Ағылшыншамен салыстырыңыз: абзацты басыңыз — түпнұсқа терезеде ашылады. Абзац астындағы EN түймесі оны мәтін ішінде көрсетеді.
Кіріспе
Криптографияда құпияны бөлісу схемасы, егер ойыншыларға өз үлестерін дұрыстығын тексеруге мүмкіндік беретін қосымша ақпарат берілсе, тексеріледі. Нақтырақ айтқанда, тексерілетін құпияны бөлісу дилер қастандық жасаған жағдайда да, ойыншылар кейіннен қайта құрастыра алатын анықталған құпияның болуын қамтамасыз етеді. (Стандартты құпияны бөлісуде дилердің адал екені ескеріледі.) Тексерілетін құпияны бөлісу (VSS) тұжырымдамасын 1985 жылы Бени Чор, Шафи Голдвассер, Сильвио Микали және Барух Авербух енгізді. VSS протоколында құпияны бөліскісі келетін ерекше ойыншы дилер деп аталады. Протокол екі кезеңнен тұрады: бөлісу кезеңі және қайта құру кезеңі. Бөлісу: Бастапқыда дилер құпияны кіріс ретінде сақтайды, ал әрбір ойыншы тәуелсіз кездейсоқ кіріс мәліметін ұстайды. Бөлісу кезеңі бірнеше раундтан тұруы мүмкін. Әр раундта әр ойыншы басқа ойыншыларға жеке хабарлар жіберуге және хабар таратуға мүмкіндік алады. Ойыншы жіберген немесе таратқан әрбір хабар оның кірісі, кездейсоқ кірісі және алдыңғы раундтарда басқа ойыншылардан алынған хабарларға байланысты анықталады. Қайта құру: Бұл кезеңде әр ойыншы бөлісу кезеңінен алған барлық ақпаратын ұсынады және қайта құру функциясы қолданылып, протоколдың нәтижесі ретінде алынады. Одед Голдрейх берген балама анықтама VSS-ді, белгілі бір (тексерілмейтін) құпияны бөлісу схемасына сәйкес келетін кездейсоқ функционалды есептеуге арналған қауіпсіз көп тарапты протокол ретінде анықтайды. Бұл анықтама басқа анықтамалардан күштірек және жалпы көп тарапты қауіпсіз есептеулер контекстінде қолдануға өте қолайлы. Тексерілетін құпияны бөлісу қауіпсіз көп тарапты есептеу үшін маңызды. Көп тарапты есептеу әдетте кіріс деректерін құпия бөлісу арқылы және кейбір функцияларды есептеу үшін осы үлестерді өңдеу арқылы жүзеге асырылады. "Белсенді" қарсыластарды (яғни, түйіндерді бұзып, оларды протоколдан ауытқуға мәжбүр ететін қарсыластарды) басқару үшін құпияны бөлісу схемасы тексерілетін болуы керек, бұл ауытқып кеткен түйіндердің протоколды бұзуына жол бермейді.
In cryptography, a secret sharing scheme is verifiable if auxiliary information is included that allows players to verify their shares as consistent. More formally, verifiable secret sharing ensures that even if the dealer is malicious there is a well defined secret that the players can later reconstruct. (In standard secret sharing, the dealer is assumed to be honest.) The concept of verifiable secret sharing (VSS) was first introduced in 1985 by Benny Chor, Shafi Goldwasser, Silvio Micali and Baruch Awerbuch. In a VSS protocol a distinguished player who wants to share the secret is referred to as the dealer. The protocol consists of two phases: a sharing phase and a reconstruction phase. Sharing: Initially the dealer holds secret as input and each player holds an independent random input. The sharing phase may consist of several rounds. At each round each player can privately send messages to other players and can also broadcast a message. Each message sent or broadcast by a player is determined by its input, its random input and messages received from other players in previous rounds. Reconstruction: In this phase each player provides its entire view from the sharing phase and a reconstruction function is applied and is taken as the protocol's output. An alternative definition given by Oded Goldreich defines VSS as a secure multi party protocol for computing the randomized functionality corresponding to some (non verifiable) secret sharing scheme. This definition is stronger than that of the other definitions and is very convenient to use in the context of general secure multi party computation. Verifiable secret sharing is important for secure multiparty computation. Multiparty computation is typically accomplished by making secret shares of the inputs, and manipulating the shares to compute some function. To handle "active" adversaries (that is, adversaries that corrupt nodes and then make them deviate from the protocol), the secret sharing scheme needs to be verifiable to prevent the deviating nodes from throwing off the protocol.
Құпия дауыс беру арқылы сайлау
Тексерілетін құпия бөлісуді ұштан-ұшқа дейінгі аудиттелмелі дауыс беру жүйелерін құру үшін пайдалануға болады. Тексерілетін құпия бөлісу әдісін қолдану арқылы, осы жерде сипатталатын сайлау мәселесін шешуге болады. Сайлау мәселесінде әрбір сайлаушы 0 (қарсы) немесе 1 (қолдау) дауыс бере алады, ал барлық дауыстардың қосындысы сайлау нәтижесін анықтайды. Сайлаудың жүзеге асуы үшін келесі шарттар орындалуын қамтамасыз ету қажет:
Verifiable secret sharing can be used to build end to end auditable voting systems. Using the technique of verifiable secret sharing one can satisfy the election problem that will be described here. In the election problem each voter can vote either 0 (to oppose) or 1 (for support), and the sum of all votes will determine election's result. For the election to execute, it is necessary to make sure that the following conditions are fulfilled:
Сайлаушылардың жеке өміріне зиян келтірілмеуі керек. Сайлау әкімшісі әрбір сайлаушының әділетсіз әрекет етпегенін тексеруі тиіс. Тексерілетін құпия бөлісуді қолданса, n санаушы жалғыз сайлау әкімшісінің орнын басады. Әрбір сайлаушы өзінің құпия дауысының бір үлесін n санаушының әрқайсысына бөліп береді. Осылайша сайлаушының жеке өмірі сақталады және бірінші шарт орындалады. Егер k < n санаушылар полином P-ні анықтауға жеткілікті болса, сайлау нәтижесін қайта құру оңай.
The voters' privacy should not be compromised. The election administrator must verify that no voter committed fraud. If using verifiable secret sharing, n tellers will replace the single election administrator. Each voter will distribute one share of its secret vote to every one of the n tellers. This way the privacy of the voter is preserved and the first condition is satisfied. Reconstruction of the election's result is easy, if there exist enough k < n tellers to discover polynomial P.
Интерактивті дәлелдеме дауыс үлестерін тексеруге мүмкіндік беру үшін сәл кеңейтілуі мүмкін. Әрбір сайлаушы өзінің дауысының заңдылығын интерактивті дәлелдемелердің бес қадамын қолдана отырып, (құпия үлестіру кезеңінде) санаушыларға дәлелдейді.
The interactive proof can be generalized slightly to allow verification of the vote shares. Each voter will prove (in the distribution of the secret share phase) to the tellers that his vote is legitimate using the five steps of the interactive proof.