Paper 2026/2288

Kettle: Short Post-Quantum Threshold Signatures from the HAWK Signature Scheme

Calvin Abou Haidar, NTT Social Informatics Laboratories
Daniel Escudero, Taceo
Thomas Espitau, PQ Shield France
Clément Hoffmann, NTT Social Informatics Laboratories
Kaoru Takemure, PQ Shield Japan
Mehdi Tibouchi, NTT Social Informatics Laboratories
Hernán Darío Vanegas Madrigal, HashCloak Inc.
Abstract

HAWK is a lattice-based hash-and-sign signature scheme that was a third round candidate in the NIST additional call for post-quantum signatures. It has short signatures and keys, as well as fast and portable signing and verification. However, in response to a highly-publicized AI-driven cryptanalytic result that reduced its security (roughly doubling the required dimension to achieve a given security level), the authors de- cided to withdraw from the competition. The need to increase parameters was seen as limiting the size advantage of HAWK compared to the already selected lattice schemes ML-DSA and Falcon, which was one of its primary selling points along- side speed and the lack of floating-point arithmetic. In this paper, we identify another attractive aspect of the HAWK design that is not affected by the AI attack and has been overlooked so far: its surprising friendliness to multi- party computation (MPC). Indeed, HAWK signing can be achieved in a generic way from a small collection of basic composable MPC functionalities (like integer multiplication, uniform random generation, etc.) in such a way that instanti- ating those functionalities using MPC protocols with given security properties (semi-honest vs. malicious, honest vs. dis- honest majority, etc.) yields a secure protocol for MPC signing with those same properties. As a result, we obtain Kettle, a UC-secure threshold signa- ture protocol that outputs specification-compliant HAWK sig- natures and scales to an arbitrary number of parties. It offers essentially the shortest signature size so far for a lattice-based threshold signature, while achieving significantly lower round complexity and online communication cost than other thresh- old protocols built from pre-existing, non-threshold lattice- based signatures (like ML-DSA and Falcon): as low as 2 online rounds (a dozen rounds total) and 2 kB online com- munication per party, depending on the specific setting and optimization choices. We also provide a proof-of-concept implementation of our approach in the MP-SPDZ framework, which can be instanti- ated with any number of parties, any threshold, and a variety of security properties.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Threshold signaturesPost-quantum cryptographyLattice-based cryptographyHAWKUniversal composability
Contact author(s)
calvin abou-haidar @ protonmail com
escudero @ taceo io
thomas espitau @ pqshield com
clement hoffmann @ hotmail fr
kaoru takemure @ pqshield com
mehdi tibouchi @ normalesup org
hernan @ hashcloak com
History
2026-10-04: revised
2026-10-01: received
See all versions
Short URL
https://ia.cr/2026/2288
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2288,
      author = {Calvin Abou Haidar and Daniel Escudero and Thomas Espitau and Clément Hoffmann and Kaoru Takemure and Mehdi Tibouchi and Hernán Darío Vanegas Madrigal},
      title = {Kettle: Short Post-Quantum Threshold Signatures from the {HAWK} Signature Scheme},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2288},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2288}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.