Multi-Threshold Secret Sharing for Hierarchical Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional secret sharing techniques lack flexibility in managing individual components of a secret key, as they treat all components equally and do not allow for hierarchical access or assignment of importance, making them inadequate for applications requiring different thresholds and weights among various groups.

Innovation Solution

A multiple threshold secret sharing scheme is introduced, where a secret value is divided into components with assigned threshold levels, allowing different groups to recover the secret with varying numbers of components based on their threshold levels, and enabling weights to be assigned to each component for hierarchical access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional secret sharing techniques are used, then the secret key can be divided and distributed among users, but all components are treated equally without flexibility for hierarchical access or different importance levels

Engineering Contradiction:
Improveflexibility in managing key componentsVSAvoidcomplexity of secret sharing scheme
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The secret key is segmented into multiple components with different threshold levels. Each component is assigned a specific threshold value that determines its importance and the number of components needed to recover the secret. This segmentation allows hierarchical access control where different groups of users can recover the secret based on their assigned threshold levels, providing flexibility without excessive complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different key components are assigned different threshold levels (local qualities) rather than treating all components uniformly. This allows certain components to have higher importance (lower threshold) than others, enabling hierarchical access where some users can recover the secret with fewer components while others require more. This differential assignment provides adaptability while maintaining manageable scheme complexity.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If all key components are treated equally in secret sharing, then the scheme is simple to implement, but it cannot provide hierarchical access or assign different importance levels to different components

Engineering Contradiction:
Improvehierarchical access capabilityVSAvoidease of key management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The secret sharing scheme is made dynamic by allowing different threshold levels to be assigned to different components based on their importance. This dynamic assignment enables hierarchical access control where the system can adapt to different recovery scenarios. The threshold levels can be adjusted to reflect changing security requirements and user hierarchies, providing adaptability while maintaining ease of operation through a systematic approach to threshold assignment.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If a multi-threshold secret sharing scheme is implemented, then flexible hierarchical access is achieved, but the system complexity increases compared to conventional schemes

Engineering Contradiction:
Improveflexibility for different groups with different thresholdsVSAvoidcomplexity of secret sharing scheme
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The scheme manages complexity by systematically changing the threshold parameter for different components. Instead of creating entirely separate schemes for different hierarchical levels, the invention modifies the threshold parameter to control access. This parameter-based approach provides flexible hierarchical access for different groups while maintaining a unified secret sharing framework, thereby limiting the increase in system complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7787619B2Method and apparatus for secure key management using multi-threshold secret sharing
Publication Date: 2010.08.31 AVAYA INC
  • US7787619B2 patent drawing
  • US7787619B2 patent drawing
  • US7787619B2 patent drawing

AI summary

A method and apparatus are disclosed for managing components of a secret key according to a secret sharing scheme. The disclosed secret sharing scheme divides a secret value, R, into n secret components (R1, R2, . . . , Rn) and one super component, S, in such a way that R can be computed from (i) any k or more Ri components (k<n); or (ii) S and any one component of Ri. The secret components (R1, R2, . . . , Rn) are distributed to a number of authorized users. A multiple threshold secret sharing scheme assigns various users in a group into one of a number of classes. Each user class has a corresponding threshold level that indicates the number of users that must come together with their assigned components to obtain access to the shared secret. The multiple threshold scheme divides the secret into n components each having an assigned threshold level (i.e., the number of such components that are required to obtain the secret). Any component having a lower threshold level can satisfy the role of a component having a higher threshold level. The multiple threshold scheme provides a hierarchical scheme that allows the secret, R, to be shared among different groups of people with different thresholds.