← Latest papers
💻 computer science

Quantum Leakage Resilience of Shamir Secret Sharing

This paper establishes that unmodified Shamir secret sharing over prime fields remains secure against quantum local leakage when the threshold rate exceeds approximately 0.73339, provided that leakage devices have limited or no entanglement, while demonstrating that arbitrary entanglement among devices can completely break security even with classical leakage.

Original authors: Rishabh Batra, Fuyuki Kitagawa, Ryo Nishimaki, Takashi Yamakawa

Published 2026-09-30
📖 5 min read🧠 Deep dive

Original authors: Rishabh Batra, Fuyuki Kitagawa, Ryo Nishimaki, Takashi Yamakawa

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the digital age, protecting a secret often means splitting it into pieces and handing those pieces to different people. This method, known as secret sharing, ensures that no single person holds the entire key to a vault, a password, or a private code. Instead, a specific number of people must come together to reconstruct the original information. This approach is a cornerstone of modern cryptography, used to manage encryption keys and secure communications. For decades, researchers have studied how to make these systems robust against a specific type of threat: an attacker who cannot steal the entire pieces but can peek at tiny fragments of them. This is called leakage. If an attacker can read even a single bit of information from every person's piece, they might be able to piece together the whole secret. The question has always been: how much can an attacker learn before the system breaks?

Now, as technology moves from classical computers to quantum machines, the nature of these tiny fragments changes. Instead of just bits of information, an attacker might be able to extract a quantum bit, or qubit, which can exist in a complex state of multiple possibilities at once. A new study by researchers at EPFL and NTT Social Informatics Laboratories investigates whether the standard, widely used method of secret sharing can survive this new kind of quantum peeking. They found that the system remains secure, but only if the number of people required to unlock the secret is high enough. Specifically, if the group needs more than about seventy-three percent of the total participants to reconstruct the secret, the scheme holds up even when an attacker tries to extract a quantum bit from every single participant's share. This security holds true even if the attacker measures all the leaked quantum bits together at once.

The researchers also explored a more complex scenario where the devices holding the secret pieces might share a special quantum connection called entanglement with each other, or even with the attacker. Entanglement is a phenomenon where particles become linked so that the state of one instantly influences the other, regardless of distance. The study shows that the system can still withstand this threat, provided the number of devices sharing these connections remains relatively small compared to the total group size. However, the researchers also discovered a hard limit. If the number of devices sharing entanglement grows too large, the system becomes vulnerable. They demonstrated a specific attack where a group of devices, using a shared quantum state known as a GHZ state, could leak just one classical bit each and still reveal the secret. This attack works even if the devices have no entanglement with the attacker, proving that the size of the entangled group is the critical factor.

The work relies on a mathematical approach that treats the secret sharing process like a pattern of waves. By analyzing how these waves interact, the researchers could prove that as long as the threshold for reconstruction is high enough, the information leaked by the quantum bits is too scrambled to be useful. They showed that for a group of participants, if the required number to unlock the secret is roughly seventy-three percent of the total, the chance of an attacker guessing the secret correctly is so small it is effectively zero. This result is significant because it applies to the unmodified version of the secret sharing scheme that is already in use today, meaning no changes to existing protocols are needed to gain this level of quantum security.

The study also clarifies the boundary between safety and danger. While a small number of devices sharing entanglement is safe, the researchers proved that if a large enough group shares these connections, the security collapses. They found that even with classical bits, if enough devices are entangled, they can coordinate their leaks to reveal the secret. This suggests that in a world with quantum capabilities, the security of secret sharing depends not just on how much information is leaked, but on how the devices holding that information are connected. The findings provide a clear map for where these systems are safe and where they are not, offering a guide for building secure systems in a future where quantum computers are a reality.

The researchers did not stop at proving security; they also identified the precise point where it fails. They calculated that for a system to remain secure against a linear number of entangled devices, the threshold rate must be sufficiently high. If the threshold is too low, the system is insecure. This balance between the number of participants needed to unlock the secret and the amount of entanglement allowed is the key takeaway. The study confirms that while quantum leakage is a serious concern, it is manageable with the right parameters. The results offer a reassuring conclusion for those relying on these cryptographic tools: the familiar methods of secret sharing are resilient, provided the rules for reconstruction are set high enough to keep the quantum threats at bay.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →