2023-05-22 23:04:39 -07:00
|
|
|
// Copyright (c) Meta Platforms, Inc. and affiliates.
|
2022-01-21 22:52:09 +01:00
|
|
|
//
|
2023-05-22 23:04:39 -07:00
|
|
|
// This source code is dual-licensed under either the MIT license found in the
|
|
|
|
|
// LICENSE-MIT file in the root directory of this source tree or the Apache
|
2022-01-21 22:52:09 +01:00
|
|
|
// License, Version 2.0 found in the LICENSE-APACHE file in the root directory
|
2023-05-22 23:04:39 -07:00
|
|
|
// of this source tree. You may select, at your option, one of the above-listed
|
|
|
|
|
// licenses.
|
2022-01-21 22:52:09 +01:00
|
|
|
|
|
|
|
|
//! Defines the CipherSuite trait to specify the underlying primitives for VOPRF
|
|
|
|
|
|
|
|
|
|
use crate::Group;
|
2026-06-27 17:04:58 +02:00
|
|
|
use core::ops::Mul;
|
|
|
|
|
use digest::block_api::BlockSizeUser;
|
|
|
|
|
use digest::typenum::{IsLess, IsLessOrEqual, U256};
|
|
|
|
|
use digest::{Digest, FixedOutput, HashMarker, OutputSizeUser};
|
2026-06-28 13:14:48 +02:00
|
|
|
use hash2curve::OprfParameters;
|
2026-06-27 17:04:58 +02:00
|
|
|
use hybrid_array::ArraySize;
|
|
|
|
|
use hybrid_array::typenum::{IsGreaterOrEqual, Prod, True, U2};
|
2022-01-21 22:52:09 +01:00
|
|
|
|
|
|
|
|
/// Configures the underlying primitives used in VOPRF
|
|
|
|
|
pub trait CipherSuite
|
|
|
|
|
where
|
2026-06-27 17:04:58 +02:00
|
|
|
<Self::Group as Group>::SecurityLevel: Mul<U2>,
|
|
|
|
|
<Self::Hash as OutputSizeUser>::OutputSize: ArraySize
|
|
|
|
|
+ IsLess<U256>
|
|
|
|
|
+ IsLessOrEqual<<Self::Hash as BlockSizeUser>::BlockSize, Output = True>
|
|
|
|
|
+ IsGreaterOrEqual<Prod<<Self::Group as Group>::SecurityLevel, U2>, Output = True>,
|
2022-01-21 22:52:09 +01:00
|
|
|
{
|
|
|
|
|
/// The ciphersuite identifier as dictated by
|
2024-01-11 11:58:36 -08:00
|
|
|
/// <https://www.rfc-editor.org/rfc/rfc9497>
|
2026-06-27 17:04:58 +02:00
|
|
|
const ID: &'static [u8];
|
2022-01-21 22:52:09 +01:00
|
|
|
|
|
|
|
|
/// A finite cyclic group along with a point representation that allows some
|
|
|
|
|
/// customization on how to hash an input to a curve point. See [`Group`].
|
|
|
|
|
type Group: Group;
|
|
|
|
|
|
|
|
|
|
/// The main hash function to use (for HKDF computations and hashing
|
|
|
|
|
/// transcripts).
|
2026-06-27 17:04:58 +02:00
|
|
|
type Hash: Digest + BlockSizeUser + Default + FixedOutput + HashMarker;
|
2022-01-21 22:52:09 +01:00
|
|
|
}
|
2026-06-28 13:14:48 +02:00
|
|
|
|
|
|
|
|
/// A generic [`CipherSuite`] implementation for any compatible (Group, Hash) pair
|
|
|
|
|
#[allow(dead_code)]
|
|
|
|
|
#[derive(Debug)]
|
|
|
|
|
pub struct Suite<G, H>(core::marker::PhantomData<(G, H)>);
|
|
|
|
|
|
|
|
|
|
impl<G, H> CipherSuite for Suite<G, H>
|
|
|
|
|
where
|
|
|
|
|
G: Group + OprfParameters,
|
|
|
|
|
H: BlockSizeUser + Default + FixedOutput + HashMarker + OutputSizeUser,
|
|
|
|
|
<G as Group>::SecurityLevel: Mul<U2>,
|
|
|
|
|
<H as OutputSizeUser>::OutputSize: ArraySize
|
|
|
|
|
+ IsLess<U256>
|
|
|
|
|
+ IsLessOrEqual<<H as BlockSizeUser>::BlockSize, Output = True>
|
|
|
|
|
+ IsGreaterOrEqual<Prod<<G as Group>::SecurityLevel, U2>, Output = True>,
|
|
|
|
|
{
|
|
|
|
|
const ID: &'static [u8] = G::ID;
|
|
|
|
|
type Group = G;
|
|
|
|
|
type Hash = H;
|
|
|
|
|
}
|