PiVer Preview

32 views
Skip to first unread message

Karim Baghery

unread,
Jan 29, 2026, 6:59:32 AMJan 29
to MPTC-forum, pi...@esat.kuleuven.be
Dear Threshold Crypto friends,

Following Luís’s invitation, I would like to briefly introduce PiVer, our preview submission to the NIST Threshold Cryptography Call (Category S7), on behalf of the PiVer team.

PiVer is a unified and modular framework for constructing computationally secure Verifiable Secret Sharing (VSS) schemes in the synchronous communication model. It builds upon the Π framework (2023/1669) for computational VSS and significantly extends it by supporting a wide range of variants, instantiations and optimizations under minimal cryptographic assumptions.

In particular, PiVer:

Uses any commitment scheme satisfying hiding and binding (optionally homomorphic, non-malleable, and/or post-quantum secure),

Unifies several Π-based advances, including:
- the original Π VSS protocol (PiVer),
- a round-optimal variant (PiVer-2R),
- a pre-constructed variant with public commitment to the secret (PiVer-PC),
- batched and packed extensions for improved efficiency (PiVer-Batch),
- and a generalized construction supporting arbitrary 𝒬₂ access structures (PiVer-Q2).

Together, these results enable flexible and efficient design of computational VSS and publicly verifiable VSS schemes, including post-quantum–secure instantiations. Our preview includes both discrete-logarithm–based and post-quantum instantiations, along with open-source implementations and concrete performance evaluations.

I will be presenting PiVer today during:
Session 4b (11:10–12:50): Miscellaneous: RSA DKG; VSS; BB Limitations
• Talk 4b2. 11:37–12:02: PiVer: Π Verifiable Secret Sharing Framework

We very much welcome feedback and discussion, both during the workshop and afterwards.

Looking forward to the talks and discussions at MPTS.

Best regards,
Karim Baghery
On behalf of the PiVer team
COSIC, KU Leuven
Reply all
Reply to author
Forward
0 new messages