#crypto #threshold #signature #schnorr


Types and traits to support implementing Flexible Round-Optimized Schnorr Threshold signature schemes (FROST)

9 releases (1 stable)

new 1.0.0 Feb 19, 2024
1.0.0-rc.0 Nov 17, 2023
0.7.0 Sep 13, 2023
0.6.0 Jul 5, 2023
0.1.0 Mar 9, 2023

#161 in Cryptography

Download history 61/week @ 2023-11-06 331/week @ 2023-11-13 266/week @ 2023-11-20 303/week @ 2023-11-27 384/week @ 2023-12-04 969/week @ 2023-12-11 351/week @ 2023-12-18 290/week @ 2023-12-25 499/week @ 2024-01-01 640/week @ 2024-01-08 727/week @ 2024-01-15 747/week @ 2024-01-22 1331/week @ 2024-01-29 738/week @ 2024-02-05 864/week @ 2024-02-12 988/week @ 2024-02-19

3,984 downloads per month
Used in 9 crates (7 directly)


4.5K SLoC

FROST (Flexible Round-Optimised Schnorr Threshold signatures) Core

Base traits and types in Rust that implement 'Two-Round Threshold Schnorr Signatures with FROST' generically for Ciphersuite implementations.

For key generation, refer to the keys module. For round-specific types and functions, refer to the round1 and round2 modules. This module contains types and functions not directly related to key generation and the FROST rounds.

Status ⚠

The FROST specification is not yet finalized, though no significant changes are expected at this point. This code base has been audited by NCC. The APIs and types in frost-core are subject to change during the release candidate phase, and will follow SemVer guarantees after 1.0.0.


frost-core implements the base traits and types in a generic manner, to enable top-level implementations for different ciphersuites / curves without having to implement all of FROST from scratch. End-users should not use frost-core if they want to sign and verify signatures, they should use the crate specific to their ciphersuite/curve parameters that uses frost-core as a dependency, such as frost_ristretto255.


See ciphersuite-specific crates, e.g. frost_ristretto255.


~139K SLoC