[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83345-en":3,"doc-seo-83345-105":30,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83345,687197207919,"Theodora","https://ap-avatar.wpscdn.com/avatar/a000253d6f5f7c60be?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779446848396160552",8,"Research & Report","Threshold Authorization Without Threshold Signatures: Signature-Agnostic MPC Custody","Digital-asset custody traditionally relies on threshold multi-party approval where t-of-n participants authorize and fewer than t compromised parties cannot authorize or learn the secret. Post-quantum migration disrupts threshold signature efficiency, while lattice- and hash-based threshold approaches remain difficult for production. A dual-gate architecture separates member authentication from threshold authorization: ordinary member signatures verify approvals, and a quorum derives a threshold seal from Shamir-shared secrets bound to the operation. The seal supports programmable authorization policies without thresholding the signature itself, enabling cryptographic agility and enforcing-layer security.","arXiv :2607 .08226v 1 [ cs .CR] 9 Jul 2026  \nThreshold Authorization Without Threshold  \nSignatures:  \nSignature-Agnostic MPC Custody  \nDariia Porechna [0009-0009-8834-4652]  \nEternaX Labs  \n[dariia.p@eternax.ai](dariia.p@eternax.ai)  \nAbstract. Digital-asset custody has been built on threshold multi-party approval: no operation proceeds unless t of n parties approve, and fewer than t compromised parties can neither authorize nor learn the authorization secret. Threshold signature schemes (TSS) have been the standard mechanism, but the post-quantum transition disrupts this model: standardized hash-based signatures resist efficient threshold signing, and lattice-based threshold protocols remain an emerging research track.  \nWe present a dual-gate architecture that separates member authentication from threshold authorization. Each member signs its approval with an ordinary signature under any EUF-CMA scheme; the quorum jointly produces a threshold seal from Shamir-shared secrets bound to the operation. The seal is the base instance of a programmable authorization computation: simple quorum is the minimal policy, while richer policies can evaluate secret-shared state without making the member-signature scheme part of that computation. The signature scheme is a deployment parameter: migrating from ECDSA to SLH-DSA or ML-DSA is a key rotation, not a protocol redesign, and members holding keys in commodity HSMs participate through the standard sign API.  \nThe architecture can be deployed wherever the asset-control path supports programmable verification, such as smart contracts, vault modules, or HSMs guarding a master key, and produces an enforcement-layer authorization rather than a native chain signature. Below-threshold secrecy is information-theoretic; an adversary holding ≥ t signing keys but no coefficient shares still cannot produce the seal.  \nKeywords: Threshold cryptography · MPC custody · Post-quantum migration · Secret sharing · Digital-asset custody  \n1 Introduction  \n1.1 The post-quantum custody problem  \nDigital-asset custody faces the post-quantum transition as a control-plane problem as much as a transaction-signature problem. A custodian cannot make Bitcoin, Ethereum, or any other chain accept a new signature scheme before  \n2 D. Porechna  \nthe protocol does, but it can make the layers it controls post-quantum ready and cryptographically agile: member authentication, policy enforcement, vendor integrations, backups, and the signing infrastructure that will extend to future on-chain schemes. That is highlighted in the Taurus June 2026 report [18]: readiness means avoiding architecture choices that lock the authorization layer to one classical signature protocol while standards, vendors, and chains are in active research and transition.  \nThe pressure is concrete on both the regulatory and the protocol side. Executive Order 14412 (June 2026) mandates the transition of federal high-value and high-impact systems to post-quantum digital signatures by the end of 2031 and extends post-quantum FIPS compliance to federal contractors through procurement rules [19] . The FIPS-approved hash-based signatures appear on major blockchain migration paths and make the problem more pressing for MPC custody stacks [7, 18] .  \nThe cryptographic promise of threshold-signature MPC custody concerns key material: no compromise of fewer than t of the n key shares yields the signing key or a signature. Threshold ECDSA (GG18/GG20, CMP, FROST [8,4 , 12]) delivers this for classical signatures by bundling member authentication and threshold authorization into one cryptographic object.  \nThe post-quantum migration breaks that bundle. Lattice-based threshold signatures (ML-DSA, Falcon) are an active research and standardization track [16, 17 ,5] but not the production baseline occupied by threshold ECDSA. For hash-based signatures (SLH-DSA [15], LMS/HSS), Kondi, Kumar, and Vanegas [13] rule out black-box threshold protocols, so any threshold sig","cbCaij7RgYUTBlOI","https://ap.wps.com/l/cbCaij7RgYUTBlOI","pdf",584005,3,1,25,"English","en",105,"# Introduction\n## The post-quantum custody problem\n## Separating authentication from authorization","[{\"question\":\"How does the design support cryptographic agility when moving to post-quantum signature schemes?\",\"answer\":\"The signature scheme is treated as a deployment parameter: rotating keys from ECDSA to SLH-DSA or ML-DSA is treated as a key rotation rather than a protocol redesign. Members can participate through standard sign APIs while the authorization seal mechanism remains the enforcement layer.\"}]",1784186911,63,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":28},"threshold-authorization-without-threshold-signatures-signature-agnostic-mpc-custody","",{"@graph":36,"@context":77},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/threshold-authorization-without-threshold-signatures-signature-agnostic-mpc-custody/83345/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"How does the design support cryptographic agility when moving to post-quantum signature schemes?","Question",{"text":75,"@type":76},"The signature scheme is treated as a deployment parameter: rotating keys from ECDSA to SLH-DSA or ML-DSA is treated as a key rotation rather than a protocol redesign. Members can participate through standard sign APIs while the authorization seal mechanism remains the enforcement layer.","Answer","https://schema.org",{"og:url":51,"og:type":79,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":81,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":84},[85,89,93,97,102,107,112,115,120,123,127],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},6,"Technology",50,"technology",{"id":108,"doc_module":4,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":113,"slug":114},30,"research-report",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},9,"Religion & Spirituality",20,"religion-spirituality",{"id":118,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":118,"slug":122},"World Cup","world-cup",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":124,"slug":126},10,"Lifestyle","lifestyle",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":98,"slug":130},19,"General","general"]