Context
A shielded vault holding a customer’s supplier funds must not be movable by one person, including anyone at Corridor. Ironwood randomizes the spend validating key per action, so any threshold scheme must sign under the randomized key.Decision
Each vault’sak is a FROST group key, 2-of-3 between customer approver, customer finance and Corridor. corridor-frost signs only actions whose rk == ak + [alpha]G, runs both rounds rerandomized by alpha, verifies the signature under rk, and applies it to the PCZT. Batches wait in the saga until the threshold approves.
Consequences
- The full spending key never exists.
- Threshold control costs no on-chain privacy: spends remain unlinkable.
- The demo uses a trusted dealer and runs both rounds in one process; production uses distributed key generation and per-device signers through
frostd, with the same PCZT interface.
Alternatives rejected
- Single-key vaults with operational controls: one compromised machine moves the funds.
- Multisig at the transparent layer: gives up shielding.