Date: 12 May 2000

Practical Threshold Signatures


We present an RSA threshold signature scheme. The scheme enjoys the following properties:

  1. it is unforgeable and robust in the random oracle model, assuming the RSA problem is hard;

  2. signature share generation and verification is completely non-interactive;

  3. the size of an individual signature share is bounded by a constant times the size of the RSA modulus.