Under threshold keys no party can decrypt alone. A ciphertext is
sent to each site; each site applies its own secret share and
returns a partial decryption, and the partials are fused (see
decrypt()). The share never leaves the site, so no other
party ends up holding anything that would let it decrypt.
Arguments
- site
a LocalSite, or a user-defined subclass of RemoteSite.
- ...
method-specific arguments; the built-in method takes
ciphertextandlead, a flag marking the first site in the chain.
Value
a partial decryption, to be fused by decrypt().
Details
Whether a site plays the lead role is fixed by its position in the
key-generation chain, so it arrives with the request; the site does
not choose and does not need to know who is asking.
A site that cannot be reached must signal site_unavailable().
Because decryption is n-of-n, this loses the entire round rather
than one summand — see the availability note in RemoteSite.
