“Preview Talk” (by Team Twig) @ TCPT2, in reply to the NIST Threshold Call
Abstract: In this talk, I will present Twig, a multi-party threshold ECDSA scheme that takes only two rounds of interaction for signing, which our team plans to submit to the NIST threshold call. The signing protocol features a small message size of 1.2-1.9 KiB at 128-bit security and follows an online/offline paradigm with a lightweight online phase. The protocol makes use of 1) a Non-Interactive Multiplication gadget instantiated using class groups in the Castagnos–Laguillaumie (CL) framework, originating from research on Homomorphic Secret Sharing, and 2) a presignature re-randomization technique inspired by recent work of Adjedj et al. (PKC '26). I will discuss the protocol design and provide information on its implementation and performance.
Joint work: Yingjie Lyu, Zengpeng Li, Xudong Deng, Hong-Sheng Zhou, Mei Wang, Puwen Wei, Chen Qian
[Slides] Suggested readings:
Presented at TCPT2 (2026-July-07): Threshold Call Preview Talks #2
Security and Privacy: cryptography