Paper 2025/1001
A Plausible Attack on the Adaptive Security of Threshold Schnorr Signatures
Abstract
The standard notion of security for threshold signature schemes is static security, where the set of corrupt parties is assumed to be fixed before protocol execution. In this model, the adversary may corrupt up to t−1 out of a threshold of t parties. A stronger notion of security for threshold signatures considers an adaptive adversary, who may corrupt parties dynamically based on its view of the protocol execution, learning the corrupted parties’ secret keys as well as their states. Adaptive security of threshold signatures has become an active area of research recently due to ongoing standardization efforts. Of particular interest is full adaptive security, the analogue of static security, where the adversary may adaptively corrupt a full t−1 parties. We present a plausible attack on the full adaptive security of threshold Schnorr signature schemes with public key shares of the form $pk_i = g^{sk_i},$ where all secret keys $sk_i$ lie on a polynomial. We show that a wide range of threshold Schnorr signature schemes, including all variants of FROST, Sparkle, and Lindell’22, cannot be proven fully adaptively secure without modifications or assuming the hardness of a search problem that we define in this work. We then prove a generalization that extends below t−1 adaptive corruptions.
Note: This extends the CRYPTO 2025 proceedings version with the addition of Section 7 discussing the relationship between the hardness of the problem we consider and Reed-Solomon codes.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- A major revision of an IACR publication in CRYPTO 2025
- Keywords
- threshold signaturesSchnorr signaturesadaptive security
- Contact author(s)
-
elizabeth_crites @ alumni brown edu
alistair @ web3 foundation - History
- 2025-06-02: approved
- 2025-05-30: received
- See all versions
- Short URL
- https://ia.cr/2025/1001
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1001,
author = {Elizabeth Crites and Alistair Stewart},
title = {A Plausible Attack on the Adaptive Security of Threshold Schnorr Signatures},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1001},
year = {2025},
url = {https://eprint.iacr.org/2025/1001}
}