MuSig2: Simple Two-Round Schnorr Multi-signatures
Jonas Nick, Tim Ruffing, Yannick Seurin
Abstract
Multi-signatures enable a group of signers to produce a joint signature on a joint message. Recently, Drijvers et al. (S&P'19) showed that all thus far proposed two-round multi-signature schemes in the pure DL setting (without pairings) are insecure under concurrent signing sessions. While Drijvers et al. proposed a secure two-round scheme, this efficiency in terms of rounds comes with the price of having signatures that are more than twice as large as Schnorr signatures, which are becoming popular in cryptographic systems due to their practicality (e.g., they will likely be adopted in Bitcoin). If one needs a multi-signature scheme that can be used as a drop-in replacement for Schnorr signatures, then one is forced to resort either to a three-round scheme or to sequential signing sessions, both of which are undesirable options in practice.
In this work, we propose MuSig2, a simple and highly practical two-round multi-signature scheme. This is the first scheme that simultaneously i) is secure under concurrent signing sessions, ii) supports key aggregation, iii) outputs ordinary Schnorr signatures, iv) needs only two communication rounds, and v) has similar signer complexity as ordinary Schnorr signatures. Furthermore, it is the first multi-signature scheme in the pure DL setting that supports preprocessing of all but one rounds, effectively enabling a non-interactive signing process without forgoing security under concurrent sessions. We prove the security of MuSig2 in the random oracle model, and the security of a more efficient variant in the combination of the random oracle and the algebraic group model. Both our proofs rely on a weaker variant of the OMDL assumption.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5947869e-5a1f-44d1-aabc-3dd376bb049eCited by top-tier papers15
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- MuSig-L: Lattice-Based Multi-signature with Single-Round Online PhaseCecilia Boschini, Akira Takahashi, Mehdi TibouchiCRYPTO 2022 · 54 citations
- ROAST: Robust Asynchronous Schnorr Threshold SignaturesTim Ruffing, Viktoria Ronge, Elliott Jin, Jonas Schneider-Bensch et al.CCS 2022 · 50 citations
- Threshold and Multi-signature Schemes from Linear Hash FunctionsStefano Tessaro, Chenzhi ZhuEUROCRYPT 2023 · 48 citations
- Threshold Signatures with Private AccountabilityDan Boneh, Chelsea KomloCRYPTO 2022 · 48 citations
Related papers
- Chopsticks: Fork-Free Two-Round Multi-signatures from Non-interactive AssumptionsJiaxin Pan, Benedikt WagnerEUROCRYPT 2023 · 24 citations
- On the Security of Two-Round Multi-SignaturesManu Drijvers, Kasra Edalatnejad, Bryan Ford, Eike Kiltz et al.S&P 2019 · 126 citations
- MuSig-DN: Schnorr Multi-Signatures with Verifiably Deterministic NoncesJonas Nick, Tim Ruffing, Yannick Seurin, Pieter WuilleCCS 2020 · 2 citations
- DahLIAS: Discrete Logarithm-Based Interactive Aggregate SignaturesJonas Nick, Tim Ruffing, Yannick SeurinEUROCRYPT 2026
- Schnorr Signatures and MuSig2 are Jointly Secure, Even in Deterministic WalletsRenas Bacho, Yanbo Chen, Poulami Das, Julian Loss et al.CCS 2026
