Baek提出了一个基于身份的门限秘密共享方案IdThdBm,该方案门限值作为参数在系统初始化时确定,无法灵活改变,难以适应网络环境动态变化的安全需求。针对这个问题,提出了一个基于IRE的(t,n)门限秘密共享方案及其门限调整算法。方案通过IBE公钥算法进行秘密分发,影子秘密通过RSA算法进行验证,可有效避免参与者欺骗,当门限值改变时.只需在原有影子秘密基础上增加相应信息,其安全性基于CDH问题难解性。形式化分析和证明显示.新方案能在保证安全性的基础上灵活调整门限值,与已有方案对比分析,新方案具有计算复杂度和影子秘密复用率等方面优势。
Back proposed a threshold secret sharing scheme based on IBE named IdThdBm, however, the value of threshold is fixed in system's initialization, it is not flexible enough to abapt the security requiement of the communication scope dynamic changing. To .solve this problem, proposed a ( t, n) threshold secret sharing scheme based on IBE and the threshold adjustment algorithm. This scheme distributed the secret based on IBE public key algorithm, the shadow .secret was demonstrated via RSA algorithm to avoid the cheating between participants. When the value of the threshold changed, the corresponding information should be added to the former shadow .secret, the security is based on the CDH problem. The analysis and proof showed that the new scheme not only can adjust the value neatly, but also can insure the security. Compared with the existing scheme, new scheme has some advantages such as the complexity and the rate of reusing the shadow secret and so on.