> > I am familiar with the Princeton threshold signature but I was under the > impression a single key needed to be generated on a single device then > split and distributed. > > Does this scheme work the same way? > No, it doesn't. Neither device ever sees as master private key.