Who knows the secret index?
What should be nonzero?
Dealer point key. Leaf shares are subtractive, so reconstruct subtracts them. This prints 7 0.
#include <cstdint>
#include <iostream>
#include "dpf.hpp"
int main()
{
const std::uint8_t alpha = 42;
const std::uint64_t beta = 7;
auto [k0, k1] = dpf::make_dpf(alpha, beta);
const std::uint64_t at = dpf::reconstruct(
*dpf::eval_point(k0, alpha),
*dpf::eval_point(k1, alpha));
const std::uint64_t off = dpf::reconstruct(
*dpf::eval_point(k0, std::uint8_t{0}),
*dpf::eval_point(k1, std::uint8_t{0}));
std::cout << at << " " << off << "\n";
return (at == beta && off == 0) ? 0 : 1;
}
c++ -std=c++17 -march=native -I include -I thirdparty examples/mwe/point.cpp
One comparison on the same key. Comparison shares are additive, so reconstruct adds them. This prints 1 0.
#include <cstdint>
#include <iostream>
#include "dpf.hpp"
int main()
{
const std::uint8_t alpha = 40;
auto [k0, k1] = dpf::make_dpf(alpha, dpf::gt(std::uint64_t{1}));
const auto above = dpf::reconstruct(
dpf::eval_point(dpf::cmp, k0, std::uint8_t{50}),
dpf::eval_point(dpf::cmp, k1, std::uint8_t{50}));
const auto below = dpf::reconstruct(
dpf::eval_point(dpf::cmp, k0, std::uint8_t{10}),
dpf::eval_point(dpf::cmp, k1, std::uint8_t{10}));
std::cout << above << " " << below << "\n";
return (above == 1 && below == 0) ? 0 : 1;
}
c++ -std=c++17 -march=native -I include -I thirdparty examples/mwe/compare.cpp
The secret is a mask. The public interval is on x - r. This prints 9 0: 14 - 10 = 4, which sits in [3, 5].
#include <cstdint>
#include <iostream>
#include "dpf.hpp"
int main()
{
const std::uint8_t r = 10;
const std::uint64_t beta = 9;
auto [k0, k1] = dpf::make_dpf(r, dpf::ic(std::uint8_t{3}, std::uint8_t{5}, beta));
const auto inside = dpf::reconstruct(
dpf::eval_point(dpf::ic, k0, std::uint8_t{14}),
dpf::eval_point(dpf::ic, k1, std::uint8_t{14}));
const auto outside = dpf::reconstruct(
dpf::eval_point(dpf::ic, k0, std::uint8_t{0}),
dpf::eval_point(dpf::ic, k1, std::uint8_t{0}));
std::cout << inside << " " << outside << "\n";
return (inside == beta && outside == 0) ? 0 : 1;
}
c++ -std=c++17 -march=native -I include -I thirdparty examples/mwe/interval.cpp
Each party holds an XOR share of alpha. A pad dealer supplies the tape and does not learn alpha. The key is reusable. This prints 7.
#include <cstdint>
#include <iostream>
#include "dpf.hpp"
int main()
{
const std::uint8_t alpha = 42;
const std::uint64_t beta = 7;
const std::uint8_t x0 = 7;
const std::uint8_t x1 = static_cast<std::uint8_t>(alpha ^ x0);
auto root = []() { return dpf::uniform_sample<simde__m128i>(); };
struct pad {
simde__m128i block() { return dpf::uniform_sample<simde__m128i>(); }
std::uint8_t bit() {
return static_cast<std::uint8_t>(dpf::uniform_sample<unsigned>() & 1u);
}
};
dpf::ds_randomness<decltype(root), pad> rng{root, {}};
auto keys = dpf::make_dpf_doerner_shelat(x0, x1, rng, beta);
const std::uint64_t opened = dpf::reconstruct(
*dpf::eval_point(keys.first, alpha),
*dpf::eval_point(keys.second, alpha));
std::cout << opened << "\n";
return opened == beta ? 0 : 1;
}
c++ -std=c++17 -march=native -I include -I thirdparty examples/mwe/shared_index.cpp
Same share convention as the reusable key, and the parties open the value along the query. The call does not hand back a key you can evaluate again. The openings are on dpf/geneval.hpp: geneval_point, geneval_interval, geneval_sequence, geneval_full, and geneval_cmp.
Three evaluators, any two open. Spines are Shamir shares in fp61. The dealerless form is make_dpf3_doerner_shelat. Comparisons for that setting are make_dpf3_cmp and make_dpf3_ic.