2026-09-26 23:51:06 -06:00
# Verifiability & authenticity {#verifiability}
2026-09-28 05:59:19 -06:00
\htmlonly
< div class = "eli5" > < b > ELI5.< / b > The proof rides on the same walk as the payload. verifiable checks that the correction seeds were the honest ones. extractable checks that the path is weight 1, so a second programmed point fails. A MAC checks the leaf share after it is opened.< / div >
\endhtmlonly
2026-09-26 23:51:06 -06:00
Prove that a DPF walk used honest correction seeds, or that a weight-1
sketch over the path is consistent. The tags ride along as extra
`make_dpf` arguments; eval still returns the usual leaf share.
| Tag / call | What you get |
| --- | --- |
| [dpf::verifiable ](@ref dpf/verifiable.hpp ) | Proof token folded on the path (de Castro– Polychroniadou, EUROCRYPT 2022 / [ePrint 2021/580 ](@ref bib_vdpf )). Equal tokens across parties mean honest seeds. |
| [dpf::extractable ](@ref dpf/verifiable.hpp ) | Weight-1 `fp61` sketch on the same walk. A second hot point fails the check. |
| [dpf::output_mac ](@ref dpf/verifiable.hpp ) / `mac_authenticate` | Authenticated leaf shares and batch checks. |
| Path sketches | [path_sketch.hpp ](@ref dpf/path_sketch.hpp ) for prefix / parent sketches used by application mockups. |
```cpp
auto [k0, k1] = dpf::make_dpf(std::uint8_t{42}, std::uint64_t{7},
dpf::verifiable{});
auto [e0, e1] = dpf::make_dpf(std::uint8_t{42}, std::uint64_t{7},
dpf::extractable{});
```
Multipoint keys take the same `dpf::verifiable{}` tag for a batched
proof (one token for the cuckoo set). Three-party keys can be
verifiable or extractable as well; see [Multiparty & 3-server ](@ref multiparty ).
**Go deeper:** [guided tour ](@ref tour_vdpf ), ideal figures
[F_VDPF ](@ref verifiable.hpp ) / [F_Sketch ](@ref verifiable.hpp ),
[bibliography ](@ref bibliography ).