Papers
Topics
Authors
Recent
Search
2000 character limit reached

Packed Shamir Secret Sharing (PSS)

Updated 26 January 2026
  • Packed Shamir Secret Sharing is a method that encodes a vector of secrets into a single polynomial, enabling parallel sharing while preserving threshold privacy.
  • It optimizes secure multi-party computation by reducing communication overhead and increasing throughput, notably for deep neural network inference.
  • The scheme employs VM-RandTuple structures and filter packing techniques to support efficient vector–matrix multiplication and convolution with maintained t-privacy.

Packed Shamir Secret Sharing (PSS) is a generalization of Shamir’s (t,n)(t, n)-threshold secret sharing scheme, enabling the encoding of a vector of kk secrets into a single polynomial of degree d≥k−1d \geq k-1 over a finite field. This structure permits parallel, or "packed," computation over multiple secret values with communication and round complexity closely matching that for sharing a single value. PSS is particularly designed to enhance throughput and scalability in secure multi-party computation (MPC), especially for deep neural network inference in honest-majority settings, by reducing the otherwise prohibitive communication overhead and enabling high degrees of parallelism (Zhang et al., 19 Jan 2026).

1. Formal Definition and Construction

PSS operates over the field Fp\mathbb{F}_p, where p=2ℓ−1p=2^\ell-1 is a Mersenne prime (with typical choices ℓ∈{31,61}\ell\in\{31,61\}), optimizing arithmetic efficiency. For n=2d+1n=2d+1 servers and packing factor k≤dk\le d, the threshold is set to t=d−k+1t=d-k+1 for privacy. A vector of kk secrets kk0 is packed as the coefficients of a degree-kk1 polynomial:

kk2

Each server kk3 is assigned a publicly known, pairwise-distinct point kk4 and receives a share kk5. Any kk6 shares suffice to reconstruct the entire vector by Lagrange interpolation, whereas any kk7 or fewer reveal nothing. Extraction of the kk8th secret utilizes the Lagrange coefficients:

kk9

where d≥k−1d \geq k-10 are determined by the interpolation basis at the corresponding evaluation points. This construction provides parallel privacy and reconstruction for the d≥k−1d \geq k-11 secrets at the cost of a single polynomial evaluation per server, achieving packing efficiency while maintaining d≥k−1d \geq k-12 threshold security properties (Zhang et al., 19 Jan 2026).

2. VM-RandTuple Structures for Vector–Matrix Multiplication

Efficient secure vector–matrix multiplication in the MPC context leverages Vector-Matrix Multiplication–Friendly Random Share Tuples (VM-RandTuples). A VM-RandTuple is a pair d≥k−1d \geq k-13, where d≥k−1d \geq k-14 is a packed vector in d≥k−1d \geq k-15 and d≥k−1d \geq k-16 produces a packed sum for each output coordinate. The protocol generates these tuples offline using a two-round Vandermonde-matrix method, with each server secret-sharing d≥k−1d \geq k-17 random values and exchanging linear combinations via the transposed Vandermonde matrices. Privacy for up to d≥k−1d \geq k-18 colluding servers is preserved, as each PSS instance ensures information-theoretic secrecy for packs of d≥k−1d \geq k-19 secrets.

This structure allows vector–matrix or matrix–matrix products to be performed in parallel across all Fp\mathbb{F}_p0 packed values per lane. Field element complexity for VM-RandTuple generation is Fp\mathbb{F}_p1 per server offline and Fp\mathbb{F}_p2 per server online (Zhang et al., 19 Jan 2026).

3. Filter Packing for Parallel Secure Convolution

PSS enables efficient packing of filters for secure convolutional neural network evaluation by grouping Fp\mathbb{F}_p3 filters into a single PSS value for each spatial weight position. For a convolutional layer with Fp\mathbb{F}_p4 filters (each of shape Fp\mathbb{F}_p5), packing is performed so that each position Fp\mathbb{F}_p6 has

Fp\mathbb{F}_p7

mapped into a degree-Fp\mathbb{F}_p8 polynomial Fp\mathbb{F}_p9. Input tensors are similarly packed. Convolution is then reduced to a packed inner product and an add-and-truncate operation, enabling simultaneous processing across all p=2ℓ−1p=2^\ell-10 channels with negligible overhead over a single channel computation. Padding is efficiently handled by packing zeros, incurring no extra communication. The offline complexity per server for this operation is p=2ℓ−1p=2^\ell-11 field elements in 4 rounds, and the online complexity is p=2ℓ−1p=2^\ell-12 field elements in one round, where p=2ℓ−1p=2^\ell-13 is the post-unfolding matrix shape (Zhang et al., 19 Jan 2026).

4. Efficient Parallel Non-Linear Operations

All Boolean and bitwise operations can be performed in parallel across all p=2ℓ−1p=2^\ell-14 packed values within a single PSS instance. For example, prefix-OR (critical to comparisons) is computed via a binary tree of DN-style multiplications in p=2ℓ−1p=2^\ell-15 rounds. Bitwise less-than is implemented by decomposition, XOR, and prefix-OR, with all p=2ℓ−1p=2^\ell-16 comparisons done simultaneously inside one PSS in p=2ℓ−1p=2^\ell-17 rounds. For DReLU/ReLU, the protocol masks p=2ℓ−1p=2^\ell-18 with random p=2ℓ−1p=2^\ell-19, evaluates one bitwise less-than, and corrects the result; DReLU is completed in ℓ∈{31,61}\ell\in\{31,61\}0 rounds, and ReLU requires one additional multiplication round. Maxpool combines ReLU and pairwise comparisons in ℓ∈{31,61}\ell\in\{31,61\}1 rounds, all parallelized. Every invocation of a DN-style multiplication or degree transformation maintains ℓ∈{31,61}\ell\in\{31,61\}2-privacy inherent to PSS (Zhang et al., 19 Jan 2026).

5. Performance Metrics and Empirical Scalability

For packing factor ℓ∈{31,61}\ell\in\{31,61\}3, PSS realizes significant reductions in both communication and computational overhead across secure inference protocols.

Operation Offline rounds/comm. Online rounds/comm.
Vector-matrix multiplication 2 rounds, ℓ∈{31,61}\ell\in\{31,61\}4 1 round, ℓ∈{31,61}\ell\in\{31,61\}5
Convolution 4 rounds, ℓ∈{31,61}\ell\in\{31,61\}6 1 round, ℓ∈{31,61}\ell\in\{31,61\}7
ReLU ℓ∈{31,61}\ell\in\{31,61\}8 online rounds ℓ∈{31,61}\ell\in\{31,61\}9 communication/lane

Empirical evaluations (11–63 servers, n=2d+1n=2d+10, fixed-point 13 bits) indicate communication reductions compared to Shamir-only schemes of Liu et al. (USENIX’24) up to n=2d+1n=2d+11 (offline), n=2d+1n=2d+12 (online), n=2d+1n=2d+13 (total) and speedups up to n=2d+1n=2d+14 (offline), n=2d+1n=2d+15 (online), n=2d+1n=2d+16 (total) on wide-area networks. These improvements, especially for deeper architectures like VGG16 run with up to 63 servers, are due to the parallelization enabled by PSS. In local area networks, where computation dominates, offline speedups up to n=2d+1n=2d+17 and total up to n=2d+1n=2d+18 are observed on deep networks (Zhang et al., 19 Jan 2026).

6. Cryptographic and Practical Implications

PSS maintains the n=2d+1n=2d+19-threshold privacy and reconstruction guarantees per pack of k≤dk\le d0 values, with each operation—linear or nonlinear—executed in parallel over all lanes. This property enables throughput and scalability increases by roughly a factor of k≤dk\le d1 for both linear layers (matrix operations) and elementwise functions, with little connectivity or round overhead. The ability to parallelize across many secrets positions PSS as a practical primitive for secure, high-throughput computation in multi-party inference and cryptographic ML, overcoming the severe scalability and latency limitations of classical Shamir-based MPC protocols in network-constrained environments (Zhang et al., 19 Jan 2026).

Definition Search Book Streamline Icon: https://streamlinehq.com
References (1)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Packed Shamir Secret Sharing (PSS).