Timed-release computational secret sharing and threshold encryption

Timed-release computational secret sharing and threshold encryption
复制标题

DOI:
10.1007/s10623-016-0324-2
复制
发表时间:
2018-01-01
影响因子:
1.6
通讯作者:
Shikata, Junji
Shikata, Junji
中科院分区:
数学3区
文献类型:
--
作者:
Watanabe, Yohei;Shikata, Junji

文献摘要

被引文献

相似文献

在现代密码学中,秘密共享方案是一种重要的密码原语。特别地,Krawczyk提出了一种计算秘密共享(CSS)方案,这是一种实用、简单的秘密共享方案。在本文中,我们专注于一个具有定时释放功能的CSS方案,我们称之为定时释放计算秘密共享(TR-CSS)方案。在TR-CSS中,大于或等于阈值的参与者只有在经销商指定的时间到来时才能通过使用他们的份额来重建秘密。我们的主要目的是实现一个通用的和有效的方式在共享大小的TR-CSS计划。具体来说,我们首先介绍了一个模型和形式化的安全TR-CSS。此外,我们提出了两种结构的TR-CSS:第一个是一个简单的和通用的结构从基于身份的密钥封装机制(IB-KEM)开始,第二个,这是一个更有效的建设比第一个,是建立使用特定的IB-KEM作为底层IB-KEM。因此,我们可以将TR-CSS视为Krawczyk的CSS在模型和构造方面的自然扩展,并且我们最终成功地以较小的开销向Krawczyk的CSS添加了定时发布功能,这几乎是最佳的。此外,我们的建议TR-CSS是重要的构造阈值加密和多重加密与定时发布功能的通用和有效的方式。Dodis和Katz展示了(i)从多重加密中简单而通用的阈值加密构造;以及(ii)简单、优雅而通用的多重加密构造。通过使用TR-CSS,我们可以有效地应用Dodis-Katz范式,即使在定时发布安全性的上下文中。
In modern cryptography, a secret sharing scheme is an important cryptographic primitive. In particular, Krawczyk proposed a computational secret sharing (CSS) scheme, which is a practical, simple secret sharing scheme. In this paper, we focus on a CSS scheme with timed-release functionality, which we call a timed-release computational secret sharing (TR-CSS) scheme. In TR-CSS, participants more than or equal to a threshold number can reconstruct a secret by using their shares only when the time specified by a dealer has come. Our main purpose is to realize a TR-CSS scheme in a generic and efficient way in terms of the share size. Specifically, we first introduce a model and formalization of security of TR-CSS. In addition, we propose two kinds of constructions of TR-CSS: the first one is a simple and generic construction starting from an identity-based key encapsulation mechanism (IB-KEM); the second one, which is a more efficient construction than the first one, is built using a specific IB-KEM as the underlying IB-KEM. As a result, we can regard TR-CSS as a natural extension of Krawczyk's CSS in terms of both a model and constructions, and we finally succeed to add timed-release functionality to Krawczyk's CSS with small overhead, which is almost optimal. Moreover, our proposal of TR-CSS is important for constructing threshold encryption and multiple encryption with timed-release functionality in a generic and efficient way. Dodis and Katz showed (i) a simple and generic construction of threshold encryption from multiple encryption; and (ii) a simple, elegant and generic construction of multiple encryption. By using TR-CSS, we can effectively apply the Dodis-Katz paradigm even in the context of timed-release security.