<pclass="hero-lead"><code>libdpf++</code> is a header-only C++17 library of distributed point functions: short keys that hide one secret index, then answer at public points as secret shares. The same tree ships a TLS party mesh, round scheduling, MPC on those leaf shares, leveled run logs, and paper-cost statistics — so readers do not have to dig the API to find them.</p>
<aclass="feature-card"href="verifiability.html"><spanclass="feature-kicker">Proofs</span><strong>Verifiability & authenticity</strong><p>Honest correction seeds, a weight-1 sketch, and MACs on the leaves, on the same walk.</p></a>
<aclass="feature-card"href="programmability.html"><spanclass="feature-kicker">Late binding</span><strong>Programmability</strong><p>Fill the index or the payload after the key exists. Rewrite an updatable leaf in place.</p></a>
<aclass="feature-card"href="comparisons.html"><spanclass="feature-kicker">Predicates</span><strong>Comparisons & ranges</strong><p>Less-than, equality, interval containment, and blocked checks, as keys.</p></a>
<aclass="feature-card"href="multipoint_keys.html"><spanclass="feature-kicker">Many secrets</span><strong>Multipoint keys</strong><p>Pack many secret points into one cuckoo key. One batched proof covers the set.</p></a>
<aclass="feature-card"href="multiparty.html"><spanclass="feature-kicker">Three parties</span><strong>Multiparty & 3-server</strong><p>Any two of three open a Shamir key. Or an information-theoretic three-server DPF.</p></a>
<aclass="feature-card"href="dealer_free.html"><spanclass="feature-kicker">No dealer</span><strong>Dealer-free keygen</strong><p>The parties already share the index. Doerner–Shelat, geneval, and IKNP finish the key.</p></a>
<aclass="feature-card"href="jet_and_ring.html"><spanclass="feature-kicker">After the offset</span><strong>Grotto</strong><p>Jets, polynomials, carry, and exact ring changes once a public offset is open. Several LUTs share one comparison.</p></a>
<aclass="feature-card"href="ppvc_manual.html"><spanclass="feature-kicker">Commitments</span><strong>Programmable vectors</strong><p>Bind a vector, then open one hidden coordinate or the sum.</p></a>
<aclass="feature-card"href="applications.html"><spanclass="feature-kicker">Sketches</span><strong>Application sketches</strong><p>The DPF step of Duoram, keyword PIR, PSI, Prio, LLAMA, and the rest.</p></a>
</div>
<h2id="around-the-keys">Around the keys</h2>
<pclass="hero-lead"style="font-size:1.05rem;margin-bottom:0.6rem">Live parties, composition, MPC on leaf shares, logging, and statistics — first-class, not buried in the reference.</p>
<divclass="feature-grid">
<aclass="feature-card"href="network_and_mpc.html"><spanclass="feature-kicker">Links</span><strong>Network & party mesh</strong><p>TLS 1.3 party sessions, trio mesh, RoundSink rounds, lanes, and reconnect.</p></a>
<aclass="feature-card"href="protocol_compose.html"><spanclass="feature-kicker">Schedule</span><strong>Protocol composition</strong><p>FSS walks next to Beaver opens on one RoundSink plan, with explicit reshares.</p></a>
<aclass="feature-card"href="beaver_triples.html"><spanclass="feature-kicker">Multiplication</span><strong>Beaver triples</strong><p>Authenticated products on leaf shares, including the ABY2.0 MAC check.</p></a>
<aclass="feature-card"href="yao_leaf.html"><spanclass="feature-kicker">Circuits</span><strong>Yao on a leaf</strong><p>Split a leaf into bits, garble a netlist, share the answer back as a leaf.</p></a>
<aclass="feature-card"href="experiment_costs.html"><spanclass="feature-kicker">Observability</span><strong>Logging & statistics</strong><p>Leveled run logs, provenance banners, replayable seeds, and CSV wire / PRG / timing breakdowns.</p></a>