Shamir or FROST? The right architecture depends on how you use your assets.
Over the last posts, we looked at two approaches to distributed key management: Shamir Secret Sharing and FROST threshold signatures.
Both can remove dependency on a single keyholder. But they solve different operational problems.
Shamir is fundamentally simple to understand: split a secret into several shares and define a threshold — for example, 3-of-5.
When recovery is required, enough shares are combined and the original secret can be reconstructed.
That makes Shamir particularly interesting when the main objective is secure backup and recovery. A single asset owner can even distribute their shares across separate secure locations.
The trade-off comes when the key needs to be used. Once the threshold is reached, the complete secret can exist again during reconstruction. The reconstruction environment therefore becomes part of the security model.
FROST approaches everyday operation differently.
Again, participants hold shares of a common signing key and a threshold can be defined. But during normal signing, the required participants cooperate to create signature shares. Those are combined into one valid Schnorr signature — without reconstructing the complete signing key.
That makes FROST particularly interesting when distributed control is required not only for recovery, but for regular transaction signing.
So which is better?
There is no universal answer.
For an individual investor or single high-value trader, Shamir can offer an understandable way to distribute recovery material and avoid keeping one complete secret in one location.
For a family office or small organization, the decision increasingly depends on operational requirements. Is distributed control primarily needed for disaster recovery, or should several people participate every time important assets are moved?
For SMEs, institutions and professional asset operations, FROST can become particularly interesting where multiple authorized participants should jointly sign transactions without reconstructing the complete signing key during normal operation.
And there are more questions than security alone:
- How easy is the initial setup?
- How does recovery work?
- How convenient is everyday signing?
- What happens when a participant leaves?
- How are shares replaced or refreshed?
- What happens if participants are unavailable?
- Which blockchains and signature schemes are supported?
- And how does the cryptographic threshold connect to the organization’s actual governance?
That last question is crucial.
A 3-of-5 cryptographic threshold does not automatically tell you who is allowed to initiate a €5 million transaction, which assets they may move, which addresses are permitted or what transaction limits apply.
That is governance.
With BlockSign, organizations can choose a key-management architecture that fits their operational and security requirements and combine it with roles, approvals, policies, transaction limits and audit evidence.
Shamir distributes the secret.
FROST distributes the signing process.
BlockSign adds the governance around it.
Not sure which architecture fits your digital asset operations? Talk to us.
What if you could sign with a private key, without ever bringing the complete key back together?
That is the idea behind FROST (= Flexible Round-Optimized Schnorr Threshold) Signatures.
Imagine a 3-of-5 setup. Five participants each hold a secret share of a common signing key. At least three must cooperate to create a valid signature.
But unlike the reconstruction process we described in our Shamir post, the participants do not need to combine their shares to reconstruct the complete private key before signing.
Instead, each participating signer uses its own share to produce a signature share. Once the required threshold participates, those signature shares are aggregated into one valid Schnorr signature. The complete group signing key does not need to be reconstructed during normal signing.
This removes an important risk: there is no moment during normal signing when the complete private key needs to be brought together in one place.
And compromising a single participant is not enough. An attacker would need to compromise enough signing participants to reach the defined threshold.
But cryptography alone is not governance.
FROST can enforce that, for example, 3-of-5 cryptographic participants must cooperate. BlockSign adds the operational governance around it: who may initiate a transaction, who may approve it, which limits apply and which assets or addresses are permitted.
With BlockSign, organizations can choose the key-management architecture that fits their security and governance requirements, including Shamir-based and FROST-based models.
Shamir can reconstruct the secret.
FROST creates the signature without reconstructing it during normal signing.
In our next and final post in this series, we’ll put Shamir and FROST side by side and explain when the differences matter.
Want to discuss which key-management architecture fits your digital asset operations? Talk to us. DM us.