SSS · All Schemes

Scheme Comparison

Three secret sharing schemes, side-by-side — security model, verifiability, traceability guarantees, and suitability for distributed protocols.

Scheme Comparison

PropertyShamir SSSFeldman VSSTraceable Shamir
Evaluation points Fixed integers 1, …, n Fixed integers 1, …, n Random xᵢ ←$ 𝔽*
Threshold (t+1)-of-(n−1) (t+1)-of-(n−1) t-of-n
Share verifiability None Per-share group check None (combinable with Feldman)
Dealer must be trusted Yes No — commitments are public Yes
Identify leakers Impossible Impossible Yes — up to f < t parties
Trace key — — tk = (H(x₁),…,H(xₙ))
Extra public data — t+1 group elements —
Oracle access needed — — Black-box reconstruction oracle
Info-theoretic security Yes Yes (DLog for verifiability) Yes
Suitable for DKG Risky Yes Yes (random points compatible)
Choosing a scheme: use Shamir when simplicity and performance are paramount. Use Feldman when guardians need to verify their shares or when building DKG protocols. Use Traceable Shamir when accountability matters — to deter leakers or identify and prove leakage after the fact.