-
Notifications
You must be signed in to change notification settings - Fork 87
Description
I see in the docs (https://frost.zfnd.org/tutorial/signing.html#participants-round-1) that it states:
SigningCommitments must be sent to the Coordinator using an authenticated channel.
However I see no mention in the FROST paper about this or the draft protocol (https://www.ietf.org/archive/id/draft-irtf-cfrg-frost-14.html#section-5.2). There is no mention of participants verifying that the commitments belong to the other participants in the commitment set. The commitments are sent by the coordinator and could be anything.
I assumed that if the coordinator could send arbitrary commitments to participants, that the coordinator could not use this to forge signatures. I assumed that it would only result in failure for the signature to be generated.
Is this wrong? Is there a security concern that isn't mentioned in the FROST paper or draft standard?