Publish a scannable manual and a bibliography that links each paper back to the pages that use it.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-26 23:51:06 -06:00
parent cf8054a0b3
commit 695f8e84f7
45 changed files with 4848 additions and 338 deletions

View file

@ -1,34 +1,38 @@
# Introduction
\htmlonly
<p class="hero-lead"><code>libdpf++</code> is a header-only C++17 library of distributed point functions: short keys that hide one secret index, then answer at public points as secret shares.</p>
<h2 id="features">What it does</h2>
<div class="feature-grid">
<a class="feature-card" href="verifiability.html"><span class="feature-kicker">Proofs</span><strong>Verifiability &amp; authenticity</strong><p>Honest correction seeds, a weight-1 sketch, and MACs on the leaves, on the same walk.</p></a>
<a class="feature-card" href="programmability.html"><span class="feature-kicker">Late binding</span><strong>Programmability</strong><p>Fill the index or the payload after the key exists. Rewrite an updatable leaf in place.</p></a>
<a class="feature-card" href="comparisons.html"><span class="feature-kicker">Predicates</span><strong>Comparisons &amp; ranges</strong><p>Less-than, equality, interval containment, and blocked checks, as keys.</p></a>
<a class="feature-card" href="multipoint_keys.html"><span class="feature-kicker">Many secrets</span><strong>Multipoint keys</strong><p>Pack many secret points into one cuckoo key. One batched proof covers the set.</p></a>
<a class="feature-card" href="multiparty.html"><span class="feature-kicker">Three parties</span><strong>Multiparty &amp; 3-server</strong><p>Any two of three open a Shamir key. Or an information-theoretic three-server DPF.</p></a>
<a class="feature-card" href="dealer_free.html"><span class="feature-kicker">No dealer</span><strong>Dealer-free keygen</strong><p>The parties already share the index. Doerner–Shelat, geneval, and IKNP finish the key.</p></a>
<a class="feature-card" href="beaver_triples.html"><span class="feature-kicker">Multiplication</span><strong>Beaver triples</strong><p>Authenticated products on leaf shares, including the ABY2.0 MAC check.</p></a>
<a class="feature-card" href="jet_and_ring.html"><span class="feature-kicker">After the offset</span><strong>Grotto</strong><p>Jets, polynomials, carry, and exact ring changes once a public offset is open.</p></a>
<a class="feature-card" href="ppvc_manual.html"><span class="feature-kicker">Commitments</span><strong>Programmable vectors</strong><p>Bind a vector, then open one hidden coordinate or the sum.</p></a>
<a class="feature-card" href="applications.html"><span class="feature-kicker">Protocols</span><strong>Application sketches</strong><p>The DPF step of Duoram, keyword PIR, PSI, Prio, LLAMA, and the rest.</p></a>
</div>
\endhtmlonly
## Synopsis {#synopsis}
## A complete program {#first_program}
`libdpf++` is a fast and extensible, header-only C++17 implementation of
`(2,2)-`*distributed point functions* (or *DPFs*). In addition to core DPF
functionality, `libdpf++` provides a plethora of data structures, helper
functions, and syntactic sugar designed to facilitate seamless integration
into higher-level cryptographic protocols and primitives. With its focus on
speed and ease of use, `libdpf++` is an ideal building block for implementing
private information retrieval (PIR), secure multiparty computation (MPC),
zero-knowledge arguments, anonymous messaging, and more.
Leaf shares are subtractive. `reconstruct` is `share0 - share1`.
The same program is `examples/mwe/point.cpp`.
More programs are on [Pick a construction](@ref which_dpf) and [Code examples](@ref listings).
## Features {#features}
\htmlonly
<pre class="fragment">#include "dpf.hpp"
- <i class="fa-solid fa-right-from-bracket"></i> input types
- <i class="fa-solid fa-right-to-bracket"></i> output types
- <i class="fa-solid fa-shuffle"></i> wildcards
- <i class="fa-brands fa-pagelines"></i> multiple leaves
- <i class="fa-solid fa-ellipsis"></i> evaluation types
- <i class="fa-solid fa-memory"></i> memoizers
- <i class="fa-solid fa-file-lines"></i> json serialization
- <i class="fa-solid fa-route"></i> asynchronous I/O
- <i class="fa-solid fa-fingerprint"></i> [point-programmable vector commitments](@ref ppvc_manual)
const std::uint8_t alpha = 42;
const std::uint64_t beta = 7;
auto [k0, k1] = dpf::make_dpf(alpha, beta);
## Credits {#credits}
const std::uint64_t at = dpf::reconstruct(
*dpf::eval_point(k0, alpha),
*dpf::eval_point(k1, alpha));
// at == 7; any other public point opens to 0
- Adithya Vadapalli (IIT Kanpur)
- Kyle Storrier (UCalgary)
- Allan Lyons (UCalgary)
## Disclaimer {#disclaimer}
We bet you $50 that there is at least one security bug in this code base. If you are you use this code, it is on you to verify that bug does not cross any of the same code paths as you.
// c++ -std=c++17 -march=native -I include -I thirdparty examples/mwe/point.cpp
</pre>
\endhtmlonly