---
title: 'Threshold Seal: A Multidomain Perspective'
url: https://www.emergentmind.com/topics/threshold-seal
type: topic
---

# Threshold Seal: A Multidomain Perspective

Threshold seal is a polysemous technical term whose meaning depends on domain. In recent arXiv usage, it denotes several distinct but structurally related threshold-conditioned phenomena: a topological criterion for the existence of an oral seal during infant breastfeeding, a hydrodynamic transition separating surface-seal from no-seal regimes in water entry, a one-way sealing policy for protection-key domains in RISC-V isolation, and cryptographic or quantum mechanisms in which authorization, disclosure, or revocation occurs only after quorum or reconstruction conditions are satisfied [2602.17389], [1912.05785], [2012.02715], [2607.08226]. This suggests a family of constructions in which a “seal” is not merely local contact or binary closure, but a global state whose existence, persistence, or breakage is governed by an explicit threshold.

## 1. Semantic range and shared structure

The term appears in at least six technically distinct settings. In biomechanics, the seal is a continuous circumferential contact band around the nipple. In fluid dynamics, it is closure of a splash curtain over an air cavity. In computer architecture, it is an irreversible policy state for domains, pages, or permissions. In cryptography, it is a quorum-generated authorization artifact or a threshold-conditioned disclosure mechanism. In quantum secret sharing, it is a revocable sharing state whose premature opening is detectable [2602.17389], [1912.05785], [2012.02715], [2607.08226], [2408.01255], [2409.07863].

| Setting | Sealed object | Threshold condition |
|---|---|---|
| Breastfeeding biomechanics | Encircling oral contact band | Existence of an admissible non-contractible loop |
| Water entry | Splash-curtain closure at the surface | Critical \(U_{\text{air}}/U_0\) and associated \(We_c\) |
| RISC-V isolation | Domain, page, or permission mutability | Transition to sealed state until key and pages are freed |
| MPC custody | Authorization artifact | At least \(t\) verified envelopes and one unused slot |
| Secret petitions | Encrypted signatures and testimonies | At least \(n\) signatures gathered |
| Quantum secret sharing | Reconstructable secret state | Access-structure or \((t,n)\) reconstruction and seal checks |

A recurrent misconception, rejected in several of these literatures, is that local or componentwise indicators suffice. The breastfeeding work argues that local tongue–palate distances or local pressure measurements cannot establish global seal continuity. The splash-curtain study argues that impact velocity alone does not determine surface seal. The custody paper argues that member signatures alone do not provide threshold authorization. The common implication is that threshold seal is typically defined by a global invariant, policy state, or collective computation rather than by isolated local measurements.

## 2. Geometric and topological threshold seal in infant breastfeeding

In "Geometric and topological constraints on oral seal formation during infant breastfeeding" [2602.17389], the oral seal is modeled as a global geometric-topological object. Each sagittal ultrasound frame at time \(t\) is represented by a bounded planar domain
\[
I_t \subset \mathbb{R}^2,
\]
with nipple cross-section
\[
N_t = \{x \in \mathbb{R}^2 : \|x-c_t\| \le r_t\},
\]
and an effective contact band
\[
A_t \subset I_t \setminus \operatorname{int}(N_t).
\]
Seal-preserving configurations are constructed so that \(A_t\) has the homotopy type of an annulus,
\[
A_t \sim S^1 \times [0,1],
\]
whereas seal-breaking configurations are simply connected or disconnected.

The seal criterion is the existence of a closed curve in \(A_t\) that encircles the nipple exactly once. For piecewise \(C^1\) closed curves \(\gamma\) in \(A_t\), admissibility is defined by winding number
\[
\operatorname{wind}(\gamma,c_t)=\frac{1}{2\pi}\int_\gamma \frac{(x-c_t)^\perp \cdot \mathrm{d}x}{\|x-c_t\|^2}=1.
\]
These admissible curves are the non-contractible loops of the annular contact band. The shortest such loop defines the systolic invariant
\[
\operatorname{sys}(t)=\inf_{\gamma \in \Gamma(A_t),\,\operatorname{wind}(\gamma,c_t)=1}\operatorname{Length}(\gamma),
\]
and if no admissible curve exists, \(\operatorname{sys}(t)\) is declared undefined.

The paper further defines a normalized systolic index
\[
\phi(t)=\frac{\operatorname{sys}(t)}{2\pi r_t},
\]
which is dimensionless and separates a binary topological component from a continuous geometric component. If \(\phi\) is undefined, no encircling curve exists and the seal is broken. If \(\phi \approx 1\), the admissible loop is tight relative to the nipple circumference. This formulation explicitly rejects the idea that a set of normal local distances or pressures guarantees global seal integrity; a small gap anywhere in the band can destroy circumferential continuity.

Threshold behavior is encoded by a feasibility function
\[
F(t,\theta)=
\begin{cases}
1, & \text{if an admissible encircling curve exists},\\
0, & \text{otherwise},
\end{cases}
\]
where \(t\) is normalized band thickness and \(\theta\) is angular discontinuity size. The paper numerically estimates a critical thickness
\[
t_c \approx 0.194,
\]
below which admissibility is lost irrespective of angular perturbation magnitude. In static regime mapping, **80.63%** of sampled configurations were seal-preserving and **19.37%** were topologically infeasible. Sensitivity to angular discontinuity increases sharply when \(t<0.3\), producing a narrow admissible corridor.

The comparative perturbation analysis shows that localized gaps are more destructive than symmetric thinning. For matched normalized perturbation magnitude \(\lambda\), symmetric thinning collapses at \(\lambda_1=0.4\), whereas localized discontinuity collapses earlier at \(\lambda_2=0.25\). In the overlapping admissible range \(\lambda<0.25\), mean systolic lengths were \(6.126 \pm 0.091\) for symmetric thinning and \(6.322 \pm 0.023\) for localized gaps, with paired t-test \(t=-27.22\), \(p<0.001\). Dynamic simulations with
\[
u(t)=u_0+A\sin(2\pi f t),\quad u_0=1.0,\ A=0.25,\ f=1.2\ \text{Hz},
\]
noise \(n(t)\sim\mathcal N(0,\sigma^2)\) with \(\sigma=0.06\), and robustness
\[
R(t)=u(t)-\delta+n(t),\quad \delta=0.92,
\]
yielded a seal dropout fraction of **0.393** over 10 s. Thus \(\operatorname{sys}(t)\) can alternate between finite and undefined values even when overall geometric motion remains smooth.

The paper is theoretical, but it proposes integration with sagittal submental ultrasound and pressure recordings through contour segmentation, binary masks for \(A_t\), graph-based cycle detection, winding-number checks, and framewise correlation of \(F(t)\), \(\phi(t)\), or \(f_{\text{seal}}\) with pressure and milk transfer. It also identifies important limitations: a 2D sagittal model rather than full 3D contact topology, simplified nipple geometry, no viscoelastic or fluid–structure interaction model, and simulation-dependent thresholds.

## 3. Surface-seal thresholds in water-entry hydrodynamics

In "To Seal or Not To Seal" [1912.05785], threshold seal refers to the occurrence of a surface seal during water entry. A hydrophobic sphere creates both a splash curtain above the free surface and an air cavity below it. The paper distinguishes deep seal, driven primarily by hydrostatic pressure and cavity pressure deficit below the free surface, from surface seal, driven by splash-curtain dynamics at or slightly below the free surface. Surface seal is formally defined by
\[
r(t)=0 \quad \text{and} \quad z(t)<0,
\]
where \(r(t)\) and \(z(t)\) are the radial and vertical coordinates of the curtain rim.

The decisive control parameter is not simply impact velocity. Cavity expansion induces air inflow with volumetric rate
\[
Q(t)=\frac{dV_{\text{cav}}(t)}{dt},
\]
opening radius \(R^*(t)\), and characteristic air velocity
\[
U_{\text{air}}(t)\approx \frac{Q(t)}{\pi R^{*2}(t)}.
\]
Via Bernoulli, the cavity pressure difference is
\[
\Delta P(t)=P_{\text{atm}}-P_{\text{cav}}(t)=\frac{1}{2}\rho_{\text{air}}U_{\text{air}}^2(t),
\]
and this pressure difference acts normal to the splash curtain, pulling it inward. The full rim dynamics are described by a second-order nonlinear ODE including centrifugal force, surface tension, gravity, air drag, and \(\Delta P(t)\). Using measured \(\Delta P(t)\), model-predicted rim trajectories show good agreement with experiments.

The paper’s central threshold result is a critical dimensionless number based on the ratio \(U_{\text{air}}/U_0\), where \(U_0\) is sphere impact velocity. The simplified scaling gives
\[
t_{\text{surf}} \propto \frac{R_0}{U_{\text{air}}},
\]
and experimental data fit
\[
\frac{t_{\text{surf}}U_0}{R_0} \approx 1.68\left(\frac{U_{\text{air}}}{U_0}\right)^{-0.12}+7.35
\]
with correlation \(R^2 \approx 0.89\). A model-derived critical condition yields
\[
\left(\frac{U_{\text{air}}}{U_0}\right)_{\text{crit}} \approx 0.146 \pm 0.005,
\]
while the experimental regime transition appears around \(U_{\text{air}}/U_0 \approx 0.12\). The associated critical Weber number is taken as
\[
We_c=\frac{\rho U_0^2R_0}{\gamma}\approx 1000,
\]
with measured rim radius \(a\approx 0.095R_0\).

The threshold seal condition is therefore a regime separator:
\[
\frac{U_{\text{air}}}{U_0}\gtrsim 0.12\text{--}0.15
\quad \Rightarrow \quad \text{surface seal},
\]
whereas smaller ratios give no surface seal even at high impact speed. This directly challenges the prior view that impact velocity alone is the determinant parameter. The paper reports that using time-varying \(\Delta P(t)\propto U_{\text{air}}^2(t)\) reduces the maximum error in predicted \(t_{\text{surf}}\) to **5.6%**, whereas using a constant pressure based on \(U_0\) gives poor correlation.

The experiments used hydrophobic spheres of acrylic, glass, alumina, steel, and tungsten, with diameters \(9.525\)–\(19.05\) mm, impact velocities \(2.0\)–\(6.0\) m/s, and high-speed imaging at 5000 fps. The authors also note significant limitations: axisymmetry, constant rim radius \(a\), incompressible and spatially uniform cavity airflow, laminar drag law \(C_d=24/\mathrm{Re}\), neglect of some forces in the reduced scaling, and a parameter range limited to water and spheres. The threshold is therefore robust within the studied regime, but not universal across arbitrary fluids or projectiles.

## 4. Threshold sealing as one-way policy in RISC-V isolation

In "Efficient Sealable Protection Keys for RISC-V" [2012.02715], threshold seal denotes a one-way policy transition in intra-process memory isolation. SealPK extends RISC-V Sv39 PTEs by using bits 54–63 to store a 10-bit protection key, yielding
\[
K(p)\in\{0,\dots,2^{10}-1\}=1024 \text{ domains}.
\]
Permission metadata are stored in PKR, a **2 Kb SRAM** organized as \(32\) rows \(\times\) \(32\) keys per row \(\times\) \(2\) bits per key. For key \(k\), the permission mask is
\[
\text{perm}(k)=(\text{RD}_k,\text{WD}_k)\in\{0,1\}^2,
\]
and effective access is the intersection of PTE permissions with key permissions:
\[
R_{\text{eff}}=R_p \land \neg \text{RD}_k,\qquad
W_{\text{eff}}=W_p \land \neg \text{WD}_k.
\]

SealPK moves domain switching to user space through custom instructions RDPKR and WRPKR, avoiding kernel context switches and TLB flushes. Its distinctive contribution is three sealing primitives. **Domain sealing** prevents further changes to PTE permissions or pkey assignments for pages with key \(k\) once `sealed_domain[k]=1`. **Page sealing** prevents additional pages from being assigned to domain \(k\) once `sealed_page[k]=1`. **Permission sealing** restricts WRPKR for key \(k\) to a specific contiguous code range recorded in SealReg and cached in PK-CAM; after sealing, WRPKR succeeds only if the current PC lies in \([\text{addr}_{\text{start}},\text{addr}_{\text{end}}]\). The paper explicitly states that there is no unseal operation; the only way to remove the effect is freeing the key/domain and starting over.

This threshold logic is reinforced by lazy deallocation, which addresses Intel MPK’s protection-key use-after-free problem. SealPK maintains `alloc_map`, `dirty_map`, and `counter_map`. A key is not returned by `pkey_alloc` unless
\[
alloc\_map[i]=0 \land dirty\_map[i]=0.
\]
If `pkey_free(i)` is called while `counter_map[i]>0`, the key enters a dirty state rather than becoming free; dirty keys are never reallocated. This guarantees that a freed pkey cannot be reused while any page still references it.

The architecture is intended for workloads that need frequent permission switching or many domains, including OpenSSL-like multi-component applications and isolated shadow stacks. The implementation on a Rocket processor and FPGA prototype reports area overhead of approximately **5.6% LUT** and **2.7% FF**, with estimated power overhead **<5%** and context-switch overhead **<1%**. In the shadow-stack evaluation, geometric mean overheads versus baseline were approximately **2875.62×** for mprotect on SPECint2000, **1982.70×** on SPECint2006, and **320.21×** on MiBench, compared with **21.00×**, **14.81×**, and **8.52×** for SealPK-RD+RW. The authors summarize this as approximately **88× faster** than mprotect for isolated shadow stacks.

The main limitation is conceptual as well as architectural. SealPK provides threshold-like sealing of policy state, not cryptographic threshold authorization. Its guarantees assume trusted kernel and hardware, do not address speculative-execution side channels, and only support one contiguous trusted range per pkey for permission sealing.

## 5. Threshold seal as signature-agnostic authorization in MPC custody

In "Threshold Authorization Without Threshold Signatures: Signature-Agnostic MPC Custody" [2607.08226], the threshold seal is a cryptographic object that replaces threshold signatures as the authorization primitive in digital-asset custody. The architecture is dual-gate. The first gate authenticates each approver with any EUF-CMA signature scheme \(\mathrm{Sig}=(\mathrm{KeyGen},\mathrm{Sign},\mathrm{Verify})\). The second gate verifies that a quorum jointly produced a valid threshold seal bound to the operation.

For slot \(\nu\), the seal is an affine authenticator over \(\mathbb F_p\):
\[
\sigma_\nu = k_1^{(\nu)}x + k_2^{(\nu)},
\]
where \(k_1^{(\nu)}\) and \(k_2^{(\nu)}\) are global coefficients that are Shamir-shared among the members and never known to any one party. Each member \(C_i\) holds shares \([k_1^{(\nu)}]_i\) and \([k_2^{(\nu)}]_i\), computes
\[
[\sigma_\nu]_i=[k_1^{(\nu)}]_i\cdot x+[k_2^{(\nu)}]_i,
\]
and signs an envelope carrying this evaluation together with a share-correctness opening against a recorded commitment
\[
\text{com}_i^{(\nu)}=Com(([k_1^{(\nu)}]_i,[k_2^{(\nu)}]_i);\rho_i^{(\nu)}).
\]
The evaluation point \(x\) is derived from the operation \(M\), custody metadata, and slot identifier by domain-separated hashing.

Authorization accepts only if four checks succeed. **(C1)** At least \(t\) envelopes carry valid member signatures and match the operation and slot. **(C2)** The commitment openings verify and each evaluation satisfies the affine relation. **(C3)** The verifier interpolates the polynomial
\[
g(z)=x f_1^{(\nu)}(z)+f_2^{(\nu)}(z)
\]
from at least \(t\) accepted points and reconstructs
\[
\sigma_\nu=g(0)=xk_1^{(\nu)}+k_2^{(\nu)}
\]
by Lagrange interpolation. **(C4)** The coefficient slot is fresh and then consumed. The output is an enforcement-layer authorization receipt, not a native chain signature.

The security model distinguishes key-only corruption from full corruption. The paper’s central claim is that an adversary holding \(\ge t\) signing keys but no coefficient shares for a fresh slot still cannot produce a valid seal. Threshold unforgeability is bounded by signature EUF-CMA advantage, commitment opening-unforgeability, and hash-collision resistance:
\[
Adv^{\mathrm{uf}}(\mathcal A)\le n\cdot Adv^{\mathrm{euf\text{-}cma}}_{\mathrm{Sig}}(\mathcal B_1)
+nB\cdot Adv^{\mathrm{ou}}_{\Pi}(\mathcal B_2)
+Adv^{\mathrm{cr}}_H(\mathcal B_3).
\]
Unused-slot secrecy is information-theoretic apart from commitment hiding leakage, because Shamir sharing reveals nothing below threshold.

The principal significance of the threshold seal here is decoupling threshold authorization from threshold signing. Migrating from ECDSA to SLH-DSA or ML-DSA is then a member-key rotation, not a redesign of the authorization layer. The paper therefore frames the signature scheme as a deployment parameter rather than a protocol parameter. The tradeoff is that the seal must be verified by programmable logic in a smart contract, vault module, or HSM policy engine; it is not a stock signature accepted by legacy verifiers.

## 6. Threshold-conditioned disclosure in secret petitions

In "SeCritMass: Threshold Secret Petitions" [2408.01255], a threshold seal is an \(n\)-threshold secret petition: a petition that gathers encrypted signatures from valid users and permits decryption if and only if at least \(n\) signatures have been gathered. Below threshold, identities and testimonies remain sealed; once the petition is triggered, they become decryptable by anyone.

The construction uses ElGamal over a cyclic group \(G\) of order \(q\), with public key
\[
p=g^s
\]
and secret key fragmented as
\[
s=s_1+s_2+\cdots+s_n \in \mathbb Z_q.
\]
Each signature event causes one previously hidden fragment \(s_j\) to be reconstructed by a threshold of key rabbits and published alongside the user’s encrypted signature. Before \(n\) signatures, at least one fragment is missing and the secret key \(s\) cannot be computed. After \(n\) signatures,
\[
s=\sum_{j=1}^n s_j \pmod q,
\]
so all ElGamal ciphertexts can be decrypted.

The system separates roles among author, users, validators, and key rabbits. Threshold parameters are layered: \(n\) is the global decryption threshold, \(t<k\) is the threshold of key rabbits needed to reconstruct a fragment, and \(v\) is the threshold number of validators needed for user validity. Validators issue a unique identifier \(u\in \mathbb Z_q\); key rabbits receive secret shares of \(u\), compute a petition-specific hash \(h_p(u)\) via MPC, and use it to enforce uniqueness. A typical cyphersignature is
\[
\big(E(m_V), E(u_1), E(u_2), \dots, E(u_k), h_p(u), s_j\big),
\]
where \(m_V\) is the testimony and \(u_1,\dots,u_k\) are encrypted shares of the user identifier.

The scheme is designed for coordination problems in which users do not want early individual exposure. The paper discusses workplace petitions, reporting sexual harassment, police brutality complaints, and internal complaint systems. Its core security objective is pre-threshold anonymity combined with post-threshold global disclosure. It also requires user validity, user uniqueness, and irrevocability of appended signatures.

The scheme is not fully trustless and does not claim complete coercion resistance. The paper explicitly notes a weakness: a user may be able to prove non-signing by going through the whole signing process and showing that a new cyphersignature has been added to the chain. Publicly verifiable secret sharing is therefore critical to exclude hidden master-key control, while the honest-threshold assumptions over validators and key rabbits remain central. The paper also sketches multi-threshold extensions in which different users choose different acceptable reveal thresholds \(n_U\), producing layered seals that open at different participation counts.

## 7. Quantum secret sharing with seal property

In "Collaboration Encouraging Quantum Secret Sharing Scheme with Seal Property" [2409.07863], seal denotes revocable and detectable restraint on premature reconstruction. The paper introduces CE-QSS-Seal, in which the dealer can ask participants to return their shares before a predefined date or event and can test whether they attempted early reconstruction. The work separates two constructions.

The first is unconditionally secure and uses a GHZ-like state
\[
|\Psi\rangle = |x\rangle + |\bar x\rangle,
\]
where \(\bar x\) is the bitwise negation of \(x\). Each of the \(n\) participants receives one qubit. If all \(n\) cooperate, reconstruction succeeds with probability \(1\), because measuring in the computational basis yields either \(x\) or \(\bar x\), both of which encode the same secret. If \(k\) participants are missing, success probability is
\[
2^{-k},
\]
since the missing bits must be guessed. This is the paper’s collaboration-encouraging property: reconstruction probability diminishes exponentially with the number of missing parties.

The seal check asks participants to return their shares, after which the dealer measures in the basis
\[
\left\{
\frac{1}{\sqrt{2}}(|x\rangle + |\bar x\rangle),
\frac{1}{\sqrt{2}}(|x\rangle - |\bar x\rangle)
\right\}.
\]
If no one has tried to reconstruct, the state remains the original superposition and the dealer always gets the “+” outcome. If some participant measured in the computational basis to recover the secret prematurely, the global state collapses to \(|x\rangle\) or \(|\bar x\rangle\), and the dealer detects cheating with probability
\[
\frac{1}{2}.
\]
The paper emphasizes that this matches the optimal unconditional bound for seal schemes with perfect reconstruction.

The second construction uses post-quantum PKE with certified deletion. A share contains a quantum state
\[
|x\rangle_\theta=\bigotimes_{i=1}^n |x_i\rangle_{\theta_i}
\]
together with a post-quantum encryption of \(\theta\) and a masked bit. Reconstruction requires computational-basis measurement, whereas certified deletion requires Hadamard-basis measurement. A participant who measures early to learn the secret cannot later supply correct deletion evidence on the qubits encoded in the Hadamard basis. The paper therefore claims cheat-detection probability close to \(1\), surpassing the unconditional \(1/2\) ceiling by introducing post-quantum computational assumptions.

The paper also gives a revocable \((t,n)\)-threshold extension built from Shamir secret sharing wrapped with certified deletion. The dealer encrypts each Shamir share \(S_i\) into a quantum-classical object of the form
\[
|x\rangle_\theta,\ \text{ENC}(\theta, S_i \text{ masked by } x),
\]
and can revoke the secret by asking \(t\) or more members to measure their quantum states in the Fourier basis and return evidence. If these \(t\) participants are honest, enough shares are destroyed that the secret is no longer reconstructable. The authors note, however, that this extension loses the original collaboration-encouraging property: it becomes a revocable threshold QSS rather than a graded \(2^{-k}\)-style scheme.

Across these literatures, threshold seal does not denote a single standardized mechanism. It denotes a class of threshold-governed global states: annular contact continuity around a nipple, airflow-driven splash closure, irreversible policy freezing in hardware-assisted isolation, quorum-bound authorization artifacts, collective decryption triggers, and revocable quantum sharing states. The shared technical lesson is that seal adequacy, seal occurrence, or seal authorization is typically determined by global topology, system state, or collective computation, and cannot be reduced to local contact, local permission bits, or signatures considered in isolation.

Source: https://www.emergentmind.com/topics/threshold-seal