Threshold Encryption with Silent Setup
Sanjam Garg, Dimitris Kolonelos, Guru-Vamsi Policharla, Mingyuan Wang
Abstract
We build a concretely efficient threshold encryption scheme where the joint public key of a set of parties is computed as a deterministic function of their locally computed public keys, enabling a silent setup phase. By eliminating interaction from the setup phase, our scheme immediately enjoys several highly desirable features such as asynchronous setup, multiverse support, and dynamic threshold. Prior to our work, the only known constructions of threshold encryption with silent setup relied on heavy cryptographic machinery such as indistinguishability Obfuscation or witness encryption for all of . Our core technical innovation lies in building a special purpose witness encryption scheme for the statement ``at least parties have signed a given message''. Our construction relies on pairings and is proved secure in the Generic Group Model. Notably, our construction, restricted to the special case of threshold , gives an alternative construction of the (flexible) distributed broadcast encryption from pairings, which has been the central focus of several recent works. We implement and evaluate our scheme to demonstrate its concrete efficiency. Both encryption and partial decryption are constant time, taking ms and ms, respectively. For a committee of parties, the aggregation of partial decryptions takes ms, when all parties provide partial decryptions. The size of each ciphertext is larger than an ElGamal ciphertext.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers12
- Multi-authority Registered Attribute-Based EncryptionGeorge Lu, Brent Waters, David J. WuEUROCRYPT 2025 · 14 citations
- Unbounded Distributed Broadcast Encryption and Registered ABE from Succinct LWEHoeteck Wee, David J. WuCRYPTO 2025 · 12 citations
- Threshold Batched Identity-Based Encryption from Pairings in the Plain ModelJunqing Gong, Brent Waters, Hoeteck Wee, David J. WuEUROCRYPT 2026 · 9 citations
- TACITA: Threshold Aggregation without Client InteractionVarun Madathil, Arthur Lazzaretti, Zeyu Liu, Charalampos PapamanthouCCS 2026 · 2 citations
- Silent Threshold Cryptography from Pairings: Expressive Policies in the Plain ModelBrent Waters, David J. WuEUROCRYPT 2026 · 2 citations
Related papers
- Practical Silent Threshold Signatures and Silent Threshold Encryption for Dynamic CommitteesYifei He, Zheng Zhou, Yu Chen, Zhi Guan et al.CCS 2026
- BEAST-MEV: Batched Threshold Encryption with Silent Setup for MEV preventionJan Bormet, Arka Rai Choudhuri, Sebastian Faust, Sanjam Garg et al.CCS 2026 · 12 citations
- hinTS: Threshold Signatures with Silent SetupSanjam Garg, Abhishek Jain, Pratyay Mukherjee, Rohit Sinha et al.S&P 2024 · 48 citations
- How to Use (Plain) Witness Encryption: Registered ABE, Flexible Broadcast, and MoreCody Freitag, Brent Waters, David J. WuCRYPTO 2023 · 49 citations
- A Generic Approach to Adaptively-Secure Broadcast Encryption in the Plain ModelYao-Ching Hsieh, Brent Waters, David J. WuEUROCRYPT 2025 · 5 citations
