拜占庭容错后量子分布式仲裁签名
Byzantine Fault-Tolerant Post-Quantum Distributed Quorum Signatures
浏览论文内容
中文总结 AI 辅助
研究如何将拜占庭容错系统迁移至后量子安全,核心方法是引入分布式仲裁签名(DQS),它由普通数字签名和广播构建,消息固定大小,总通信量二次,开销与经典方案有竞争力,解决了后量子仲裁签名难题。
中文摘要 AI 辅助
阈值、聚合和多重签名(统称为仲裁签名)可证明一定数量的节点认可某一声明,且证书大小仅为单个签名。目前尚无已知的固定大小后量子仲裁签名:所有候选方案都随签名者数量增长且聚合缓慢,这使仲裁签名成为将拜占庭容错系统迁移至后量子安全的最大障碍。本文通过改变协议通信方式避开了这一开放密码学问题。我们引入了一种称为分布式仲裁签名(DQS)的原语,它仅由普通数字签名和Bracha风格的批准广播构建而成。DQS将证书从网络消息转变为本地事件。两种事件类型划分了证书所起的作用:弱证书捕获安全性,强证书捕获活性。在DQS中,每条消息大小固定,无论节点数量多少都适合单个数据报。总通信量是二次的,且安全假设不变。在大型分布式系统中,后量子DQS的开销与经典的前量子BLS方案具有竞争力。
英文摘要
Threshold, aggregate, and multi-signatures -- which we collectively call quorum signatures -- certify that a quorum of nodes endorsed a statement, with a certificate as small as a single signature. No constant-size post-quantum quorum signature is known: all candidates grow with the number of signers and are slow to aggregate, making quorum signatures the hardest obstacle to migrating byzantine fault-tolerant systems to post-quantum security. In this paper, we sidestep this open cryptographic problem by changing how the protocol communicates. We introduce a primitive we call Distributed Quorum Signature (DQS), built solely from ordinary digital signatures and a Bracha-style approval broadcast. DQS turns certificates from network messages into local events. Two event types divide the roles certificates play: weak certificates capture safety, strong certificates capture liveness. In DQS every message is constant size, fitting a single datagram regardless of the number of nodes. The total communication is quadratic, and no security assumptions change. In a large distributed system, the overhead of post-quantum DQS is competitive with the canonical pre-quantum BLS scheme.