Distributed Point Functions and Function Secret Sharing
arXiv:2607.27696
The paper surveys the cryptographic primitive of distributed point functions (DPFs) and its extension to function secret sharing (FSS), covering definitions, constructions, and a range of applications such as private information retrieval and secure computation.
Abstract
A distributed point function (DPF) is a cryptographic primitive that enables compressed additive sharing of a secret weight-1 vector (equivalently, a point function) across two or more parties. The appealing lightweight structure of DPF constructions has enabled a wide range of applications. These include private information retrieval, anonymous messaging, secure computation with preprocessing, and pseudorandom correlation generators for expanding small correlated seeds into large pseudorandom instances of cryptographic correlations. In this article, we survey definitions, constructions, and applications of DPFs. We also discuss the extension of DPF to function secret sharing (FSS), which generalizes point functions to support richer function classes. Efficient FSS schemes yield a similar generalization for most of the applications of DPFs.