Hermes / FROST

FROST: any t of n can sign

MuSig2 (demo 12) was n-of-n: every cosigner had to sign. FROST (RFC 9591) is t-of-n: any threshold, say 2 of 3, can produce one signature, and any 1 alone cannot. The group secret is Shamir-shared once and never reassembled; signing folds the shares into the signature through Lagrange interpolation. Lose a key and the treasury is safe; a thief with one share has nothing. It's the cryptographic shape of a real corporate vault, delivered as one ordinary Schnorr signature.

1 · The dealer splits one key into three shares

group public key  · the vault, from a secret no one holds whole
–

A trusted dealer draws one random group secret, splits it across a degree-1 polynomial (so any 2 points recover it), and hands each officer a share. The dealer then forgets the secret. New group re-runs the deal.

2 · Choose who signs, then run the ceremony

tick any two officers above
pick a signing set to begin

Two rounds (like MuSig2): each present officer commits a nonce pair, then returns a signature share zi weighted by their Lagrange coefficient λi. The coordinator adds the shares, and out comes a single signature the whole group could have made.

The signature

aggregate (R ‖ z) · 65 bytes, verifies under the group key
run the ceremony…

vs MuSig2 (demo 12)

MuSig2

n-of-n
every key must sign: a 2-of-2 or a full board. Miss one and there's no signature.

FROST

t-of-n
any threshold signs: 2 of 3, 3 of 5. Keys can be lost or absent and the vault still works.

Both produce one Schnorr signature. FROST adds fault-tolerance: the difference between "everyone, always" and "enough of us."

Why the secret never exists

Shamir places the secret at f(0) of a hidden polynomial; each officer holds one point f(i). Any two points fix the line and thus f(0), but no single point reveals anything. FROST does this recombination inside the signature math, so f(0) is never actually computed anywhere.

Things to notice

One short is a hard no

Select a single officer and the ceremony can't even start: below the threshold there's no valid Lagrange set. Two is enough; the third is redundant. That's the "flexible" in FROST.

Same signature, either pair

Officers {1,2}, {1,3} or {2,3} all sign for the same group key and produce a valid signature under it. The verifier can't tell which two showed up, or even that it was a threshold scheme at all.

Accountable shares

Each share zi verifies on its own before aggregation (RFC 9591's identifiable abort), so a faulty or malicious signer is named rather than just producing a dud signature.