Checkpoint the party/runtime stack before share-program and malicious-mode work.
Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
695f8e84f7
commit
0d22946a0e
1835 changed files with 170291 additions and 2849 deletions
|
|
@ -75,6 +75,10 @@ mockup [I-DPF max and k-th](@ref app_idpf_agg).
|
|||
|
||||
## Assigning a wildcard leaf {#wildcard_assign}
|
||||
|
||||
\htmlonly
|
||||
<div class="eli5"><b>ELI5.</b> The blank leaf is a Beaver slot from keygen. Filling it in rewrites the correction word: the parties exchange one blinded share of the new payload and both apply the same patch. assign_cmp rewrites the n comparison words locally and sends nothing. An updatable leaf is the same patch later, O(λ) and independent of the depth.</div>
|
||||
\endhtmlonly
|
||||
|
||||
An output wildcard is a placeholder for a payload filled after keygen.
|
||||
The type and the `dpf::wildcards` names are on
|
||||
[Output types](@ref output_types). Evaluation of an unassigned slot throws
|
||||
|
|
@ -149,6 +153,10 @@ either party's type accepts both parties. Name that type with
|
|||
|
||||
## Memoizers {#memoizers}
|
||||
|
||||
\htmlonly
|
||||
<div class="eli5"><b>ELI5.</b> The first walk stores interior nodes. The next query starts from the deepest stored node that still lies on its path, instead of from the root. An interval memoizer stores the nodes that cover a range; a sequence memoizer stores the nodes along a sorted list.</div>
|
||||
\endhtmlonly
|
||||
|
||||
## Path memoizers {#path_memoizers}
|
||||
|
||||
`eval_point` walks one root-to-leaf path. `make_basic_path_memoizer<Key>()`
|
||||
|
|
@ -331,6 +339,10 @@ size both for that domain.
|
|||
|
||||
## Deferred input evaluation {#defer_eval}
|
||||
|
||||
\htmlonly
|
||||
<div class="eli5"><b>ELI5.</b> The PRG expand runs once, into a full-domain buffer, before the index is known. When the offset opens, get() rotates that buffer. The tree is not expanded again.</div>
|
||||
\endhtmlonly
|
||||
|
||||
Additive input blinding evaluates in tree coordinates `x ↦ x + δ`, where
|
||||
`δ` is reconstructed by `assign_wildcard_input` into `offset_x`. Eager
|
||||
`eval_interval` folds that map into the traversed range and throws if the
|
||||
|
|
@ -364,6 +376,10 @@ Buffers must outlive both.
|
|||
|
||||
## dpf::eval_inner_product {#eval_inner_product}
|
||||
|
||||
\htmlonly
|
||||
<div class="eli5"><b>ELI5.</b> The walk is the same as an interval or full-domain eval, but each leaf is multiplied by a public weight and added into one accumulator. The expanded vector is not stored. A sequence inner product does that only at the listed points.</div>
|
||||
\endhtmlonly
|
||||
|
||||
`eval_inner_product` multiply-accumulates DPF shares against another vector
|
||||
during the walk. It does not write the output vector.
|
||||
|
||||
|
|
@ -469,6 +485,10 @@ on that list: at most `O(n m)` expands and `m` output slots.
|
|||
|
||||
## Buffered PRG {#buffered_prg}
|
||||
|
||||
\htmlonly
|
||||
<div class="eli5"><b>ELI5.</b> One AES expand produces more blocks than a single tree node needs. The buffered PRG keeps the leftover blocks and serves the next nodes from them, so a wide walk makes fewer expands. The keys do not change.</div>
|
||||
\endhtmlonly
|
||||
|
||||
`dpf::randomness::buffered_prg<PRG, Ts...>` (alias
|
||||
`dpf::randomness::aes_buffered_prg<Ts...>`) is a forward cursor with one
|
||||
PRG stream per value type. `get<I>()` and `fill<I>(out, n)` consume the
|
||||
|
|
@ -496,6 +516,10 @@ element. `fill_values` / `fill_masks` of `q` elements are `Θ(q)`.
|
|||
|
||||
## Three-party (2,3) DPF {#dpf3}
|
||||
|
||||
\htmlonly
|
||||
<div class="eli5"><b>ELI5.</b> Each evaluator key is two VDPF+ spines. eval_point walks both, Θ(n) expands, then scales into fp61. Opening two or three as_share values is a constant amount of field arithmetic. An updatable rewrite patches four leaves and refreshes an offset, independent of n.</div>
|
||||
\endhtmlonly
|
||||
|
||||
`make_dpf3(α, β)` builds three evaluator keys after Guy Zyskind, Avishay Yanai, and Alex "Sandy" Pentland, [ePrint 2024/1658](@ref bib_dpf3), Figure 3:
|
||||
two VDPF+ spines plus Shamir embedding in `fp61`. `eval_point` returns a
|
||||
field share; open with `dpf::reconstruct` on any two (or all three)
|
||||
|
|
@ -525,6 +549,10 @@ two-party comparison, interval, or cuckoo packing, on top of those spines.
|
|||
|
||||
## Information-theoretic 3-server DPF {#it_dpf3}
|
||||
|
||||
\htmlonly
|
||||
<div class="eli5"><b>ELI5.</b> There is no PRG tree. For this domain each key is an additive share of a 256-word table. The three shares sum to beta at alpha and to zero elsewhere. A PIR answer is three inner products with the database; those three dots sum to the record.</div>
|
||||
\endhtmlonly
|
||||
|
||||
`make_it_dpf3(α, β)` ([ePrint 2023/028](@ref bib_itdpf)) is a different object from
|
||||
`make_dpf3`. Each of three parties holds an additive share of the
|
||||
characteristic vector on `{0..255}`; the **sum** of all three
|
||||
|
|
@ -573,7 +601,13 @@ claimed speedup over dealer keygen or over Half-Tree §5.2.
|
|||
<div class="tabbed">
|
||||
|
||||
- <b class="tab-title">eval_dpf3_point.cpp</b> \include{cpp} evaluation/eval_dpf3_point.cpp
|
||||
|
||||
- <b class="tab-title">eval_dpf3_doerner_shelat.cpp</b> \include{cpp} evaluation/eval_dpf3_doerner_shelat.cpp
|
||||
|
||||
- <b class="tab-title">eval_dpf3_cmp_ic.cpp</b> \include{cpp} evaluation/eval_dpf3_cmp_ic.cpp
|
||||
|
||||
</div>
|
||||
|
||||
\htmlonly
|
||||
<div class="tldr"><b>TL;DR.</b> eval_point is one path. An interval costs the path plus the length of the range. A full domain costs the size of the domain; an inner product does that walk and keeps only the accumulator. Wildcard assign and an updatable rewrite patch the leaf and do not depend on the depth. Three-party eval is two walks and a short field open. The information-theoretic key is a 256-word share, not a walk.</div>
|
||||
\endhtmlonly
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue