EP0723348A2

Method and system for a public key cryptosystem having proactive, robust, and recoverable distributed threshold secret sharing

Abstract

A proactive threshold secret sharing cryptosystem using a set of servers. The cryptosystem is a threshold cryptosystem, in the sense that service is maintained if at least (k + 1) out of n servers are active and honest. The secret signature key is compromised only if the adversary breaks into at least (k + 1) servers. It is robust in the sense that the honest servers detect faulty ones and the service is not disrupted. It is recoverable, because if the adversary erases all the local information on the server it compromised, the information can be restored as soon as the server comes back to performing the correct protocol. The method and system has proactiveness, which means that in order to learn the secret, the adversary has to break into (k + 1) servers during the same round of the algorithm because the shares of the secret are periodically redistributed and rerandomized. The present invention uses a verifiable secret sharing mechanism to get the security requirements during the update between two rounds. The security of the scheme depends on the assumption of intractability of computing logarithms in a field of a big prime order and the ElGamal signature scheme.

EP0723348A2, drawing sheet 1
Sheet 1 of 63

Term

Term ended

Projected expiry passed 15 December 2015, 10.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

18 claims: 2 independent, 16 dependent

  1. 1
    A method of public key cryptography having proactive, robust and recoverable distributed threshold secret sharing, comprising the steps of:initializing servers linked by a communications network to form keys;synchronizing said servers to operate in discrete rounds having ends;calculating updated keys at said ends of said rounds from messages broadcast on said communications network;verifying said updated keys to form a set of compromised servers;and recovering said set of compromised servers.
  2. 10
    A data processing system for processing a public key cryptography scheme having proactive, robust and recoverable distributed threshold secret sharing, comprising:servers linked by a communications network;initialization means for initializing said servers to form keys associated with said servers;timing means for synchronizing operation of said servers into discrete rounds having ends;updating means for updating said keys at the end of each round of said discrete rounds to produce updated keys;verification means for verifying said updated keys to form a set of compromised servers;and recovery means for recovering said set of compromised servers.