A Master that drives the protocol over openfhe.R with
threshold key generation, under whichever scheme the supplied
crypto context was built for (CKKS for real-valued work, BFV or
BGV for exact integer work). There is no single secret key: each
site generates and keeps its own share sk_i, and the joint public
key pk_{1..n} is built by chaining keygen_round() across the
sites. Encryption goes under joint_pubkey. Decryption requires
all n sites to return partial decryptions, which the master then
fuses.
Usage
ThresholdMaster(
name = character(0),
state = new.env(parent = emptyenv()),
crypto_context = openfhe.R::CryptoContext(),
joint_pubkey = openfhe.R::PublicKey()
)Arguments
- name
short identifier.
- state
an environment for mutable bookkeeping (the wired sites, in the order the key-generation chain visited them).
- crypto_context
an
openfhe.RCryptoContextwith theMULTIPARTYfeature enabled.- joint_pubkey
the joint public key produced by chaining
keygen_round()across the sites.
Value
an S7 object of class ThresholdMaster, inheriting from Master,
with properties name, crypto_context, joint_pubkey and
state. It carries no secret key and no secret shares: decryption
is driven by asking each site for a partial decryption and fusing
the results, so no party — the master included — can decrypt
alone. Construct with make_threshold_master().
Details
The master has no secret-key or secret-share property, and its
methods use no secret material. Its properties are the crypto
context and the joint public key, both public; the shares live at
the sites that generated them and never travel. That is what makes
the n-of-n claim true of the objects and not merely of the prose —
see partial_decrypt() for the decryption seam.
Read that at the right scope. In a LocalSite demonstration every role still inhabits one R process, and the master holds the site objects in order to query them, so the shares are reachable from the master's object graph even though no property of the master contains one. A boundary between the parties requires separately controlled processes behind RemoteSite.
Exact-integer contexts
Under BFV or BGV a site cannot contribute a value the scheme
cannot carry: contribute() refuses a non-integer, a non-finite
value, or one outside the plaintext modulus rather than rounding
it. What no party can check is the total: a sum that exceeds the
modulus wraps, and the wrapped value decrypts as an ordinary
integer with nothing to mark it. Choose plaintext_modulus for
the largest total the protocol can produce, not the largest
summand.
Constructed by make_threshold_master().
