Lune

CRYPTO2024顶会

Traceable Secret Sharing: Strong Security and Efficient Constructions

Dan Boneh, Aditi Partap, Lior Rotem

2024年份
21被引次数
3顶会引用

摘要

Suppose Alice uses a tt-out-of-nn secret sharing to store her secret key on nn servers. Her secret key is protected as long as tt of them do not collude. However, what if a less-than-tt subset of the servers decides to offer the shares they have for sale? In this case, Alice should be able to hold them accountable, or else nothing prevents them from selling her shares. With this motivation in mind, Goyal, Song, and Srinivasan (CRYPTO 21) introduced the concept of traceable secret sharing. In such schemes, it is possible to provably trace the leaked secret shares back to the servers who leaked them. Goyal et al. presented the first construction of a traceable secret sharing scheme. However, secret shares in their construction are quadratic in the secret size, and their tracing algorithm is quite involved as it relies on Goldreich-Levin decoding.

In this work, we put forth new definitions and practical constructions for traceable secret sharing. In our model, some f<tf < t servers output a reconstruction box RR that may arbitrarily depend on their shares. Given additional t−ft-f shares, RR reconstructs and outputs the secret. The task is to trace RR back to the corrupted servers given black-box access to RR. Unlike Goyal et al., we do not assume that the tracing algorithm has any information on how the corrupted servers constructed RR from the shares in their possession.

We then present two very efficient constructions of traceable secret sharing based on two classic secret sharing schemes. In both of our schemes, shares are only twice as large as the secret, improving over the quadratic overhead of Goyal et al. Our first scheme is obtained by presenting a new practical tracing algorithm for the widely-used Shamir secret sharing scheme. Our second construction is based on an extension of Blakley's secret sharing scheme. Tracing in this scheme is optimally efficient, and requires just one successful query to RR. We believe that our constructions are an important step towards bringing traceable secret-sharing schemes to practice. This work also raises several interesting open problems that we describe in the paper.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper3

问问它们各自怎么用它

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖