The secret key is basically a Shamir secret share so neither the key-share server nor the device ever sees the full key.
j previous speech k next speech