Fast Batched Asynchronous Distributed Key Generation
Jens Groth, Victor Shoup
Abstract
We present new protocols for threshold Schnorr signatures that work in an asynchronous communication setting, providing robustness and optimal resilience. These protocols provide unprecedented performance in terms of communication and computational complexity. In terms of communication complexity, for each signature, a single party must transmit a few dozen group elements and scalars across the network (independent of the size of the signing committee). In terms of computational complexity, the amortized cost for one party to generate a signature is actually less than that of just running the standard Schnorr signing or verification algorithm (at least for moderately sized signing committees, say, up to 100).
For example, we estimate that with a signing committee of 49 parties, at most 16 of which are corrupt, we can generate 50,000 Schnorr signatures per second (assuming each party can dedicate one standard CPU core and 500Mbs of network bandwidth to signing). Importantly, this estimate includes both the cost of an offline precomputation phase (which just churns out message independent "presignatures") and an online signature generation phase. Also, the online signing phase can generate a signature with very little network latency (just one to three rounds, depending on how throughput and latency are balanced).
To achieve this result, we provide two new innovations. One is a new secret sharing protocol (again, asynchronous, robust, optimally resilient) that allows the dealer to securely distribute shares of a large batch of ephemeral secret keys, and to publish the corresponding ephemeral public keys. To achieve better performance, our protocol minimizes public-key operations, and in particular, is based on a novel technique that does not use the traditional technique based on "polynomial commitments". The second innovation is a new algorithm to efficiently combine ephemeral public keys contributed by different parties (some possibly corrupt) into a smaller number of secure ephemeral public keys. This new algorithm is based on a novel construction of a so-called "super-invertible matrix" along with a corresponding highly-efficient algorithm for multiplying this matrix by a vector of group elements.
As protocols for verifiably sharing a secret key with an associated public key and the technology of super-invertible matrices both play a major role in threshold cryptography and multi-party computation, our two new innovations should have applicability well beyond that of threshold Schnorr signatures.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers7
- Unmasking TRaccoon: A Lattice-Based Threshold Signature with An Efficient Identifiable Abort ProtocolRafaël Del Pino, Shuichi Katsumata, Guilhem Niot, Michael Reichle et al.CRYPTO 2025 · 8 citations
- GoSSamer: Lightweight and Linear-Communication Asynchronous (Dynamic Proactive) Secret Sharing and the ApplicationsXinxin Xing, Yizhong Liu, Boyang Liao, Jianwei Liu et al.S&P 2026 · 2 citations
- Secure Multiparty Computation of Threshold Signatures Made More EfficientHarry W. H. Wong, Jack P. K. Ma, Sherman S. M. ChowNDSS 2024
- Dumbo-MPC: Efficient Fully Asynchronous MPC with Optimal ResilienceYuan Su, Yuan Lu, Jiliang Li, Yuyi Wang et al.USENIX Security 2025
- SoK: Dlog-Based Distributed Key GenerationRenas Bacho, Alireza KavousiS&P 2025
Related papers
- SPRINT: High-Throughput Robust Distributed Schnorr SignaturesFabrice Benhamouda, Shai Halevi, Hugo Krawczyk, Yiping Ma et al.EUROCRYPT 2024 · 25 citations
- Succinct Two-Round Two-Party Signing from PCFsLennart Braun, Geoffroy Couteau, Kelsey Melissaris, Mahshid Riahinia et al.CRYPTO 2026
- Perfect Asynchronous MPC with Linear Communication OverheadIttai Abraham, Gilad Asharov, Shravani Patil, Arpita PatraEUROCRYPT 2024 · 15 citations
- Adaptively-Secure Three-Round Threshold Schnorr from DLGuilhem Niot, Michael Reichle, Kaoru TakemureEUROCRYPT 2026
- Adaptively Secure Three-Round Threshold Schnorr Signatures from DDHRenas Bacho, Sourav Das, Julian Loss, Ling RenCRYPTO 2025 · 12 citations
