A secret-sharing scheme distributes shares of a secret so that authorized collections can reconstruct it while unauthorized collections reveal no information about it.
An threshold secret-sharing scheme issues shares: every collection of at least shares reconstructs the secret, while every collection of fewer than shares has a distribution independent of the secret.
Shamir's secret sharing places a secret at the constant term of a random polynomial of degree at most and issues distinct nonzero evaluation pairs . Any shares recover by polynomial interpolation. Given fewer than shares, every candidate constant term has the same number of compatible coefficient tuples, which gives perfect secrecy.
Conditioned on any shares in Shamir's secret sharing, each candidate secret in remains equally likely. Appending to those shares determines exactly one degree-at-most- polynomial for every candidate , by the nonzero Vandermonde determinant.
Articles by others on the same topic
Secret sharing is a method in cryptography and information security that allows a secret (such as a cryptographic key, password, or other sensitive information) to be divided into several parts, called "shares." Each share is distributed to different participants, ensuring that no single participant has access to the entire secret. The secret can only be reconstructed when a sufficient number of participants combine their shares.