Works best when

  • Encrypted state must become permanently inaccessible after a defined window, without relying on storage deletion or operational hygiene.
  • Each computation should be isolated from others. Key material from one execution must not compromise another.
  • The data disposal guarantee must combine cryptographic and procedural mechanisms. Key destruction renders ciphertexts undecryptable. Honest disposal by node operators is still required, since no cryptographic protocol can force data deletion.

Avoid when

  • Persistent encrypted state is needed across multiple computations or time periods. Use long-lived key management instead.
  • The committee cannot be trusted to discard keys (the guarantee depends on honest disposal).
  • Recovery or rollback of encrypted state after the committee window closes is a hard requirement.

I2I vs I2U — context differences

Institution to institution

I2I

Between institutions, disposable state means no long-term key custody liability for either party. After the committee disbands, neither side can be compelled to decrypt historical data because the key material no longer exists anywhere.

Institution to end user

I2U

For end users, the guarantee that their encrypted inputs will become permanently inaccessible after the computation protects against future data breaches or compelled disclosure. The guarantee is no stronger than the honest-majority key disposal assumption.

Post-quantum exposure

Risk · medium
Vector
Encrypted state collected during the active window has HNDL exposure if the underlying encryption is not post-quantum. State after key disposal is information-theoretically lost regardless of quantum capability, assuming honest disposal.
Mitigation
Combine with post-quantum encryption schemes. The disposal guarantee itself is not quantum-dependent.

Components

  • Ephemeral committee: A group of nodes selected for a single computation (one E3, one auction, one ballot). The committee exists for the duration of that computation and no longer.
  • Single-use key material: The DKG produces a public key used exclusively for one computation. After decryption, the corresponding private key shares serve no further purpose.
  • Key disposal (toxic waste) protocol: After the output is decrypted and published, honest committee members securely delete their key shares. The act is off-chain and cannot be cryptographically proven, so it is reinforced by economic incentives (slashing for any provable future use of the key material).
  • Timeout-enforced lifecycle: The coordinating contract enforces strict deadlines (committee formation, DKG, input window, compute, decryption). If any phase times out, the E3 fails and keys should still be discarded. If compute never finishes, encrypted inputs become permanently inaccessible.
  • Slashing for intermediate decryption: Attempting to decrypt anything other than the agreed-upon output (inputs, intermediate state, or outputs from other computations) is slashable. Combined with key disposal, this creates both ex-ante (economic) and ex-post (key destruction) barriers to unauthorized decryption.

Protocol

  1. operator A committee is formed for a specific computation request (via sortition or explicit selection).
  2. operator The committee runs DKG to produce a shared public key. Each member holds a private key share scoped to this committee alone.
  3. user Data providers encrypt inputs to the committee public key during the input window. No other committee's key can decrypt these inputs.
  4. operator The compute provider executes the program over encrypted inputs and publishes the ciphertext output.
  5. operator The committee performs threshold decryption of the output and publishes the plaintext result.
  6. operator Honest committee members securely delete (overwrite, shred) their private key shares. These shares are now toxic waste. Retaining them is a liability, not an asset.
  7. contract The E3 lifecycle completes. Any encrypted state that was not decrypted during the active window (inputs from non-winning bidders, intermediate ciphertexts, abandoned computations) is now permanently inaccessible. The keys to decrypt it no longer exist.

Guarantees & threat model

Guarantees:

  • Time-bounded decryption window: encrypted state is accessible while a threshold of committee members possess their key shares, and at no other time. After the window closes and keys are discarded, decryption becomes impossible under the honest-majority assumption.
  • Cryptographic data disposal: undecrypted state becomes permanently inaccessible without requiring storage deletion. Even if ciphertexts are retained indefinitely, they cannot be decrypted once the keys are gone.
  • Isolation across computations: each committee uses fresh key material, so compromise of one committee's keys does not expose state from any other computation.
  • Economic backstop: slashing conditions for intermediate decryption and key retention create a cost for misbehavior that complements the cryptographic disposal guarantee.

Threat model:

  • Key retention: if a threshold of committee members retains their key shares instead of discarding them, undecrypted state remains accessible. This cannot be cryptographically prevented. It relies on honest behavior, economic incentives, and the fact that retained keys are a liability (provable use triggers slashing).
  • Key exfiltration before disposal: if an attacker compromises a threshold of nodes during the active window and exfiltrates their key shares before disposal, the state remains accessible to the attacker regardless of subsequent disposal.
  • Liveness during active window: if the committee fails before decryption (timeout, insufficient online members), encrypted state may become permanently inaccessible. That is the desired guarantee for privacy. It is a failure mode for the computation's utility.
  • Disposal verification gap: unlike DKG and decryption (which produce on-chain verifiable proofs), key disposal is an off-chain action with no cryptographic proof. The guarantee rests on incentives, not verification.

Trade-offs

  • No recovery: once the committee disbands and keys are discarded, undecrypted state is irrecoverable. This is the intended guarantee, but it means there is no "undo" for failed computations or accidental early disposal.
  • Honest-majority disposal assumption: the cryptographic disposal guarantee is no stronger than the honest-majority key destruction commitment. Retained key shares (maliciously or accidentally) undermine the guarantee.
  • Fresh DKG per computation: generating new key material for every computation adds latency and on-chain verification cost compared to long-lived keys.
  • Liveness risk: if the committee fails to reach threshold during decryption, the output is lost. Timeout mechanisms and refund logic in the coordinating contract mitigate economic harm but cannot recover the lost output.
  • Key destruction hygiene: secure deletion in practice (memory overwrite, hardware security module zeroization, filesystem shredding) is operationally non-trivial and varies across deployment environments.

Example

A sealed-bid auction uses an ephemeral committee of 5 nodes with threshold 3 for decryption. The committee generates a fresh public key scoped to this auction. Bidders encrypt their bids; the compute provider determines the winner over encrypted bids and publishes the ciphertext result; the committee decrypts the winning price and publishes it. After decryption, all 5 nodes securely delete their key shares. The losing bids, still encrypted on-chain, are now permanently inaccessible: no key material exists anywhere that can decrypt them. Even if the auction contract's storage is preserved for years, the losing bids can never be revealed.

See also

Open-source implementations

Last reviewed 2026-07-21