libdpf/doc/pages/introduction.md
Ryan Henry 0d22946a0e Checkpoint the party/runtime stack before share-program and malicious-mode work.
Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-28 05:59:19 -06:00

47 lines
4.6 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

\htmlonly
<p class="hero-lead"><code>libdpf++</code> is a header-only C++17 library of distributed point functions: short keys that hide one secret index, then answer at public points as secret shares. The same tree ships a TLS party mesh, round scheduling, MPC on those leaf shares, leveled run logs, and paper-cost statistics — so readers do not have to dig the API to find them.</p>
<h2 id="features">What it does</h2>
<div class="feature-grid">
<a class="feature-card" href="verifiability.html"><span class="feature-kicker">Proofs</span><strong>Verifiability &amp; authenticity</strong><p>Honest correction seeds, a weight-1 sketch, and MACs on the leaves, on the same walk.</p></a>
<a class="feature-card" href="programmability.html"><span class="feature-kicker">Late binding</span><strong>Programmability</strong><p>Fill the index or the payload after the key exists. Rewrite an updatable leaf in place.</p></a>
<a class="feature-card" href="comparisons.html"><span class="feature-kicker">Predicates</span><strong>Comparisons &amp; ranges</strong><p>Less-than, equality, interval containment, and blocked checks, as keys.</p></a>
<a class="feature-card" href="multipoint_keys.html"><span class="feature-kicker">Many secrets</span><strong>Multipoint keys</strong><p>Pack many secret points into one cuckoo key. One batched proof covers the set.</p></a>
<a class="feature-card" href="multiparty.html"><span class="feature-kicker">Three parties</span><strong>Multiparty &amp; 3-server</strong><p>Any two of three open a Shamir key. Or an information-theoretic three-server DPF.</p></a>
<a class="feature-card" href="dealer_free.html"><span class="feature-kicker">No dealer</span><strong>Dealer-free keygen</strong><p>The parties already share the index. Doerner–Shelat, geneval, and IKNP finish the key.</p></a>
<a class="feature-card" href="jet_and_ring.html"><span class="feature-kicker">After the offset</span><strong>Grotto</strong><p>Jets, polynomials, carry, and exact ring changes once a public offset is open. Several LUTs share one comparison.</p></a>
<a class="feature-card" href="ppvc_manual.html"><span class="feature-kicker">Commitments</span><strong>Programmable vectors</strong><p>Bind a vector, then open one hidden coordinate or the sum.</p></a>
<a class="feature-card" href="applications.html"><span class="feature-kicker">Sketches</span><strong>Application sketches</strong><p>The DPF step of Duoram, keyword PIR, PSI, Prio, LLAMA, and the rest.</p></a>
</div>
<h2 id="around-the-keys">Around the keys</h2>
<p class="hero-lead" style="font-size:1.05rem;margin-bottom:0.6rem">Live parties, composition, MPC on leaf shares, logging, and statistics — first-class, not buried in the reference.</p>
<div class="feature-grid">
<a class="feature-card" href="network_and_mpc.html"><span class="feature-kicker">Links</span><strong>Network &amp; party mesh</strong><p>TLS 1.3 party sessions, trio mesh, RoundSink rounds, lanes, and reconnect.</p></a>
<a class="feature-card" href="protocol_compose.html"><span class="feature-kicker">Schedule</span><strong>Protocol composition</strong><p>FSS walks next to Beaver opens on one RoundSink plan, with explicit reshares.</p></a>
<a class="feature-card" href="beaver_triples.html"><span class="feature-kicker">Multiplication</span><strong>Beaver triples</strong><p>Authenticated products on leaf shares, including the ABY2.0 MAC check.</p></a>
<a class="feature-card" href="arith_runtime.html"><span class="feature-kicker">Shares</span><strong>Arithmetic share runtime</strong><p>edaBits, truncate, share compare, matmul, and hidden shuffle beside FSS.</p></a>
<a class="feature-card" href="yao_leaf.html"><span class="feature-kicker">Circuits</span><strong>Yao on a leaf</strong><p>Split a leaf into bits, garble a netlist, share the answer back as a leaf.</p></a>
<a class="feature-card" href="experiment_costs.html"><span class="feature-kicker">Observability</span><strong>Logging &amp; statistics</strong><p>Leveled run logs, provenance banners, replayable seeds, and CSV wire / PRG / timing breakdowns.</p></a>
</div>
\endhtmlonly
## A complete program {#first_program}
Leaf shares are subtractive. `reconstruct` is `share0 - share1`.
The same program is `examples/mwe/point.cpp`.
More programs are on [Pick a construction](@ref which_dpf) and [Code examples](@ref listings).
\htmlonly
<pre class="fragment">#include "dpf.hpp"
const std::uint8_t alpha = 42;
const std::uint64_t beta = 7;
auto [k0, k1] = dpf::make_dpf(alpha, beta);
const std::uint64_t at = dpf::reconstruct(
*dpf::eval_point(k0, alpha),
*dpf::eval_point(k1, alpha));
// at == 7; any other public point opens to 0
// c++ -std=c++17 -march=native -I include -I thirdparty examples/mwe/point.cpp
</pre>
\endhtmlonly