Publish a scannable manual and a bibliography that links each paper back to the pages that use it.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-26 23:51:06 -06:00
parent cf8054a0b3
commit 695f8e84f7
45 changed files with 4848 additions and 338 deletions

View file

@ -5,7 +5,8 @@ A point-programmable vector commitment binds a vector
after the commitment is published.
`n` is a power of two, the bit length of the input type, and at most
2^16. `s` is the `Width` parameter, from 1 to 64.
2^20, because evaluation stores one entry per domain point. `s` is
the `Width` parameter, from 1 to 64.
The manual construction is `dpf::ppvc`. `dpf::k_ppvc<K, ...>` is `K`
independent copies of that object.
@ -64,6 +65,12 @@ exactly one place where the two keys disagree, at the recorded index,
with payload 1.
`audit` expands a seed and accepts when the published commitment matches
that expansion and the replica is well formed.
When many replica seeds sit as leaves of a GGM tree, the audit opening of
the pool is a [`dpf::pprf_copath`](@ref dpf/pprf.hpp) built by
`dpf::puncture(master, live…, /*program_hidden=*/false)`: every audited
leaf re-expands with `dpf::pprf_eval`, and a live seed is never among the
published nodes. Sampling the audit set and combining live copies stay in
the protocol, not in this library.
`k_ppvc` asks for the same checks on every copy, and for distinct hidden
indices. `combine_rotated` adds the rotated vectors in `Z/2^s Z`.
@ -79,7 +86,6 @@ The generator is `dpf::prg::aes128` unless another 128-bit PRG is named.
**Try**\n
@ref mwe/ppvc.cpp
Naor's string commitment is Moni Naor, "Bit Commitment Using
Pseudorandomness," Journal of Cryptology 4(2), 1991, pp. 151–158.
Naor's string commitment is Moni Naor, [Bit Commitment Using Pseudorandomness](@ref bib_naor), Journal of Cryptology 1991.
The point keys are the Boyle–Gilboa–Ishai construction named in
[DPF basics](@ref point_functions).