libdpf/doc/pages/verifiability.md
2026-09-26 23:51:06 -06:00

1.4 KiB
Raw Blame History

Verifiability & authenticity

Prove that a DPF walk used honest correction seeds, or that a weight-1 sketch over the path is consistent. The tags ride along as extra make_dpf arguments; eval still returns the usual leaf share.

Tag / call What you get
[dpf::verifiable](@ref dpf/verifiable.hpp) Proof token folded on the path (de Castro–Polychroniadou, EUROCRYPT 2022 / [ePrint 2021/580](@ref bib_vdpf)). Equal tokens across parties mean honest seeds.
[dpf::extractable](@ref dpf/verifiable.hpp) Weight-1 fp61 sketch on the same walk. A second hot point fails the check.
[dpf::output_mac](@ref dpf/verifiable.hpp) / mac_authenticate Authenticated leaf shares and batch checks.
Path sketches [path_sketch.hpp](@ref dpf/path_sketch.hpp) for prefix / parent sketches used by application mockups.
auto [k0, k1] = dpf::make_dpf(std::uint8_t{42}, std::uint64_t{7},
    dpf::verifiable{});
auto [e0, e1] = dpf::make_dpf(std::uint8_t{42}, std::uint64_t{7},
    dpf::extractable{});

Multipoint keys take the same dpf::verifiable{} tag for a batched proof (one token for the cuckoo set). Three-party keys can be verifiable or extractable as well; see [Multiparty & 3-server](@ref multiparty).

Go deeper: [guided tour](@ref tour_vdpf), ideal figures [F_VDPF](@ref verifiable.hpp) / [F_Sketch](@ref verifiable.hpp), [bibliography](@ref bibliography).