U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

Presentation

Notes on Threshold EdDSA/Schnorr Signatures

August 10, 2022

Presenters

Luís T. A. N. Brandão

Description

Abstract: EdDSA is one of the signature schemes specified in the NIST Draft FIPS 186-5. As a Schnorr-style scheme, its signature makes an interesting linear combination of two secrets --- the signing key and a (pseudo)random secret nonce. Assuming both secrets are linearly secret-shared, it is easy to obtain a signature in a threshold manner, i.e., without reconstructing the key. However, the secret-sharing of the nonce gives rise to various approaches, which, absent proper consideration, can be insecurely instantiated (allowing key recovery or forgeries). This presentation will overview some notes on conventional EdDSA/Schnorr, and on threshold signatures interchangeable with respect to the FIPS-specified EdDSA verification.

Joint work (NIST IR 8214B) with Michael Davidson

Presented at

Crypto Reading Club talk on 2022-Aug-10

Parent Project

See: Crypto Reading Club

Related Topics

Security and Privacy: cryptography

Created August 11, 2022