Paper 2016/013

Threshold-optimal DSA/ECDSA signatures and an application to Bitcoin wallet security

Rosario Gennaro, Steven Goldfeder, and Arvind Narayanan


While threshold signature schemes have been presented before, there has never been an optimal threshold signature algorithm for DSA. Due to the properties of DSA, it is far more difficult to create a threshold scheme for it than for other signature algorithms. In this paper, we present a breakthrough scheme that provides a threshold DSA algorithm that is efficient and optimal. We also present a compelling application to use our scheme: securing Bitcoin wallets. Bitcoin thefts are on the rise, and threshold DSA is necessary to secure Bitcoin wallets. Our scheme is the first general threshold DSA scheme that does not require an honest majority and is useful for securing Bitcoin wallets.

Available format(s)
Cryptographic protocols
Publication info
Preprint. MINOR revision.
DSAECDSAthreshold signaturesthreshold cryptographyBitcoin
Contact author(s)
sgoldfed @ gmail com
2016-01-27: revised
2016-01-07: received
See all versions
Short URL
Creative Commons Attribution


      author = {Rosario Gennaro and Steven Goldfeder and Arvind Narayanan},
      title = {Threshold-optimal DSA/ECDSA signatures and an application to Bitcoin wallet security},
      howpublished = {Cryptology ePrint Archive, Paper 2016/013},
      year = {2016},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.