“Preview Talk” (by Team LoTRS) @ TCPT2, in reply to the NIST Threshold Call
Abstract: In this presentation, we will introduce LoTRS, a lattice-based post-quantum structured threshold ring signature scheme. A threshold ring signature lets a quorum jointly sign while hiding which eligible signers participated. LoTRS formalizes a structured version of this primitive: public keys are arranged in a table, and a valid quorum consists of one hidden column, with one signer from each row. This captures settings where the approval pattern is public, such as one delegate per organization, role, or precinct, but the actual approving column should remain private. The construction separates threshold signing from the anonymity mechanism: a two-round lattice-based multi-signature proves that the quorum signed, while a one-out-of-many zero-knowledge proof hides which column was used. To the best of our knowledge, LoTRS is the first construction in which a TRS variant is obtained by combining these primitives. We will describe the new structured threshold ring signature model, the LoTRS construction, and our implementation results. For the headline setting with 50 rows and 100 candidate columns, LoTRS produces signatures of about 35 KB, roughly 3.5 times smaller than the previous best lattice-based threshold ring signature, with signing and verification wall-clock times of 789 ms and 250 ms, respectively. Our work includes Python and Rust implementations, deterministic test vectors, parameter-estimation scripts, and benchmarks.
Joint work: Nikai Jagganath, Muhammed Esgin, Ron Steinfeld, Amin Sakzad, Markku-Juhani O. Saarinen, Dongxi Liu
[Slides] Suggested readings:
Presented at TCPT2 (2026-July-08): Threshold Call Preview Talks #2
Security and Privacy: cryptography