ROAST: Robust Asynchronous Schnorr Threshold Signatures
Tim Ruffing, Viktoria Ronge, Elliott Jin, Jonas Schneider-Bensch, Dominique Schröder
Abstract
Bitcoin and other cryptocurrencies have recently introduced support for Schnorr signatures whose cleaner algebraic structure, as compared to ECDSA, allows for simpler and more practical constructions of highly demanded "𝑡-of-𝑛" threshold signatures. However, existing Schnorr threshold signature schemes still fall short of the needs of real-world applications due to their assumption that the network is synchronous and due to their lack of robustness, i.e., the guarantee that 𝑡 honest signers are able to obtain a valid signature even in the presence of other malicious signers who try to disrupt the protocol. This hinders the adoption of threshold signatures in the cryptocurrency ecosystem, e.g., in second-layer protocols built on top of cryptocurrencies.
In this work, we propose ROAST, a simple wrapper that turns a given threshold signature scheme into a scheme with a robust and asynchronous signing protocol, as long as the underlying signing protocol is semi-interactive (i.e., has one preprocessing round and one actual signing round), provides identifiable aborts, and is unforgeable under concurrent signing sessions. When applied to the state-of-the-art Schnorr threshold signature scheme FROST, which fulfills these requirements, we obtain a simple, efficient, and highly practical Schnorr threshold signature scheme.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6ae0f8d6-e203-467c-b202-204080cecf58Cited by top-tier papers8
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Practical Schnorr Threshold Signatures Without the Algebraic Group ModelHien Chu, Paul Gerhart, Tim Ruffing, Dominique SchröderCRYPTO 2023 · 38 citations
- Flood and Submerse: Distributed Key Generation and Robust Threshold Signature from LatticesThomas Espitau, Guilhem Niot, Thomas PrestCRYPTO 2024 · 29 citations
- Unmasking TRaccoon: A Lattice-Based Threshold Signature with An Efficient Identifiable Abort ProtocolRafaël Del Pino, Shuichi Katsumata, Guilhem Niot, Michael Reichle et al.CRYPTO 2025 · 8 citations
- An Extended Hierarchy of Security Notions for Threshold Signature Schemes and Automated Analysis of Protocols That Use ThemCas Cremers, Aleksi Peltonen, Mang ZhaoCCS 2026 · 4 citations
Builds on10
- Fast Multiparty Threshold ECDSA with Fast Trustless SetupRosario Gennaro, Steven GoldfederCCS 2018 · 264 citations
- Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency CustodyYehuda Lindell, Ariel NofCCS 2018 · 220 citations
- Threshold ECDSA from ECDSA Assumptions: The Multiparty CaseJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2019 · 167 citations
- MuSig2: Simple Two-Round Schnorr Multi-signaturesJonas Nick, Tim Ruffing, Yannick SeurinCRYPTO 2021 · 147 citations
- UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable AbortsRan Canetti, Rosario Gennaro, Steven Goldfeder, Nikolaos Makriyannis et al.CCS 2020 · 135 citations
Related papers
- Adaptively Secure Partially Non-interactive Threshold Schnorr Signatures in the AGMRenas Bacho, Yanbo Chen, Julian Loss, Stefano Tessaro et al.EUROCRYPT 2026 · 5 citations
- Adaptively-Secure Three-Round Threshold Schnorr from DLGuilhem Niot, Michael Reichle, Kaoru TakemureEUROCRYPT 2026
- On the Adaptive Security of FROSTElizabeth C. Crites, Jonathan Katz, Chelsea Komlo, Stefano Tessaro et al.CRYPTO 2025 · 9 citations
- Adaptively Secure Three-Round Threshold Schnorr Signatures from DDHRenas Bacho, Sourav Das, Julian Loss, Ling RenCRYPTO 2025 · 12 citations
- Better than Advertised Security for Non-interactive Threshold SignaturesMihir Bellare, Elizabeth C. Crites, Chelsea Komlo, Mary Maller et al.CRYPTO 2022 · 71 citations
