Papers
Topics
Authors
Recent
Search
2000 character limit reached

Threshold Seal: A Multidomain Perspective

Updated 12 July 2026
  • Threshold seal is a polysemous concept defined by global invariant conditions rather than local criteria, as seen in diverse domains like biomechanics, hydrodynamics, and computing.
  • It is modeled using precise metrics such as the normalized systolic index in breastfeeding and the critical Weber number in water-entry experiments to delineate seal transitions.
  • In computing and quantum secret sharing, threshold seal governs irreversible policy states and quorum-based authorizations, ensuring robust security with high detection probabilities.

Threshold seal is a polysemous technical term whose meaning depends on domain. In recent arXiv usage, it denotes several distinct but structurally related threshold-conditioned phenomena: a topological criterion for the existence of an oral seal during infant breastfeeding, a hydrodynamic transition separating surface-seal from no-seal regimes in water entry, a one-way sealing policy for protection-key domains in RISC-V isolation, and cryptographic or quantum mechanisms in which authorization, disclosure, or revocation occurs only after quorum or reconstruction conditions are satisfied (Tozzi, 19 Feb 2026, Eshraghi et al., 2019, Delshadtehrani et al., 2020, Porechna, 9 Jul 2026). This suggests a family of constructions in which a “seal” is not merely local contact or binary closure, but a global state whose existence, persistence, or breakage is governed by an explicit threshold.

1. Semantic range and shared structure

The term appears in at least six technically distinct settings. In biomechanics, the seal is a continuous circumferential contact band around the nipple. In fluid dynamics, it is closure of a splash curtain over an air cavity. In computer architecture, it is an irreversible policy state for domains, pages, or permissions. In cryptography, it is a quorum-generated authorization artifact or a threshold-conditioned disclosure mechanism. In quantum secret sharing, it is a revocable sharing state whose premature opening is detectable (Tozzi, 19 Feb 2026, Eshraghi et al., 2019, Delshadtehrani et al., 2020, Porechna, 9 Jul 2026, Breuer, 2024, Cheng et al., 2024).

Setting Sealed object Threshold condition
Breastfeeding biomechanics Encircling oral contact band Existence of an admissible non-contractible loop
Water entry Splash-curtain closure at the surface Critical Uair/U0U_{\text{air}}/U_0 and associated WecWe_c
RISC-V isolation Domain, page, or permission mutability Transition to sealed state until key and pages are freed
MPC custody Authorization artifact At least tt verified envelopes and one unused slot
Secret petitions Encrypted signatures and testimonies At least nn signatures gathered
Quantum secret sharing Reconstructable secret state Access-structure or (t,n)(t,n) reconstruction and seal checks

A recurrent misconception, rejected in several of these literatures, is that local or componentwise indicators suffice. The breastfeeding work argues that local tongue–palate distances or local pressure measurements cannot establish global seal continuity. The splash-curtain study argues that impact velocity alone does not determine surface seal. The custody paper argues that member signatures alone do not provide threshold authorization. The common implication is that threshold seal is typically defined by a global invariant, policy state, or collective computation rather than by isolated local measurements.

2. Geometric and topological threshold seal in infant breastfeeding

In "Geometric and topological constraints on oral seal formation during infant breastfeeding" (Tozzi, 19 Feb 2026), the oral seal is modeled as a global geometric-topological object. Each sagittal ultrasound frame at time tt is represented by a bounded planar domain

ItR2,I_t \subset \mathbb{R}^2,

with nipple cross-section

Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},

and an effective contact band

AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).

Seal-preserving configurations are constructed so that AtA_t has the homotopy type of an annulus,

WecWe_c0

whereas seal-breaking configurations are simply connected or disconnected.

The seal criterion is the existence of a closed curve in WecWe_c1 that encircles the nipple exactly once. For piecewise WecWe_c2 closed curves WecWe_c3 in WecWe_c4, admissibility is defined by winding number

WecWe_c5

These admissible curves are the non-contractible loops of the annular contact band. The shortest such loop defines the systolic invariant

WecWe_c6

and if no admissible curve exists, WecWe_c7 is declared undefined.

The paper further defines a normalized systolic index

WecWe_c8

which is dimensionless and separates a binary topological component from a continuous geometric component. If WecWe_c9 is undefined, no encircling curve exists and the seal is broken. If tt0, the admissible loop is tight relative to the nipple circumference. This formulation explicitly rejects the idea that a set of normal local distances or pressures guarantees global seal integrity; a small gap anywhere in the band can destroy circumferential continuity.

Threshold behavior is encoded by a feasibility function

tt1

where tt2 is normalized band thickness and tt3 is angular discontinuity size. The paper numerically estimates a critical thickness

tt4

below which admissibility is lost irrespective of angular perturbation magnitude. In static regime mapping, 80.63% of sampled configurations were seal-preserving and 19.37% were topologically infeasible. Sensitivity to angular discontinuity increases sharply when tt5, producing a narrow admissible corridor.

The comparative perturbation analysis shows that localized gaps are more destructive than symmetric thinning. For matched normalized perturbation magnitude tt6, symmetric thinning collapses at tt7, whereas localized discontinuity collapses earlier at tt8. In the overlapping admissible range tt9, mean systolic lengths were nn0 for symmetric thinning and nn1 for localized gaps, with paired t-test nn2, nn3. Dynamic simulations with

nn4

noise nn5 with nn6, and robustness

nn7

yielded a seal dropout fraction of 0.393 over 10 s. Thus nn8 can alternate between finite and undefined values even when overall geometric motion remains smooth.

The paper is theoretical, but it proposes integration with sagittal submental ultrasound and pressure recordings through contour segmentation, binary masks for nn9, graph-based cycle detection, winding-number checks, and framewise correlation of (t,n)(t,n)0, (t,n)(t,n)1, or (t,n)(t,n)2 with pressure and milk transfer. It also identifies important limitations: a 2D sagittal model rather than full 3D contact topology, simplified nipple geometry, no viscoelastic or fluid–structure interaction model, and simulation-dependent thresholds.

3. Surface-seal thresholds in water-entry hydrodynamics

In "To Seal or Not To Seal" (Eshraghi et al., 2019), threshold seal refers to the occurrence of a surface seal during water entry. A hydrophobic sphere creates both a splash curtain above the free surface and an air cavity below it. The paper distinguishes deep seal, driven primarily by hydrostatic pressure and cavity pressure deficit below the free surface, from surface seal, driven by splash-curtain dynamics at or slightly below the free surface. Surface seal is formally defined by

(t,n)(t,n)3

where (t,n)(t,n)4 and (t,n)(t,n)5 are the radial and vertical coordinates of the curtain rim.

The decisive control parameter is not simply impact velocity. Cavity expansion induces air inflow with volumetric rate

(t,n)(t,n)6

opening radius (t,n)(t,n)7, and characteristic air velocity

(t,n)(t,n)8

Via Bernoulli, the cavity pressure difference is

(t,n)(t,n)9

and this pressure difference acts normal to the splash curtain, pulling it inward. The full rim dynamics are described by a second-order nonlinear ODE including centrifugal force, surface tension, gravity, air drag, and tt0. Using measured tt1, model-predicted rim trajectories show good agreement with experiments.

The paper’s central threshold result is a critical dimensionless number based on the ratio tt2, where tt3 is sphere impact velocity. The simplified scaling gives

tt4

and experimental data fit

tt5

with correlation tt6. A model-derived critical condition yields

tt7

while the experimental regime transition appears around tt8. The associated critical Weber number is taken as

tt9

with measured rim radius ItR2,I_t \subset \mathbb{R}^2,0.

The threshold seal condition is therefore a regime separator: ItR2,I_t \subset \mathbb{R}^2,1 whereas smaller ratios give no surface seal even at high impact speed. This directly challenges the prior view that impact velocity alone is the determinant parameter. The paper reports that using time-varying ItR2,I_t \subset \mathbb{R}^2,2 reduces the maximum error in predicted ItR2,I_t \subset \mathbb{R}^2,3 to 5.6%, whereas using a constant pressure based on ItR2,I_t \subset \mathbb{R}^2,4 gives poor correlation.

The experiments used hydrophobic spheres of acrylic, glass, alumina, steel, and tungsten, with diameters ItR2,I_t \subset \mathbb{R}^2,5–ItR2,I_t \subset \mathbb{R}^2,6 mm, impact velocities ItR2,I_t \subset \mathbb{R}^2,7–ItR2,I_t \subset \mathbb{R}^2,8 m/s, and high-speed imaging at 5000 fps. The authors also note significant limitations: axisymmetry, constant rim radius ItR2,I_t \subset \mathbb{R}^2,9, incompressible and spatially uniform cavity airflow, laminar drag law Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},0, neglect of some forces in the reduced scaling, and a parameter range limited to water and spheres. The threshold is therefore robust within the studied regime, but not universal across arbitrary fluids or projectiles.

4. Threshold sealing as one-way policy in RISC-V isolation

In "Efficient Sealable Protection Keys for RISC-V" (Delshadtehrani et al., 2020), threshold seal denotes a one-way policy transition in intra-process memory isolation. SealPK extends RISC-V Sv39 PTEs by using bits 54–63 to store a 10-bit protection key, yielding

Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},1

Permission metadata are stored in PKR, a 2 Kb SRAM organized as Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},2 rows Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},3 Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},4 keys per row Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},5 Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},6 bits per key. For key Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},7, the permission mask is

Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},8

and effective access is the intersection of PTE permissions with key permissions: Nt={xR2:xctrt},N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},9

SealPK moves domain switching to user space through custom instructions RDPKR and WRPKR, avoiding kernel context switches and TLB flushes. Its distinctive contribution is three sealing primitives. Domain sealing prevents further changes to PTE permissions or pkey assignments for pages with key AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).0 once sealed_domain[k]=1. Page sealing prevents additional pages from being assigned to domain AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).1 once sealed_page[k]=1. Permission sealing restricts WRPKR for key AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).2 to a specific contiguous code range recorded in SealReg and cached in PK-CAM; after sealing, WRPKR succeeds only if the current PC lies in AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).3. The paper explicitly states that there is no unseal operation; the only way to remove the effect is freeing the key/domain and starting over.

This threshold logic is reinforced by lazy deallocation, which addresses Intel MPK’s protection-key use-after-free problem. SealPK maintains alloc_map, dirty_map, and counter_map. A key is not returned by pkey_alloc unless

AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).4

If pkey_free(i) is called while counter_map[i]\>0, the key enters a dirty state rather than becoming free; dirty keys are never reallocated. This guarantees that a freed pkey cannot be reused while any page still references it.

The architecture is intended for workloads that need frequent permission switching or many domains, including OpenSSL-like multi-component applications and isolated shadow stacks. The implementation on a Rocket processor and FPGA prototype reports area overhead of approximately 5.6% LUT and 2.7% FF, with estimated power overhead <5% and context-switch overhead <1%. In the shadow-stack evaluation, geometric mean overheads versus baseline were approximately 2875.62× for mprotect on SPECint2000, 1982.70× on SPECint2006, and 320.21× on MiBench, compared with 21.00×, 14.81×, and 8.52× for SealPK-RD+RW. The authors summarize this as approximately 88× faster than mprotect for isolated shadow stacks.

The main limitation is conceptual as well as architectural. SealPK provides threshold-like sealing of policy state, not cryptographic threshold authorization. Its guarantees assume trusted kernel and hardware, do not address speculative-execution side channels, and only support one contiguous trusted range per pkey for permission sealing.

5. Threshold seal as signature-agnostic authorization in MPC custody

In "Threshold Authorization Without Threshold Signatures: Signature-Agnostic MPC Custody" (Porechna, 9 Jul 2026), the threshold seal is a cryptographic object that replaces threshold signatures as the authorization primitive in digital-asset custody. The architecture is dual-gate. The first gate authenticates each approver with any EUF-CMA signature scheme AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).5. The second gate verifies that a quorum jointly produced a valid threshold seal bound to the operation.

For slot AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).6, the seal is an affine authenticator over AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).7: AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).8 where AtItint(Nt).A_t \subset I_t \setminus \operatorname{int}(N_t).9 and AtA_t0 are global coefficients that are Shamir-shared among the members and never known to any one party. Each member AtA_t1 holds shares AtA_t2 and AtA_t3, computes

AtA_t4

and signs an envelope carrying this evaluation together with a share-correctness opening against a recorded commitment

AtA_t5

The evaluation point AtA_t6 is derived from the operation AtA_t7, custody metadata, and slot identifier by domain-separated hashing.

Authorization accepts only if four checks succeed. (C1) At least AtA_t8 envelopes carry valid member signatures and match the operation and slot. (C2) The commitment openings verify and each evaluation satisfies the affine relation. (C3) The verifier interpolates the polynomial

AtA_t9

from at least WecWe_c00 accepted points and reconstructs

WecWe_c01

by Lagrange interpolation. (C4) The coefficient slot is fresh and then consumed. The output is an enforcement-layer authorization receipt, not a native chain signature.

The security model distinguishes key-only corruption from full corruption. The paper’s central claim is that an adversary holding WecWe_c02 signing keys but no coefficient shares for a fresh slot still cannot produce a valid seal. Threshold unforgeability is bounded by signature EUF-CMA advantage, commitment opening-unforgeability, and hash-collision resistance: WecWe_c03 Unused-slot secrecy is information-theoretic apart from commitment hiding leakage, because Shamir sharing reveals nothing below threshold.

The principal significance of the threshold seal here is decoupling threshold authorization from threshold signing. Migrating from ECDSA to SLH-DSA or ML-DSA is then a member-key rotation, not a redesign of the authorization layer. The paper therefore frames the signature scheme as a deployment parameter rather than a protocol parameter. The tradeoff is that the seal must be verified by programmable logic in a smart contract, vault module, or HSM policy engine; it is not a stock signature accepted by legacy verifiers.

6. Threshold-conditioned disclosure in secret petitions

In "SeCritMass: Threshold Secret Petitions" (Breuer, 2024), a threshold seal is an WecWe_c04-threshold secret petition: a petition that gathers encrypted signatures from valid users and permits decryption if and only if at least WecWe_c05 signatures have been gathered. Below threshold, identities and testimonies remain sealed; once the petition is triggered, they become decryptable by anyone.

The construction uses ElGamal over a cyclic group WecWe_c06 of order WecWe_c07, with public key

WecWe_c08

and secret key fragmented as

WecWe_c09

Each signature event causes one previously hidden fragment WecWe_c10 to be reconstructed by a threshold of key rabbits and published alongside the user’s encrypted signature. Before WecWe_c11 signatures, at least one fragment is missing and the secret key WecWe_c12 cannot be computed. After WecWe_c13 signatures,

WecWe_c14

so all ElGamal ciphertexts can be decrypted.

The system separates roles among author, users, validators, and key rabbits. Threshold parameters are layered: WecWe_c15 is the global decryption threshold, WecWe_c16 is the threshold of key rabbits needed to reconstruct a fragment, and WecWe_c17 is the threshold number of validators needed for user validity. Validators issue a unique identifier WecWe_c18; key rabbits receive secret shares of WecWe_c19, compute a petition-specific hash WecWe_c20 via MPC, and use it to enforce uniqueness. A typical cyphersignature is

WecWe_c21

where WecWe_c22 is the testimony and WecWe_c23 are encrypted shares of the user identifier.

The scheme is designed for coordination problems in which users do not want early individual exposure. The paper discusses workplace petitions, reporting sexual harassment, police brutality complaints, and internal complaint systems. Its core security objective is pre-threshold anonymity combined with post-threshold global disclosure. It also requires user validity, user uniqueness, and irrevocability of appended signatures.

The scheme is not fully trustless and does not claim complete coercion resistance. The paper explicitly notes a weakness: a user may be able to prove non-signing by going through the whole signing process and showing that a new cyphersignature has been added to the chain. Publicly verifiable secret sharing is therefore critical to exclude hidden master-key control, while the honest-threshold assumptions over validators and key rabbits remain central. The paper also sketches multi-threshold extensions in which different users choose different acceptable reveal thresholds WecWe_c24, producing layered seals that open at different participation counts.

7. Quantum secret sharing with seal property

In "Collaboration Encouraging Quantum Secret Sharing Scheme with Seal Property" (Cheng et al., 2024), seal denotes revocable and detectable restraint on premature reconstruction. The paper introduces CE-QSS-Seal, in which the dealer can ask participants to return their shares before a predefined date or event and can test whether they attempted early reconstruction. The work separates two constructions.

The first is unconditionally secure and uses a GHZ-like state

WecWe_c25

where WecWe_c26 is the bitwise negation of WecWe_c27. Each of the WecWe_c28 participants receives one qubit. If all WecWe_c29 cooperate, reconstruction succeeds with probability WecWe_c30, because measuring in the computational basis yields either WecWe_c31 or WecWe_c32, both of which encode the same secret. If WecWe_c33 participants are missing, success probability is

WecWe_c34

since the missing bits must be guessed. This is the paper’s collaboration-encouraging property: reconstruction probability diminishes exponentially with the number of missing parties.

The seal check asks participants to return their shares, after which the dealer measures in the basis

WecWe_c35

If no one has tried to reconstruct, the state remains the original superposition and the dealer always gets the “+” outcome. If some participant measured in the computational basis to recover the secret prematurely, the global state collapses to WecWe_c36 or WecWe_c37, and the dealer detects cheating with probability

WecWe_c38

The paper emphasizes that this matches the optimal unconditional bound for seal schemes with perfect reconstruction.

The second construction uses post-quantum PKE with certified deletion. A share contains a quantum state

WecWe_c39

together with a post-quantum encryption of WecWe_c40 and a masked bit. Reconstruction requires computational-basis measurement, whereas certified deletion requires Hadamard-basis measurement. A participant who measures early to learn the secret cannot later supply correct deletion evidence on the qubits encoded in the Hadamard basis. The paper therefore claims cheat-detection probability close to WecWe_c41, surpassing the unconditional WecWe_c42 ceiling by introducing post-quantum computational assumptions.

The paper also gives a revocable WecWe_c43-threshold extension built from Shamir secret sharing wrapped with certified deletion. The dealer encrypts each Shamir share WecWe_c44 into a quantum-classical object of the form

WecWe_c45

and can revoke the secret by asking WecWe_c46 or more members to measure their quantum states in the Fourier basis and return evidence. If these WecWe_c47 participants are honest, enough shares are destroyed that the secret is no longer reconstructable. The authors note, however, that this extension loses the original collaboration-encouraging property: it becomes a revocable threshold QSS rather than a graded WecWe_c48-style scheme.

Across these literatures, threshold seal does not denote a single standardized mechanism. It denotes a class of threshold-governed global states: annular contact continuity around a nipple, airflow-driven splash closure, irreversible policy freezing in hardware-assisted isolation, quorum-bound authorization artifacts, collective decryption triggers, and revocable quantum sharing states. The shared technical lesson is that seal adequacy, seal occurrence, or seal authorization is typically determined by global topology, system state, or collective computation, and cannot be reduced to local contact, local permission bits, or signatures considered in isolation.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Threshold Seal.