IOHK | 論文

ライブラリー > Tweakable Sleeve: A Novel Sleeve Construction based on Tweakable Hash Functions

Tweakable Sleeve: A Novel Sleeve Construction based on Tweakable Hash Functions

July/2022, Marble '22

WALLET

Recently, Chaum et al. (ACNS'21) introduced Sleeve, which describes an extra security layer for signature schemes, i.e., ECDSA. This distinctive feature is a new key generation mechanism, allowing users to generate a ''back up key'' securely nested inside the secret key of a signature scheme.

Using this novel construction, the ''back up key'', which is secret, can be used to generate a ''proof of ownership'', i.e., only the rightful owner of this secret key can generate such a proof. This design offers a quantum secure fallback, i.e., a brand new quantum resistant signature, ready to be used, nested in the ECDSA secret key. In this work, we rely on the original Sleeve definition to generalize the construction to a modular design based on Tweakable Hash Functions, thus yielding a cleaner design of the primitive. Furthermore, we provide a thorough security analysis taking into account the security of the ECDSA signature scheme, which is lacking in the original work. Finally, we provide an analysis based on formal methods using Verifpal assuring the security guarantees our construction provides.