Re: Timed-release crypto - Proactive security plug

At 7:03 PM 11/13/95, Amir Herzberg wrote:
>A small note/plug: the schemes by Tim and Michael are based on `long lived'
>secret sharing, i.e. you trust each share of your secret to a server for a
>really long time. Some people may be concerned that such a long time would
>allow an attacker to break into most servers and reconstruct the secret (key).
>A solution to this is proactive secret sharing, as described in [HJKY95].
>In this protocol, the secret shares are periodically refreshed (i.e. new
>shares are computed distributively and then the old shares are erased).
>In this manner, an attacker has to break into most servers during the same
>period; shares from one period are worthless on the next period.
>Best, Amir
>[HJKY95] `Proactive Secret Sharing', A. Herzberg, H. Krawczyk, S. Jareski,
>M. Yung, Crypto 95.

I also was sent a copy of Ron Rivest's latest paper on timed-release crypto
(also available at the URL http://theory.lcs.mit.edu/~rivest/).

These noted cryptographers, Amir, Ron, and others, are of course doing
"real cryptography" on this timed-released stuff....my speculations in '93
and later are informal, rough considerations. There are dangers in using
"common sense" in protocols like this, but, then, few of us have the time
to explore things in enough detail.

I just wanted to clarify things, though I suspect most of you know that
many of my arguments (and those of others, too) are based on informal, bull
session, sorts of foundations. This is often enough at a very early stage.
No substitute for much more rigorous, published-paper-quality analyses, of

