New paper alert! 🚨
Weighted Batched Threshold Encryption with Efficient DKG
w/ Alexander Frolov,
@AditiPartap97, and
@ErtemNusretTas
In multi proposer consensus, transactions should be hidden until “valency”, the point of no return at which the consensus outcome has been decided. The cleanest way to achieve this property is with threshold encryption. But existing schemes forced difficult tradeoffs between batched, weighted, and efficient schemes. I asked the
@a16zcrypto research summer interns if they could come up with a new scheme that was weighted, batched, performant, and didn’t require a trusted setup. Turns out they did!!!
With some optimizations, I was able to get decryption for up to 16 simultaneous proposals to run in ~40ms on 12 cores with thousands of virtual shares and decryption shares that are small enough to fit in a single UDP packet along with the rest of the vote data. This leaves enough performance headroom room on my dev box to run a full Solana validator at the tip with the remaining cores!!!
These results, along with other recent work in threshold encryption are finally pushing threshold encryption into the realm of practicality for use in the Solana protocol. We still have some more optimizations to try so we might be able to push it even lower!