“Preview Talk” (by Team FaFROST) @ TCPT2, in reply to the NIST Threshold Call
Abstract: In this presentation we present FaFROST, a two-round Schnorr threshold signature scheme that achieves full adaptive security together with identifiable aborts under the Algebraic One-More Discrete Logarithm (AOMDL) assumption alone. Our construction builds on FROST (Flexible Round-Optimized Schnorr Threshold Signatures), one of the leading two-round candidates in the ongoing standardization of threshold signatures. Recent work has shown that proving FROST adaptively secure under standard assumptions is difficult, and existing solutions each give up an important property: they either rely on an additional non-standard assumption, require an extra communication round, or forgo identifiable aborts. Identifiable aborts allow honest parties to identify a misbehaving signer whenever a signing attempt fails, so that the responsible signer can be excluded and the protocol keeps making progress. Given that without identifiable aborts even a single misbehaving signer can stall protocol execution indefinitely, we view them as deployment-critical. To our knowledge, FaFROST is the first two-round threshold Schnorr signature to combine all three: full adaptive security, reliance on the well-established AOMDL assumption alone, and identifiable aborts. It preserves FROST's communication and computation efficiency for honest signing: an additional identification protocol runs only when a signing session fails, enabling efficient fault attribution at nearly no cost to successful executions.
Joint work: Paul Gerhart, Ruben Baecker, Davide Li Calsi, Luigi Russo, Dominique Schröder, Arkady Yerukhimovich
[Slides] Suggested readings:
Presented at TCPT2 (2026-July-07): Threshold Call Preview Talks #2
Security and Privacy: cryptography