<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">IJCNS</journal-id><journal-title-group><journal-title>International Journal of Communications, Network and System Sciences</journal-title></journal-title-group><issn pub-type="epub">1913-3715</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/ijcns.2014.71003</article-id><article-id pub-id-type="publisher-id">IJCNS-42075</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Asynchronous Secret Reconstruction and Its Application to the Threshold Cryptography
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>ein</surname><given-names>Harn</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Changlu</surname><given-names>Lin</given-names></name><xref ref-type="aff" rid="aff2"><sup>2</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib></contrib-group><aff id="aff1"><addr-line>Department of Computer Science Electrical Engineering, University of Missouri-Kansas City, Kansas City, USA</addr-line></aff><aff id="aff2"><addr-line>School of Mathematics and Computer Sciences, Fujian Normal University, Fuzhou, China</addr-line></aff><author-notes><corresp id="cor1">* E-mail:<email>cllin@fjnu.edu.cn(CL)</email>;</corresp></author-notes><pub-date pub-type="epub"><day>06</day><month>01</month><year>2014</year></pub-date><volume>07</volume><issue>01</issue><fpage>22</fpage><lpage>29</lpage><history><date date-type="received"><day>October</day>	<month>26,</month>	<year>2013</year></date><date date-type="rev-recd"><day>November</day>	<month>26,</month>	<year>2013</year>	</date><date date-type="accepted"><day>December</day>	<month>3,</month>	<year>2013</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
     
   In Shamir’s(<em>t,n</em>)  threshold of the secret sharing scheme, a secret is divided into <em style="font-family:Verdana;text-align:justify;white-space:normal;">n </em>shares by a dealer and is shared among <em style="font-family:Verdana;text-align:justify;white-space:normal;">n </em>shareholders in such a way that (a) the secret can be reconstructed when there are <em>t </em>or more than <em style="text-align:justify;white-space:normal;">t </em>shares; and (b) the secret cannot be obtained when there are fewer than <em style="text-align:justify;white-space:normal;">t </em>shares. In the secret reconstruction, participating users can be either legitimate shareholders or attackers. Shamir’s scheme only considers the situation when all participating users are legitimate shareholders. In this paper, we show that when there are more than <em>t </em>users participating and shares are released asynchronously in the secret reconstruction, an attacker can always release his share last. In such a way, after knowing <em style="font-family:Verdana;text-align:justify;white-space:normal;">t</em> valid shares of legitimate shareholders, the attacker can obtain the secret and therefore, can successfully impersonate to be a legitimate shareholder without being detected. We propose a simple modification of Shamir’s scheme to fix this security problem. Threshold cryptography is a research of group-oriented applications based on the secret sharing scheme. We show that a similar security problem also exists in threshold cryptographic applications. We propose a modified scheme to fix this security problem as well.  
      
   
    
   
    
 
</p></abstract><kwd-group><kwd>Shamir’s(&lt;i&gt;t</kwd><kwd>n&lt;/i&gt;)Secret Sharing Scheme; Secret Reconstruction; Threshold Cryptography; Threshold Decryption; Asynchronous Networks</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>Secret sharing schemes (SSs) were first introduced by both Blakley [<xref ref-type="bibr" rid="scirp.42075-ref1">1</xref>] and Shamir [<xref ref-type="bibr" rid="scirp.42075-ref2">2</xref>] separately in 1979 as a solution for safeguarding cryptographic keys and have been studied extensively in the literature. SS has become one of the most basic tools in cryptographic research. In Shamir’s <img src="3-9701810x\9ea1f706-080b-4b8c-994e-4e4bea16bf42.jpg" /> SS, a secret, <img src="3-9701810x\eee8eb8e-f2bc-4403-a5ff-2ccc233c0121.jpg" />is divided into <img src="3-9701810x\9d956281-934a-429b-93bc-04cadd4226da.jpg" /> shares by a dealer and shares are sent to shareholders secretly. The security requirements of a <img src="3-9701810x\a5e3f24f-90c2-41ad-bc44-c45ce73dd0d6.jpg" /> SS satisfy that (a) the secret can be reconstructed when there are <img src="3-9701810x\937302ee-aa57-458f-9cd7-526f8ee248e3.jpg" /> or more than <img src="3-9701810x\59ec66d0-e46b-4d36-80a3-814f9316bddb.jpg" /> shares; and (b) the secret cannot be obtained when there are fewer than <img src="3-9701810x\1f24d2cc-00e0-43bb-8c96-44150c8d2a79.jpg" /> shares. Shamir’s <img src="3-9701810x\0f69c393-dd8c-4e11-b624-adb027262944.jpg" /> SS is based on the linear polynomial and is unconditionally secure. There are other types of SS. For example, Blakely’s scheme [<xref ref-type="bibr" rid="scirp.42075-ref1">1</xref>] is based on the geometry, Mignotte’s scheme [<xref ref-type="bibr" rid="scirp.42075-ref3">3</xref>] and Asmuth-Bloom’s scheme [<xref ref-type="bibr" rid="scirp.42075-ref4">4</xref>] are based on the Chinese Remainder Theorem (CRT).</p><p>In the secret reconstruction, participating users can be either legitimate shareholders or attackers. Shamir’s scheme only considers the situation when all participating users are legitimate shareholders. When there are more than <img src="3-9701810x\61c68385-7d52-4578-a28a-7b4e29e5b695.jpg" /> users participating and shares are released asynchronously in the secret reconstruction, an attacker can always release his share last. In such a way, after knowing <img src="3-9701810x\eaf50546-6829-43b0-98f9-0f4df8fb95bf.jpg" /> valid shares, the attacker can obtain the secret and therefore, can successfully impersonate to be legitimate shareholder without being detected. One simple way to overcome this security problem is to authenticate every participating user to be a legitimate sharesholder before reconstructing the secret. Since all user authentication schemes are one-to-one type of interactions between one prover and one verifier, this approach may slow down the secret reconstruction significantly especially when there are a large number of users who participated in the process.</p><p>In this paper, we propose a simple modification of Shamir’s scheme to fix the security problem in the secret reconstruction. Our solution does not use any user authentication. The secret can be reconstructed successfully only when all participating users are legitimate shareholders and release their shares honestly. If there are any attackers among participating users, the secret cannot be reconstructed by users since the attacker does not own any valid share. Furthermore, the attacker cannot obtain the secret from partially released valid shares of legitimate shareholders.</p><p>In Shamir’s <img src="3-9701810x\bd21560e-43cd-4b02-8da5-634c1f53ec09.jpg" /> SS, every share can only be used for one time to recover the secret. This is because once the secret has been recovered, then all shares released and the secret are no longer secret. Therefore, the <img src="3-9701810x\c9010163-452e-4cbc-9718-91ac29f87727.jpg" />SS is not very efficient. To improve its efficiency, the <img src="3-9701810x\63b276b6-285e-41a5-b5e2-244785d2a8f1.jpg" /> SS has been incorporated with public-key cryptography in the threshold cryptography. The group-oriented threshold cryptosystem was first introduced by Desmedt [<xref ref-type="bibr" rid="scirp.42075-ref5">5</xref>] in 1987. In such a system, each group, instead of each individual group member, publishes a single group public key. The corresponding private key of the group’s public key is divided into n shares and is shared among n group members following a <img src="3-9701810x\62fee991-c555-453b-84cb-29a4211324af.jpg" /> SS [1-4], where t is a predefined threshold value. Threshold cryptography is the study of efficient multiparty computation protocols for cryptographic functions (e.g. signing or decrypting), in which each group member has a share of the private key which allows the computation of such function. Threshold cryptography utilizes some computational assumptions, such as factoring a composite integer or solving the discrete logarithm, to enable shares of group members to be reused for multiple times. Similar to the <img src="3-9701810x\36e1af3e-8739-4aa7-a1cf-916d52b402ba.jpg" /> SS, participating users in a threshold cryptographic application can be either legitimate group members or attackers. All threshold cryptographic applications only consider the situation when all participating users are legitimate group members. When there are more than <img src="3-9701810x\89bcb318-48eb-43b0-8ba4-8b5a0e70ddba.jpg" /> users participating and values of users are released asynchronously in a threshold application, an attacker can always release his computed values last. In such a way, after knowing <img src="3-9701810x\50d726c4-dc66-466f-9f34-127162a20ae3.jpg" /> valid values of legitimate group members, the attacker can obtain the valid output of the cryptographic function and therefore, can successfully impersonate to be a legitimate group member without being detected. We also propose a modified scheme to fix this security problem.</p><p>Related Works. The security of cryptographic schemes/protocols can be classified into two types, computational security and unconditional security. Computational security assumes that the adversary has bounded computing power that limits the adversary to solving hard mathematical problem, such as factoring a large composite integer into two primes. Unconditional security means that the security holds even if the adversary has unbounded computing power. Research on developing cryptographic schemes/protocols with unconditional security has received wide attention recently. Shamir’s <img src="3-9701810x\871eb5a5-95ff-4eeb-afab-74a931d6f90c.jpg" /> SS scheme is based on a linear polynomial and is unconditionally secure.</p><p>Shamir’s <img src="3-9701810x\12fc2e1c-5c52-446a-8cc6-210beeea0b6d.jpg" /> SS is very simple; but if the secret reconstruction is performed over networks, possible threats make the secret reconstruction very complicate. In fact, attackers who do not own valid shares may impersonate to be shareholders who participated in the secret reconstruction. In 1985, Chor et al. [<xref ref-type="bibr" rid="scirp.42075-ref6">6</xref>] proposed the notion of verifiable secret sharing (VSS). VSS enables shareholders to verify that their shares are valid without revealing their shares. There are vast research papers on VSS [6-8] in the literature. VSS is a complicate process which requires additional information and processing time.</p><p>How the secret should be reconstructed fairly is another research problem. When all other participating shareholders honestly present their shares in the secret reconstruction process, a dishonest shareholder can always exclusively get the secret by presenting a fake share and thus the others get nothing but a fake secret. Although protocols have been developed to detect fake shares [9-12], they do not prevent a dishonest shareholder from gaining this advantage. Even if the cheater is detected, this problem still persists as the cheater has already obtained the secret. The first protocol to solve this problem is proposed by Tompa et al. [<xref ref-type="bibr" rid="scirp.42075-ref10">10</xref>]. Most fair secret reconstruction proposals share one basic idea that utilizes a process where information is revealed slowly [<xref ref-type="bibr" rid="scirp.42075-ref13">13</xref>]. Chaum et al. [<xref ref-type="bibr" rid="scirp.42075-ref14">14</xref>], and Beaver et al. [<xref ref-type="bibr" rid="scirp.42075-ref15">15</xref>] considered the general problem of fair multiparty computation. Most of these works are based on a computational model, i.e., some computational assumptions are used like the existence of an oblivious transfer protocol or the quadratic residuosity assumption. In 1995, Lin et al. [<xref ref-type="bibr" rid="scirp.42075-ref16">16</xref>] proposed the first fair secret reconstruction protocol in which the real secret can be reconstructed as a whole entity without simultaneously releasing constraint. Cheating immune SSs through which the cheaters gain no advantage over honest participants by submitting invalid shares, are proposed in [17,18]; but secret and shares are limited to be either binary or from <img src="3-9701810x\8c7e920b-d398-41f3-83ca-660b27d930f5.jpg" /></p><p>Our proposed scheme is not a VSS since in our scheme, shares are the only information of shareholders to prevent attackers from obtaining the secret and shares are not protected in the secret reconstruction. Furthermore, our proposed scheme cannot prevent a dishonest shareholder from presenting a fake share last in the secret reconstruction. In such a way, the dishonest shareholder can always exclusively get the secret but others get nothing but a fake secret. How the secret should be reconstructed fairly is a different research problem.</p><p>In a threshold signature scheme [<xref ref-type="bibr" rid="scirp.42075-ref19">19</xref>], when there are t or more than t group members, a group signature can be generated successfully. The group signature can be verified by any verifier using the group public key. On the other hand, in a threshold decryption scheme [20,21], any sender of a secret message can generate a cipher-text to the group using the group public key. When there are t or more than t group members, the group cipher-text can be decrypted successfully. All existing threshold cryptographic algorithms [19-26] only consider the situation when all participating users are legitimate group members. In this paper, we point out that when there are more than t participating users and computed valued are released asynchronously in a threshold application, an attacker can obtain the valid output of the application and therefore, can impersonate to be a legitimate group member without being detected.</p><p>We summarize the contributions of this paper in the following.</p><p>• We point out a security problem in Shamir’s <img src="3-9701810x\a74ca26b-3c40-4078-a02e-a85296902758.jpg" /> SS when there are more than t participating users and shares are released asynchronously in the secret reconstruction.</p><p>• A modified <img src="3-9701810x\3b0969ee-5f1f-47d5-b51f-d2fdede3ae5a.jpg" /> SS based on Shamir’s <img src="3-9701810x\9abf4a50-0fb9-4d9c-b57b-da25c88f8c3c.jpg" /> is proposed to fix the security problem.</p><p>• We point out a similar security problem in all existing threshold algorithms when there are more than t participating users in threshold applications.</p><p>• A modified threshold decryption is proposed to fix the security problem.</p><p>The rest of this paper is organized as follows. In Section 2, we review Shamir’s <img src="3-9701810x\636d7e3c-3a4d-4fb0-b2af-911a3eba5ded.jpg" /> SS scheme and point out a security problem in Shamir’s <img src="3-9701810x\36f87ca7-b2c1-4b18-8b71-e72ef8761925.jpg" /> SS. In Section 3, we present a modified SS to fix the security problem when there are more than t participating users and shares are released asynchronously in the secret reconstruction. In Section 4, we point out the similar security problem and propose a solution to fix the security problem of a threshold decryption scheme. We conclude in Section 5.</p></sec><sec id="s2"><title>2. Review of Shamir’s (t, n) SS [<xref ref-type="bibr" rid="scirp.42075-ref2">2</xref>]</title><p>In Shamir’s (t, n) SS based on a linear polynomial, the dealer D is responsible to select a secret and generate shares of the secret to n shareholders,</p><p><img src="3-9701810x\ecca60d0-3843-4431-aa6e-799705a8e953.jpg" />The scheme consists of two algorithms as illustrated in <xref ref-type="fig" rid="fig1">Figure 1</xref>.</p><p>Shamir’s SS satisfies security requirements of the (t, n) SS, that are, (a) the secret can be reconstructed with t or more than t shares; and (b) no information about the secret can be obtained with fewer than t shares. In other words, if there are exactly t legitimate shareholders participated in the secret reconstruction, Shamir’s scheme can recover the secret. Shamir’s secret reconstruction scheme can be generalized to take more than t shares. For example, if there are j (i.e.,<img src="3-9701810x\90193346-d6db-4972-a784-8e5ffbb2f728.jpg" />) participated shareholders with their shares, <img src="3-9701810x\8e52833f-8e3a-448f-82ea-f6abdf9a9dac.jpg" />in the secret reconstruction, the secret can be recovered as follows.</p><p><img src="3-9701810x\47952a35-134d-44eb-89a7-3c74af765e2f.jpg" /></p><p>During secret reconstruction, participated users can be either legitimate shareholders or attackers. Shamir’s scheme only considers the situation when all participated users are legitimate shareholders. When there are more than t users participated in the secret reconstruction and shares are released asynchronously, an attacker can always release his share last. After knowing t valid shares of legitimate shareholders, since the secret polynomial, <img src="3-9701810x\de031d65-5a71-4bed-8c3d-11b15dbb0d8f.jpg" />having degree<img src="3-9701810x\798cc5fb-0920-416a-984c-5d23888fb6b2.jpg" />, the attacker can reconstruct the secret. Furthermore, the attacker can successfully forge a valid share on the polynomial, <img src="3-9701810x\fa6eb731-16a0-43df-888c-f1d2c24439c7.jpg" />without being detected. Thus, Shamir’s (t, n) SS is no longer secure if there are more than t users participated in the secret reconstruction.</p></sec><sec id="s3"><title>3. Proposed (t, n) Secret Sharing Scheme</title><p>In this section, we propose a (t, n) SS to fix the security problem of Shamir’s (t, n) SS when there are more than t participated users and shares are released asynchronously</p><p>in the secret reconstruction. The outcome of our proposed secret reconstruction is either (a) the secret if all participated users are legitimate shareholders; or (b) not the secret if there are attackers. The basic idea is that the dealer in Shamir’s (t, n) SS scheme selects <img src="3-9701810x\95db1640-e440-4bbe-87d1-5db67c0ee250.jpg" /> (i.e., <img src="3-9701810x\c35f860d-012a-4d67-8e34-98ff3fb268ea.jpg" />for example, if <img src="3-9701810x\69cdf2de-d65a-4898-82d6-012cf2e344dc.jpg" /> <img src="3-9701810x\e63765af-6e62-4455-8b93-f9841ece4893.jpg" /> then <img src="3-9701810x\a63e36cf-e3ad-492e-914f-a009afc582de.jpg" /> We will prove this condition in Theorem 1) random polynomials, <img src="3-9701810x\432ccf36-22f7-47fd-bd73-b23bcf6c5119.jpg" />, having degree <img src="3-9701810x\85949d24-8a8e-4a9f-ac7e-4f956fa5bd07.jpg" /> each, and generates shares, <img src="3-9701810x\d0513aa8-c615-41a5-9ea5-68a45ce2c45a.jpg" />, for each shareholder, <img src="3-9701810x\70cb07c8-9392-4c48-9260-a1919edcc1f3.jpg" />where <img src="3-9701810x\6e2cfdca-8286-4dd0-b12c-e9f5821a3acb.jpg" /> is the public information of shareholder, <img src="3-9701810x\47d902ed-6814-420d-8147-12914fac51de.jpg" />For the secret, s, the dealer can always find integers, <img src="3-9701810x\5f945479-ea7a-4f7f-9d76-9eeef015e5d6.jpg" />in GF(p)such that <img src="3-9701810x\7573e41c-f1e4-4ccd-ad5b-d57c26c9da28.jpg" /> where <img src="3-9701810x\468b4455-157f-42ca-953c-c8dae500c322.jpg" /> for every pair of i and j, and <img src="3-9701810x\5274d579-773a-452e-82a4-69b7f4f79cec.jpg" /> The dealer makes these integers, <img src="3-9701810x\656022cd-b15a-4f3f-a32f-392be0e0ab95.jpg" />publicly known.</p><p>We assume that there are j (i.e.,<img src="3-9701810x\ffefe851-0756-4d6f-baca-b203cee4d880.jpg" />) participated shareholders, <img src="3-9701810x\159ff3e6-f1e9-4f60-b6bc-6e1704ee3e19.jpg" />in the secret reconstruction. Each shareholder <img src="3-9701810x\3b977d43-e842-4a8c-880f-0b3869cf19ef.jpg" /> uses his shares, <img src="3-9701810x\13ee2325-96b8-4d79-b226-ae53424474f4.jpg" />to compute and release one Lagrange component, <img src="3-9701810x\a3984b17-f755-476a-8a69-c3f00552a044.jpg" /></p><p>to other participants. After knowing <img src="3-9701810x\916f53f6-5078-4415-83fc-c5fdee289c7e.jpg" /> each shareholder can recover the secret as</p><p><img src="3-9701810x\60bb916d-108d-4b89-bd47-79b9bda7eb16.jpg" />We outline this scheme, Scheme 1, in</p><p><xref ref-type="fig" rid="fig2">Figure 2</xref>.</p><p>Theorem 1. The outcome of Scheme 1 is either (a) the secret when all participated users are legitimate shareholders; or (b) not the secret when there are attackers.</p><p>Proof. In Scheme 1, if all participated users are legitimate shareholders and act honestly to compute their Lagrange components, <img src="3-9701810x\4d252e83-4ca8-46ab-84b9-aa204d06918c.jpg" />in Step 1, then in Step 2, we get</p><p><img src="3-9701810x\adaaddad-0d19-4a73-a02e-7463d8d034cd.jpg" /></p><p>The outcome is the secret.</p><p>On the other hand, if there are attackers in the secret reconstruction, since attackers do not know any valid shares, the outcome of Scheme 1 is not the secret.</p><p>In the following discussion, we want to determine whether attackers can still recover the secret from partially released Lagrange components, <img src="3-9701810x\f46a9d4d-b1f1-4391-affd-bf23e035a7e3.jpg" />of legitimate shareholders. We analyze the security of the scenario which gives an attacker the most information to recover the secret. We assume that there are n users participated in the secret reconstruction and among them, there are <img src="3-9701810x\6c500216-4a81-42de-95f1-b34ac258424e.jpg" /> legitimate shareholders and the attacker is the last one to release his Lagrange component. Since each released Lagrange component is a linear function of kt coefficients of polynomials, <img src="3-9701810x\cdc95eb8-6a75-4dac-9fb7-f75c5c7a6da8.jpg" />having degree <img src="3-9701810x\27ae6b57-4d94-437c-95f0-9e2e0f3b9ecb.jpg" /> the attacker can obtain <img src="3-9701810x\0bc90b1f-4185-4bf6-9e21-8760ca4d5b6e.jpg" /> Lagrange components to form <img src="3-9701810x\7960dda4-88d5-4c24-8a92-80a34da6f8af.jpg" /> equations. The condition, <img src="3-9701810x\f36085e1-1f85-45d4-969b-f23f13cf89d3.jpg" />(i.e., kt is the number of unknown coefficients of polynomials, <img src="3-9701810x\8e2c88cb-d246-4d2a-a3d5-07e69b59ea4e.jpg" />having degree <img src="3-9701810x\f9f4d49a-2a8e-4d6c-9d0c-2a634ed22a9f.jpg" /> each), prevents the attacker solving the secret polynomials, <img src="3-9701810x\11325ff9-e06e-41c0-bd99-456399ec4d55.jpg" />Thus, the attacker cannot recover the secret in Scheme 1. We have come to this conclusion without making any computational assumption. Thus, the proposed scheme is unconditionally secure.■</p><p>Remark 1. For the secret, s, the dealer needs to select <img src="3-9701810x\80981a2a-9568-4879-87c9-dd7bd977a391.jpg" /> for every pair of i and j and the secret is</p><p><img src="3-9701810x\b2b2a6ad-18d1-4a0b-ad08-c0040639ae2a.jpg" />If <img src="3-9701810x\a2577c62-275d-4360-85be-e93cd0113620.jpg" /> for every pair of i and j, the attacker can still recover the secret after knowing t partially released Lagrange components, <img src="3-9701810x\dee97dec-603a-4bd0-81ff-1d5446043fe9.jpg" />of legitimate shareholders. This is because in this case, the secret, <img src="3-9701810x\cb697673-9283-4067-a3e6-b8a20c90b011.jpg" />is a share of the additive sum of polynomials, <img src="3-9701810x\b50f7c71-f2ae-4eee-af57-8068a252df96.jpg" />having degree <img src="3-9701810x\acca8114-0748-4133-ad6f-e6df6062b87b.jpg" /> Each participated shareholder, <img src="3-9701810x\b6f30bb3-96ff-46b7-9cf8-9b392e2c414e.jpg" />needs to use his shares to compute and release the Lagrange component,</p><p><img src="3-9701810x\65df9ece-e566-478b-afd2-8a5aa60e5394.jpg" />The attacker can recover the additive sum of shares, <img src="3-9701810x\1f4ceb4a-07f5-4f04-83b6-4b1c61f06596.jpg" />from each released Lagrange component <img src="3-9701810x\77442c00-64ca-472c-b08d-4ed7e517c983.jpg" /> Thus, after knowing t additive sum of shares, the attacker can recover secret as,</p><p><img src="3-9701810x\f7035c1d-5ec1-4f3c-92fb-1f8726b9f383.jpg" /></p></sec><sec id="s4"><title>4. Proposed Threshold Decryption Scheme</title><p>In this section, we present two <img src="3-9701810x\5641d008-fa1d-4ff7-a2ad-158b30caf708.jpg" /> threshold decryption schemes; one is a basic scheme and the other one is a modified scheme, in which the security of both schemes is based on the computational difficulty of solving the discrete logarithm problem. We use the basic scheme to point the security problem when there are more than t users participated in a threshold application. The threshold decryption scheme is one of the grouporiented threshold cryptographic algorithms. In this application, a group manager (GM), instead of each individual group member, publishes a single group public key. The corresponding private key of the group’s public key is divided into n shares and is shared among n group members. Then, any t or more than t group members can enable a threshold application.</p><sec id="s4_1"><title>4.1. Basic Scheme</title><p>We assume that there are <img src="3-9701810x\d80d2ec2-d678-4710-b5c2-f4ebcccda579.jpg" /> members, <img src="3-9701810x\b71a4493-e16d-4b1c-aeae-688ef852a565.jpg" />for</p><p><img src="3-9701810x\305adb4e-c662-4cb8-bd7b-ff69826ea3b9.jpg" />forming a group.</p><sec id="s4_1_1"><title>Initialization</title><p>The GM selects two large public primes, <img src="3-9701810x\8a862c37-a754-43ec-9ac3-14dd3831ac9a.jpg" />and<img src="3-9701810x\681b498b-cf64-4f53-95f1-bc2e56d08a60.jpg" />, such that <img src="3-9701810x\890ec659-a0ff-4a06-ae7a-7cf39f6b3aa0.jpg" /> divides <img src="3-9701810x\47bb6201-acd8-48ba-9cb8-d2639f8b850f.jpg" /> <img src="3-9701810x\555eeedb-8b49-470f-87c4-9a07c3814c77.jpg" /> is a unique subgroup of <img src="3-9701810x\d3556add-ca09-4157-81ff-c7e5171acb1f.jpg" /> with order<img src="3-9701810x\8d635a97-9f89-4726-9ec9-829924d107f8.jpg" />, and one public generator, <img src="3-9701810x\156ba62d-f94a-4901-a902-c84e7eec2763.jpg" />from <img src="3-9701810x\7ceeb464-589a-4f1e-9744-643bdffc5cbd.jpg" /> GM selects a private key, <img src="3-9701810x\658941af-0a1d-4e19-bb32-af6e4c9e3389.jpg" />and computes the public key of the group, <img src="3-9701810x\f971a47c-58ae-4f08-a6d8-bd4278ba0007.jpg" />GM acts like a dealer in Shamir’s <img src="3-9701810x\0abc5e18-e03c-439b-8c67-10486d7733f9.jpg" /> SS to select a random polynomial <img src="3-9701810x\3885a157-8f28-4514-bb6d-72749865afa2.jpg" /> of degree</p><p><img src="3-9701810x\eca4a5fb-2bce-4ec1-9aad-50856613dbf9.jpg" />: <img src="3-9701810x\a3230089-5b9f-4e7a-b2aa-b4dc19d85bbb.jpg" />such that the private key is <img src="3-9701810x\0b6f07fb-a7d8-493f-855c-ce3dda470a79.jpg" /> and all coefficients, <img src="3-9701810x\2938aff5-981b-4c42-8741-ef841c614551.jpg" />for <img src="3-9701810x\988b4199-badb-4c6e-af32-5d86a58e0e65.jpg" /> are in <img src="3-9701810x\aa954f15-f76e-4f01-96e4-2d5b21ece3d7.jpg" /> with <img src="3-9701810x\15c9f4a8-589e-43db-a18f-aaf4eba77355.jpg" /> GM computes <img src="3-9701810x\feb81795-af06-430e-a16b-d4d6eb035281.jpg" /> shares, <img src="3-9701810x\3c24548d-20cd-4674-a35b-9e1cff5a18e2.jpg" />where <img src="3-9701810x\109ddece-de4d-440b-baa3-a760341ece6e.jpg" /> is the public information associated with group member <img src="3-9701810x\bcb153b6-2b21-4b48-a583-d7b30e9af1e5.jpg" /> Each share, <img src="3-9701810x\07f30013-7ae5-477e-bd72-72ba13f40ecb.jpg" />is sent to group member, <img src="3-9701810x\8c47a875-e4df-45d8-bff7-40537e0e2cfa.jpg" />secretly.</p></sec><sec id="s4_1_2"><title>Generation of a cipher-text</title><p>We adopt the ElGamal’s encryption scheme [<xref ref-type="bibr" rid="scirp.42075-ref27">27</xref>]. With access to the group public key, <img src="3-9701810x\838d03d0-2984-4983-8aa9-304e2bf09325.jpg" />the sender can generate a cipher-text, <img src="3-9701810x\0a9d7898-c890-4fbd-be0b-a43ec17491b7.jpg" />of message m by computing <img src="3-9701810x\1bd90c69-d728-4a3f-802e-7b6305752120.jpg" /> where <img src="3-9701810x\d5e27921-6964-4379-948b-f2c5726c9626.jpg" /> is a random integer in <img src="3-9701810x\c5c48270-e6f2-46c5-b84f-4bc5077abb8a.jpg" /> and <img src="3-9701810x\da4c99b8-63a5-4f42-9a99-bfd74853a6ab.jpg" /> where <img src="3-9701810x\ab00f509-7414-4605-ad5d-6efaf89b32ee.jpg" /> The sender sends the cipher-text, <img src="3-9701810x\0ed81c93-183b-4dee-960b-f77ac6e5fb1a.jpg" />to the group.</p></sec><sec id="s4_1_3"><title>Decryption of a cipher-text</title><p>Let us assume that j (i.e.,<img src="3-9701810x\ba19ef71-6093-4f71-8abb-605a86b5ed74.jpg" />) group members,</p><p><img src="3-9701810x\fc88c78a-9884-4fd3-9bfd-91815b4ab6ba.jpg" />work together to decrypt a cipher-text.</p><p>Each group member, <img src="3-9701810x\4ce6f266-17a6-4347-8dfd-a8f4207e3d4b.jpg" />uses his private share, <img src="3-9701810x\b5a5e42f-865f-4dfa-a959-c3594bf9c662.jpg" />to compute a partial session key,</p><p><img src="3-9701810x\8033f821-b9f1-48b4-81f8-006267975209.jpg" />The value, <img src="3-9701810x\386475ab-f0e4-4012-b1d0-c63a2c1eff20.jpg" />is sent to other group members participated in the decryption. After collecting all partial session keys, the session key, <img src="3-9701810x\9b82e729-6411-477f-a246-a8003c90fc10.jpg" />can be computed as</p><p><img src="3-9701810x\7efc31c4-44a5-4119-a8e8-5d60c3be032c.jpg" /></p><p>Each participated group member can decrypt the ciphertext as <img src="3-9701810x\86e6978d-5978-4f84-94e8-35319782844a.jpg" /></p></sec><sec id="s4_1_4"><title>Security discussion</title><p>In a practical application, participated users in a threshold decryption can be either legitimate group members or attackers. We assume that an attacker has collected <img src="3-9701810x\ecbb86cc-6275-4ddd-8897-01c7adbe6083.jpg" /> valid partial session keys,</p><p><img src="3-9701810x\045043d7-c6a6-4cef-bd4e-a919ec68f36e.jpg" /></p><p>of legitimate group members. Then, the attacker can compute</p><p><img src="3-9701810x\7e316120-6a1b-422a-978a-1aaca0d1cd33.jpg" /></p><p>The real session key, <img src="3-9701810x\baa13864-5804-49da-a6a7-8c3c79de3df4.jpg" />can be obtained by computing <img src="3-9701810x\cb5fa66a-fcc2-424f-894d-288cedaf662c.jpg" /></p><p>Thus, the attacker can decrypt the cipher-text as</p><p><img src="3-9701810x\67a6de2f-af57-42f7-a3b0-154e35087e0f.jpg" />Furthermore, the attacker can successfully forge a valid partial session key of other legitimate group member, say <img src="3-9701810x\e4792fa2-b5fc-4f98-8270-8ebff1dc446f.jpg" /> as</p><p><img src="3-9701810x\28cc35ae-19b6-4fad-8dbb-a54524c304fb.jpg" /></p><p>without being detected in this process. The security problem of this basic scheme is caused by the fact that the modular exponentiation of each share, <img src="3-9701810x\32e3c07f-307b-43b3-97e5-05df52b72764.jpg" />can be obtained from the partial session key, <img src="3-9701810x\c8ec1e79-0031-4d30-bb73-96513ef02781.jpg" />With any <img src="3-9701810x\67c9ed8a-e9c4-47cc-8706-ac6670949dfc.jpg" /> modular exponentiations of shares, the attacker can successfully recover the modular exponentiation of the constant term of the polynomial and to recover the session key, <img src="3-9701810x\a023c9dd-7027-46f5-ad62-c8d9bb05abe1.jpg" />In the following subsection, we propose a simple modification to fix this security problem.</p></sec></sec><sec id="s4_2"><title>4.2. Modified Scheme</title><sec id="s4_2_1"><title>Initialization</title><p>GM selects two large public primes, <img src="3-9701810x\eccffd22-6689-4305-9f65-1cb0745e0b8f.jpg" />and<img src="3-9701810x\c218618a-9b06-4b23-88b1-4716c58d9d88.jpg" />, such that <img src="3-9701810x\aca4d8f9-0aa1-4bda-b12a-e5e1540b7c17.jpg" /> divides <img src="3-9701810x\e5ff0694-69ff-4c84-978d-16e023ad0211.jpg" /> <img src="3-9701810x\8d10d3df-057f-4d5a-b379-79758ba739b4.jpg" /> is a unique subgroup of <img src="3-9701810x\3026bccb-2033-4ee0-aaed-c858ac0f327b.jpg" /> with order<img src="3-9701810x\6437fd31-5014-4fc8-bd9e-f923f5d7f60b.jpg" />, and one public generator, <img src="3-9701810x\3af58421-4e01-48fa-a620-8041e7e5eacc.jpg" />from <img src="3-9701810x\8640747a-9309-4f2e-bbcf-5f99b8c18a8e.jpg" /> GM selects a private key, <img src="3-9701810x\ffae6bef-2819-4c23-a886-8e6614653a3d.jpg" />and computes the public key of the group,</p><p><img src="3-9701810x\b362613f-c3e2-4848-915d-6a70e65ad1c9.jpg" />GM acts like a dealer in Shamir’s <img src="3-9701810x\7cd50854-ebe7-4de8-a346-c564f6cc2e4a.jpg" /> SS to select two random polynomials, <img src="3-9701810x\b63b2e38-7c9e-4636-bb7e-3335ba409670.jpg" />and <img src="3-9701810x\9375fb6e-3a7b-4af1-b398-08e666db52e7.jpg" /> having degree <img src="3-9701810x\523367f6-cb5d-40e1-8ae3-fada18a7e635.jpg" /> each:</p><p><img src="3-9701810x\402af0b7-d7fb-476b-8ba3-03eda777d5e8.jpg" />and</p><p><img src="3-9701810x\e06219eb-f677-4232-871d-f8a56f6ac5ee.jpg" />such that the private key, <img src="3-9701810x\1b101afc-7a8c-49a7-aca1-801ba529c0a1.jpg" />is divided into <img src="3-9701810x\1ba8be6b-abfe-48fb-8cf0-e356e47e968d.jpg" /> with <img src="3-9701810x\3e6cc202-ec62-45c4-907f-c06adafc0402.jpg" /> and <img src="3-9701810x\b63d3a4d-bb1f-4de5-81c7-a42502c7aba0.jpg" /> all coefficients, <img src="3-9701810x\0b92def3-6860-4d19-88f0-b40129526da7.jpg" />and <img src="3-9701810x\835ea53e-b63d-4653-a649-082cff21a23c.jpg" /> for <img src="3-9701810x\e92d3e74-eee4-4172-9efc-b2036a7e6ba1.jpg" /> are in <img src="3-9701810x\2aff925f-8ca7-4cd8-ba7e-139b87628945.jpg" /> with <img src="3-9701810x\32203766-4999-420e-bb8e-f5b6887f7e26.jpg" /> GM computes a pair of shares, <img src="3-9701810x\a14401cd-201d-4742-b26d-348442c38498.jpg" />and <img src="3-9701810x\359681dc-b257-4c6e-b967-8a1b7cc0a8fc.jpg" /> for each shareholder, <img src="3-9701810x\bc178728-7020-492d-a8aa-a43b3bab3002.jpg" />where <img src="3-9701810x\c34fa998-24b1-4071-8d38-ef1235db6c87.jpg" /> is the public information associated with <img src="3-9701810x\beb18a7f-e6ee-48cb-8b6f-2b55b2d3f373.jpg" /> Each pair of shares, <img src="3-9701810x\285ff228-c35e-432c-8946-312dcdad1bd7.jpg" />and <img src="3-9701810x\5617c606-59ed-4d55-bcbb-d9cda5673d15.jpg" /> is sent to group member, <img src="3-9701810x\7d83386e-5c2e-44f0-a64f-17331d0bd2b1.jpg" />secretly.</p></sec><sec id="s4_2_2"><title>Generation of a cipher-text</title><p>This part of process is the same as the basic scheme. A group cipher-text, <img src="3-9701810x\94fa2082-f526-4982-baa2-caaa03f1fbc6.jpg" />of message m is generated by computing <img src="3-9701810x\bb964b8a-4fa8-482f-99cd-528a387d6312.jpg" /> and <img src="3-9701810x\a8571b74-ac33-4fab-b539-14944410d96e.jpg" /> where <img src="3-9701810x\162bda61-8e64-47a1-b401-a37103b9fa25.jpg" /> is a random integer from <img src="3-9701810x\f158e405-e38d-4a6b-90c7-e3e468a0129f.jpg" /> and</p><p><img src="3-9701810x\5064a898-c8cd-432a-8817-07eed3dea911.jpg" />The sender sends the cipher-text,</p><p><img src="3-9701810x\93b13a77-20f3-4d87-bb7d-50082c76144e.jpg" />to the group.</p></sec><sec id="s4_2_3"><title>Decryption of cipher-text</title><p>Let us assume that j (i.e.,<img src="3-9701810x\908ded7e-b4c4-42d1-b691-0b777b6782ef.jpg" />) group members, <img src="3-9701810x\44825baa-57c0-43d3-9fe6-378836a676ea.jpg" />work together to decrypt the ciphertext. Each group member, <img src="3-9701810x\3ad94285-ef71-48f4-b30b-879f4ba72062.jpg" />uses his pair of private shares, <img src="3-9701810x\842f5cee-3248-4124-b460-3806fac84f00.jpg" />and <img src="3-9701810x\d12aa1df-d37f-4944-a352-05e367c19b91.jpg" /> to compute a partial session key, <img src="3-9701810x\b2d6f3bd-4d76-4630-84d9-35c8696e1e08.jpg" />The value <img src="3-9701810x\2b7ea4e5-c28e-4425-88f4-e4d4a8c3141a.jpg" /> is sent to other participated shareholders. After collecting all partial session keys from other group members, the member can decrypt the cipher-text as <img src="3-9701810x\ceb9520d-258b-470d-85eb-3663836d8d97.jpg" /> We outline this scheme, Scheme 2, in <xref ref-type="fig" rid="fig3">Figure 3</xref>.</p><p>Theorem 2. In Scheme 2, if all participated users are legitimate group members and act honestly, the ciphertext, <img src="3-9701810x\793b6192-de4d-4ffb-aa7f-f6cea9135102.jpg" />of the message m can be decrypted successfully.</p><p>Proof. If all group members act honestly, the real session key, <img src="3-9701810x\ad5ff87f-b61a-4cd4-9ce8-9b8951a30601.jpg" />can be obtained as</p><p>The session key can be used to recover the message as<img src="3-9701810x\d7c88671-3c09-4055-82f1-b96efd9fdaea.jpg" />■</p></sec><sec id="s4_2_4"><title>Security discussion</title><p>In this modified scheme, the partial session key is</p><p><img src="3-9701810x\8ba3a987-6ccf-426c-9f5f-3fccfba00f4f.jpg" />Since the exponent of each partial session key is a linear combination of two shares, <img src="3-9701810x\b9de4b13-edca-452a-8ac7-06666751b0d2.jpg" />and <img src="3-9701810x\28fbd418-fb3c-4782-8e3a-1b90cd0c716d.jpg" /> attackers cannot separate these two shares to obtain the modular exponentiation of each share. In other words, attackers need to collect all partial session keys to be able to decrypt the cipher-text of the group. Therefore, if there are attackers participated in the decryption, the cipher-text cannot be decrypted.</p><p>We want to determine whether attackers can still decrypt the group cipher-text from a portion of partial session keys which are released from legitimate group members. There are 2t coefficients in polynomials, <img src="3-9701810x\ecc2c9b9-7dd0-4eba-893a-282b7d33c0a3.jpg" />and <img src="3-9701810x\d4709b40-b7f7-4001-91dd-280a1f8ae9bd.jpg" /> having degree <img src="3-9701810x\23bef514-6bf0-4d23-889e-348d5b293f8e.jpg" /> each. If an attacker can obtain <img src="3-9701810x\018a0809-33dc-4089-bc45-291a3efd0e6b.jpg" /> (i.e.,<img src="3-9701810x\cddbc5f6-f45d-479e-a2fe-d1cbec467b80.jpg" />) additive sum of shares, <img src="3-9701810x\a590df2f-310c-4abb-86d2-ba07345cca28.jpg" /></p><p>from released partial session keys, the attacker is able to solve both polynomials, <img src="3-9701810x\883a3ef6-ad4a-4f7b-a786-c422c52b5d18.jpg" />and <img src="3-9701810x\d75e4f46-9b8f-4dae-946b-5bb14b8b5a94.jpg" /> However, this attack is computational infeasible due to the difficulty of solving the discrete logarithm problem.</p><p>Remark 3. For any secret, s, the dealer needs to select two different points on the polynomials, <img src="3-9701810x\7ff625b1-2592-4b05-8708-68462d6c16a8.jpg" />and <img src="3-9701810x\45776c54-6719-40f2-951b-9a002e482d3f.jpg" /> for example, <img src="3-9701810x\6bb7fb4a-c9f9-4a71-aaed-d064af40b50e.jpg" />and <img src="3-9701810x\c5545946-bd13-4123-ab84-c0a89e2bbd03.jpg" /> If two points are the same such as <img src="3-9701810x\5a0b9d80-e5f8-410e-99b3-af786fdb5915.jpg" /> the secret, <img src="3-9701810x\62dbfde3-a236-40f2-9462-4798eec257f6.jpg" />is a share of the additive sum of polynomials, <img src="3-9701810x\aa55010f-21ca-466d-b5b2-cac7e595ee5b.jpg" />having degree <img src="3-9701810x\03947f6e-d28f-4c4d-982d-66f82ddcfa35.jpg" /> The partial session key of <img src="3-9701810x\a19e3ad2-cdd5-47b9-a765-e598cee72b7f.jpg" /> is <img src="3-9701810x\3e1a2e03-6769-4c10-93dd-aab7a43e9ee9.jpg" /> If one attacker has obtained <img src="3-9701810x\de68159c-dc8b-4fee-a76d-c871be29f6f0.jpg" /> partial session keys,</p><p><img src="3-9701810x\4a538fe1-1d62-40e2-8ed7-733f99345be0.jpg" />of legitimate group members, the attacker can compute</p><p><img src="3-9701810x\24c8b9e3-b2bd-41ef-bad5-1dcfd2159783.jpg" /></p><p>Therefore, the session key, <img src="3-9701810x\eb8a887b-0931-4a2e-9f87-b5a47b178736.jpg" />can be obtained by computing</p><p><img src="3-9701810x\211c3066-47c4-4c10-b620-bafab7cbf502.jpg" /></p></sec></sec></sec><sec id="s5"><title>5. Conclusion</title><p>We pointed out security problems of a (t, n) SS and a threshold algorithm. The security problems occurred when there are more than t participated users and shares/ values that are released asynchronously in the secret reconstruction/threshold application. Since all existing networks are asynchronous networks and we cannot exclude the probability that with more than t users participating in a secret reconstruction/threshold application, our paper has made significant contributions to addressing the security problems and proposing solutions. We believe that we have opened a new research direction in both the secret sharing and the threshold cryptography.</p></sec><sec id="s6"><title>Acknowledgements</title><p>This research is supported by the National Natural Science Foundations of China under Grant No. 61103247.</p></sec><sec id="s7"><title>REFERENCES</title></sec><sec id="s8"><title>NOTES</title></sec></body><back><ref-list><title>References</title><ref id="scirp.42075-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">G. R. Blakley, “Safeguarding Cryptographic Keys,” Proceedings of Americian Federation of Information Processing Societies (AFIPS’79) National Computer Conference, 25-28 February 1979, California, pp. 313-317.</mixed-citation></ref><ref id="scirp.42075-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">A. Shamir, “How to Share a Secret,” Academic Common Market, Vol. 22, No. 11, 1979, pp. 612-613.http://dx.doi.org/10.1145/359168.359176</mixed-citation></ref><ref id="scirp.42075-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">M. Mignotte, “How to Share a Secret,” CryptographyProceedings of the Workshop on Cryptography, Burg Feuerstein, 29 March-2 April 1982, pp. 371-375.</mixed-citation></ref><ref id="scirp.42075-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">C. A. Asmuth and J. Bloom, “A Modular Approach to Key Safeguarding,” IEEE Transactions on Information Theory, Vol. IT-29, No. 2, 1983, pp. 208-210.http://dx.doi.org/10.1109/TIT.1983.1056651</mixed-citation></ref><ref id="scirp.42075-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Y. Desmedtm, “Society and Group Oriented Cryptography: An New Concept,” Advances in Cryptography—7th Annual International Cryptology Conference (CRYPTO ’87), Santa Barbara, 16-20 August 1987, pp. 120-127.</mixed-citation></ref><ref id="scirp.42075-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">B. Chor, S. Goldwasser, S. Micali and B. Awerbuch, “Verifiable Secret Sharing and Achieving Simultaneity in the Presence of Faults,” Proceedings of the 26th IEEE Symposium on the Foundations of Computer Science, Portland, 21-23 October 1985, pp. 383-395.</mixed-citation></ref><ref id="scirp.42075-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">M. H. Dehkordi and S. Mashhad, “New Efficient and Practical Verifiable Multi-SSs,” Information Sciences, Vol. 178, No. 9, 2008, pp. 2262-2274.http://dx.doi.org/10.1016/j.ins.2007.11.031</mixed-citation></ref><ref id="scirp.42075-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">J. C. Benaloh, “Secret Sharing Homomorphisms: Keeping Shares of a Secret Secret,” Advances in Cryptology—6th Annual International Cryptology Conference (CRYPTO ‘86), Santa Barbara, 17-21 August 1987, pp. 251-260.</mixed-citation></ref><ref id="scirp.42075-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">E. F. Brickle and D. R. Stinson, “The Detection of Cheaters in Threshold Schemes,” Advances in Cryptology—9th Annual International Cryptology Conference (CRYPTO ‘88), Santa Barbara, 21-25 August 1988, pp. 564-577.</mixed-citation></ref><ref id="scirp.42075-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">M. Tompa and H. Woll, “How to Share a Secret with Cheaters,” Journal of Cryptology, Vol. 1, No. 3, 1988, pp. 133-138. http://dx.doi.org/10.1007/BF02252871</mixed-citation></ref><ref id="scirp.42075-ref11"><label>11</label><mixed-citation publication-type="other" xlink:type="simple">T. Rabin and M. Ben-Or, “Verifiable Secret Sharing and Multiparty Protocols with Honest Majority,” Proceedings of the 21st ACM Symposium on the Theory of Computing, Seattle, Washington DC, 14-17 May 1989, pp. 73-85.</mixed-citation></ref><ref id="scirp.42075-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">D. Chaum, C. Crepeau and I. Damgard, “Multipary Unconditionally Secure Protocols,” Proceedings of the 20th ACM Symposium on the Theory of Computing, Chicago, 2-4 May 1988, pp. 11-19.</mixed-citation></ref><ref id="scirp.42075-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">J. He and E. Dawson, “Shared Secret Reconstruction,” Designs, Codes and Cryptography, Vol. 14, No. 3, 1998, pp. 221-237. http://dx.doi.org/10.1023/A:1008200702849</mixed-citation></ref><ref id="scirp.42075-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">D. Chaum, I. Damgard and J. van de Graaf, “Multiparty Computations Ensuring Privacy of Each Party’s Input and Correctness of the Result,” Advances in Cryptography—7th Annual International Cryptology Conference (CRYPTO ’87), Santa Barbara, 16-20 August 1987, pp. 87-119.</mixed-citation></ref><ref id="scirp.42075-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">D. Beaver and S. Goldwasser, “Multiparty Computation with Faulty Majority,” Proceedings of the 30th IEEE Symposium on the Foundations of Computer Science, Research Triangle Park, North Carolina, 30 October-1 November 1989, pp. 468-473.</mixed-citation></ref><ref id="scirp.42075-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">H. Y. Lin and L. Harn, “Fair Reconstruction of a Secret,” Information Processing Letters, Vol. 55, No. 1, 1995, pp. 45-47. http://dx.doi.org/10.1016/0020-0190(95)00045-E</mixed-citation></ref><ref id="scirp.42075-ref17"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">J. Pieprzyk and X.-M. Zhang, “Cheating Prevention in Secret Sharing over  ” Progress in Cryptology— 2nd International Conference on Cryptology, Chennai, 16-20 December 2001, pp. 79-90.</mixed-citation></ref><ref id="scirp.42075-ref18"><label>18</label><mixed-citation publication-type="other" xlink:type="simple">J. Pieprzyk and X.-M. Zhang, “On Cheating Immune Secret Sharing,” Discrete Mathematics and Theoretical Computer Science, Vol. 6, No. 2, 2004, pp. 253-264.</mixed-citation></ref><ref id="scirp.42075-ref19"><label>19</label><mixed-citation publication-type="other" xlink:type="simple">L. Harn, “Group-Oriented (t, n) Threshold Digital Signature Scheme and Digital Multisignature,” IEE Proceedings—Computers and Digital Techniques, Vol. 141, No. 5, 1994, pp. 307-313.http://dx.doi.org/10.1049/ip-cdt:19941293</mixed-citation></ref><ref id="scirp.42075-ref20"><label>20</label><mixed-citation publication-type="other" xlink:type="simple">C. Delerablee and D. Pointcheval, “Dynamic Threshold Public-Key Encryption,” Advances in Cryptography—28th Annual International Cryptology Conference (CRYPTO ’08), Santa Barbara, 17-21 August 2008, pp. 317-334.</mixed-citation></ref><ref id="scirp.42075-ref21"><label>21</label><mixed-citation publication-type="other" xlink:type="simple">R. Bendlin and I. Damgard, “Threshold Decryption and Zero-Knowledge Proofs for Lattice-Based Cryptosystems,” Proceedings of 7th Theory of Cryptography Conference (TCC ‘10), Zurich, 9-11 February 2010, pp. 201-218.</mixed-citation></ref><ref id="scirp.42075-ref22"><label>22</label><mixed-citation publication-type="other" xlink:type="simple">L. Ertaul and W. Lu, “ECC Based Threshold Cryptography for Secure Data Forwarding and Secure Key Exchange in MANET (I),” Proceedings of the 4th IFIP-TC6 International Conference on Networking Technologies, Services, and Protocols; Performance of Computer and Communication Networks; Mobile and Wireless Communication Systems, Waterloo, 2-6 May 2005, pp. 102-113.</mixed-citation></ref><ref id="scirp.42075-ref23"><label>23</label><mixed-citation publication-type="other" xlink:type="simple">Y. Desmedt, “Some Recent Research Aspects of Threshold Cryptography,” Proceedings of the 1st International Workshop (ISW ‘97), Tatsunokuchi, 17-19 September 1997, pp. 158-173.</mixed-citation></ref><ref id="scirp.42075-ref24"><label>24</label><mixed-citation publication-type="other" xlink:type="simple">Y. Desmedt, “Threshold Cryptosystems,” Proceedings of the Workshop on the Theory and Application of Cryptographic Techniques (AUSCRYPT ‘92), Gold Coast, Queensland, 13-16 December 1992, pp. 1-14.</mixed-citation></ref><ref id="scirp.42075-ref25"><label>25</label><mixed-citation publication-type="other" xlink:type="simple">M. Abdalla, S. Miner and C. Namprempre, “Forwardsecure Threshold Signature Schemes,” Topics in Cryptology—The Cryptographer’s Track at RSA Conference (CT-RSA ‘01), San Francisco, 8-12 April 2001, pp. 441-456.</mixed-citation></ref><ref id="scirp.42075-ref26"><label>26</label><mixed-citation publication-type="other" xlink:type="simple">J. Baek and Y. Zheng, “Identity-Based Threshold Signature Scheme from the Bilinear Pairings,” Proceedings of the International Conference on Information Technology: Coding and Computing (ITCC ‘04), Las Vegas, 5-7 April 2004, p. 124.</mixed-citation></ref><ref id="scirp.42075-ref27"><label>27</label><mixed-citation publication-type="other" xlink:type="simple">T. A. ElGamal, “A Public-Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms,” IEEE Transactions on Information Theory, Vol. 31, No. 4, 1985, pp. 469-472.http://dx.doi.org/10.1109/TIT.1985.1057074</mixed-citation></ref></ref-list></back></article>