\(\textsf{FROST}\) and its variants are state-of-the-art protocols for threshold Schnorr signatures that are used in real-world applications. While static security of these protocols has been shown by several works, the security of these protocols under adaptive corruptions—where an adversary can choose which parties to corrupt at any time based on information it learns during protocol executions—has remained a notorious open problem that has received renewed attention due to recent standardization efforts for threshold schemes. We show adaptive security (without erasures) of \(\textsf{FROST}\) and several variants under different corruption thresholds and computational assumptions. Let n be the total number of parties, \(t+1\) the signing threshold, and \(t_c\) an upper bound on the number of corrupted parties.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

On the Adaptive Security of FROST

  • Elizabeth Crites,
  • Jonathan Katz,
  • Chelsea Komlo,
  • Stefano Tessaro,
  • Chenzhi Zhu

摘要

\(\textsf{FROST}\) and its variants are state-of-the-art protocols for threshold Schnorr signatures that are used in real-world applications. While static security of these protocols has been shown by several works, the security of these protocols under adaptive corruptions—where an adversary can choose which parties to corrupt at any time based on information it learns during protocol executions—has remained a notorious open problem that has received renewed attention due to recent standardization efforts for threshold schemes. We show adaptive security (without erasures) of \(\textsf{FROST}\) and several variants under different corruption thresholds and computational assumptions. Let n be the total number of parties, \(t+1\) the signing threshold, and \(t_c\) an upper bound on the number of corrupted parties.