Split a secret into N shares, recover with any K of them. Implemented over GF(256) using the AES Rijndael polynomial. Visualize the polynomial, run Lagrange interpolation step-by-step.
Shamir's Secret Sharing is the elegant 1979 construction that turns a secret into N pieces, any K of which can recover it. Its mathematical foundation is polynomial interpolation: a polynomial of degree K-1 is uniquely determined by K points. Below K points, there are infinitely many polynomials passing through those points — including all possible secret values. The secret is the constant term (y-value at x=0); each share is (x, f(x)) for a random degree-(K-1) polynomial.
Real implementations operate byte-by-byte over GF(256) — the field with 256 elements defined by the polynomial x⁸ + x⁴ + x³ + x + 1 (0x11B), the same irreducible polynomial AES uses. This keeps each byte independent: the secret "Hello" is split into 5 independent polynomials (one per byte). Recovery is 5 independent Lagrange interpolations at x=0. No big-number arithmetic, no modular inverse problems that get intractable in prime fields.
The polynomial visualization tab shows the actual coefficients and plotted points. For a 1-byte secret with K=3, you get degree-2 polynomials in GF(256). We plot the points (x, y) on a 2D plane — even though the field is finite, the visual intuition transfers: with 2 points you can't determine a quadratic; with 3 points you can.
The K-1 leak test demonstrates information-theoretic security empirically. You provide K-1 shares; we let you guess the secret; the answer reveals that your guess has no signal — knowing 2 of 3 shares tells you nothing about byte 73.
A Bitcoin wallet seed, a master encryption key, a root CA private key. Split into 5 shares, require 3 to reconstruct, distribute to board members or geographically separated backups.
Shamir's is the building block for threshold signatures, distributed key generation, and multi-party computation. This tool implements the basic scheme correctly so you can build on it.
Visualizing the polynomial and Lagrange interpolation makes abstract algebra concrete. The K-1 leak test provides empirical evidence of information-theoretic security.