Adaptively-Secure Three-Round Threshold Schnorr from DL
Guilhem Niot, Michael Reichle, Kaoru Takemure
Abstract
Threshold signatures are an important tool for trust distribution, and preserving the interface of standardized signatures, such as Schnorr signatures, is crucial for their adoption. In practice, latency dominates end-to-end signing time, so minimizing the number of interaction rounds is critical. Ideally, this is achieved under minimal assumptions and with adaptive security, where the adversary can corrupt signers on-the-fly during the protocol.
While Schnorr signatures are proven secure under the Discrete Logarithm (DL) assumption in the random oracle model, the most round-efficient adaptively-secure threshold Schnorr protocols rely on stronger assumptions such as Decisional Diffie-Hellman (DDH), the Algebraic One-More Discrete Logarithm (AOMDL) or even the Low-Dimensional Vector Representation (LDVR) assumptions. The only adaptively-secure threshold Schnorr signature from the DL assumption requires five rounds, leaving a significant gap in our understanding of this fundamental primitive. Achieving low-round protocols with adaptive security from the DL assumption has remained an open question.
We resolve this question by presenting the first adaptively-secure threshold Schnorr scheme in three rounds (two online, one offline) in the random oracle model under the DL assumption. Our result demonstrates that achieving both low round complexity and adaptive security is possible while preserving the (so far) minimal assumptions for Schnorr signatures. To achieve this, we introduce new techniques, including a novel use of an equivocal commitment scheme paired with a simulation-extractable NIZK, and a masking-based aggregated opening strategy for homomorphic commitments. Our work also makes several contributions that might be of independent interest, including a formalization of a strong adaptive security notion, a stronger commitment equivocation property, and an analysis of the simulation-extractability of the randomized Fischlin transformation. This is the full version of a paper to appear in the proceedings of EUROCRYPT 2026. It additionally contains the formal definitions and detailed proofs deferred from the published version. 1. We introduce labels which allow for more fine-grained control over which proofs are extractable.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on19
- On the Security of Two-Round Multi-SignaturesManu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz et al.S&P 2019 · 126 citations
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Better than Advertised Security for Non-interactive Threshold SignaturesMihir Bellare, Elizabeth C. Crites, Chelsea Komlo, Mary Maller et al.CRYPTO 2022 · 71 citations
- Threshold Raccoon: Practical Threshold Signatures from Standard Lattice AssumptionsRafaël Del Pino, Shuichi Katsumata, Mary Maller, Fabrice Mouhartem et al.EUROCRYPT 2024 · 61 citations
- ROAST: Robust Asynchronous Schnorr Threshold SignaturesTim Ruffing, Viktoria Ronge, Elliott Jin, Jonas Schneider-Bensch et al.CCS 2022 · 50 citations
Related papers
- Adaptively Secure Three-Round Threshold Schnorr Signatures from DDHRenas Bacho, Sourav Das, Julian Loss, Ling RenCRYPTO 2025 · 12 citations
- Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDHPaul Gerhart, Davide Li Calsi, Luigi Russo, Dominique SchröderEUROCRYPT 2026 · 1 citation
- Adaptively Secure Partially Non-interactive Threshold Schnorr Signatures in the AGMRenas Bacho, Yanbo Chen, Julian Loss, Stefano Tessaro et al.EUROCRYPT 2026 · 5 citations
- Adaptively Secure 5 Round Threshold Signatures from MLWE/MSIS and DL with RewindingShuichi Katsumata, Michael Reichle, Kaoru TakemureCRYPTO 2024 · 34 citations
- On the Adaptive Security of FROSTElizabeth C. Crites, Jonathan Katz, Chelsea Komlo, Stefano Tessaro et al.CRYPTO 2025 · 9 citations
