PostQuantum.SecretSharing.Vss
2.0.0-preview.2
See the version list below for details.
dotnet add package PostQuantum.SecretSharing.Vss --version 2.0.0-preview.2
NuGet\Install-Package PostQuantum.SecretSharing.Vss -Version 2.0.0-preview.2
<PackageReference Include="PostQuantum.SecretSharing.Vss" Version="2.0.0-preview.2" />
<PackageVersion Include="PostQuantum.SecretSharing.Vss" Version="2.0.0-preview.2" />
<PackageReference Include="PostQuantum.SecretSharing.Vss" />
paket add PostQuantum.SecretSharing.Vss --version 2.0.0-preview.2
#r "nuget: PostQuantum.SecretSharing.Vss, 2.0.0-preview.2"
#:package PostQuantum.SecretSharing.Vss@2.0.0-preview.2
#addin nuget:?package=PostQuantum.SecretSharing.Vss&version=2.0.0-preview.2&prerelease
#tool nuget:?package=PostQuantum.SecretSharing.Vss&version=2.0.0-preview.2&prerelease
PostQuantum.SecretSharing.Vss
Opt-in Verifiable Secret Sharing (VSS) for PostQuantum.SecretSharing. Detect a malicious dealer who hands inconsistent shares to different trustees, so every quorum is guaranteed to reconstruct the same secret.
Preview, unaudited new cryptography. Ships as
2.0.0-preview.x. See the honest tradeoff below and the design doc.
Quick example
using PostQuantum.SecretSharing;
using PostQuantum.SecretSharing.Vss;
using System.Security.Cryptography;
byte[] secret = RandomNumberGenerator.GetBytes(32);
// Dealer splits 3-of-5 and publishes commitments (broadcast/pin them like a dealer key).
VssSplit split = PedersenVss.Split(secret, new SharePolicy(Threshold: 3, TotalShares: 5));
VssCommitments commitments = split.Commitments;
// Each trustee verifies their share BEFORE any reconstruction — a malicious dealer is
// caught here (Verify == false), not after recovering a wrong secret.
foreach (VssShare s in split.Shares)
Console.WriteLine($"share {s.ShareIndex}: {s.Verify(commitments)}");
// Any K verified shares reconstruct; Reconstruct re-verifies and refuses bad inputs.
using ZeroizingBuffer recovered = PedersenVss.Reconstruct(
new[] { split.Shares[0], split.Shares[2], split.Shares[4] }, commitments);
▶ Runnable demo:
samples/MaliciousDealerDetected
— an honest split where every trustee verifies, then a dealer who slips one trustee an
inconsistent share, caught before reconstruction.
Why this is a separate package
The core PostQuantum.SecretSharing library is dependency-free and its secrecy is
information-theoretic / post-quantum. VSS needs a prime-order group (NIST P-256 via
a vetted EC dependency), so it lives here — you opt in to that dependency and to one
specific tradeoff:
- Secrecy stays unconditional. Pedersen commitments are perfectly hiding: the commitment transcript reveals nothing about the secret, against any adversary, including a quantum one. The headline guarantee is untouched.
- Malicious-dealer detection is computational. Commitment binding rests on discrete-log hardness. A quantum dealer could defeat the consistency check — not the secrecy. We document this exactly the way the core documents its ML-DSA layer.
Documentation
Status
Pedersen VSS over NIST P-256, with .pqss v2 records and a pinned nothing-up-my-sleeve
second generator. Preview-quality: the public API and format may still change, and
ML-DSA-signed commitments are a later preview (for now, pin the commitments out-of-band
like the dealer key).
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- BouncyCastle.Cryptography (>= 2.5.1)
- PostQuantum.SecretSharing (>= 1.0.0-rc.1)
-
net8.0
- BouncyCastle.Cryptography (>= 2.5.1)
- PostQuantum.SecretSharing (>= 1.0.0-rc.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 2.2.1 | 126 | 8/20/2026 |
| 2.2.0 | 137 | 6/14/2026 |
| 2.1.0 | 136 | 6/14/2026 |
| 2.0.1-preview.1 | 85 | 6/13/2026 |
| 2.0.0-preview.2 | 81 | 6/13/2026 |
| 2.0.0-preview.1 | 81 | 6/13/2026 |