An threshold secret-sharing scheme issues shares: every collection of at least shares reconstructs the secret, while every collection of fewer than shares has a distribution independent of the secret.
Shamir's secret sharing places a secret at the constant term of a random polynomial of degree at most and issues distinct nonzero evaluation pairs . Any shares recover by polynomial interpolation. Given fewer than shares, every candidate constant term has the same number of compatible coefficient tuples, which gives perfect secrecy.
Conditioned on any shares in Shamir's secret sharing, each candidate secret in remains equally likely. Appending to those shares determines exactly one degree-at-most- polynomial for every candidate , by the nonzero Vandermonde determinant.

Articles by others on the same topic (0)

There are currently no matching articles.