Paper 2026/1670

RSS: Robust Signing Service using Threshold Signatures and TEEs

Filip Rezabek, Technical University of Munich
Kilian Glas, Technical University of Munich
Eber Christer, Technical University of Munich
Xinxin Fan, IoTeX
Georg Carle, Technical University of Munich
Abstract

Threshold signatures reduce the risk of single-key compromise by distributing signing authority, but each key share remains exposed to compromise of the software and infrastructure that execute the protocol. We present RSS, a threshold signing service that runs share generation and signing inside Trusted Execution Environments (TEEs). We integrate GG20 threshold ECDSA, FROST, and threshold BLS into the EnGINE experimentation framework and evaluate local and Google Cloud deployments using AMD SEV-SNP and Intel TDX. Our experiments separate distributed key generation (DKG), preprocessing, and online signing, and cover up to 40 logical protocol participants distributed across four physical hosts or confidential VMs (CVMs). In matched-platform comparisons, confidential execution adds limited overhead relative to protocol and deployment effects. DKG is the main scaling bottleneck: for 40 participants, it completes within seconds in the evaluated configurations, whereas signing completes in tens of milliseconds. Threshold BLS is approximately twice as slow as FROST for comparable values of $n$ and $t$. These results establish the performance feasibility of executing threshold-signature workloads inside CVMs under benign-operation assumptions. The evaluation does not cover a complete attestation-bound provisioning lifecycle, persistent-state rollback protection, or Byzantine fault behavior.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
TEEThreshold CryptographyMethodologyEvaluation
Contact author(s)
filip rezabek @ tum de
glask @ net in tum de
christer @ net in tum de
xinxin @ iotex io
carle @ tum de
History
2026-08-15: approved
2026-08-12: received
See all versions
Short URL
https://ia.cr/2026/1670
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/1670,
      author = {Filip Rezabek and Kilian Glas and Eber Christer and Xinxin Fan and Georg Carle},
      title = {{RSS}: Robust Signing Service using Threshold Signatures and {TEEs}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1670},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1670}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.