Enabling Efficient Threshold Signature Computation via Java Card API

Warning

This publication doesn't include Faculty of Economics and Administration. It includes Faculty of Informatics. Official publication website can be found on muni.cz.
Authors

DUFKA Antonín ŠVENDA Petr

Year of publication 2023
Type Article in Proceedings
Conference Proceedings of the 18th International Conference on Availability, Reliability and Security
MU Faculty or unit

Faculty of Informatics

Citation
Web Odkaz na autorský pre-print
Doi http://dx.doi.org/10.1145/3600160.3600180
Keywords threshold cryptography; Java Card; elliptic curves; Schnorr signatures; smartcards
Description Threshold signatures are becoming an increasingly popular method of signing key protection, primarily due to their ability to produce signatures that require the cooperation of multiple parties yet appear indistinguishable from a regular signature. This unique feature allows for their easy integration with existing systems, making them highly desirable in applications like national identity systems and transaction authorization, where they are being gradually deployed; their growing importance is further attested by NIST’s recently initiated efforts to standardize threshold schemes [19]. An issue often encountered in the deployment of threshold schemes is that their execution is not supported by current secure hardware, which is necessary for the secure handling of secrets, as storing the shares in regular memory puts them at an increased risk of compromise. This raises the question of whether it is possible to run state-of-the-art threshold protocols with current secure hardware that we attempt to answer for cryptographic smartcards. We analyzed algorithms available on smartcards with the Java Card platform and repurposed them to construct operations needed in threshold protocols. We use these derived operations to implement , a state-of-the-art threshold signature scheme currently in a standardization process, making it the first open smartcard implementation of a threshold protocol supporting an arbitrary threshold. We demonstrate the practicality of this approach on the latest smartcards with no requirement for proprietary libraries.
Related projects:

You are running an old browser version. We recommend updating your browser to its latest version.