Eurocrypt 2026
Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDH
Paul Gerhart
TU Wien
Davide Li Calsi
TU Wien
Luigi Russo
TU Wien
Dominique Schröder
TU Wien
Keywords: threshold signatures, Schnorr signatures, adaptive security, distributed cryptography, DDH
Abstract
Threshold Schnorr signatures enable $t$-out-of-$n$ parties to collaboratively produce signatures that are indistinguishable from standard Schnorr signatures, ensuring compatibility with existing verification systems. While constructions achieving static security are well understood and attain optimal round complexity, achieving full adaptive security that tolerates up to $t-1$ dynamic corruptions under standard assumptions remains a longstanding and unresolved challenge: Recent impossibility results (CRYPTO’25) either rule out known proof techniques for widely deployed schemes or require speculative assumptions and idealized models, while positive examples achieving full adaptivity from falsifiable assumptions incur higher round complexity (EUROCRYPT’25, CRYPTO’25).
We overcome these barriers with the first round-optimal threshold Schnorr signature scheme that, under a slightly relaxed security model, achieves full adaptive security from DDH in the random oracle model.
Our model is relaxed in the sense that the adversary may adaptively corrupt parties at any time, but each signer must refresh part of their public key after a fixed number of signing queries. These updates are executed via lightweight, succinct, stateless tokens, preserving the aggregated signature format. Our construction is enabled by a new proof technique, equivocal deterministic nonce derivation, which may be of independent interest.
Publication
EUROCRYPT 2026, LNCS 16542
PaperArtifact
Artifact number
eurocrypt/2026/a1
Artifact published
July 25, 2026
Badge
🏆 IACR EUROCRYPT Results Reproduced
License
This work is licensed under the MIT License.
Note that license information is supplied by the authors and has not been confirmed by the IACR.
BibTeX How to cite
Paul Gerhart, Davide Li Calsi, Luigi Russo, and Dominique Schröder. (2026). Fully-Adaptive Two-Round Threshold Schnorr Signatures from DDH. In Advances in Cryptology – EUROCRYPT 2026, Lecture Notes in Computer Science vol. 16542, pp. 251–283, Springer. https://doi.org/10.1007/978-3-032-25317-0_9. Artifact at https://artifacts.iacr.org/eurocrypt/2026/a1.