{"catalogVersion":"threshold-signature-dossier-v3-atomic-contributions","constructions":[{"adaptive_security":"not claimed on this card","api_style":null,"associated_data":null,"assumption_family":"discrete_log","assumption_id":"TSIG-ASSUMPTION-HARDNESS-OF-FORGING-THE-UNDERLYING-DSS-SIGNATURE-UNDER-THE-PAPER-MODEL","assumption_name":"hardness of forging the underlying DSS signature under the paper model","authors":["Rosario Gennaro","Stanisław Jarecki","Hugo Krawczyk","Tal Rabin"],"base_signature":"DSS","block_size":null,"bootstrapping":null,"capabilities":["ordinary-verifier-output","malicious-security","robustness"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"historical interactive protocol; exact accounting queued","construction_family":"threshold_dss","correctness":null,"corruption_model":"malicious faults with separate robustness bounds","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","identifiable_abort":"scoped share verification; modern terminology not used","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary DSS signature","packing":null,"paper_title":"Robust Threshold DSS Signatures","paper_url":"https://doi.org/10.1007/3-540-68339-9_31","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"protocol-dependent","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"unforgeability against up to t corrupted players in the stated range","response_communication":null,"robustness":"paper gives distinct bounds for nonparticipation and incorrect partial signatures","security_mode":"threshold public-key","security_model":"paper-specific","security_notion":"threshold unforgeability and scoped robustness","server_model":null,"server_work":null,"setup_model":"distributed sharing of the DSS secret","signer_model":null,"signing_cost":null,"signing_rounds":"interactive multiparty protocol","sizes":{"public_key":"ordinary DSS public key","signature":"ordinary DSS signature"},"statefulness":null,"summary":"The threshold t, signing-quorum size, crash tolerance, and malicious-share tolerance are not collapsed into one number.","supported_gates":null,"tag_size":null,"threshold_policy":"2t+1 participating signers for t<n/2 in the base threshold statement","transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"TSIG-PAPER-1996-GJKR-DSS","year":1996},{"adaptive_security":"not claimed on this card","api_style":null,"associated_data":null,"assumption_family":"factoring","assumption_id":"TSIG-ASSUMPTION-RSA-FUNCTION-SECURITY-WITH-PAPER-SPECIFIC-SHARING-ASSUMPTIONS","assumption_name":"RSA-function security with paper-specific sharing assumptions","authors":["Rosario Gennaro","Stanisław Jarecki","Hugo Krawczyk","Tal Rabin"],"base_signature":"RSA function with a signature encoding supplied by the profile","block_size":null,"bootstrapping":null,"capabilities":["rsa-function-sharing","robustness"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"exact accounting queued","construction_family":"threshold_rsa","correctness":null,"corruption_model":"malicious threshold adversary","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","identifiable_abort":"share verification rather than modern identifiable-abort interface","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"RSA function output; signature encoding must be fixed separately","packing":null,"paper_title":"Robust and Efficient Sharing of RSA Functions","paper_url":"https://doi.org/10.1007/3-540-68697-5","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"key sharing and verification setup","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"paper-specific threshold","response_communication":null,"robustness":"yes under the scoped model","security_mode":"threshold public-key","security_model":"paper-specific","security_notion":"robust shared RSA evaluation","server_model":null,"server_work":null,"setup_model":"shared RSA trapdoor","signer_model":null,"signing_cost":null,"signing_rounds":"nontrivial distributed protocol","sizes":{"public_key":"RSA modulus and exponent","signature":"one RSA function output before profile encoding"},"statefulness":null,"summary":"The proceedings PDF is required to promote exact round, threshold, and assumption fields.","supported_gates":null,"tag_size":null,"threshold_policy":"general threshold with robustness under the paper's bounds","transform":null,"update_model":null,"verification_cost":null,"verification_status":"bibliographic_reviewed","work_id":"TSIG-PAPER-1996-GJKR-RSA","year":1996},{"adaptive_security":"not claimed on this card","api_style":null,"associated_data":null,"assumption_family":"factoring","assumption_id":"TSIG-ASSUMPTION-RSA-ASSUMPTION-PLUS-PAPER-SPECIFIC-NUMBER-THEORETIC-SETUP","assumption_name":"RSA assumption plus paper-specific number-theoretic setup","authors":["Victor Shoup"],"base_signature":"RSA","block_size":null,"bootstrapping":null,"capabilities":["noninteractive-signature-shares","robustness","ordinary-verifier-output"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"one signature share per participating server plus combining metadata","construction_family":"threshold_rsa","correctness":null,"corruption_model":"static malicious adversary in the paper model","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2000-SHOUP","identifiable_abort":"invalid shares are detectable","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary RSA signature value for the specified encoding","packing":null,"paper_title":"Practical Threshold Signatures","paper_url":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"distributed key setup outside the signing algorithm","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"threshold unforgeability under stated bounds","response_communication":null,"robustness":"combiner verifies signature shares and can proceed with enough valid shares","security_mode":"threshold public-key","security_model":"random-oracle/profile-dependent encoding","security_notion":"robust threshold unforgeability","server_model":null,"server_work":null,"setup_model":"RSA modulus and verified secret-key shares","signer_model":null,"signing_cost":null,"signing_rounds":"noninteractive share generation followed by combining","sizes":{"public_key":"ordinary RSA public key","signature":"ordinary RSA modulus element"},"statefulness":null,"summary":"“Noninteractive” describes per-server signature-share production, not dealer-free key generation.","supported_gates":null,"tag_size":null,"threshold_policy":"k-out-of-l threshold in the paper notation","transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"TSIG-PAPER-2000-SHOUP","year":2000},{"adaptive_security":"not the card's claim","api_style":null,"associated_data":null,"assumption_family":"pairing","assumption_id":"TSIG-ASSUMPTION-GAP-DIFFIE-HELLMAN-CO-CDH-LINEAGE-IN-PAIRING-GROUPS","assumption_name":"gap Diffie-Hellman / co-CDH lineage in pairing groups","authors":["Alexandra Boldyreva"],"base_signature":"BLS","block_size":null,"bootstrapping":null,"capabilities":["compact-output","noninteractive-signature-shares","public-share-verification"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"one group-element share per participant","construction_family":"threshold_pairing","correctness":null,"corruption_model":"static threshold adversary in the paper model","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","identifiable_abort":"malformed shares are attributable to their senders","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary one-group-element BLS signature","packing":null,"paper_title":"Threshold Signatures, Multisignatures and Blind Signatures Based on the Gap-Diffie-Hellman-Group Signature Scheme","paper_url":"https://eprint.iacr.org/2002/118","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"distributed key setup","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"threshold unforgeability under the stated bound","response_communication":null,"robustness":"valid shares can be publicly checked in the pairing setting","security_mode":"threshold public-key","security_model":"random oracle","security_notion":"threshold EUF-CMA lineage","server_model":null,"server_work":null,"setup_model":"shared scalar key in a gap-Diffie-Hellman group","signer_model":null,"signing_cost":null,"signing_rounds":"noninteractive shares and public combining","sizes":{"public_key":"ordinary BLS public key plus share-verification data","signature":"one BLS signature group element"},"statefulness":null,"summary":"The assumption is a pairing/GDH-family point, not the plain DDH assumption used by Glacius.","supported_gates":null,"tag_size":null,"threshold_policy":"t-out-of-n threshold sharing under the paper notation","transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"TSIG-PAPER-2003-BOLDYREVA","year":2003},{"adaptive_security":"not claimed on this card","api_style":null,"associated_data":null,"assumption_family":"discrete_log_and_factoring","assumption_id":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RELATED-ASSUMPTIONS-UNDER-THE-PROOF","assumption_name":"ECDSA/discrete-log and Paillier-related assumptions under the proof","authors":["Yehuda Lindell"],"base_signature":"ECDSA","block_size":null,"bootstrapping":null,"capabilities":["ordinary-verifier-output","two-party-signing","malicious-security"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"constant number of two-party messages; exact bytes parameter-dependent","construction_family":"threshold_ecdsa_paillier","correctness":null,"corruption_model":"one malicious party","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2017-LINDELL","identifiable_abort":"paper-specific proofs/checks","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary ECDSA signature","packing":null,"paper_title":"Fast Secure Two-Party ECDSA Signing","paper_url":"https://eprint.iacr.org/2017/552","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"offline work supported by protocol organization","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"no single party can forge alone","response_communication":null,"robustness":"abort on malicious behavior; guaranteed output not claimed","security_mode":"threshold public-key","security_model":"paper-specific","security_notion":"maliciously secure two-party signing","server_model":null,"server_work":null,"setup_model":"jointly held ECDSA key with Paillier-related setup","signer_model":null,"signing_cost":null,"signing_rounds":"interactive online signing","sizes":{"public_key":"ordinary ECDSA public key","signature":"ordinary ECDSA signature"},"statefulness":null,"summary":"ECDSA's inversion and multiplication structure makes its threshold protocol qualitatively different from linear Schnorr aggregation.","supported_gates":null,"tag_size":null,"threshold_policy":"2-out-of-2","transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"TSIG-PAPER-2017-LINDELL","year":2017},{"adaptive_security":"not claimed on this card","api_style":null,"associated_data":null,"assumption_family":"discrete_log","assumption_id":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-PLUS-HASH-PROOF-SYSTEM-AND-OT-ASSUMPTIONS","assumption_name":"ECDSA/discrete-log plus hash-proof-system and OT assumptions","authors":["Jack Doerner","Yashvanth Kondi","Eysa Lee","abhi shelat"],"base_signature":"ECDSA","block_size":null,"bootstrapping":null,"capabilities":["ordinary-verifier-output","two-party-signing","paillier-free-route"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"OT/hash-proof-system dependent","construction_family":"threshold_ecdsa_ot","correctness":null,"corruption_model":"malicious two-party adversary","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2018-DKLS2","identifiable_abort":"two-party blame is implicit when a session fails","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary ECDSA signature","packing":null,"paper_title":"Two-Party ECDSA from Hash Proof Systems and Efficient Instantiations","paper_url":"https://eprint.iacr.org/2018/499","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"correlated oblivious-transfer-style work","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"no single party can forge alone","response_communication":null,"robustness":"abort on detected cheating","security_mode":"threshold public-key","security_model":"paper-specific","security_notion":"maliciously secure two-party signing","server_model":null,"server_work":null,"setup_model":"jointly held ECDSA key without Paillier encryption","signer_model":null,"signing_cost":null,"signing_rounds":"interactive","sizes":{"public_key":"ordinary ECDSA public key","signature":"ordinary ECDSA signature"},"statefulness":null,"summary":"This is the two-party root of the DKLS route; its cryptographic setup is not interchangeable with Paillier-based ECDSA protocols.","supported_gates":null,"tag_size":null,"threshold_policy":"2-out-of-2","transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"TSIG-PAPER-2018-DKLS-2P","year":2018},{"adaptive_security":"not claimed on this card","api_style":null,"associated_data":null,"assumption_family":"discrete_log_and_factoring","assumption_id":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RELATED-ASSUMPTIONS","assumption_name":"ECDSA/discrete-log and Paillier-related assumptions","authors":["Rosario Gennaro","Steven Goldfeder"],"base_signature":"ECDSA","block_size":null,"bootstrapping":null,"capabilities":["ordinary-verifier-output","multiparty","trustless-setup"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"multiparty interactive protocol; exact accounting parameter-dependent","construction_family":"threshold_ecdsa_paillier","correctness":null,"corruption_model":"malicious threshold adversary in the paper model","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2018-GG","identifiable_abort":"scoped blame mechanisms; use exact paper definition","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary ECDSA signature","packing":null,"paper_title":"Fast Multiparty Threshold ECDSA with Fast Trustless Setup","paper_url":"https://eprint.iacr.org/2019/114","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"key-generation and presigning components","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"threshold unforgeability","response_communication":null,"robustness":"abort-oriented protocol with verifiable steps","security_mode":"threshold public-key","security_model":"paper-specific","security_notion":"malicious threshold signing","server_model":null,"server_work":null,"setup_model":"trustless distributed setup with Paillier-related proofs","signer_model":null,"signing_cost":null,"signing_rounds":"interactive signing protocol","sizes":{"public_key":"ordinary ECDSA public key","signature":"ordinary ECDSA signature"},"statefulness":null,"summary":"The setup and signing protocols should be compared separately; “fast setup” does not make the online signer noninteractive.","supported_gates":null,"tag_size":null,"threshold_policy":"t-out-of-n multiparty threshold","transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"TSIG-PAPER-2018-GG","year":2018},{"adaptive_security":"not claimed on this card","api_style":null,"associated_data":null,"assumption_family":"discrete_log","assumption_id":"TSIG-ASSUMPTION-ECDSA-CENTERED-ASSUMPTIONS-PLUS-OT-HASH-PROOF-SYSTEM-INGREDIENTS","assumption_name":"ECDSA-centered assumptions plus OT/hash-proof-system ingredients","authors":["Jack Doerner","Yashvanth Kondi","Eysa Lee","abhi shelat"],"base_signature":"ECDSA","block_size":null,"bootstrapping":null,"capabilities":["ordinary-verifier-output","general-threshold","paillier-free-route"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"OT and multiparty arithmetic dependent","construction_family":"threshold_ecdsa_ot","correctness":null,"corruption_model":"malicious threshold adversary under paper bounds","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2019-DKLSN","identifiable_abort":"exact property queued for full-text audit","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary ECDSA signature","packing":null,"paper_title":"Threshold ECDSA from ECDSA Assumptions","paper_url":"https://doi.org/10.1109/SP.2019.00024","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"OT-based correlated preprocessing","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"threshold unforgeability","response_communication":null,"robustness":"abort-oriented","security_mode":"threshold public-key","security_model":"paper-specific","security_notion":"threshold unforgeability","server_model":null,"server_work":null,"setup_model":"distributed ECDSA key","signer_model":null,"signing_cost":null,"signing_rounds":"interactive protocol","sizes":{"public_key":"ordinary ECDSA public key","signature":"ordinary ECDSA signature"},"statefulness":null,"summary":"Promote round, corruption, and blame fields only after local audit of the final IEEE version.","supported_gates":null,"tag_size":null,"threshold_policy":"general t-out-of-n","transform":null,"update_model":null,"verification_cost":null,"verification_status":"bibliographic_reviewed","work_id":"TSIG-PAPER-2019-DKLS-N","year":2019},{"adaptive_security":"UC/proactive profile; exact adaptive clauses follow paper","api_style":null,"associated_data":null,"assumption_family":"discrete_log_and_factoring","assumption_id":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RANGE-PROOF-RELATED-ASSUMPTIONS","assumption_name":"ECDSA/discrete-log and Paillier-range-proof related assumptions","authors":["Ran Canetti","Rosario Gennaro","Steven Goldfeder","Nikolaos Makriyannis","Udi Peled"],"base_signature":"ECDSA","block_size":null,"bootstrapping":null,"capabilities":["ordinary-verifier-output","identifiable-abort","proactive-refresh","noninteractive-online"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"shifted toward preprocessing; online contribution is noninteractive","construction_family":"threshold_ecdsa_paillier","correctness":null,"corruption_model":"UC malicious adversary in the paper model","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2020-CGGMP","identifiable_abort":true,"key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary ECDSA signature","packing":null,"paper_title":"UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable Aborts","paper_url":"https://eprint.iacr.org/2021/060","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"substantial presigning phase","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"threshold unforgeability with proactive refresh support","response_communication":null,"robustness":"identifiable abort rather than guaranteed output","security_mode":"threshold public-key","security_model":"UC","security_notion":"UC threshold signing with identifiable abort","server_model":null,"server_work":null,"setup_model":"distributed key generation and auxiliary cryptographic setup","signer_model":null,"signing_cost":null,"signing_rounds":"noninteractive online contribution after preprocessing","sizes":{"public_key":"ordinary ECDSA public key","signature":"ordinary ECDSA signature"},"statefulness":null,"summary":"The online-round claim presupposes valid presignatures; total latency must include replenishing them.","supported_gates":null,"tag_size":null,"threshold_policy":"t-out-of-n under the paper bounds","transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"TSIG-PAPER-2020-CGGMP","year":2020},{"adaptive_security":"no; static proof profile","api_style":null,"associated_data":null,"assumption_family":"discrete_log","assumption_id":"TSIG-ASSUMPTION-DISCRETE-LOGARITHM","assumption_name":"discrete logarithm","authors":["Chelsea Komlo","Ian Goldberg"],"base_signature":"Schnorr","block_size":null,"bootstrapping":null,"capabilities":["ordinary-verifier-output","two-round","optional-preprocessing","true-threshold"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"two messages per signer in the two-round mode","construction_family":"threshold_schnorr","correctness":null,"corruption_model":"static adversary controlling fewer than the threshold","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2020-FROST","identifiable_abort":"operational participant identification in the paper protocol","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary Schnorr-family signature under the chosen ciphersuite","packing":null,"paper_title":"FROST: Flexible Round-Optimized Schnorr Threshold Signatures","paper_url":"https://eprint.iacr.org/2020/852","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"optional nonce-commitment preprocessing","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"true threshold participation","response_communication":null,"robustness":"abort and identify/exclude a misbehaving participant","security_mode":"threshold public-key","security_model":"random-oracle lineage","security_notion":"chosen-message threshold unforgeability","server_model":null,"server_work":null,"setup_model":"threshold key shares; DKG can be composed separately","signer_model":null,"signing_cost":null,"signing_rounds":"two rounds; one online round with preprocessing","sizes":{"public_key":"ordinary Schnorr public key","signature":"ordinary Schnorr signature"},"statefulness":null,"summary":"Nonce commitments are consumable protocol material; Figure 3 requires deletion after use, and Section 5.2 warns that reuse can expose the long-term secret share. FROST attributes an invalid response and aborts; it does not guarantee completion against withholding participants.","supported_gates":null,"tag_size":null,"threshold_policy":"t-out-of-n","transform":null,"update_model":null,"verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"TSIG-PAPER-2020-FROST","year":2020},{"adaptive_security":"no claim on this card","api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"TSIG-ASSUMPTION-MODULE-SIS-AND-MODULE-LWE","assumption_name":"Module-SIS and Module-LWE","authors":["Ivan Damgård","Claudio Orlandi","Akira Takahashi","Mehdi Tibouchi"],"base_signature":"Dilithium-G-style Fiat-Shamir with aborts","block_size":null,"bootstrapping":null,"capabilities":["post-quantum","two-round","abort-leakage-defense"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"two-round commitments and masked lattice responses","construction_family":"lattice_fswa_distributed","correctness":null,"corruption_model":"malicious adversary under the paper model","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2021-DOTT","identifiable_abort":"commitment-based transcript protection, not general robust completion","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"distributed Dilithium-G variant; verifier/parameters differ from standardized Dilithium","packing":null,"paper_title":"Two-round n-out-of-n and Multi-Signatures and Trapdoor Commitment from Lattices","paper_url":"https://eprint.iacr.org/2020/1110","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"Module-SIS and Module-LWE","preprocessing":"no online-round removal claimed on this card","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"all n signers required","response_communication":null,"robustness":"abort leakage is hidden; availability still fails when one signer withholds","security_mode":"n-out-of-n","security_model":"random-oracle lineage","security_notion":"distributed-signature unforgeability","server_model":null,"server_work":null,"setup_model":"distributed public key and lattice trapdoor commitment machinery","signer_model":null,"signing_cost":null,"signing_rounds":"two","sizes":{"public_key":"distributed-scheme public key","signature":"grows with the paper parameters and signer count"},"statefulness":null,"summary":"This is a full-threshold distributed signature, not a general t-out-of-n scheme. The paper's two-round profile uses parallel repetition to drive the probability of a successful non-aborting execution high; Section 3.2 explains that a single execution has three messages and succeeds only with its rejection probability.","supported_gates":null,"tag_size":null,"threshold_policy":"n-out-of-n","transform":null,"update_model":null,"verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"TSIG-PAPER-2021-DOTT","year":2021},{"adaptive_security":"not the main claim on this card","api_style":null,"associated_data":null,"assumption_family":"discrete_log","assumption_id":"TSIG-ASSUMPTION-DISCRETE-LOG-AND-STANDARD-SYMMETRIC-COMMITMENT-ASSUMPTIONS","assumption_name":"discrete-log and standard symmetric/commitment assumptions","authors":["François Garillot","Yashvanth Kondi","Payman Mohassel","Valeria Nikolaenko"],"base_signature":"Schnorr","block_size":null,"bootstrapping":null,"capabilities":["deterministic-nonce","stateless-signing","dishonest-majority","ordinary-verifier-output"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"garbled-circuit and proof dependent","construction_family":"threshold_schnorr_mpc_nonce","correctness":null,"corruption_model":"static adversary corrupting up to n-1 parties","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2021-GKMN","identifiable_abort":"protocol-specific","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary Schnorr signature","packing":null,"paper_title":"Threshold Schnorr with Stateless Deterministic Signing from Standard Assumptions","paper_url":"https://eprint.iacr.org/2021/1055","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"reusable commitment setup for the zero-knowledge layer","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"threshold unforgeability","response_communication":null,"robustness":"abort-oriented","security_mode":"threshold public-key","security_model":"standard assumptions with specified idealizations","security_notion":"threshold unforgeability with deterministic nonces","server_model":null,"server_work":null,"setup_model":"shared Schnorr key plus UC-commitment and garbled-circuit machinery","signer_model":null,"signing_cost":null,"signing_rounds":"three","sizes":{"public_key":"ordinary Schnorr public key","signature":"ordinary Schnorr signature"},"statefulness":null,"summary":"Stateless refers to nonce derivation and long-term signer state, not absence of all setup or protocol transcripts.","supported_gates":null,"tag_size":null,"threshold_policy":"n-out-of-n in the instantiated n-party protocol","transform":null,"update_model":null,"verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"TSIG-PAPER-2021-GKMN","year":2021},{"adaptive_security":"not claimed on this card","api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"TSIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS","assumption_name":"Module-LWE and Module-SIS","authors":["Peeter Laud","Nikita Snetkov","Jelizaveta Vakarjuk"],"base_signature":"Dilithium-derived","block_size":null,"bootstrapping":null,"capabilities":["post-quantum","two-party","signature-compression"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"network bytes not benchmarked; signing communication repeats with the audited preprint's average 101.55 rejections","construction_family":"lattice_fswa_distributed","correctness":null,"corruption_model":"one malicious party under the paper model","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","identifiable_abort":"not promoted from the outdated preprint","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"closer to Dilithium through signature compression; exact standard interoperability not asserted","packing":null,"paper_title":"DiLizium 2.0: Revisiting Two-Party Crystals-Dilithium","paper_url":"https://eprint.iacr.org/2022/644","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"Module-LWE and Module-SIS","preprocessing":"not normalized across preprint and final version","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"both parties required","response_communication":null,"robustness":"abort-oriented","security_mode":"two-party","security_model":"classical random oracle in the preprint","security_notion":"two-party signature unforgeability","server_model":null,"server_work":null,"setup_model":"two-party shared module-lattice secret and additively homomorphic commitment","signer_model":null,"signing_cost":null,"signing_rounds":"three in the audited ePrint","sizes":{"public_key":"2976 bytes in the audited preprint","secret_key_share":"8864 bytes in the audited preprint","signature":"21120 bytes in the audited preprint"},"statefulness":null,"summary":"The ePrint page says the preprint is outdated. Section 4 reports Java 17/Bouncy Castle measurements on an AMD Ryzen 5 PRO 3500U: 1.48 ms key generation, 174.65 ms signing, 1.18 ms verification, and 101.55 average rejections over 1000 executions, excluding network delay. All values are retained only as preprint observations, not current journal benchmarks.","supported_gates":null,"tag_size":null,"threshold_policy":"2-out-of-2","transform":null,"update_model":null,"verification_cost":null,"verification_status":"fulltext_preprint_reviewed_final_pending","work_id":"TSIG-PAPER-2022-DILIZIUM2","year":2022},{"adaptive_security":"not claimed on this card","api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"TSIG-ASSUMPTION-STANDARD-RING-LWE-AND-SIS-FAMILY-LATTICE-ASSUMPTIONS","assumption_name":"standard Ring-LWE and SIS-family lattice assumptions","authors":["Kamil Doruk Gur","Jonathan Katz","Tjerand Silde"],"base_signature":"lattice Fiat-Shamir-with-aborts line","block_size":null,"bootstrapping":null,"capabilities":["post-quantum","arbitrary-threshold","two-round","distributed-key-generation"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"two online rounds with ciphertext/proof overhead","construction_family":"lattice_threshold_he","correctness":null,"corruption_model":"active adversary under the paper threshold-HE model","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2023-GKS","identifiable_abort":"exact property not promoted","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"scheme-specific lattice signature","packing":null,"paper_title":"Two-Round Threshold Lattice-Based Signatures from Threshold Homomorphic Encryption","paper_url":"https://eprint.iacr.org/2023/1318","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"Ring-LWE and SIS lineage through threshold HE and the signature layer","preprocessing":"DKG and threshold-HE setup","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"arbitrary threshold t<=n","response_communication":null,"robustness":"abort handling within active security; guaranteed output not claimed here","security_mode":"t-out-of-n","security_model":"random-oracle lineage","security_notion":"actively secure threshold signing","server_model":null,"server_work":null,"setup_model":"actively secure threshold linearly homomorphic encryption and distributed key generation","signer_model":null,"signing_cost":null,"signing_rounds":"two","sizes":{"public_key":"13.6 KB for that same estimate","signature":"46.6 KB for the paper's 128-bit 3-out-of-5 estimate"},"statefulness":null,"summary":"The concrete byte figures are bound to the paper's stated 3-out-of-5, 128-bit estimate and are not universal scheme constants. Figure 7 gives the actively secure two-round protocol; Theorem 3 includes the threshold-HE, NIZK, commitment, and random-oracle terms rather than reducing the complete package to Ring-LWE/SIS alone in one step.","supported_gates":null,"tag_size":null,"threshold_policy":"arbitrary t-out-of-n","transform":null,"update_model":null,"verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"TSIG-PAPER-2023-GKS","year":2023},{"adaptive_security":"no claim on this card","api_style":null,"associated_data":null,"assumption_family":"discrete_log","assumption_id":"TSIG-ASSUMPTION-ALGEBRAIC-ONE-MORE-DISCRETE-LOGARITHM-AND-RANDOM-ORACLE","assumption_name":"algebraic one-more discrete logarithm and random oracle","authors":["Hien Chu","Paul Gerhart","Tim Ruffing","Dominique Schröder"],"base_signature":"Schnorr","block_size":null,"bootstrapping":null,"capabilities":["ordinary-verifier-output","proof-without-agm","pedersen-dkg"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"FROST3 profile plus DKG cost","construction_family":"threshold_schnorr","correctness":null,"corruption_model":"static threshold adversary in the proof","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2023-OLAF","identifiable_abort":"protocol-specific","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary Schnorr-family signature","packing":null,"paper_title":"Practical Schnorr Threshold Signatures Without the Algebraic Group Model","paper_url":"https://eprint.iacr.org/2023/899","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"FROST-family nonce preprocessing options","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"threshold unforgeability","response_communication":null,"robustness":"abort-oriented FROST family","security_mode":"threshold public-key","security_model":"ROM without AGM","security_notion":"threshold unforgeability","server_model":null,"server_work":null,"setup_model":"Pedersen-DKG variant composed with FROST3","signer_model":null,"signing_cost":null,"signing_rounds":"FROST3 signing profile","sizes":{"public_key":"ordinary Schnorr public key plus DKG verification data","signature":"ordinary Schnorr signature"},"statefulness":null,"summary":"Removing AGM from the proof does not mean the scheme relies only on plain discrete log; the AOMDL assumption is recorded explicitly.","supported_gates":null,"tag_size":null,"threshold_policy":"t-out-of-n","transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"TSIG-PAPER-2023-OLAF","year":2023},{"adaptive_security":"no for signer corruption; the main reduction uses adaptive AOM-MLWE as an assumption","api_style":null,"associated_data":null,"assumption_family":"lattice_one_more","assumption_id":"TSIG-ASSUMPTION-ADAPTIVE-AOM-MLWE-AND-PRF-SECURITY-SELECTIVE-AOM-UMLWE-HAS-A-UMLWE-MSIS-REDUCTION","assumption_name":"adaptive AOM-MLWE and PRF security; selective AOM-UMLWE has a UMLWE/MSIS reduction","authors":["Thomas Espitau","Shuichi Katsumata","Kaoru Takemure"],"base_signature":"Lyubashevsky-style lattice signature","block_size":null,"bootstrapping":null,"capabilities":["post-quantum","two-round","noninteractive-online","large-threshold"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"at 128-bit security and T=1024, 14.1 KB optimized online or 276 KB naive online per user, plus 262 KB offline","construction_family":"lattice_one_more","correctness":null,"corruption_model":"selective/static corruption of fewer than T signers","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2024-AOMMLWE","identifiable_abort":"no; misbehavior detection is left as future work","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"scheme-specific lattice signature","packing":null,"paper_title":"Two-Round Threshold Signature from Algebraic One-More Learning with Errors","paper_url":"https://eprint.iacr.org/2024/496","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"adaptive AOM-MLWE; only its selective variant is reduced from UMLWE and MSIS","preprocessing":"first round can be prepared without the message or signer set","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"threshold signing","response_communication":null,"robustness":"no; robust signing is left as future work","security_mode":"T-out-of-N","security_model":"selective-corruption random-oracle game under adaptive AOM-MLWE","security_notion":"threshold unforgeability","server_model":null,"server_work":null,"setup_model":"trusted-dealer key generation; DKG is left as future work","signer_model":null,"signing_cost":null,"signing_rounds":"two; online phase noninteractive after message-independent preprocessing","sizes":{"public_key":"5.5 KB for the same Table 3 profile","signature":"10.8 KB at 128-bit security and T=1024"},"statefulness":null,"summary":"The assumption axis is intentionally separated from standard MLWE-only constructions. Theorem 6.1 bases threshold unforgeability on adaptive AOM-MLWE, whereas Theorem 4.5 reduces only selective AOM-UMLWE to UMLWE and MSIS; the final revision leaves bridging this adaptivity gap open.","supported_gates":null,"tag_size":null,"threshold_policy":"arbitrary T-out-of-N with concrete support up to T=1024","transform":null,"update_model":null,"verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"TSIG-PAPER-2024-AOMMLWE","year":2024},{"adaptive_security":"not claimed on this card","api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"TSIG-ASSUMPTION-MODULE-LWE","assumption_name":"Module-LWE","authors":["Thomas Espitau","Guilhem Niot","Thomas Prest"],"base_signature":"lattice hash-and-sign","block_size":null,"bootstrapping":null,"capabilities":["post-quantum","robust-dkg","hash-and-sign","no-fhe"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"paper-specific; no FHE ciphertext layer","construction_family":"lattice_hash_and_sign_submersion","correctness":null,"corruption_model":"malicious threshold adversary under the paper model","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2024-FLOOD","identifiable_abort":"verifiable shares support blame; exact interface follows paper","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"scheme-specific hash-and-sign lattice verifier","packing":null,"paper_title":"Flood and Submerse: Distributed Key Generation and Robust Threshold Signature from Lattices","paper_url":"https://eprint.iacr.org/2024/959","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"MLWE, random submersions, and noise flooding","preprocessing":"verifiable short-secret-sharing and DKG material","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"threshold unforgeability","response_communication":null,"robustness":"yes, including key generation in the paper claim","security_mode":"threshold public-key","security_model":"random oracle","security_notion":"robust threshold unforgeability","server_model":null,"server_work":null,"setup_model":"robust DKG via random submersions","signer_model":null,"signing_cost":null,"signing_rounds":"distributed hash-and-sign protocol; exact count parameterized","sizes":{"public_key":"parameter-set-specific","signature":"about 13 KB in the paper's typical T=16 parameter set"},"statefulness":null,"summary":"The 13 KB observation is tied to the paper's typical T=16 parameter set.","supported_gates":null,"tag_size":null,"threshold_policy":"general threshold profile with a representative T=16 parameter set","transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"TSIG-PAPER-2024-FLOOD","year":2024},{"adaptive_security":"full adaptive security","api_style":null,"associated_data":null,"assumption_family":"ddh","assumption_id":"TSIG-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","assumption_name":"decisional Diffie-Hellman","authors":["Renas Bacho","Sourav Das","Julian Loss","Ling Ren"],"base_signature":"Schnorr","block_size":null,"bootstrapping":null,"capabilities":["ordinary-verifier-output","full-adaptive-security","full-corruption-threshold","identifiable-abort","constant-size-signing-key"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"exact table parameter-dependent","construction_family":"threshold_schnorr_adaptive","correctness":null,"corruption_model":"fully adaptive adversary","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2024-GLACIUS","identifiable_abort":"yes, with a formal game-based definition","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"ordinary Schnorr-family signature","packing":null,"paper_title":"Glacius: Threshold Schnorr Signatures from DDH with Full Adaptive Security","paper_url":"https://eprint.iacr.org/2024/1628","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"none","preprocessing":"protocol setup and signing-key material","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"full corruption threshold stated as t<n in the paper","response_communication":null,"robustness":"identifiable abort rather than guaranteed output","security_mode":"threshold public-key","security_model":"random oracle","security_notion":"fully adaptive threshold unforgeability with identifiable abort","server_model":null,"server_work":null,"setup_model":"distributed Schnorr key with constant-size per-signer signing keys","signer_model":null,"signing_cost":null,"signing_rounds":"exact protocol phases follow paper","sizes":{"public_key":"ordinary Schnorr public key","signature":"ordinary Schnorr signature"},"statefulness":null,"summary":"DDH here is a precise proof assumption for a 2024/2025 threshold-Schnorr result, not the origin assumption of the entire threshold-signature field.","supported_gates":null,"tag_size":null,"threshold_policy":"full threshold range t<n under the paper's convention","transform":null,"update_model":null,"verification_cost":null,"verification_status":"primary_source_reviewed","work_id":"TSIG-PAPER-2024-GLACIUS","year":2024},{"adaptive_security":"no; static corruption game","api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"TSIG-ASSUMPTION-HINT-MLWE-AND-SELFTARGETMSIS-WITH-REDUCTIONS-TO-MLWE-MSIS","assumption_name":"Hint-MLWE and SelfTargetMSIS with reductions to MLWE/MSIS","authors":["Rafael del Pino","Shuichi Katsumata","Mary Maller","Fabrice Mouhartem","Thomas Prest","Markku-Juhani Saarinen"],"base_signature":"Raccoon lattice signature","block_size":null,"bootstrapping":null,"capabilities":["post-quantum","large-threshold","implementation","symmetric-and-simple-lattice-signing"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"Table 2 reports 40.8 KB per signer at kappa=128; implementation accounting is 40800+16T bytes with pairwise MACs","construction_family":"lattice_masked_partial_signatures","correctness":null,"corruption_model":"static corrupt set chosen before key generation with fewer than T parties","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2024-RACCOON","identifiable_abort":"no; left as future work","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"verification algorithm identical to the paper's Raccoon variant; concrete parameters are not tuned for Raccoon interchangeability","packing":null,"paper_title":"Threshold Raccoon: Practical Threshold Signatures from Standard Lattice Assumptions","paper_url":"https://eprint.iacr.org/2024/184","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"Module-LWE and Module-SIS lineage","preprocessing":"pairwise PRF seeds provisioned at key generation; per-session additive masks are generated online","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"threshold signing under standard lattice assumptions","response_communication":null,"robustness":"abort-oriented; robustness against malicious failure is left as future work","security_mode":"T-out-of-N","security_model":"random-oracle static-corruption game with bounded signing queries","security_notion":"threshold unforgeability","server_model":null,"server_work":null,"setup_model":"trusted centralized key generation; a compatible DKG is outside the paper's scope","signer_model":null,"signing_cost":null,"signing_rounds":"three","sizes":{"public_key":"3.9 KB in Table 2; implementation value 3856 bytes","signature":"12.7 KB at kappa=128 in Table 2; implementation upper bound 12736 bytes with high probability"},"statefulness":null,"summary":"The paper requires a unique session identifier so pairwise PRF-derived masks are never reused. At the 128-bit parameter set, Table 3 reports three per-signer ShareSign phases; Section 9 reports 116 ms per signer at T=1024 only when communication latency is ignored and 4.5 GHz turbo is enabled.","supported_gates":null,"tag_size":null,"threshold_policy":"any 1<=T<=N<=1024 in the concrete parameter profile","transform":null,"update_model":null,"verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"TSIG-PAPER-2024-RACCOON","year":2024},{"adaptive_security":"proactive mobile-corruption security across refresh periods; not full within-period adaptive security","api_style":null,"associated_data":null,"assumption_family":"lattice","assumption_id":"TSIG-ASSUMPTION-MLWE-AND-MSIS-PLUS-THE-FPREP-HYBRID-PREPROCESSING-MODEL","assumption_name":"MLWE and MSIS plus the FPREP-hybrid preprocessing model","authors":["Guofeng Tang","Bo Pang","Long Chen","Zhenfeng Zhang"],"base_signature":"paper-specific lattice signature with ordinary verifier","block_size":null,"bootstrapping":null,"capabilities":["post-quantum","arbitrary-threshold","interchangeable-output","proactive-refresh","implementation"],"ciphertext_security":null,"circuit_class":null,"client_storage":null,"communication":"1.417 MB sent per party in 15 online rounds for the Table 4 profile","construction_family":"lattice_mpc_rejection_sampling","correctness":null,"corruption_model":"mobile malicious adversary corrupting at most t-1 parties in each refresh period","decapsulation_cost":null,"decrypt_cost":{},"decrypt_pairings":"","decryption_failure":null,"encapsulation_cost":null,"exactness":null,"ggm_file":null,"id":"TSIG-CONSTRUCTION-2024-TANG","identifiable_abort":"no general identifiable-abort claim promoted","key_size":null,"large_universe":null,"misuse_resistance":null,"multi_use_attributes":null,"noise_management":null,"nonce_generation":null,"nonce_requirement":null,"nonce_size":null,"normative_status":null,"object_type":null,"online":null,"output_compatibility":"yes; same verification algorithm as the paper's non-threshold signature","packing":null,"paper_title":"Efficient Lattice-Based Threshold Signatures with Functional Interchangeability","paper_url":"https://doi.org/10.1109/TIFS.2023.3293408","parallelizable":null,"plaintext_space":null,"policy_class":null,"post_quantum_mechanism":"lattice assumptions and efficient distributed rejection sampling","preprocessing":"t-out-of-n authenticated bits and Beaver triples generated before DKG and signing; the reported batch supports five signatures","primitive":"threshold_signature","privacy_model":null,"proof_model":null,"quantum_security":null,"query_communication":null,"resilience":"t-out-of-n signing","response_communication":null,"robustness":"abort and restart on failed distributed rejection or MAC checks; guaranteed output not claimed","security_mode":"t-out-of-n","security_model":"random oracle and FPREP hybrid","security_notion":"proactive threshold EUF-CMA","server_model":null,"server_work":null,"setup_model":"t-out-of-n SPDZ variant and distributed key generation","signer_model":null,"signing_cost":null,"signing_rounds":"15 online rounds in the Table 3 parameter profile","sizes":{"public_key":"same as the paper's non-threshold base public key and independent of party count","signature":"same as the paper's non-threshold base signature and independent of party count"},"statefulness":null,"summary":"The 1.417 MB and 15-round figures are per-party online costs under Table 4's 123-classical/112-quantum-bit parameter setting. The MP-SPDZ-derived implementation reports 0.5-second two-party LAN signing and 1.5-second two-party WAN signing; these are environment-specific measurements, not cross-paper rankings.","supported_gates":null,"tag_size":null,"threshold_policy":"arbitrary t-out-of-n","transform":null,"update_model":null,"verification_cost":null,"verification_status":"fulltext_reviewed","work_id":"TSIG-PAPER-2024-TANG","year":2024}],"edges":[{"evidenceLocator":"CGGMP revised full version, abstract and contribution overview","evidenceUrl":"https://eprint.iacr.org/2021/060","id":"TSIG-REL-024967F8CD2DEC","note":"Building on GG18, CGGMP strengthens the practical multiparty-ECDSA line with an adaptive UC treatment in the global random-oracle model.","resultId":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA","reviewStatus":"primary_source_checked","source":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA","target":"TSIG-RESULT-2020-CGGMP-UC-THRESHOLD-ECDSA","type":"STRENGTHENS_SECURITY"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-028693147BEECD","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-GLACIUS","target":"TSIG-RESULT-2024-GLACIUS-FULLY-ADAPTIVE-THRESHOLD-SCHNORR-FROM-DDH","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-02886234E91727","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2023-GKS","target":"TSIG-ASSUMPTION-STANDARD-RING-LWE-AND-SIS-FAMILY-LATTICE-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-04727A7D4E4CE7","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2020-CGGMP","target":"TSIG-PAPER-2020-CGGMP","type":"DESCRIBED_IN"},{"evidenceLocator":"Shoup abstract and Introduction","evidenceUrl":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","id":"TSIG-REL-05593A6BE1E951","note":"Relative to early distributed RSA private operations, Shoup gives a robust signing construction whose servers independently produce publicly checkable shares after setup; this does not compare total key-generation costs.","resultId":"TSIG-RESULT-1989-DF-DISTRIBUTED-RSA-SIGNING-ROOT","reviewStatus":"primary_source_checked","source":"TSIG-RESULT-1989-DF-DISTRIBUTED-RSA-SIGNING-ROOT","target":"TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-0885A9B08244C2","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2003-BOLDYREVA","target":"TSIG-ASSUMPTION-GAP-DIFFIE-HELLMAN-CO-CDH-LINEAGE-IN-PAIRING-GROUPS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-0953583663B3A7","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-RACCOON","target":"TSIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-0B44E95D4B0D8A","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2026-NIST8214C","target":"TSIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-0CCB3EB5565EC5","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2021-DOTT","target":"TSIG-ASSUMPTION-MODULE-SIS-AND-MODULE-LWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-0D29D935F44DD2","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2021-GKMN","target":"TSIG-PAPER-2021-GKMN","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-0D718152169B3F","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-ROUTE-001","target":"TSIG-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-0E0683FEAD96B3","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2003-BOLDYREVA","target":"TSIG-PAPER-2003-BOLDYREVA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-115D4E097864E8","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-TANG","target":"TSIG-RESULT-2024-TANG-PROACTIVE-REFRESH","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-14950893CC9699","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2020-CGGMP","target":"TSIG-RESULT-2020-CGGMP-ONE-MESSAGE-DEPENDENT-ONLINE-ROUND","type":"HAS_RESULT"},{"evidenceLocator":"Threshold Raccoon Section 1.1, PDF pp. 4–5; Sections 2.3 and 6; Tables 2–3, PDF pp. 8–10, 20–23, and 43–44","evidenceUrl":"https://eprint.iacr.org/2024/184","id":"TSIG-REL-1B319BE15B2A9D","note":"Threshold Raccoon trades DOTT's two-round homomorphic-trapdoor-commitment route for a three-round, pairwise-mask design with concrete parameter sets through T=1024.","resultId":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","reviewStatus":"fulltext_checked","source":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","target":"TSIG-RESULT-2024-RACCOON-EFFICIENT-LARGE-THRESHOLD-LATTICE-SIGNING","type":"CHANGES_ROUNDS_AND_MECHANISM"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-1C242B3CAF23FB","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2000-SHOUP","target":"TSIG-PAPER-2000-SHOUP","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-1F1C0B3A6412C8","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2021-GKMN","target":"TSIG-ASSUMPTION-DISCRETE-LOG-AND-STANDARD-SYMMETRIC-COMMITMENT-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-1F63CCD767A656","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-OP-001","target":"TSIG-PAPER-2024-FLOOD","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-246FA45B09EFC1","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2026-NIST8214C","target":"TSIG-RESULT-2026-NIST8214C-NIST-THRESHOLD-CRYPTOGRAPHY-PACKAGE-FRAMEWORK","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-2564CD2A60CAEB","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-BARRIER-001","target":"TSIG-OP-001","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-28AD3D11D13F5A","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2023-OLAF","target":"TSIG-PAPER-2023-OLAF","type":"DESCRIBED_IN"},{"evidenceLocator":"GJKR CRYPTO 1996 paper, overview and robustness sections","evidenceUrl":"https://doi.org/10.1007/3-540-68697-5","id":"TSIG-REL-29A902B7276EDD","note":"GJKR develops the shared-RSA branch with verifiable shares and robustness against malicious behavior rather than only distributing the private operation.","resultId":"TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM","reviewStatus":"bibliographic_checked","source":"TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM","target":"TSIG-RESULT-1996-GJKR-RSA-ROBUST-THRESHOLD-RSA-FUNCTION-SHARING","type":"STRENGTHENS_ROBUSTNESS"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-2A8556D4DC06C7","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2019-DKLSN","target":"TSIG-PAPER-2019-DKLS-N","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-2B6173158A57E0","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2018-DKLS2","target":"TSIG-PAPER-2018-DKLS-2P","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-2C96121091E4C9","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-1996-GJKR-RSA","target":"TSIG-RESULT-1996-GJKR-RSA-ROBUST-THRESHOLD-RSA-FUNCTION-SHARING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-2E6D7A522740F3","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2022-DILIZIUM2","target":"TSIG-PAPER-2022-DILIZIUM2","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-2EA94DA42E12B3","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2023-GKS","target":"TSIG-RESULT-2023-GKS-ACTIVELY-SECURE-THRESHOLD-LINEAR-HE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-31247D38CC61A4","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2021-DOTT","target":"TSIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-31AEE04816B8D5","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-AOMMLWE","target":"TSIG-RESULT-2024-AOMMLWE-TWO-ROUND-LATTICE-THRESHOLD-WITHOUT-FHE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-338CFF1B87E572","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-1996-GJKR-DSS","target":"TSIG-ASSUMPTION-HARDNESS-OF-FORGING-THE-UNDERLYING-DSS-SIGNATURE-UNDER-THE-PAPER-MODEL","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-33A439A36906D7","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2023-GKS","target":"TSIG-RESULT-2023-GKS-TWO-ROUND-ARBITRARY-THRESHOLD-LATTICE-SIGNATURE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-353E6471395328","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2018-GG","target":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RELATED-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-361F52B45BCD16","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-AOMMLWE","target":"TSIG-RESULT-2024-AOMMLWE-OFFLINE-ONLINE-SIGNING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-39A349CD51A8DA","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-1989-DF","target":"TSIG-RESULT-1989-DF-DISTRIBUTED-RSA-SIGNING-ROOT","type":"HAS_RESULT"},{"evidenceLocator":"FROST Sections 2.3 and 5.1, Figure 1, PDF pp. 6–10","evidenceUrl":"https://eprint.iacr.org/2020/852","id":"TSIG-REL-3CEF565C68BCD0","note":"FROST can be composed with a discrete-log DKG to create the shared Schnorr key, while its paper focuses on round-optimized signing.","resultId":"TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER","reviewStatus":"fulltext_checked","source":"TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER","target":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","type":"COMPOSES_SETUP"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-3EBF346D400EDF","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2020-CGGMP","target":"TSIG-RESULT-2020-CGGMP-IDENTIFIABLE-ABORT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-472BBCED29F48C","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-FLOOD","target":"TSIG-RESULT-2024-FLOOD-FIRST-HASH-AND-SIGN-LATTICE-THRESHOLD-SIGNATURE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-4892A9254F6AA0","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2024-TANG","target":"TSIG-ASSUMPTION-MLWE-AND-MSIS-PLUS-THE-FPREP-HYBRID-PREPROCESSING-MODEL","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-53048E93034D46","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2020-FROST","target":"TSIG-OP-001","type":"TARGETS"},{"evidenceLocator":"Glacius abstract and Introduction","evidenceUrl":"https://eprint.iacr.org/2024/1628","id":"TSIG-REL-5B5E7835B1AAEA","note":"Glacius changes the security point to fully adaptive corruptions from DDH while retaining compact Schnorr output and adding a formal identifiable-abort guarantee.","resultId":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","reviewStatus":"primary_source_checked","source":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","target":"TSIG-RESULT-2024-GLACIUS-FULLY-ADAPTIVE-THRESHOLD-SCHNORR-FROM-DDH","type":"STRENGTHENS_ADAPTIVE_SECURITY"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-610EF4860D34DD","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2018-GG","target":"TSIG-RESULT-2018-GG-DISTRIBUTED-SETUP","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-619E6095F105A8","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2021-DOTT","target":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-61BC4BA99A9F19","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-RACCOON","target":"TSIG-RESULT-2024-RACCOON-EFFICIENT-LARGE-THRESHOLD-LATTICE-SIGNING","type":"HAS_RESULT"},{"evidenceLocator":"EUROCRYPT 1996 paper and journal abstract","evidenceUrl":"https://doi.org/10.1007/3-540-68339-9_31","id":"TSIG-REL-6252126CD5DEED","note":"GJKR realizes quorum-controlled signing for the DSS signing equation, producing ordinary DSS signatures with the construction's stated resilience and robustness conditions.","resultId":"TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM","reviewStatus":"primary_source_checked","source":"TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM","target":"TSIG-RESULT-1996-GJKR-DSS-ROBUST-THRESHOLD-DSS","type":"INSTANTIATES_MODEL"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-629E05DCDF61F4","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2019-DKLS-N","target":"TSIG-RESULT-2019-DKLS-N-GENERAL-THRESHOLD-ECDSA","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-631DCA2E4545F8","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2022-DILIZIUM2","target":"TSIG-RESULT-2022-DILIZIUM2-TWO-PARTY-DILITHIUM-LINE","type":"HAS_RESULT"},{"evidenceLocator":"IEEE paper abstract and construction overview","evidenceUrl":"https://doi.org/10.1109/SP.2019.00024","id":"TSIG-REL-63843B1D86ED75","note":"The later DKLS threshold construction generalizes the two-party OT/hash-proof-system route to a general threshold protocol.","resultId":"TSIG-RESULT-2018-DKLS-2P-TWO-PARTY-ECDSA-WITHOUT-PAILLIER","reviewStatus":"bibliographic_checked","source":"TSIG-RESULT-2018-DKLS-2P-TWO-PARTY-ECDSA-WITHOUT-PAILLIER","target":"TSIG-RESULT-2019-DKLS-N-GENERAL-THRESHOLD-ECDSA","type":"GENERALIZES"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-6411F943768935","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2024-FLOOD","target":"TSIG-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-666C62FFA38DD8","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2024-AOMMLWE","target":"TSIG-PAPER-2024-AOMMLWE","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-6749CB744F436B","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2024-RACCOON","target":"TSIG-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-6D33DECE753CA4","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-BARRIER-002","target":"TSIG-OP-001","type":"BLOCKS"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-6E22C303909840","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2024-FLOOD","target":"TSIG-ASSUMPTION-MODULE-LWE","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-70ACB2F3230075","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2020-CGGMP","target":"TSIG-RESULT-2020-CGGMP-PROACTIVE-SECURITY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-71EBBE4AA35EF1","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-ROUTE-003","target":"TSIG-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-73C12D6D1A1F2D","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2020-CGGMP","target":"TSIG-RESULT-2020-CGGMP-UC-THRESHOLD-ECDSA","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-75FC8F854C4B7E","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2000-SHOUP","target":"TSIG-RESULT-2000-SHOUP-NONINTERACTIVE-SHARE-GENERATION","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-762F4AAD4183DE","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-TANG","target":"TSIG-RESULT-2024-TANG-IMPLEMENTED-T-OUT-OF-N-LATTICE-SIGNATURE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-7A1DF12C039FA4","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-1996-GJKR-RSA","target":"TSIG-PAPER-1996-GJKR-RSA","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-7CBB9D475BE352","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2023-GKS","target":"TSIG-PAPER-2023-GKS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-7D0F512C9F4AF3","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2024-TANG","target":"TSIG-PAPER-2024-TANG","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-7D63603FE42D69","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-1996-GJKR-DSS","target":"TSIG-RESULT-1996-GJKR-DSS-ROBUST-THRESHOLD-DSS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-7D8E952F861460","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2018-DKLS-2P","target":"TSIG-RESULT-2018-DKLS-2P-HASH-PROOF-SYSTEM-ROUTE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-7E67E6E493212C","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2020-FROST","target":"TSIG-RESULT-2020-FROST-ONE-ROUND-WITH-PREPROCESSING","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-7FA2A84481CE9B","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2024-AOMMLWE","target":"TSIG-ASSUMPTION-ADAPTIVE-AOM-MLWE-AND-PRF-SECURITY-SELECTIVE-AOM-UMLWE-HAS-A-UMLWE-MSIS-REDUCTION","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-800219E1F8B7C8","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2026-NIST8214C","target":"TSIG-RESULT-2026-NIST8214C-INTEROPERABLE-OUTPUT-EMPHASIS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-84DD1E65583A9D","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2024-GLACIUS","target":"TSIG-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-86C0CD1A465CFB","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2024-RACCOON","target":"TSIG-ASSUMPTION-HINT-MLWE-AND-SELFTARGETMSIS-WITH-REDUCTIONS-TO-MLWE-MSIS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-8785ED1CA476EA","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-1996-GJKR-DSS","target":"TSIG-PAPER-1996-GJKR-DSS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-8C9A908B424519","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-OP-001","target":"TSIG-PAPER-2024-AOMMLWE","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-8EEA4DAA873061","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-1996-GJKR-RSA","target":"TSIG-ASSUMPTION-RSA-FUNCTION-SECURITY-WITH-PAPER-SPECIFIC-SHARING-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-8F3D8247619786","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-GLACIUS","target":"TSIG-OP-001","type":"TARGETS"},{"evidenceLocator":"Olaf abstract and Introduction","evidenceUrl":"https://eprint.iacr.org/2023/899","id":"TSIG-REL-9095C76262CC64","note":"Olaf combines the efficient FROST3 variant with a Pedersen-DKG variant and proves unforgeability without the algebraic group model.","resultId":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","reviewStatus":"primary_source_checked","source":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","target":"TSIG-RESULT-2023-OLAF-PROOF-WITHOUT-AGM","type":"REFINES_PROOF"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-97ED5EC39E5FF0","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2020-FROST","target":"TSIG-PAPER-2020-FROST","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-9AA5C0EC7776DF","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2019-DKLSN","target":"TSIG-ASSUMPTION-ECDSA-CENTERED-ASSUMPTIONS-PLUS-OT-HASH-PROOF-SYSTEM-INGREDIENTS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-9AC61BA54733DC","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2023-OLAF","target":"TSIG-RESULT-2023-OLAF-PROOF-WITHOUT-AGM","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-9C6D7A5133384C","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2023-GKS","target":"TSIG-OP-001","type":"TARGETS"},{"evidenceLocator":"Shoup related-work comparison and construction overview","evidenceUrl":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","id":"TSIG-REL-9FBC650675612F","note":"Shoup presents a more practical robust threshold-RSA signature protocol with noninteractive signature shares and direct share verification.","resultId":"TSIG-RESULT-1996-GJKR-RSA-ROBUST-THRESHOLD-RSA-FUNCTION-SHARING","reviewStatus":"primary_source_checked","source":"TSIG-RESULT-1996-GJKR-RSA-ROBUST-THRESHOLD-RSA-FUNCTION-SHARING","target":"TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA","type":"IMPROVES_EFFICIENCY"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-A146BE022EF43F","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-OP-001","target":"TSIG-PAPER-2026-NIST8214C","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-A1962195A024D0","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-1999-GJKR-DKG","target":"TSIG-RESULT-1999-GJKR-DKG-MALICIOUS-MINORITY-SECURITY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-A28E30C255B8DF","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2022-DILIZIUM2","target":"TSIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-A52516DC33BD76","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-FLOOD","target":"TSIG-RESULT-2024-FLOOD-RANDOM-SUBMERSIONS","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-A745FB2FC7DD9D","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-RACCOON","target":"TSIG-RESULT-2024-RACCOON-ONE-TIME-ADDITIVE-MASK-DEFENSE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-AA20DEE8A549A9","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2020-FROST","target":"TSIG-RESULT-2020-FROST-IDENTIFIABLE-MISBEHAVING-PARTICIPANT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-AC60971851BB16","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2018-GG","target":"TSIG-PAPER-2018-GG","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-AD7F8A9C07113D","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-TANG","target":"TSIG-RESULT-2024-TANG-FUNCTIONAL-INTERCHANGEABILITY","type":"HAS_RESULT"},{"evidenceLocator":"DiLizium 2.0 Sections 1.1–1.2, PDF pp. 2–3; audited ePrint is marked outdated","evidenceUrl":"https://eprint.iacr.org/2022/644","id":"TSIG-REL-B0574E00C59EC3","note":"DiLizium 2.0 follows the DOTT commitment-based logic but incorporates Dilithium signature-compression techniques in a two-party authentication setting.","resultId":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","reviewStatus":"fulltext_checked","source":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","target":"TSIG-RESULT-2022-DILIZIUM2-TWO-PARTY-DILITHIUM-LINE","type":"CHANGES_ENCODING"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-B1487ED834D12D","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2021-DOTT","target":"TSIG-RESULT-2021-DOTT-ABORT-LEAKAGE-COUNTERMEASURE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-B18D6572D1DCCD","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2024-RACCOON","target":"TSIG-PAPER-2024-RACCOON","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-B1A8F781B6A579","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2021-DOTT","target":"TSIG-PAPER-2021-DOTT","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-B22F5EA3923845","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2018-DKLS2","target":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-PLUS-HASH-PROOF-SYSTEM-AND-OT-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-B4128A909BBFB9","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2017-LINDELL","target":"TSIG-RESULT-2017-LINDELL-MALICIOUS-SECURITY","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-B613958C0BCAF2","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2023-OLAF","target":"TSIG-ASSUMPTION-ALGEBRAIC-ONE-MORE-DISCRETE-LOGARITHM-AND-RANDOM-ORACLE","type":"RELIES_ON"},{"evidenceLocator":"CGGMP revised full version, abstract and contribution overview","evidenceUrl":"https://eprint.iacr.org/2021/060","id":"TSIG-REL-B678E6D9CE289B","note":"Building on GG18, CGGMP moves all message-independent signing rounds into preprocessing and leaves one message-dependent online round.","resultId":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA","reviewStatus":"primary_source_checked","source":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA","target":"TSIG-RESULT-2020-CGGMP-ONE-MESSAGE-DEPENDENT-ONLINE-ROUND","type":"IMPROVES_ONLINE_INTERACTION"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-B93456F1A45B3D","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-OP-001","target":"TSIG-PAPER-2024-TANG","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-B9CAC67D741526","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2024-GLACIUS","target":"TSIG-PAPER-2024-GLACIUS","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-BA7683DA792569","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-OP-001","target":"TSIG-PAPER-2023-GKS","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-BBEB8B9BE72F87","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2018-GG","target":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-C043063306CD42","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-1989-DF","target":"TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-C108FB87190BDF","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2000-SHOUP","target":"TSIG-ASSUMPTION-RSA-ASSUMPTION-PLUS-PAPER-SPECIFIC-NUMBER-THEORETIC-SETUP","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-C2B2DF933A420E","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2020-CGGMP","target":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RANGE-PROOF-RELATED-ASSUMPTIONS","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-C5075727A9D8AA","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2020-FROST","target":"TSIG-ASSUMPTION-DISCRETE-LOGARITHM","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-C96FCCBF05BB34","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-OP-001","target":"TSIG-PAPER-2024-RACCOON","type":"GROUNDED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-C9AB14182DF373","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2023-GKS","target":"TSIG-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-CC8C9E96ACD0C5","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-1991-PEDERSEN","target":"TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER","type":"HAS_RESULT"},{"evidenceLocator":"GG18 abstract, introduction, and prior-work comparison","evidenceUrl":"https://eprint.iacr.org/2019/114","id":"TSIG-REL-D17F4255E59802","note":"GG18 moves the practical Paillier-based ECDSA line from two parties to a general multiparty threshold setting with distributed setup.","resultId":"TSIG-RESULT-2017-LINDELL-EFFICIENT-TWO-PARTY-ECDSA","reviewStatus":"primary_source_checked","source":"TSIG-RESULT-2017-LINDELL-EFFICIENT-TWO-PARTY-ECDSA","target":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA","type":"GENERALIZES"},{"evidenceLocator":"GJKR DKG abstract, introduction, and protocol comparison","evidenceUrl":"https://doi.org/10.1007/3-540-48910-X_21","id":"TSIG-REL-D2871697DFB891","note":"GJKR revisits discrete-log DKG and supplies a robust malicious-security treatment for distributed key generation.","resultId":"TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER","reviewStatus":"primary_source_checked","source":"TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER","target":"TSIG-RESULT-1999-GJKR-DKG-ROBUST-DISCRETE-LOG-DKG","type":"STRENGTHENS_ROBUSTNESS"},{"evidenceLocator":"AOM-MLWE Sections 1.1, 2.1, and 6.2, Figures 2 and 8, Theorem 6.1, PDF pp. 4–10 and 33–36","evidenceUrl":"https://eprint.iacr.org/2024/496","id":"TSIG-REL-D442E3941447FA","note":"Starting from Threshold Raccoon's pairwise-mask approach, the AOM-MLWE construction reduces signing from three rounds to two and makes the first round message- and signer-set-independent by introducing an algebraic one-more lattice assumption.","resultId":"TSIG-RESULT-2024-RACCOON-ONE-TIME-ADDITIVE-MASK-DEFENSE","reviewStatus":"fulltext_checked","source":"TSIG-RESULT-2024-RACCOON-ONE-TIME-ADDITIVE-MASK-DEFENSE","target":"TSIG-RESULT-2024-AOMMLWE-TWO-ROUND-LATTICE-THRESHOLD-WITHOUT-FHE","type":"CHANGES_ASSUMPTION_AND_ROUNDS"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-DCCE30CCDC0EA5","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2021-GKMN","target":"TSIG-RESULT-2021-GKMN-STATELESS-DETERMINISTIC-THRESHOLD-SCHNORR","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-DCE13E854DDAEF","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-ROUTE-002","target":"TSIG-OP-001","type":"ENABLES"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-DF3847736F6B40","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2024-TANG","target":"TSIG-OP-001","type":"APPROACHES"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-DF41C64E4573FA","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2022-DILIZIUM2","target":"TSIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-E13B4D24A2F884","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2020-FROST","target":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-E4C52A21AC8B84","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2018-DKLS-2P","target":"TSIG-RESULT-2018-DKLS-2P-TWO-PARTY-ECDSA-WITHOUT-PAILLIER","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-E7BDB56BC4F805","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2003-BOLDYREVA","target":"TSIG-RESULT-2003-BOLDYREVA-THRESHOLD-BLS-SIGNATURE","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-E8E9AD9994E100","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2024-AOMMLWE","target":"TSIG-OP-001","type":"APPROACHES"},{"evidenceLocator":"GKS Section 5, Figure 7 and Theorem 3, PDF pp. 22–26","evidenceUrl":"https://eprint.iacr.org/2023/1318","id":"TSIG-REL-EBF60742CF0CBC","note":"GKS preserves two signing rounds while moving from DOTT's full n-out-of-n threshold to arbitrary t<=n through threshold linearly homomorphic encryption.","resultId":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","reviewStatus":"fulltext_checked","source":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","target":"TSIG-RESULT-2023-GKS-TWO-ROUND-ARBITRARY-THRESHOLD-LATTICE-SIGNATURE","type":"GENERALIZES_THRESHOLD"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-ED885C4DA2F65E","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2000-SHOUP","target":"TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-EE8C0987FD762C","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2017-LINDELL","target":"TSIG-PAPER-2017-LINDELL","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-EFE51CF8E5ADCF","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-FLOOD","target":"TSIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-F0955A77887562","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-CONSTRUCTION-2024-FLOOD","target":"TSIG-PAPER-2024-FLOOD","type":"DESCRIBED_IN"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-F198DDB374474F","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-1999-GJKR-DKG","target":"TSIG-RESULT-1999-GJKR-DKG-ROBUST-DISCRETE-LOG-DKG","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-F1DAF9C4CE24F2","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-AOMMLWE","target":"TSIG-OP-001","type":"TARGETS"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-F40CB171E1C478","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2003-BOLDYREVA","target":"TSIG-RESULT-2003-BOLDYREVA-UNIQUE-COMPACT-OUTPUT","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-F57D832EC245EB","note":"","resultId":null,"reviewStatus":"scheme_declared","source":"TSIG-CONSTRUCTION-2017-LINDELL","target":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RELATED-ASSUMPTIONS-UNDER-THE-PROOF","type":"RELIES_ON"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-FB3E56BEF8F385","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2017-LINDELL","target":"TSIG-RESULT-2017-LINDELL-EFFICIENT-TWO-PARTY-ECDSA","type":"HAS_RESULT"},{"evidenceLocator":"","evidenceUrl":"","id":"TSIG-REL-FBA9CC7EC1734A","note":"","resultId":null,"reviewStatus":"source_declared","source":"TSIG-PAPER-2024-TANG","target":"TSIG-OP-001","type":"TARGETS"}],"nodes":[{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-ADAPTIVE-AOM-MLWE-AND-PRF-SECURITY-SELECTIVE-AOM-UMLWE-HAS-A-UMLWE-MSIS-REDUCTION","keywords":["lattice_one_more"],"metadata":{"family":"lattice_one_more","name":"adaptive AOM-MLWE and PRF security; selective AOM-UMLWE has a UMLWE/MSIS reduction"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice_one_more","summary":"Assumption used by one or more Threshold Signature construction records: adaptive AOM-MLWE and PRF security; selective AOM-UMLWE has a UMLWE/MSIS reduction.","title":"adaptive AOM-MLWE and PRF security; selective AOM-UMLWE has a UMLWE/MSIS reduction","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-ADAPTIVE-AOM-MLWE-AND-PRF-SECURITY-SELECTIVE-AOM-UMLWE-HAS-A-UMLWE-MSIS-REDUCTION"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-ALGEBRAIC-ONE-MORE-DISCRETE-LOGARITHM-AND-RANDOM-ORACLE","keywords":["discrete_log"],"metadata":{"family":"discrete_log","name":"algebraic one-more discrete logarithm and random oracle"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log","summary":"Assumption used by one or more Threshold Signature construction records: algebraic one-more discrete logarithm and random oracle.","title":"algebraic one-more discrete logarithm and random oracle","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-ALGEBRAIC-ONE-MORE-DISCRETE-LOGARITHM-AND-RANDOM-ORACLE"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN","keywords":["ddh"],"metadata":{"family":"ddh","name":"decisional Diffie-Hellman"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"ddh","summary":"Assumption used by one or more Threshold Signature construction records: decisional Diffie-Hellman.","title":"decisional Diffie-Hellman","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-DECISIONAL-DIFFIE-HELLMAN"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-DISCRETE-LOG-AND-STANDARD-SYMMETRIC-COMMITMENT-ASSUMPTIONS","keywords":["discrete_log"],"metadata":{"family":"discrete_log","name":"discrete-log and standard symmetric/commitment assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log","summary":"Assumption used by one or more Threshold Signature construction records: discrete-log and standard symmetric/commitment assumptions.","title":"discrete-log and standard symmetric/commitment assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-DISCRETE-LOG-AND-STANDARD-SYMMETRIC-COMMITMENT-ASSUMPTIONS"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-DISCRETE-LOGARITHM","keywords":["discrete_log"],"metadata":{"family":"discrete_log","name":"discrete logarithm"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log","summary":"Assumption used by one or more Threshold Signature construction records: discrete logarithm.","title":"discrete logarithm","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-DISCRETE-LOGARITHM"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-ECDSA-CENTERED-ASSUMPTIONS-PLUS-OT-HASH-PROOF-SYSTEM-INGREDIENTS","keywords":["discrete_log"],"metadata":{"family":"discrete_log","name":"ECDSA-centered assumptions plus OT/hash-proof-system ingredients"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log","summary":"Assumption used by one or more Threshold Signature construction records: ECDSA-centered assumptions plus OT/hash-proof-system ingredients.","title":"ECDSA-centered assumptions plus OT/hash-proof-system ingredients","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-ECDSA-CENTERED-ASSUMPTIONS-PLUS-OT-HASH-PROOF-SYSTEM-INGREDIENTS"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RANGE-PROOF-RELATED-ASSUMPTIONS","keywords":["discrete_log_and_factoring"],"metadata":{"family":"discrete_log_and_factoring","name":"ECDSA/discrete-log and Paillier-range-proof related assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log_and_factoring","summary":"Assumption used by one or more Threshold Signature construction records: ECDSA/discrete-log and Paillier-range-proof related assumptions.","title":"ECDSA/discrete-log and Paillier-range-proof related assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RANGE-PROOF-RELATED-ASSUMPTIONS"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RELATED-ASSUMPTIONS","keywords":["discrete_log_and_factoring"],"metadata":{"family":"discrete_log_and_factoring","name":"ECDSA/discrete-log and Paillier-related assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log_and_factoring","summary":"Assumption used by one or more Threshold Signature construction records: ECDSA/discrete-log and Paillier-related assumptions.","title":"ECDSA/discrete-log and Paillier-related assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RELATED-ASSUMPTIONS"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RELATED-ASSUMPTIONS-UNDER-THE-PROOF","keywords":["discrete_log_and_factoring"],"metadata":{"family":"discrete_log_and_factoring","name":"ECDSA/discrete-log and Paillier-related assumptions under the proof"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log_and_factoring","summary":"Assumption used by one or more Threshold Signature construction records: ECDSA/discrete-log and Paillier-related assumptions under the proof.","title":"ECDSA/discrete-log and Paillier-related assumptions under the proof","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-AND-PAILLIER-RELATED-ASSUMPTIONS-UNDER-THE-PROOF"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-PLUS-HASH-PROOF-SYSTEM-AND-OT-ASSUMPTIONS","keywords":["discrete_log"],"metadata":{"family":"discrete_log","name":"ECDSA/discrete-log plus hash-proof-system and OT assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log","summary":"Assumption used by one or more Threshold Signature construction records: ECDSA/discrete-log plus hash-proof-system and OT assumptions.","title":"ECDSA/discrete-log plus hash-proof-system and OT assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-ECDSA-DISCRETE-LOG-PLUS-HASH-PROOF-SYSTEM-AND-OT-ASSUMPTIONS"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-GAP-DIFFIE-HELLMAN-CO-CDH-LINEAGE-IN-PAIRING-GROUPS","keywords":["pairing"],"metadata":{"family":"pairing","name":"gap Diffie-Hellman / co-CDH lineage in pairing groups"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"pairing","summary":"Assumption used by one or more Threshold Signature construction records: gap Diffie-Hellman / co-CDH lineage in pairing groups.","title":"gap Diffie-Hellman / co-CDH lineage in pairing groups","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-GAP-DIFFIE-HELLMAN-CO-CDH-LINEAGE-IN-PAIRING-GROUPS"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-HARDNESS-OF-FORGING-THE-UNDERLYING-DSS-SIGNATURE-UNDER-THE-PAPER-MODEL","keywords":["discrete_log"],"metadata":{"family":"discrete_log","name":"hardness of forging the underlying DSS signature under the paper model"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"discrete_log","summary":"Assumption used by one or more Threshold Signature construction records: hardness of forging the underlying DSS signature under the paper model.","title":"hardness of forging the underlying DSS signature under the paper model","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-HARDNESS-OF-FORGING-THE-UNDERLYING-DSS-SIGNATURE-UNDER-THE-PAPER-MODEL"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-HINT-MLWE-AND-SELFTARGETMSIS-WITH-REDUCTIONS-TO-MLWE-MSIS","keywords":["lattice"],"metadata":{"family":"lattice","name":"Hint-MLWE and SelfTargetMSIS with reductions to MLWE/MSIS"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Threshold Signature construction records: Hint-MLWE and SelfTargetMSIS with reductions to MLWE/MSIS.","title":"Hint-MLWE and SelfTargetMSIS with reductions to MLWE/MSIS","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-HINT-MLWE-AND-SELFTARGETMSIS-WITH-REDUCTIONS-TO-MLWE-MSIS"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-MLWE-AND-MSIS-PLUS-THE-FPREP-HYBRID-PREPROCESSING-MODEL","keywords":["lattice"],"metadata":{"family":"lattice","name":"MLWE and MSIS plus the FPREP-hybrid preprocessing model"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Threshold Signature construction records: MLWE and MSIS plus the FPREP-hybrid preprocessing model.","title":"MLWE and MSIS plus the FPREP-hybrid preprocessing model","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-MLWE-AND-MSIS-PLUS-THE-FPREP-HYBRID-PREPROCESSING-MODEL"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-MODULE-LWE","keywords":["lattice"],"metadata":{"family":"lattice","name":"Module-LWE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Threshold Signature construction records: Module-LWE.","title":"Module-LWE","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-MODULE-LWE"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS","keywords":["lattice"],"metadata":{"family":"lattice","name":"Module-LWE and Module-SIS"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Threshold Signature construction records: Module-LWE and Module-SIS.","title":"Module-LWE and Module-SIS","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-MODULE-LWE-AND-MODULE-SIS"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-MODULE-SIS-AND-MODULE-LWE","keywords":["lattice"],"metadata":{"family":"lattice","name":"Module-SIS and Module-LWE"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Threshold Signature construction records: Module-SIS and Module-LWE.","title":"Module-SIS and Module-LWE","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-MODULE-SIS-AND-MODULE-LWE"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-RSA-ASSUMPTION-PLUS-PAPER-SPECIFIC-NUMBER-THEORETIC-SETUP","keywords":["factoring"],"metadata":{"family":"factoring","name":"RSA assumption plus paper-specific number-theoretic setup"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"factoring","summary":"Assumption used by one or more Threshold Signature construction records: RSA assumption plus paper-specific number-theoretic setup.","title":"RSA assumption plus paper-specific number-theoretic setup","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-RSA-ASSUMPTION-PLUS-PAPER-SPECIFIC-NUMBER-THEORETIC-SETUP"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-RSA-FUNCTION-SECURITY-WITH-PAPER-SPECIFIC-SHARING-ASSUMPTIONS","keywords":["factoring"],"metadata":{"family":"factoring","name":"RSA-function security with paper-specific sharing assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"factoring","summary":"Assumption used by one or more Threshold Signature construction records: RSA-function security with paper-specific sharing assumptions.","title":"RSA-function security with paper-specific sharing assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-RSA-FUNCTION-SECURITY-WITH-PAPER-SPECIFIC-SHARING-ASSUMPTIONS"},{"evidence":"scheme_declared","id":"TSIG-ASSUMPTION-STANDARD-RING-LWE-AND-SIS-FAMILY-LATTICE-ASSUMPTIONS","keywords":["lattice"],"metadata":{"family":"lattice","name":"standard Ring-LWE and SIS-family lattice assumptions"},"primaryUrl":null,"sections":[],"status":"catalogued","subtitle":"lattice","summary":"Assumption used by one or more Threshold Signature construction records: standard Ring-LWE and SIS-family lattice assumptions.","title":"standard Ring-LWE and SIS-family lattice assumptions","type":"assumption","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ASSUMPTION-STANDARD-RING-LWE-AND-SIS-FAMILY-LATTICE-ASSUMPTIONS"},{"evidence":"primary_source_checked","id":"TSIG-BARRIER-001","keywords":[],"metadata":{"claim":"Naively applying ordinary field-based Shamir sharing to a short lattice signing secret does not ensure that the local shares remain short enough for the target signing distribution and norm constraints.","does_not_exclude":["Threshold homomorphic-encryption routes","Verifiable short secret sharing and random submersions","MPC protocols that never expose short local signing shares"],"dossier_type":"barrier","escape_hatches":["threshold linear homomorphic encryption","verifiable short secret sharing","jointly sampled masked responses","specialized lattice MPC"],"evidence":"primary_source_checked","excludes":["Treating a field-shared lattice secret as if every local share automatically had the base scheme's short distribution","Generalizing an n-out-of-n additive-share proof to arbitrary t-out-of-n without a new short-share mechanism"],"id":"TSIG-BARRIER-001","scope":{"resource":"short secret shares needed by lattice signature equations","setting":"general t-out-of-n lattice threshold signing"},"status":"scoped_literature_barrier","targets":["TSIG-OP-001"],"title":"Ordinary Shamir shares do not preserve a lattice signing key's shortness"},"primaryUrl":null,"sections":[{"content":"GKS ePrint 2023/1318, Introduction Sections 1.1-1.3, states the short-share obstacle and motivates its threshold-HE solution. This is not an impossibility theorem for all secret-sharing methods.","heading":"Evidence note"}],"status":"scoped_literature_barrier","subtitle":"","summary":"GKS ePrint 2023/1318, Introduction Sections 1.1-1.3, states the short-share obstacle and motivates its threshold-HE solution. This is not an impossibility theorem for all secret-sharing methods.","title":"Ordinary Shamir shares do not preserve a lattice signing key's shortness","type":"barrier","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-BARRIER-001"},{"evidence":"primary_source_checked","id":"TSIG-BARRIER-002","keywords":[],"metadata":{"claim":"A distributed signer cannot reveal signer-correlated abort or rejection behavior naively; the transcript distribution must be proven independent of the hidden shares up to the declared leakage.","does_not_exclude":["Homomorphic or trapdoor commitments that hide the first message until responses are fixed","One-time additive masks or noise-flooding techniques with a complete proof","Threshold-HE routes that sample the response under encryption"],"dossier_type":"barrier","escape_hatches":["commit-before-challenge","trapdoor commitments","one-time additive masks","noise flooding","encrypted response sampling"],"evidence":"primary_source_checked","excludes":["Assuming the single-signer rejection-sampling proof composes automatically across separately aborting parties","Reusing abandoned partial transcripts without a proof that conditions on the abort event"],"id":"TSIG-BARRIER-002","scope":{"adversary_view":"commitments partial responses and abort decisions across sessions","setting":"distributed Fiat-Shamir-with-aborts lattice signing"},"status":"scoped_literature_barrier","targets":["TSIG-OP-001"],"title":"Rejection and abort transcripts can leak partial lattice signing keys"},"primaryUrl":null,"sections":[{"content":"DOTT ePrint 2020/1110 identifies leakage from aborting after the first message and supplies a commitment-based defense; later branches change the defense mechanism rather than eliminating the distributional obligation.","heading":"Evidence note"}],"status":"scoped_literature_barrier","subtitle":"","summary":"DOTT ePrint 2020/1110 identifies leakage from aborting after the first message and supplies a commitment-based defense; later branches change the defense mechanism rather than eliminating the distributional obligation.","title":"Rejection and abort transcripts can leak partial lattice signing keys","type":"barrier","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-BARRIER-002"},{"evidence":"primary_source_reviewed","id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","keywords":["threshold_signature","threshold_dss","ordinary-verifier-output","malicious-security","robustness"],"metadata":{"adaptive_security":"not claimed on this card","assumption":{"family":"discrete_log","name":"hardness of forging the underlying DSS signature under the paper model"},"base_signature":"DSS","capabilities":["ordinary-verifier-output","malicious-security","robustness"],"communication":"historical interactive protocol; exact accounting queued","construction_family":"threshold_dss","corruption_model":"malicious faults with separate robustness bounds","dossier_type":"construction","evidence":"primary_source_checked","id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","identifiable_abort":"scoped share verification; modern terminology not used","name":"GJKR robust threshold DSS","output_compatibility":"ordinary DSS signature","post_quantum_mechanism":"none","preprocessing":"protocol-dependent","primitive":"threshold_signature","resilience":"unforgeability against up to t corrupted players in the stated range","robustness":"paper gives distinct bounds for nonparticipation and incorrect partial signatures","security":{"mode":"threshold public-key","model":"paper-specific","notion":"threshold unforgeability and scoped robustness"},"setup_model":"distributed sharing of the DSS secret","signing_rounds":"interactive multiparty protocol","sizes":{"public_key":"ordinary DSS public key","signature":"ordinary DSS signature"},"status":"historical","threshold_policy":"2t+1 participating signers for t<n/2 in the base threshold statement","title":"GJKR robust threshold DSS","verification":{"status":"primary_source_reviewed"},"work_id":"TSIG-PAPER-1996-GJKR-DSS","year":1996},"primaryUrl":"https://doi.org/10.1007/3-540-68339-9_31","sections":[{"content":"The threshold t, signing-quorum size, crash tolerance, and malicious-share tolerance are not collapsed into one number.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"threshold_signature · 1996","summary":"The threshold t, signing-quorum size, crash tolerance, and malicious-share tolerance are not collapsed into one number.","title":"GJKR robust threshold DSS","type":"construction","venue":"EUROCRYPT 1996","year":1996,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-1996-GJKR-DSS"},{"evidence":"bibliographic_reviewed","id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","keywords":["threshold_signature","threshold_rsa","rsa-function-sharing","robustness"],"metadata":{"adaptive_security":"not claimed on this card","assumption":{"family":"factoring","name":"RSA-function security with paper-specific sharing assumptions"},"base_signature":"RSA function with a signature encoding supplied by the profile","capabilities":["rsa-function-sharing","robustness"],"communication":"exact accounting queued","construction_family":"threshold_rsa","corruption_model":"malicious threshold adversary","dossier_type":"construction","evidence":"bibliographic_checked","id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","identifiable_abort":"share verification rather than modern identifiable-abort interface","name":"GJKR robust threshold RSA line","output_compatibility":"RSA function output; signature encoding must be fixed separately","post_quantum_mechanism":"none","preprocessing":"key sharing and verification setup","primitive":"threshold_signature","resilience":"paper-specific threshold","robustness":"yes under the scoped model","security":{"mode":"threshold public-key","model":"paper-specific","notion":"robust shared RSA evaluation"},"setup_model":"shared RSA trapdoor","signing_rounds":"nontrivial distributed protocol","sizes":{"public_key":"RSA modulus and exponent","signature":"one RSA function output before profile encoding"},"status":"historical","threshold_policy":"general threshold with robustness under the paper's bounds","title":"GJKR robust RSA function sharing","verification":{"status":"bibliographic_reviewed"},"work_id":"TSIG-PAPER-1996-GJKR-RSA","year":1996},"primaryUrl":"https://doi.org/10.1007/3-540-68697-5","sections":[],"status":"bibliographic_reviewed","subtitle":"threshold_signature · 1996","summary":"The proceedings PDF is required to promote exact round, threshold, and assumption fields.","title":"GJKR robust threshold RSA line","type":"construction","venue":"CRYPTO 1996","year":1996,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-1996-GJKR-RSA"},{"evidence":"primary_source_reviewed","id":"TSIG-CONSTRUCTION-2000-SHOUP","keywords":["threshold_signature","threshold_rsa","noninteractive-signature-shares","robustness","ordinary-verifier-output"],"metadata":{"adaptive_security":"not claimed on this card","assumption":{"family":"factoring","name":"RSA assumption plus paper-specific number-theoretic setup"},"base_signature":"RSA","capabilities":["noninteractive-signature-shares","robustness","ordinary-verifier-output"],"communication":"one signature share per participating server plus combining metadata","construction_family":"threshold_rsa","corruption_model":"static malicious adversary in the paper model","dossier_type":"construction","evidence":"primary_source_checked","id":"TSIG-CONSTRUCTION-2000-SHOUP","identifiable_abort":"invalid shares are detectable","name":"Shoup practical threshold RSA","output_compatibility":"ordinary RSA signature value for the specified encoding","post_quantum_mechanism":"none","preprocessing":"distributed key setup outside the signing algorithm","primitive":"threshold_signature","resilience":"threshold unforgeability under stated bounds","robustness":"combiner verifies signature shares and can proceed with enough valid shares","security":{"mode":"threshold public-key","model":"random-oracle/profile-dependent encoding","notion":"robust threshold unforgeability"},"setup_model":"RSA modulus and verified secret-key shares","signing_rounds":"noninteractive share generation followed by combining","sizes":{"public_key":"ordinary RSA public key","signature":"ordinary RSA modulus element"},"status":"historical_active_lineage","threshold_policy":"k-out-of-l threshold in the paper notation","title":"Shoup practical threshold RSA","verification":{"status":"primary_source_reviewed"},"work_id":"TSIG-PAPER-2000-SHOUP","year":2000},"primaryUrl":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","sections":[{"content":"“Noninteractive” describes per-server signature-share production, not dealer-free key generation.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"threshold_signature · 2000","summary":"“Noninteractive” describes per-server signature-share production, not dealer-free key generation.","title":"Shoup practical threshold RSA","type":"construction","venue":"EUROCRYPT 2000","year":2000,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2000-SHOUP"},{"evidence":"primary_source_reviewed","id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","keywords":["threshold_signature","threshold_pairing","compact-output","noninteractive-signature-shares","public-share-verification"],"metadata":{"adaptive_security":"not the card's claim","assumption":{"family":"pairing","name":"gap Diffie-Hellman / co-CDH lineage in pairing groups"},"base_signature":"BLS","capabilities":["compact-output","noninteractive-signature-shares","public-share-verification"],"communication":"one group-element share per participant","construction_family":"threshold_pairing","corruption_model":"static threshold adversary in the paper model","dossier_type":"construction","evidence":"primary_source_checked","id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","identifiable_abort":"malformed shares are attributable to their senders","name":"Boldyreva threshold BLS/GDH signature","output_compatibility":"ordinary one-group-element BLS signature","post_quantum_mechanism":"none","preprocessing":"distributed key setup","primitive":"threshold_signature","resilience":"threshold unforgeability under the stated bound","robustness":"valid shares can be publicly checked in the pairing setting","security":{"mode":"threshold public-key","model":"random oracle","notion":"threshold EUF-CMA lineage"},"setup_model":"shared scalar key in a gap-Diffie-Hellman group","signing_rounds":"noninteractive shares and public combining","sizes":{"public_key":"ordinary BLS public key plus share-verification data","signature":"one BLS signature group element"},"status":"research_and_deployment_lineage","threshold_policy":"t-out-of-n threshold sharing under the paper notation","title":"Boldyreva threshold BLS","verification":{"status":"primary_source_reviewed"},"work_id":"TSIG-PAPER-2003-BOLDYREVA","year":2003},"primaryUrl":"https://eprint.iacr.org/2002/118","sections":[{"content":"The assumption is a pairing/GDH-family point, not the plain DDH assumption used by Glacius.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"threshold_signature · 2003","summary":"The assumption is a pairing/GDH-family point, not the plain DDH assumption used by Glacius.","title":"Boldyreva threshold BLS/GDH signature","type":"construction","venue":"PKC 2003","year":2003,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2003-BOLDYREVA"},{"evidence":"primary_source_reviewed","id":"TSIG-CONSTRUCTION-2017-LINDELL","keywords":["threshold_signature","threshold_ecdsa_paillier","ordinary-verifier-output","two-party-signing","malicious-security"],"metadata":{"adaptive_security":"not claimed on this card","assumption":{"family":"discrete_log_and_factoring","name":"ECDSA/discrete-log and Paillier-related assumptions under the proof"},"base_signature":"ECDSA","capabilities":["ordinary-verifier-output","two-party-signing","malicious-security"],"communication":"constant number of two-party messages; exact bytes parameter-dependent","construction_family":"threshold_ecdsa_paillier","corruption_model":"one malicious party","dossier_type":"construction","evidence":"primary_source_checked","id":"TSIG-CONSTRUCTION-2017-LINDELL","identifiable_abort":"paper-specific proofs/checks","name":"Lindell fast two-party ECDSA","output_compatibility":"ordinary ECDSA signature","post_quantum_mechanism":"none","preprocessing":"offline work supported by protocol organization","primitive":"threshold_signature","resilience":"no single party can forge alone","robustness":"abort on malicious behavior; guaranteed output not claimed","security":{"mode":"threshold public-key","model":"paper-specific","notion":"maliciously secure two-party signing"},"setup_model":"jointly held ECDSA key with Paillier-related setup","signing_rounds":"interactive online signing","sizes":{"public_key":"ordinary ECDSA public key","signature":"ordinary ECDSA signature"},"status":"practical_lineage","threshold_policy":"2-out-of-2","title":"Lindell fast two-party ECDSA","verification":{"status":"primary_source_reviewed"},"work_id":"TSIG-PAPER-2017-LINDELL","year":2017},"primaryUrl":"https://eprint.iacr.org/2017/552","sections":[{"content":"ECDSA's inversion and multiplication structure makes its threshold protocol qualitatively different from linear Schnorr aggregation.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"threshold_signature · 2017","summary":"ECDSA's inversion and multiplication structure makes its threshold protocol qualitatively different from linear Schnorr aggregation.","title":"Lindell fast two-party ECDSA","type":"construction","venue":"CRYPTO 2017","year":2017,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2017-LINDELL"},{"evidence":"primary_source_reviewed","id":"TSIG-CONSTRUCTION-2018-DKLS2","keywords":["threshold_signature","threshold_ecdsa_ot","ordinary-verifier-output","two-party-signing","paillier-free-route"],"metadata":{"adaptive_security":"not claimed on this card","assumption":{"family":"discrete_log","name":"ECDSA/discrete-log plus hash-proof-system and OT assumptions"},"base_signature":"ECDSA","capabilities":["ordinary-verifier-output","two-party-signing","paillier-free-route"],"communication":"OT/hash-proof-system dependent","construction_family":"threshold_ecdsa_ot","corruption_model":"malicious two-party adversary","dossier_type":"construction","evidence":"primary_source_checked","id":"TSIG-CONSTRUCTION-2018-DKLS2","identifiable_abort":"two-party blame is implicit when a session fails","name":"DKLS hash-proof-system two-party ECDSA","output_compatibility":"ordinary ECDSA signature","post_quantum_mechanism":"none","preprocessing":"correlated oblivious-transfer-style work","primitive":"threshold_signature","resilience":"no single party can forge alone","robustness":"abort on detected cheating","security":{"mode":"threshold public-key","model":"paper-specific","notion":"maliciously secure two-party signing"},"setup_model":"jointly held ECDSA key without Paillier encryption","signing_rounds":"interactive","sizes":{"public_key":"ordinary ECDSA public key","signature":"ordinary ECDSA signature"},"status":"practical_lineage","threshold_policy":"2-out-of-2","title":"DKLS two-party ECDSA","verification":{"status":"primary_source_reviewed"},"work_id":"TSIG-PAPER-2018-DKLS-2P","year":2018},"primaryUrl":"https://eprint.iacr.org/2018/499","sections":[{"content":"This is the two-party root of the DKLS route; its cryptographic setup is not interchangeable with Paillier-based ECDSA protocols.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"threshold_signature · 2018","summary":"This is the two-party root of the DKLS route; its cryptographic setup is not interchangeable with Paillier-based ECDSA protocols.","title":"DKLS hash-proof-system two-party ECDSA","type":"construction","venue":"CRYPTO 2018","year":2018,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2018-DKLS2"},{"evidence":"primary_source_reviewed","id":"TSIG-CONSTRUCTION-2018-GG","keywords":["threshold_signature","threshold_ecdsa_paillier","ordinary-verifier-output","multiparty","trustless-setup"],"metadata":{"adaptive_security":"not claimed on this card","assumption":{"family":"discrete_log_and_factoring","name":"ECDSA/discrete-log and Paillier-related assumptions"},"base_signature":"ECDSA","capabilities":["ordinary-verifier-output","multiparty","trustless-setup"],"communication":"multiparty interactive protocol; exact accounting parameter-dependent","construction_family":"threshold_ecdsa_paillier","corruption_model":"malicious threshold adversary in the paper model","dossier_type":"construction","evidence":"primary_source_checked","id":"TSIG-CONSTRUCTION-2018-GG","identifiable_abort":"scoped blame mechanisms; use exact paper definition","name":"Gennaro-Goldfeder threshold ECDSA","output_compatibility":"ordinary ECDSA signature","post_quantum_mechanism":"none","preprocessing":"key-generation and presigning components","primitive":"threshold_signature","resilience":"threshold unforgeability","robustness":"abort-oriented protocol with verifiable steps","security":{"mode":"threshold public-key","model":"paper-specific","notion":"malicious threshold signing"},"setup_model":"trustless distributed setup with Paillier-related proofs","signing_rounds":"interactive signing protocol","sizes":{"public_key":"ordinary ECDSA public key","signature":"ordinary ECDSA signature"},"status":"practical_lineage","threshold_policy":"t-out-of-n multiparty threshold","title":"GG18 multiparty threshold ECDSA","verification":{"status":"primary_source_reviewed"},"work_id":"TSIG-PAPER-2018-GG","year":2018},"primaryUrl":"https://eprint.iacr.org/2019/114","sections":[{"content":"The setup and signing protocols should be compared separately; “fast setup” does not make the online signer noninteractive.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"threshold_signature · 2018","summary":"The setup and signing protocols should be compared separately; “fast setup” does not make the online signer noninteractive.","title":"Gennaro-Goldfeder threshold ECDSA","type":"construction","venue":"ACM CCS 2018","year":2018,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2018-GG"},{"evidence":"bibliographic_reviewed","id":"TSIG-CONSTRUCTION-2019-DKLSN","keywords":["threshold_signature","threshold_ecdsa_ot","ordinary-verifier-output","general-threshold","paillier-free-route"],"metadata":{"adaptive_security":"not claimed on this card","assumption":{"family":"discrete_log","name":"ECDSA-centered assumptions plus OT/hash-proof-system ingredients"},"base_signature":"ECDSA","capabilities":["ordinary-verifier-output","general-threshold","paillier-free-route"],"communication":"OT and multiparty arithmetic dependent","construction_family":"threshold_ecdsa_ot","corruption_model":"malicious threshold adversary under paper bounds","dossier_type":"construction","evidence":"bibliographic_checked","id":"TSIG-CONSTRUCTION-2019-DKLSN","identifiable_abort":"exact property queued for full-text audit","name":"DKLS threshold ECDSA from ECDSA assumptions","output_compatibility":"ordinary ECDSA signature","post_quantum_mechanism":"none","preprocessing":"OT-based correlated preprocessing","primitive":"threshold_signature","resilience":"threshold unforgeability","robustness":"abort-oriented","security":{"mode":"threshold public-key","model":"paper-specific","notion":"threshold unforgeability"},"setup_model":"distributed ECDSA key","signing_rounds":"interactive protocol","sizes":{"public_key":"ordinary ECDSA public key","signature":"ordinary ECDSA signature"},"status":"practical_lineage","threshold_policy":"general t-out-of-n","title":"DKLS general-threshold ECDSA","verification":{"status":"bibliographic_reviewed"},"work_id":"TSIG-PAPER-2019-DKLS-N","year":2019},"primaryUrl":"https://doi.org/10.1109/SP.2019.00024","sections":[],"status":"bibliographic_reviewed","subtitle":"threshold_signature · 2019","summary":"Promote round, corruption, and blame fields only after local audit of the final IEEE version.","title":"DKLS threshold ECDSA from ECDSA assumptions","type":"construction","venue":"IEEE Symposium on Security and Privacy 2019","year":2019,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2019-DKLSN"},{"evidence":"primary_source_reviewed","id":"TSIG-CONSTRUCTION-2020-CGGMP","keywords":["threshold_signature","threshold_ecdsa_paillier","ordinary-verifier-output","identifiable-abort","proactive-refresh","noninteractive-online"],"metadata":{"adaptive_security":"UC/proactive profile; exact adaptive clauses follow paper","assumption":{"family":"discrete_log_and_factoring","name":"ECDSA/discrete-log and Paillier-range-proof related assumptions"},"base_signature":"ECDSA","capabilities":["ordinary-verifier-output","identifiable-abort","proactive-refresh","noninteractive-online"],"communication":"shifted toward preprocessing; online contribution is noninteractive","construction_family":"threshold_ecdsa_paillier","corruption_model":"UC malicious adversary in the paper model","dossier_type":"construction","evidence":"primary_source_checked","id":"TSIG-CONSTRUCTION-2020-CGGMP","identifiable_abort":true,"name":"UC noninteractive-online threshold ECDSA with identifiable aborts","output_compatibility":"ordinary ECDSA signature","post_quantum_mechanism":"none","preprocessing":"substantial presigning phase","primitive":"threshold_signature","resilience":"threshold unforgeability with proactive refresh support","robustness":"identifiable abort rather than guaranteed output","security":{"mode":"threshold public-key","model":"UC","notion":"UC threshold signing with identifiable abort"},"setup_model":"distributed key generation and auxiliary cryptographic setup","signing_rounds":"noninteractive online contribution after preprocessing","sizes":{"public_key":"ordinary ECDSA public key","signature":"ordinary ECDSA signature"},"status":"practical_lineage","threshold_policy":"t-out-of-n under the paper bounds","title":"CGGMP20 threshold ECDSA","verification":{"status":"primary_source_reviewed"},"work_id":"TSIG-PAPER-2020-CGGMP","year":2020},"primaryUrl":"https://eprint.iacr.org/2021/060","sections":[{"content":"The online-round claim presupposes valid presignatures; total latency must include replenishing them.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"threshold_signature · 2020","summary":"The online-round claim presupposes valid presignatures; total latency must include replenishing them.","title":"UC noninteractive-online threshold ECDSA with identifiable aborts","type":"construction","venue":"ACM CCS 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2020-CGGMP"},{"evidence":"fulltext_reviewed","id":"TSIG-CONSTRUCTION-2020-FROST","keywords":["threshold_signature","threshold_schnorr","ordinary-verifier-output","two-round","optional-preprocessing","true-threshold"],"metadata":{"adaptive_security":"no; static proof profile","assumption":{"family":"discrete_log","name":"discrete logarithm"},"base_signature":"Schnorr","capabilities":["ordinary-verifier-output","two-round","optional-preprocessing","true-threshold"],"communication":"two messages per signer in the two-round mode","construction_family":"threshold_schnorr","corruption_model":"static adversary controlling fewer than the threshold","dossier_type":"construction","evidence":"fulltext_checked","id":"TSIG-CONSTRUCTION-2020-FROST","identifiable_abort":"operational participant identification in the paper protocol","name":"FROST threshold Schnorr","output_compatibility":"ordinary Schnorr-family signature under the chosen ciphersuite","post_quantum_mechanism":"none","preprocessing":"optional nonce-commitment preprocessing","primitive":"threshold_signature","resilience":"true threshold participation","robustness":"abort and identify/exclude a misbehaving participant","security":{"mode":"threshold public-key","model":"random-oracle lineage","notion":"chosen-message threshold unforgeability"},"setup_model":"threshold key shares; DKG can be composed separately","signing_rounds":"two rounds; one online round with preprocessing","sizes":{"public_key":"ordinary Schnorr public key","signature":"ordinary Schnorr signature"},"status":"standards_lineage","threshold_policy":"t-out-of-n","title":"FROST threshold Schnorr","verification":{"locator":"Section 2.4 and Figure 3, PDF p. 15","status":"fulltext_reviewed"},"work_id":"TSIG-PAPER-2020-FROST","year":2020},"primaryUrl":"https://eprint.iacr.org/2020/852","sections":[{"content":"Nonce commitments are consumable protocol material; Figure 3 requires deletion after use, and Section 5.2 warns that reuse can expose the long-term secret share. FROST attributes an invalid response and aborts; it does not guarantee completion against withholding participants.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"threshold_signature · 2020","summary":"Nonce commitments are consumable protocol material; Figure 3 requires deletion after use, and Section 5.2 warns that reuse can expose the long-term secret share. FROST attributes an invalid response and aborts; it does not guarantee completion against withholding participants.","title":"FROST threshold Schnorr","type":"construction","venue":"SAC 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2020-FROST"},{"evidence":"fulltext_reviewed","id":"TSIG-CONSTRUCTION-2021-DOTT","keywords":["threshold_signature","lattice_fswa_distributed","post-quantum","two-round","abort-leakage-defense"],"metadata":{"adaptive_security":"no claim on this card","assumption":{"family":"lattice","name":"Module-SIS and Module-LWE"},"base_signature":"Dilithium-G-style Fiat-Shamir with aborts","capabilities":["post-quantum","two-round","abort-leakage-defense"],"communication":"two-round commitments and masked lattice responses","construction_family":"lattice_fswa_distributed","corruption_model":"malicious adversary under the paper model","dossier_type":"construction","evidence":"fulltext_checked","id":"TSIG-CONSTRUCTION-2021-DOTT","identifiable_abort":"commitment-based transcript protection, not general robust completion","name":"DOTT n-out-of-n lattice signature","output_compatibility":"distributed Dilithium-G variant; verifier/parameters differ from standardized Dilithium","post_quantum_mechanism":"Module-SIS and Module-LWE","preprocessing":"no online-round removal claimed on this card","primitive":"threshold_signature","resilience":"all n signers required","robustness":"abort leakage is hidden; availability still fails when one signer withholds","security":{"mode":"n-out-of-n","model":"random-oracle lineage","notion":"distributed-signature unforgeability"},"setup_model":"distributed public key and lattice trapdoor commitment machinery","signing_rounds":"two","sizes":{"public_key":"distributed-scheme public key","signature":"grows with the paper parameters and signer count"},"status":"foundational_post_quantum","threshold_policy":"n-out-of-n","title":"DOTT two-round lattice distributed signature","verification":{"locator":"Section 3.1, Figure 6; Section 3.3, Theorem 1","status":"fulltext_reviewed"},"work_id":"TSIG-PAPER-2021-DOTT","year":2021},"primaryUrl":"https://eprint.iacr.org/2020/1110","sections":[{"content":"This is a full-threshold distributed signature, not a general t-out-of-n scheme. The paper's two-round profile uses parallel repetition to drive the probability of a successful non-aborting execution high; Section 3.2 explains that a single execution has three messages and succeeds only with its rejection probability.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"threshold_signature · 2021","summary":"This is a full-threshold distributed signature, not a general t-out-of-n scheme. The paper's two-round profile uses parallel repetition to drive the probability of a successful non-aborting execution high; Section 3.2 explains that a single execution has three messages and succeeds only with its rejection probability.","title":"DOTT n-out-of-n lattice signature","type":"construction","venue":"PKC 2021; Journal of Cryptology 2022","year":2021,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2021-DOTT"},{"evidence":"fulltext_reviewed","id":"TSIG-CONSTRUCTION-2021-GKMN","keywords":["threshold_signature","threshold_schnorr_mpc_nonce","deterministic-nonce","stateless-signing","dishonest-majority","ordinary-verifier-output"],"metadata":{"adaptive_security":"not the main claim on this card","assumption":{"family":"discrete_log","name":"discrete-log and standard symmetric/commitment assumptions"},"base_signature":"Schnorr","capabilities":["deterministic-nonce","stateless-signing","dishonest-majority","ordinary-verifier-output"],"communication":"garbled-circuit and proof dependent","construction_family":"threshold_schnorr_mpc_nonce","corruption_model":"static adversary corrupting up to n-1 parties","dossier_type":"construction","evidence":"fulltext_checked","id":"TSIG-CONSTRUCTION-2021-GKMN","identifiable_abort":"protocol-specific","name":"GKMN deterministic-nonce threshold Schnorr","output_compatibility":"ordinary Schnorr signature","post_quantum_mechanism":"none","preprocessing":"reusable commitment setup for the zero-knowledge layer","primitive":"threshold_signature","resilience":"threshold unforgeability","robustness":"abort-oriented","security":{"mode":"threshold public-key","model":"standard assumptions with specified idealizations","notion":"threshold unforgeability with deterministic nonces"},"setup_model":"shared Schnorr key plus UC-commitment and garbled-circuit machinery","signing_rounds":"three","sizes":{"public_key":"ordinary Schnorr public key","signature":"ordinary Schnorr signature"},"status":"research","threshold_policy":"n-out-of-n in the instantiated n-party protocol","title":"Stateless deterministic threshold Schnorr","verification":{"locator":"Section 9 protocol and Theorem 9.3, PDF pp. 33–34","status":"fulltext_reviewed"},"work_id":"TSIG-PAPER-2021-GKMN","year":2021},"primaryUrl":"https://eprint.iacr.org/2021/1055","sections":[{"content":"Stateless refers to nonce derivation and long-term signer state, not absence of all setup or protocol transcripts.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"threshold_signature · 2021","summary":"Stateless refers to nonce derivation and long-term signer state, not absence of all setup or protocol transcripts.","title":"GKMN deterministic-nonce threshold Schnorr","type":"construction","venue":"CRYPTO 2021","year":2021,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2021-GKMN"},{"evidence":"fulltext_preprint_reviewed_final_pending","id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","keywords":["threshold_signature","lattice_fswa_distributed","post-quantum","two-party","signature-compression"],"metadata":{"adaptive_security":"not claimed on this card","assumption":{"family":"lattice","name":"Module-LWE and Module-SIS"},"base_signature":"Dilithium-derived","capabilities":["post-quantum","two-party","signature-compression"],"communication":"network bytes not benchmarked; signing communication repeats with the audited preprint's average 101.55 rejections","construction_family":"lattice_fswa_distributed","corruption_model":"one malicious party under the paper model","dossier_type":"construction","evidence":"fulltext_checked","id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","identifiable_abort":"not promoted from the outdated preprint","name":"DiLizium 2.0 two-party Dilithium-line signature","output_compatibility":"closer to Dilithium through signature compression; exact standard interoperability not asserted","post_quantum_mechanism":"Module-LWE and Module-SIS","preprocessing":"not normalized across preprint and final version","primitive":"threshold_signature","resilience":"both parties required","robustness":"abort-oriented","security":{"mode":"two-party","model":"classical random oracle in the preprint","notion":"two-party signature unforgeability"},"setup_model":"two-party shared module-lattice secret and additively homomorphic commitment","signing_rounds":"three in the audited ePrint","sizes":{"public_key":"2976 bytes in the audited preprint","secret_key_share":"8864 bytes in the audited preprint","signature":"21120 bytes in the audited preprint"},"status":"published_final_version_pending_audit","threshold_policy":"2-out-of-2","title":"DiLizium 2.0","verification":{"locator":"Theorem 1 and Section 4, Table 2","status":"fulltext_preprint_reviewed_final_pending"},"work_id":"TSIG-PAPER-2022-DILIZIUM2","year":2022},"primaryUrl":"https://eprint.iacr.org/2022/644","sections":[{"content":"The ePrint page says the preprint is outdated. Section 4 reports Java 17/Bouncy Castle measurements on an AMD Ryzen 5 PRO 3500U: 1.48 ms key generation, 174.65 ms signing, 1.18 ms verification, and 101.55 average rejections over 1000 executions, excluding network delay. All values are retained only as preprint observations, not current journal benchmarks.","heading":"Version warning"}],"status":"fulltext_preprint_reviewed_final_pending","subtitle":"threshold_signature · 2022","summary":"The ePrint page says the preprint is outdated. Section 4 reports Java 17/Bouncy Castle measurements on an AMD Ryzen 5 PRO 3500U: 1.48 ms key generation, 174.65 ms signing, 1.18 ms verification, and 101.55 average rejections over 1000 executions, excluding network delay. All values are retained only as preprint observations, not current journal benchmarks.","title":"DiLizium 2.0 two-party Dilithium-line signature","type":"construction","venue":"Journal of Computer Security final version","year":2022,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2022-DILIZIUM2"},{"evidence":"fulltext_reviewed","id":"TSIG-CONSTRUCTION-2023-GKS","keywords":["threshold_signature","lattice_threshold_he","post-quantum","arbitrary-threshold","two-round","distributed-key-generation"],"metadata":{"adaptive_security":"not claimed on this card","assumption":{"family":"lattice","name":"standard Ring-LWE and SIS-family lattice assumptions"},"base_signature":"lattice Fiat-Shamir-with-aborts line","capabilities":["post-quantum","arbitrary-threshold","two-round","distributed-key-generation"],"communication":"two online rounds with ciphertext/proof overhead","construction_family":"lattice_threshold_he","corruption_model":"active adversary under the paper threshold-HE model","dossier_type":"construction","evidence":"fulltext_checked","id":"TSIG-CONSTRUCTION-2023-GKS","identifiable_abort":"exact property not promoted","name":"GKS threshold-HE lattice signature","output_compatibility":"scheme-specific lattice signature","post_quantum_mechanism":"Ring-LWE and SIS lineage through threshold HE and the signature layer","preprocessing":"DKG and threshold-HE setup","primitive":"threshold_signature","resilience":"arbitrary threshold t<=n","robustness":"abort handling within active security; guaranteed output not claimed here","security":{"mode":"t-out-of-n","model":"random-oracle lineage","notion":"actively secure threshold signing"},"setup_model":"actively secure threshold linearly homomorphic encryption and distributed key generation","signing_rounds":"two","sizes":{"public_key":"13.6 KB for that same estimate","signature":"46.6 KB for the paper's 128-bit 3-out-of-5 estimate"},"status":"research","threshold_policy":"arbitrary t-out-of-n","title":"GKS two-round t-out-of-n lattice signature","verification":{"locator":"Section 5, Figure 7 and Theorem 3, PDF pp. 22–26","status":"fulltext_reviewed"},"work_id":"TSIG-PAPER-2023-GKS","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/1318","sections":[{"content":"The concrete byte figures are bound to the paper's stated 3-out-of-5, 128-bit estimate and are not universal scheme constants. Figure 7 gives the actively secure two-round protocol; Theorem 3 includes the threshold-HE, NIZK, commitment, and random-oracle terms rather than reducing the complete package to Ring-LWE/SIS alone in one step.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"threshold_signature · 2023","summary":"The concrete byte figures are bound to the paper's stated 3-out-of-5, 128-bit estimate and are not universal scheme constants. Figure 7 gives the actively secure two-round protocol; Theorem 3 includes the threshold-HE, NIZK, commitment, and random-oracle terms rather than reducing the complete package to Ring-LWE/SIS alone in one step.","title":"GKS threshold-HE lattice signature","type":"construction","venue":"PQCrypto 2024","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2023-GKS"},{"evidence":"primary_source_reviewed","id":"TSIG-CONSTRUCTION-2023-OLAF","keywords":["threshold_signature","threshold_schnorr","ordinary-verifier-output","proof-without-agm","pedersen-dkg"],"metadata":{"adaptive_security":"no claim on this card","assumption":{"family":"discrete_log","name":"algebraic one-more discrete logarithm and random oracle"},"base_signature":"Schnorr","capabilities":["ordinary-verifier-output","proof-without-agm","pedersen-dkg"],"communication":"FROST3 profile plus DKG cost","construction_family":"threshold_schnorr","corruption_model":"static threshold adversary in the proof","dossier_type":"construction","evidence":"primary_source_checked","id":"TSIG-CONSTRUCTION-2023-OLAF","identifiable_abort":"protocol-specific","name":"Olaf FROST3 with Pedersen DKG","output_compatibility":"ordinary Schnorr-family signature","post_quantum_mechanism":"none","preprocessing":"FROST-family nonce preprocessing options","primitive":"threshold_signature","resilience":"threshold unforgeability","robustness":"abort-oriented FROST family","security":{"mode":"threshold public-key","model":"ROM without AGM","notion":"threshold unforgeability"},"setup_model":"Pedersen-DKG variant composed with FROST3","signing_rounds":"FROST3 signing profile","sizes":{"public_key":"ordinary Schnorr public key plus DKG verification data","signature":"ordinary Schnorr signature"},"status":"research","threshold_policy":"t-out-of-n","title":"Olaf threshold Schnorr","verification":{"status":"primary_source_reviewed"},"work_id":"TSIG-PAPER-2023-OLAF","year":2023},"primaryUrl":"https://eprint.iacr.org/2023/899","sections":[{"content":"Removing AGM from the proof does not mean the scheme relies only on plain discrete log; the AOMDL assumption is recorded explicitly.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"threshold_signature · 2023","summary":"Removing AGM from the proof does not mean the scheme relies only on plain discrete log; the AOMDL assumption is recorded explicitly.","title":"Olaf FROST3 with Pedersen DKG","type":"construction","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2023-OLAF"},{"evidence":"fulltext_reviewed","id":"TSIG-CONSTRUCTION-2024-AOMMLWE","keywords":["threshold_signature","lattice_one_more","post-quantum","two-round","noninteractive-online","large-threshold"],"metadata":{"adaptive_security":"no for signer corruption; the main reduction uses adaptive AOM-MLWE as an assumption","assumption":{"family":"lattice_one_more","name":"adaptive AOM-MLWE and PRF security; selective AOM-UMLWE has a UMLWE/MSIS reduction"},"base_signature":"Lyubashevsky-style lattice signature","capabilities":["post-quantum","two-round","noninteractive-online","large-threshold"],"communication":"at 128-bit security and T=1024, 14.1 KB optimized online or 276 KB naive online per user, plus 262 KB offline","construction_family":"lattice_one_more","corruption_model":"selective/static corruption of fewer than T signers","dossier_type":"construction","evidence":"fulltext_checked","id":"TSIG-CONSTRUCTION-2024-AOMMLWE","identifiable_abort":"no; misbehavior detection is left as future work","name":"Two-round threshold signature from AOM-MLWE","output_compatibility":"scheme-specific lattice signature","post_quantum_mechanism":"adaptive AOM-MLWE; only its selective variant is reduced from UMLWE and MSIS","preprocessing":"first round can be prepared without the message or signer set","primitive":"threshold_signature","resilience":"threshold signing","robustness":"no; robust signing is left as future work","security":{"mode":"T-out-of-N","model":"selective-corruption random-oracle game under adaptive AOM-MLWE","notion":"threshold unforgeability"},"setup_model":"trusted-dealer key generation; DKG is left as future work","signing_rounds":"two; online phase noninteractive after message-independent preprocessing","sizes":{"public_key":"5.5 KB for the same Table 3 profile","signature":"10.8 KB at 128-bit security and T=1024"},"status":"research","threshold_policy":"arbitrary T-out-of-N with concrete support up to T=1024","title":"AOM-MLWE two-round lattice threshold signature","verification":{"locator":"Figure 8, Theorem 6.1, and Table 3","status":"fulltext_reviewed"},"work_id":"TSIG-PAPER-2024-AOMMLWE","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/496","sections":[{"content":"The assumption axis is intentionally separated from standard MLWE-only constructions. Theorem 6.1 bases threshold unforgeability on adaptive AOM-MLWE, whereas Theorem 4.5 reduces only selective AOM-UMLWE to UMLWE and MSIS; the final revision leaves bridging this adaptivity gap open.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"threshold_signature · 2024","summary":"The assumption axis is intentionally separated from standard MLWE-only constructions. Theorem 6.1 bases threshold unforgeability on adaptive AOM-MLWE, whereas Theorem 4.5 reduces only selective AOM-UMLWE to UMLWE and MSIS; the final revision leaves bridging this adaptivity gap open.","title":"Two-round threshold signature from AOM-MLWE","type":"construction","venue":"CRYPTO 2024; Journal of Cryptology revision","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2024-AOMMLWE"},{"evidence":"primary_source_reviewed","id":"TSIG-CONSTRUCTION-2024-FLOOD","keywords":["threshold_signature","lattice_hash_and_sign_submersion","post-quantum","robust-dkg","hash-and-sign","no-fhe"],"metadata":{"adaptive_security":"not claimed on this card","assumption":{"family":"lattice","name":"Module-LWE"},"base_signature":"lattice hash-and-sign","capabilities":["post-quantum","robust-dkg","hash-and-sign","no-fhe"],"communication":"paper-specific; no FHE ciphertext layer","construction_family":"lattice_hash_and_sign_submersion","corruption_model":"malicious threshold adversary under the paper model","dossier_type":"construction","evidence":"primary_source_checked","id":"TSIG-CONSTRUCTION-2024-FLOOD","identifiable_abort":"verifiable shares support blame; exact interface follows paper","name":"Robust hash-and-sign lattice threshold signature","output_compatibility":"scheme-specific hash-and-sign lattice verifier","post_quantum_mechanism":"MLWE, random submersions, and noise flooding","preprocessing":"verifiable short-secret-sharing and DKG material","primitive":"threshold_signature","resilience":"threshold unforgeability","robustness":"yes, including key generation in the paper claim","security":{"mode":"threshold public-key","model":"random oracle","notion":"robust threshold unforgeability"},"setup_model":"robust DKG via random submersions","signing_rounds":"distributed hash-and-sign protocol; exact count parameterized","sizes":{"public_key":"parameter-set-specific","signature":"about 13 KB in the paper's typical T=16 parameter set"},"status":"research","threshold_policy":"general threshold profile with a representative T=16 parameter set","title":"Flood and Submerse threshold signature","verification":{"status":"primary_source_reviewed"},"work_id":"TSIG-PAPER-2024-FLOOD","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/959","sections":[{"content":"The 13 KB observation is tied to the paper's typical T=16 parameter set.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"threshold_signature · 2024","summary":"The 13 KB observation is tied to the paper's typical T=16 parameter set.","title":"Robust hash-and-sign lattice threshold signature","type":"construction","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2024-FLOOD"},{"evidence":"primary_source_reviewed","id":"TSIG-CONSTRUCTION-2024-GLACIUS","keywords":["threshold_signature","threshold_schnorr_adaptive","ordinary-verifier-output","full-adaptive-security","full-corruption-threshold","identifiable-abort","constant-size-signing-key"],"metadata":{"adaptive_security":"full adaptive security","assumption":{"family":"ddh","name":"decisional Diffie-Hellman"},"base_signature":"Schnorr","capabilities":["ordinary-verifier-output","full-adaptive-security","full-corruption-threshold","identifiable-abort","constant-size-signing-key"],"communication":"exact table parameter-dependent","construction_family":"threshold_schnorr_adaptive","corruption_model":"fully adaptive adversary","dossier_type":"construction","evidence":"primary_source_checked","id":"TSIG-CONSTRUCTION-2024-GLACIUS","identifiable_abort":"yes, with a formal game-based definition","name":"Glacius fully adaptive threshold Schnorr from DDH","output_compatibility":"ordinary Schnorr-family signature","post_quantum_mechanism":"none","preprocessing":"protocol setup and signing-key material","primitive":"threshold_signature","resilience":"full corruption threshold stated as t<n in the paper","robustness":"identifiable abort rather than guaranteed output","security":{"mode":"threshold public-key","model":"random oracle","notion":"fully adaptive threshold unforgeability with identifiable abort"},"setup_model":"distributed Schnorr key with constant-size per-signer signing keys","signing_rounds":"exact protocol phases follow paper","sizes":{"public_key":"ordinary Schnorr public key","signature":"ordinary Schnorr signature"},"status":"published","threshold_policy":"full threshold range t<n under the paper's convention","title":"Glacius threshold Schnorr","verification":{"status":"primary_source_reviewed"},"work_id":"TSIG-PAPER-2024-GLACIUS","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/1628","sections":[{"content":"DDH here is a precise proof assumption for a 2024/2025 threshold-Schnorr result, not the origin assumption of the entire threshold-signature field.","heading":"Construction note"}],"status":"primary_source_reviewed","subtitle":"threshold_signature · 2024","summary":"DDH here is a precise proof assumption for a 2024/2025 threshold-Schnorr result, not the origin assumption of the entire threshold-signature field.","title":"Glacius fully adaptive threshold Schnorr from DDH","type":"construction","venue":"EUROCRYPT 2025","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2024-GLACIUS"},{"evidence":"fulltext_reviewed","id":"TSIG-CONSTRUCTION-2024-RACCOON","keywords":["threshold_signature","lattice_masked_partial_signatures","post-quantum","large-threshold","implementation","symmetric-and-simple-lattice-signing"],"metadata":{"adaptive_security":"no; static corruption game","assumption":{"family":"lattice","name":"Hint-MLWE and SelfTargetMSIS with reductions to MLWE/MSIS"},"base_signature":"Raccoon lattice signature","capabilities":["post-quantum","large-threshold","implementation","symmetric-and-simple-lattice-signing"],"communication":"Table 2 reports 40.8 KB per signer at kappa=128; implementation accounting is 40800+16T bytes with pairwise MACs","construction_family":"lattice_masked_partial_signatures","corruption_model":"static corrupt set chosen before key generation with fewer than T parties","dossier_type":"construction","evidence":"fulltext_checked","id":"TSIG-CONSTRUCTION-2024-RACCOON","identifiable_abort":"no; left as future work","name":"Threshold Raccoon practical lattice signature","output_compatibility":"verification algorithm identical to the paper's Raccoon variant; concrete parameters are not tuned for Raccoon interchangeability","post_quantum_mechanism":"Module-LWE and Module-SIS lineage","preprocessing":"pairwise PRF seeds provisioned at key generation; per-session additive masks are generated online","primitive":"threshold_signature","resilience":"threshold signing under standard lattice assumptions","robustness":"abort-oriented; robustness against malicious failure is left as future work","security":{"mode":"T-out-of-N","model":"random-oracle static-corruption game with bounded signing queries","notion":"threshold unforgeability"},"setup_model":"trusted centralized key generation; a compatible DKG is outside the paper's scope","signing_rounds":"three","sizes":{"public_key":"3.9 KB in Table 2; implementation value 3856 bytes","signature":"12.7 KB at kappa=128 in Table 2; implementation upper bound 12736 bytes with high probability"},"status":"published","threshold_policy":"any 1<=T<=N<=1024 in the concrete parameter profile","title":"Threshold Raccoon","verification":{"locator":"Figure 5, Theorem 7.2, Tables 2–3","status":"fulltext_reviewed"},"work_id":"TSIG-PAPER-2024-RACCOON","year":2024},"primaryUrl":"https://eprint.iacr.org/2024/184","sections":[{"content":"The paper requires a unique session identifier so pairwise PRF-derived masks are never reused. At the 128-bit parameter set, Table 3 reports three per-signer ShareSign phases; Section 9 reports 116 ms per signer at T=1024 only when communication latency is ignored and 4.5 GHz turbo is enabled.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"threshold_signature · 2024","summary":"The paper requires a unique session identifier so pairwise PRF-derived masks are never reused. At the 128-bit parameter set, Table 3 reports three per-signer ShareSign phases; Section 9 reports 116 ms per signer at T=1024 only when communication latency is ignored and 4.5 GHz turbo is enabled.","title":"Threshold Raccoon practical lattice signature","type":"construction","venue":"EUROCRYPT 2024","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2024-RACCOON"},{"evidence":"fulltext_reviewed","id":"TSIG-CONSTRUCTION-2024-TANG","keywords":["threshold_signature","lattice_mpc_rejection_sampling","post-quantum","arbitrary-threshold","interchangeable-output","proactive-refresh","implementation"],"metadata":{"adaptive_security":"proactive mobile-corruption security across refresh periods; not full within-period adaptive security","assumption":{"family":"lattice","name":"MLWE and MSIS plus the FPREP-hybrid preprocessing model"},"base_signature":"paper-specific lattice signature with ordinary verifier","capabilities":["post-quantum","arbitrary-threshold","interchangeable-output","proactive-refresh","implementation"],"communication":"1.417 MB sent per party in 15 online rounds for the Table 4 profile","construction_family":"lattice_mpc_rejection_sampling","corruption_model":"mobile malicious adversary corrupting at most t-1 parties in each refresh period","dossier_type":"construction","evidence":"fulltext_checked","id":"TSIG-CONSTRUCTION-2024-TANG","identifiable_abort":"no general identifiable-abort claim promoted","name":"Functionally interchangeable lattice threshold signature","output_compatibility":"yes; same verification algorithm as the paper's non-threshold signature","post_quantum_mechanism":"lattice assumptions and efficient distributed rejection sampling","preprocessing":"t-out-of-n authenticated bits and Beaver triples generated before DKG and signing; the reported batch supports five signatures","primitive":"threshold_signature","resilience":"t-out-of-n signing","robustness":"abort and restart on failed distributed rejection or MAC checks; guaranteed output not claimed","security":{"mode":"t-out-of-n","model":"random oracle and FPREP hybrid","notion":"proactive threshold EUF-CMA"},"setup_model":"t-out-of-n SPDZ variant and distributed key generation","signing_rounds":"15 online rounds in the Table 3 parameter profile","sizes":{"public_key":"same as the paper's non-threshold base public key and independent of party count","signature":"same as the paper's non-threshold base signature and independent of party count"},"status":"published","threshold_policy":"arbitrary t-out-of-n","title":"Tang-Pang-Chen-Zhang lattice threshold signature","verification":{"locator":"Sections 4–5 and Theorem 2; Tables 3–7","status":"fulltext_reviewed"},"work_id":"TSIG-PAPER-2024-TANG","year":2024},"primaryUrl":"https://doi.org/10.1109/TIFS.2023.3293408","sections":[{"content":"The 1.417 MB and 15-round figures are per-party online costs under Table 4's 123-classical/112-quantum-bit parameter setting. The MP-SPDZ-derived implementation reports 0.5-second two-party LAN signing and 1.5-second two-party WAN signing; these are environment-specific measurements, not cross-paper rankings.","heading":"Construction note"}],"status":"fulltext_reviewed","subtitle":"threshold_signature · 2024","summary":"The 1.417 MB and 15-round figures are per-party online costs under Table 4's 123-classical/112-quantum-bit parameter setting. The MP-SPDZ-derived implementation reports 0.5-second two-party LAN signing and 1.5-second two-party WAN signing; these are environment-specific measurements, not cross-paper rankings.","title":"Functionally interchangeable lattice threshold signature","type":"construction","venue":"IEEE Transactions on Information Forensics and Security 18, 4173–4187","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-CONSTRUCTION-2024-TANG"},{"evidence":"normalized_from_literature","id":"TSIG-OP-001","keywords":[],"metadata":{"acceptance":{"assurance":"complete reduction plus side-channel-aware implementation review","costs":"setup preprocessing online refresh key and signature bytes","interoperability":"public test vectors accepted by the target ordinary verifier","semantics":"fixed threshold convention and corruption/participation bounds"},"barriers":["TSIG-BARRIER-001","TSIG-BARRIER-002"],"closest_results":["TSIG-CONSTRUCTION-2023-GKS","TSIG-CONSTRUCTION-2024-TANG","TSIG-CONSTRUCTION-2024-RACCOON","TSIG-CONSTRUCTION-2024-FLOOD","TSIG-CONSTRUCTION-2024-AOMMLWE"],"dossier_type":"open_problem","evidence":"normalized_from_literature","hierarchy_links":[],"hierarchy_role":"post_quantum_standardization_endpoint","id":"TSIG-OP-001","normalization_delta":"Combines arbitrary-threshold signing, ordinary-verifier interoperability, malicious and adaptive security, robust dealer-free key generation, low online rounds, proactive refresh, and practical concrete cost; no audited source establishes this entire conjunction.","origin_evidence":["TSIG-PAPER-2023-GKS","TSIG-PAPER-2024-TANG","TSIG-PAPER-2024-RACCOON","TSIG-PAPER-2024-FLOOD","TSIG-PAPER-2026-NIST8214C"],"origin_type":"normalized_lineage_gap","profile":{"evidence":"reproducible implementation and full cost accounting","interoperability":"standardized ordinary verifier","latency":"at most two online rounds","lifecycle":"robust DKG plus proactive refresh","security":"malicious fully adaptive with explicit abort semantics","threshold":"arbitrary t-out-of-n"},"provenance":["TSIG-PAPER-2023-GKS","TSIG-PAPER-2024-TANG","TSIG-PAPER-2024-RACCOON","TSIG-PAPER-2024-FLOOD","TSIG-PAPER-2024-AOMMLWE","TSIG-PAPER-2026-NIST8214C"],"resolution_condition":"One construction, specification, and public artifact jointly meet every declared axis at a fixed security level and report setup, preprocessing, online computation, communication, failure, refresh, key, and signature costs.","routes":["TSIG-ROUTE-001","TSIG-ROUTE-002","TSIG-ROUTE-003"],"status":"open","target_profile":{"access_structure":"arbitrary t-out-of-n with signer-set flexibility","availability":"identifiable abort or stronger robustness, including key generation","evidence":"complete implementation and reproducible matched benchmark","operations":"at most two online signing rounds and proactive refresh","output":"accepted by an unmodified standardized post-quantum signature verifier","security":"malicious and fully adaptive corruptions with an explicit erasure model","setup":"dealer-free robust DKG with no trusted preprocessing party"},"title":"Interoperable practical post-quantum threshold signing across the full deployment profile"},"primaryUrl":null,"sections":[{"content":"Build and independently reproduce a dealer-free, arbitrary-t-out-of-n post-quantum threshold protocol whose output is accepted by an unmodified standardized verifier, with malicious fully adaptive security, explicit abort or robustness guarantees, proactive refresh, and at most two online signing rounds.","heading":"Exact normalized target"},{"content":"Round count alone hides setup and presigning costs; a small signature can still use a new verifier; and threshold unforgeability alone does not imply availability, adaptive security, or safe refresh. The target keeps those axes visible.","heading":"Why the conjunction matters"}],"status":"open","subtitle":"","summary":"Build and independently reproduce a dealer-free, arbitrary-t-out-of-n post-quantum threshold protocol whose output is accepted by an unmodified standardized verifier, with malicious fully adaptive security, explicit abort or robustness guarantees, proactive refresh, and at most two online signing rounds.","title":"Interoperable practical post-quantum threshold signing across the full deployment profile","type":"open_problem","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-OP-001"},{"evidence":"bibliographic_checked","id":"TSIG-PAPER-1989-DF","keywords":["foundations","threshold","rsa","secret-sharing"],"metadata":{"authors":["Yvo Desmedt","Yair Frankel"],"dossier_type":"paper","evidence":"bibliographic_checked","id":"TSIG-PAPER-1989-DF","keywords":["foundations","threshold","rsa","secret-sharing"],"primary_url":"https://doi.org/10.1007/0-387-34805-0_28","status":"published","title":"Threshold Cryptosystems","venue":"CRYPTO 1989","versions":["conference paper"],"year":1989},"primaryUrl":"https://doi.org/10.1007/0-387-34805-0_28","sections":[{"content":"Establishes the threshold-cryptosystem paradigm and gives the classical starting point for distributing RSA-style private operations.","heading":"Atomic claims"}],"status":"published","subtitle":"Yvo Desmedt, Yair Frankel · 1989","summary":"Establishes the threshold-cryptosystem paradigm and gives the classical starting point for distributing RSA-style private operations.","title":"Threshold Cryptosystems","type":"paper","venue":"CRYPTO 1989","year":1989,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-1989-DF"},{"evidence":"bibliographic_checked","id":"TSIG-PAPER-1991-PEDERSEN","keywords":["dkg","discrete-log","verifiable-secret-sharing","foundations"],"metadata":{"authors":["Torben Pryds Pedersen"],"dossier_type":"paper","evidence":"bibliographic_checked","id":"TSIG-PAPER-1991-PEDERSEN","keywords":["dkg","discrete-log","verifiable-secret-sharing","foundations"],"primary_url":"https://doi.org/10.1007/3-540-46416-6_47","status":"published","title":"A Threshold Cryptosystem without a Trusted Party","venue":"EUROCRYPT 1991","versions":["conference paper"],"year":1991},"primaryUrl":"https://doi.org/10.1007/3-540-46416-6_47","sections":[{"content":"Provides an early distributed-key-generation route for discrete-log keys without a trusted dealer.","heading":"Atomic claims"}],"status":"published","subtitle":"Torben Pryds Pedersen · 1991","summary":"Provides an early distributed-key-generation route for discrete-log keys without a trusted dealer.","title":"A Threshold Cryptosystem without a Trusted Party","type":"paper","venue":"EUROCRYPT 1991","year":1991,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-1991-PEDERSEN"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-1996-GJKR-DSS","keywords":["dss","discrete-log","robustness","malicious-security"],"metadata":{"authors":["Rosario Gennaro","Stanisław Jarecki","Hugo Krawczyk","Tal Rabin"],"citation_key":"GJKR96b","dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-1996-GJKR-DSS","keywords":["dss","discrete-log","robustness","malicious-security"],"primary_url":"https://doi.org/10.1007/3-540-68339-9_31","status":"published","title":"Robust Threshold DSS Signatures","venue":"EUROCRYPT 1996","versions":["EUROCRYPT 1996 paper","Information and Computation 2001 journal version"],"year":1996},"primaryUrl":"https://doi.org/10.1007/3-540-68339-9_31","sections":[{"content":"Presents threshold DSS where 2t+1 signers can produce an ordinary DSS signature for t<n/2, together with scoped robustness guarantees.","heading":"Atomic claims"},{"content":"Proceedings paper and journal abstract; exact fault bounds are kept distinct in the construction card.","heading":"Evidence locator"}],"status":"published","subtitle":"Rosario Gennaro, Stanisław Jarecki, Hugo Krawczyk et al. · 1996","summary":"Presents threshold DSS where 2t+1 signers can produce an ordinary DSS signature for t<n/2, together with scoped robustness guarantees.","title":"Robust Threshold DSS Signatures","type":"paper","venue":"EUROCRYPT 1996","year":1996,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-1996-GJKR-DSS"},{"evidence":"bibliographic_checked","id":"TSIG-PAPER-1996-GJKR-RSA","keywords":["rsa","threshold","robustness","function-sharing"],"metadata":{"authors":["Rosario Gennaro","Stanisław Jarecki","Hugo Krawczyk","Tal Rabin"],"citation_key":"GJKR96a","dossier_type":"paper","evidence":"bibliographic_checked","id":"TSIG-PAPER-1996-GJKR-RSA","keywords":["rsa","threshold","robustness","function-sharing"],"primary_url":"https://doi.org/10.1007/3-540-68697-5","status":"published","title":"Robust and Efficient Sharing of RSA Functions","venue":"CRYPTO 1996","versions":["CRYPTO 1996 paper","Journal of Cryptology version"],"year":1996},"primaryUrl":"https://doi.org/10.1007/3-540-68697-5","sections":[{"content":"Develops robust sharing of RSA signing and decryption functions, providing a classical threshold-RSA branch before Shoup's later simplification.","heading":"Atomic claims"}],"status":"published","subtitle":"Rosario Gennaro, Stanisław Jarecki, Hugo Krawczyk et al. · 1996","summary":"Develops robust sharing of RSA signing and decryption functions, providing a classical threshold-RSA branch before Shoup's later simplification.","title":"Robust and Efficient Sharing of RSA Functions","type":"paper","venue":"CRYPTO 1996","year":1996,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-1996-GJKR-RSA"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-1999-GJKR-DKG","keywords":["dkg","discrete-log","malicious-security","robustness"],"metadata":{"authors":["Rosario Gennaro","Stanisław Jarecki","Hugo Krawczyk","Tal Rabin"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-1999-GJKR-DKG","keywords":["dkg","discrete-log","malicious-security","robustness"],"primary_url":"https://doi.org/10.1007/3-540-48910-X_21","status":"published","title":"Secure Distributed Key Generation for Discrete-Log Based Cryptosystems","venue":"EUROCRYPT 1999","versions":["conference paper"],"year":1999},"primaryUrl":"https://doi.org/10.1007/3-540-48910-X_21","sections":[{"content":"Gives a robust distributed key-generation protocol for discrete-log cryptosystems with explicit adversarial-threshold conditions.","heading":"Atomic claims"},{"content":"Proceedings paper, abstract, model, and protocol sections.","heading":"Evidence locator"}],"status":"published","subtitle":"Rosario Gennaro, Stanisław Jarecki, Hugo Krawczyk et al. · 1999","summary":"Gives a robust distributed key-generation protocol for discrete-log cryptosystems with explicit adversarial-threshold conditions.","title":"Secure Distributed Key Generation for Discrete-Log Based Cryptosystems","type":"paper","venue":"EUROCRYPT 1999","year":1999,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-1999-GJKR-DKG"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-2000-SHOUP","keywords":["rsa","threshold","robustness","practical"],"metadata":{"authors":["Victor Shoup"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-2000-SHOUP","keywords":["rsa","threshold","robustness","practical"],"primary_url":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","status":"published","title":"Practical Threshold Signatures","venue":"EUROCRYPT 2000","versions":["conference paper"],"year":2000},"primaryUrl":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","sections":[{"content":"Presents a practical robust threshold RSA signature in which signing servers produce shares noninteractively and a combiner verifies and joins them.","heading":"Atomic claims"},{"content":"Abstract and Sections 1-4 of the proceedings paper.","heading":"Evidence locator"}],"status":"published","subtitle":"Victor Shoup · 2000","summary":"Presents a practical robust threshold RSA signature in which signing servers produce shares noninteractively and a combiner verifies and joins them.","title":"Practical Threshold Signatures","type":"paper","venue":"EUROCRYPT 2000","year":2000,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2000-SHOUP"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-2003-BOLDYREVA","keywords":["pairing","gap-diffie-hellman","bls","threshold","compact-output"],"metadata":{"authors":["Alexandra Boldyreva"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-2003-BOLDYREVA","keywords":["pairing","gap-diffie-hellman","bls","threshold","compact-output"],"primary_url":"https://eprint.iacr.org/2002/118","status":"published","title":"Threshold Signatures, Multisignatures and Blind Signatures Based on the Gap-Diffie-Hellman-Group Signature Scheme","venue":"PKC 2003","versions":["ePrint 2002/118","conference paper"],"year":2003},"primaryUrl":"https://eprint.iacr.org/2002/118","sections":[{"content":"Constructs a threshold version of the BLS/GDH signature whose combined output remains an ordinary compact BLS signature.","heading":"Atomic claims"},{"content":"ePrint 2002/118, abstract and threshold-signature section.","heading":"Evidence locator"}],"status":"published","subtitle":"Alexandra Boldyreva · 2003","summary":"Constructs a threshold version of the BLS/GDH signature whose combined output remains an ordinary compact BLS signature.","title":"Threshold Signatures, Multisignatures and Blind Signatures Based on the Gap-Diffie-Hellman-Group Signature Scheme","type":"paper","venue":"PKC 2003","year":2003,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2003-BOLDYREVA"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-2017-LINDELL","keywords":["ecdsa","two-party","paillier","malicious-security"],"metadata":{"authors":["Yehuda Lindell"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-2017-LINDELL","keywords":["ecdsa","two-party","paillier","malicious-security"],"primary_url":"https://eprint.iacr.org/2017/552","status":"published","title":"Fast Secure Two-Party ECDSA Signing","venue":"CRYPTO 2017","versions":["ePrint 2017/552","conference paper"],"year":2017},"primaryUrl":"https://eprint.iacr.org/2017/552","sections":[{"content":"Provides a fast maliciously secure two-party protocol producing standard ECDSA signatures.","heading":"Atomic claims"},{"content":"ePrint 2017/552, abstract and protocol overview.","heading":"Evidence locator"}],"status":"published","subtitle":"Yehuda Lindell · 2017","summary":"Provides a fast maliciously secure two-party protocol producing standard ECDSA signatures.","title":"Fast Secure Two-Party ECDSA Signing","type":"paper","venue":"CRYPTO 2017","year":2017,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2017-LINDELL"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-2018-DKLS-2P","keywords":["ecdsa","two-party","oblivious-transfer","hash-proof-system"],"metadata":{"authors":["Jack Doerner","Yashvanth Kondi","Eysa Lee","abhi shelat"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-2018-DKLS-2P","keywords":["ecdsa","two-party","oblivious-transfer","hash-proof-system"],"primary_url":"https://eprint.iacr.org/2018/499","status":"published","title":"Two-Party ECDSA from Hash Proof Systems and Efficient Instantiations","venue":"CRYPTO 2018","versions":["ePrint 2018/499","conference paper"],"year":2018},"primaryUrl":"https://eprint.iacr.org/2018/499","sections":[{"content":"Gives a two-party ECDSA route using hash-proof-system techniques rather than Paillier-based multiplication.","heading":"Atomic claims"},{"content":"ePrint 2018/499, abstract and construction overview.","heading":"Evidence locator"}],"status":"published","subtitle":"Jack Doerner, Yashvanth Kondi, Eysa Lee et al. · 2018","summary":"Gives a two-party ECDSA route using hash-proof-system techniques rather than Paillier-based multiplication.","title":"Two-Party ECDSA from Hash Proof Systems and Efficient Instantiations","type":"paper","venue":"CRYPTO 2018","year":2018,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2018-DKLS-2P"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-2018-GG","keywords":["ecdsa","multiparty","paillier","dkg"],"metadata":{"authors":["Rosario Gennaro","Steven Goldfeder"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-2018-GG","keywords":["ecdsa","multiparty","paillier","dkg"],"primary_url":"https://eprint.iacr.org/2019/114","status":"published","title":"Fast Multiparty Threshold ECDSA with Fast Trustless Setup","venue":"ACM CCS 2018","versions":["ePrint 2019/114","conference paper"],"year":2018},"primaryUrl":"https://eprint.iacr.org/2019/114","sections":[{"content":"Extends practical threshold ECDSA to the multiparty setting with a trustless setup protocol and standard ECDSA output.","heading":"Atomic claims"},{"content":"ePrint 2019/114, abstract and introduction.","heading":"Evidence locator"}],"status":"published","subtitle":"Rosario Gennaro, Steven Goldfeder · 2018","summary":"Extends practical threshold ECDSA to the multiparty setting with a trustless setup protocol and standard ECDSA output.","title":"Fast Multiparty Threshold ECDSA with Fast Trustless Setup","type":"paper","venue":"ACM CCS 2018","year":2018,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2018-GG"},{"evidence":"bibliographic_checked","id":"TSIG-PAPER-2019-DKLS-N","keywords":["ecdsa","threshold","oblivious-transfer","multiparty"],"metadata":{"authors":["Jack Doerner","Yashvanth Kondi","Eysa Lee","abhi shelat"],"dossier_type":"paper","evidence":"bibliographic_checked","id":"TSIG-PAPER-2019-DKLS-N","keywords":["ecdsa","threshold","oblivious-transfer","multiparty"],"primary_url":"https://doi.org/10.1109/SP.2019.00024","status":"published","title":"Threshold ECDSA from ECDSA Assumptions","venue":"IEEE Symposium on Security and Privacy 2019","versions":["ePrint 2018/499 lineage","conference paper"],"year":2019},"primaryUrl":"https://doi.org/10.1109/SP.2019.00024","sections":[{"content":"Develops the DKLS line into general threshold ECDSA while keeping the online output compatible with ordinary ECDSA verification.","heading":"Atomic claims"}],"status":"published","subtitle":"Jack Doerner, Yashvanth Kondi, Eysa Lee et al. · 2019","summary":"Develops the DKLS line into general threshold ECDSA while keeping the online output compatible with ordinary ECDSA verification.","title":"Threshold ECDSA from ECDSA Assumptions","type":"paper","venue":"IEEE Symposium on Security and Privacy 2019","year":2019,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2019-DKLS-N"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-2020-CGGMP","keywords":["ecdsa","uc-security","identifiable-abort","proactive","preprocessing"],"metadata":{"authors":["Ran Canetti","Rosario Gennaro","Steven Goldfeder","Nikolaos Makriyannis","Udi Peled"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-2020-CGGMP","keywords":["ecdsa","uc-security","identifiable-abort","proactive","preprocessing"],"primary_url":"https://eprint.iacr.org/2021/060","status":"published","title":"UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable Aborts","venue":"ACM CCS 2020","versions":["ePrint 2021/060 (revised full version)","conference paper"],"year":2020},"primaryUrl":"https://eprint.iacr.org/2021/060","sections":[{"content":"Proves adaptive UC security for two threshold-ECDSA protocols in the global random-oracle model under the paper's stated assumptions. Moves every message-independent round into preprocessing, leaving one message-dependent online round. Adds identifiable abort and proactive share refresh as separate guarantees.","heading":"Atomic claims"},{"content":"ePrint 2021/060 revised full version, abstract and contribution overview. The earlier 2020/540 report is obsolete and is not used as proof evidence.","heading":"Evidence locator"}],"status":"published","subtitle":"Ran Canetti, Rosario Gennaro, Steven Goldfeder et al. · 2020","summary":"Proves adaptive UC security for two threshold-ECDSA protocols in the global random-oracle model under the paper's stated assumptions. Moves every message-independent round into preprocessing, leaving one message-dependent online round. Adds identifiable abort and proactive share refresh as separate guarantees.","title":"UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable Aborts","type":"paper","venue":"ACM CCS 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2020-CGGMP"},{"evidence":"fulltext_checked","id":"TSIG-PAPER-2020-FROST","keywords":["schnorr","discrete-log","two-round","preprocessing","practical"],"metadata":{"authors":["Chelsea Komlo","Ian Goldberg"],"dossier_type":"paper","evidence":"fulltext_checked","id":"TSIG-PAPER-2020-FROST","keywords":["schnorr","discrete-log","two-round","preprocessing","practical"],"maps_to":["TSIG-OP-001"],"primary_url":"https://eprint.iacr.org/2020/852","status":"published","title":"FROST: Flexible Round-Optimized Schnorr Threshold Signatures","venue":"SAC 2020","versions":["ePrint 2020/852","conference paper"],"year":2020},"primaryUrl":"https://eprint.iacr.org/2020/852","sections":[{"content":"Gives a true t-out-of-n Schnorr threshold protocol with two-round signing, or one online round after preprocessing, under a static-adversary security treatment.","heading":"Atomic claims"},{"content":"ePrint 2020/852, Sections 5.1–5.2 and Figures 1–3 (PDF pp. 10–15) for key generation, preprocessing, the two-round variant, the single online round, and share attribution; Section 6.2 and Theorem 6.1 (PDF pp. 16–18) for the chosen-message reduction and fewer-than-t corruption bound.","heading":"Evidence locator"}],"status":"published","subtitle":"Chelsea Komlo, Ian Goldberg · 2020","summary":"Gives a true t-out-of-n Schnorr threshold protocol with two-round signing, or one online round after preprocessing, under a static-adversary security treatment.","title":"FROST: Flexible Round-Optimized Schnorr Threshold Signatures","type":"paper","venue":"SAC 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2020-FROST"},{"evidence":"fulltext_checked","id":"TSIG-PAPER-2021-DOTT","keywords":["lattice","module-lwe","module-sis","fiat-shamir-with-aborts","n-out-of-n","two-round"],"metadata":{"authors":["Ivan Damgård","Claudio Orlandi","Akira Takahashi","Mehdi Tibouchi"],"dossier_type":"paper","evidence":"fulltext_checked","id":"TSIG-PAPER-2021-DOTT","keywords":["lattice","module-lwe","module-sis","fiat-shamir-with-aborts","n-out-of-n","two-round"],"maps_to":["TSIG-OP-001"],"primary_url":"https://eprint.iacr.org/2020/1110","status":"published","title":"Two-round n-out-of-n and Multi-Signatures and Trapdoor Commitment from Lattices","venue":"PKC 2021; Journal of Cryptology 2022","versions":["ePrint 2020/1110","conference paper","journal paper"],"year":2021},"primaryUrl":"https://eprint.iacr.org/2020/1110","sections":[{"content":"Constructs two-round n-out-of-n distributed lattice signing and identifies abort-transcript leakage as a security issue addressed with homomorphic trapdoor commitments.","heading":"Atomic claims"},{"content":"ePrint 2020/1110 full Journal of Cryptology version: Section 1.1 (PDF pp. 4–7) for abort leakage and homomorphic commitments; Section 3.1 and Figure 6 (PDF pp. 16–19) for DS2; Section 3.3, Theorem 1 (PDF pp. 19–26) for DS-UF-CMA security; Section 5 and Theorem 3 for the trapdoor commitment.","heading":"Evidence locator"}],"status":"published","subtitle":"Ivan Damgård, Claudio Orlandi, Akira Takahashi et al. · 2021","summary":"Constructs two-round n-out-of-n distributed lattice signing and identifies abort-transcript leakage as a security issue addressed with homomorphic trapdoor commitments.","title":"Two-round n-out-of-n and Multi-Signatures and Trapdoor Commitment from Lattices","type":"paper","venue":"PKC 2021; Journal of Cryptology 2022","year":2021,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2021-DOTT"},{"evidence":"fulltext_checked","id":"TSIG-PAPER-2021-GKMN","keywords":["schnorr","deterministic-nonce","stateless","garbled-circuits","dishonest-majority"],"metadata":{"authors":["François Garillot","Yashvanth Kondi","Payman Mohassel","Valeria Nikolaenko"],"dossier_type":"paper","evidence":"fulltext_checked","id":"TSIG-PAPER-2021-GKMN","keywords":["schnorr","deterministic-nonce","stateless","garbled-circuits","dishonest-majority"],"primary_url":"https://eprint.iacr.org/2021/1055","status":"published","title":"Threshold Schnorr with Stateless Deterministic Signing from Standard Assumptions","venue":"CRYPTO 2021","versions":["ePrint 2021/1055","conference paper"],"year":2021},"primaryUrl":"https://eprint.iacr.org/2021/1055","sections":[{"content":"Constructs dishonest-majority threshold Schnorr with deterministic nonce derivation and no evolving long-term state, using standardized block ciphers and zero-knowledge-from-garbled-circuits tools.","heading":"Atomic claims"},{"content":"ePrint 2021/1055, Sections 1.3–1.4 (PDF pp. 4–9) for the standard-assumption toolchain and stateless deterministic objective; Section 9 protocol rounds and Theorem 9.3 (PDF pp. 33–34) for the three-round signing flow and static n-1-corruption UC claim in the stated hybrid model.","heading":"Evidence locator"}],"status":"published","subtitle":"François Garillot, Yashvanth Kondi, Payman Mohassel et al. · 2021","summary":"Constructs dishonest-majority threshold Schnorr with deterministic nonce derivation and no evolving long-term state, using standardized block ciphers and zero-knowledge-from-garbled-circuits tools.","title":"Threshold Schnorr with Stateless Deterministic Signing from Standard Assumptions","type":"paper","venue":"CRYPTO 2021","year":2021,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2021-GKMN"},{"evidence":"fulltext_checked","id":"TSIG-PAPER-2022-DILIZIUM2","keywords":["lattice","module-lwe","module-sis","dilithium","two-party","compression"],"metadata":{"authors":["Peeter Laud","Nikita Snetkov","Jelizaveta Vakarjuk"],"dossier_type":"paper","evidence":"fulltext_checked","id":"TSIG-PAPER-2022-DILIZIUM2","keywords":["lattice","module-lwe","module-sis","dilithium","two-party","compression"],"maps_to":["TSIG-OP-001"],"primary_url":"https://eprint.iacr.org/2022/644","status":"published_with_outdated_eprint","title":"DiLizium 2.0: Revisiting Two-Party Crystals-Dilithium","venue":"Journal of Computer Security final version","versions":["ePrint 2022/644","journal article"],"year":2022},"primaryUrl":"https://eprint.iacr.org/2022/644","sections":[{"content":"Refines the DOTT-style two-party line with Dilithium compression techniques and reports a three-round protocol in the audited preprint.","heading":"Atomic claims"},{"content":"ePrint 2022/644, Section 1.1 (PDF p. 2) for the three-round construction and compression delta; Theorem 1 (PDF pp. 10–11) for classical-ROM DS-UF-CMA security from the commitment properties, Module-LWE, and Module-SIS; Section 4 and Table 2 (PDF pp. 14–15) for the Java benchmark and preprint parameters.","heading":"Evidence locator"},{"content":"The ePrint page explicitly marks 2022/644 as outdated relative to the final journal version; the audited PDF's parameters and measurements remain preprint observations and must not be copied as final-journal values without a journal audit.","heading":"Version warning"}],"status":"published_with_outdated_eprint","subtitle":"Peeter Laud, Nikita Snetkov, Jelizaveta Vakarjuk · 2022","summary":"Refines the DOTT-style two-party line with Dilithium compression techniques and reports a three-round protocol in the audited preprint.","title":"DiLizium 2.0: Revisiting Two-Party Crystals-Dilithium","type":"paper","venue":"Journal of Computer Security final version","year":2022,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2022-DILIZIUM2"},{"evidence":"fulltext_checked","id":"TSIG-PAPER-2023-GKS","keywords":["lattice","ring-lwe","sis","threshold-he","arbitrary-threshold","two-round"],"metadata":{"authors":["Kamil Doruk Gur","Jonathan Katz","Tjerand Silde"],"dossier_type":"paper","evidence":"fulltext_checked","id":"TSIG-PAPER-2023-GKS","keywords":["lattice","ring-lwe","sis","threshold-he","arbitrary-threshold","two-round"],"maps_to":["TSIG-OP-001"],"primary_url":"https://eprint.iacr.org/2023/1318","status":"published","title":"Two-Round Threshold Lattice-Based Signatures from Threshold Homomorphic Encryption","venue":"PQCrypto 2024","versions":["ePrint 2023/1318","conference paper"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2023/1318","sections":[{"content":"Generalizes the two-round lattice line from full threshold to arbitrary t<=n by using an actively secure threshold linearly homomorphic-encryption layer.","heading":"Atomic claims"},{"content":"ePrint 2023/1318, Section 3 and Theorem 1 (PDF pp. 12–16) for threshold linear HE; Section 5, Figures 6–7, and Theorem 3 (PDF pp. 22–26) for active two-round t-out-of-n signing; Section 7 and the concrete-size table (PDF pp. 30–31) for the 3-out-of-5 estimate.","heading":"Evidence locator"}],"status":"published","subtitle":"Kamil Doruk Gur, Jonathan Katz, Tjerand Silde · 2023","summary":"Generalizes the two-round lattice line from full threshold to arbitrary t<=n by using an actively secure threshold linearly homomorphic-encryption layer.","title":"Two-Round Threshold Lattice-Based Signatures from Threshold Homomorphic Encryption","type":"paper","venue":"PQCrypto 2024","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2023-GKS"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-2023-OLAF","keywords":["schnorr","frost","dkg","aomdl","random-oracle","proof-model"],"metadata":{"authors":["Hien Chu","Paul Gerhart","Tim Ruffing","Dominique Schröder"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-2023-OLAF","keywords":["schnorr","frost","dkg","aomdl","random-oracle","proof-model"],"primary_url":"https://eprint.iacr.org/2023/899","status":"published","title":"Practical Schnorr Threshold Signatures Without the Algebraic Group Model","venue":"CRYPTO 2023","versions":["ePrint 2023/899","conference paper"],"year":2023},"primaryUrl":"https://eprint.iacr.org/2023/899","sections":[{"content":"Combines FROST3 with a Pedersen-DKG variant and proves unforgeability without the algebraic group model, under AOMDL in the random-oracle model.","heading":"Atomic claims"},{"content":"ePrint 2023/899, abstract and proof overview.","heading":"Evidence locator"}],"status":"published","subtitle":"Hien Chu, Paul Gerhart, Tim Ruffing et al. · 2023","summary":"Combines FROST3 with a Pedersen-DKG variant and proves unforgeability without the algebraic group model, under AOMDL in the random-oracle model.","title":"Practical Schnorr Threshold Signatures Without the Algebraic Group Model","type":"paper","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2023-OLAF"},{"evidence":"fulltext_checked","id":"TSIG-PAPER-2024-TANG","keywords":["lattice","t-out-of-n","mpc","rejection-sampling","interchangeable-output","proactive"],"metadata":{"authors":["Guofeng Tang","Bo Pang","Long Chen","Zhenfeng Zhang"],"dossier_type":"paper","evidence":"fulltext_checked","id":"TSIG-PAPER-2024-TANG","keywords":["lattice","t-out-of-n","mpc","rejection-sampling","interchangeable-output","proactive"],"maps_to":["TSIG-OP-001"],"primary_url":"https://doi.org/10.1109/TIFS.2023.3293408","status":"published","title":"Efficient Lattice-Based Threshold Signatures with Functional Interchangeability","venue":"IEEE Transactions on Information Forensics and Security 18, 4173–4187","versions":["journal article, DOI 10.1109/TIFS.2023.3293408","ePrint 2024/1067"],"year":2023},"primaryUrl":"https://doi.org/10.1109/TIFS.2023.3293408","sections":[{"content":"Reports an implemented t-out-of-n lattice threshold signature with ordinary-verifier interoperability, distributed rejection sampling, and proactive refresh.","heading":"Atomic claims"},{"content":"ePrint 2024/1067, Section 1.1 (PDF p. 4) for functional interchangeability, implementation scope, and proactive security; Sections 5–6, Definition 3, and Theorem 2 (PDF pp. 12–18) for the ordinary verifier and mobile-adversary model; Section 7, Tables 2–7 (PDF pp. 21–27) for preprocessing, 15 online signing rounds, 1.417 MB per-party communication in the reported profile, and LAN/WAN measurements.","heading":"Evidence locator"}],"status":"published","subtitle":"Guofeng Tang, Bo Pang, Long Chen et al. · 2023","summary":"Reports an implemented t-out-of-n lattice threshold signature with ordinary-verifier interoperability, distributed rejection sampling, and proactive refresh.","title":"Efficient Lattice-Based Threshold Signatures with Functional Interchangeability","type":"paper","venue":"IEEE Transactions on Information Forensics and Security 18, 4173–4187","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2024-TANG"},{"evidence":"fulltext_checked","id":"TSIG-PAPER-2024-AOMMLWE","keywords":["lattice","aom-mlwe","two-round","offline-online","large-threshold"],"metadata":{"authors":["Thomas Espitau","Shuichi Katsumata","Kaoru Takemure"],"dossier_type":"paper","evidence":"fulltext_checked","id":"TSIG-PAPER-2024-AOMMLWE","keywords":["lattice","aom-mlwe","two-round","offline-online","large-threshold"],"maps_to":["TSIG-OP-001"],"primary_url":"https://eprint.iacr.org/2024/496","status":"published","title":"Two-Round Threshold Signature from Algebraic One-More Learning with Errors","venue":"CRYPTO 2024; Journal of Cryptology revision","versions":["ePrint 2024/496","conference paper","journal version"],"year":2024},"primaryUrl":"https://eprint.iacr.org/2024/496","sections":[{"content":"Builds an efficient two-round lattice threshold signature without FHE or homomorphic trapdoor commitments, with a message- and signer-set-independent offline round.","heading":"Atomic claims"},{"content":"ePrint 2024/496, final author revision dated 2026-04-07: Sections 1.1 and 2.1, Figure 2 (PDF pp. 4–10) for the two-round offline/online construction; Theorem 4.5 (PDF pp. 27–32) for the selective AOM-UMLWE reduction from UMLWE/MSIS; Theorem 6.1 (PDF pp. 35–36) for threshold unforgeability under adaptive AOM-MLWE and PRF security; Section 8.3, Table 3 (PDF p. 58) for the threshold-1024 parameter profiles.","heading":"Evidence locator"}],"status":"published","subtitle":"Thomas Espitau, Shuichi Katsumata, Kaoru Takemure · 2024","summary":"Builds an efficient two-round lattice threshold signature without FHE or homomorphic trapdoor commitments, with a message- and signer-set-independent offline round.","title":"Two-Round Threshold Signature from Algebraic One-More Learning with Errors","type":"paper","venue":"CRYPTO 2024; Journal of Cryptology revision","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2024-AOMMLWE"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-2024-FLOOD","keywords":["lattice","hash-and-sign","mlwe","robust-dkg","noise-flooding","random-submersion"],"metadata":{"authors":["Thomas Espitau","Guilhem Niot","Thomas Prest"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-2024-FLOOD","keywords":["lattice","hash-and-sign","mlwe","robust-dkg","noise-flooding","random-submersion"],"maps_to":["TSIG-OP-001"],"primary_url":"https://eprint.iacr.org/2024/959","status":"published","title":"Flood and Submerse: Distributed Key Generation and Robust Threshold Signature from Lattices","venue":"CRYPTO 2024","versions":["ePrint 2024/959","conference paper"],"year":2024},"primaryUrl":"https://eprint.iacr.org/2024/959","sections":[{"content":"Introduces a robust hash-and-sign lattice threshold route using verifiable short secret sharing via random submersions and noise flooding, without FHE.","heading":"Atomic claims"},{"content":"ePrint 2024/959, abstract and framework overview.","heading":"Evidence locator"}],"status":"published","subtitle":"Thomas Espitau, Guilhem Niot, Thomas Prest · 2024","summary":"Introduces a robust hash-and-sign lattice threshold route using verifiable short secret sharing via random submersions and noise flooding, without FHE.","title":"Flood and Submerse: Distributed Key Generation and Robust Threshold Signature from Lattices","type":"paper","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2024-FLOOD"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-2024-GLACIUS","keywords":["schnorr","ddh","adaptive-security","identifiable-abort","constant-size-signing-key"],"metadata":{"authors":["Renas Bacho","Sourav Das","Julian Loss","Ling Ren"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-2024-GLACIUS","keywords":["schnorr","ddh","adaptive-security","identifiable-abort","constant-size-signing-key"],"maps_to":["TSIG-OP-001"],"primary_url":"https://eprint.iacr.org/2024/1628","status":"published","title":"Glacius: Threshold Schnorr Signatures from DDH with Full Adaptive Security","venue":"EUROCRYPT 2025","versions":["ePrint 2024/1628","conference paper"],"year":2024},"primaryUrl":"https://eprint.iacr.org/2024/1628","sections":[{"content":"Gives threshold Schnorr with full adaptive security from DDH in the random-oracle model, full t<n corruption tolerance under the paper's convention, constant-size signing keys, and identifiable abort.","heading":"Atomic claims"},{"content":"ePrint 2024/1628, abstract and security-definition discussion.","heading":"Evidence locator"}],"status":"published","subtitle":"Renas Bacho, Sourav Das, Julian Loss et al. · 2024","summary":"Gives threshold Schnorr with full adaptive security from DDH in the random-oracle model, full t<n corruption tolerance under the paper's convention, constant-size signing keys, and identifiable abort.","title":"Glacius: Threshold Schnorr Signatures from DDH with Full Adaptive Security","type":"paper","venue":"EUROCRYPT 2025","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2024-GLACIUS"},{"evidence":"fulltext_checked","id":"TSIG-PAPER-2024-RACCOON","keywords":["lattice","module-lwe","module-sis","large-threshold","implementation","masks"],"metadata":{"authors":["Rafael del Pino","Shuichi Katsumata","Mary Maller","Fabrice Mouhartem","Thomas Prest","Markku-Juhani Saarinen"],"citation_key":"PKM+24","citation_note":"Pin the author-year form used in Ringtail; del Pino also appears under other particle conventions in the literature.","citation_sources":["https://eprint.iacr.org/2024/1113.pdf"],"dossier_type":"paper","evidence":"fulltext_checked","id":"TSIG-PAPER-2024-RACCOON","keywords":["lattice","module-lwe","module-sis","large-threshold","implementation","masks"],"maps_to":["TSIG-OP-001"],"primary_url":"https://eprint.iacr.org/2024/184","status":"published","title":"Threshold Raccoon: Practical Threshold Signatures from Standard Lattice Assumptions","venue":"EUROCRYPT 2024","versions":["ePrint 2024/184","conference paper"],"year":2024},"primaryUrl":"https://eprint.iacr.org/2024/184","sections":[{"content":"Constructs a three-round lattice threshold signature from standard lattice assumptions, with pairwise one-time additive masks and concrete parameter sets supporting thresholds up to 1024.","heading":"Atomic claims"},{"content":"ePrint 2024/184, Sections 1.1 and 2.3 (PDF pp. 4–10) for the three-round design and mask mechanism; Sections 6–7, Figure 5, and Theorem 7.2 (PDF pp. 20–25) for trusted centralized key generation, static corruption below T, and unforgeability; Section 8.3, Table 2, and Section 9, Table 3 (PDF pp. 43–44) for the 128-bit 3.9 KB verification key, 12.7 KB signature, communication, and cycle-count profiles.","heading":"Evidence locator"}],"status":"published","subtitle":"Rafael del Pino, Shuichi Katsumata, Mary Maller et al. · 2024","summary":"Constructs a three-round lattice threshold signature from standard lattice assumptions, with pairwise one-time additive masks and concrete parameter sets supporting thresholds up to 1024.","title":"Threshold Raccoon: Practical Threshold Signatures from Standard Lattice Assumptions","type":"paper","venue":"EUROCRYPT 2024","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2024-RACCOON"},{"evidence":"primary_source_checked","id":"TSIG-PAPER-2026-NIST8214C","keywords":["nist","standardization","threshold","evaluation","interoperability"],"metadata":{"authors":["National Institute of Standards and Technology"],"dossier_type":"paper","evidence":"primary_source_checked","id":"TSIG-PAPER-2026-NIST8214C","keywords":["nist","standardization","threshold","evaluation","interoperability"],"maps_to":["TSIG-OP-001"],"primary_url":"https://csrc.nist.gov/pubs/ir/8214/c/final","status":"published","title":"NIST First Call for Multi-Party Threshold Schemes","venue":"NIST Interagency/Internal Report","versions":["NIST IR 8214C final"],"year":2026},"primaryUrl":"https://csrc.nist.gov/pubs/ir/8214/c/final","sections":[{"content":"Issues NIST's first public call for multi-party threshold schemes and defines submission packages containing a technical specification, reference implementation, and experimental-evaluation report.","heading":"Atomic claims"},{"content":"NIST publication page and final report package requirements.","heading":"Evidence locator"}],"status":"published","subtitle":"National Institute of Standards and Technology · 2026","summary":"Issues NIST's first public call for multi-party threshold schemes and defines submission packages containing a technical specification, reference implementation, and experimental-evaluation report.","title":"NIST First Call for Multi-Party Threshold Schemes","type":"paper","venue":"NIST Interagency/Internal Report","year":2026,"sourcePath":"data/threshold-signature-catalog.json#TSIG-PAPER-2026-NIST8214C"},{"evidence":"bibliographic_checked","id":"TSIG-RESULT-1989-DF-DISTRIBUTED-RSA-SIGNING-ROOT","keywords":["atomic-result","foundations","threshold","rsa","secret-sharing","rsa_function_sharing","round_efficient_robust_signing","capability_result"],"metadata":{"claim_slug":"distributed-rsa-signing-root","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"bibliographic_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["rsa_function_sharing"]},"historical_context":{"narrative":"Centralized signing made one private key holder a single compromise and availability point. Desmedt and Frankel recast the private operation as a quorum service: parties hold shares, and only an authorized subset can jointly produce the result. Their work established the threshold-cryptosystem interface and an early distributed RSA line, but it preceded the richer robustness and composability contracts developed by later protocols. A second node isolates the RSA instantiation, in which exponent shares support a distributed signing operation. Later GJKR and Shoup work strengthens robustness and online usability rather than being collapsed into this origin claim.","prior_boundary":"Public-key signatures assumed one signing key holder, so compromise or unavailability of that holder was a single point of failure.","significance_at_publication":"The threshold-cryptosystem abstraction made distributed private-key operations a cryptographic interface and established the RSA-signing root later robustness work refined.","technical_delta":"Secret exponent shares allowed a qualified set to produce the RSA private transformation without centralizing the exponent."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-1989-DF-DISTRIBUTED-RSA-SIGNING-ROOT","keywords":["foundations","threshold","rsa","secret-sharing","rsa_function_sharing","round_efficient_robust_signing","capability_result"],"limitations":["Later work strengthens robustness and share verification."],"paper_id":"TSIG-PAPER-1989-DF","qualifiers":["RSA-style threshold operation in the paper's model."],"source_locator":{"dossier_section":"TSIG-PAPER-1989-DF § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://doi.org/10.1007/0-387-34805-0_28","status":"not_normalized"},"statement":"The threshold-cryptosystem framework distributes RSA-style private exponentiation across multiple servers.","statement_status":"source_normalized_statement","status":"published","title":"Distributed RSA signing from exponent shares","work_id":"TSIG-PAPER-1989-DF"},"primaryUrl":"https://doi.org/10.1007/0-387-34805-0_28","sections":[],"status":"published","subtitle":"Threshold Cryptosystems","summary":"The threshold-cryptosystem framework distributes RSA-style private exponentiation across multiple servers.","title":"Distributed RSA signing from exponent shares","type":"result","venue":"CRYPTO 1989","year":1989,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-1989-DF-DISTRIBUTED-RSA-SIGNING-ROOT"},{"evidence":"bibliographic_checked","id":"TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM","keywords":["atomic-result","foundations","threshold","rsa","secret-sharing","threshold_foundations","definition"],"metadata":{"claim_slug":"threshold-cryptosystem-paradigm","contribution_kind":"definition","dossier_type":"contribution","evidence":"bibliographic_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":[],"technical_thread":["threshold_foundations"]},"historical_context":{"narrative":"Centralized signing made one private key holder a single compromise and availability point. Desmedt and Frankel recast the private operation as a quorum service: parties hold shares, and only an authorized subset can jointly produce the result. Their work established the threshold-cryptosystem interface and an early distributed RSA line, but it preceded the richer robustness and composability contracts developed by later protocols. The foundational node captures the new service boundary: a quorum performs one private-key function without reconstructing the secret at a single participant. Exact resilience and active-security guarantees remain construction-specific.","prior_boundary":"Public-key signatures assumed one signing key holder, so compromise or unavailability of that holder was a single point of failure.","significance_at_publication":"The threshold-cryptosystem abstraction made distributed private-key operations a cryptographic interface and established the RSA-signing root later robustness work refined.","technical_delta":"The paper separated a cryptographic service from any single secret-key holder and made the quorum threshold part of the primitive's interface."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM","keywords":["foundations","threshold","rsa","secret-sharing","threshold_foundations","definition"],"limitations":["Does not supply the later modern robustness contract for all threshold signatures."],"paper_id":"TSIG-PAPER-1989-DF","qualifiers":["Foundational paradigm; exact corruption and robustness guarantees are construction-specific."],"source_locator":{"dossier_section":"TSIG-PAPER-1989-DF § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://doi.org/10.1007/0-387-34805-0_28","status":"not_normalized"},"statement":"Desmedt and Frankel formulate threshold cryptosystems in which a quorum jointly performs a private-key operation without reconstructing the full secret at one party.","statement_status":"source_normalized_statement","status":"published","title":"Threshold cryptosystems distribute one private-key operation","work_id":"TSIG-PAPER-1989-DF"},"primaryUrl":"https://doi.org/10.1007/0-387-34805-0_28","sections":[],"status":"published","subtitle":"Threshold Cryptosystems","summary":"Desmedt and Frankel formulate threshold cryptosystems in which a quorum jointly performs a private-key operation without reconstructing the full secret at one party.","title":"Threshold cryptosystems distribute one private-key operation","type":"result","venue":"CRYPTO 1989","year":1989,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM"},{"evidence":"bibliographic_checked","id":"TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER","keywords":["atomic-result","dkg","discrete-log","verifiable-secret-sharing","foundations","threshold_foundations","dealerless_setup","mechanism"],"metadata":{"claim_slug":"distributed-key-generation-without-dealer","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"bibliographic_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["dealerless_setup"],"technical_thread":["threshold_foundations"]},"historical_context":{"narrative":"Threshold signing could distribute an existing secret while still trusting one dealer to create and share it. Pedersen moved that trust boundary into a protocol among the participants themselves. By combining verifiable polynomial contributions, the parties obtained shares of a discrete-log secret and a common public key without any one party learning the full exponent. This became a reusable setup layer for many later threshold systems. The mapped contribution is dealerless generation of a shared discrete-log key, not a complete signing protocol. The present evidence remains bibliographic-level, so later attack refinements and exact robustness bounds are not inferred here.","prior_boundary":"Early threshold systems could distribute signing after a dealer generated and shared the secret, leaving setup itself as a trusted single point.","significance_at_publication":"Dealerless distributed key generation made the shared public key emerge from participant contributions and became a reusable setup layer for discrete-log threshold signatures.","technical_delta":"Participant-generated polynomial shares removed the dealer from the key-generation trust boundary."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER","keywords":["dkg","discrete-log","verifiable-secret-sharing","foundations","threshold_foundations","dealerless_setup","mechanism"],"limitations":["This bibliographically reviewed card does not normalize all later DKG attack and repair details."],"paper_id":"TSIG-PAPER-1991-PEDERSEN","qualifiers":["Discrete-log key generation; robustness depends on the exact protocol model."],"source_locator":{"dossier_section":"TSIG-PAPER-1991-PEDERSEN § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://doi.org/10.1007/3-540-46416-6_47","status":"not_normalized"},"statement":"Pedersen gives a protocol in which participants jointly generate a discrete-log public key and shares of its secret without a trusted dealer.","statement_status":"source_normalized_statement","status":"published","title":"Dealerless distributed generation of discrete-log keys","work_id":"TSIG-PAPER-1991-PEDERSEN"},"primaryUrl":"https://doi.org/10.1007/3-540-46416-6_47","sections":[],"status":"published","subtitle":"A Threshold Cryptosystem without a Trusted Party","summary":"Pedersen gives a protocol in which participants jointly generate a discrete-log public key and shares of its secret without a trusted dealer.","title":"Dealerless distributed generation of discrete-log keys","type":"result","venue":"EUROCRYPT 1991","year":1991,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-1996-GJKR-DSS-ROBUST-THRESHOLD-DSS","keywords":["atomic-result","dss","discrete-log","robustness","malicious-security","threshold_foundations","round_efficient_robust_signing","construction"],"metadata":{"claim_slug":"robust-threshold-dss","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["threshold_foundations"]},"historical_context":{"narrative":"The algebra of DSS made threshold signing more involved than merely sharing an RSA exponent: nonce inversion and multiplication had to be coordinated without exposing either nonce or key. Gennaro, Jarecki, Krawczyk, and Rabin constructed a robust protocol under an honest-majority-style bound whose output remained an ordinary DSS signature. The result opened a separate threshold line for nonlinear signing equations. The atomic construction distributes DSS's nonlinear signing equation and handles malformed behavior under the paper's precise party threshold. It does not provide a generic threshold compiler for unrelated signatures.","prior_boundary":"Thresholding RSA did not directly solve DSS signing, whose inverse and multiplicative nonce terms require coordinated computation under malicious faults.","significance_at_publication":"The work established a robust threshold DSS construction with ordinary DSS output, opening a distinct algebraic protocol line.","technical_delta":"The protocol distributed the nonlinear DSS signing equation and incorporated checks against malformed participant behavior."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-1996-GJKR-DSS-ROBUST-THRESHOLD-DSS","keywords":["dss","discrete-log","robustness","malicious-security","threshold_foundations","round_efficient_robust_signing","construction"],"limitations":["The result is not a general compiler for arbitrary base signatures."],"paper_id":"TSIG-PAPER-1996-GJKR-DSS","qualifiers":["Exact party and fault thresholds follow the cited construction."],"source_locator":{"dossier_section":"TSIG-PAPER-1996-GJKR-DSS § Atomic claims and Evidence locator","primary_source":"Proceedings paper and journal abstract; exact fault bounds are kept distinct in the construction card.","primary_source_url":"https://doi.org/10.1007/3-540-68339-9_31","status":"section_checked"},"statement":"GJKR constructs threshold DSS signing for an honest-majority-style resilience bound while producing signatures accepted by ordinary DSS verification.","statement_status":"source_normalized_statement","status":"published","title":"Robust threshold DSS with ordinary DSS output","work_id":"TSIG-PAPER-1996-GJKR-DSS"},"primaryUrl":"https://doi.org/10.1007/3-540-68339-9_31","sections":[],"status":"published","subtitle":"Robust Threshold DSS Signatures","summary":"GJKR constructs threshold DSS signing for an honest-majority-style resilience bound while producing signatures accepted by ordinary DSS verification.","title":"Robust threshold DSS with ordinary DSS output","type":"result","venue":"EUROCRYPT 1996","year":1996,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-1996-GJKR-DSS-ROBUST-THRESHOLD-DSS"},{"evidence":"bibliographic_checked","id":"TSIG-RESULT-1996-GJKR-RSA-ROBUST-THRESHOLD-RSA-FUNCTION-SHARING","keywords":["atomic-result","rsa","threshold","robustness","function-sharing","rsa_function_sharing","round_efficient_robust_signing","construction"],"metadata":{"claim_slug":"robust-threshold-rsa-function-sharing","contribution_kind":"construction","dossier_type":"contribution","evidence":"bibliographic_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["rsa_function_sharing"]},"historical_context":{"narrative":"Early distributed RSA demonstrated the threshold idea but left malicious shares and disrupted executions as major operational concerns. Gennaro, Jarecki, Krawczyk, and Rabin strengthened the RSA branch with verifiable function sharing and robustness machinery. Their construction became the relevant active-adversary baseline for Shoup's later simplification, while retaining setup and protocol costs that kept practical threshold RSA an open engineering target. This node records robust, verifiable sharing of the RSA function. Its source is still bibliographic-level in the dossier, so it remains reviewed-related until theorem and page locators are normalized.","prior_boundary":"The original threshold-RSA paradigm distributed exponentiation but left stronger robustness and verifiable-share handling as protocol concerns.","significance_at_publication":"GJKR supplied robust RSA function sharing, giving later threshold-RSA work a concrete malicious-behavior baseline to simplify.","technical_delta":"The construction added malicious-share handling to the distributed RSA line."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-1996-GJKR-RSA-ROBUST-THRESHOLD-RSA-FUNCTION-SHARING","keywords":["rsa","threshold","robustness","function-sharing","rsa_function_sharing","round_efficient_robust_signing","construction"],"limitations":["Later Shoup protocols target a simpler practical signing path."],"paper_id":"TSIG-PAPER-1996-GJKR-RSA","qualifiers":["RSA function sharing under the paper's setup and resilience conditions."],"source_locator":{"dossier_section":"TSIG-PAPER-1996-GJKR-RSA § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://doi.org/10.1007/3-540-68697-5","status":"not_normalized"},"statement":"GJKR develops verifiable, robust sharing of RSA private operations for threshold signing and decryption.","statement_status":"source_normalized_statement","status":"published","title":"Robust sharing of RSA signing functions","work_id":"TSIG-PAPER-1996-GJKR-RSA"},"primaryUrl":"https://doi.org/10.1007/3-540-68697-5","sections":[],"status":"published","subtitle":"Robust and Efficient Sharing of RSA Functions","summary":"GJKR develops verifiable, robust sharing of RSA private operations for threshold signing and decryption.","title":"Robust sharing of RSA signing functions","type":"result","venue":"CRYPTO 1996","year":1996,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-1996-GJKR-RSA-ROBUST-THRESHOLD-RSA-FUNCTION-SHARING"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-1999-GJKR-DKG-MALICIOUS-MINORITY-SECURITY","keywords":["atomic-result","dkg","discrete-log","malicious-security","robustness","threshold_foundations","malicious_robustness_and_blame","security_result"],"metadata":{"claim_slug":"malicious-minority-security","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["malicious_robustness_and_blame"],"technical_thread":["threshold_foundations"]},"historical_context":{"narrative":"Dealerless discrete-log key generation removed a trusted setup party, but a malicious minority could still try to bias the key, distribute inconsistent shares, or prevent honest users from agreeing. The GJKR treatment made those threats explicit and provided a robust protocol under a stated corruption threshold. It separated secure key creation from the signing algorithm and turned DKG into an independently auditable cryptographic component. The companion security node isolates the malicious-minority guarantee and its model. Separating it from the protocol prevents “robust DKG” from hiding the exact corruption threshold and assumptions.","prior_boundary":"Dealerless discrete-log key generation existed, but malicious participants could disrupt consistency or bias the resulting distributed key without a robust treatment.","significance_at_publication":"The protocol strengthened DKG against a malicious minority and clarified the adversarial conditions under which a usable shared key is produced.","technical_delta":"The proof turned dealerless setup into an adversarially analyzed component rather than an honest-execution procedure."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-1999-GJKR-DKG-MALICIOUS-MINORITY-SECURITY","keywords":["dkg","discrete-log","malicious-security","robustness","threshold_foundations","malicious_robustness_and_blame","security_result"],"limitations":["Does not establish adaptive security for every protocol composed with the DKG."],"paper_id":"TSIG-PAPER-1999-GJKR-DKG","qualifiers":["Security holds under the paper's exact corruption threshold and model."],"source_locator":{"dossier_section":"TSIG-PAPER-1999-GJKR-DKG § Atomic claims and Evidence locator","primary_source":"Proceedings paper, abstract, model, and protocol sections.","primary_source_url":"https://doi.org/10.1007/3-540-48910-X_21","status":"section_checked"},"statement":"The GJKR analysis specifies when malicious participants cannot bias or make inconsistent the jointly generated discrete-log key.","statement_status":"source_normalized_statement","status":"published","title":"Malicious-minority security for discrete-log DKG","work_id":"TSIG-PAPER-1999-GJKR-DKG"},"primaryUrl":"https://doi.org/10.1007/3-540-48910-X_21","sections":[],"status":"published","subtitle":"Secure Distributed Key Generation for Discrete-Log Based Cryptosystems","summary":"The GJKR analysis specifies when malicious participants cannot bias or make inconsistent the jointly generated discrete-log key.","title":"Malicious-minority security for discrete-log DKG","type":"result","venue":"EUROCRYPT 1999","year":1999,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-1999-GJKR-DKG-MALICIOUS-MINORITY-SECURITY"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-1999-GJKR-DKG-ROBUST-DISCRETE-LOG-DKG","keywords":["atomic-result","dkg","discrete-log","malicious-security","robustness","threshold_foundations","dealerless_setup","malicious_robustness_and_blame","mechanism"],"metadata":{"claim_slug":"robust-discrete-log-dkg","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["dealerless_setup","malicious_robustness_and_blame"],"technical_thread":["threshold_foundations"]},"historical_context":{"narrative":"Dealerless discrete-log key generation removed a trusted setup party, but a malicious minority could still try to bias the key, distribute inconsistent shares, or prevent honest users from agreeing. The GJKR treatment made those threats explicit and provided a robust protocol under a stated corruption threshold. It separated secure key creation from the signing algorithm and turned DKG into an independently auditable cryptographic component. One contribution is the robust DKG protocol that produces a consistent public key and compatible shares despite bounded faults. It is setup infrastructure and does not independently prove a composed signature secure.","prior_boundary":"Dealerless discrete-log key generation existed, but malicious participants could disrupt consistency or bias the resulting distributed key without a robust treatment.","significance_at_publication":"The protocol strengthened DKG against a malicious minority and clarified the adversarial conditions under which a usable shared key is produced.","technical_delta":"The protocol repaired the operational robustness boundary of dealerless key generation."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-1999-GJKR-DKG-ROBUST-DISCRETE-LOG-DKG","keywords":["dkg","discrete-log","malicious-security","robustness","threshold_foundations","dealerless_setup","malicious_robustness_and_blame","mechanism"],"limitations":["It is a setup component, not a complete threshold-signature protocol."],"paper_id":"TSIG-PAPER-1999-GJKR-DKG","qualifiers":["Adversarial threshold and synchrony conditions are part of the result."],"source_locator":{"dossier_section":"TSIG-PAPER-1999-GJKR-DKG § Atomic claims and Evidence locator","primary_source":"Proceedings paper, abstract, model, and protocol sections.","primary_source_url":"https://doi.org/10.1007/3-540-48910-X_21","status":"section_checked"},"statement":"GJKR gives a distributed key-generation protocol that produces a consistent discrete-log public key despite a bounded malicious minority.","statement_status":"source_normalized_statement","status":"published","title":"Robust distributed key generation for discrete-log systems","work_id":"TSIG-PAPER-1999-GJKR-DKG"},"primaryUrl":"https://doi.org/10.1007/3-540-48910-X_21","sections":[],"status":"published","subtitle":"Secure Distributed Key Generation for Discrete-Log Based Cryptosystems","summary":"GJKR gives a distributed key-generation protocol that produces a consistent discrete-log public key despite a bounded malicious minority.","title":"Robust distributed key generation for discrete-log systems","type":"result","venue":"EUROCRYPT 1999","year":1999,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-1999-GJKR-DKG-ROBUST-DISCRETE-LOG-DKG"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2000-SHOUP-NONINTERACTIVE-SHARE-GENERATION","keywords":["atomic-result","rsa","threshold","robustness","practical","rsa_function_sharing","round_efficient_robust_signing","optimization"],"metadata":{"claim_slug":"noninteractive-share-generation","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["rsa_function_sharing"]},"historical_context":{"narrative":"Robust RSA function sharing existed before Shoup, yet its interaction and machinery limited the appeal of replacing a centralized signer. Shoup reorganized the online path so each server could generate a publicly checkable share without talking to the other servers, leaving a combiner to verify and assemble the ordinary RSA result. This supplied a concrete threshold-RSA design with a much cleaner signing interface. The optimization record concerns only the post-setup signing phase: servers emit shares independently for public checking and combination. Key generation and initial distribution remain separate interactive obligations.","prior_boundary":"Robust threshold RSA constructions carried significant interaction and machinery, limiting their appeal as a practical replacement for centralized RSA signing.","significance_at_publication":"Shoup made signature-share production noninteractive and publicly checkable, giving robust threshold RSA a concrete, operationally sharper design point.","technical_delta":"The online protocol removed inter-server interaction from share generation and exposed invalid shares to the combiner."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2000-SHOUP-NONINTERACTIVE-SHARE-GENERATION","keywords":["rsa","threshold","robustness","practical","rsa_function_sharing","round_efficient_robust_signing","optimization"],"limitations":["Setup and key generation remain separate protocol obligations."],"paper_id":"TSIG-PAPER-2000-SHOUP","qualifiers":["Noninteraction is for the signing-share phase after setup."],"source_locator":{"dossier_section":"TSIG-PAPER-2000-SHOUP § Atomic claims and Evidence locator","primary_source":"Abstract and Sections 1-4 of the proceedings paper.","primary_source_url":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","status":"section_checked"},"statement":"After setup, each Shoup signing server independently produces a signature share that a combiner can verify and combine without an interactive signing round among servers.","statement_status":"source_normalized_statement","status":"published","title":"Noninteractive generation and verification of RSA signature shares","work_id":"TSIG-PAPER-2000-SHOUP"},"primaryUrl":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","sections":[],"status":"published","subtitle":"Practical Threshold Signatures","summary":"After setup, each Shoup signing server independently produces a signature share that a combiner can verify and combine without an interactive signing round among servers.","title":"Noninteractive generation and verification of RSA signature shares","type":"result","venue":"EUROCRYPT 2000","year":2000,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2000-SHOUP-NONINTERACTIVE-SHARE-GENERATION"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA","keywords":["atomic-result","rsa","threshold","robustness","practical","rsa_function_sharing","round_efficient_robust_signing","malicious_robustness_and_blame","construction"],"metadata":{"claim_slug":"practical-robust-threshold-rsa","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing","malicious_robustness_and_blame"],"technical_thread":["rsa_function_sharing"]},"historical_context":{"narrative":"Robust RSA function sharing existed before Shoup, yet its interaction and machinery limited the appeal of replacing a centralized signer. Shoup reorganized the online path so each server could generate a publicly checkable share without talking to the other servers, leaving a combiner to verify and assemble the ordinary RSA result. This supplied a concrete threshold-RSA design with a much cleaner signing interface. The construction record captures the complete robust threshold-RSA signature and its standard output. Compatibility remains tied to the exact RSA signature relation and setup assumed by the paper.","prior_boundary":"Robust threshold RSA constructions carried significant interaction and machinery, limiting their appeal as a practical replacement for centralized RSA signing.","significance_at_publication":"Shoup made signature-share production noninteractive and publicly checkable, giving robust threshold RSA a concrete, operationally sharper design point.","technical_delta":"The design simplified earlier robust RSA sharing into a practical signing protocol with a direct combiner path."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA","keywords":["rsa","threshold","robustness","practical","rsa_function_sharing","round_efficient_robust_signing","malicious_robustness_and_blame","construction"],"limitations":["Ordinary RSA output does not imply compatibility with every RSA encoding profile."],"paper_id":"TSIG-PAPER-2000-SHOUP","qualifiers":["RSA-based threshold signing and the paper's setup model."],"source_locator":{"dossier_section":"TSIG-PAPER-2000-SHOUP § Atomic claims and Evidence locator","primary_source":"Abstract and Sections 1-4 of the proceedings paper.","primary_source_url":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","status":"section_checked"},"statement":"Shoup constructs robust threshold RSA signing with publicly verifiable shares and ordinary RSA signature output.","statement_status":"source_normalized_statement","status":"published","title":"Robust threshold RSA with publicly verifiable shares","work_id":"TSIG-PAPER-2000-SHOUP"},"primaryUrl":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","sections":[],"status":"published","subtitle":"Practical Threshold Signatures","summary":"Shoup constructs robust threshold RSA signing with publicly verifiable shares and ordinary RSA signature output.","title":"Robust threshold RSA with publicly verifiable shares","type":"result","venue":"EUROCRYPT 2000","year":2000,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2003-BOLDYREVA-THRESHOLD-BLS-SIGNATURE","keywords":["atomic-result","pairing","gap-diffie-hellman","bls","threshold","compact-output","pairing_threshold_signatures","round_efficient_robust_signing","interoperable_output_and_evaluation","construction"],"metadata":{"claim_slug":"threshold-bls-signature","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing","interoperable_output_and_evaluation"],"technical_thread":["pairing_threshold_signatures"]},"historical_context":{"narrative":"Threshold RSA had shown that a quorum could preserve an ordinary signature interface, but BLS offered a different algebraic opportunity through its linear signing exponent. Boldyreva shared that exponent and let participants produce partial signatures that a combiner assembles without reconstructing the secret. This record captures the distributed signing mechanism itself. A companion contribution records the unique one-group-element output and ordinary BLS verification interface, keeping construction and output capability distinct. The scheme inherits the base pairing and security setting and does not address independent-key rogue-key attacks, which belong to multisignatures rather than this shared-key threshold model.","prior_boundary":"Threshold RSA produced ordinary signatures but not the one-group-element uniqueness and compactness offered by the emerging BLS signature.","significance_at_publication":"The work showed that BLS's linear exponent structure admits a direct threshold construction without reconstructing the secret key.","technical_delta":"The construction turned the BLS signing exponent into verifiable partial exponentiations that a quorum could combine."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2003-BOLDYREVA-THRESHOLD-BLS-SIGNATURE","keywords":["pairing","gap-diffie-hellman","bls","threshold","compact-output","pairing_threshold_signatures","round_efficient_robust_signing","interoperable_output_and_evaluation","construction"],"limitations":["The construction does not cover rogue-key multisignatures without their separate defenses."],"paper_id":"TSIG-PAPER-2003-BOLDYREVA","qualifiers":["Pairing-group and base BLS security setting."],"source_locator":{"dossier_section":"TSIG-PAPER-2003-BOLDYREVA § Atomic claims and Evidence locator","primary_source":"ePrint 2002/118, abstract and threshold-signature section.","primary_source_url":"https://eprint.iacr.org/2002/118","status":"section_checked"},"statement":"Boldyreva distributes the BLS secret exponent so a quorum can produce and combine partial signatures without reconstructing the signing key.","statement_status":"source_normalized_statement","status":"published","title":"Exponent-share threshold BLS signing","work_id":"TSIG-PAPER-2003-BOLDYREVA"},"primaryUrl":"https://eprint.iacr.org/2002/118","sections":[],"status":"published","subtitle":"Threshold Signatures, Multisignatures and Blind Signatures Based on the Gap-Diffie-Hellman-Group Signature Scheme","summary":"Boldyreva distributes the BLS secret exponent so a quorum can produce and combine partial signatures without reconstructing the signing key.","title":"Exponent-share threshold BLS signing","type":"result","venue":"PKC 2003","year":2003,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2003-BOLDYREVA-THRESHOLD-BLS-SIGNATURE"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2003-BOLDYREVA-UNIQUE-COMPACT-OUTPUT","keywords":["atomic-result","pairing","gap-diffie-hellman","bls","threshold","compact-output","pairing_threshold_signatures","interoperable_output_and_evaluation","capability_result"],"metadata":{"claim_slug":"unique-compact-output","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["interoperable_output_and_evaluation"],"technical_thread":["pairing_threshold_signatures"]},"historical_context":{"narrative":"Threshold RSA preserved an ordinary-verifier interface, but the emerging BLS signature offered a uniquely compact one-group-element result with especially simple exponent linearity. Boldyreva distributed that signing exponent across a quorum and retained the base verifier after combination. The construction showed directly that thresholdization need not enlarge or specialize the final signature. This capability record isolates preservation of a unique one-element result accepted by ordinary BLS verification, while its companion card carries the distributed signing mechanism. The output property is specific to the base scheme and cannot be generalized to all threshold signatures.","prior_boundary":"Threshold RSA produced ordinary signatures but not the one-group-element uniqueness and compactness offered by the emerging BLS signature.","significance_at_publication":"Threshold BLS preserved the base signature's unique compact output after share combination, showing how a concise ordinary-verifier interface could survive thresholdization.","technical_delta":"Thresholdization preserved both uniqueness and compact output instead of introducing a threshold-specific proof object."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2003-BOLDYREVA-UNIQUE-COMPACT-OUTPUT","keywords":["pairing","gap-diffie-hellman","bls","threshold","compact-output","pairing_threshold_signatures","interoperable_output_and_evaluation","capability_result"],"limitations":["Uniqueness is not a generic property of all threshold signatures."],"paper_id":"TSIG-PAPER-2003-BOLDYREVA","qualifiers":["Output compatibility is with the exact BLS/GDH scheme."],"source_locator":{"dossier_section":"TSIG-PAPER-2003-BOLDYREVA § Atomic claims and Evidence locator","primary_source":"ePrint 2002/118, abstract and threshold-signature section.","primary_source_url":"https://eprint.iacr.org/2002/118","status":"section_checked"},"statement":"Combining valid threshold BLS shares yields a unique one-group-element signature with the ordinary BLS verification interface.","statement_status":"source_normalized_statement","status":"published","title":"Unique compact threshold output compatible with BLS verification","work_id":"TSIG-PAPER-2003-BOLDYREVA"},"primaryUrl":"https://eprint.iacr.org/2002/118","sections":[],"status":"published","subtitle":"Threshold Signatures, Multisignatures and Blind Signatures Based on the Gap-Diffie-Hellman-Group Signature Scheme","summary":"Combining valid threshold BLS shares yields a unique one-group-element signature with the ordinary BLS verification interface.","title":"Unique compact threshold output compatible with BLS verification","type":"result","venue":"PKC 2003","year":2003,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2003-BOLDYREVA-UNIQUE-COMPACT-OUTPUT"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2017-LINDELL-EFFICIENT-TWO-PARTY-ECDSA","keywords":["atomic-result","ecdsa","two-party","paillier","malicious-security","ecdsa_paillier","round_efficient_robust_signing","construction"],"metadata":{"claim_slug":"efficient-two-party-ecdsa","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["ecdsa_paillier"]},"historical_context":{"narrative":"ECDSA resists straightforward thresholdization because its signing equation combines a secret key, a fresh nonce, multiplication, and inversion. Lindell used Paillier-style homomorphic computation and zero-knowledge checks to realize a fast two-party protocol secure against malicious behavior. Producing an ordinary ECDSA signature made the work immediately relevant to existing verifiers and established a practical baseline for subsequent multiparty protocols. The main construction node records efficient two-party signing with standard-verifier output. It does not extend directly to arbitrary quorums, which required later protocols.","prior_boundary":"ECDSA's multiplicative inverse and nonce structure made maliciously secure two-party signing much less direct than threshold Schnorr or RSA.","significance_at_publication":"Lindell provided an efficient two-party protocol with standard ECDSA output, establishing a practical Paillier-based baseline for later multiparty and UC-secure work.","technical_delta":"Paillier-style multiplication and zero-knowledge checks made malicious two-party ECDSA practical."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2017-LINDELL-EFFICIENT-TWO-PARTY-ECDSA","keywords":["ecdsa","two-party","paillier","malicious-security","ecdsa_paillier","round_efficient_robust_signing","construction"],"limitations":["The protocol is not a general t-out-of-n construction."],"paper_id":"TSIG-PAPER-2017-LINDELL","qualifiers":["Two-party setting and the paper's preprocessing/setup assumptions."],"source_locator":{"dossier_section":"TSIG-PAPER-2017-LINDELL § Atomic claims and Evidence locator","primary_source":"ePrint 2017/552, abstract and protocol overview.","primary_source_url":"https://eprint.iacr.org/2017/552","status":"section_checked"},"statement":"Lindell gives a Paillier-based two-party protocol that jointly computes a standard ECDSA signature without reconstructing the signing key.","statement_status":"source_normalized_statement","status":"published","title":"Paillier-based two-party ECDSA with standard verifier output","work_id":"TSIG-PAPER-2017-LINDELL"},"primaryUrl":"https://eprint.iacr.org/2017/552","sections":[],"status":"published","subtitle":"Fast Secure Two-Party ECDSA Signing","summary":"Lindell gives a Paillier-based two-party protocol that jointly computes a standard ECDSA signature without reconstructing the signing key.","title":"Paillier-based two-party ECDSA with standard verifier output","type":"result","venue":"CRYPTO 2017","year":2017,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2017-LINDELL-EFFICIENT-TWO-PARTY-ECDSA"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2017-LINDELL-MALICIOUS-SECURITY","keywords":["atomic-result","ecdsa","two-party","paillier","malicious-security","ecdsa_paillier","malicious_robustness_and_blame","security_result"],"metadata":{"claim_slug":"malicious-security","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["malicious_robustness_and_blame"],"technical_thread":["ecdsa_paillier"]},"historical_context":{"narrative":"ECDSA resists straightforward thresholdization because its signing equation combines a secret key, a fresh nonce, multiplication, and inversion. Lindell used Paillier-style homomorphic computation and zero-knowledge checks to realize a fast two-party protocol secure against malicious behavior. Producing an ordinary ECDSA signature made the work immediately relevant to existing verifiers and established a practical baseline for subsequent multiparty protocols. A separate node captures the protocol's protection against one malicious participant in its stated model. UC composition, proactive refresh, and adaptive corruption are not part of this claim.","prior_boundary":"ECDSA's multiplicative inverse and nonce structure made maliciously secure two-party signing much less direct than threshold Schnorr or RSA.","significance_at_publication":"Lindell provided an efficient two-party protocol with standard ECDSA output, establishing a practical Paillier-based baseline for later multiparty and UC-secure work.","technical_delta":"The security treatment strengthened earlier efficient semi-honest two-party signing points without changing the ordinary ECDSA output."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2017-LINDELL-MALICIOUS-SECURITY","keywords":["ecdsa","two-party","paillier","malicious-security","ecdsa_paillier","malicious_robustness_and_blame","security_result"],"limitations":["This does not imply UC, proactive, or fully adaptive security."],"paper_id":"TSIG-PAPER-2017-LINDELL","qualifiers":["Static malicious security in the paper's specified model."],"source_locator":{"dossier_section":"TSIG-PAPER-2017-LINDELL § Atomic claims and Evidence locator","primary_source":"ePrint 2017/552, abstract and protocol overview.","primary_source_url":"https://eprint.iacr.org/2017/552","status":"section_checked"},"statement":"The two-party ECDSA protocol includes proofs and checks intended to preserve security when one participant deviates maliciously.","statement_status":"source_normalized_statement","status":"published","title":"Malicious security for Lindell's Paillier-based two-party ECDSA","work_id":"TSIG-PAPER-2017-LINDELL"},"primaryUrl":"https://eprint.iacr.org/2017/552","sections":[],"status":"published","subtitle":"Fast Secure Two-Party ECDSA Signing","summary":"The two-party ECDSA protocol includes proofs and checks intended to preserve security when one participant deviates maliciously.","title":"Malicious security for Lindell's Paillier-based two-party ECDSA","type":"result","venue":"CRYPTO 2017","year":2017,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2017-LINDELL-MALICIOUS-SECURITY"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2018-DKLS-2P-HASH-PROOF-SYSTEM-ROUTE","keywords":["atomic-result","ecdsa","two-party","oblivious-transfer","hash-proof-system","ecdsa_ot_hps","round_efficient_robust_signing","mechanism"],"metadata":{"claim_slug":"hash-proof-system-route","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["ecdsa_ot_hps"]},"historical_context":{"narrative":"Efficient two-party ECDSA had converged on Paillier encryption and accompanying range-proof machinery. Doerner, Kondi, Lee, and shelat developed a different route based on hash-proof systems and oblivious transfer. Their protocol preserved standard ECDSA output while changing the setup, assumptions, and dominant correlated computation, demonstrating that Paillier was a design choice rather than an inherent requirement of distributed ECDSA. The mechanism node isolates the hash-proof machinery that implements ECDSA's correlated multiplication. It is a reusable protocol component, not a complete threshold signature on its own.","prior_boundary":"Practical two-party ECDSA primarily used Paillier-style homomorphic multiplication and associated range-proof machinery.","significance_at_publication":"DKLS introduced a hash-proof-system and oblivious-transfer route, showing that standard ECDSA output did not require the Paillier design point.","technical_delta":"The reusable mechanism replaced the dominant Paillier multiplication pattern with an HPS-based protocol path."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2018-DKLS-2P-HASH-PROOF-SYSTEM-ROUTE","keywords":["ecdsa","two-party","oblivious-transfer","hash-proof-system","ecdsa_ot_hps","round_efficient_robust_signing","mechanism"],"limitations":["The component alone is not a complete threshold ECDSA scheme."],"paper_id":"TSIG-PAPER-2018-DKLS-2P","qualifiers":["Security and efficiency depend on the selected HPS instantiation."],"source_locator":{"dossier_section":"TSIG-PAPER-2018-DKLS-2P § Atomic claims and Evidence locator","primary_source":"ePrint 2018/499, abstract and construction overview.","primary_source_url":"https://eprint.iacr.org/2018/499","status":"section_checked"},"statement":"DKLS uses smooth projective hash or hash-proof-system machinery to realize the correlated computations needed for two-party ECDSA.","statement_status":"source_normalized_statement","status":"published","title":"Hash-proof systems implement the ECDSA multiplication step","work_id":"TSIG-PAPER-2018-DKLS-2P"},"primaryUrl":"https://eprint.iacr.org/2018/499","sections":[],"status":"published","subtitle":"Two-Party ECDSA from Hash Proof Systems and Efficient Instantiations","summary":"DKLS uses smooth projective hash or hash-proof-system machinery to realize the correlated computations needed for two-party ECDSA.","title":"Hash-proof systems implement the ECDSA multiplication step","type":"result","venue":"CRYPTO 2018","year":2018,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2018-DKLS-2P-HASH-PROOF-SYSTEM-ROUTE"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2018-DKLS-2P-TWO-PARTY-ECDSA-WITHOUT-PAILLIER","keywords":["atomic-result","ecdsa","two-party","oblivious-transfer","hash-proof-system","ecdsa_ot_hps","round_efficient_robust_signing","capability_result"],"metadata":{"claim_slug":"two-party-ecdsa-without-paillier","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["ecdsa_ot_hps"]},"historical_context":{"narrative":"Efficient two-party ECDSA had converged on Paillier encryption and accompanying range-proof machinery. Doerner, Kondi, Lee, and shelat developed a different route based on hash-proof systems and oblivious transfer. Their protocol preserved standard ECDSA output while changing the setup, assumptions, and dominant correlated computation, demonstrating that Paillier was a design choice rather than an inherent requirement of distributed ECDSA. The capability change is Paillier-free two-party ECDSA with unchanged public verification. Avoiding Paillier does not eliminate setup, oblivious transfer, or the paper's own assumption requirements.","prior_boundary":"Practical two-party ECDSA primarily used Paillier-style homomorphic multiplication and associated range-proof machinery.","significance_at_publication":"DKLS introduced a hash-proof-system and oblivious-transfer route, showing that standard ECDSA output did not require the Paillier design point.","technical_delta":"The protocol changed the setup and assumption route while preserving ordinary ECDSA signatures."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2018-DKLS-2P-TWO-PARTY-ECDSA-WITHOUT-PAILLIER","keywords":["ecdsa","two-party","oblivious-transfer","hash-proof-system","ecdsa_ot_hps","round_efficient_robust_signing","capability_result"],"limitations":["Paillier-free does not mean setup-free or assumption-free."],"paper_id":"TSIG-PAPER-2018-DKLS-2P","qualifiers":["Two-party ECDSA and the paper's HPS/OT instantiations."],"source_locator":{"dossier_section":"TSIG-PAPER-2018-DKLS-2P § Atomic claims and Evidence locator","primary_source":"ePrint 2018/499, abstract and construction overview.","primary_source_url":"https://eprint.iacr.org/2018/499","status":"section_checked"},"statement":"DKLS constructs two-party ECDSA from hash-proof-system and oblivious-transfer techniques rather than Paillier-based multiplication.","statement_status":"source_normalized_statement","status":"published","title":"Two-party ECDSA without Paillier homomorphic encryption","work_id":"TSIG-PAPER-2018-DKLS-2P"},"primaryUrl":"https://eprint.iacr.org/2018/499","sections":[],"status":"published","subtitle":"Two-Party ECDSA from Hash Proof Systems and Efficient Instantiations","summary":"DKLS constructs two-party ECDSA from hash-proof-system and oblivious-transfer techniques rather than Paillier-based multiplication.","title":"Two-party ECDSA without Paillier homomorphic encryption","type":"result","venue":"CRYPTO 2018","year":2018,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2018-DKLS-2P-TWO-PARTY-ECDSA-WITHOUT-PAILLIER"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2018-GG-DISTRIBUTED-SETUP","keywords":["atomic-result","ecdsa","multiparty","paillier","dkg","ecdsa_paillier","dealerless_setup","mechanism"],"metadata":{"claim_slug":"distributed-setup","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["dealerless_setup"],"technical_thread":["ecdsa_paillier"]},"historical_context":{"narrative":"Fast maliciously secure ECDSA was strongest in the two-party setting, while larger signing groups faced heavier setup and online coordination. Gennaro and Goldfeder extended the practical Paillier-based line to a multiparty threshold and included a trustless distributed setup. This shifted both the participant model and key-generation boundary without changing what an ordinary ECDSA verifier receives. The companion setup node records joint creation of threshold key material without a trusted dealer. That capability does not yet provide the proactive epoch refresh introduced in later protocols.","prior_boundary":"Efficient maliciously secure ECDSA protocols were strongest in the two-party case, while multiparty setup remained expensive or trusted.","significance_at_publication":"GG18 extended the practical Paillier line to multiparty threshold ECDSA and paired it with a faster trustless setup protocol.","technical_delta":"The setup mechanism moved key generation into the multiparty protocol instead of assuming pre-shared trusted material."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2018-GG-DISTRIBUTED-SETUP","keywords":["ecdsa","multiparty","paillier","dkg","ecdsa_paillier","dealerless_setup","mechanism"],"limitations":["Dealerless setup does not by itself supply proactive refresh."],"paper_id":"TSIG-PAPER-2018-GG","qualifiers":["Setup cost and security follow the paper's Paillier-based construction."],"source_locator":{"dossier_section":"TSIG-PAPER-2018-GG § Atomic claims and Evidence locator","primary_source":"ePrint 2019/114, abstract and introduction.","primary_source_url":"https://eprint.iacr.org/2019/114","status":"section_checked"},"statement":"GG18 includes a distributed setup procedure that creates the threshold ECDSA key material without entrusting the full signing key to one dealer.","statement_status":"source_normalized_statement","status":"published","title":"Dealerless setup for multiparty threshold ECDSA","work_id":"TSIG-PAPER-2018-GG"},"primaryUrl":"https://eprint.iacr.org/2019/114","sections":[],"status":"published","subtitle":"Fast Multiparty Threshold ECDSA with Fast Trustless Setup","summary":"GG18 includes a distributed setup procedure that creates the threshold ECDSA key material without entrusting the full signing key to one dealer.","title":"Dealerless setup for multiparty threshold ECDSA","type":"result","venue":"ACM CCS 2018","year":2018,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2018-GG-DISTRIBUTED-SETUP"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA","keywords":["atomic-result","ecdsa","multiparty","paillier","dkg","ecdsa_paillier","capability_result"],"metadata":{"claim_slug":"multiparty-threshold-ecdsa","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":[],"technical_thread":["ecdsa_paillier"]},"historical_context":{"narrative":"Fast maliciously secure ECDSA was strongest in the two-party setting, while larger signing groups faced heavier setup and online coordination. Gennaro and Goldfeder extended the practical Paillier-based line to a multiparty threshold and included a trustless distributed setup. This shifted both the participant model and key-generation boundary without changing what an ordinary ECDSA verifier receives. The primary contribution is the shift from two parties to a genuine multiparty threshold while preserving ordinary ECDSA output. Later work strengthens composition and failure accountability.","prior_boundary":"Efficient maliciously secure ECDSA protocols were strongest in the two-party case, while multiparty setup remained expensive or trusted.","significance_at_publication":"GG18 extended the practical Paillier line to multiparty threshold ECDSA and paired it with a faster trustless setup protocol.","technical_delta":"The protocol changed the participant and threshold setting of the practical ECDSA line."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA","keywords":["ecdsa","multiparty","paillier","dkg","ecdsa_paillier","capability_result"],"limitations":["The later CGGMP work strengthens composition and abort handling."],"paper_id":"TSIG-PAPER-2018-GG","qualifiers":["Multiparty threshold ECDSA under the paper's corruption bound."],"source_locator":{"dossier_section":"TSIG-PAPER-2018-GG § Atomic claims and Evidence locator","primary_source":"ePrint 2019/114, abstract and introduction.","primary_source_url":"https://eprint.iacr.org/2019/114","status":"section_checked"},"statement":"GG18 extends efficient Paillier-based threshold ECDSA beyond two parties while retaining output accepted by standard ECDSA verification.","statement_status":"source_normalized_statement","status":"published","title":"Multiparty t-out-of-n ECDSA with ordinary signatures","work_id":"TSIG-PAPER-2018-GG"},"primaryUrl":"https://eprint.iacr.org/2019/114","sections":[],"status":"published","subtitle":"Fast Multiparty Threshold ECDSA with Fast Trustless Setup","summary":"GG18 extends efficient Paillier-based threshold ECDSA beyond two parties while retaining output accepted by standard ECDSA verification.","title":"Multiparty t-out-of-n ECDSA with ordinary signatures","type":"result","venue":"ACM CCS 2018","year":2018,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA"},{"evidence":"bibliographic_checked","id":"TSIG-RESULT-2019-DKLS-N-GENERAL-THRESHOLD-ECDSA","keywords":["atomic-result","ecdsa","threshold","oblivious-transfer","multiparty","ecdsa_ot_hps","round_efficient_robust_signing","capability_result"],"metadata":{"claim_slug":"general-threshold-ecdsa","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"bibliographic_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["ecdsa_ot_hps"]},"historical_context":{"narrative":"The Paillier-free DKLS design first handled only two parties, leaving general quorum signing on that assumption route unresolved. Its later threshold construction extended the same broad hash-proof and oblivious-transfer direction to a t-out-of-n setting while retaining ordinary ECDSA output. The record remains bibliographic-level, so exact theorem coordinates and costs are intentionally not promoted beyond that scoped generalization claim. The mapped delta is general-threshold ECDSA on the alternative DKLS route. Because only bibliographic evidence is normalized, no claim of UC, proactive, or comparative performance superiority is attached.","prior_boundary":"The Paillier-free DKLS technique first addressed two-party ECDSA, leaving general t-out-of-n signing as a separate protocol problem.","significance_at_publication":"The later construction generalized that design direction to threshold ECDSA while retaining ordinary ECDSA verification.","technical_delta":"The result changed the participant threshold while retaining the alternative HPS/OT assumption route."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2019-DKLS-N-GENERAL-THRESHOLD-ECDSA","keywords":["ecdsa","threshold","oblivious-transfer","multiparty","ecdsa_ot_hps","round_efficient_robust_signing","capability_result"],"limitations":["This card does not claim the later UC or proactive properties of CGGMP."],"paper_id":"TSIG-PAPER-2019-DKLS-N","qualifiers":["Bibliographically reviewed; exact theorem coordinates remain to be normalized."],"source_locator":{"dossier_section":"TSIG-PAPER-2019-DKLS-N § Atomic claims and Evidence locator","primary_source":"Abstract and main construction or theorem discussion in the linked primary paper.","primary_source_url":"https://doi.org/10.1109/SP.2019.00024","status":"not_normalized"},"statement":"The DKLS line generalizes its two-party techniques to a t-out-of-n threshold ECDSA protocol with standard verifier output.","statement_status":"source_normalized_statement","status":"published","title":"General threshold ECDSA from the Paillier-free DKLS route","work_id":"TSIG-PAPER-2019-DKLS-N"},"primaryUrl":"https://doi.org/10.1109/SP.2019.00024","sections":[],"status":"published","subtitle":"Threshold ECDSA from ECDSA Assumptions","summary":"The DKLS line generalizes its two-party techniques to a t-out-of-n threshold ECDSA protocol with standard verifier output.","title":"General threshold ECDSA from the Paillier-free DKLS route","type":"result","venue":"IEEE Symposium on Security and Privacy 2019","year":2019,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2019-DKLS-N-GENERAL-THRESHOLD-ECDSA"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2020-CGGMP-IDENTIFIABLE-ABORT","keywords":["atomic-result","ecdsa","uc-security","identifiable-abort","proactive","preprocessing","ecdsa_paillier","malicious_robustness_and_blame","attack_or_repair"],"metadata":{"claim_slug":"identifiable-abort","contribution_kind":"attack_or_repair","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["malicious_robustness_and_blame"],"technical_thread":["ecdsa_paillier"]},"historical_context":{"narrative":"Practical multiparty ECDSA protocols still separated several desirable guarantees: composable security, accountable failure, share refresh, and a short online phase. CGGMP brought those features together by moving expensive work into preprocessing and analyzing the result in a UC framework. The protocol retained ordinary ECDSA verification while materially strengthening how applications could reason about aborts and compromise across epochs. The accountability node turns some malicious failures into evidence naming a deviating participant. It does not force an unavailable signer to continue or guarantee liveness after refusal.","prior_boundary":"Multiparty threshold ECDSA had efficient protocols, but stronger composition, proactive refresh, and accountable failure were not integrated into one online-efficient construction.","significance_at_publication":"CGGMP combined UC security, identifiable aborts, proactive security, and preprocessing into a stronger threshold-ECDSA contract.","technical_delta":"The result changed robustness from undifferentiated failure to accountable failure."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2020-CGGMP-IDENTIFIABLE-ABORT","keywords":["ecdsa","uc-security","identifiable-abort","proactive","preprocessing","ecdsa_paillier","malicious_robustness_and_blame","attack_or_repair"],"limitations":["Identifiable abort does not guarantee liveness after a party refuses to participate."],"paper_id":"TSIG-PAPER-2020-CGGMP","qualifiers":["Identification guarantee follows the protocol's exact blame mechanism."],"source_locator":{"dossier_section":"TSIG-PAPER-2020-CGGMP § Atomic claims and Evidence locator","primary_source":"ePrint 2021/060 revised full version, abstract and contribution overview.","primary_source_url":"https://eprint.iacr.org/2021/060","status":"section_checked"},"statement":"When CGGMP signing aborts because of malicious behavior, the protocol provides evidence identifying a misbehaving participant under its model.","statement_status":"source_normalized_statement","status":"published","title":"Identifiable abort for malicious threshold-ECDSA failures","work_id":"TSIG-PAPER-2020-CGGMP"},"primaryUrl":"https://eprint.iacr.org/2021/060","sections":[],"status":"published","subtitle":"UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable Aborts","summary":"When CGGMP signing aborts because of malicious behavior, the protocol provides evidence identifying a misbehaving participant under its model.","title":"Identifiable abort for malicious threshold-ECDSA failures","type":"result","venue":"ACM CCS 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2020-CGGMP-IDENTIFIABLE-ABORT"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2020-CGGMP-ONE-MESSAGE-DEPENDENT-ONLINE-ROUND","keywords":["atomic-result","ecdsa","preprocessing","online-rounds","noninteractive-online","ecdsa_paillier","round_efficient_robust_signing","optimization"],"metadata":{"claim_slug":"one-message-dependent-online-round","contribution_kind":"optimization","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["ecdsa_paillier"]},"historical_context":{"narrative":"Earlier practical threshold-ECDSA protocols required multiple interactions after the message to be signed was known, tying online latency to the full protocol. CGGMP separated those costs by moving every message-independent round into preprocessing. Once that material exists, only the last round depends on the message, so participants need not be online together throughout the expensive preparation. This record isolates the online interaction improvement rather than folding it into the paper's UC theorem. The complete protocols still take four or seven rounds, depending on the accountability tradeoff, and their one-round online description is valid only after the separate preprocessing phase.","prior_boundary":"Practical threshold-ECDSA protocols required several message-dependent interactions, increasing latency and forcing signers to remain online together.","significance_at_publication":"The result made online noninteraction a precisely scoped latency property for threshold ECDSA without pretending that the complete protocol had only one round.","technical_delta":"CGGMP moved every message-independent round into preprocessing so the online signing phase consists of one final message-dependent exchange."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2020-CGGMP-ONE-MESSAGE-DEPENDENT-ONLINE-ROUND","keywords":["ecdsa","preprocessing","online-rounds","noninteractive-online","ecdsa_paillier","round_efficient_robust_signing","optimization"],"limitations":["One online round does not mean one round from setup through signature output."],"paper_id":"TSIG-PAPER-2020-CGGMP","qualifiers":["The online count excludes message-independent preprocessing; the two complete protocols have different total round counts."],"source_locator":{"dossier_section":"TSIG-PAPER-2020-CGGMP § Atomic claims and Evidence locator","primary_source":"ePrint 2021/060 revised full version, abstract and contribution overview.","primary_source_url":"https://eprint.iacr.org/2021/060","status":"section_checked"},"statement":"In both CGGMP protocols, all rounds except the last can be completed before the message is known, leaving one message-dependent online round.","statement_status":"source_normalized_statement","status":"published","title":"One message-dependent online round after CGGMP preprocessing","work_id":"TSIG-PAPER-2020-CGGMP"},"primaryUrl":"https://eprint.iacr.org/2021/060","sections":[],"status":"published","subtitle":"UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable Aborts","summary":"In both CGGMP protocols, all rounds except the last can be completed before the message is known, leaving one message-dependent online round.","title":"One message-dependent online round after CGGMP preprocessing","type":"result","venue":"ACM CCS 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2020-CGGMP-ONE-MESSAGE-DEPENDENT-ONLINE-ROUND"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2020-CGGMP-PROACTIVE-SECURITY","keywords":["atomic-result","ecdsa","uc-security","identifiable-abort","proactive","preprocessing","ecdsa_paillier","proactive_refresh","security_result"],"metadata":{"claim_slug":"proactive-security","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["proactive_refresh"],"technical_thread":["ecdsa_paillier"]},"historical_context":{"narrative":"Practical multiparty ECDSA protocols still separated several desirable guarantees: composable security, accountable failure, share refresh, and a short online phase. CGGMP brought those features together by moving expensive work into preprocessing and analyzing the result in a UC framework. The protocol retained ordinary ECDSA verification while materially strengthening how applications could reason about aborts and compromise across epochs. The proactive node records share renewal across epochs without changing the public verification key. Its benefit depends on the model's epoch separation and erasure assumptions.","prior_boundary":"Multiparty threshold ECDSA had efficient protocols, but stronger composition, proactive refresh, and accountable failure were not integrated into one online-efficient construction.","significance_at_publication":"CGGMP combined UC security, identifiable aborts, proactive security, and preprocessing into a stronger threshold-ECDSA contract.","technical_delta":"The protocol added a time/refresh dimension to the threshold-ECDSA security contract."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2020-CGGMP-PROACTIVE-SECURITY","keywords":["ecdsa","uc-security","identifiable-abort","proactive","preprocessing","ecdsa_paillier","proactive_refresh","security_result"],"limitations":["Refresh does not change the underlying public verification key."],"paper_id":"TSIG-PAPER-2020-CGGMP","qualifiers":["Proactive guarantees depend on the epoch and erasure assumptions in the model."],"source_locator":{"dossier_section":"TSIG-PAPER-2020-CGGMP § Atomic claims and Evidence locator","primary_source":"ePrint 2021/060 revised full version, abstract and contribution overview.","primary_source_url":"https://eprint.iacr.org/2021/060","status":"section_checked"},"statement":"CGGMP supports refreshing distributed key shares so compromise across separated epochs need not accumulate against one static sharing.","statement_status":"source_normalized_statement","status":"published","title":"Proactive refresh for threshold ECDSA key shares","work_id":"TSIG-PAPER-2020-CGGMP"},"primaryUrl":"https://eprint.iacr.org/2021/060","sections":[],"status":"published","subtitle":"UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable Aborts","summary":"CGGMP supports refreshing distributed key shares so compromise across separated epochs need not accumulate against one static sharing.","title":"Proactive refresh for threshold ECDSA key shares","type":"result","venue":"ACM CCS 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2020-CGGMP-PROACTIVE-SECURITY"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2020-CGGMP-UC-THRESHOLD-ECDSA","keywords":["atomic-result","ecdsa","uc-security","identifiable-abort","proactive","preprocessing","ecdsa_paillier","adaptive_corruption_security","proof_models_and_assumptions","security_result"],"metadata":{"claim_slug":"uc-threshold-ecdsa","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["adaptive_corruption_security","proof_models_and_assumptions"],"technical_thread":["ecdsa_paillier"]},"historical_context":{"narrative":"Practical multiparty ECDSA protocols already produced ordinary signatures, but their security contracts did not cover the adaptive UC setting reached by CGGMP. The revised full version analyzes two protocols that realize an ideal threshold-signature functionality in the global random-oracle model while adversarial corruptions may occur adaptively. This record isolates that composability and corruption-timing result. The paper's preprocessing boundary, proactive refresh, and identifiable-abort mechanism are separate contributions rather than evidence for the UC theorem by themselves. The guarantee remains tied to the specified functionalities and to Strong RSA, DDH, Paillier semantic security, and the paper's enhanced ECDSA-unforgeability assumption.","prior_boundary":"Practical multiparty ECDSA protocols existed, but their analyses did not yet provide the same adaptive UC composition contract as the CGGMP constructions.","significance_at_publication":"It made composable, adaptive security an explicit coordinate for practical threshold ECDSA rather than treating malicious security as a single undifferentiated label.","technical_delta":"The work realized an ideal threshold-signature functionality against adaptive corruptions in the global random-oracle model."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2020-CGGMP-UC-THRESHOLD-ECDSA","keywords":["ecdsa","uc-security","identifiable-abort","proactive","preprocessing","ecdsa_paillier","adaptive_corruption_security","proof_models_and_assumptions","security_result"],"limitations":["The claim is not a standard-model reduction from a single ECDSA assumption."],"paper_id":"TSIG-PAPER-2020-CGGMP","qualifiers":["Adaptive UC claim is in the global random-oracle model under Strong RSA, DDH, Paillier semantic security, and the paper's enhanced ECDSA-unforgeability assumption."],"source_locator":{"dossier_section":"TSIG-PAPER-2020-CGGMP § Atomic claims and Evidence locator","primary_source":"ePrint 2021/060 revised full version, abstract and contribution overview.","primary_source_url":"https://eprint.iacr.org/2021/060","status":"section_checked"},"statement":"CGGMP realizes threshold ECDSA in the UC framework against adaptive corruptions in the global random-oracle model under its stated assumptions.","statement_status":"source_normalized_statement","status":"published","title":"Adaptively secure UC threshold ECDSA in the global random-oracle model","work_id":"TSIG-PAPER-2020-CGGMP"},"primaryUrl":"https://eprint.iacr.org/2021/060","sections":[],"status":"published","subtitle":"UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable Aborts","summary":"CGGMP realizes threshold ECDSA in the UC framework against adaptive corruptions in the global random-oracle model under its stated assumptions.","title":"Adaptively secure UC threshold ECDSA in the global random-oracle model","type":"result","venue":"ACM CCS 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2020-CGGMP-UC-THRESHOLD-ECDSA"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2020-FROST-IDENTIFIABLE-MISBEHAVING-PARTICIPANT","keywords":["atomic-result","schnorr","discrete-log","two-round","preprocessing","practical","schnorr_nonce_protocols","malicious_robustness_and_blame","attack_or_repair"],"metadata":{"claim_slug":"identifiable-misbehaving-participant","contribution_kind":"attack_or_repair","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["malicious_robustness_and_blame"],"technical_thread":["schnorr_nonce_protocols"]},"historical_context":{"narrative":"Schnorr's linear response makes it friendlier to threshold execution than ECDSA, yet existing protocols still paid in rounds, rigidity, or preprocessing assumptions. FROST combined nonce commitments, signer-set binding, and response aggregation into a flexible t-out-of-n workflow. The paper presents both a two-round mode and a preprocessed one-online-round mode, with security tied to its stated adversary model. The failure-handling record concerns verification of individual response shares and attribution of an invalid one. It detects malformed contributions but cannot prevent denial of service by absence.","prior_boundary":"Threshold Schnorr protocols either required more signing interaction or specialized participant assumptions despite the base signature's simple linear structure.","significance_at_publication":"FROST delivered a flexible t-out-of-n protocol with two signing rounds and a one-online-round preprocessed mode, becoming a practical Schnorr threshold baseline.","technical_delta":"The protocol made malformed-share failure attributable without changing the ordinary Schnorr output."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2020-FROST-IDENTIFIABLE-MISBEHAVING-PARTICIPANT","keywords":["schnorr","discrete-log","two-round","preprocessing","practical","schnorr_nonce_protocols","malicious_robustness_and_blame","attack_or_repair"],"limitations":["It does not prevent denial of service by absent signers."],"paper_id":"TSIG-PAPER-2020-FROST","qualifiers":["Covers invalid shares under the protocol transcript."],"source_locator":{"dossier_section":"TSIG-PAPER-2020-FROST § Atomic claims and Evidence locator","primary_source":"ePrint 2020/852, Figure 3 step 7.b (PDF p. 15) and Sections 5.2–6.2 (PDF pp. 12–18).","primary_source_url":"https://eprint.iacr.org/2020/852","status":"section_checked"},"statement":"FROST's share verification lets the coordinator detect which participant supplied an invalid signing share.","statement_status":"source_normalized_statement","status":"published","title":"FROST identifies invalid signature-share senders","work_id":"TSIG-PAPER-2020-FROST"},"primaryUrl":"https://eprint.iacr.org/2020/852","sections":[],"status":"published","subtitle":"FROST: Flexible Round-Optimized Schnorr Threshold Signatures","summary":"FROST's share verification lets the coordinator detect which participant supplied an invalid signing share.","title":"FROST identifies invalid signature-share senders","type":"result","venue":"SAC 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2020-FROST-IDENTIFIABLE-MISBEHAVING-PARTICIPANT"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2020-FROST-ONE-ROUND-WITH-PREPROCESSING","keywords":["atomic-result","schnorr","discrete-log","two-round","preprocessing","practical","schnorr_nonce_protocols","round_efficient_robust_signing","optimization"],"metadata":{"claim_slug":"one-round-with-preprocessing","contribution_kind":"optimization","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["schnorr_nonce_protocols"]},"historical_context":{"narrative":"Schnorr's linear response makes it friendlier to threshold execution than ECDSA, yet existing protocols still paid in rounds, rigidity, or preprocessing assumptions. FROST combined nonce commitments, signer-set binding, and response aggregation into a flexible t-out-of-n workflow. The paper presents both a two-round mode and a preprocessed one-online-round mode, with security tied to its stated adversary model. The optimization moves nonce commitments before the message-dependent phase, leaving one online round. Counting the preprocessing makes clear that this is not an end-to-end one-round protocol.","prior_boundary":"Threshold Schnorr protocols either required more signing interaction or specialized participant assumptions despite the base signature's simple linear structure.","significance_at_publication":"FROST delivered a flexible t-out-of-n protocol with two signing rounds and a one-online-round preprocessed mode, becoming a practical Schnorr threshold baseline.","technical_delta":"The optimization shifted interaction from the online critical path into stored preprocessing material."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2020-FROST-ONE-ROUND-WITH-PREPROCESSING","keywords":["schnorr","discrete-log","two-round","preprocessing","practical","schnorr_nonce_protocols","round_efficient_robust_signing","optimization"],"limitations":["It is not a one-round protocol when preprocessing is counted end to end."],"paper_id":"TSIG-PAPER-2020-FROST","qualifiers":["One online round assumes fresh, correctly managed preprocessed nonces."],"source_locator":{"dossier_section":"TSIG-PAPER-2020-FROST § Atomic claims and Evidence locator","primary_source":"ePrint 2020/852, Section 5.2 and Figures 2–3 (PDF pp. 12–15).","primary_source_url":"https://eprint.iacr.org/2020/852","status":"section_checked"},"statement":"FROST can move nonce commitments to preprocessing so the message-dependent online phase uses one round.","statement_status":"source_normalized_statement","status":"published","title":"One online signing round after FROST nonce preprocessing","work_id":"TSIG-PAPER-2020-FROST"},"primaryUrl":"https://eprint.iacr.org/2020/852","sections":[],"status":"published","subtitle":"FROST: Flexible Round-Optimized Schnorr Threshold Signatures","summary":"FROST can move nonce commitments to preprocessing so the message-dependent online phase uses one round.","title":"One online signing round after FROST nonce preprocessing","type":"result","venue":"SAC 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2020-FROST-ONE-ROUND-WITH-PREPROCESSING"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","keywords":["atomic-result","schnorr","discrete-log","two-round","preprocessing","practical","schnorr_nonce_protocols","round_efficient_robust_signing","construction"],"metadata":{"claim_slug":"two-round-threshold-schnorr","contribution_kind":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["schnorr_nonce_protocols"]},"historical_context":{"narrative":"Schnorr's linear response makes it friendlier to threshold execution than ECDSA, yet existing protocols still paid in rounds, rigidity, or preprocessing assumptions. FROST combined nonce commitments, signer-set binding, and response aggregation into a flexible t-out-of-n workflow. The paper presents both a two-round mode and a preprocessed one-online-round mode, with security tied to its stated adversary model. The construction record is the two-round t-out-of-n signing path with ordinary Schnorr output. DKG and participant availability are related requirements but not silently included in its round count.","prior_boundary":"Threshold Schnorr protocols either required more signing interaction or specialized participant assumptions despite the base signature's simple linear structure.","significance_at_publication":"FROST delivered a flexible t-out-of-n protocol with two signing rounds and a one-online-round preprocessed mode, becoming a practical Schnorr threshold baseline.","technical_delta":"The protocol coupled signer-set binding and nonce commitments with linear response aggregation to reach a flexible two-round design."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","keywords":["schnorr","discrete-log","two-round","preprocessing","practical","schnorr_nonce_protocols","round_efficient_robust_signing","construction"],"limitations":["Key generation and signer availability are separate concerns."],"paper_id":"TSIG-PAPER-2020-FROST","qualifiers":["Static-adversary security treatment in the paper."],"source_locator":{"dossier_section":"TSIG-PAPER-2020-FROST § Atomic claims and Evidence locator","primary_source":"ePrint 2020/852, Section 5.2 (PDF pp. 12–15) and Section 6.2, Theorem 6.1 (PDF pp. 16–18).","primary_source_url":"https://eprint.iacr.org/2020/852","status":"theorem_checked"},"statement":"FROST produces ordinary Schnorr signatures with two rounds of interaction among a selected threshold of signers.","statement_status":"source_normalized_statement","status":"published","title":"Two-round t-out-of-n FROST signing","work_id":"TSIG-PAPER-2020-FROST"},"primaryUrl":"https://eprint.iacr.org/2020/852","sections":[],"status":"published","subtitle":"FROST: Flexible Round-Optimized Schnorr Threshold Signatures","summary":"FROST produces ordinary Schnorr signatures with two rounds of interaction among a selected threshold of signers.","title":"Two-round t-out-of-n FROST signing","type":"result","venue":"SAC 2020","year":2020,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2021-DOTT-ABORT-LEAKAGE-COUNTERMEASURE","keywords":["atomic-result","lattice","module-lwe","module-sis","fiat-shamir-with-aborts","n-out-of-n","two-round","lattice_fswa_threshold","post_quantum_thresholding","abort_leakage_security","attack_or_repair"],"metadata":{"claim_slug":"abort-leakage-countermeasure","contribution_kind":"attack_or_repair","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_thresholding","abort_leakage_security"],"technical_thread":["lattice_fswa_threshold"]},"historical_context":{"narrative":"Lattice Fiat–Shamir signatures could not simply add participant responses as in Schnorr: rejection events and partial transcripts risked leaking information about distributed short secrets. DOTT made that obstacle explicit and built a two-round n-out-of-n protocol around a homomorphic trapdoor commitment. The construction established an efficient lattice threshold starting point while exposing abort leakage as a mechanism-level security problem. The repair node isolates homomorphic trapdoor commitments as protection against information accumulating through aborted transcripts. It is tied to DOTT's design and does not certify every rejection-sampling protocol.","prior_boundary":"Lattice signatures had no direct analogue of linear Schnorr aggregation because rejection sampling and abort transcripts can leak distributed secret information.","significance_at_publication":"DOTT obtained two-round n-out-of-n signing and isolated abort leakage as a mechanism-level obstacle requiring a trapdoor-commitment countermeasure.","technical_delta":"The countermeasure made repeated abort behavior an explicit security object rather than an efficiency nuisance."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2021-DOTT-ABORT-LEAKAGE-COUNTERMEASURE","keywords":["lattice","module-lwe","module-sis","fiat-shamir-with-aborts","n-out-of-n","two-round","lattice_fswa_threshold","post_quantum_thresholding","abort_leakage_security","attack_or_repair"],"limitations":["It is not a generic proof that every abort-based threshold signature is safe."],"paper_id":"TSIG-PAPER-2021-DOTT","qualifiers":["Leakage defense is coupled to the DOTT protocol and commitment assumptions."],"source_locator":{"dossier_section":"TSIG-PAPER-2021-DOTT § Atomic claims and Evidence locator","primary_source":"ePrint 2020/1110 full journal version, Section 1.1 (PDF pp. 4–7), Section 2.4, and Section 3.1, Figure 6 (PDF pp. 12–19).","primary_source_url":"https://eprint.iacr.org/2020/1110","status":"section_checked"},"statement":"DOTT uses a homomorphic trapdoor-commitment mechanism so abort transcripts do not expose accumulated information about distributed lattice signing secrets.","statement_status":"source_normalized_statement","status":"published","title":"Homomorphic trapdoor commitments contain lattice abort leakage","work_id":"TSIG-PAPER-2021-DOTT"},"primaryUrl":"https://eprint.iacr.org/2020/1110","sections":[],"status":"published","subtitle":"Two-round n-out-of-n and Multi-Signatures and Trapdoor Commitment from Lattices","summary":"DOTT uses a homomorphic trapdoor-commitment mechanism so abort transcripts do not expose accumulated information about distributed lattice signing secrets.","title":"Homomorphic trapdoor commitments contain lattice abort leakage","type":"result","venue":"PKC 2021; Journal of Cryptology 2022","year":2021,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2021-DOTT-ABORT-LEAKAGE-COUNTERMEASURE"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","keywords":["atomic-result","lattice","module-lwe","module-sis","fiat-shamir-with-aborts","n-out-of-n","two-round","lattice_fswa_threshold","post_quantum_thresholding","round_efficient_robust_signing","construction"],"metadata":{"claim_slug":"two-round-n-out-of-n-lattice-signing","contribution_kind":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_thresholding","round_efficient_robust_signing"],"technical_thread":["lattice_fswa_threshold"]},"historical_context":{"narrative":"Lattice Fiat–Shamir signatures could not simply add participant responses as in Schnorr: rejection events and partial transcripts risked leaking information about distributed short secrets. DOTT made that obstacle explicit and built a two-round n-out-of-n protocol around a homomorphic trapdoor commitment. The construction established an efficient lattice threshold starting point while exposing abort leakage as a mechanism-level security problem. The construction node establishes two-round lattice signing only when all n parties participate. Arbitrary t-out-of-n capability arrived later and required different machinery.","prior_boundary":"Lattice signatures had no direct analogue of linear Schnorr aggregation because rejection sampling and abort transcripts can leak distributed secret information.","significance_at_publication":"DOTT obtained two-round n-out-of-n signing and isolated abort leakage as a mechanism-level obstacle requiring a trapdoor-commitment countermeasure.","technical_delta":"The construction established two-round feasibility for distributed rejection-sampling signatures despite abort-related leakage."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","keywords":["lattice","module-lwe","module-sis","fiat-shamir-with-aborts","n-out-of-n","two-round","lattice_fswa_threshold","post_quantum_thresholding","round_efficient_robust_signing","construction"],"limitations":["The security mechanism adds trapdoor-commitment machinery."],"paper_id":"TSIG-PAPER-2021-DOTT","qualifiers":["Full n-out-of-n participation, not arbitrary t-out-of-n."],"source_locator":{"dossier_section":"TSIG-PAPER-2021-DOTT § Atomic claims and Evidence locator","primary_source":"ePrint 2020/1110 full journal version, Section 3.1, Figure 6 (PDF pp. 16–19), and Section 3.3, Theorem 1 (PDF pp. 19–26).","primary_source_url":"https://eprint.iacr.org/2020/1110","status":"theorem_checked"},"statement":"DOTT constructs a two-round distributed lattice signature in which all n signers participate and the output follows a Fiat–Shamir-with-aborts line.","statement_status":"source_normalized_statement","status":"published","title":"Two-round n-out-of-n lattice signing","work_id":"TSIG-PAPER-2021-DOTT"},"primaryUrl":"https://eprint.iacr.org/2020/1110","sections":[],"status":"published","subtitle":"Two-round n-out-of-n and Multi-Signatures and Trapdoor Commitment from Lattices","summary":"DOTT constructs a two-round distributed lattice signature in which all n signers participate and the output follows a Fiat–Shamir-with-aborts line.","title":"Two-round n-out-of-n lattice signing","type":"result","venue":"PKC 2021; Journal of Cryptology 2022","year":2021,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2021-GKMN-STATELESS-DETERMINISTIC-THRESHOLD-SCHNORR","keywords":["atomic-result","schnorr","deterministic-nonce","stateless","garbled-circuits","dishonest-majority","schnorr_nonce_protocols","round_efficient_robust_signing","capability_result"],"metadata":{"claim_slug":"stateless-deterministic-threshold-schnorr","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["schnorr_nonce_protocols"]},"historical_context":{"narrative":"Threshold Schnorr implementations often relied on fresh randomized nonces, preprocessed state, or careful continuity of state across sessions. Garillot, Kondi, Mohassel, and Nikolaenko pursued a different operational contract: deterministic nonce derivation without evolving signer state. Their protocol used standardized block-cipher and garbled-circuit tools to protect the derivation, trading extra machinery for a more robust nonce-management interface. The capability change is deterministic, stateless nonce handling for dishonest-majority threshold Schnorr. That operational improvement does not eliminate artifact-level side-channel and fault obligations in practice.","prior_boundary":"Fast threshold Schnorr signing typically relied on randomized nonce generation, preprocessing state, or protocols whose state-management contract complicated robust deployment.","significance_at_publication":"The work achieved deterministic stateless threshold signing under standard assumptions by using block-cipher and garbled-circuit tools for nonce handling.","technical_delta":"The protocol changed the nonce/state interface rather than only reducing rounds."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2021-GKMN-STATELESS-DETERMINISTIC-THRESHOLD-SCHNORR","keywords":["schnorr","deterministic-nonce","stateless","garbled-circuits","dishonest-majority","schnorr_nonce_protocols","round_efficient_robust_signing","capability_result"],"limitations":["Determinism does not eliminate all implementation or side-channel obligations."],"paper_id":"TSIG-PAPER-2021-GKMN","qualifiers":["Uses block-cipher and garbled-circuit/zero-knowledge machinery."],"source_locator":{"dossier_section":"TSIG-PAPER-2021-GKMN § Atomic claims and Evidence locator","primary_source":"ePrint 2021/1055, Sections 1.3–1.4 (PDF pp. 4–9), Section 9 signing protocol, and Theorem 9.3 (PDF pp. 33–34).","primary_source_url":"https://eprint.iacr.org/2021/1055","status":"theorem_checked"},"statement":"GKMN constructs threshold Schnorr with deterministic nonce derivation and no evolving long-term signing state under its standard-assumption toolchain.","statement_status":"source_normalized_statement","status":"published","title":"Stateless deterministic threshold Schnorr signing","work_id":"TSIG-PAPER-2021-GKMN"},"primaryUrl":"https://eprint.iacr.org/2021/1055","sections":[],"status":"published","subtitle":"Threshold Schnorr with Stateless Deterministic Signing from Standard Assumptions","summary":"GKMN constructs threshold Schnorr with deterministic nonce derivation and no evolving long-term signing state under its standard-assumption toolchain.","title":"Stateless deterministic threshold Schnorr signing","type":"result","venue":"CRYPTO 2021","year":2021,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2021-GKMN-STATELESS-DETERMINISTIC-THRESHOLD-SCHNORR"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2022-DILIZIUM2-TWO-PARTY-DILITHIUM-LINE","keywords":["atomic-result","lattice","module-lwe","module-sis","dilithium","two-party","compression","lattice_fswa_threshold","post_quantum_thresholding","construction"],"metadata":{"claim_slug":"two-party-dilithium-line","contribution_kind":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_thresholding"],"technical_thread":["lattice_fswa_threshold"]},"historical_context":{"narrative":"DOTT established a commitment-based route to distributed lattice signing, but direct use with Dilithium's compression conventions and a focused two-party workflow required different choices. DiLizium 2.0 revisited that line, incorporated Dilithium-style encoding techniques, and reported a revised three-round protocol. It remains a two-party construction rather than an arbitrary-threshold ML-DSA package. The mapped object is a three-round two-party construction using Dilithium-oriented compression. It neither supplies arbitrary thresholds nor claims byte compatibility with the later ML-DSA standard or its normative parameter profiles.","prior_boundary":"DOTT established a lattice multisignature route, but direct compatibility with Dilithium's compression choices and a focused two-party workflow remained unsettled.","significance_at_publication":"DiLizium 2.0 adapted the commitment-based approach to a two-party Dilithium-oriented construction and revised its round and encoding tradeoffs.","technical_delta":"The work changed the concrete encoding and round tradeoff for a focused two-party post-quantum protocol."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2022-DILIZIUM2-TWO-PARTY-DILITHIUM-LINE","keywords":["lattice","module-lwe","module-sis","dilithium","two-party","compression","lattice_fswa_threshold","post_quantum_thresholding","construction"],"limitations":["It is not an arbitrary-threshold ML-DSA package."],"paper_id":"TSIG-PAPER-2022-DILIZIUM2","qualifiers":["Two-party setting and the audited preprint version."],"source_locator":{"dossier_section":"TSIG-PAPER-2022-DILIZIUM2 § Atomic claims and Evidence locator","primary_source":"ePrint 2022/644, Section 1.1 (PDF p. 2), Theorem 1 (PDF pp. 10–11), and Section 4, Table 2 (PDF pp. 14–15).","primary_source_url":"https://eprint.iacr.org/2022/644","status":"theorem_checked"},"statement":"DiLizium 2.0 revisits two-party lattice signing and incorporates Dilithium compression techniques into the DOTT-related construction line.","statement_status":"source_normalized_statement","status":"published_with_outdated_eprint","title":"Three-round two-party signing with Dilithium-style compression","work_id":"TSIG-PAPER-2022-DILIZIUM2"},"primaryUrl":"https://eprint.iacr.org/2022/644","sections":[],"status":"published_with_outdated_eprint","subtitle":"DiLizium 2.0: Revisiting Two-Party Crystals-Dilithium","summary":"DiLizium 2.0 revisits two-party lattice signing and incorporates Dilithium compression techniques into the DOTT-related construction line.","title":"Three-round two-party signing with Dilithium-style compression","type":"result","venue":"Journal of Computer Security final version","year":2022,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2022-DILIZIUM2-TWO-PARTY-DILITHIUM-LINE"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2023-GKS-ACTIVELY-SECURE-THRESHOLD-LINEAR-HE","keywords":["atomic-result","lattice","ring-lwe","sis","threshold-he","arbitrary-threshold","two-round","lattice_fswa_threshold","post_quantum_thresholding","mechanism"],"metadata":{"claim_slug":"actively-secure-threshold-linear-he","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_thresholding"],"technical_thread":["lattice_fswa_threshold"]},"historical_context":{"narrative":"Two-round lattice signing had been achieved when every participant was required, leaving arbitrary quorums without a secure way to combine masked linear values. GKS introduced an actively secure threshold linearly homomorphic encryption layer for that role. The resulting protocol retained two signing rounds while allowing t-out-of-n participation, at the cost of a more substantial homomorphic setup and component stack. The mechanism node isolates that actively secure linear-homomorphic layer and its role in reconstructing masked signing values. It is not independently a signature scheme.","prior_boundary":"Two-round lattice signing was available for n-out-of-n participation, while arbitrary thresholds required a way to reconstruct masked linear operations securely.","significance_at_publication":"GKS introduced an actively secure threshold linearly homomorphic-encryption layer to reach arbitrary t-out-of-n signing in two rounds.","technical_delta":"The component supplied the missing reconstruction mechanism between full-participation lattice signing and t-out-of-n signing."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2023-GKS-ACTIVELY-SECURE-THRESHOLD-LINEAR-HE","keywords":["lattice","ring-lwe","sis","threshold-he","arbitrary-threshold","two-round","lattice_fswa_threshold","post_quantum_thresholding","mechanism"],"limitations":["It is not a standalone signature scheme."],"paper_id":"TSIG-PAPER-2023-GKS","qualifiers":["Component security is tied to the GKS protocol and parameters."],"source_locator":{"dossier_section":"TSIG-PAPER-2023-GKS § Atomic claims and Evidence locator","primary_source":"ePrint 2023/1318, Section 3 and Theorem 1 (PDF pp. 12–16), plus Section 5.1, Figures 6–7 (PDF pp. 22–25).","primary_source_url":"https://eprint.iacr.org/2023/1318","status":"theorem_checked"},"statement":"GKS builds an actively secure threshold linearly homomorphic-encryption layer to aggregate masked lattice signing values for arbitrary thresholds.","statement_status":"source_normalized_statement","status":"published","title":"Actively secure threshold linear-HE as a signing component","work_id":"TSIG-PAPER-2023-GKS"},"primaryUrl":"https://eprint.iacr.org/2023/1318","sections":[],"status":"published","subtitle":"Two-Round Threshold Lattice-Based Signatures from Threshold Homomorphic Encryption","summary":"GKS builds an actively secure threshold linearly homomorphic-encryption layer to aggregate masked lattice signing values for arbitrary thresholds.","title":"Actively secure threshold linear-HE as a signing component","type":"result","venue":"PQCrypto 2024","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2023-GKS-ACTIVELY-SECURE-THRESHOLD-LINEAR-HE"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2023-GKS-TWO-ROUND-ARBITRARY-THRESHOLD-LATTICE-SIGNATURE","keywords":["atomic-result","lattice","ring-lwe","sis","threshold-he","arbitrary-threshold","two-round","lattice_fswa_threshold","post_quantum_thresholding","round_efficient_robust_signing","capability_result"],"metadata":{"claim_slug":"two-round-arbitrary-threshold-lattice-signature","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_thresholding","round_efficient_robust_signing"],"technical_thread":["lattice_fswa_threshold"]},"historical_context":{"narrative":"Two-round lattice signing had been achieved when every participant was required, leaving arbitrary quorums without a secure way to combine masked linear values. GKS introduced an actively secure threshold linearly homomorphic encryption layer for that role. The resulting protocol retained two signing rounds while allowing t-out-of-n participation, at the cost of a more substantial homomorphic setup and component stack. The capability node records two-round signing for a late-chosen t-out-of-n quorum. It relies on the threshold-encryption component rather than avoiding homomorphic machinery.","prior_boundary":"Two-round lattice signing was available for n-out-of-n participation, while arbitrary thresholds required a way to reconstruct masked linear operations securely.","significance_at_publication":"GKS introduced an actively secure threshold linearly homomorphic-encryption layer to reach arbitrary t-out-of-n signing in two rounds.","technical_delta":"The result generalized the two-round lattice line beyond n-out-of-n signers."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2023-GKS-TWO-ROUND-ARBITRARY-THRESHOLD-LATTICE-SIGNATURE","keywords":["lattice","ring-lwe","sis","threshold-he","arbitrary-threshold","two-round","lattice_fswa_threshold","post_quantum_thresholding","round_efficient_robust_signing","capability_result"],"limitations":["The protocol does not avoid homomorphic-encryption machinery."],"paper_id":"TSIG-PAPER-2023-GKS","qualifiers":["Threshold-LHE setup and active-security assumptions are part of the construction."],"source_locator":{"dossier_section":"TSIG-PAPER-2023-GKS § Atomic claims and Evidence locator","primary_source":"ePrint 2023/1318, Section 5, Figure 7 (PDF pp. 22–25), and Theorem 3 (PDF p. 26).","primary_source_url":"https://eprint.iacr.org/2023/1318","status":"theorem_checked"},"statement":"GKS constructs a two-round lattice signature for arbitrary t-out-of-n participation using threshold linearly homomorphic encryption.","statement_status":"source_normalized_statement","status":"published","title":"Two-round arbitrary-threshold lattice signing","work_id":"TSIG-PAPER-2023-GKS"},"primaryUrl":"https://eprint.iacr.org/2023/1318","sections":[],"status":"published","subtitle":"Two-Round Threshold Lattice-Based Signatures from Threshold Homomorphic Encryption","summary":"GKS constructs a two-round lattice signature for arbitrary t-out-of-n participation using threshold linearly homomorphic encryption.","title":"Two-round arbitrary-threshold lattice signing","type":"result","venue":"PQCrypto 2024","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2023-GKS-TWO-ROUND-ARBITRARY-THRESHOLD-LATTICE-SIGNATURE"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2023-OLAF-PROOF-WITHOUT-AGM","keywords":["atomic-result","schnorr","frost","dkg","aomdl","random-oracle","proof-model","schnorr_nonce_protocols","proof_models_and_assumptions","security_result"],"metadata":{"claim_slug":"proof-without-agm","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["proof_models_and_assumptions"],"technical_thread":["schnorr_nonce_protocols"]},"historical_context":{"narrative":"FROST offered an attractive protocol shape, but its strongest efficient analyses used the algebraic group model. Olaf combined a FROST variant with a Pedersen-style DKG and proved unforgeability without that model, relying instead on AOMDL in the random-oracle setting. The result changed the proof foundation of practical threshold Schnorr without claiming a plain-model reduction from ordinary discrete log. The exact advance is a FROST-style proof without the algebraic group model. Random oracles and the AOMDL assumption remain, so the node does not assert a standard-model proof from plain discrete log.","prior_boundary":"FROST-style efficiency was accompanied by proofs using the algebraic group model, leaving a proof-model gap for deployable threshold Schnorr.","significance_at_publication":"Olaf paired a FROST variant with Pedersen-style DKG and established unforgeability without the algebraic group model under its stated AOMDL/ROM assumptions.","technical_delta":"The analysis changed the proof-model coordinate while retaining a practical Schnorr protocol shape."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2023-OLAF-PROOF-WITHOUT-AGM","keywords":["schnorr","frost","dkg","aomdl","random-oracle","proof-model","schnorr_nonce_protocols","proof_models_and_assumptions","security_result"],"limitations":["Removing AGM does not yield a standard-model proof from plain discrete log."],"paper_id":"TSIG-PAPER-2023-OLAF","qualifiers":["AOMDL assumption and random-oracle model remain explicit."],"source_locator":{"dossier_section":"TSIG-PAPER-2023-OLAF § Atomic claims and Evidence locator","primary_source":"ePrint 2023/899, abstract and proof overview.","primary_source_url":"https://eprint.iacr.org/2023/899","status":"section_checked"},"statement":"Olaf combines a FROST variant with Pedersen-style DKG and proves unforgeability without the algebraic group model under AOMDL in the random-oracle model.","statement_status":"source_normalized_statement","status":"published","title":"FROST-style threshold Schnorr proof without the algebraic group model","work_id":"TSIG-PAPER-2023-OLAF"},"primaryUrl":"https://eprint.iacr.org/2023/899","sections":[],"status":"published","subtitle":"Practical Schnorr Threshold Signatures Without the Algebraic Group Model","summary":"Olaf combines a FROST variant with Pedersen-style DKG and proves unforgeability without the algebraic group model under AOMDL in the random-oracle model.","title":"FROST-style threshold Schnorr proof without the algebraic group model","type":"result","venue":"CRYPTO 2023","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2023-OLAF-PROOF-WITHOUT-AGM"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2024-TANG-FUNCTIONAL-INTERCHANGEABILITY","keywords":["atomic-result","lattice","t-out-of-n","mpc","rejection-sampling","interchangeable-output","proactive","threshold_package_interfaces","interoperable_output_and_evaluation","post_quantum_thresholding","capability_result"],"metadata":{"claim_slug":"functional-interchangeability","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["interoperable_output_and_evaluation","post_quantum_thresholding"],"technical_thread":["threshold_package_interfaces"]},"historical_context":{"narrative":"Post-quantum threshold proposals frequently changed the verifier interface or lacked a package joining arbitrary quorums, implementation evidence, and long-lived share management. Tang and coauthors targeted functional interchangeability with an ordinary lattice signature, implemented t-out-of-n signing, and added proactive refresh. Their specialized MPC and rejection-sampling route therefore spans capability and realization. Section 5 states that DSign outputs a signature accepted by the conventional Section 4 verifier, with public-key and signature sizes independent of the participant count. The capability is relative to the paper's base signature and is not an ML-DSA interoperability claim.","prior_boundary":"Threshold post-quantum schemes often changed the verification interface or lacked a package combining arbitrary thresholds, implementation evidence, and refresh.","significance_at_publication":"Tang et al. targeted functional interchangeability with the ordinary signature, implemented t-out-of-n signing, and added proactive refresh through specialized MPC.","technical_delta":"Functional interchangeability made thresholdization invisible to relying-party verification rather than defining a separate threshold format."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2024-TANG-FUNCTIONAL-INTERCHANGEABILITY","keywords":["lattice","t-out-of-n","mpc","rejection-sampling","interchangeable-output","proactive","threshold_package_interfaces","interoperable_output_and_evaluation","post_quantum_thresholding","capability_result"],"limitations":["This base-scheme interchangeability does not imply byte-for-byte compatibility with ML-DSA."],"paper_id":"TSIG-PAPER-2024-TANG","qualifiers":["Interchangeability is with the paper's selected base construction and package."],"source_locator":{"dossier_section":"TSIG-PAPER-2024-TANG § Atomic claims and Evidence locator","primary_source":"ePrint 2024/1067, Section 1.1 (PDF p. 4) and Section 5 DSign interface (PDF pp. 12–17).","primary_source_url":"https://eprint.iacr.org/2024/1067","status":"section_checked"},"statement":"Tang et al. design threshold lattice signatures whose combined output is accepted through the corresponding ordinary-signature verification interface.","statement_status":"source_normalized_statement","status":"published","title":"Threshold lattice signing with ordinary-verifier interchangeability","work_id":"TSIG-PAPER-2024-TANG"},"primaryUrl":"https://doi.org/10.1109/TIFS.2023.3293408","sections":[],"status":"published","subtitle":"Efficient Lattice-Based Threshold Signatures with Functional Interchangeability","summary":"Tang et al. design threshold lattice signatures whose combined output is accepted through the corresponding ordinary-signature verification interface.","title":"Threshold lattice signing with ordinary-verifier interchangeability","type":"result","venue":"IEEE Transactions on Information Forensics and Security 18, 4173–4187","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2024-TANG-FUNCTIONAL-INTERCHANGEABILITY"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2024-TANG-IMPLEMENTED-T-OUT-OF-N-LATTICE-SIGNATURE","keywords":["atomic-result","lattice","t-out-of-n","mpc","rejection-sampling","interchangeable-output","proactive","threshold_package_interfaces","interoperable_output_and_evaluation","post_quantum_thresholding","implementation_result"],"metadata":{"claim_slug":"implemented-t-out-of-n-lattice-signature","contribution_kind":"implementation_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["interoperable_output_and_evaluation","post_quantum_thresholding"],"technical_thread":["threshold_package_interfaces"]},"historical_context":{"narrative":"Post-quantum threshold proposals frequently changed the verifier interface or lacked a package joining arbitrary quorums, implementation evidence, and long-lived share management. Tang and coauthors targeted functional interchangeability with an ordinary lattice signature, implemented t-out-of-n signing, and added proactive refresh. Their specialized MPC and rejection-sampling route therefore spans capability and realization. Under Table 4's 123-classical/112-quantum-bit parameters, Table 3 reports 15 online rounds and 1.417 MB sent per party; Table 5 reports 0.5-second two-party LAN signing. These measurements establish executable feasibility in the paper's MP-SPDZ-derived environment, not a normalized cross-paper ranking.","prior_boundary":"Threshold post-quantum schemes often changed the verification interface or lacked a package combining arbitrary thresholds, implementation evidence, and refresh.","significance_at_publication":"Tang et al. targeted functional interchangeability with the ordinary signature, implemented t-out-of-n signing, and added proactive refresh through specialized MPC.","technical_delta":"The artifact moved functional interchangeability from a theorem-level property to an executable protocol instance."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2024-TANG-IMPLEMENTED-T-OUT-OF-N-LATTICE-SIGNATURE","keywords":["lattice","t-out-of-n","mpc","rejection-sampling","interchangeable-output","proactive","threshold_package_interfaces","interoperable_output_and_evaluation","post_quantum_thresholding","implementation_result"],"limitations":["Implementation existence is not a normalized performance ranking."],"paper_id":"TSIG-PAPER-2024-TANG","qualifiers":["Artifact version and benchmark context remain paper-specific."],"source_locator":{"dossier_section":"TSIG-PAPER-2024-TANG § Atomic claims and Evidence locator","primary_source":"ePrint 2024/1067, Section 7, Tables 3–7 and Figures 2–3 (PDF pp. 21–27).","primary_source_url":"https://eprint.iacr.org/2024/1067","status":"section_checked"},"statement":"Tang et al. implement arbitrary-threshold lattice signing and report a 15-round, 1.417 MB-per-party online profile with 0.5-second LAN signing for two parties under their stated parameters.","statement_status":"source_normalized_statement","status":"published","title":"Implemented t-out-of-n lattice threshold signing","work_id":"TSIG-PAPER-2024-TANG"},"primaryUrl":"https://doi.org/10.1109/TIFS.2023.3293408","sections":[],"status":"published","subtitle":"Efficient Lattice-Based Threshold Signatures with Functional Interchangeability","summary":"Tang et al. implement arbitrary-threshold lattice signing and report a 15-round, 1.417 MB-per-party online profile with 0.5-second LAN signing for two parties under their stated parameters.","title":"Implemented t-out-of-n lattice threshold signing","type":"result","venue":"IEEE Transactions on Information Forensics and Security 18, 4173–4187","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2024-TANG-IMPLEMENTED-T-OUT-OF-N-LATTICE-SIGNATURE"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2024-TANG-PROACTIVE-REFRESH","keywords":["atomic-result","lattice","t-out-of-n","mpc","rejection-sampling","interchangeable-output","proactive","threshold_package_interfaces","proactive_refresh","capability_result"],"metadata":{"claim_slug":"proactive-refresh","contribution_kind":"capability_result","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["proactive_refresh"],"technical_thread":["threshold_package_interfaces"]},"historical_context":{"narrative":"Post-quantum threshold proposals frequently changed the verifier interface or lacked a package joining arbitrary quorums, implementation evidence, and long-lived share management. Tang and coauthors targeted functional interchangeability with an ordinary lattice signature, implemented t-out-of-n signing, and added proactive refresh. Their specialized MPC and rejection-sampling route therefore spans capability and realization. Definition 3 models a mobile adversary and Theorem 2 proves proactive security when at most t-1 parties are corrupted in each period between refreshes. The lifecycle node isolates renewal of lattice key shares while the public key remains stable; it does not cover threshold compromise within one period.","prior_boundary":"Threshold post-quantum schemes often changed the verification interface or lacked a package combining arbitrary thresholds, implementation evidence, and refresh.","significance_at_publication":"Tang et al. targeted functional interchangeability with the ordinary signature, implemented t-out-of-n signing, and added proactive refresh through specialized MPC.","technical_delta":"The capability extended the lifetime security model of the post-quantum threshold package across epochs."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2024-TANG-PROACTIVE-REFRESH","keywords":["lattice","t-out-of-n","mpc","rejection-sampling","interchangeable-output","proactive","threshold_package_interfaces","proactive_refresh","capability_result"],"limitations":["Refresh does not repair a key already compromised beyond the modeled threshold within one epoch."],"paper_id":"TSIG-PAPER-2024-TANG","qualifiers":["Refresh security depends on epoch separation and the paper's corruption model."],"source_locator":{"dossier_section":"TSIG-PAPER-2024-TANG § Atomic claims and Evidence locator","primary_source":"ePrint 2024/1067, Section 5.1, Definition 3 (PDF pp. 13–14), and Section 6, Theorem 2 (PDF pp. 17–18).","primary_source_url":"https://eprint.iacr.org/2024/1067","status":"theorem_checked"},"statement":"The Tang et al. package refreshes distributed lattice signing shares while preserving the public verification key and threshold functionality.","statement_status":"source_normalized_statement","status":"published","title":"Proactive refresh for lattice threshold-signature shares","work_id":"TSIG-PAPER-2024-TANG"},"primaryUrl":"https://doi.org/10.1109/TIFS.2023.3293408","sections":[],"status":"published","subtitle":"Efficient Lattice-Based Threshold Signatures with Functional Interchangeability","summary":"The Tang et al. package refreshes distributed lattice signing shares while preserving the public verification key and threshold functionality.","title":"Proactive refresh for lattice threshold-signature shares","type":"result","venue":"IEEE Transactions on Information Forensics and Security 18, 4173–4187","year":2023,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2024-TANG-PROACTIVE-REFRESH"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2024-AOMMLWE-OFFLINE-ONLINE-SIGNING","keywords":["atomic-result","lattice","aom-mlwe","two-round","offline-online","large-threshold","lattice_fswa_threshold","round_efficient_robust_signing","optimization"],"metadata":{"claim_slug":"offline-online-signing","contribution_kind":"optimization","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["round_efficient_robust_signing"],"technical_thread":["lattice_fswa_threshold"]},"historical_context":{"narrative":"Arbitrary-threshold lattice protocols used threshold homomorphic encryption or heavy commitment machinery to contain distributed response leakage. The AOM-MLWE construction replaced those components with a new algebraic one-more lattice assumption and a two-round protocol. Its first phase can be prepared before either the message or signer subset is known, creating a useful offline/online boundary while introducing a less standard assumption. The optimization node isolates preprocessing that is independent of both message and eventual signer set. The complete protocol still has two phases when offline work is counted.","prior_boundary":"Arbitrary-threshold lattice signatures used threshold homomorphic encryption or heavy commitment machinery to control distributed response leakage.","significance_at_publication":"The AOM-MLWE route achieved a two-round protocol with an offline message- and signer-set-independent phase without FHE, at the cost of a new algebraic one-more assumption.","technical_delta":"The optimization made preprocessing reusable across late-bound message and signer-set choices."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2024-AOMMLWE-OFFLINE-ONLINE-SIGNING","keywords":["lattice","aom-mlwe","two-round","offline-online","large-threshold","lattice_fswa_threshold","round_efficient_robust_signing","optimization"],"limitations":["Two rounds still count when the offline phase is included."],"paper_id":"TSIG-PAPER-2024-AOMMLWE","qualifiers":["Offline material and reuse rules follow the exact protocol."],"source_locator":{"dossier_section":"TSIG-PAPER-2024-AOMMLWE § Atomic claims and Evidence locator","primary_source":"ePrint 2024/496 final author revision, Sections 2.1 and 6.1, Figures 2 and 8 (PDF pp. 8–10 and 33–35), plus Table 3 (PDF p. 58).","primary_source_url":"https://eprint.iacr.org/2024/496","status":"section_checked"},"statement":"The first AOM-MLWE signing round can be computed before the message and participating signer set are known, leaving a short online completion phase.","statement_status":"source_normalized_statement","status":"published","title":"Signer-set-independent offline phase for two-round lattice signing","work_id":"TSIG-PAPER-2024-AOMMLWE"},"primaryUrl":"https://eprint.iacr.org/2024/496","sections":[],"status":"published","subtitle":"Two-Round Threshold Signature from Algebraic One-More Learning with Errors","summary":"The first AOM-MLWE signing round can be computed before the message and participating signer set are known, leaving a short online completion phase.","title":"Signer-set-independent offline phase for two-round lattice signing","type":"result","venue":"CRYPTO 2024; Journal of Cryptology revision","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2024-AOMMLWE-OFFLINE-ONLINE-SIGNING"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2024-AOMMLWE-TWO-ROUND-LATTICE-THRESHOLD-WITHOUT-FHE","keywords":["atomic-result","lattice","aom-mlwe","two-round","offline-online","large-threshold","lattice_fswa_threshold","post_quantum_thresholding","round_efficient_robust_signing","construction"],"metadata":{"claim_slug":"two-round-lattice-threshold-without-fhe","contribution_kind":"construction","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_thresholding","round_efficient_robust_signing"],"technical_thread":["lattice_fswa_threshold"]},"historical_context":{"narrative":"Arbitrary-threshold lattice protocols used threshold homomorphic encryption or heavy commitment machinery to contain distributed response leakage. The AOM-MLWE construction replaced those components with a new algebraic one-more lattice assumption and a two-round protocol. Its first phase can be prepared before either the message or signer subset is known, creating a useful offline/online boundary while introducing a less standard assumption. The construction node records the two-round, no-FHE route to threshold lattice signing. Avoiding FHE should not be confused with relying only on standard MLWE, because AOM-MLWE is central.","prior_boundary":"Arbitrary-threshold lattice signatures used threshold homomorphic encryption or heavy commitment machinery to control distributed response leakage.","significance_at_publication":"The AOM-MLWE route achieved a two-round protocol with an offline message- and signer-set-independent phase without FHE, at the cost of a new algebraic one-more assumption.","technical_delta":"A new algebraic one-more LWE route replaced the heavier homomorphic components of earlier arbitrary-threshold constructions."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2024-AOMMLWE-TWO-ROUND-LATTICE-THRESHOLD-WITHOUT-FHE","keywords":["lattice","aom-mlwe","two-round","offline-online","large-threshold","lattice_fswa_threshold","post_quantum_thresholding","round_efficient_robust_signing","construction"],"limitations":["Avoiding FHE does not mean relying only on standard MLWE, and the remaining adaptive-versus-selective assumption gap is explicit."],"paper_id":"TSIG-PAPER-2024-AOMMLWE","qualifiers":["Threshold unforgeability relies on adaptive AOM-MLWE, while Theorem 4.5 reduces only the selective AOM-UMLWE variant to UMLWE and MSIS."],"source_locator":{"dossier_section":"TSIG-PAPER-2024-AOMMLWE § Atomic claims and Evidence locator","primary_source":"ePrint 2024/496 final author revision, Section 6.1, Figure 8, Theorem 6.1 (PDF pp. 33–36), and Theorem 4.5 (PDF pp. 27–32).","primary_source_url":"https://eprint.iacr.org/2024/496","status":"theorem_checked"},"statement":"The AOM-MLWE construction obtains two-round threshold lattice signing without fully homomorphic encryption or homomorphic trapdoor commitments.","statement_status":"source_normalized_statement","status":"published","title":"Two-round lattice threshold signatures without FHE","work_id":"TSIG-PAPER-2024-AOMMLWE"},"primaryUrl":"https://eprint.iacr.org/2024/496","sections":[],"status":"published","subtitle":"Two-Round Threshold Signature from Algebraic One-More Learning with Errors","summary":"The AOM-MLWE construction obtains two-round threshold lattice signing without fully homomorphic encryption or homomorphic trapdoor commitments.","title":"Two-round lattice threshold signatures without FHE","type":"result","venue":"CRYPTO 2024; Journal of Cryptology revision","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2024-AOMMLWE-TWO-ROUND-LATTICE-THRESHOLD-WITHOUT-FHE"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2024-FLOOD-FIRST-HASH-AND-SIGN-LATTICE-THRESHOLD-SIGNATURE","keywords":["atomic-result","lattice","hash-and-sign","mlwe","robust-dkg","noise-flooding","random-submersion","lattice_hash_sign_threshold","post_quantum_thresholding","construction"],"metadata":{"claim_slug":"first-hash-and-sign-lattice-threshold-signature","contribution_kind":"construction","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_thresholding"],"technical_thread":["lattice_hash_sign_threshold"]},"historical_context":{"narrative":"Most efficient threshold lattice signatures followed the Fiat–Shamir-with-aborts family, whereas GPV-style hash-and-sign lacked robust distributed tools for short trapdoor secrets. Flood and Submerse opened that second route through random submersions, verifiable short sharing, robust key generation, and noise flooding. The work broadened the mechanism landscape without claiming a generic compiler for every lattice signature. The construction node captures robust GPV-style threshold hash-and-sign as a distinct lineage. Its assumptions and distributed trapdoor procedures do not automatically threshold every related lattice scheme.","prior_boundary":"Efficient threshold lattice signatures largely followed abort-based Fiat–Shamir designs, while GPV-style hash-and-sign lacked robust distributed short-secret machinery.","significance_at_publication":"Flood and Submerse created a separate hash-and-sign lineage using random submersions, verifiable short sharing, and noise flooding.","technical_delta":"The result opened a threshold lattice lineage distinct from Fiat–Shamir-with-aborts constructions."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2024-FLOOD-FIRST-HASH-AND-SIGN-LATTICE-THRESHOLD-SIGNATURE","keywords":["lattice","hash-and-sign","mlwe","robust-dkg","noise-flooding","random-submersion","lattice_hash_sign_threshold","post_quantum_thresholding","construction"],"limitations":["The paper does not claim to threshold every lattice hash-and-sign scheme generically."],"paper_id":"TSIG-PAPER-2024-FLOOD","qualifiers":["Hash-and-sign assumptions, DKG, and noise-flooding parameters are integral."],"source_locator":{"dossier_section":"TSIG-PAPER-2024-FLOOD § Atomic claims and Evidence locator","primary_source":"ePrint 2024/959, abstract and framework overview.","primary_source_url":"https://eprint.iacr.org/2024/959","status":"section_checked"},"statement":"The Flood and Submerse work constructs a robust threshold signature from a GPV-style lattice hash-and-sign route using distributed short-secret machinery.","statement_status":"source_normalized_statement","status":"published","title":"Robust lattice threshold hash-and-sign","work_id":"TSIG-PAPER-2024-FLOOD"},"primaryUrl":"https://eprint.iacr.org/2024/959","sections":[],"status":"published","subtitle":"Flood and Submerse: Distributed Key Generation and Robust Threshold Signature from Lattices","summary":"The Flood and Submerse work constructs a robust threshold signature from a GPV-style lattice hash-and-sign route using distributed short-secret machinery.","title":"Robust lattice threshold hash-and-sign","type":"result","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2024-FLOOD-FIRST-HASH-AND-SIGN-LATTICE-THRESHOLD-SIGNATURE"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2024-FLOOD-RANDOM-SUBMERSIONS","keywords":["atomic-result","lattice","hash-and-sign","mlwe","robust-dkg","noise-flooding","random-submersion","lattice_hash_sign_threshold","post_quantum_thresholding","mechanism"],"metadata":{"claim_slug":"random-submersions","contribution_kind":"mechanism","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_thresholding"],"technical_thread":["lattice_hash_sign_threshold"]},"historical_context":{"narrative":"Most efficient threshold lattice signatures followed the Fiat–Shamir-with-aborts family, whereas GPV-style hash-and-sign lacked robust distributed tools for short trapdoor secrets. Flood and Submerse opened that second route through random submersions, verifiable short sharing, robust key generation, and noise flooding. The work broadened the mechanism landscape without claiming a generic compiler for every lattice signature. The component node records random submersions as a way to verify and reconstruct short shared secrets. Noise flooding and parameter constraints remain integral to its use.","prior_boundary":"Efficient threshold lattice signatures largely followed abort-based Fiat–Shamir designs, while GPV-style hash-and-sign lacked robust distributed short-secret machinery.","significance_at_publication":"Flood and Submerse created a separate hash-and-sign lineage using random submersions, verifiable short sharing, and noise flooding.","technical_delta":"The mechanism addressed the conflict between public verifiability and preserving the shortness needed for trapdoor sampling."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2024-FLOOD-RANDOM-SUBMERSIONS","keywords":["lattice","hash-and-sign","mlwe","robust-dkg","noise-flooding","random-submersion","lattice_hash_sign_threshold","post_quantum_thresholding","mechanism"],"limitations":["The component is not a complete DKG or signature by itself."],"paper_id":"TSIG-PAPER-2024-FLOOD","qualifiers":["Used with noise flooding and the paper's lattice parameter regime."],"source_locator":{"dossier_section":"TSIG-PAPER-2024-FLOOD § Atomic claims and Evidence locator","primary_source":"ePrint 2024/959, abstract and framework overview.","primary_source_url":"https://eprint.iacr.org/2024/959","status":"section_checked"},"statement":"Random submersions support verifiable sharing and reconstruction of short lattice secrets used by the Flood and Submerse threshold hash-and-sign construction.","statement_status":"source_normalized_statement","status":"published","title":"Random submersions verify shares of short lattice secrets","work_id":"TSIG-PAPER-2024-FLOOD"},"primaryUrl":"https://eprint.iacr.org/2024/959","sections":[],"status":"published","subtitle":"Flood and Submerse: Distributed Key Generation and Robust Threshold Signature from Lattices","summary":"Random submersions support verifiable sharing and reconstruction of short lattice secrets used by the Flood and Submerse threshold hash-and-sign construction.","title":"Random submersions verify shares of short lattice secrets","type":"result","venue":"CRYPTO 2024","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2024-FLOOD-RANDOM-SUBMERSIONS"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2024-GLACIUS-FULLY-ADAPTIVE-THRESHOLD-SCHNORR-FROM-DDH","keywords":["atomic-result","schnorr","ddh","adaptive-security","identifiable-abort","constant-size-signing-key","schnorr_nonce_protocols","adaptive_corruption_security","proof_models_and_assumptions","security_result"],"metadata":{"claim_slug":"fully-adaptive-threshold-schnorr-from-ddh","contribution_kind":"security_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["adaptive_corruption_security","proof_models_and_assumptions"],"technical_thread":["schnorr_nonce_protocols"]},"historical_context":{"narrative":"Efficient threshold Schnorr protocols mainly addressed static corruption or relied on specialized proof assumptions. Glacius targeted the stronger case in which the adversary chooses corruptions during execution. Under the paper's model, it obtained full adaptive security from DDH in the random-oracle model while keeping constant-size signing keys and adding identifiable abort. The result strengthens corruption timing without becoming a plain-model proof. The security record isolates adaptive corruption tolerance from DDH together with identifiable abort. Its exact claim still depends on the paper's full-threshold convention and random-oracle proof.","prior_boundary":"Practical threshold Schnorr protocols mainly treated static corruption or used stronger proof-model assumptions, leaving full adaptive security from a standard group assumption unresolved.","significance_at_publication":"Glacius reached full adaptive security from DDH in the random-oracle model while retaining compact Schnorr output and identifiable abort.","technical_delta":"The result strengthened the corruption-timing boundary without relying on the algebraic group model."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2024-GLACIUS-FULLY-ADAPTIVE-THRESHOLD-SCHNORR-FROM-DDH","keywords":["schnorr","ddh","adaptive-security","identifiable-abort","constant-size-signing-key","schnorr_nonce_protocols","adaptive_corruption_security","proof_models_and_assumptions","security_result"],"limitations":["The claim is not a plain-model proof."],"paper_id":"TSIG-PAPER-2024-GLACIUS","qualifiers":["Full adaptivity supports the paper's full threshold t<n and is proved from DDH in the random-oracle model."],"source_locator":{"dossier_section":"TSIG-PAPER-2024-GLACIUS § Atomic claims and Evidence locator","primary_source":"ePrint 2024/1628, abstract and security-definition discussion.","primary_source_url":"https://eprint.iacr.org/2024/1628","status":"section_checked"},"statement":"Glacius proves threshold Schnorr secure against fully adaptive corruptions from DDH in the random-oracle model, with constant-size signing keys and identifiable abort.","statement_status":"source_normalized_statement","status":"published","title":"Fully adaptive threshold Schnorr from DDH","work_id":"TSIG-PAPER-2024-GLACIUS"},"primaryUrl":"https://eprint.iacr.org/2024/1628","sections":[],"status":"published","subtitle":"Glacius: Threshold Schnorr Signatures from DDH with Full Adaptive Security","summary":"Glacius proves threshold Schnorr secure against fully adaptive corruptions from DDH in the random-oracle model, with constant-size signing keys and identifiable abort.","title":"Fully adaptive threshold Schnorr from DDH","type":"result","venue":"EUROCRYPT 2025","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2024-GLACIUS-FULLY-ADAPTIVE-THRESHOLD-SCHNORR-FROM-DDH"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2024-RACCOON-EFFICIENT-LARGE-THRESHOLD-LATTICE-SIGNING","keywords":["atomic-result","lattice","module-lwe","module-sis","large-threshold","implementation","masks","lattice_fswa_threshold","post_quantum_thresholding","round_efficient_robust_signing","optimization"],"metadata":{"claim_slug":"efficient-large-threshold-lattice-signing","contribution_kind":"optimization","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_thresholding","round_efficient_robust_signing"],"technical_thread":["lattice_fswa_threshold"]},"historical_context":{"narrative":"Abort-aware lattice threshold signing often required costly homomorphic commitments and had limited evidence at large quorum sizes. Threshold Raccoon used pairwise one-time additive masks and comparatively simple lattice operations to protect partial signing material. Table 2 gives a 128-bit parameter set supporting T up to 1024 with a 3.9 KB verification key, 12.7 KB signature, and 40.8 KB transcript contribution per signer under its accounting. Table 3 measures all three ShareSign phases and reports per-signer computation at T=1024; the implementation section separately gives 40800+16T bytes when pairwise MACs are included. These are paper-specific scale measurements, not a cross-paper ranking.","prior_boundary":"Earlier abort-aware lattice threshold signing used costly homomorphic commitments or did not scale to large threshold sizes with practical communication.","significance_at_publication":"Threshold Raccoon replaced that machinery with one-time additive masks and reported a large-threshold performance point under standard lattice assumptions.","technical_delta":"The implementation-aware protocol moved the abort-based lattice line toward large committees using simple lattice operations."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2024-RACCOON-EFFICIENT-LARGE-THRESHOLD-LATTICE-SIGNING","keywords":["lattice","module-lwe","module-sis","large-threshold","implementation","masks","lattice_fswa_threshold","post_quantum_thresholding","round_efficient_robust_signing","optimization"],"limitations":["The parameter and implementation profiles are not normalized as cross-paper benchmarks."],"paper_id":"TSIG-PAPER-2024-RACCOON","qualifiers":["Concrete figures are reported for the paper's parameter and network profile."],"source_locator":{"dossier_section":"TSIG-PAPER-2024-RACCOON § Atomic claims and Evidence locator","primary_source":"ePrint 2024/184, Section 8.3, Table 2, and Section 9, Table 3 (PDF pp. 43–44).","primary_source_url":"https://eprint.iacr.org/2024/184","status":"section_checked"},"statement":"Threshold Raccoon gives concrete 128-bit parameters up to threshold 1024 with a 3.9 KB verification key, 12.7 KB signature, and a three-round implementation profile.","statement_status":"source_normalized_statement","status":"published","title":"Lattice signing reported at threshold sizes up to 1024","work_id":"TSIG-PAPER-2024-RACCOON"},"primaryUrl":"https://eprint.iacr.org/2024/184","sections":[],"status":"published","subtitle":"Threshold Raccoon: Practical Threshold Signatures from Standard Lattice Assumptions","summary":"Threshold Raccoon gives concrete 128-bit parameters up to threshold 1024 with a 3.9 KB verification key, 12.7 KB signature, and a three-round implementation profile.","title":"Lattice signing reported at threshold sizes up to 1024","type":"result","venue":"EUROCRYPT 2024","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2024-RACCOON-EFFICIENT-LARGE-THRESHOLD-LATTICE-SIGNING"},{"evidence":"fulltext_checked","id":"TSIG-RESULT-2024-RACCOON-ONE-TIME-ADDITIVE-MASK-DEFENSE","keywords":["atomic-result","lattice","module-lwe","module-sis","large-threshold","implementation","masks","lattice_fswa_threshold","post_quantum_thresholding","abort_leakage_security","attack_or_repair"],"metadata":{"claim_slug":"one-time-additive-mask-defense","contribution_kind":"attack_or_repair","dossier_type":"contribution","evidence":"fulltext_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["post_quantum_thresholding","abort_leakage_security"],"technical_thread":["lattice_fswa_threshold"]},"historical_context":{"narrative":"Abort-aware lattice threshold signing often required costly homomorphic commitments and had limited evidence at large quorum sizes. Threshold Raccoon uses pairwise one-time additive masks, derived non-interactively from pairwise PRF seeds and a unique session identifier, to hide response shares while allowing the masks to cancel under aggregation. Section 2.3 and Figure 5 make session uniqueness and retained state explicit. The repair is protocol-specific: it requires unique session identifiers, and the paper leaves stateless signing, robustness, and identifiable abort as future work.","prior_boundary":"Earlier abort-aware lattice threshold signing used costly homomorphic commitments or did not scale to large threshold sizes with practical communication.","significance_at_publication":"Threshold Raccoon replaced that machinery with one-time additive masks and reported a large-threshold performance point under standard lattice assumptions.","technical_delta":"The defense replaced heavier homomorphic-commitment machinery with a protocol-specific masking discipline."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2024-RACCOON-ONE-TIME-ADDITIVE-MASK-DEFENSE","keywords":["lattice","module-lwe","module-sis","large-threshold","implementation","masks","lattice_fswa_threshold","post_quantum_thresholding","abort_leakage_security","attack_or_repair"],"limitations":["This protocol-specific masking record does not generalize to every lattice threshold signature."],"paper_id":"TSIG-PAPER-2024-RACCOON","qualifiers":["Unique session identifiers and non-reuse of PRF-derived masks are security-critical."],"source_locator":{"dossier_section":"TSIG-PAPER-2024-RACCOON § Atomic claims and Evidence locator","primary_source":"ePrint 2024/184, Sections 2.2–2.4 (PDF pp. 8–10), Sections 6.1–6.2, Figure 5 (PDF pp. 20–23), and Remark 6.1.","primary_source_url":"https://eprint.iacr.org/2024/184","status":"section_checked"},"statement":"Threshold Raccoon uses fresh additive masks to prevent repeated partial-signature and abort information from accumulating against a participant's lattice secret.","statement_status":"source_normalized_statement","status":"published","title":"One-time additive masks protect partial lattice signing keys","work_id":"TSIG-PAPER-2024-RACCOON"},"primaryUrl":"https://eprint.iacr.org/2024/184","sections":[],"status":"published","subtitle":"Threshold Raccoon: Practical Threshold Signatures from Standard Lattice Assumptions","summary":"Threshold Raccoon uses fresh additive masks to prevent repeated partial-signature and abort information from accumulating against a participant's lattice secret.","title":"One-time additive masks protect partial lattice signing keys","type":"result","venue":"EUROCRYPT 2024","year":2024,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2024-RACCOON-ONE-TIME-ADDITIVE-MASK-DEFENSE"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2026-NIST8214C-INTEROPERABLE-OUTPUT-EMPHASIS","keywords":["atomic-result","nist","standardization","threshold","evaluation","interoperability","threshold_package_interfaces","interoperable_output_and_evaluation","standardization_result"],"metadata":{"claim_slug":"interoperable-output-emphasis","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["interoperable_output_and_evaluation"],"technical_thread":["threshold_package_interfaces"]},"historical_context":{"narrative":"Threshold proposals often described compatibility informally, leaving unclear whether a combined output could be consumed by the same subsequent operation as the ordinary primitive. NIST IR 8214C makes this functional interchangeability part of the call's package contract. For signatures, the relevant question is whether the threshold output can be used through the reference verification operation under the declared interface. This is an eligibility and evaluation coordinate, not a new cryptographic construction. Two interchangeable packages may still differ in setup, corruption model, abort behavior, performance, and assumptions, so interface compatibility must not be read as overall equivalence.","prior_boundary":"Threshold constructions were compared paper by paper, without a common package contract connecting specifications, implementations, interfaces, and evaluation artifacts.","significance_at_publication":"It gave ordinary-verifier compatibility a precise place in the submission and evaluation process without turning that property into a security or performance ranking.","technical_delta":"The call made interchangeability with a designated reference operation an explicit package coordinate instead of an informal deployment preference."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2026-NIST8214C-INTEROPERABLE-OUTPUT-EMPHASIS","keywords":["nist","standardization","threshold","evaluation","interoperability","threshold_package_interfaces","interoperable_output_and_evaluation","standardization_result"],"limitations":["Interface compatibility does not make protocols security- or performance-equivalent."],"paper_id":"TSIG-PAPER-2026-NIST8214C","qualifiers":["This is a requirement of the public call, not a claim that a submitted scheme has been selected or standardized."],"source_locator":{"dossier_section":"TSIG-PAPER-2026-NIST8214C § Atomic claims and Evidence locator","primary_source":"NIST publication page and final report package requirements.","primary_source_url":"https://csrc.nist.gov/pubs/ir/8214/c/final","status":"section_checked"},"statement":"NIST IR 8214C requires submitted threshold schemes to specify how their outputs are interchangeable with a reference non-threshold primitive in the subsequent operation.","statement_status":"source_normalized_statement","status":"published","title":"Functional interchangeability as a threshold-call eligibility coordinate","work_id":"TSIG-PAPER-2026-NIST8214C"},"primaryUrl":"https://csrc.nist.gov/pubs/ir/8214/c/final","sections":[],"status":"published","subtitle":"NIST First Call for Multi-Party Threshold Schemes","summary":"NIST IR 8214C requires submitted threshold schemes to specify how their outputs are interchangeable with a reference non-threshold primitive in the subsequent operation.","title":"Functional interchangeability as a threshold-call eligibility coordinate","type":"result","venue":"NIST Interagency/Internal Report","year":2026,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2026-NIST8214C-INTEROPERABLE-OUTPUT-EMPHASIS"},{"evidence":"primary_source_checked","id":"TSIG-RESULT-2026-NIST8214C-NIST-THRESHOLD-CRYPTOGRAPHY-PACKAGE-FRAMEWORK","keywords":["atomic-result","nist","standardization","threshold","evaluation","interoperability","threshold_package_interfaces","interoperable_output_and_evaluation","standardization_result"],"metadata":{"claim_slug":"nist-threshold-cryptography-package-framework","contribution_kind":"standardization_result","dossier_type":"contribution","evidence":"primary_source_checked","facet_status":"normalized_for_research_map","facets":{"problem_lens":["interoperable_output_and_evaluation"],"technical_thread":["threshold_package_interfaces"]},"historical_context":{"narrative":"Threshold schemes had usually been presented as papers or isolated implementations, without a common package contract joining interfaces, specifications, reference code, and experimental evidence. NIST IR 8214C changed the process by issuing a public call whose submissions must contain a technical specification, a reference implementation, and an evaluation report. The contribution is procedural and architectural rather than a new signing theorem. It creates an assessable unit for later public analysis, but it neither approves existing constructions nor standardizes every scheme that enters the process. Technical originality remains attributable to each submitted protocol and its source papers.","prior_boundary":"Threshold constructions were compared paper by paper, without a common package contract connecting specifications, implementations, interfaces, and evaluation artifacts.","significance_at_publication":"It shifted NIST's threshold effort from general criteria toward a public collection and analysis process for assessable scheme packages.","technical_delta":"The call made a technical specification, reference implementation, and experimental-evaluation report the required parts of one submission package."},"historical_context_status":"curator_synthesis","id":"TSIG-RESULT-2026-NIST8214C-NIST-THRESHOLD-CRYPTOGRAPHY-PACKAGE-FRAMEWORK","keywords":["nist","standardization","threshold","evaluation","interoperability","threshold_package_interfaces","interoperable_output_and_evaluation","standardization_result"],"limitations":["The report is not itself a threshold-signature security proof."],"paper_id":"TSIG-PAPER-2026-NIST8214C","qualifiers":["Evaluation framework rather than an approval of every referenced construction."],"source_locator":{"dossier_section":"TSIG-PAPER-2026-NIST8214C § Atomic claims and Evidence locator","primary_source":"NIST publication page and final report package requirements.","primary_source_url":"https://csrc.nist.gov/pubs/ir/8214/c/final","status":"section_checked"},"statement":"NIST IR 8214C calls for threshold-scheme packages containing a technical specification, reference implementation, and experimental-evaluation report.","statement_status":"source_normalized_statement","status":"published","title":"NIST call requirements for threshold-scheme submission packages","work_id":"TSIG-PAPER-2026-NIST8214C"},"primaryUrl":"https://csrc.nist.gov/pubs/ir/8214/c/final","sections":[],"status":"published","subtitle":"NIST First Call for Multi-Party Threshold Schemes","summary":"NIST IR 8214C calls for threshold-scheme packages containing a technical specification, reference implementation, and experimental-evaluation report.","title":"NIST call requirements for threshold-scheme submission packages","type":"result","venue":"NIST Interagency/Internal Report","year":2026,"sourcePath":"data/threshold-signature-catalog.json#TSIG-RESULT-2026-NIST8214C-NIST-THRESHOLD-CRYPTOGRAPHY-PACKAGE-FRAMEWORK"},{"evidence":"source_grounded_route","id":"TSIG-ROUTE-001","keywords":[],"metadata":{"current_bottleneck":"General t-out-of-n sharing, rejection probability, output interoperability, robustness, and proof assumptions move differently across the constructions.","dossier_type":"route","entry_results":["TSIG-PAPER-2021-DOTT","TSIG-PAPER-2022-DILIZIUM2","TSIG-PAPER-2024-RACCOON","TSIG-PAPER-2024-TANG"],"evidence":"source_grounded_route","falsifiable_next_test":"Fix one ML-DSA parameter set and signer matrix, then account for every setup, presigning, online, abort, refresh, and verification byte while testing whether the output passes the unmodified ML-DSA verifier.","id":"TSIG-ROUTE-001","mechanism":"Distribute the linear lattice response while hiding signer-dependent abort and rejection information through commitments, masks, or a jointly sampled response distribution.","status":"proposed","targets":["TSIG-OP-001"],"title":"Distributed Fiat-Shamir-with-aborts with explicit leakage control"},"primaryUrl":null,"sections":[{"content":"Sharing a Dilithium-like linear equation does not by itself give ML-DSA interoperability or a secure distributed rejection sampler.","heading":"Route boundary"}],"status":"proposed","subtitle":"","summary":"Sharing a Dilithium-like linear equation does not by itself give ML-DSA interoperability or a secure distributed rejection sampler.","title":"Distributed Fiat-Shamir-with-aborts with explicit leakage control","type":"route","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ROUTE-001"},{"evidence":"source_grounded_route","id":"TSIG-ROUTE-002","keywords":[],"metadata":{"current_bottleneck":"Ciphertexts, proofs, and DKG make the route heavier than direct masked signing, and the resulting signature is not automatically a standardized scheme output.","dossier_type":"route","entry_results":["TSIG-PAPER-2023-GKS"],"evidence":"source_grounded_route","falsifiable_next_test":"Implement the same t-out-of-n parameter matrix as the direct-masking route and compare total DKG, proof, ciphertext, online, and recovery costs under identical active-security semantics.","id":"TSIG-ROUTE-002","mechanism":"Keep the signing secret protected under actively secure threshold linearly homomorphic encryption so the parties can form a correctly distributed short response at arbitrary threshold.","status":"active","targets":["TSIG-OP-001"],"title":"Threshold homomorphic encryption for short-share handling"},"primaryUrl":null,"sections":[{"content":"This route uses a specialized threshold linear-HE layer; it does not require evaluating the entire signing circuit with generic FHE.","heading":"Route boundary"}],"status":"active","subtitle":"","summary":"This route uses a specialized threshold linear-HE layer; it does not require evaluating the entire signing circuit with generic FHE.","title":"Threshold homomorphic encryption for short-share handling","type":"route","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ROUTE-002"},{"evidence":"source_grounded_route","id":"TSIG-ROUTE-003","keywords":[],"metadata":{"current_bottleneck":"The route has scheme-specific verification and concrete signature/communication costs; interoperability with an existing standardized hash-and-sign verifier is not inherited.","dossier_type":"route","entry_results":["TSIG-PAPER-2024-FLOOD"],"evidence":"source_grounded_route","falsifiable_next_test":"Instantiate a fixed threshold matrix, reproduce DKG and signing failures, and compare total bytes and robustness against both the FSwA and threshold-HE routes.","id":"TSIG-ROUTE-003","mechanism":"Use random submersions and noise flooding to share and verify short trapdoor-related secrets, then run a distributed hash-and-sign protocol with robust DKG.","status":"active","targets":["TSIG-OP-001"],"title":"Verifiable short secret sharing for lattice hash-and-sign"},"primaryUrl":null,"sections":[{"content":"Hash-and-sign here refers to a lattice trapdoor/preimage paradigm, not the stateless hash-only SLH-DSA family.","heading":"Route boundary"}],"status":"active","subtitle":"","summary":"Hash-and-sign here refers to a lattice trapdoor/preimage paradigm, not the stateless hash-only SLH-DSA family.","title":"Verifiable short secret sharing for lattice hash-and-sign","type":"route","venue":null,"year":null,"sourcePath":"data/threshold-signature-catalog.json#TSIG-ROUTE-003"}],"propertyAssertions":[{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-01A7AF7F59CE8F","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"distributed public key and lattice trapdoor commitment machinery"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-01E0DBC3BC39D0","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"general t-out-of-n"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-02D2F4F9CAB20F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"threshold unforgeability under the stated bound"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-05D02995582C7D","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"Module-SIS and Module-LWE"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-068606658DD3B6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"constant number of two-party messages; exact bytes parameter-dependent"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-06A4E91DAFB2AA","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"noninteractive-online"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-079D1E967A49BA","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"none"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-085B092E95C3A1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"multiparty interactive protocol; exact accounting parameter-dependent"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-08811D68029BEB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"full threshold range t<n under the paper's convention"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-0953B5E1A80D95","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"threshold_signature"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-09BAD269FF15C8","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"two-party shared module-lattice secret and additively homomorphic commitment"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-09E35D24F1150E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"UC/proactive profile; exact adaptive clauses follow paper"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-0AA50D2FE4F5E5","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"ordinary ECDSA signature"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-0B8F6F45036AF1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"jointly held ECDSA key without Paillier encryption"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-0D661D44B4B95E","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"pairwise PRF seeds provisioned at key generation; per-session additive masks are generated online"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-0E1FF79AE4DB54","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"FROST-family nonce preprocessing options"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-0EB123718D8731","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"threshold_dss"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-0F0843B6BCCE68","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"exact protocol phases follow paper"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-0F6D08596AF29C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"interactive signing protocol"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-0F80E5C3BA02BB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"threshold_signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-0F8CBA62B974B0","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"ordinary-verifier-output"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-0FCF49193E8592","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"arbitrary t-out-of-n"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-117D0137819B5E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"key-generation and presigning components"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-11E150AC59CEEB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"none"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-1227A803B6AACA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"Pedersen-DKG variant composed with FROST3"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-1315B9B4F8EA70","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"OT/hash-proof-system dependent"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-1417DDC3CBCBD8","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"full corruption threshold stated as t<n in the paper"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-1456695B2FC390","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"one signature share per participating server plus combining metadata"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-1468D75D3D30EC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"RSA modulus and verified secret-key shares"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-15B9A8879DB805","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"verifiable short-secret-sharing and DKG material"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-162F6D13A01E6D","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"two-round commitments and masked lattice responses"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-181ADBF236EC55","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"post-quantum"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-18FC294B3C764C","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"robustness"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-191DA5FCDD89F5","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"malicious threshold adversary"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-19CB91FA614848","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"threshold_signature"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-19D58322DB1002","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"abort handling within active security; guaranteed output not claimed here"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-1A1648BE18EC79","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"RSA function with a signature encoding supplied by the profile"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-1B5C235D38D398","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"paillier-free-route"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-1C591CEEDFCE8C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"lattice_masked_partial_signatures"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-1D775DF6CD39FE","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"Module-LWE and Module-SIS"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-1E60B66024F6C1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"protocol-dependent"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-1F74C18C662CCE","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"scheme-specific lattice signature"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-209E9EEEBFBF48","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"Schnorr"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-2230B9DDA999C5","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"none"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-22CF368936FD21","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"malformed shares are attributable to their senders"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-22D65A8E69AB5C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"no; static corruption game"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-22EE5C5C61A173","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"full-corruption-threshold"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-2384743EC1979A","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"identifiable-abort"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-2475BCAA4BC3E5","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"public-share-verification"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-2506F8EFDAEDF0","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"threshold unforgeability"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-2516D491DFF818","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"distributed key generation and auxiliary cryptographic setup"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-25319B961AA10C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"correlated oblivious-transfer-style work"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-2539757D994F77","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"none"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-25426EDA70F52D","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"threshold_schnorr_mpc_nonce"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-258C8B050E4660","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"no-fhe"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-25F138FE56FC09","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"threshold_schnorr_adaptive"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-272FB5D5F9C254","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"trustless distributed setup with Paillier-related proofs"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-27D8238D22E086","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"OT and multiparty arithmetic dependent"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-28AC39890955E5","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"none"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-28DB9FF26EA960","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"historical interactive protocol; exact accounting queued"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-2A482330900CBB","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"two online rounds with ciphertext/proof overhead"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-2A6565E9AC3450","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"abort on malicious behavior; guaranteed output not claimed"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-2BA84141DD8A2A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"malicious two-party adversary"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-2D0874CD729A29","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"threshold unforgeability"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-2D86AEE38209B8","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"at 128-bit security and T=1024, 14.1 KB optimized online or 276 KB naive online per user, plus 262 KB offline"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-2EA657F9031CB5","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"shifted toward preprocessing; online contribution is noninteractive"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-2F00C1D6086A3E","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"arbitrary t-out-of-n"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-2F3212F6FE5965","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"threshold_signature"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-30E59C1CF50150","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"three"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-320B194048990D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"ECDSA"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-321CDC6B35EC43","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"two"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-3230E9F415C51D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"not claimed on this card"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-32DEBAF23EB826","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"ECDSA"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-33113C29CC2E8A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"t-out-of-n"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-33369BACD5A411","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"not claimed on this card"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-3375CF648E8962","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"adaptive AOM-MLWE; only its selective variant is reduced from UMLWE and MSIS"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-3404127797E322","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"implementation"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-34FEAA0C62B512","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"ordinary Schnorr-family signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-35F5B988847CF2","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"interchangeable-output"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-386B845AB0708C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"actively secure threshold linearly homomorphic encryption and distributed key generation"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-390EE41808B9DC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"paper-specific; no FHE ciphertext layer"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-39B53D560A494E","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"active adversary under the paper threshold-HE model"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-39F459CE20AF60","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"full adaptive security"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-3A576CE9FF9982","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"t-out-of-n"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-3A85A55B8FFC31","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"two-party-signing"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-3ABA9012EE3961","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"Schnorr"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-3B521AD470DE76","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"identifiable-abort"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-3B939AE46BDA65","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"any 1<=T<=N<=1024 in the concrete parameter profile"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-3C62D2CC6BEF6B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"identifiable abort rather than guaranteed output"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-3CBAFDBA6E03A6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"not claimed on this card"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-3D71180E519601","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"interactive protocol"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-3DBEFA6DA7297D","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"true threshold participation"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-3E20732040E86D","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"lattice_mpc_rejection_sampling"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-3EE2935D91000C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"lattice_one_more"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-3FAE0826EB08C3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"threshold_signature"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-3FD213266AE628","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"ECDSA"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-406F14311969CA","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"distributed Dilithium-G variant; verifier/parameters differ from standardized Dilithium"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-4135135D21A580","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"proactive-refresh"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-43D898DEEC5962","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"deterministic-nonce"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-455CD87C89DD5A","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"Ring-LWE and SIS lineage through threshold HE and the signature layer"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-462D668825B39D","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"two-round"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-467D4AB9769429","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"abort and restart on failed distributed rejection or MAC checks; guaranteed output not claimed"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-46EFA223A1F8F2","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"implementation"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-47CA18B899961B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"noninteractive share generation followed by combining"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-49D5A170CEDB39","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"ordinary DSS signature"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-4A53E898D27EA2","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"lattice Fiat-Shamir-with-aborts line"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-4A9703208A0B57","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"large-threshold"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-4B5BAF5A1ABB80","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"Module-LWE and Module-SIS lineage"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-4DB13A8E493093","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"shared RSA trapdoor"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-4F660E1CBBED50","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"noninteractive-online"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-505751994897B5","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"jointly held ECDSA key with Paillier-related setup"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-50E6BB768EE6DA","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"arbitrary threshold t<=n"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-51544C0304A189","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"no; static proof profile"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-51552212049940","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"three in the audited ePrint"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-51DF499534A9A0","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"interactive online signing"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-51EFCFA49BBF24","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"proactive mobile-corruption security across refresh periods; not full within-period adaptive security"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-5220115C66B8C7","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"two-party blame is implicit when a session fails"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-523B700338EBFB","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"threshold_signature"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-53089C35ACC3CC","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"none"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-538540D698C480","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"2-out-of-2"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-5389C1E282CB2F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"no single party can forge alone"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-56A384194C83F4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"ordinary ECDSA signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-56A8521505E4B6","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"ordinary-verifier-output"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-56F1AEFFCAD703","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"yes under the scoped model"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-5738CABFFFA744","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"none"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-5896A0D95DB9EF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"combiner verifies signature shares and can proceed with enough valid shares"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-58AF71FC3A6995","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"threshold_pairing"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-590E5BBA3166C2","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"distributed ECDSA key"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-593EC6B8A3AF3A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"BLS"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-5A98DE91252485","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"shared Schnorr key plus UC-commitment and garbled-circuit machinery"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-5B9766E0A7B447","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"compact-output"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-5BBE092F9E0E45","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"exact table parameter-dependent"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-5C2AB77AA9E465","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"2-out-of-2"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-5C6A95C979EF8B","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"no; left as future work"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-5DA63E0ECAB26A","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"ordinary-verifier-output"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-5F7D89854C4367","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"robust-dkg"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-61F0AD8601AD1B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"threshold_ecdsa_paillier"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-62479C608FB21A","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"not claimed on this card"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-6326E204E16C56","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"FROST3 signing profile"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-64AA6884189D04","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"general-threshold"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-651E476E8B834A","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"1.417 MB sent per party in 15 online rounds for the Table 4 profile"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-663099662521DA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"DSS"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-66FFBF5E748318","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"pedersen-dkg"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-6717BC70915CF3","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"commitment-based transcript protection, not general robust completion"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-67BB56E6F68765","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"yes, including key generation in the paper claim"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-67EA7AB59ACEA8","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"two-party"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-67FCB1E382D965","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"distributed key setup outside the signing algorithm"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-6A7574F4A13614","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"malicious-security"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-6AC457769DA1F0","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"lattice_threshold_he"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-6B2D95E1EF3A83","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"post-quantum"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-6B7428E5C254D4","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"noninteractive-signature-shares"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-6BF71C69F0BFD0","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"robustness"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-6CC46F781258B7","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"threshold_signature"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-6DB82469E34963","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"static threshold adversary in the paper model"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-6E59554358F1A2","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"threshold key shares; DKG can be composed separately"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-6F4C400139BFE7","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"not the card's claim"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-702743559C9151","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"threshold_ecdsa_paillier"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-70456B133A8B17","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"distributed Schnorr key with constant-size per-signer signing keys"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-7108992C8F525F","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"not promoted from the outdated preprint"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-719E3918066FB6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"none"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-71F09D9841C81C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"none"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-7418B435833101","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"threshold_rsa"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-7572192F75B5D1","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"all n signers required"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-775B7860F0C652","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"Table 2 reports 40.8 KB per signer at kappa=128; implementation accounting is 40800+16T bytes with pairwise MACs"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-783E8AC21D6398","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"one malicious party under the paper model"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-789BB667A26AC2","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"threshold_signature"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-78F13881B1FC83","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"abort and identify/exclude a misbehaving participant"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-78F364D0C846AE","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"protocol-specific"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-794303F2DE7AD6","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"invalid shares are detectable"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-79B552C6778A2A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"threshold_signature"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-79FA66CC9551CC","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"abort-oriented"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-7A76C00ED3FB59","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"Dilithium-G-style Fiat-Shamir with aborts"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-7AE2572EFFCF57","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"threshold_signature"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-7B06E5C838CBC9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"protocol setup and signing-key material"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-7B218672DBCEED","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"nontrivial distributed protocol"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-7BD8DAE02B4063","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"trusted-dealer key generation; DKG is left as future work"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-7C66A9A3F7F812","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"MLWE, random submersions, and noise flooding"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-7C70268E93DCF5","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"two messages per signer in the two-round mode"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-7E95732D5FCE78","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"abort-oriented"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-7F06181E8D69A1","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"threshold_signature"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-7F4B2FBF2DCBF6","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"arbitrary T-out-of-N with concrete support up to T=1024"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-80C903E4DECBAC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"threshold_ecdsa_paillier"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-81377B48B2E479","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"post-quantum"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-82876B3FF2A9B2","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"two-round"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-82908094F2283B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"scoped share verification; modern terminology not used"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-8425F2AE414081","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"no single party can forge alone"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-8530F2301E1520","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"no claim on this card"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-858A9B2D27C2C8","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"threshold signing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-859982D64AC379","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"post-quantum"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-862C06A00A1826","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"ordinary-verifier-output"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-883369862FEDB0","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"t-out-of-n SPDZ variant and distributed key generation"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-889C0F8DDFFCB4","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"OT-based correlated preprocessing"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-88EAC15D3813DA","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"mobile malicious adversary corrupting at most t-1 parties in each refresh period"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-89CB5F29975F69","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"t-out-of-n authenticated bits and Beaver triples generated before DKG and signing; the reported batch supports five signatures"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-8B6080118AEB9E","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"15 online rounds in the Table 3 parameter profile"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-8BADAD2D009BF0","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"two-party-signing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-8C0915E7E2772F","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"dishonest-majority"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-8DB9C72F014B20","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"threshold_signature"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-8DFF886F1344F4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"static threshold adversary in the proof"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-8F4F47685EFE0E","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"ordinary-verifier-output"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-90ACC109C54D0B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"threshold_signature"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-90EC0341DB8B6F","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"static adversary controlling fewer than the threshold"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-911DC0D6858DFF","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"true-threshold"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-915F3E6BFE31D3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"ordinary one-group-element BLS signature"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-91B76027B6F4A8","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"2-out-of-2"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-91DE95EEC20E69","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"general threshold with robustness under the paper's bounds"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-9215881DCEC6D2","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"paper-specific lattice signature with ordinary verifier"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-926B748D4297D6","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"ordinary-verifier-output"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-926FAF45870479","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"distributed-key-generation"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-92D27F89F72604","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"ordinary Schnorr-family signature under the chosen ciphersuite"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-97AB9983A2C1F8","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"both parties required"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-97DFB84A4C889B","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"paillier-free-route"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-984EADEA58721B","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"network bytes not benchmarked; signing communication repeats with the audited preprint's average 101.55 rejections"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-988FB56162F443","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"Raccoon lattice signature"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-98A295D6EDB96D","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"first round can be prepared without the message or signer set"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-998DC1DA0796DA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"ordinary ECDSA signature"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-9BCA42321BA4FB","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"abort-oriented"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-9C89084B9492FF","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"ordinary-verifier-output"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-9CCE5F111BB8C7","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"static adversary corrupting up to n-1 parties"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-9D13962FF6FA3E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"RSA"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-9D21B6A2396366","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"UC malicious adversary in the paper model"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-9DC82DDA3CEDD2","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"closer to Dilithium through signature compression; exact standard interoperability not asserted"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-9E16E084629E43","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"no claim on this card"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-A0888383ED53A8","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"interactive"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-A09D1FC874B08A","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"two rounds; one online round with preprocessing"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-A13A157728338E","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"verification algorithm identical to the paper's Raccoon variant; concrete parameters are not tuned for Raccoon interchangeability"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-A1466CAD08D056","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"threshold_ecdsa_ot"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-A17DABE54471A1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"none"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-A224A7C2895C45","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"threshold_signature"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-A41E9FC9E0CEDC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"general threshold profile with a representative T=16 parameter set"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-A44365162F0B66","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"not claimed on this card"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-A4E025DD8F1941","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"not claimed on this card"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-A4E6E8D9EC6A4D","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"arbitrary-threshold"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-A523791C11561C","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"ordinary-verifier-output"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-A54DB444063698","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"threshold_signature"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-A56C8C6E81DD4C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"no online-round removal claimed on this card"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-A586CBC0133349","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"abort-leakage-defense"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-A70BD0E05EA17F","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"static corrupt set chosen before key generation with fewer than T parties"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-A8B70F33C446D3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"not claimed on this card"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-AA83F8D394CB08","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"lattice hash-and-sign"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-AAE79A81A8F60B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"k-out-of-l threshold in the paper notation"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-AB63716362B014","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"distributed sharing of the DSS secret"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-AC8680EC946F9F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"threshold unforgeability with proactive refresh support"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-AC9A93DDE419EF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"threshold unforgeability under stated bounds"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-AD6160367328B0","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"t-out-of-n signing"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-ADFF0066142757","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"reusable commitment setup for the zero-knowledge layer"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-AE6D619AADD0EA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"not claimed on this card"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-AF02680CF63F7E","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"rsa-function-sharing"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-AF0D75493B218F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"abort-oriented protocol with verifiable steps"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-B0A91873F41797","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"abort on detected cheating"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-B21C8C3386C35C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"abort-oriented; robustness against malicious failure is left as future work"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-B21F4BEB821730","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"ordinary RSA signature value for the specified encoding"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-B3F8A71F5FB849","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"trusted centralized key generation; a compatible DKG is outside the paper's scope"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-B451AE8B8DCD6E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"identifiable abort rather than guaranteed output"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-B4D906C86062CD","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"post-quantum"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-B619DAA0362BC3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"fully adaptive adversary"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-B772E5D93FEC1F","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"n-out-of-n"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-B8ED728891BD1E","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"post-quantum"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-B8FFC2F7F003A6","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"lattice assumptions and efficient distributed rejection sampling"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-B98DF51197251F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"malicious faults with separate robustness bounds"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-BA505AB2995758","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"one group-element share per participant"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-BB00AFEBFAB062","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"protocol-specific"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-BB911DF6E42D75","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"lattice_hash_and_sign_submersion"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-BBB9A7AB9ED23C","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"not claimed on this card"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-BD92902D3FF491","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"no for signer corruption; the main reduction uses adaptive AOM-MLWE as an assumption"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-BE7E879BAEA6C2","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"exact property not promoted"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-BEE6F651AA9B7A","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"noninteractive shares and public combining"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-BFF1738884A1B3","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"no; misbehavior detection is left as future work"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-BFF1C18277DA16","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"two"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-C14285D0C9575B","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"ordinary ECDSA signature"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-C315C6C4CE9518","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"no general identifiable-abort claim promoted"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-C4A6ABF2C0A17E","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"robustness"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-C52C8482BE9608","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"substantial presigning phase"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-C68A15250CF766","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"unforgeability against up to t corrupted players in the stated range"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-C85172D399DE3E","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"threshold_rsa"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-CA798FC0923C49","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"hash-and-sign"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-CABAF04389DDE1","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"ordinary ECDSA signature"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-CAFFB3A5BBF3BB","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"threshold_ecdsa_ot"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-CB3EA74E3E8B27","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"optional nonce-commitment preprocessing"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-CB8104F56C3211","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"t-out-of-n under the paper bounds"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-CBD150312FC192","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"exact property queued for full-text audit"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-CBDCCFC8C97963","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"scheme-specific hash-and-sign lattice verifier"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-CCA661F2C36C93","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"paper-specific threshold"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-CCB976A86655D4","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"signature-compression"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-CE604AFBBD3759","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"key sharing and verification setup"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-CEE8BAD6A798C3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"one malicious party"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-CFE68552A43FB9","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"not claimed on this card"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-D03B87ABECDDB6","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"threshold unforgeability"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-D13BCECE09C4AE","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"two-round"},{"dimension":"adaptive_security","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-D1D02197F04FC3","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"not the main claim on this card"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-D290BACC23CC72","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"Schnorr"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-D32F5BA2B66455","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"static malicious adversary in the paper model"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-D3325A8B351099","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"shared scalar key in a gap-Diffie-Hellman group"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-D39B45C8F0F0DF","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"large-threshold"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-D421BD5254D3CB","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"proof-without-agm"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-D476AF91142151","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"distributed key setup"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-D48A2524ECA61A","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"malicious threshold adversary under paper bounds"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-D4EEB63828AF1C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"threshold unforgeability"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-D525AA77A765FC","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"not normalized across preprint and final version"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-D529E818902F2C","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"RSA function output; signature encoding must be fixed separately"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-D57B0D6AE292CA","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"distributed hash-and-sign protocol; exact count parameterized"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-D58C1588F4FFE4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"interactive multiparty protocol"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-D5D00503C18A31","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"scoped blame mechanisms; use exact paper definition"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-D6111ED16F2267","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"t-out-of-n multiparty threshold"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-D623C47A95B437","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"yes; same verification algorithm as the paper's non-threshold signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-D7415AD8333FC2","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"constant-size-signing-key"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-D759C4275B04F3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"2t+1 participating signers for t<n/2 in the base threshold statement"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-D7C93D5D2A991E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"threshold unforgeability"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-D9E432044FC2D0","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"two; online phase noninteractive after message-independent preprocessing"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-DKLS2.md","id":"TSIG-PROP-D9EF7F302974A4","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-DKLS2","value":"none"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-DA7C9E171F926C","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"multiparty"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-DAA0CD6979D185","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"Schnorr"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-DACC2CE8BE23B9","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"arbitrary-threshold"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-DDC2372674D376","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"stateless-signing"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-DE933AC896F57F","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"DKG and threshold-HE setup"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-DFCE233775B048","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"malicious threshold adversary under the paper model"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-E0D426061BD5B1","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"paper-specific proofs/checks"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-E0EBB1F676C71C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"threshold_signature"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-E175ADA1D93D4E","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"exact accounting queued"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-E1E7C01DB879FC","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"threshold_signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-E22059B1D26D7A","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"optional-preprocessing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-E29528B7C6D8D0","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"ordinary-verifier-output"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-E445CD6D6CFA77","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"ordinary-verifier-output"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-E48BA686F792C5","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"scheme-specific lattice signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-E4BECDA7C9EE15","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"malicious-security"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-E5DE31F256F33D","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"ordinary-verifier-output"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-E620C0907C9E5C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"none"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-RSA.md","id":"TSIG-PROP-E669A82BA64C97","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-RSA","value":"share verification rather than modern identifiable-abort interface"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2019-DKLSN.md","id":"TSIG-PROP-E6BF90394F6325","review_status":"bibliographic_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2019-DKLSN","value":"ECDSA"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-E720CB9BE6A314","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"full-adaptive-security"},{"dimension":"post_quantum_mechanism","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-E7381CC248E48F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"none"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-E7A0738AA20B72","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"ordinary Schnorr signature"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-E7F0D92F5AD391","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"abort leakage is hidden; availability still fails when one signer withholds"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-E9029B12AEBAD0","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"threshold_schnorr"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-E9DB53B8A0840C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"lattice_fswa_distributed"},{"dimension":"output_compatibility","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-EB366B28C5A0CC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"ordinary Schnorr-family signature"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-EB9B1216DE0412","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"Dilithium-derived"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-ECECA063AC193D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"ECDSA"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-EFC62024853886","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"selective/static corruption of fewer than T signers"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-F00F263703212F","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"abort-oriented FROST family"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-GLACIUS.md","id":"TSIG-PROP-F1A1A49F26BF38","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-GLACIUS","value":"yes, with a formal game-based definition"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-F1E28A7D1D76DD","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"threshold_schnorr"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-F2DB6F2314088D","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"verifiable shares support blame; exact interface follows paper"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-F2F2BE0B8F7A3C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"threshold_signature"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-F37E413CA17216","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"threshold_signature"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-F42AEAC338C68C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"t-out-of-n threshold sharing under the paper notation"},{"dimension":"threshold_policy","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-F42FFA415E2C95","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"n-out-of-n in the instantiated n-party protocol"},{"dimension":"primitive","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-F438294074E24E","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"threshold_signature"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-F4C77F75D6C720","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"trustless-setup"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-F4F44A14027836","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"post-quantum"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-GKS.md","id":"TSIG-PROP-F51CB89491D928","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-GKS","value":"two-round"},{"dimension":"resilience","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-F5C48EB1F3ECA3","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"threshold signing under standard lattice assumptions"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-RACCOON.md","id":"TSIG-PROP-F6D6C0022EC673","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-RACCOON","value":"symmetric-and-simple-lattice-signing"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2023-OLAF.md","id":"TSIG-PROP-F7F5FA2A56CEEF","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2023-OLAF","value":"FROST3 profile plus DKG cost"},{"dimension":"preprocessing","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2017-LINDELL.md","id":"TSIG-PROP-F8950042B6C70C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2017-LINDELL","value":"offline work supported by protocol organization"},{"dimension":"construction_family","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2022-DILIZIUM2.md","id":"TSIG-PROP-F89AF8372A1366","review_status":"fulltext_preprint_reviewed_final_pending","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2022-DILIZIUM2","value":"lattice_fswa_distributed"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-DOTT.md","id":"TSIG-PROP-F91EF7825B3037","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-DOTT","value":"malicious adversary under the paper model"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-F9266E0129B22C","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"no; robust signing is left as future work"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-F964D0476D73CC","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"noninteractive online contribution after preprocessing"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2000-SHOUP.md","id":"TSIG-PROP-F9D70B8C45C285","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2000-SHOUP","value":"noninteractive-signature-shares"},{"dimension":"corruption_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2018-GG.md","id":"TSIG-PROP-FA8E14F2EA2AC3","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2018-GG","value":"malicious threshold adversary in the paper model"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-CGGMP.md","id":"TSIG-PROP-FBF1BA9B453D6C","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-CGGMP","value":"True"},{"dimension":"signing_rounds","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-FC0B99B3E29512","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"three"},{"dimension":"capability_tag","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-TANG.md","id":"TSIG-PROP-FC0EE5051D289F","review_status":"scheme_declared","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-TANG","value":"proactive-refresh"},{"dimension":"identifiable_abort","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2020-FROST.md","id":"TSIG-PROP-FCAE78104EA071","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2020-FROST","value":"operational participant identification in the paper protocol"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-1996-GJKR-DSS.md","id":"TSIG-PROP-FCE5E71273CE55","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-1996-GJKR-DSS","value":"paper gives distinct bounds for nonparticipation and incorrect partial signatures"},{"dimension":"robustness","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2003-BOLDYREVA.md","id":"TSIG-PROP-FCE90ADA603884","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2003-BOLDYREVA","value":"valid shares can be publicly checked in the pairing setting"},{"dimension":"setup_model","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-FLOOD.md","id":"TSIG-PROP-FD6FB42BF17C45","review_status":"primary_source_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-FLOOD","value":"robust DKG via random submersions"},{"dimension":"communication","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2021-GKMN.md","id":"TSIG-PROP-FF3D68E81E4C57","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2021-GKMN","value":"garbled-circuit and proof dependent"},{"dimension":"base_signature","evidence_ref":"knowledge/primitives/threshold-signature/schemes/TSIG-CONSTRUCTION-2024-AOMMLWE.md","id":"TSIG-PROP-FF738DDE4407E4","review_status":"fulltext_reviewed","scope":"construction","subject_id":"TSIG-CONSTRUCTION-2024-AOMMLWE","value":"Lyubashevsky-style lattice signature"}],"researchMap":{"lanes":[{"id":"foundation","label":"Foundation","question":"What is the problem, and what can be established or ruled out?"},{"id":"construction","label":"Construction","question":"How is the goal realized?"},{"id":"efficiency","label":"Efficiency","question":"Which resource cost or trade-off is advanced?"}],"nodes":{"TSIG-RESULT-1989-DF-DISTRIBUTED-RSA-SIGNING-ROOT":{"anchor_roles":[],"group":"construction","label":"Distributed RSA signing","lane_rationale":"Instantiates the threshold paradigm by distributing RSA private exponentiation rather than defining a separate notion.","lenses":["round_efficient_robust_signing"],"selection_rationale":"Shows the early RSA instantiation of the threshold paradigm; it remains related because GJKR and Shoup supply the robust, operationally sharper RSA lineage.","thread":"rsa_function_sharing","visibility":"reviewed_related"},"TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM":{"anchor_roles":[],"group":"foundation","label":"Distributed private-key operations","lane_rationale":"Formulates quorum-controlled private-key operations as the threshold-cryptosystem research interface, without claiming modern robustness for all instantiations.","lenses":[],"primary":true,"selection_rationale":"Preserves the original quorum-service boundary for private-key operations; bibliographic-level evidence and later robustness refinements keep it beside, rather than on, the default backbone.","thread":"threshold_foundations","visibility":"reviewed_related"},"TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER":{"anchor_roles":[],"group":"construction","label":"Dealerless discrete-log DKG","lane_rationale":"Provides a dealerless discrete-log key-generation protocol as an independently reusable setup mechanism.","lenses":["dealerless_setup"],"primary":true,"selection_rationale":"Keeps dealerless discrete-log setup visible as an independent component; the later GJKR result carries the robust malicious-minority transition on the backbone.","thread":"threshold_foundations","visibility":"reviewed_related"},"TSIG-RESULT-1996-GJKR-DSS-ROBUST-THRESHOLD-DSS":{"anchor_roles":[],"group":"construction","label":"Robust threshold DSS","lane_rationale":"Constructs threshold DSS with ordinary verification output and the paper's scoped resilience bound.","lenses":["round_efficient_robust_signing"],"primary":true,"selection_rationale":"Retains the first robust treatment of DSS's nonlinear signing equation without implying a generic compiler; its exact resilience bound is part of the contribution.","thread":"threshold_foundations","visibility":"reviewed_related"},"TSIG-RESULT-1996-GJKR-RSA-ROBUST-THRESHOLD-RSA-FUNCTION-SHARING":{"anchor_roles":[],"group":"construction","label":"Robust RSA function sharing","lane_rationale":"Gives verifiable robust sharing of RSA private operations under its stated setup and resilience conditions.","lenses":["round_efficient_robust_signing"],"primary":true,"selection_rationale":"Records the robust RSA-function-sharing baseline from which Shoup simplifies the signing path; bibliographic-level locators keep it as reviewed context.","thread":"rsa_function_sharing","visibility":"reviewed_related"},"TSIG-RESULT-1999-GJKR-DKG-ROBUST-DISCRETE-LOG-DKG":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Robust discrete-log DKG","lane_rationale":"Supplies the robust malicious-party DKG protocol, a setup mechanism separable from any one signing scheme.","lenses":["dealerless_setup","malicious_robustness_and_blame"],"primary":true,"selection_rationale":"Marks the point where dealerless key generation becomes a robust malicious-party protocol and an auditable component separable from any one signature scheme.","thread":"threshold_foundations","visibility":"backbone"},"TSIG-RESULT-2000-SHOUP-NONINTERACTIVE-SHARE-GENERATION":{"anchor_roles":[],"group":"efficiency","label":"Noninteractive RSA signature shares","lane_rationale":"Reduces the post-setup signing-share interaction requirement by allowing independent share production and checking; setup is explicitly excluded.","lenses":["round_efficient_robust_signing"],"selection_rationale":"Separates Shoup's post-setup noninteractive share path from the complete scheme, preventing the online round claim from silently including key generation.","thread":"rsa_function_sharing","visibility":"reviewed_related"},"TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Verifiable-share threshold RSA","lane_rationale":"Gives a complete robust RSA threshold-signature construction with publicly verifiable shares and ordinary RSA output.","lenses":["round_efficient_robust_signing","malicious_robustness_and_blame"],"primary":true,"selection_rationale":"Anchors the mature threshold-RSA branch with a complete robust scheme, publicly checkable shares, and ordinary RSA output rather than only an early distributed exponentiation idea.","thread":"rsa_function_sharing","visibility":"backbone"},"TSIG-RESULT-2003-BOLDYREVA-THRESHOLD-BLS-SIGNATURE":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Threshold BLS","lane_rationale":"Constructs threshold BLS by exponent sharing and combination of partial signatures without reconstructing the private key.","lenses":["round_efficient_robust_signing","interoperable_output_and_evaluation"],"primary":true,"selection_rationale":"Opens the pairing branch with exponent-share threshold BLS; its one-element ordinary-verifier output is kept as a neighboring capability rather than folded into the mechanism.","thread":"pairing_threshold_signatures","visibility":"backbone"},"TSIG-RESULT-2017-LINDELL-EFFICIENT-TWO-PARTY-ECDSA":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Paillier-based two-party ECDSA","lane_rationale":"Provides a concrete Paillier-based two-party protocol yielding an ordinary ECDSA signature, not a general t-out-of-n scheme.","lenses":["round_efficient_robust_signing"],"primary":true,"selection_rationale":"Establishes the Paillier-based two-party ECDSA baseline with ordinary verifier output; later multiparty work changes the participant setting rather than replacing this starting point.","thread":"ecdsa_paillier","visibility":"backbone"},"TSIG-RESULT-2018-DKLS-2P-HASH-PROOF-SYSTEM-ROUTE":{"anchor_roles":[],"group":"construction","label":"HPS-based ECDSA multiplication","lane_rationale":"Isolates the reusable HPS-based correlated-computation mechanism used in the ECDSA multiplication step.","lenses":["round_efficient_robust_signing"],"selection_rationale":"Isolates the hash-proof-system multiplication component so readers do not mistake the phrase Paillier-free for setup-free or for a complete scheme mechanism by itself.","thread":"ecdsa_ot_hps","visibility":"reviewed_related"},"TSIG-RESULT-2018-DKLS-2P-TWO-PARTY-ECDSA-WITHOUT-PAILLIER":{"anchor_roles":[],"group":"construction","label":"Paillier-free two-party ECDSA","lane_rationale":"Constructs two-party ECDSA using the HPS/OT route instead of Paillier multiplication, without implying setup-free or assumption-free signing.","lenses":["round_efficient_robust_signing"],"primary":true,"selection_rationale":"Preserves the Paillier-free ECDSA route as a serious alternative assumption stack; it remains related because the main ECDSA backbone follows the Paillier-to-multiparty transition.","thread":"ecdsa_ot_hps","visibility":"reviewed_related"},"TSIG-RESULT-2018-GG-DISTRIBUTED-SETUP":{"anchor_roles":[],"group":"construction","label":"Dealerless ECDSA setup","lane_rationale":"Provides dealerless setup of the distributed ECDSA key material as a distinct protocol component.","lenses":["dealerless_setup"],"selection_rationale":"Keeps trustless key generation beside GG18's multiparty signing result, making clear that dealerless setup is a component and not the later proactive-refresh guarantee.","thread":"ecdsa_paillier","visibility":"reviewed_related"},"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Multiparty threshold ECDSA","lane_rationale":"Realizes multiparty threshold ECDSA beyond the two-party setting while preserving ordinary verification output.","lenses":[],"primary":true,"selection_rationale":"Marks the participant-model transition from two parties to a genuine t-out-of-n ECDSA protocol while keeping the ordinary verification interface unchanged.","thread":"ecdsa_paillier","visibility":"backbone"},"TSIG-RESULT-2019-DKLS-N-GENERAL-THRESHOLD-ECDSA":{"anchor_roles":[],"group":"construction","label":"General Paillier-free threshold ECDSA","lane_rationale":"Extends the Paillier-free route to a general threshold protocol; the broad bibliographic claim is retained without new exact theorem or performance coordinates.","lenses":["round_efficient_robust_signing"],"primary":true,"selection_rationale":"Extends the alternative DKLS assumption route to general quorums; bibliographic-level evidence keeps it reviewed-related and prevents unsupported UC or performance comparisons.","thread":"ecdsa_ot_hps","visibility":"reviewed_related"},"TSIG-RESULT-2020-CGGMP-IDENTIFIABLE-ABORT":{"anchor_roles":[],"group":"construction","label":"Identifiable ECDSA abort","lane_rationale":"Provides the protocol's accountable-abort mechanism identifying a misbehaving participant, without treating blame as liveness.","lenses":["malicious_robustness_and_blame"],"selection_rationale":"Records accountable failure without implying liveness; it remains related because the UC security treatment carries the paper's primary map position.","thread":"ecdsa_paillier","visibility":"reviewed_related"},"TSIG-RESULT-2020-CGGMP-ONE-MESSAGE-DEPENDENT-ONLINE-ROUND":{"anchor_roles":[],"group":"efficiency","label":"One online CGGMP round","lane_rationale":"Moves message-independent work to preprocessing so only one signing round depends on the message, without claiming one round end to end.","lenses":["round_efficient_robust_signing"],"selection_rationale":"Separates message-dependent latency from the paper's UC theorem; it stays related because the complete protocol still includes a multi-round preprocessing phase.","thread":"ecdsa_paillier","visibility":"reviewed_related"},"TSIG-RESULT-2020-CGGMP-PROACTIVE-SECURITY":{"anchor_roles":[],"group":"construction","label":"Proactive ECDSA share refresh","lane_rationale":"Implements share renewal across epochs while retaining the verification key; the refresh mechanism depends on explicit erasure and corruption conditions.","lenses":["proactive_refresh"],"selection_rationale":"Makes epoch-based share refresh visible as a lifecycle guarantee, while keeping its erasure and corruption assumptions separate from the core UC-signing claim.","thread":"ecdsa_paillier","visibility":"reviewed_related"},"TSIG-RESULT-2020-CGGMP-UC-THRESHOLD-ECDSA":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Adaptive UC threshold ECDSA","lane_rationale":"Realizes threshold ECDSA with adaptive UC security in the global random-oracle model; the security advance belongs to the stronger-secure protocol rather than a generic assumption label.","lenses":["adaptive_corruption_security","proof_models_and_assumptions"],"primary":true,"selection_rationale":"Marks the composable-security transition for practical multiparty ECDSA; preprocessing, proactive refresh, and blame remain separately inspectable coordinates rather than one compound label.","thread":"ecdsa_paillier","visibility":"backbone"},"TSIG-RESULT-2020-FROST-ONE-ROUND-WITH-PREPROCESSING":{"anchor_roles":[],"group":"efficiency","label":"One online FROST round","lane_rationale":"Reduces message-dependent online interaction to one round using fresh preprocessed nonces, with preprocessing still counted separately.","lenses":["round_efficient_robust_signing"],"selection_rationale":"Preserves the latency optimization while stating its accounting boundary explicitly; one online round must not be presented as one round end to end.","thread":"schnorr_nonce_protocols","visibility":"reviewed_related"},"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Two-round t-out-of-n FROST","lane_rationale":"Defines the complete two-round t-out-of-n Schnorr signing workflow, keeping the nonce-preprocessing latency result separate.","lenses":["round_efficient_robust_signing"],"primary":true,"selection_rationale":"Anchors the Schnorr branch with a true t-out-of-n two-round signing workflow; preprocessing and malformed-share handling remain separate neighboring contributions.","thread":"schnorr_nonce_protocols","visibility":"backbone"},"TSIG-RESULT-2021-DOTT-ABORT-LEAKAGE-COUNTERMEASURE":{"anchor_roles":[],"group":"construction","label":"Abort-leakage trapdoor commitments","lane_rationale":"Provides the homomorphic trapdoor-commitment countermeasure that protects the DOTT protocol's abort transcripts, not a generic impossibility or security analysis.","lenses":["post_quantum_thresholding","abort_leakage_security"],"selection_rationale":"Makes abort leakage a first-class security problem and records DOTT's protocol-specific repair; it remains related because it is a component of the complete construction.","thread":"lattice_fswa_threshold","visibility":"reviewed_related"},"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Two-round n-out-of-n lattice signing","lane_rationale":"Gives a concrete two-round lattice signing protocol for full n-out-of-n participation, not arbitrary threshold participation.","lenses":["post_quantum_thresholding","round_efficient_robust_signing"],"primary":true,"selection_rationale":"Establishes two-round lattice Fiat–Shamir-with-aborts signing at the n-out-of-n boundary, giving later arbitrary-threshold work a precise starting point.","thread":"lattice_fswa_threshold","visibility":"backbone"},"TSIG-RESULT-2021-GKMN-STATELESS-DETERMINISTIC-THRESHOLD-SCHNORR":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Stateless deterministic threshold Schnorr","lane_rationale":"Builds deterministic stateless threshold Schnorr using nonce-generation and proof machinery, realizing a distinct operational contract.","lenses":["round_efficient_robust_signing"],"primary":true,"selection_rationale":"Marks a different operational contract for dishonest-majority Schnorr signing, replacing fresh randomness and evolving state with deterministic nonce machinery.","thread":"schnorr_nonce_protocols","visibility":"backbone"},"TSIG-RESULT-2022-DILIZIUM2-TWO-PARTY-DILITHIUM-LINE":{"anchor_roles":[],"group":"construction","label":"Three-round two-party Dilithium","lane_rationale":"Constructs the audited three-round two-party DOTT-related protocol with Dilithium compression; its outdated preprint and limited party setting remain explicit.","lenses":["post_quantum_thresholding"],"primary":true,"selection_rationale":"Keeps the full-text-audited three-round two-party Dilithium-oriented point visible without promoting it to arbitrary-threshold or ML-DSA compatibility; the available ePrint is explicitly outdated relative to the journal version.","thread":"lattice_fswa_threshold","visibility":"reviewed_related"},"TSIG-RESULT-2023-GKS-ACTIVELY-SECURE-THRESHOLD-LINEAR-HE":{"anchor_roles":[],"group":"construction","label":"Actively secure threshold linear HE","lane_rationale":"Provides the actively secure threshold-LHE aggregation layer as an independently meaningful signing component.","lenses":["post_quantum_thresholding"],"selection_rationale":"Keeps the actively secure linear-HE layer independently inspectable so the GKS threshold generalization is not misread as avoiding homomorphic machinery.","thread":"lattice_fswa_threshold","visibility":"reviewed_related"},"TSIG-RESULT-2023-GKS-TWO-ROUND-ARBITRARY-THRESHOLD-LATTICE-SIGNATURE":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Two-round t-out-of-n lattice signing","lane_rationale":"Realizes arbitrary t-out-of-n lattice signing in two rounds through threshold linear HE, a new construction setting rather than unconditional efficiency dominance.","lenses":["post_quantum_thresholding","round_efficient_robust_signing"],"primary":true,"selection_rationale":"Marks the shift from DOTT's full participation to arbitrary t-out-of-n signing while retaining two rounds, with threshold linear HE made explicit as the enabling cost.","thread":"lattice_fswa_threshold","visibility":"backbone"},"TSIG-RESULT-2023-OLAF-PROOF-WITHOUT-AGM":{"anchor_roles":["capability_boundary"],"group":"foundation","label":"FROST proof without AGM","lane_rationale":"The principal contribution is a FROST-variant unforgeability analysis without AGM, retaining AOMDL and the random-oracle model.","lenses":["proof_models_and_assumptions"],"primary":true,"selection_rationale":"Represents the proof-model transition away from AGM for a FROST-style protocol while leaving AOMDL and the random oracle visible as the replacement assumptions.","thread":"schnorr_nonce_protocols","visibility":"backbone"},"TSIG-RESULT-2024-AOMMLWE-OFFLINE-ONLINE-SIGNING":{"anchor_roles":[],"group":"efficiency","label":"Signer-independent offline lattice phase","lane_rationale":"Makes the first round independent of both message and signer set to reduce online completion work, without removing total offline interaction.","lenses":["round_efficient_robust_signing"],"selection_rationale":"Separates signer-set- and message-independent preprocessing from the complete two-round scheme so online latency is not confused with total interaction.","thread":"lattice_fswa_threshold","visibility":"reviewed_related"},"TSIG-RESULT-2024-AOMMLWE-TWO-ROUND-LATTICE-THRESHOLD-WITHOUT-FHE":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Two-round lattice signing without FHE","lane_rationale":"Constructs two-round threshold lattice signing without FHE or homomorphic trapdoor commitments, under the explicit adaptive AOM-MLWE assumption.","lenses":["post_quantum_thresholding","round_efficient_robust_signing"],"primary":true,"selection_rationale":"Anchors the two-round lattice route that avoids FHE and homomorphic trapdoor commitments, while exposing AOM-MLWE rather than suggesting an assumption-free simplification.","thread":"lattice_fswa_threshold","visibility":"backbone"},"TSIG-RESULT-2024-FLOOD-FIRST-HASH-AND-SIGN-LATTICE-THRESHOLD-SIGNATURE":{"anchor_roles":["reusable_mechanism"],"group":"construction","label":"Lattice threshold hash-and-sign","lane_rationale":"Constructs a robust distributed GPV-style hash-and-sign protocol rather than a universal compiler for every lattice signature.","lenses":["post_quantum_thresholding"],"primary":true,"selection_rationale":"Opens a lattice hash-and-sign threshold branch distinct from abort-based designs; the distributed short-secret tools are kept as companion mechanisms.","thread":"lattice_hash_sign_threshold","visibility":"backbone"},"TSIG-RESULT-2024-FLOOD-RANDOM-SUBMERSIONS":{"anchor_roles":[],"group":"construction","label":"Random-submersion short-share proofs","lane_rationale":"Supplies the random-submersion mechanism for verifiable sharing of short lattice secrets, with noise flooding and parameters retained.","lenses":["post_quantum_thresholding"],"selection_rationale":"Records the short-share verification mechanism required by Flood and Submerse without presenting it as either a complete DKG or a standalone signature.","thread":"lattice_hash_sign_threshold","visibility":"reviewed_related"},"TSIG-RESULT-2024-GLACIUS-FULLY-ADAPTIVE-THRESHOLD-SCHNORR-FROM-DDH":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Fully adaptive DDH threshold Schnorr","lane_rationale":"Provides the stronger-secure threshold Schnorr protocol achieving full adaptivity from DDH in the ROM with identifiable abort; it is not only a reproof of an unchanged protocol.","lenses":["adaptive_corruption_security","proof_models_and_assumptions"],"primary":true,"selection_rationale":"Marks the corruption-timing frontier for threshold Schnorr by combining full t<n adaptivity from DDH in the ROM with constant-size signing keys and identifiable abort.","thread":"schnorr_nonce_protocols","visibility":"backbone"},"TSIG-RESULT-2024-RACCOON-EFFICIENT-LARGE-THRESHOLD-LATTICE-SIGNING":{"anchor_roles":["capability_boundary"],"group":"efficiency","label":"Three-round lattice signing through T=1024","lane_rationale":"Establishes a contextual concrete size-and-scale point through threshold 1024 with a three-round profile, not a normalized cross-paper benchmark ranking.","lenses":["post_quantum_thresholding","round_efficient_robust_signing"],"primary":true,"selection_rationale":"Anchors the practical standard-lattice scale point with a full-text-audited three-round protocol, concrete T=1024 parameters, and implementation tables; trusted KeyGen and non-robust abort behavior remain explicit coordinates.","thread":"lattice_fswa_threshold","visibility":"backbone"},"TSIG-RESULT-2024-RACCOON-ONE-TIME-ADDITIVE-MASK-DEFENSE":{"anchor_roles":[],"group":"construction","label":"Additive-mask abort-leakage defense","lane_rationale":"Introduces the session-unique pairwise additive-mask mechanism preventing accumulated partial-signature leakage, with mask non-reuse conditions explicit.","lenses":["post_quantum_thresholding","abort_leakage_security"],"selection_rationale":"Exposes the full-text-audited pairwise one-time-mask mechanism behind Raccoon's scale claim; it remains related because session-unique PRF masking is a component, not a generic repair for all lattice threshold signatures.","thread":"lattice_fswa_threshold","visibility":"reviewed_related"},"TSIG-RESULT-2024-TANG-FUNCTIONAL-INTERCHANGEABILITY":{"anchor_roles":["capability_boundary"],"group":"construction","label":"Ordinary-verifier lattice threshold signing","lane_rationale":"Constructs threshold lattice signing whose output follows the selected ordinary scheme's verification interface, without asserting ML-DSA compatibility.","lenses":["interoperable_output_and_evaluation","post_quantum_thresholding"],"primary":true,"selection_rationale":"Anchors ordinary-verifier interchangeability with full-text evidence that DSign outputs the base scheme's conventional signature format and that key/signature sizes are independent of the participant count; this remains distinct from ML-DSA compatibility.","thread":"threshold_package_interfaces","visibility":"backbone"},"TSIG-RESULT-2024-TANG-PROACTIVE-REFRESH":{"anchor_roles":[],"group":"construction","label":"Proactive lattice share refresh","lane_rationale":"Provides a proactive lattice share-renewal procedure preserving the public key under the paper's epoch and corruption model.","lenses":["proactive_refresh"],"selection_rationale":"Keeps Theorem 2's proactive share renewal as a lifecycle coordinate rather than merging it with construction or interoperability; the at-most-t-1 corruption bound per refresh period remains explicit.","thread":"threshold_package_interfaces","visibility":"reviewed_related"}},"overview_reading_path":["TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA","TSIG-RESULT-2003-BOLDYREVA-THRESHOLD-BLS-SIGNATURE","TSIG-RESULT-2017-LINDELL-EFFICIENT-TWO-PARTY-ECDSA","TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","TSIG-RESULT-2023-GKS-TWO-ROUND-ARBITRARY-THRESHOLD-LATTICE-SIGNATURE","TSIG-RESULT-2024-TANG-FUNCTIONAL-INTERCHANGEABILITY","TSIG-RESULT-2024-RACCOON-EFFICIENT-LARGE-THRESHOLD-LATTICE-SIGNING","TSIG-RESULT-2024-AOMMLWE-TWO-ROUND-LATTICE-THRESHOLD-WITHOUT-FHE","TSIG-RESULT-2024-GLACIUS-FULLY-ADAPTIVE-THRESHOLD-SCHNORR-FROM-DDH"],"problems":[{"id":"dealerless_setup","label":"Dealerless setup","question":"How can parties create consistent threshold keys without entrusting the full secret to one dealer?","reading_path":["TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER","TSIG-RESULT-1999-GJKR-DKG-ROBUST-DISCRETE-LOG-DKG","TSIG-RESULT-2018-GG-DISTRIBUTED-SETUP"]},{"id":"proactive_refresh","label":"Proactive share refresh","question":"How can parties renew shares across epochs while preserving the public key and limiting cumulative compromise?","reading_path":["TSIG-RESULT-2020-CGGMP-PROACTIVE-SECURITY","TSIG-RESULT-2024-TANG-PROACTIVE-REFRESH"]},{"id":"round_efficient_robust_signing","label":"Round-efficient robust signing","question":"Which protocol families reduce online rounds and communication without giving up robustness?","reading_path":["TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA","TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","TSIG-RESULT-2024-RACCOON-EFFICIENT-LARGE-THRESHOLD-LATTICE-SIGNING","TSIG-RESULT-2024-AOMMLWE-OFFLINE-ONLINE-SIGNING"]},{"id":"adaptive_corruption_security","label":"Adaptive corruption security","question":"Which protocols remain secure when the adversary chooses corruptions during execution rather than fixing them in advance?","reading_path":["TSIG-RESULT-2020-CGGMP-UC-THRESHOLD-ECDSA","TSIG-RESULT-2024-GLACIUS-FULLY-ADAPTIVE-THRESHOLD-SCHNORR-FROM-DDH"]},{"id":"proof_models_and_assumptions","label":"Proof models and assumptions","question":"Which proof-model or hardness assumptions underwrite deployable threshold signing, and what changes when one is removed?","reading_path":["TSIG-RESULT-2020-CGGMP-UC-THRESHOLD-ECDSA","TSIG-RESULT-2023-OLAF-PROOF-WITHOUT-AGM","TSIG-RESULT-2024-GLACIUS-FULLY-ADAPTIVE-THRESHOLD-SCHNORR-FROM-DDH"]},{"id":"malicious_robustness_and_blame","label":"Malicious robustness and blame","question":"How do protocols preserve consistency or identify deviators when participants submit malformed setup or signing shares?","reading_path":["TSIG-RESULT-1999-GJKR-DKG-ROBUST-DISCRETE-LOG-DKG","TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA","TSIG-RESULT-2020-CGGMP-IDENTIFIABLE-ABORT"]},{"id":"abort_leakage_security","label":"Abort-leakage security","question":"How do lattice protocols prevent repeated partial signatures and abort transcripts from leaking distributed signing secrets?","reading_path":["TSIG-RESULT-2021-DOTT-ABORT-LEAKAGE-COUNTERMEASURE","TSIG-RESULT-2024-RACCOON-ONE-TIME-ADDITIVE-MASK-DEFENSE"]},{"id":"post_quantum_thresholding","label":"Post-quantum thresholding","question":"How can lattice signing tolerate distributed secrets, abort leakage, and arbitrary thresholds?","reading_path":["TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","TSIG-RESULT-2023-GKS-TWO-ROUND-ARBITRARY-THRESHOLD-LATTICE-SIGNATURE","TSIG-RESULT-2024-RACCOON-ONE-TIME-ADDITIVE-MASK-DEFENSE","TSIG-RESULT-2024-FLOOD-FIRST-HASH-AND-SIGN-LATTICE-THRESHOLD-SIGNATURE","TSIG-RESULT-2024-AOMMLWE-TWO-ROUND-LATTICE-THRESHOLD-WITHOUT-FHE"]},{"id":"interoperable_output_and_evaluation","label":"Interoperable output and evaluation","question":"Which results preserve ordinary verification and support comparable, swappable threshold packages?","reading_path":["TSIG-RESULT-2024-TANG-FUNCTIONAL-INTERCHANGEABILITY"]}],"relations":[{"change_dimensions":["functionality","security"],"evidence_locator":"GJKR CRYPTO 1996 paper, overview and robustness sections","evidence_url":"https://doi.org/10.1007/3-540-68697-5","id":"lineage-4b2079cd4776f1d4","map_relation":"reference","predecessor":"TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM","relation_basis":"model_relation","relation_type":"STRENGTHENS_ROBUSTNESS","review_status":"bibliographic_checked","statement":"GJKR develops the shared-RSA branch with verifiable shares and robustness against malicious behavior rather than only distributing the private operation.","successor":"TSIG-RESULT-1996-GJKR-RSA-ROBUST-THRESHOLD-RSA-FUNCTION-SHARING"},{"change_dimensions":["functionality","security"],"evidence_locator":"EUROCRYPT 1996 paper and journal abstract","evidence_url":"https://doi.org/10.1007/3-540-68339-9_31","id":"lineage-cda7b4f9c280a1a9","map_relation":"lineage","predecessor":"TSIG-RESULT-1989-DF-THRESHOLD-CRYPTOSYSTEM-PARADIGM","relation_basis":"model_relation","relation_type":"INSTANTIATES_MODEL","review_status":"primary_source_checked","statement":"GJKR realizes quorum-controlled signing for the DSS signing equation, producing ordinary DSS signatures with the construction's stated resilience and robustness conditions.","successor":"TSIG-RESULT-1996-GJKR-DSS-ROBUST-THRESHOLD-DSS"},{"change_dimensions":["efficiency","security"],"evidence_locator":"Shoup abstract and Introduction","evidence_url":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","id":"lineage-8fda5840e1592622","map_relation":"lineage","predecessor":"TSIG-RESULT-1989-DF-DISTRIBUTED-RSA-SIGNING-ROOT","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"Relative to early distributed RSA private operations, Shoup gives a robust signing construction whose servers independently produce publicly checkable shares after setup; this does not compare total key-generation costs.","successor":"TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA"},{"change_dimensions":["efficiency"],"evidence_locator":"Shoup related-work comparison and construction overview","evidence_url":"https://www.iacr.org/archive/eurocrypt2000/1807/18070209-new.pdf","id":"lineage-c3900192af553495","map_relation":"lineage","predecessor":"TSIG-RESULT-1996-GJKR-RSA-ROBUST-THRESHOLD-RSA-FUNCTION-SHARING","relation_basis":"result_progression","relation_type":"IMPROVES_EFFICIENCY","review_status":"primary_source_checked","statement":"Shoup presents a more practical robust threshold-RSA signature protocol with noninteractive signature shares and direct share verification.","successor":"TSIG-RESULT-2000-SHOUP-PRACTICAL-ROBUST-THRESHOLD-RSA"},{"change_dimensions":["mechanism","security"],"evidence_locator":"GJKR DKG abstract, introduction, and protocol comparison","evidence_url":"https://doi.org/10.1007/3-540-48910-X_21","id":"lineage-f56a15cafa1c01a0","map_relation":"lineage","predecessor":"TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER","relation_basis":"technical_dependency","relation_type":"STRENGTHENS_ROBUSTNESS","review_status":"primary_source_checked","statement":"GJKR revisits discrete-log DKG and supplies a robust malicious-security treatment for distributed key generation.","successor":"TSIG-RESULT-1999-GJKR-DKG-ROBUST-DISCRETE-LOG-DKG"},{"change_dimensions":["functionality","model"],"evidence_locator":"GG18 abstract, introduction, and prior-work comparison","evidence_url":"https://eprint.iacr.org/2019/114","id":"lineage-b057307e7c3a8cef","map_relation":"lineage","predecessor":"TSIG-RESULT-2017-LINDELL-EFFICIENT-TWO-PARTY-ECDSA","relation_basis":"result_progression","relation_type":"GENERALIZES","review_status":"primary_source_checked","statement":"GG18 moves the practical Paillier-based ECDSA line from two parties to a general multiparty threshold setting with distributed setup.","successor":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA"},{"change_dimensions":["functionality","model"],"evidence_locator":"IEEE paper abstract and construction overview","evidence_url":"https://doi.org/10.1109/SP.2019.00024","id":"lineage-4882646609f024ab","map_relation":"reference","predecessor":"TSIG-RESULT-2018-DKLS-2P-TWO-PARTY-ECDSA-WITHOUT-PAILLIER","relation_basis":"technical_dependency","relation_type":"GENERALIZES","review_status":"bibliographic_checked","statement":"The later DKLS threshold construction generalizes the two-party OT/hash-proof-system route to a general threshold protocol.","successor":"TSIG-RESULT-2019-DKLS-N-GENERAL-THRESHOLD-ECDSA"},{"change_dimensions":["mechanism","security","assumption"],"evidence_locator":"CGGMP revised full version, abstract and contribution overview","evidence_url":"https://eprint.iacr.org/2021/060","id":"lineage-6d3c0970b57f2535","map_relation":"lineage","predecessor":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA","relation_basis":"technical_dependency","relation_type":"STRENGTHENS_SECURITY","review_status":"primary_source_checked","statement":"Building on GG18, CGGMP strengthens the practical multiparty-ECDSA line with an adaptive UC treatment in the global random-oracle model.","successor":"TSIG-RESULT-2020-CGGMP-UC-THRESHOLD-ECDSA"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"CGGMP revised full version, abstract and contribution overview","evidence_url":"https://eprint.iacr.org/2021/060","id":"lineage-a8ff659af0c3e1c8","map_relation":"lineage","predecessor":"TSIG-RESULT-2018-GG-MULTIPARTY-THRESHOLD-ECDSA","relation_basis":"technical_dependency","relation_type":"IMPROVES_ONLINE_INTERACTION","review_status":"primary_source_checked","statement":"Building on GG18, CGGMP moves all message-independent signing rounds into preprocessing and leaves one message-dependent online round.","successor":"TSIG-RESULT-2020-CGGMP-ONE-MESSAGE-DEPENDENT-ONLINE-ROUND"},{"change_dimensions":["mechanism"],"evidence_locator":"FROST Sections 2.3 and 5.1, Figure 1, PDF pp. 6–10","evidence_url":"https://eprint.iacr.org/2020/852","id":"lineage-3f68d7d50c326c14","map_relation":"lineage","predecessor":"TSIG-RESULT-1991-PEDERSEN-DISTRIBUTED-KEY-GENERATION-WITHOUT-DEALER","relation_basis":"technical_dependency","relation_type":"COMPOSES_SETUP","review_status":"fulltext_checked","statement":"FROST can be composed with a discrete-log DKG to create the shared Schnorr key, while its paper focuses on round-optimized signing.","successor":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR"},{"change_dimensions":["assumption","security"],"evidence_locator":"Olaf abstract and Introduction","evidence_url":"https://eprint.iacr.org/2023/899","id":"lineage-ad45a8a5f4457dd1","map_relation":"lineage","predecessor":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","relation_basis":"analysis","relation_type":"REFINES_PROOF","review_status":"primary_source_checked","statement":"Olaf combines the efficient FROST3 variant with a Pedersen-DKG variant and proves unforgeability without the algebraic group model.","successor":"TSIG-RESULT-2023-OLAF-PROOF-WITHOUT-AGM"},{"change_dimensions":["security","assumption"],"evidence_locator":"Glacius abstract and Introduction","evidence_url":"https://eprint.iacr.org/2024/1628","id":"lineage-e5bac67f73dd8bc9","map_relation":"lineage","predecessor":"TSIG-RESULT-2020-FROST-TWO-ROUND-THRESHOLD-SCHNORR","relation_basis":"result_progression","relation_type":"STRENGTHENS_ADAPTIVE_SECURITY","review_status":"primary_source_checked","statement":"Glacius changes the security point to fully adaptive corruptions from DDH while retaining compact Schnorr output and adding a formal identifiable-abort guarantee.","successor":"TSIG-RESULT-2024-GLACIUS-FULLY-ADAPTIVE-THRESHOLD-SCHNORR-FROM-DDH"},{"change_dimensions":["mechanism","model"],"evidence_locator":"DiLizium 2.0 Sections 1.1–1.2, PDF pp. 2–3; audited ePrint is marked outdated","evidence_url":"https://eprint.iacr.org/2022/644","id":"lineage-b1db2af00ef2f812","map_relation":"lineage","predecessor":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","relation_basis":"technical_dependency","relation_type":"CHANGES_ENCODING","review_status":"fulltext_checked","statement":"DiLizium 2.0 follows the DOTT commitment-based logic but incorporates Dilithium signature-compression techniques in a two-party authentication setting.","successor":"TSIG-RESULT-2022-DILIZIUM2-TWO-PARTY-DILITHIUM-LINE"},{"change_dimensions":["functionality","mechanism"],"evidence_locator":"GKS Section 5, Figure 7 and Theorem 3, PDF pp. 22–26","evidence_url":"https://eprint.iacr.org/2023/1318","id":"lineage-6e0afa13b8126f01","map_relation":"lineage","predecessor":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","relation_basis":"result_progression","relation_type":"GENERALIZES_THRESHOLD","review_status":"fulltext_checked","statement":"GKS preserves two signing rounds while moving from DOTT's full n-out-of-n threshold to arbitrary t<=n through threshold linearly homomorphic encryption.","successor":"TSIG-RESULT-2023-GKS-TWO-ROUND-ARBITRARY-THRESHOLD-LATTICE-SIGNATURE"},{"change_dimensions":["mechanism","efficiency"],"evidence_locator":"Threshold Raccoon Section 1.1, PDF pp. 4–5; Sections 2.3 and 6; Tables 2–3, PDF pp. 8–10, 20–23, and 43–44","evidence_url":"https://eprint.iacr.org/2024/184","id":"lineage-68ecdf4c514cbbd6","map_relation":"lineage","predecessor":"TSIG-RESULT-2021-DOTT-TWO-ROUND-N-OUT-OF-N-LATTICE-SIGNING","relation_basis":"result_progression","relation_type":"CHANGES_ROUNDS_AND_MECHANISM","review_status":"fulltext_checked","statement":"Threshold Raccoon trades DOTT's two-round homomorphic-trapdoor-commitment route for a three-round, pairwise-mask design with concrete parameter sets through T=1024.","successor":"TSIG-RESULT-2024-RACCOON-EFFICIENT-LARGE-THRESHOLD-LATTICE-SIGNING"},{"change_dimensions":["mechanism","assumption","efficiency"],"evidence_locator":"AOM-MLWE Sections 1.1, 2.1, and 6.2, Figures 2 and 8, Theorem 6.1, PDF pp. 4–10 and 33–36","evidence_url":"https://eprint.iacr.org/2024/496","id":"lineage-cf6440663e2f13d5","map_relation":"lineage","predecessor":"TSIG-RESULT-2024-RACCOON-ONE-TIME-ADDITIVE-MASK-DEFENSE","relation_basis":"technical_dependency","relation_type":"CHANGES_ASSUMPTION_AND_ROUNDS","review_status":"fulltext_checked","statement":"Starting from Threshold Raccoon's pairwise-mask approach, the AOM-MLWE construction reduces signing from three rounds to two and makes the first round message- and signer-set-independent by introducing an algebraic one-more lattice assumption.","successor":"TSIG-RESULT-2024-AOMMLWE-TWO-ROUND-LATTICE-THRESHOLD-WITHOUT-FHE"}],"rubric_version":1,"schema_version":1,"selection_policy":"semantic_contract_anchors","threads":[{"color":"#667784","description":"Threshold cryptosystem interfaces, secret sharing, dealerless setup, and robust DKG.","id":"threshold_foundations","label":"Threshold definitions and sharing"},{"color":"#8b6340","description":"Distributed RSA evaluation and robust noninteractive signature-share combination.","id":"rsa_function_sharing","label":"RSA function sharing"},{"color":"#9a6a32","description":"Compact and unique threshold signatures in pairing groups.","id":"pairing_threshold_signatures","label":"Pairing threshold signatures"},{"color":"#2f718e","description":"Two-party and multiparty ECDSA built from Paillier-style multiplication and range proofs.","id":"ecdsa_paillier","label":"ECDSA with Paillier-style MPC"},{"color":"#b65358","description":"Paillier-free ECDSA routes based on oblivious transfer and hash-proof systems.","id":"ecdsa_ot_hps","label":"ECDSA with OT and hash proofs"},{"color":"#73549a","description":"Round-efficient Schnorr signing, deterministic nonces, identifiable aborts, and adaptive security.","id":"schnorr_nonce_protocols","label":"Schnorr nonce protocols"},{"color":"#4f7b60","description":"Threshold lattice signatures using abort-aware masking, threshold HE, and offline/online protocols.","id":"lattice_fswa_threshold","label":"Lattice Fiat–Shamir with aborts"},{"color":"#876b22","description":"Robust distributed trapdoors and short-share handling for lattice hash-and-sign.","id":"lattice_hash_sign_threshold","label":"Lattice hash-and-sign"},{"color":"#6c5a91","description":"Ordinary-verifier outputs, implementation interchangeability, and evaluation-package interfaces.","id":"threshold_package_interfaces","label":"Interoperable threshold packages"}]},"stats":{"constructions":20,"countsByType":{"assumption":20,"barrier":2,"construction":20,"open_problem":1,"paper":24,"result":44,"route":3},"entities":114,"lineageRelationships":14,"propertyAssertions":370,"relationships":126,"unresolvedReferences":0},"unresolved":[],"sourceCommit":"v0.2.0","sourceBoundary":"Published literature snapshot"}