Generalized Password-Based Secret Sharing for Fixed Share Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secret sharing schemes are limited in supporting richer classes of sharing schemes beyond Shamir's threshold scheme or XOR-based secret sharing, particularly in securely incorporating fixed shares such as user passwords.

Innovation Solution

The development of generalized password-based secret sharing methods that utilize linear secret sharing schemes and threshold secret sharing schemes based on orthogonal arrays, allowing for the secure selection and distribution of fixed shares, including user passwords, while ensuring secure reconstruction of secrets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional secret sharing schemes (Shamir's threshold scheme or XOR-based schemes) are used, then the secret can be split into shares, but the schemes cannot securely incorporate fixed shares such as user passwords

Engineering Contradiction:
Improveability to support fixed sharesVSAvoidsecurity of secret sharing
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent changes the parameters of the secret sharing scheme by introducing a hybrid approach that combines threshold secret sharing with fixed shares. The system allows some shares to be predetermined (fixed) while others remain random, changing the traditional parameter structure where all shares are randomly generated. This enables secure incorporation of user passwords or other fixed values as shares without compromising the overall security model.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If fixed values are incorporated into secret sharing schemes, then user passwords can be used as shares, but the mathematical structure of traditional schemes becomes insufficient

Engineering Contradiction:
Improvesupport for password-based sharesVSAvoidcomplexity of sharing scheme structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the shares into two distinct categories: fixed shares (which can be user passwords or predetermined values) and random shares (which are generated through the secret sharing protocol). This segmentation allows the system to handle different types of shares with appropriate mathematical operations, making the scheme more versatile while maintaining manageable complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal secret sharing framework that can accommodate multiple types of shares (fixed and random) within a single mathematical structure. The scheme is designed to be multi-functional, supporting both traditional random shares and fixed password-based shares, thereby eliminating the need for separate schemes for different share types and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If richer classes of sharing schemes are supported, then more flexibility is achieved, but security guarantees become harder to establish

Engineering Contradiction:
Improverichness of sharing scheme classesVSAvoidsecurity proof robustness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary mathematical structure that bridges fixed shares and random shares. This intermediary layer ensures that the combination of fixed and random shares maintains the security properties required for secret reconstruction, providing a proven security model even as the scheme becomes more versatile and supports richer classes of sharing arrangements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9929860B1Methods and apparatus for generalized password-based secret sharing
Publication Date: 2018.03.27 RSA SECURITY USA LLC
  • US9929860B1 patent drawing
  • US9929860B1 patent drawing
  • US9929860B1 patent drawing

AI summary

Generalized password-based secret sharing schemes are provided. A secret sharing method comprises obtaining a secret; obtaining fixed values from one or more parties; setting an element of a column vector of a password-based linear secret sharing scheme based on the secret; randomly selecting values from a field for additional elements of the column vector; setting remaining elements of the column vector to values that ensure that a product of a matrix and the column vector, for each fixed-share party, is equal to the corresponding fixed value; and distributing non-fixed shares to additional parties using a labeling function. In another method, a defining matrix corresponds to the secret and a field of both the secret and a plurality of shares of the secret. A given share for each party in the set is set to the corresponding obtained fixed value. A row in the defining matrix is randomly selected such that an element in the row corresponding to each party in the set is equal to the corresponding obtained fixed value.