1.1 KiB
1.1 KiB
Dealer-free keygen
The two parties already hold shares of the secret index.
Nobody sends alpha to a dealer.
| Call | What you get |
|---|---|
| [dpf::make_dpf_doerner_shelat](@ref dpf/doerner_shelat.hpp) | A reusable two-party key from XOR shares of alpha (Doerner–Shelat, CCS 2017 / [ePrint 2017/827](@ref bib_ds)) |
[dpf::geneval_point](@ref dpf/geneval.hpp) / geneval_interval / geneval_cmp |
Answer shares for one query. No reusable key |
| IKNP pads | The same Doerner–Shelat walk after Chou–Orlandi base OT ([ePrint 2015/267](@ref bib_chou)), with no pad dealer |
const std::uint8_t alpha = 42;
const std::uint8_t x0 = 0x13;
const std::uint8_t x1 = static_cast<std::uint8_t>(alpha ^ x0);
auto [k0, k1] = dpf::make_dpf_doerner_shelat(x0, x1, std::uint64_t{7});
Three evaluators have the same shape: make_dpf3_doerner_shelat.
Socket sessions live under party/dist_ds.hpp and party/iknp_deal.hpp.
Go deeper: [Doerner–Shelat](@ref tour_ds), [geneval.hpp](@ref dpf/geneval.hpp), [Multiparty & 3-server](@ref multiparty).