3.1 KiB
\htmlonly
libdpf++ is a header-only C++17 library of distributed point functions: short keys that hide one secret index, then answer at public points as secret shares.
What it does
Honest correction seeds, a weight-1 sketch, and MACs on the leaves, on the same walk.
Late bindingProgrammabilityFill the index or the payload after the key exists. Rewrite an updatable leaf in place.
PredicatesComparisons & rangesLess-than, equality, interval containment, and blocked checks, as keys.
Many secretsMultipoint keysPack many secret points into one cuckoo key. One batched proof covers the set.
Three partiesMultiparty & 3-serverAny two of three open a Shamir key. Or an information-theoretic three-server DPF.
No dealerDealer-free keygenThe parties already share the index. Doerner–Shelat, geneval, and IKNP finish the key.
MultiplicationBeaver triplesAuthenticated products on leaf shares, including the ABY2.0 MAC check.
After the offsetGrottoJets, polynomials, carry, and exact ring changes once a public offset is open.
CommitmentsProgrammable vectorsBind a vector, then open one hidden coordinate or the sum.
ProtocolsApplication sketchesThe DPF step of Duoram, keyword PIR, PSI, Prio, LLAMA, and the rest.
A complete program
Leaf shares are subtractive. reconstruct is share0 - share1.
The same program is examples/mwe/point.cpp.
More programs are on [Pick a construction](@ref which_dpf) and [Code examples](@ref listings).
\htmlonly
#include "dpf.hpp"
const std::uint8_t alpha = 42;
const std::uint64_t beta = 7;
auto [k0, k1] = dpf::make_dpf(alpha, beta);
const std::uint64_t at = dpf::reconstruct(
*dpf::eval_point(k0, alpha),
*dpf::eval_point(k1, alpha));
// at == 7; any other public point opens to 0
// c++ -std=c++17 -march=native -I include -I thirdparty examples/mwe/point.cpp
\endhtmlonly