Document the new DPF surfaces in one command set, and test the field, half-tree, and multipoint edges.
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
0d8a5a8131
commit
0dff6df8ed
250 changed files with 12199 additions and 1981 deletions
|
|
@ -50,16 +50,21 @@
|
|||
namespace dpf
|
||||
{
|
||||
|
||||
/// Shares and the correction words opened along the query trie.
|
||||
/// `correction_words[i]` / `correction_advice[i]` match a reusable key at
|
||||
/// @brief Shares and the correction words opened along the query trie.
|
||||
/// @details `correction_words[i]` / `correction_advice[i]` match a reusable key at
|
||||
/// the same target for every `i < live_levels`. `leaf_live` means the
|
||||
/// target's leaf was in the trie, so `leaf` is that key's leaf word.
|
||||
/// @tparam Output output
|
||||
/// @tparam Leaf leaf
|
||||
template <typename Output, typename Leaf>
|
||||
struct geneval_result
|
||||
{
|
||||
std::vector<Output> party0;
|
||||
std::vector<Output> party1;
|
||||
HEDLEY_PRAGMA(GCC diagnostic push)
|
||||
HEDLEY_PRAGMA(GCC diagnostic ignored "-Wignored-attributes")
|
||||
std::vector<simde__m128i, aligned_allocator<simde__m128i>> correction_words;
|
||||
HEDLEY_PRAGMA(GCC diagnostic pop)
|
||||
std::vector<uint8_t> correction_advice;
|
||||
std::size_t live_levels = 0;
|
||||
bool leaf_live = false;
|
||||
|
|
@ -88,8 +93,11 @@ T geneval_flipped(T x)
|
|||
return x;
|
||||
}
|
||||
|
||||
/// Leaf-node id of an already MSB-flipped input. The id is the high
|
||||
/// @brief Leaf-node id of an already MSB-flipped input. The id is the high
|
||||
/// `depth` bits; the low `lg(outputs_per_leaf)` bits select the lane.
|
||||
/// @tparam Dpf dpf
|
||||
/// @param x the `x`
|
||||
/// @return Leaf-node id of an already MSB-flipped input
|
||||
template <typename Dpf>
|
||||
uint64_t geneval_leaf_id(typename Dpf::input_type x)
|
||||
{
|
||||
|
|
@ -134,9 +142,9 @@ template <typename InteriorPRG,
|
|||
typename OutputT,
|
||||
typename RootSampler,
|
||||
typename PadRng>
|
||||
auto geneval_run(bool arith, InputT x0, InputT x1,
|
||||
auto geneval_run(bool arith, bool arith_out, InputT x0, InputT x1,
|
||||
const std::vector<InputT> & queries, RootSampler & root_sampler,
|
||||
PadRng & pads, OutputT y)
|
||||
PadRng & pads, OutputT y0, OutputT y1 = OutputT{})
|
||||
{
|
||||
static_assert(std::is_integral_v<InputT>,
|
||||
"geneval input shares are an integral domain");
|
||||
|
|
@ -147,7 +155,11 @@ auto geneval_run(bool arith, InputT x0, InputT x1,
|
|||
|
||||
using dpf_type = utils::dpf_type_t<InteriorPRG, ExteriorPRG, InputT, OutputT>;
|
||||
using node = typename dpf_type::interior_node;
|
||||
HEDLEY_PRAGMA(GCC diagnostic push)
|
||||
HEDLEY_PRAGMA(GCC diagnostic ignored "-Wignored-attributes")
|
||||
using leaf_node = leaf_node_t<node, OutputT>;
|
||||
HEDLEY_PRAGMA(GCC diagnostic pop)
|
||||
using outputs_tuple = std::tuple<OutputT>;
|
||||
constexpr std::size_t depth = dpf_type::depth;
|
||||
|
||||
if (queries.empty())
|
||||
|
|
@ -183,8 +195,16 @@ auto geneval_run(bool arith, InputT x0, InputT x1,
|
|||
|
||||
constexpr auto to_int = utils::to_integral_type<InputT>{};
|
||||
|
||||
const node root0 = dpf::unset_lo_bit(static_cast<node>(root_sampler()));
|
||||
const node root1 = dpf::set_lo_bit(static_cast<node>(root_sampler()));
|
||||
using tree = dpf::tree_traits<InteriorPRG>;
|
||||
HEDLEY_PRAGMA(GCC diagnostic push)
|
||||
HEDLEY_PRAGMA(GCC diagnostic ignored "-Wignored-attributes")
|
||||
node roots[2];
|
||||
HEDLEY_PRAGMA(GCC diagnostic pop)
|
||||
tree::root_init(roots, [&]() -> node {
|
||||
return static_cast<node>(root_sampler());
|
||||
});
|
||||
const node root0 = roots[0];
|
||||
const node root1 = roots[1];
|
||||
|
||||
struct slot
|
||||
{
|
||||
|
|
@ -195,7 +215,10 @@ auto geneval_run(bool arith, InputT x0, InputT x1,
|
|||
std::vector<slot> frontier;
|
||||
frontier.push_back(slot{0, root0, root1});
|
||||
|
||||
HEDLEY_PRAGMA(GCC diagnostic push)
|
||||
HEDLEY_PRAGMA(GCC diagnostic ignored "-Wignored-attributes")
|
||||
geneval_result<OutputT, leaf_node> result;
|
||||
HEDLEY_PRAGMA(GCC diagnostic pop)
|
||||
std::memset(&result.leaf, 0, sizeof(result.leaf));
|
||||
result.correction_words.reserve(depth);
|
||||
result.correction_advice.reserve(depth);
|
||||
|
|
@ -207,6 +230,7 @@ auto geneval_run(bool arith, InputT x0, InputT x1,
|
|||
const uint8_t bit0 = static_cast<uint8_t>(!!(to_int(mask) & to_int(x0c)));
|
||||
const uint8_t bit1 = static_cast<uint8_t>(!!(to_int(mask) & to_int(x1c)));
|
||||
const uint64_t parent_id = geneval_prefix(secret_leaf, depth, level);
|
||||
const bool is_last = tree::is_last_level(level, depth);
|
||||
|
||||
node L0 = simde_mm_setzero_si128();
|
||||
node R0 = simde_mm_setzero_si128();
|
||||
|
|
@ -225,8 +249,8 @@ auto geneval_run(bool arith, InputT x0, InputT x1,
|
|||
{
|
||||
if (n.id == parent_id)
|
||||
level_live = true;
|
||||
const auto c0 = InteriorPRG::eval01(dpf::unset_lo_2bits(n.s0));
|
||||
const auto c1 = InteriorPRG::eval01(dpf::unset_lo_2bits(n.s1));
|
||||
const auto c0 = tree::expand(n.s0, is_last);
|
||||
const auto c1 = tree::expand(n.s1, is_last);
|
||||
L0 = ds_xor(L0, c0[0]);
|
||||
R0 = ds_xor(R0, c0[1]);
|
||||
L1 = ds_xor(L1, c1[0]);
|
||||
|
|
@ -242,21 +266,42 @@ auto geneval_run(bool arith, InputT x0, InputT x1,
|
|||
auto opened = proto.open_cw(blinds);
|
||||
cw = opened.first;
|
||||
advice = opened.second;
|
||||
if constexpr (tree::is_half_tree)
|
||||
{
|
||||
if (!is_last)
|
||||
advice = 0;
|
||||
}
|
||||
++result.live_levels;
|
||||
}
|
||||
else
|
||||
{
|
||||
still_live = false;
|
||||
cw = pads.block();
|
||||
const uint8_t t0 = static_cast<uint8_t>(pads.bit() & 1u);
|
||||
const uint8_t t1 = static_cast<uint8_t>(pads.bit() & 1u);
|
||||
advice = static_cast<uint8_t>((t1 << 1) | t0);
|
||||
if constexpr (tree::is_half_tree)
|
||||
{
|
||||
if (!is_last)
|
||||
{
|
||||
advice = 0;
|
||||
}
|
||||
else
|
||||
{
|
||||
const uint8_t t0 = static_cast<uint8_t>(pads.bit() & 1u);
|
||||
const uint8_t t1 = static_cast<uint8_t>(pads.bit() & 1u);
|
||||
advice = static_cast<uint8_t>((t1 << 1) | t0);
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
const uint8_t t0 = static_cast<uint8_t>(pads.bit() & 1u);
|
||||
const uint8_t t1 = static_cast<uint8_t>(pads.bit() & 1u);
|
||||
advice = static_cast<uint8_t>((t1 << 1) | t0);
|
||||
}
|
||||
}
|
||||
result.correction_words.push_back(cw);
|
||||
result.correction_advice.push_back(advice);
|
||||
|
||||
const node cw0 = dpf::set_lo_bit(cw, advice & 1u);
|
||||
const node cw1 = dpf::set_lo_bit(cw, (advice >> 1) & 1u);
|
||||
const node cw0 = tree::pack_cw(cw, advice, false, is_last);
|
||||
const node cw1 = tree::pack_cw(cw, advice, true, is_last);
|
||||
const std::size_t child_bits = level + 1;
|
||||
std::vector<slot> next;
|
||||
next.reserve(exps.size() * 2);
|
||||
|
|
@ -294,11 +339,23 @@ auto geneval_run(bool arith, InputT x0, InputT x1,
|
|||
}
|
||||
if (on == nullptr)
|
||||
throw std::logic_error("geneval: secret leaf missing from trie");
|
||||
const bool sign0 = dpf::get_lo_bit(on->s0);
|
||||
auto built = dpf::make_leaves<ExteriorPRG>(alpha,
|
||||
dpf::unset_lo_2bits(on->s0), dpf::unset_lo_2bits(on->s1), sign0,
|
||||
std::size_t{0}, y);
|
||||
result.leaf = std::get<0>(built.first.first);
|
||||
if (arith_out)
|
||||
{
|
||||
const uint8_t t0 = static_cast<uint8_t>(dpf::get_lo_bit(on->s0));
|
||||
const uint8_t t1 = static_cast<uint8_t>(dpf::get_lo_bit(on->s1));
|
||||
const std::size_t lane = static_cast<std::size_t>(to_int(alpha));
|
||||
result.leaf = proto.template open_arith_leaf<ExteriorPRG, 0, outputs_tuple>(
|
||||
dpf::unset_lo_2bits(on->s0), dpf::unset_lo_2bits(on->s1), t0, t1,
|
||||
y0, y1, std::size_t{0}, lane);
|
||||
}
|
||||
else
|
||||
{
|
||||
const bool sign0 = dpf::get_lo_bit(on->s0);
|
||||
auto built = dpf::make_leaves<ExteriorPRG>(alpha,
|
||||
dpf::unset_lo_2bits(on->s0), dpf::unset_lo_2bits(on->s1), sign0,
|
||||
std::size_t{0}, y0);
|
||||
result.leaf = std::get<0>(built.first.first);
|
||||
}
|
||||
}
|
||||
|
||||
result.party0.reserve(flipped.size());
|
||||
|
|
@ -326,6 +383,20 @@ auto geneval_run(bool arith, InputT x0, InputT x1,
|
|||
return result;
|
||||
}
|
||||
|
||||
template <typename InteriorPRG,
|
||||
typename ExteriorPRG,
|
||||
typename InputT,
|
||||
typename OutputT,
|
||||
typename RootSampler,
|
||||
typename PadRng>
|
||||
auto geneval_run(bool arith, InputT x0, InputT x1,
|
||||
const std::vector<InputT> & queries, RootSampler & root_sampler,
|
||||
PadRng & pads, OutputT y)
|
||||
{
|
||||
return geneval_run<InteriorPRG, ExteriorPRG>(arith, false, x0, x1, queries,
|
||||
root_sampler, pads, y, OutputT{});
|
||||
}
|
||||
|
||||
template <typename InteriorPRG,
|
||||
typename ExteriorPRG,
|
||||
typename InputT,
|
||||
|
|
@ -335,8 +406,8 @@ template <typename InteriorPRG,
|
|||
auto geneval_run(InputT x0, InputT x1, const std::vector<InputT> & queries,
|
||||
RootSampler & root_sampler, PadRng & pads, OutputT y)
|
||||
{
|
||||
return geneval_run<InteriorPRG, ExteriorPRG>(false, x0, x1, queries,
|
||||
root_sampler, pads, y);
|
||||
return geneval_run<InteriorPRG, ExteriorPRG>(false, false, x0, x1, queries,
|
||||
root_sampler, pads, y, OutputT{});
|
||||
}
|
||||
|
||||
template <typename InputT>
|
||||
|
|
@ -400,7 +471,26 @@ std::vector<InputT> geneval_inclusive(InputT from, InputT to)
|
|||
|
||||
} // namespace detail
|
||||
|
||||
/// Geneval at one public point. The secret point is `x0 XOR x1`.
|
||||
/// @name Point geneval
|
||||
/// @tparam InteriorPRG PRG that expands interior nodes. Defaults to `dpf::prg::aes128`
|
||||
/// @tparam ExteriorPRG PRG that expands the root. Defaults to `InteriorPRG`
|
||||
/// @tparam InputT input domain type
|
||||
/// @tparam OutputT output type
|
||||
/// @tparam RootSampler sampler for the Doerner–Shelat root seed
|
||||
/// @tparam PadRng pad stream for the Doerner–Shelat protocol
|
||||
/// @param x0 party 0's share of the secret point
|
||||
/// @param x1 party 1's share of the secret point
|
||||
/// @param query the query point
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @{
|
||||
|
||||
/// @brief The secret point is `x0 XOR x1`.
|
||||
/// @param x0 party 0's share of the secret point
|
||||
/// @param x1 party 1's share of the secret point
|
||||
/// @param query the query point
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param y the payload
|
||||
/// @return the opened shares and correction words
|
||||
template <typename InteriorPRG = dpf::prg::aes128,
|
||||
typename ExteriorPRG = InteriorPRG,
|
||||
typename InputT,
|
||||
|
|
@ -411,11 +501,17 @@ HEDLEY_WARN_UNUSED_RESULT
|
|||
auto geneval_point(InputT x0, InputT x1, InputT query,
|
||||
ds_randomness<RootSampler, PadRng> rng, OutputT y)
|
||||
{
|
||||
return detail::geneval_run<InteriorPRG, ExteriorPRG>(false, x0, x1,
|
||||
std::vector<InputT>{query}, rng.root, rng.pad, y);
|
||||
return detail::geneval_run<InteriorPRG, ExteriorPRG>(false, false, x0, x1,
|
||||
std::vector<InputT>{query}, rng.root, rng.pad, y, OutputT{});
|
||||
}
|
||||
|
||||
/// Geneval at one public point. The secret point is `x0 + x1`.
|
||||
/// @brief The secret point is `x0 + x1`.
|
||||
/// @param x0 party 0's share of the secret point
|
||||
/// @param x1 party 1's share of the secret point
|
||||
/// @param query the query point
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param y the payload
|
||||
/// @return the opened shares and correction words
|
||||
template <typename InteriorPRG = dpf::prg::aes128,
|
||||
typename ExteriorPRG = InteriorPRG,
|
||||
typename InputT,
|
||||
|
|
@ -426,11 +522,70 @@ HEDLEY_WARN_UNUSED_RESULT
|
|||
auto geneval_point(arith_input_t, InputT x0, InputT x1, InputT query,
|
||||
ds_randomness<RootSampler, PadRng> rng, OutputT y)
|
||||
{
|
||||
return detail::geneval_run<InteriorPRG, ExteriorPRG>(true, x0, x1,
|
||||
std::vector<InputT>{query}, rng.root, rng.pad, y);
|
||||
return detail::geneval_run<InteriorPRG, ExteriorPRG>(true, false, x0, x1,
|
||||
std::vector<InputT>{query}, rng.root, rng.pad, y, OutputT{});
|
||||
}
|
||||
|
||||
/// Geneval on the inclusive interval `[from, to]`.
|
||||
/// @brief XOR-index shares, additively shared payload `y0 + y1 = β`.
|
||||
/// @param x0 party 0's share of the secret point
|
||||
/// @param x1 party 1's share of the secret point
|
||||
/// @param query the query point
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param y0 party 0's share of the payload
|
||||
/// @param y1 party 1's share of the payload
|
||||
/// @return the opened shares and correction words
|
||||
template <typename InteriorPRG = dpf::prg::aes128,
|
||||
typename ExteriorPRG = InteriorPRG,
|
||||
typename InputT,
|
||||
typename OutputT,
|
||||
typename RootSampler,
|
||||
typename PadRng>
|
||||
HEDLEY_WARN_UNUSED_RESULT
|
||||
auto geneval_point(arith_output_t, InputT x0, InputT x1, InputT query,
|
||||
ds_randomness<RootSampler, PadRng> rng, OutputT y0, OutputT y1)
|
||||
{
|
||||
return detail::geneval_run<InteriorPRG, ExteriorPRG>(false, true, x0, x1,
|
||||
std::vector<InputT>{query}, rng.root, rng.pad, y0, y1);
|
||||
}
|
||||
|
||||
/// @brief Additive index and additive payload shares.
|
||||
/// @param x0 party 0's share of the secret point
|
||||
/// @param x1 party 1's share of the secret point
|
||||
/// @param query the query point
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param y0 party 0's share of the payload
|
||||
/// @param y1 party 1's share of the payload
|
||||
/// @return the opened shares and correction words
|
||||
template <typename InteriorPRG = dpf::prg::aes128,
|
||||
typename ExteriorPRG = InteriorPRG,
|
||||
typename InputT,
|
||||
typename OutputT,
|
||||
typename RootSampler,
|
||||
typename PadRng>
|
||||
HEDLEY_WARN_UNUSED_RESULT
|
||||
auto geneval_point(arith_input_t, arith_output_t, InputT x0, InputT x1,
|
||||
InputT query, ds_randomness<RootSampler, PadRng> rng, OutputT y0, OutputT y1)
|
||||
{
|
||||
return detail::geneval_run<InteriorPRG, ExteriorPRG>(true, true, x0, x1,
|
||||
std::vector<InputT>{query}, rng.root, rng.pad, y0, y1);
|
||||
}
|
||||
|
||||
/// @}
|
||||
|
||||
/// @brief Geneval on the inclusive interval `[from, to]`.
|
||||
/// @tparam InteriorPRG PRG that expands interior nodes. Defaults to `dpf::prg::aes128`
|
||||
/// @tparam ExteriorPRG PRG that expands the root. Defaults to `InteriorPRG`
|
||||
/// @tparam InputT input domain type
|
||||
/// @tparam OutputT output type
|
||||
/// @tparam RootSampler sampler for the Doerner–Shelat root seed
|
||||
/// @tparam PadRng pad stream for the Doerner–Shelat protocol
|
||||
/// @param x0 the `x0`
|
||||
/// @param x1 the `x1`
|
||||
/// @param from the inclusive start of the range
|
||||
/// @param to the `to`
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param y the `y`
|
||||
/// @return Geneval on the inclusive interval `[from, to]`
|
||||
template <typename InteriorPRG = dpf::prg::aes128,
|
||||
typename ExteriorPRG = InteriorPRG,
|
||||
typename InputT,
|
||||
|
|
@ -459,7 +614,18 @@ auto geneval_interval(arith_input_t, InputT x0, InputT x1, InputT from,
|
|||
detail::geneval_inclusive(from, to), rng.root, rng.pad, y);
|
||||
}
|
||||
|
||||
/// Geneval on the whole domain. Refuses a domain above 2^20 inputs.
|
||||
/// @brief Geneval on the whole domain. Refuses a domain above 2^20 inputs.
|
||||
/// @tparam InteriorPRG PRG that expands interior nodes. Defaults to `dpf::prg::aes128`
|
||||
/// @tparam ExteriorPRG PRG that expands the root. Defaults to `InteriorPRG`
|
||||
/// @tparam InputT input domain type
|
||||
/// @tparam OutputT output type
|
||||
/// @tparam RootSampler sampler for the Doerner–Shelat root seed
|
||||
/// @tparam PadRng pad stream for the Doerner–Shelat protocol
|
||||
/// @param x0 the `x0`
|
||||
/// @param x1 the `x1`
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param y the `y`
|
||||
/// @return Geneval on the whole domain
|
||||
template <typename InteriorPRG = dpf::prg::aes128,
|
||||
typename ExteriorPRG = InteriorPRG,
|
||||
typename InputT,
|
||||
|
|
@ -488,7 +654,21 @@ auto geneval_full(arith_input_t, InputT x0, InputT x1,
|
|||
detail::geneval_full_domain<InputT>(), rng.root, rng.pad, y);
|
||||
}
|
||||
|
||||
/// Geneval on a public sequence, in the order given.
|
||||
/// @brief Geneval on a public sequence, in the order given.
|
||||
/// @tparam InteriorPRG PRG that expands interior nodes. Defaults to `dpf::prg::aes128`
|
||||
/// @tparam ExteriorPRG PRG that expands the root. Defaults to `InteriorPRG`
|
||||
/// @tparam InputT input domain type
|
||||
/// @tparam OutputT output type
|
||||
/// @tparam RootSampler sampler for the Doerner–Shelat root seed
|
||||
/// @tparam PadRng pad stream for the Doerner–Shelat protocol
|
||||
/// @tparam ForwardIterator forward iterator type
|
||||
/// @param x0 the `x0`
|
||||
/// @param x1 the `x1`
|
||||
/// @param begin the iterator to the first query
|
||||
/// @param end the iterator past the last query
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param y the `y`
|
||||
/// @return Geneval on a public sequence, in the order given
|
||||
template <typename InteriorPRG = dpf::prg::aes128,
|
||||
typename ExteriorPRG = InteriorPRG,
|
||||
typename InputT,
|
||||
|
|
@ -522,14 +702,17 @@ auto geneval_sequence(arith_input_t, InputT x0, InputT x1,
|
|||
std::move(qs), rng.root, rng.pad, y);
|
||||
}
|
||||
|
||||
/// Opened comparison key material and one prefix share per endpoint.
|
||||
/// `live_levels` is the full depth: a comparison value word depends on the
|
||||
/// @brief Opened comparison key material and one prefix share per endpoint.
|
||||
/// @details `live_levels` is the full depth: a comparison value word depends on the
|
||||
/// secret path at every level, so there is no early dummy-word tail.
|
||||
struct geneval_cmp_result
|
||||
{
|
||||
std::vector<uint64_t> party0;
|
||||
std::vector<uint64_t> party1;
|
||||
HEDLEY_PRAGMA(GCC diagnostic push)
|
||||
HEDLEY_PRAGMA(GCC diagnostic ignored "-Wignored-attributes")
|
||||
std::vector<simde__m128i, aligned_allocator<simde__m128i>> correction_words;
|
||||
HEDLEY_PRAGMA(GCC diagnostic pop)
|
||||
std::vector<uint8_t> correction_advice;
|
||||
std::vector<uint64_t> value_cw;
|
||||
std::vector<uint64_t> tail_cw;
|
||||
|
|
@ -540,10 +723,30 @@ struct geneval_cmp_result
|
|||
std::size_t live_levels = 0;
|
||||
};
|
||||
|
||||
/// Doerner–Shelat comparison geneval. `x0 XOR x1` is the secret point, in the
|
||||
/// same share convention as `geneval_point`. `spec` is an `lt` / `leq` / `gt`
|
||||
/// / `geq` pack. Each endpoint is returned in order as the two parties'
|
||||
/// `eval_point(cmp, ...)` shares. An empty range opens nothing.
|
||||
/// @name Comparison geneval
|
||||
/// @tparam InputT input domain type
|
||||
/// @tparam ForwardIterator forward iterator type
|
||||
/// @tparam RootSampler sampler for the Doerner–Shelat root seed
|
||||
/// @tparam PadRng pad stream for the Doerner–Shelat protocol
|
||||
/// @param x0 party 0's share of the secret point
|
||||
/// @param x1 party 1's share of the secret point
|
||||
/// @param begin the iterator to the first query
|
||||
/// @param end the iterator past the last query
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @return the opened comparison shares
|
||||
/// @{
|
||||
|
||||
/// @brief `x0 XOR x1` is the secret point, in the same share convention as
|
||||
/// `geneval_point`. `spec` is an `lt` / `leq` / `gt` / `geq` pack. Each
|
||||
/// endpoint is returned in order as the two parties' `eval_point(cmp, ...)`
|
||||
/// shares. An empty range opens nothing.
|
||||
/// @tparam Spec comparison or interval specification
|
||||
/// @param x0 party 0's share of the secret point
|
||||
/// @param x1 party 1's share of the secret point
|
||||
/// @param begin the iterator to the first query
|
||||
/// @param end the iterator past the last query
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param spec the comparison specification
|
||||
template <typename InputT,
|
||||
typename ForwardIterator,
|
||||
typename RootSampler,
|
||||
|
|
@ -597,7 +800,14 @@ geneval_cmp_result geneval_cmp(InputT x0, InputT x1,
|
|||
return out;
|
||||
}
|
||||
|
||||
/// Comparison geneval with additive shares of the point (`x0 + x1`).
|
||||
/// @brief Additive shares of the point (`x0 + x1`).
|
||||
/// @tparam Spec comparison or interval specification
|
||||
/// @param x0 party 0's share of the secret point
|
||||
/// @param x1 party 1's share of the secret point
|
||||
/// @param begin the iterator to the first query
|
||||
/// @param end the iterator past the last query
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param spec the comparison specification
|
||||
template <typename InputT,
|
||||
typename ForwardIterator,
|
||||
typename RootSampler,
|
||||
|
|
@ -651,7 +861,13 @@ geneval_cmp_result geneval_cmp(arith_input_t, InputT x0, InputT x1,
|
|||
return out;
|
||||
}
|
||||
|
||||
/// `gt(beta)` comparison geneval. `if_false` is 0.
|
||||
/// @brief `gt(beta)` on XOR shares of the point. `if_false` is 0.
|
||||
/// @param x0 party 0's share of the secret point
|
||||
/// @param x1 party 1's share of the secret point
|
||||
/// @param begin the iterator to the first query
|
||||
/// @param end the iterator past the last query
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param beta the true payload
|
||||
template <typename InputT,
|
||||
typename ForwardIterator,
|
||||
typename RootSampler,
|
||||
|
|
@ -665,6 +881,13 @@ geneval_cmp_result geneval_cmp(InputT x0, InputT x1,
|
|||
std::move(rng), dpf::gt(beta));
|
||||
}
|
||||
|
||||
/// @brief `gt(beta)` on additive shares of the point. `if_false` is 0.
|
||||
/// @param x0 party 0's share of the secret point
|
||||
/// @param x1 party 1's share of the secret point
|
||||
/// @param begin the iterator to the first query
|
||||
/// @param end the iterator past the last query
|
||||
/// @param rng the Doerner–Shelat randomness tapes
|
||||
/// @param beta the true payload
|
||||
template <typename InputT,
|
||||
typename ForwardIterator,
|
||||
typename RootSampler,
|
||||
|
|
@ -678,6 +901,8 @@ geneval_cmp_result geneval_cmp(arith_input_t, InputT x0, InputT x1,
|
|||
std::move(rng), dpf::gt(beta));
|
||||
}
|
||||
|
||||
/// @}
|
||||
|
||||
} // namespace dpf
|
||||
|
||||
#endif // LIBDPF_INCLUDE_DPF_GENEVAL_HPP__
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue