4 ms·
Sure. One example is as follows: each party i generates a random polynomial P_i, and n secret shares of that polynomial (j, P_i(j)) for j in 1..n Then, party
by plopilop 4y ago
Sure.
One example is as follows: each party i generates a random polynomial P_i, and n secret shares of that polynomial (j, P_i(j)) for j in 1..n
Then, party i sends (j, P_i(j)) to party j. Party i similarly receives shares (i, P_j(i)) for j=1..n. Party i stores the share (i, sum(P_j(i))).
Then, parties reveal their shares as usual, the secret is then the sum_i P_i(0).
Of course, if the parties are dishonest, you might want some additional safety mechanisms, which can be dealt with with Kate commitments.
This papers https://eprint.iacr.org/2020/504.pdf https://eprint.iacr.org/2020/504.pdf goes into details, and much more.