Real Threshold ECDSA
Harry W. H. Wong, Jack P. K. Ma, Hoover H. F. Yin, Sherman S. M. Chow
Abstract
—Threshold ECDSA recently regained popularity due to decentralized applications such as DNSSEC and cryptocur-rency asset custody. Latest (communication-optimizing) schemes often assume all n or at least n ′ ≥ t participating users remain honest throughout the pre-signing phase, essentially degenerating to n ′ -out-of- n ′ multiparty signing instead of t -out-of- n threshold signing. When anyone misbehaves, all signers must restart from scratch, rendering prior computation and communication in vain. This hampers the adoption of threshold ECDSA in time-critical situations and confines its use to a small signing committee. To mitigate such denial-of-service vulnerabilities prevalent in state-of-the-art, we propose a robust threshold ECDSA scheme that achieves the t -out-of- n threshold flexibility “for real” throughout the whole pre-signing and signing phases without assuming an honest majority. Our scheme is desirable when computational resources are scarce and in a decentralized setting where faults are easier to be induced. Our design features 4 - round pre-signing, O ( n ) cheating identification, and self-healing machinery over distributive shares. Prior arts mandate abort after an O ( n 2 ) -cost identification, albeit with 3 -round pre-signing (Canetti et al., CCS ’20), or O ( n ) using 6 rounds (Castagnos et al., TCS ’23). Empirically, our scheme saves up to ∼ 30% of the communication cost, depending on at which stage the fault occurred.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Unmasking TRaccoon: A Lattice-Based Threshold Signature with An Efficient Identifiable Abort ProtocolRafaël Del Pino, Shuichi Katsumata, Guilhem Niot, Michael Reichle et al.CRYPTO 2025 · 8 citations
- Threshold ECDSA in Two RoundsYingjie Lyu, Zengpeng Li, Hong-Sheng Zhou, Xudong DengCCS 2025
- Efficient Proofs of Possession for Legacy SignaturesAnna P. Y. Woo, Alex Ozdemir, Chad Sharp, Thomas Pornin et al.S&P 2025
- Trout: Two-Round Threshold ECDSA from Class GroupsHila Dahari-Garbian, Ariel Nof, Luke ParkerCCS 2025
- Robust Threshold ECDSA with Online-Friendly Design in Three RoundsGuofeng Tang, Haiyang XueS&P 2025
Builds on6
- Fast Multiparty Threshold ECDSA with Fast Trustless SetupRosario Gennaro, Steven GoldfederCCS 2018 · 264 citations
- Fast Secure Multiparty ECDSA with Practical Distributed Key Generation and Applications to Cryptocurrency CustodyYehuda Lindell, Ariel NofCCS 2018 · 220 citations
- Threshold ECDSA from ECDSA Assumptions: The Multiparty CaseJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2019 · 167 citations
- UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable AbortsRan Canetti, Rosario Gennaro, Steven Goldfeder, Nikolaos Makriyannis et al.CCS 2020 · 135 citations
- Low-Bandwidth Threshold ECDSA via Pseudorandom Correlation GeneratorsDamiano Abram, Ariel Nof, Claudio Orlandi, Peter Scholl et al.S&P 2022 · 51 citations
Related papers
- Secure Multiparty Computation of Threshold Signatures Made More EfficientHarry W. H. Wong, Jack P. K. Ma, Sherman S. M. ChowNDSS 2024
- Threshold ECDSA in Three RoundsJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2024 · 31 citations
- Separating Broadcast from Cheater IdentificationYashvanth Kondi, Divya RaviCCS 2025
- Secure Two-party Threshold ECDSA from ECDSA AssumptionsJack Doerner, Yashvanth Kondi, Eysa Lee, Abhi ShelatS&P 2018 · 171 citations
- Adaptively Secure Three-Round Threshold Schnorr Signatures from DDHRenas Bacho, Sourav Das, Julian Loss, Ling RenCRYPTO 2025 · 12 citations
