The hardened tss-lib (threshold-network/tss-lib#37) offers two transcript modes. keep-core#4349 hardcodes ProtocolModeLegacy for its first release, which keeps the historical wire transcript.
ProtocolModeSecurityV2 adds tagged, session-bound Fiat-Shamir challenges and binds the signed message and its width into the signing session ID. It is a wire break: legacy and security-v2 parties cannot share a ceremony, and there is no negotiation or fallback, so every signer in a group must switch at the same point.
Requirements
- Every member of a ceremony uses the same mode; a mismatch aborts the ceremony.
- Security-v2 needs one unique session nonce per ceremony, agreed by all members (
params.SetSessionNonce / SetSessionNonceBytes).
- The legacy-only historical Bob compatibility flag must already be retired.
Options
- On-chain activation block or epoch. Governance sets the switch point and nodes read it. Strongest coordination; needs contract work and a release that supports both modes.
- Release that hardcodes security-v2. Simplest code, but any node that hasn't upgraded aborts ceremonies until it does.
- Config flag. Flexible, but one misconfigured operator can split a signing group.
Also to decide
- Where the per-ceremony nonce comes from (for example, derived from on-chain data every member already has).
- Who owns the cutover and how it is announced.
Deferred until the legacy release is deployed and the compatibility flag is retired.
The hardened tss-lib (threshold-network/tss-lib#37) offers two transcript modes. keep-core#4349 hardcodes
ProtocolModeLegacyfor its first release, which keeps the historical wire transcript.ProtocolModeSecurityV2adds tagged, session-bound Fiat-Shamir challenges and binds the signed message and its width into the signing session ID. It is a wire break: legacy and security-v2 parties cannot share a ceremony, and there is no negotiation or fallback, so every signer in a group must switch at the same point.Requirements
params.SetSessionNonce/SetSessionNonceBytes).Options
Also to decide
Deferred until the legacy release is deployed and the compatibility flag is retired.