MPC Wallets: TSS, DKG & Secure Custody
Learning Goal: Implementing Multi-Party Computation (MPC) Wallets: Designing Threshold Signature Schemes (TSS) and Distributed Key Generation for Secure Cryptographic Custody.
This curriculum provides a mathematically sound, production-oriented path to understanding, designing, and engineering institutional-grade digital asset custody systems. By progressing from standard public-key cryptography to multi-party computation protocols, you will master how to eliminate the single point of failure (the private key) while maintaining compatibility with legacy blockchains.
- Prerequisites: Basic linear algebra (finite fields, polynomial interpolation), familiarity with public-key cryptography (RSA, ECC), and basic reading competence in system programming languages (Rust or Go).
- Estimated Total Study Time: 24 Hours
Module 1: Foundations of Cryptography & Digital Signatures
Before diving into distributed systems and multi-party cryptographic protocols, you must master the fundamental building blocks of digital signature architectures. This module establishes the mathematical foundation of Elliptic Curve Cryptography (ECC) and the Elliptic Curve Digital Signature Algorithm (ECDSA)—the standard signing scheme behind Bitcoin, Ethereum, and many other layer-1 protocols.
Recommended Videos
- Why this video: This video provides a high-level conceptual base of Elliptic Curve Cryptography. It contrasts ECC with traditional asymmetric algorithms like RSA, helping you understand how ECC achieves comparable security margins with significantly smaller key sizes—a key reason for its ubiquitous adoption in distributed ledger technologies.
- Why this video: This deep-dive lecture unpacks the exact mechanics of the ECDSA signature process. It walks through how ephemeral keys () are combined with private keys to generate signature parameters , and how these values are verified using only the public key. Understanding this dynamic is crucial, as splitting this specific signature generation step is the core goal of Threshold ECDSA.
- Why this video: This lecture segment from MIT OpenCourseWare formalizes standard digital signatures mathematically. It introduces the precise relation between the generator point , the scalar private key , and the public key point , establishing standard notations and correctness criteria.
Knowledge Checkpoint
- Understand why ECC provides a stronger cryptographic density than RSA and how -bit keys are utilized in systems like secp256k1.
- Define the roles of the base point , scalar multiplication, and the discrete logarithm problem (DLP) in public key derivation.
- Write down the mathematical steps for ECDSA signature generation and verify how an ephemeral key is used.
- Explain why reusing an ephemeral key in ECDSA allows an attacker to easily reconstruct the private key.
Module 2: Secret Sharing & Introduction to MPC
With standard digital signature fundamentals in place, we move into the mechanics of splitting secrets. In this module, you will learn the mathematical foundation of Shamir’s Secret Sharing (SSS) and how it generalizes into Secure Multi-Party Computation (MPC), enabling collaborative computations without any participant revealing their secret inputs.
Recommended Videos
- Why this video: This lecture visually explains polynomial interpolation over finite fields, which forms the mathematical backbone of Shamir's Secret Sharing. It details how a secret is embedded as the constant term in a polynomial of degree , and how points are both necessary and sufficient to reconstruct the polynomial using Lagrange interpolation.
- Why this video: A comprehensive academic introduction to MPC from the Simons Institute. This lecture goes beyond simple sharing schemes to detail how multiple parties can jointly evaluate functions (represented as arithmetic or boolean circuits) over their private shares without revealing the underlying data.
- Why this video: Led by Yehuda Lindell, a preeminent researcher in MPC and industrial custody, this talk bridges the gap between historical MPC theory and practical, real-world blockchain utility. It explains how modern MPC evolved from theoretical construct to the bedrock of digital asset security.
Knowledge Checkpoint
- Formulate a random polynomial of degree to share a secret scalar among participants.
- Reconstruct a secret from a set of threshold shares using Lagrange basis polynomials.
- Explain why a standard Shamir's Secret Sharing scheme requires a centralized "dealer" to initially split the secret, and point out why this dealer represents a single point of failure.
- Differentiate between passive (honest-but-curious) and active (malicious) adversary security models in MPC.
Module 3: Distributed Key Generation (DKG)
To eliminate the centralized "dealer" vulnerability inherent in Shamir's Secret Sharing, we must utilize Distributed Key Generation (DKG). In DKG, multiple decentralized parties collaboratively generate a public-private key pair. At no point in time does any single party ever hold, know, or generate the complete private key.
Recommended Videos
- Why this video: Verifiable Secret Sharing (VSS) is a critical stepping stone to DKG. This video covers how VSS allows participants to verify that their shares are mathematically consistent with the overall shared secret, defending against a malicious dealer who distributes garbage shares.
- Why this video: This BlackHat security briefing analyzes real-world implementation vulnerabilities in DKG and MPC setups. It illustrates why simple, naive DKG implementations (such as skipping validation steps or ignoring malicious side-channels) lead to complete key compromise in production systems.
- Why this video: This short presentation highlights Non-Interactive Distributed Key Generation (NI-DKG) in high-throughput environments. It describes how advanced, non-interactive variants minimize round trips, which is critical for scaling DKG protocols inside decentralized networks.
Algorithmic Depth & Coverage Gaps
While standard video resources cover high-level DKG, you must understand the mathematical protocols underpinning Feldman's Verifiable Secret Sharing (VSS) and Pedersen’s Distributed Key Generation algorithm to construct these systems.
1. Feldman's VSS Protocol
In Feldman's scheme, the dealer distributes shares of a polynomial . To make this verifiable, the dealer publishes commitments to the polynomial coefficients using elliptic curve points: Each participant can independently verify that their private share is correct by checking:
2. Pedersen's DKG Protocol
Pedersen's DKG addresses the centralized dealer issue by running parallel instances of Feldman's VSS. Each participant acts as a dealer, generating their own secret polynomial with constant term .
- Each participant distributes sub-shares to every participant , and publishes commitments .
- Every participant verifies their incoming sub-shares against the corresponding commitments.
- If no complaints are raised, the joint private key share of participant is the sum of the validated sub-shares: .
- The collaborative public key is derived as: .
Independent Study Search Terms:
- "Feldman Verifiable Secret Sharing mathematical proof"
- "Pedersen Distributed Key Generation adversary bias prevention"
- "GJKR Distributed Key Generation protocol" (which repairs the security flaws in Pedersen's original scheme under malicious conditions)
Knowledge Checkpoint
- Explain how Feldman's VSS uses homomorphic encryption properties to verify that a private scalar share matches a public commitment.
- Diagram the step-by-step messaging sequence of Pedersen's DKG.
- Explain why a standard Pedersen DKG is vulnerable to a malicious party biasing the final public key, and how the GJKR99 protocol resolves this by running a preliminary protocol to lock commitments.
- Draft a recovery strategy for when a participant fails to provide their VSS commitments during the key generation round.
Module 4: Threshold Signature Schemes (TSS)
Threshold Signature Schemes (TSS) represent the operational phase of an MPC wallet. They allow a defined threshold of key share holders to interactively generate a single, standard digital signature (such as ECDSA or Schnorr) without ever reconstructing the private key on any machine.
Recommended Videos
- Why this video: This video introduces the FROST (Flexible Round-Optimized Schnorr Threshold) signature scheme. It explains how FROST leverages Schnorr signatures to produce single-round threshold signatures, avoiding the high communication overhead associated with Threshold ECDSA.
- Why this video: This video emphasizes the performance and transparency benefits of Threshold ECDSA. It explains how threshold signatures produce a standard, single-signature output identical to a non-MPC signature, thereby saving transaction fees and preserving privacy on-chain compared to native multisig.
- Why this video: This snippet contrasts Threshold Signature Schemes (TSS) with traditional on-chain multi-signature (MultiSig) smart contracts. Understanding this distinction is vital for wallet architecture design: MultiSig requires the blockchain to process multiple signatures (high fees, visible participants), whereas TSS handles the complexity off-chain, yielding a single signature.
Protocol Gaps: GG18 & GG20 deep dives
The video pool lacks granular, step-by-step explanations of GG18 and GG20 protocols. These are the dominant multi-party threshold ECDSA protocols in production today.
GG18 / GG20 Threshold ECDSA Core Phases:
+-------------------------------------------+
| Phase 1: Phase Key Derivation & Commit |
| Parties generate ephemeral key shares |
+----------------------++-------------------+
||
\/
+-------------------------------------------+
| Phase 2: Multiplicative-to-Additive |
| (MtA) conversion using Paillier/OT |
+----------------------++-------------------+
||
\/
+-------------------------------------------+
| Phase 3: Range Proofs & Verification |
| Verify secret scalars lie in range |
+----------------------++-------------------+
||
\/
+-------------------------------------------+
| Phase 4: Signature Reconstruction |
| Combine components to output (r, s) |
+-------------------------------------------+
To sign an ECDSA message threshold-wise without reconstructing or , parties must evaluate the multiplication of secret shares: Because and are additively shared, calculating requires a Multiplicative-to-Additive (MtA) conversion protocol. This is accomplished in GG18/GG20 via Paillier Homomorphic Encryption or Oblivious Transfer (OT).
- GG18 utilizes a zero-knowledge range proof to ensure no participant uses out-of-range scalars that could leak the private key shares during the MtA step.
- GG20 reduces the round complexity and communication overhead of GG18 by optimizing these zero-knowledge proofs and committing to the ephemeral parameters earlier in the protocol.
Independent Study Search Terms:
- "GG18 threshold ECDSA protocol specification"
- "GG20 threshold signature scheme paper Gennaro Goldfeder"
- "Multiplicative to Additive (MtA) protocol Paillier homomorphic"
Knowledge Checkpoint
- Differentiate between on-chain Multi-Signature (MultiSig) and cryptographic Threshold Signatures (TSS) in terms of fee efficiency and privacy.
- Explain how FROST reduces signature generation to a single, non-interactive round in the optimistic path.
- Describe the purpose of the Multiplicative-to-Additive (MtA) conversion step in Threshold ECDSA protocols.
- Identify where Paillier encryption and zero-knowledge range proofs are used in the GG18 signing flow.
Module 5: Engineering Secure MPC Custody Systems
Designing an institutional custody system requires wrapping raw cryptographic primitives into a resilient, production-ready, secure enclave infrastructure. In this final module, we shift focus to backend software engineering, key rotation schemes, proactive secret sharing, and secure backup mechanics.
Recommended Videos
- Why this video: This video provides an architecture breakdown of an enterprise custody platform. It details how private key shares are distributed across clients, servers, and cold recovery environments, demonstrating how to eliminate single points of failure in live operating environments.
- Why this video: Led by Professor Dan Boneh, this video covers key rotation and Proactive Secret Sharing (PSS). You will learn how to proactively refresh secret key shares over time without altering the overall public key, rendering stolen key shares obsolete to a persistent attacker.
- Why this video: This talk discusses building production-grade cryptographic pipelines. It highlights the safety advantages of using systems languages like Rust, where type systems and memory safety guarantees prevent common runtime exploits that plague cryptographic implementations.
Production Engineering Gaps & Implementation Guidelines
To transition this theory into production code (Rust or Go), you must address several design patterns not covered in promotional wallet materials.
1. Proactive Secret Sharing (PSS) & Key Refresh
To prevent an adversary from slowly compromising nodes over a long period (perpetual leakage), you must implement PSS.
- The Math: During a refresh cycle, each node generates a random polynomial of degree such that the constant term is zero: .
- Node distributes sub-shares to node .
- Each node updates their existing secret share :
- Because the sum of all constants added is zero, the master secret key (and thus the public key) remains unchanged, but all historical key shares are completely invalidated.
2. Production Codebases to Study
Do not write custom cryptography from scratch for production systems. Instead, audit and integrate established open-source libraries:
- Rust:
multi-party-sig(maintained by ZenGo): Comprehensive implementation of GG18, GG20, and modern two-party ECDSA.frost-dalek: A modular Rust implementation of the FROST threshold signature scheme over Ed25519 and Ristretto.
- Go:
multi-party-sig(Go ports): Highly audited and used in decentralized node network integrations.
Independent Study Search Terms:
- "Proactive Secret Sharing update protocol mathematics"
- "ZenGo multi-party-sig Rust repository"
- "Implementing Threshold ECDSA in Secure Enclaves AWS Nitro Enclaves"
Knowledge Checkpoint
- Explain how Proactive Secret Sharing (PSS) updates private shares without altering the master public address.
- Design a disaster recovery model for a 2-of-3 MPC wallet where one client device is permanently lost or compromised.
- Explain why standard memory management bugs (e.g., buffer overflows) are critical in cryptography, and how Rust's borrow checker mitigates these risks.
- Outline how to implement a network protocol that manages asynchronous messaging rounds required for a GG18 signing transaction.
Course Map
This flowchart maps the logical dependencies of the modules and shows how theoretical fundamentals lead to advanced system engineering.
Key People Index
Understanding the primary researchers in threshold cryptography helps you track academic publications and state-of-the-art standards.
- Adi Shamir: Co-inventor of RSA and creator of Shamir's Secret Sharing (1979), establishing the foundation of secret partitioning.
- Yehuda Lindell: Co-founder of Unbound Security, pioneer in fast threshold ECDSA protocols, and leading academic in the commercialization of MPC wallets.
- Torben Pryds Pedersen: Inventor of the Pedersen Commitment scheme and Pedersen Distributed Key Generation protocol, essential for decentralized coordinate setups.
- Rosario Gennaro & Steven Goldfeder: Authors of the GG18 and GG20 protocols, which established standard frameworks for highly efficient Threshold ECDSA signatures.
- Dan Boneh: Head of the Stanford Applied Cryptography Group, leading researcher in pairings-based cryptography, and vocal authority on practical security practices in decentralized networks.
- Tal Rabin: Prominent cryptographer, co-inventor of Proactive Security and numerous Verifiable Secret Sharing protocols, driving secure-distributed database research.
Final Self-Assessment
To verify your mastery of this curriculum, complete the following comprehensive engineering and theoretical challenge items:
- 1. Can you write out the mathematical definition of a Shamir Secret Sharing polynomial and explain how a threshold is enforced?
- 2. Can you explain the distinct security flaw of Pedersen's DKG protocol compared to modern GJKR DKG protocols?
- 3. Do you understand the homomorphic equation used in Feldman's Verifiable Secret Sharing to confirm share correctness without exposing the share value?
- 4. Can you sketch the operational workflow of a 2-of-2 Threshold ECDSA signing run, pointing out when the MtA (Multiplicative-to-Additive) step is triggered?
- 5. Do you know why a zero-knowledge range proof is mandatory during the GG18 signature generation phase?
- 6. Can you explain the difference in message round efficiency between FROST (Schnorr-based) and GG20 (ECDSA-based) threshold schemes?
- 7. Can you mathematically formulate how Proactive Secret Sharing (PSS) updates participant key shares while leaving the public master key unchanged?
- 8. Are you able to design a production infrastructure architecture that handles backup recovery keys using cold hardware, cloud secure enclaves, and client-side devices?
- 9. Can you identify three critical vulnerabilities in multi-party computation libraries highlighted in modern security audits (e.g., side-channel leakage, missing commitment validations)?
- 10. Do you understand the advantages of using Rust's memory safety primitives to build cryptographic packages compared to traditional C/C++ libraries?














