Context Binding and Reusable Leakage in Threshold Decryption
Abstract
Threshold decryption is increasingly used to hide economically sensitive data until a public release time. The main strategic risk is not merely premature decryption of one ciphertext, but leakage of a coalition-generated decoder that may remain useful across many future contexts. We formalize a repeated leakage game for arbitrary monotone access structures with transferable utility, one-time public accountability exposure, and an abstract reachability correspondence that records which future contexts become compromised after a first leak. Our main theorem gives an exact characterization: honest non-leakage is coalition safe if and only if, for every authorized coalition S, its exposure κ(S) dominates the maximum discounted leakage value over the contexts reachable from a single first leak by S. Two important consequences follow. In fully reusable schemes, the exact deterrence threshold equals the coalition’s continuation leakage value, yielding horizon amplification. In context-isolating schemes, including context dependent threshold decryption, the reachable set collapses to the current context, so the threshold drops to the one-shot value. We also prove a sharp separation: for a T-round family with unit per-round leakage value, reusable leakage requires Θ(T) total exposure, whereas context isolation requires only Θ(1). Additional corollaries give a geometric threshold under bounded reuse multiplicity, exact equal-stake formulas for t-out-of-n committees, a direct encrypted-mempool instantiation, and a converse lower bound showing that without a bound on reuse multiplicity no uniform O(1) exposure can suffice. The contribution is theorem-driven and deliberately orthogonal to post- decryption ordering or proposer-builder-separation equilibrium analyses