BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//Computer Science and Engineering - ECPv6.13.0//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-ORIGINAL-URL:https://homecse.iitd.ac.in
X-WR-CALDESC:Events for Computer Science and Engineering
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:Asia/Kolkata
BEGIN:STANDARD
TZOFFSETFROM:+0530
TZOFFSETTO:+0530
TZNAME:IST
DTSTART:20260101T000000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=Asia/Kolkata:20260105T120000
DTEND;TZID=Asia/Kolkata:20260105T130000
DTSTAMP:20261010T153545
CREATED:20260103T092244Z
LAST-MODIFIED:20260103T170405Z
UID:2260-1767614400-1767618000@homecse.iitd.ac.in
SUMMARY:Traceable Secret Sharing: Strong Security and Efficient Constructions by Aditi Partap
DESCRIPTION:Venue: Bharti 501 \nAbstract: Suppose Alice uses a t-out-of-n secret sharing to store her secret key on n servers. Her secret key is protected as long as t of them do not collude. However\, what if a less-than-t subset of the servers decides to offer the shares they have for sale? In this case\, Alice should be able to hold them accountable\, or else nothing prevents them from selling her shares. With this motivation in mind\, Goyal\, Song\, and Srinivasan (CRYPTO 21) introduced the concept of {\em traceable secret sharing}. In such schemes\, it is possible to provably trace the leaked secret shares back to the servers who leaked them. Goyal et al. presented the first construction of a traceable secret sharing scheme. However\, secret shares in their construction are quadratic in the secret size\, and their tracing algorithm is quite involved as it relies on Goldreich-Levin decoding. \nIn this work\, we put forth new definitions and practical constructions for traceable secret sharing. In our model\, some f<t servers output a reconstruction box R that may arbitrarily depend on their shares. Given t-f additional shares\, R reconstructs and outputs the secret. The task is to trace R back to the corrupted servers given black-box access to R. Unlike Goyal et al.\, we do not assume that the tracing algorithm has any information on how the corrupted servers constructed R from the shares in their possession. \nWe then present two very efficient constructions of traceable secret sharing based on two classic secret sharing schemes. In both of our schemes\, shares are only twice as large as the secret\, improving over the quadratic overhead of Goyal et al. Our first scheme is obtained by presenting a new practical tracing algorithm for the widely-used Shamir secret sharing scheme. Our second construction is based on an extension of Blakley’s secret sharing scheme. Tracing in this scheme is optimally efficient\, and requires just one successful query to R. We believe that our constructions are an important step towards bringing traceable secret-sharing schemes to practice. This work also raises several interesting open problems that we describe in the paper. \nIf there’s time\, perhaps I’ll mention our new results on TSS (https://eprint.iacr.org/2025/1980) \n  \nSpeaker Bio: Aditi Partap is a fifth year CS Ph.D. student at Stanford University\, where she works on cryptography research (advised by Dan Boneh). Her current focus is on accountability in threshold cryptography and leader election protocols. \nPrior to joining Stanford\, she completed her Masters in May 2021 from University of Illinois at Urbana Champaign. She received her bachelors degree in Computer Science from IIT Delhi in 2018.
URL:https://homecse.iitd.ac.in/event/title-traceable-secret-sharing-strong-security-and-efficient-constructions-by-aditi-partap/
LOCATION:Bharti 501\, IIT Campus\, Hauz Khas\, New Delhi
END:VEVENT
END:VCALENDAR