sharing scheme
40 papers tagged with this keyword
Discrepancy for Random Linear Codes
We prove that random linear codes have nearly optimal discrepancy properties in a broad range of regimes. Our main results are two general theorems: one controlling all translates of a fixed test, and another controlling large families of Fourier-pseudorandom tests. Two motivating applications follow.
First, random linear codes match unstructured random codes for list-decoding from errors above capacity. If $C\subseteq\mathbb F_q^n$ is a random linear code of rate $1-\frac1n\log_q |B_ρ|+ε$, where $B_ρ$ is a radius-$ρ$ Hamming ball, then with high probability $$ |C\cap B|=(1\pm o(1))\frac{|C||B|}{q^n} $$ simultaneously for all radius-$ρ$ Hamming balls $B\subseteq\mathbb F_q^n$. This extends the classical result that such codes have covering radius at most $ρn$ whp (Blinovsky, 1987).
Second, over prime fields, random linear codes match unstructured random codes for zero-error list-recovery above capacity. For prime $q>2$ and $2\le \ell\le q-1$, a random linear code of rate $1-\log_q\ell+ε$ satisfies, with high probability, $$ |C\cap S|=(1\pm o(1))\frac{|C|\ell^n}{q^n} $$ simultaneously for all rectangles $S=S_1\times\cdots\times S_n$ with $|S_i|=\ell$. As a consequence, there are abundant $n$-party linear ramp secret sharing schemes over $\mathbb F_q$ with privacy threshold about $n/(2\log q)$ and reconstruction threshold about $5n/(2\log q)$, resilient to balanced local leakage; prior existence results required thresholds above $n/2$ even in this case.
The translate result, hence the list-decoding application, holds over arbitrary finite fields, even growing with $n$. The list-recovery and leakage applications hold over prime fields under moderate growth, e.g. $q\le n^{1/5-o(1)}$. The proofs use a refined second-moment analysis tracking intersection sizes as random generators are added to $C$.
How to reconstruct (anonymously) a secret cellular automaton
We consider threshold secret sharing schemes based on cellular automata (CA) that allows for anonymous reconstruction, meaning that the secret can be recovered only as a function of the shares, without knowing the participants' identities. To this end, we revisit the basic characterization of $(2,n)$ threshold schemes based on CA in terms of Mutually Orthogonal Latin Squares (MOLS), and redefine the secret space as the MOLS family itself, showing that the new resulting scheme enables anonymous reconstruction of secret CA rules. Finally, we discuss the trade-off between the number of secret CA that can be shared and the computational complexity of the recovery phase.
Optimal and Efficient Partite Decompositions of Hypergraphs
We study the problem of partitioning the edges of a $d$-uniform hypergraph $H$ into a family $F$ of complete $d$-partite hypergraphs ($d$-cliques). We show that there is a partition $F$ in which every vertex $v \in V(H)$ belongs to at most $(\frac{1}{d!} + o_d(1))n^{d-1}/\lg n$ members of $F$. This settles the central question of a line of research initiated by Erdős and Pyber (1997) for graphs, and more recently by Csirmaz, Ligeti, and Tardos (2014) for hypergraphs. The $d=2$ case of this theorem answers a 40-year-old question of Chung, Erdős, and Spencer (1983). An immediate corollary of our result is an improved upper bound for the maximum share size for binary secret sharing schemes on uniform hypergraphs.
Building on results of Nechiporuk (1969), we prove that every graph with fixed edge density $γ\in (0,1)$ has a biclique partition of total weight at most $(\tfrac{1}{2}+o(1))\cdot h_2(γ) \frac{n^2}{\lg n}$, where $h_2$ is the binary entropy function. Our construction implies that such biclique partitions can be constructed in time $O(m)$, which answers a question of Feder and Motwani (1995) and also improves upon results of Mubayi and Turán (2010) as well as Chavan, Rabinia, Grosu, and Brocanelli (2025). Using similar techniques, we also give an $n^{1+o(1)}$ algorithm for finding a subgraph $K_{t,t}$ with $t = (1-o(1)) \fracγ{h_2(γ)} \lg n$.
Our results show that biclique partitions are information-theoretically optimal representations for graphs at every fixed density. We show that with this succinct representation one can answer independent set queries and cut queries in time $O(n^2/ \lg n)$, and if we increase the space usage by a constant factor, we can compute a $2α$-approximation for the densest subgraph problem in time $O(n^2/\lg α)$ for any $α> 1$.
Minimal codes from hypersurfaces in even characteristic
The setting of projective systems can be used to study the parameters of a projective linear code $\mathcal{C}$. This can be done by considering the intersections of the point set $Ω$ defined by the columns of a generating matrix for $\mathcal{C}$ with the hyperplanes of a projective space. In particular, $\mathcal{C}$ is minimal if $Ω$ is cutting, i.e., every hyperplane is spanned by its intersection with $Ω$. Minimal linear codes have important applications for secret sharing schemes and secure two-party computation. In this article we first investigate the properties of some algebraic hypersurfaces $\mathcal{V}_{\varepsilon}^r$ related to certain quasi-Hermitian varieties of $\mathrm{PG}(r,q^2)$, with $q=2^e$, $e>1$ odd. These varieties give rise to a new infinite family of linear codes which are minimal except for $r=3$ and $e\equiv 1 \pmod 4$. In the case $r \in \{3,4\}$, we exhibit codes having at most 6 non-zero weights whose we provide the complete list. As a byproduct, we obtain $(r+1)$-dimensional codes with just $3$ non-zero weights. We point out that linear codes with few weights are also important in authentication codes and association schemes. In the last part of the paper we consider an extension of the notion of being cutting with respect to subspaces other than hyperplanes and introduce the definition of cutting gap in order to characterize and measure what happens when this property is not satisfied. Finally, we then apply these notions to Hermitian codes and to the codes related to $\mathcal{V}_\varepsilon^r$ discussed before.
Optimizing Extension Techniques for Discovering Non-Algebraic Matroids
Published in Journal of Algebraic Combinatorics 62, 50 (2025)
• View Publication
• BIB
In this work, we revisit some combinatorial and information-theoretic extension techniques for detecting non-algebraic matroids. These are the Dress-Lovász and Ahlswede-Körner extension properties. We provide optimizations of these techniques to reduce their computational complexity, finding new non-algebraic matroids on 9 and 10 points. In addition, we use the Ahlswede-Körner extension property to find better lower bounds on the information ratio of secret sharing schemes for ports of non-algebraic matroids.
Two-weight rank-metric codes
Two-weight linear codes are linear codes in which any nonzero codeword can have only two possible distinct weights. Those in the Hamming metric have proven to be very interesting for their connections with authentication codes, association schemes, strongly regular graphs, and secret sharing schemes. In this paper, we characterize two-weight codes in the rank metric, answering a recent question posed by Pratihar and Randrianarisoa.
Efficient Representation of Lattice Path Matroids
Efficient deterministic algorithms to construct representations of lattice path matroids over finite fields are presented. They are built on known constructions of hierarchical secret sharing schemes, a recent characterization of hierarchical matroid ports, and the existence of isolating weight functions for lattice path matroids whose values are polynomial on the size of the ground set.
On Ideal Secret-Sharing Schemes for $k$-homogeneous access structures
A $k$-uniform hypergraph is a hypergraph where each $k$-hyperedge has exactly $k$ vertices. A $k$-homogeneous access structure is represented by a $k$-uniform hypergraph $\mathcal{H}$, in which the participants correspond to the vertices of hypergraph $\mathcal{H}$. A set of vertices can reconstruct the secret value from their shares if they are connected by a $k$-hyperedge, while a set of non-adjacent vertices does not obtain any information about the secret. One parameter for measuring the efficiency of a secret sharing scheme is the information rate, defined as the ratio between the length of the secret and the maximum length of the shares given to the participants. Secret sharing schemes with an information rate equal to one are called ideal secret sharing schemes. An access structure is considered ideal if an ideal secret sharing scheme can realize it. Characterizing ideal access structures is one of the important problems in secret sharing schemes. The characterization of ideal access structures has been studied by many authors~\cite{BD, CT,JZB, FP1,FP2,DS1,TD}. In this paper, we characterize ideal $k$-homogeneous access structures using the independent sequence method. In particular, we prove that the reduced access structure of $Γ$ is an $(k, n)$-threshold access structure when the optimal information rate of $Γ$ is larger than $\frac{k-1}{k}$, where $Γ$ is a $k$-homogeneous access structure satisfying specific criteria.
Unconditionally Secure Non-malleable Secret Sharing and Circular External Difference Families
Various notions of non-malleable secret sharing schemes have been considered. In this paper, we review the existing work on non-malleable secret sharing and suggest a novel game-based definition. We provide a new construction of an unconditionally secure non-malleable threshold scheme with respect to a specified relation. To do so, we introduce a new type of algebraic manipulation detection (AMD) code and construct examples of new variations of external difference families, which are of independent combinatorial interest.
Characterization of Plotkin-optimal two-weight codes over finite chain rings and related applications
Few-weight codes over finite chain rings are associated with combinatorial objects such as strongly regular graphs (SRGs), strongly walk-regular graphs (SWRGs) and finite geometries, and are also widely used in data storage systems and secret sharing schemes. The first objective of this paper is to characterize all possible parameters of Plotkin-optimal two-homogeneous weight regular projective codes over finite chain rings, as well as their weight distributions. We show the existence of codes with these parameters by constructing an infinite family of two-homogeneous weight codes. The parameters of their Gray images have the same weight distribution as that of the two-weight codes of type SU1 in the sense of Calderbank and Kantor (Bull Lond Math Soc 18: 97-122, 1986). Further, we also construct three-homogeneous weight regular projective codes over finite chain rings combined with some known results. Finally, we study applications of our constructed codes in secret sharing schemes and graph theory. In particular, infinite families of SRGs and SWRGs with non-trivial parameters are obtained.
Ideal Secret Sharing Schemes: Combinatorial Characterizations, Certain Access Structures, and Related Geometric Problems
An ideal secret sharing scheme is a method of sharing a secret key in some key space among a finite set of participants in such a way that only the authorized subsets of participants can reconstruct the secret key from their shares which are of the same length as that of the secret key. The set of all authorized subsets of participants is the access structure of the secret sharing scheme. In this paper, we derive several properties and restate the combinatorial characterization of an ideal secret sharing scheme in Brickell-Stinson model in terms of orthogonality of its representative array. We propose two practical models, namely the parallel and hierarchical models, for access structures, and then, by the restated characterization, we discuss sufficient conditions on finite geometries for ideal secret sharing schemes to realize these access structure models. Several series of ideal secret sharing schemes realizing special parallel or hierarchical access structure model are constructed from finite projective planes.
Secret Sharing on Superconcentrator
Using information inequalities, we prove any unrestricted arithmetic circuits computing the shares of any $(t, n)$-threshold secret sharing scheme must satisfy some superconcentrator-like connection properties. In the reverse direction, we prove, when the underlying field is large enough, any graph satisfying these connection properties can be turned into a linear arithmetic circuit computing the shares of a $(t, n)$-threshold secret sharing scheme. Specifically, $n$ shares can be computed by a linear arithmetic circuits with $O(n)$ wires in depth $O(α(t, n))$, where $α(t, n)$ is the two-parameter version of the inverse Ackermann function. For example, when $n \ge t^{2.5}$, depth $2$ would be enough; when $n \ge t \log^{2.5} t$, depth 3 would be enough.
On entropic and almost multilinear representability of matroids
This article studies two notions of generalized matroid representations motivated by algorithmic information theory and cryptographic secret sharing. The first (entropic representability) involves discrete random variables, while the second (almost-multilinear representability) deals with approximate subspace arrangements. In both cases, we prove that determining whether an input matroid has such a representation is undecidable. Consequently, the conditional independence implication problem is also undecidable, providing an independent answer to a question posed by Geiger and Pearl, recently resolved by Cheuk Ting Li. These problems are also closely related to characterizing achievable rates in network coding and constructing secret sharing schemes. For example, another corollary of our work is that deciding whether an access structure admits an ideal secret sharing scheme is undecidable. Our approach reduces undecidable problems from group theory to matroid representation problems. Specifically, we reduce the uniform word problem for finite groups to entropic representability and the word problem for sofic groups to almost-multilinear representability. A key part of this reduction involves modifying group presentations into forms where linear representations are generic in an appropriate sense when restricted to the generating set.
Linear Secret-Sharing Schemes for $k$-uniform access structures
A {\it $k$-uniform hypergraph} $\mathcal{H}=(V, E)$ consists of a set $V$ of vertices and a set $E$ of hyperedges ($k$-hyperedges), which is a family of $k$-subsets of $V$. A {\it forbidden $k$-homogeneous (or forbidden $k$-hypergraph)} access structure $\mathcal{A}$ is represented by a $k$-uniform hypergraph $\mathcal{H}=(V, E)$ and has the following property: a set of vertices (participants) can reconstruct the secret value from their shares in the secret sharing scheme if they are connected by a $k$-hyperedge or their size is at least $k+1$. A forbidden $k$-homogeneous access structure has been studied by many authors under the terminology of $k$-uniform access structures. In this paper, we provide efficient constructions on the total share size of linear secret sharing schemes for sparse and dense $k$-uniform access structures for a constant $k$ using the hypergraph decomposition technique and the monotone span programs.
Some hypersurfaces over finite fields, minimal codes and secret sharing schemes
Published in Designs, Codes and Cryptography (2022) 90:1503-1519
• View Publication
• BIB
Linear error-correcting codes can be used for constructing secret sharing schemes; however finding in general the access structures of these secret sharing schemes and, in particular, determining efficient access structures is difficult. Here we investigate the properties of certain algebraic hypersurfaces over finite fields, whose intersection numbers with any hyperplane only takes a few values; these varieties give rise to $q$-divisible linear codes with at most $5$ weights. Furthermore, for $q$ odd these codes turn out to be minimal and we characterize the access structures of the secret sharing schemes based on their dual codes. Indeed, the secret sharing schemes thus obtained are democratic, that is each participant belongs to the same number of minimal access sets and can easily be described.
Extremal Set Theory and LWE Based Access Structure Hiding Verifiable Secret Sharing with Malicious-Majority and Free Verification
Published in Theoretical Computer Science, 2021, volume 886, pp. 106-138
• View Publication
• BIB
Secret sharing allows distributing a secret among several parties such that only authorized subsets, specified by an access structure, can reconstruct the secret. Sehrawat and Desmedt (COCOON 2020) introduced hidden access structures, that remain secret until some authorized subset of parties collaborate. However, their scheme assumes semi-honest parties and supports only restricted access structures. We address these shortcomings by constructing an access structure hiding verifiable secret sharing scheme that supports all monotone access structures. It is the first secret sharing scheme to support cheater identification and share verifiability in malicious-majority settings. The verification procedure of our scheme incurs no communication overhead. As the building blocks of our scheme, we introduce and construct: (i) a set-system with $> \exp\left(c\frac{2(\log h)^2}{(\log\log h)}\right)+2\exp\left(c\frac{(\log h)^2}{(\log\log h)}\right)$ subsets of a set of $h$ elements. Our set-system, $\mathcal{H}$, is defined over $\mathbb{Z}_m$, where $m$ is a non-prime-power. The size of each set in $\mathcal{H}$ is divisible by $m$ but the sizes of their pairwise intersections are not, unless one set is a subset of another, (ii) a new variant of the learning with errors (LWE) problem, called PRIM-LWE, wherein the secret matrix is sampled such that its determinant is a generator of $\mathbb{Z}_q^*$, where $q$ is the LWE modulus. The security of our scheme relies on the hardness of the LWE problem, and its share size is $$(1+ o(1)) \dfrac{2^{\ell}}{\sqrt{π\ell/2}}(2 q^{\varrho + 0.5} + \sqrt{q} + \mathrmΘ(h)),$$ where $\varrho \leq 1$ is a constant and $\ell$ is the total number of parties. We also provide directions for future work to reduce the share size to
\[\leq \dfrac{1}{3} \left( (1+ o(1)) \dfrac{2^{\ell}}{\sqrt{π\ell/2}}(2 q^{\varrho + 0.5} + 2\sqrt{q}) \right).\]
A construction of minimal linear codes from partial difference sets
Published
• View Publication
• BIB
In this paper, we study a class of linear codes defined by characteristic functions of certain subsets of a finite field. We derive a sufficient and necessary condition for such a code to be a minimal linear code by a character-theoretical approach. We obtain new three-weight or four-weight minimal linear codes that do not satisfy the Ashikhmin-Barg condition by using partial difference sets. We show that our construction yields minimal linear codes that do not arise from cutting vectorial blocking sets, and also discuss their applications in secret sharing schemes.
Access Structures Determined by Uniform Polymatroids
Published
• View Publication
• BIB
An access structure is said to be multipartite, if the set of participants is divided into several parts and all participants in the same part play an equivalent role. The search for ideal secret sharing schemes for some special interesting families of multipartite access structures, has been carried out by many authors. In this paper a new concept of study of ideal access structures is proposed. We do not consider special classes of access structures defined by imposing certain prescribed assumptions, but we investigate all access structures obtained from uniform polymatroids using the method developed by Farràs, Martí-Farré and Padró. They satisfy necessary condition to be ideal, i.e., they are matroid ports. Moreover some objects in this family can be useful for the applications of secret sharing. The choice of uniform polymatroids is motivated by the fact that each such polymatroid defines ideal access structures. The method presented in this article is universal and can be continued with other classes of polymatroids in further similar studies. Here we are especially interested in hierarchy of participants determined by the access structure and we distinguish two main classes: they are compartmented and hierarchical access structures. The vast majority of papers discussing hierarchical access structures consider access structures which are compartment or totally hierarchical. The main results are summarized in Section 4, which presents situations where partial hierarchy properties may arise. In particular, hierarchical orders of obtained structures are described. It is surprising, that the hierarchical orders of access structures obtained from uniform polymatroids are flat, i.e., every chain has at most 2 elements. The ideality of some families of hierarchical access structures is proved in Section 5.
On the weight distribution of some minimal codes
Published
• View Publication
• BIB
Minimal codes are a class of linear codes which gained interest in the last years, thanks to their connections to secret sharing schemes. In this paper we provide the weight distribution and the parameters of families of minimal codes recently introduced by C. Tang, Y. Qiu, Q. Liao, Z. Zhou, answering some open questions.
Optimal Threshold Padlock Systems
Published
• View Publication
• BIB
In 1968, Liu described the problem of securing documents in a shared secret project. In an example, at least six out of eleven participating scientists need to be present to open the lock securing the secret documents. Shamir proposed a mathematical solution to this physical problem in 1979, by designing an efficient $k$-out-of-$n$ secret sharing scheme based on Lagrange's interpolation. Liu and Shamir also claimed that the minimal solution using physical locks is clearly impractical and exponential in the number of participants. In this paper we relax some implicit assumptions in their claim and propose an optimal physical solution to the problem of Liu that uses physical padlocks, but the number of padlocks is not greater than the number of participants. Then, we show that no device can do better for $k$-out-of-$n$ threshold padlock systems as soon as $k\geq{\sqrt{2n}}$, which holds true in particular for Liu's example. More generally, we derive bounds required to implement any threshold system and prove a lower bound of $\mathcal{O}{\log(n)}$ padlocks for any threshold larger than $2$. For instance we propose an optimal scheme reaching that bound for $2$-out-of-$n$ threshold systems and requiring less than $2\log_2(n)$ padlocks. We also discuss more complex access structures, a wrapping technique, and other sublinear realizations like an algorithm to generate $3$-out-of-$n$ systems with $2.5\sqrt{n}$ padlocks. Finally we give an algorithm building $k$-out-of-$n$ threshold padlock systems with only $\mathcal{O}{\log(n)^{k-1}}$ padlocks. Apart from the physical world, our results also show that it is possible to implement secret sharing over small fields.