Chapter 17: Secret Sharing Schemes

Chapter 17 of Trappe & Washington: secret splitting among m people using uniform random masks, the definition of a (t, w) threshold scheme, and Shamir's construction placing the secret at the constant term of a random degree t−1 polynomial recovered by Lagrange interpolation over a finite field. Includes the information-theoretic security proof — every candidate secret is consistent with exactly one polynomial — Blakley's geometric alternative, and the polynomial-reuse failure that leaks the difference of two secrets to any single shareholder.

Subject: Cryptography · 60 slides · diagram-first lesson

Open the interactive version of this deck

What this lesson covers

The lesson, slide by slide

1. Secret Sharing Schemes

Title

Cryptography · Chapter 17

Split a secret among w people so any t can recover it and any t−1 learn nothing at all

2. What you will be able to do

Objectives

A short chapter with an unusual property: its main construction is unconditionally secure. Almost nothing else in this book is — the one-time pad in Chapter 4, and this.

Figure (svg): Where threshold schemes are used: key custody, root CA keys, and cryptocurrency wallets.

The requirement is always the same shape: distrust of any individual, and tolerance for some being unavailable.

3. Why not just encrypt the secret?

Warm-up

A company wants no single person to hold the master key, but wants any three of five directors to be able to recover it.

Discussion prompt

Why does encrypting the key and distributing the ciphertext not solve this?

Hint: Ask who holds the key to the encryption.

Answer:

Because it moves the problem rather than solving it. Encrypting the master key produces a new key, which somebody must hold — and that person is now the single point of trust the exercise was meant to remove.

Splitting the ciphertext into pieces does not help either, because a ciphertext's pieces are not independent: several bytes of AES output plus the key structure can leak, and in any case whoever holds the key still needs only the ciphertext.

What is wanted is a scheme where the pieces themselves carry no information — where holding two of five shares is genuinely no better than holding none.

And where the threshold is tunable. Requiring all five is fragile: one director on holiday or one who disagrees blocks everything. Requiring any three tolerates both.

Those two requirements — pieces that reveal nothing, and a threshold below the total — are exactly the definition this chapter formalises.

4. Secret Splitting

Section

Section 17.1 · pp. 340-341

5. Secret Splitting between two people

Concept

Start with the simplest case. You have a message M, represented as an integer, to split between Alice and Bob so that neither alone can reconstruct it.

Give Alice a random integer r and give Bob M − r. To reconstruct, they add their pieces.

There is a technical problem: you cannot choose a random integer uniformly from all integers, because infinitely many equal probabilities cannot sum to 1. So choose n larger than any possible message and work mod n — then each residue has probability 1/n and everything is well defined.

\[ \text{Alice: } r, \qquad \text{Bob: } M - r \pmod n, \qquad r + (M - r) \equiv M \]

Alice's share is uniformly random and independent of M. Bob's is too, because M − r is uniform when r is. Neither share carries any information at all — which is the same reasoning as the one-time pad's, and it is why the security is unconditional.

Figure (svg): Secret splitting among three people: two random values and the remainder, which sum to the secret mod n.

Each share is a uniform random value on its own; only the complete set carries any information at all.

6. Splitting among m people

Worked example

The general case is the same idea, repeated.

Choose m − 1 random numbers r₁, …, r_{m−1} mod n

Why: Uniform and independent.

Give r₁ through r_{m−1} to m − 1 of the people

Why: Each of these shares is a uniform random value with no relation to M.

Give M − (r₁ + ⋯ + r_{m−1}) mod n to the remaining person

Why: This is also uniform, because subtracting a uniform value from anything gives a uniform value.

Reconstruction: everyone adds their share mod n

Why: The random terms cancel and M remains.

Verify: any m − 1 of the shares are jointly uniform and independent of M

Why: Whichever share is missing, the remaining ones are consistent with every possible M — for each candidate there is exactly one value the missing share could take. So m−1 participants learn nothing, and they learn nothing even with unlimited computing power.

Figure (svg): Secret splitting among three people: two random values and the remainder, which sum to the secret mod n.

Each share is a uniform random value on its own; only the complete set carries any information at all.

7. Why is this unconditionally secure?

Socratic

Almost every scheme in this book rests on a computational assumption. This one does not.

Discussion prompt

Explain the difference, and identify the only other unconditionally secure construction in the course.

Hint: Ask what an adversary with infinite computing power could do.

Answer:

The missing information does not exist. Given m−1 shares, every possible secret is consistent with exactly one value of the missing share — so the shares literally do not distinguish between secrets. There is nothing to compute.

Compare RSA: given n, the factorisation exists and is determined; it is merely expensive to find. An adversary with unlimited power recovers it immediately. Here she recovers nothing, because there is nothing there.

The other unconditionally secure construction is the one-time pad, Chapter 4 — and the mathematics is the same. A share here is a message masked by a uniform random value, which is exactly a pad.

And the same trade appears. The pad's price was a key as long as the message; secret sharing's price is that every share is as large as the secret, so w participants store w times the data.

Which explains the practical pattern: the secret shared is almost always a key, not the data. Split a 256-bit key among five directors, encrypt the terabyte with it. Chapter 1's hybrid argument, in a third setting.

8. Threshold Schemes

Section

Section 17.2 · pp. 341-346

9. The Threshold Scheme definition

Concept

Splitting requires everyone. The book's motivating story: the control of nuclear weapons in Russia was reported to use a mechanism where two out of three important people were needed to launch — and the spy-film image of three key slots requiring two keys turned together is the same idea.

Why not use splitting? Because one of the three officials might be away on a diplomatic mission, or might simply refuse. Requiring all three makes the system fragile in exactly the situation it is meant for.

(t, w) threshold scheme — A method of sharing a message M among w participants such that any subset of t participants can reconstruct M, and no subset of smaller size can reconstruct it. Note that t ≤ w, and t = w is the splitting scheme of the previous section.

Two parameters, two different risks. A small t makes recovery easy and collusion easy. A large t makes the secret hard to misuse and easy to lose. Choosing them is the design decision, and the rest of the chapter is how to implement any choice.

Figure (svg): A degree-two polynomial through three points: any three shares determine it, and two leave infinitely many candidates.

A degree t−1 polynomial is fixed by t points and utterly undetermined by t−1, which is the whole scheme.

10. The Shamir Threshold Scheme

Concept

Invented by Shamir in 1979, and also known as the Lagrange Interpolation scheme. It rests on a fact from school algebra: t points determine a polynomial of degree t−1 uniquely.

  1. Choose a prime p larger than the secret and larger than w, and work mod p
  2. Choose a polynomial s(x) of degree t−1 whose constant term is the secret M, with the other coefficients random
  3. Give participant i the pair (x_i, y_i) with y_i = s(x_i), for distinct non-zero x_i

\[ s(x) = M + a_1 x + a_2 x^2 + \cdots + a_{t-1}x^{t-1} \pmod p, \qquad M = s(0) \]

Any t participants pool their points and interpolate, recovering s and therefore s(0) = M. Any t−1 have too few points: infinitely many degree t−1 polynomials pass through them, one for every possible constant term.

Figure (svg): A degree-two polynomial through three points: any three shares determine it, and two leave infinitely many candidates.

A degree t−1 polynomial is fixed by t points and utterly undetermined by t−1, which is the whole scheme.

11. Building and recovering a (3, 5) scheme

Worked example

Take t = 3, w = 5, and a prime p — the book uses p = 1234567890133 for a realistic example.

Choose s(x) = M + a₁x + a₂x² mod p, with a₁ and a₂ random

Why: Degree 2, because t − 1 = 2. The secret is the constant term.

Evaluate at x = 1, 2, 3, 4, 5 and give participant i the pair (i, s(i))

Why: The x values are public labels; the y values are the shares. Note x = 0 is never given out, because s(0) is the secret.

To recover, any three participants supply their points

Why: Three points determine a unique degree-2 polynomial.

Interpolate with Lagrange's formula and evaluate at x = 0

Why: In fact you can evaluate at 0 directly without building the polynomial, which is how implementations do it.

\[ M = s(0) = \sum_{i} y_i \prod_{j \ne i} \frac{0 - x_j}{x_i - x_j} \pmod p \]

Verify: all arithmetic is mod p, so the divisions are modular inverses

Why: Which is why p must be prime — Section 3.11's requirement that every non-zero element be invertible. Over the integers the interpolation would produce fractions and the scheme would leak information through their size.

Figure (svg): Lagrange interpolation recovering the secret from three shares by a weighted sum.

Nothing here is cryptographic. It is interpolation, done modulo a prime so that division always works.

12. Why t−1 shares reveal nothing

Worked example

The security proof is short and worth doing, because it establishes an information-theoretic claim rather than a computational one.

Suppose t−1 participants pool their points

Why: They have t−1 points on a polynomial of degree t−1.

Pick any candidate secret M′ and add the point (0, M′) to their set

Why: Now they have t points.

Those t points determine exactly one polynomial of degree t−1

Why: By the same uniqueness fact the scheme is built on.

So for every candidate M′ there is exactly one polynomial consistent with their shares

Why: A bijection between candidate secrets and consistent polynomials.

Verify: every possible secret is therefore equally likely

Why: Their shares distinguish between no two candidates, so they have gained no information — not merely insufficient information. This holds against unlimited computing power, and it is why the book's schemes stand beside the one-time pad rather than beside RSA.

Figure (svg): With t−1 shares, every possible secret remains equally likely: for each candidate there is exactly one polynomial through the shares.

This is why the scheme is unconditionally secure: the missing information does not exist, rather than being expensive to find.

13. Blakley's geometric scheme

Concept

The book gives a second construction, due to Blakley and also from 1979, using geometry instead of algebra.

The secret is a point in t-dimensional space. Each share is a hyperplane passing through that point — a plane in three dimensions, a line in two.

Any t hyperplanes in general position intersect in exactly one point, which is the secret. Fewer than t intersect in a line, a plane, or a larger set — every point of which is an equally possible secret.

The picture is immediate in two dimensions: two lines cross at a point, and a single line leaves every point on it possible. That is a (2, w) scheme.

It is less efficient than Shamir's. A hyperplane in t dimensions takes t coordinates to describe, so each share is t times the size of the secret, where Shamir's shares are the same size as the secret. Shamir's scheme is what is used in practice, and Blakley's is valuable mainly for making the idea visual.

Figure (svg): Blakley's scheme: each share is a hyperplane, and the secret is the point where t of them intersect.

The same idea in geometry rather than algebra: intersection of t hyperplanes in t-dimensional space.

14. Shamir against Blakley

Comparison

Both are (t, w) threshold schemes from 1979. Fill the blanks.

Comparison matrix

ShamirBlakley
Underlying objecta polynomial of degree t−1a point where t hyperplanes intersect
A share isone point on the curveone hyperplane
Share sizethe same size as the secrett times the size of the secret
RecoveryLagrange interpolationsolve a linear system
Securityunconditionalunconditional

Both are unconditionally secure; only the share size differs, and that is why Shamir's is the one deployed.

15. The curve that carries the secret

Picture it

A degree t−1 polynomial, with the secret at x = 0 and the shares at x = 1, 2, 3, … The whole scheme is visible in one picture.

Figure (svg): A degree-two polynomial through three points: any three shares determine it, and two leave infinitely many candidates.

A degree t−1 polynomial is fixed by t points and utterly undetermined by t−1, which is the whole scheme.

Any three of those marked points determine the curve, and therefore its value at zero. Any two determine nothing at all — a fact that is much easier to see once the picture is in mind.

16. Lagrange Interpolation over a finite field

Concept

The recovery step deserves its own treatment, because it is the only piece of machinery the scheme needs and it is entirely elementary.

Given t points (x₁, y₁) … (x_t, y_t) with distinct x values, there is exactly one polynomial of degree at most t−1 passing through them, and Lagrange's formula writes it down directly.

\[ s(x) = \sum_{i=1}^{t} y_i \, L_i(x), \qquad L_i(x) = \prod_{j \ne i} \frac{x - x_j}{x_i - x_j} \]

Each basis polynomial L_i is designed to equal 1 at x_i and 0 at every other x_j — so the sum takes the value y_i at x_i, which is exactly what interpolation means.

And we only ever need s(0). Substituting x = 0 turns each L_i into a constant, so the secret is a weighted sum of the shares with publicly computable weights. No polynomial is ever constructed in an implementation.

Figure (svg): Lagrange interpolation recovering the secret from three shares by a weighted sum.

Nothing here is cryptographic. It is interpolation, done modulo a prime so that division always works.

17. Recovering a secret by hand

Worked example

A (3, 5) example worked mod p = 17, small enough that every step can be checked. The dealer used s(x) = 5 + 2x + x², so the secret is 5 and the shares are (1, 8), (2, 13), (3, 3).

L₁(0) = ((0−2)/(1−2)) · ((0−3)/(1−3)) = (−2/−1) · (−3/−2) = 2 · (3/2)

Why: The fractions are modular: 3/2 means 3 · 2⁻¹ mod 17, and 2⁻¹ = 9 because 2 · 9 = 18 ≡ 1.

So L₁(0) = 2 · 3 · 9 = 54 ≡ 3 (mod 17)

Why: One weight, computed from the public labels alone — no share value has been used yet.

L₂(0) = (−1/1) · (−3/−1) = (−1) · 3 = −3 ≡ 14, and L₃(0) = (−1/2) · (−2/1) = (−9) · (−2) = 18 ≡ 1

Why: Each weight depends only on which participants turned up.

Sanity check: the weights must sum to 1, since interpolating the constant polynomial 1 must give 1. 3 + 14 + 1 = 18 ≡ 1 ✓

Why: A free check on the arithmetic before any secret is touched, and worth doing every time.

\[ M = 8 \cdot 3 + 13 \cdot 14 + 3 \cdot 1 = 24 + 182 + 3 = 209 \equiv 5 \pmod{17} \]

Verify: 209 = 12 · 17 + 5, and the dealer's secret was 5

Why: Recovered exactly. Note that the recovery never reconstructed the polynomial — it computed three public weights and took a weighted sum of the shares, which is how implementations do it.

Figure (svg): Lagrange interpolation recovering the secret from three shares by a weighted sum.

Nothing here is cryptographic. It is interpolation, done modulo a prime so that division always works.

18. Read the sanity check

Prediction

Three participants compute Lagrange weights 5, 9 and 4 mod 17, before combining any shares.

Predict first

What does this tell you?

  • The secret is 18
  • The weights are consistent, since 5 + 9 + 4 = 18 ≡ 1 (mod 17)
  • There is an arithmetic error
  • The threshold must be 4

Correct: The weights are consistent, since 5 + 9 + 4 = 18 ≡ 1 (mod 17)

Note that the weights say nothing about the secret: they are computed from public labels alone, so they can be worked out before any share is revealed.

Which has a practical use — the weights for each possible quorum can be precomputed and published, so a recovery ceremony involves no arithmetic under pressure.

Why: The weights are the Lagrange basis polynomials evaluated at zero, and interpolating the constant polynomial 1 through the same points must return 1 — so the weights always sum to 1 modulo p. Here they do, so the arithmetic is consistent. It is a free check costing one addition, and it catches sign errors, wrong modular inverses and mistyped labels, which are the three commonest slips.

19. Why do the weights sum to one?

Socratic

The Lagrange weights at x = 0 always sum to 1 mod p, whatever the labels.

Discussion prompt

Prove it in one line, and say why the fact is useful.

Hint: Interpolate a polynomial you already know.

Answer:

Interpolate the constant polynomial s(x) = 1. Every share value is then 1, so the weighted sum is exactly the sum of the weights.

But interpolation of a degree-0 polynomial through t points returns that polynomial, so evaluating at 0 gives 1. Hence the weights sum to 1.

Why it is useful: it is a free consistency check. Compute the weights, add them, and confirm the total is 1 before combining any shares. This catches sign errors, wrong modular inverses and mistyped labels — the three commonest slips — at the cost of one addition.

And it has a design consequence too. Because the weights are determined entirely by which participants show up, they can be precomputed and published for each possible quorum, so a recovery ceremony needs no arithmetic under pressure.

It is also a small illustration of a useful habit: test a construction on an input whose answer you already know. Here the constant polynomial gives an identity for free.

20. The Lagrange weight at zero

Fill the middle

Complete the formula for the weight attached to participant i's share.

Fill in the blanks

L_i(0) = \prod_−x_j \fracx_i − x_j}___} \pmod p

Why: Substituting x = 0 into the basis polynomial gives a product of ratios of public labels — so the weights can be computed by anyone, before any share is revealed. That is a practically useful property: a recovery protocol can compute its weights first and then collect shares, and the weights themselves leak nothing.

21. Public or secret?

Definition probe

Getting this right is what makes an implementation safe.

Sort into buckets

Sort each quantity in a Shamir deployment.

Public
The prime p; The participant labels x_i; The threshold t; The Lagrange weights L_i(0)
Secret
The share values y_i; The polynomial's coefficients a₁ … a_{t−1}
pub
The modulus, the labels, the threshold and the weights derived from the labels are all public — Kerckhoffs's principle applies here as everywhere, and none of them constrains the secret.
sec
Only the share values and the random coefficients. The coefficients should in fact be destroyed after distribution: they serve no purpose afterwards, and anyone holding them plus one share recovers the secret. The same discard-the-setup-secret discipline as Chapter 16's digital cash.

22. How many participants can share one prime?

Estimation

The prime p must exceed both the secret and the number of participants.

Predict first

With a 256-bit secret, what practical limit does p place on w?

  • About 256
  • About 2¹²⁸
  • Effectively none
  • Exactly t

Correct: Effectively none

Which is worth knowing because the condition looks like a constraint and is not. Implementations pick p as a standard prime just above the secret's size — often 2²⁵⁷ − 93 or a similar value — and never think about w again.

The real practical limits on w are operational: how many people can be trusted to keep a share safe and be available when needed.

Why: p must exceed 2²⁵⁶ to hold the secret, which leaves room for astronomically more distinct non-zero labels than any deployment could use. The w < p condition binds only in toy examples with tiny primes — with a realistic secret, the modulus is set by the secret's size and the participant count never comes close.

23. A share that is smaller than the secret

Anomaly

An implementation stores 128-bit shares for a 256-bit secret, to halve the storage.

Predict first

What has gone wrong?

  • Nothing — shares can be compressed
  • The scheme cannot be information-theoretically secure, because there are not enough share values to be consistent with every secret
  • Recovery will be slower
  • The threshold must be increased to compensate

Correct: The scheme cannot be information-theoretically secure, because there are not enough share values to be consistent with every secret

The general rule that follows: in any information-theoretically secure scheme, each share is at least as large as the secret. Any implementation offering smaller shares has either given up the unconditional guarantee or made an error.

Computationally secure schemes can do better — Krawczyk's secret sharing encrypts the data with a random key, shares the key with Shamir, and erasure-codes the ciphertext, giving shares of size |secret|/t. It is a genuinely useful construction and it is not unconditional.

Why: The security proof requires that, for every candidate secret, there is exactly one value the missing share could take. With shares half the size of the secret there are only 2¹²⁸ possible share values against 2²⁵⁶ candidate secrets, so most secrets have no consistent completion — and the shares therefore rule some out. This is Proposition 4.4's counting argument again: unconditional security requires the key space to be at least as large as the message space.

24. What a threshold scheme guarantees

Two truths and a lie

Two of these overstate the guarantee.

Eliminate the wrong options

Which statement is correct?

  • a. Fewer than t participants learn nothing about the secret, even with unlimited computing power
  • b. The scheme prevents t participants from colluding
  • c. The scheme detects if a participant supplies a wrong share

Survives elimination: a

Why: The guarantee is precisely stated and precisely bounded: below the threshold, nothing at all, unconditionally. At or above the threshold, everything. And nothing whatever about honesty — a wrong share corrupts the result invisibly, which is why every serious deployment uses a verifiable variant.

25. Sharing, splitting, or neither?

Discrimination

Several schemes that distribute a secret. Only some are secret sharing.

Sort into buckets

Sort each one.

A real sharing scheme
Give each of five people a random value, with the fifth being the secret minus the sum; Points on a random degree-2 polynomial through the secret
Not sharing — each piece is useful, or the whole is duplicated
Give each of five people 51 bits of a 256-bit key; Encrypt the key five ways, one per person's public key; Write the key on five pieces of paper in five safes
share
Both are masking constructions: each share is uniform and independent of the secret, so a sub-threshold set is consistent with every candidate. Splitting is the t = w case of the polynomial scheme.
not
Dividing the bits leaves each holder with real information and reduces an attacker's search. Encrypting to each person's key gives every person the whole secret. And five copies is five single points of failure. All three describe distribution without any of sharing's properties.

26. What sharing costs

Cost model

Unconditional security has a price, and it is the same price as the one-time pad's.

Annotate

On: \( \text{total storage} = w \times |M|, \qquad \text{recovery} = O(t^2) \text{ field operations} \)

  • Every share is the size of the secret, so five participants store five copies' worth. This is forced by the counting argument, not by the construction.
  • Computing t Lagrange weights, each a product of t−1 ratios. For realistic t this is microseconds — the recovery cost is never the constraint.
  • The size of w does not appear in the recovery cost, only t. Adding participants costs storage and nothing else, which is why generous w is cheap.
  • Share a key, not the data. A 256-bit key across seven holders is 224 bytes in total; a terabyte archive across seven holders is seven terabytes.
  • Krawczyk's scheme gives shares of size |M|/t by encrypting first and erasure-coding the ciphertext — at the cost of the guarantee becoming computational.

The same trade as every unconditional construction in this book: perfect security, paid for in space.

27. Why must the coefficients be destroyed?

Socratic

After distributing shares, the dealer holds the polynomial's random coefficients a₁ … a_{t−1}.

Discussion prompt

What can someone holding them do, and what practice does this suggest?

Hint: Count how many unknowns remain once the coefficients are known.

Answer:

Anyone holding the coefficients plus a single share recovers the secret. With a₁ and a₂ known, one point y_i = M + a₁x_i + a₂x_i² has one unknown, and M falls out in one subtraction.

**Worse, the coefficients alone plus knowledge of any one share value is enough** — so a compromised dealer's notes turn a (3, 5) scheme into a (1, 5) scheme.

So the dealer must destroy them, and ideally must not have been able to record them: a hardware module that generates, distributes and forgets is the right shape.

This is exactly Chapter 16's discipline. Brands' scheme discards its setup exponents because storing them serves no purpose and their discovery compromises everything. Same reasoning, different scheme.

And it generalises into a design principle: any value that is needed once and never again should be destroyed rather than stored, and a construction that can be arranged so the value never exists in one place is better still. Trusted setup ceremonies and threshold key generation both take this to its conclusion.

28. How a root key ceremony actually runs

Real world

The DNSSEC root key and commercial root CA keys are protected by threshold schemes, in ceremonies with published procedures.

Discussion prompt

Describe what such a ceremony involves, and which parts are cryptography.

Hint: Most of it is not cryptography, which is the point.

Answer:

Physical controls first: a shielded room, tamper-evident bags, safes with separate combinations, and participants from several organisations and jurisdictions who do not report to one another.

Key generation inside a hardware security module, so the private key never exists in software and cannot be copied out.

Shares distributed on physical tokens or smart cards, held by named officers who take them away to separate locations.

The whole thing filmed, witnessed and audited, with a published script followed step by step and any deviation recorded.

And rehearsed, because the procedure must work years later with different people, from documentation alone.

Which parts are cryptography? The threshold scheme and the HSM's key generation. Everything else — the room, the witnesses, the script, the jurisdictions — is process, and it is the majority of the effort because it is where the realistic failures are.

This is the clearest example in the book of cryptography being the easy part.

Figure (svg): Where threshold schemes are used: key custody, root CA keys, and cryptocurrency wallets.

The requirement is always the same shape: distrust of any individual, and tolerance for some being unavailable.

29. Find the problems in this custody procedure

Error analysis

From a company's key management policy.

Annotate

  • Any two executives can recover the master key — a very low bar for collusion, and probably below what the policy intends. With five holders, three is the usual choice.
  • A stolen or backed-up laptop yields a share, and two compromised laptops yield the key. Shares belong on hardware tokens or in safes, not in a filesystem that syncs to a cloud.
  • Fatal. The coefficients plus any single share give the secret, so the log turns a (2, 5) scheme into a (1, 5) one — and log files are the least protected artefact in most systems.
  • Media degrade, people leave, procedures are forgotten. An untested recovery is a hope, and four years is long enough for at least one share to have silently become unusable.

The third point is the one that voids the scheme entirely, and it is the kind of thing added for convenience by someone who did not know what the coefficients were.

30. Order these by how much they weaken a (3, 5) scheme

Ranking

Five deviations from correct practice.

Put in order

  1. Publishing the participant labels
  2. Choosing p only slightly larger than the secret
  3. One share stored on a shared network drive
  4. Reusing the coefficients for a second secret
  5. Keeping the coefficients in a log file

Why: Publishing labels is harmless — they are public by design. A tight prime is fine provided it exceeds the secret. One exposed share still leaves the attacker needing two more. Coefficient reuse leaks the difference of two secrets to any single holder. And keeping the coefficients reduces the threshold to one, which destroys the scheme outright. The ordering runs from 'no effect' to 'total compromise', and only the last two involve the mathematics at all.

31. Why does the secret live at x = 0?

Explain it to yourself

Shamir's scheme puts the secret at s(0) and hands out s(1), s(2), and so on.

Discussion prompt

Is x = 0 special, and what would change if the secret were at s(7) instead?

Hint: Ask what makes a point usable as a share.

Answer:

Nothing is mathematically special about 0. The scheme would work identically with the secret at s(7), provided no participant is given the label 7 — the requirement is only that the secret's point is not handed out.

Zero is chosen for convenience. It makes the secret the polynomial's constant term, which is the easiest coefficient to set, and it makes the Lagrange weights slightly simpler to compute.

And it makes the label rule easy to state: participants get non-zero labels, which is a check an implementation can enforce trivially.

What would genuinely break the scheme is giving some participant the label where the secret lives — that person would simply hold the secret. Which sounds obvious and is exactly the kind of off-by-one an implementation can make when labels are assigned from a list that starts at zero.

The general observation: many choices in a cryptographic construction are conventions rather than requirements, and knowing which is which is what lets you read a specification correctly. Here, 'the secret is the constant term' is a convention and 'no participant holds that point' is a requirement.

32. Match each requirement to its parameter

Matching

Four requirements on the prime and the labels, each for a different reason.

Match the pairs

  • n1. p must be prime
  • n2. p must exceed the secret
  • n3. p must exceed w
  • n4. Labels must be distinct and non-zero
  • m1. Interpolation divides, so every non-zero element must be invertible
  • m2. Otherwise the secret wraps and recovery returns M mod p
  • m3. Otherwise there are not enough distinct labels to go round
  • m4. Repeated labels give the same equation twice; the zero label is the secret itself

Why: Four conditions, four distinct reasons, and only the first is cryptographic in flavour — it is Section 3.11's field requirement. The others are bookkeeping, and violating any of them produces a scheme that appears to work in testing and fails in a specific case: a large secret, a large participant count, or a badly assigned label.

33. How small can t be?

Edge cases

A (1, 5) scheme means any one participant can recover the secret.

Discussion prompt

Is that a valid threshold scheme, and what does it degenerate into?

Hint: Work out what a degree-0 polynomial looks like.

Answer:

It is valid and it is useless as a secret. With t = 1 the polynomial has degree 0, so it is the constant M — and every share is just M itself.

Which means it degenerates into replication: five copies of the secret, one per participant. The scheme provides availability and no confidentiality against any participant.

And that is sometimes the right answer, when the requirement is 'do not lose this' rather than 'do not let one person use it'. Recognising it saves building machinery for a problem that is not there.

At the other end, t = w is splitting, with maximum collusion resistance and zero tolerance for loss.

So the parameter t interpolates between two familiar things — replication at one end and unanimity at the other — and every intermediate value is a stated position on the two risks. Naming the endpoints makes the choice in the middle easier to justify.

34. Which failure would you insure against?

Commit first

A (3, 5) scheme has protected a company's master key for six years.

Predict first

What do you expect has already gone wrong?

  • An attacker has collected two shares
  • At least one share is unusable — a departed holder, a corrupted medium, or a forgotten passphrase
  • The interpolation code has a bug
  • The prime was too small

Correct: At least one share is unusable — a departed holder, a corrupted medium, or a forgotten passphrase

The mitigation is annual rehearsal plus verifiable sharing, so each holder can confirm their share is consistent without assembling anything.

It is worth noting how different this is from the rest of the course: the adversary is not the problem here. Entropy is.

Why: Six years is long enough for staff turnover, media degradation and forgotten procedures, and none of these announces itself — a share only proves unusable when recovery is attempted. Since three of five are needed, two silent failures still leave the scheme working and a third makes the key unrecoverable, with no warning at any point.

35. Complete the security argument

Faded example

Four blanks, and the proof is on the page.

Fill in the blanks

Suppose t − 1 participants pool their shares. For any candidate secret M′, adding the point (0, M′) gives t points, which determine exactly one polynomial of degree t−1. So there is a bijection between candidate secrets and consistent polynomials, and every secret is equally likely.

Why: The whole proof is the bijection: one polynomial per candidate secret means the shares distinguish between none of them. Note what is not in the argument — no computational assumption, no hardness, no bound on the adversary's resources. That absence is what makes the guarantee unconditional, and it is the same absence that makes the one-time pad's proof work.

36. Reading the Lagrange formula

Notation

One formula recovers the secret, and each part of it has a job.

Annotate

On: \( M = \sum_{i=1}^{t} y_i \prod_{j \ne i} \frac{0 - x_j}{x_i - x_j} \pmod p \)

  • The share values — the only secret inputs. Everything else in the formula is public.
  • The Lagrange basis coefficient for participant i: it is 1 at x_i and 0 at every other x_j, which is what makes the sum reproduce the polynomial.
  • The point being evaluated. The secret is s(0), so the formula is specialised to that from the start — no polynomial ever needs to be constructed.
  • A difference of public labels, so it is known to everyone; its modular inverse is computed by Section 3.2's extended Euclidean algorithm.
  • Essential, and not merely for convenience. Over the rationals the coefficients would be fractions whose sizes leak information about the shares, and the security proof would fail.

Note that the x-labels are public and only the y-values are secret — which means a participant's index can be assigned openly and need not be protected.

37. Which scheme does each requirement need?

Definition probe

Three parameters, and the requirement decides them.

Sort into buckets

Sort each requirement by the scheme it calls for.

Splitting — t = w
All five directors must consent
A threshold scheme with t < w
Any three of five directors suffice; Two officials of three can launch; The secret must survive two directors leaving
Not a sharing problem — just give everyone a copy
Any one of five can act alone
split
Requiring unanimity is exactly t = w, which is Section 17.1's construction. Maximum protection against collusion and maximum fragility.
thresh
Anything with t strictly between 1 and w. Note the last row is the same requirement stated from the availability side: surviving two departures from five means t ≤ 3.
copy
If one person can act alone there is no secret to share — the requirement is availability, and copying is the answer. Recognising this saves building machinery for a problem that does not exist.

38. Why must p be prime?

Explain it to yourself

Shamir's scheme works mod p, and the book requires p to be prime and larger than both the secret and w.

Discussion prompt

Explain each of the three requirements.

Hint: Interpolation involves division, and the labels must be distinct.

Answer:

Prime, because interpolation divides. The Lagrange coefficients contain (x_i − x_j)⁻¹, and Section 3.11 says every non-zero element is invertible exactly when the modulus is prime. Mod a composite, some differences would have no inverse and recovery would sometimes fail.

Larger than the secret, or the secret would wrap around and the value recovered would be M mod p rather than M. The same requirement as the splitting scheme's n.

Larger than w, so that w distinct non-zero labels x₁, …, x_w exist. Two participants sharing a label would give the same equation twice, so t of them would not determine the polynomial.

And a fourth, implicit requirement: the coefficients a₁, …, a_{t−1} must be uniformly random. If they were predictable, the polynomial could be guessed from fewer points and the security proof — which assumes every candidate secret is equally likely — would not hold.

Chapter 5's rule, appearing in yet another place: the construction is only as good as the randomness feeding it.

39. Reuse a polynomial and lose everything

Counterexample

An administrator shares two different secrets among the same five people, using the same polynomial coefficients a₁ and a₂ and only changing the constant term.

Discussion prompt

Show that any single participant can now recover both secrets.

Hint: Compare the two shares one participant holds.

Answer:

Participant i holds y_i = M₁ + a₁x_i + a₂x_i² and y′_i = M₂ + a₁x_i + a₂x_i².

Subtracting gives y_i − y′_i = M₁ − M₂, so one participant immediately learns the difference of the two secrets — which for many applications is already fatal.

And if either secret is ever revealed or guessed, the other follows at once, from one share.

With two participants it is worse: two pairs give two equations in a₁ and a₂ after the difference has cancelled M, so the coefficients fall out and then both secrets do.

The rule is that every sharing must use fresh random coefficients. This is the fourth appearance of the same failure — the two-time pad in Chapter 4, keystream reuse in Chapter 5, a repeated signature nonce in Chapter 13, and now polynomial reuse.

The pattern is exact: a scheme masking a secret with random values collapses when the random values are reused, and it collapses to a linear relation between the secrets.

40. Where threshold schemes are actually used

Real world

Secret sharing is one of the few constructions in this book deployed almost exactly as described.

Discussion prompt

Name three real deployments and the reason each chose a threshold rather than a single key.

Hint: Certificate authorities, cryptocurrency custody, and the internet's root of trust.

Answer:

Root CA key ceremonies. A certificate authority's root private key is generated in a filmed ceremony and split among officers, with shares stored in separate safes in separate buildings. No individual can sign, and no individual's absence blocks a signing.

DNSSEC root key signing. The root zone's key is protected by a ceremony with holders of physical share cards from several countries, requiring a quorum to attend. It is a (t, w) scheme with people flying to it.

Cryptocurrency custody. Multi-signature wallets require k of n keys to authorise a transfer — technically threshold signatures rather than sharing a secret, but the same requirement and often the same mathematics.

And disaster recovery generally: an organisation's master encryption key split among directors, so that the departure or death of any one is survivable and no single person can act alone.

The common shape is two simultaneous distrusts: distrust of any individual acting, and distrust that everyone will be available. A single key fails the first and unanimity fails the second.

Figure (svg): Where threshold schemes are used: key custody, root CA keys, and cryptocurrency wallets.

The requirement is always the same shape: distrust of any individual, and tolerance for some being unavailable.

41. How do shares scale?

Estimation

A (3, 5) Shamir scheme protects a 256-bit key.

Predict first

How large is each share?

  • About 85 bits
  • About 256 bits
  • About 768 bits
  • About 1280 bits

Correct: About 256 bits

The parallel with the one-time pad is exact. There, unconditional security cost a key as long as the message; here it costs w copies' worth of storage. Both follow from the same counting argument — Proposition 4.4's requirement that the key space be at least as large as the message space.

It is also why the shared secret is nearly always a key rather than the data itself: 256 bits × 5 participants is trivial, and a terabyte × 5 is not.

Why: Each share is a point (x_i, y_i) where y_i is an element mod p, and p must exceed the secret — so each share is about the size of the secret itself, roughly 256 bits plus a small index. Shares do not shrink with t: the total storage across w participants is w times the secret, which is the price of the unconditional guarantee.

42. Choosing t and w

Trade off

Two parameters, two opposing risks. Fill the blanks.

Comparison matrix

t smallt large
Risk of collusionhigh — few people can act togetherlow — many must agree
Risk of losslow — many participants may be unavailablehigh — few absences block recovery
t = 1no secret at all — everyone can act—
t = w—any single loss is permanent
Choose byhow many people you distrusthow many you expect to be unavailable

The two rows pull in opposite directions, so there is no universally right answer — only a statement of how much of each risk is acceptable.

43. What does secret sharing not provide?

Socratic

The scheme is unconditionally secure and reconstructs perfectly. It also has clear limits.

Discussion prompt

Name three things it does not do, and say what would be needed for each.

Hint: Consider a dishonest dealer, a dishonest participant, and what happens after reconstruction.

Answer:

It does not detect a cheating dealer. The person who creates the shares could hand out inconsistent ones, so that different subsets reconstruct different secrets — and nobody would know until reconstruction. Verifiable secret sharing adds commitments to each coefficient so participants can check their share is consistent.

It does not detect a cheating participant. Someone who supplies a wrong share at reconstruction corrupts the result silently, and the honest participants recover a wrong secret with no indication. The same commitments fix this.

It does not survive reconstruction. Once t shares are combined, whoever did the combining holds the secret in full — so the protection ends exactly at the moment of use. Threshold cryptography avoids this by having participants compute with their shares without ever assembling the secret.

And it does not handle changing membership. Adding a participant or changing t requires re-sharing, which needs the secret — so the dealer must be involved again, or a proactive re-sharing protocol used.

The general point, which is Chapter 15's: a primitive provides exactly one property. Everything else is a construction on top, and each construction has its own name and its own paper.

44. Complete the Shamir scheme

Faded example

Four blanks and the whole construction is on the page.

Fill in the blanks

Choose a prime p larger than the secret. Build a polynomial of degree t − 1 whose constant term is the secret and whose other coefficients are random. Give participant i the value of the polynomial at x_i. Any t participants recover the secret by interpolating and evaluating at 0.

Why: The degree is t−1 because that is what t points determine uniquely — one less than the threshold, which is the single fact to remember. The coefficients must be uniformly random or the security proof fails, and the labels must be non-zero because zero is where the secret lives.

45. Which change breaks the scheme?

Elimination

Four modifications to a working (3, 5) Shamir deployment.

Eliminate the wrong options

Which one destroys the security?

  • a. Publishing the participants' x labels
  • b. Using a larger prime p
  • c. Deriving the coefficients a₁, a₂ from the secret by a fixed rule
  • d. Storing shares in five different vaults

Survives elimination: c

Why: Deriving the coefficients from the secret means the polynomial is determined entirely by the secret, so a single share plus knowledge of the rule reduces recovery to guessing the secret and checking. The security proof requires that for every candidate secret there is a consistent polynomial, and a deterministic rule leaves exactly one polynomial per secret — which is fine — but makes each share a checkable function of the secret, which turns an unconditional guarantee into a search.

46. Match each variant to what it adds

Matching

Shamir's scheme is the base; several named extensions address its limits.

Match the pairs

  • v1. Verifiable secret sharing
  • v2. Proactive secret sharing
  • v3. Threshold signatures
  • v4. Weighted sharing
  • w1. Participants can check their share is consistent, catching a cheating dealer
  • w2. Shares are refreshed periodically, so an attacker must compromise t of them within one period
  • w3. Participants sign using their shares without ever assembling the key
  • w4. Some participants hold more shares, so a director counts more than a clerk

Why: Each extension answers a limitation of the base scheme: no cheating detection, no protection against slow accumulation of shares over years, no way to use the secret without exposing it, and no way to express unequal authority. Weighted sharing is the simplest — give a director three of the five shares — and threshold signatures the most valuable, because they remove the moment of exposure entirely.

47. Design a key custody scheme

Constraint

A company's master encryption key protects ten years of archives. There are seven executives; two typically travel; the board wants no individual able to decrypt and no plausible scenario in which the archive is lost.

Discussion prompt

Choose t and w, and specify the surrounding process.

Hint: Two constraints bound t from opposite sides.

Answer:

Lower bound on t: no individual, and preferably no pair, should be able to act — so t ≥ 3.

Upper bound on t: two are typically travelling and one might leave or be unreachable, so recovery must work with four available. That gives t ≤ 4.

Choose t = 3, w = 7. Three of seven: collusion needs three executives, and recovery survives four being unavailable simultaneously. The margin on both sides is deliberate.

Use verifiable secret sharing, so each holder can check their share is consistent — otherwise a dishonest dealer or a corrupted store is undetectable until the day the archive is needed.

Rehearse the recovery annually. An untested recovery procedure is not a recovery procedure, and a share that has silently corrupted is indistinguishable from a working one until used.

And re-share when membership changes, rather than reassigning an existing share — a departing executive's share must stop being useful, which requires new coefficients rather than a new holder.

Note that four of the six decisions are operational. The cryptography here is genuinely easy; the process around it is what fails.

48. Order these by how much they threaten a threshold scheme

Ranking

Five things that can go wrong with a deployed (3, 5) scheme.

Put in order

  1. One share is lost
  2. Two shares are stolen
  3. The dealer distributed inconsistent shares
  4. The same polynomial was reused for a second secret
  5. Three shares are stolen

Why: Losing one share leaves four, which still exceeds the threshold — no harm. Two stolen shares reveal nothing, by the security proof. Inconsistent shares mean recovery fails or produces a wrong secret, discovered only when needed — bad, and detectable in advance with verifiable sharing. Polynomial reuse leaks the difference of the two secrets to any single holder. And three stolen shares is a complete compromise. The ordering is by how much of the guarantee survives.

49. Where would a custody scheme actually fail?

Commit first

A (3, 5) Shamir scheme, correctly implemented, shares stored in five safes.

Predict first

What is most likely to go wrong over ten years?

  • The mathematics of Lagrange interpolation
  • Operational failure — a lost share, a corrupted medium, an untested recovery, or nobody remembering the procedure
  • An attacker solving for the polynomial
  • The prime p being too small

Correct: Operational failure — a lost share, a corrupted medium, an untested recovery, or nobody remembering the procedure

This is unusual for this course and worth noticing: for once the cryptography is genuinely not the weak point, because there is no computational assumption to age.

Which shifts the entire review to process: annual rehearsal, share verification, documented custody, and a re-sharing trigger on personnel change.

Why: The construction is unconditionally secure, so there is nothing for an attacker to solve. Over ten years the realistic failures are all operational: media degrading, people leaving without their share being reissued, the recovery procedure never being rehearsed, and the documentation being encrypted with the key it protects. That last one is a real and recurring failure.

50. What is missing from “the key is split among five people”?

Missing information

A control document states that the master key is split among five executives.

Discussion prompt

List what a reviewer still cannot determine.

Hint: Two parameters, one construction, and several process questions.

Answer:

How many are needed to recover it? 'Split' could mean all five, which is fragile, or a threshold, which is not. The document names w and omits t.

Is it a real sharing scheme, or a divided key? Giving each person a fifth of the bits is not secret sharing — four people would then face only a 2⁵¹ search on a 256-bit key rather than 2²⁵⁶.

Can shares be verified? Without verifiable sharing, a corrupted or malicious share is undetectable until recovery is attempted.

Has recovery been tested? An untested procedure is a hope.

What happens when someone leaves? A departing executive's share must become useless, which needs re-sharing rather than collection.

And where is the recovery documentation? If it is in the archive the key protects, the scheme has a circular dependency that only surfaces in a real incident.

The second question is the one that most often reveals a real problem: dividing a key is not sharing it, and the two are described identically in plain English.

51. Explain why two shares reveal nothing

Explain it

A colleague is sceptical: surely two of three shares must narrow down the secret somewhat.

Discussion prompt

Convince them, using the smallest possible example.

Hint: Work in a tiny modulus where every case can be listed.

Answer:

Use the two-person splitting case first, because it is the clearest. Alice has a random r and Bob has M − r, mod n. Alice's share is uniform and independent of M: whatever M is, r was equally likely to be any value.

Then the key move: for any candidate secret M′, there is exactly one value Bob's share would need to take. So Alice's share is consistent with every possible secret, and equally so.

Extend to the polynomial case. Two points and a candidate secret give three points, which determine exactly one degree-2 polynomial. One polynomial per candidate, so all candidates remain equally likely.

The intuition to leave them with: the shares are not pieces of the secret, they are constraints on it — and t−1 constraints on a t-dimensional space leave a whole line of possibilities, every point of which is a valid secret.

And the contrast that makes it stick: if you cut a written password into three strips, two strips do narrow it down. Secret sharing is not cutting; it is masking, and that is exactly why it gives an unconditional guarantee where cutting gives none.

52. What if t participants are dishonest?

Edge cases

The scheme guarantees that t−1 learn nothing. It says nothing about what t can do.

Discussion prompt

What can a coalition of exactly t dishonest participants achieve, and what would limit them?

Hint: They can do everything an honest quorum can do.

Answer:

They recover the secret, completely. That is not a flaw; it is the specification. A (t, w) scheme grants exactly the authority of t participants to any t participants, honest or not.

They can also do it silently. Nothing in the scheme records that a reconstruction happened, so a coalition can recover a key and use it with no trace.

Limiting them means changing t or changing the model. Raising t raises the collusion bar and lowers availability — the trade from the earlier slide, with no way around it.

Or use threshold cryptography instead, where participants compute a signature or a decryption jointly without assembling the key. Then a coalition can use the key for one operation but never holds it, so misuse is bounded and, if the protocol logs participation, visible.

Or add a second factor entirely: a hardware module that requires physical presence, or an auditable log of every reconstruction. Both are outside the cryptography.

The honest summary: secret sharing distributes trust; it does not create accountability. Those are different properties, and conflating them is how custody schemes end up with no audit trail.

53. What makes this chapter unusual

Pattern

Seventeen chapters in, and this is only the second construction with an unconditional guarantee. The reasons are worth collecting.

  1. The security is information-theoretic. For every candidate secret there is exactly one consistent set of shares, so the missing information does not exist. Unlimited computing power gains nothing.
  2. The mathematics is elementary. t points determine a degree t−1 polynomial — school algebra, done over a finite field so that division works.
  3. The price is the same as the one-time pad's. Unconditional security costs storage proportional to the secret, per participant. Chapter 4's counting argument, in a new setting.
  4. And the failure mode is the same too. Reusing the random coefficients across two secrets leaks their difference, exactly as a reused pad, a reused keystream and a reused signature nonce do.

The practical consequence: share a key, not the data, and generate fresh coefficients every time. Then the guarantee is real and permanent, which almost nothing else in this book can say.

Figure (svg): With t−1 shares, every possible secret remains equally likely: for each candidate there is exactly one polynomial through the shares.

This is why the scheme is unconditionally secure: the missing information does not exist, rather than being expensive to find.

54. Splitting a key into pieces is secret sharing

Trap

The trap

The trap. A 256-bit key is split into five 51-bit chunks, one per executive. No single person has the key, and all five together reconstruct it by concatenation. This achieves the same thing as Shamir's scheme with far less mathematics.

It is the obvious implementation, and it appears in real control documents.

The fix

Why it fails. Each chunk is part of the key, so four executives hold 205 of the 256 bits and face a search of 2⁵¹ — about two quadrillion, which is hours on modest hardware. Four people who should have no capability whatever can recover the key.

Even one chunk is damaging. A single executive removes 51 bits from an attacker's search, so a 256-bit key becomes a 205-bit key for anyone who compromises one person. The guarantee degrades smoothly, which is precisely what a threshold scheme is defined not to do.

And there is no threshold at all. Concatenation requires every chunk, so it is t = w with none of the availability tolerance — the worst of both designs.

In a real sharing scheme each share is uniformly random and independent of the secret. Four of five Shamir shares leave a 256-bit key with all 256 bits of uncertainty, because the shares constrain the polynomial rather than containing the key.

The distinguishing question: is a share the same size as the secret and statistically independent of it? If a share is smaller than the secret, it is a piece and not a share — and the scheme is not what it claims.

55. Check: the polynomial's degree

Check

Work it out before you click.

Check your understanding

For a (4, 9) Shamir threshold scheme, what degree polynomial is used?

  • A. 4
  • B. 3 (correct)
  • C. 9
  • D. 8

Answer: B

Why: Degree t − 1 = 3, because four points determine a cubic uniquely and three leave one degree of freedom — exactly one candidate polynomial for each possible secret. The threshold is the number of points needed; the degree is one less.

Why A tempts people
Degree 4 would need five points to determine, making it a (5, 9) scheme. Off by one in the direction most people go.
Why C tempts people
9 is w, the number of participants, which sets how many shares are handed out and nothing about the degree.
Why D tempts people
Degree w − 1 would require all nine participants, which is the splitting case rather than a threshold scheme.

56. Check: what t−1 shares reveal

Check

Apply the security argument.

Check your understanding

In a (3, 5) scheme, two participants pool their shares. What do they learn about the secret?

  • A. Two thirds of it
  • B. Enough to narrow it to a small set
  • C. Nothing — every possible secret remains equally likely (correct)
  • D. The secret, if they also know p

Answer: C

Why: For every candidate secret M′, adding the point (0, M′) to their two points gives three points determining exactly one quadratic. So there is a one-to-one correspondence between candidate secrets and consistent polynomials, and the shares distinguish between none of them. The guarantee is information-theoretic and holds against unlimited computing power.

Why A tempts people
This is what dividing a key into pieces would give, and it is exactly the failure the scheme is designed to avoid.
Why B tempts people
There is no narrowing at all — the set of candidates is not reduced by even one value.
Why D tempts people
p is public. Knowing the modulus is assumed throughout and gives no advantage.

57. Check: reusing coefficients

Check

Consider what one participant can compute.

Check your understanding

Two secrets are shared using the same random coefficients, changing only the constant term. What does a single participant learn?

  • A. Nothing — the scheme still holds
  • B. The difference of the two secrets (correct)
  • C. Both secrets
  • D. The polynomial's coefficients

Answer: B

Why: Participant i holds M₁ + a₁x_i + a₂x_i² and M₂ + a₁x_i + a₂x_i². Subtracting cancels every term involving the coefficients and leaves M₁ − M₂. This is the fourth appearance of the reuse failure in the course — after the two-time pad, keystream reuse and the repeated signature nonce — and it has the same shape every time.

Why A tempts people
The subtraction is one operation and requires nothing beyond the two shares the participant already holds.
Why C tempts people
The difference alone does not give both, unless one is separately known or guessable — which is often true, and is why the leak matters.
Why D tempts people
Two participants can recover the coefficients; one cannot, because the difference eliminates them rather than exposing them.

58. One page on secret sharing

Connect it up

The chapter is short and unusually self-contained.

Draw it

Write the splitting scheme for m people in two lines. Then write Shamir's scheme in four: the prime, the polynomial and its degree, the shares, and the recovery. Draw the security argument as a bijection between candidate secrets and consistent polynomials. Note the two parameters and the opposing risks they trade. Finish with the reuse failure and the three earlier chapters where the same failure appeared.

That last line is the most transferable thing here: masking with random values is a recurring pattern, and reusing the mask breaks it every time, in exactly the same way.

59. Exit ticket

Exit ticket

One question, about what makes this chapter different from the sixteen before it.

Predict first

Why is Shamir's scheme unconditionally secure, where RSA is not?

  • Because polynomial interpolation is harder than factoring
  • Because with t−1 shares every candidate secret is consistent with exactly one polynomial, so the information is absent rather than merely expensive to compute
  • Because the shares are longer than the secret
  • Because the prime p is very large

Correct: Because with t−1 shares every candidate secret is consistent with exactly one polynomial, so the information is absent rather than merely expensive to compute

Why: RSA's factorisation exists and is determined by n; it is only expensive to find, so unlimited computing power recovers it. Here the shares are consistent with every possible secret in exactly one way each, so there is nothing to find — an adversary with infinite power learns nothing. This is the same kind of guarantee as the one-time pad's, and it comes at the same kind of price: storage proportional to the secret, per participant.

60. What to carry into Chapter 18

Recap

A short chapter with a rare guarantee.

Chapter 18 next. Games — flipping a coin over the telephone and playing poker with no trusted dealer. Both use the square roots mod n of Section 3.9, and both are protocols between parties who actively expect each other to cheat.

Figure (svg): With t−1 shares, every possible secret remains equally likely: for each candidate there is exactly one polynomial through the shares.

This is why the scheme is unconditionally secure: the missing information does not exist, rather than being expensive to find.

Sources

  1. Introduction to Cryptography with Coding Theory, 3rd edition — Wade Trappe and Lawrence C. Washington — Pearson, 2020 (ISBN 978-0-13-485906-4)
  2. Chapter 17 — Secret Sharing Schemes (sections 17.1-17.2) — Trappe & Washington, 3rd edition, pp. 340-348

Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108