pub enum Distribution {
TernaryFixed(usize),
TernaryProb(f64),
BinaryFixed(usize),
BinaryProb(f64),
BinaryBlock(usize),
ENCAPSULATED(&'static str),
ZERO,
NONE,
}Expand description
Describes the probability distribution the base secret was sampled from.
Each variant encodes either a fixed Hamming weight or a per-coefficient
probability. The enum is serialised as a single little-endian u64
word via write_to / read_from.
For probabilistic variants the f64 payload is stored with a
precision loss below 2^-44 (8 least-significant mantissa bits
are discarded to fit the tag byte).
§What this tag means
It records how the key material was originally sampled, which is what the security estimate and the noise analysis are stated against. It is not a claim that a given buffer’s coefficients are, right now, an i.i.d. sample from that distribution.
The tag is set only by the fill_* samplers (and by
Distribution::ZERO for the debug all-zero secret). Every other
operation on a secret propagates it verbatim.
§Transforms that preserve it
A secret keeps its tag under any transform that permutes and/or negates coefficients, or that only changes the representation:
- the
X -> X^-1automorphism used byglwe_secret_from_lwe_secret/lwe_secret_from_glwe_secret, and any otherX -> X^kautomorphism: the multiset of non-zero coefficients, and hence the Hamming weight and the per-coefficient marginals, are unchanged (up to sign, which the ternary and binary families are analysed against anyway); - flattening a rank-
rGLWE secret into an LWE secret and back: the tag describes each polynomial component of the source key and is not rescaled by the rank; - DFT preparation (
GLWESecretPrepared) and transfers between backends: pure changes of representation.
§Where it deliberately does not describe the coefficients
GLWESecretTensor holds the products
s_i * s_j of a base secret (s_0, ..., s_{r-1}), e.g.
(1, s_0, s_1)^(x)2 = (s_0^2, s_0*s_1, s_1^2). Those coefficients are
not ternary or binary any more, and no variant of this enum describes
them. The tensor key still carries the base secret’s tag, on purpose:
it is the handle on the underlying secret’s parameters, from which the
product’s own statistics follow.
Concretely, if the base secret has zero-mean coefficients of variance
s^2 in ring degree N (for instance s^2 = h/N for
TernaryFixed(h)), then for independent
components i != j each coefficient of s_i * s_j mod X^N + 1 is a
sum of N independent products and has variance N * s^4. The diagonal
blocks s_i^2 carry twice that, 2 * N * s^4, because each unordered
pair s_a * s_b contributes to the same coefficient from both orders.
Both are measured to hold on the reference backend. The statistics of
the tensor therefore stay a closed-form function of the base
distribution recorded here; see var_tensor_key in the noise module.
Variants§
TernaryFixed(usize)
Ternary in {-1, 0, 1} with exactly h non-zero coefficients.
TernaryProb(f64)
Ternary in {-1, 0, 1} where each coefficient is non-zero with probability p.
BinaryFixed(usize)
Binary in {0, 1} with exactly h ones.
BinaryProb(f64)
Binary in {0, 1} where each coefficient is 1 with probability p.
BinaryBlock(usize)
Binary in {0, 1} split into blocks of size 2^k, with one 1 per block.
ENCAPSULATED(&'static str)
Encapsulated category, only valid within its ephemeral context: cannot back a public key and cannot be serialized.
ZERO
All-zero secret (debug / testing only).
NONE
Uninitialized — no distribution has been set yet.
Implementations§
Source§impl Distribution
impl Distribution
Sourcepub fn write_to<W: Write>(&self, writer: &mut W) -> Result<()>
pub fn write_to<W: Write>(&self, writer: &mut W) -> Result<()>
Serialises this distribution as a single little-endian u64 word.
The top byte carries a variant tag; the lower 56 bits carry either
a usize payload (for fixed/block variants) or a truncated f64
(for probabilistic variants).
ENCAPSULATED has no wire form and returns
std::io::ErrorKind::InvalidData.
Sourcepub fn read_from<R: Read>(reader: &mut R) -> Result<Self>
pub fn read_from<R: Read>(reader: &mut R) -> Result<Self>
Deserialises a Distribution from a single little-endian u64 word.
Returns std::io::ErrorKind::InvalidData if the tag byte is unrecognised.
Trait Implementations§
Source§impl Clone for Distribution
impl Clone for Distribution
Source§fn clone(&self) -> Distribution
fn clone(&self) -> Distribution
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl Copy for Distribution
Source§impl Debug for Distribution
impl Debug for Distribution
impl Eq for Distribution
Auto Trait Implementations§
impl Freeze for Distribution
impl RefUnwindSafe for Distribution
impl Send for Distribution
impl Sync for Distribution
impl Unpin for Distribution
impl UnsafeUnpin for Distribution
impl UnwindSafe for Distribution
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more