libdpf/doc/pages/dealer_free.md

28 lines
1.4 KiB
Markdown
Raw Permalink Normal View History

# Dealer-free keygen {#dealer_free}
\htmlonly
<div class="eli5"><b>ELI5.</b> The index is already split. Doerner–Shelat turns those shares into a reusable key by opening one masked correction per level. geneval stops after a single public query and returns answer shares, not a key. IKNP is how the pads are sampled when no dealer supplies them.</div>
\endhtmlonly
The two parties already hold shares of the secret index.
Nobody sends `alpha` to a dealer.
| Call | What you get |
| --- | --- |
| [dpf::make_dpf_doerner_shelat](@ref dpf/doerner_shelat.hpp) | A reusable two-party key from XOR shares of `alpha` (Doerner–Shelat, CCS 2017 / [ePrint 2017/827](@ref bib_ds)) |
| [dpf::geneval_point](@ref dpf/geneval.hpp) / `geneval_interval` / `geneval_cmp` | Answer shares for one query. No reusable key |
| IKNP pads | The same Doerner–Shelat walk after Chou–Orlandi base OT ([ePrint 2015/267](@ref bib_chou)), with no pad dealer |
```cpp
const std::uint8_t alpha = 42;
const std::uint8_t x0 = 0x13;
const std::uint8_t x1 = static_cast<std::uint8_t>(alpha ^ x0);
auto [k0, k1] = dpf::make_dpf_doerner_shelat(x0, x1, std::uint64_t{7});
```
Three evaluators have the same shape: `make_dpf3_doerner_shelat`.
Socket sessions live under `party/dist_ds.hpp` and `party/iknp_deal.hpp`.
**Go deeper:** [Doerner–Shelat](@ref tour_ds), [geneval.hpp](@ref dpf/geneval.hpp),
[Multiparty & 3-server](@ref multiparty).