Configure Rustfmt and Taplo (#38)
* Configure rustfmt * Add Taplo configuration and run in CI
This commit is contained in:
+121
-118
@@ -14,10 +14,10 @@
|
||||
//!
|
||||
//! # Overview
|
||||
//!
|
||||
//! A verifiable oblivious pseudorandom function is a protocol that is
|
||||
//! evaluated between a client and a server. They must first agree on a
|
||||
//! collection of primitives to be kept consistent throughout protocol
|
||||
//! execution. These include:
|
||||
//! A verifiable oblivious pseudorandom function is a protocol that is evaluated
|
||||
//! between a client and a server. They must first agree on a collection of
|
||||
//! primitives to be kept consistent throughout protocol execution. These
|
||||
//! include:
|
||||
//! - a finite cyclic group along with a point representation, and
|
||||
//! - a hashing function.
|
||||
//!
|
||||
@@ -31,35 +31,35 @@
|
||||
//! ## Modes of Operation
|
||||
//!
|
||||
//! VOPRF can be used in two modes:
|
||||
//! - [Base Mode](#base-mode), which corresponds to a normal OPRF evaluation with no
|
||||
//! support for the verification of the OPRF outputs
|
||||
//! - [Verifiable Mode](#verifiable-mode), which corresponds to an OPRF evaluation where
|
||||
//! the outputs can be verified against a server public key
|
||||
//! - [Base Mode](#base-mode), which corresponds to a normal OPRF evaluation
|
||||
//! with no support for the verification of the OPRF outputs
|
||||
//! - [Verifiable Mode](#verifiable-mode), which corresponds to an OPRF
|
||||
//! evaluation where the outputs can be verified against a server public key
|
||||
//!
|
||||
//! In either mode, the protocol begins with a client blinding, followed by
|
||||
//! a server evaluation, and finishes with a client finalization.
|
||||
//! In either mode, the protocol begins with a client blinding, followed by a
|
||||
//! server evaluation, and finishes with a client finalization.
|
||||
//!
|
||||
//! ## Base Mode
|
||||
//!
|
||||
//! In base mode, a [NonVerifiableClient] interacts with a
|
||||
//! [NonVerifiableServer] to compute the output of the VOPRF.
|
||||
//! In base mode, a [NonVerifiableClient] interacts with a [NonVerifiableServer]
|
||||
//! to compute the output of the VOPRF.
|
||||
//!
|
||||
//! ### Server Setup
|
||||
//!
|
||||
//! The protocol begins with a setup phase, in which the server must run
|
||||
//! [NonVerifiableServer::new()] to produce an instance of itself. This
|
||||
//! instance must be persisted on the server and used for online
|
||||
//! client evaluations.
|
||||
//! [NonVerifiableServer::new()] to produce an instance of itself. This instance
|
||||
//! must be persisted on the server and used for online client evaluations.
|
||||
//!
|
||||
//! ```
|
||||
//! # type Group = curve25519_dalek::ristretto::RistrettoPoint;
|
||||
//! # type Hash = sha2::Sha512;
|
||||
//! use rand::rngs::OsRng;
|
||||
//! use rand::RngCore;
|
||||
//! use voprf::NonVerifiableServer;
|
||||
//! use rand::{rngs::OsRng, RngCore};
|
||||
//!
|
||||
//! let mut server_rng = OsRng;
|
||||
//! let server = NonVerifiableServer::<Group, Hash>::new(&mut server_rng)
|
||||
//! .expect("Unable to construct server");
|
||||
//! .expect("Unable to construct server");
|
||||
//! ```
|
||||
//!
|
||||
//! ### Client Blinding
|
||||
@@ -73,14 +73,14 @@
|
||||
//! ```
|
||||
//! # type Group = curve25519_dalek::ristretto::RistrettoPoint;
|
||||
//! # type Hash = sha2::Sha512;
|
||||
//! use rand::rngs::OsRng;
|
||||
//! use rand::RngCore;
|
||||
//! use voprf::NonVerifiableClient;
|
||||
//! use rand::{rngs::OsRng, RngCore};
|
||||
//!
|
||||
//! let mut client_rng = OsRng;
|
||||
//! let client_blind_result = NonVerifiableClient::<Group, Hash>::blind(
|
||||
//! b"input".to_vec(),
|
||||
//! &mut client_rng,
|
||||
//! ).expect("Unable to construct client");
|
||||
//! let client_blind_result =
|
||||
//! NonVerifiableClient::<Group, Hash>::blind(b"input".to_vec(), &mut client_rng)
|
||||
//! .expect("Unable to construct client");
|
||||
//! ```
|
||||
//!
|
||||
//! ### Server Evaluation
|
||||
@@ -106,10 +106,9 @@
|
||||
//! # let mut server_rng = OsRng;
|
||||
//! # let server = NonVerifiableServer::<Group, Hash>::new(&mut server_rng)
|
||||
//! # .expect("Unable to construct server");
|
||||
//! let server_evaluate_result = server.evaluate(
|
||||
//! &client_blind_result.message,
|
||||
//! None,
|
||||
//! ).expect("Unable to perform server evaluate");
|
||||
//! let server_evaluate_result = server
|
||||
//! .evaluate(&client_blind_result.message, None)
|
||||
//! .expect("Unable to perform server evaluate");
|
||||
//! ```
|
||||
//!
|
||||
//! ### Client Finalization
|
||||
@@ -137,79 +136,79 @@
|
||||
//! # &client_blind_result.message,
|
||||
//! # None,
|
||||
//! # ).expect("Unable to perform server evaluate");
|
||||
//! let client_finalize_result = client_blind_result.state.finalize(
|
||||
//! &server_evaluate_result.message,
|
||||
//! None,
|
||||
//! ).expect("Unable to perform client finalization");
|
||||
//! let client_finalize_result = client_blind_result
|
||||
//! .state
|
||||
//! .finalize(&server_evaluate_result.message, None)
|
||||
//! .expect("Unable to perform client finalization");
|
||||
//!
|
||||
//! println!("VOPRF output: {:?}", client_finalize_result.to_vec());
|
||||
//! ```
|
||||
//!
|
||||
//! ## Verifiable Mode
|
||||
//!
|
||||
//! In verifiable mode, a [VerifiableClient] interacts with a
|
||||
//! [VerifiableServer] to compute the output of the VOPRF. In order to
|
||||
//! verify the server's computation, the client checks a server-generated
|
||||
//! proof against the server's public key. If the proof fails to verify,
|
||||
//! then the client does not receive an output.
|
||||
//! In verifiable mode, a [VerifiableClient] interacts with a [VerifiableServer]
|
||||
//! to compute the output of the VOPRF. In order to verify the server's
|
||||
//! computation, the client checks a server-generated proof against the server's
|
||||
//! public key. If the proof fails to verify, then the client does not receive
|
||||
//! an output.
|
||||
//!
|
||||
//! In batch mode, a single proof can be used for multiple VOPRF evaluations.
|
||||
//! See [the batching section](#batching)
|
||||
//! for more details on how to perform batch evaluations.
|
||||
//! See [the batching section](#batching) for more details on how to perform
|
||||
//! batch evaluations.
|
||||
//!
|
||||
//! ### Server Setup
|
||||
//!
|
||||
//! The protocol begins with a setup phase, in which the server must run
|
||||
//! [VerifiableServer::new()] to produce an instance of itself. This
|
||||
//! instance must be persisted on the server and used for online
|
||||
//! client evaluations.
|
||||
//! [VerifiableServer::new()] to produce an instance of itself. This instance
|
||||
//! must be persisted on the server and used for online client evaluations.
|
||||
//!
|
||||
//! ```
|
||||
//! # type Group = curve25519_dalek::ristretto::RistrettoPoint;
|
||||
//! # type Hash = sha2::Sha512;
|
||||
//! use rand::rngs::OsRng;
|
||||
//! use rand::RngCore;
|
||||
//! use voprf::VerifiableServer;
|
||||
//! use rand::{rngs::OsRng, RngCore};
|
||||
//!
|
||||
//! let mut server_rng = OsRng;
|
||||
//! let server = VerifiableServer::<Group, Hash>::new(&mut server_rng)
|
||||
//! .expect("Unable to construct server");
|
||||
//! let server =
|
||||
//! VerifiableServer::<Group, Hash>::new(&mut server_rng).expect("Unable to construct server");
|
||||
//!
|
||||
//! // To be sent to the client
|
||||
//! println!("Server public key: {:?}", server.get_public_key());
|
||||
//! ```
|
||||
//!
|
||||
//! The public key should be sent to the client, since the client will
|
||||
//! need it in the final step of the protocol in order to complete
|
||||
//! the evaluation of the VOPRF.
|
||||
//! The public key should be sent to the client, since the client will need it
|
||||
//! in the final step of the protocol in order to complete the evaluation of the
|
||||
//! VOPRF.
|
||||
//!
|
||||
//! ### Client Blinding
|
||||
//!
|
||||
//! In the first step, the client chooses an input, and runs
|
||||
//! [VerifiableClient::blind] to produce a [VerifiableClientBlindResult],
|
||||
//! which consists of a [BlindedElement] to be sent to the server and a
|
||||
//! [VerifiableClient] which must be persisted on the client for the final
|
||||
//! step of the VOPRF protocol.
|
||||
//! [VerifiableClient::blind] to produce a [VerifiableClientBlindResult], which
|
||||
//! consists of a [BlindedElement] to be sent to the server and a
|
||||
//! [VerifiableClient] which must be persisted on the client for the final step
|
||||
//! of the VOPRF protocol.
|
||||
//!
|
||||
//! ```
|
||||
//! # type Group = curve25519_dalek::ristretto::RistrettoPoint;
|
||||
//! # type Hash = sha2::Sha512;
|
||||
//! use rand::rngs::OsRng;
|
||||
//! use rand::RngCore;
|
||||
//! use voprf::VerifiableClient;
|
||||
//! use rand::{rngs::OsRng, RngCore};
|
||||
//!
|
||||
//! let mut client_rng = OsRng;
|
||||
//! let client_blind_result = VerifiableClient::<Group, Hash>::blind(
|
||||
//! b"input".to_vec(),
|
||||
//! &mut client_rng,
|
||||
//! ).expect("Unable to construct client");
|
||||
//! let client_blind_result =
|
||||
//! VerifiableClient::<Group, Hash>::blind(b"input".to_vec(), &mut client_rng)
|
||||
//! .expect("Unable to construct client");
|
||||
//! ```
|
||||
//!
|
||||
//! ### Server Evaluation
|
||||
//!
|
||||
//! In the second step, the server takes as input the message from
|
||||
//! [VerifiableClient::blind] (a [BlindedElement]), and runs
|
||||
//! [VerifiableServer::evaluate] to produce a
|
||||
//! [VerifiableServerEvaluateResult], which consists of an
|
||||
//! [EvaluationElement] to be sent to the client along with a proof.
|
||||
//! [VerifiableServer::evaluate] to produce a [VerifiableServerEvaluateResult],
|
||||
//! which consists of an [EvaluationElement] to be sent to the client along with
|
||||
//! a proof.
|
||||
//!
|
||||
//! ```
|
||||
//! # type Group = curve25519_dalek::ristretto::RistrettoPoint;
|
||||
@@ -226,19 +225,17 @@
|
||||
//! # let mut server_rng = OsRng;
|
||||
//! # let server = VerifiableServer::<Group, Hash>::new(&mut server_rng)
|
||||
//! # .expect("Unable to construct server");
|
||||
//! let server_evaluate_result = server.evaluate(
|
||||
//! &mut server_rng,
|
||||
//! &client_blind_result.message,
|
||||
//! None,
|
||||
//! ).expect("Unable to perform server evaluate");
|
||||
//! let server_evaluate_result = server
|
||||
//! .evaluate(&mut server_rng, &client_blind_result.message, None)
|
||||
//! .expect("Unable to perform server evaluate");
|
||||
//! ```
|
||||
//!
|
||||
//! ### Client Finalization
|
||||
//!
|
||||
//! In the final step, the client takes as input the message from
|
||||
//! [VerifiableServer::evaluate] (an [EvaluationElement]),
|
||||
//! the proof, and the server's public key, and runs
|
||||
//! [VerifiableClient::finalize] to produce an output for the protocol.
|
||||
//! [VerifiableServer::evaluate] (an [EvaluationElement]), the proof, and the
|
||||
//! server's public key, and runs [VerifiableClient::finalize] to produce an
|
||||
//! output for the protocol.
|
||||
//!
|
||||
//! ```
|
||||
//! # type Group = curve25519_dalek::ristretto::RistrettoPoint;
|
||||
@@ -260,12 +257,15 @@
|
||||
//! # &client_blind_result.message,
|
||||
//! # None,
|
||||
//! # ).expect("Unable to perform server evaluate");
|
||||
//! let client_finalize_result = client_blind_result.state.finalize(
|
||||
//! &server_evaluate_result.message,
|
||||
//! &server_evaluate_result.proof,
|
||||
//! server.get_public_key(),
|
||||
//! None,
|
||||
//! ).expect("Unable to perform client finalization");
|
||||
//! let client_finalize_result = client_blind_result
|
||||
//! .state
|
||||
//! .finalize(
|
||||
//! &server_evaluate_result.message,
|
||||
//! &server_evaluate_result.proof,
|
||||
//! server.get_public_key(),
|
||||
//! None,
|
||||
//! )
|
||||
//! .expect("Unable to perform client finalization");
|
||||
//!
|
||||
//! println!("VOPRF output: {:?}", client_finalize_result.to_vec());
|
||||
//! ```
|
||||
@@ -278,15 +278,14 @@
|
||||
//!
|
||||
//! ## Batching
|
||||
//!
|
||||
//! It is sometimes desirable to generate only a single, constant-size
|
||||
//! proof for an unbounded number of VOPRF evaluations (on arbitrary inputs).
|
||||
//! [VerifiableClient] and [VerifiableServer] support a batch API for
|
||||
//! handling this case. In the following example, we show how to use
|
||||
//! the batch API to produce a single proof for 10 parallel
|
||||
//! VOPRF evaluations.
|
||||
//! It is sometimes desirable to generate only a single, constant-size proof for
|
||||
//! an unbounded number of VOPRF evaluations (on arbitrary inputs).
|
||||
//! [VerifiableClient] and [VerifiableServer] support a batch API for handling
|
||||
//! this case. In the following example, we show how to use the batch API to
|
||||
//! produce a single proof for 10 parallel VOPRF evaluations.
|
||||
//!
|
||||
//! First, the client produces 10 blindings, storing their resulting
|
||||
//! states and messages:
|
||||
//! First, the client produces 10 blindings, storing their resulting states and
|
||||
//! messages:
|
||||
//!
|
||||
//! ```
|
||||
//! # type Group = curve25519_dalek::ristretto::RistrettoPoint;
|
||||
@@ -298,19 +297,18 @@
|
||||
//! let mut client_states = vec![];
|
||||
//! let mut client_messages = vec![];
|
||||
//! for _ in 0..10 {
|
||||
//! let client_blind_result = VerifiableClient::<Group, Hash>::blind(
|
||||
//! b"input".to_vec(),
|
||||
//! &mut client_rng,
|
||||
//! ).expect("Unable to construct client");
|
||||
//! let client_blind_result =
|
||||
//! VerifiableClient::<Group, Hash>::blind(b"input".to_vec(), &mut client_rng)
|
||||
//! .expect("Unable to construct client");
|
||||
//! client_states.push(client_blind_result.state);
|
||||
//! client_messages.push(client_blind_result.message);
|
||||
//! }
|
||||
//! ```
|
||||
//!
|
||||
//! Next, the server calls the [VerifiableServer::batch_evaluate]
|
||||
//! function on a set of client messages, to produce a corresponding
|
||||
//! set of messages to be returned to the client (returned in the same order),
|
||||
//! along with a single proof:
|
||||
//! Next, the server calls the [VerifiableServer::batch_evaluate] function on a
|
||||
//! set of client messages, to produce a corresponding set of messages to be
|
||||
//! returned to the client (returned in the same order), along with a single
|
||||
//! proof:
|
||||
//!
|
||||
//! ```
|
||||
//! # type Group = curve25519_dalek::ristretto::RistrettoPoint;
|
||||
@@ -333,17 +331,15 @@
|
||||
//! let mut server_rng = OsRng;
|
||||
//! # let server = VerifiableServer::<Group, Hash>::new(&mut server_rng)
|
||||
//! # .expect("Unable to construct server");
|
||||
//! let server_batch_evaluate_result = server.batch_evaluate(
|
||||
//! &mut server_rng,
|
||||
//! &client_messages,
|
||||
//! None,
|
||||
//! ).expect("Unable to perform server batch evaluate");
|
||||
//! let server_batch_evaluate_result = server
|
||||
//! .batch_evaluate(&mut server_rng, &client_messages, None)
|
||||
//! .expect("Unable to perform server batch evaluate");
|
||||
//! ```
|
||||
//!
|
||||
//! Then, the client calls [VerifiableClient::batch_finalize] on
|
||||
//! the client states saved from the first step, along with the messages
|
||||
//! returned by the server, along with the server's proof, in order to produce
|
||||
//! a vector of outputs if the proof verifies correctly.
|
||||
//! Then, the client calls [VerifiableClient::batch_finalize] on the client
|
||||
//! states saved from the first step, along with the messages returned by the
|
||||
//! server, along with the server's proof, in order to produce a vector of
|
||||
//! outputs if the proof verifies correctly.
|
||||
//!
|
||||
//! ```
|
||||
//! # type Group = curve25519_dalek::ristretto::RistrettoPoint;
|
||||
@@ -377,7 +373,8 @@
|
||||
//! &server_batch_evaluate_result.proof,
|
||||
//! server.get_public_key(),
|
||||
//! None,
|
||||
//! ).expect("Unable to perform client batch finalization");
|
||||
//! )
|
||||
//! .expect("Unable to perform client batch finalization");
|
||||
//!
|
||||
//! println!("VOPRF batch outputs: {:?}", client_batch_finalize_result);
|
||||
//! ```
|
||||
@@ -386,34 +383,40 @@
|
||||
//!
|
||||
//! The optional metadata parameter included in the protocol allows clients and
|
||||
//! servers (of either mode) to cryptographically bind additional data to the
|
||||
//! VOPRF output. This metadata is known to both parties at the start of the protocol,
|
||||
//! and is inserted under the server's evaluate step and the client's finalize step.
|
||||
//! This metadata can be constructed with some type of higher-level domain separation
|
||||
//! to avoid cross-protocol attacks or related issues.
|
||||
//! VOPRF output. This metadata is known to both parties at the start of the
|
||||
//! protocol, and is inserted under the server's evaluate step and the client's
|
||||
//! finalize step. This metadata can be constructed with some type of
|
||||
//! higher-level domain separation to avoid cross-protocol attacks or related
|
||||
//! issues.
|
||||
//!
|
||||
//! A custom metadata can be specified, for example, by: `Some(b"custom metadata")`.
|
||||
//! A custom metadata can be specified, for example, by:
|
||||
//! `Some(b"custom metadata")`.
|
||||
//!
|
||||
//! # Features
|
||||
//!
|
||||
//! - The `p256` feature enables using p256 as the underlying group for the [Group](group::Group) choice.
|
||||
//! Note that this is currently an experimental feature ⚠️, and is not yet ready for production use.
|
||||
//! - The `p256` feature enables using p256 as the underlying group for the
|
||||
//! [Group](group::Group) choice. Note that this is currently an experimental
|
||||
//! feature ⚠️, and is not yet ready for production use.
|
||||
//!
|
||||
//! - The `serde` feature, enabled by default, provides convenience functions for serializing and deserializing with
|
||||
//! [serde](https://serde.rs/).
|
||||
//! - The `serde` feature, enabled by default, provides convenience functions
|
||||
//! for serializing and deserializing with [serde](https://serde.rs/).
|
||||
//!
|
||||
//! - The `danger` feature, disabled by default, exposes functions for setting and getting
|
||||
//! internal values not available in the default API. These functions are intended for use in
|
||||
//! by higher-level cryptographic protocols that need access to these raw values and are able to
|
||||
//! perform the necessary validations on them (such as being valid group elements).
|
||||
//! - The `danger` feature, disabled by default, exposes functions for setting
|
||||
//! and getting internal values not available in the default API. These
|
||||
//! functions are intended for use in by higher-level cryptographic protocols
|
||||
//! that need access to these raw values and are able to perform the necessary
|
||||
//! validations on them (such as being valid group elements).
|
||||
//!
|
||||
//! - The backend features are re-exported from
|
||||
//! [curve25519-dalek](https://doc.dalek.rs/curve25519_dalek/index.html#backends-and-features) and allow for selecting
|
||||
//! the corresponding backend for the curve arithmetic used. The `ristretto255_u64` feature is included as the default.
|
||||
//! Other features are mapped as `ristretto255_u32`, `ristretto255_fiat_u64` and `ristretto255_fiat_u32`.
|
||||
//! - The backend features are re-exported from [curve25519-dalek](https://doc.dalek.rs/curve25519_dalek/index.html#backends-and-features)
|
||||
//! and allow for selecting the corresponding backend for the curve arithmetic
|
||||
//! used. The `ristretto255_u64` feature is included as the default. Other
|
||||
//! features are mapped as `ristretto255_u32`, `ristretto255_fiat_u64` and
|
||||
//! `ristretto255_fiat_u32`.
|
||||
//!
|
||||
//! - The `ristretto255_simd` feature is re-exported from
|
||||
//! [curve25519-dalek](https://doc.dalek.rs/curve25519_dalek/index.html#backends-and-features) and enables parallel formulas,
|
||||
//! using either AVX2 or AVX512-IFMA. This will automatically enable the `ristretto255_u64` feature and requires Rust nightly.
|
||||
//! - The `ristretto255_simd` feature is re-exported from [curve25519-dalek](https://doc.dalek.rs/curve25519_dalek/index.html#backends-and-features)
|
||||
//! and enables parallel formulas, using either AVX2 or AVX512-IFMA. This will
|
||||
//! automatically enable the `ristretto255_u64` feature and requires Rust
|
||||
//! nightly.
|
||||
|
||||
#![deny(unsafe_code)]
|
||||
#![no_std]
|
||||
|
||||
Reference in New Issue
Block a user