\htmlonly

libdpf++ is a header-only C++17 library of distributed point functions: short keys that hide one secret index, then answer at public points as secret shares. The same tree ships a TLS party mesh, round scheduling, MPC on those leaf shares, leveled run logs, and paper-cost statistics — so readers do not have to dig the API to find them.

What it does

ProofsVerifiability & authenticity

Honest correction seeds, a weight-1 sketch, and MACs on the leaves, on the same walk.

Late bindingProgrammability

Fill the index or the payload after the key exists. Rewrite an updatable leaf in place.

PredicatesComparisons & ranges

Less-than, equality, interval containment, and blocked checks, as keys.

Many secretsMultipoint keys

Pack many secret points into one cuckoo key. One batched proof covers the set.

Three partiesMultiparty & 3-server

Any two of three open a Shamir key. Or an information-theoretic three-server DPF.

No dealerDealer-free keygen

The parties already share the index. Doerner–Shelat, geneval, and IKNP finish the key.

After the offsetGrotto

Jets, polynomials, carry, and exact ring changes once a public offset is open. Several LUTs share one comparison.

CommitmentsProgrammable vectors

Bind a vector, then open one hidden coordinate or the sum.

SketchesApplication sketches

The DPF step of Duoram, keyword PIR, PSI, Prio, LLAMA, and the rest.

Around the keys

Live parties, composition, MPC on leaf shares, logging, and statistics — first-class, not buried in the reference.

LinksNetwork & party mesh

TLS 1.3 party sessions, trio mesh, RoundSink rounds, lanes, and reconnect.

ScheduleProtocol composition

FSS walks next to Beaver opens on one RoundSink plan, with explicit reshares.

MultiplicationBeaver triples

Authenticated products on leaf shares, including the ABY2.0 MAC check.

SharesArithmetic share runtime

edaBits, truncate, share compare, matmul, and hidden shuffle beside FSS.

CircuitsYao on a leaf

Split a leaf into bits, garble a netlist, share the answer back as a leaf.

ObservabilityLogging & statistics

Leveled run logs, provenance banners, replayable seeds, and CSV wire / PRG / timing breakdowns.

\endhtmlonly ## A complete program {#first_program} Leaf shares are subtractive. `reconstruct` is `share0 - share1`. The same program is `examples/mwe/point.cpp`. More programs are on [Pick a construction](@ref which_dpf) and [Code examples](@ref listings). \htmlonly
#include "dpf.hpp"

const std::uint8_t alpha = 42;
const std::uint64_t beta = 7;
auto [k0, k1] = dpf::make_dpf(alpha, beta);

const std::uint64_t at = dpf::reconstruct(
    *dpf::eval_point(k0, alpha),
    *dpf::eval_point(k1, alpha));
// at == 7; any other public point opens to 0

// c++ -std=c++17 -march=native -I include -I thirdparty examples/mwe/point.cpp
\endhtmlonly