Methods for sharing and recovering threshold secrets on a multi-compartment infrastructure
The method addresses limitations in existing threshold secret sharing by implementing Lagrangian interpolation and encrypted secret values to create multiple compartments and arbitrary access structures, enhancing security and flexibility in hierarchical systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- INDUSTRY UNIVERSITY COOPERATION FOUNDATION HANYANG UNIVERSITY
- Filing Date
- 2023-04-25
- Publication Date
- 2026-05-15
AI Technical Summary
Existing threshold secret sharing methods, such as Shamir's and Blakely's, are limited in creating multiple compartments at a single level and do not allow for arbitrary access structures or efficient recovery conditions, particularly in hierarchical secret sharing systems.
A method for sharing and recovering threshold secrets on a multi-compartment infrastructure using Lagrangian interpolation with polynomials, allowing for the creation of multiple compartments at a single level and enabling arbitrary access structures through the use of encrypted secret values and internal shares.
Enables diverse hierarchical secret sharing systems with arbitrary access structures and efficient recovery of secrets using Lagrangian interpolation, enhancing security and flexibility in secret sharing scenarios.
Smart Images

Figure 0007859633000002 
Figure 0007859633000003 
Figure 0007859633000004
Abstract
Description
[Technical Field]
[0001] The present invention relates to a method for sharing and recovering threshold secrets on a multi-compartment infrastructure, and more particularly, to a method for generating shares and recovering secrets in a system composed of multiple compartments. [Background technology]
[0002] (t, n) Threshold Secret Sharing (TSS) is a method in which, after creating n shares from a secret S, the secret S can be reconstructed using any t of those n shares.
[0003] Representative methods for sharing threshold secrets include Shamir's secret sharing method, which uses polynomials, and Blakely's secret sharing method, which utilizes geometric properties. For example, in Shamir's secret sharing method, which uses polynomials, the constant terms of the polynomial are designated as the secret S, and n points passing through the polynomial are designated as shares. Then, the polynomial is reconstructed using t points, and the secret S is reconstructed. Using such a secret sharing method not only increases the secrecy of the secret S because the shares are stored in distributed locations, but also reduces the risk of losing the secret.
[0004] The secret sharing system can also be configured by dividing participants into multiple levels, which is called hierarchical secret sharing or multilevel secret sharing. In hierarchical secret sharing, shares at higher levels are treated as more powerful than shares at lower levels, which is useful when controlling access to secrets in various scenarios.
[0005] In Tassa's proposed conjunction-based hierarchical secret sharing, recovering a secret at a lower level always requires shares at a higher level. For example, a secret can be recovered with the shares of two vice presidents, but not with the shares of three employees. However, if the share of one vice president is added to the shares of three employees, it becomes possible to recover the secret. For this conjunction-based hierarchical secret sharing, Tassa uses polynomial derivatives, which have several limitations. First, since the shares at each level are generated from a single derivative, only one participant group (compartment) can be created at each level. Second, only secret recovery based on conjunctions is possible, and arbitrary secret recovery conditions cannot be specified. Third, because derivatives are used, Birkhoff interpolation is required, which is more complex and difficult to implement than Lagrange interpolation, which is used in polynomial-based secret sharing. [Overview of the project] [Problems that the invention aims to solve]
[0006] A method for sharing and recovering threshold secrets on a multi-compartment infrastructure, according to various embodiments of the present invention, may involve creating multiple compartments at a single level and embodying any access structure, including logical AND operations.
[0007] A method for sharing and recovering threshold secrets on a multi-compartment substrate, according to various embodiments of the present invention, may also apply Lagrangian interpolation using polynomials. [Means for solving the problem]
[0008] A method for sharing threshold secrets on a multi-compartment infrastructure according to various embodiments of the present invention may include the operation of generating an encrypted secret value using an external share belonging to at least one second compartment but not belonging to the first compartment, when at least one second compartment is unidirectionally related toward the first compartment; the operation of generating a first polynomial defining the first compartment using the encrypted secret value; and the operation of generating an internal share of the first compartment using the first polynomial.
[0009] A method for recovering a threshold secret on a multi-compartment base according to various embodiments of the present invention may include the following steps: recovering a first polynomial defining a first compartment using an internal share belonging to the first compartment, when at least one second compartment is unidirectionally related to the first compartment; obtaining an encrypted secret using the recovered first polynomial and an external share belonging to at least one second compartment; and decrypting the encrypted secret using the external share.
[0010] A method for sharing threshold secrets on a multi-compartment infrastructure, according to various embodiments of the present invention, may include the operation of creating or extending a second compartment that is unidirectionally associated with the first compartment, if a share relating to the first compartment exists; the operation of generating a first polynomial that defines the first compartment using the internal shares belonging to the first compartment and an encrypted secret value; and the operation of further generating internal shares belonging to the first compartment using the first polynomial. [Effects of the Invention]
[0011] The various embodiments of the present invention provide methods for sharing and recovering threshold secrets on a multi-compartment infrastructure, which may constitute diverse hierarchical secret sharing systems.
[0012] A method for sharing and recovering threshold secrets on a multi-compartment substrate, according to various embodiments of the present invention, may define an arbitrary access structure.
[0013] A variety of embodiments of the present invention offer the advantage that the method for sharing and recovering threshold secrets on a multi-compartment substrate may use Lagrangian interpolation based on polynomials. [Brief explanation of the drawing]
[0014] [Figure 1] This is a diagram showing some of the components for realizing a threshold secret sharing environment 100 according to an embodiment of the present invention. [Figure 2] This is a block diagram showing some of the components of an electronic device 200 according to one embodiment of the present invention. [Figure 3] This diagram shows a directed graph that can embody any access structure through various embodiments. [Figure 4] This is a sequence diagram illustrating a method for generating an internal share of a first compartment for secret sharing of a multi-compartment substrate, using various embodiments. [Figure 5a] This is a sequence diagram illustrating a method for generating internal shares of a first compartment for secret sharing of a multi-compartment substrate using polynomial interpolation, with various embodiments. [Figure 5b] This is a sequence diagram illustrating a method for generating internal shares of a first compartment for secret sharing of a multi-compartment substrate using polynomial interpolation, with various embodiments. [Figure 6a] This is a sequence diagram illustrating, through various embodiments, a method for generating an internal share of a first compartment for secret sharing of a multi-compartment substrate using polynomial coefficients. [Figure 6b] This is a sequence diagram illustrating, through various embodiments, a method for generating an internal share of a first compartment for secret sharing of a multi-compartment substrate using polynomial coefficients. [Figure 7] This is a diagram illustrating an embodiment of generating an internal share of a first compartment for the secret sharing of a multi-compartment base, according to various embodiments, showing the state before the internal share of the first compartment is generated. [Figure 8] This is a sequence diagram illustrating a method for recovering secrets from a multi-compartment substrate using various embodiments. [Figure 9] This is a sequence diagram illustrating a method for recovering secrets from a multi-compartment substrate using polynomial interpolation, based on various embodiments. [Figure 10] This is a sequence diagram illustrating a method for recovering secrets from a multi-compartment substrate using polynomial coefficients, based on various embodiments. [Figure 11] This is an embodiment of utilizing the internal share of the first compartment for secret recovery of a multi-compartment substrate, as illustrated by various embodiments, and is a diagram showing the state after the internal share of the first compartment has been generated, in relation to Figure 7. [Figure 12] This is a step diagram illustrating various embodiments of how to add an external share necessary for secret recovery to the first compartment for secret sharing on a multi-compartment infrastructure. [Figure 13] This diagram illustrates an example of adding a new external share set ri(m+1) to Ri in the state shown in Figure 11, where an internal share for the first compartment has already been allocated for the secret sharing of a multi-compartment base, according to various embodiments. [Figure 14] This is an illustrative diagram showing various hierarchical secret-sharing systems through diverse implementations. [Modes for carrying out the invention]
[0015] While the present invention may be subject to various modifications and may have numerous embodiments, specific embodiments are described in detail with illustrations in the drawings. However, this should not be understood as limiting the present invention to specific embodiments, but rather as including all modifications, equivalents, or substitutes that fall within the spirit and technical scope of the present invention. Similar reference numerals have been used for similar components in the description of each drawing.
[0016] Terms such as First, Second, A, B, etc., may be used to describe various components, but the components should not be limited by such terms. The terms are used solely for the purpose of distinguishing one component from another. For example, the First component may be named as the Second component without falling outside the scope of the present invention, and similarly, the Second component may be named as the First component. The terms and / or include combinations of multiple items of description or any one of multiple items of description.
[0017] When it is stated that one component is “connected” or “linked” to another component, it should be understood that it may be directly connected or linked to the other component, but it may also be that other components exist in between. On the other hand, when it is stated that one component is “directly connected” or “directly linked” to another component, it should be understood that there are no other components in between.
[0018] The terms used in this application are used solely to describe specific embodiments and are not intended to limit the invention. Unless the context clearly indicates otherwise, singular expressions include plural expressions. In this application, terms such as “includes” or “having” are intended to specify the existence of features, figures, stages, operations, components, parts, or combinations thereof described in the specification, and should not be understood to preemptively exclude the existence or possibility of adding one or more other features, figures, stages, operations, components, parts, or combinations thereof.
[0019] Unless otherwise defined, all terms used herein, including technical and scientific terms, have the same meaning as those generally understood by a person of ordinary skill in the art to which this invention pertains. Terms as defined in commonly used dictionaries should be interpreted as having the meaning consistent with their meaning in the context of the relevant art, and not as ideally or excessively formally defined in this application unless explicitly defined otherwise.
[0020] Preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0021] Figure 1 is a diagram showing some of the components for realizing a threshold secret sharing environment 100 according to an embodiment of the present invention.
[0022] Referring to Figure 1, the threshold secret sharing environment 100 assumes that multiple electronic devices 110, 120, and 130 are connected via a network 150 by wire or wireless, and can share or recover secrets via the network 150.
[0023] Figure 1 is an example for illustrating the invention, and the number of electronic devices is not limited to that shown in Figure 1. The threshold secret sharing environment 100 in Figure 1 is merely an example illustrating one environment applicable to this embodiment, and the environments applicable to this embodiment are not limited to the threshold secret sharing environment 100 in Figure 1.
[0024] In various embodiments, the multiple user terminal devices 110, 120, and 130 may be fixed electronic devices embodied in computer equipment or mobile electronic devices. Examples of the multiple user terminal devices 110, 120, and 130 include smartphones, mobile phones, navigation systems, computers, laptop computers, digital broadcasting terminals, PDAs (Personal Digital Assistants), PMPs (Portable Multimedia Players), and tablet PCs.
[0025] For example, Figure 1 shows the shape of a smartphone as an example of the first electronic device 110, but in various embodiments of the present invention, the first electronic device 110 may mean one of various physical computer devices that can communicate with other electronic devices 120, 130 via the network 150 using substantially wireless or wired communication methods.
[0026] An apparatus embodying the method for sharing and recovering threshold secrets on a multi-compartment base according to an embodiment of the present invention may be one of a plurality of user terminal devices 110, 120, 130. For example, the first electronic device 110 may generate a share of the threshold secret sharing base, and the second electronic device 120 and the third electronic device 130 may participate in the threshold secret sharing and receive a share from the first electronic device 110.
[0027] The communication method of network 150 is not limited, and may include not only communication methods that utilize communication networks that network 150 may include (for example, mobile communication networks, wired internet, wireless internet, broadcasting networks), but also short-range wireless communication between devices. For example, network 150 may include one or more arbitrary networks such as PAN (personal area network), LAN (local area network), CAN (campus area network), MAN (metropolitan area network), WAN (wide area network), BBN (broadband network), and the Internet.
[0028] Figure 2 is a block diagram showing some components of an electronic device 200 according to one embodiment of the present invention. Each of the user terminal devices 110, 120, and 130 described earlier may be embodied by the electronic device 200 shown through Figure 2, and the method for sharing and recovering threshold secrets on a multi-compartment substrate according to one embodiment may be embodied by such an electronic device 200.
[0029] Referring to Figure 2, the electronic device 200 may include a storage unit 210, a processor 220, a communication unit 230, an input / output interface 240, and a sensor unit 250, as shown in Figure 2.
[0030] The storage unit 210 is a computer-readable recording medium and may include a permanent mass storage device such as RAM (random access memory), ROM (read-only memory), and a disk drive. Here, the ROM and the permanent mass storage device such as a disk drive are separate permanent storage devices distinct from the storage unit 210 and may be included in the electronic device 200.
[0031] Furthermore, the storage unit 210 may store an operational system and at least one program code. Such software components may be loaded into the storage unit 210 from a computer-readable recording medium separate from the storage unit 210. Such a separate computer-readable recording medium may include computer-readable recording media such as floppy drives, disks, tapes, DVD / CD-ROM drives, and memory cards. In other embodiments, software components may be loaded into the storage unit 210 via a communication unit 230 that is not a computer-readable recording medium. For example, software components may be loaded into the storage unit 210 of the electronic device 200 based on a computer program installed by a file received via the network 150.
[0032] In various embodiments, the storage unit 210 may store encrypted information (passwords) or biometric information specified by the user.
[0033] The processor 220 is a component that controls the overall operation of the electronic device 200 and may be configured to process computer program instructions by performing basic arithmetic, logic, and input / output operations. Instructions may be provided to the processor 220 by a storage unit 210 or a communication unit 230. For example, the processor 220 may be configured to execute instructions received by program code stored in a recording device such as the storage unit 210.
[0034] The processor 220 may be configured, for example, to generate an encrypted secret value using an external share belonging to at least one second compartment but not belonging to the first compartment, when at least one second compartment is unidirectionally related to the first compartment, to generate a first polynomial defining the first compartment using the encrypted secret value, and to generate an internal share of the first compartment using the first polynomial.
[0035] The processor 220 may be configured to generate a first polynomial defining the first compartment by utilizing at least a portion of the internal shares belonging to the first compartment when at least one second compartment is unidirectionally related to the first compartment, to obtain an encrypted secret value using the generated first polynomial and external shares belonging to at least one second compartment that do not belong to the first compartment, and to decrypt the secret using the encrypted secret value.
[0036] The processor 220 may be configured, for example, to generate or extend a second compartment that is unidirectionally associated with the first compartment, generate a second encrypted secret value using an external share belonging to the second compartment, generate a first polynomial that defines the first compartment using the first and second encrypted secret values, and further generate an internal share belonging to the first compartment using the first polynomial.
[0037] The communication unit 230 may provide functions for communicating with other devices (for example, the storage device described earlier) via the network 150. For example, requests, commands, data, files, etc., generated by the processor 220 of the electronic device 200 from program code stored in a recording device such as the storage unit 210 may be transmitted to other devices via the network 150 under the control of the communication unit 230.
[0038] Conversely, signals, commands, data, and files from other devices may be received by the electronic device 200 via the network 150 and the communication unit 230. Signals, commands, and data received via the communication unit 230 may be transmitted to the processor 220 and the storage unit 210, and files may be stored in a storage medium (the permanent storage device described above) that the electronic device 200 may further include.
[0039] The input / output interface 240 may be a means for interface with the input / output device 260. For example, the input device may include a microphone, keyboard, or mouse, and the output device may include a display or speaker. In another example, the input / output interface 240 may be a means for interface with a device that integrates input and output functions into a single unit, such as a touchscreen.
[0040] The sensor module 250 can sense the operating state of the electronic device 200 (e.g., power or temperature) or the external environmental state (e.g., user status) and generate an electrical signal or data value corresponding to the sensed state. According to one embodiment, the sensor module 250 may include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biosensor, a temperature sensor, a humidity sensor, or an illuminance sensor.
[0041] Furthermore, in other embodiments, the electronic device 200 may include fewer or more components than those shown in Figure 2. However, it is not necessary to clearly illustrate most conventional technical components. For example, the electronic device 200 may be embodied to include at least a portion of the input / output device 250 described above, or it may further include other components such as a transceiver or a database. Figure 3 is a diagram illustrating directed graphs that can embody arbitrary access structures through various embodiments.
[0042] A node represents a compartment composed of participants, and an arrow indicates the condition that shares of an external compartment are required to recover a secret in the compartment. For example, referring to FIG. 3, it may mean that shares of compartments C1 and C2 are required to recover the secret in compartment C4. Compartment C1 without an arrow coming in from an external compartment means that shares of an external compartment are not required to recover the secret. When shares of an external compartment are not required to recover the secret as in compartment C1, the internal shares of compartment C1 can be generated using a conventional method such as the Shamir method as it is.
[0043] According to various embodiments of the present invention, an access structure may be defined for each compartment. For example, assuming a set of n i participants belonging to compartment C i is U i = {U (i、1) , U (i、2) ,..., U (i、ni)}, in compartment C i , the secret S can be recovered using t i internal share holders belonging to U i and shares of external share holders belonging to other compartments.
[0044] According to various embodiments of the present invention, the set of external share holders required to recover the secret in compartment C i may be denoted by r i(·) . If there are m i such sets, they may be represented as R i = {r i(1) , r i(2) ,... r i(mi)}. That is, as long as there is one element of R i , t i of compartment C iIt could also mean that the secret can be restored together with the owner of the internal share of the name.
[0045] Compartment C according to various embodiments of the present invention i The set of owners of internal and external shares who can restore the secret may be defined as an access set. The collection of access sets is placed in compartment C. i Access structure A i It may also be defined as follows. For example, compartment C i Access structure A i U is the set of owners of the internal share. i Power set 2 Ui R defined by the owner of the external share i Defined in, access structure A i It may also be defined as shown in the following formula.
[0046]
number
[0047] A method for sharing and recovering threshold secrets on a multi-compartment infrastructure, according to various embodiments of the present invention, may include an arbitrary set of external share owners in the access structure. Logical AND and various secret recovery conditions may also be specified. However, in the access structure of the present invention, external shares cannot substitute for internal shares. This differs from disjunctive hierarchical secret sharing techniques on logically coupled infrastructures, where higher-level shares can substitute for lower-level shares.
[0048] The basic idea of this invention is R iThe process involves using an external share to encrypt the secret, generating a polynomial with the encrypted secret value inserted, and then generating an internal share. While the polynomial can be reconstructed using the internal share, the result is an encrypted secret, and decrypting it requires the external share used for encryption.
[0049] While various encryption methods may be used in this invention, security of secrets can be guaranteed by using an encryption method that is resistant to COA (Ciphertext-Only Attack) while preserving sufficient entropy. Generally, in secret sharing methods using polynomials, security of secrets is guaranteed by using randomly generated polynomials. In contrast, in this invention, since the polynomial is derived from the encrypted secret value, security of secrets cannot be guaranteed unless the encrypted secret value has sufficient entropy. Furthermore, since the encrypted secret value is obtained after the polynomial is reconstructed using internal shares, the encryption algorithm must be resistant to COA (Ciphertext-Only Attack). Otherwise, there is a possibility that the secret may be discovered even with only internal shares.
[0050] According to various examples, compartment C i The collection of external shareholder owners (R) i ={r i(1) , r i(2) ,...r i(mi) The set of encryption keys obtained from} is K i ={K i(1) , K i(2) ,...K i(mi) It may also be shown as}. Each r i(k) Encryption key K from external share i(k) We assume that the method for finding this is known in advance.
[0051] In the following explanation, Compartment C i Participant U belonging to (i、j) The share to be allocated to V (i、j) Assuming that such a set of shares is V i ={V (i、1) , V (i、2) ,...,V (i、ni) You may also represent this with}.
[0052] Figure 4 is a sequence diagram illustrating various embodiments of methods for generating an internal share of a first compartment for secret sharing on a multi-compartment substrate.
[0053] Referring to Figure 4, in operation 410, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can generate an encrypted secret value using an external share that does not belong to the first compartment but belongs to at least one second compartment, when at least one second compartment is unidirectionally related toward the first compartment.
[0054] In various embodiments, the secret sharing system may have compartments that are unidirectionally directed or related.
[0055] In Figure 3, for example, if compartment C4 is the first compartment, then compartments C1 and C2 become the second compartment and may be related in one direction toward the first compartment. As another example, if compartment C2 is the first compartment, then compartment C1 becomes the second compartment and may be related in one direction toward the first compartment.
[0056] In various embodiments, electronic devices can generate encrypted secret values using external shares that do not belong to the first compartment but belong to at least one second compartment. Figure 3 shows, for example, a case where compartment C4 is the first compartment and compartments C1 and C2 are the second compartments, and {U} belongs to compartment C1. (1、1) , U (1、2) , ...} and / or belonging to compartment C2 {U (2、1) , U (2、2) A secret value can be generated using {U}. Another example is when compartment C2 is the first compartment and compartment C1 is the second compartment, then {U} belonging to compartment C1. (1、1) , U (1、2) Encrypted secret values can be generated using , ...}.
[0057] In operation 420, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can use an encrypted secret value to generate a first polynomial that defines a first compartment.
[0058] In various embodiments, an electronic device can generate at least one coordinate obtained by encrypting a secret value using an encrypted secret value, and generate a first polynomial that passes through the coordinate obtained by encrypting the secret value. For example, the electronic device can use an encryption algorithm E(key, plaintext) to generate m points (n+1, E(K) that have the value obtained by encrypting a secret S as their coordinate. i(1) , S)), (n+2, E(K i(2) ,S)),...(n+m,E(K i(m) Generate S)) and randomly select coefficient a while passing through the m generated points. t-1 a t-2 ,...,a m A polynomial of degree (t-1) having f i (x=a t-1 x t-1 +a t-2 x t-2+...a m-1 x m-1 +a m-2 x m-2 +...a0 can be generated.
[0059] In various embodiments, an electronic device can generate at least one coefficient obtained by encrypting a secret value using an encrypted secret value, and generate a first polynomial using the coefficient obtained by encrypting the secret value. For example, the electronic device can use an encryption algorithm E(key, plaintext) to encrypt m coefficients a of the secret S. m-1 =E(K i(m) , S), a m-2 =E(K i(m-1) ,S),...,a0=E(K i(1) Generate S), and combine the generated coefficients with a randomly selected coefficient a t-1 a t-2 ,...,a m (t-1)th order f has i (x=a t-1 x t-1 +a t-2 x t-2 +...a m-1 x m-1 +a m-2 x m-2 +...a0 can be generated.
[0060] In operation 430, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can use a first polynomial to generate an internal share of the first compartment.
[0061] Figure 3 shows, for example, that if compartment C4 is the first compartment and compartments C1 and C2 are the second compartments, the electronic device uses the first polynomial to determine {U} belonging to compartment C4. (4、1) , U (4、2),...} can be generated. As another example, when compartment C2 is the first compartment and compartment C1 is the second compartment, the electronic device can use the first polynomial to generate {U (2、1) , U (2、2) ,...} belonging to compartment C2.
[0062] FIGS. 5A to 5B are sequential diagrams showing a method for generating internal shares of a first compartment for multi-compartment based secret sharing using polynomial interpolation according to various embodiments.
[0063] Referring to FIGS. 5A to 5B, when the secret S and R i are given, after obtaining K i from R i first, the process of generating n i , n i internal shares for (t i , n i ) secret sharing will be described. In the following, for convenience of explanation, the subscripts such as t i , n i , m
[0064] In operation 510, the electronic device (e.g., the electronic devices 110, 120, 130 of FIG. 1 or the electronic device 200 of FIG. 2) can generate an encrypted secret value based on coordinates using at least a part of the secrets S and R i .
[0065] Referring to FIG. 5B, for example, after the electronic device selects t and n that satisfy n≧t≧m, it uses the encryption algorithm E(key, plaintext) to encrypt the secret S and has m points with the encrypted values as coordinates (n + 1, E(K i(1) , S)), (n + 2, E(K i(2) , S)),... (n + m, E(K i(m) , S)) can be generated.
[0066] In operation 520, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can use the generated encrypted secret to produce a polynomial that defines the compartment.
[0067] Figure 5b shows, for example, an electronic device passing through m generated points, with a randomly selected coefficient a t-1 a t-2 ,...,a m A polynomial of degree (t-1) having f i (x=a t-1 x t-1 +a t-2 x t-2 +...a m-1 x m-1 +a m-2 x m-2 +...a0 can be generated.
[0068] In operation 530, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can generate an internal share using a polynomial that defines a compartment.
[0069] Figure 5b shows, for example, that an electronic device is a polynomial f i (x) is a point (1, f i (1), (2, f i (2)), ...(n, f i (n)) from n internal shares V (i、1) =f i (1), V (i、2) =f i (2), ...V (i、n) =f i (n) is generated, and compartment C i Participant U (i、1) , U (i、2) ,...,U (i、ni) It may be assigned to that.
[0070] Figures 6a to 6b are sequence diagrams illustrating, in various embodiments, a method for generating an internal share of a first compartment for secret sharing of a multi-compartment substrate using polynomial coefficients.
[0071] Referring to Figures 6a to 6b, the secrets S and R i Given R i From K i After first finding (t i , n i ) n for secret sharing i This explains the process of generating individual internal shares. In the following, for the sake of explanation, t i , n i , m i Subscripts such as t, n, and m have been omitted and are indicated by these subscripts.
[0072] In operation 610, the electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) is secret S and R i At least a portion of this can be used to generate a coefficient-based encrypted secret value.
[0073] Figure 6b shows, for example, an electronic device selects t and n that satisfy n≧t≧m, and then uses the encryption algorithm E(key, plaintext) to encrypt the secret S using m coefficients a m-1 =E(K i(m) , S), a m-2 =E(K i(m-1) ,S),...,a0=E(K i(1) It is possible to generate S).
[0074] In operation 620, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can use the generated encrypted secret to produce a polynomial that defines the compartment.
[0075] Figure 6b shows, for example, an electronic device that generates a coefficient and randomly selected coefficient a t-1 a t-2 ,...,a m (t-1)th order f has i (x=a t-1 x t-1 +a t-2 xt-2 +...a m-1 x m-1 +a m-2 x m-2 +...a0 can be generated.
[0076] In operation 630, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can generate an internal share using a polynomial that defines a compartment.
[0077] Figure 6b shows, for example, an electronic device, which is a polynomial f i (x) is a point (1, f i (1), (2, f i (2)), ...(n, f i (n)) from n internal shares V (i、1) =f i (1), V (i、2) =f i (2), ...V (i、n) =f i (n) is generated, and compartment C i Participant U (i、1) , U (i、2) ,...,U (i、ni) It may be assigned to that.
[0078] Figure 7 is a diagram showing the state before the internal share of the first compartment is generated for the secret sharing of a multi-compartment substrate, according to various embodiments.
[0079] In Figure 7, the finite field F is shown. q An example of applying the secret sharing described above is shown. Finite field F q The value of is defined by the remaining value after dividing by q, and for computational convenience, we assume the prime number 19 as the value of q. Thus, the secret S used for secret sharing, and the coefficient a i The coordinate values and share are all F 19 It is defined as follows.
[0080] Referring to Figure 7, a secret sharing system consisting of three compartments is shown. Compartment C1 contains two internal shares V1 = {V (1、1) , V (1、2)}, Compartment C2 has 4 internal shares V2 = {V (2、1) , V (2、2) , V (2、3) , V (2、4) Assume that {V} has already been allocated. Compartment C3 has not yet been allocated any internal shares. In compartment C3, t3=2 and n3=3, and compartment C3 has two or more internal shares and external shares {V (1、2) , V (2、4) Three internal shares can be generated so that the secret S can be restored.
[0081] Let S=8 secrets, and the set of external shares {V} required for secret recovery. (1、2) , V (2、4) The key obtained by} is K 1(1) When the secret is encrypted, E(K 1(1) , S) = E(K 1(1) Assume that 8) = 7.
[0082] (Example 1) A method for generating internal shares of the first compartment for secret sharing of a multi-compartment base using polynomial interpolation. In Figure 7, since m3=1 and n3=3, the electronic device in various embodiments has a single point (n) whose coordinates are the values obtained by encrypting the secret S using the encryption algorithm E(). 3+1 , E(K 1(1) , S)), that is, (4, 7) can be generated first. Since t3=2, the electronic device can generate a linear polynomial f3(x)=a1x+a0=3x+14 with a randomly selected coefficient a1=3 while passing through the generated point (4, 7). Since n3=3, the electronic device can generate three internal shares V from three points (1, f3(1)), (2, f3(2)), and (3, f3(3)) passing through the polynomial f3(x). (3、1) =f3(1)=17, V (3、2)=f3(2)=1, V (3、3) =f3(3)=4 can be generated.
[0083] (Example 2) A method for generating internal shares of a first compartment for secret sharing of a multi-compartment base using polynomial coefficients In Figure 7, since m3=1 and n3=3, the electronic device, according to various embodiments, uses the encryption algorithm E() to encrypt the secret S, and the result is a single coefficient a0=E(K 1(1) , S), that is, a0=7 may be determined first. Since t3=2, the electronic device can generate a linear polynomial f3(x)=a1x+a0=3x+7 with the remaining coefficient a1=3 randomly selected. Since n3=3, the electronic device can obtain three internal shares V from three points (1, f3(1)), (2, f3(2)), and (3, f3(3)) passing through the polynomial f3(x). (3、1) =f3(1)=10, V (3、2) =f3(2)=13, V (3、3) It is possible to generate =f3(3)=16.
[0084] In the secret sharing system shown in Figure 7, the access structure A3 of compartment C3 is {{U (3、1) , U (3、2) , U (1、2) , U (2、4)}, {U (3、1) , U (3、3) , U (1、2) , U (2、4)}, {U (3、2) , U (3、3) , U (1、2) , U (2、4)}, {U (3、1) , U (3、2) , U (3、3) , U (1、2) , U (2、4) It becomes}}.
[0085] Figure 8 is a sequence diagram illustrating various embodiments of a method for recovering secrets from a multi-compartment substrate.
[0086] Referring to Figure 8, in operation 810, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can reconstruct a first polynomial defining the first compartment by utilizing the internal shares belonging to the first compartment, when at least one second compartment is related to the first compartment in a unidirectional manner.
[0087] In various embodiments, the secret sharing system may have compartments that are unidirectionally directed or related.
[0088] In Figure 3, for example, if compartment C4 is the first compartment (assuming no internal shares exist), then compartments C1 and C2 become the second compartment and may be unidirectionally related toward the first compartment. As another example, if compartment C2 is the first compartment (assuming no internal shares exist), then compartment C1 becomes the second compartment and may be unidirectionally related toward the first compartment.
[0089] In various embodiments, the electronic device can reconstruct the first polynomial defining the first compartment by utilizing at least a portion of the internal shares belonging to the first compartment. Figure 3 shows, for example, when compartment C4 is the first compartment and compartments C1 and C2 are the second compartments, the {U} belonging to compartment C4. (4、1) , U (4、2) Using at least a part of , ...}, we can reconstruct the first polynomial that defines compartment C4. Another example is when compartment C2 is the first compartment and compartment C1 is the second compartment, then {U (2、1) , U (2、2) Using at least a portion of , ...}, we can reconstruct the first polynomial that defines compartment C2.
[0090] In various embodiments, electronic devices can reconstruct a (t-1)th polynomial using t internal shares. For example, an electronic device can apply Lagrangian interpolation to reconstruct a polynomial f i (x) can be reconstructed.
[0091] In operation 820, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) may obtain an encrypted secret value using the recovered first polynomial and an external share belonging to at least one second compartment.
[0092] In various embodiments, the electronic device generates the polynomial f i The secret value E(K) is calculated by finding the y-axis coordinate of the point whose x-axis coordinate is n+k among the points that (x) passes through. i (k), S) may be acquired. For example, an electronic device may acquire E(K i(k) , S)=f i Using the point that (n+k) i You may calculate (n+k) and obtain an encrypted secret value.
[0093] In operation 830, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) may decrypt the encrypted secret value using an external share.
[0094] Electronic devices, according to various embodiments, are r i (k) Key K required for decryption i (k) can be determined, and the secret S can be recovered using the decryption algorithm D(key, ciphertext). For example, if the encrypted secret S is encoded in the coordinates, the electronic device can calculate S=D(K i(k) , E(K i(k) The secret S can be recovered by utilizing the fact that S)). Another example is when the secret S is encoded in polynomial coefficients, then the electronic device can recover E(K i (k, S) = a k-1 Using the point that S=D(K i(k) , E(Ki(k) The secret S can be restored using S).
[0095] Figure 9 is a sequence diagram illustrating a method for recovering secrets from a multi-compartment substrate using polynomial interpolation, based on various embodiments.
[0096] In operation 910, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can use the internal shares belonging to the first compartment to reconstruct the first polynomial that defines the first compartment.
[0097] Figure 5b shows, for example, an electronic device, with an external share of the owner set r i Access set α∈A including (k) i Using the t internal shares belonging to the access set α, we obtain a polynomial of degree (t-1) f i (x=a t-1 x t-1 +a t-2 x t-2 +...a m-1 x m-1 +a m-2 x m-2 +...a0 can be restored.
[0098] In operation 920, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) may obtain an encrypted secret value based on coordinates using an external share belonging to the second compartment.
[0099] Figure 5b shows, for example, an electronic device, and the restored polynomial f i The secret value E(K) is calculated by finding the y-axis coordinate of the point whose x-axis coordinate is n+k among the points that (x) passes through. i (k), S) may be acquired. The electronic device is E(K i (k, S) = f i Using the point that (n+k) i You may also calculate (n+k).
[0100] In operation 930, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) may decrypt the encrypted secret value using an external share.
[0101] Figure 5b shows, for example, an electronic device, r i (k) Key K required for decryption i By finding (k), the secret S can be recovered using the decryption algorithm D(key, ciphertext). For an electronic device, S=D(K i (k), E(K i The secret S can be reconstructed by taking advantage of the fact that (k), S)).
[0102] Figure 10 is a sequence diagram illustrating a method for recovering secrets from a multi-compartment substrate using polynomial coefficients, based on various embodiments.
[0103] In operation 1010, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can use the internal shares belonging to the first compartment to reconstruct the first polynomial that defines the first compartment.
[0104] Figure 6b shows, for example, an electronic device, with an external share of the owner set r i Access set α∈A including (k) i Using the t internal shares belonging to the access set α, we obtain a polynomial of degree (t-1) f i (x=a t-1 x t-1 +a t-2 x t-2 +...a m-1 x m-1 +a m-2 x m-2 +...a0 can be restored.
[0105] In operation 1020, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) may use an external share belonging to the second compartment to obtain an encrypted secret value based on a coefficient.
[0106] Figure 6b shows, for example, an electronic device, and the restored polynomial f i The secret value E(K) is calculated by finding the y-axis coordinate of the point whose x-axis coordinate is n+k among the points that (x) passes through. i (k), S) may be acquired. The electronic device is E(K i (k, S) = f i Using the point that (n+k) i You may also calculate (n+k).
[0107] In operation 1030, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) may decrypt the encrypted secret value using an external share.
[0108] Figure 6b shows, for example, an electronic device, r i (k) Key K required for decryption i (k) can be determined, and the secret S can be recovered using the decryption algorithm D(key, ciphertext). The electronic device is E(K i (k, S) = a k-1 Therefore, S = D(K i (k), E(K i The secret S can be reconstructed by taking advantage of the fact that (k), S)).
[0109] Figure 11 is a diagram illustrating an example of utilizing the internal share of the first compartment for secret recovery of a multi-compartment substrate, in relation to Figure 7, and shows the state after the internal share of the first compartment has been generated.
[0110] (Example 1) Method for recovering secrets from a multi-compartment substrate using polynomial interpolation. In various embodiments, the electronic device has two internal share V (3、2) , V (3、3) and one external share set {V (1、2) , V (2、4) The secret can be recovered using}. The electronic device has two internal shares V (3、2) =1, V(3、3) Using =4, the polynomial f3(x)=3x+14 can be generated by Lagrangian interpolation. The encrypted secret is point (n 3+1 The y-axis coordinates of E(K1(1),S)) may also be the values of the y-axis. Since n3=3, the electronic device may obtain E(K1(1),S)=f3(4)=7. Also, the electronic device may use the point S=D(K1(1),E(K1(1),S)) to obtain the external share set {V (1、2) , V (2、4) Alternatively, we can calculate K1(1) from} and obtain S=D(K1(1),7)=8.
[0111] (Example 2) Method for recovering secrets from a multi-compartment substrate using polynomial coefficients In various embodiments, the electronic device has two internal share V (3、2) , V (3、3) and one external share set {V (1、2) , V (2、4) The secret can be recovered using}. The electronic device has two internal shares V (3、2) =13, V (3、3) Using =16, the polynomial f3(x)=3x+7 can be generated by Lagrange interpolation. Considering that the encrypted secret is coefficient a0, the electronic device may determine that E(K1(1),S)=a0=7. Alternatively, the electronic device may use the fact that S=D(K1(1),E(K1(1),S)) to determine the outer share set {V (1、1) , V (2、4) Alternatively, we can calculate K1(1) from} and obtain S=D(K1(1),7)=8.
[0112] Figure 12 is a sequence diagram illustrating various embodiments of adding an external share necessary for secret recovery to the first compartment for secret sharing on a multi-compartment infrastructure.
[0113] In Figure 12, Compartment C i An internal share for R has already been allocated. i A new external share set r i(m+1) This shows how to add it.i(m+1) The key obtained from this is K i(m+1) Let's assume that...
[0114] When a new set of external shares is added, the number of internal shares n, the critical value t, and the polynomial f i (x) may be changed. For example, if n* and t* are the number of internal shares and threshold after the change, respectively, then any n* and t* that satisfy n*≧t*≧n+m+1 may be selected.
[0115] In Figure 12, assuming that n* and t* were selected first, the polynomial newly generated after the change is f i You can also prove it using *(x).
[0116] Referring to Figure 12, in operation 1210, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) may create or extend a second compartment that is unidirectionally related to the first compartment, if a share relating to the first compartment exists.
[0117] Through various implementations, the second compartment is a new external share set r i It may also be defined in a compartment containing (m+1).
[0118] In various embodiments, the first compartment may include a share relating to the first compartment. This share may include, for example, all internal shares belonging to the first compartment and all external shares not belonging to the first compartment. For example, the first compartment may not have any external compartments unidirectionally related to it. For instance, if there are no external compartments relating to the first compartment, the share relating to the first compartment may consist only of internal shares belonging to the first compartment. In this case, the second compartment can be created by adding new external shares necessary to restore the secret in the first compartment. Another example is when there are external compartments relating to the first compartment; the share relating to the first compartment may consist of internal shares belonging to the first compartment and external shares not belonging to the first compartment. In this case, the second compartment can be expanded by adding new external shares necessary to restore the secret in the first compartment.
[0119] In operation 1220, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can generate an encrypted secret value using an external share belonging to the second compartment.
[0120] For example, an electronic device uses an encryption algorithm E(key, plaintext) to encrypt a secret S into a value E(K i (m+1), S) can be generated.
[0121] In operation 1230, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can generate a first polynomial that defines the first compartment using the internal shares belonging to the first compartment and the encrypted secret value.
[0122] When the encrypted value of secret S is used as the coordinates of a point, for example, an electronic device has (m+1) points (n*+1, E(Ki(1), S)), (n*+2, E(Ki(2), S)), ... (n*+m, E(Ki(m), S)), (n*+m+1, E(Ki(m+1), S)) defined by (m+1) encrypted secret values and n points (1, V) determined by the internal share of the first compartment. (i、1) ), (2, V (i、2) ), ...(n, V (i、n) The (t-1) degree polynomial f passing through ) i *(x)=a t*-1 x t*-1 +a t*-2 x t*-2 +...a m x m +a m-1 x m-1 +a m-2 x m-2 +...a0 can be generated. In this case, if t* > n + m + 1, (t* - nm - 1) coefficients may be selected randomly.
[0123] When the encrypted value of secret S is used as the coefficient of a polynomial, for example, an electronic device has (m+1) coefficients defined by (m+1) encrypted secret values, and n points (1, V) determined by the internal share of the first compartment. (i、1) ), (2, V (i、2) ), ...(n, V (i、n) The (t-1) degree polynomial f passing through ) i *(x)=a t*-1 x t*-1 +a t*-2 x t*-2 +...a m x m +a m-1 x m-1 +a m-2 x m-2 +...a0 can be generated. In this case, if t* > n + m + 1, (t* - nm - 1) coefficients may be selected randomly.
[0124] In operation 1240, an electronic device (e.g., electronic devices 110, 120, 130 in Figure 1 or electronic device 200 in Figure 2) can use the first polynomial to generate further internal shares belonging to the first compartment.
[0125] For example, an electronic device is a polynomial f i *The point (n+1, f) passing through (x) i *(n+1)), (n+2, f i *(n+2)), ...(n*, f i From *(n*)), there are (n*-n) shares V (i、n+1) =f i *(n+1), V (i、n+2) =f i *(n+2), ...V (i、n*) =f i *(n*) can be generated further.
[0126] Figure 13 shows the state in Figure 11 where an internal share for the first compartment has already been allocated for the secret sharing of a multi-compartment base according to various embodiments. i A new external share set r i(m+1) This is a drawing showing an example of adding [something].
[0127] According to the embodiment shown in Figure 13, the electronic device may add an external share set without affecting the existing share. This may be used when implementing a secret sharing system represented by a directed graph in which a cycle exists.
[0128] In Figure 13, for the sake of explanation, we assumed that R1 is equal to compartment C1, that is, that an external share is not required to restore the secret. However, in various embodiments, the electronic device may also utilize this embodiment when an external share R1 exists for compartment C1.
[0129] In Figure 13, external share V is used to restore the secret of compartment C1. (3、3) We assumed that =4 is necessary. That is, R1={{U(3、3) An example of how to modify it to become}} is shown.
[0130] Compartment C1 uses a randomly generated polynomial f1(x)=13x+12 and two shares V1={V (1、1) , V (1、2)}, that is, V (1、1) =6, V (1、2) It is also possible to assign =0. Since m1=0, we may choose new t1* and n1* that satisfy n1*≧t1*≧n1+m1+1=3. For example, we may newly choose t1*=3 and n1*=4.
[0131] (Example 1) External share V (3、3) A single point (n*+1, E(K1(1), S)) can be generated whose coordinates are the encrypted value of the secret S using an encryption key K1(1) which may be calculated as follows. When E(K1(1), S) = 13, a polynomial of degree (t*-1) f1*(x) can be formed by passing through the generated point (5, 13) and two points (1, 6) and (2, 0) determined by the original share, i.e., f1*(x) = x 2 The electron apparatus can generate +10x+14. The electron apparatus has two internal shares V from the points (n1+1, f1*(n1+1)), (n+2, f1*(n+2)), i.e., (3, 15) and (4, 13) that pass through the polynomial f1*(x). (1、3) =f1*(3)=15, V (1、4) It is possible to generate =f1*(4)=13 further.
[0132] (Example 2) External share V (3、3) The coefficient a0 = E(K1(1), S) may be determined by calculating the encryption key K1(1) and the value obtained by encrypting the secret S using the encryption algorithm E(). If a0 = E(K1(1), S) = 13, then the (t*-1) polynomial f1*(x) = 10x, which has the coefficient generated in this way and passes through two points (1, 6) and (2, 0) determined by the existing share, will be formed. 2The electronic device can be generated by +21x+13. The electronic device has two internal shares V from the points (n1+1, f1*(n1+1)), (n+2, f1*(n+2)), i.e., (3, 14) and (4, 10) passing through the polynomial f1*(x). (1、3) =f1*(3)=14, V (1、4) It is possible to generate another value of =f1*(4)=10.
[0133] Figure 14 is an illustrative diagram showing various hierarchical secret sharing systems based on diverse embodiments.
[0134] This invention is a generalization of a logical AND-based hierarchical secret sharing method like Tassa, and offers three advantages.
[0135] Firstly, various hierarchical secret-sharing systems can be constructed. In particular, it becomes possible to create multiple compartments at a single level. By redrawing the secret-sharing system in Figure 3, which is represented as a directed acyclic graph, using topological sorting, the hierarchical structure in Figure 14 can be generated.
[0136] Referring to Figure 14, a single level may contain several compartments, and there is no limit to the number of levels. For comparison, in Tassa's method using derivatives, only one compartment exists per level, and the number of levels is limited by the degree of the initial polynomial.
[0137] Secondly, an arbitrary access structure may be defined. The access structure may be specified using a logical conjunction, or any external share, as a condition for recovering the secret in each compartment.
[0138] Thirdly, the present invention is based on polynomials and may utilize Lagrange interpolation. Lagrange interpolation is less complex and easier to implement than Birkhoff interpolation, which is required when using derivatives.
[0139] The features, structures, and effects described in the examples above are included in at least one example of the present invention, and are not necessarily limited to just one example. Furthermore, the features, structures, and effects exemplified in each example can be combined or modified and implemented in other examples by a person with ordinary skill in the art to which the example belongs. Therefore, such combinations and modifications must be considered to fall within the scope of the present invention.
[0140] Furthermore, although the above description has focused on embodiments, these are merely illustrative examples and do not limit the present invention. Anyone with ordinary skill in the art to which the present invention belongs will understand that various modifications and applications not exemplified above are possible, as long as they do not deviate from the essential characteristics of these embodiments. For example, each component specifically shown in the embodiments may be modified and implemented. Any differences arising from such modifications and applications must be considered to fall within the scope of the present invention as defined in the appended claims.
Claims
1. A method for sharing hierarchical threshold secrets on a multi-compartment substrate using electronic devices including a processor, The processor performs the operation of generating an encrypted secret value using an encryption key obtained from an external share, which is a higher-level share belonging to the at least one second compartment but does not belong to the first compartment, when at least one second compartment is unidirectionally related toward the first compartment. The processor operates by using the encrypted secret value to generate coefficients or constant terms of a first polynomial that defines the first compartment, The process includes the operation of the processor generating an internal share of the first compartment using the first polynomial which contains an encrypted secret value, The at least one second compartment is configured as a higher hierarchy than the first compartment, A method for sharing threshold secrets on a multi-compartment infrastructure, characterized in that the external share is used to restore the secret of at least one second compartment, and the internal share is used to restore the secret of the first compartment.
2. The operation of generating a first polynomial that defines the first compartment using the encrypted secret value is: The operation of generating at least one coordinate with the encrypted secret value using the encrypted secret value, A method for sharing a threshold secret of a multi-compartment substrate according to claim 1, further comprising the operation of generating the first polynomial that passes through the coordinates of the encrypted secret value.
3. A method for sharing a threshold secret on a multi-compartment base according to claim 2, further comprising the operation of generating m points whose coordinates are the encrypted values of the secret S using an encryption algorithm.
4. The operation of generating a first polynomial that defines the first compartment using the encrypted secret value is: The operation of generating at least one coefficient by encrypting the secret value using the encrypted secret value, A method for sharing a threshold secret of a multi-compartment base according to claim 1, comprising the operation of generating the first polynomial using the coefficients obtained by encrypting the secret value.
5. A method for sharing a threshold secret on a multi-compartment base according to claim 4, further comprising the operation of generating m coefficients that encrypt the secret S using an encryption algorithm.
6. A method for sharing threshold secrets on a multi-compartment infrastructure according to claim 4, comprising the operation of assigning the internal shares to the participants of the first compartment.
7. A method for recovering a hierarchical threshold secret of a multi-compartment substrate using an electronic device including a processor, The processor performs the operation of reconstructing an incomplete first polynomial that defines the first compartment by utilizing the internal shares belonging to the first compartment, when at least one second compartment is related to the first compartment in a one-way direction. The processor performs an operation to obtain an encrypted secret value related to the completion of the first polynomial by utilizing the recovered incomplete first polynomial and the external shares belonging to at least one second compartment, The process includes the operation of the processor using the external share to decrypt the secret using the encrypted secret value, The encrypted secret value relates to the coefficient or constant term of the first polynomial, The at least one second compartment is configured as a higher hierarchy than the first compartment, A method for recovering threshold secrets on a multi-compartment base, characterized in that the external share is used to recover the secret of at least one second compartment, and the internal share is used to recover the secret of the first compartment.
8. The operation of decrypting the secret using the encrypted secret value is as follows: A method for recovering a threshold secret on a multi-compartment substrate according to claim 7, comprising the operation of recovering an encrypted secret S through coordinates.
9. A method for restoring a threshold secret of a multi-compartment substrate according to claim 8, further comprising the operation of restoring the secret S using a restoration algorithm.
10. The operation of decrypting the secret using the encrypted secret value is as follows: A method for recovering a threshold secret on a multi-compartment substrate according to claim 7, further comprising the operation of recovering a secret S encrypted through a coefficient.
11. A method for recovering a threshold secret of a multi-compartment substrate according to claim 10, further comprising the operation of recovering the secret S using a decryption algorithm.
12. The operation of using the internal shares belonging to the first compartment to reconstruct the first polynomial that defines the first compartment is: A method for recovering a threshold secret on a multi-compartment base according to claim 7, comprising the operation of generating a first polynomial that defines the first compartment based on Lagrangian interpolation.
13. A method for sharing hierarchical threshold secrets on a multi-compartment substrate using electronic devices including a processor, The processor, if a share exists relating to the first compartment, performs the operation of creating or extending a second compartment that is unidirectionally related to the first compartment, The processor generates an encrypted secret value using an encryption key obtained from an external share, which is a higher-level share belonging to the second compartment. The processor operates by using the internal share belonging to the first compartment and the encrypted secret value to generate coefficients or constant terms of a first polynomial that defines the first compartment, The processor further generates internal shares belonging to the first compartment using the first polynomial which includes an encrypted secret value, At least one of the second compartments is configured as a higher hierarchy than the first compartment, A method for sharing threshold secrets on a multi-compartment infrastructure, characterized in that the external share is used to restore the secret of at least one of the second compartments, and the internal share is used to restore the secret of the first compartment.