Share refresh (proactive security)
Share refresh (Herzberg 1995) replaces every share with a fresh randomization of the same underlying key. Each party generates random polynomials with zero constant term and distributes the deltas; after applying them, all parties hold new shares for the same public key, and old shares are useless — an adversary that collects shares slowly, across compromise windows, never reaches the threshold.
Confium ships refresh sessions for the FROST crates and the
confium threshold refresh CLI. Operational guidance: choose the
refresh window from your containment SLA (e.g. quarterly), and always
refresh after any suspected share exposure.