangeably with the term ‘secret share’ because as just described, the method could be performed by a single user in respect of each secret share. Accordingly, the term ‘signer’ should not be interpreted as requiring a separate user or a separate information processing apparatus. Figure 1 is a schematic diagram of components of an example information processing apparatus 1 suitable for use in the signature method. The diagram is illustrative and different hardware configurations for information processing apparatus are possible as is well known in the art. The information processing apparatus includes an I / O interface 10, such a USB port, Thunderbolt port, etc. to which an additional device, such as a storage device, could be connected. The information processing apparatus 1 comprises a processor 11, a storage in the form of memory 12, a network module 13, a display 14, and a user interface 15. The network module may allow the information processing apparatus 1 to communicate over a network such as a Wi-Fi network, a mobile telecommunications network, a local area network etc. The user interface may include components such as a keyboard, mouse, camera, etc. The components of the information processing apparatus may communicate with each other over a bus 16. Further components may be provided but are not shown or described. Any of the steps of the subsequently described methods may be performed by computer-readable instructions of one or more programs stored in a storage and executed by a processor on one or more information processing apparatuses. Figure 2 illustrates steps of a key generation method. At step 1, a central actor generates a uniform matrix, A, over a ring of polynomials, Rq. Rq is a ring of polynomials modulo q. The Ring, R, is defined for n and q as + 1) and Rq is defined as: « / q’R The matrix, A, has dimensions of k by I and each entry in the matrix is a polynomial of Rq. At step 2, the central actor generates a secret, s, from a distribution D. D is a distribution over Rq. The distribution D is labelled Dvk to distinguish from any other distributions. Accordingly, s is a sampled polynomial modulo q. In some examples, a discrete Gaussian distribution is used. A discrete Gaussian distribution about a point v with a standard deviation of g is given by: 2a2 / In a case in which the center is zero, we will use the terminology Do below. At step 3, the central actor uses Linear Shamir Secret Sharing to generate N secret shares. Si. In accordance with this method, a polynomial, P, with degree T-l, is generated over Rq. 7 is the threshold number of shares required to perform the signature. The threshold number of shares, T, may be considered, in some examples, to be the number of active signers required to generate the signature. The polynomial at zero is equal to the selected secret s i.e. P(0) = s. At step 4, the Shamir Secret sharing is continued, and N secret shares are generated from the polynomial, P. The value N is the number of secret shares to be generated where N is greater than or equal to T the threshold number of secret shares required to complete the signature process. The N secret shares are provided to a set of potential signers, S. Reconstruction of the polynomial P will be performed later, as described below in connection with Figure 4b. The reconstruction is performed using Lagrange polynomials. For i e S, we define: where L.sis a Lagrange coefficient. A set of evaluation points, E, is defined each having coordinates xt, y, for each of N different values of i (corresponding to the N secret shares), yi = P(xi) In this case S = V • y,. zeS Accordingly, during the key generation process, each potential signer receives a respective secret share Si = yi. At steps 5 and 6, shared seeds, which are random binary values of length k are generated by each potential signer and distributed pair-wise. That is to say that each of the N potential signers generates a seed for itself and a separate seed for each other potential signer. Each potential signer sends each other potential signer an associated seed. The generated seeds are illustrated in Fig. 3 for a case in which N = 3. A potential signer identifier (Al to A3) is shown on the edges of the matrix corresponding to each potential signer. Seedl,l is generated in respect of potential signer Al and is stored locally in association with a first secret share but not distributed to any other potential signer. Likewise, Seed2,2 is generated by potential signer A2 and stored locally and Seed3,3 is generated by potential signer A3 and stored locally. The other seeds are generated and distributed to the respective potential signers. So, for example, potential signer A2 will receive Seedl,2 from potential signer Al and Seed3,2 from potential signer A3. Correspondingly, potential signer A2 will generate Seed2,l and distribute it to potential signer Al and generate Seed2,3 and distribute it to potential signer A3. However, potential signer A2 does not learn seed values that are not either generated by potential signer A2 (i.e. Seed 2,1, Seed 2,2 and Seed 2,3) or received from the other potential signers (i.e. Seed 1,2 and Seed 3,2) In other words, in this example, potential signer A2 does not know Seedl,l, Seed3,l, Seedl,3 and Seed3,3. The same applies mutatis mutandis to the other potential signers Al and A3. In this example, the shared seeds are generated by the potential signers. However, the skilled person will appreciate that the shared seeds could equally be generated by the central actor and distributed appropriately. Returning to Figure 2, in step 7 the central actor samples a small noise (or error), e, from the distribution D. At step 8, the central actor generates a public key, vk, that is A, As+e. The seeds are generated and distributed as described above. Otherwise, the Matrix, A, and the public key, vk, are made publicly available parameters by the central actor. The secret, s, is destroyed by the central actor after the key shares and public key are generated. Similarly, the small noise (error), e, is destroyed after the public key is generated. Signature scheme The signature scheme proceeds in three rounds. In some implementations each round will be time limited such that each of a threshold number of active signers (hereinafter ‘signers’) of the N potential signers should complete the specified steps within the time limit. If the threshold number of signers do not complete the required steps for a round within the time limit, the signature method may be aborted. In a first round, each signer generates and makes available a commitment, cmtj, and a blinder, mj. In a second round, each signer makes available an LWE commitment, wj. In a third round, each signer makes available a response zj. The central actor can then generate a signed message based on the available information. Each round may be completed sequentially in order to maintain security of the signature scheme. At the end of each round the signers may check that the round has been completed before initiating steps in the subsequent round. The first round of making available a commitment, cmtj, and a blinder, mj, is shown at the top of Figure 4a. In step 1, checks are made for the session identifier, which changes with each iteration of the signature method. The session identifier may be implemented as a counter or generated randomly for each iteration of the signature method. In step 2 of the first round, each signer samples a small ephemeral randomness q and a small noise (or error), e’j. Each sample is taken from a distribution across Rq, Ds, as described above. In step 3, each signer retrieves seeds that it has generated and / or received during the key generation phase and in step 4 generates a column blinder mj. The column blinder, mj, is generated based on the seeds associated with the threshold T signers involved in the threshold signature method. At a simple conceptual level, looking at the particular matrix of Seeds shown in Figure 3 and considering signer A2, signer A2 would sum along the column including Seed2,2 to generate a blinder that is the sum of the column. Accordingly, the signer A2 would generate the first blinder based on the shared seed generated in respect of the secret share for itself (Seed2,2) and T-\ shared seeds that were generated in respect of 7-1 other signers in connection with that signer (Seed 1,2 and Seed3,2). Returning to step 3 of the top part of Figure 4a, each Seed is used as a seed for a pseudorandom function (PRF) along with a session identifier, sid. As the session identifier changes between sessions the values of the blinders also changes thereby improving security. In step 5, a Learning with Errors (LWE) commitment, Wj, is generated based on the lattice A generated in the key generation phase and the generated small ephemeral randomness, rj, and small noise (error), e’j, generated by the signer. The LWE commitment, Wj, is the sum of the small noise (error), e’j and a product of the uniform matrix, A, and the generated small ephemeral randomness, rj. In step 6, a hash commitment, cmtj, is generated. Each signer generates a hash using a function HCOm based on the session id (sid), message to be signed (msg), identity of the signer, act, and generated LWE commitment (wj). The Hash function H is labelled ‘com’ to distinguish from other hash functions. The Hash function may, in some examples, be selected from the four recommended hash functions in NIST special publication 800-185: SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash and Parallel Hash. The commitment, cmtj, and column blinder, mj, of each signer is made available to each other signer at the end of the first round in a contribution, contribi. The second round of the signature method is illustrated in the lower portion of figure 4a. In a first step of the second round, a check is made to ensure that the contributions from the first round are complete and that the session identifier is consistent among the contributions, contribi from the first round. In the remaining steps of the second round the signers retrieve the LWE commitment, wj, that each generated in the first round and make their LWE commitment, Wj, available to the other signers in a second contribution, contrib?. The top portion of Figure 4b shows the third round of the signature method. In steps 1 and 2, the session ID is checked and it is checked that the first and second rounds were successfully completed with contributions received from each of the signers. In step 3, each signer retrieves the column blinders, mj, that were made available at the end of round 1. In step 4, each signer calculates an aggregated commitment, w, which is obtained by summing, across the signers, the LWE commitments, Wj, made available at the end of the second round in combination with a product of the column blinders, m,, and the uniform matrix, A. The aggregated commitment, w, is subjected to bit dropping in accordance with a parameter, uw, which is a parameter that is made openly available to signers using the signature method. The bit dropping serves several purposes. The dropping of bits serves to make the commitment shorter and thus the resulting signature shorter and also serves to improve the resistance of the scheme from direct forgery attacks by hiding the ephemeral randomness in the aggregated commitment, w. The bit dropping is similar to the bit dropping technique that is used in connection with CRYSTALS-Dilithium. At step 5, each signer calculates a global challenge, c, that is a hash of the public key, vk, the message, msg, and the aggregated commitment, w. Although not shown in Figure 4b, the hash function used is Hraccoon. The Hash function H is labelled ‘raccoon’ to distinguish from other hash functions, such as the earlier ‘com’ hash function. Further details of the hash function are given further below. In steps 6 and 7, a row blinder m*j is calculated. This row blinder is calculated in an analogous manner to the column blinder described above. The row blinder, m*j, is generated based on the seeds associated with the threshold T signers involved in the threshold signature method. Returning to the particular example in Figure 3 and considering signer A2, signer A2 would sum along the row including Seed2,2 to generate a blinder that is the sum of the row. That is to say that the row blinder is based on each of T of the N shared seeds generated in respect of the signer (i.e. Seed2,l, Seed2,2, Seed2,3) Returning to steps 6 and 7, each Seed is used as a seed for a pseudorandom function (PRF) along with a session identifier, sid. Many PRF could be used for the signature scheme. In some embodiments, the PRF is based on HMAC (details of which are described in IETF RFC 2104) with SHA-256. In other examples, a PRF derived from SHAKE: NIST publication FIPS PUB 202: SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions may be used. The output of these techniques may be a bit string that needs to be mapped to a mathematical object, such as a vector or matrix. Techniques for performing this mapping are known in the art from, for example, schemes such as Dilithium, Kyber and Falcon. As the session identifier changes between sessions, the values of the row blinders also change therefore change improving security. At step 8, each signer generates an individual response Zj. The individual response is the sum of three components. The first component is a product of the global challenge, c, the signer’s Lagrange coefficient, Xj,act, and the signer’s secret share, Sj. The second component is the ephemeral randomness, rj, that was generated in the first round. The third component is the generated column blinder, m*b At step 9, each signer makes available their individual response, Zj, to the other signers. The method shown in the lower part of figure 4b shows a combine operation performed by the central actor. In steps 1 and 2, the central actor obtains each of the column blinders, mi, LWE commitments, Wi, and individual responses, Zi, generated by the signers, i. The central actor also obtains the public key, vk = (A,t), generated in the key generation phase. Here it is noted that t = As + e. At step 3, the central actor generates an aggregated commitment, w. This step is the same as was performed by each of the signers in step 4 of the third round described above. The aggregated commitment, w, is obtained by summing, across the signers, the LWE commitments, Wi, made available at the end of the second round in combination with a product of the column blinders, mi, and the uniform matrix, A. The aggregated commitment is subjected to bit dropping in accordance with a parameter, uw, which is a parameter that is made openly available to signers using the signature method. At step 4, the central actor generates an aggregated response, z, by summing each of the individual responses, z,, made available at the end of the third round. At step 5, the central actor generates a global challenge, c. The global challenge, c, is generated by hashing the public key, vk, the message to be signed, msg, and the aggregate commitment, w, calculated in step 3. The central actor generates the hash using a function HraccOon. The Hash function H is labelled ‘raccoon’ to distinguish from other hash functions, such as the earlier ‘com’ hash function. The Hash function may, in some examples, be selected from the four recommended hash functions in NIST special publication 800-185: SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash and Parallel Hash. In a further example, SHAKE described in NIST publication FIPS PUB 202: SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions may be used. The Hash functions HcOm and HraccOon should preferably be different, at least in the parameters used. The selection of different hash functions has the effect of domain separation and may improve the security of the signature scheme. In step 6, a noisy commitment, y, is generated by the central actor. The noisy commitment is generated from the difference of two components. The first component is a product of the uniform matrix, A, and the aggregated response, z. The second component is a product of the global challenge c, calculated in step 5, and t = As + e generated in the key generation phase. The calculated difference is subjected to bit shifting to multiply the value by two to the power ut. This is a renormalization to allow for bit dropping. The noisy commitment is then subject to bit dropping by uw bits. Both Ct and uw are public parameters. At step 7, a hint, h, is generated by the central actor. The hint is a difference between the aggregated commitment, w, and the noisy commitment, y. At step 8, the signature of the message, msg, is provided. The signature includes three components: the global challenge, c, the aggregated response, z, and the hint, h. Public parameters ut and uw are referred to above. In general, it is desirable to maximise the value of Ut and uw in order to drop more bits. This has the beneficial effect of shortening the bit sizes. However, security of the scheme against direct forgery attack decreases with increased utand uw. Accordingly, while different values of utanduw can be selected, in some examples, they may be chosen as follows: and vt — Vt * jk’hj T is the threshold number of users as identified above, gw is the standard deviation of the distribution used to select the error when generating the public key, and c is the global challenge. In a typical implementation, around 80% of the bits may be dropped. Verifying the signature Steps for verifying the signature are shown in Figure 5. A party verifying the signature is assumed to also have a copy of the message, msg, which has been signed and against which the signature is being checked and a copy of the public key, vk. Other public parameters described above, including uw , ut, and the hash function, Hraccoon, are also available to the verifying party. The party verifying the signature does not need to be (but could be) a member of the group of signers that were involved in generating the signature. At step 2, the party verifying the signature generates a signature derived value. The signature derived value is a product of the uniform matrix, A, and the aggregated response, z, minus a product of the global challenge, c, and t = As + e from the public key. The signature derived value is subjected to bit dropping of uw bits and has the hint, h, added to it. A new challenge value c' is calculated by taking a hash of: the public key, the message, and the signature derived value after bit dropping and addition of the hint. In step 3, the party verifying the signature determines whether the new challenge value, c’, is equal to the challenge value, c, in the signature. A further check is performed to see that a vector formed of a concatenation of the aggregated response, z, and a product of 2 to the power uw and the hint, h, is shorter than, B. The shortness of the vector relates to the module short integer solution (M-SIS) problem. B is set larger than zero and less than q (recalling from above that the uniform matrix is a set of polynomials of modulo q). B should be set to a large enough value to allow the M-SIS problem to allow the signer to realistically find a signature. On the other hand, B should be set small enough to provide security with respect to the M-SIS problem. More information on setting a suitable value of B may be found, for example, in Chitchanok Chuengsatiansup, Thomas Prest, Damien Stehle, Alexandre Wallet, and Keita Xagawa. ModFalcon: Compact signatures based on module-NTRU lattices, ASIA ACCS 20, pages 853 to866. In one example: B +         < min (cp™ In which 1, k, q are defined in the Module Short Integer Solution problem, q is the modulo of the Ring, k and 1 are dimensions of the Ring, n is the order of polynomials of the Ring (see definition above). The parameter "p" is related to an algorithm called BKZ (block Korkine-Zolotarev). The best known approach to solve MSIS is via the BKZ algorithm. P is a parameter of the BKZ algorithm. The success probability and the running time of BKZ are both increasing functions of p. Accordingly, the equation above guarantees that BKZ can only succeed with reasonable probability if P is set large enough. Accordingly, P can be set so that the running time required for BKZ to break the security of the signature scheme is too large to be tractable and the value B can be determined accordingly. The Module Short Integer Solution is defined as: Given A , find an element s £ such that: A (A• s — 0 mod ^). In steps 4 and 5, if both conditions in step 3 are satisfied, the signature is verified and the method returns a value 1 confirming the signature. Otherwise, in step 5, the method returns 0 indicating that the signature is invalid. Further embodiment Figure 6a illustrates steps of first and second rounds of a threshold signature method according to a further embodiment. The key generation steps for this further embodiment are the same as those shown and described with respect to Figure 2 above and the method for verifying the signature is also unchanged. There are many similarities between the further embodiment and the embodiment described above in connection with Figures 4a and 4b. Accordingly only differences will be described. In the first round, the notation has changed from Do1 to Dw1. However, the sampling of a small ephemeral randomness q and a small noise (or error), e’j, are the same between both methods. Accordingly, there are no differences in the first round compared to the previously described embodiment. The lower part of Figure 6b shows the second round of the further embodiment. Again, there are no differences in the second round compared to the previously described embodiment. Figure 6b illustrates steps of a third round of a threshold signature method and steps for combining the contributions from three rounds of the threshold signature method to generate a signature according to a further embodiment. At step 4 of the third round shown in the in upper part of Figure 6b, each signer calculates an aggregated commitment, w, which is obtained by summing, across the signers, the LWE commitments, wj, made available at the end of the second round. The aggregated commitment, w, is subjected to bit dropping in accordance with a parameter, vw, which is a parameter that is made openly available to signers using the signature method. Accordingly, compared to the earlier embodiment, the term that is a product of the column blinders, mi, and the uniform matrix, A, is not included. In the combining process shown in a lower part of Figure 6b, at step 3, each signer calculates an aggregated commitment, w, which is obtained by summing, across the signers, the LWE commitments, Wj, made available at the end of the second round. The aggregated commitment, w, is subjected to bit dropping in accordance with a parameter, uw. Accordingly, compared to the earlier embodiment the term that is a product of the column blinders, mi, and the uniform matrix, A, is not included. In step 4, the central actor generates an aggregated response, z, by summing a difference between each of the individual responses, zi, made available at the end of the third round and the column blinder, mi, made available at the end of the first round. The difference in this step compared to the previously described method is the subtraction of the column blinder, mi. It is noted that in step 6, the term 2 to the power ut is equivalent to the bit shifting described previously in connection with the same step in Figure 4b. The differences between the previously described embodiment and the further embodiment serve to reduce the size of the aggregated response, z, making the signature method more efficient. The above embodiments are to be understood as illustrative examples of the invention. Further embodiments of the invention are envisaged. For example, in the description above, the key generation steps shown in Figure 2 are performed by a trusted central actor. In other implementations, a distributed key generation method could be used. Such distributed key generation could be performed using known techniques for secure multiparty computation. By distributing the key generation either among the signers, where the signers represent different devices, or among a plurality of other information processing apparatus, the overall security of the scheme may be improved but at the expense of additional computational load. In the examples above, the blinders are calculated based on pseudo-random function taking the shared seeds and a session identifier as an input. However, the use of the pseudorandom function and a session identifier is optional. The blinders could be generated by simply using sums of the shared seeds. In this case, the blinders would not vary with each iteration of the signature method. The session identifier described varies with each performance of the signature scheme and changes the blinders between each performance of the signature scheme. In the embodiments described above, the session identifier may be a counter or may be randomly generated for each session. The examples described above include the use of blinders. In further examples, the blinders may be omitted. Omitting the generation of each of the row and column blinders from the described methods, omitting publishing of the column blinders in the first round, and otherwise omitting terms relating to the row or column blinders where they appear in the method, such as during generation of the aggregated commitment, will result in a functioning threshold signature method. The blinders are included in the threshold signature method described above for security considerations. More particularly, the blinders shield information about the secret key that may be leaked by honest participants in the signature method when returning the secret share in the individual responses, Zj. In the examples above, two sets of blinders are generated in a T-out-of-T threshold fashion such that X / eact m; = Xieact m7 is publicly shared at the end of round 1 while m*7 can only be computed by actor j. Accordingly, each commitment w / is hidden behind an additive mask m*7 during the computation of individual responses z / . To preserve correctness during signature verification, the blinder is compensated for by adding A ■ m / to each LWE commitment, W / . The calculation of m and m* described above is symmetric as explained above in connection with Figure 3. Accordingly, the use of row and column blinders described above can be swapped (i.e. the row blinder used where the column blinder was used and vice versa). It is to be understood that any feature described in relation to any one embodiment may be used alone, or in combination with other features described, and may also be used in combination with one or more features of any other of the embodiments, or any combination of any other of the embodiments. Furthermore, equivalents and modifications not described above may also be employed without departing from the scope of the invention, which is defined in the accompanying claims.

Claims

1. A threshold signature method performed by one or more information processing apparatus for generating a signature using a threshold number, T, out of a number N of secret shares generated from a secret, s, wherein the number of secret shares, N, is greater than the threshold number, T, the method comprising:generating a public matrix, A, and the secret, s;generating a small noise, e, and a public key, vk = (A, t) including a portion of the public key, t, that is a sum of the small noise, e, with a product of the public matrix, A, and the secret, s; andgenerating N secret shares, Si, from the secret, s;for each of the threshold number T of secret shares: generating a learning with errors sample, wj; generating a commitment, cmtj, that is a hash of at least the generated learning with error sample, Wj, andmaking the commitment, cmti, available in a first round of the signature method and making the learning with errors sample, Wj, available in a second round of the signature method;for each of the T secret shares in a third round of the signature method:generating an aggregated commitment, w, by summing the learning with errors samples, wj, across the T secret shares;generating a challenge, c, that is a hash of the public key, vk, a message to be signed, msg, and the aggregated commitment, w;generating an individual response, Zj, based on the challenge, c, the secret share, Sj, and an ephemeral randomness used to generate the learning with errors sample, rj; andmaking the individual response, Zj, available in the third round;combining the contributions in respect of the T secret shares in the first, second and third rounds to generate a signature by:generating an aggregated commitment, w, by summing the learning with errors samples, w, across the T secret shares;generating an aggregated response, z, by summing the individual responses, zj;generating a global challenge, c, by hashing the public key, vk, the message to be signed, msg, and the aggregated commitment, w;generating a hint, h, by:determining a noisy commitment, y, by subtracting a product of the global challenge, c, and the portion of the public key, t, from a product of the aggregated response, z, and the public matrix, A; andsubtracting the noisy commitment, y, from the aggregated commitment, w, to generate the hint, h; andoutputting a signature comprising the global challenge, c, the aggregated response, z, and the hint, h.

2. A method according to claim 1, further comprising:for each of the T secret shares generating a first blinder associated with the secret share;wherein the first blinder, mj, associated with each of the T secret shares is made available in a first round of the signature method;wherein in the third round:generating an aggregated commitment, w, comprises summing the learning with errors samples, Wj, and a product of the first blinder, mj, and the public matrix, A, across the T secret shares; andthe third round comprises generating a second blinder, m*j, associated with each of the T secret shares;wherein each individual response, zj, is based on the challenge, c, the secret share, Sj, an ephemeral randomness used to generate the learning with errors sample and the second blinder, m*j;wherein when combining the contributions in respect of the T secret shares in the first, second and third rounds to generate a signature:generating an aggregated commitment, w, is performed by summing across the T secret shares: the learning with errors samples, Wj, and a product of the first blinder, mj, and the public matrix, A.

3. A method according to claim 1, further comprising:for each of the T secret shares generating a first blinder associated with the secret share;wherein the first blinder, mj, associated with each of the T secret shares is made available in a first round of the signature method;generating a second blinder, m*j, associated with each of the T secret shares in the third round;wherein each individual response, zj, is based on the challenge, c, the secret share, sj, an ephemeral randomness used to generate the learning with errors sample and the second blinder, m*j;wherein when combining the contributions in respect of the T secret shares in the first, second and third rounds to generate a signature:generating an aggregated response, z, is performed by summing across the T secret shares: a difference between the individual responses, zj, and first blinder, mj.

4. A method according to claim 2 or claim 3 further comprising in connection with each of the N secret shares:generating a shared seed for the secret share and a respective shared seed for each of the other secret shares, andstoring the generated shared seeds in association with the respective secret shares such that each secret share is associated with shared seeds that were generated in respect of that secret share and shared seeds that were generated in respect of different secret shares in connection with that secret share.

5. A method according to claim 4, wherein generating the first blinder, mj, comprises one of: 1) generating the blinder based on T of the N shared seeds generated in respect of that secret share and 2) generating the blinder based on the shared seed generated in respect of the secret share for itself and T-l shared seeds that were generated in respect of 7-1 secret shares in connection with that secret share.

6. A method according to claim 5, wherein generating the second blinder, m*j, comprises the other of the following options that was not used to generate the first blinder: 1) generating the blinder based on T of the N shared seeds generated in respect of that secret share and 2) generating the blinder based on the shared seed generated in respect of the secret share for itself and T-\ shared seeds that were generated in respect of 7-1 secret shares in connection with that secret share.

7. A method according to claim 5 or claim 6, wherein generating a blinder based on a shared seed comprises generating the blinder based on the output of a pseudorandom function to which the shared seed and a session identifier are input.

8. A method according to any preceding claim wherein generating the aggregate commitment, w, comprises dropping a predetermined number of bits from the sum.

9. A method according to any preceding claim wherein the N secret shares are secret shares generated from a secret, s, using Shamir secret sharing algorithm based on a polynomial of degree at most T-l.

10. A method according to claim 9 wherein:generating an individual response for each secret share comprises taking a product of the challenge, c, a Lagrange coefficient, Xj, from the Shamir secret sharing algorithm associated with the secret share, Sj, and the secret share, Sj, and then adding to the product the ephemeral randomness, rj, used to generate the learning with errors sample and the second blinder, m*j.

11. A method according to any preceding claim further comprising verifying the signature, wherein verifying the signature comprises:generating a signature derived value that is a product of the public matrix, A, and the aggregated response, z, from the signature minus a product of the global challenge, c, from the signature and the portion of the public key, t;generating a new challenge value, c’, by taking a hash of: the public key, vk, the message, msg, and the signature derived value plus the hint from the signature, h; andcomparing the new challenge value, c\ to the global challenge, c, to determine if the signature is valid.

12. A method according to claim 11, further comprising comparing a length of the aggregated response, z, and the hint, h, from the signature with one or more threshold.

13. A method according to claim 12, wherein the signature is determined to be valid if the new challenge value, c\ is equal to the global challenge, c, from the signature and the length of the aggregated response and the hint are less than the one or more threshold.

14. A method according to any preceding claim, wherein in the first round, generating a learning with errors sample, Wj, comprises sampling the ephemeral randomness, q, and a small error, q, and generating the learning with errors sample, Wj, by taking adding the small error, ej, to a product of the public matrix, A, and the ephemeral randomness, q,15. A method according to any preceding claim wherein generating a commitment, cmtj, comprises generating a hash of the generated learning with error sample, wj, and one or more of: the message, msg, a session identifier, sid, and an identifier of the signer, act.

16. A method according to any of claims 1 to 15 wherein:generating a public matrix, A, generating a small noise, e, generating N signature shares, and the steps of combining the contributions in respect of the T secret shares in the first, second and third rounds is performed by a central information processing apparatus; andthe steps of the first, second and third rounds in respect of individual secret shares are performed by respective user information processing apparatus.

17. A method according to any of claims 1 to 15 wherein all the steps of the method are performed by a single information processing apparatus.

18. A method according to claim 17, comprising:sequentially retrieving each of the T secret shares from respective storage locations and performing the steps in the first round in respect of each secret share;sequentially retrieving each of the T secret shares from their respective storage locations and performing the steps in the second round in respect of each secret share; andsequentially retrieving each of the T secret shares from respective storage locations and performing the steps in the third round in respect of each secret share.

19. A method according to any of claims 1 to 15, wherein the following steps are performed by distributed multi-party computation:generating a public matrix, A, and the secret, s;generating a small noise, e, and a public key, vk = (A, t) for t that is a sum of the small noise, e, with a product of the public matrix, A, and the secret, s; andgenerating N shared secrets from, Si, from the secret, s.

20. One or more information processing apparatus, each comprising a processor and a storage medium storing computer-readable instructions, wherein the computer-readable instructions are configured to cause the one or more information processing apparatus to perform a method according to any of claims 1 to 19.

21. One or more programs that, when executed on one or more information processing apparatus cause the one or more information processing apparatus to perform a method according to any of claims 1 to 19.

Citation Information

Patent Citations

  • Lattice-based cryptographic digital signature scheme utilising masking

    EP4224785A1