Publicly Verifiable Secret Sharing
A secret sharing scheme allows to share a secret among several participants such that only certain groups of them can recover it. Verifiable secret sharing has been proposed to achieve security against cheating participants. Its first realization has the special property that everybody, not only the participants, is able to check that the shares are correctly distributed. We will call such schemes publicly verifiable secret sharing schemes, discuss new applications to escrow cryptosystems and payment systems with revocable anonymity, and present two new realizations based on ElGamal's cryptosystem.
[Sta96] Stadler M.. Publicly Verifiable Secret Sharing. In Advances in Cryptology - Eurocrypt '96, LNCS 1070, pages 190-199, Springer-Verlag, 1996.