Share strengthening method for multi-factor threshold secret sharing

The share enhancement method for threshold secret sharing addresses the complexity and security issues of using predetermined values by incorporating entropy-preserving functions, enhancing security and usability without requiring additional devices.

JP7710653B2Active Publication Date: 2025-07-22INDUSTRY UNIVERSITY COOPERATION FOUNDATION HANYANG UNIVERSITY +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023071643
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-04-07
Filing Date
2023-04-25
Publication Date
2025-07-22
Estimated Expiration
2043-04-25

AI Technical Summary

Technical Problem

Existing threshold secret sharing methods require complex and long-form shares that are difficult to manage without a computer or digital device, and using predetermined values like passwords or biometrics as shares poses security risks due to low entropy.

Method used

A share enhancement method that includes verifying pre-specified first shares, generating random second shares, determining aggregate shares, and creating polynomials for threshold secret sharing, ensuring security through entropy-preserving functions.

Benefits of technology

Enhances security and usability by allowing password or biometric information as shares, reducing the need for separate devices and minimizing risks of electronic hacking or duplication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007710653000007
    Figure 0007710653000007
  • Figure 0007710653000008
    Figure 0007710653000008
  • Figure 0007710653000009
    Figure 0007710653000009
Patent Text Reader

Abstract

To provide a threshold secret sharing method for a share strengthening method for multi-factor threshold secret sharing, which includes an arbitrary share predetermined by a user and can guarantee security.SOLUTION: A share strengthening method for multi-factor threshold secret sharing includes the operation of confirming at least one predetermined first share value, the operation of randomly generating at least one second share value corresponding to at least one predetermined first share value, the operation of determining an aggregate share using at least one predetermined first share value and at least one second share value, the operation of generating a polynomial for threshold secret sharing on the basis of the determined aggregate share, and the operation of generating remaining full shares on the basis of the generated polynomial.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a share enhancement method for multi-factor threshold secret sharing, and more particularly, to a threshold secret sharing method that includes any share specified in advance by a user and can guarantee security.

Background Art

[0002] (t, n) Threshold Secret Sharing (TSS) is a method in which after creating n shares from a secret S, the secret S can be reconstructed using any t of the n shares.

[0003] Typical threshold secret sharing methods include Shamir's secret sharing method using a polynomial and Blakely's secret sharing method using geometric properties. For example, in Shamir's secret sharing method using a polynomial, the constant term of the polynomial is determined as the secret S, and after determining n points passing through the polynomial as shares, the polynomial can be restored using t points to find the secret S. Using such a secret sharing method, since the shares are stored at dispersed locations, not only does the secrecy of the secret S increase, but the risk of losing the secret also decreases.

[0004] However, such secret sharing methods generate shares in a complex and long form because they induce shares from a randomly generated polynomial or plane.

[0005] For example, shares generated from a polynomial or plane are impossible to memorize and difficult to manage, and thus require a computer system or a separate digital device to store and manage the shares.

Summary of the Invention

Problems to be Solved by the Invention

[0006] If it is possible to use as a share biometric information such as a password or fingerprint that can be memorized, it is not necessary to have a separate computer or digital device, and the usability of secret sharing can be improved.

[0007] For example, by slightly modifying the conventional method, it is possible to use a predetermined value such as a password or biometric information as a share. However, if information such as a password or biometric information is used as a share, it may be difficult to guarantee security. If the predetermined value is not random or has low entropy, the adversary may be able to deduce the secret S from only (t-1) shares through guessing or brute force attack on the predetermined value.

[0008] The share strengthening method for multi-factor threshold secret sharing according to various embodiments of the present invention can guarantee the security and safety of secret sharing while using a value specified in advance by a user such as a password or biometric information as a share.

[0009] In the share strengthening method for multi-factor threshold secret sharing according to various embodiments of the present invention, a share strengthening method is proposed that uses, as shares, the knowledge of the user such as a password and / or the inherence of the user such as biometric information. Using the proposed method enables multi-factor secret sharing in which a secret can be restored using various elements.

Means for Solving the Problems

[0010] A share enhancement method for multi-factor threshold secret sharing according to various embodiments may include an operation of verifying at least one pre-specified first share value, an operation of randomly generating at least one second share value corresponding to the at least one pre-specified first share value, an operation of determining an aggregate share using the at least one pre-specified first share value and the at least one second share value, an operation of generating a polynomial for threshold secret sharing based on the determined aggregate share, and an operation of generating remaining full shares based on the generated polynomial.

[0011] A share enhancement method for multi-factor threshold secret sharing according to various embodiments may include an operation of generating an arbitrary polynomial for threshold secret sharing, an operation of verifying at least one pre-specified first share value, an operation of generating m-1 second share values (enhanced shares) by a random method, an operation of determining an aggregate share using the at least one pre-specified first share value and the generated m-1 second share values and obtaining a last second share value, and an operation of generating remaining full shares based on at least a part of the generated polynomial.

[0012] A share enhancement method for multi-factor threshold secret sharing according to various embodiments may include an operation of generating full shares using an arbitrary secret sharing method, an operation of determining one share of the full shares as an aggregate share, an operation of verifying at least one pre-specified first share value, an operation of generating a polynomial for threshold secret sharing based on the aggregate share and the at least one first share value, and an operation of generating at least one second share value corresponding to the at least one first share value based on the generated polynomial.

Advantages of the Invention

[0013] According to various embodiments of the present invention, a share enhancement method for multi-factor threshold secret sharing can improve security by further using a password and / or biometric information with a low risk of electronic hacking or duplication in the threshold secret sharing method.

[0014] According to various embodiments of the present invention, a share enhancement method for multi-factor threshold secret sharing does not require a separate computer or digital device for storing passwords or biometric information, and can improve the usability of secret sharing due to excellent accessibility.

Brief Description of the Drawings

[0015]

Figure 1

Figure 2

Figure 3

Figure 4a

Figure 4b

Figure 5a

Figure 5b

Figure 6

Figure 7

Figure 8a

Figure 8b

Figure 9a

Figure 9b

Figure 10a

Figure 10b

Figure 11

Figure 12

Best Mode for Carrying Out the Invention

[0016] The present invention can be subjected to various modifications and may have various embodiments. Specific embodiments will be illustrated in the drawings and described in detail hereinafter. However, this is not intended to limit the present invention to specific embodiments, and it should be understood that the present invention includes all modifications, equivalents, and alternatives included in the spirit and technical scope of the present invention. Similar reference numerals are used for similar components while explaining each drawing.

[0017] Terms such as first, second, A, B, etc. may be used to describe various components, but the components should not be limited by these terms. These terms are only used for the purpose of distinguishing one component from another. For example, without departing from the scope of the present invention, the first component may be named as the second component, and similarly, the second component may also be named as the first component. The term "and / or" includes any combination of a plurality of related listed items or any one of the plurality of related listed items.

[0018] When it is mentioned that a certain component is "connected" or "coupled" to another component, it should be understood that it may be directly connected or coupled to the other component, but there may also be other components in between. On the other hand, when it is mentioned that a certain component is "directly connected" or "directly coupled" to another component, it should be understood that there are no other components in between.

[0019] The terms used in this application are only used to explain specific embodiments and are not intended to limit the present invention. Singular expressions include plural expressions unless the context clearly indicates otherwise. In this application, terms such as "including" or "having" are intended to specify the presence of features, numbers, steps, operations, components, parts, or combinations thereof described in the specification, and should not be construed as precluding the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.

[0020] Unless otherwise defined, all terms used herein, including technical and scientific terms, shall have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs. Terms as defined in commonly used dictionaries shall be construed to have a meaning consistent with the meaning in the context of the relevant art, and shall not be construed in an idealized or overly formal sense unless clearly defined herein.

[0021] Hereinafter, preferred embodiments according to the present invention will be described in detail with reference to the accompanying drawings.

[0022] FIG. 1 is a drawing showing some components for implementing a threshold secret sharing environment 100 according to an embodiment of the present invention.

[0023] Referring to FIG. 1, it is assumed that in the threshold secret sharing environment 100, a plurality of electronic devices 110, 120, 130 are connected wired or wirelessly via a network 150 and can share or restore secrets via the network 150.

[0024] FIG. 1 is an example for the description of the invention, and the number of electronic devices is not limited as shown in FIG. 1. The threshold secret sharing environment 100 in FIG. 1 only explains one example of an environment applicable to the embodiment, and the environment applicable to this embodiment is not limited to the threshold secret sharing environment 100 in FIG. 1.

[0025] According to various embodiments, the plurality of user terminal devices 110, 120, 130 may be fixed electronic devices implemented by a computer device or mobile electronic devices. The plurality of user terminal devices 110, 120, 130 may be, for example, a smart phone, a mobile phone, a navigation device, a computer, a laptop computer, a digital broadcast terminal, a PDA (Personal Digital Assistants), a PMP (Portable Multimedia Player), a tablet PC, and the like.

[0026] As an example, in FIG. 1, the shape of a smart phone is shown as an example of the first electronic device 110. However, in various embodiments of the present invention, the first electronic device 110 may mean one of various physical computer devices that can communicate with other electronic devices 120, 130 via the network 150 using substantially wireless or wired communication methods.

[0027] The apparatus implementing the share enhancement method for multi-factor threshold secret sharing according to an embodiment of the present invention may be one of the plurality of user terminal devices 110, 120, 130. For example, the first electronic device 110 may generate a share for threshold secret sharing, and the second electronic device 120 and the third electronic device 130 may participate in the threshold secret sharing and share the share from the first electronic device 110.

[0028] The communication method of network 150 is not limited, and it is not only a communication method that utilizes a communication network (for example, a mobile communication network, a wired Internet, a wireless Internet, a broadcast network) that network 150 may include, but also short-range wireless communication between devices may be included. For example, network 150 may include one or more arbitrary networks such as PAN (personal area network), LAN (local area network), CAN (campus area network), MAN (metropolitan area network), WAN (wide area network), BBN (broadband network), the Internet, etc.

[0029] FIG. 2 is a block diagram showing some components of the electronic device 200 according to an embodiment of the present invention. Each of the plurality of user terminal devices 110, 120, 130 described above may be implemented by the electronic device 200 shown through FIG. 2, and a method for generating shares of a threshold secret sharing infrastructure according to an embodiment may be implemented by such an electronic device 200.

[0030] Referring to FIG. 2, the electronic device 200 may include a storage unit 210, a processor 220, a communication unit 230, an input / output interface 240, and a sensor unit 250, as shown in FIG. 2.

[0031] The storage unit 210 is a computer-readable recording medium, and may include a non-volatile mass storage device such as RAM (random access memory), ROM (read only memory), and a disk drive. Here, non-volatile mass storage devices such as ROM and a disk drive are separate permanent storage devices distinct from the storage unit 210 and may be included in the electronic device 200.

[0032] Further, the storage unit 210 may store an operation system and at least one program code. Such software components may be loaded from a computer-readable recording medium separate from the storage unit 210 into the storage unit 210. Such a separate computer-readable recording medium may include computer-readable recording media such as a floppy drive, a disk, a tape, a DVD / CD-ROM drive, a memory card, and the like. In other embodiments, the software components may be loaded into the storage unit 210 via the communication unit 230 which is not a computer-readable recording medium. For example, the software components may be loaded into the storage unit 210 of the electronic device 200 based on a computer program installed by a file received via the network 150.

[0033] According to various embodiments, the storage unit 210 may store an encryption (password) specified by the user, biometric information, or the like.

[0034] The processor 220 is a component that controls the overall operation of the electronic device 200 and may be configured to process instructions of a computer program by performing basic arithmetic, logic, and input / output operations. The instructions may be provided to the processor 220 by the storage unit 210 or the communication unit 230. For example, the processor 220 may be configured to execute instructions received by a program code stored in a recording device such as the storage unit 210.

[0035] The processor 220 may be configured to, for example, check at least one pre-specified first share value, randomly generate at least one second share value corresponding to the at least one pre-specified first share value, determine an aggregate share using the at least one pre-specified first share value and the at least one second share value, generate a polynomial for threshold secret sharing based on the determined aggregate share, and generate the remaining full shares based on the generated polynomial.

[0036] The processor 220 may be configured to, for example, generate an arbitrary polynomial for threshold secret sharing, check at least one pre-specified first share value, generate m-1 second share values (enhanced shares) in a random manner, determine an aggregate share using the at least one pre-specified first share value and the generated m-1 second share values to obtain the last second share value, and generate the remaining full shares based on the generated polynomial.

[0037] The processor 220 may be configured to, for example, generate full shares using any secret sharing method, determine one of the full shares as the aggregate share, check at least one pre-specified first share value, generate a polynomial for threshold secret sharing based on the aggregate share and the at least one pre-specified first share value, and generate at least one second share value corresponding to the at least one pre-specified first share value based on the generated polynomial.

[0038] The communication unit 230 may provide a function for communicating with other devices (e.g., the storage device described above) via the network 150. As an example, requests, instructions, data, files, etc. generated by the program code stored in a recording device such as the storage unit 210 by the processor 220 of the electronic device 200 may be transmitted to other devices via the network 150 under the control of the communication unit 230.

[0039] Conversely, signals, instructions, data, files, etc. from other devices may be received by the electronic device 200 via the network 150 through the communication unit 230. Signals, instructions, data, etc. received through the communication unit 230 may be transmitted to the processor 220 or the storage unit 210, and files, etc. may be stored in a storage medium (the permanent storage device described above) that the electronic device 200 may further include.

[0040] The input / output interface 240 may be means for interfacing with an input / output device (260). For example, the input device may include devices such as a microphone, keyboard, or mouse, and the output device may include devices such as a display or speaker. As another example, the input / output interface 240 may also be means for interfacing with a device in which functions for input and output are integrated into one, such as a touch screen.

[0041] The sensor module 250 can sense the operating state of the electronic device 200 (e.g., power or temperature), or the external environmental state (e.g., the state of the user), and generate an electrical signal or data value corresponding to the sensed state. According to one embodiment, the sensor module 250 may include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0042] In another embodiment, the electronic device 200 may include fewer or more components than those of the components of FIG. 2. However, there is no need to clearly illustrate most of the conventional technical components. For example, the electronic device 200 may be implemented to include at least a part of the input / output device 250 described above, or may further include other components such as a transceiver, a database, and the like.

[0043] FIG. 3 is a sequence diagram showing an unconstrained share generation method of a share strengthening method for multi-factor threshold secret sharing according to various embodiments.

[0044] Referring to FIG. 3, in operation 310, an electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) may check at least one first share value specified in advance.

[0045] The first share (or 'predetermined share') means a share specified in advance from a user, such as a password or biometric information. Existing secret sharing methods first determine a polynomial or a geometric object and then generate shares in a complex and long form to derive shares therefrom. The shares generated in this way are not memorizable and difficult to manage, and there is a problem that a computer system or a separate digital device must be used to store and manage the shares. However, if shares such as a memorizable password or biometric information such as a fingerprint can be used, a separate device for storing the shares is not required, and the usability of secret sharing can be greatly improved by excellent accessibility.

[0046] In operation 320, an electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) can randomly generate at least one second share value corresponding to at least one pre-specified first share value.

[0047] For example, one or more second shares (or ‘hardening shares’) having randomness and sufficient entropy may be bound to a pre-selected first share (or ‘designated share’).

[0048] According to various embodiments, the electronic device may determine m hardening shares h1, h2,...h that are bound to the designated share p. m To distinguish from the full shares generated by conventional secret sharing methods, the first share (designated share) and the second share (hardening share) may be called partial shares.

[0049] The present invention does not limit the number of designated shares (first shares). However, in this document, for the sake of convenience of explanation, only the case where m hardening shares (second shares) are bound to one designated share is exemplified. The share hardening method for multi-factor threshold secret sharing according to various embodiments of the present invention may extend the designated share (first share) to multiple shares and does not limit the number of designated shares to one. Secret sharing using m hardening shares for one designated share is expressed as (t, (m), n) secret sharing. If one designated share is used and no hardening share is used, this may be expressed as (t, (0), n) secret sharing, which is distinguished from the conventional (t, n) secret sharing that does not use a designated share.

[0050] In operation 330, the electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) may determine an aggregate share using at least one pre-specified first share value and at least one second share value.

[0051] For example, if the shares generated by the conventional threshold secret sharing method are called full shares, the information obtained by aggregating all the designated shares p and m enhanced shares is defined as the aggregate share. Compared with the full shares generated by the conventional method, although the method of generating the aggregate share is different from that of the full share, the aggregate share and the full share may be treated equally when restoring the secret. This is because when the total number of the aggregate share and the full share is t, the secret can be restored.

[0052] The (t, (m), n) secret sharing method according to various embodiments of the present invention may utilize partial shares that satisfy the following two properties.

[0053] (Property 1) When all the designated share and m enhanced shares are aggregated, a full share or equivalent information to the full share is obtained. This is a property for secret reconstruction, meaning that when all the designated share and enhanced shares are aggregated, the secret S can be found together with the other (t - 1) full shares.

[0054] (Property 2) No information about the aggregate share can be found from (m - 1) enhanced shares. This is a property for the secrecy of the aggregate share. Theoretically, when the probability of finding the aggregate share with (m - 1) enhanced shares known is the same as the probability of finding the aggregate share without knowing any enhanced shares, it is considered that Property 2 is satisfied.

[0055] Property 2 is related to the perfect security of the secret S. Generally, a (t, n) threshold secret sharing system is said to have perfect security when no information about the secret S can be inferred from fewer than t shares. Applying the enhanced shares that satisfy Property 2 to the conventional (t, n) secret sharing method that provides perfect security, no information about the secret S can be found from (t - 1) complete shares and (m - 1) enhanced shares. If Property 2 is satisfied, the (m - 1) enhanced shares are of no use in finding the aggregated share, and thus the information that can be used to find the secret is only the (t - 1) complete shares. If the conventional (t, n) secret sharing method to which the present invention is applied provides perfect security, no information about the secret S can be found from (t - 1) complete shares.

[0056] In operation 340, an electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) can generate a polynomial for threshold secret sharing based on the determined aggregated share. For example, the electronic device uses the aggregated share and the complete shares, the total number of which is t, to generate a (t - 1) - degree polynomial f(x)=a t-1 x t-1 +a t-2 x t-2 +...S in which the secret S is included in the constant term.

[0057] FIGS. 4a to 4b show a method for generating a polynomial required to generate a single enhanced share using an unconstrained point generation technique according to various embodiments. The aggregated share determined by the designated share and the enhanced share has the form of a point, and it is a secret sharing method that uses points as shares based on a polynomial.

[0058] Referring to FIGS. 4a to 4b, it shows a method for first determining a single enhanced share and then determining a polynomial using an unconstrained point generation technique.

[0059] Referring to FIG. 4a, in operation 410, an electronic device (e.g., the electronic device 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) may select a point R where the x-axis coordinate value is the first share value and the y-axis coordinate value is the second share value.

[0060] For example, a point R(p, h) where the x-axis coordinate value is the first specified share p and the y-axis coordinate value is the enhancement share h may be selected. For example, referring to FIG. 4b, a point corresponding to R(p, h)=R(p, f(h)) may be selected.

[0061] In operation 420, the electronic device (e.g., the electronic device 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) can generate the polynomial having the coefficient a i as a variable.

[0062] For example, while taking one coefficient a i as a variable, the electronic device randomly generates the remaining coefficients except a i and generates a (t - 1) - degree polynomial f(x)=a t-1 x t-1 +a t-2 x t-2 +...S.

[0063] In operation 430, the electronic device (e.g., the electronic device 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) may determine the coefficient a i such that the polynomial passes through the point R.

[0064] For example, the electronic device determines the coefficient a i such that the polynomial f(x) passes through the point R, and can generate a polynomial for threshold secret sharing.

[0065] FIGS. 5a to 5b show a method for generating a polynomial necessary for generating a plurality of enhancement shares using an unconstrained point generation technique according to various embodiments.

[0066] Referring to FIGS. 5a through 5b, a method for first randomly determining a plurality of enhanced shares and then determining a polynomial using a constrained point generation technique is shown.

[0067] In operation 510, an electronic device (e.g., electronic device 110, 120, 130 of FIG. 1 or electronic device 200 of FIG. 2) may select a point R determined by partial shares p, h1, h2,... h m and.

[0068] According to various embodiments, the electronic device may determine point R using a function g( ) that preserves entropy in order to utilize a plurality of enhanced shares. Using the function g( ) that preserves entropy is to satisfy Property 2. If the function g( ) preserves entropy and the function g( ) is applied to the partial shares p, h1, h2,... h m to determine the coordinate values of point R, then point R corresponding to the aggregated share cannot be found if even one of the enhanced shares h1, h2,... h m is unknown. This is because the enhanced shares h1, h2,... h m are randomly generated and g( ) preserves entropy.

[0069] According to various embodiments, the function g( ) that preserves entropy may include an encryption algorithm, a one-way function, a pseudorandom generator, a pseudorandom function, etc. Typically, it uses XOR encryption. When represented by the XOR operator + , g(p, h1, h2,... h m-1 ) = p + h1 + h2 + ... + h m-1 may be obtained.

[0070] The method of selecting point R according to various embodiments uses one partial share as the x-axis or y-axis coordinate value of point R, and uses the function g( ) that preserves entropy for the remaining partial shares as the remaining coordinate values of point R. In this case, the form of the aggregated share may be (p, g(h1, h2,...h m ), (h i , g(h1, h2,...p,...h m ), (g(h1, h2,...h m ), p), (g(h1, h2,...p,...h m ), h i ), etc.

[0071] Another method of selecting point R according to other embodiments is to apply the functions g1( ) and g2( ) that preserve entropy to the x-axis coordinate value and the y-axis coordinate value respectively. In this case, the form of the aggregated share may be (g1(p, h1, h2,...), g2(h i ,...h m ). At this time, each partial share must be used at least once. For example, referring to FIG. 5b, point R may be selected as the coordinates obtained by using p, h1, h2,...h m at least once.

[0072] In operation 520, an electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) can generate an arbitrary polynomial f(x) with one coefficient a i as a variable. For example, generate the remaining coefficients except for one coefficient a i randomly to generate a (t - 1) - degree polynomial f(x) = a t-1 x t-1 + a t-2 x t-2 +...S.

[0073] In operation 530, an electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) determines the coefficient a i so that the polynomial f(x) passes through point R, and can generate a polynomial for threshold secret sharing.

[0074] FIG. 6 shows a method for generating a polynomial using an unconstrained coefficient generation technique according to various embodiments. The aggregated shares determined by the designated shares and the enhanced shares indicate the coefficients of a polynomial or a plane equation that are not points. Therefore, it may be applied to the Shamir method using a polynomial or the Blakely method using a plane, etc.

[0075] Referring to FIG. 6, a method for determining a plurality of enhanced shares and then determining a polynomial using an unconstrained coefficient generation technique is shown.

[0076] In operation 610, an electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) can randomly generate a plurality of enhanced shares h1, h2,... h m

[0077] In operation 620, an electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) may use a function g( ) that preserves entropy to determine the value of one coefficient a i . For example, determine the value of one coefficient a i as g(p, h1, h2,... h m ). However, a i should not be a coefficient used secretly.

[0078] Functions g( ) that preserve entropy according to various embodiments may include an encryption algorithm, a one-way function, a pseudorandom generator, a pseudorandom function, etc. Typically, it uses XOR encryption. When represented by the XOR operator + , g(p, h1, h2,... h m-1 ) = p​+ h1 + h2 + ... + h m-1 may also be used.

[0079] In operation 630, the electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) can generate a (t - 1)-th degree polynomial f(x) including the coefficient a i .

[0080] In operation 640, the electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) may randomly generate the remaining coefficients except the coefficient a i to determine the complete (t - 1)-th degree polynomial f(x).

[0081] The non - restrictive coefficient generation technique is such that although the aggregated shares have the form of coefficients, they still satisfy Property 1. Generally, a (t - 1)-th degree polynomial or a (t - 1)-dimensional plane f( ) may be uniquely determined by t coefficients. If t points are selected such that f( ) can be uniquely determined by the t shares indicating the points, then f( ) may be uniquely determined by (t - 1) shares and one coefficient. In this case, from the perspective of restoring the secret, the shares indicating the points and the coefficient may be regarded as equivalent. That is, the coefficient a m determined by g(p, h1, h2,...h i ) may be used equivalently to one complete share from the perspective of restoring the secret, so it satisfies Property 1. Also, since a function g( ) that preserves entropy is used to determine the coefficient, it also satisfies Property 2.

[0082] Returning to FIG. 3, in operation 350, an electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) can generate the remaining complete shares based on the generated polynomial. For example, when the electronic device uses a single enhanced share, it can generate (n - 2) complete shares, and when using multiple enhanced shares m, it can generate (n - m - 1) full shares.

[0083] Although not shown, the electronic device may share the secret by distributing the generated complete shares to the number of participants corresponding to the complete shares.

[0084] - First Embodiment (Non - restrictive Point Generation Technique) An embodiment of applying the present invention to Shamir secret sharing over a finite field F q will be described. For the finite field F q is defined by the remainder value when divided by q, and for the convenience of calculation, assume that the value of q is the prime number 13. Accordingly, the secret S, coefficients, coordinate values, and shares used for secret sharing are all defined over F 13 is defined.

[0085] Assume that the secret value S = 3, the specified share p = 5, and m enhanced shares are to be generated.

[0086] 1) When generating a single enhanced share (m = 1), first generate the enhanced share h by a random method, and assume that the obtained value is h = 8. At this time, the point R(p, h) serving as the aggregated share is (5, 8). Assuming that the total number of aggregated shares and complete shares required to restore the secret is 3, generate the remaining coefficients except for one coefficient a2 randomly to generate the quadratic polynomial f(x)=a2x 2 +a1x + a0=a2x 2 +9x + 3. When determining the coefficient a2 so that the polynomial f(x) passes through the point R(5, 8), f(x) may be obtained as follows.

[0087] [Number]

[0088] F 13 Using the fact that the multiplicative inverse of 25 modulo 12 is 12,

[0089] [Number]

[0090] Therefore, the quadratic polynomial may be f(x) = x 2 + 9x + 3.

[0091] The generated quadratic polynomial may be used to generate perfect shares in the same way as the conventional method. If, assuming n = 5, a total of 5 shares need to be generated, then 3 perfect shares can be generated by subtracting the already determined designated share and one enhanced share. Using the polynomial f(x) = x 2 + 9x + 3 determined above, 3 perfect shares (1, 0), (2, 12), (3, 0) can be obtained. In this case, it is represented as a (3, (1), 5) secret sharing.

[0092] 2) When generating multiple enhanced shares (m > 1), assume m = 3. First, generate 3 enhanced shares h1, h2, h3 by a random method, and the obtained values may be h1 = 6 (= 0110), h2 = 8 (= 1000), h3 = 2 (= 0010) respectively. As already explained, there are various methods to determine the aggregation share point R. Here, a form of (p, g(h1, h2,... h m )) may be used. For example, when using XOR encryption for g(), the coordinates of point R are (p, h1 + h2 + h3)), and h1 + h2 + h3 may be calculated as follows.

[0093] [Number]

[0094] Therefore, the coordinates of point R are (5, 12). Assuming that the total number of aggregation shares and complete shares required to restore the secret is 3, the remaining coefficients except one coefficient a2 are randomly generated to obtain a quadratic polynomial f(x) = a2x 2 + a1x + a0 = a2x 2 + 9x + 3. The coefficient a2 can be determined such that this polynomial f(x) passes through point R(5, 12).

[0095] [Number]

[0096] F 13 By using the fact that the multiplicative inverse of 25 in F is 12,

[0097] [Number]

[0098] Therefore, the quadratic polynomial may be f(x) = 10x 2 + 9x + 3.

[0099] The generated quadratic polynomial may be used to generate complete shares in the same way as the conventional method. If, assuming n = 6, a total of 6 shares need to be generated, then 2 complete shares can be generated by subtracting the already determined designated share and 3 enhancement shares. Using the polynomial f(x) = 10x 2 + 9x + 3 determined above, 2 complete shares (1, 9), (2, 9) can be obtained. In this case, it is represented by a (3, (3), 6) secret sharing.

[0100] - Second Embodiment (Unconstrained Coefficient Generation Technique) The present invention is in a finite field Fq An embodiment applicable to Shamir secret sharing is described. A finite field F q is defined by the remainder when divided by q, and for computational convenience, assume the prime number 13 as the value of q. Accordingly, the secret S, coefficients, coordinate values, and shares used for secret sharing are all defined in F 13 .

[0101] Assume that the designated share is determined to be p = 5 with the secret value S = 3, and m enhanced shares are to be generated.

[0102] When m = 3, three enhanced shares h1, h2, and h3 can be generated first by a random method. For example, if the obtained values are h1 = 6 (= 0110), h2 = 8 (= 1000), and h3 = 2 (= 0010) respectively, the value of one coefficient a2 can be determined as p + h1 + h2 + h3.

[0103] a2 = p + h1 + h2 + h3 = 0101 + 0110 + 1000 + 0010 = 1011 (= 11) Assuming that the total number of aggregated shares and complete shares required to recover the secret is 3, the remaining coefficients excluding the coefficient a2 are randomly generated to obtain the quadratic polynomial f(x) = a2x 2 + a1x + a0 = 11x 2 + 9x + 3 or the two-dimensional plane f(x1, x2) = 11x1 + 9x2 + 3 can be generated.

[0104] The generated quadratic polynomial or two-dimensional plane may be used to generate complete shares in the same way as the conventional method. If it is assumed that n = 6 and a total of 6 shares need to be generated, the remaining 2 complete shares can be generated by subtracting the already determined designated share of 1 and the 3 enhanced shares. If the quadratic polynomial 11x determined above 2By using +9x + 3, two complete shares (1, 10), (2, 0) can be obtained. In this case, it is represented by a (3, (3), 6) secret sharing.

[0105] FIG. 7 is an order diagram showing a method for generating Constrained Share Generation of a share enhancement method for multi - factor threshold secret sharing according to various embodiments.

[0106] Referring to FIG. 7, in operation 710, an electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) can generate any polynomial for threshold secret sharing. For example, the electronic device can generate a (t - 1) - degree polynomial f(x)=a i having a random coefficient a and with the secret S included in the constant term. t-1 x t-1 +a t-2 x t-2 +...S.

[0107] In operation 720, the electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) can verify at least one predetermined first share value. The first share (or 'predetermined share') means a share predetermined from the user, such as a password or biometric information, and can be represented by a unique value. If biometric information such as a memorizable password or fingerprint can be used as a share, a separate device for storing the share is not required, and the usability of secret sharing can be greatly improved due to excellent accessibility.

[0108] In operation 730, when attempting to use a plurality of enhanced shares, m - 1 second share (enhanced share) values having sufficient entropy can be randomly generated. For example, when attempting to generate m enhanced shares h1, h2,...h m to be combined with the designated share p, the electronic device can generate the enhanced shares h1, h2,...hm-1 A value corresponding to this can be generated in advance.

[0109] If a single second share (enhanced share) is to be generated, operation 730 may be omitted.

[0110] In operation 740, an electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) determines an aggregated share using the first share value and the generated m - 1 second share values, and may obtain the last second share value h m For example, applying a function g() that preserves entropy to the first share value and the generated m - 1 second share values to determine the last enhanced share h m Specifically, the electronic device applies a function g() that preserves entropy to a pre - specified first share value p and the generated m - 1 enhanced shares h1, h2,...h m-1 to select a point R whose x - axis coordinate value is g(p, h1, h2,...h m-1 ), and calculates the y - axis coordinate value of R to determine the last second share (enhanced share) h m .

[0111] As another example, when generating a single second share (enhanced share), the y - axis coordinate value of the point among the points of the generated polynomial f(x) whose x - axis coordinate is the first share value may be determined as the second share (enhanced share) value.

[0112] If the shares generated by the conventional threshold secret sharing method are called complete shares, the information obtained by aggregating all of the designated share p and the m enhanced shares is regarded as an aggregated share and is distinguished from the complete shares.

[0113] In operation 750, an electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) can generate the remaining complete shares based on the polynomial generated such that the sum of the number of partial shares and complete shares is n.

[0114] For example, the electronic device can generate the remaining n - m - 1 complete shares based on the generated polynomial.

[0115] Although not shown in the figure, the electronic device may share the secret by distributing the generated complete shares to the number of participants corresponding to the complete shares.

[0116] FIGS. 8A to 8B show a secret sharing method in which the enhanced share is singular using a selective technique for restrictive points.

[0117] Referring to FIG. 8A, in operation 810, an electronic device (e.g., electronic device 110, 120, 130 of FIG. 1 or electronic device 200 of FIG. 2) can generate a (t - 1) - degree polynomial f(x) having a random coefficient a i thereof.

[0118] For example, the electronic device can generate a (t - 1) - degree polynomial f(x)=a i having a random coefficient a t-1 x t-1 +a t-2 x t-2 +...S thereof.

[0119] In operation 820, the electronic device (e.g., electronic device 110, 120, 130 of FIG. 1 or electronic device 200 of FIG. 2) may select a point R using the polynomial f(x) and the designated share p.

[0120] For example, the electronic device may select a point R whose x - axis coordinate value is p among the points through which the polynomial f(x) passes. That is, using the y - axis coordinate value corresponding to f(p), the point R(p, f(p)) may be selected. For example, referring to FIG. 8B, a point that is R(p, f(p)) may be selected using the polynomial.

[0121] In operation 830, the electronic device (e.g., electronic device 110, 120, 130 of FIG. 1 or electronic device 200 of FIG. 2) may calculate the y - axis coordinate value of the point R to determine the enhanced share h.

[0122] For example, if h = f(p), the aggregated share may be at point R(p, h).

[0123] In operation 840, an electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) can generate a complete share based on a polynomial.

[0124] Although not shown, the electronic device may share the secret by distributing the generated complete shares to a number of participants corresponding to the complete shares.

[0125] FIGS. 9a to 9b show a secret sharing method with multiple enhanced shares using a restricted point selection technique.

[0126] Referring to FIG. 9a, in operation 910, an electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) can generate a polynomial f(x) of degree (t - 1) having a random coefficient a i .

[0127] For example, the electronic device can generate a polynomial f(x) = a i having a random coefficient a t-1 x t-1 + a t-2 x t-2 +...S of degree (t - 1).

[0128] In operation 920, an electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) can generate (m - 1) enhanced shares.

[0129] For example, the electronic device can generate (m - 1) enhanced shares h1, h2,... h m-1 by a random method. According to one embodiment, the electronic device can generate one or more enhanced shares having randomness and sufficient entropy.

[0130] In operation 930, the electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) may select point R using a function g( ) that preserves entropy. For example, the electronic device may use g( ) to select a point R whose x-axis coordinate value is g(p, h1, h2,...h m-1 ). For example, referring to FIG. 9b, a polynomial may be used to select a point that is R(g(p, h1, h2,...h m-1 ), f(g(p, h1, h2,...h m-1 ))).

[0131] According to various embodiments, the function g( ) that preserves entropy may include an encryption algorithm, a one-way function, a pseudorandom generator, a pseudorandom function, etc. Typically, it uses XOR encryption. When represented by the XOR operator + , g(p, h1, h2,...h m-1 ) = p + h1 + h2 + ... + h m-1 may be obtained.

[0132] In operation 940, the electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) may calculate the y-axis coordinate value of point R to determine the enhanced share h m .

[0133] For example, h m = f(g(p, h1, h2,...h m-1 )) and the aggregated share may be the point R(g(p, h1, h2,...h m-1 ), h m ).

[0134] In operation 950, an electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) can generate a complete share based on a polynomial.

[0135] Although not shown, the electronic device may share a secret by distributing the generated complete shares to a number of participants corresponding to the complete shares.

[0136] - Third Embodiment (Constrained Point Selection Technique) An embodiment of applying the present invention to Shamir secret sharing over a finite field F q will be described. The finite field F q is defined by the remainder value when divided by q, and for computational convenience, assume that the value of q is the prime number 13. Thus, the secret S, coefficients a i used for secret sharing, coordinate values, and shares are all defined in F13.

[0137] Assume that the secret value S = 3, the specified share p = 5, and m enhanced shares are to be generated.

[0138] If a randomly generated quadratic polynomial f(x) = x 2 + 9x + 3 is given and it is assumed that three complete shares are to be generated, three complete shares V1 = 0, V2 = 12, V3 = 0 can be obtained from the three points (1, f(1)), (2, f(2)), (3, f(3)) through which f(x) passes.

[0139] 1) When generating a single enhanced share (m = 1), a point R whose x-axis coordinate value among the points existing in f(x) is p = 5 (= 0101) may be selected. The y-axis coordinate value of point R becomes the enhanced share h, that is, h = f(p) = f(5) = 8. At this time, the coordinates of point R are (5, 8).

[0140] 2) When generating multiple enhancement shares (m > 1), assume m = 3. Two enhancement shares h1 and h2 may be generated first by a random method, and the obtained values may be h1 = 6 (= 0110) and h2 = 8 (= 1000), respectively. Using XOR encryption as the function g( ), when the x-axis coordinate value is p + h1 + select the point R where h2, then p + h1 + h2 may be calculated as follows.

[0141]

Equation

[0142] Figures 10a to 10b show a secret sharing method with a single specified share using a hierarchical share generation technique according to various embodiments. In Figures 10a to 10b, for the sake of convenience of explanation, the secret sharing method is divided into two levels to generate partial shares. However, various embodiments of the present invention are not intended to be limited to two levels and may be extended and implemented in multiple levels.

[0143] Referring to Figure 10a, in operation 1001, an electronic device (e.g., the electronic devices 110, 120, 130 in Figure 1 or the electronic device 200 in Figure 2) can generate at least one complete share using any secret sharing method.

[0144] For example, the electronic device can generate (n - m - 1) complete shares V1, V2,..., V of the first level based on the complete first polynomial f1(x) using any secret sharing method TSS1 that uses a polynomial. n-m-1 The hierarchical share generation method according to various embodiments of the present invention may use the Blakely method using geometric objects or other conventional secret sharing methods in the first level, and does not limit the secret sharing methods that may be used in the first level.

[0145] In operation 1003, the electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) may determine at least one of the generated complete shares as an aggregated share.

[0146] Referring to FIG. 10b, for example, the electronic device may select one share V of the shares generated at the first layer and determine it as the aggregated share. j and determine it as the aggregated share.

[0147] In operation 1005, the electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) may determine at least one first share value corresponding to the aggregated share. The first share (or 'predetermined share') means a share specified in advance by the user, such as a password or biometric information, and may be represented by a unique value. If biometric information such as a memorizable password or fingerprint can be used as a share, a separate device for storing the share is not required, and the usability of secret sharing can be greatly improved by excellent accessibility.

[0148] In operation 1007, the electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) can generate a polynomial for threshold secret sharing based on the aggregated share and at least one first share value.

[0149] For example, the electronic device can generate a complete polynomial f2(x) that defines the second layer. For example, the electronic device may determine a point R(k, p) having an arbitrary value k as the x-axis coordinate value and the first share (designated share) p as the y-axis coordinate value. Thereafter, the electronic device randomly generates the remaining coefficients except for one coefficient a i to generate an m-degree polynomial f2(x)=a m x m +a m-1 x m-1 +...V j After generating, the coefficient a is such that it passes through the point Ri may be determined.

[0150] In operation 1009, an electronic device (e.g., the electronic devices 110, 120, 130 in FIG. 1 or the electronic device 200 in FIG. 2) can generate at least one second share value corresponding to at least one first share value based on the generated polynomial.

[0151] For example, the electronic device can select m different points among the points of the polynomial f2(x) that are not R and generate the y-axis coordinate value of each point as a second share (enhanced share).

[0152] Referring to FIG. 10b, for example, the electronic device may determine the shares V'1, V'2... V' generated in the second layer as second shares (enhanced shares). In FIG. 10b, any conventional secret sharing method used in the first layer is expressed as TSS1, and the secret sharing method used in the second layer uses a polynomial based on a pre-specified first share (designated share), so to distinguish it from the conventional secret sharing method, it is expressed as TSS m 2. *

[0153] The hierarchical share generation technique can generate partial shares that satisfy Property 2 when the second layer provides perfect security. If the second layer provides perfect security, the remaining enhanced shares cannot be found from (m - 1) enhanced shares, and thus the aggregated shares cannot be found either.

[0154] - Fourth Embodiment (Hierarchical Share Generation Technique) An embodiment of applying the present invention to Shamir secret sharing over a finite field F q will be described. The finite field F q is defined by the remainder value when divided by q, and for computational convenience, assume that the value of q is the prime number 13. Accordingly, the secret S, coefficients a i , coordinate values, and shares used for secret sharing are all in F​13 is justified.

[0155] Assume that the secret value S = 3 is specified, the share p = 5 is determined, and enhanced shares for (3, (2), 4) secret sharing are generated.

[0156] In the first layer, after determining the quadratic polynomial f1(x)=x 2 +9x + 3 using the Shamir method, two shares V1 = 0 and V2 = 12 can be generated from the three points (1, f1(1)) and (2, f1(2)). It is also possible to select V2 from the generated shares and determine it as a complete share.

[0157] In the second layer, using V2 = 12 as the secret and the specified share p = 5, the coordinates of point R can be determined as (3, 5). The coefficient a1 is randomly generated, and the quadratic polynomial f2(x)=a2x 2 +a1x + a0=x 2 +12x + 12 passing through point R can be generated. Two enhanced shares h1 = 12 and h2 = 1 can be generated from the points (1, f2(1)) and (2, f2(2)) through which f2(x) passes.

[0158] FIG. 11 shows a method for enhancing shares for multi - factor threshold secret sharing according to various embodiments in comparison with conventional techniques.

[0159] Referring to FIG. 11, it is a comparison between a (3, (0), 8) secret sharing that uses the specified share but not the enhanced share and a (3, (1), 8) secret sharing according to various embodiments of the present invention that uses both the specified share and the enhanced share.

[0160] In the conventional (3, (0), 8) secret sharing method, when an attacker obtains three shares, the secret S can be found. Moreover, even when two shares are obtained, it may be possible to infer information about the secret S by exploiting the vulnerability of the designated share p7. However, in the (3, (1), 8) secret sharing method, the secret S cannot be found from any three shares including the designated share. Furthermore, it goes without saying that the secret S cannot be found from two or fewer shares, and no information about S can be inferred either.

[0161] Also, referring to FIG. 11, the (3, (1), 8) secret sharing method according to various embodiments of the present invention may induce more costs than the (3, (0), 8) secret sharing method when restoring the secret in a normal case. This is because a total of four shares are required when the designated share or the enhanced share is used. However, when a password or biometric information is used for the designated share p7, no separate device for storage is required. Although an additional user interface and processing are required to receive the input of the password or biometric information, an improved security and usability can be provided, so a trade-off may be considered to exist.

[0162] FIG. 12 shows a share enhancement method for multi-factor threshold secret sharing according to various embodiments in comparison with conventional techniques.

[0163] Referring to FIG. 12, it compares the secret sharing without using designated shares (3, 8) with the secret sharing using all of the designated shares and enhanced shares (3, (1), 8). In the (3, 8) secret sharing method, if an attacker obtains any three shares, the secret S can be found. In the (3, (1), 8) secret sharing method, if the three shares obtained by the attacker do not include the enhanced share and the designated share, the secret S can be found in the same way as the (3, 8) secret sharing method. However, if the three shares obtained by the attacker include the designated share p7, the secret S cannot be found. Also, if the three shares obtained by the attacker include the enhanced share h8, since the designated share p7 is required, additional effort is needed to find p7. Therefore, the (3, (1), 8) secret sharing method has better security than the (3, 8) secret sharing method.

[0164] In the existing (t, n) secret sharing or the (t, (0), n) secret sharing method without using enhanced shares, increasing the threshold t can enhance the security against attacks. For example, using the (t + 1, n) or (t + 1, (0), n) secret sharing method, the attacker has to obtain (t + 1) shares, so the security against attacks is enhanced. However, when comparing such a method with the (t + 1, (m), n) secret sharing method, it can be shown that the security of the (t + 1, (m), n) secret sharing method is relatively excellent in the same way as the above explanation.

[0165] Finally, by applying the present invention, it becomes possible to perform Multi-Factor Secret Sharing that uses, as shares, a user's knowledge such as a password and a user's inherence such as biometric information. A password is invulnerable to electronic hacking, and biometric information is difficult to hack electronically and at the same time has a low risk of duplication. Also, a password and biometric information do not require a separate digital device for storage, and furthermore, with better accessibility, the usability of the secret sharing system can be improved.

[0166] The features, structures, effects, etc. described in the embodiments above are included in at least one embodiment of the present invention and are not necessarily limited to only one embodiment. Furthermore, the features, structures, effects, etc. exemplified in each embodiment can be combined or modified and implemented for other embodiments by those with ordinary knowledge in the field to which the embodiments belong. Therefore, the content related to such combinations and modifications should be analyzed as being included in the scope of the present invention.

[0167] Also, although the embodiments have been mainly described above, this is merely an illustration and does not limit the present invention. It can be understood that those with ordinary knowledge in the field to which the present invention belongs can make various modifications and applications not exemplified above without departing from the essential characteristics of this embodiment. For example, each component specifically shown in the embodiment can be implemented with modifications. And the differences related to such modifications and applications should be analyzed as being included in the scope of the present invention defined in the appended claims.

Claims

1. A share strengthening method for multi-factor threshold secret sharing of an electronic device including a processor, comprising: an operation in which the processor checks at least one pre-specified first share value; an operation in which the processor randomly generates at least one second share value corresponding to the at least one pre-specified first share value; an operation in which the processor determines an aggregate share using the at least one pre-specified first share value and the at least one second share value; an operation in which the processor generates a polynomial for threshold secret sharing based on the determined aggregate share; and an operation in which the processor generates remaining full shares based on the generated polynomial; the aggregate share is one of the full shares or information obtainable from one of the full shares, and includes an operation in which at least one coordinate value corresponding to the aggregate share is generated by applying a function that retains entropy with respect to the at least one second share value; the function that retains entropy includes at least one of an encryption algorithm, a one-way function, a pseudorandom generator, or a pseudorandom function, and the calculation is performed such that the aggregate share cannot be calculated unless all of the first share and the second share are known. A share strengthening method for multi-factor threshold secret sharing, characterized by this.

2. The operation of generating a polynomial for threshold secret sharing based on the determined aggregate share is: an operation of selecting a point R corresponding to the determined aggregate share; Coefficient a i the operation of generating the polynomial with the variable, and An operation of determining the coefficient a such that the polynomial passes through the point R i The share strengthening method for multi-factor threshold secret sharing according to claim 1, including the operation of

3. The operation of generating a polynomial for threshold secret sharing based on the determined aggregate share is: The operation of generating the polynomial including at least one undetermined coefficient a i and At least one of the undetermined coefficients a i The method for strengthening a share for multi-factor threshold secret sharing according to claim 1, comprising an operation of randomly determining the remaining coefficients excluding the above to determine a complete polynomial.

4. A share strengthening method for multi-factor threshold secret sharing of an electronic device including a processor, comprising: an operation in which the processor generates an arbitrary polynomial for threshold secret sharing; The operation of the processor to check at least one pre-specified first share value; The operation of the processor to generate m - 1 second share values by a random method; The operation of the processor to determine an aggregate share using the at least one pre-specified first share value and the generated m - 1 second share values, and obtain the last second share value; and The operation of the processor to generate the remaining full shares based on the generated polynomial, including: The aggregate share is one of the full shares or information obtainable from one of the full shares, and by applying a function that retains entropy to the m - 1 randomly generated second share values, at least one coordinate value corresponding to the aggregate share is generated. The function that retains entropy includes at least one of an encryption algorithm, a one-way function, a pseudorandom generator, or a pseudorandom function, and performs calculations such that the aggregate share cannot be calculated if all of the first share and the second shares are not known. A share enhancement method for multi-factor threshold secret sharing, characterized in that.

5. The operation of determining an aggregate share using the at least one pre-specified first share value and the generated m - 1 second share values, and obtaining the last second share value is: When generating a single second share, the operation of selecting a point R on the generated polynomial such that the x-axis coordinate corresponds to the generated first share value, and the operation of determining the y-axis coordinate value of R as the second share; and When generating a plurality of second shares, the operation of selecting a point R on the generated polynomial by applying a function g( ) that retains entropy to the generated first share value and second share values, and the operation of determining the y-axis coordinate value of R as the last second share. The share enhancement method for multi-factor threshold secret sharing according to claim 4.

6. Including a storage unit, a processor, and a communication unit, The processor is configured to check at least one pre-specified first share value, randomly generate at least one second share value corresponding to the at least one pre-specified first share value, determine an aggregate share using the at least one pre-specified first share value and the at least one second share value, generate a polynomial for threshold secret sharing based on the determined aggregate share, and generate remaining full shares based on the generated polynomial. The aggregate share is one of the full shares or information obtainable from one of the full shares, and includes an operation of applying a function that retains entropy to the at least one second share value to generate at least one coordinate value corresponding to the aggregate share. The function that retains entropy includes at least one of an encryption algorithm, a one-way function, a pseudorandom generator, or a pseudorandom function, and performs calculations such that the aggregate share cannot be calculated unless all of the first share and the second share are known. An electronic device characterized by this. **Claim 7** The processor selects a point R corresponding to the determined aggregate share. Coefficient a i generate the polynomial with the variable The coefficient a is set so as to determine the polynomial so that it passes through the point R. i The electronic device according to claim 6, characterized in that it is set so as to determine the coefficient a so that the polynomial passes through the point R. **Claim 8** The processor is configured to obtain the x-axis coordinate of point R using the first share value and obtain the y-axis coordinate of point R using the second share value, or to obtain the x-axis coordinate value and the y-axis coordinate value by applying a function that retains entropy. The electronic device according to claim 7, characterized by this. **Claim 9** The processor generates the polynomial including at least one undetermined coefficient a i and is configured to randomly determine the remaining coefficients excluding the at least one undetermined coefficient a i to determine a complete polynomial, the electronic device according to claim 6, characterized in that.

Citation Information

Patent Citations

  • Electronic information transport system

    JP2007156573A

  • Secret sharing system

    JP2009103774A

  • Protection of a secret on a mobile device using a secret-splitting technique with a fixed user share

    US9455968B1

  • Methods and apparatus for password-based secret sharing schemes

    US9813243B1

  • Methods and apparatus for generalized password-based secret sharing

    US9929860B1