Paper 2026/2294

Deniable Secret Sharing: Towards Practical Faking

Ignacio Amores, Aarhus University
Tamar Ben David, Ariel University
Matteo Campanelli, University of Tartu, Offchain Labs
Sebastian Kolby, Aarhus University
Eran Omri, Ariel University
Anat Paskin-Cherniavsky, Ariel University
Sophia Yakobuov, Aarhus University
Abstract

Deniable secret sharing (DSS; Canetti et al, TCC 2025) is designed for a scenario where an adversary is able to bribe or coerce all shareholders to divulge their shares of a secret. A deniable secret sharing scheme is equipped with a faking function that enables shareholders to produce fake shares that look like real shares, but do not actually reveal any additional information about the secret. Existing DSS constructions require the fakers to jointly compute on their shares, without considering how this computation might be realized. In this paper, we investigate two crucial properties of such computations: the extent to which the fakers themselves learn information about the secret (privacy against fakers), and the number of messages they need to exchange (message complexity). Message complexity can be seen as a measure of faking conspicuousness, if the adversary is able to observe network traffic. We prove that to obtain the strongest notion of DSS, any information-theoretic construction requires the fakers to exchange a non-zero number of messages, which could be large (depending on the access structure). We describe a general construction that matches this lower bound in many cases, e.g. for threshold access structures. Furthermore, for linear secret sharing schemes, we prove that certain unqualified sets must learn the secret as a result of faking. Moving to the computational setting, we describe two constructions which require no interaction beyond the knowledge of who the fakers are. This implies that both inconspicuousness and privacy against fakers are achieved. The first construction requires the share size to be exponential in the number of shareholders, but assumes only a PRG. The second construction has small shares, but assumes virtual black-box obfuscation. We see the latter construction as a stepping stone for a future iO-based instantiation. All of our lower bounds and constructions consider general access structures.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Published by the IACR in TCC 2026
Keywords
secret sharingdeniable secret sharingdeniability
Contact author(s)
amores-sesar @ cs au dk
tamaryahav123 @ gmail com
binarywhalesinternaryseas @ gmail com
sk @ cs au dk
omrier @ ariel ac il
anatpc @ ariel ac il
sophia yakoubov @ cs au dk
History
2026-10-04: approved
2026-10-01: received
See all versions
Short URL
https://ia.cr/2026/2294
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2294,
      author = {Ignacio Amores and Tamar Ben David and Matteo Campanelli and Sebastian Kolby and Eran Omri and Anat Paskin-Cherniavsky and Sophia Yakobuov},
      title = {Deniable Secret Sharing: Towards Practical Faking},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2294},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2294}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.