Threshold key management: the key that never exists
If state is encrypted, the obvious question is: who holds the key? Celar's answer: no single seat, and no party below the threshold. The TFHE decryption key exists only as shares spread across the committee, generated by a distributed ceremony. Threshold decryption never reconstructs it; a coalition larger than the threshold (13 or more seats) could, and that limit is stated below.
How it works
- Distributed key generation. A publicly verifiable ceremony produces key shares with published transcripts; misbehaving participants are excluded before genesis.
- Threshold decryption. Any decryption or re-encryption requires a threshold quorum of seats to cooperate. Partial decryptions are designed to be signed and attributable, so that unauthorized service can be proven and slashed once the fraud-evidence module is built. The committee configuration is 50 seats, threshold 12 — run and verified end-to-end in a test ceremony, and not yet securing value. Up to 12 seats learn nothing; 13 colluding seats could reconstruct the key, and we publish that rather than hide it. Larger committees are not reachable on this engine, and no work is scoped to reach them. Whitepaper §7.1 states the configuration and its limits.
- Proactive refresh. Proactive refresh is implemented and validated: the committee re-randomizes every share without changing the key. Once attested erasure of superseded shares is built, refresh will also limit how long an attacker has to assemble a quorum. Seat rotation on staggered terms is designed but deferred.
- Noise-flooded decryption. Authorized partial decryptions carry calibrated noise so repeated decryptions stay safe even against adversarially crafted ciphertexts.
A security number you can check
Most chains say "decentralized." Celar states a bound and publishes its inputs. How much stake it would take to capture a decryption quorum, and how likely that is over a rolling 10-year window, is set out as a curve on the health dashboard and in whitepaper §7.7 — it is a curve rather than a single number, and at this committee size a sufficiently large adversary captures every configuration. On top sits the live health rule ℋ ≥ 2: attacking must always cost at least twice what it could steal.