On the Adaptive Security of FROST
Elizabeth C. Crites, Jonathan Katz, Chelsea Komlo, Stefano Tessaro, Chenzhi Zhu
Abstract
FROST and its variants are state-of-the-art protocols for threshold Schnorr signatures that are used in real-world applications. While static security of these protocols has been shown by several works, the security of these protocols under adaptive corruptions—where an adversary can choose which parties to corrupt at any time based on information it learns during protocol executions—has remained a notorious open problem that has received renewed attention due to recent standardization efforts for threshold schemes.
We show adaptive security (without erasures) of FROST and several variants under different corruption thresholds and computational assumptions. Let n be the total number of parties, t+1 the signing threshold, and t_c an upper bound on the number of corrupted parties.
-
We prove adaptive security when t_c = t/2 in the random oracle model (ROM) based on the algebraic one-more discrete logarithm assumption (AOMDL)—the same conditions under which FROST is proven statically secure.
-
We introduce the low-dimensional vector representation (LDVR) problem, parameterized by t_c, t, and n, and prove adaptive security in the algebraic group model (AGM) and ROM based on the AOMDL assumption and the hardness of the LDVR problem for the corresponding parameters. In some regimes (including some t_c >t/2) we show the LDVR problem is unconditionally hard, while in other regimes (in particular, when t_c = t) we show that hardness of the LDVR problem is necessary for adaptive security to hold. In fact, we show that hardness of the LDVR problem is necessary for proving adaptive security of a broad class of threshold Schnorr signatures.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers2
- Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDHPaul Gerhart, Davide Li Calsi, Luigi Russo, Dominique SchröderEUROCRYPT 2026 · 1 citation
- Adaptively-Secure Three-Round Threshold Schnorr from DLGuilhem Niot, Michael Reichle, Kaoru TakemureEUROCRYPT 2026
Related papers
- Adaptively Secure Partially Non-interactive Threshold Schnorr Signatures in the AGMRenas Bacho, Yanbo Chen, Julian Loss, Stefano Tessaro et al.EUROCRYPT 2026 · 5 citations
- A Plausible Attack on the Adaptive Security of Threshold Schnorr SignaturesElizabeth C. Crites, Alistair StewartCRYPTO 2025 · 11 citations
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- On the Adaptive Security of Key-Unique Threshold SignaturesMichele Ciampi, Elizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2026
- Adaptively Secure Three-Round Threshold Schnorr Signatures from DDHRenas Bacho, Sourav Das, Julian Loss, Ling RenCRYPTO 2025 · 12 citations
