Demo 15's threshold vault had a catch: a trusted dealer drew the whole group secret, split it, and handed out shares. For a moment, one party knew everything. Distributed key generation deletes that party. Each participant brings a secret only they choose and Shamir-shares it with the others; the group key is the sum of everyone's contribution, so the group secret Σ ai0 is never assembled anywhere, yet the shares everyone ends up with are ordinary FROST shares that demo 15's signer accepts unchanged. This is PedPoP, Pedersen DKG with proofs of possession.
Everyone samples their own random polynomial and publishes commitments to every coefficient, φi0 = ai0·G, φi1 = ai1·G, … (the first is their contribution to the group key, the full vector is what Feldman checks against), plus a proof of possession that they actually know ai0. New ceremony redraws every secret.
Participant i sends fi(j) privately to each j, who verifies it against i's public commitment (Feldman). Row = sender, column = recipient:
Each participant sums the shares they received into their long-term share si = Σj fj(i), and sums every published φj0 into the group key. No dealer, no moment where Σ ai0 exists in one place.
The DKG shares drop straight into the demo-15 signer. Tick any two, and out comes one Schnorr signature that verifies under the group key. That is proof the dealer-free setup produced real, working threshold key material.
The si are Shamir shares of a polynomial whose constant term is the group secret. Any 2 interpolate to it, but that's the one step the ceremony is designed so nobody ever performs.
Without it, a participant could wait to see the others' φj0 and choose their own contribution to cancel them, steering the group key to one they secretly control (a rogue-key attack). Forcing each participant to prove they know their ai0 makes that impossible: you can't prove knowledge of a key built to subtract someone else's.
Trusted-dealer keygen is fine until you ask "who watched the dealer?" DKG answers by never creating a party with anything worth stealing. The secret is born distributed.
Corrupt a sub-share and its recipient's Feldman check fails against the sender's public commitment, pinning the fault on its author, so the ceremony aborts and restarts without the cheat, not with a broken key.
DKG changes only setup. The resulting shares sign with the exact demo-15 / RFC 9591 ceremony, and the verifier sees one ordinary Schnorr signature, with no trace of how the key was born.