[curves] Threshold ECDSA for Bitcoin
watsonbladd at gmail.com
Fri Mar 28 15:36:09 PDT 2014
On Fri, Mar 28, 2014 at 6:14 PM, Trevor Perrin <trevp at trevp.net> wrote:
> Apparently based on this:
> I'd be interested to hear how the state-of-the-art in threshold-ECDSA
> compares to threshold-Schnorr, if anyone knows.
Threshold Schnorr requires computing only a multiplication and an
addition. As a result you don't need special tricks: if you have k
people out of n who can get the key, 2k-1 can compute the shares of
the signature value and reconstruct in the usual manner. This way
avoids the inversion and degree reduction protocols entirely.
> Curves mailing list
> Curves at moderncrypto.org
"Those who would give up Essential Liberty to purchase a little
Temporary Safety deserve neither Liberty nor Safety."
-- Benjamin Franklin
More information about the Curves