|
Abstract : |
Abstract. Yranklin and Reiter introduced at Eurocrypt '95 verifiable signature sharing, a primitive for a fault tolerant distribution of signature verification. They proposed various practical protocols. For RSA signatures with exponent e-- 3 and n processors their protocol allows for up to (n- 1)/5 faulty processors (in general (n- 1)/(2 + e)). We consider a new unifying approach which uses homomorphlsms of secret sharing schemes, and present a verifiable signature sharing scheme for which as many as (n- 1)/3 processors can be faulty (for any value of e), and for which the number of interactions is reduced. I, |