סמינר: ceClub: The Technion Computer Engineering Club
How to stop parties holding pieces of a secret from reconstructing the secret?
Imagine a dealer who splits a secret into pieces and distributes the pieces to a group of parties. This splitting or sharing primitive ensures that authorized groups of parties can reconstruct the secret from received shares, while other groups cannot learn anything about the secret from their shares. Parties are typically not expected to reconstruct the secret at their will, because otherwise the dealer could directly send the secret to authorized parties. Instead of assuming enough parties are honest and only reconstruct the secret when necessary, we will discuss mechanisms to disincentivize parties from illegal or premature reconstruction. Such mechanisms have a wide range of applications in secret-sharing style primitives, such as multi-server private information retrieval, secure multi-party computation, and multi-device cryptocurrency wallets.

