Sebery J.Cryptography.An introduction to computer security.1989
.pdf9.4 Information Rate |
341 |
Shamir threshold schemes assign shares and the secret from the same set (normally from GF (p)) so their information rate is one. On the other hand, secret sharing based on cumulative arrays tends to produce much longer shares. Threshold schemes are ultimate example of the ineÆciency of cumulative arrays.
De nition 31. A perfect secret sharing scheme is ideal if i = 1; so the length of the secret equals to the length of a share held by a participant. In this case,
= ~ = 1.
9.4.1 Upper Bounds
It is interesting to nd secret sharing schemes whose information rates are higher than those obtained using Ito-Saito-Nishizeki or Benaloh-Leichter constructions for general access structures. There is also a more fundamental question about existence of perfect secret sharing for a given information rate or more precisely, what are upper bounds on information rates beyond which, perfect secret sharing simply does not exist. Secret sharing that attains the upper bounds on information rates is called optimal. The nonexistence argument is developed by using tools (entropy) from Information Theory. Upper bounds are important for designers of secret sharing schemes. Knowing the bounds, the designers may in the rst attempt, obtain the optimal scheme. If, however, this turns out to be diÆcult, the designers may be satis ed with a scheme whose information rates are \close" enough to the upper bounds.
Benaloh and Leichter [24] observed that there are access structures for which there is no ideal scheme. The access structure with the base 0 = ffP1; P2g; fP2; P3g; fP3; P4gg is in this category. Capocelli, De Santis, Gargano, and Vaccaro rst showed in [75] how to get upper bounds on information rates. To simplify our notation, we are going to denote the entropy of the random variable that represents the share associated with the participant P 2 P by H(P ) instead of H(SP ). The entropy of the secret is H(K). First we prove two lemmas.
Lemma 15. Let Y 2= and X [ Y 2 . Then
H(X j Y) = H(K) + H(X j Y; K):
Proof. Note that H(X ; K j Y) can be written in two ways (Section 2.4.1):
H(X; K j Y) = H(X j Y) + H(K j X; Y)
342 9 SECRET SHARING or
H(X; K j Y) = H(K j Y) + H(X j Y; K)
Thus we get the following sequence: |
|
H(X j Y) + H(K j X; Y) = H(K j Y) + H(X j Y; K) |
|
H(X j Y) = H(K j Y) + H(X j Y; K) H(K j X; Y) |
(9.4) |
As X [ Y 2 so H(K j X ; Y) = 0. On the other hand the scheme is perfect and Y 2= so H(K j Y) = H(K) and the nal result follows. tu
Lemma 16. Let X [ Y 2= , then
H(Y j X) = H(Y j X ; K)
Proof. According to Equation (9.4) from Lemma 15, we have
H(X j Y) = H(K j Y) + H(X j Y; K) H(K j X; Y):
Note that H(K j Y) = H(K) and H(K j X; Y) = H(K) so H(Y j X ) = H(Y j
X ; K). ut
Now we are ready to prove the main result.
Theorem 43. [75] Given access structure
= cl(ffP1; P2g; fP2; P3g; fP3; P4gg)
for four participants P1; P2; P3; P4. Then the inequality
H(P2) + H(P3) 3H(K)
has to be satis ed for any perfect secret sharing over .
Proof. First observe that secret sharing is perfect so the following equations are true:
1. H(KjP1; P2) = H(KjP2; P3) = H(KjP3; P4) = 0
2. H(KjP1) = H(KjP2) = H(KjP3) = H(KjP1; P3) = H(KjP1; P4) = H(KjP2; P4) = H(K)
Consider the set fP1; P3; P4g 2 . The set fP1; P4g 2= so from Lemma 15, we have
H(P3 j P1; P4) = H(K) + H(P3 j P1; P4; K):
9.4 Information Rate |
343 |
This is a starting point of the following sequence of inequalities:
H(K) = H(P3 j P1; P4) H(P3 |
j P1; P4; K) |
|
|||||
H(P3 j P1; P4) |
|
|
|
|
|
|
entropy is non-negative |
H(P3 j P1) |
|
|
|
|
|
|
as H(P3 j P1; P4) H(P3 j P1) |
= H(P3 j P1; K) |
|
|
|
|
|
|
from Lemma 16 |
= H(P2; P3 j P1; K) H(P2 j P1; P3; K) |
|
||||||
H(P2; P3 j P1; K) |
|
|
|
|
|
|
entropy is non-negative |
= H(P2 j P1; K) + H(P3 j |
P1; P2; K) |
|
|||||
H(P2 j P1; K) + H(P3 |
j |
P2; K) |
|
as H(P3 j P1; P2; K) H(P3 j P2; K) |
|||
= H(P2 j P1) H(K) + H(P3 j P2) H(K) |
from Lemma 15 |
||||||
H(P2) + H(P3 j P2) |
|
2H(K) |
|
as H(P2 j P1 ) H(P2) |
|||
= H(P2) + H(P2; P3) |
|
H(P2) |
|
2H(K) |
as H(P2; P3) = H(P2) + H(P3 j P2) |
||
= H(P2; P3) 2H(K) |
|
|
|
|
|
|
|
Thus we have
3H(K) H(P2; P3) = H(P2) + H(P3 j P2) H(P2) + H(P3) which concludes our proof. ut
Corollary 5. Given access structure = cl(ffP1; P2g; fP2; P3g; fP3; P4gg). Then for any secret sharing, the information rate 23 and ~ 56 .
Proof. Note that H(P1) H(K) and H(P4) H(K) must hold according to Theorem 40. Clearly,
H(P2) |
|
|
H(P3) |
|
|
|
|
||
H(K) 1 and |
H(K) 1 |
|
|
|
|
||||
Adding the two inequalities, we obtain |
|
||||||||
H(P2) + H(P3) |
2 1 |
|
|
|
|
||||
H(K) |
|
|
|
|
|||||
From Theorem 43 we have that H(P2) + H(P3) 3H(K) so |
|
||||||||
2 |
|
|
|
|
|
|
|
|
|
3: |
|
|
|
|
|
|
|
|
|
This also means that 2 |
2 |
and 3 |
|
2 |
. As we noted above 1 |
1 and 4 1. |
|||
3 |
3 |
||||||||
Consequently, ~ |
5 |
. |
tu |
|
|
|
|
||
6 |
|
|
|
|
|||||
Consider the following collection of access structures:
344 9 SECRET SHARING
1 = cl(ffP1; P2g; fP2; P3g; fP3; P4g; fP2; P4gg)2 = cl(ffP1; P2g; fP2; P3g; fP1; P3; P4gg)
3 = cl(ffP1; P2g; fP2; P3g; fP1; P3; P4g; fP2; P4gg)
In a similar way to Theorem 43, it can be shown that the hypotheses of Theorem 43 is also valid for the access structures 1; 2; 3. So their information rates are also smaller or equal to 23 and ~ = 56 .
9.4.2 Ideal Schemes
Ideal secret sharing attains the best possible information rate ~ = = 1. Now we are going to discuss the construction of ideal schemes using a linear vector space by Brickell [66] (this idea is also credited to Simmons [474]).
Recall the Shamir scheme with the polynomial f(x) = a0 + a1x + : : : + at 1xt 1 over GF (p). The share is
si = f(xi) = a0 + a1xi + : : : + at 1xti 1:
This can be equivalently rewritten as
si = (a0; a1; : : : ; at 1) (1; xi; : : : ; xti 1) = a xi
where vectors a and xi belong to the vector space GF (pt). Each participant Pi is assigned the public vector xi and the secret share si = a xi, the inner product of the two vectors.
Brickell [66] observed that ideal secret sharing schemes can be designed in a vector space GF (pt). His method generalizes the Shamir approach. Given a vector space GF (pt).
1.Let a function : P ! GF (pt) assign a public vector xi to Pi 2 P in such a way that
8B2 (1; 0; : : : ; 0) = b1x1 + b2x2 + : : : + btxt |
(9.5) |
||
|
|
t |
). |
for some public vector b = (b1 |
; b2; : : : ; bt) 2 GF (p |
||
2. The vector (1; 0; : : : ; 0) cannot be expressed as a linear combination of vec- |
|||
tors xi if the subset |
= . |
|
|
|
B 2 |
|
|
The dealer rst determines the vector space, the function and the collec-
tion of public vectors x1 = (P1); : : : ; xn = (Pn) where n = jPj. Don also selects at random t elements of GF (p) { let them be a1; : : : ; at. The vector
9.4 Information Rate |
345 |
a = (a1; a2; : : : ; at) and the secret k = a (1; 0; : : : ; 0) = a1. The share assigned to Pi is
si = a xi |
|
(9.6) |
for i = 1; : : : ; n. |
|
|
At the pooling time, participants submit their shares to the combiner. |
||
1. If the subset B 2 |
|
|
, Clara takes the public vector b = (b1 |
; : : : ; bt) such that |
|
(1; 0; : : : ; 0) = b1x1 + b2x2 + : : : + btxt:
She multiplies both sides of the equation by the vector a and using Equation (9.6) she calculates the secret
|
t |
|
|
|
t |
|
|
|
k = |
X |
bia |
xi = |
X |
bisi |
: |
||
i=1 |
i=1 |
|||||||
|
|
B 2 |
jBj |
|
||||
2. If the subset |
|
= and |
|
= r (r < t), then Clara gets r linear equations |
||||
xi a = si for Pi |
2 B |
|
|
|||||
in the t unknowns (a1; : : : ; at). The secret k = a1 cannot be found as
6
(1; 0; : : : ; 0) = b1x1 + b2x2 + : : : + btxt for any vector b = (b1; : : : ; bt).
The vector space construction is easy to implement if a suitable function can be found. Unfortunately, for a general access structure, there is no general algorithm known, which would allow to nd suitable functions eÆciently.
Consider the access structure = cl(ffP1; P2; P3g; fP1; P4gg) over four participants. Let GF (pt) be selected for t = 3 and for some big enough p. Assume the following assignment of public vectors:
(P1) = x1 = (0; 1; 1)(P2) = x2 = (0; 1; 0)(P3) = x3 = (1; 0; 1)
(P4) = x4 = ( 1; 1; 1)
First we check whether any minimal authorized set B 2 can get the vector (1; 0; 0) by a linear combination of its public vectors.
{ If B = fP1; P2; P3g, then
(1; 0; 0) = x3 + x2 x1 = (1; 0; 1) + (0; 1; 0) (0; 1; 1):
346 9 SECRET SHARING
{ If B = fP1; P4g, then
(1; 0; 0) = x4 x1 = (1; 1; 1) (0; 1; 1):
Next we have to verify that any B 2= is not able to determine the vector (1; 0; 0). We choose the maximal unauthorized subsets, i.e. those which become authorized after adding any single participant to them. These subsets are fP1; P2g, fP1; P3g, and fP2; P3; P4g.
{ If B = fP1; P2g, then we are looking for b1; b2 2 GF (p) such that
?
b1x1 + b2x2 = b1(0; 1; 1) + b2 (0; 1;0) = (1; 0; 0)
which clearly has no solution.
{ If B = fP1; P3g, then we are looking for b1; b3 2 GF (p) such that
?
b1x1 + b3x3 = b1(0; 1; 1) + b3 (1; 0;1) = (b3; b1; b1 + b3 ) = (1; 0; 0):
To satisfy the equation, b3 = 1 and b1 = 0 so the third component b1 + b3 = 1 6= 0. So there is no such pair.
{ If B = fP2; P3; P4g, then we have to nd b2; b3; b4 2 GF (p) such that
?
b2x2 + b3x3 + b4x4 = (1; 0;0): This is equivalent to the system
b3 b4 = 1 b2 b4 = 0 b3 b4 = 0
which has no solution.
Finally, knowing the public vectors xi, the dealer selects at random a vector a. Let it be a = (12; 17; 6) over GF(19). The collection of shares are:
s1 = a x1 = (12; 17; 6)(0; 1; 1) = 23; s2 = a x2 = (12; 17; 6)(0; 1; 0) = 17; s3 = a x3 = (12; 17; 6)(1; 0; 1) = 18;
s4 = a x4 = (12; 17; 6)( 1; 1; 1) = 3:
The secret k = a (1; 0; 0) = 12. Recovery of the secret is possible only when the vector (1; 0; 0) is a linear combination of public vectors xi for some i. So for B = fP1; P2; P3g, we know that (1; 0; 0) = x3 + x2 x1. If a combiner knows the shares s1; s2 and s3, the secret k = a(1; 0; 0) = a(x3 + x2 x1)= s3 + s2 s1 = 18 + 17 23 12 mod 19.
9.4 Information Rate 347
9.4.3 Non-ideal Optimal Secret Sharing
Consider secret sharing over the access structure whose upper bound on information rates are di erent from 1. Clearly, it is impossible to design ideal schemes (as they do not exist). It makes sense, however, to investigate how the optimal scheme can be constructed.
Consider the access structure = cl(ffP1; P2g; fP2; P3g; fP3; P4gg) whose upper bound on information rate is 2=3. Using the Ito-Saito-Nishizeki
construction, we get:
s1 s2 s3
P1 1 0 0
P2 0 1 1
P3 1 1 0
P4 0 0 1
In other words, the participants hold the following shares
P1 ! fs1g
P2 ! fs2; s3g
P3 ! fs1; s2g
P4 ! fs3g
where si 2 T are share tokens; i = 1;2; 3; 4. Note that for any B 2 , the members of B have the complete collection fs1; s2; s3; s4g that allows them to recover the secret
3
k = X si
i=1
as in the Karnin-Greene-Hellman scheme where k; si 2 GF (p). The information rate of the scheme is = 12 , which is smaller then optimal.
The information rates of the scheme can be improved if we give the participant P3 a single share token s1 + s2 so the distribution of tokens is as follows:
s1 s2 s3 s1 + s2
P1 |
1 |
0 |
0 |
0 |
P2 |
0 |
1 |
1 |
0 |
P3 |
0 |
0 |
0 |
1 |
P4 |
0 |
0 |
1 |
0 |
There is also the second variant with the same information rates for which P2 gets a single token. This variant can be represented as:
348 9 SECRET SHARING
s1 s2 s3 s2 + s3
P1 |
1 |
0 |
0 |
0 |
P2 |
0 |
0 |
0 |
1 |
P3 |
1 |
1 |
0 |
1 |
P4 |
0 |
0 |
1 |
0 |
Assume that our scheme is used for the secret k = (k1; k2) 2 GF (p) GF (p). Now we use the rst variant for k1 2 GF (p) and the second for k2 2 GF (p). The secret sharing is illustrated below.
s11 s12 s13 s11 + s12 s21 s22 s23 s22 + s23
P1 |
1 |
0 |
0 |
0 |
1 |
0 |
0 |
0 |
P2 |
0 |
1 |
1 |
0 |
0 |
0 |
0 |
1 |
P3 |
0 |
0 |
0 |
1 |
1 |
1 |
0 |
0 |
P4 |
0 |
0 |
1 |
0 |
0 |
0 |
1 |
0 |
In other words, the participants hold the following shares (collections of tokens):
The information rates are 1 = 4 = 1 and 2 = 3 = 23 . So = 23 and ~ = 56 . This is an optimal scheme. The approach presented is taken from [84]. Some other methods for optimal secret sharing are based on the ideal decomposition and the linear programming [495].
9.5 Extended Capabilities
So far we have studied fundamental properties and constructions of secret sharing. In many circumstances, secret sharing is expected to provide extra functionality. Here is a list that shows some examples.
{The scheme is set up collectively by all participants (there is no single entity called the dealer).
{The parameters of secret sharing need to be modi ed. The modi cation typically includes admission of a new participant to the group (enrollment), removal of a participant from the group (disenrollment), change of the access structure (say increment or decrement of the threshold parameter).
9.5 Extended Capabilities |
349 |
{Shares in long-lived secret sharing are subject to numerous risks related to their loss or corruption. These risks, although negligible for secret sharing whose life-span is short (say a week/month), tend to cumulate over the time and cannot be ignored for long-lived secret sharing (whose life-span is years or tens of years). Proactive secret sharing allows us to recover lost shares by running (collectively) a share refreshment protocol.
{Veri able secret sharing allows participants to check whether shares they are given by the dealer are consistent with other shares and the secret.
{Cheating prevention in which a dishonest participant intentionally modi es shares in such a way that after the combiner announces the secret, the cheating participant is able to compute it.
Let us consider the cheating problem. So far we have assumed that all participants are honest and follow the recovery protocol of the secret. Tompa and Woll [510] studied the problem of cheaters who do not obey the protocol. Although they analyzed the susceptibility of the Shamir scheme to cheating, their results can be easily extended to many other implementations of secret sharing.
Given a (t; n) Shamir scheme with a polynomial f(x) = a0 + a1x + over GF (p). Assume that at the pooling time, there are t cooperating participants P1; : : : ; Pt who wish to reconstruct the secret. Among
them there is a cheater, say P1, who wants to submit a false share. The share is modi ed in a such way that after the combiner announces the reconstructed (incorrect) secret, P1 can correct it and recreate the correct value of the secret.
How can the cheater P1 modify his share? Assume that P1 knows all cooperating participants so he knows the set fP1; P2; : : : ; Ptg. P1 can now use the public information to determine a polynomial (x) such that
(0) = Æ; (x2) = 0; : : : ; (xt) = 0:
This can be easily done using Lagrange interpolation. The cheater computes(x1) and creates his false share
s~1 = s1 + (x1):
P1 submits s~1 to the combiner. Clara takes all shares s~1; s2; : : : ; st and deter-
~
mines the polynomial f(x) + (x) and the secret k = f (0) + (0) = k + Æ that is clearly di erent from the original. Nobody except the cheater can get the
~
true secret k = k Æ. Cheating will be undetected.
350 9 SECRET SHARING
How can the Shamir scheme be modi ed so it is immune against this type of cheating ? One solution is that the points x1; : : : ; xn have to be made secret as well. So the share is the pair si = (xi; f(xi)) and is kept secret by Pi. The selection of x1; : : : ; xn is done by the dealer at random from all permutations of n distinct elements from GF (p) n f0g. Now if ` participants cheat (` t 1), there is an overwhelming probability that the recovered secret is a random value that cannot be corrected by the cheaters. Note that the cost is the increase of share size.
9.6 Problems and Exercises
1. Design a (4; 5) Shamir threshold scheme over GF(787). Choose at random all coeÆcients of the polynomial f(x) and determine shares for the participants. Assume that you are a combiner. A collection of three participants P2, P4 and P5 provided their shares so you know three points on the parabola. Let them be (2; 123), (4; 345), and (5; 378). Find out the polynomial and the secret assuming that the threshold is 3 and arithmetic is done in GF(787).
2. Consider the modular threshold scheme with the parameters p0 = 97, p1 = 101, p2 = 103, p3 = 107, p4 = 109.
{ Given the secret k = 72 and s1 = 54. Compute the rest of shares providing the threshold t = 2 (n = 4).
{ A combiner is given two shares s2 = 51 and s4 = 66 and the threshold is 2, what is the secret?
3. Take an instance of the Karnin-Greene-Hellman scheme. { Design a system for t = 7 over GF(101).
{ What is the secret if t = 5 and shares are s1 = 23, s2 = 75, s3 = 13, s4 = 86 and s5 = 56 in GF(101)?
4. Suppose that P = fA; B; C; Dg and the access structure basis 0 = ffA; Bg; fB; Cg; fC; Dgg. Write down a full expression for the access structure (or = cl( 0)).
5. Given the access structure bases
{ 0 = ffA; Bg; fB; Cg; fB; Dg; fC; Dgg; { 0 = ffA; Bg; fB; Cg; fC; Dgg;
{ 0 = ffA; B; Cg; fA; B; Dgg.
Construct cumulative arrays for the above access structures. Using the share assignments provided by the corresponding cumulative arrays and the Karnin-Greene-Hellman scheme, show how to design secret sharing schemes for the above access structures.
Design secret sharing for the above access structures using the Benaloh-Leichter construction. Compare the resulting schemes with the schemes obtained using cumulative arrays.
