Verifiable Secret Reconstruction Proof for Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secret sharing schemes lack the ability to verify the specific subset of shares used during secret reconstruction, which limits access control to a simple 'all-or-nothing' model and fails to provide differentiated access levels based on the reconstruction mode (online or offline).
Innovation Solution
Implementing a verifiable reconstruction type in secret sharing schemes that generates a proof identifying the subset of shares used in reconstruction, allowing a verifier to grant access based on predefined policies and providing visibility into the reconstruction process, including the use of polynomial evaluation verifiability and proof generation techniques.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional secret sharing schemes are used for access control, then secret reconstruction is possible with sufficient shares, but the system cannot verify which specific shares were used and cannot provide differentiated access levels
Solution Approach 1:
The patent introduces a proof mechanism as an intermediary between share reconstruction and access granting. The proof serves as verification evidence that demonstrates which specific shares were used in the reconstruction process, enabling the verifier to make informed access control decisions without directly accessing the secret or shares themselves.
Solution Approach 2:
The system implements feedback by generating a proof that provides information back to the verifier about the reconstruction process. This proof feedback enables the verifier to determine whether to grant access based on the specific combination of shares used, creating a closed-loop verification system that enhances access control reliability.
2Adaptability or versatility
If all shares are required for secret reconstruction, then security is maximized, but access control becomes rigid and cannot support differentiated access levels
Solution Approach 1:
The patent makes the access control system dynamic by allowing different reconstruction thresholds and share combinations depending on the access level required. The verifier can adaptively determine the appropriate reconstruction policy based on the proof provided, enabling flexible access levels while maintaining security through cryptographic verification of the reconstruction process.
Solution Approach 2:
The system segments access control into different levels by verifying specific properties of the reconstruction process through the proof mechanism. Different access levels can be granted based on different combinations and numbers of shares used, allowing fine-grained access control while maintaining overall secret security through the threshold requirement.
3Measurement precision
If the verifier has full visibility into the reconstruction process, then access control precision is improved, but the complexity of verification increases
Solution Approach 1:
Instead of requiring the verifier to directly observe or access the actual shares and reconstruction process, the system uses a cryptographic proof as a copy or representation of the reconstruction evidence. This proof copy contains sufficient information for verification without exposing the actual secret or shares, reducing verification complexity while maintaining precision.
Solution Approach 2:
The proof acts as an intermediary that translates the complex reconstruction process into a verifiable form. It provides precise information about which shares were used without requiring the verifier to directly handle or analyze the complex cryptographic reconstruction operations, thereby reducing verification complexity while maintaining measurement precision.
Data Source
AI summary
Methods and apparatus are provided for secret sharing with a verifiable reconstruction type. An exemplary method comprises receiving a plurality of shares of a secret generated using a secret splitting scheme; reconstructing the secret if the plurality of shares satisfies a predefined reconstruction threshold; and generating a proof identifying at least one of the plurality of shares used in the reconstruction. The proof is optionally verified by a verifier and the verification is optionally based on auxiliary information derived by the secret splitting scheme used to share the secret. The verifier optionally implements layered access control, for example, based on a rank of the shares used for reconstruction. The reconstructed secret is optionally provided to the verifier. A user can be granted a level of access to a protected resource based on the proof, the reconstructed secret and one or more predefined policies. One or more steps can be proactivized to maintain share freshness.


