Secret sharing method based on linear code general access structure
By using a general access structure based on linear codes and employing bivariate one-way functions and congruence equations, the problems of difficulty in determining the access structure and vulnerability to attacks are solved, thereby achieving security and reliability of the secret sharing scheme and supporting multiple uses of sub-secrets and rich user authorization.
Patent Information
- Application Number
- CN202510944763.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-09
- Publication Date
- 2025-10-31
AI Technical Summary
The access structure of existing secret sharing schemes based on linear codes is difficult to determine and is vulnerable to Tompa-Woll attacks, which allow dishonest users to tamper with sub-secrets and affect secret recovery.
It adopts a general access structure based on linear codes, selects security parameters and a generation matrix during the initialization phase, randomly selects vectors, and uses bivariate one-way functions and congruence equations to distribute and reconstruct secrets, enabling multiple uses and verifications of sub-secrets and resisting malicious behavior by dishonest users.
It effectively resists Tompa-Woll attacks, enables the reuse of sub-secrets, ensures the security and reliability of secret recovery, and provides a rich set of user authorizations.
Smart Images

Figure CN120880647A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secret sharing, and more particularly to a secret sharing method based on a linear code general access structure. Background Technology
[0002] There are two types of constructions for secret sharing based on linear codes: The first type hides the secret in the first component of the message vector, multiplies the message vector by the linear code generator matrix to obtain the codeword, and then distributes each component of the codeword as a sub-secret to the corresponding user. The second type involves the distributor randomly selecting the message vector such that the first component of the codeword obtained by multiplying the message vector by the generator matrix is the secret, and the remaining components of the codeword are distributed as sub-secrets to the corresponding users. Based on the second type of secret sharing, Massey pointed out that its access structure has a one-to-one correspondence with the minimal codeword of the dual code. Theoretically, a secret sharing scheme can be constructed for every linear code, but determining its access structure is difficult. The access structure problem of secret sharing schemes based on linear codes is equivalent to the problem of finding the minimal codeword of a linear code. The minimal codeword of a minimal linear code is easy to determine; therefore, the construction of secret sharing schemes based on linear codes is transformed into constructing minimal linear codes and studying when an existing linear code is a minimal linear code.
[0003] Secret-sharing schemes based on linear codes have a linear secret recovery function. This property makes them vulnerable to Tompa-Woll attacks, where dishonest users provide incorrect sub-secrets during the secret recovery phase, preventing honest users from obtaining the secret. Summary of the Invention
[0004] The purpose of this invention is to provide a secret sharing method based on a linear code general access structure.
[0005] The technical solution adopted in this invention is:
[0006] A secret sharing method based on the general access structure of linear codes is divided into an initialization phase, a secret distribution phase, and a secret reconstruction phase, specifically including the following steps:
[0007] Step 1: The distributor selects and discloses the security parameters of the secret sharing scheme; the security parameters include a parameter r within a finite field and a bivariate one-way function, and the secret s is within a finite field.
[0008] Step 2: The distributor selects a linear code C, a generator matrix G, and a parity check matrix H based on the number of users n; the code length of the linear code is n+1.
[0009] Specifically, once the length, dimension, and generator matrix of a linear code are determined, the parity-check matrix is uniquely determined. Any codeword multiplied by the parity-check matrix is always equal to zero.
[0010] Step 3: The distributor randomly selects a vector u based on the dimension of the linear code, multiplies the vector by the generator matrix to obtain the corresponding codeword; where the secret s is equal to the vector multiplied by the first column of the generator matrix;
[0011] Step 4, any user P i Select the corresponding sub-secret q i The sub-secret is sent to the distributor via a secure channel, and the distributor checks the sub-secret to ensure that the sub-secrets are pairwise coprime and greater than the chosen finite field.
[0012] Step 5: The distributor executes the secret distribution algorithm to calculate the general solution X that satisfies the system of congruence equations and then publishes X.
[0013] Step 6: Users in the authorized subset cooperate to restore the secret after verification.
[0014] Furthermore, step 1 specifically includes the following steps:
[0015] Step 1-1: Select a prime number p to obtain a finite field F with p elements. p ;
[0016] Steps 1-2: Select a bivariate unidirectional function and randomly select the parameter r within a finite domain;
[0017] Steps 1-3 require that the selection of the public parameter r and the bivariate unidirectional function be within a finite domain.
[0018] Specifically, the distributor randomly selects r∈F p We select a bivariate unidirectional function f(x,y) and expose f(r,y).
[0019] Furthermore, in step 1-1, the prime number p is usually chosen to be 256, so as to obtain a 256-bit finite field.
[0020] Furthermore, in step 2, the distributor selects a linear code C of length n+1 and dimension k, and generates a matrix G = (g0, g1, ..., g n ).
[0021] Furthermore, in step 3, the distributor randomly selects a vector u = (u0, u1, ..., u...). k-1 ), such that the secret s = ug0, calculate the corresponding codeword (c, c1, ..., c n ) = uG, the first component c of the codeword is the secret s, and the codeword has codeword components c1,…,c with the number of users n. n .
[0022] Furthermore, in step 4, user P i Choose the secret q i Binko Secret q iThe secret q is sent to the distributor via a secure channel, and the distributor checks the sub-secret q. i Until gcd(q i ,q j )=1, i=1,2,…,n and i≠j.
[0023] Furthermore, the system of congruence equations in step 5 is as follows:
[0024]
[0025] Where c1 is the first component of the codeword, c n It is the nth component of the codeword.
[0026] Furthermore, in step 5, β is calculated based on the general solution X and the bivariate one-way function. i ,β i =f(r,c i (mod p), i = 1, 2, ..., n.
[0027] Furthermore, the specific steps of step 6 are as follows:
[0028] Step 6-1, Authorize the user Use the publicly available general solution X to correspond to the sub-secret of the authorized user. Authorized user's code item
[0029] Step 6-2, based on authorized users The first column of the generator matrix is calculated using linear representation.
[0030] in, It is the coefficient when the product of the smallest codeword in the dual code and the codeword containing the secret codeword equals zero; These are columns v1, v2, and v3 of the generated matrix, respectively. i column, v m List;
[0031] Step 6-2: Perform reconstruction calculations to obtain the initial secret s. The calculation expression is:
[0032]
[0033] This invention employs the above technical solution and utilizes the Chinese Remainder Theorem to enable the multiple uses of subsecrets. Verification is performed using a bivariate one-way function, effectively resisting malicious behavior from dishonest users. Attached Figure Description
[0034] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments;
[0035] Figure 1 This is a flowchart illustrating a secret sharing method based on a linear code general access structure according to the present invention. Detailed Implementation
[0036] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0037] This invention relates to the composition of a distributor, a set of participants, an initialization algorithm, a secret distribution algorithm, and a secret reconstruction algorithm.
[0038] like Figure 1 As shown, this invention discloses a secret sharing method based on the general access structure of linear codes, which is divided into an initialization phase, a secret distribution phase, and a secret reconstruction phase, specifically including the following steps:
[0039] Step 1: The distributor selects and discloses the security parameters of the secret sharing scheme; the security parameters include a parameter r within a finite field and a bivariate one-way function, and the secret s is within a finite field.
[0040] Step 2: The distributor selects a linear code C, a generator matrix G, and a parity check matrix H based on the number of users n; the code length of the linear code is n+1; specifically, once the length, dimension, and generator matrix of a linear code are determined, the parity check matrix is uniquely determined. Any codeword multiplied by the parity check matrix is always equal to zero.
[0041] Step 3: The distributor randomly selects a vector u based on the dimension of the linear code, multiplies the vector by the generator matrix to obtain the corresponding codeword; where the secret s is equal to the vector multiplied by the first column of the generator matrix;
[0042] Step 4, any user P i Select the corresponding sub-secret q i The sub-secret is sent to the distributor via a secure channel, and the distributor checks the sub-secret to ensure that the sub-secrets are pairwise coprime and greater than the chosen finite field.
[0043] Step 5: The distributor executes the secret distribution algorithm to calculate the general solution X that satisfies the system of congruence equations and then publishes X.
[0044] Step 6: Users in the authorized subset cooperate to restore the secret after verification.
[0045] Furthermore, step 1 specifically includes the following steps:
[0046] Step 1-1: Select a prime number p to obtain a finite field F with p elements. p ;
[0047] Steps 1-2: Select a bivariate unidirectional function and randomly select the parameter r within a finite domain;
[0048] Steps 1-3 require that the selection of the public parameter r and the bivariate unidirectional function be within a finite domain.
[0049] Specifically, the distributor randomly selects r∈F p We select a bivariate unidirectional function f(x,y) and expose f(r,y).
[0050] Furthermore, in step 1-1, the prime number p is usually chosen to be 256, so as to obtain a 256-bit finite field.
[0051] Furthermore, in step 2, the distributor selects a linear code C of length n+1 and dimension k, and generates a matrix G = (g0, g1, ..., g n ).
[0052] Furthermore, in step 3, the distributor randomly selects a vector u = (u0, u1, ..., u...). k-1 ), such that the secret s = ug0, calculate the corresponding codeword (c, c1, ..., c n )=uG.
[0053] Furthermore, in step 4, user P i Choose the secret q i Binko Secret q i The secret q is sent to the distributor via a secure channel, and the distributor checks the sub-secret q. i Until gcd(q i ,q j )=1, i=1,2,…,n and i≠j.
[0054] Furthermore, the system of congruence equations in step 5 is as follows:
[0055]
[0056] Where c1 is the first component of the codeword, c n It is the nth component of the codeword.
[0057] Furthermore, in step 5, β is calculated based on the general solution X and the bivariate one-way function. i ,β i =f(r,c i (mod p), i = 1, 2, ..., n.
[0058] Furthermore, the specific steps of step 6 are as follows:
[0059] Step 6-1, Authorize the user Use the publicly available general solution X to correspond to the sub-secret of the authorized user. Authorized user's code item
[0060] Step 6-2, based on authorized users The first column of the generator matrix is calculated using linear representation.
[0061] in, It is the coefficient when the product of the smallest codeword in the dual code and the codeword containing the secret codeword equals zero; These are columns v1, v2, and v3 of the generated matrix, respectively. i column, v m List;
[0062] Step 6-2: Perform reconstruction calculations to obtain the initial secret s. The calculation expression is:
[0063]
[0064] Specifically, this invention is divided into an initialization phase, a secret distribution phase, and a secret reconstruction phase:
[0065] Initialization phase:
[0066] The distributor selects a large prime number p and lets the shared secret be s∈f. P Where F P Let {P1, P2, ..., Pn} be a finite field with p elements and n users. n}express.
[0067] The distributor selects a linear code C of length n+1 and dimension k, with a generation matrix of G = (g0, g1, ..., g n ).
[0068] The distributor randomly selects a vector u = (u0, u1, ..., u k-1 ), such that the secret s = ug0, calculate the corresponding codeword (c, c1, ..., c n )=uG.
[0069] The distributor randomly selects r∈F p We select a bivariate unidirectional function f(x,y) and expose f(r,y).
[0070] Secret distribution phase:
[0071] User P i Choose q i (i = 1, 2, ..., n) is the child secret q i The message is sent to the distributor via a secure channel, and the distributor checks q. i Until gcd(q i ,q j ) = 1 (i ≠ j).
[0072] The distributor publicly discloses that the following system of congruence equations X satisfies:
[0073]
[0074] The user calculates β based on the publicly available X and f(r,y). i =f(r,c i (mod p), i = 1, 2, ...
[0075] Secret Reconstruction Phase:
[0076] m users By verifying the cooperation to restore the secret, the user Using the model of public X to get
[0077] g0 by Linear representation The original secret is then obtained through reconstruction calculation.
[0078] Example 1: The example describes a secret sharing scheme based on the general access structure of linear codes, with the following steps:
[0079] Step 1: Choose the prime number 7, and the shared secret s = 6. Assume the user set is {P1, P2, P3}.
[0080] Step 2, the distributor selects the [4,2] linear code C, and the generated matrix is... The verification matrix is
[0081] Step 3, the distributor selects a random vector u = (4,2), the corresponding codeword is
[0082]
[0083] Step 4, select a bivariate one-way function f(x,y) = 3 x ·5 y (mod 7), randomly select r=1, public
[0084] f(1,y)=3·5 y (mod 7).
[0085] Step 5: User P1 selects 11; User P2 selects 13; User P3 selects 17; the sub-secret is transmitted via secure mail.
[0086] The message is given to the distributor.
[0087] Step 6: The distributor publicly discloses the following system of congruence equations X:
[0088]
[0089] X≡342(mod 2 431).
[0090] Step 7: The user calculates β1 = 1, β2 = 6, and β3 = 5 based on the publicly available X and f(r,y).
[0091] Step 8: If the authorized subset {P1,P2} cooperates to recover the secret, user P1 uses the modulo of public 342 to get 11, user P2 uses the modulo of public 342 to get 4, and user P3 uses the modulo of public 342 to get 2.
[0092] Step 9, g0 can be linearly represented by {g1, g2}.
[0093] s = 4c1 + 4c2.
[0094] This invention employs the above technical solution, utilizing the Chinese Remainder Theorem to enable multiple uses of subsecrets. Verification is performed using a bivariate one-way function, effectively resisting malicious behavior from dishonest users. This invention effectively resists Tompa-Woll attacks while simultaneously enabling multiple uses of user subsecrets; furthermore, this access structure is a general access structure with a rich set of user authorizations.
[0095] Obviously, the described embodiments are only a part of the embodiments of this application, not all of them. Without conflict, the embodiments and features in the embodiments of this application can be combined with each other. The components of the embodiments of this application described and illustrated herein can generally be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of this application is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
Claims
1. A secret sharing method based on a linear code general access structure, characterized in that: It includes the following steps: Step 1: The distributor selects and discloses the security parameters of the secret sharing scheme; the security parameters include a parameter r within a finite field and a bivariate one-way function, and the secret s is within a finite field. Step 2: The distributor selects a linear code C, a generator matrix G, and a parity check matrix H based on the number of users n; the code length of the linear code is n+1. Step 3: The distributor randomly selects a vector u based on the dimension of the linear code, multiplies the vector by the generator matrix to obtain the corresponding codeword; where the secret s is equal to the vector multiplied by the first column of the generator matrix; Step 4, any user P i Select the corresponding sub-secret q i The sub-secret is sent to the distributor via a secure channel, and the distributor checks the sub-secret to ensure that the sub-secrets are pairwise coprime and greater than the chosen finite field. Step 5: The distributor executes the secret distribution algorithm to calculate the general solution X that satisfies the system of congruence equations and then publishes X. Step 6: Users in the authorized subset cooperate to restore the secret after verification.
2. The secret sharing method based on a linear code general access structure according to claim 1, characterized in that: Step 1 specifically includes the following steps: Step 1-1: Select a prime number p to obtain a finite field with p elements; Steps 1-2: Select a bivariate unidirectional function and randomly select the parameter r within a finite domain; Steps 1-3 require that the selection of the public parameter r and the bivariate unidirectional function be within a finite domain.
3. The secret sharing method based on a linear code general access structure according to claim 2, characterized in that: In step 1-1, the prime number p is selected as 256 to obtain a 256-bit finite field.
4. The secret sharing method based on a linear code general access structure according to claim 1, characterized in that: In step 2, the distributor selects a linear code C of length n+1 and dimension k, and generates a matrix G = (g0, g1, ..., g...). n ).
5. A secret sharing method based on a linear code general access structure according to claim 1 or 4, characterized in that: In step 3, the distributor randomly selects a vector u = (u0, u1, ..., u... k-1 ), such that the secret s = ug0, calculate the corresponding codeword (c, c1, ..., c). n ) = uG, the first component c of the codeword is the secret s, and the codeword has codeword components c1, ..., c with the number of users n. n .
6. The secret sharing method based on the general access structure of linear codes according to claim 1, characterized in that: In step 4, user P i Choose the secret q i Binko Secret q i The secret q is sent to the distributor via a secure channel, and the distributor checks the sub-secret q. i Until gcd(q i q j )=1, i=1,2,...,n and i≠j.
7. A secret sharing method based on a linear code general access structure according to claim 5, characterized in that: The system of congruence equations in step 5 is as follows: Where c1 is the first component of the codeword, c n It is the nth component of the codeword.
8. The secret sharing method based on the general access structure of linear codes according to claim 1, characterized in that: The specific steps of step 6 are as follows: Step 6-1, Authorize the user Use the publicly available general solution X to correspond to the sub-secret of the authorized user. Authorized user's code item Step 6-2, based on authorized users The first column of the generator matrix is calculated using linear representation. in, It is the coefficient when the product of the smallest codeword in the dual code and the codeword containing the secret codeword equals zero; These are columns v1, v2, and v3 of the generated matrix, respectively. i column, v m List; Step 6-2: Perform reconstruction calculations to obtain the initial secret s. The calculation expression is: