Conference paper

Adaptively Secure, Universally Composable Distributed Generation of Discrete-Logarithm Based Keys from Standard Assumptions

Abstract

Distributed key generation (DKG) protocols enable a set of parties to distributively generate a threshold-shared key pair (pk, sk), such that at least t parties must participate to reconstruct the secret. We introduce the first DKG protocols for discrete-logarithm based keys that are both universally composable and adaptively secure in the random oracle model, without erasure, inconsistent players, interactive assumptions, or oracle-aided simulation.

Our contributions are as follows:

  1. an adaptively secure, universally composable DKG that achieves guaranteed output delivery in three rounds assuming an honest majority,
  2. an adaptively secure, universally composable committed DKG that realizes our novel committed DKG functionality in two rounds with identifiable abort for a full corruption threshold, and
  3. as an application, an incredibly simple threshold Schnorr protocol in the committed DKG-hybrid model, implying a three-round adaptively secure and universally composable threshold Schnorr protocol with identifiable abort for a dishonest majority.

Most importantly, our DKG constructions are secure in the random oracle model under the DDH assumption. Our output guarantees are proven under the assumption of synchrony. To date, all existing DKG protocols for discrete-logarithm based keys satisfy weaker security notions or require stronger assumptions.