CELARDOCS CELAR.NETWORK →
Protocol · CELAR DOCS

Threshold key management: the key that never exists

If state is encrypted, the obvious question is: who holds the key? Celar's answer: no single seat, and no party below the threshold. The TFHE decryption key exists only as shares spread across the committee, generated by a distributed ceremony. Threshold decryption never reconstructs it; a coalition larger than the threshold (13 or more seats) could, and that limit is stated below.

How it works

A security number you can check

Most chains say "decentralized." Celar states a bound and publishes its inputs. How much stake it would take to capture a decryption quorum, and how likely that is over a rolling 10-year window, is set out as a curve on the health dashboard and in whitepaper §7.7 — it is a curve rather than a single number, and at this committee size a sufficiently large adversary captures every configuration. On top sits the live health rule ℋ ≥ 2: attacking must always cost at least twice what it could steal.

Honest limitation: the FHE tier's privacy is conditional on this committee (a coalition at or above the decryption quorum could decrypt); the ZK pool is deliberately independent of it. Even disaster recovery is public-by-construction — timelocked, transcript-published, resharing-only. No covert decryption path exists.