Distribute a secret across n guardians so that any t+1 can reconstruct it — while t or fewer learn nothing at all. Three implementations ranging from the classic Shamir construction to verifiable Feldman commitments and a traceable variant that can identify which guardians leaked.
The foundational threshold scheme. A random degree-t polynomial encodes the secret at f(0); each guardian receives one evaluation point. Reconstruction is Lagrange interpolation — no group operations, no hardness assumptions.
Extends Shamir with public polynomial commitments Cj = aj·G. Each guardian independently verifies their share with a group check — no trust in the dealer, no interaction, and one multi-scalar multiplication per share.
Random evaluation points make the scheme traceable. If up to f < t guardians leak their shares, the dealer — with only black-box oracle access — can identify exactly who leaked via Guruswami-Sudan list decoding.