Advances in Cryptology — EUROCRYPT 2000

Volume 1807 of the series Lecture Notes in Computer Science pp 207-220


Practical Threshold Signatures

  • Victor ShoupAffiliated withIBM Zürich Research Lab


We present an RSA threshold signature scheme. The scheme enjoys the following properties:
  1. 1.

    it is unforgeable and robust in the random oracle model, assuming the RSA problem is hard;

  2. 2.

    signature share generation and verification is completely non-interactive;

  3. 3.

    the size of an individual signature share is bounded by a constant times the size of the RSA modulus.