Featured Developer Sponsor • Zero-Token Protection
Threshold Decryption & Distributed Key Generation Studio
Architect dealer-less collective cryptographic authority with Pedersen DKG & Threshold ElGamal.
Simulate polynomial secret sharing rounds, complaint verification, QUAL set consensus,
and partial decryption share reconstruction with Lagrange basis coefficients.
Pedersen DKG
Zero Trusted Dealer
Threshold ElGamal
GJKR99 Unbiased
Total committee size n and reconstruction quorum t
Fault injection for complaint & disqualification testing
Prime-order elliptic curve generator group G
Payload encrypted under collective public key Y
DKG Committee Consensus & Key State
QUAL: 5/5 ACTIVE
Master Key Status
DEALER-LESS
Master secret x never materialized
Quorum Quota
3 of 5 Nodes
Threshold required for decryption
Decryption Time
1.45 ms
Parallel share evaluation
Disqualified Nodes
0 Nodes
Ejected via complaint consensus
Collective Public Key: Y = ∏i ∈ QUAL gzi mod p
Participant Share: xj = ∑i ∈ QUAL fi(j) mod q
Decryption Aggregation: Yr = ∏j ∈ S Djλj(0)
Committee Node Registry & Share Contributions
Active Set: QUAL Committee
Production Pedersen DKG & Threshold ElGamal Decryption
Python 3.11+ / Petlib (secp256k1)
The Two Rounds of Pedersen DKG
Pedersen Distributed Key Generation orchestrates parallel Verifiable Secret Sharing (VSS):
- Round 1 (Polynomial Commitments): Every node $P_i$ picks secret value $z_i$ and generates polynomial $f_i(x)$ with $f_i(0) = z_i$. $P_i$ publishes commitments $C_{i,k} = g^{a_{i,k}} h^{b_{i,k}}$ for all coefficients.
- Round 2 (Pairwise Share Exchange): $P_i$ computes share $s_{i,j} = f_i(j)$ and transmits it to $P_j$ over an encrypted channel. $P_j$ validates $s_{i,j}$ against the public commitments $C_{i,k}$.
- Complaint Resolution & QUAL: If $s_{i,j}$ fails validation, $P_j$ publishes a complaint. $P_i$ must reveal the share publicly; failure to do so results in $P_i$ being disqualified. The remaining nodes form the qualified set $QUAL$.
Threshold Decryption without Private Key Assembly
Once encrypted under joint key $Y$, decrypting data never requires reconstructing the master secret:
- Partial Decryption Shares: Each node $P_j in S$ computes $D_j = C_1^{x_j}$ and attaches a zero-knowledge discrete logarithm equality proof.
- Lagrange Recombination: The aggregator computes coefficients $lambda_j(0) = prod_{m in S, m eq j} rac{-m}{j - m} pmod q$.
- Instant Recovery: Computing $prod_{j in S} D_j^{lambda_j(0)} = C_1^{sum x_j lambda_j(0)} = C_1^x = Y^r$ cancels the ElGamal ephemeral factor in constant time.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement