arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

通过嵌套阈值多重签名为闪电网络启用阈值托管

Enabling Threshold Custody for the Lightning Network with Nested Threshold Multi-Signatures

Paul Gerhart, Nadav Kohen, Jesse Posner, Matias Furszyfer

arXiv 2608.20705首次发表:更新:

AI 中文总结

该研究针对闪电网络通道依赖易受攻击单密钥的问题,提出新型密码原语嵌套阈值多重签名,构造出Iceberg方案,实现单边部署阈值托管且开销低,吞吐量达未修改端点的93%以上。

AI 中文摘要

比特币闪电网络保障着价值数亿美元的资产,然而通道端点依赖的是易受攻击的单个在线密钥。尽管阈值签名已常规用于保护比特币链上资产,但闪电网络通道却始终缺乏实用的部署方案。这是因为将闪电网络参与方阈值化,需要在既定的两方MuSig2协议内部嵌套阈值签名方案,且不得改变其随机数交换或消息流。本研究通过形式化嵌套阈值多重签名解决了这一限制,这是一种用于在多重签名协议内部对单个参与方进行阈值化的新型密码原语。作为该原语的一个实例,我们提出了Iceberg,这是首个嵌套阈值MuSig2签名的构造方案。Iceberg使闪电网络通道的一侧可作为t-out-of-n阈值群组运行,同时对交易对手方而言表现为标准MuSig2参与方。因此,阈值托管可在当前闪电网络上单边部署,无需对比特币、闪电协议或通道交易对手方进行任何修改。我们证明了Iceberg的安全性,将原型集成到生产级闪电节点中并对其性能进行了基准测试。测量结果显示,对闪电网络通道进行阈值化仅会产生适度开销:当阈值群组容忍1个被损坏成员时,其支付吞吐量可达未修改端点的93%以上。

英文摘要

The Bitcoin Lightning Network secures hundreds of millions of dollars, yet channel endpoints rely on vulnerable single online keys. Although threshold signatures are routinely used to protect on-chain Bitcoin, no practical deployment has been possible for Lightning channels. This is because thresholdizing a Lightning party requires nesting a threshold signature scheme inside of an established two-party MuSig2 protocol without altering its nonce exchange or message flow. In this work, we resolve this limitation by formalizing nested threshold multi-signatures, a new cryptographic primitive for thresholdizing one participant inside a multi-signature protocol. As an instance of this primitive, we present Iceberg, the first construction for nested threshold MuSig2 signatures. Iceberg enables one side of a Lightning channel to operate as a $t$-of-$n$ threshold group while appearing to the counterparty as a standard MuSig2 participant. As a result, threshold custody can be deployed unilaterally on today's Lightning Network without requiring any modifications to Bitcoin, the Lightning protocol, or channel counterparties. We prove the security of Iceberg, integrate a prototype into a production Lightning node, and benchmark its performance. Our measurements show that thresholdizing a Lightning channel incurs only modest overhead, since a threshold group tolerating one corrupted member sustains over $93\%$ of the payment throughput of an unmodified endpoint.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑