SlideShare a Scribd company logo
A Threshold Cryptosystem without a Trusted Party
Advances in Cryptology — EUROCRYPT ’91. EUROCRYPT 1991
Torben Pryds Pedersen
Aarhus University, Computer Science Department
林彥賓
2021/1/23
1. chooses at random and computes and brocast
2. each player opnen , the public key is
3. choose random polynomial of degree such that .
f (z) =
i f +
i,0 f z +
i,1 ... + f z
i,k−1
k−1
where
4. compute for and brocast
5. send secretely to for
6. verifies share received by by checking
Pi xi h =
i gxi
C =
i Com(h )
i
Ci h = h
∏i=1
n
i
Pi f (z)
i k − 1 f (0) =
i xi
f =
i,0 xi
Pi F =
i,j gfi,j
j = 0, ..., k − 1 Fi,j
Pi s =
i,j f (j)
i Pj j = 0, ..., k − 1
Pi Pj g =
si,j
F
∏ℓ=0
k−1
j,ℓ
iℓ
2
Set
Let be polynomid over
we know that for , thus is a share of
f (0), f (1), f (2), ..., f (k −
1 1 1 1 1)
+
...
+
f (0), f (1), f (2), ..., f (k −
k−1 k−1 k−1 k−1 1)
x = f(0), s =
1 f(1), ..., s =
k−1 f(k − 1)
s =
i s
∑j=1
n
j,i
f Z :
q f(z) = f (z) +
1 ... + f (z)
n
s =
i f(i) i = 1, ..., n si f(0) = x
3
For share of , can compute public key
σ =
i g =
j=1
∏
n
sj,i
(h F )
j=1
∏
n
j
ℓ=1
∏
k−1
j,ℓ
iℓ
si Pi
4

More Related Content

PDF
Technologies du lait et produits dérivés.pdf
PDF
3-Move Undeniable Signature Scheme
PDF
Distributed key generation protocol with hierarchical threshold access structure
PDF
One round threshold ecdsa with identifiable abort
PDF
Dynamic and verifiable hierarchical secret sharing
PDF
User Account Access Graphs
PDF
Fast Multiparty Threshold ECDSA with Fast TrustlessSetup
PDF
Threshold-optimal DSAECDSA signatures and an application to Bitcoin wallet se...
Technologies du lait et produits dérivés.pdf
3-Move Undeniable Signature Scheme
Distributed key generation protocol with hierarchical threshold access structure
One round threshold ecdsa with identifiable abort
Dynamic and verifiable hierarchical secret sharing
User Account Access Graphs
Fast Multiparty Threshold ECDSA with Fast TrustlessSetup
Threshold-optimal DSAECDSA signatures and an application to Bitcoin wallet se...

Recently uploaded (20)

PPTX
ANEMIA WITH LEUKOPENIA MDS 07_25.pptx htggtftgt fredrctvg
PDF
VARICELLA VACCINATION: A POTENTIAL STRATEGY FOR PREVENTING MULTIPLE SCLEROSIS
PDF
. Radiology Case Scenariosssssssssssssss
DOCX
Q1_LE_Mathematics 8_Lesson 5_Week 5.docx
PDF
Mastering Bioreactors and Media Sterilization: A Complete Guide to Sterile Fe...
PDF
SEHH2274 Organic Chemistry Notes 1 Structure and Bonding.pdf
PPTX
Vitamins & Minerals: Complete Guide to Functions, Food Sources, Deficiency Si...
PPTX
INTRODUCTION TO EVS | Concept of sustainability
PPTX
Taita Taveta Laboratory Technician Workshop Presentation.pptx
PPT
The World of Physical Science, • Labs: Safety Simulation, Measurement Practice
PDF
Biophysics 2.pdffffffffffffffffffffffffff
PPTX
Protein & Amino Acid Structures Levels of protein structure (primary, seconda...
PDF
An interstellar mission to test astrophysical black holes
PDF
Warm, water-depleted rocky exoplanets with surfaceionic liquids: A proposed c...
PPTX
The KM-GBF monitoring framework – status & key messages.pptx
PDF
HPLC-PPT.docx high performance liquid chromatography
PPT
6.1 High Risk New Born. Padetric health ppt
PDF
Unveiling a 36 billion solar mass black hole at the centre of the Cosmic Hors...
PPTX
EPIDURAL ANESTHESIA ANATOMY AND PHYSIOLOGY.pptx
PPTX
Introduction to Cardiovascular system_structure and functions-1
ANEMIA WITH LEUKOPENIA MDS 07_25.pptx htggtftgt fredrctvg
VARICELLA VACCINATION: A POTENTIAL STRATEGY FOR PREVENTING MULTIPLE SCLEROSIS
. Radiology Case Scenariosssssssssssssss
Q1_LE_Mathematics 8_Lesson 5_Week 5.docx
Mastering Bioreactors and Media Sterilization: A Complete Guide to Sterile Fe...
SEHH2274 Organic Chemistry Notes 1 Structure and Bonding.pdf
Vitamins & Minerals: Complete Guide to Functions, Food Sources, Deficiency Si...
INTRODUCTION TO EVS | Concept of sustainability
Taita Taveta Laboratory Technician Workshop Presentation.pptx
The World of Physical Science, • Labs: Safety Simulation, Measurement Practice
Biophysics 2.pdffffffffffffffffffffffffff
Protein & Amino Acid Structures Levels of protein structure (primary, seconda...
An interstellar mission to test astrophysical black holes
Warm, water-depleted rocky exoplanets with surfaceionic liquids: A proposed c...
The KM-GBF monitoring framework – status & key messages.pptx
HPLC-PPT.docx high performance liquid chromatography
6.1 High Risk New Born. Padetric health ppt
Unveiling a 36 billion solar mass black hole at the centre of the Cosmic Hors...
EPIDURAL ANESTHESIA ANATOMY AND PHYSIOLOGY.pptx
Introduction to Cardiovascular system_structure and functions-1
Ad
Ad

A Threshold Cryptosystem without a Trusted Party

  • 1. A Threshold Cryptosystem without a Trusted Party Advances in Cryptology — EUROCRYPT ’91. EUROCRYPT 1991 Torben Pryds Pedersen Aarhus University, Computer Science Department 林彥賓 2021/1/23
  • 2. 1. chooses at random and computes and brocast 2. each player opnen , the public key is 3. choose random polynomial of degree such that . f (z) = i f + i,0 f z + i,1 ... + f z i,k−1 k−1 where 4. compute for and brocast 5. send secretely to for 6. verifies share received by by checking Pi xi h = i gxi C = i Com(h ) i Ci h = h ∏i=1 n i Pi f (z) i k − 1 f (0) = i xi f = i,0 xi Pi F = i,j gfi,j j = 0, ..., k − 1 Fi,j Pi s = i,j f (j) i Pj j = 0, ..., k − 1 Pi Pj g = si,j F ∏ℓ=0 k−1 j,ℓ iℓ 2
  • 3. Set Let be polynomid over we know that for , thus is a share of f (0), f (1), f (2), ..., f (k − 1 1 1 1 1) + ... + f (0), f (1), f (2), ..., f (k − k−1 k−1 k−1 k−1 1) x = f(0), s = 1 f(1), ..., s = k−1 f(k − 1) s = i s ∑j=1 n j,i f Z : q f(z) = f (z) + 1 ... + f (z) n s = i f(i) i = 1, ..., n si f(0) = x 3
  • 4. For share of , can compute public key σ = i g = j=1 ∏ n sj,i (h F ) j=1 ∏ n j ℓ=1 ∏ k−1 j,ℓ iℓ si Pi 4