logo

Threshold Cryptography IV: Multiplicative-to-Additive (MtA) Protocol and Paillier Encryption Scheme

ID: e41a2b65-b110-5f96-86bc-a9361b5775b7

STIX ID: report--e41a2b65-b110-5f96-86bc-a9361b5775b7

Feed Name: CertiK Blog

Date Published: 2025-08-10

Date Updated: 2026-06-11

...
...

## Executive summary This post explains the Paillier additively homomorphic encryption scheme and its use in the MtA (Multiplicative-to-Additive) protocol for converting multiplicative shares into additive shares within threshold ECDSA (as used in Binance tss-lib and GG18). It covers Paillier key generation, encryption/decryption correctness, additive homomorphism properties, and a detailed description of the three-round interactive MtA(MtAwc) protocol including range- and Bob-proofs, under the assumption of mutually verified public parameters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.