Multi-Threshold Secret Sharing for Hierarchical Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional secret sharing techniques lack flexibility in managing individual components of a secret key, as they treat all components equally and do not allow for hierarchical access or assignment of importance, making them inadequate for applications requiring different thresholds and weights among various groups.
Innovation Solution
A multiple threshold secret sharing scheme is introduced, where a secret value is divided into components with assigned threshold levels, allowing different groups to recover the secret with varying numbers of components based on their threshold levels, and enabling weights to be assigned to each component for hierarchical access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional secret sharing techniques are used, then the secret key can be divided and distributed among users, but all components are treated equally without flexibility for hierarchical access or different importance levels
Solution Approach 1:
The secret key is segmented into multiple components with different threshold levels. Each component is assigned a specific threshold value that determines its importance and the number of components needed to recover the secret. This segmentation allows hierarchical access control where different groups of users can recover the secret based on their assigned threshold levels, providing flexibility without excessive complexity.
Solution Approach 2:
Different key components are assigned different threshold levels (local qualities) rather than treating all components uniformly. This allows certain components to have higher importance (lower threshold) than others, enabling hierarchical access where some users can recover the secret with fewer components while others require more. This differential assignment provides adaptability while maintaining manageable scheme complexity.
2Adaptability or versatility
If all key components are treated equally in secret sharing, then the scheme is simple to implement, but it cannot provide hierarchical access or assign different importance levels to different components
Solution Approach 1:
The secret sharing scheme is made dynamic by allowing different threshold levels to be assigned to different components based on their importance. This dynamic assignment enables hierarchical access control where the system can adapt to different recovery scenarios. The threshold levels can be adjusted to reflect changing security requirements and user hierarchies, providing adaptability while maintaining ease of operation through a systematic approach to threshold assignment.
3Adaptability or versatility
If a multi-threshold secret sharing scheme is implemented, then flexible hierarchical access is achieved, but the system complexity increases compared to conventional schemes
Solution Approach 1:
The scheme manages complexity by systematically changing the threshold parameter for different components. Instead of creating entirely separate schemes for different hierarchical levels, the invention modifies the threshold parameter to control access. This parameter-based approach provides flexible hierarchical access for different groups while maintaining a unified secret sharing framework, thereby limiting the increase in system complexity.
Data Source
AI summary
A method and apparatus are disclosed for managing components of a secret key according to a secret sharing scheme. The disclosed secret sharing scheme divides a secret value, R, into n secret components (R1, R2, . . . , Rn) and one super component, S, in such a way that R can be computed from (i) any k or more Ri components (k<n); or (ii) S and any one component of Ri. The secret components (R1, R2, . . . , Rn) are distributed to a number of authorized users. A multiple threshold secret sharing scheme assigns various users in a group into one of a number of classes. Each user class has a corresponding threshold level that indicates the number of users that must come together with their assigned components to obtain access to the shared secret. The multiple threshold scheme divides the secret into n components each having an assigned threshold level (i.e., the number of such components that are required to obtain the secret). Any component having a lower threshold level can satisfy the role of a component having a higher threshold level. The multiple threshold scheme provides a hierarchical scheme that allows the secret, R, to be shared among different groups of people with different thresholds.


