Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Presentation

KU25: Honest-Majority Threshold ECDSA

July 7, 2026

Presenters

Antoine Urban - Dfns @ France

Description

Preview Talk” (by Team Dfns-KU) @ TCPT2, in reply to the NIST Threshold Call

Abstract: In this presentation, we introduce KU, an honest-majority threshold ECDSA protocol submitted to Category N1.2 of the NIST Threshold Call. While recent standardization efforts have heavily favored the dishonest-majority setting, the goal of this talk is to advocate for the compelling architectural advantages of honest-majority protocols in Key Management Networks (KMNs). In KMNs, a fixed set of servers secures millions of keys across independent trust domains, making an honest-majority assumption highly practical. By embracing this assumption, KU achieves two interesting practical properties: key-independent presignatures and the highly efficient batch generation of these presignatures. These properties enable a highly optimized division between the offline and online signing phases. During the offline phase, KU generates a single global pool of presignatures in massive batches, drastically reducing amortized network costs. Unlike state-of-the-art protocols that require provisioning key-dependent presignatures for every individual key, this shared pool eliminates massive management bottlenecks. Then, during the non-interactive online phase, a presignature from this pool can be consumed instantly for any requested key. We will present benchmarks demonstrating an amortized offline generation cost of 1.3 ms per presignature and a sustained, very high online throughput.

Joint work: Antoine Urban, Jonathan Katz, Denis Varlakov, Nikita Sorokovikov

[Slides] Suggested readings:

  • Preview Writeup (PDF): Coordinated MPC: Message delivery protocol designed for MPC systems with a central Coordinator 
  • "Honest-Majority Threshold ECDSA with Batch Generation of Key-Independent Presignatures" (ia.cr/2024/2011)
  • “Fast Large-Scale Honest-Majority MPC for Malicious Adversaries” (ia.cr/2018/570)

Presented at

Presented at TCPT2 (2026-July-07): Threshold Call Preview Talks #2

Downloads

Event Details

Location

    
                                

Related Topics

Security and Privacy: cryptography

Created July 06, 2026, Updated July 27, 2026