Efficient Verifiable Secret Sharing with Share Recovery in BFT Protocols
Soumya Basu, Alin Tomescu, Ittai Abraham, Dahlia Malkhi, Michael K. Reiter, Emin Gün Sirer
Abstract
Byzantine fault tolerant state machine replication (SMR) provides powerful integrity guarantees, but fails to provide any privacy guarantee whatsoever. A natural way to add such privacy guarantees is to secret-share state instead of fully replicating it. Such a com- bination would enable simple solutions to difficult problems, such as a fair exchange or a distributed certification authority. However, incorporating secret shared state into traditional Byzantine fault tolerant (BFT) SMR protocols presents unique challenges. BFT protocols often use a network model that has some degree of asynchrony, making verifiable secret sharing (VSS) unsuitable. However, full asynchronous VSS (AVSS) is unnecessary as well since the BFT algorithm provides a broadcast channel. We first present the VSS with share recovery problem, which is the subproblem of AVSS required to incorporate secret shared state into a BFT engine. Then, we provide the first VSS with share recovery solution, KZG-VSSR, in which a failure-free sharing incurs only a constant number of cryptographic operations per replica. Finally, we show how to efficiently integrate any instantiation of VSSR into a BFT replication protocol while incurring only constant overhead. Instantiating VSSR with prior AVSS protocols would require a quadratic communication cost for a single shared value and incur a linear overhead when incorporated into BFT replication. We demonstrate our end-to-end solution via a a private key-value store built using BFT replication and two instantiations of VSSR, KZG-VSSR and Ped-VSSR, and present its evaluation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b989a0a5-a889-4673-a7ce-77bc0a0673dbCited by top-tier papers5
- Towards Scalable Threshold CryptosystemsAlin Tomescu, Robert Chen, Yiming Zheng, Ittai Abraham et al.S&P 2020 · 102 citations
- Asynchronous Data Dissemination and its ApplicationsSourav Das, Zhuolun Xiang, Ling RenCCS 2021 · 3 citations
- hbACSS: How to Robustly Share Many SecretsThomas Yurek, Licheng Luo, Jaiden Fairoze, Aniket Kate et al.NDSS 2022
- MVP-ORAM: a Wait-free Concurrent ORAM for Confidential BFT StorageRobin Vassantlal, Hasan Heydari, Bernardo Ferreira, Alysson BessaniNDSS 2026
- Long Live The Honey Badger: Robust Asynchronous DPSS and its ApplicationsThomas Yurek, Zhuolun Xiang, Yu Xia, Andrew MillerUSENIX Security 2023
Builds on2
Related papers
- COBRA: Dynamic Proactive Secret Sharing for Confidential BFT ServicesRobin Vassantlal, Eduardo Alchieri, Bernardo Ferreira, Alysson BessaniS&P 2022 · 41 citations
- RandPiper - Reconfiguration-Friendly Random Beacons with Quadratic CommunicationAdithya Bhat, Nibesh Shrestha, Zhongtang Luo, Aniket Kate et al.CCS 2021 · 5 citations
- On the Security of KZG Commitment for VSSAtsuki Momose, Sourav Das, Ling RenCCS 2023 · 3 citations
- State Machine Replication Among Strangers, Fast and Self-sufficientJuan A. Garay, Aggelos Kiayias, Yu ShenCRYPTO 2025 · 3 citations
- Practical Asynchronous Distributed Key Reconfiguration and Its ApplicationsHanwen Feng, Yingzi Gao, Yuan Lu, Qiang Tang et al.S&P 2026 · 5 citations
