Ringtail: Practical Two-Round Threshold Signatures from Learning with Errors
Cecilia Boschini, Darya Kaviani, Russell W. F. Lai, Giulio Malavolta, Akira Takahashi, Mehdi Tibouchi
Abstract
A threshold signature scheme splits the signing key amongparties, such that any-subset of parties can jointly generate signatures on a given message. Designing concretely efficient post-quantum threshold signatures is a pressing question, as evidenced by NIST's recent call. In this work, we propose, implement, and evaluate a lattice-based threshold signature scheme, Ringtail, which is the first to achieve a combination of desirable properties: (i) The signing protocol consists of only two rounds, where the first round is message-independent and can thus be preprocessed offline. (ii) The scheme is concretely efficient and scalable toparties. For 128-bit security andparties, we achieve 13.4 KB signature size and 10.5 KB of online communication. (iii) The security is based on the standard learning with errors (LWE) assumption in the random oracle model. This improves upon the state-of-the-art (with comparable efficiency) which either has a three-round signing protocol [Eurocrypt'24] or relies on a new non-standard assumption [Crypto'24]. To substantiate the practicality of our scheme, we conduct the first WAN experiment deploying a lattice-based threshold signature, across 8 countries in 5 continents. We observe that an overwhelming majority of the end-to-end latency is consumed by network latency, underscoring the need for round-optimized schemes.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get cf36ad55-7e01-45c4-8022-71bfd80621cbCited by top-tier papers8
- Unmasking TRaccoon: A Lattice-Based Threshold Signature with An Efficient Identifiable Abort ProtocolRafaël Del Pino, Shuichi Katsumata, Guilhem Niot, Michael Reichle et al.CRYPTO 2025 · 8 citations
- Lattice-Based Threshold Blind SignaturesSebastian Faller, Guilhem Niot, Michael ReichleS&P 2026 · 2 citations
- Efficient Threshold ML-DSASofía Celi, Rafael del Pino, Thomas Espitau, Guilhem Niot et al.USENIX Security 2026 · 1 citation
- Quorus: Efficient, Scalable Threshold ML-DSA Signatures from MPCAlexander Bienstock, Leo de Castro, Daniel Escudero, Antigoni Polychroniadou et al.USENIX Security 2026 · 1 citation
- Thresholdizing Standardized FALCON SignaturesRadhika Garg, Daniel Escudero, Antigoni Polychroniadou, Akira Takahashi et al.CCS 2026
Related papers
- Threshold Raccoon: Practical Threshold Signatures from Standard Lattice AssumptionsRafaël Del Pino, Shuichi Katsumata, Mary Maller, Fabrice Mouhartem et al.EUROCRYPT 2024 · 61 citations
- Two-Round Threshold Signature from Algebraic One-More Learning with ErrorsThomas Espitau, Shuichi Katsumata, Kaoru TakemureCRYPTO 2024 · 25 citations
- Olingo: Threshold Lattice Signatures with DKG and Identifiable AbortKamil Doruk Gur, Patrick Hough, Jonathan Katz, Caroline Sandsbråten et al.CCS 2026
- Compact Ring Signatures from Learning with ErrorsRohit Chatterjee, Sanjam Garg, Mohammad Hajiabadi, Dakshita Khurana et al.CRYPTO 2021 · 22 citations
- Lattice-Based Blind Signatures: Short, Efficient, and Round-OptimalWard Beullens, Vadim Lyubashevsky, Ngoc Khanh Nguyen, Gregor SeilerCCS 2023 · 22 citations
