Optimal round VSS with a non-interactive Dealer: VSS as a special case of VSR
Yvo Desmedt
The University of Texas at Dallas, USA and University College London,UK May 31, 2016
c Yvo Desmedt
Optimal round VSS with a non-interactive Dealer: VSS as a special - - PowerPoint PPT Presentation
Optimal round VSS with a non-interactive Dealer: VSS as a special case of VSR Yvo Desmedt The University of Texas at Dallas, USA and University College London,UK May 31, 2016 Yvo Desmedt c This is joint work with Kirill Morozov (Tokyo
c Yvo Desmedt
c Yvo Desmedt 1
c Yvo Desmedt 2
P, recompute the
P′ can recompute
c Yvo Desmedt 3
c Yvo Desmedt 4
c Yvo Desmedt 5
c Yvo Desmedt 6
c Yvo Desmedt 7
j, . . . , αt j), and
c Yvo Desmedt 8
c Yvo Desmedt 9
P and Γ P′
c Yvo Desmedt 10
c Yvo Desmedt 11
c Yvo Desmedt 12
c Yvo Desmedt 13
j = (sj, r1,j, r2,j, . . . , rt′,j)T, and
j = (s1,j, s2,j, . . . , sn′,j)T = G′T · uT j
i ∈ P′ privately.
i ∈ P′ having received s′ i = (s′ i,1, s′ i,2, . . . , s′ i,n)
i · HT
c Yvo Desmedt 14
i ∈ P′ runs a non-interactive decoding process
c Yvo Desmedt 15
j must be a consistent share sj, which
c Yvo Desmedt 16
i, si,j) must correspond to points on a polynomial
j = G′T · uT j is replaced by Pj into
j + eT j ,
j is an n′-column.
j .
c Yvo Desmedt 17
i ∈ P′ can each broadcast their incorrect
i.
i.
c Yvo Desmedt 18
c Yvo Desmedt 19
c Yvo Desmedt 20
c Yvo Desmedt 21
c Yvo Desmedt 22
c Yvo Desmedt 23
B In−k], where B ∈ Γ P.
B Vn−k] · FπB where
c Yvo Desmedt 24
c Yvo Desmedt 25
n−k, we obtain that: e′In−k, where
c Yvo Desmedt 26
B , where V −1 B
2
B
B H (spread
c Yvo Desmedt 27
c Yvo Desmedt 28
c Yvo Desmedt 29
30
Clever monkeys are just copycats (2012 study!!)
30
c Yvo Desmedt 31
j∈J ′
τ′
i ·
τ
c Yvo Desmedt 32
c Yvo Desmedt 33
c Yvo Desmedt 34