USENIX Security2026Top-tier venue
Quorus: Efficient, Scalable Threshold ML-DSA Signatures from MPC
Alexander Bienstock, Leo de Castro, Daniel Escudero, Antigoni Polychroniadou, Akira Takahashi
Abstract
A threshold signature protocol divides a secret signing key among multiple parties, enabling any subset above a threshold to jointly create a signature. While post-quantum (PQ) threshold signatures are being studied, especially following NIST's call for threshold schemes, most solutions focus on specially designed, threshold-friendly signature schemes. However, real-world applications like distributed certificate authorities and digital currencies require signatures verifiable under existing standardized procedures. With NIST's standardization of PQ signatures and ongoing industry deployment, designing an efficient threshold scheme compatible with NIST-standardized verification remains a critical challenge. In this work, we present the first efficient and scalable solution for multi-party generation of the module-lattice digital signature algorithm (ML-DSA), one of NIST's PQ signature standards. Our contributions are two-fold. First, we present a variant of the ML-DSA signing algorithm that is amenable to efficient multi-party computation (MPC) and prove that this variant achieves the same security as the original ML-DSA scheme. Second, we present several efficient & scalable MPC protocols to instantiate the threshold signing functionality. Our protocols can produce threshold signatures with as little as 150 KB (per party) of online communication per rejection-sampling round. In addition, we instantiate our protocols in the honest-majority setting, which allows us to avoid any additional public key assumptions. Our signatures verify under the same ML-DSA implementation for all security levels, with signature and verification key sizes matching ML-DSA; previous lattice-based threshold schemes could not match both of these sizes. Our solution provides the first method for producing threshold post-quantum signatures compatible with NIST-standardized verification, scalable to any number of parties, without new assumptions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on15
- Improved Primitives for MPC over Mixed Arithmetic-Binary CircuitsDaniel Escudero, Satrajit Ghosh, Marcel Keller, Rahul Rachuri et al.CRYPTO 2020 · 123 citations
- Fully Adaptive Schnorr Threshold SignaturesElizabeth C. Crites, Chelsea Komlo, Mary MallerCRYPTO 2023 · 79 citations
- Guaranteed Output Delivery Comes Free in Honest Majority MPCVipul Goyal, Yifan Song, Chenzhi ZhuCRYPTO 2020 · 68 citations
- Threshold Raccoon: Practical Threshold Signatures from Standard Lattice AssumptionsRafaël Del Pino, Shuichi Katsumata, Mary Maller, Fabrice Mouhartem et al.EUROCRYPT 2024 · 61 citations
- MuSig-L: Lattice-Based Multi-signature with Single-Round Online PhaseCecilia Boschini, Akira Takahashi, Mehdi TibouchiCRYPTO 2022 · 54 citations
Related papers
- Efficient Threshold ML-DSASofía Celi, Rafael del Pino, Thomas Espitau, Guilhem Niot et al.USENIX Security 2026 · 1 citation
- Ringtail: Practical Two-Round Threshold Signatures from Learning with ErrorsCecilia Boschini, Darya Kaviani, Russell W. F. Lai, Giulio Malavolta et al.S&P 2025
- Secure Two-party Threshold ECDSA from ECDSA AssumptionsJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2018 · 171 citations
- A Full Threshold NIST PQC-Compliant Framework for Distributed Trust in Federal Public Key InfrastructureKiarash Sedghighadikolaei, Changqi Sun, Thang Hoang, Bechir Hamdaoui et al.S&P 2026
- Two-Round Threshold Signature from Algebraic One-More Learning with ErrorsThomas Espitau, Shuichi Katsumata, Kaoru TakemureCRYPTO 2024 · 25 citations
