Paper 2025/1163

Quorus: Efficient, Scalable Threshold ML-DSA Signatures from MPC

Alexander Bienstock, JP Morgan Chase
Leo de Castro, JP Morgan Chase
Daniel Escudero, JP Morgan Chase
Antigoni Polychroniadou, JP Morgan Chase
Akira Takahashi, JP Morgan Chase
Abstract

A threshold signature protocol divides a secret signing key among multiple parties, enabling any subset above a threshold to jointly create a signature. While post-quantum (PQ) threshold signatures are being studied, especially following NIST's call for threshold schemes, most solutions focus on specially designed, threshold-friendly signature schemes. However, real-world applications like distributed certificate authorities and digital currencies require signatures verifiable under existing standardized procedures. With NIST's standardization of PQ signatures and ongoing industry deployment, designing an efficient threshold scheme compatible with NIST-standardized verification remains a critical challenge. In this work, we present the first efficient and scalable solution for multi-party generation of the module-lattice digital signature algorithm (ML-DSA), one of NIST's PQ signature standards. Our contributions are two-fold. First, we present a variant of the ML-DSA signing algorithm that is amenable to efficient multi-party computation (MPC) and prove that this variant achieves the same security as the original ML-DSA scheme. Second, we present several efficient & scalable MPC protocols to instantiate the threshold signing functionality. Our protocols can produce threshold signatures with as little as 100 KB (per party) of online communication per rejection-sampling round. In addition, we instantiate our protocols in the honest-majority setting, which allows us to avoid any additional public key assumptions. Our signatures verify under the same ML-DSA implementation for all security levels, with signature and verification key sizes matching ML-DSA; previous lattice-based threshold schemes could not match both of these sizes. Our solution provides the first method for producing threshold post-quantum signatures compatible with NIST-standardized verification, scalable to any number of parties, without new assumptions.

Note: This is the full version of this work that will appear in USENIX 2026. Change log: - Added security proof for UF-CMA_bot unforgeability. - Updated the BatchedOr protocol - Updated discussion of the offline phase for ML-DSA-44 and added a separate variant of the setup protocol for these parameters. - Updated performance benchmarks to reflect changes in the protocol.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Threshold SignaturesThreshold ML-DSA
Contact author(s)
alex bienstock @ jpmchase com
leo decastro @ jpmchase com
daniel escudero @ jpmchase com
antigoni polychroniadou @ jpmchase com
akira takahashi @ jpmchase com
History
2026-01-28: last of 2 revisions
2025-06-19: received
See all versions
Short URL
https://ia.cr/2025/1163
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1163,
      author = {Alexander Bienstock and Leo de Castro and Daniel Escudero and Antigoni Polychroniadou and Akira Takahashi},
      title = {Quorus: Efficient, Scalable Threshold {ML}-{DSA} Signatures from {MPC}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1163},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1163}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.