/// \page ideal_functionalities Ideal functionalities /// /// Each MPC protocol's file page carries one figure: the ideal functionality /// that protocol realizes. The figure states the parties, the inputs, the /// outputs, and what is revealed. A protocol may open a masked value or a /// public offset; that appears in the figure only when the parties learn it. /// /// \htmlonly ///
ELI5. An ideal functionality is the specification the protocol is measured against: who holds what, what goes in, what comes out, and which values become public.
/// \endhtmlonly /// /// /// ## Sharing /// /// /// - \ref secret_share.hpp "F_Open" /// - \ref shamir3.hpp "F_Shamir" /// /// ## Dealer keys /// /// /// - \ref dpf_key.hpp "F_DPF" /// - \ref incremental.hpp "F_IDPF" /// - \ref grow.hpp "F_Grow" /// - \ref wildcard.hpp "F_Assign" /// - \ref dcf.hpp "F_DCF" /// - \ref blocked_dcf.hpp "F_BDCF" /// - \ref interval.hpp "F_IC" /// - \ref multipoint.hpp "F_MPDPF" /// /// ## Two-party generation and evaluation /// /// /// - \ref iknp.hpp "F_IKNP" /// - \ref doerner_shelat.hpp "F_DS" /// - \ref grow_ds.hpp "F_GrowDS" /// - \ref geneval.hpp "F_GenEval" /// - \ref beaver.hpp "F_Beaver and F_BeaverAuth" /// - \ref yao.hpp "F_Yao" /// - \ref yao_share.hpp "F_YaoShare" /// - \ref constrained_cmp.hpp "F_CCMP" /// - \ref verifiable.hpp "F_VDPF, F_Sketch, and F_OblivHash" /// /// ## Three evaluators /// /// /// - \ref dpf3.hpp "F_DPF3" /// - \ref dpf3_ds.hpp "F_DPF3DS" /// - \ref dpf3_cmp.hpp "F_DPF3CMP" /// - \ref dpf3_multipoint.hpp "F_DPF3MP" /// /// ## Offset corrections /// /// /// - \ref offset_horner.hpp "F_Horner" /// - \ref offset_poly.hpp "F_Poly" /// - \ref offset_jet.hpp "F_Jet" /// - \ref ring_switch.hpp "F_Switch" /// - \ref offset_repr.hpp "F_Repr" /// - \ref offset_twist.hpp "F_Twist" /// - \ref carry.hpp "F_Carry" /// @file dpf/secret_share.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Open" /// digraph F_Open { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Open
Parties. P0 and P1. Each holds one share.
Input. An additive share, a subtractive share, or an XOR share.
Output. Both parties receive the opened value:
additive is share0 + share1, subtractive is share0 - share1,
XOR is share0 XOR share1.
Leakage. That opened value, and nothing else.
/// >]; /// } /// \enddot /// @file dpf/shamir3.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Shamir" /// digraph F_Shamir { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Shamir
Parties. Evaluators 1, 2, and 3 over fp61.
Input. A secret s. The dealer samples a uniform slope a.
Output. Party i receives s_i = s + a*i.
Any two parties reconstruct s by Lagrange.
A share embeds into a 61-bit XOR string for the (2,3) point key.
Leakage. One share hides s. Two shares reveal it.
/// >]; /// } /// \enddot /// @file dpf/dpf_key.hpp /// /// @par Ideal functionality /// \dot "Functionality F_DPF" /// digraph F_DPF { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_DPF
Parties. An honest dealer, then evaluators P0 and P1.
Input. A secret point alpha and one or more payloads beta.
A payload may be a wildcard, filled later by F_Assign.
The interior PRG is BGI or Half-Tree. The outputs do not change.
Output. Key k_i to party i.
Eval(x) returns subtractive shares of beta when x = alpha, else 0.
An XOR payload is an XOR share. Several outputs are independent.
Leakage. The keys hide alpha and beta.
Eval of an unassigned wildcard aborts.
/// >]; /// } /// \enddot /// @file dpf/incremental.hpp /// /// @par Ideal functionality /// \dot "Functionality F_IDPF" /// digraph F_IDPF { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_IDPF
Parties. Same dealer and two evaluators as F_DPF.
Input. Secret point alpha.
Each output is placed at a public prefix length.
An optional comparison spec adds an F_DCF channel on the same alpha.
Output. One key per party.
Eval of a prefix slot returns that slot's shares on its programmed domain.
The comparison channel returns F_DCF shares.
Leakage. None beyond those shares. A wildcard slot aborts until F_Assign.
/// >]; /// } /// \enddot /// @file dpf/grow.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Grow" /// digraph F_Grow { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Grow
Parties. An honest dealer holding both F_IDPF keys, then evaluators P0 and P1.
Input. An existing key pair for secret alpha.
/// extend: the next path bit of alpha and specs whose prefixes equal the new depth.
/// add_output: specs whose prefixes are already levels of the key.
/// Optional warm path memoizers supply the on-path seeds (must already be filled).
Output. A new key pair whose type is the old key plus the new material.
/// Earlier correction words, advice bits, leaves, and comparison words are unchanged share for share.
/// Eval of an old slot on the new keys matches the old keys. New slots match F_IDPF for those specs.
Leakage. None beyond the new keys. Specs that need a deeper tree, share a packing group with an old slot, or sit on the wrong level abort.
/// >]; /// } /// \enddot /// @file dpf/grow_ds.hpp /// /// @par Ideal functionality /// \dot "Functionality F_GrowDS" /// digraph F_GrowDS { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_GrowDS
Parties. P0 and P1 hold matching F_IDPF keys and on-path seeds at the frontier.
/// P2 may deal pads and learns nothing. A joint local simulator holds both keys.
Input. XOR shares of alpha, warm path memoizers through the old depth,
/// and the same specs as F_Grow. extend_ds opens one new interior correction word.
/// add_output_ds opens only the new leaf (or comparison) material.
Output. The same grown keys F_Grow would return for that alpha and those specs,
/// with the same roots and the same public correction words as a dealer extend / add_output.
Leakage. Default: none beyond the keys. P2 never sees alpha or payloads.
/// Off-path memoizer leftovers are not a valid plant site for secret outputs.
/// >]; /// } /// \enddot /// @file dpf/wildcard.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Assign" /// digraph F_Assign { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Assign
Parties. P0 and P1, holding keys from F_DPF or F_IDPF.
Input. A payload beta, or shares of beta, for a wildcard slot.
A public delta is applied as given.
A subtractive share is converted with that party's coefficient.
Output. The same keys, now evaluating to shares of beta at alpha.
Alpha does not move.
Leakage. None. Eval before Assign aborts.
/// >]; /// } /// \enddot /// @file dpf/dcf.hpp /// /// @par Ideal functionality /// \dot "Functionality F_DCF" /// digraph F_DCF { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_DCF
Parties. An honest dealer, then evaluators P0 and P1.
Input. Secret point alpha, payloads if_true and if_false,
and a predicate lt, leq, gt, or geq.
A path-paint kind plants one public constant on each sibling subtree.
Output. One key per party.
Eval(x) returns additive shares of if_true when the predicate holds,
and of if_false otherwise.
Leakage. None. The same outputs are realized by F_BDCF.
/// >]; /// } /// \enddot /// @file dpf/blocked_dcf.hpp /// /// @par Ideal functionality /// \dot "Functionality F_BDCF" /// digraph F_BDCF { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_BDCF
Parties. Same dealer and evaluators as F_DCF.
Input. The F_DCF inputs, plus a public checkpoint schedule.
Ring words are stored only at those checkpoints.
A residual tail, when the key sets it, is a table on the node at that height.
Output. Additive shares of the same predicate or path-paint as F_DCF.
Leakage. The schedule is public. It does not reveal alpha.
/// >]; /// } /// \enddot /// @file dpf/interval.hpp /// /// @par Ideal functionality /// \dot "Functionality F_IC" /// digraph F_IC { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_IC
Parties. An honest dealer, then evaluators P0 and P1.
Input. Secret mask r, public bounds p and q,
and payloads if_true and if_false.
Output. One key per party.
Eval(x) returns additive shares of if_true when
p <= (x - r) mod 2^n <= q, and of if_false otherwise.
Leakage. The bounds are public. r and the payloads stay hidden.
/// >]; /// } /// \enddot /// @file dpf/multipoint.hpp /// /// @par Ideal functionality /// \dot "Functionality F_MPDPF" /// digraph F_MPDPF { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_MPDPF
Parties. An honest dealer, then evaluators P0 and P1.
Input. t distinct points and their payloads.
The verifiable tag selects VDPF buckets.
Output. m = O(t) bucket keys on a cuckoo packing with 3 probes.
Eval(x) sums the three probed buckets and matches the sum of the t point functions.
A batched proof is one 2-lambda token.
Leakage. None beyond the output shares and, when requested, the proof.
/// >]; /// } /// \enddot /// @file dpf/iknp.hpp /// /// @par Ideal functionality /// \dot "Functionality F_IKNP" /// digraph F_IKNP { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_IKNP
Parties. P0 and P1. Semi-honest. Base OT is Chou-Orlandi.
Input. sample: both parties pass the same lengths
(bit x block, bit x bit, B2A, correction-word pads).
transfer_labels: the sender holds two 128-bit strings per row;
the receiver holds a choice bit per row.
Output. sample gives each party its share of the pads:
bit x block, bit AND, a daBit, and a correction-word gamma
that hides the peer pad bit.
transfer_labels gives the receiver exactly the chosen string.
The sender's output buffer is cleared. An empty transfer sends nothing.
Leakage. Lengths are public. Choice bits, the unchosen string,
and the peer pad bit stay hidden.
One role_state is one direction; the first call runs the base OT.
/// >]; /// } /// \enddot /// @file dpf/doerner_shelat.hpp /// /// @par Ideal functionality /// \dot "Functionality F_DS" /// digraph F_DS { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_DS
Parties. P0 and P1 hold the point. P2 deals pads and learns nothing.
Input. XOR shares of alpha, or additive shares.
Additive shares are converted by a ripple-carry. The sum is not opened.
Beta is public, or additively shared as leaf-key material without opening the payload.
An optional Reveal flag asks for the encoded point (and, for a packed wildcard, the lane).
Output. Each of P0 and P1 receives the F_DPF or F_DCF key make_dpf would emit
for that alpha, the same roots, and the same beaver coins.
When Reveal is set, the encoded point is an explicit output,
and a packed wildcard also returns its lane. Paint comparisons require Reveal.
Leakage. Default leakage is none beyond the keys.
P2 receives neither the point, the prefix, nor the payload.
The tree prefix, the lane, and a shared payload stay hidden unless Reveal is set.
/// >]; /// } /// \enddot /// @file dpf/geneval.hpp /// /// @par Ideal functionality /// \dot "Functionality F_GenEval" /// digraph F_GenEval { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_GenEval
Parties. P0 and P1. No reusable key is returned.
Input. XOR or additive shares of alpha, a public or shared payload,
and a public query: one point, an interval, a sequence, or the full domain.
Output. Shares of F_DPF on that query.
Leaves are subtractive. Comparison prefixes are additive.
geneval_cmp returns a prefix share at each public endpoint.
The point is not opened. Additive inputs are converted without opening the sum.
Leakage. Evaluators receive the query-trie correction words.
Off-path words are uniform. On-path words match a dealer key and hide the point.
/// >]; /// } /// \enddot /// @file dpf/beaver.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Beaver" /// digraph F_Beaver { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Beaver
Parties. P0 and P1 evaluate. P2 is an honest dealer.
Input. Additive shares of wires, and a public formula:
a polynomial, an inner product, a scale, or a bit-mux.
A later round may reuse a wire. Repeated factors share one blind.
Output. Additive shares of the formula. P2 learns nothing.
Classic triples are the same functionality on fresh wires.
Leakage. None. Opened masks delta = x + lambda are uniform.
/// >]; /// } /// \enddot /// /// \dot "Functionality F_BeaverAuth" /// digraph F_BeaverAuth { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_BeaverAuth
Parties. Same as F_Beaver. A MAC key Delta is fixed before sampling.
Input. The F_Beaver inputs. Every blind, monomial, and value is tagged under Delta.
Output. The same additive shares, together with tag shares.
verify_delta and verify_auth_opening accept only consistent tags.
Leakage. None when the check accepts. A bad tag aborts.
/// >]; /// } /// \enddot /// @file dpf/constrained_cmp.hpp /// /// @par Ideal functionality /// \dot "Functionality F_CCMP" /// digraph F_CCMP { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_CCMP
Parties. P0 holds x0. P1 holds x1.
Input. Positive integers with absolute difference 1.
Each party forms two bits from the low bits of its input.
Output. Both parties receive the bit 1{x0 < x1}.
The bit is one AND of those derived bits.
Leakage. That bit. If the inputs do not differ by one, the protocol aborts.
/// >]; /// } /// \enddot /// @file dpf/verifiable.hpp /// /// @par Ideal functionality /// \dot "Functionality F_VDPF" /// digraph F_VDPF { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_VDPF
Parties. P0 and P1, on keys generated under the verifiable tag.
Input. The F_DPF inputs, plus a public evaluation point.
Output. The F_DPF share, and a 2-lambda proof token from each party.
Verify accepts exactly when the path and the output share match:
correction seeds, the leaf correction word, and comparison value words fold into the token.
Leakage. The accept or reject bit. Nothing else.
A tampered seed, leaf, value word, or proof rejects. A zero token rejects.
/// >]; /// } /// \enddot /// /// \dot "Functionality F_Sketch" /// digraph F_Sketch { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Sketch
Parties. P0 and P1, on an extractable key. Default eval does not fold.
Input. Payload shares written during evaluation,
and caller-chosen fp61 challenges, one per payload.
Output. Subtractive shares of three moments (z1, z2, z3).
sketch_verify accepts when z2^2 = z1*z3 after the shares are opened,
that is, when the opened payloads have at most one nonzero point.
Leakage. The accept or reject bit. A second hot point rejects.
/// >]; /// } /// \enddot /// /// \dot "Functionality F_OblivHash" /// digraph F_OblivHash { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_OblivHash
Parties. P0 and P1. Correlated AND triples come from the dealer tape.
The two-party realization is party/oblivious_hash.hpp.
Input. Each party holds the seed it owns,
and a XOR share of the path prefix. The level is public.
Output. Both parties receive H(s0) XOR H(s1),
the same block as hash_node on the joined prefix and the two seeds.
Leakage. That opened block. The prefix is not opened.
/// >]; /// } /// \enddot /// @file dpf/dpf3.hpp /// /// @par Ideal functionality /// \dot "Functionality F_DPF3" /// digraph F_DPF3 { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_DPF3
Parties. An honest dealer and evaluators 1, 2, and 3.
Input. Secret point alpha and payload beta in fp61.
The updatable tag keeps the leaf writable.
The verifiable and extractable tags select those checks.
Output. One key per evaluator.
Eval(x) is a degree-1 Shamir share of beta when x = alpha, else 0.
Any two parties reconstruct. Update(beta') rewrites the payload and does not move alpha.
Update on a non-updatable key aborts. verify_dpf3 accepts only a consistent triple of proofs.
Leakage. One key hides alpha and beta. A bad proof rejects.
/// >]; /// } /// \enddot /// @file dpf/dpf3_ds.hpp /// /// @par Ideal functionality /// \dot "Functionality F_DPF3DS" /// digraph F_DPF3DS { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_DPF3DS
Parties. Two shareholders of alpha, producing keys for three evaluators.
Input. XOR shares of alpha, after the signed-MSB flip on share 0.
Payload beta in fp61 is a shared input of keygen, not an opened point.
Verifiable, updatable, and extractable select the same options as F_DPF3.
Reveal on a spine is the same optional flag as F_DS.
Output. Three F_DPF3 keys for alpha = x0 XOR x1 and that beta.
Two independent Doerner-Shelat spines carry the Fig. 3 payloads.
Leakage. Neither share alone reveals alpha or beta.
The point and the payload stay shared unless Reveal is set on a spine.
/// >]; /// } /// \enddot /// @file dpf/dpf3_cmp.hpp /// /// @par Ideal functionality /// \dot "Functionality F_DPF3CMP" /// digraph F_DPF3CMP { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_DPF3CMP
Parties. Evaluators 1, 2, and 3.
Input. A secret comparison or interval point, and a payload.
Each evaluator holds one DCF half. A Shamir tip of the payload is bookkeeping for updates.
Interval containment also takes the public scale c_x in {-1, 0, 1}.
Output. One additive share of the F_DCF or F_IC predicate value per evaluator,
unreduced in uint64. A complementary pair (1 with 2, or 3 with 2) opens by summation into fp61.
One party holds one DCF share, not both.
Leakage. One evaluator does not learn the point or the clear payload.
/// >]; /// } /// \enddot /// @file dpf/dpf3_multipoint.hpp /// /// @par Ideal functionality /// \dot "Functionality F_DPF3MP" /// digraph F_DPF3MP { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_DPF3MP
Parties. Same three evaluators as F_DPF3.
Input. t distinct points and fp61 payloads.
Packing matches F_MPDPF. Each bucket is an F_DPF3 key.
Output. Eval(x) sums Shamir shares across the three probes
and reconstructs to the sum of the t point functions.
Update replays the existing cuckoo placement and rewrites each occupied bucket.
It does not draw a new packing.
Leakage. Same as F_DPF3 on each bucket.
/// >]; /// } /// \enddot /// @file grotto/offset_horner.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Horner" /// digraph F_Horner { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Horner
Parties. P0 and P1. The dealer keyed powers 1, c, c^2, c^3 at a hidden center.
Input. Additive shares of x. Public coefficients of a cubic.
The parties open eta = x - r. The center is 2r when wired that way.
Output. Additive shares of the polynomial at the wrapped group element.
The binomial shift by the public carry kappa is local. No further round.
Leakage. eta. Not x, and not the center.
/// >]; /// } /// \enddot /// @file grotto/offset_poly.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Poly" /// digraph F_Poly { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Poly
Parties. P0 and P1, after the same public opening of eta as F_Horner.
Input. A polynomial of runtime degree, at most 16.
Coefficients are public, or additively shared.
Output. Additive shares of f at the wrapped x.
Public coefficients are a local binomial shift and a dot.
Shared coefficients use that local shift and one F_Beaver inner product.
Leakage. eta, and nothing further from F_Beaver.
/// >]; /// } /// \enddot /// @file grotto/offset_jet.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Jet" /// digraph F_Jet { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Jet
Parties. P0 and P1. The dealer keyed binom(center, k) for k = 0..d.
Input. Additive shares of x. The parties open eta = x - r.
Output. Additive shares, in Z/2^64, of binom(x, 0), ..., binom(x, d)
after the public Chu-Vandermonde shift by the carry kappa.
A public dot, forward difference, or hockey-stick prefix is local.
Leakage. eta. Not x, and not the center.
/// >]; /// } /// \enddot /// @file grotto/ring_switch.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Switch" /// digraph F_Switch { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Switch
Parties. P0 and P1. The dealer keyed the wrap comparison and a split of r.
Input. An n-bit limb x, n at most 64, and a public destination modulus.
The parties open eta = x - r.
Destinations are zn64, zn128, field128, and the P-256 scalar field.
Output. Additive shares of x in that residue group.
The wrap indicator stays inside the share. A factor of the modulus reduces locally.
Leakage. eta. Not x, and not the wrap bit in the clear.
/// >]; /// } /// \enddot /// @file grotto/offset_repr.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Repr" /// digraph F_Repr { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Repr
Parties. P0 and P1. The dealer keyed a state vector S_c at the hidden center.
Input. A public invertible matrix M over Z/2^64, or XOR shares for a GF(2) checkpoint.
The parties open eta = x - r. The hot piece has a public carry kappa.
Output. Shares of M^kappa * S_c.
Negative kappa multiplies by M inverse. The determinant must be odd.
Fibonacci, geometric powers, and a CRC jump are this functionality.
Leakage. eta and the public matrix power. Not the state, and not the center.
/// >]; /// } /// \enddot /// @file grotto/offset_twist.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Twist" /// digraph F_Twist { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Twist
Parties. P0 and P1. The dealer keyed c^m * lambda^c in Z/2^64.
Input. Public coefficients a_m and a public unit lambda, or the dyadic tag lambda = 1/2.
The parties open eta = x - r. The hot piece has public carry kappa.
Output. For odd lambda, additive shares of sum a_m (c+kappa)^m lambda^(c+kappa).
For lambda = 1/2, additive shares of sum a_m x^m / 2^x.
The untwisted sum is shifted by a masked low-limb carry. The opened mask is uniform.
The untwisted sum stays shared.
Leakage. eta. Not the untwisted sum, and not the center.
/// >]; /// } /// \enddot /// @file grotto/carry.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Carry" /// digraph F_Carry { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Carry
Parties. P0 and P1, with optional verifiable comparison keys and a MAC key.
Input. Additive shares of an n-bit limb, a public shift, and,
for the carry-out form, public knowledge that the secret is negative, nonnegative, or unknown.
Output. Additive shares of the matching cleartext oracle:
exact truncate-and-reduce, arithmetic right shift plus the unit correction,
exact fused arithmetic right shift, signed extension,
unknown-sign carry-out, window overflow, or fused same-ring.
Leakage. A fresh masked opening is uniform and hides the secret limb.
A bad path proof or a bad MAC aborts. The secret limb is not learned.
/// >]; /// } /// \enddot /// @file dpf/yao.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Yao" /// digraph F_Yao { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_Yao
Parties. P0 garbles. P1 evaluates. Semi-honest.
Input. A public straight-line bit netlist.
Each shared input is an XOR share of that bit.
A private input is known to one party.
The usual source of those bits is a DPF leaf, via F_YaoShare.
Output. XOR shares of each output bit.
P0's share is the permute bit of the zero label.
P1's share is the color of the label it holds.
Leakage. None beyond the output shares.
Tables are one-time. P1 does not learn Delta.
P0 does not learn P1's private bits or P1's shares.
/// >]; /// } /// \enddot /// @file dpf/yao_share.hpp /// /// @par Ideal functionality /// \dot "Functionality F_YaoShare" /// digraph F_YaoShare { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< /// /// /// /// /// /// ///
F_YaoShare
Parties. P0 and P1. For a replicated leaf, P2 is idle.
Input. One share each of an integer the DPF already produced:
subtractive (point leaf), additive (comparison leaf),
an fss_share, or the party-0 and party-1 replicated views.
The reverse calls take XOR shares of the low width bits.
Output. XOR shares of those bits, least-significant bit first,
or ring shares of the integer the bits encode, in the leaf's scheme.
y2rss deals a fresh replicated triple of that integer.
Leakage. A2B opens a masked x - r. B2A opens a masked bit.
Both masks are uniform. The integer stays shared.
This is not the local (3,3) cast dpf::rss2y / dpf::y2rss.
/// >]; /// } /// \enddot /// \htmlonly ///
TL;DR. Each figure states the parties, the inputs, the outputs, and what is revealed. A masked value or a public offset appears only when the parties learn it.
/// \endhtmlonly