Skip to main content
Springer Nature Link
Log in
Menu
Find a journal Publish with us Track your research
Search
Saved research
Cart
  1. Home
  2. Journal of Cryptology
  3. Article

Secure Distributed Key Generation for Discrete-Log Based Cryptosystems

  • Published: 24 May 2006
  • Volume 20, pages 51–83 (2007)
  • Cite this article
Download PDF
Save article
View saved research
Image Journal of Cryptology Aims and scope Submit manuscript
Secure Distributed Key Generation for Discrete-Log Based Cryptosystems
Download PDF
  • Rosario Gennaro1,
  • Stanislaw Jarecki2,
  • Hugo Krawczyk1 &
  • …
  • Tal Rabin1 
  • 11k Accesses

  • 362 Citations

  • 21 Altmetric

  • Explore all metrics

Abstract

A Distributed Key Generation (DKG) protocol is an essential component of threshold cryptosystems required to initialize the cryptosystem securely and generate its private and public keys. In the case of discrete-log-based (dlog-based) threshold signature schemes (ElGamal and its derivatives), the DKG protocol is further used in the distributed signature generation phase to generate one-time signature randomizers (r = gk). In this paper we show that a widely used dlog-based DKG protocol suggested by Pedersen does not guarantee a uniformly random distribution of generated keys: we describe an efficient active attacker controlling a small number of parties which successfully biases the values of the generated keys away from uniform. We then present a new DKG protocol for the setting of dlog-based cryptosystems which we prove to satisfy the security requirements from DKG protocols and, in particular, it ensures a uniform distribution of the generated keys. The new protocol can be used as a secure replacement for the many applications of Pedersen's protocol. Motivated by the fact that the new DKG protocol incurs additional communication cost relative to Pedersen's original protocol, we investigate whether the latter can be used in specific applications which require relaxed security properties from the DKG protocol. We answer this question affirmatively by showing that Pedersen's protocol suffices for the secure implementation of certain threshold cryptosystems whose security can be reduced to the hardness of the discrete logarithm problem. In particular, we show Pedersen's DKG to be sufficient for the construction of a threshold Schnorr signature scheme. Finally, we observe an interesting trade-off between security (reductions), computation, and communication that arises when comparing Pedersen's DKG protocol with ours.

Article PDF

Download to read the full article text

Similar content being viewed by others

Image

Round-Optimal, Fully Secure Distributed Key Generation

Chapter © 2024
Image

Distributed Key Generation for SM2 and Its Application to Threshold Encryption

Chapter © 2026
Image

Adaptively Secure, Universally Composable Distributed Generation of Discrete-Logarithm Based Keys from Standard Assumptions

Chapter © 2026

Explore related subjects

Discover the latest articles, books and news in related subjects, suggested using machine learning.
  • DNA computing and cryptography
  • Principles and Models of Security
  • Quantum Communications and Cryptography
  • Register-Transfer-Level Implementation
  • Cryptology
  • Blockchain
  • Security Protocols for Networked Systems

Author information

Authors and Affiliations

  1. IBM T.J. Watson Research Center, P.O. Box 704, Yorktown Heights, NY 10598, USA

    Rosario Gennaro, Hugo Krawczyk & Tal Rabin

  2. School of Information and Computer Science, University of California, Irvine, CA 92697-3425, USA

    Stanislaw Jarecki

Authors
  1. Rosario Gennaro
    View author publications

    Search author on:PubMed Google Scholar

  2. Stanislaw Jarecki
    View author publications

    Search author on:PubMed Google Scholar

  3. Hugo Krawczyk
    View author publications

    Search author on:PubMed Google Scholar

  4. Tal Rabin
    View author publications

    Search author on:PubMed Google Scholar

Corresponding authors

Correspondence to Rosario Gennaro, Stanislaw Jarecki, Hugo Krawczyk or Tal Rabin.

Rights and permissions

Reprints and permissions

About this article

Cite this article

Gennaro, R., Jarecki, S., Krawczyk, H. et al. Secure Distributed Key Generation for Discrete-Log Based Cryptosystems. J Cryptology 20, 51–83 (2007). https://doi.org/10.1007/s00145-006-0347-3

Download citation

  • Received: 09 September 2003

  • Revised: 02 August 2005

  • Published: 24 May 2006

  • Issue date: January 2007

  • DOI: https://doi.org/10.1007/s00145-006-0347-3

Share this article

Anyone you share the following link with will be able to read this content:

Sorry, a shareable link is not currently available for this article.

Provided by the Springer Nature SharedIt content-sharing initiative

Keywords

  • Signature Scheme
  • Secret Sharing
  • Discrete Logarithm
  • Threshold Scheme
  • Random Oracle Model

Advertisement

Search

Navigation

  • Find a journal
  • Publish with us
  • Track your research

Footer Navigation

Discover content

  • Journals A-Z
  • Books A-Z
  • Subjects A-Z

Publish with us

  • Journal finder
  • Publish your research
  • Language editing
  • Open access publishing

Products and services

  • Our products
  • Librarians
  • Societies
  • Partners and advertisers

Our brands

  • Springer
  • Nature Portfolio
  • BMC
  • Palgrave Macmillan
  • Apress
  • Discover

Corporate Navigation

  • Your US state privacy rights
  • Accessibility statement
  • Terms and conditions
  • Privacy policy
  • Help and support
  • Legal notice
  • Cancel contracts here

104.23.243.214

Not affiliated

Springer Nature

© 2026 Springer Nature