International Association for Cryptologic Research

International Association
for Cryptologic Research

Eurocrypt 2026

Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDH


Paul Gerhart
TU Wien

Davide Li Calsi
TU Wien

Luigi Russo
TU Wien

Dominique Schröder
TU Wien


Keywords: threshold signatures, Schnorr signatures, adaptive security, distributed cryptography, DDH


Abstract

Threshold Schnorr signatures enable $t$-out-of-$n$ parties to collaboratively produce signatures that are indistinguishable from standard Schnorr signatures, ensuring compatibility with existing verification systems. While constructions achieving static security are well understood and attain optimal round complexity, achieving full adaptive security that tolerates up to $t-1$ dynamic corruptions under standard assumptions remains a longstanding and unresolved challenge: Recent impossibility results (CRYPTO’25) either rule out known proof techniques for widely deployed schemes or require speculative assumptions and idealized models, while positive examples achieving full adaptivity from falsifiable assumptions incur higher round complexity (EUROCRYPT’25, CRYPTO’25).

We overcome these barriers with the first round-optimal threshold Schnorr signature scheme that, under a slightly relaxed security model, achieves full adaptive security from DDH in the random oracle model.

Our model is relaxed in the sense that the adversary may adaptively corrupt parties at any time, but each signer must refresh part of their public key after a fixed number of signing queries. These updates are executed via lightweight, succinct, stateless tokens, preserving the aggregated signature format. Our construction is enabled by a new proof technique, equivocal deterministic nonce derivation, which may be of independent interest.

Publication

EUROCRYPT 2026, LNCS 16542

Paper

Artifact

Artifact number
eurocrypt/2026/a1

Artifact published
July 25, 2026

Badge
🏆 IACR EUROCRYPT Results Reproduced

README

ZIP (125 KB)  

View on Github

License
This work is licensed under the MIT License.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Paul Gerhart, Davide Li Calsi, Luigi Russo, and Dominique Schröder. (2026). Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDH. In Advances in Cryptology – EUROCRYPT 2026, Lecture Notes in Computer Science vol. 16542, pp. 251–283, Springer. https://doi.org/10.1007/978-3-032-25317-0_9. Artifact at https://artifacts.iacr.org/eurocrypt/2026/a1.