Where do si come from for each decryption ?
Servers share in advance random poly’s S1,…Sk s.t. deg (Sj) = t and Sj(0)=sj . I.e server i holds sji= Sj(i) for all j, to use for decrypting jth cipher text.
To avoid synchronization errors, servers can share in advance on a single 2-var polynomial S(x,y) where S(c,) is as above, I.e server i holds polynomial S(x, i), and uses si=S(c,I) for cipher text c.