发明名称 METHOD OF VERIFIABLY SHARING A SECRET IN POTENTIALLY ASYNCHRONOUS NETWORKS
摘要 In accordance with the present invention, there is provided a method for sharing a secret value x among n participating network devices via an asynchronous network. The n participating network devices comprises t faulty devices and k sub-devices capable of reconstructing the secret value x, wherein t<n/3 and k<n. The secret value x being provided by a distributor. The method comprising of deriving by the distributor share values s<SUB>i </SUB>and subshare values s<SUB>ij </SUB>of the secret value x by applying a linear secret sharing scheme and deriving verification values g<SUP>s</SUP><SUP><SUB2>ij </SUB2></SUP>usable for verification of validity of the share values s<SUB>i </SUB>and the subshare values s<SUB>ij</SUB>; sending to each participating network device a share message comprising the corresponding subshare values s<SUB>Ai</SUB>,s<SUB>iA</SUB>, s<SUB>Bi</SUB>,s<SUB>iB</SUB>, s<SUB>Ci</SUB>,s<SUB>iC</SUB>; broadcasting a verification message comprising the verification values g<SUP>s</SUP><SUP><SUB2>ij</SUB2></SUP>; receiving by at least l participating network devices the verification message comprising the verification values g<SUP>s</SUP><SUP><SUB2>ij</SUB2></SUP>, wherein n-t>=l>=2t+1, and performing the following steps 1) to 4) for each recipient network device, 1) if a share message comprising subshare values s<SUB>ij </SUB>is received, determining the validity of the subshare values s<SUB>ij </SUB>in dependence on the verification values g<SUP>s</SUP><SUP><SUB2>ij </SUB2></SUP>and 2) broadcasting in the event of positive determination an agree message comprising an agree-value Y; 3) receiving l agree messages comprising the agree-values Y<SUB>A</SUB>, Y<SUB>B</SUB>, Y<SUB>c</SUB>; 4) in the event of l received agree messages, obtaining the share value s<SUB>i </SUB>either from the share message sent by the distributor D or from subshare values s<SUB>ij </SUB>received from participating network devices and determining the validity of the subshare values s<SUB>ij </SUB>in dependence on the verification values g<SUP>s</SUP><SUP><SUB2>ij</SUB2></SUP>. In a second aspect of the present invention a method without broadcast is disclosed.
申请公布号 KR100570133(B1) 申请公布日期 2006.04.12
申请号 KR20037012085 申请日期 2003.09.16
申请人 发明人
分类号 H04L9/08 主分类号 H04L9/08
代理机构 代理人
主权项
地址