Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up

Threshold Decryption & Distributed Key Generation Studio

Architect dealer-less collective cryptographic authority with Pedersen DKG & Threshold ElGamal. Simulate polynomial secret sharing rounds, complaint verification, QUAL set consensus, and partial decryption share reconstruction with Lagrange basis coefficients.

Pedersen DKG Zero Trusted Dealer Threshold ElGamal GJKR99 Unbiased
Total committee size n and reconstruction quorum t
Fault injection for complaint & disqualification testing
Prime-order elliptic curve generator group G
Payload encrypted under collective public key Y
DKG Committee Consensus & Key State QUAL: 5/5 ACTIVE
Master Key Status
DEALER-LESS
Master secret x never materialized
Quorum Quota
3 of 5 Nodes
Threshold required for decryption
Decryption Time
1.45 ms
Parallel share evaluation
Disqualified Nodes
0 Nodes
Ejected via complaint consensus
Collective Public Key: Y = ∏i ∈ QUAL gzi mod p
Participant Share: xj = ∑i ∈ QUAL fi(j) mod q
Decryption Aggregation: Yr = ∏j ∈ S Djλj(0)
Committee Node Registry & Share Contributions
Active Set: QUAL Committee
Production Pedersen DKG & Threshold ElGamal Decryption Python 3.11+ / Petlib (secp256k1)

The Two Rounds of Pedersen DKG

Pedersen Distributed Key Generation orchestrates parallel Verifiable Secret Sharing (VSS):

  • Round 1 (Polynomial Commitments): Every node $P_i$ picks secret value $z_i$ and generates polynomial $f_i(x)$ with $f_i(0) = z_i$. $P_i$ publishes commitments $C_{i,k} = g^{a_{i,k}} h^{b_{i,k}}$ for all coefficients.
  • Round 2 (Pairwise Share Exchange): $P_i$ computes share $s_{i,j} = f_i(j)$ and transmits it to $P_j$ over an encrypted channel. $P_j$ validates $s_{i,j}$ against the public commitments $C_{i,k}$.
  • Complaint Resolution & QUAL: If $s_{i,j}$ fails validation, $P_j$ publishes a complaint. $P_i$ must reveal the share publicly; failure to do so results in $P_i$ being disqualified. The remaining nodes form the qualified set $QUAL$.

Threshold Decryption without Private Key Assembly

Once encrypted under joint key $Y$, decrypting data never requires reconstructing the master secret:

  • Partial Decryption Shares: Each node $P_j in S$ computes $D_j = C_1^{x_j}$ and attaches a zero-knowledge discrete logarithm equality proof.
  • Lagrange Recombination: The aggregator computes coefficients $lambda_j(0) = prod_{m in S, m eq j} rac{-m}{j - m} pmod q$.
  • Instant Recovery: Computing $prod_{j in S} D_j^{lambda_j(0)} = C_1^{sum x_j lambda_j(0)} = C_1^x = Y^r$ cancels the ElGamal ephemeral factor in constant time.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement