“Preview Talk” (by Team TALUS) @ TCPT2, in reply to the NIST Threshold Call
Editor's note: There is a recent claim (ia.cr/2026/1386) of a key-recovery attack on TALUS. The authors are preparing a technical response. This page will be updated then.
Abstract: In this presentation, we introduce TALUS, a threshold signing protocol for ML-DSA (FIPS 204) that achieves one-round online signing by filtering nonces offline. The core technique is the Boundary Clearance Condition (BCC): a publicly verifiable predicate on the nonce vector that geometrically guarantees the secondary rejection check will pass, eliminating the only secret-dependent abort in ML-DSA's signing loop. For ML-DSA-65, approximately 31.7% of random nonces satisfy BCC, meaning roughly three offline attempts produce a usable nonce in expectation. We present two deployment models. TALUS-TEE uses a Trusted Execution Environment to hold the aggregate nonce, enabling single-round signing with 1.52 ms end-to-end latency at a 3-of-5 threshold. TALUS-MPC removes the hardware trust assumption via a fully distributed protocol using carry elimination and masked broadcast, achieving 4.09 ms with honest majority. Both models produce standard FIPS 204 signatures verifiable by any unmodified ML-DSA verifier.
Joint work: Leo Kao, Raymond Chang
Suggested readings:
Presented at TCPT2 (2026-July-08): Threshold Call Preview Talks #2
Security and Privacy: cryptography