FROST Guide
Threshold RedPallas: FROST and its Zcash integration surfaces
Abstract
Assuming Schnorr signatures from the Crypto Guide, RedPallas from the Ironwood Guide, PCZT from the Wallet Guide, and the finalizer model from the Crosslink Guide, this volume of The Zcash Arboretum documents threshold signing for Zcash. It constructs FROST as specified in RFC 9591, then its re-randomised form for Zcash spend authorisation and recoverability custody. The re-randomised Zcash stack is outside the completed cryptographic-library audits identified here; each design-stage claim is classified by the rigour of its source.
Contents
- 1 Scope, sources, and deployment surfaces
-
2 FROST
- 2.1 Shamir sharing and share conversion
- 2.2 Key generation: Pedersen’s DKG with a knowledge proof
- 2.3 Preprocessing and the two-round signing protocol
- 2.4 Why the binding factor exists: Drijvers and ROS
- 2.5 Nonce hygiene
- 2.6 The security theorem as stated
- 2.7 The corrected and extended analyses
- 2.8 RFC 9591 against the paper: what the RFC changed
-
3 Re-Randomized FROST for RedPallas
- 3.1 The mismatch: consensus verifies only randomised keys
- 3.2 Re-Randomized FROST: the construction
- 3.3 Unforgeability: TRUF, AOMDL, and Theorem 1
- 3.4 ZIP 312: the specification
- 3.5 The ciphersuite FROST(Pallas, BLAKE2b-512)
- 3.6 Published library implementation: frost-rerandomized and reddsa
- 3.7 Custody surfaces and classification
-
4 Deployment and open questions
- 4.1 The shipped library stack
- 4.2 The randomizer flow: draft ZIP against shipped crate
- 4.3 PCZT as the integration surface
- 4.4 Wallet-integration constraints
- 4.5 Transport: frostd and frost-client
- 4.6 Audit coverage, precisely
- 4.7 Custody of the ZIP-2005 quantum spending key
- 4.8 Crosslink finalizer keys
- 4.9 Classification and revisit triggers