2026-09-26 23:51:06 -06:00
# Beaver triples {#beaver_triples}
2026-09-28 05:59:19 -06:00
\htmlonly
< div class = "eli5" > < b > ELI5.< / b > A product opens as d = x − a and e = y − b, with a and b the preprocessing blinds. The product share is de plus the blinded cross terms, all local once d and e are public. The session keeps blinds that were already opened and only samples monomials it has not seen.< / div >
\endhtmlonly
2026-09-26 23:51:06 -06:00
ABY2.0-style sessions open masked wires once (Patra, Schneider, Suresh,
and Yalame, USENIX Security 2021 / [ePrint 2020/1225 ](@ref bib_aby2 )).
A fresh triple follows Beaver, [CRYPTO 1991 ](@ref bib_beaver ): both masked factors are
reconstructed, and the product share is a local correction.
Optional MAC tags are the Shark/SPDZ check.
2026-09-28 05:59:19 -06:00
Constant-round word arithmetic is a separate gadget. [Ball, Malkin, and
Rosulek, CCS 2016](@ref bib_garble_gadgets) give free addition, free scaling
by a public constant, and a unary projection of `m − 1` ciphertexts.
[arith_garble.hpp ](@ref dpf/arith_garble.hpp ) is that circuit. A session does
not become one: it still opens δ once per wire. A public table on masked
bits is [FLUTE ](@ref bib_flute ) in [flute.hpp ](@ref dpf/flute.hpp ): the table
is a multi-fan-in inner product, and the online exchange is two bits per
output bit. `eval_trio` is the same product on three XOR shares of each mask.
2026-09-26 23:51:06 -06:00
One call that samples a list of formulae opens the new wires in one
round. Communication is one masked value per newly opened wire, plus a
tag share of the same width when MACs are on. Preprocessing is one blind
per wire and one product share per monomial.
2026-09-28 05:59:19 -06:00
`schedule_objective::prep` (default) peels shared factors for Appendix-E
prep savings and may add interactive rounds.
`schedule_objective::rounds` emits the polynomial in one online round
(Pika / online Grotto). Composer-owned sessions use `rounds` .
Compose FSS walks, ABY products, and RSS refreshes on one sink with
[protocol composition ](@ref protocol_compose ).
**Go deeper:** [a small word ](@ref arith_garble_word ),
[a public table ](@ref flute_lut ), [beaver.hpp ](@ref dpf/beaver.hpp ),
[compose.hpp ](@ref dpf/compose.hpp ),
2026-09-26 23:51:06 -06:00
[F_Beaver ](@ref beaver.hpp ), [F_BeaverAuth ](@ref beaver.hpp ),
and the cost notes in the [guided tour ](@ref tour_beaver ).