Two-party ECDSA with JavaCard-based smartcards
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14330%2F25%3A00140394" target="_blank" >RIV/00216224:14330/25:00140394 - isvavai.cz</a>
Result on the web
<a href="http://dx.doi.org/10.1007/978-3-031-95764-2_7" target="_blank" >http://dx.doi.org/10.1007/978-3-031-95764-2_7</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1007/978-3-031-95764-2_7" target="_blank" >10.1007/978-3-031-95764-2_7</a>
Alternative languages
Result language
angličtina
Original language name
Two-party ECDSA with JavaCard-based smartcards
Original language description
Threshold signatures are an effective method for enhancing the security of signing keys based on distributing their storage across multiple devices and enabling direct signing using the produced key shares without reconstructing the original keys. For instance, a private key can be split between a smartphone and a smartcard, with each device controlling a key share. To create a signature, a user simply taps the smartcard on the smartphone, executing the threshold signing protocol over the contactless interface, which results in the signature. However, computing threshold signatures on smartcards presents significant challenges due to their limited computational resources. This issue becomes even more pronounced with ECDSA signatures, the most widely used type of elliptic-curve-based signatures. Unlike other common EC-based signature schemes, threshold ECDSA is computationally intensive because it requires the multiplication of secretly shared values. To address this challenge, we surveyed protocols for computing threshold ECDSA signatures and proposed three approaches viable for computation on current smartcards with different trade-offs. The first approach is based on a two-party protocol by Lindell [22], which is computable on smartcards thanks to their modular exponentiation coprocessor but still relatively slow. The remaining two approaches utilize the preprocessing model with an optional trusted preprocessing party. We implemented all three approaches for the JavaCard platform while considering the hardware constraints and evaluated their performance on a physical smartcard to assess their practicality.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
<a href="/en/project/VJ01010084" target="_blank" >VJ01010084: Digital evidence in criminal proceedings</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2025
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Applied Cryptography and Network Security: 23rd International Conference on Applied Cryptography and Network Security
ISBN
9783031957635
ISSN
0302-9743
e-ISSN
—
Number of pages
18
Pages from-to
158-175
Publisher name
Lecture Notes in Computer Science
Place of publication
Cham, Switzerland
Event location
Munich
Event date
Jan 1, 2025
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
001549663000007