Paper 2025/1696
Threshold ECDSA in Two Rounds
Abstract
We propose the first two-round multi-party signing protocol for the Elliptic Curve Digital Signature Algorithm (ECDSA) in the threshold-optimal setting, reducing the number of rounds by one compared to the state of the art (Doerner et al., S&P '24). We also resolve the security issue of presigning pointed out by Groth and Shoup (Eurocrypt '22), evading a security loss that increases with the number of pre-released, unused presignatures, for the first time among threshold-optimal schemes. Our construction builds on Non-Interactive Multiplication (NIM), a notion proposed by Boyle et al. (PKC '25), which allows parties to evaluate multiplications on secret-shared values in one round. In particular, we use the construction of Abram et al. (Eurocrypt '24) instantiated with class groups. The setup is minimal and transparent, consisting of only two class-group generators. The signing protocol is efficient in bandwidth, with a message size of 1.9 KiB at 128-bit security, and has competitive computational performance.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Minor revision. ACM CCS 2025
- DOI
- 10.1145/3719027.3765176
- Keywords
- ECDSAThreshold SignaturesThreshold Cryptography
- Contact author(s)
-
yingjielyu @ mail sdu edu cn
zengpengliz @ gmail com
hszhou @ vcu edu
xudongdeng @ mail sdu edu cn - History
- 2026-01-14: last of 3 revisions
- 2025-09-18: received
- See all versions
- Short URL
- https://ia.cr/2025/1696
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1696,
author = {Yingjie Lyu and Zengpeng Li and Hong-Sheng Zhou and Xudong Deng},
title = {Threshold {ECDSA} in Two Rounds},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1696},
year = {2025},
doi = {10.1145/3719027.3765176},
url = {https://eprint.iacr.org/2025/1696}
}