libdpf/doc/pages/verifiability.md
Ryan Henry 0d22946a0e Checkpoint the party/runtime stack before share-program and malicious-mode work.
Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-28 05:59:19 -06:00

31 lines
1.7 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Verifiability & authenticity {#verifiability}
\htmlonly
<div class="eli5"><b>ELI5.</b> The proof rides on the same walk as the payload. verifiable checks that the correction seeds were the honest ones. extractable checks that the path is weight 1, so a second programmed point fails. A MAC checks the leaf share after it is opened.</div>
\endhtmlonly
Prove that a DPF walk used honest correction seeds, or that a weight-1
sketch over the path is consistent. The tags ride along as extra
`make_dpf` arguments; eval still returns the usual leaf share.
| Tag / call | What you get |
| --- | --- |
| [dpf::verifiable](@ref dpf/verifiable.hpp) | Proof token folded on the path (de Castro–Polychroniadou, EUROCRYPT 2022 / [ePrint 2021/580](@ref bib_vdpf)). Equal tokens across parties mean honest seeds. |
| [dpf::extractable](@ref dpf/verifiable.hpp) | Weight-1 `fp61` sketch on the same walk. A second hot point fails the check. |
| [dpf::output_mac](@ref dpf/verifiable.hpp) / `mac_authenticate` | Authenticated leaf shares and batch checks. |
| Path sketches | [path_sketch.hpp](@ref dpf/path_sketch.hpp) for prefix / parent sketches used by application mockups. |
```cpp
auto [k0, k1] = dpf::make_dpf(std::uint8_t{42}, std::uint64_t{7},
dpf::verifiable{});
auto [e0, e1] = dpf::make_dpf(std::uint8_t{42}, std::uint64_t{7},
dpf::extractable{});
```
Multipoint keys take the same `dpf::verifiable{}` tag for a batched
proof (one token for the cuckoo set). Three-party keys can be
verifiable or extractable as well; see [Multiparty & 3-server](@ref multiparty).
**Go deeper:** [guided tour](@ref tour_vdpf), ideal figures
[F_VDPF](@ref verifiable.hpp) / [F_Sketch](@ref verifiable.hpp),
[bibliography](@ref bibliography).