Shamir SSS augmented with public polynomial commitments — each guardian independently verifies their share against Cj = aj·G without trusting the dealer or interacting with other parties.
Paul Feldman's 1987 construction makes Shamir VSS verifiable by having the dealer publish a commitment vector alongside the shares. Each coefficient aj of the sharing polynomial is committed as Cj = aj·G in the group. A guardian receiving share (x, y) can verify that y·G equals Σj Cj·xj — if the check fails, the dealer cheated. This single multi-scalar multiplication per share is the only overhead above Shamir.
Feldman VSS is the standard building block for distributed key generation (DKG) protocols because it prevents a malicious dealer from distributing inconsistent shares while keeping the secret hidden. The verification requires discrete-log hardness; security against a cheating dealer is computational, while confidentiality against colluding guardians remains information-theoretic.
(x, y) by checking
y · G = Σⱼ Cⱼ · xʲ in the group.
This requires no interaction — only the public commitment vector.
use arc_pleiades::FeldmanVSS;
use arc_pleiades::secret_sharing::{SecretSharing, VerifiableSS};
use midnight_curves::{G1Projective, Fq as Scalar};
use rand::thread_rng;
let mut rng = thread_rng();
let vss = FeldmanVSS::<G1Projective>::new(2, 5)?; // 3-out-of-4
let secret = Scalar::from(42u64);
// Split → shares + public commitments (t+1 group elements)
let poly = vss.polynomial(secret, &mut rng);
let shares = vss.split(&poly)?;
let vk = vss.compute_verification_key(&poly)?;
// Each guardian independently verifies their own share
for share in &shares {
vss.verify_share(share, &vk)?; // Err if the dealer cheated
}
// Reconstruct — same Lagrange as Shamir once shares are verified
let recovered = vss.reconstruct(&shares[..vss.threshold()])?;
assert_eq!(secret, recovered);