BUSS and Traceable BUSS side-by-side — security model, public data overhead, and traceability guarantees.
| Property | BUSS (ANARKey §5.1) | Traceable BUSS (§4.1) |
|---|---|---|
| Evaluation points | Integer indices j = 1, …, n−1 | Random xⱼ ←$ 𝔽* |
| Guardian share derivation | σⱼ = H(owner_id ‖ skⱼ) | Same + random xⱼ |
| Guardian storage | None — σⱼ always rederivable | None — xⱼ and σⱼ rederivable |
| Public φ entries | y-values only — n−t−1 scalars | Full (x, y) pairs — n−t−1 pairs |
| Trace / verification key | None | tk = vk = (H(x₁), …, H(xₙ₋₁)) |
| Identify leakers | No | Yes — up to f ≤ t, from an imperfect reconstruction box |
| Non-imputability | No — tracer can frame innocent guardian | Yes — hash binding prevents false accusations |
| Tracing cost | — | N synthetic reconstruction queries + Guruswami-Sudan list decoding |
| Verification cost | — | O(f) hash evaluations |
| Info-theoretic security | Yes | Yes |
| Adaptive corruption | ≤ t parties | ≤ t parties |
| Suitable for community SKR | Yes | Yes, with accountability |