/// \page ideal_functionalities Ideal functionalities /// /// Each MPC protocol's file page carries one figure: the ideal functionality /// that protocol realizes. The figure states the parties, the inputs, the /// outputs, and what is revealed. A protocol may open a masked value or a /// public offset; that appears in the figure only when the parties learn it. /// /// ## Sharing /// /// - \ref secret_share.hpp "F_Open" /// - \ref shamir3.hpp "F_Shamir" /// /// ## Dealer keys /// /// - \ref dpf_key.hpp "F_DPF" /// - \ref incremental.hpp "F_IDPF" /// - \ref grow.hpp "F_Grow" /// - \ref wildcard.hpp "F_Assign" /// - \ref dcf.hpp "F_DCF" /// - \ref blocked_dcf.hpp "F_BDCF" /// - \ref interval.hpp "F_IC" /// - \ref multipoint.hpp "F_MPDPF" /// /// ## Two-party generation and evaluation /// /// - \ref doerner_shelat.hpp "F_DS" /// - \ref grow_ds.hpp "F_GrowDS" /// - \ref geneval.hpp "F_GenEval" /// - \ref beaver.hpp "F_Beaver and F_BeaverAuth" /// - \ref constrained_cmp.hpp "F_CCMP" /// - \ref verifiable.hpp "F_VDPF, F_Sketch, and F_OblivHash" /// /// ## Three evaluators /// /// - \ref dpf3.hpp "F_DPF3" /// - \ref dpf3_ds.hpp "F_DPF3DS" /// - \ref dpf3_cmp.hpp "F_DPF3CMP" /// - \ref dpf3_multipoint.hpp "F_DPF3MP" /// /// ## Offset corrections /// /// - \ref offset_horner.hpp "F_Horner" /// - \ref offset_poly.hpp "F_Poly" /// - \ref offset_jet.hpp "F_Jet" /// - \ref ring_switch.hpp "F_Switch" /// - \ref offset_repr.hpp "F_Repr" /// - \ref offset_twist.hpp "F_Twist" /// - \ref carry.hpp "F_Carry" /// @file dpf/secret_share.hpp /// /// @par Ideal functionality /// \dot "Functionality F_Open" /// digraph F_Open { /// graph [bgcolor="transparent"]; /// node [shape=plaintext, fontname="Helvetica", fontsize=11]; /// F [label=< ///
| F_Open |
| Parties. P0 and P1. Each holds one share. |
| Input. An additive share, a subtractive share, or an XOR share. |
| Output. Both parties receive the opened value: additive is share0 + share1, subtractive is share0 - share1, XOR is share0 XOR share1. |
| Leakage. That opened value, and nothing else. |
| F_Shamir |
| Parties. Evaluators 1, 2, and 3 over fp61. |
| Input. A secret s. The dealer samples a uniform slope a. |
| Output. Party i receives s_i = s + a*i. Any two parties reconstruct s by Lagrange. A share embeds into a 61-bit XOR string for the (2,3) point key. |
| Leakage. One share hides s. Two shares reveal it. |
| F_DPF |
| Parties. An honest dealer, then evaluators P0 and P1. |
| Input. A secret point alpha and one or more payloads beta. A payload may be a wildcard, filled later by F_Assign. The interior PRG is BGI or Half-Tree. The outputs do not change. |
| Output. Key k_i to party i. Eval(x) returns subtractive shares of beta when x = alpha, else 0. An XOR payload is an XOR share. Several outputs are independent. |
| Leakage. The keys hide alpha and beta. Eval of an unassigned wildcard aborts. |
| F_IDPF |
| Parties. Same dealer and two evaluators as F_DPF. |
| Input. Secret point alpha. Each output is placed at a public prefix length. An optional comparison spec adds an F_DCF channel on the same alpha. |
| Output. One key per party. Eval of a prefix slot returns that slot's shares on its programmed domain. The comparison channel returns F_DCF shares. |
| Leakage. None beyond those shares. A wildcard slot aborts until F_Assign. |
| F_Grow |
| Parties. An honest dealer holding both F_IDPF keys, then evaluators P0 and P1. |
| Input. An existing key pair for secret alpha. /// extend: the next path bit of alpha and specs whose prefixes equal the new depth. /// add_output: specs whose prefixes are already levels of the key. /// Optional warm path memoizers supply the on-path seeds (must already be filled). |
| Output. A new key pair whose type is the old key plus the new material. /// Earlier correction words, advice bits, leaves, and comparison words are unchanged share for share. /// Eval of an old slot on the new keys matches the old keys. New slots match F_IDPF for those specs. |
| Leakage. None beyond the new keys. Specs that need a deeper tree, share a packing group with an old slot, or sit on the wrong level abort. |
| F_GrowDS |
| Parties. P0 and P1 hold matching F_IDPF keys and on-path seeds at the frontier. /// P2 may deal pads and learns nothing. A joint local simulator holds both keys. |
| Input. XOR shares of alpha, warm path memoizers through the old depth, /// and the same specs as F_Grow. extend_ds opens one new interior correction word. /// add_output_ds opens only the new leaf (or comparison) material. |
| Output. The same grown keys F_Grow would return for that alpha and those specs, /// with the same roots and the same public correction words as a dealer extend / add_output. |
| Leakage. Default: none beyond the keys. P2 never sees alpha or payloads. /// Off-path memoizer leftovers are not a valid plant site for secret outputs. |
| F_Assign |
| Parties. P0 and P1, holding keys from F_DPF or F_IDPF. |
| Input. A payload beta, or shares of beta, for a wildcard slot. A public delta is applied as given. A subtractive share is converted with that party's coefficient. |
| Output. The same keys, now evaluating to shares of beta at alpha. Alpha does not move. |
| Leakage. None. Eval before Assign aborts. |
| F_DCF |
| Parties. An honest dealer, then evaluators P0 and P1. |
| Input. Secret point alpha, payloads if_true and if_false, and a predicate lt, leq, gt, or geq. A path-paint kind plants one public constant on each sibling subtree. |
| Output. One key per party. Eval(x) returns additive shares of if_true when the predicate holds, and of if_false otherwise. |
| Leakage. None. The same outputs are realized by F_BDCF. |
| F_BDCF |
| Parties. Same dealer and evaluators as F_DCF. |
| Input. The F_DCF inputs, plus a public checkpoint schedule. Ring words are stored only at those checkpoints. A residual tail, when the key sets it, is a table on the node at that height. |
| Output. Additive shares of the same predicate or path-paint as F_DCF. |
| Leakage. The schedule is public. It does not reveal alpha. |
| F_IC |
| Parties. An honest dealer, then evaluators P0 and P1. |
| Input. Secret mask r, public bounds p and q, and payloads if_true and if_false. |
| Output. One key per party. Eval(x) returns additive shares of if_true when p <= (x - r) mod 2^n <= q, and of if_false otherwise. |
| Leakage. The bounds are public. r and the payloads stay hidden. |
| F_MPDPF |
| Parties. An honest dealer, then evaluators P0 and P1. |
| Input. t distinct points and their payloads. The verifiable tag selects VDPF buckets. |
| Output. m = O(t) bucket keys on a cuckoo packing with 3 probes. Eval(x) sums the three probed buckets and matches the sum of the t point functions. A batched proof is one 2-lambda token. |
| Leakage. None beyond the output shares and, when requested, the proof. |
| F_DS |
| Parties. P0 and P1 hold the point. P2 deals pads and learns nothing. |
| Input. XOR shares of alpha, or additive shares. Additive shares are converted by a ripple-carry. The sum is not opened. Beta is public, or additively shared as leaf-key material without opening the payload. An optional Reveal flag asks for the encoded point (and, for a packed wildcard, the lane). |
| Output. Each of P0 and P1 receives the F_DPF or F_DCF key make_dpf would emit for that alpha, the same roots, and the same beaver coins. When Reveal is set, the encoded point is an explicit output, and a packed wildcard also returns its lane. Paint comparisons require Reveal. |
| Leakage. Default leakage is none beyond the keys. P2 receives neither the point, the prefix, nor the payload. The tree prefix, the lane, and a shared payload stay hidden unless Reveal is set. |
| F_GenEval |
| Parties. P0 and P1. No reusable key is returned. |
| Input. XOR or additive shares of alpha, a public or shared payload, and a public query: one point, an interval, a sequence, or the full domain. |
| Output. Shares of F_DPF on that query. Leaves are subtractive. Comparison prefixes are additive. geneval_cmp returns a prefix share at each public endpoint. The point is not opened. Additive inputs are converted without opening the sum. |
| Leakage. Evaluators receive the query-trie correction words. Off-path words are uniform. On-path words match a dealer key and hide the point. |
| F_Beaver |
| Parties. P0 and P1 evaluate. P2 is an honest dealer. |
| Input. Additive shares of wires, and a public formula: a polynomial, an inner product, a scale, or a bit-mux. A later round may reuse a wire. Repeated factors share one blind. |
| Output. Additive shares of the formula. P2 learns nothing. Classic triples are the same functionality on fresh wires. |
| Leakage. None. Opened masks delta = x + lambda are uniform. |
| F_BeaverAuth |
| Parties. Same as F_Beaver. A MAC key Delta is fixed before sampling. |
| Input. The F_Beaver inputs. Every blind, monomial, and value is tagged under Delta. |
| Output. The same additive shares, together with tag shares. verify_delta and verify_auth_opening accept only consistent tags. |
| Leakage. None when the check accepts. A bad tag aborts. |
| F_CCMP |
| Parties. P0 holds x0. P1 holds x1. |
| Input. Positive integers with absolute difference 1. Each party forms two bits from the low bits of its input. |
| Output. Both parties receive the bit 1{x0 < x1}. The bit is one AND of those derived bits. |
| Leakage. That bit. If the inputs do not differ by one, the protocol aborts. |
| F_VDPF |
| Parties. P0 and P1, on keys generated under the verifiable tag. |
| Input. The F_DPF inputs, plus a public evaluation point. |
| Output. The F_DPF share, and a 2-lambda proof token from each party. Verify accepts exactly when the path and the output share match: correction seeds, the leaf correction word, and comparison value words fold into the token. |
| Leakage. The accept or reject bit. Nothing else. A tampered seed, leaf, value word, or proof rejects. A zero token rejects. |
| F_Sketch |
| Parties. P0 and P1, on an extractable key. Default eval does not fold. |
| Input. Payload shares written during evaluation, and caller-chosen fp61 challenges, one per payload. |
| Output. Subtractive shares of three moments (z1, z2, z3). sketch_verify accepts when z2^2 = z1*z3 after the shares are opened, that is, when the opened payloads have at most one nonzero point. |
| Leakage. The accept or reject bit. A second hot point rejects. |
| F_OblivHash |
| Parties. P0 and P1. Correlated AND triples come from the dealer tape. The two-party realization is party/oblivious_hash.hpp. |
| Input. Each party holds the seed it owns, and a XOR share of the path prefix. The level is public. |
| Output. Both parties receive H(s0) XOR H(s1), the same block as hash_node on the joined prefix and the two seeds. |
| Leakage. That opened block. The prefix is not opened. |
| F_DPF3 |
| Parties. An honest dealer and evaluators 1, 2, and 3. |
| Input. Secret point alpha and payload beta in fp61. The updatable tag keeps the leaf writable. The verifiable and extractable tags select those checks. |
| Output. One key per evaluator. Eval(x) is a degree-1 Shamir share of beta when x = alpha, else 0. Any two parties reconstruct. Update(beta') rewrites the payload and does not move alpha. Update on a non-updatable key aborts. verify_dpf3 accepts only a consistent triple of proofs. |
| Leakage. One key hides alpha and beta. A bad proof rejects. |
| F_DPF3DS |
| Parties. Two shareholders of alpha, producing keys for three evaluators. |
| Input. XOR shares of alpha, after the signed-MSB flip on share 0. Payload beta in fp61 is a shared input of keygen, not an opened point. Verifiable, updatable, and extractable select the same options as F_DPF3. Reveal on a spine is the same optional flag as F_DS. |
| Output. Three F_DPF3 keys for alpha = x0 XOR x1 and that beta. Two independent Doerner-Shelat spines carry the Fig. 3 payloads. |
| Leakage. Neither share alone reveals alpha or beta. The point and the payload stay shared unless Reveal is set on a spine. |
| F_DPF3CMP |
| Parties. Evaluators 1, 2, and 3. |
| Input. A secret comparison or interval point, and a payload. Each evaluator holds one DCF half. A Shamir tip of the payload is bookkeeping for updates. Interval containment also takes the public scale c_x in {-1, 0, 1}. |
| Output. One additive share of the F_DCF or F_IC predicate value per evaluator, unreduced in uint64. A complementary pair (1 with 2, or 3 with 2) opens by summation into fp61. One party holds one DCF share, not both. |
| Leakage. One evaluator does not learn the point or the clear payload. |
| F_DPF3MP |
| Parties. Same three evaluators as F_DPF3. |
| Input. t distinct points and fp61 payloads. Packing matches F_MPDPF. Each bucket is an F_DPF3 key. |
| Output. Eval(x) sums Shamir shares across the three probes and reconstructs to the sum of the t point functions. Update replays the existing cuckoo placement and rewrites each occupied bucket. It does not draw a new packing. |
| Leakage. Same as F_DPF3 on each bucket. |
| F_Horner |
| Parties. P0 and P1. The dealer keyed powers 1, c, c^2, c^3 at a hidden center. |
| Input. Additive shares of x. Public coefficients of a cubic. The parties open eta = x - r. The center is 2r when wired that way. |
| Output. Additive shares of the polynomial at the wrapped group element. The binomial shift by the public carry kappa is local. No further round. |
| Leakage. eta. Not x, and not the center. |
| F_Poly |
| Parties. P0 and P1, after the same public opening of eta as F_Horner. |
| Input. A polynomial of runtime degree, at most 16. Coefficients are public, or additively shared. |
| Output. Additive shares of f at the wrapped x. Public coefficients are a local binomial shift and a dot. Shared coefficients use that local shift and one F_Beaver inner product. |
| Leakage. eta, and nothing further from F_Beaver. |
| F_Jet |
| Parties. P0 and P1. The dealer keyed binom(center, k) for k = 0..d. |
| Input. Additive shares of x. The parties open eta = x - r. |
| Output. Additive shares, in Z/2^64, of binom(x, 0), ..., binom(x, d) after the public Chu-Vandermonde shift by the carry kappa. A public dot, forward difference, or hockey-stick prefix is local. |
| Leakage. eta. Not x, and not the center. |
| F_Switch |
| Parties. P0 and P1. The dealer keyed the wrap comparison and a split of r. |
| Input. An n-bit limb x, n at most 64, and a public destination modulus. The parties open eta = x - r. Destinations are zn64, zn128, field128, and the P-256 scalar field. |
| Output. Additive shares of x in that residue group. The wrap indicator stays inside the share. A factor of the modulus reduces locally. |
| Leakage. eta. Not x, and not the wrap bit in the clear. |
| F_Repr |
| Parties. P0 and P1. The dealer keyed a state vector S_c at the hidden center. |
| Input. A public invertible matrix M over Z/2^64, or XOR shares for a GF(2) checkpoint. The parties open eta = x - r. The hot piece has a public carry kappa. |
| Output. Shares of M^kappa * S_c. Negative kappa multiplies by M inverse. The determinant must be odd. Fibonacci, geometric powers, and a CRC jump are this functionality. |
| Leakage. eta and the public matrix power. Not the state, and not the center. |
| F_Twist |
| Parties. P0 and P1. The dealer keyed c^m * lambda^c in Z/2^64. |
| Input. Public coefficients a_m and a public unit lambda, or the dyadic tag lambda = 1/2. The parties open eta = x - r. The hot piece has public carry kappa. |
| Output. For odd lambda, additive shares of sum a_m (c+kappa)^m lambda^(c+kappa). For lambda = 1/2, additive shares of sum a_m x^m / 2^x. The untwisted sum is shifted by a masked low-limb carry. The opened mask is uniform. The untwisted sum stays shared. |
| Leakage. eta. Not the untwisted sum, and not the center. |
| F_Carry |
| Parties. P0 and P1, with optional verifiable comparison keys and a MAC key. |
| Input. Additive shares of an n-bit limb, a public shift, and, for the carry-out form, public knowledge that the secret is negative, nonnegative, or unknown. |
| Output. Additive shares of the matching cleartext oracle: exact truncate-and-reduce, arithmetic right shift plus the unit correction, exact fused arithmetic right shift, signed extension, unknown-sign carry-out, window overflow, or fused same-ring. |
| Leakage. A fresh masked opening is uniform and hides the secret limb. A bad path proof or a bad MAC aborts. The secret limb is not learned. |