Let
An
sharing a message
such that any subset of
can reconstruct
but no subset of smaller size can.
Shamir’s method
Let
by the Leader.
The Leader chooses a prime
The Leader chooses independent random coefficients
and distinct integers
Define:
The
Now suppose
They have the data
where
and can solve:
because the Vandermonde matrix has nonzero determinant
Then
However, if only
Which can be solved for any
so we have no idea which one is correct.