IP Library Granted Patent US 9,929,860
Granted Patent B1
US 9,929,860 · App. 14/984,352 · Granted Mar 27, 2018

Methods and apparatus for generalized password-based secret sharing

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,929,860
App. No.
14/984,352
Granted
Mar 27, 2018
Kind
B1
Abstract

Generalized password-based secret sharing schemes are provided. A secret sharing method comprises obtaining a secret; obtaining fixed values from one or more parties; setting an element of a column vector of a password-based linear secret sharing scheme based on the secret; randomly selecting values from a field for additional elements of the column vector; setting remaining elements of the column vector to values that ensure that a product of a matrix and the column vector, for each fixed-share party, is equal to the corresponding fixed value; and distributing non-fixed shares to additional parties using a labeling function. In another method, a defining matrix corresponds to the secret and a field of both the secret and a plurality of shares of the secret. A given share for each party in the set is set to the corresponding obtained fixed value. A row in the defining matrix is randomly selected such that an element in the row corresponding to each party in the set is equal to the corresponding obtained fixed value.

Claims (60)

1. A secret sharing method for the protection of at least one data item, comprising:

obtaining a secret, wherein said secret protects said at least one data item;

obtaining m fixed values from one or more parties, where m is greater than or equal to one;

setting, using at least one processing device, a first element of a column vector of a password-based linear secret sharing scheme having a size t to a value that depends on said secret;

randomly selecting, using said at least one processing device, values from a field for t−m−1 additional elements of said column vector;

setting, using said at least one processing device, remaining elements of said column vector to values that ensure that a product of an m-by-t matrix and said column vector, for each of said one or more parties, is equal to the fixed value of said corresponding party; and

distributing, using said at least one processing device, non-fixed shares based on said product to at least one device of additional parties during a secret sharing phase using a labeling function, such that said secret is reconstructed during a secret reconstruction phase only when a predefined minimum number of said secret shares are provided to one or more authentication servers.

2. The method of claim 1 , wherein said fixed values comprise a result of a hash function applied to a password of said one or more parties.

3. The method of claim 1 , wherein said fixed value comprises one or more of secret information related to said one or more parties and a password of said one or more parties.

4. The method of claim 1 , wherein said secret protects at least one data item.

5. The method of claim 1 , wherein t shares comprise a minimal authorized set needed for reconstruction of said secret and wherein said t shares must be obtained in a predefined order to reconstruct said secret.

6. The method of claim 1 , wherein a reconstruction of said secret is based on an access structure comprising one or more authorized sets of parties, wherein said authorized sets of parties comprise an ordered set of parties that need to combine shares in a predefined order to reconstruct said secret.

7. A non-transitory machine-readable recordable storage medium having encoded therein executable code of one or more software programs for the protection of at least one data item, wherein the one or more software programs when executed by one or more processing devices implement the following steps:

obtaining a secret, wherein said secret protects said at least one data item;

obtaining m fixed values from one or more parties, where m is greater than or equal to one;

setting, using at least one processing device, a first element of a column vector of a password-based linear secret sharing scheme having a size t to a value that depends on said secret;

randomly selecting, using said at least one processing device, values from a field for t−m−1 additional elements of said column vector;

setting, using said at least one processing device, remaining elements of said column vector to values that ensure that a product of an m-by-t matrix and said column vector, for each of said one or more parties, is equal to the fixed value of said corresponding party; and

distributing, using said at least one processing device, non-fixed shares based on said product to at least one device of additional parties during a secret sharing phase using a labeling function, such that said secret is reconstructed during a secret reconstruction phase only when a predefined minimum number of said secret shares are provided to one or more authentication servers.

8. An apparatus for the protection of at least one data item, comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to implement the following steps:

obtaining a secret, wherein said secret protects said at least one data item;

obtaining m fixed values from one or more parties, where m is greater than or equal to one;

setting, using at least one processing device, a first element of a column vector of a password-based linear secret sharing scheme having a size t to a value that depends on said secret;

randomly selecting, using said at least one processing device, values from a field for t−m−1 additional elements of said column vector;

setting, using said at least one processing device, remaining elements of said column vector to values that ensure that a product of an m-by-t matrix and said column vector, for each of said one or more parties, is equal to the fixed value of said corresponding party; and

distributing, using said at least one processing device, non-fixed shares based on said product to at least one device of additional parties during a secret sharing phase using a labeling function, such that said secret is reconstructed during a secret reconstruction phase only when a predefined minimum number of said secret shares are provided to one or more authentication servers.

9. The apparatus of claim 8 , wherein said fixed values comprise one or more of secret information related to said one or more parties, a password of said one or more parties, and a result of a hash function applied to a password of said one or more parties.

10. A secret sharing method for the protection of at least one data item, comprising:

obtaining a secret, wherein said secret protects said at least one data item;

obtaining at least one fixed value from one or more parties in a set of parties;

obtaining a defining matrix corresponding to said secret for a threshold secret sharing scheme with a threshold and a field of both the secret and a plurality of shares of the secret;

setting, using at least one processing device, a given share for each party in said set of parties to said corresponding obtained fixed value for all parties in said set of parties;

randomly selecting, using said at least one processing device, a row in said defining matrix from all rows of said defining matrix such that an element in said row corresponding to each of said one or more parties in said set of parties is equal to said corresponding obtained fixed value; and

distributing, using at least one processing device, non-fixed shares from the elements of the selected row to at least one device of corresponding parties not in said set of parties during a secret sharing phase, such that said secret is reconstructed during a secret reconstruction phase only when a predefined minimum number of said secret shares are provided to one or more authentication servers.

11. The method of claim 10 , wherein said random row selection further requires that an element in said row corresponding to said secret is equal to said secret.

12. The method of claim 10 , wherein said fixed values comprise a result of a hash function applied to a password of said one or more parties.

13. The method of claim 10 , wherein said fixed value comprises one or more of secret information related to said one or more parties and a password of said one or more parties.

14. The method of claim 10 , wherein said secret protects at least one data item.

15. The method of claim 10 , wherein t shares comprise a minimal authorized set needed for reconstruction of said secret and wherein said t shares must be obtained in a predefined order to reconstruct said secret.

16. A non-transitory machine-readable recordable storage medium having encoded therein executable code of one or more software programs for the protection of at least one data item, wherein the one or more software programs when executed by one or more processing devices implement the following steps:

obtaining a secret, wherein said secret protects said at least one data item;

obtaining at least one fixed value from one or more parties in a set of parties;

obtaining a defining matrix corresponding to said secret for a threshold secret sharing scheme with a threshold and a field of both the secret and a plurality of shares of the secret;

setting, using at least one processing device, a given share for each party in said set of parties to said corresponding obtained fixed value for all parties in said set of parties;

randomly selecting, using said at least one processing device, a row in said defining matrix from all rows of said defining matrix such that an element in said row corresponding to each of said one or more parties in said set of parties is equal to said corresponding obtained fixed value; and

distributing, using at least one processing device, non-fixed shares from the elements of the selected row to at least one device of corresponding parties not in said set of parties during a secret sharing phase, such that said secret is reconstructed during a secret reconstruction phase only when a predefined minimum number of said secret shares are provided to one or more authentication servers.

17. An apparatus for the protection of at least one data item, comprising:

a memory; and

at least one hardware device, coupled to the memory, operative to implement the following steps:

obtaining a secret, wherein said secret protects said at least one data item;

obtaining at least one fixed value from one or more parties in a set of parties;

obtaining a defining matrix corresponding to said secret for a threshold secret sharing scheme with a threshold and a field of both the secret and a plurality of shares of the secret;

setting, using at least one processing device, a given share for each party in said set of parties to said corresponding obtained fixed value for all parties in said set of parties;

randomly selecting, using said at least one processing device, a row in said defining matrix from all rows of said defining matrix such that an element in said row corresponding to each of said one or more parties in said set of parties is equal to said corresponding obtained fixed value; and

distributing, using said at least one processing device, non-fixed shares from the elements of the selected row to at least one device of corresponding parties not in said set of parties during a secret sharing phase, such that said secret is reconstructed during a secret reconstruction phase only when a predefined minimum number of said secret shares are provided to one or more authentication servers.

18. The apparatus of claim 17 , wherein said random row selection further requires that an element in said row corresponding to said secret is equal to said secret.

19. The apparatus of claim 17 , wherein said fixed values comprise one or more of secret information related to said one or more parties, a password of said one or more parties, and a result of a hash function applied to a password of said one or more parties.

20. The apparatus of claim 17 , wherein t shares comprise a minimal authorized set needed for reconstruction of said secret and wherein said t shares must be obtained in a predefined order to reconstruct said secret.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 9, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 054362/0039 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2020
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 054277/0579 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 053682/0956 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2016
From: TRIANDOPOULOS, NIKOLAOS; ZHANG, YUPENG
To: EMC CORPORATION
Reel/Frame 039207/0967 →