UC-Secure Star DKG for Non-Exportable Key Shares with VSS-Free Enforcement
Vipin Singh Sehrawat

TL;DR
This paper introduces a UC-secure distributed key generation scheme tailored for non-exportable hardware-backed key shares, eliminating the need for verifiable secret sharing while ensuring security and consistency.
Contribution
It presents the first UC-secure DKG scheme compatible with non-exportable key shares enforced by hardware modules, using novel verification and proof techniques.
Findings
Constructs a UC-secure multi-device threshold wallet scheme.
Achieves security under standard cryptographic assumptions with practical overhead.
Enforces affine consistency without share resharing or exporting.
Abstract
Distributed Key Generation (DKG) lets parties derive a common public key while keeping the signing key secret-shared. UC-secure DKG requires a verifiable-sharing enforcement layer -- classically satisfied via Verifiable Secret Sharing (VSS) and/or commitment-and-proof mechanisms -- for secrecy, uniqueness, and affine consistency. We target the Non-eXportable Key (NXK) setting enforced by hardware-backed key-isolation modules (e.g., TEEs, HSM-like APIs), formalized via an ideal KeyBox (keystore) functionality that keeps shares non-exportable and permits only attested KeyBox-to-KeyBox sealing. With confidentiality delegated to the NXK boundary, the remaining challenge is enforcing transcript-defined affine consistency without exporting or resharing shares. State continuity rules out rewinding-based extraction, mandating straight-line techniques. We combine (i)…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
