HIP-1398: TSS ceremony - #1398
Conversation
Signed-off-by: Rohit Sinha <rohit@hashgraph.com>
Signed-off-by: Rohit Sinha <rohit@hashgraph.com>
…des, not signing laptops (which do not have reliable networking and may not be powered on for more than a few minutes at a time). Signed-off-by: Joseph S. <121976561+jsync-swirlds@users.noreply.github.com>
Signed-off-by: Rohit Sinha <rohit@hashgraph.com>
Signed-off-by: Rohit Sinha <rohit@hashgraph.com>
Signed-off-by: Rohit Sinha <rohit@hashgraph.com>
Signed-off-by: Rohit Sinha <rohit@hashgraph.com>
jsync-swirlds
left a comment
There was a problem hiding this comment.
Thanks for putting this together.
Just a few minor comments.
Signed-off-by: Rohit Sinha <rohit@hashgraph.com>
Neurone
left a comment
There was a problem hiding this comment.
I suggest this change for the HIP to highlight we can potentially include selected community members in the TSS ceremony process.
Signed-off-by: Giuseppe Bertone <giuseppe.bertone@proton.me>
Signed-off-by: Joseph S. <121976561+jsync-swirlds@users.noreply.github.com>
Signed-off-by: Michael Garber <michael.garber@hashgraph.com>
|
The link to the Hedera Cryptography repository for the reference implementation is broken, is this not yet a public repo? @rsinha |
Signed-off-by: Michael Garber <michael.garber@hashgraph.com>
|
Request for further governance / participation clarification The HIP states that the ceremony will be executed by “the council members — specifically, those council members that also run consensus nodes.” However, the participation model is not fully specified. It would be helpful to clarify the intended governance and participation requirements for the ceremony. In particular:
Since the security model relies on the assumption that at least one participant contributes honest randomness and deletes their secret material, clearly specifying the eligibility and quorum expectations for contributors would strengthen the operational clarity of the proposal. Additionally, it would be helpful to clarify how this ceremony applies to third-party deployments of a Hiero-ledger–based network. For example:
Clarifying the intended model for downstream or private deployments would help ensure that the specification is usable by implementers beyond the initial network environment. |
It is not yet public. We are working towards making it public. |
The consensus node servers will run the software autonomously. Participation means letting their servers run as normal.
As long as at least 1 honest entity participates in the ceremony, the result is valid.
The software automatically times out if a prior node does not produce output and continues the ceremony without that node.
We are looking into options for a selected number of additional participants. @Neurone is working on that process.
Yes, all inputs and outputs will be public and independent observers are welcome and encouraged to verify the integrity and validity of the result.
This should be clear in the text (if not, we need to add this). All Hiero networks can use the output of this one ceremony without any reduction in cryptographic quality or security. There is no requirement nor expectation that any entity will repeat this ceremony. |
Description:
This HIP specifies the TSS ceremony operations, which is necessary to perform TSS operations (as specified in HIP-1200).