Hi,

I’ve been dabbling in trying to figure out the Enigma whitepaper. My brick wall came at p. 5 where SHE is outlined and this paper is referenced. My problem is that this paper, and every other that comes up when I google this technique, assumes that the shares [s]_p_i add up to the original secret s.

However I see no reason for this to be the case for the definition stipulated by Shamir’s scheme in equation (3). Are there additional ‘obvious’ conditions that I am missing here that force each sum of kth powers to be 0 (1 <= k <= t)? Appreciate anyone’s expertise here.