{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,2]],"date-time":"2026-01-02T07:51:04Z","timestamp":1767340264600,"version":"3.41.2"},"reference-count":67,"publisher":"International Association for Cryptologic Research","license":[{"start":{"date-parts":[[2024,4,9]],"date-time":"2024-04-09T00:00:00Z","timestamp":1712620800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,6,3]]},"abstract":"<jats:p>  Distributed key generation (DKG) is a key building block in developing many efficient threshold cryptosystems. This work initiates the study of communication complexity and round complexity of DKG protocols over a point-to-point (bounded) synchronous network. Our key result is the first synchronous DKG protocol for discrete log-based cryptosystems with <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n              <mml:mrow>\n                <mml:mi>O<\/mml:mi>\n                <mml:mo stretchy=\"false\">(<\/mml:mo>\n                <mml:mi>\u03ba<\/mml:mi>\n                <mml:msup>\n                  <mml:mi>n<\/mml:mi>\n                  <mml:mn>3<\/mml:mn>\n                <\/mml:msup>\n                <mml:mo stretchy=\"false\">)<\/mml:mo>\n              <\/mml:mrow>\n            <\/mml:math> communication complexity (<mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n              <mml:mrow>\n                <mml:mi>\u03ba<\/mml:mi>\n              <\/mml:mrow>\n            <\/mml:math> denotes a security parameter) that tolerates any <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n              <mml:mrow>\n                <mml:mi>t<\/mml:mi>\n                <mml:mo>&lt;<\/mml:mo>\n                <mml:mi>n<\/mml:mi>\n                <mml:mo>\/<\/mml:mo>\n                <mml:mn>2<\/mml:mn>\n              <\/mml:mrow>\n            <\/mml:math> Byzantine faults among <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n              <mml:mrow>\n                <mml:mi>n<\/mml:mi>\n              <\/mml:mrow>\n            <\/mml:math> parties. We present two variants of the protocol: (i) a protocol with worst-case <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n              <mml:mrow>\n                <mml:mi>O<\/mml:mi>\n                <mml:mo stretchy=\"false\">(<\/mml:mo>\n                <mml:mi>\u03ba<\/mml:mi>\n                <mml:msup>\n                  <mml:mi>n<\/mml:mi>\n                  <mml:mn>3<\/mml:mn>\n                <\/mml:msup>\n                <mml:mo stretchy=\"false\">)<\/mml:mo>\n              <\/mml:mrow>\n            <\/mml:math> communication and  <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n              <mml:mrow>\n                <mml:mi>O<\/mml:mi>\n                <mml:mo stretchy=\"false\">(<\/mml:mo>\n                <mml:mi>t<\/mml:mi>\n                <mml:mo stretchy=\"false\">)<\/mml:mo>\n              <\/mml:mrow>\n            <\/mml:math> rounds, and (ii) a protocol with expected <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n              <mml:mrow>\n                <mml:mi>O<\/mml:mi>\n                <mml:mo stretchy=\"false\">(<\/mml:mo>\n                <mml:mi>\u03ba<\/mml:mi>\n                <mml:msup>\n                  <mml:mi>n<\/mml:mi>\n                  <mml:mn>3<\/mml:mn>\n                <\/mml:msup>\n                <mml:mo stretchy=\"false\">)<\/mml:mo>\n              <\/mml:mrow>\n            <\/mml:math> communication and expected constant rounds. In the process of achieving our results, we design (1) a novel weak gradecast protocol with a communication complexity of <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n              <mml:mrow>\n                <mml:mi>O<\/mml:mi>\n                <mml:mo stretchy=\"false\">(<\/mml:mo>\n                <mml:mi>\u03ba<\/mml:mi>\n                <mml:msup>\n                  <mml:mi>n<\/mml:mi>\n                  <mml:mn>2<\/mml:mn>\n                <\/mml:msup>\n                <mml:mo stretchy=\"false\">)<\/mml:mo>\n              <\/mml:mrow>\n            <\/mml:math> for linear-sized inputs and constant rounds, (2) a protocol called \u201crecoverable-set-of-shares\u201d for ensuring recovery of shared secrets, (3) an oblivious leader election protocol with <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n              <mml:mrow>\n                <mml:mi>O<\/mml:mi>\n                <mml:mo stretchy=\"false\">(<\/mml:mo>\n                <mml:mi>\u03ba<\/mml:mi>\n                <mml:msup>\n                  <mml:mi>n<\/mml:mi>\n                  <mml:mn>3<\/mml:mn>\n                <\/mml:msup>\n                <mml:mo stretchy=\"false\">)<\/mml:mo>\n              <\/mml:mrow>\n            <\/mml:math> communication and constant rounds, and (4) a multi-valued validated Byzantine agreement (MVBA) protocol with <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n              <mml:mrow>\n                <mml:mi>O<\/mml:mi>\n                <mml:mo stretchy=\"false\">(<\/mml:mo>\n                <mml:mi>\u03ba<\/mml:mi>\n                <mml:msup>\n                  <mml:mi>n<\/mml:mi>\n                  <mml:mn>3<\/mml:mn>\n                <\/mml:msup>\n                <mml:mo stretchy=\"false\">)<\/mml:mo>\n              <\/mml:mrow>\n            <\/mml:math> communication complexity for linear-sized inputs and expected constant rounds. Each of these primitives is of independent interest. <\/jats:p>","DOI":"10.62056\/ayfhsgvtw","type":"journal-article","created":{"date-parts":[[2024,7,8]],"date-time":"2024-07-08T15:52:04Z","timestamp":1720453924000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":3,"title":["Synchronous Distributed Key Generation without Broadcasts"],"prefix":"10.62056","author":[{"given":"Nibesh","family":"Shrestha","sequence":"first","affiliation":[{"name":"Supra Research","place":["USA"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adithya","family":"Bhat","sequence":"additional","affiliation":[{"name":"Visa Research","place":["USA"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aniket","family":"Kate","sequence":"additional","affiliation":[{"name":"Supra Research","place":["USA"]},{"name":"Purdue University","place":["USA"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kartik","family":"Nayak","sequence":"additional","affiliation":[{"name":"Duke University","place":["USA"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"48349","published-online":{"date-parts":[[2024,7,8]]},"reference":[{"key":"ref1:boldyreva2003threshold","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1007\/3-540-36288-6_3","article-title":"Threshold Signatures, Multisignatures and Blind Signatures\n  Based on the Gap-Diffie-Hellman-Group Signature Scheme","volume-title":"PKC\u00a02003: 6th International Workshop on Theory and Practice\n  in Public Key Cryptography","volume":"2567","author":"Alexandra Boldyreva","year":"2003"},{"key":"ref2:shoup2000practical","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/3-540-45539-6_15","article-title":"Practical Threshold Signatures","volume-title":"Advances in Cryptology \u2013 EUROCRYPT\u00a02000","volume":"1807","author":"Victor Shoup","year":"2000"},{"key":"ref3:DesmedtF89","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"307","DOI":"10.1007\/0-387-34805-0_28","article-title":"Threshold Cryptosystems","volume-title":"Advances in Cryptology \u2013 CRYPTO'89","volume":"435","author":"Yvo Desmedt","year":"1990"},{"journal-title":"GitHub","article-title":"Drand - A Distributed Randomness Beacon Daemon","author":"Drand","key":"ref4:drand"},{"key":"ref5:cachin2005random","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1145\/343477.343531","article-title":"Random oracles in constantipole: practical asynchronous\n  Byzantine agreement using cryptography (extended abstract)","volume-title":"19th ACM Symposium Annual on Principles of Distributed\n  Computing","author":"Christian Cachin","year":"2000"},{"key":"ref6:yin2019hotstuff","doi-asserted-by":"publisher","first-page":"347","DOI":"10.1145\/3293611.3331591","article-title":"HotStuff: BFT Consensus with Linearity and\n  Responsiveness","volume-title":"38th ACM Symposium Annual on Principles of Distributed\n  Computing","author":"Maofan Yin","year":"2019"},{"key":"ref7:shrestha2020optimality","doi-asserted-by":"publisher","first-page":"839","DOI":"10.1145\/3372297.3417284","article-title":"On the Optimality of Optimistic Responsiveness","volume-title":"ACM CCS 2020: 27th Conference on Computer and Communications\n  Security","author":"Nibesh Shrestha","year":"2020"},{"key":"ref8:hirt2005cryptographic","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"322","DOI":"10.1007\/11426639_19","article-title":"Cryptographic Asynchronous Multi-party Computation with\n  Optimal Resilience (Extended Abstract)","volume-title":"Advances in Cryptology \u2013 EUROCRYPT\u00a02005","volume":"3494","author":"Martin Hirt","year":"2005"},{"key":"ref9:hofheinz2004synchronous","article-title":"A Synchronous Model for Multi-Party Computation and the\n  Incompleteness of Oblivious Transfer","author":"Dennis Hofheinz","year":"2004","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref10:distributedKDC","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"346","DOI":"10.1007\/3-540-36178-2_22","article-title":"On Unconditionally Secure Robust Distributed Key\n  Distribution Centers","volume-title":"Advances in Cryptology \u2013 ASIACRYPT\u00a02002","volume":"2501","author":"Paolo D'Arco","year":"2002"},{"article-title":"Torus: Globally accessible public key infrastructure for\n  everyone","year":"2021","author":"Torus Lab","key":"ref11:Torus"},{"key":"ref12:pedersendkg","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"522","DOI":"10.1007\/3-540-46416-6_47","article-title":"A Threshold Cryptosystem without a Trusted Party","volume-title":"Advances in Cryptology \u2013 EUROCRYPT'91","volume":"547","author":"Torben P. Pedersen","year":"1991"},{"key":"ref13:gennaro2007secure","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/s00145-006-0347-3","article-title":"Secure distributed key generation for discrete-log based\n  cryptosystems","author":"Rosario Gennaro","year":"2007","journal-title":"Journal of Cryptology"},{"key":"ref14:canetti1999adaptive","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1007\/3-540-48405-1_7","article-title":"Adaptive Security for Threshold Cryptosystems","volume-title":"Advances in Cryptology \u2013 CRYPTO'99","volume":"1666","author":"Ran Canetti","year":"1999"},{"key":"ref15:nejidkgwithcomplaints","doi-asserted-by":"publisher","first-page":"4585","DOI":"10.1002\/sec.1651","article-title":"Distributed key generation protocol with a new complaint\n  management strategy","volume":"9","author":"Wafa Neji","year":"2016","journal-title":"Security and communication networks"},{"key":"ref16:gurkan2021aggregatable","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/978-3-030-77870-5_6","article-title":"Aggregatable distributed key generation","volume-title":"Annual International Conference on the Theory and\n  Applications of Cryptographic Techniques (EUROCRYPT'21)","author":"Kobi Gurkan","year":"2021"},{"key":"ref17:feldman1987practical","doi-asserted-by":"publisher","first-page":"427","DOI":"10.1109\/SFCS.1987.4","article-title":"A Practical Scheme for Non-interactive Verifiable Secret\n  Sharing","volume-title":"28th Annual Symposium on Foundations of Computer Science","author":"Paul Feldman","year":"1987"},{"key":"ref18:backes2011computational","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"590","DOI":"10.1007\/978-3-642-25385-0_32","article-title":"Computational Verifiable Secret Sharing Revisited","volume-title":"Advances in Cryptology \u2013 ASIACRYPT\u00a02011","volume":"7073","author":"Michael Backes","year":"2011"},{"key":"ref19:dolev1983authenticated","doi-asserted-by":"publisher","first-page":"656","DOI":"10.1137\/0212045","article-title":"Authenticated algorithms for Byzantine agreement","volume-title":"SIAM Journal on Computing","volume":"12","author":"Danny Dolev","year":"1983"},{"key":"ref20:tsimos2020gossiping","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"439","DOI":"10.1007\/978-3-031-15982-4_15","article-title":"Gossiping for Communication-Efficient Broadcast","volume-title":"Advances in Cryptology \u2013 CRYPTO\u00a02022, Part\u00a0III","volume":"13509","author":"Georgios Tsimos","year":"2022"},{"key":"ref21:katz2006expected","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"445","DOI":"10.1007\/11818175_27","article-title":"On Expected Constant-Round Protocols for Byzantine\n  Agreement","volume-title":"Advances in Cryptology \u2013 CRYPTO\u00a02006","volume":"4117","author":"Jonathan Katz","year":"2006"},{"key":"ref22:groth2016size","doi-asserted-by":"publisher","first-page":"305","DOI":"10.1007\/978-3-662-49896-5_11","article-title":"On the size of pairing-based non-interactive arguments","volume-title":"Advances in Cryptology\u2013EUROCRYPT 2016: 35th Annual\n  International Conference on the Theory and Applications of Cryptographic\n  Techniques, Vienna, Austria, May 8-12, 2016, Proceedings, Part II 35","author":"Jens Groth","year":"2016"},{"key":"ref23:momose2020optimal","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.DISC.2021.32","article-title":"Optimal Communication Complexity of Authenticated Byzantine\n  Agreement","volume-title":"35th International Symposium on Distributed Computing (DISC\n  2021)","author":"Atsuki Momose","year":"2021"},{"key":"ref24:schindler2019ethdkg","article-title":"ETHDKG: Distributed Key Generation with Ethereum Smart\n  Contracts","author":"Philipp Schindler","year":"2019","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref25:groth2021non","first-page":"339","article-title":"Non-interactive distributed key generation and key\n  resharing.","volume":"2021","author":"Jens Groth","year":"2021","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref26:cascudo2023mt","isbn-type":"print","doi-asserted-by":"publisher","first-page":"645","DOI":"10.1007\/978-3-031-33491-7_24","article-title":"Mt. Random: Multi-tiered Randomness Beacons","volume-title":"Applied Cryptography and Network Security: 21st\n  International Conference, ACNS 2023, Kyoto, Japan, June 19\u201322, 2023,\n  Proceedings, Part II","author":"Ignacio Cascudo","year":"2023","ISBN":"https:\/\/id.crossref.org\/isbn\/9783031334900"},{"key":"ref27:kate2012distributed","first-page":"377","article-title":"Distributed Key Generation in the Wild.","volume":"2012","author":"Aniket Kate","year":"2012","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref28:asyncdkg","doi-asserted-by":"publisher","first-page":"1751","DOI":"10.1145\/3372297.3423364","article-title":"Asynchronous Distributed Key Generation for\n  Computationally-Secure Randomness, Consensus, and Threshold Signatures","volume-title":"ACM CCS 2020: 27th Conference on Computer and Communications\n  Security","author":"Eleftherios Kokoris-Kogias","year":"2020"},{"key":"ref29:abraham2021reaching","series-title":"PODC'21","isbn-type":"print","doi-asserted-by":"publisher","first-page":"363","DOI":"10.1145\/3465084.3467914","article-title":"Reaching Consensus for Asynchronous Distributed Key\n  Generation","volume-title":"Proceedings of the 2021 ACM Symposium on Principles of\n  Distributed Computing","author":"Ittai Abraham","year":"2021","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450385480"},{"key":"ref30:das2021practical","doi-asserted-by":"publisher","first-page":"2518","DOI":"10.1109\/SP46214.2022.9833584","article-title":"Practical Asynchronous Distributed Key Generation","volume-title":"2022 IEEE Symposium on Security and Privacy","author":"Sourav Das","year":"2022"},{"key":"ref31:das2023practical","isbn-type":"print","first-page":"5359","article-title":"Practical Asynchronous High-threshold Distributed Key\n  Generation and Distributed Polynomial Sampling","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Sourav Das","year":"2023","ISBN":"https:\/\/id.crossref.org\/isbn\/9781939133373"},{"key":"ref32:abraham2023bingo","isbn-type":"print","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-031-38557-5_2","article-title":"Bingo: Adaptivity and Asynchrony in Verifiable Secret\n  Sharing and Distributed Key Generation","volume-title":"Advances in Cryptology \u2013 CRYPTO 2023: 43rd Annual\n  International Cryptology Conference, CRYPTO 2023, Santa Barbara, CA, USA,\n  August 20\u201324, 2023, Proceedings, Part I","author":"Ittai Abraham","year":"2023","ISBN":"https:\/\/id.crossref.org\/isbn\/9783031385568"},{"key":"ref33:ben2003resilient","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/s00446-002-0083-3","article-title":"Resilient-optimal interactive consistency in constant time","volume":"16","author":"Michael Ben-Or","year":"2003","journal-title":"Distributed Computing"},{"key":"ref34:pedersen1991non","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1007\/3-540-46766-1_9","article-title":"Non-Interactive and Information-Theoretic Secure Verifiable\n  Secret Sharing","volume-title":"Advances in Cryptology \u2013 CRYPTO'91","volume":"576","author":"Torben P. Pedersen","year":"1992"},{"key":"ref35:feldman1988optimal","doi-asserted-by":"publisher","first-page":"148","DOI":"10.1145\/62212.62225","article-title":"Optimal Algorithms for Byzantine Agreement","volume-title":"20th Annual ACM Symposium on Theory of Computing","author":"Paul Feldman","year":"1988"},{"key":"ref36:cachin2001secure","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"524","DOI":"10.1007\/3-540-44647-8_31","article-title":"Secure and Efficient Asynchronous Broadcast Protocols","volume-title":"Advances in Cryptology \u2013 CRYPTO\u00a02001","volume":"2139","author":"Christian Cachin","year":"2001"},{"key":"ref37:garay2007round","doi-asserted-by":"publisher","first-page":"658","DOI":"10.1109\/FOCS.2007.61","article-title":"Round Complexity of Authenticated Broadcast with a Dishonest\n  Majority","volume-title":"48th Annual Symposium on Foundations of Computer Science","author":"Juan A. Garay","year":"2007"},{"key":"ref38:abraham2019asymptotically","doi-asserted-by":"publisher","first-page":"337","DOI":"10.1145\/3293611.3331612","article-title":"Asymptotically Optimal Validated Asynchronous Byzantine\n  Agreement","volume-title":"38th ACM Symposium Annual on Principles of Distributed\n  Computing","author":"Ittai Abraham","year":"2019"},{"key":"ref39:lu2020dumbo","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1145\/3382734.3405707","article-title":"Dumbo-MVBA: Optimal Multi-Valued Validated Asynchronous\n  Byzantine Agreement, Revisited","volume-title":"39th ACM Symposium Annual on Principles of Distributed\n  Computing","author":"Yuan Lu","year":"2020"},{"key":"ref40:nayak2020improved","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.DISC.2020.28","article-title":"Improved Extension Protocols for Byzantine Broadcast and\n  Agreement","volume-title":"34th International Symposium on Distributed Computing (DISC\n  2020)","author":"Kartik Nayak","year":"2020"},{"key":"ref41:gao2022efficient","doi-asserted-by":"publisher","first-page":"246","DOI":"10.1109\/ICDCS54860.2022.00032","article-title":"Efficient asynchronous byzantine agreement without private\n  setups","volume-title":"2022 IEEE 42nd International Conference on Distributed\n  Computing Systems (ICDCS'22)","author":"Yingzi Gao","year":"2022"},{"key":"ref42:reed1960polynomial","doi-asserted-by":"publisher","first-page":"300","DOI":"10.1137\/0108018","article-title":"Polynomial codes over certain finite fields","volume":"8","author":"Irving S Reed","year":"1960","journal-title":"Journal of the society for industrial and applied\n  mathematics"},{"key":"ref43:nguyen2005accumulators","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1007\/978-3-540-30574-3_19","article-title":"Accumulators from Bilinear Pairings and Applications","volume-title":"Topics in Cryptology \u2013 CT-RSA\u00a02005","volume":"3376","author":"Lan Nguyen","year":"2005"},{"key":"ref44:boneh2008short","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1007\/s00145-007-9005-7","article-title":"Short Signatures Without Random Oracles and the SDH\n  Assumption in Bilinear Groups","volume":"21","author":"Dan Boneh","year":"2008","journal-title":"Journal of Cryptology"},{"key":"ref45:bhatrandpiper","doi-asserted-by":"publisher","first-page":"3502","DOI":"10.1145\/3460120.3484574","article-title":"RandPiper - Reconfiguration-Friendly Random Beacons with\n  Quadratic Communication","volume-title":"ACM CCS 2021: 28th Conference on Computer and Communications\n  Security","author":"Adithya Bhat","year":"2021"},{"key":"ref46:katedkginternet","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1109\/ICDCS.2009.21","article-title":"Distributed Key Generation for the Internet","volume-title":"29th IEEE International Conference on Distributed Computing\n  Systems\u2013ICDCS'09","author":"Aniket Kate","year":"2009"},{"key":"ref47:bacho2022adaptive","series-title":"CCS '22","isbn-type":"print","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1145\/3548606.3560656","article-title":"On the Adaptive Security of the Threshold BLS Signature\n  Scheme","volume-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer\n  and Communications Security","author":"Renas Bacho","year":"2022","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450394505"},{"key":"ref48:komlo2023formal","article-title":"A Formal Treatment of Distributed Key Generation, and New\n  Constructions","author":"Chelsea Komlo","year":"2023","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref49:merkle1987digital","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"369","DOI":"10.1007\/3-540-48184-2_32","article-title":"A Digital Signature Based on a Conventional Encryption\n  Function","volume-title":"Advances in Cryptology \u2013 CRYPTO'87","volume":"293","author":"Ralph C. Merkle","year":"1988"},{"key":"ref50:cascudo2017scrape","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/978-3-319-61204-1_27","article-title":"SCRAPE: Scalable Randomness Attested by Public Entities","volume-title":"ACNS 17: 15th International Conference on Applied\n  Cryptography and Network Security","volume":"10355","author":"Ignacio Cascudo","year":"2017"},{"key":"ref51:baric1997collision","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"480","DOI":"10.1007\/3-540-69053-0_33","article-title":"Collision-Free Accumulators and Fail-Stop Signature Schemes\n  Without Trees","volume-title":"Advances in Cryptology \u2013 EUROCRYPT'97","volume":"1233","author":"Niko Bari","year":"1997"},{"key":"ref52:feldman1997optimal","doi-asserted-by":"publisher","first-page":"873","DOI":"10.1137\/S0097539790187084","article-title":"An optimal probabilistic protocol for synchronous Byzantine\n  agreement","volume":"26","author":"Pesech Feldman","year":"1997","journal-title":"SIAM Journal on Computing"},{"key":"ref53:kate2010constant","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1007\/978-3-642-17373-8_11","article-title":"Constant-Size Commitments to Polynomials and Their\n  Applications","volume-title":"Advances in Cryptology \u2013 ASIACRYPT\u00a02010","volume":"6477","author":"Aniket Kate","year":"2010"},{"key":"ref54:erwig2021large","article-title":"Large-Scale Non-Interactive Threshold Cryptosystems in the\n  YOSO Model","author":"Andreas Erwig","year":"2021","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref55:katz2023round","article-title":"Round Optimal Fully Secure Distributed Key Generation","author":"Jonathan Katz","year":"2023","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref56:abraham2019synchronous","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"320","DOI":"10.1007\/978-3-030-32101-7_20","article-title":"Synchronous Byzantine Agreement with Expected $O(1)$\n  Rounds, Expected $O(n^2)$ Communication, and Optimal Resilience","volume-title":"FC 2019: 23rd International Conference on Financial\n  Cryptography and Data Security","volume":"11598","author":"Ittai Abraham","year":"2019"},{"key":"ref57:tomescu2020towards","doi-asserted-by":"publisher","first-page":"877","DOI":"10.1109\/SP40000.2020.00059","article-title":"Towards Scalable Threshold Cryptosystems","volume-title":"2020 IEEE Symposium on Security and Privacy","author":"Alin Tomescu","year":"2020"},{"key":"ref58:bacho2023network","isbn-type":"print","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/978-3-031-38557-5_3","article-title":"Network-Agnostic Security Comes (Almost) for Free in DKG and\n  MPC","volume-title":"Advances in Cryptology \u2013 CRYPTO 2023: 43rd Annual\n  International Cryptology Conference, CRYPTO 2023, Santa Barbara, CA, USA,\n  August 20\u201324, 2023, Proceedings, Part I","author":"Renas Bacho","year":"2023","ISBN":"https:\/\/id.crossref.org\/isbn\/9783031385568"},{"key":"ref59:bacho2023grandline","article-title":"GRandLine: Adaptively Secure DKG and Randomness Beacon\n  with (Almost) Quadratic Communication Complexity","author":"Renas Bacho","year":"2023","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref60:fuchsbauer2018algebraic","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-319-96881-0_2","article-title":"The algebraic group model and its applications","volume-title":"Advances in Cryptology (CRYPTO'18): 38th Annual\n  International Cryptology Conference, Santa Barbara, CA, USA, August 19\u201323,\n  2018, Proceedings, Part II 38","author":"Georg Fuchsbauer","year":"2018"},{"key":"ref61:feng2024breaking","article-title":"Breaking the Cubic Barrier: Distributed Key and Randomness\n  Generation through Deterministic Sharding","author":"Hanwen Feng","year":"2024","journal-title":"Cryptology ePrint Archive"},{"key":"ref62:fitzi2003efficient","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1145\/872035.872066","article-title":"Efficient player-optimal protocols for strong and\n  differential consensus","volume-title":"Proceedings of the twenty-second annual symposium on\n  Principles of distributed computing (PODC'03)","author":"Matthias Fitzi","year":"2003"},{"article-title":"Byzantine agreement, made trivial","year":"2016","author":"Silvio Micali","key":"ref63:micali2016byzantine"},{"key":"ref64:abraham2022asymptotically","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"384","DOI":"10.1007\/978-3-031-22318-1_14","article-title":"Asymptotically Free Broadcast in Constant Expected Time via\n  Packed VSS","volume-title":"TCC\u00a02022: 20th Theory of Cryptography Conference, Part\u00a0I","volume":"13747","author":"Ittai Abraham","year":"2022"},{"key":"ref65:fitzi2021new","series-title":"PODC'21","isbn-type":"print","doi-asserted-by":"publisher","first-page":"355","DOI":"10.1145\/3465084.3467907","article-title":"A New Way to Achieve Round-Efficient Byzantine Agreement","volume-title":"Proceedings of the 2021 ACM Symposium on Principles of\n  Distributed Computing","author":"Matthias Fitzi","year":"2021","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450385480"},{"key":"ref66:dolev1985bounds","doi-asserted-by":"publisher","first-page":"132","DOI":"10.1145\/800220.806690","article-title":"Bounds on Information Exchange for Byzantine Agreement","volume-title":"1st ACM Symposium Annual on Principles of Distributed\n  Computing","author":"Danny Dolev","year":"1982"},{"key":"ref67:fitzi2006optimally","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1145\/1146381.1146407","article-title":"Optimally efficient multi-valued Byzantine agreement","volume-title":"25th ACM Symposium Annual on Principles of Distributed\n  Computing","author":"Matthias Fitzi","year":"2006"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T21:26:59Z","timestamp":1733866019000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/2\/19"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,8]]},"references-count":67,"URL":"https:\/\/doi.org\/10.62056\/ayfhsgvtw","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"type":"electronic","value":"3006-5496"}],"subject":[],"published":{"date-parts":[[2024,7,8]]},"assertion":[{"value":"2024-04-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-06-03","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-2-66"}}