100%-ban a böngészőben fut, Web Crypto használatával — a titok és a réssei sosem hagyják el az eszközét.
Write a Python implementation of Shamir's Secret Sharing over GF(256) that interoperates with these share strings: each share is the two-digit hex x-coordinate, a dash, then one hex byte per secret byte (e.g. "01-a3b2c1"). It must split a secret into 5 shares with threshold 3, and reconstruct from any 3 of them. Use the AES reduction polynomial 0x11B and rejection-free crypto-random coefficients.
(Documentation in English)
What it does
Shamir’s Secret Sharing splits a secret into N shares so that any K of them reconstruct it - and fewer than K reveal nothing at all, not even a partial hint. It is the mathematical basis for splitting a crypto wallet seed phrase, a master password, or an encryption key across several people or locations so that no single holder (and no coalition smaller than K) can act alone. Real-world uses include cryptocurrency custody (multi-party wallet backup), key escrow, nuclear launch codes, estate planning (lawyer + spouse + safety deposit box), and disaster-recovery envelopes.
The tool runs the whole scheme in your browser over GF(256) - the same Galois field AES uses - with polynomial coefficients from Web Crypto. Nothing you type, and no share you paste, ever leaves your device.
How to use it
- Pick a mode with the Split / Reconstruct toggle at the top.
- Split: enter the secret, set Total shares (N) (2-255) and Threshold (K) (2-N, the minimum needed to recover), then press Split secret.
- Copy each numbered share to its holder (every share has its own Copy button; Copy all shares grabs the lot). The shield note reminds you: any K of the N shares recover the secret; K-1 reveal nothing.
- Reconstruct: paste one share per field (Add share for more), then press Reconstruct secret. The recovered secret appears in the green output with a copy button; invalid or mismatched shares produce a clear error.
Examples
Split a seed phrase 3-of-5
Secret: river vacuum lamp fiber quiz noise border mind smile crouch tuna — with N=5, K=3 you get five shares, each like:
01-9f3ac27e1b84d05c…
02-4b19e7a2c83f5d16…
03-c7e02f9a45b6138d…
04-2ad673f1e09b85c4…
05-85d31c6b7a49f0e2…
(Your values will differ - the polynomial coefficients are freshly random on every split, so no two splits of the same secret look alike.)
Recover from any 3 of the 5
Paste shares 01-…, 03-…, 05-… into three fields and press Reconstruct secret - the original seed phrase comes back exactly. Shares 1+2, 2+4+5, any combination of three works; two shares alone reconstruct only garbage.
A wrong pairing fails loudly
Mixing shares from two different splits (or two shares claiming the same position) gives Two different shares both claim x=01 - they cannot come from the same split, instead of silently returning a wrong secret.
Good to know
- Why K-1 shares reveal nothing: each secret byte becomes the constant term of a random degree-(K-1) polynomial. K-1 points are consistent with every possible constant term - the secret is information-theoretically hidden, not just computationally hard. This holds even against unlimited computing power.
- The math in one line: shares are polynomial evaluations f(1)…f(N) over GF(256); reconstruction is Lagrange interpolation at x=0. Addition is XOR, multiplication uses the AES reduction polynomial (0x11B).
- Fresh randomness every split: splitting the same secret twice yields completely different shares; both sets independently reconstruct it.
- Handle shares like keys: a share is half (or a third, or a fifth) of your secret. Store them in separate places - if an attacker collects K of them, they own the secret.
- Private: runs 100% client-side; the share link carries only your N/K settings, never the secret.
- Related tools: Password Strength Analyser, Secure Token Generator, HMAC Generator.