\htmlonly

libdpf++ is a header-only C++17 library of distributed point functions: short keys that hide one secret index, then answer at public points as secret shares.

What it does

ProofsVerifiability & authenticity

Honest correction seeds, a weight-1 sketch, and MACs on the leaves, on the same walk.

Late bindingProgrammability

Fill the index or the payload after the key exists. Rewrite an updatable leaf in place.

PredicatesComparisons & ranges

Less-than, equality, interval containment, and blocked checks, as keys.

Many secretsMultipoint keys

Pack many secret points into one cuckoo key. One batched proof covers the set.

Three partiesMultiparty & 3-server

Any two of three open a Shamir key. Or an information-theoretic three-server DPF.

No dealerDealer-free keygen

The parties already share the index. Doerner–Shelat, geneval, and IKNP finish the key.

MultiplicationBeaver triples

Authenticated products on leaf shares, including the ABY2.0 MAC check.

After the offsetGrotto

Jets, polynomials, carry, and exact ring changes once a public offset is open.

CommitmentsProgrammable vectors

Bind a vector, then open one hidden coordinate or the sum.

ProtocolsApplication sketches

The DPF step of Duoram, keyword PIR, PSI, Prio, LLAMA, and the rest.

\endhtmlonly ## A complete program {#first_program} Leaf shares are subtractive. `reconstruct` is `share0 - share1`. The same program is `examples/mwe/point.cpp`. More programs are on [Pick a construction](@ref which_dpf) and [Code examples](@ref listings). \htmlonly
#include "dpf.hpp"

const std::uint8_t alpha = 42;
const std::uint64_t beta = 7;
auto [k0, k1] = dpf::make_dpf(alpha, beta);

const std::uint64_t at = dpf::reconstruct(
    *dpf::eval_point(k0, alpha),
    *dpf::eval_point(k1, alpha));
// at == 7; any other public point opens to 0

// c++ -std=c++17 -march=native -I include -I thirdparty examples/mwe/point.cpp
\endhtmlonly