Skip to main content

Distribution

Enum Distribution 

Source
pub enum Distribution {
    TernaryFixed(usize),
    TernaryProb(f64),
    BinaryFixed(usize),
    BinaryProb(f64),
    BinaryBlock(usize),
    ENCAPSULATED(&'static str),
    ZERO,
    NONE,
}
Expand description

Describes the probability distribution the base secret was sampled from.

Each variant encodes either a fixed Hamming weight or a per-coefficient probability. The enum is serialised as a single little-endian u64 word via write_to / read_from.

For probabilistic variants the f64 payload is stored with a precision loss below 2^-44 (8 least-significant mantissa bits are discarded to fit the tag byte).

§What this tag means

It records how the key material was originally sampled, which is what the security estimate and the noise analysis are stated against. It is not a claim that a given buffer’s coefficients are, right now, an i.i.d. sample from that distribution.

The tag is set only by the fill_* samplers (and by Distribution::ZERO for the debug all-zero secret). Every other operation on a secret propagates it verbatim.

§Transforms that preserve it

A secret keeps its tag under any transform that permutes and/or negates coefficients, or that only changes the representation:

  • the X -> X^-1 automorphism used by glwe_secret_from_lwe_secret / lwe_secret_from_glwe_secret, and any other X -> X^k automorphism: the multiset of non-zero coefficients, and hence the Hamming weight and the per-coefficient marginals, are unchanged (up to sign, which the ternary and binary families are analysed against anyway);
  • flattening a rank-r GLWE secret into an LWE secret and back: the tag describes each polynomial component of the source key and is not rescaled by the rank;
  • DFT preparation (GLWESecretPrepared) and transfers between backends: pure changes of representation.

§Where it deliberately does not describe the coefficients

GLWESecretTensor holds the products s_i * s_j of a base secret (s_0, ..., s_{r-1}), e.g. (1, s_0, s_1)^(x)2 = (s_0^2, s_0*s_1, s_1^2). Those coefficients are not ternary or binary any more, and no variant of this enum describes them. The tensor key still carries the base secret’s tag, on purpose: it is the handle on the underlying secret’s parameters, from which the product’s own statistics follow.

Concretely, if the base secret has zero-mean coefficients of variance s^2 in ring degree N (for instance s^2 = h/N for TernaryFixed(h)), then for independent components i != j each coefficient of s_i * s_j mod X^N + 1 is a sum of N independent products and has variance N * s^4. The diagonal blocks s_i^2 carry twice that, 2 * N * s^4, because each unordered pair s_a * s_b contributes to the same coefficient from both orders. Both are measured to hold on the reference backend. The statistics of the tensor therefore stay a closed-form function of the base distribution recorded here; see var_tensor_key in the noise module.

Variants§

§

TernaryFixed(usize)

Ternary in {-1, 0, 1} with exactly h non-zero coefficients.

§

TernaryProb(f64)

Ternary in {-1, 0, 1} where each coefficient is non-zero with probability p.

§

BinaryFixed(usize)

Binary in {0, 1} with exactly h ones.

§

BinaryProb(f64)

Binary in {0, 1} where each coefficient is 1 with probability p.

§

BinaryBlock(usize)

Binary in {0, 1} split into blocks of size 2^k, with one 1 per block.

§

ENCAPSULATED(&'static str)

Encapsulated category, only valid within its ephemeral context: cannot back a public key and cannot be serialized.

§

ZERO

All-zero secret (debug / testing only).

§

NONE

Uninitialized — no distribution has been set yet.

Implementations§

Source§

impl Distribution

Source

pub fn write_to<W: Write>(&self, writer: &mut W) -> Result<()>

Serialises this distribution as a single little-endian u64 word.

The top byte carries a variant tag; the lower 56 bits carry either a usize payload (for fixed/block variants) or a truncated f64 (for probabilistic variants).

ENCAPSULATED has no wire form and returns std::io::ErrorKind::InvalidData.

Source

pub fn read_from<R: Read>(reader: &mut R) -> Result<Self>

Deserialises a Distribution from a single little-endian u64 word.

Returns std::io::ErrorKind::InvalidData if the tag byte is unrecognised.

Trait Implementations§

Source§

impl Clone for Distribution

Source§

fn clone(&self) -> Distribution

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Distribution

Source§

impl Debug for Distribution

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for Distribution

Source§

impl PartialEq for Distribution

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V