Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

TCPT3: Threshold Call Preview Talks #3

TCPT3 is a virtual event hosting 20+ "Preview Talks" with plans of upcoming submissions to the NIST Threshold Call (IR 8214C). This is the third phase of the Threshold Call Previews. The previous two phases received 36 previews: 26 at MPTS 2026; and 10 at TCPT2.

  • TCPT3 dates: September 30 and October {6, 7, 13}, 2026
    • 1st day (Sep 30, 10:00–12:00: (4 talks) Threshold FHE; ZKP
    • 2nd day (Oct 6), 10:00–15:00: (8 talks) Threshold post-quantum signatures
    • 3rd day (Oct 7), 10:00–14:20: (6 talks) Threshold quantum-vulnerable signatures and PKE
    • 4th day (Oct 13), 10:00–12:30: (5 talks) Threshold FHE, Threshold PKE, DKG
  • Attendance: Free, with online registration
  • Participation: Requires abiding by the Code of Conduct for NIST conferences

Other quick Links

  • List of submitted previews: Sequential list of Preview Writeups and Links to Talks
  • Previews Console: Grid with many links (to be updated with phase 3 reference material)
  • Previews Phase 2: Presented at TCPT2 (July 7–8, 2026)
  • Previews Phase 1: Presented at MPTS 2026 (Jan 26–29)

Tentative schedule (subject to updates). All times are displayed in Eastern Daylight Time (EDT = UTC -4).

The workshop hosts 20+ "Preview Talks" (plans of upcoming submissions to the NIST Threshold Call). 

1st day (Wednesday, 2026-Sep-30): FHE and ZKP

• Talk 101. 10:00–10:10: TCPT3 Welcome and Introduction.
• Talk 1a1. 10:10–10:35: Kryptallage: A unified FHE scheme and its threshold protocol layer. Erin Hales (Royal Holloway @ London, United Kingdom)
• Talk 1a2. 10:35–11:00: MOZI: Threshold FHE at Scale: Efficient and Resilient, for Large-Scale MPC. Yijia Chang (The Hong Kong Polytechnic University @ Hong Kong, China)
• Talk 1a3. 11:15–11:40: Holocron: Ciphertext-Interchangeable Threshold K-PKE via FHE. Yongsoo Song (Seoul National University @ Seoul, South Korea)
• Talk 1a4. 11:40–12:05: ark-pq: post-quantum zero-knowledge arguments of knowledge. Alessandro Chiesa (EPFL @ Lausanne, Switzerland)

2nd day (Tuesday, 2026-Oct-06): Post-quantum (PQ) threshold schemes

• 10:00–10:10: Login and day intro. (NIST MPTC)
• Talk 2a1. 10:10–10:35: ATMACA: Lattice-Based Threshold Signing for FALCON. Metin Bektaş (TÜBİTAK BİLGEM @ Gebze, Türkiye)
• Talk 2a2. 10:35–11:00: Kettle: Short Threshold HAWK Signatures. Clément Hoffmann (NTT @ Japan)
• Talk 2a3. 11:15–11:40: DUOV: A Dressing in Advance for Threshold UOV with Pre-signing. Elouan Gros (Astran @ Paris, France)
• Talk 2a4. 11:40–12:05: TALH: Threshold Authentication via Leaf-sharing in Hash-based Signatures. Muhammed Gündoğan (TÜBİTAK BİLGEM @ Gebze,Türkiye)

• Talk 2b1. 13:00–13:25: TalonG and P-DualTS: 2-round Lattice-based Threshold Signatures. Liming Gao (Chinese Academy of Sciences @ China)
• Talk 2b2. 13:25–13:50: LaTSEC: Lattice-Based Threshold Signature from Expander Codes. Muhammad Arzaki (Monash University @ Melbourne, Australia)
• Talk 2b3. 14:05–14:30: Thimza: Lattice-Based Stateless Threshold Signatures at Optimal Bandwidth. Hamidreza Khorasgani (Purdue University @ USA)
• Talk 2b4. 14:30–14:55: TSitH: Threshold Signatures in the Head. Auguste Warmé-Janville (CryptoExperts; Sorbonne University @ France)

3rd day (Wednesday, 2026-Oct-07): Quantum-vulnerable (QV) threshold schemes

• 10:00–10:10: Login and day intro. (NIST MPTC)
• Talk 3a1. 10:10–10:35: (Threshold-)CL: (Threshold) Linearly Homomorphic PKE from Class Groups. Quentin Combal (Université de Montpellier @ France)
• Talk 3a2. 10:35–11:00: Axolotl: Robust Asynchronous Threshold Schnorr. Luke Parker (Serai DEX @ Florida, USA)
• Talk 3a3. 11:10–11:25: Stoats: Short Two-round vOle-bAsed Threshold Signatures. Elahe Sadeghi (University of Texas @ Austin, USA)

• Talk 3b1. 13:00–13:25: DKLs: Threshold ECDSA from VOLE and Commitments. Jack Doerner (University of Virginia @ Charlottesville, USA)
• Talk 3b2. 13:25–13:50: Menshen and (T)CL: 3-round threshold ECDSA schemes. Haiyang Xue (Singapore Management University @ Singapore)
• Talk 3b3. 13:50–14:15: TapTop & Robot: 2-party threshold BBS schemes. Guofeng Tang (Singapore Management University @ Singapore)

4th day (Tuesday, 2026-Oct-13)

• Talk 401. 10:00–10:10: Login and day intro. (NIST MPTC)
• Talk 4a1. 10:10–10:35: Tulva (Threshold FHE). TBA
• Talk 4a2. 10:35–11:00: AdpTD (Threshold Decryption). TBA
• Talk 4a3. 11:15–11:40: TBA
• Talk 4a4. 11:40–11:55: TBA
• Talk 4a5. 11:55–12:20: TBA

The NIST Threshold Call (NIST IR 8214C) specified three "Preview" phases where teams submit a Preview Writeup and give a Preview Talk presenting the team's plan for an upcoming package submission.  Preview writeups are posted in the submissions webpage of the MPTC website.  Preview talks are presented in virtual workshops:

• Phase 1: 26 Preview Talks were presented at MPTS 2026 (January 26–29)
• Phase 2: 10 Preview Talks were presented at TCPT2 (July 7–8, 2026)
• Phase 3: 20+ Preview Talks will be presented at TCPT3 (September 30 and October {6,7,13}, 2026)

Selected Presentations
September 30, 2026 Type
10:00 AM TCPT3 Welcome and Introduction

Abstract. This brief talk opens the NIST TCPT event: Threshold Call Preview Talks #3 (3rd phase). This short segment welcomes the participants, recalls the context of the NIST Threshold Call, explains the logistics of the virtual event, and transitions to the first technical session.

Suggested readings:

Presentation
10:10 AM Introducing Kryptallage: A Unified FHE Scheme and its Threshold Protocol Layer
Erin Hales - Royal Holloway, University of London, UK

"Preview Talk" (by team Kryptallage) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this talk we present an overview of our threshold integrated Fully Homomorphic Encryption (FHE) system, Kryptallage, targeting NIST Threshold Categories S4 and S5. Kryptallage unifies several homomorphic encryption schemes and the procedures for switching between them into a single encrypted-computation framework. Rather than working with specific named FHE schemes, we consider ciphertexts through their functionality, message space, encoding, and mathematical representation. This offers a more generic framework to describe scheme switching, via ciphertext characteristics. We will present an overview of the different ciphertext types and how they interact. Our scheme switching approach is used to make leveled evaluation of look-up tables (LUTs), comparisons, and other operations practical at scale. We will motivate and overview the batched circuit bootstrapping process which is used to enable our approach. The FHE specification that we use features distributed key generation and decryption. This is enabled by a module threshold layer that realises these distributed operations using Shamir secret sharing over Galois rings. The threshold protocols are proven UC-secure against a static malicious adversary corrupting t<n/2 parties, providing active security with abort for key generation and guaranteed output delivery for decryption.

Joint work: Ghada Almashaqbeh, Sonia Belaïd, Nicolas Bon, Ilaria Chillotti, Mariana Gama, Antonio Guimarães, Erin Hales, Hyojun Kim, Elena Kirshanova, Damien Ligier, Ryan Orendorff, Emmanuela Orsini, Matthieu Rivain, Luisa Siniscalchi, Ravital Solomon, Rick Weber.

Suggested readings

Presentation
10:35 AM MOZI: Threshold FHE at Scale: Efficient and Resilient, for Large-Scale MPC
Yijia Chang - The Hong Kong Polytechnic University @ China

"Preview Talk" (by team MOZI) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this presentation, I will introduce MOZI and discuss how to make threshold fully homomorphic encryption (ThFHE) scalable for hundreds or thousands of participants. ThFHE enables computation on encrypted data while distributing decryption authority among multiple key holders. Scaling this capability requires careful control of computation, communication, and storage complexity. I will explain MOZI’s modular design, which uses approximate secret sharing (ApproxSS) to separate threshold decryption from the underlying encryption scheme. This design supports two complementary systems: MOZI-Fang uses lattice-based symmetric encryption and targets post-quantum security, while MOZI-Yuan combines lattice techniques with elliptic-curve operations to explore lower recovery costs under quantum-vulnerable assumptions. These goals include guaranteed output delivery with an available semi-honest combiner and sufficient honest participation, and security with abort against a malicious combiner. Finally, I will outline our evaluation plan, covering network costs, optional preprocessing, and authenticated Beaver-triple generation for secure multi-party computation. The talk will highlight the design choices and practical tradeoffs involved in scaling threshold encryption for collaborative applications.

Joint work: Man Ho Au, Yijia Chang, Rongmao Chen, Xinyi Huang, Xianhui Lu, Moti Yung.

Suggested readings

  • Preview Writeup (PDF): MOZI: Threshold FHE at Scale: Efficient and Resilient, for Large-Scale MPC
  • Arbitrary-Threshold Fully Homomorphic Encryption with Lower Complexity (ia.cr/2025/084)
  • Resolving the Efficiency-Utility Dilemma of Threshold Linearly Homomorphic Encryption via Message-Space Adapter (ia.cr/2025/948)
Presentation
11:00 AM Holocron: Ciphertext-Interchangeable Threshold K-PKE via FHE
Yongsoo Song - Seoul National University @ South Korea

"Preview Talk" (by team Holocron) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this presentation, we introduce a framework for thresholdizing K-PKE, the public-key encryption (PKE) underlying ML-KEM, using fully homomorphic encryption (FHE). Our construction achieves full ciphertext interchangeability: threshold encryption outputs a K-PKE ciphertext that can be decrypted by standard K-PKE decryption, while threshold decryption decrypts ordinary K-PKE ciphertexts with equivalent functionality. For encryption, parties combine independently sampled random bits while encrypted in a discrete Cheon-Kim-Kim-Song (CKKS) ciphertext. By lifting the plaintext space utilizing CKKS short-integer bootstrapping, we exploit noise flooding, plaintext masking, and linearity to form the final ciphertext without revealing the message or randomness. For decryption, we embed the K-PKE phase computation into a Brakerski-Gentry-Vaikuntanathan (BGV) scheme, homomorphically evaluate the nonlinear compression/decompression step, and use modulus expansion and noise flooding to protect partial decryptions. We discuss correctness and active-static security with abort based on the commit-and-reveal technique and Buckler non-interactive zero-knowledge proofs (NIZKs).

Joint work: Jihoon Cho, Siwoo Eum, Kyoohyung Han, Intak Hwang, Jaejun Ko, Jihoon Kwon, Byeonghak Lee, Sangyub Lee, Seonhong Min, Hwajeong Seo, Yongsoo Song, Hyojin Yoon.

Suggested readings

    • Preview Writeup (PDF): Holocron: Threshold K-PKE Encryption and Decryption from FHE
Presentation
11:40 AM ark-pq: post-quantum zero-knowledge arguments of knowledge
Alessandro Chiesa - EPFL @ Switzerland

"Preview Talk" (by team ark-pq) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this talk, we introduce ark-pq, a library for transparent, post-quantum zero-knowledge succinct non-interactive arguments of knowledge (zkSNARKs). ark-pq can prove sensitive claims about threshold cryptographic primitives without exposing sensitive data (e.g., knowledge of a secret key, or the validity of a signature), as well as an extensive range of complex well-formedness conditions. ark-pq is built from two very well-understood primitives: interactive oracle proofs (IOPs) and Merkle tree vector commitments (VCs). ark-pq is designed to be modular and configurable, allowing for the construction of a wide range of zkSNARKs with different trade-offs between proof size, prover time, and verifier time.

Joint work: Alessandro Chiesa, Giacomo Fenzi, Christian Knabenhans, Andrew Zitek-Estrada.

Suggested readings

Presentation
October 6, 2026 Type
10:10 AM ATMACA: Lattice-Based Threshold Signing for FALCON
Metin Bektaş - TÜBİTAK BİLGEM @ Gebze, Turkey

Abstract: In this talk, we will introduce ATMACA, an efficient post-quantum threshold signature protocol for the FFT (fast Fourier transform) over NTRU-Lattice-Based Digital Signature Algorithm (FN-DSA/FALCON). The main difficulty of threshold signing for FALCON in multi-party computation (MPC) is that FALCON's sampler draws its Gaussian samples sequentially. Therefore, the number of rounds grows linearly with the ring degree. ATMACA evaluates the hybrid sampler used by Mitaka, a FALCON variant, with annular NTRU trapdoor generation (ANTRAG) keys. In this setting, only two steps are sequential, and the samples within each step are drawn in parallel. The signatures still pass the unchanged FALCON verifier. ATMACA tolerates a dishonest majority with security with abort, uses a trusted dealer, and aims for Category N1 at NIST security categories 1 and 5. We estimate fewer than 180 online rounds per attempt in expectation, and at most 350 under a reasonable iteration cap, against thousands reported for earlier threshold FALCON work. In this presentation, we go over the main design choices and differences from the past work.

Joint work: Erdem Alkım, Metin Bektaş, Erem Ersoy, Muhammed Said Gündoğan.

Suggested readings

  • Preview Writeup (PDF): ATMACA (A Threshold Multiparty Algorithm for Compact Authentication): Lattice-Based Threshold Signing for FALCON
  • Mitaka: a simpler, parallelizable, maskable variant of Falcon (ia.cr/2021/1486)
  • Antrag: Annular NTRU Trapdoor Generation (ia.cr/2023/1335)
  • Thresholdizing Standardized FALCON Signatures (ia.cr/2026/1300)
Presentation
10:35 AM Kettle: Short Threshold HAWK Signatures
Clément Hoffmann - NTT @ Japan

"Preview Talk" (by team Kettle) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this talk, we present Kettle, a thresholdized version of the signature scheme HAWK. While HAWK has been attacked recently, its security remains exponential, and its parameters are still competitive compared to existing threshold schemes. We demonstrate that HAWK can be evaluated with as few as 2 online rounds, provide short signatures and low online communication cost. Through a tailored way of daBits, we manage to move the Gaussian sampling and a secret multiplication to the offline phase, lowering the number of online rounds and communication cost. We prove the security of our scheme in the ABB framework, which make our building blocks (eg. Gaussian sampling) reusable in other schemes.

Joint work: Calvin Abou Haidar, Daniel Escudero, Thomas Espitau, Clément Hoffmann, Haruhisa Kosuge, Kaoru Takemure, Mehdi Tibouchi, Hernán Darío Vanegas Madrigal.

Suggested readings

  • Preview Writeup (PDF): Kettle: Short Post-Quantum Threshold Signatures from the HAWK Signature Scheme
  • HAWK: version 1.1 (February 5, 2025) (PDF)
Presentation
11:15 AM DUOV: A Dressing in Advance for Threshold UOV with Pre-signing
Elouan Gros - Astran @ Paris, France

"Preview Talk" (by team MASTER) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this presentation, we preview DUOV, a planned submission to the NIST Multi-Party Threshold Cryptography (MPTC) process. DUOV is a post-quantum threshold version of the Unbalanced Oil and Vinegar (UOV) multivariate signature scheme, enhanced with pre-signing. We will present the main ideas underlying the scheme and an evaluation of a Common Lisp prototype deployed on up to 16 cloud instances located in distinct Amazon Web Services (AWS) regions and communicating over the public internet.

Joint work: Elouan Gros, Dayane Horkos, River Moreira Ferreira, Ludovic Perret.

Suggested readings

Presentation
11:40 AM TALH: Threshold Authentication via Leaf-sharing in Hash-based Signatures
Muhammed Gündoğan - TÜBİTAK BİLGEM @ Gebze, Turkey

"Preview Talk" (by team TALH) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this talk, I will preview TALH and ASPEN, two hash-based threshold signature schemes planned for submission to the NIST Multi-Party Threshold Cryptography (MPTC) Call. Both schemes rest on the security of a hash function alone, rather than on a structured algebraic problem. TALH (Threshold Authentication via Leaf-sharing in Hash-based Signatures) is stateless. It distributes among the trustees the secret leaves of a forest of random subsets (FORS) and signs in three rounds, two of which fix a randomizer by commit-then-reveal. I will present two ways of sharing these secrets: a compact version based on replicated seeds, whose storage grows combinatorially with the number of trustees, and a scalable version based on Shamir sharing, which avoids that growth and therefore also fits the medium and large party-count profiles of the Call. ASPEN is stateful. It removes the randomizer, so that signing takes a single round and no interaction among trustees is needed, turning the stateful standards XMSS (eXtended Merkle Signature Scheme) and LMS (Leighton-Micali Signatures) into threshold schemes with a non-interactive signing phase. Both schemes assume a trusted dealer, and the aggregator holds only public data, so any trustee can play its role. I will also discuss how the schemes fit categories S1 and N1.5 of the Call.

Joint work: Muhammed Said Gündoğan.

Suggested readings:

  • Preview Writeup (PDF): TALH: Threshold Authentication via Leaf-sharing in Hash-based Signatures
  • Turning hash-based signatures into distributed signatures and threshold signatures (ia.cr/2022/241)
  • Haystack: Threshold and Distributed Stateful Hash-Based Signatures (Preview writeup)
  • FIPS 205: Stateless Hash-Based Digital Signature Standard.
Presentation
1:00 PM TalonG and P-DualTS: Two-Round Lattice-Based Threshold Signatures
Liming Gao - Chinese Academy of Sciences @ China

"Preview Talk" (by team Octopus) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this presentation, we will present two lattice-based two-round threshold signature schemes supporting general t-out-of-n access structures for the NIST Multi-Party Threshold Cryptography Call. The first scheme, TalonG, targets large-scale threshold settings and focuses on reducing per-party communication overhead. It follows the Raccoon signature framework and its threshold variants, and uses Shamir secret sharing in a trusted-dealer setup. The second scheme, P-DualTS, targets small-party deployments and focuses on compact public keys, short signatures, and efficient communication. It follows the ML-DSA signature framework and recent threshold constructions, and uses replicated secret sharing in a trusted-dealer setup. Both schemes provide post-quantum security under standard lattice assumptions and target Category S1: [Special] Signing of the NIST Threshold Cryptography Call. We will describe the system and security models, the main construction approaches, implementation status, and preliminary performance results, as well as our plans for the final submissions.

Joint work: Man Ho Au, Robert H. Deng, Liming Gao, Bowen Jiang, Xianhui Lu, Tian Qiu, Guofeng Tang, Ruida Wang, Haiyang Xue, Guomin Yang, Chengru Zhang.

Suggested readings

  • Preview Writeup (PDF): TalonG and P-DualTS: Lattice-based Threshold Signatures
  • TalonG: Bandwidth-Efficient Two-Round Threshold Signatures from Lattices (ia.cr/2026/303) 
Presentation
1:25 PM LaTSEC: Lattice-Based Threshold Signature from Expander Codes
Muhammad Arzaki - Monash University @ Melbourne, Australia

"Preview Talk" (by team LaTSEC) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this talk, we present our plan to submit two related cryptosystems to the NIST Threshold Call. Lattice-based threshold signatures with identifiable abort, where misbehaving signers are pinpointed rather than merely detected, need a secret sharing scheme whose shares and reconstruction coefficients are all short; existing schemes of this kind give each participant many short sub-shares, and with them many public verification keys. We first introduce SEC, a secret sharing scheme over integer modules built from a lossless bipartite expander graph, which gives each participant exactly one short share, and we explain why its privacy is computational, reducing to the Module Learning With Errors (MLWE) problem. We then present LaTSEC, a three-round threshold signature over an authenticated broadcast channel that uses SEC as its sharing layer: each participant holds one short signing share and one public abort key, so every partial response is checked independently and non-interactively, without zero-knowledge proofs. We outline its security under the MLWE and Module Short Integer Solution (MSIS) assumptions and show concrete parameters: for 60 participants at 128-bit security, each participant stores a 15.19-KiB share, many times smaller than in the closest comparable scheme. We also discuss the trade-offs, namely a gap between the corruption and signing thresholds, larger signatures, and a trusted dealer, and our plans for the submission package.

Joint work: Muhammad Arzaki, Muhammed F. Esgin, Markku-Juhani O. Saarinen, Amin Sakzad, Ron Steinfeld.

Suggested readings

  • Preview Writeup (PDF): LaTSEC: Lattice-Based Threshold Signature from Expander Codes: Identifiable Aborts from Everywhere-Short Secret Sharing over Integer Modules
  • Blackbox secret sharing revisited: A coding-theoretic approach with application to expansionless near-threshold schemes (ia.cr/2019/1134)
  • Threshold Raccoon: Practical threshold signatures from standard lattice assumptions (ia.cr/2024/184)
  • Hermine: An efficient lattice-based FROST-like threshold signature (ia.cr/2026/419)
Presentation
2:05 PM Thimza: Stateless Threshold Signatures Over Module Lattices with O(1) Signer State
Hamidreza Khorasgani - Purdue University @ USA

"Preview Talk" (by team Thimza) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this presentation, we will talk about Thimza, a threshold signature over module lattices. In a (t,n) threshold signature scheme, a signing key is distributed among n parties such that any subset of at least t members of participants can jointly produce a valid signature which can be verified by an ordinary verifier. The signatures in Thimza are based on Raccoon system (CRYPTO’ 24). Threshold Raccoon is a lattice-based signature scheme which is a Fiat-Shamir construction and has had a significant influence on threshold lattice-based signatures that avoid expensive operations. This scheme and its variants hide partial signatures behind one-time additive masks. However, there are three main issues with this mechanism. First, a signer needs to remember every session identifier it has ever used to avoid repeating masks, which could leak the key share. Moreover, in the two-round case, a signer set is fixed. The next issue is that the channels need to be authenticated by some message authentication code. Previous attempts to address this issue have resulted in signature inflation from 11 to 30-50 kilobytes. The third issue is that the amount of communication per signer is in the range of 27 to 613 kilobytes, which is inefficient. In our signature scheme, we address all these issues. We first show that interactive Fiat-Shamir threshold signatures cannot be stateless; however, one ephemeral self-erasing token per session is enough. Then, we discuss that masks derived from signer’s view imply a view-partition lemma stating that honest responses decompose based on the views of honest parties. This removes authenticated channels and preprocessing awareness of the signer set. We discuss the security analysis of our scheme and show that it is more efficient than previous schemes. For threshold t=1024, the communication per signer is 16.3 KiB which is 1.6 times less than best prior schemes, while it is at least 1.6 times faster.

Joint work: Navid Abapour, Hamidreza Amini Khorasgani.

Suggested readings

  • Preview Writeup (PDF): Thimza: Stateless Threshold Signatures at Optimal Bandwidth
  • Raccoon: A Masking-Friendly Signature Proven in the Probing Model (ia.cr/2024/1291)
  • Threshold Raccoon: Practical Threshold Signatures from Standard Lattice Assumptions (ia.cr/2024/184)
  • Lattice Signatures without Trapdoors (ia.cr/2011/537)
Presentation
2:30 PM TSitH: Threshold Signatures in the Head
Auguste Warmé-Janville - CryptoExperts, Sorbonne University @ France

"Preview Talk" (by team TSitH) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this talk, we will introduce a family of threshold signature schemes based on the MPC-in-the-Head paradigm with threshold-friendly Merkle-tree commitments. It builds on the recent Threshold-Signatures-in-the-Head (TSitH) framework which enables the construction of threshold signatures from any one-way function. The submission will include three concrete instantiations of the framework, based respectively on the block cipher AES, the multivariate quadratic problem (MQ), and the syndrome decoding problem (SD). These variants are intended to provide plausibly post-quantum security: no efficient quantum or classical attacks are known against the underlying symmetric primitives used in the MPC-in-the-Head construction, nor against the hard problems on which the three instantiations rely. The TSitH framework was introduced as a preprint in mid-2026. The present submission aims to develop that framework into concrete threshold signature schemes suitable for consideration in the NIST MPTC process. These schemes combine techniques from hash-based proof systems (MPC-in-the-Head with Merkle tree commitments) and generic secure multiparty computation in order to obtain practical threshold signatures schemes based on various security assumptions.

Joint work: Thibauld Feneuil, Matthieu Rivain, Damien Vergnaud, Auguste Warmé-Janville.

Suggested readings

  • Preview Writeup (PDF): TSitH: Threshold Signatures in the Head: A framework for threshold MPC-in-the-Head signatures
  • “Threshold Signatures in the Head” (ia.cr/2026/1125)
  • Threshold computation in the head: Improved framework for post-quantum signatures and zero-knowledge arguments (ia.cr/2023/1573)
Presentation
October 7, 2026 Type
10:10 AM (Threshold-)CL: (Threshold) Linearly Homomorphic PKE from Class Groups
Quentin Combal - Université de Montpellier @ France

"Preview Talk" (by team CL) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this talk, I will present the Castagnos-Laguillaumie (CL) encryption scheme, a Linearly Homomorphic Public-Key Encryption (LHE) scheme based on Class Groups of imaginary quadratic fields, as well as its threshold variant, Threshold-CL. Both schemes are submitted to the NIST Threshold Call as Gadgets (category S7). LHE and Threshold-LHE have become key tools for building secure MPC protocols. CL offers a LHE that, compared to Paillier, is more efficient for security levels of 128 bits and above, and gives shorter ciphertexts. CL does not require a trusted setup, thanks to the unique context of class groups, another useful property for secure MPC. The threshold variant, Threshold-CL, is statically secure in the honest majority setting, and provides efficient distributed decryption that scales well with large sets of parties. I will provide a performance overview of CL and Threshold-CL from their implementation in the BICYCL library, and give examples of threshold schemes that make use of CL or Threshold-CL.

Joint work: Cyril Bouvier, Lennart Braun, Guilhem Castagnos, Quentin Combal, Fabien Laguillaumie, Kelsey Melissaris, Ida Tucker.

Suggested readings

  • Preview Writeup (PDF): CL and Threshold-CL: (Threshold) Linearly Homomorphic PKE from Class Group
  • Practical Fully Secure Unrestricted Inner Product Functional Encryption modulo p (ia.cr/2018/791)
  • An Improved Threshold Homomorphic Cryptosystem Based on Class Groups (ia.cr/2024/717)
Presentation
10:35 AM Axolotl: Robust Asynchronous Threshold Schnorr
Luke Parker - Serai DEX @ Florida, USA

"Preview Talk" (by team Trout) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this talk, we will present Axolotl, a multi-party pseudo-random function. Axolotl can be executed by arbitrary thresholds over an asynchronous network where participants solely have peer-to-peer channels with each other. Despite this flexibility, Axolotl is concretely efficient, requiring just a few kibibytes be multicast by each participant at the 128-bit security level.

We then premise a threshold Schnorr signing protocol upon Axolotl. The result is a two-round protocol which does not require a consistent set to participate in each round, nor a consistent view over who participated in the first round, avoiding the overhead (and assumptions) required for agreement. We manage to achieve this result without the use of Fully Homomorphic Encryption or similarly heavy cryptography, instead premising our instantiation on a group of unknown order.

Joint work: Hila Dahari-Garbian, Ariel Nof, Luke Parker.

Suggested readings

Presentation
11:00 AM Stoats: Short Two-round vOle-bAsed Threshold Signatures
Elahe Sadeghi - University of Texas @ Austin, USA

"Preview Talk" (by team The Stoats) @ TCPT3, in reply to the NIST Threshold Call

Abstract: This presentation covers our plan to submit Stoats, a family of two-round two-party threshold signature crypto-systems built from pseudorandom correlation functions (PCFs). The principal crypto-systems computes ECDSA (Elliptic Curve Digital Signature Algorithm) or Schnorr signatures in two rounds with about a hundred bytes of communication and a runtime in the range of one millisecond. The crypto-systems from the Stoats family satisfy malicious security in the universal composability framework and include variants with stateless and deterministic signing, i.e., nonces are derived pseudorandomly without keeping state across signing sessions. Signing is enabled by a one-time interactive setup that distributes keys for a PCF generating vector oblivious linear evaluation (VOLE) correlations; the PCF is based on the well-studied sparse learning-parity-with-noise (LPN) assumption in the random oracle model. The underlying VOLE-PCF and its maliciously secure distributed key generation are also specified as a standalone gadget and submitted as a crypto-system.

Joint work: Lennart Braun, Geoffroy Couteau, Kelsey Melissaris, Mahshid Riahinia, Peter Rindal, Elahe Sadeghi.

Suggested readings

  • Preview Writeup (PDF): Stoats: Short Two-round vOle-bAsed Threshold Signatures: Two-Party Signing from Pseudorandom Correlated Functions for Vector OLE
  • Succinct Two-Round Two-Party Signing from PCFs (ia.cr/2026/1978)
  • Fast Pseudorandom Correlation Functions from Sparse LPN (ia.cr/2025/1644)
Presentation
11:40 AM Stoats: Short Two-round vOle-bAsed Threshold Signatures
Elahe Sadeghi - University of Texas @ Austin, USA

"Preview Talk" (by team The Stoats) @ TCPT3, in reply to the NIST Threshold Call

Abstract: This presentation covers our plan to submit Stoats, a family of two-round two-party threshold signature crypto-systems built from pseudorandom correlation functions (PCFs). The principal crypto-systems computes ECDSA (Elliptic Curve Digital Signature Algorithm) or Schnorr signatures in two rounds with about a hundred bytes of communication and a runtime in the range of one millisecond. The crypto-systems from the Stoats family satisfy malicious security in the universal composability framework and include variants with stateless and deterministic signing, i.e., nonces are derived pseudorandomly without keeping state across signing sessions. Signing is enabled by a one-time interactive setup that distributes keys for a PCF generating vector oblivious linear evaluation (VOLE) correlations; the PCF is based on the well-studied sparse learning-parity-with-noise (LPN) assumption in the random oracle model. The underlying VOLE-PCF and its maliciously secure distributed key generation are also specified as a standalone gadget and submitted as a crypto-system.

Joint work: Lennart Braun, Geoffroy Couteau, Kelsey Melissaris, Mahshid Riahinia, Peter Rindal, Elahe Sadeghi.

Suggested readings

  • Preview Writeup (PDF): Stoats: Short Two-round vOle-bAsed Threshold Signatures: Two-Party Signing from Pseudorandom Correlated Functions for Vector OLE
  • Succinct Two-Round Two-Party Signing from PCFs (ia.cr/2026/1978)
  • Fast Pseudorandom Correlation Functions from Sparse LPN (ia.cr/2025/1644)
Presentation
1:00 PM DKLs: Threshold ECDSA from VOLE and Commitments
Jack Doerner - University of Virginia @ Charlottesville, USA

"Preview Talk" (by team ABCDKLs: Associated Builders of and Contributors to the DKLs protocols) @ TCPT3, in reply to the NIST Threshold Call

Abstract: TBA

Joint work: Jack Doerner, Yashvanth Kondi, Eysa Lee, Peter Rindal, Lawrence Roy, abhi shelat.

Suggested readings

Presentation
1:25 PM Menshen and Octopus-(T)CL: Two-party and Threshold ECDSA Schemes
Haiyang Xue - Singapore Management University @ Singapore

"Preview Talk" (by team Octopus) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this talk, we present three threshold ECDSA schemes — a two-party protocol and two t-out-of-n threshold signature protocols — submitted as the Octopus team's preview proposals to the NIST Multi-Party Threshold Cryptography (MPTC) call. All three schemes run in three rounds. (1) Our two-party scheme, Menshen, requires only a single multiplicative-to-additive (MtA) conversion, also known as oblivious linear evaluation (OLE); importantly, this MtA is key-independent. (2) Our first t-out-of-n scheme, Octopus-CL, relies on standard Castagnos–Laguillaumie (CL) encryption. It provides cheater identification for any threshold t, and additionally guarantees robustness in the honest-majority setting. (3) Our second t-out-of-n scheme, Octopus-TCL, builds on a threshold version of CL encryption.

Joint work: Man Ho Au, Robert H. Deng, Liming Gao, Bowen Jiang, Xianhui Lu, Tian Qiu, Guofeng Tang, Ruida Wang, Haiyang Xue, Guomin Yang, Chengru Zhang.

Suggested readings

  • Preview Writeup (PDF): Menshen and Octopus-(T)CL: Two-party and Threshold ECDSA Schemes
  • Efficient online-friendly two-party ECDSA signature (ia.cr/2022/318)
  • Robust Threshold ECDSA with Online-Friendly Design in Three Rounds (ia.cr/2025/910)
  • Three-Round (Robust) Threshold ECDSA from Threshold CL Encryption (ia.cr/2026/190)
Presentation
1:50 PM TapTop and Robot: Two-party BBS and Robust Threshold BBS Schemes
Guofeng Tang - Singapore Management University @ Singapore

"Preview Talk" (by team Octopus) @ TCPT3, in reply to the NIST Threshold Call

Abstract: In this presentation, we will introduce a two-round threshold BBS scheme, which currently achieves the minimum number of rounds. It is the best of both worlds: it satisfies security under a dishonest majority assumption and robustness under an honest majority, meaning that the signing protocol is guaranteed to output a valid signature as long as there are enough honest signers. Additionally, we will discuss how this protocol achieves high efficiency while minimizing communication rounds and maintaining robustness. At the same time, we will also introduce a two-party BBS scheme in two passes, which outperforms previous two-party constructions in terms of both communication and computation. This makes our solutions highly practical for decentralized credential systems and real-world privacy-preserving applications.

Joint work: Man Ho Au, Robert H. Deng, Liming Gao, Bowen Jiang, Xianhui Lu, Tian Qiu, Guofeng Tang, Ruida Wang, Haiyang Xue, Guomin Yang, Chengru Zhang.

Suggested readings

Presentation

Event Details

Starts: September 29, 2026 - 10:00 AM EDT
Ends: October 13, 2026 - 11:30 AM EDT

Format: Virtual Type: Workshop

Register

Attendance Type: Open to public
Audience Type: Other, Academia, Government, Industry

Related Topics

Security and Privacy: cryptography, privacy

Created August 07, 2026, Updated October 06, 2026