Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up

Functional Encryption & Inner-Product Predicates Studio

Architect fine-grained, non-all-or-nothing cryptographic access control. Simulate DDH-based Inner-Product Functional Encryption (IPFE), derive function-specific decryption keys sky, and evaluate dot products ⟨x, y⟩ with mathematical zero leakage.

Abdalla-DDH IPFE Selective Disclosure Zero-Leakage ⟨x, y⟩ Collusion-Resistant
Preconfigured functional encryption workload
Confidential vector encrypted by client into ciphertext C
Vector embedded inside recipient functional key sk_y
Underlying prime field group arithmetic
Functional Decryption Result ⟨x, y⟩ = 889
Inner Product Result
889
Scalar revealed to decryptor
Information Leakage
0.00%
Coordinates x_i remain unrevealed
Ciphertext Size
192 Bytes
(d + 1) Group elements in G_1
Decryption Time
0.42 ms
Multi-exponentiation + baby-giant dlog
Master Key: msk = (s1, ..., sd) ∈ ℤpd
Functional Key: sky = ⟨msk, y⟩ = ∑ si · yi mod p
Decryption: ∏ Ciyi / C0sky = h⟨x, y⟩
Ciphertext & Key Group Components
Curve: BN254
// 1. Functional Secret Key sk_y (Single Scalar Value)
sk_y = 0x6e2a91b4d08f32194c7a52... (Authorized for vector y)
// 2. Encrypted Ciphertext C = (C_0, C_1, ..., C_d)
C_0 = g^r: 0x03a9f1...
C_1 = g^(r*s_1) * h^(x_1): 0x027b4e...
C_2 = g^(r*s_2) * h^(x_2): 0x031c9a...
Production DDH Inner-Product Functional Encryption Python 3.11+ / Petlib (OpenSSL EC)

The Decisional Diffie-Hellman (DDH) Construction

The Abdalla-Bourse-De Caro-Pointcheval (ABDP15) scheme provides efficient IPFE under standard DDH assumptions:

  • Public Generators: Two generators $g, h in mathbb{G}$ with unknown relative discrete logarithm.
  • Master Secret: Vector $s = (s_1, ldots, s_d) in mathbb{Z}_p^d$. Public key $h_i = g^{s_i}$.
  • Encryption: For randomness $r in mathbb{Z}_p$, the ciphertext consists of $C_0 = g^r$ and $C_i = h_i^r cdot h^{x_i} = g^{r cdot s_i} cdot h^{x_i}$.
  • Homomorphic Cancellation: Exponentiating each $C_i$ by $y_i$ and dividing by $C_0^{sk_y}$ exactly cancels $g^{r sum s_i y_i}$, leaving $h^{langle x, y angle}$.

Collusion Resistance & Privacy Guarantees

Functional Encryption enforces strict mathematical boundaries against adversarial query exploitation:

  • Linear Algebraic Isolation: Possessing $sk_{y_1}$ and $sk_{y_2}$ reveals only $langle x, y_1 angle$ and $langle x, y_2 angle$. The adversary cannot recover $x$ unless they obtain $d$ linearly independent functional keys.
  • Discrete Log Bound: Because the output appears in the exponent $h^{langle x, y angle}$, decryption requires solving a small discrete logarithm via Pollard's rho or baby-step giant-step (feasible when $langle x, y angle < 2^{32}$).
  • Zero Untrusted Infrastructure Risk: Cloud inference engines can hold $sk_y$ and evaluate classification models on encrypted user data without ever possessing permission to decrypt raw inputs.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement