François Garillot
48412c8ee4
Merge pull request #46 from huitseeker/elligator2
...
Implement and use Elligator2 for the Curve25519 larger subgroup instance
2020-09-03 15:21:01 -04:00
François Garillot
ab8db3bf03
Propagate usage of Elligator2 map
...
Fixes #30 , #37
2020-09-03 14:17:45 -04:00
François Garillot
dede91a5b7
Add additional test vectors from Signal
2020-09-03 14:17:44 -04:00
François Garillot
f1bdfcd3a0
Add elligator mapping for hash-to-curve
2020-09-03 14:17:43 -04:00
François Garillot
cc4a292b6d
Merge pull request #45 from huitseeker/crash_tests
...
Proptests exercising `try_from` for most structures based on random data
2020-09-02 17:40:08 -04:00
François Garillot
2c9e47d14d
Proptests exercising try_from for most structures based on random data
...
This also fixes crashes in:
- RegisterFirstMessage,
- LoginFirstMessage,
- ClientRegistration,
- ClientLogin
2020-09-02 10:29:22 -04:00
Kevin Lewi
195a698ad8
Fix omission of nonce in hmac computation for envelope ( #44 )
2020-09-01 11:23:00 -07:00
Kevin Lewi
cdf0c7bf72
Update copyright in benches/oprf.rs
2020-09-01 10:23:39 -07:00
François Garillot
59af252168
Merge pull request #42 from huitseeker/dependency-updates
...
Update all dependencies to the latest version
2020-08-26 16:00:30 -04:00
François Garillot
6dde7c5351
Update all dependencies to the lates version
...
Not. now using the same upcoming dalek versions (curve25519-dalek v 3)
2020-08-26 09:44:23 -04:00
François Garillot
694c51c982
remove unneeded Repr = Key
2020-08-24 15:16:51 -04:00
François Garillot
07a702c1be
make clippy happier
2020-08-24 15:13:20 -04:00
François Garillot
29ba1b93b5
Check for small subgroup components when using the EdwardsPoint group for the OPRF
...
A malicious attacker sending a small point could lead the server / user to leak private information.
The check avoiding mixed order points (rather than just small) is prohibitively expensive, and I don't know how an attacker would extract any data from that => we focus on a small order check.
Fixes #34 .
2020-08-24 14:50:29 -04:00
Kevin Lewi
c2edb2d95e
Adding a hash type to CipherSuite ( #24 )
2020-07-27 15:25:04 -07:00
François Garillot
72a3928cbb
Merge pull request #29 from huitseeker/maintenance
...
Maintenance
2020-07-23 14:53:36 -04:00
François Garillot
6b1e485763
Update minor versions as appropriate
2020-07-23 14:49:49 -04:00
François Garillot
7b11da3bd6
Remove 2x superfluous to_vec
2020-07-23 13:45:46 -04:00
François Garillot
4aae404e29
Merge pull request #27 from huitseeker/curve2559_backends
...
Pass-through x,curve2559 backends
2020-07-22 17:56:03 -04:00
François Garillot
1f8d786be8
Merge pull request #28 from huitseeker/quickfix_26
...
Re-establish `cargo check --all-targets`
2020-07-22 17:55:53 -04:00
François Garillot
8885fe5aa1
Re-establish cargo check --all-targets
...
The bench in benches/oprf.rs requires a feature to have visibility over private members, and doesn't work without it.
`cargo check --all-targets` is the standard quick way to check code under build & test targets, but does not specify features.
This simply skips the `benches` when the `"bench"` feature it depends on is not activated.
2020-07-22 15:22:47 -04:00
François Garillot
b0b9cd0ab2
Restructure GH tests, run on u64 & u32
2020-07-22 15:04:06 -04:00
François Garillot
4fda240a7d
Pass the {curve, x}25519-dalek features through the build
2020-07-22 14:59:06 -04:00
François Garillot
5a7b60bec7
Merge pull request #26 from huitseeker/basic-benches
...
Benchmarks for the OPRF
2020-07-22 14:38:34 -04:00
François Garillot
91137903c6
Add benchmarks for OPRF functions (under a bench feature)
2020-07-22 14:32:58 -04:00
François Garillot
e93e8fd5a8
Make the group mod public
2020-07-22 11:58:00 -04:00
Kevin Lewi
f8285c60ba
Introducing a trait for key exchange ( #20 )
2020-07-13 15:23:29 -07:00
François Garillot
2959290582
Merge pull request #22 from huitseeker/missing_docs
...
Activate #![deny(missing_docs)], #![deny(unsafe_code)]
2020-07-06 16:01:42 -04:00
François Garillot
69449cca3e
Activate #![deny(missing_docs)], #![deny(unsafe_code)]
2020-07-06 15:40:35 -04:00
François Garillot
988b9bae77
Merge pull request #21 from huitseeker/digest-on-group
...
Restructure password-hashing-to-the-curve as an extension trait of Group
2020-07-03 21:10:11 -04:00
François Garillot and KevinLewi
9d40aa7659
As a way to roll back the genericity, implement an extension trait of group for password-to-curve hashing,
...
This supersedes #18 .
Co-authored-by: KevinLewi <[email protected] >
2020-07-03 21:05:18 -04:00
François Garillot
41cd80ccb5
Make oprf::generate_oprf1 generic in the Digest, as long as it matches the hash-to-curve intake of the group
...
We used to have three problems:
- overuse of the <Sha256 as Digest>::OutputSize, which is just, well, U32. Sometimes used as a parameter (as in generate_oprf1), sometimes as a constant (as in generate_oprf3).
- the `hash_to_curve` operation for `RistrettoPoint` which requires 64 bits of input entropy, is fed 64 bits of which the last 32 are zero,
- the `hash_to_curve` operation for `Curve25519Point` which requires 32 bits of input entropy, is fed 64 bits of which the last 32 are discarded,
This corrects all three and uses U32 where the size of the digest is not meant to be a constraint.
Addresses #15 partially.
2020-07-03 18:28:34 -04:00
François Garillot
45ea7b6e84
Merge pull request #19 from huitseeker/simplify_types
...
Straightforward cleanups
2020-07-03 17:37:28 -04:00
François Garillot
52429dd2fa
fix a clone-on-copy-type
2020-07-03 17:30:33 -04:00
François Garillot
bb9c365998
Rename Group::to_bytes() into Group::to_arr(),
...
This brings the `Group` and `SizedBytes` traits into some sort of name
coherence (they both return a GenericArray). This also uses
`&my_generic_array[..]` (i.e. the `Deref` impl) over
`my_generic_array.as_slice()`.
2020-07-03 17:30:32 -04:00
François Garillot
3e41f2441d
mention issue for direct call into uniform_bytes in RistrattoPoint
2020-07-03 16:12:14 -04:00
François Garillot
59d997900e
Simplify "<CS as CipherSuite>" where possible
2020-07-03 15:58:42 -04:00
Kevin Lewi
6d02c72aae
Updating to draft-krawczyk-cfrg-opaque-06, reworking envelope construction and removing AEAD ( #14 )
...
Updating to draft-krawczyk-cfrg-opaque-06, reworking envelope construction and removing AEAD
2020-07-02 12:24:53 -07:00
François Garillot
4a638b8a22
add deny check to CI
2020-06-29 15:52:30 -07:00
zer0x64
1a5e704cf6
updated CONTRIBUTING.md
2020-06-22 12:26:24 -07:00
François Garillot
d5e585db1d
Merge pull request #12 from huitseeker/backports
...
Backports from the Key Exchange customization PR
2020-06-19 15:33:31 -04:00
François Garillot
642d5188f5
Run CI with all-features
2020-06-19 15:24:04 -04:00
François Garillot
c9d467e368
Add (normal) macros showing how to generate SizedBytes to/from TryFrom + to_bytes
...
This is useful for getting serialization of the KEXState, KEXMessage formats without too much boilerplate
Add client_login, login_first_message roundtrip serialization tests
2020-06-19 15:23:21 -04:00
François Garillot
738b90188d
add build badge
2020-06-19 15:23:04 -04:00
François Garillot
7a2d309263
Moves the keypair generation to an extension trait
...
This technical change lets us avoid polluting the code with derives of Debug.
2020-06-19 15:23:03 -04:00
François Garillot
f989330807
Merge pull request #9 from huitseeker/updates
...
Update digest & hash libraries to their latest versions
2020-06-16 09:27:23 -04:00
François Garillot
4f9b7fe86f
Update digest & hashes libraries to their latest versions
2020-06-16 06:24:14 -07:00
Kevin Lewi
aab8ff8e19
Merge pull request #8 from kevinlewi/bundle_api
...
Adding CipherSuite trait to handle bundling of underlying crypto primitives
2020-06-15 17:42:18 -07:00
Kevin Lewi
2cf6808665
Adding documentation to each component of CipherSuite
2020-06-15 16:40:46 -07:00
Kevin Lewi
ab1b1d6209
Adding CipherSuite trait to handle bundling of underlying crypto primitives
2020-06-14 23:29:25 -07:00
Kevin Lewi
0cf13c2266
Adding CipherSuite trait to handle bundling of underlying crypto primitives
2020-06-14 23:25:31 -07:00