Paper 2025/279
Context-Dependent Threshold Decryption and its Applications
Abstract
In a threshold decryption system a secret key is split across a number of parties so that any threshold of them can decrypt a given ciphertext. We introduce a new concept in threshold decryption called a decryption context, which is an additional argument that is used during decryption. The context ensures that decryption shares that are generated for a ciphertext using different contexts are isolated from each other and cannot be jointly used to decrypt the ciphertext. For example, suppose the decryption threshold is $t$. Further, suppose that less than $t$ decryption shares are generated for a ciphertext $c$ under one context, and less than $t$ decryption shares are generated for $c$ under a different context. Then this set of shares is insufficient to decrypt $c$ even if the total number of shares exceeds $t$. This new concept has several important applications, most notably for implementing an encrypted mempool in a consensus protocol. We give two CCA-secure threshold decryption constructions that support context. One is based on ElGamal encryption, and the other is generic showing how to add context to any CCA-secure threshold decryption system without changing the encryption algorithm.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- A major revision of an IACR publication in ASIACRYPT 2025
- Keywords
- Threshold DecryptionAtomic Broadcast
- Contact author(s)
-
dabo @ cs stanford edu
bb @ nyu edu
kartik @ cs duke edu
lior rotem @ cs huji ac il
victor @ shoup net - History
- 2025-09-09: last of 2 revisions
- 2025-02-18: received
- See all versions
- Short URL
- https://ia.cr/2025/279
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/279,
author = {Dan Boneh and Benedikt Bünz and Kartik Nayak and Lior Rotem and Victor Shoup},
title = {Context-Dependent Threshold Decryption and its Applications},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/279},
year = {2025},
url = {https://eprint.iacr.org/2025/279}
}