Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up
IETF RFC 9591 Standard t-of-n Threshold Schnorr Taproot & Ed25519 Indistinguishable

FROST Threshold Schnorr Signatures Studio

Simulate RFC 9591 two-round threshold Schnorr signatures. Inspect Shamir polynomial secret sharing, Drijvers-resistant binding factors, Lagrange interpolation, and on-chain indistinguishable signature aggregation.

1. Threshold Quorum Topography

2. Transaction Message & Signing Trigger

Active Signers
2 / 3
Quorum satisfied (t ≥ 2)
Online Network Rounds
1 Round
Pre-computed nonces
On-Chain Wire Size
64 Bytes
Matches 1-of-1 Schnorr
Drijvers Attack Immunity
SECURE
Binding factors bound to m
Schnorr Verification
VALID
g^z == R · Y^c

3. Interactive RFC 9591 Protocol Trace

Round 1: Nonce Commitments
Signers generate pairs (d_i, e_i) → Publish commitments (D_i, E_i).
Aggregator builds commitment list B = [(1, D_1, E_1), (2, D_2, E_2)].
Round 2: Binding & Share Generation
Binding factors ρ_i = H_1(i, m, B).
Group commitment R = ∑ (D_i + ρ_i · E_i).
Challenge c = H_2(R, Y, m).
Share z_i = d_i + (e_i · ρ_i) + λ_i · s_i · c.
Final: Signature Aggregation
Sum scalar shares: z = ∑ z_i mod q.
Output: σ = (R, z) [64 bytes].
Verification: g^z == R + c · Y.
Aggregated Group Schnorr Signature (R, z):
79be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798483ada7726a3c4655da4fbfc0e1108a8fd17b448a68554199c47d08ffb10d4b8

4. RFC 9591 Python / Rust Cryptographic Implementation


      
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement