Paper 2026/1909
Tightly and Adaptively Secure Two-Round Threshold Signatures from DDH
Abstract
Threshold signatures enable a set of $n$ parties to jointly generate signatures under a single public key such that any subset of at least $t+1$ parties can produce a valid signature, whereas any coalition of at most $t$ parties cannot. They constitute a fundamental primitive for distributed trust and are widely deployed in systems such as certification authorities, blockchains, and multiparty wallets. Modern applications require strong security guarantees under realistic adversarial models, including resistance to adaptive corruptions, tight security reductions, and low interaction complexity—most notably, a minimal number of communication rounds. Recent progress has produced threshold signature schemes in pairing-free groups that achieve tight and adaptive security with three rounds of interaction. This leaves open the central question of whether one can simultaneously achieve tight security, adaptive security, and two-round signing under a standard, non-interactive hardness assumption. In this work, we resolve this question by presenting TZAR, the first two-round threshold signature scheme that is tightly and adaptively secure under the standard decisional Diffie-Hellman (DDH) assumption in pairing-free cyclic groups. Our construction achieves full adaptive security against up to $t < n$ corruptions and admits a tight security reduction with only constant-factor loss. Consequently, TZAR provides strong provable security guarantees and minimizes interaction by requiring only two signing rounds, an important advantage for latency-sensitive distributed environments.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- A major revision of an IACR publication in ASIACRYPT 2026
- Keywords
- Threshold SignaturesTight SecurityAdaptive SecurityPairing-Free Groups
- Contact author(s)
-
renas bacho @ rub de
ychen918 @ uottawa ca - History
- 2026-09-10: approved
- 2026-09-07: received
- See all versions
- Short URL
- https://ia.cr/2026/1909
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1909,
author = {Renas Bacho and Yanbo Chen},
title = {Tightly and Adaptively Secure Two-Round Threshold Signatures from {DDH}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1909},
year = {2026},
url = {https://eprint.iacr.org/2026/1909}
}