Practical Schnorr Threshold Signatures Without the Algebraic Group Model
Hien Chu, Paul Gerhart, Tim Ruffing, Dominique Schröder
Abstract
Threshold signatures are digital signature schemes in which a set of n signers specify a threshold t such that any subset of size t is authorized to produce signatures on behalf of the group. There has recently been a renewed interest in this primitive, largely driven by the need to secure highly valuable signing keys, e.g., DNSSEC keys or keys protecting digital wallets in the cryptocurrency ecosystem. Of special interest is FROST, a practical Schnorr threshold signature scheme, which is currently undergoing standardization in the IETF and whose security was recently analyzed at CRYPTO'22. We continue this line of research by focusing on FROST's unforgeability combined with a practical distributed key generation (DKG) algorithm. Existing proofs of this setup either use non-standard heuristics, idealized group models like the AGM, or idealized key generation. Moreover, existing proofs do not consider all practical relevant optimizations that have been proposed. We close this gap between theory and practice by presenting the Schnorr threshold signature scheme Olaf, which combines the most efficient known FROST variant FROST3 with a variant of Pedersen's DKG protocol (as commonly used for FROST), and prove its unforgeability. Our proof relies on the AOMDL assumption (a weaker and falsifiable variant of the OMDL assumption) and, like proofs of regular Schnorr signatures, on the random oracle model.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3eb94f91-0bbc-4e9f-8eb5-92857f12450dCited by top-tier papers5
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Distributed Randomness Using Weighted VUFsSourav Das, Benny Pinkas, Alin Tomescu, Zhuolun XiangEUROCRYPT 2025 · 7 citations
- Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDHPaul Gerhart, Davide Li Calsi, Luigi Russo, Dominique SchröderEUROCRYPT 2026 · 1 citation
- Do You Need a Receipt? Anonymous Credential Revocation at Continental Scale via Private Record CertificationKasra EdalatNejad, Sebastian Faust, Jonas Hofmann, Philipp-Florens Lehwalder et al.USENIX Security 2026 · 1 citation
- Adaptively-Secure Three-Round Threshold Schnorr from DLGuilhem Niot, Michael Reichle, Kaoru TakemureEUROCRYPT 2026
Builds on9
- Fast Multiparty Threshold ECDSA with Fast Trustless SetupRosario Gennaro, Steven GoldfederCCS 2018 · 264 citations
- Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency CustodyYehuda Lindell, Ariel NofCCS 2018 · 220 citations
- Threshold ECDSA from ECDSA Assumptions: The Multiparty CaseJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2019 · 167 citations
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 147 citations
- UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable AbortsRan Canetti, Rosario Gennaro, Steven Goldfeder, Nikolaos Makriyannis et al.CCS 2020 · 135 citations
Related papers
- Adaptively Secure Partially Non-interactive Threshold Schnorr Signatures in the AGMRenas Bacho, Yanbo Chen, Julian Loss, Stefano Tessaro et al.EUROCRYPT 2026 · 5 citations
- ROAST: Robust Asynchronous Schnorr Threshold SignaturesTim Ruffing, Viktoria Ronge, Elliott Jin, Jonas Schneider-Bensch et al.CCS 2022 · 50 citations
- Better than Advertised Security for Non-interactive Threshold SignaturesMihir Bellare, Elizabeth C. Crites, Chelsea Komlo, Mary Maller et al.CRYPTO 2022 · 71 citations
- On the Adaptive Security of FROSTElizabeth C. Crites, Jonathan Katz, Chelsea Komlo, Stefano Tessaro et al.CRYPTO 2025 · 9 citations
- Adaptively Secure Three-Round Threshold Schnorr Signatures from DDHRenas Bacho, Sourav Das, Julian Loss, Ling RenCRYPTO 2025 · 12 citations
