BUSS · All Schemes

Scheme Comparison

BUSS and Traceable BUSS side-by-side — security model, public data overhead, and traceability guarantees.

Scheme Comparison

PropertyBUSS (ANARKey §5.1)Traceable BUSS (§4.1)
Evaluation points Integer indices j = 1, …, n−1 Random xⱼ ←$ 𝔽*
Guardian share derivation σⱼ = H(owner_id ‖ skⱼ) Same + random xⱼ
Guardian storage None — σⱼ always rederivable None — xⱼ and σⱼ rederivable
Public φ entries y-values only — n−t−1 scalars Full (x, y) pairs — n−t−1 pairs
Trace / verification key None tk = vk = (H(x₁), …, H(xₙ₋₁))
Identify leakers No Yes — up to f ≤ t, from an imperfect reconstruction box
Non-imputability No — tracer can frame innocent guardian Yes — hash binding prevents false accusations
Tracing cost — N synthetic reconstruction queries + Guruswami-Sudan list decoding
Verification cost — O(f) hash evaluations
Info-theoretic security Yes Yes
Adaptive corruption ≤ t parties ≤ t parties
Suitable for community SKR Yes Yes, with accountability
Choosing a scheme: use BUSS when you need stateless guardian recovery and your threat model assumes honest participants — or when the ability to trace leakers is not required. Use Traceable BUSS when accountability matters: you want to be able to identify and prove which guardian leaked, and you want to guarantee that honest guardians cannot be falsely accused, even by the tracer.
vs. classic SSS: both BUSS and Traceable BUSS differ fundamentally from Shamir and Feldman in that guardians choose their own shares — the owner never creates or stores them. This makes guardian loss a non-issue: a guardian who forgets everything can still contribute to recovery using only their existing secret key.