libdpf/doc/pages/verifiability.md
Ryan Henry 0d22946a0e Checkpoint the party/runtime stack before share-program and malicious-mode work.
Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-28 05:59:19 -06:00

1.7 KiB
Raw Permalink Blame History

Verifiability & authenticity

\htmlonly

ELI5. The proof rides on the same walk as the payload. verifiable checks that the correction seeds were the honest ones. extractable checks that the path is weight 1, so a second programmed point fails. A MAC checks the leaf share after it is opened.
\endhtmlonly

Prove that a DPF walk used honest correction seeds, or that a weight-1 sketch over the path is consistent. The tags ride along as extra make_dpf arguments; eval still returns the usual leaf share.

Tag / call What you get
[dpf::verifiable](@ref dpf/verifiable.hpp) Proof token folded on the path (de Castro–Polychroniadou, EUROCRYPT 2022 / [ePrint 2021/580](@ref bib_vdpf)). Equal tokens across parties mean honest seeds.
[dpf::extractable](@ref dpf/verifiable.hpp) Weight-1 fp61 sketch on the same walk. A second hot point fails the check.
[dpf::output_mac](@ref dpf/verifiable.hpp) / mac_authenticate Authenticated leaf shares and batch checks.
Path sketches [path_sketch.hpp](@ref dpf/path_sketch.hpp) for prefix / parent sketches used by application mockups.
auto [k0, k1] = dpf::make_dpf(std::uint8_t{42}, std::uint64_t{7},
    dpf::verifiable{});
auto [e0, e1] = dpf::make_dpf(std::uint8_t{42}, std::uint64_t{7},
    dpf::extractable{});

Multipoint keys take the same dpf::verifiable{} tag for a batched proof (one token for the cuckoo set). Three-party keys can be verifiable or extractable as well; see [Multiparty & 3-server](@ref multiparty).

Go deeper: [guided tour](@ref tour_vdpf), ideal figures [F_VDPF](@ref verifiable.hpp) / [F_Sketch](@ref verifiable.hpp), [bibliography](@ref bibliography).