Proactive secret sharing and public key cryptosystems

Stanisław Jarecki · DSpace@MIT (Massachusetts Institute of Technology) · 1995

Secret sharing schemes protect secrecy and integrity of information by dividing it into shares and distributing these shares among different locations. In k + 1 out of n threshold schemes, security is assured if throughout the entire life-time of the secret the adversary compromises no more than k of the n locations. For long-lived and sensitive secrets this protection may be insufficient. We propose a new type of secret sharing scheme, called proactive, in which the share holders periodically (e.g. once a day) rerandomize the distribution of the secret into shares in such a way that if the adversary learns no more than k shares before the rerandomization, this information is useless for attacking the secret afterwards. In other words, the adversary willing to learn or destroy the secret has to break to at least k + 1 locations during the same time period, i.e. between consecutive executions of the rerandomization protocol. We extend proactive secret sharing schemes to function shari...

Read the paper · More papers on PaperTik