The NIST Threshold Call (NIST IR 8214C) specified three "Previews" phases where teams submit a Preview Writeup and give a Preview Talk presenting the team's plan for an upcoming package submission.
Upcoming event: TCPT #2 (July 07–08): Threshold Call Preview Talks Round 2 (ZoomGov link)
• Previews Talks Phase 1: Presented at MPTS 2026 (Jan 26–29)
• Previews Talks Phase 2: Presented at TCPT2 (July 07–08). (Schedule below. Free online registration.)
• Previews Talks Phase 3: Upcoming (Writeups by July 31; Talks TBA)
Participation in any session of Preview Talks requires abiding by the Code of Conduct for NIST conferences.
Preview writeups are posted in the MPTC website, within the submissions webpage:
• Previews Writeups Phase 1: 26 preview writeups
• Previews Writeups Phase 2: 10 preview writeups
• Previews Writeups Phase 3: TBA
The 2nd phase of previews will be held on July 07–08, 2026, including virtual presentations of 10 preview talks. The corresponding Preview Writeups will be posted in the MPTC-Submissions webpage.
All times are specified in timezone EDT = UTC –4. Free online registration.
• 10:30–10:40: Login and Intro to event
• 10:40–11:05: Talk 1a1: Trout++: Robust Asynchronous Two-Round ECDSA for Arbitrary Thresholds
• 11:05–11:30: Talk 1a2: Twig: Two-Round Threshold ECDSA from Non-Interactive Multiplication
• 11:30–11:55: Talk 1a3: KU25: Honest-Majority Threshold ECDSA
• 13:05–13:30: Talk 1b1: Coordinated MPC: Transport Layer for Multi-Party Protocols
• 13:30–13:55: Talk 1b2: FaFROST: Fully Adaptive FROST with Identifiable Aborts from AOMDL
The following talks will be retransmitted on Wednesday morning:
• 18:05–18:30: Talk 2a2: Lemur: Scalable Post-Quantum Synchronized Multi-Signatures
• 18:30–18:55: Talk 2a3: LoTRS: Practical Post-Quantum Structured Threshold Ring Signatures from Lattices
• 10:30–10:40: [Login time]
• 10:40–11:05: Talk 2a1: TALUS: Threshold ML-DSA with One-Round Online Signing
• 11:05–11:30: Talk 2a2: Lemur: Scalable Post-Quantum Synchronized Multi-Signatures
• 11:30–11:55: Talk 2a3: LoTRS: Practical Post-Quantum Structured Threshold Ring Signatures from Lattices
• 13:30–13:55: Talk 2b1: LaZer: Lattice-Based Zero-Knowledge Arguments for Lattice Relations
• 13:55–14:20: Talk 2b2: Threshcon: Multi-Party Threshold Ascon
Participation in this virtual event requires abiding by the Code of Conduct for NIST conferences.
| Selected Presentations | |
|---|---|
| July 7, 2026 | Type |
|
10:40 AM
Trout++: Robust Asynchronous Two-Round ECDSA for Arbitrary Thresholds Luke Parker - Serai DEX @ USA “Preview Talk” (by Team Trout) @ TCPT2, in reply to the NIST Threshold Call Abstract: In this talk, we will present Trout++, a two-round threshold ECDSA signing protocol which may be used to achieve a robust, asynchronous protocol for arbitrary thresholds. Our protocol works with no additional prior setup/secure storage, offers a prover with complexity independent to the signing set, and avoids the complexity of the Asynchronous Common Subset problem via the extremely straightforward, yet still efficient, ROAST transformation. Our focus with Trout++ has been an exceptionally practical scheme, with comprehensive coverage of the concerns which are raised when actually deploying a threshold signature scheme, as we will discuss in this talk. We will also discuss our planned future work to ensure Trout++ is a leading candidate for standardization. Joint work: Luke Parker, Hila Dahari-Garbian, Ariel Nof Suggested readings:
|
Presentation |
|
11:05 AM
Twig: Two-Round Threshold ECDSA from Non-Interactive Multiplication Yingjie Lyu - Shandong University @ China “Preview Talk” (by Team Twig) @ TCPT2, in reply to the NIST Threshold Call Abstract: In this talk, I will present Twig, a multi-party threshold ECDSA scheme that takes only two rounds of interaction for signing, which our team plans to submit to the NIST threshold call. The signing protocol features a small message size of 1.2-1.9 KiB at 128-bit security and follows an online/offline paradigm with a lightweight online phase. The protocol makes use of 1) a Non-Interactive Multiplication gadget instantiated using class groups in the Castagnos–Laguillaumie (CL) framework, originating from research on Homomorphic Secret Sharing, and 2) a presignature re-randomization technique inspired by recent work of Adjedj et al. (PKC '26). I will discuss the protocol design and provide information on its implementation and performance. Joint work: Yingjie Lyu, Zengpeng Li, Xudong Deng, Hong-Sheng Zhou, Mei Wang, Puwen Wei, Chen Qian Suggested readings:
|
Presentation |
|
11:30 AM
KU25: Honest-Majority Threshold ECDSA Antoine Urban - Dfns @ France Preview Talk” (by Team Dfns-KU) @ TCPT2, in reply to the NIST Threshold Call Abstract: In this presentation, we introduce KU, an honest-majority threshold ECDSA protocol submitted to Category N1.2 of the NIST Threshold Call. While recent standardization efforts have heavily favored the dishonest-majority setting, the goal of this talk is to advocate for the compelling architectural advantages of honest-majority protocols in Key Management Networks (KMNs). In KMNs, a fixed set of servers secures millions of keys across independent trust domains, making an honest-majority assumption highly practical. By embracing this assumption, KU achieves two interesting practical properties: key-independent presignatures and the highly efficient batch generation of these presignatures. These properties enable a highly optimized division between the offline and online signing phases. During the offline phase, KU generates a single global pool of presignatures in massive batches, drastically reducing amortized network costs. Unlike state-of-the-art protocols that require provisioning key-dependent presignatures for every individual key, this shared pool eliminates massive management bottlenecks. Then, during the non-interactive online phase, a presignature from this pool can be consumed instantly for any requested key. We will present benchmarks demonstrating an amortized offline generation cost of 1.3 ms per presignature and a sustained, very high online throughput. Joint work: Antoine Urban, Jonathan Katz, Denis Varlakov, Nikita Sorokovikov Suggested readings:
|
Presentation |
|
1:05 PM
Coordinated MPC: Transport Layer for Multi-Party Protocols Denis Varlakov - Dfns @ France “Preview Talk” (by Team Dfns-Coord) @ TCPT2, in reply to the NIST Threshold Call Abstract: This presentation dives into challenges of production deployment of Multi-Party Computation (MPC) protocols in production, specifically the message delivery layer that enables parties of the protocol to communicate. Its role is crucial: it has to fulfill strict security properties, with the security of the entire system at stake if they are not met. Implementing own delivery layer is error-prone, especially when other requirements are taken into account: such as operational simplicity, zero-downtime, and in-depth security. We will present the Coordinated MPC, the Transport Layer for MPC protocols that is designed and optimized for real-world MPC deployment and provides MPC-specific features, such as 1-round consensus on list of participants, globally unique execution nonce derivation, provable attribution of decryption. We will show the architecture of our Transport Layer which uses a central party (the coordinator) to relay messages. The coordinator is designed to be trustless, an adversary that fully controls it is limited to Denial-of-Service attacks only. Finally, we will discuss how the security of the protocol is proven in the Universally Composable (UC) model, allowing it to be safely composed with other UC protocols. Joint work: Denis Varlakov, Antoine Urban, Nikita Sorokovikov Suggested readings:
|
Presentation |
|
1:30 PM
FaFROST: Fully Adaptive FROST with Identifiable Aborts from AOMDL Paul Gerhart - TU Wien @ Austria “Preview Talk” (by Team FaFROST) @ TCPT2, in reply to the NIST Threshold Call Abstract: In this presentation we present FaFROST, a two-round Schnorr threshold signature scheme that achieves full adaptive security together with identifiable aborts under the Algebraic One-More Discrete Logarithm (AOMDL) assumption alone. Our construction builds on FROST (Flexible Round-Optimized Schnorr Threshold Signatures), one of the leading two-round candidates in the ongoing standardization of threshold signatures. Recent work has shown that proving FROST adaptively secure under standard assumptions is difficult, and existing solutions each give up an important property: they either rely on an additional non-standard assumption, require an extra communication round, or forgo identifiable aborts. Identifiable aborts allow honest parties to identify a misbehaving signer whenever a signing attempt fails, so that the responsible signer can be excluded and the protocol keeps making progress. Given that without identifiable aborts even a single misbehaving signer can stall protocol execution indefinitely, we view them as deployment-critical. To our knowledge, FaFROST is the first two-round threshold Schnorr signature to combine all three: full adaptive security, reliance on the well-established AOMDL assumption alone, and identifiable aborts. It preserves FROST's communication and computation efficiency for honest signing: an additional identification protocol runs only when a signing session fails, enabling efficient fault attribution at nearly no cost to successful executions. Joint work: Paul Gerhart, Ruben Baecker, Davide Li Calsi, Luigi Russo, Dominique Schröder, Arkady Yerukhimovich Suggested readings:
|
Presentation |
| July 8, 2026 | Type |
|
10:40 AM
TALUS: Threshold ML-DSA with One-Round Online Signing Leo Kao - Codebat Technologies Inc. @ Canada “Preview Talk” (by Team TALUS) @ TCPT2, in reply to the NIST Threshold Call Abstract: In this presentation, we introduce TALUS, a threshold signing protocol for ML-DSA (FIPS 204) that achieves one-round online signing by filtering nonces offline. The core technique is the Boundary Clearance Condition (BCC): a publicly verifiable predicate on the nonce vector that geometrically guarantees the secondary rejection check will pass, eliminating the only secret-dependent abort in ML-DSA's signing loop. For ML-DSA-65, approximately 31.7% of random nonces satisfy BCC, meaning roughly three offline attempts produce a usable nonce in expectation. We present two deployment models. TALUS-TEE uses a Trusted Execution Environment to hold the aggregate nonce, enabling single-round signing with 1.52 ms end-to-end latency at a 3-of-5 threshold. TALUS-MPC removes the hardware trust assumption via a fully distributed protocol using carry elimination and masked broadcast, achieving 4.09 ms with honest majority. Both models produce standard FIPS 204 signatures verifiable by any unmodified ML-DSA verifier. Joint work: Leo Kao, Raymond Chang Suggested readings:
|
Presentation |
|
11:05 AM
Lemur: Scalable Post-Quantum Synchronized Multi-Signatures Yini Lin - Monash University @ Australia “Preview Talk” (by Team Lemur) @ TCPT2, in reply to the NIST Threshold Call Abstract: In this talk, we present Lemur, a non-interactive synchronized multi-signature scheme based on lattice cryptography, designed for large-scale distributed systems such as blockchain protocols. Lemur builds on the ideas introduced in Squirrel and Chipmunk but fundamentally redesigns the cryptographic foundations of the framework to achieve improved efficiency. A central contribution is the introduction of the Dual Hint-MLWE assumption, a new lattice assumption that we show is at least as hard as the standard Module-LWE problem. Leveraging this assumption, Lemur redesigns the underlying key-homomorphic one-time signature (KOTS) component, resulting in significantly improved compactness and scalability, with up to an order-of-magnitude reduction in KOTS size compared with Chipmunk. We also revisit the homomorphic vector commitment layer, moving from Ring-SIS to Module-SIS assumptions and extending commitment domain from vectors to matrices, further improving aggregation efficiency. Together, these advances enable Lemur to reduce aggregate signature sizes by roughly a factor of two while supporting extremely large signer sets, making it a practical post-quantum solution for synchronized multi-signature applications. Concretely, at 128-bit post-quantum security, the current Rust implementation profile yields an aggregate of about 380 KB for one million individual signatures (versus Chipmunk’s ∼728 KB), while keeping stateful signing millisecond-scale and aggregated verification in the tens of milliseconds for 1024 signers. Joint work: Yini Lin, Muhammed F. Esgin, Markku-Juhani O. Saarinen, Amin Sakzad, Ron Steinfeld Suggested readings:
|
Presentation |
|
11:30 AM
LoTRS: Practical Post-Quantum Structured Threshold Ring Signatures from Lattices Nikai Jagganath - Monash University, CSIRO @ Australia “Preview Talk” (by Team LoTRS) @ TCPT2, in reply to the NIST Threshold Call Abstract: In this presentation, we will introduce LoTRS, a lattice-based post-quantum structured threshold ring signature scheme. A threshold ring signature lets a quorum jointly sign while hiding which eligible signers participated. LoTRS formalizes a structured version of this primitive: public keys are arranged in a table, and a valid quorum consists of one hidden column, with one signer from each row. This captures settings where the approval pattern is public, such as one delegate per organization, role, or precinct, but the actual approving column should remain private. The construction separates threshold signing from the anonymity mechanism: a two-round lattice-based multi-signature proves that the quorum signed, while a one-out-of-many zero-knowledge proof hides which column was used. To the best of our knowledge, LoTRS is the first construction in which a TRS variant is obtained by combining these primitives. We will describe the new structured threshold ring signature model, the LoTRS construction, and our implementation results. For the headline setting with 50 rows and 100 candidate columns, LoTRS produces signatures of about 35 KB, roughly 3.5 times smaller than the previous best lattice-based threshold ring signature, with signing and verification wall-clock times of 789 ms and 250 ms, respectively. Our work includes Python and Rust implementations, deterministic test vectors, parameter-estimation scripts, and benchmarks. Joint work: Nikai Jagganath, Muhammed Esgin, Ron Steinfeld, Amin Sakzad, Markku-Juhani O. Saarinen, Dongxi Liu Suggested readings:
|
Presentation |
|
1:30 PM
LaZer: Lattice-Based Zero-Knowledge Arguments for Lattice Relations Patrick Steuer - IBM Research @ Zurich, Switzerland “Preview Talk” (by Team LaZer) @ TCPT2, in reply to the NIST Threshold Call Abstract: In this talk we present LaZer, our Category S6 submission to the NIST First Call for Multi-Party Threshold Schemes: a lattice-based, non-interactive, transparent (no trusted setup) zero-knowledge argument of knowledge for statements about secrets in module lattices. The defining feature of LaZer is that it proves lattice relations natively - that is, directly in module-ring arithmetic, without first arithmetizing them into a circuit. This lets the proof system share lattice arithmetic (such as the NTT) with the application it certifies, express statements in their natural language of ring equalities and norm bounds, and reduce security to the very same Module-SIS and Module-LWE assumptions that already underpin the primitive being proven - introducing no new assumptions. Security is computational and plausibly post-quantum, at the 128-bit level, obtained via the Fiat–Shamir transform of a public-coin interactive argument. Joint work: Patrick Steuer, Ngoc Khanh Nguyen, Vadim Lyubashevsky, Michał Osadnik, Gregor Seiler Suggested readings:
|
Presentation |
|
1:55 PM
Threshcon: Multi-Party Threshold Ascon Peter Schwarz - COSIC, KU Leuven @ Belgium “Preview Talk” (by Team Threshcon) @ TCPT2, in reply to the NIST Threshold Call Abstract: In this talk, we present the planned package submission for Threshcon, a protocol family developed to securely evaluate the Ascon lightweight symmetric cryptography suite within a multi-party threshold context. Our submission covers the Ascon-AEAD128 authenticated encryption and decryption scheme, as well as the Ascon-Hash256 and Ascon-CXOF128 modes, and guarantees strict functional equivalence with the standard NIST primitives. Threshcon is set in the preprocessing model and is designed for an n-party setting with an honest supermajority, providing information-theoretic security against active malicious adversaries that corrupt up to t < n/3 parties. Beyond Shamir secret sharing, we rely on Reverse Multiplication-Friendly Embeddings (RMFEs) to align the multi-party evaluation more closely with Ascon's parallelized bitwise design. We will discuss secret-sharing semantics applied to the required inputs and outputs. Finally, we will provide an overview of the ongoing implementation efforts for the NIST multi-party threshold call. Joint work: Peter Schwarz, Aysajan Abidin Suggested readings:
|
Presentation |
Starts: July 07, 2026 - 10:30 AM EDT
Ends: July 08, 2026 - 03:00 PM EDT
Format: Virtual Type: Workshop
Attendance Type: Open to public
Audience Type: Industry, Government, Academia, Other
Security and Privacy: cryptography, privacy