Skip to contents

A Master that drives the protocol over openfhe.R with threshold key generation, under whichever scheme the supplied crypto context was built for (CKKS for real-valued work, BFV or BGV for exact integer work). There is no single secret key: each site generates and keeps its own share sk_i, and the joint public key pk_{1..n} is built by chaining keygen_round() across the sites. Encryption goes under joint_pubkey. Decryption requires all n sites to return partial decryptions, which the master then fuses.

Usage

ThresholdMaster(
  name = character(0),
  state = new.env(parent = emptyenv()),
  crypto_context = openfhe.R::CryptoContext(),
  joint_pubkey = openfhe.R::PublicKey()
)

Arguments

name

short identifier.

state

an environment for mutable bookkeeping (the wired sites, in the order the key-generation chain visited them).

crypto_context

an openfhe.R CryptoContext with the MULTIPARTY feature enabled.

joint_pubkey

the joint public key produced by chaining keygen_round() across the sites.

Value

an S7 object of class ThresholdMaster, inheriting from Master, with properties name, crypto_context, joint_pubkey and state. It carries no secret key and no secret shares: decryption is driven by asking each site for a partial decryption and fusing the results, so no party — the master included — can decrypt alone. Construct with make_threshold_master().

Details

The master has no secret-key or secret-share property, and its methods use no secret material. Its properties are the crypto context and the joint public key, both public; the shares live at the sites that generated them and never travel. That is what makes the n-of-n claim true of the objects and not merely of the prose — see partial_decrypt() for the decryption seam.

Read that at the right scope. In a LocalSite demonstration every role still inhabits one R process, and the master holds the site objects in order to query them, so the shares are reachable from the master's object graph even though no property of the master contains one. A boundary between the parties requires separately controlled processes behind RemoteSite.

Exact-integer contexts

Under BFV or BGV a site cannot contribute a value the scheme cannot carry: contribute() refuses a non-integer, a non-finite value, or one outside the plaintext modulus rather than rounding it. What no party can check is the total: a sum that exceeds the modulus wraps, and the wrapped value decrypts as an ordinary integer with nothing to mark it. Choose plaintext_modulus for the largest total the protocol can produce, not the largest summand.

Constructed by make_threshold_master().