Traceable Secret Sharing and Applications
Vipul Goyal, Yifan Song, Akshayaram Srinivasan
Abstract
Consider a scenario where Alice stores some secret data s on n servers using a t-out-of-n secret sharing scheme. Trudy (the collector) is interested in the secret data of Alice and is willing to pay for it. Trudy publishes an advertisement on the internet which describes an elaborate cryptographic scheme to collect the shares from the n servers. Each server who decides to submit its share is paid a hefty monetary reward and is guaranteed "immunity" from being caught or prosecuted in a court for violating its service agreement with Alice. Bob is one of the servers and sees this advertisement. On examining the collection scheme closely, Bob concludes that there is no way for Alice to prove anything in a court that he submitted his share. Indeed, if Bob is rational, he might use the cryptographic scheme in the advertisement and submit his share since there are no penalties and no fear of being caught and prosecuted. Can we design a secret sharing scheme which Alice can use to avoid such a scenario?
We introduce a new primitive called as Traceable Secret Sharing to tackle this problem. In particular, a traceable secret sharing scheme guarantees that a cheating server always runs the risk of getting traced and prosecuted by providing a valid evidence (which can be examined in a court of law) implicating its dishonest behavior. We explore various definitional aspects and show how they are highly non-trivial to construct (even ignoring efficiency aspects). We then give an efficient construction of traceable secret sharing assuming the existence of a secure two-party computation protocol. We also show an application of this primitive in constructing traceable protocols for multi-server delegation of computation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 456df2f0-db96-4bd0-b3e2-57eadcda8003Cited by top-tier papers6
- Threshold Signatures with Private AccountabilityDan Boneh, Chelsea KomloCRYPTO 2022 · 48 citations
- More is Merrier: Relax the Non-Collusion Assumption in Multi-Server PIRTiantian Gong, Ryan Henry, Alexandros Psomas, Aniket KateS&P 2024 · 7 citations
- Disincentivize Collusion in Verifiable Secret SharingTiantian Gong, Aniket Kate, Hemanta K. Maji, Hai H. NguyenEUROCRYPT 2025 · 3 citations
- CCA-Secure Traceable Threshold (ID-based) Encryption and ApplicationRishiraj Bhattacharyya, Jan Bormet, Sebastian Faust, Pratyay Mukherjee et al.CCS 2025 · 2 citations
- Breaking Omertà: On Threshold Cryptography, Smart Collusion, and WhistleblowingMahimna Kelkar, Aadityan Ganesh, Aditi Partap, Joseph Bonneau et al.CCS 2025 · 1 citation
Related papers
- Traceable Secret Sharing: Strong Security and Efficient ConstructionsDan Boneh, Aditi Partap, Lior RotemCRYPTO 2024 · 21 citations
- Traceable Secret Sharing RevisitedVipul Goyal, Abhishek Jain, Aditi PartapEUROCRYPT 2026
- Accountability for Misbehavior in Threshold Decryption via Threshold Traitor TracingDan Boneh, Aditi Partap, Lior RotemCRYPTO 2024 · 16 citations
- Traceable Secret Sharing Schemes for General Access StructuresOriol Farràs, Miquel GuiotEUROCRYPT 2026
- Traceable Verifiable Random FunctionsDan Boneh, Aditi Partap, Lior RotemCRYPTO 2025 · 7 citations
