libdpf/doc/pages/multiparty.md
Ryan Henry 0d22946a0e Checkpoint the party/runtime stack before share-program and malicious-mode work.
Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-28 05:59:19 -06:00

41 lines
2.5 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Multiparty & 3-server {#multiparty}
\htmlonly
<div class="eli5"><b>ELI5.</b> make_dpf3 is two ordinary spines per party and a Shamir payload, so any two parties open and the third key is independent of the value. make_it_dpf3 shares the whole truth table instead, and all three shares are required. Doerner–Shelat and geneval are the two-party, no-dealer alternatives.</div>
\endhtmlonly
Two-party keys are the default. The library also builds three-evaluator
`(2,3)` keys, information-theoretic three-server DPFs, and dealer-free
two-party keygen when the index is already shared.
| Construction | Parties | Header |
| --- | --- | --- |
| [dpf::make_dpf3](@ref dpf/dpf3.hpp) | Any two of three open (Shamir / dual spine, [ePrint 2024/1658](@ref bib_dpf3)) | `dpf3.hpp` |
| [dpf::make_dpf3_doerner_shelat](@ref dpf/dpf3_ds.hpp) | Same keys from XOR shares of `alpha` | `dpf3_ds.hpp` |
| `make_dpf3_cmp` / `make_dpf3_ic` / `make_multipoint3` | Comparisons, intervals, multipoint | `dpf3_cmp.hpp`, `dpf3_multipoint.hpp` |
| [dpf::make_it_dpf3](@ref dpf/it_dpf3.hpp) | Information-theoretic 3-server DPF ([ePrint 2023/028](@ref bib_itdpf)) | `it_dpf3.hpp` |
| [dpf::make_dpf_doerner_shelat](@ref dpf/doerner_shelat.hpp) | Two parties, shared index, no dealer for the point | `doerner_shelat.hpp` |
| [dpf::geneval_*](@ref dpf/geneval.hpp) | Answer shares for one query, no reusable key | `geneval.hpp` |
| [dpf::shamir::deal](@ref dpf/shamir.hpp) | (K,N) Shamir. `(2,3)` is the `make_dpf3` payload | `shamir.hpp` |
The payload inside `make_dpf3` is degree-1 Shamir on the points `1`, `2`,
and `3`. That access structure is `shamir::two_of_three`, the type
`shamir_share`. The same split takes other thresholds:
`shamir::deal<T, K, N>` and `shamir::share_secret`. `make_dpf3` stays
`(2,3)`. See [secret shares](@ref secret_shares) and `examples/mwe/shamir.cpp`.
```cpp
auto [k1, k2, k3] = dpf::make_dpf3(std::uint8_t{42}, dpf::fp61{7});
auto opened = dpf::reconstruct(
dpf::as_share(k1, dpf::eval_point(k1, std::uint8_t{42})),
dpf::as_share(k2, dpf::eval_point(k2, std::uint8_t{42})),
dpf::as_share(k3, dpf::eval_point(k3, std::uint8_t{42})));
```
Party meshes and socket walks live under [trio.hpp](@ref dpf/net/trio.hpp)
and the `party/` harnesses. Application-shaped sketches include
[3-party Duoram](@ref app_duoram) and [three-server PIR](@ref app_pir3).
**Go deeper:** [guided tour — three evaluators](@ref tour_dpf3),
[Doerner–Shelat](@ref tour_ds), [evaluating DPFs](@ref evaluation),
[bibliography](@ref bibliography).