{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T17:30:53Z","timestamp":1783791053154,"version":"3.55.0"},"reference-count":37,"publisher":"International Association for Cryptologic Research","issue":"1","license":[{"start":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T00:00:00Z","timestamp":1736726400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2025,3,11]]},"abstract":"<jats:p>Recently, a number of highly optimized threshold signing protocols for Schnorr signatures have been proposed. While these proposals contain important new techniques, some of them present and analyze these techniques in very specific contexts, making it less than obvious how these techniques can be adapted to other contexts, or combined with one another. The main goal of this paper is to abstract out and extend in various ways some of these techniques, building a toolbox of techniques that can be easily combined in different ways and in different contexts. To this end, we present security results for various \u201cenhanced\u201d modes of attack on the Schnorr signature scheme in the non-distributed setting, and we demonstrate how to reduce the security in the distributed threshold setting to these enhanced modes of attack in the non-distributed setting. This results in a very modular approach to protocol design and analysis, which can be used to easily design new threshold Schnorr protocols that enjoy better security and\/or performance properties than existing ones. <\/jats:p>","DOI":"10.62056\/ahsgvurzn","type":"journal-article","created":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T21:23:17Z","timestamp":1744147397000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":2,"title":["The many faces of Schnorr:   a toolkit for the modular design of threshold Schnorr signatures"],"prefix":"10.62056","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-6996-5660","authenticated-orcid":false,"given":"Victor","family":"Shoup","sequence":"first","affiliation":[{"name":"Offchain Labs","place":["USA"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,4,8]]},"reference":[{"key":"ref1:FROST","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/978-3-030-81652-0_2","article-title":"FROST: Flexible Round-Optimized Schnorr Threshold\n  Signatures","volume":"12804","author":"Chelsea Komlo","year":"2020"},{"key":"ref2:cryptoeprint:2021\/1375","volume-title":"How to Prove Schnorr Assuming Schnorr: Security of\n  Multi- and Threshold Signatures","author":"Elizabeth Crites","year":"2021"},{"key":"ref3:SPRINT","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1007\/978-3-031-58740-5_3","article-title":"SPRINT: High-Throughput Robust Distributed Schnorr\n  Signatures","volume":"14655","author":"Fabrice Benhamouda","year":"2024"},{"key":"ref4:FastBatchedADKG","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"370","DOI":"10.1007\/978-3-031-58740-5_13","article-title":"Fast Batched Asynchronous Distributed Key Generation","volume":"14655","author":"Jens Groth","year":"2024"},{"key":"ref5:cryptoeprint:2022:506","volume-title":"Design and analysis of a distributed ECDSA signing\n  service","author":"Jens Groth","year":"2022"},{"key":"ref6:GrothShoupEC22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1109\/SP.2019.00050","article-title":"On the Security of ECDSA with Additive Key Derivation and\n  Presignatures","volume":"13275","author":"Jens Groth","year":"2022"},{"key":"ref7:DEF+19","doi-asserted-by":"publisher","first-page":"1084","DOI":"10.1109\/SP.2019.00050","article-title":"On the Security of Two-Round Multi-Signatures","author":"Manu Drijvers","year":"2019"},{"key":"ref8:ROS","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1007\/s00145-022-09436-0","article-title":"On the (in)Security of ROS","volume":"35","author":"Fabrice Benhamouda","year":"2022","journal-title":"J. Cryptol."},{"key":"ref9:CGG+20","doi-asserted-by":"publisher","first-page":"1769","DOI":"10.1145\/3372297.3423367","article-title":"UC Non-Interactive, Proactive, Threshold ECDSA with\n  Identifiable Aborts","author":"Ran Canetti","year":"2020"},{"key":"ref10:cryptoeprint:2022\/550","volume-title":"ROAST: Robust Asynchronous Schnorr Threshold Signatures","author":"Tim Ruffing","year":"2022"},{"key":"ref11:DBLP:conf\/crypto\/HirtN06","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/11818175_28","article-title":"Robust Multiparty Computation with Linear Communication\n  Complexity","volume":"4117","author":"Martin Hirt","year":"2006"},{"key":"ref12:BFP21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"587","DOI":"10.1007\/978-3-030-92068-5_20","article-title":"The One-More Discrete Logarithm Assumption in the Generic\n  Group Model","volume":"13093","author":"Balthazar Bauer","year":"2021"},{"key":"ref13:DBLP:journals\/jmc\/NevenSW09","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1515\/JMC.2009.004","article-title":"Hash function requirements for Schnorr signatures","volume":"3","author":"Gregory Neven","year":"2009","journal-title":"J. Math. Cryptol."},{"key":"ref14:DBLP:conf\/eurocrypt\/BlockiL22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"614","DOI":"10.1007\/978-3-031-07085-3_21","article-title":"On the Multi-user Security of Short Schnorr Signatures\n  with Preprocessing","volume":"13276","author":"Jeremiah Blocki","year":"2022"},{"key":"ref15:DBLP:journals\/joc\/PointchevalS00","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1007\/S001450010003","article-title":"Security Arguments for Digital Signatures and Blind\n  Signatures","volume":"13","author":"David Pointcheval","year":"2000","journal-title":"J. Cryptol."},{"key":"ref16:BIP32","volume-title":"BIP32: Hierarchical deterministic wallets","author":"P. Wuille","year":"2020"},{"key":"ref17:DfinityWP2","volume-title":"The Internet Computer for Geeks","author":"The DFINITY Team","year":"2022"},{"key":"ref18:cryptoeprint:2021:339","volume-title":"Non-interactive distributed key generation and key\n  resharing","author":"Jens Groth","year":"2021"},{"key":"ref19:DBLP:journals\/joc\/GennaroJKR07","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/s00145-006-0347-3","article-title":"Secure Distributed Key Generation for Discrete-Log Based\n  Cryptosystems","volume":"20","author":"Rosario Gennaro","year":"2007","journal-title":"J. Cryptol."},{"key":"ref20:BonehShoup-v0.6","volume-title":"A Graduate Course in Applied Cryptography (v0.6)","author":"Dan Boneh","year":"2023"},{"key":"ref21:DBLP:conf\/crypto\/Wagner02","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"288","DOI":"10.1007\/3-540-45708-9_19","article-title":"A Generalized Birthday Problem","volume":"2442","author":"David A. Wagner","year":"2002"},{"key":"ref22:BLS-sigs","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"514","DOI":"10.1007\/3-540-45682-1_30","article-title":"Short Signatures from the Weil Pairing","volume":"2248","author":"Dan Boneh","year":"2001"},{"key":"ref23:DBLP:conf\/pkc\/Boldyreva03","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1007\/3-540-36288-6_3","article-title":"Threshold Signatures, Multisignatures and Blind Signatures\n  Based on the Gap-Diffie-Hellman-Group Signature Scheme","volume":"2567","author":"Alexandra Boldyreva","year":"2003"},{"key":"ref24:SEC2","volume-title":"SEC 2: Recommended Elliptic Curve Domain Parameters","author":"Certicom Research","year":"2010"},{"key":"ref25:Zha22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1007\/978-3-031-15982-4_3","article-title":"To Label, or Not To Label (in Generic Groups)","volume":"13509","author":"Mark Zhandry","year":"2022"},{"key":"ref26:DBLP:conf\/eurocrypt\/Shoup97","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1007\/3-540-69053-0_18","article-title":"Lower Bounds for Discrete Logarithms and Related Problems","volume":"1233","author":"Victor Shoup","year":"1997"},{"key":"ref27:DBLP:conf\/ima\/Maurer05","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11586821_1","article-title":"Abstract Models of Computation in Cryptography","volume":"3796","author":"Ueli M. Maurer","year":"2005"},{"key":"ref28:UC","doi-asserted-by":"publisher","DOI":"10.1145\/3402457","article-title":"Universally Composable Security","volume":"67","author":"Ran Canetti","year":"2020","journal-title":"J. ACM"},{"key":"ref29:LightweightAVSS","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1007\/S00145-024-09505-6","article-title":"Lightweight Asynchronous Verifiable Secret Sharing with\n  Optimal Resilience","volume":"37","author":"Victor Shoup","year":"2024","journal-title":"J. Cryptol."},{"key":"ref30:DBLP:journals\/tit\/ChoudhuryP17","doi-asserted-by":"publisher","first-page":"428","DOI":"10.1109\/TIT.2016.2614685","article-title":"An Efficient Framework for Unconditionally Secure Multiparty\n  Computation","volume":"63","author":"Ashish Choudhury","year":"2017","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref31:PBFT-short","first-page":"173","article-title":"Practical Byzantine Fault Tolerance","author":"Miguel Castro","year":"1999"},{"key":"ref32:cryptoeprint:2021:632","volume-title":"Internet Computer Consensus","author":"Jan Camenisch","year":"2021"},{"key":"ref33:SimplexTCC","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"452","DOI":"10.1007\/978-3-031-48624-1_17","article-title":"Simplex Consensus: A Simple and Fast Consensus Protocol","volume":"14372","author":"Benjamin Y. Chan","year":"2023"},{"key":"ref34:DBLP:conf\/eurocrypt\/Shoup00","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/3-540-45539-6_15","article-title":"Practical Threshold Signatures","volume":"1807","author":"Victor Shoup","year":"2000"},{"key":"ref35:cryptoeprint:2022\/833","volume-title":"Stronger Security for Non-Interactive Threshold Signatures:\n  BLS and FROST","author":"Mihir Bellare","year":"2022"},{"key":"ref36:HashVABA:CCS","doi-asserted-by":"publisher","first-page":"3242","DOI":"10.1145\/3658644.3670327","article-title":"Asynchronous Consensus without Trusted Setup or Public-Key\n  Cryptography","author":"Sourav Das","year":"2024"},{"key":"ref37:cryptoeprint:2024\/696","volume-title":"A Theoretical Take on a Practical Consensus Protocol","author":"Victor Shoup","year":"2024"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T21:24:18Z","timestamp":1744147458000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/2\/1\/18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,8]]},"references-count":37,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,4,8]]}},"URL":"https:\/\/doi.org\/10.62056\/ahsgvurzn","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,8]]},"assertion":[{"value":"2025-01-13","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-03-11","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc2-1-25"}}