based on the intractability of the discrete logarithm (DL) and the RSA encryption algorithm is presented
in which the participants' shadows remain secret and can be reused
even if all subshadows are made public.Meanwhile
by using a zero-knowledge proof protocol
the validity verification of shadow and subshadow is also provided to prevent both dealer cheating and other participant cheating
and any freely given secrets without pre-computation by dealer can be reconstructed.The scheme can be applied to many areas such as conference key distribution