QUT QUT ePrints

GBD Threshold Cryptography with an Application to RSA Key Recovery

Steketee, Chris and Brown, Jaimee and Gonzalez Nieto, Juan M. and Montague, Paul (2005) GBD Threshold Cryptography with an Application to RSA Key Recovery. In Boyd, Colin and Gonzalez Nieto, Juan M., Eds. Proceedings 10th Australasian Conference on Information Security and Privacy 3574, pages pp. 394-405, Brisbane, Australia.

This is the latest version of this eprint.

Full text available as:
PDF (Author version) - Requires Adobe Acrobat Reader or other PDF viewer.

Abstract

We present protocols for threshold cryptography in the GBD public-key cryptosystem. Both threshold decryption and threshold key generation are covered, in the "honest-but-curious" setting. This shows that it is possible to perform GBD computations in a distributed manner during both key generation and decryption, without revealing the private key to any party. GBD threshold decryption is similar to El-Gamal threshold decryption. GBD threshold key generation is based on adaptations of protocols for RSA key generation by Boneh and Franklin, and Catalano et al, and includes a new protocol for efficiently computing the inverse of a shared secret modulo another shared secret. We also show an application of GBD threshold cryptography to RSA key recovery. This is based on the use of GBD as a master cryptosystem, whose use allows generation by individual users of RSA moduli that can be factored by using the GBD private key as trapdoor information. This application requires RSA key generation to be tailored, but other operations are standard RSA. Clearly, compromise of the GBD private key would compromise all corresponding RSA private keys, so the security of the GBD master private key should be stronger than the security of the individual RSA keys, and this can be achieved using threshold methods. Finally, we point out two open problems in the RSA key recovery application.

Item Type:Conference Paper
Status:Published
Subjects:280000 Information, Computing and Communication Sciences > 280500 Data Format > 280505 Data Security
280000 Information, Computing and Communication Sciences > 280500 Data Format > 280504 Data Encryption
280000 Information, Computing and Communication Sciences
ID Code:1736
Deposited By:Gonzalez Nieto, Juan M
Deposited On:28 October 2005
Alternative Locations:http://dx.doi.org/10.1007/11506157_33
Copyright Owner:Copyright 2005 Springer
Copyright Statement:This is the author-version of the work. Conference proceedings published, by Springer Verlag, will be available via SpringerLink. http://www.springer.de/comp/lncs/ Lecture Notes in Computer Science

Available Versions of this Item