Chapter 17 of Trappe & Washington: secret splitting among m people using uniform random masks, the definition of a (t, w) threshold scheme, and Shamir's construction placing the secret at the constant term of a random degree t−1 polynomial recovered by Lagrange interpolation over a finite field. Includes the information-theoretic security proof — every candidate secret is consistent with exactly one polynomial — Blakley's geometric alternative, and the polynomial-reuse failure that leaks the difference of two secrets to any single shareholder.
Subject: Cryptography · 60 slides · diagram-first lesson
Open the interactive version of this deck
Title
Cryptography · Chapter 17
Split a secret among w people so any t can recover it and any t−1 learn nothing at all
Objectives
A short chapter with an unusual property: its main construction is unconditionally secure. Almost nothing else in this book is — the one-time pad in Chapter 4, and this.
Figure (svg): Where threshold schemes are used: key custody, root CA keys, and cryptocurrency wallets.
Warm-up
A company wants no single person to hold the master key, but wants any three of five directors to be able to recover it.
Discussion prompt
Why does encrypting the key and distributing the ciphertext not solve this?
Hint: Ask who holds the key to the encryption.
Answer:
Because it moves the problem rather than solving it. Encrypting the master key produces a new key, which somebody must hold — and that person is now the single point of trust the exercise was meant to remove.
Splitting the ciphertext into pieces does not help either, because a ciphertext's pieces are not independent: several bytes of AES output plus the key structure can leak, and in any case whoever holds the key still needs only the ciphertext.
What is wanted is a scheme where the pieces themselves carry no information — where holding two of five shares is genuinely no better than holding none.
And where the threshold is tunable. Requiring all five is fragile: one director on holiday or one who disagrees blocks everything. Requiring any three tolerates both.
Those two requirements — pieces that reveal nothing, and a threshold below the total — are exactly the definition this chapter formalises.
Section
Section 17.1 · pp. 340-341
Concept
Start with the simplest case. You have a message M, represented as an integer, to split between Alice and Bob so that neither alone can reconstruct it.
Give Alice a random integer r and give Bob M − r. To reconstruct, they add their pieces.
There is a technical problem: you cannot choose a random integer uniformly from all integers, because infinitely many equal probabilities cannot sum to 1. So choose n larger than any possible message and work mod n — then each residue has probability 1/n and everything is well defined.
\[ \text{Alice: } r, \qquad \text{Bob: } M - r \pmod n, \qquad r + (M - r) \equiv M \]
Alice's share is uniformly random and independent of M. Bob's is too, because M − r is uniform when r is. Neither share carries any information at all — which is the same reasoning as the one-time pad's, and it is why the security is unconditional.
Figure (svg): Secret splitting among three people: two random values and the remainder, which sum to the secret mod n.
Worked example
The general case is the same idea, repeated.
Choose m − 1 random numbers r₁, …, r_{m−1} mod n
Why: Uniform and independent.
Give r₁ through r_{m−1} to m − 1 of the people
Why: Each of these shares is a uniform random value with no relation to M.
Give M − (r₁ + ⋯ + r_{m−1}) mod n to the remaining person
Why: This is also uniform, because subtracting a uniform value from anything gives a uniform value.
Reconstruction: everyone adds their share mod n
Why: The random terms cancel and M remains.
Verify: any m − 1 of the shares are jointly uniform and independent of M
Why: Whichever share is missing, the remaining ones are consistent with every possible M — for each candidate there is exactly one value the missing share could take. So m−1 participants learn nothing, and they learn nothing even with unlimited computing power.
Figure (svg): Secret splitting among three people: two random values and the remainder, which sum to the secret mod n.
Socratic
Almost every scheme in this book rests on a computational assumption. This one does not.
Discussion prompt
Explain the difference, and identify the only other unconditionally secure construction in the course.
Hint: Ask what an adversary with infinite computing power could do.
Answer:
The missing information does not exist. Given m−1 shares, every possible secret is consistent with exactly one value of the missing share — so the shares literally do not distinguish between secrets. There is nothing to compute.
Compare RSA: given n, the factorisation exists and is determined; it is merely expensive to find. An adversary with unlimited power recovers it immediately. Here she recovers nothing, because there is nothing there.
The other unconditionally secure construction is the one-time pad, Chapter 4 — and the mathematics is the same. A share here is a message masked by a uniform random value, which is exactly a pad.
And the same trade appears. The pad's price was a key as long as the message; secret sharing's price is that every share is as large as the secret, so w participants store w times the data.
Which explains the practical pattern: the secret shared is almost always a key, not the data. Split a 256-bit key among five directors, encrypt the terabyte with it. Chapter 1's hybrid argument, in a third setting.
Section
Section 17.2 · pp. 341-346
Concept
Splitting requires everyone. The book's motivating story: the control of nuclear weapons in Russia was reported to use a mechanism where two out of three important people were needed to launch — and the spy-film image of three key slots requiring two keys turned together is the same idea.
Why not use splitting? Because one of the three officials might be away on a diplomatic mission, or might simply refuse. Requiring all three makes the system fragile in exactly the situation it is meant for.
(t, w) threshold scheme — A method of sharing a message M among w participants such that any subset of t participants can reconstruct M, and no subset of smaller size can reconstruct it. Note that t ≤ w, and t = w is the splitting scheme of the previous section.
Two parameters, two different risks. A small t makes recovery easy and collusion easy. A large t makes the secret hard to misuse and easy to lose. Choosing them is the design decision, and the rest of the chapter is how to implement any choice.
Figure (svg): A degree-two polynomial through three points: any three shares determine it, and two leave infinitely many candidates.
Concept
Invented by Shamir in 1979, and also known as the Lagrange Interpolation scheme. It rests on a fact from school algebra: t points determine a polynomial of degree t−1 uniquely.
\[ s(x) = M + a_1 x + a_2 x^2 + \cdots + a_{t-1}x^{t-1} \pmod p, \qquad M = s(0) \]
Any t participants pool their points and interpolate, recovering s and therefore s(0) = M. Any t−1 have too few points: infinitely many degree t−1 polynomials pass through them, one for every possible constant term.
Figure (svg): A degree-two polynomial through three points: any three shares determine it, and two leave infinitely many candidates.
Worked example
Take t = 3, w = 5, and a prime p — the book uses p = 1234567890133 for a realistic example.
Choose s(x) = M + a₁x + a₂x² mod p, with a₁ and a₂ random
Why: Degree 2, because t − 1 = 2. The secret is the constant term.
Evaluate at x = 1, 2, 3, 4, 5 and give participant i the pair (i, s(i))
Why: The x values are public labels; the y values are the shares. Note x = 0 is never given out, because s(0) is the secret.
To recover, any three participants supply their points
Why: Three points determine a unique degree-2 polynomial.
Interpolate with Lagrange's formula and evaluate at x = 0
Why: In fact you can evaluate at 0 directly without building the polynomial, which is how implementations do it.
\[ M = s(0) = \sum_{i} y_i \prod_{j \ne i} \frac{0 - x_j}{x_i - x_j} \pmod p \]
Verify: all arithmetic is mod p, so the divisions are modular inverses
Why: Which is why p must be prime — Section 3.11's requirement that every non-zero element be invertible. Over the integers the interpolation would produce fractions and the scheme would leak information through their size.
Figure (svg): Lagrange interpolation recovering the secret from three shares by a weighted sum.
Worked example
The security proof is short and worth doing, because it establishes an information-theoretic claim rather than a computational one.
Suppose t−1 participants pool their points
Why: They have t−1 points on a polynomial of degree t−1.
Pick any candidate secret M′ and add the point (0, M′) to their set
Why: Now they have t points.
Those t points determine exactly one polynomial of degree t−1
Why: By the same uniqueness fact the scheme is built on.
So for every candidate M′ there is exactly one polynomial consistent with their shares
Why: A bijection between candidate secrets and consistent polynomials.
Verify: every possible secret is therefore equally likely
Why: Their shares distinguish between no two candidates, so they have gained no information — not merely insufficient information. This holds against unlimited computing power, and it is why the book's schemes stand beside the one-time pad rather than beside RSA.
Figure (svg): With t−1 shares, every possible secret remains equally likely: for each candidate there is exactly one polynomial through the shares.
Concept
The book gives a second construction, due to Blakley and also from 1979, using geometry instead of algebra.
The secret is a point in t-dimensional space. Each share is a hyperplane passing through that point — a plane in three dimensions, a line in two.
Any t hyperplanes in general position intersect in exactly one point, which is the secret. Fewer than t intersect in a line, a plane, or a larger set — every point of which is an equally possible secret.
The picture is immediate in two dimensions: two lines cross at a point, and a single line leaves every point on it possible. That is a (2, w) scheme.
It is less efficient than Shamir's. A hyperplane in t dimensions takes t coordinates to describe, so each share is t times the size of the secret, where Shamir's shares are the same size as the secret. Shamir's scheme is what is used in practice, and Blakley's is valuable mainly for making the idea visual.
Figure (svg): Blakley's scheme: each share is a hyperplane, and the secret is the point where t of them intersect.
Comparison
Both are (t, w) threshold schemes from 1979. Fill the blanks.
Comparison matrix
| Shamir | Blakley | |
|---|---|---|
| Underlying object | a polynomial of degree t−1 | a point where t hyperplanes intersect |
| A share is | one point on the curve | one hyperplane |
| Share size | the same size as the secret | t times the size of the secret |
| Recovery | Lagrange interpolation | solve a linear system |
| Security | unconditional | unconditional |
Both are unconditionally secure; only the share size differs, and that is why Shamir's is the one deployed.
Picture it
A degree t−1 polynomial, with the secret at x = 0 and the shares at x = 1, 2, 3, … The whole scheme is visible in one picture.
Figure (svg): A degree-two polynomial through three points: any three shares determine it, and two leave infinitely many candidates.
Any three of those marked points determine the curve, and therefore its value at zero. Any two determine nothing at all — a fact that is much easier to see once the picture is in mind.
Concept
The recovery step deserves its own treatment, because it is the only piece of machinery the scheme needs and it is entirely elementary.
Given t points (x₁, y₁) … (x_t, y_t) with distinct x values, there is exactly one polynomial of degree at most t−1 passing through them, and Lagrange's formula writes it down directly.
\[ s(x) = \sum_{i=1}^{t} y_i \, L_i(x), \qquad L_i(x) = \prod_{j \ne i} \frac{x - x_j}{x_i - x_j} \]
Each basis polynomial L_i is designed to equal 1 at x_i and 0 at every other x_j — so the sum takes the value y_i at x_i, which is exactly what interpolation means.
And we only ever need s(0). Substituting x = 0 turns each L_i into a constant, so the secret is a weighted sum of the shares with publicly computable weights. No polynomial is ever constructed in an implementation.
Figure (svg): Lagrange interpolation recovering the secret from three shares by a weighted sum.
Worked example
A (3, 5) example worked mod p = 17, small enough that every step can be checked. The dealer used s(x) = 5 + 2x + x², so the secret is 5 and the shares are (1, 8), (2, 13), (3, 3).
L₁(0) = ((0−2)/(1−2)) · ((0−3)/(1−3)) = (−2/−1) · (−3/−2) = 2 · (3/2)
Why: The fractions are modular: 3/2 means 3 · 2⁻¹ mod 17, and 2⁻¹ = 9 because 2 · 9 = 18 ≡ 1.
So L₁(0) = 2 · 3 · 9 = 54 ≡ 3 (mod 17)
Why: One weight, computed from the public labels alone — no share value has been used yet.
L₂(0) = (−1/1) · (−3/−1) = (−1) · 3 = −3 ≡ 14, and L₃(0) = (−1/2) · (−2/1) = (−9) · (−2) = 18 ≡ 1
Why: Each weight depends only on which participants turned up.
Sanity check: the weights must sum to 1, since interpolating the constant polynomial 1 must give 1. 3 + 14 + 1 = 18 ≡ 1 ✓
Why: A free check on the arithmetic before any secret is touched, and worth doing every time.
\[ M = 8 \cdot 3 + 13 \cdot 14 + 3 \cdot 1 = 24 + 182 + 3 = 209 \equiv 5 \pmod{17} \]
Verify: 209 = 12 · 17 + 5, and the dealer's secret was 5
Why: Recovered exactly. Note that the recovery never reconstructed the polynomial — it computed three public weights and took a weighted sum of the shares, which is how implementations do it.
Figure (svg): Lagrange interpolation recovering the secret from three shares by a weighted sum.
Prediction
Three participants compute Lagrange weights 5, 9 and 4 mod 17, before combining any shares.
Predict first
What does this tell you?
Correct: The weights are consistent, since 5 + 9 + 4 = 18 ≡ 1 (mod 17)
Note that the weights say nothing about the secret: they are computed from public labels alone, so they can be worked out before any share is revealed.
Which has a practical use — the weights for each possible quorum can be precomputed and published, so a recovery ceremony involves no arithmetic under pressure.
Why: The weights are the Lagrange basis polynomials evaluated at zero, and interpolating the constant polynomial 1 through the same points must return 1 — so the weights always sum to 1 modulo p. Here they do, so the arithmetic is consistent. It is a free check costing one addition, and it catches sign errors, wrong modular inverses and mistyped labels, which are the three commonest slips.
Socratic
The Lagrange weights at x = 0 always sum to 1 mod p, whatever the labels.
Discussion prompt
Prove it in one line, and say why the fact is useful.
Hint: Interpolate a polynomial you already know.
Answer:
Interpolate the constant polynomial s(x) = 1. Every share value is then 1, so the weighted sum is exactly the sum of the weights.
But interpolation of a degree-0 polynomial through t points returns that polynomial, so evaluating at 0 gives 1. Hence the weights sum to 1.
Why it is useful: it is a free consistency check. Compute the weights, add them, and confirm the total is 1 before combining any shares. This catches sign errors, wrong modular inverses and mistyped labels — the three commonest slips — at the cost of one addition.
And it has a design consequence too. Because the weights are determined entirely by which participants show up, they can be precomputed and published for each possible quorum, so a recovery ceremony needs no arithmetic under pressure.
It is also a small illustration of a useful habit: test a construction on an input whose answer you already know. Here the constant polynomial gives an identity for free.
Fill the middle
Complete the formula for the weight attached to participant i's share.
Fill in the blanks
L_i(0) = \prod_−x_j \fracx_i − x_j}___} \pmod p
Why: Substituting x = 0 into the basis polynomial gives a product of ratios of public labels — so the weights can be computed by anyone, before any share is revealed. That is a practically useful property: a recovery protocol can compute its weights first and then collect shares, and the weights themselves leak nothing.
Definition probe
Getting this right is what makes an implementation safe.
Sort into buckets
Sort each quantity in a Shamir deployment.
Estimation
The prime p must exceed both the secret and the number of participants.
Predict first
With a 256-bit secret, what practical limit does p place on w?
Correct: Effectively none
Which is worth knowing because the condition looks like a constraint and is not. Implementations pick p as a standard prime just above the secret's size — often 2²⁵⁷ − 93 or a similar value — and never think about w again.
The real practical limits on w are operational: how many people can be trusted to keep a share safe and be available when needed.
Why: p must exceed 2²⁵⁶ to hold the secret, which leaves room for astronomically more distinct non-zero labels than any deployment could use. The w < p condition binds only in toy examples with tiny primes — with a realistic secret, the modulus is set by the secret's size and the participant count never comes close.
Anomaly
An implementation stores 128-bit shares for a 256-bit secret, to halve the storage.
Predict first
What has gone wrong?
Correct: The scheme cannot be information-theoretically secure, because there are not enough share values to be consistent with every secret
The general rule that follows: in any information-theoretically secure scheme, each share is at least as large as the secret. Any implementation offering smaller shares has either given up the unconditional guarantee or made an error.
Computationally secure schemes can do better — Krawczyk's secret sharing encrypts the data with a random key, shares the key with Shamir, and erasure-codes the ciphertext, giving shares of size |secret|/t. It is a genuinely useful construction and it is not unconditional.
Why: The security proof requires that, for every candidate secret, there is exactly one value the missing share could take. With shares half the size of the secret there are only 2¹²⁸ possible share values against 2²⁵⁶ candidate secrets, so most secrets have no consistent completion — and the shares therefore rule some out. This is Proposition 4.4's counting argument again: unconditional security requires the key space to be at least as large as the message space.
Two truths and a lie
Two of these overstate the guarantee.
Eliminate the wrong options
Which statement is correct?
Survives elimination: a
Why: The guarantee is precisely stated and precisely bounded: below the threshold, nothing at all, unconditionally. At or above the threshold, everything. And nothing whatever about honesty — a wrong share corrupts the result invisibly, which is why every serious deployment uses a verifiable variant.
Discrimination
Several schemes that distribute a secret. Only some are secret sharing.
Sort into buckets
Sort each one.
Cost model
Unconditional security has a price, and it is the same price as the one-time pad's.
Annotate
On: \( \text{total storage} = w \times |M|, \qquad \text{recovery} = O(t^2) \text{ field operations} \)
The same trade as every unconditional construction in this book: perfect security, paid for in space.
Socratic
After distributing shares, the dealer holds the polynomial's random coefficients a₁ … a_{t−1}.
Discussion prompt
What can someone holding them do, and what practice does this suggest?
Hint: Count how many unknowns remain once the coefficients are known.
Answer:
Anyone holding the coefficients plus a single share recovers the secret. With a₁ and a₂ known, one point y_i = M + a₁x_i + a₂x_i² has one unknown, and M falls out in one subtraction.
**Worse, the coefficients alone plus knowledge of any one share value is enough** — so a compromised dealer's notes turn a (3, 5) scheme into a (1, 5) scheme.
So the dealer must destroy them, and ideally must not have been able to record them: a hardware module that generates, distributes and forgets is the right shape.
This is exactly Chapter 16's discipline. Brands' scheme discards its setup exponents because storing them serves no purpose and their discovery compromises everything. Same reasoning, different scheme.
And it generalises into a design principle: any value that is needed once and never again should be destroyed rather than stored, and a construction that can be arranged so the value never exists in one place is better still. Trusted setup ceremonies and threshold key generation both take this to its conclusion.
Real world
The DNSSEC root key and commercial root CA keys are protected by threshold schemes, in ceremonies with published procedures.
Discussion prompt
Describe what such a ceremony involves, and which parts are cryptography.
Hint: Most of it is not cryptography, which is the point.
Answer:
Physical controls first: a shielded room, tamper-evident bags, safes with separate combinations, and participants from several organisations and jurisdictions who do not report to one another.
Key generation inside a hardware security module, so the private key never exists in software and cannot be copied out.
Shares distributed on physical tokens or smart cards, held by named officers who take them away to separate locations.
The whole thing filmed, witnessed and audited, with a published script followed step by step and any deviation recorded.
And rehearsed, because the procedure must work years later with different people, from documentation alone.
Which parts are cryptography? The threshold scheme and the HSM's key generation. Everything else — the room, the witnesses, the script, the jurisdictions — is process, and it is the majority of the effort because it is where the realistic failures are.
This is the clearest example in the book of cryptography being the easy part.
Figure (svg): Where threshold schemes are used: key custody, root CA keys, and cryptocurrency wallets.
Error analysis
From a company's key management policy.
Annotate
The third point is the one that voids the scheme entirely, and it is the kind of thing added for convenience by someone who did not know what the coefficients were.
Ranking
Five deviations from correct practice.
Put in order
Why: Publishing labels is harmless — they are public by design. A tight prime is fine provided it exceeds the secret. One exposed share still leaves the attacker needing two more. Coefficient reuse leaks the difference of two secrets to any single holder. And keeping the coefficients reduces the threshold to one, which destroys the scheme outright. The ordering runs from 'no effect' to 'total compromise', and only the last two involve the mathematics at all.
Explain it to yourself
Shamir's scheme puts the secret at s(0) and hands out s(1), s(2), and so on.
Discussion prompt
Is x = 0 special, and what would change if the secret were at s(7) instead?
Hint: Ask what makes a point usable as a share.
Answer:
Nothing is mathematically special about 0. The scheme would work identically with the secret at s(7), provided no participant is given the label 7 — the requirement is only that the secret's point is not handed out.
Zero is chosen for convenience. It makes the secret the polynomial's constant term, which is the easiest coefficient to set, and it makes the Lagrange weights slightly simpler to compute.
And it makes the label rule easy to state: participants get non-zero labels, which is a check an implementation can enforce trivially.
What would genuinely break the scheme is giving some participant the label where the secret lives — that person would simply hold the secret. Which sounds obvious and is exactly the kind of off-by-one an implementation can make when labels are assigned from a list that starts at zero.
The general observation: many choices in a cryptographic construction are conventions rather than requirements, and knowing which is which is what lets you read a specification correctly. Here, 'the secret is the constant term' is a convention and 'no participant holds that point' is a requirement.
Matching
Four requirements on the prime and the labels, each for a different reason.
Match the pairs
Why: Four conditions, four distinct reasons, and only the first is cryptographic in flavour — it is Section 3.11's field requirement. The others are bookkeeping, and violating any of them produces a scheme that appears to work in testing and fails in a specific case: a large secret, a large participant count, or a badly assigned label.
Edge cases
A (1, 5) scheme means any one participant can recover the secret.
Discussion prompt
Is that a valid threshold scheme, and what does it degenerate into?
Hint: Work out what a degree-0 polynomial looks like.
Answer:
It is valid and it is useless as a secret. With t = 1 the polynomial has degree 0, so it is the constant M — and every share is just M itself.
Which means it degenerates into replication: five copies of the secret, one per participant. The scheme provides availability and no confidentiality against any participant.
And that is sometimes the right answer, when the requirement is 'do not lose this' rather than 'do not let one person use it'. Recognising it saves building machinery for a problem that is not there.
At the other end, t = w is splitting, with maximum collusion resistance and zero tolerance for loss.
So the parameter t interpolates between two familiar things — replication at one end and unanimity at the other — and every intermediate value is a stated position on the two risks. Naming the endpoints makes the choice in the middle easier to justify.
Commit first
A (3, 5) scheme has protected a company's master key for six years.
Predict first
What do you expect has already gone wrong?
Correct: At least one share is unusable — a departed holder, a corrupted medium, or a forgotten passphrase
The mitigation is annual rehearsal plus verifiable sharing, so each holder can confirm their share is consistent without assembling anything.
It is worth noting how different this is from the rest of the course: the adversary is not the problem here. Entropy is.
Why: Six years is long enough for staff turnover, media degradation and forgotten procedures, and none of these announces itself — a share only proves unusable when recovery is attempted. Since three of five are needed, two silent failures still leave the scheme working and a third makes the key unrecoverable, with no warning at any point.
Faded example
Four blanks, and the proof is on the page.
Fill in the blanks
Suppose t − 1 participants pool their shares. For any candidate secret M′, adding the point (0, M′) gives t points, which determine exactly one polynomial of degree t−1. So there is a bijection between candidate secrets and consistent polynomials, and every secret is equally likely.
Why: The whole proof is the bijection: one polynomial per candidate secret means the shares distinguish between none of them. Note what is not in the argument — no computational assumption, no hardness, no bound on the adversary's resources. That absence is what makes the guarantee unconditional, and it is the same absence that makes the one-time pad's proof work.
Notation
One formula recovers the secret, and each part of it has a job.
Annotate
On: \( M = \sum_{i=1}^{t} y_i \prod_{j \ne i} \frac{0 - x_j}{x_i - x_j} \pmod p \)
Note that the x-labels are public and only the y-values are secret — which means a participant's index can be assigned openly and need not be protected.
Definition probe
Three parameters, and the requirement decides them.
Sort into buckets
Sort each requirement by the scheme it calls for.
Explain it to yourself
Shamir's scheme works mod p, and the book requires p to be prime and larger than both the secret and w.
Discussion prompt
Explain each of the three requirements.
Hint: Interpolation involves division, and the labels must be distinct.
Answer:
Prime, because interpolation divides. The Lagrange coefficients contain (x_i − x_j)⁻¹, and Section 3.11 says every non-zero element is invertible exactly when the modulus is prime. Mod a composite, some differences would have no inverse and recovery would sometimes fail.
Larger than the secret, or the secret would wrap around and the value recovered would be M mod p rather than M. The same requirement as the splitting scheme's n.
Larger than w, so that w distinct non-zero labels x₁, …, x_w exist. Two participants sharing a label would give the same equation twice, so t of them would not determine the polynomial.
And a fourth, implicit requirement: the coefficients a₁, …, a_{t−1} must be uniformly random. If they were predictable, the polynomial could be guessed from fewer points and the security proof — which assumes every candidate secret is equally likely — would not hold.
Chapter 5's rule, appearing in yet another place: the construction is only as good as the randomness feeding it.
Counterexample
An administrator shares two different secrets among the same five people, using the same polynomial coefficients a₁ and a₂ and only changing the constant term.
Discussion prompt
Show that any single participant can now recover both secrets.
Hint: Compare the two shares one participant holds.
Answer:
Participant i holds y_i = M₁ + a₁x_i + a₂x_i² and y′_i = M₂ + a₁x_i + a₂x_i².
Subtracting gives y_i − y′_i = M₁ − M₂, so one participant immediately learns the difference of the two secrets — which for many applications is already fatal.
And if either secret is ever revealed or guessed, the other follows at once, from one share.
With two participants it is worse: two pairs give two equations in a₁ and a₂ after the difference has cancelled M, so the coefficients fall out and then both secrets do.
The rule is that every sharing must use fresh random coefficients. This is the fourth appearance of the same failure — the two-time pad in Chapter 4, keystream reuse in Chapter 5, a repeated signature nonce in Chapter 13, and now polynomial reuse.
The pattern is exact: a scheme masking a secret with random values collapses when the random values are reused, and it collapses to a linear relation between the secrets.
Real world
Secret sharing is one of the few constructions in this book deployed almost exactly as described.
Discussion prompt
Name three real deployments and the reason each chose a threshold rather than a single key.
Hint: Certificate authorities, cryptocurrency custody, and the internet's root of trust.
Answer:
Root CA key ceremonies. A certificate authority's root private key is generated in a filmed ceremony and split among officers, with shares stored in separate safes in separate buildings. No individual can sign, and no individual's absence blocks a signing.
DNSSEC root key signing. The root zone's key is protected by a ceremony with holders of physical share cards from several countries, requiring a quorum to attend. It is a (t, w) scheme with people flying to it.
Cryptocurrency custody. Multi-signature wallets require k of n keys to authorise a transfer — technically threshold signatures rather than sharing a secret, but the same requirement and often the same mathematics.
And disaster recovery generally: an organisation's master encryption key split among directors, so that the departure or death of any one is survivable and no single person can act alone.
The common shape is two simultaneous distrusts: distrust of any individual acting, and distrust that everyone will be available. A single key fails the first and unanimity fails the second.
Figure (svg): Where threshold schemes are used: key custody, root CA keys, and cryptocurrency wallets.
Estimation
A (3, 5) Shamir scheme protects a 256-bit key.
Predict first
How large is each share?
Correct: About 256 bits
The parallel with the one-time pad is exact. There, unconditional security cost a key as long as the message; here it costs w copies' worth of storage. Both follow from the same counting argument — Proposition 4.4's requirement that the key space be at least as large as the message space.
It is also why the shared secret is nearly always a key rather than the data itself: 256 bits × 5 participants is trivial, and a terabyte × 5 is not.
Why: Each share is a point (x_i, y_i) where y_i is an element mod p, and p must exceed the secret — so each share is about the size of the secret itself, roughly 256 bits plus a small index. Shares do not shrink with t: the total storage across w participants is w times the secret, which is the price of the unconditional guarantee.
Trade off
Two parameters, two opposing risks. Fill the blanks.
Comparison matrix
| t small | t large | |
|---|---|---|
| Risk of collusion | high — few people can act together | low — many must agree |
| Risk of loss | low — many participants may be unavailable | high — few absences block recovery |
| t = 1 | no secret at all — everyone can act | — |
| t = w | — | any single loss is permanent |
| Choose by | how many people you distrust | how many you expect to be unavailable |
The two rows pull in opposite directions, so there is no universally right answer — only a statement of how much of each risk is acceptable.
Socratic
The scheme is unconditionally secure and reconstructs perfectly. It also has clear limits.
Discussion prompt
Name three things it does not do, and say what would be needed for each.
Hint: Consider a dishonest dealer, a dishonest participant, and what happens after reconstruction.
Answer:
It does not detect a cheating dealer. The person who creates the shares could hand out inconsistent ones, so that different subsets reconstruct different secrets — and nobody would know until reconstruction. Verifiable secret sharing adds commitments to each coefficient so participants can check their share is consistent.
It does not detect a cheating participant. Someone who supplies a wrong share at reconstruction corrupts the result silently, and the honest participants recover a wrong secret with no indication. The same commitments fix this.
It does not survive reconstruction. Once t shares are combined, whoever did the combining holds the secret in full — so the protection ends exactly at the moment of use. Threshold cryptography avoids this by having participants compute with their shares without ever assembling the secret.
And it does not handle changing membership. Adding a participant or changing t requires re-sharing, which needs the secret — so the dealer must be involved again, or a proactive re-sharing protocol used.
The general point, which is Chapter 15's: a primitive provides exactly one property. Everything else is a construction on top, and each construction has its own name and its own paper.
Faded example
Four blanks and the whole construction is on the page.
Fill in the blanks
Choose a prime p larger than the secret. Build a polynomial of degree t − 1 whose constant term is the secret and whose other coefficients are random. Give participant i the value of the polynomial at x_i. Any t participants recover the secret by interpolating and evaluating at 0.
Why: The degree is t−1 because that is what t points determine uniquely — one less than the threshold, which is the single fact to remember. The coefficients must be uniformly random or the security proof fails, and the labels must be non-zero because zero is where the secret lives.
Elimination
Four modifications to a working (3, 5) Shamir deployment.
Eliminate the wrong options
Which one destroys the security?
Survives elimination: c
Why: Deriving the coefficients from the secret means the polynomial is determined entirely by the secret, so a single share plus knowledge of the rule reduces recovery to guessing the secret and checking. The security proof requires that for every candidate secret there is a consistent polynomial, and a deterministic rule leaves exactly one polynomial per secret — which is fine — but makes each share a checkable function of the secret, which turns an unconditional guarantee into a search.
Matching
Shamir's scheme is the base; several named extensions address its limits.
Match the pairs
Why: Each extension answers a limitation of the base scheme: no cheating detection, no protection against slow accumulation of shares over years, no way to use the secret without exposing it, and no way to express unequal authority. Weighted sharing is the simplest — give a director three of the five shares — and threshold signatures the most valuable, because they remove the moment of exposure entirely.
Constraint
A company's master encryption key protects ten years of archives. There are seven executives; two typically travel; the board wants no individual able to decrypt and no plausible scenario in which the archive is lost.
Discussion prompt
Choose t and w, and specify the surrounding process.
Hint: Two constraints bound t from opposite sides.
Answer:
Lower bound on t: no individual, and preferably no pair, should be able to act — so t ≥ 3.
Upper bound on t: two are typically travelling and one might leave or be unreachable, so recovery must work with four available. That gives t ≤ 4.
Choose t = 3, w = 7. Three of seven: collusion needs three executives, and recovery survives four being unavailable simultaneously. The margin on both sides is deliberate.
Use verifiable secret sharing, so each holder can check their share is consistent — otherwise a dishonest dealer or a corrupted store is undetectable until the day the archive is needed.
Rehearse the recovery annually. An untested recovery procedure is not a recovery procedure, and a share that has silently corrupted is indistinguishable from a working one until used.
And re-share when membership changes, rather than reassigning an existing share — a departing executive's share must stop being useful, which requires new coefficients rather than a new holder.
Note that four of the six decisions are operational. The cryptography here is genuinely easy; the process around it is what fails.
Ranking
Five things that can go wrong with a deployed (3, 5) scheme.
Put in order
Why: Losing one share leaves four, which still exceeds the threshold — no harm. Two stolen shares reveal nothing, by the security proof. Inconsistent shares mean recovery fails or produces a wrong secret, discovered only when needed — bad, and detectable in advance with verifiable sharing. Polynomial reuse leaks the difference of the two secrets to any single holder. And three stolen shares is a complete compromise. The ordering is by how much of the guarantee survives.
Commit first
A (3, 5) Shamir scheme, correctly implemented, shares stored in five safes.
Predict first
What is most likely to go wrong over ten years?
Correct: Operational failure — a lost share, a corrupted medium, an untested recovery, or nobody remembering the procedure
This is unusual for this course and worth noticing: for once the cryptography is genuinely not the weak point, because there is no computational assumption to age.
Which shifts the entire review to process: annual rehearsal, share verification, documented custody, and a re-sharing trigger on personnel change.
Why: The construction is unconditionally secure, so there is nothing for an attacker to solve. Over ten years the realistic failures are all operational: media degrading, people leaving without their share being reissued, the recovery procedure never being rehearsed, and the documentation being encrypted with the key it protects. That last one is a real and recurring failure.
Missing information
A control document states that the master key is split among five executives.
Discussion prompt
List what a reviewer still cannot determine.
Hint: Two parameters, one construction, and several process questions.
Answer:
How many are needed to recover it? 'Split' could mean all five, which is fragile, or a threshold, which is not. The document names w and omits t.
Is it a real sharing scheme, or a divided key? Giving each person a fifth of the bits is not secret sharing — four people would then face only a 2⁵¹ search on a 256-bit key rather than 2²⁵⁶.
Can shares be verified? Without verifiable sharing, a corrupted or malicious share is undetectable until recovery is attempted.
Has recovery been tested? An untested procedure is a hope.
What happens when someone leaves? A departing executive's share must become useless, which needs re-sharing rather than collection.
And where is the recovery documentation? If it is in the archive the key protects, the scheme has a circular dependency that only surfaces in a real incident.
The second question is the one that most often reveals a real problem: dividing a key is not sharing it, and the two are described identically in plain English.
Explain it
A colleague is sceptical: surely two of three shares must narrow down the secret somewhat.
Discussion prompt
Convince them, using the smallest possible example.
Hint: Work in a tiny modulus where every case can be listed.
Answer:
Use the two-person splitting case first, because it is the clearest. Alice has a random r and Bob has M − r, mod n. Alice's share is uniform and independent of M: whatever M is, r was equally likely to be any value.
Then the key move: for any candidate secret M′, there is exactly one value Bob's share would need to take. So Alice's share is consistent with every possible secret, and equally so.
Extend to the polynomial case. Two points and a candidate secret give three points, which determine exactly one degree-2 polynomial. One polynomial per candidate, so all candidates remain equally likely.
The intuition to leave them with: the shares are not pieces of the secret, they are constraints on it — and t−1 constraints on a t-dimensional space leave a whole line of possibilities, every point of which is a valid secret.
And the contrast that makes it stick: if you cut a written password into three strips, two strips do narrow it down. Secret sharing is not cutting; it is masking, and that is exactly why it gives an unconditional guarantee where cutting gives none.
Edge cases
The scheme guarantees that t−1 learn nothing. It says nothing about what t can do.
Discussion prompt
What can a coalition of exactly t dishonest participants achieve, and what would limit them?
Hint: They can do everything an honest quorum can do.
Answer:
They recover the secret, completely. That is not a flaw; it is the specification. A (t, w) scheme grants exactly the authority of t participants to any t participants, honest or not.
They can also do it silently. Nothing in the scheme records that a reconstruction happened, so a coalition can recover a key and use it with no trace.
Limiting them means changing t or changing the model. Raising t raises the collusion bar and lowers availability — the trade from the earlier slide, with no way around it.
Or use threshold cryptography instead, where participants compute a signature or a decryption jointly without assembling the key. Then a coalition can use the key for one operation but never holds it, so misuse is bounded and, if the protocol logs participation, visible.
Or add a second factor entirely: a hardware module that requires physical presence, or an auditable log of every reconstruction. Both are outside the cryptography.
The honest summary: secret sharing distributes trust; it does not create accountability. Those are different properties, and conflating them is how custody schemes end up with no audit trail.
Pattern
Seventeen chapters in, and this is only the second construction with an unconditional guarantee. The reasons are worth collecting.
The practical consequence: share a key, not the data, and generate fresh coefficients every time. Then the guarantee is real and permanent, which almost nothing else in this book can say.
Figure (svg): With t−1 shares, every possible secret remains equally likely: for each candidate there is exactly one polynomial through the shares.
Trap
The trap. A 256-bit key is split into five 51-bit chunks, one per executive. No single person has the key, and all five together reconstruct it by concatenation. This achieves the same thing as Shamir's scheme with far less mathematics.
It is the obvious implementation, and it appears in real control documents.
Why it fails. Each chunk is part of the key, so four executives hold 205 of the 256 bits and face a search of 2⁵¹ — about two quadrillion, which is hours on modest hardware. Four people who should have no capability whatever can recover the key.
Even one chunk is damaging. A single executive removes 51 bits from an attacker's search, so a 256-bit key becomes a 205-bit key for anyone who compromises one person. The guarantee degrades smoothly, which is precisely what a threshold scheme is defined not to do.
And there is no threshold at all. Concatenation requires every chunk, so it is t = w with none of the availability tolerance — the worst of both designs.
In a real sharing scheme each share is uniformly random and independent of the secret. Four of five Shamir shares leave a 256-bit key with all 256 bits of uncertainty, because the shares constrain the polynomial rather than containing the key.
The distinguishing question: is a share the same size as the secret and statistically independent of it? If a share is smaller than the secret, it is a piece and not a share — and the scheme is not what it claims.
Check
Work it out before you click.
Check your understanding
For a (4, 9) Shamir threshold scheme, what degree polynomial is used?
Answer: B
Why: Degree t − 1 = 3, because four points determine a cubic uniquely and three leave one degree of freedom — exactly one candidate polynomial for each possible secret. The threshold is the number of points needed; the degree is one less.
Check
Apply the security argument.
Check your understanding
In a (3, 5) scheme, two participants pool their shares. What do they learn about the secret?
Answer: C
Why: For every candidate secret M′, adding the point (0, M′) to their two points gives three points determining exactly one quadratic. So there is a one-to-one correspondence between candidate secrets and consistent polynomials, and the shares distinguish between none of them. The guarantee is information-theoretic and holds against unlimited computing power.
Check
Consider what one participant can compute.
Check your understanding
Two secrets are shared using the same random coefficients, changing only the constant term. What does a single participant learn?
Answer: B
Why: Participant i holds M₁ + a₁x_i + a₂x_i² and M₂ + a₁x_i + a₂x_i². Subtracting cancels every term involving the coefficients and leaves M₁ − M₂. This is the fourth appearance of the reuse failure in the course — after the two-time pad, keystream reuse and the repeated signature nonce — and it has the same shape every time.
Connect it up
The chapter is short and unusually self-contained.
Draw it
Write the splitting scheme for m people in two lines. Then write Shamir's scheme in four: the prime, the polynomial and its degree, the shares, and the recovery. Draw the security argument as a bijection between candidate secrets and consistent polynomials. Note the two parameters and the opposing risks they trade. Finish with the reuse failure and the three earlier chapters where the same failure appeared.
That last line is the most transferable thing here: masking with random values is a recurring pattern, and reusing the mask breaks it every time, in exactly the same way.
Exit ticket
One question, about what makes this chapter different from the sixteen before it.
Predict first
Why is Shamir's scheme unconditionally secure, where RSA is not?
Correct: Because with t−1 shares every candidate secret is consistent with exactly one polynomial, so the information is absent rather than merely expensive to compute
Why: RSA's factorisation exists and is determined by n; it is only expensive to find, so unlimited computing power recovers it. Here the shares are consistent with every possible secret in exactly one way each, so there is nothing to find — an adversary with infinite power learns nothing. This is the same kind of guarantee as the one-time pad's, and it comes at the same kind of price: storage proportional to the secret, per participant.
Recap
A short chapter with a rare guarantee.
Chapter 18 next. Games — flipping a coin over the telephone and playing poker with no trusted dealer. Both use the square roots mod n of Section 3.9, and both are protocols between parties who actively expect each other to cheat.
Figure (svg): With t−1 shares, every possible secret remains equally likely: for each candidate there is exactly one polynomial through the shares.
Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.