Preview Talk” (by Team Dfns-KU) @ TCPT2, in reply to the NIST Threshold Call
Abstract: In this presentation, we introduce KU, an honest-majority threshold ECDSA protocol submitted to Category N1.2 of the NIST Threshold Call. While recent standardization efforts have heavily favored the dishonest-majority setting, the goal of this talk is to advocate for the compelling architectural advantages of honest-majority protocols in Key Management Networks (KMNs). In KMNs, a fixed set of servers secures millions of keys across independent trust domains, making an honest-majority assumption highly practical. By embracing this assumption, KU achieves two interesting practical properties: key-independent presignatures and the highly efficient batch generation of these presignatures. These properties enable a highly optimized division between the offline and online signing phases. During the offline phase, KU generates a single global pool of presignatures in massive batches, drastically reducing amortized network costs. Unlike state-of-the-art protocols that require provisioning key-dependent presignatures for every individual key, this shared pool eliminates massive management bottlenecks. Then, during the non-interactive online phase, a presignature from this pool can be consumed instantly for any requested key. We will present benchmarks demonstrating an amortized offline generation cost of 1.3 ms per presignature and a sustained, very high online throughput.
Joint work: Antoine Urban, Jonathan Katz, Denis Varlakov, Nikita Sorokovikov
[Slides] Suggested readings:
Presented at TCPT2 (2026-July-07): Threshold Call Preview Talks #2
Security and Privacy: cryptography