Basically just Lagrange interpolation of signature shares (on G1) to construct the total signature, then verification against the public key. [link to paper](https://link.springer.com/content/pdf/10.1007/3-540-36288-6_3.pdf)