Programmable Distributed Point Functions
Elette Boyle, Niv Gilboa, Yuval Ishai, Victor I. Kolobov
Abstract
A distributed point function (DPF) is a cryptographic primitive that enables compressed additive sharing of a secret unit vector across two or more parties. Despite growing ubiquity within applications and notable research efforts, the best 2-party DPF construction to date remains the tree-based construction from (Boyle et al., CCS'16), with no significantly new approaches since.
We present a new framework for 2-party DPF construction, which applies in the setting of feasible (polynomial-size) domains. This captures in particular all DPF applications in which the keys are expanded to the full domain. Our approach is motivated by a strengthened notion we put forth, of programmable DPF (PDPF): in which a short, inputindependent "offline" key can be reused for sharing many point functions.
-PDPF from OWF. We construct a PDPF for feasible domains from the minimal assumption that one-way functions exist, where the second "online" key size is polylogarithmic in the domain size N . Our approach offers multiple new efficiency features and applications:
-Privately puncturable PRFs. Our PDPF gives the first OWF-based privately puncturable PRFs (for feasible domains) with sublinear keys. -O(1)-round distributed DPF Gen. We obtain a (standard) DPF with polylog-size keys that admits an analog of Doerner-shelat (CCS'17) distributed key generation, requiring only O(1) rounds (versus log N ). -PCG with 1 short key. Compressing useful correlations for secure computation, where one key is of minimal size. This provides up to exponential communication savings in some application scenarios.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 30e27116-ef89-4451-80ef-4bcb025bc391Cited by top-tier papers3
- Do You Need a Receipt? Anonymous Credential Revocation at Continental Scale via Private Record CertificationKasra EdalatNejad, Sebastian Faust, Jonas Hofmann, Philipp-Florens Lehwalder et al.USENIX Security 2026 · 1 citation
- Streaming Function Secret Sharing and Its ApplicationsXiangfu Song, Jianli Bai, Ye Dong, Yijian Liu et al.USENIX Security 2026
- Private Access Control for Function Secret SharingSacha Servan-Schreiber, Simon Beyzerov, Eli Yablon, Hyojae ParkS&P 2023
Builds on12
- Function Secret Sharing: Improvements and ExtensionsElette Boyle, Niv Gilboa, Yuval IshaiCCS 2016 · 404 citations
- QUOTIENT: Two-Party Secure Neural Network Training and PredictionNitin Agrawal, Ali Shahin Shamsabadi, Matt J. Kusner, Adrià GascónCCS 2019 · 241 citations
- Efficient Two-Round OT Extension and Silent Non-Interactive Secure ComputationElette Boyle, Geoffroy Couteau, Niv Gilboa, Yuval Ishai et al.CCS 2019 · 238 citations
- Scaling ORAM for Secure ComputationJack Doerner, Abhi ShelatCCS 2017 · 221 citations
- Compressing Vector OLEElette Boyle, Geoffroy Couteau, Niv Gilboa, Yuval IshaiCCS 2018 · 220 citations
Related papers
- Improved Constructions for Distributed Multi-Point FunctionsElette Boyle, Niv Gilboa, Matan Hamilis, Yuval Ishai et al.S&P 2025
- Multiparty Distributed Point FunctionsAarushi Goel, Mingyuan Wang, Zhiheng WangCRYPTO 2025 · 5 citations
- Pseudorandom Functions with Weak Programming Privacy and Applications to Private Information RetrievalAshrujit Ghoshal, Mingxun Zhou, Elaine Shi, Bo PengEUROCRYPT 2025 · 2 citations
- Fast Public-Key Silent OT and More from Constrained Naor-ReingoldDung Bui, Geoffroy Couteau, Pierre Meyer, Alain Passelègue et al.EUROCRYPT 2024 · 22 citations
- Compressing Unit-Vector Correlations via Sparse Pseudorandom GeneratorsAmit Agarwal, Elette Boyle, Niv Gilboa, Yuval Ishai et al.CRYPTO 2024 · 6 citations
