On dealer-free dynamic threshold schemes

Mehrdad Nojoumian, Douglas R. Stinson · Advances in Mathematics of Communications · 2013

In a threshold scheme, the sensitivity of the secret as well as the number of players may fluctuate due to various reasons, e.g., mutual trust may vary or the structure of the players' organization might be changed. A possible solution to this problem is to modify the threshold and/or change the secret. Moreover, a common problem with almost all secret sharing schemes is that they are 'one-time', meaning that the secret and shares are known to everyone after a public secret recovery process. This problem could be resolved if the dealer shares various secrets at the beginning, but a better solution is to dynamically generate new secrets in the absence of the dealer. These issues are our main motivation to revisit dynamic threshold schemes. Therefore, we first provide the first comprehensive study of threshold modification techniques in both the passive and active adversary models. We first review an existing method for threshold modificationbased on resharing shares of a secret; this method is secure in the setting of a passive adversarialcoalition. We then discuss two methods, termed public evaluation (for thresholdreduction) and zero addition (for threshold increase) that can be used in both the passive andactive adversarial setting. In the case of an active adversary, the techniques makeuse of verifiable secret sharing schemes, whereas the schemes considered in the passiveadversary model are all based on the Shamir scheme.As an application, we discuss how the threshold and the secret can be changed multiple timesto arbitrary values after the scheme's initialization.

Read the paper · More papers on PaperTik