What a lovely hat

Is it made out of tin foil?

Paper 2025/1666

Trout: Two-Round Threshold ECDSA from Class Groups

Hila Dahari-Garbian, Weizmann Institute of Science
Ariel Nof, Bar-Ilan University
Luke Parker, Serai DEX
Abstract

We present Trout (Two-ROUnd Threshold), the \textit{first} distributed two-round ECDSA signing protocol for arbitrary thresholds. Trout has constant upload bandwidth per-party and processing time linear in the amount of participants. Moreover, Trout achieves the Identifiable Abort (IA) property, which means that if the protocol cannot terminate due to a failure, parties can attribute the failure to a specific party. We achieve this without a trusted setup. Our protocol relies on linear-homomorphic encryptions and commitments over class groups. To obtain our result, we leverage the recent construction of an exponent-VRF (Boneh et al., Eurocrypt 2025) and a novel protocol to multiply an encrypted value with a committed value and simultaneously decrypt it, which we call "scaled decryption". We believe that this protocol may be of independent interest. Our protocol has a very low communication cost of just 6.5 KB sent per party. Furthermore, we implemented our protocol in Rust and provide benchmarks for various configurations, showing its practicality even for 100 parties. Our implementation includes a constant-time variant which, to the best of our knowledge, is the first of its kind for class-group-based threshold ECDSA protocols.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. ACM CCS 2025
Keywords
mpc; threshold signatures
Contact author(s)
hila dahari @ weizmann ac il
ariel nof @ biu ac il
lukeparker @ serai exchange
History
2025-09-17: approved
2025-09-14: received
See all versions
Short URL
https://ia.cr/2025/1666
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1666,
      author = {Hila Dahari-Garbian and Ariel Nof and Luke Parker},
      title = {Trout: Two-Round Threshold {ECDSA} from Class Groups},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1666},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1666}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.
Morty Proxy This is a proxified and sanitized view of the page, visit original site.