[curves] Threshold ECDSA / comparison to Schnorr

Trevor Perrin trevp at trevp.net
Mon Mar 9 14:21:30 PDT 2015

Some advances have been made on practical threshold ECDSA by Steven
Goldfeder et al:


Is anyone able to breakdown how this compares to threshold Schnorr?

In particular:  Does Schnorr still hold an advantage in this area, or
has ECDSA closed the gap?  What are the differences with respect to:
 - trust assumptions (trusted setup, robustness to misbehaving parties)
 - communication costs (in particular, # of rounds)
 - computation costs
 - implementation complexity


