Although threshold key-recovery systems for the discrete log basedcryptosystems such as the ElGamal scheme have been proposed byFeldman and Pedersen 6, 11, 12, no (practical) thresholdkey-recovery system for the factoring based cryptosystems such as theRSA scheme has been proposed~* . This paper proposes the first(practical) threshold key-recovery sys- tems for the factoring basedcryptosystems including the RSA and Rabin schemes. Almost all of theproposed systems are un- conditionally secures since the systemsutilize unconditionally se- cure bit-commitment protocols andunconditionally secure VSS.
展开▼