One crucial defense against exposure of private keys is offered by threshold cryptogTaphy where the private key functions are distributed among several parties such that a predetermined nurnber of parties must mperate in order to corrctly perform this operation. An efficient scheme based on peetry which implements (T
N)-threshold RSA cryptosytem is presentetl. In the system
the power to decrypt and to sign is shared by N players such that any subset of T players can collahaate to perform RSA functions
but no subset of fewer than T corrupted players can decrypt a ciphertext of forg a signature.