Polynomial

Random degree-(t-1) polynomial f with f(0) = S. Share i = f(i). t points determine polynomial via Lagrange interpolation.

Advertisement

Reconstruction

Given t shares, compute f(0) via Lagrange. O(t²) or O(t log² t) with FFT-based interpolation.

Advertisement

Verifiable SSS

Add commitments so shareholders detect malicious dealer. Feldman VSS + Pedersen VSS.

Applications

Multi-signature wallets. HSM key backup. Threshold decryption. Distributed key generation.