基于信息理论安全的承诺方案和知识的零知识证明协议,构造一个公开可验证的密钥共享方案.在该方案中,任何参与者在密钥分布协议中都能验证其他参与者密钥分块的有效性,且在密钥重构中,仅密钥分块的接收者能验证该分块的有效性.对比可验证的密钥共享方案,该方案更具实用性,是一个独到的具有信息理论意义下安全的公开可验证密钥共享方案.
Based on information-theoretic hiding commitment scheme and zero-knowledge proof of knowledge, a publicly verifiable secret sharing (PVSS) scheme was constructed. In this scheme, any party could verify the validi- ty of participants' shares in the distribution protocol. Only the receiver could verify validity of these shares gained from the other participants in the reconstruction protocol. This PVSS scheme with information-theoretic security has demostrated that it is more applicable in some cases than any verifiable secrete sharing scheme.