I don't really understand the basic concept, is there not a write up somewhere?

If the main claim is 1 round signing with nonce preprocessing, how is that different to FROST? That was one of FROST's main claims, that you could optionally do that; it's even in the abstract of the original paper.

Reply to this note

Please Login to reply.

Discussion

Yes, you can perform nonce preprocessing with FROST as well, but the problem is that a disruptive signer can force a re-do of the entire signing session. This means you must repeatedly attempt the signing session until it succeeds, and therefore you need to run a server.

In contrast, with NOIST, a valid partial signature is guaranteed to produce a valid full signature when combined with others. A signer cannot force a re-do of the entire session.