Hermes / FROST DKG

FROST DKG: a shared key with no dealer

Demo 15's threshold vault had a catch: a trusted dealer drew the whole group secret, split it, and handed out shares. For a moment, one party knew everything. Distributed key generation deletes that party. Each participant brings a secret only they choose and Shamir-shares it with the others; the group key is the sum of everyone's contribution, so the group secret Σ ai0 is never assembled anywhere, yet the shares everyone ends up with are ordinary FROST shares that demo 15's signer accepts unchanged. This is PedPoP, Pedersen DKG with proofs of possession.

1 · Each participant brings a secret

Everyone samples their own random polynomial and publishes commitments to every coefficient, φi0 = ai0·G, φi1 = ai1·G, … (the first is their contribution to the group key, the full vector is what Feldman checks against), plus a proof of possession that they actually know ai0. New ceremony redraws every secret.

2 · Everyone shares with everyone, and checks it

Participant i sends fi(j) privately to each j, who verifies it against i's public commitment (Feldman). Row = sender, column = recipient:

3 · The shares fold into one key

group public key  = Σ φi0, private counterpart never assembled
–

Each participant sums the shares they received into their long-term share si = Σj fj(i), and sums every published φj0 into the group key. No dealer, no moment where Σ ai0 exists in one place.

4 · And it just signs

tick two participants, then sign

The DKG shares drop straight into the demo-15 signer. Tick any two, and out comes one Schnorr signature that verifies under the group key. That is proof the dealer-free setup produced real, working threshold key material.

The math

each i: fi(x) = ai0 + ai1x  ·  publishes φi0 = ai0·G

share  si = Σj fj(i)
group key  Y = Σj φj0 = (Σj aj0)·G
group secret  Σ aj0  never computed

The si are Shamir shares of a polynomial whose constant term is the group secret. Any 2 interpolate to it, but that's the one step the ceremony is designed so nobody ever performs.

vs the trusted dealer (demo 15)

Trusted dealer

one knows all
the dealer draws and splits the whole secret, a single point of failure who must be trusted to forget it.

DKG

no one knows all
the secret only ever exists as the sum of independent contributions, distributed from the very first moment.

Why the proof of possession?

Without it, a participant could wait to see the others' φj0 and choose their own contribution to cancel them, steering the group key to one they secretly control (a rogue-key attack). Forcing each participant to prove they know their ai0 makes that impossible: you can't prove knowledge of a key built to subtract someone else's.

Things to notice

The dealer is the weak link

Trusted-dealer keygen is fine until you ask "who watched the dealer?" DKG answers by never creating a party with anything worth stealing. The secret is born distributed.

Bad shares are named

Corrupt a sub-share and its recipient's Feldman check fails against the sender's public commitment, pinning the fault on its author, so the ceremony aborts and restarts without the cheat, not with a broken key.

Same signer, either way

DKG changes only setup. The resulting shares sign with the exact demo-15 / RFC 9591 ceremony, and the verifier sees one ordinary Schnorr signature, with no trace of how the key was born.