Go to file
Conrado Gouvea d5551c9244 fix doc link 2022-11-23 13:44:06 -03:00
.github Bump Swatinem/rust-cache from 1 to 2 (#179) 2022-11-18 12:30:13 +00:00
frost-core fix doc link 2022-11-23 13:44:06 -03:00
frost-ed25519 Improve DKG API; add DKG example (#173) 2022-11-18 12:54:06 +00:00
frost-p256 Improve DKG API; add DKG example (#173) 2022-11-18 12:54:06 +00:00
frost-redjubjub Update digest requirement from 0.9 to 0.10 2022-07-26 20:27:06 -04:00
frost-ristretto255 Improve DKG API; add DKG example (#173) 2022-11-18 12:54:06 +00:00
gendoc Improve DKG API; add DKG example (#173) 2022-11-18 12:54:06 +00:00
rfcs add missing checks 2021-06-15 17:10:38 -04:00
.gitignore Ignore .DS_Store 2022-03-08 14:11:41 -05:00
.mergify.yml ci(Mergify): configuration update 2022-06-15 20:13:45 -04:00
CHANGELOG.md Don't reject small-order verification keys (#137) 2021-11-18 15:53:35 -03:00
Cargo.toml add Ed25519 ciphersuite (#164) 2022-10-27 18:33:32 +00:00
LICENCE Frost keygen with dealer (#47) 2021-02-25 09:06:54 -07:00
LICENCE.MIT Frost keygen with dealer (#47) 2021-02-25 09:06:54 -07:00
LICENSE.Apache-2.0 Frost keygen with dealer (#47) 2021-02-25 09:06:54 -07:00
README.md Improve examples (#160) 2022-11-01 15:54:04 +00:00
codecov.yml Port frost-ristretto255 to frost-core (#57) 2022-06-17 14:54:54 -04:00

README.md

FROST (Flexible Round-Optimised Schnorr Threshold signatures)

Rust implementations of 'Two-Round Threshold Schnorr Signatures with FROST'.

Unlike signatures in a single-party setting, threshold signatures require cooperation among a threshold number of signers, each holding a share of a common private key. The security of threshold schemes in general assume that an adversary can corrupt strictly fewer than a threshold number of participants.

'Two-Round Threshold Schnorr Signatures with FROST' presents a variant of a Flexible Round-Optimized Schnorr Threshold (FROST) signature scheme originally defined in FROST20. FROST reduces network overhead during threshold signing operations while employing a novel technique to protect against forgery attacks applicable to prior Schnorr-based threshold signature constructions. This variant of FROST requires two rounds to compute a signature, and implements signing efficiency improvements described by Schnorr21. Single-round signing with FROST is not implemented here.

Status ⚠

The FROST specification is not yet finalized, and this codebase has not yet been audited or released. The APIs and types in frost-core are subject to change.

Usage

frost-core implements the base traits and types in a generic manner, to enable top-level implementations for different ciphersuites / curves without having to implement all of FROST from scratch. End-users should not use frost-core if they want to sign and verify signatures, they should use the crate specific to their ciphersuite/curve parameters that uses frost-core as a dependency.