Compare commits
13
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
eb55e9f5b5 | ||
|
|
e944f9db3b | ||
|
|
f3f4fef0e9 | ||
|
|
23aa7813e7 | ||
|
|
0473d9db68 | ||
|
|
f0531f0812 | ||
|
|
c93884aca3 | ||
|
|
40769f7eca | ||
|
|
1b67086028 | ||
|
|
68cc7d3709 | ||
|
|
59e3fedb21 | ||
|
|
8da56845b8 | ||
|
|
c0162ec8d9 |
+12
-12
@@ -4,7 +4,7 @@ on:
|
|||||||
branches:
|
branches:
|
||||||
- main
|
- main
|
||||||
pull_request:
|
pull_request:
|
||||||
types: [opened, repoened, synchronize]
|
types: [opened, reopened, synchronize]
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
cargo-audit:
|
cargo-audit:
|
||||||
@@ -12,7 +12,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Cache cargo-audit
|
- name: Cache cargo-audit
|
||||||
uses: actions/cache@v3
|
uses: actions/cache@v4
|
||||||
with:
|
with:
|
||||||
path: |
|
path: |
|
||||||
~/.cargo/.crates.toml
|
~/.cargo/.crates.toml
|
||||||
@@ -24,7 +24,7 @@ jobs:
|
|||||||
run: cargo install cargo-audit
|
run: cargo install cargo-audit
|
||||||
|
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Run cargo audit
|
- name: Run cargo audit
|
||||||
run: cargo audit -D warnings
|
run: cargo audit -D warnings
|
||||||
@@ -43,11 +43,11 @@ jobs:
|
|||||||
- --features serde
|
- --features serde
|
||||||
toolchain:
|
toolchain:
|
||||||
- stable
|
- stable
|
||||||
- 1.65.0
|
- 1.83.0
|
||||||
name: test
|
name: test
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Install ${{ matrix.toolchain }} toolchain
|
- name: Install ${{ matrix.toolchain }} toolchain
|
||||||
uses: actions-rs/toolchain@v1
|
uses: actions-rs/toolchain@v1
|
||||||
@@ -99,8 +99,8 @@ jobs:
|
|||||||
- --features danger
|
- --features danger
|
||||||
- --features serde
|
- --features serde
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v3
|
- uses: actions/checkout@v4
|
||||||
- uses: hecrj/setup-rust-action@v1
|
- uses: hecrj/setup-rust-action@v2
|
||||||
- run: rustup target add ${{ matrix.target }}
|
- run: rustup target add ${{ matrix.target }}
|
||||||
- run: cargo build --verbose --target=${{ matrix.target }} --no-default-features ${{ matrix.frontend_feature }} ${{ matrix.backend_feature }}
|
- run: cargo build --verbose --target=${{ matrix.target }} --no-default-features ${{ matrix.frontend_feature }} ${{ matrix.backend_feature }}
|
||||||
|
|
||||||
@@ -110,7 +110,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Install stable toolchain
|
- name: Install stable toolchain
|
||||||
uses: actions-rs/toolchain@v1
|
uses: actions-rs/toolchain@v1
|
||||||
@@ -140,7 +140,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Install nightly toolchain
|
- name: Install nightly toolchain
|
||||||
uses: actions-rs/toolchain@v1
|
uses: actions-rs/toolchain@v1
|
||||||
@@ -161,7 +161,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Cache
|
- name: Cache
|
||||||
uses: actions/cache@v3
|
uses: actions/cache@v4
|
||||||
with:
|
with:
|
||||||
path: |
|
path: |
|
||||||
~/.cargo/.crates.toml
|
~/.cargo/.crates.toml
|
||||||
@@ -170,10 +170,10 @@ jobs:
|
|||||||
key: taplo
|
key: taplo
|
||||||
|
|
||||||
- name: Install Taplo
|
- name: Install Taplo
|
||||||
run: cargo install taplo-cli
|
run: cargo install taplo-cli --locked
|
||||||
|
|
||||||
- name: Checkout sources
|
- name: Checkout sources
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Run Taplo
|
- name: Run Taplo
|
||||||
run: taplo fmt --check
|
run: taplo fmt --check
|
||||||
|
|||||||
@@ -10,9 +10,10 @@ jobs:
|
|||||||
strategy:
|
strategy:
|
||||||
matrix:
|
matrix:
|
||||||
os: [ubuntu-latest]
|
os: [ubuntu-latest]
|
||||||
|
rust: [stable]
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: hecrj/setup-rust-action@v1
|
- uses: hecrj/setup-rust-action@v2
|
||||||
with:
|
with:
|
||||||
rust-version: ${{ matrix.rust }}
|
rust-version: ${{ matrix.rust }}
|
||||||
- uses: actions/checkout@master
|
- uses: actions/checkout@master
|
||||||
|
|||||||
@@ -1,5 +1,16 @@
|
|||||||
# Changelog
|
# Changelog
|
||||||
|
|
||||||
|
## 0.6.0-pre.0 (November 8, 2025)
|
||||||
|
* MSRV bumped to 1.83
|
||||||
|
* Updated Ristretto255 random scalar generation
|
||||||
|
* Updated generic-array to v1
|
||||||
|
|
||||||
|
## 0.5.0 (March 6, 2024)
|
||||||
|
* Just a version bump from v0.5.0-pre.7
|
||||||
|
|
||||||
|
## 0.5.0-pre.7 (January 11, 2024)
|
||||||
|
* Updated to be in sync with RFC 9497
|
||||||
|
|
||||||
## 0.5.0-pre.6 (July 24, 2023)
|
## 0.5.0-pre.6 (July 24, 2023)
|
||||||
* Updated curve25519-dalek dependency to 4
|
* Updated curve25519-dalek dependency to 4
|
||||||
|
|
||||||
|
|||||||
+10
-6
@@ -8,16 +8,16 @@ license = "MIT"
|
|||||||
name = "voprf"
|
name = "voprf"
|
||||||
readme = "README.md"
|
readme = "README.md"
|
||||||
repository = "https://github.com/facebook/voprf/"
|
repository = "https://github.com/facebook/voprf/"
|
||||||
rust-version = "1.65"
|
rust-version = "1.83"
|
||||||
version = "0.5.0-pre.6"
|
version = "0.6.0-pre.0"
|
||||||
|
|
||||||
[features]
|
[features]
|
||||||
alloc = []
|
alloc = []
|
||||||
danger = []
|
danger = []
|
||||||
default = ["ristretto255-ciphersuite", "dep:serde"]
|
default = ["ristretto255-ciphersuite", "dep:serde"]
|
||||||
ristretto255 = ["dep:curve25519-dalek", "generic-array/more_lengths"]
|
ristretto255 = ["dep:curve25519-dalek"]
|
||||||
ristretto255-ciphersuite = ["ristretto255", "dep:sha2"]
|
ristretto255-ciphersuite = ["ristretto255", "dep:sha2"]
|
||||||
serde = ["generic-array/serde", "dep:serde"]
|
serde = ["curve25519-dalek?/serde", "generic-array/serde", "dep:serde"]
|
||||||
std = ["alloc"]
|
std = ["alloc"]
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
@@ -33,7 +33,7 @@ elliptic-curve = { version = "0.13", features = [
|
|||||||
"sec1",
|
"sec1",
|
||||||
"voprf",
|
"voprf",
|
||||||
] }
|
] }
|
||||||
generic-array = "0.14"
|
generic-array = "1"
|
||||||
rand_core = { version = "0.6", default-features = false }
|
rand_core = { version = "0.6", default-features = false }
|
||||||
serde = { version = "1", default-features = false, features = [
|
serde = { version = "1", default-features = false, features = [
|
||||||
"derive",
|
"derive",
|
||||||
@@ -43,7 +43,7 @@ subtle = { version = "2.3", default-features = false }
|
|||||||
zeroize = { version = "1.5", default-features = false }
|
zeroize = { version = "1.5", default-features = false }
|
||||||
|
|
||||||
[dev-dependencies]
|
[dev-dependencies]
|
||||||
generic-array = { version = "0.14", features = ["more_lengths"] }
|
generic-array = { version = "1" }
|
||||||
hex = "0.4"
|
hex = "0.4"
|
||||||
p256 = { version = "0.13", default-features = false, features = [
|
p256 = { version = "0.13", default-features = false, features = [
|
||||||
"hash2curve",
|
"hash2curve",
|
||||||
@@ -53,6 +53,10 @@ p384 = { version = "0.13", default-features = false, features = [
|
|||||||
"hash2curve",
|
"hash2curve",
|
||||||
"voprf",
|
"voprf",
|
||||||
] }
|
] }
|
||||||
|
p521 = { version = "0.13.3", default-features = false, features = [
|
||||||
|
"hash2curve",
|
||||||
|
"voprf",
|
||||||
|
] }
|
||||||
proptest = "1"
|
proptest = "1"
|
||||||
rand = "0.8"
|
rand = "0.8"
|
||||||
regex = "1"
|
regex = "1"
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ An implementation of a (verifiable) oblivious pseudorandom function (VOPRF)
|
|||||||
|
|
||||||
A VOPRF is a verifiable oblivious pseudorandom function, a protocol between a client and a server. The regular (non-verifiable) OPRF is also supported in this implementation.
|
A VOPRF is a verifiable oblivious pseudorandom function, a protocol between a client and a server. The regular (non-verifiable) OPRF is also supported in this implementation.
|
||||||
|
|
||||||
This implementation is based on the [Internet Draft for VOPRF](https://github.com/cfrg/draft-irtf-cfrg-voprf).
|
This implementation is based on [RFC 9497](https://www.rfc-editor.org/rfc/rfc9497).
|
||||||
|
|
||||||
Documentation
|
Documentation
|
||||||
-------------
|
-------------
|
||||||
@@ -16,7 +16,7 @@ Installation
|
|||||||
Add the following line to the dependencies of your `Cargo.toml`:
|
Add the following line to the dependencies of your `Cargo.toml`:
|
||||||
|
|
||||||
```
|
```
|
||||||
voprf = "0.5.0-pre.6"
|
voprf = "0.6.0-pre.0"
|
||||||
```
|
```
|
||||||
|
|
||||||
### Minimum Supported Rust Version
|
### Minimum Supported Rust Version
|
||||||
|
|||||||
+4
-3
@@ -12,6 +12,7 @@ use digest::core_api::BlockSizeUser;
|
|||||||
use digest::{FixedOutput, HashMarker, OutputSizeUser};
|
use digest::{FixedOutput, HashMarker, OutputSizeUser};
|
||||||
use elliptic_curve::VoprfParameters;
|
use elliptic_curve::VoprfParameters;
|
||||||
use generic_array::typenum::{IsLess, IsLessOrEqual, U256};
|
use generic_array::typenum::{IsLess, IsLessOrEqual, U256};
|
||||||
|
use generic_array::ArrayLength;
|
||||||
|
|
||||||
use crate::Group;
|
use crate::Group;
|
||||||
|
|
||||||
@@ -19,10 +20,10 @@ use crate::Group;
|
|||||||
pub trait CipherSuite
|
pub trait CipherSuite
|
||||||
where
|
where
|
||||||
<Self::Hash as OutputSizeUser>::OutputSize:
|
<Self::Hash as OutputSizeUser>::OutputSize:
|
||||||
IsLess<U256> + IsLessOrEqual<<Self::Hash as BlockSizeUser>::BlockSize>,
|
ArrayLength + IsLess<U256> + IsLessOrEqual<<Self::Hash as BlockSizeUser>::BlockSize>,
|
||||||
{
|
{
|
||||||
/// The ciphersuite identifier as dictated by
|
/// The ciphersuite identifier as dictated by
|
||||||
/// <https://datatracker.ietf.org/doc/draft-irtf-cfrg-voprf/>
|
/// <https://www.rfc-editor.org/rfc/rfc9497>
|
||||||
const ID: &'static str;
|
const ID: &'static str;
|
||||||
|
|
||||||
/// A finite cyclic group along with a point representation that allows some
|
/// A finite cyclic group along with a point representation that allows some
|
||||||
@@ -39,7 +40,7 @@ where
|
|||||||
T: Group,
|
T: Group,
|
||||||
T::Hash: BlockSizeUser + Default + FixedOutput + HashMarker,
|
T::Hash: BlockSizeUser + Default + FixedOutput + HashMarker,
|
||||||
<T::Hash as OutputSizeUser>::OutputSize:
|
<T::Hash as OutputSizeUser>::OutputSize:
|
||||||
IsLess<U256> + IsLessOrEqual<<T::Hash as BlockSizeUser>::BlockSize>,
|
ArrayLength + IsLess<U256> + IsLessOrEqual<<T::Hash as BlockSizeUser>::BlockSize>,
|
||||||
{
|
{
|
||||||
const ID: &'static str = T::ID;
|
const ID: &'static str = T::ID;
|
||||||
|
|
||||||
|
|||||||
+30
-83
@@ -12,10 +12,9 @@ use core::convert::TryFrom;
|
|||||||
use core::ops::Add;
|
use core::ops::Add;
|
||||||
|
|
||||||
use derive_where::derive_where;
|
use derive_where::derive_where;
|
||||||
use digest::core_api::BlockSizeUser;
|
|
||||||
use digest::{Digest, Output, OutputSizeUser};
|
use digest::{Digest, Output, OutputSizeUser};
|
||||||
use generic_array::sequence::Concat;
|
use generic_array::sequence::Concat;
|
||||||
use generic_array::typenum::{IsLess, IsLessOrEqual, Unsigned, U2, U256, U9};
|
use generic_array::typenum::{IsLess, Unsigned, U2, U256, U9};
|
||||||
use generic_array::{ArrayLength, GenericArray};
|
use generic_array::{ArrayLength, GenericArray};
|
||||||
use rand_core::{CryptoRng, RngCore};
|
use rand_core::{CryptoRng, RngCore};
|
||||||
use subtle::ConstantTimeEq;
|
use subtle::ConstantTimeEq;
|
||||||
@@ -79,10 +78,7 @@ impl Mode {
|
|||||||
pub struct BlindedElement<CS: CipherSuite>(
|
pub struct BlindedElement<CS: CipherSuite>(
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
||||||
pub(crate) <CS::Group as Group>::Elem,
|
pub(crate) <CS::Group as Group>::Elem,
|
||||||
)
|
);
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>;
|
|
||||||
|
|
||||||
/// The server's response to the [BlindedElement] message from a client (either
|
/// The server's response to the [BlindedElement] message from a client (either
|
||||||
/// verifiable or not) to a server (either verifiable or not).
|
/// verifiable or not) to a server (either verifiable or not).
|
||||||
@@ -96,10 +92,7 @@ where
|
|||||||
pub struct EvaluationElement<CS: CipherSuite>(
|
pub struct EvaluationElement<CS: CipherSuite>(
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
||||||
pub(crate) <CS::Group as Group>::Elem,
|
pub(crate) <CS::Group as Group>::Elem,
|
||||||
)
|
);
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>;
|
|
||||||
|
|
||||||
/// Contains prepared [`EvaluationElement`]s by a server batch evaluate
|
/// Contains prepared [`EvaluationElement`]s by a server batch evaluate
|
||||||
/// preparation.
|
/// preparation.
|
||||||
@@ -110,10 +103,7 @@ where
|
|||||||
derive(serde::Deserialize, serde::Serialize),
|
derive(serde::Deserialize, serde::Serialize),
|
||||||
serde(bound = "")
|
serde(bound = "")
|
||||||
)]
|
)]
|
||||||
pub struct PreparedEvaluationElement<CS: CipherSuite>(pub(crate) EvaluationElement<CS>)
|
pub struct PreparedEvaluationElement<CS: CipherSuite>(pub(crate) EvaluationElement<CS>);
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>;
|
|
||||||
|
|
||||||
/// A proof produced by a server that the OPRF output matches against a server
|
/// A proof produced by a server that the OPRF output matches against a server
|
||||||
/// public key.
|
/// public key.
|
||||||
@@ -124,11 +114,7 @@ where
|
|||||||
derive(serde::Deserialize, serde::Serialize),
|
derive(serde::Deserialize, serde::Serialize),
|
||||||
serde(bound = "")
|
serde(bound = "")
|
||||||
)]
|
)]
|
||||||
pub struct Proof<CS: CipherSuite>
|
pub struct Proof<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
||||||
pub(crate) c_scalar: <CS::Group as Group>::Scalar,
|
pub(crate) c_scalar: <CS::Group as Group>::Scalar,
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
||||||
@@ -147,15 +133,11 @@ pub(crate) fn generate_proof<CS: CipherSuite, R: RngCore + CryptoRng>(
|
|||||||
k: <CS::Group as Group>::Scalar,
|
k: <CS::Group as Group>::Scalar,
|
||||||
a: <CS::Group as Group>::Elem,
|
a: <CS::Group as Group>::Elem,
|
||||||
b: <CS::Group as Group>::Elem,
|
b: <CS::Group as Group>::Elem,
|
||||||
cs: impl Iterator<Item = <CS::Group as Group>::Elem> + ExactSizeIterator,
|
cs: impl ExactSizeIterator<Item = <CS::Group as Group>::Elem>,
|
||||||
ds: impl Iterator<Item = <CS::Group as Group>::Elem> + ExactSizeIterator,
|
ds: impl ExactSizeIterator<Item = <CS::Group as Group>::Elem>,
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Result<Proof<CS>>
|
) -> Result<Proof<CS>> {
|
||||||
where
|
// https://www.rfc-editor.org/rfc/rfc9497#section-2.2.1
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
// https://www.ietf.org/archive/id/draft-irtf-cfrg-voprf-11.html#section-2.2.1
|
|
||||||
|
|
||||||
let (m, z) = compute_composites::<CS, _, _>(Some(k), b, cs, ds, mode)?;
|
let (m, z) = compute_composites::<CS, _, _>(Some(k), b, cs, ds, mode)?;
|
||||||
|
|
||||||
@@ -209,16 +191,12 @@ where
|
|||||||
pub(crate) fn verify_proof<CS: CipherSuite>(
|
pub(crate) fn verify_proof<CS: CipherSuite>(
|
||||||
a: <CS::Group as Group>::Elem,
|
a: <CS::Group as Group>::Elem,
|
||||||
b: <CS::Group as Group>::Elem,
|
b: <CS::Group as Group>::Elem,
|
||||||
cs: impl Iterator<Item = <CS::Group as Group>::Elem> + ExactSizeIterator,
|
cs: impl ExactSizeIterator<Item = <CS::Group as Group>::Elem>,
|
||||||
ds: impl Iterator<Item = <CS::Group as Group>::Elem> + ExactSizeIterator,
|
ds: impl ExactSizeIterator<Item = <CS::Group as Group>::Elem>,
|
||||||
proof: &Proof<CS>,
|
proof: &Proof<CS>,
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Result<()>
|
) -> Result<()> {
|
||||||
where
|
// https://www.rfc-editor.org/rfc/rfc9497#section-2.2.2
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
// https://www.ietf.org/archive/id/draft-irtf-cfrg-voprf-11.html#section-2.2.2
|
|
||||||
let (m, z) = compute_composites::<CS, _, _>(None, b, cs, ds, mode)?;
|
let (m, z) = compute_composites::<CS, _, _>(None, b, cs, ds, mode)?;
|
||||||
let t2 = (a * &proof.s_scalar) + &(b * &proof.c_scalar);
|
let t2 = (a * &proof.s_scalar) + &(b * &proof.c_scalar);
|
||||||
let t3 = (m * &proof.s_scalar) + &(z * &proof.c_scalar);
|
let t3 = (m * &proof.s_scalar) + &(z * &proof.c_scalar);
|
||||||
@@ -282,12 +260,8 @@ fn compute_composites<
|
|||||||
c_slice: IC,
|
c_slice: IC,
|
||||||
d_slice: ID,
|
d_slice: ID,
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Result<ComputeCompositesResult<CS>>
|
) -> Result<ComputeCompositesResult<CS>> {
|
||||||
where
|
// https://www.rfc-editor.org/rfc/rfc9497#section-2.2.1
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
// https://www.ietf.org/archive/id/draft-irtf-cfrg-voprf-11.html#section-2.2.1
|
|
||||||
|
|
||||||
let elem_len = <CS::Group as Group>::ElemLen::U16.to_be_bytes();
|
let elem_len = <CS::Group as Group>::ElemLen::U16.to_be_bytes();
|
||||||
|
|
||||||
@@ -309,7 +283,7 @@ where
|
|||||||
.chain_update(seed_dst.i2osp_2())
|
.chain_update(seed_dst.i2osp_2())
|
||||||
.chain_update_multi(&seed_dst.as_dst())
|
.chain_update_multi(&seed_dst.as_dst())
|
||||||
.finalize();
|
.finalize();
|
||||||
let seed_len = i2osp_2_array(&seed);
|
let seed_len = i2osp_2_array::<<CS::Hash as OutputSizeUser>::OutputSize>();
|
||||||
|
|
||||||
let mut m = CS::Group::identity_elem();
|
let mut m = CS::Group::identity_elem();
|
||||||
let mut z = CS::Group::identity_elem();
|
let mut z = CS::Group::identity_elem();
|
||||||
@@ -362,11 +336,7 @@ pub(crate) fn derive_key_internal<CS: CipherSuite>(
|
|||||||
seed: &[u8],
|
seed: &[u8],
|
||||||
info: &[u8],
|
info: &[u8],
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Result<<CS::Group as Group>::Scalar, Error>
|
) -> Result<<CS::Group as Group>::Scalar, Error> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let dst = Dst::new::<CS, _, _>(STR_DERIVE_KEYPAIR, mode);
|
let dst = Dst::new::<CS, _, _>(STR_DERIVE_KEYPAIR, mode);
|
||||||
|
|
||||||
let info_len = i2osp_2(info.len()).map_err(|_| Error::DeriveKeyPair)?;
|
let info_len = i2osp_2(info.len()).map_err(|_| Error::DeriveKeyPair)?;
|
||||||
@@ -400,11 +370,7 @@ pub fn derive_key<CS: CipherSuite>(
|
|||||||
seed: &[u8],
|
seed: &[u8],
|
||||||
info: &[u8],
|
info: &[u8],
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Result<<CS::Group as Group>::Scalar, Error>
|
) -> Result<<CS::Group as Group>::Scalar, Error> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
derive_key_internal::<CS>(seed, info, mode)
|
derive_key_internal::<CS>(seed, info, mode)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -418,11 +384,7 @@ pub(crate) fn derive_keypair<CS: CipherSuite>(
|
|||||||
seed: &[u8],
|
seed: &[u8],
|
||||||
info: &[u8],
|
info: &[u8],
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Result<DeriveKeypairResult<CS>, Error>
|
) -> Result<DeriveKeypairResult<CS>, Error> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let sk_s = derive_key_internal::<CS>(seed, info, mode)?;
|
let sk_s = derive_key_internal::<CS>(seed, info, mode)?;
|
||||||
let pk_s = CS::Group::base_elem() * &sk_s;
|
let pk_s = CS::Group::base_elem() * &sk_s;
|
||||||
|
|
||||||
@@ -438,11 +400,7 @@ pub(crate) fn deterministic_blind_unchecked<CS: CipherSuite>(
|
|||||||
input: &[u8],
|
input: &[u8],
|
||||||
blind: &<CS::Group as Group>::Scalar,
|
blind: &<CS::Group as Group>::Scalar,
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Result<<CS::Group as Group>::Elem>
|
) -> Result<<CS::Group as Group>::Elem> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let hashed_point = hash_to_group::<CS>(input, mode)?;
|
let hashed_point = hash_to_group::<CS>(input, mode)?;
|
||||||
Ok(hashed_point * blind)
|
Ok(hashed_point * blind)
|
||||||
}
|
}
|
||||||
@@ -451,11 +409,7 @@ where
|
|||||||
pub(crate) fn hash_to_group<CS: CipherSuite>(
|
pub(crate) fn hash_to_group<CS: CipherSuite>(
|
||||||
input: &[u8],
|
input: &[u8],
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Result<<CS::Group as Group>::Elem>
|
) -> Result<<CS::Group as Group>::Elem> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let dst = Dst::new::<CS, _, _>(STR_HASH_TO_GROUP, mode);
|
let dst = Dst::new::<CS, _, _>(STR_HASH_TO_GROUP, mode);
|
||||||
CS::Group::hash_to_curve::<CS::Hash>(&[input], &dst.as_dst()).map_err(|_| Error::Input)
|
CS::Group::hash_to_curve::<CS::Hash>(&[input], &dst.as_dst()).map_err(|_| Error::Input)
|
||||||
}
|
}
|
||||||
@@ -466,11 +420,7 @@ pub(crate) fn server_evaluate_hash_input<CS: CipherSuite>(
|
|||||||
input: &[u8],
|
input: &[u8],
|
||||||
info: Option<&[u8]>,
|
info: Option<&[u8]>,
|
||||||
issued_element: GenericArray<u8, <<CS as CipherSuite>::Group as Group>::ElemLen>,
|
issued_element: GenericArray<u8, <<CS as CipherSuite>::Group as Group>::ElemLen>,
|
||||||
) -> Result<Output<CS::Hash>>
|
) -> Result<Output<CS::Hash>> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
// OPRF & VOPRF
|
// OPRF & VOPRF
|
||||||
// hashInput = I2OSP(len(input), 2) || input ||
|
// hashInput = I2OSP(len(input), 2) || input ||
|
||||||
// I2OSP(len(issuedElement), 2) || issuedElement ||
|
// I2OSP(len(issuedElement), 2) || issuedElement ||
|
||||||
@@ -492,28 +442,27 @@ where
|
|||||||
.chain_update(info.as_ref());
|
.chain_update(info.as_ref());
|
||||||
}
|
}
|
||||||
Ok(hash
|
Ok(hash
|
||||||
.chain_update(i2osp_2(issued_element.as_ref().len()).map_err(|_| Error::Input)?)
|
.chain_update(i2osp_2(issued_element.as_slice().len()).map_err(|_| Error::Input)?)
|
||||||
.chain_update(issued_element)
|
.chain_update(issued_element)
|
||||||
.chain_update(STR_FINALIZE)
|
.chain_update(STR_FINALIZE)
|
||||||
.finalize())
|
.finalize())
|
||||||
}
|
}
|
||||||
|
|
||||||
pub(crate) struct Dst<L: ArrayLength<u8>> {
|
pub(crate) struct Dst<L: ArrayLength> {
|
||||||
dst_1: GenericArray<u8, L>,
|
dst_1: GenericArray<u8, L>,
|
||||||
dst_2: &'static str,
|
dst_2: &'static str,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<L: ArrayLength<u8>> Dst<L> {
|
impl<L: ArrayLength> Dst<L> {
|
||||||
pub(crate) fn new<CS: CipherSuite, T, TL: ArrayLength<u8>>(par_1: T, mode: Mode) -> Self
|
pub(crate) fn new<CS, T, TL>(par_1: T, mode: Mode) -> Self
|
||||||
where
|
where
|
||||||
|
CS: CipherSuite,
|
||||||
T: Into<GenericArray<u8, TL>>,
|
T: Into<GenericArray<u8, TL>>,
|
||||||
TL: Add<U9, Output = L>,
|
TL: ArrayLength + Add<U9, Output = L>,
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
{
|
||||||
let par_1 = par_1.into();
|
let par_1 = par_1.into();
|
||||||
// Generates the contextString parameter as defined in
|
// Generates the contextString parameter as defined in
|
||||||
// <https://datatracker.ietf.org/doc/draft-irtf-cfrg-voprf/>
|
// <https://www.rfc-editor.org/rfc/rfc9497#section-3.1>
|
||||||
let par_2 = GenericArray::from(STR_OPRF)
|
let par_2 = GenericArray::from(STR_OPRF)
|
||||||
.concat([mode.to_u8()].into())
|
.concat([mode.to_u8()].into())
|
||||||
.concat([b'-'].into());
|
.concat([b'-'].into());
|
||||||
@@ -569,8 +518,6 @@ pub(crate) fn i2osp_2(input: usize) -> Result<[u8; 2], InternalError> {
|
|||||||
.map_err(|_| InternalError::I2osp)
|
.map_err(|_| InternalError::I2osp)
|
||||||
}
|
}
|
||||||
|
|
||||||
pub(crate) fn i2osp_2_array<L: ArrayLength<u8> + IsLess<U256>>(
|
pub(crate) fn i2osp_2_array<L: ArrayLength + IsLess<U256>>() -> GenericArray<u8, U2> {
|
||||||
_: &GenericArray<u8, L>,
|
|
||||||
) -> GenericArray<u8, U2> {
|
|
||||||
L::U16.to_be_bytes().into()
|
L::U16.to_be_bytes().into()
|
||||||
}
|
}
|
||||||
|
|||||||
+2
-5
@@ -8,13 +8,11 @@
|
|||||||
|
|
||||||
//! Errors which are produced during an execution of the protocol
|
//! Errors which are produced during an execution of the protocol
|
||||||
|
|
||||||
use displaydoc::Display;
|
|
||||||
|
|
||||||
/// [`Result`](core::result::Result) shorthand that uses [`Error`].
|
/// [`Result`](core::result::Result) shorthand that uses [`Error`].
|
||||||
pub type Result<T, E = Error> = core::result::Result<T, E>;
|
pub type Result<T, E = Error> = core::result::Result<T, E>;
|
||||||
|
|
||||||
/// Represents an error in the manipulation of internal cryptographic data
|
/// Represents an error in the manipulation of internal cryptographic data
|
||||||
#[derive(Clone, Copy, Debug, Display, Eq, Hash, Ord, PartialEq, PartialOrd)]
|
#[derive(Clone, Copy, Debug, displaydoc::Display, Eq, Hash, Ord, PartialEq, PartialOrd)]
|
||||||
pub enum Error {
|
pub enum Error {
|
||||||
/// Size of info is longer then [`u16::MAX`].
|
/// Size of info is longer then [`u16::MAX`].
|
||||||
Info,
|
Info,
|
||||||
@@ -41,5 +39,4 @@ pub enum InternalError {
|
|||||||
I2osp,
|
I2osp,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(feature = "std")]
|
impl core::error::Error for Error {}
|
||||||
impl std::error::Error for Error {}
|
|
||||||
|
|||||||
@@ -6,39 +6,53 @@
|
|||||||
// of this source tree. You may select, at your option, one of the above-listed
|
// of this source tree. You may select, at your option, one of the above-listed
|
||||||
// licenses.
|
// licenses.
|
||||||
|
|
||||||
|
use core::ops::Add;
|
||||||
|
|
||||||
use digest::core_api::BlockSizeUser;
|
use digest::core_api::BlockSizeUser;
|
||||||
use digest::{FixedOutput, HashMarker};
|
use digest::{FixedOutput, HashMarker};
|
||||||
use elliptic_curve::group::cofactor::CofactorGroup;
|
use elliptic_curve::group::cofactor::CofactorGroup;
|
||||||
use elliptic_curve::hash2curve::{ExpandMsgXmd, FromOkm, GroupDigest};
|
use elliptic_curve::hash2curve::{ExpandMsgXmd, FromOkm, GroupDigest};
|
||||||
use elliptic_curve::sec1::{FromEncodedPoint, ModulusSize, ToEncodedPoint};
|
use elliptic_curve::sec1::{FromEncodedPoint, ModulusSize, ToEncodedPoint};
|
||||||
use elliptic_curve::{
|
use elliptic_curve::{
|
||||||
AffinePoint, Field, FieldBytesSize, Group as _, ProjectivePoint, PublicKey, Scalar, SecretKey,
|
AffinePoint, Field, FieldBytes, FieldBytesSize, Group as _, ProjectivePoint, PublicKey, Scalar,
|
||||||
|
SecretKey,
|
||||||
};
|
};
|
||||||
use generic_array::typenum::{IsLess, IsLessOrEqual, U256};
|
use generic_array::typenum::{IsLess, IsLessOrEqual, Sum, U256};
|
||||||
use generic_array::GenericArray;
|
use generic_array::{ArrayLength, GenericArray};
|
||||||
use rand_core::{CryptoRng, RngCore};
|
use rand_core::{CryptoRng, RngCore};
|
||||||
|
|
||||||
use super::Group;
|
use super::Group;
|
||||||
use crate::{Error, InternalError, Result};
|
use crate::{Error, InternalError, Result};
|
||||||
|
|
||||||
|
type ElemLen<C> = <ScalarLen<C> as ModulusSize>::CompressedPointSize;
|
||||||
|
type ScalarLen<C> = FieldBytesSize<C>;
|
||||||
|
|
||||||
impl<C> Group for C
|
impl<C> Group for C
|
||||||
where
|
where
|
||||||
C: GroupDigest,
|
C: GroupDigest,
|
||||||
ProjectivePoint<Self>: CofactorGroup + ToEncodedPoint<Self>,
|
ProjectivePoint<Self>: CofactorGroup + ToEncodedPoint<Self>,
|
||||||
FieldBytesSize<Self>: ModulusSize,
|
ScalarLen<Self>: ModulusSize,
|
||||||
|
ScalarLen<Self>: ArrayLength,
|
||||||
AffinePoint<Self>: FromEncodedPoint<Self> + ToEncodedPoint<Self>,
|
AffinePoint<Self>: FromEncodedPoint<Self> + ToEncodedPoint<Self>,
|
||||||
Scalar<Self>: FromOkm,
|
Scalar<Self>: FromOkm,
|
||||||
|
// `VoprfClientLen`, `PoprfClientLen`, `VoprfServerLen`, `PoprfServerLen`
|
||||||
|
ScalarLen<Self>: Add<ElemLen<Self>>,
|
||||||
|
Sum<ScalarLen<Self>, ElemLen<Self>>: ArrayLength,
|
||||||
|
// `ProofLen`
|
||||||
|
ScalarLen<Self>: Add<ScalarLen<Self>>,
|
||||||
|
Sum<ScalarLen<Self>, ScalarLen<Self>>: ArrayLength,
|
||||||
|
ElemLen<Self>: ArrayLength,
|
||||||
{
|
{
|
||||||
type Elem = ProjectivePoint<Self>;
|
type Elem = ProjectivePoint<Self>;
|
||||||
|
|
||||||
type ElemLen = <FieldBytesSize<Self> as ModulusSize>::CompressedPointSize;
|
type ElemLen = ElemLen<Self>;
|
||||||
|
|
||||||
type Scalar = Scalar<Self>;
|
type Scalar = Scalar<Self>;
|
||||||
|
|
||||||
type ScalarLen = FieldBytesSize<Self>;
|
type ScalarLen = ScalarLen<Self>;
|
||||||
|
|
||||||
// Implements the `hash_to_curve()` function from
|
// Implements the `hash_to_curve()` function from
|
||||||
// https://datatracker.ietf.org/doc/html/draft-irtf-cfrg-hash-to-curve-11#section-3
|
// https://www.rfc-editor.org/rfc/rfc9380.html#section-3
|
||||||
fn hash_to_curve<H>(input: &[&[u8]], dst: &[&[u8]]) -> Result<Self::Elem, InternalError>
|
fn hash_to_curve<H>(input: &[&[u8]], dst: &[&[u8]]) -> Result<Self::Elem, InternalError>
|
||||||
where
|
where
|
||||||
H: BlockSizeUser + Default + FixedOutput + HashMarker,
|
H: BlockSizeUser + Default + FixedOutput + HashMarker,
|
||||||
@@ -97,7 +111,10 @@ where
|
|||||||
}
|
}
|
||||||
|
|
||||||
fn serialize_scalar(scalar: Self::Scalar) -> GenericArray<u8, Self::ScalarLen> {
|
fn serialize_scalar(scalar: Self::Scalar) -> GenericArray<u8, Self::ScalarLen> {
|
||||||
scalar.into()
|
let bytes: FieldBytes<Self> = scalar.into();
|
||||||
|
let mut result = GenericArray::<u8, Self::ScalarLen>::default();
|
||||||
|
result.as_mut_slice().copy_from_slice(bytes.as_ref());
|
||||||
|
result
|
||||||
}
|
}
|
||||||
|
|
||||||
fn deserialize_scalar(scalar_bits: &[u8]) -> Result<Self::Scalar> {
|
fn deserialize_scalar(scalar_bits: &[u8]) -> Result<Self::Scalar> {
|
||||||
|
|||||||
+13
-5
@@ -16,7 +16,7 @@ use core::ops::{Add, Mul, Sub};
|
|||||||
|
|
||||||
use digest::core_api::BlockSizeUser;
|
use digest::core_api::BlockSizeUser;
|
||||||
use digest::{FixedOutput, HashMarker};
|
use digest::{FixedOutput, HashMarker};
|
||||||
use generic_array::typenum::{IsLess, IsLessOrEqual, U256};
|
use generic_array::typenum::{IsLess, IsLessOrEqual, Sum, U256};
|
||||||
use generic_array::{ArrayLength, GenericArray};
|
use generic_array::{ArrayLength, GenericArray};
|
||||||
use rand_core::{CryptoRng, RngCore};
|
use rand_core::{CryptoRng, RngCore};
|
||||||
#[cfg(feature = "ristretto255")]
|
#[cfg(feature = "ristretto255")]
|
||||||
@@ -27,8 +27,16 @@ use zeroize::Zeroize;
|
|||||||
use crate::{InternalError, Result};
|
use crate::{InternalError, Result};
|
||||||
|
|
||||||
/// A prime-order subgroup of a base field (EC, prime-order field ...). This
|
/// A prime-order subgroup of a base field (EC, prime-order field ...). This
|
||||||
/// subgroup is noted additively — as in the draft RFC — in this trait.
|
/// subgroup is noted additively — as in the RFC — in this trait.
|
||||||
pub trait Group {
|
pub trait Group
|
||||||
|
where
|
||||||
|
// `VoprfClientLen`, `PoprfClientLen`, `VoprfServerLen`, `PoprfServerLen`
|
||||||
|
Self::ScalarLen: Add<Self::ElemLen>,
|
||||||
|
Sum<Self::ScalarLen, Self::ElemLen>: ArrayLength,
|
||||||
|
// `ProofLen`
|
||||||
|
Self::ScalarLen: Add<Self::ScalarLen>,
|
||||||
|
Sum<Self::ScalarLen, Self::ScalarLen>: ArrayLength,
|
||||||
|
{
|
||||||
/// The type of group elements
|
/// The type of group elements
|
||||||
type Elem: ConstantTimeEq
|
type Elem: ConstantTimeEq
|
||||||
+ Copy
|
+ Copy
|
||||||
@@ -37,7 +45,7 @@ pub trait Group {
|
|||||||
+ for<'a> Mul<&'a Self::Scalar, Output = Self::Elem>;
|
+ for<'a> Mul<&'a Self::Scalar, Output = Self::Elem>;
|
||||||
|
|
||||||
/// The byte length necessary to represent group elements
|
/// The byte length necessary to represent group elements
|
||||||
type ElemLen: ArrayLength<u8> + 'static;
|
type ElemLen: ArrayLength + 'static;
|
||||||
|
|
||||||
/// The type of base field scalars
|
/// The type of base field scalars
|
||||||
type Scalar: ConstantTimeEq
|
type Scalar: ConstantTimeEq
|
||||||
@@ -48,7 +56,7 @@ pub trait Group {
|
|||||||
+ for<'a> Sub<&'a Self::Scalar, Output = Self::Scalar>;
|
+ for<'a> Sub<&'a Self::Scalar, Output = Self::Scalar>;
|
||||||
|
|
||||||
/// The byte length necessary to represent scalars
|
/// The byte length necessary to represent scalars
|
||||||
type ScalarLen: ArrayLength<u8> + 'static;
|
type ScalarLen: ArrayLength + 'static;
|
||||||
|
|
||||||
/// Transforms a password and domain separation tag (DST) into a curve point
|
/// Transforms a password and domain separation tag (DST) into a curve point
|
||||||
///
|
///
|
||||||
|
|||||||
@@ -44,7 +44,7 @@ impl Group for Ristretto255 {
|
|||||||
type ScalarLen = U32;
|
type ScalarLen = U32;
|
||||||
|
|
||||||
// Implements the `hash_to_ristretto255()` function from
|
// Implements the `hash_to_ristretto255()` function from
|
||||||
// https://www.ietf.org/archive/id/draft-irtf-cfrg-hash-to-curve-10.txt
|
// https://www.rfc-editor.org/rfc/rfc9380.html#appendix-B
|
||||||
fn hash_to_curve<H>(input: &[&[u8]], dst: &[&[u8]]) -> Result<Self::Elem, InternalError>
|
fn hash_to_curve<H>(input: &[&[u8]], dst: &[&[u8]]) -> Result<Self::Elem, InternalError>
|
||||||
where
|
where
|
||||||
H: BlockSizeUser + Default + FixedOutput + HashMarker,
|
H: BlockSizeUser + Default + FixedOutput + HashMarker,
|
||||||
@@ -59,7 +59,7 @@ impl Group for Ristretto255 {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Implements the `HashToScalar()` function from
|
// Implements the `HashToScalar()` function from
|
||||||
// https://www.ietf.org/archive/id/draft-irtf-cfrg-voprf-07.html#section-4.1
|
// https://www.rfc-editor.org/rfc/rfc9497#section-4.1
|
||||||
fn hash_to_scalar<H>(input: &[&[u8]], dst: &[&[u8]]) -> Result<Self::Scalar, InternalError>
|
fn hash_to_scalar<H>(input: &[&[u8]], dst: &[&[u8]]) -> Result<Self::Scalar, InternalError>
|
||||||
where
|
where
|
||||||
H: BlockSizeUser + Default + FixedOutput + HashMarker,
|
H: BlockSizeUser + Default + FixedOutput + HashMarker,
|
||||||
@@ -96,9 +96,10 @@ impl Group for Ristretto255 {
|
|||||||
|
|
||||||
fn random_scalar<R: RngCore + CryptoRng>(rng: &mut R) -> Self::Scalar {
|
fn random_scalar<R: RngCore + CryptoRng>(rng: &mut R) -> Self::Scalar {
|
||||||
loop {
|
loop {
|
||||||
let scalar = Scalar::random(rng);
|
let mut scalar_bytes = [0u8; 32];
|
||||||
|
rng.fill_bytes(&mut scalar_bytes);
|
||||||
|
|
||||||
if scalar != Scalar::ZERO {
|
if let Ok(scalar) = Self::deserialize_scalar(&scalar_bytes) {
|
||||||
break scalar;
|
break scalar;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -17,6 +17,7 @@ use crate::{Error, Group, Result};
|
|||||||
fn test_group_properties() -> Result<()> {
|
fn test_group_properties() -> Result<()> {
|
||||||
use p256::NistP256;
|
use p256::NistP256;
|
||||||
use p384::NistP384;
|
use p384::NistP384;
|
||||||
|
use p521::NistP521;
|
||||||
|
|
||||||
#[cfg(feature = "ristretto255")]
|
#[cfg(feature = "ristretto255")]
|
||||||
{
|
{
|
||||||
@@ -32,6 +33,9 @@ fn test_group_properties() -> Result<()> {
|
|||||||
test_identity_element_error::<NistP384>()?;
|
test_identity_element_error::<NistP384>()?;
|
||||||
test_zero_scalar_error::<NistP384>()?;
|
test_zero_scalar_error::<NistP384>()?;
|
||||||
|
|
||||||
|
test_identity_element_error::<NistP521>()?;
|
||||||
|
test_zero_scalar_error::<NistP521>()?;
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+2
-4
@@ -9,9 +9,7 @@
|
|||||||
//! An implementation of a verifiable oblivious pseudorandom function (VOPRF)
|
//! An implementation of a verifiable oblivious pseudorandom function (VOPRF)
|
||||||
//!
|
//!
|
||||||
//! Note: This implementation is in sync with
|
//! Note: This implementation is in sync with
|
||||||
//! [draft-irtf-cfrg-voprf-19](https://www.ietf.org/archive/id/draft-irtf-cfrg-voprf-19.html),
|
//! [RFC 9497](https://www.rfc-editor.org/rfc/rfc9497).
|
||||||
//! but this specification is subject to change, until the final version
|
|
||||||
//! published by the IETF.
|
|
||||||
//!
|
//!
|
||||||
//! # Overview
|
//! # Overview
|
||||||
//!
|
//!
|
||||||
@@ -512,7 +510,7 @@
|
|||||||
//! and [PoprfClient] are used, and that each of the functions accept an
|
//! and [PoprfClient] are used, and that each of the functions accept an
|
||||||
//! additional (and optional) info parameter which represents the public input.
|
//! additional (and optional) info parameter which represents the public input.
|
||||||
//! See
|
//! See
|
||||||
//! <https://www.ietf.org/archive/id/draft-irtf-cfrg-voprf-11.html#name-poprf-public-input>
|
//! <https://www.rfc-editor.org/rfc/rfc9497#name-poprf-public-input>
|
||||||
//! for more detailed information on how this public input should be used.
|
//! for more detailed information on how this public input should be used.
|
||||||
//!
|
//!
|
||||||
//! # Features
|
//! # Features
|
||||||
|
|||||||
+23
-64
@@ -11,9 +11,8 @@
|
|||||||
use core::iter::{self, Map};
|
use core::iter::{self, Map};
|
||||||
|
|
||||||
use derive_where::derive_where;
|
use derive_where::derive_where;
|
||||||
use digest::core_api::BlockSizeUser;
|
use digest::{Digest, Output};
|
||||||
use digest::{Digest, Output, OutputSizeUser};
|
use generic_array::typenum::Unsigned;
|
||||||
use generic_array::typenum::{IsLess, IsLessOrEqual, Unsigned, U256};
|
|
||||||
use generic_array::GenericArray;
|
use generic_array::GenericArray;
|
||||||
use rand_core::{CryptoRng, RngCore};
|
use rand_core::{CryptoRng, RngCore};
|
||||||
|
|
||||||
@@ -44,11 +43,7 @@ use crate::{CipherSuite, Error, Group, Result};
|
|||||||
derive(serde::Deserialize, serde::Serialize),
|
derive(serde::Deserialize, serde::Serialize),
|
||||||
serde(bound = "")
|
serde(bound = "")
|
||||||
)]
|
)]
|
||||||
pub struct OprfClient<CS: CipherSuite>
|
pub struct OprfClient<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
||||||
pub(crate) blind: <CS::Group as Group>::Scalar,
|
pub(crate) blind: <CS::Group as Group>::Scalar,
|
||||||
}
|
}
|
||||||
@@ -62,11 +57,7 @@ where
|
|||||||
derive(serde::Deserialize, serde::Serialize),
|
derive(serde::Deserialize, serde::Serialize),
|
||||||
serde(bound = "")
|
serde(bound = "")
|
||||||
)]
|
)]
|
||||||
pub struct OprfServer<CS: CipherSuite>
|
pub struct OprfServer<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
||||||
pub(crate) sk: <CS::Group as Group>::Scalar,
|
pub(crate) sk: <CS::Group as Group>::Scalar,
|
||||||
}
|
}
|
||||||
@@ -76,11 +67,7 @@ where
|
|||||||
// =================== //
|
// =================== //
|
||||||
/////////////////////////
|
/////////////////////////
|
||||||
|
|
||||||
impl<CS: CipherSuite> OprfClient<CS>
|
impl<CS: CipherSuite> OprfClient<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Computes the first step for the multiplicative blinding version of
|
/// Computes the first step for the multiplicative blinding version of
|
||||||
/// DH-OPRF.
|
/// DH-OPRF.
|
||||||
///
|
///
|
||||||
@@ -154,11 +141,7 @@ where
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<CS: CipherSuite> OprfServer<CS>
|
impl<CS: CipherSuite> OprfServer<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Produces a new instance of a [OprfServer] using a supplied RNG
|
/// Produces a new instance of a [OprfServer] using a supplied RNG
|
||||||
///
|
///
|
||||||
/// # Errors
|
/// # Errors
|
||||||
@@ -194,7 +177,7 @@ where
|
|||||||
Ok(Self { sk })
|
Ok(Self { sk })
|
||||||
}
|
}
|
||||||
|
|
||||||
// Only used for tests
|
/// Only used for tests
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
pub fn get_private_key(&self) -> <CS::Group as Group>::Scalar {
|
pub fn get_private_key(&self) -> <CS::Group as Group>::Scalar {
|
||||||
self.sk
|
self.sk
|
||||||
@@ -231,11 +214,7 @@ where
|
|||||||
|
|
||||||
/// Contains the fields that are returned by a non-verifiable client blind
|
/// Contains the fields that are returned by a non-verifiable client blind
|
||||||
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
||||||
pub struct OprfClientBlindResult<CS: CipherSuite>
|
pub struct OprfClientBlindResult<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// The state to be persisted on the client
|
/// The state to be persisted on the client
|
||||||
pub state: OprfClient<CS>,
|
pub state: OprfClient<CS>,
|
||||||
/// The message to send to the server
|
/// The message to send to the server
|
||||||
@@ -261,11 +240,7 @@ fn finalize_after_unblind<
|
|||||||
>(
|
>(
|
||||||
inputs_and_unblinded_elements: IE,
|
inputs_and_unblinded_elements: IE,
|
||||||
_unused: &'a [u8],
|
_unused: &'a [u8],
|
||||||
) -> FinalizeAfterUnblindResult<CS, I, IE>
|
) -> FinalizeAfterUnblindResult<'a, CS, I, IE> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
inputs_and_unblinded_elements.map(|(input, unblinded_element)| {
|
inputs_and_unblinded_elements.map(|(input, unblinded_element)| {
|
||||||
let elem_len = <CS::Group as Group>::ElemLen::U16.to_be_bytes();
|
let elem_len = <CS::Group as Group>::ElemLen::U16.to_be_bytes();
|
||||||
|
|
||||||
@@ -303,11 +278,7 @@ mod tests {
|
|||||||
key: <CS::Group as Group>::Scalar,
|
key: <CS::Group as Group>::Scalar,
|
||||||
info: &[u8],
|
info: &[u8],
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Output<CS::Hash>
|
) -> Output<CS::Hash> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let dst = Dst::new::<CS, _, _>(STR_HASH_TO_GROUP, mode);
|
let dst = Dst::new::<CS, _, _>(STR_HASH_TO_GROUP, mode);
|
||||||
let point = CS::Group::hash_to_curve::<CS::Hash>(&[input], &dst.as_dst()).unwrap();
|
let point = CS::Group::hash_to_curve::<CS::Hash>(&[input], &dst.as_dst()).unwrap();
|
||||||
|
|
||||||
@@ -319,11 +290,7 @@ mod tests {
|
|||||||
.unwrap()
|
.unwrap()
|
||||||
}
|
}
|
||||||
|
|
||||||
fn base_retrieval<CS: CipherSuite>()
|
fn base_retrieval<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let client_blind_result = OprfClient::<CS>::blind(input, &mut rng).unwrap();
|
let client_blind_result = OprfClient::<CS>::blind(input, &mut rng).unwrap();
|
||||||
@@ -334,11 +301,7 @@ mod tests {
|
|||||||
assert_eq!(client_finalize_result, res2);
|
assert_eq!(client_finalize_result, res2);
|
||||||
}
|
}
|
||||||
|
|
||||||
fn base_inversion_unsalted<CS: CipherSuite>()
|
fn base_inversion_unsalted<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let mut input = [0u8; 64];
|
let mut input = [0u8; 64];
|
||||||
rng.fill_bytes(&mut input);
|
rng.fill_bytes(&mut input);
|
||||||
@@ -358,11 +321,7 @@ mod tests {
|
|||||||
assert_eq!(client_finalize_result, res2);
|
assert_eq!(client_finalize_result, res2);
|
||||||
}
|
}
|
||||||
|
|
||||||
fn server_evaluate<CS: CipherSuite>()
|
fn server_evaluate<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let client_blind_result = OprfClient::<CS>::blind(input, &mut rng).unwrap();
|
let client_blind_result = OprfClient::<CS>::blind(input, &mut rng).unwrap();
|
||||||
@@ -386,11 +345,7 @@ mod tests {
|
|||||||
assert!(client_finalize != server_evaluate);
|
assert!(client_finalize != server_evaluate);
|
||||||
}
|
}
|
||||||
|
|
||||||
fn zeroize_oprf_client<CS: CipherSuite>()
|
fn zeroize_oprf_client<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let client_blind_result = OprfClient::<CS>::blind(input, &mut rng).unwrap();
|
let client_blind_result = OprfClient::<CS>::blind(input, &mut rng).unwrap();
|
||||||
@@ -404,11 +359,7 @@ mod tests {
|
|||||||
assert!(message.serialize().iter().all(|&x| x == 0));
|
assert!(message.serialize().iter().all(|&x| x == 0));
|
||||||
}
|
}
|
||||||
|
|
||||||
fn zeroize_oprf_server<CS: CipherSuite>()
|
fn zeroize_oprf_server<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let client_blind_result = OprfClient::<CS>::blind(input, &mut rng).unwrap();
|
let client_blind_result = OprfClient::<CS>::blind(input, &mut rng).unwrap();
|
||||||
@@ -427,6 +378,7 @@ mod tests {
|
|||||||
fn test_functionality() -> Result<()> {
|
fn test_functionality() -> Result<()> {
|
||||||
use p256::NistP256;
|
use p256::NistP256;
|
||||||
use p384::NistP384;
|
use p384::NistP384;
|
||||||
|
use p521::NistP521;
|
||||||
|
|
||||||
#[cfg(feature = "ristretto255")]
|
#[cfg(feature = "ristretto255")]
|
||||||
{
|
{
|
||||||
@@ -454,6 +406,13 @@ mod tests {
|
|||||||
zeroize_oprf_client::<NistP384>();
|
zeroize_oprf_client::<NistP384>();
|
||||||
zeroize_oprf_server::<NistP384>();
|
zeroize_oprf_server::<NistP384>();
|
||||||
|
|
||||||
|
base_retrieval::<NistP521>();
|
||||||
|
base_inversion_unsalted::<NistP521>();
|
||||||
|
server_evaluate::<NistP521>();
|
||||||
|
|
||||||
|
zeroize_oprf_client::<NistP521>();
|
||||||
|
zeroize_oprf_server::<NistP521>();
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+38
-116
@@ -13,10 +13,9 @@ use alloc::vec::Vec;
|
|||||||
use core::iter::{self, Map, Repeat, Zip};
|
use core::iter::{self, Map, Repeat, Zip};
|
||||||
|
|
||||||
use derive_where::derive_where;
|
use derive_where::derive_where;
|
||||||
use digest::core_api::BlockSizeUser;
|
|
||||||
use digest::{Digest, Output, OutputSizeUser};
|
use digest::{Digest, Output, OutputSizeUser};
|
||||||
use generic_array::typenum::{IsLess, IsLessOrEqual, Unsigned, U256};
|
use generic_array::typenum::Unsigned;
|
||||||
use generic_array::GenericArray;
|
use generic_array::{ArrayLength, GenericArray};
|
||||||
use rand_core::{CryptoRng, RngCore};
|
use rand_core::{CryptoRng, RngCore};
|
||||||
|
|
||||||
use crate::common::{
|
use crate::common::{
|
||||||
@@ -42,11 +41,7 @@ use crate::{CipherSuite, Error, Group, Result};
|
|||||||
derive(serde::Deserialize, serde::Serialize),
|
derive(serde::Deserialize, serde::Serialize),
|
||||||
serde(bound = "")
|
serde(bound = "")
|
||||||
)]
|
)]
|
||||||
pub struct PoprfClient<CS: CipherSuite>
|
pub struct PoprfClient<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
||||||
pub(crate) blind: <CS::Group as Group>::Scalar,
|
pub(crate) blind: <CS::Group as Group>::Scalar,
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
||||||
@@ -62,11 +57,7 @@ where
|
|||||||
derive(serde::Deserialize, serde::Serialize),
|
derive(serde::Deserialize, serde::Serialize),
|
||||||
serde(bound = "")
|
serde(bound = "")
|
||||||
)]
|
)]
|
||||||
pub struct PoprfServer<CS: CipherSuite>
|
pub struct PoprfServer<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
||||||
pub(crate) sk: <CS::Group as Group>::Scalar,
|
pub(crate) sk: <CS::Group as Group>::Scalar,
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
||||||
@@ -78,11 +69,7 @@ where
|
|||||||
// =================== //
|
// =================== //
|
||||||
/////////////////////////
|
/////////////////////////
|
||||||
|
|
||||||
impl<CS: CipherSuite> PoprfClient<CS>
|
impl<CS: CipherSuite> PoprfClient<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Computes the first step for the multiplicative blinding version of
|
/// Computes the first step for the multiplicative blinding version of
|
||||||
/// DH-OPRF.
|
/// DH-OPRF.
|
||||||
///
|
///
|
||||||
@@ -145,7 +132,10 @@ where
|
|||||||
proof: &Proof<CS>,
|
proof: &Proof<CS>,
|
||||||
pk: <CS::Group as Group>::Elem,
|
pk: <CS::Group as Group>::Elem,
|
||||||
info: Option<&[u8]>,
|
info: Option<&[u8]>,
|
||||||
) -> Result<Output<CS::Hash>> {
|
) -> Result<Output<CS::Hash>>
|
||||||
|
where
|
||||||
|
<<CS as CipherSuite>::Hash as OutputSizeUser>::OutputSize: ArrayLength,
|
||||||
|
{
|
||||||
let clients = core::array::from_ref(self);
|
let clients = core::array::from_ref(self);
|
||||||
let messages = core::array::from_ref(evaluation_element);
|
let messages = core::array::from_ref(evaluation_element);
|
||||||
|
|
||||||
@@ -180,6 +170,7 @@ where
|
|||||||
<&'a IC as IntoIterator>::IntoIter: ExactSizeIterator,
|
<&'a IC as IntoIterator>::IntoIter: ExactSizeIterator,
|
||||||
&'a IM: 'a + IntoIterator<Item = &'a EvaluationElement<CS>>,
|
&'a IM: 'a + IntoIterator<Item = &'a EvaluationElement<CS>>,
|
||||||
<&'a IM as IntoIterator>::IntoIter: ExactSizeIterator,
|
<&'a IM as IntoIterator>::IntoIter: ExactSizeIterator,
|
||||||
|
<<CS as CipherSuite>::Hash as OutputSizeUser>::OutputSize: ArrayLength,
|
||||||
{
|
{
|
||||||
let unblinded_elements = poprf_unblind(clients, messages, pk, proof, info)?;
|
let unblinded_elements = poprf_unblind(clients, messages, pk, proof, info)?;
|
||||||
|
|
||||||
@@ -193,11 +184,7 @@ where
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<CS: CipherSuite> PoprfServer<CS>
|
impl<CS: CipherSuite> PoprfServer<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Produces a new instance of a [PoprfServer] using a supplied RNG
|
/// Produces a new instance of a [PoprfServer] using a supplied RNG
|
||||||
///
|
///
|
||||||
/// # Errors
|
/// # Errors
|
||||||
@@ -235,7 +222,7 @@ where
|
|||||||
Ok(Self { sk, pk })
|
Ok(Self { sk, pk })
|
||||||
}
|
}
|
||||||
|
|
||||||
// Only used for tests
|
/// Only used for tests
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
pub fn get_private_key(&self) -> <CS::Group as Group>::Scalar {
|
pub fn get_private_key(&self) -> <CS::Group as Group>::Scalar {
|
||||||
self.sk
|
self.sk
|
||||||
@@ -427,11 +414,7 @@ where
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<CS: CipherSuite> BlindedElement<CS>
|
impl<CS: CipherSuite> BlindedElement<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Creates a [BlindedElement] from a raw group element.
|
/// Creates a [BlindedElement] from a raw group element.
|
||||||
///
|
///
|
||||||
/// # Caution
|
/// # Caution
|
||||||
@@ -450,11 +433,7 @@ where
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<CS: CipherSuite> EvaluationElement<CS>
|
impl<CS: CipherSuite> EvaluationElement<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Creates an [EvaluationElement] from a raw group element.
|
/// Creates an [EvaluationElement] from a raw group element.
|
||||||
///
|
///
|
||||||
/// # Caution
|
/// # Caution
|
||||||
@@ -480,11 +459,7 @@ where
|
|||||||
|
|
||||||
/// Contains the fields that are returned by a verifiable client blind
|
/// Contains the fields that are returned by a verifiable client blind
|
||||||
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
||||||
pub struct PoprfClientBlindResult<CS: CipherSuite>
|
pub struct PoprfClientBlindResult<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// The state to be persisted on the client
|
/// The state to be persisted on the client
|
||||||
pub state: PoprfClient<CS>,
|
pub state: PoprfClient<CS>,
|
||||||
/// The message to send to the server
|
/// The message to send to the server
|
||||||
@@ -497,11 +472,7 @@ pub type PoprfClientBatchFinalizeResult<'a, CS, II, IC, IM> =
|
|||||||
|
|
||||||
/// Contains the fields that are returned by a verifiable server evaluate
|
/// Contains the fields that are returned by a verifiable server evaluate
|
||||||
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
||||||
pub struct PoprfServerEvaluateResult<CS: CipherSuite>
|
pub struct PoprfServerEvaluateResult<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// The message to send to the client
|
/// The message to send to the client
|
||||||
pub message: EvaluationElement<CS>,
|
pub message: EvaluationElement<CS>,
|
||||||
/// The proof for the client to verify
|
/// The proof for the client to verify
|
||||||
@@ -511,11 +482,7 @@ where
|
|||||||
/// Contains the fields that are returned by a verifiable server batch evaluate
|
/// Contains the fields that are returned by a verifiable server batch evaluate
|
||||||
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
||||||
#[cfg(feature = "alloc")]
|
#[cfg(feature = "alloc")]
|
||||||
pub struct PoprfServerBatchEvaluateResult<CS: CipherSuite>
|
pub struct PoprfServerBatchEvaluateResult<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// The messages to send to the client
|
/// The messages to send to the client
|
||||||
pub messages: Vec<EvaluationElement<CS>>,
|
pub messages: Vec<EvaluationElement<CS>>,
|
||||||
/// The proof for the client to verify
|
/// The proof for the client to verify
|
||||||
@@ -545,19 +512,12 @@ pub type PoprfServerBatchEvaluatePreparedEvaluationElements<CS, I> = Map<
|
|||||||
pub struct PoprfPreparedTweak<CS: CipherSuite>(
|
pub struct PoprfPreparedTweak<CS: CipherSuite>(
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
||||||
<CS::Group as Group>::Scalar,
|
<CS::Group as Group>::Scalar,
|
||||||
)
|
);
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>;
|
|
||||||
|
|
||||||
/// Contains the fields that are returned by a partially verifiable server batch
|
/// Contains the fields that are returned by a partially verifiable server batch
|
||||||
/// evaluate prepare
|
/// evaluate prepare
|
||||||
#[derive_where(Debug; I, <CS::Group as Group>::Scalar)]
|
#[derive_where(Debug; I, <CS::Group as Group>::Scalar)]
|
||||||
pub struct PoprfServerBatchEvaluatePrepareResult<CS: CipherSuite, I>
|
pub struct PoprfServerBatchEvaluatePrepareResult<CS: CipherSuite, I> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Prepared [`EvaluationElement`].
|
/// Prepared [`EvaluationElement`].
|
||||||
pub prepared_evaluation_elements: PoprfServerBatchEvaluatePreparedEvaluationElements<CS, I>,
|
pub prepared_evaluation_elements: PoprfServerBatchEvaluatePreparedEvaluationElements<CS, I>,
|
||||||
/// Prepared tweak.
|
/// Prepared tweak.
|
||||||
@@ -576,8 +536,6 @@ pub type PoprfServerBatchEvaluateFinishedMessages<'a, CS, I> = Map<
|
|||||||
#[derive_where(Debug; <&'a I as IntoIterator>::IntoIter, <CS::Group as Group>::Scalar)]
|
#[derive_where(Debug; <&'a I as IntoIterator>::IntoIter, <CS::Group as Group>::Scalar)]
|
||||||
pub struct PoprfServerBatchEvaluateFinishResult<'a, CS: 'a + CipherSuite, I>
|
pub struct PoprfServerBatchEvaluateFinishResult<'a, CS: 'a + CipherSuite, I>
|
||||||
where
|
where
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
&'a I: IntoIterator<Item = &'a PreparedEvaluationElement<CS>>,
|
&'a I: IntoIterator<Item = &'a PreparedEvaluationElement<CS>>,
|
||||||
{
|
{
|
||||||
/// The [`EvaluationElement`]s to send to the client
|
/// The [`EvaluationElement`]s to send to the client
|
||||||
@@ -598,11 +556,7 @@ where
|
|||||||
fn compute_tweaked_key<CS: CipherSuite>(
|
fn compute_tweaked_key<CS: CipherSuite>(
|
||||||
pk: <CS::Group as Group>::Elem,
|
pk: <CS::Group as Group>::Elem,
|
||||||
info: Option<&[u8]>,
|
info: Option<&[u8]>,
|
||||||
) -> Result<<CS::Group as Group>::Elem>
|
) -> Result<<CS::Group as Group>::Elem> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
// None for info is treated the same as empty bytes
|
// None for info is treated the same as empty bytes
|
||||||
let info = info.unwrap_or_default();
|
let info = info.unwrap_or_default();
|
||||||
|
|
||||||
@@ -636,11 +590,7 @@ where
|
|||||||
fn compute_tweak<CS: CipherSuite>(
|
fn compute_tweak<CS: CipherSuite>(
|
||||||
sk: <CS::Group as Group>::Scalar,
|
sk: <CS::Group as Group>::Scalar,
|
||||||
info: Option<&[u8]>,
|
info: Option<&[u8]>,
|
||||||
) -> Result<<CS::Group as Group>::Scalar>
|
) -> Result<<CS::Group as Group>::Scalar> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
// None for info is treated the same as empty bytes
|
// None for info is treated the same as empty bytes
|
||||||
let info = info.unwrap_or_default();
|
let info = info.unwrap_or_default();
|
||||||
|
|
||||||
@@ -691,8 +641,6 @@ fn poprf_unblind<'a, CS: 'a + CipherSuite, IC, IM>(
|
|||||||
info: Option<&[u8]>,
|
info: Option<&[u8]>,
|
||||||
) -> Result<PoprfUnblindResult<'a, CS, IC, IM>>
|
) -> Result<PoprfUnblindResult<'a, CS, IC, IM>>
|
||||||
where
|
where
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
&'a IC: 'a + IntoIterator<Item = &'a PoprfClient<CS>>,
|
&'a IC: 'a + IntoIterator<Item = &'a PoprfClient<CS>>,
|
||||||
<&'a IC as IntoIterator>::IntoIter: ExactSizeIterator,
|
<&'a IC as IntoIterator>::IntoIter: ExactSizeIterator,
|
||||||
&'a IM: 'a + IntoIterator<Item = &'a EvaluationElement<CS>>,
|
&'a IM: 'a + IntoIterator<Item = &'a EvaluationElement<CS>>,
|
||||||
@@ -720,7 +668,7 @@ where
|
|||||||
)?;
|
)?;
|
||||||
|
|
||||||
Ok(blinds
|
Ok(blinds
|
||||||
.zip(messages.into_iter())
|
.zip(messages)
|
||||||
.map(|(blind, x)| x.0 * &CS::Group::invert_scalar(blind)))
|
.map(|(blind, x)| x.0 * &CS::Group::invert_scalar(blind)))
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -728,7 +676,7 @@ type FinalizeAfterUnblindResult<'a, CS, IE, II> = Map<
|
|||||||
Zip<Zip<IE, II>, Repeat<&'a [u8]>>,
|
Zip<Zip<IE, II>, Repeat<&'a [u8]>>,
|
||||||
fn(
|
fn(
|
||||||
((<<CS as CipherSuite>::Group as Group>::Elem, &[u8]), &[u8]),
|
((<<CS as CipherSuite>::Group as Group>::Elem, &[u8]), &[u8]),
|
||||||
) -> Result<GenericArray<u8, <<CS as CipherSuite>::Hash as OutputSizeUser>::OutputSize>>,
|
) -> Result<Output<<CS as CipherSuite>::Hash>>,
|
||||||
>;
|
>;
|
||||||
|
|
||||||
/// Can only fail with [`Error::Batch`] and returned values can only fail with
|
/// Can only fail with [`Error::Batch`] and returned values can only fail with
|
||||||
@@ -744,8 +692,7 @@ fn finalize_after_unblind<
|
|||||||
info: Option<&'a [u8]>,
|
info: Option<&'a [u8]>,
|
||||||
) -> Result<FinalizeAfterUnblindResult<'a, CS, IE, II>>
|
) -> Result<FinalizeAfterUnblindResult<'a, CS, IE, II>>
|
||||||
where
|
where
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
<<CS as CipherSuite>::Hash as OutputSizeUser>::OutputSize: ArrayLength,
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
{
|
||||||
if unblinded_elements.len() != inputs.len() {
|
if unblinded_elements.len() != inputs.len() {
|
||||||
return Err(Error::Batch);
|
return Err(Error::Batch);
|
||||||
@@ -784,11 +731,8 @@ where
|
|||||||
|
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
mod tests {
|
mod tests {
|
||||||
use core::ops::Add;
|
|
||||||
use core::ptr;
|
use core::ptr;
|
||||||
|
|
||||||
use generic_array::typenum::Sum;
|
|
||||||
use generic_array::ArrayLength;
|
|
||||||
use rand::rngs::OsRng;
|
use rand::rngs::OsRng;
|
||||||
|
|
||||||
use super::*;
|
use super::*;
|
||||||
@@ -800,11 +744,7 @@ mod tests {
|
|||||||
key: <CS::Group as Group>::Scalar,
|
key: <CS::Group as Group>::Scalar,
|
||||||
info: &[u8],
|
info: &[u8],
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Output<CS::Hash>
|
) -> Output<CS::Hash> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let t = compute_tweak::<CS>(key, Some(info)).unwrap();
|
let t = compute_tweak::<CS>(key, Some(info)).unwrap();
|
||||||
|
|
||||||
let dst = Dst::new::<CS, _, _>(STR_HASH_TO_GROUP, mode);
|
let dst = Dst::new::<CS, _, _>(STR_HASH_TO_GROUP, mode);
|
||||||
@@ -820,11 +760,7 @@ mod tests {
|
|||||||
.unwrap()
|
.unwrap()
|
||||||
}
|
}
|
||||||
|
|
||||||
fn verifiable_retrieval<CS: CipherSuite>()
|
fn verifiable_retrieval<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let info = b"info";
|
let info = b"info";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
@@ -847,11 +783,7 @@ mod tests {
|
|||||||
assert_eq!(client_finalize_result, res2);
|
assert_eq!(client_finalize_result, res2);
|
||||||
}
|
}
|
||||||
|
|
||||||
fn verifiable_bad_public_key<CS: CipherSuite>()
|
fn verifiable_bad_public_key<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let info = b"info";
|
let info = b"info";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
@@ -875,11 +807,7 @@ mod tests {
|
|||||||
assert!(client_finalize_result.is_err());
|
assert!(client_finalize_result.is_err());
|
||||||
}
|
}
|
||||||
|
|
||||||
fn verifiable_server_evaluate<CS: CipherSuite>()
|
fn verifiable_server_evaluate<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let info = Some(b"info".as_slice());
|
let info = Some(b"info".as_slice());
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
@@ -912,13 +840,7 @@ mod tests {
|
|||||||
assert!(client_finalize != server_evaluate);
|
assert!(client_finalize != server_evaluate);
|
||||||
}
|
}
|
||||||
|
|
||||||
fn zeroize_verifiable_client<CS: CipherSuite>()
|
fn zeroize_verifiable_client<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ElemLen>,
|
|
||||||
Sum<<CS::Group as Group>::ScalarLen, <CS::Group as Group>::ElemLen>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let client_blind_result = PoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
let client_blind_result = PoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
||||||
@@ -932,15 +854,7 @@ mod tests {
|
|||||||
assert!(message.serialize().iter().all(|&x| x == 0));
|
assert!(message.serialize().iter().all(|&x| x == 0));
|
||||||
}
|
}
|
||||||
|
|
||||||
fn zeroize_verifiable_server<CS: CipherSuite>()
|
fn zeroize_verifiable_server<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ElemLen>,
|
|
||||||
Sum<<CS::Group as Group>::ScalarLen, <CS::Group as Group>::ElemLen>: ArrayLength<u8>,
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ScalarLen>,
|
|
||||||
Sum<<CS::Group as Group>::ScalarLen, <CS::Group as Group>::ScalarLen>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let info = b"info";
|
let info = b"info";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
@@ -967,6 +881,7 @@ mod tests {
|
|||||||
fn test_functionality() -> Result<()> {
|
fn test_functionality() -> Result<()> {
|
||||||
use p256::NistP256;
|
use p256::NistP256;
|
||||||
use p384::NistP384;
|
use p384::NistP384;
|
||||||
|
use p521::NistP521;
|
||||||
|
|
||||||
#[cfg(feature = "ristretto255")]
|
#[cfg(feature = "ristretto255")]
|
||||||
{
|
{
|
||||||
@@ -994,6 +909,13 @@ mod tests {
|
|||||||
zeroize_verifiable_client::<NistP384>();
|
zeroize_verifiable_client::<NistP384>();
|
||||||
zeroize_verifiable_server::<NistP384>();
|
zeroize_verifiable_server::<NistP384>();
|
||||||
|
|
||||||
|
verifiable_retrieval::<NistP521>();
|
||||||
|
verifiable_bad_public_key::<NistP521>();
|
||||||
|
verifiable_server_evaluate::<NistP521>();
|
||||||
|
|
||||||
|
zeroize_verifiable_client::<NistP521>();
|
||||||
|
zeroize_verifiable_server::<NistP521>();
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+19
-78
@@ -9,13 +9,9 @@
|
|||||||
//! Handles the serialization of each of the components used in the VOPRF
|
//! Handles the serialization of each of the components used in the VOPRF
|
||||||
//! protocol
|
//! protocol
|
||||||
|
|
||||||
use core::ops::Add;
|
|
||||||
|
|
||||||
use digest::core_api::BlockSizeUser;
|
|
||||||
use digest::OutputSizeUser;
|
|
||||||
use generic_array::sequence::Concat;
|
use generic_array::sequence::Concat;
|
||||||
use generic_array::typenum::{IsLess, IsLessOrEqual, Sum, Unsigned, U256};
|
use generic_array::typenum::{Sum, Unsigned};
|
||||||
use generic_array::{ArrayLength, GenericArray};
|
use generic_array::GenericArray;
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
BlindedElement, CipherSuite, Error, EvaluationElement, Group, OprfClient, OprfServer,
|
BlindedElement, CipherSuite, Error, EvaluationElement, Group, OprfClient, OprfServer,
|
||||||
@@ -30,11 +26,7 @@ use crate::{
|
|||||||
/// Length of [`OprfClient`] in bytes for serialization.
|
/// Length of [`OprfClient`] in bytes for serialization.
|
||||||
pub type OprfClientLen<CS> = <<CS as CipherSuite>::Group as Group>::ScalarLen;
|
pub type OprfClientLen<CS> = <<CS as CipherSuite>::Group as Group>::ScalarLen;
|
||||||
|
|
||||||
impl<CS: CipherSuite> OprfClient<CS>
|
impl<CS: CipherSuite> OprfClient<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Serialization into bytes
|
/// Serialization into bytes
|
||||||
pub fn serialize(&self) -> GenericArray<u8, OprfClientLen<CS>> {
|
pub fn serialize(&self) -> GenericArray<u8, OprfClientLen<CS>> {
|
||||||
CS::Group::serialize_scalar(self.blind)
|
CS::Group::serialize_scalar(self.blind)
|
||||||
@@ -57,17 +49,9 @@ pub type VoprfClientLen<CS> = Sum<
|
|||||||
<<CS as CipherSuite>::Group as Group>::ElemLen,
|
<<CS as CipherSuite>::Group as Group>::ElemLen,
|
||||||
>;
|
>;
|
||||||
|
|
||||||
impl<CS: CipherSuite> VoprfClient<CS>
|
impl<CS: CipherSuite> VoprfClient<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Serialization into bytes
|
/// Serialization into bytes
|
||||||
pub fn serialize(&self) -> GenericArray<u8, VoprfClientLen<CS>>
|
pub fn serialize(&self) -> GenericArray<u8, VoprfClientLen<CS>> {
|
||||||
where
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ElemLen>,
|
|
||||||
VoprfClientLen<CS>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
<CS::Group as Group>::serialize_scalar(self.blind)
|
<CS::Group as Group>::serialize_scalar(self.blind)
|
||||||
.concat(<CS::Group as Group>::serialize_elem(self.blinded_element))
|
.concat(<CS::Group as Group>::serialize_elem(self.blinded_element))
|
||||||
}
|
}
|
||||||
@@ -93,17 +77,9 @@ pub type PoprfClientLen<CS> = Sum<
|
|||||||
<<CS as CipherSuite>::Group as Group>::ElemLen,
|
<<CS as CipherSuite>::Group as Group>::ElemLen,
|
||||||
>;
|
>;
|
||||||
|
|
||||||
impl<CS: CipherSuite> PoprfClient<CS>
|
impl<CS: CipherSuite> PoprfClient<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Serialization into bytes
|
/// Serialization into bytes
|
||||||
pub fn serialize(&self) -> GenericArray<u8, PoprfClientLen<CS>>
|
pub fn serialize(&self) -> GenericArray<u8, PoprfClientLen<CS>> {
|
||||||
where
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ElemLen>,
|
|
||||||
PoprfClientLen<CS>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
<CS::Group as Group>::serialize_scalar(self.blind)
|
<CS::Group as Group>::serialize_scalar(self.blind)
|
||||||
.concat(<CS::Group as Group>::serialize_elem(self.blinded_element))
|
.concat(<CS::Group as Group>::serialize_elem(self.blinded_element))
|
||||||
}
|
}
|
||||||
@@ -126,11 +102,7 @@ where
|
|||||||
/// Length of [`OprfServer`] in bytes for serialization.
|
/// Length of [`OprfServer`] in bytes for serialization.
|
||||||
pub type OprfServerLen<CS> = <<CS as CipherSuite>::Group as Group>::ScalarLen;
|
pub type OprfServerLen<CS> = <<CS as CipherSuite>::Group as Group>::ScalarLen;
|
||||||
|
|
||||||
impl<CS: CipherSuite> OprfServer<CS>
|
impl<CS: CipherSuite> OprfServer<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Serialization into bytes
|
/// Serialization into bytes
|
||||||
pub fn serialize(&self) -> GenericArray<u8, OprfServerLen<CS>> {
|
pub fn serialize(&self) -> GenericArray<u8, OprfServerLen<CS>> {
|
||||||
CS::Group::serialize_scalar(self.sk)
|
CS::Group::serialize_scalar(self.sk)
|
||||||
@@ -153,17 +125,9 @@ pub type VoprfServerLen<CS> = Sum<
|
|||||||
<<CS as CipherSuite>::Group as Group>::ElemLen,
|
<<CS as CipherSuite>::Group as Group>::ElemLen,
|
||||||
>;
|
>;
|
||||||
|
|
||||||
impl<CS: CipherSuite> VoprfServer<CS>
|
impl<CS: CipherSuite> VoprfServer<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Serialization into bytes
|
/// Serialization into bytes
|
||||||
pub fn serialize(&self) -> GenericArray<u8, VoprfServerLen<CS>>
|
pub fn serialize(&self) -> GenericArray<u8, VoprfServerLen<CS>> {
|
||||||
where
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ElemLen>,
|
|
||||||
VoprfServerLen<CS>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
CS::Group::serialize_scalar(self.sk).concat(CS::Group::serialize_elem(self.pk))
|
CS::Group::serialize_scalar(self.sk).concat(CS::Group::serialize_elem(self.pk))
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -185,17 +149,9 @@ pub type PoprfServerLen<CS> = Sum<
|
|||||||
<<CS as CipherSuite>::Group as Group>::ElemLen,
|
<<CS as CipherSuite>::Group as Group>::ElemLen,
|
||||||
>;
|
>;
|
||||||
|
|
||||||
impl<CS: CipherSuite> PoprfServer<CS>
|
impl<CS: CipherSuite> PoprfServer<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Serialization into bytes
|
/// Serialization into bytes
|
||||||
pub fn serialize(&self) -> GenericArray<u8, PoprfServerLen<CS>>
|
pub fn serialize(&self) -> GenericArray<u8, PoprfServerLen<CS>> {
|
||||||
where
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ElemLen>,
|
|
||||||
PoprfServerLen<CS>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
CS::Group::serialize_scalar(self.sk).concat(CS::Group::serialize_elem(self.pk))
|
CS::Group::serialize_scalar(self.sk).concat(CS::Group::serialize_elem(self.pk))
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -217,17 +173,9 @@ pub type ProofLen<CS> = Sum<
|
|||||||
<<CS as CipherSuite>::Group as Group>::ScalarLen,
|
<<CS as CipherSuite>::Group as Group>::ScalarLen,
|
||||||
>;
|
>;
|
||||||
|
|
||||||
impl<CS: CipherSuite> Proof<CS>
|
impl<CS: CipherSuite> Proof<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Serialization into bytes
|
/// Serialization into bytes
|
||||||
pub fn serialize(&self) -> GenericArray<u8, ProofLen<CS>>
|
pub fn serialize(&self) -> GenericArray<u8, ProofLen<CS>> {
|
||||||
where
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ScalarLen>,
|
|
||||||
ProofLen<CS>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
CS::Group::serialize_scalar(self.c_scalar)
|
CS::Group::serialize_scalar(self.c_scalar)
|
||||||
.concat(CS::Group::serialize_scalar(self.s_scalar))
|
.concat(CS::Group::serialize_scalar(self.s_scalar))
|
||||||
}
|
}
|
||||||
@@ -247,11 +195,7 @@ where
|
|||||||
/// Length of [`BlindedElement`] in bytes for serialization.
|
/// Length of [`BlindedElement`] in bytes for serialization.
|
||||||
pub type BlindedElementLen<CS> = <<CS as CipherSuite>::Group as Group>::ElemLen;
|
pub type BlindedElementLen<CS> = <<CS as CipherSuite>::Group as Group>::ElemLen;
|
||||||
|
|
||||||
impl<CS: CipherSuite> BlindedElement<CS>
|
impl<CS: CipherSuite> BlindedElement<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Serialization into bytes
|
/// Serialization into bytes
|
||||||
pub fn serialize(&self) -> GenericArray<u8, BlindedElementLen<CS>> {
|
pub fn serialize(&self) -> GenericArray<u8, BlindedElementLen<CS>> {
|
||||||
CS::Group::serialize_elem(self.0)
|
CS::Group::serialize_elem(self.0)
|
||||||
@@ -271,11 +215,7 @@ where
|
|||||||
/// Length of [`EvaluationElement`] in bytes for serialization.
|
/// Length of [`EvaluationElement`] in bytes for serialization.
|
||||||
pub type EvaluationElementLen<CS> = <<CS as CipherSuite>::Group as Group>::ElemLen;
|
pub type EvaluationElementLen<CS> = <<CS as CipherSuite>::Group as Group>::ElemLen;
|
||||||
|
|
||||||
impl<CS: CipherSuite> EvaluationElement<CS>
|
impl<CS: CipherSuite> EvaluationElement<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Serialization into bytes
|
/// Serialization into bytes
|
||||||
pub fn serialize(&self) -> GenericArray<u8, EvaluationElementLen<CS>> {
|
pub fn serialize(&self) -> GenericArray<u8, EvaluationElementLen<CS>> {
|
||||||
CS::Group::serialize_elem(self.0)
|
CS::Group::serialize_elem(self.0)
|
||||||
@@ -307,11 +247,11 @@ fn deserialize_scalar<G: Group>(input: &mut &[u8]) -> Result<G::Scalar> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
trait SliceExt {
|
trait SliceExt {
|
||||||
fn take_ext(self: &mut &Self, take: usize) -> Option<&Self>;
|
fn take_ext<'a>(self: &mut &'a Self, take: usize) -> Option<&'a Self>;
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<T> SliceExt for [T] {
|
impl<T> SliceExt for [T] {
|
||||||
fn take_ext(self: &mut &Self, take: usize) -> Option<&Self> {
|
fn take_ext<'a>(self: &mut &'a Self, take: usize) -> Option<&'a Self> {
|
||||||
if take > self.len() {
|
if take > self.len() {
|
||||||
return None;
|
return None;
|
||||||
}
|
}
|
||||||
@@ -391,6 +331,7 @@ mod test {
|
|||||||
|
|
||||||
let _ = $item::<p256::NistP256>::deserialize(&$bytes[..]);
|
let _ = $item::<p256::NistP256>::deserialize(&$bytes[..]);
|
||||||
let _ = $item::<p384::NistP384>::deserialize(&$bytes[..]);
|
let _ = $item::<p384::NistP384>::deserialize(&$bytes[..]);
|
||||||
|
let _ = $item::<p521::NistP521>::deserialize(&$bytes[..]);
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+910
-1020
File diff suppressed because it is too large
Load Diff
+3
-3
@@ -15,7 +15,7 @@ pub(crate) fn rfc_to_json(input: &str) -> String {
|
|||||||
}
|
}
|
||||||
|
|
||||||
fn parse_ciphersuites(input: &str) -> String {
|
fn parse_ciphersuites(input: &str) -> String {
|
||||||
let re = regex::Regex::new(r"\n## (?P<ciphersuite>.+?)\n").unwrap();
|
let re = regex::Regex::new(r"\nA\.\d\. (?P<ciphersuite>.+?)\n\n").unwrap();
|
||||||
let mut ciphersuites = vec![];
|
let mut ciphersuites = vec![];
|
||||||
|
|
||||||
let chunks: Vec<&str> = re.split(input).collect();
|
let chunks: Vec<&str> = re.split(input).collect();
|
||||||
@@ -34,7 +34,7 @@ fn parse_ciphersuites(input: &str) -> String {
|
|||||||
}
|
}
|
||||||
|
|
||||||
fn parse_modes(input: &str) -> String {
|
fn parse_modes(input: &str) -> String {
|
||||||
let re = regex::Regex::new(r"### (?P<mode>.*+) Mode").unwrap();
|
let re = regex::Regex::new(r"A\.\d.\d\. (?P<mode>.*?) Mode").unwrap();
|
||||||
let mut modes = vec![];
|
let mut modes = vec![];
|
||||||
|
|
||||||
let chunks: Vec<&str> = re.split(input).collect();
|
let chunks: Vec<&str> = re.split(input).collect();
|
||||||
@@ -53,7 +53,7 @@ fn parse_modes(input: &str) -> String {
|
|||||||
}
|
}
|
||||||
|
|
||||||
fn parse_vectors(input: &str) -> String {
|
fn parse_vectors(input: &str) -> String {
|
||||||
let re = regex::Regex::new(r"Test Vector.*+\n").unwrap();
|
let re = regex::Regex::new(r"A\.\d.\d\.\d\. Test Vector.*+\n").unwrap();
|
||||||
let mut vectors = vec![];
|
let mut vectors = vec![];
|
||||||
|
|
||||||
let chunks: Vec<&str> = re.split(input).collect();
|
let chunks: Vec<&str> = re.split(input).collect();
|
||||||
|
|||||||
@@ -9,12 +9,7 @@
|
|||||||
use alloc::string::String;
|
use alloc::string::String;
|
||||||
use alloc::vec;
|
use alloc::vec;
|
||||||
use alloc::vec::Vec;
|
use alloc::vec::Vec;
|
||||||
use core::ops::Add;
|
|
||||||
|
|
||||||
use digest::core_api::BlockSizeUser;
|
|
||||||
use digest::OutputSizeUser;
|
|
||||||
use generic_array::typenum::{IsLess, IsLessOrEqual, Sum, U256};
|
|
||||||
use generic_array::ArrayLength;
|
|
||||||
use serde_json::Value;
|
use serde_json::Value;
|
||||||
|
|
||||||
use crate::tests::mock_rng::CycleRng;
|
use crate::tests::mock_rng::CycleRng;
|
||||||
@@ -89,6 +84,7 @@ macro_rules! json_to_test_vectors {
|
|||||||
fn test_vectors() -> Result<()> {
|
fn test_vectors() -> Result<()> {
|
||||||
use p256::NistP256;
|
use p256::NistP256;
|
||||||
use p384::NistP384;
|
use p384::NistP384;
|
||||||
|
use p521::NistP521;
|
||||||
|
|
||||||
let rfc: Value = serde_json::from_str(rfc_to_json(super::cfrg_vectors::VECTORS).as_str())
|
let rfc: Value = serde_json::from_str(rfc_to_json(super::cfrg_vectors::VECTORS).as_str())
|
||||||
.expect("Could not parse json");
|
.expect("Could not parse json");
|
||||||
@@ -188,14 +184,37 @@ fn test_vectors() -> Result<()> {
|
|||||||
test_poprf_finalize::<NistP384>(&p384_poprf_tvs)?;
|
test_poprf_finalize::<NistP384>(&p384_poprf_tvs)?;
|
||||||
test_poprf_evaluate::<NistP384>(&p384_poprf_tvs)?;
|
test_poprf_evaluate::<NistP384>(&p384_poprf_tvs)?;
|
||||||
|
|
||||||
|
let p521_oprf_tvs =
|
||||||
|
json_to_test_vectors!(rfc, String::from("P521-SHA512"), String::from("OPRF"));
|
||||||
|
assert_ne!(p521_oprf_tvs.len(), 0);
|
||||||
|
test_oprf_seed_to_key::<NistP521>(&p521_oprf_tvs)?;
|
||||||
|
test_oprf_blind::<NistP521>(&p521_oprf_tvs)?;
|
||||||
|
test_oprf_blind_evaluate::<NistP521>(&p521_oprf_tvs)?;
|
||||||
|
test_oprf_finalize::<NistP521>(&p521_oprf_tvs)?;
|
||||||
|
test_oprf_evaluate::<NistP521>(&p521_oprf_tvs)?;
|
||||||
|
|
||||||
|
let p521_voprf_tvs =
|
||||||
|
json_to_test_vectors!(rfc, String::from("P521-SHA512"), String::from("VOPRF"));
|
||||||
|
assert_ne!(p521_voprf_tvs.len(), 0);
|
||||||
|
test_voprf_seed_to_key::<NistP521>(&p521_voprf_tvs)?;
|
||||||
|
test_voprf_blind::<NistP521>(&p521_voprf_tvs)?;
|
||||||
|
test_voprf_blind_evaluate::<NistP521>(&p521_voprf_tvs)?;
|
||||||
|
test_voprf_finalize::<NistP521>(&p521_voprf_tvs)?;
|
||||||
|
test_voprf_evaluate::<NistP521>(&p521_voprf_tvs)?;
|
||||||
|
|
||||||
|
let p521_poprf_tvs =
|
||||||
|
json_to_test_vectors!(rfc, String::from("P521-SHA512"), String::from("POPRF"));
|
||||||
|
assert_ne!(p521_poprf_tvs.len(), 0);
|
||||||
|
test_poprf_seed_to_key::<NistP521>(&p521_poprf_tvs)?;
|
||||||
|
test_poprf_blind::<NistP521>(&p521_poprf_tvs)?;
|
||||||
|
test_poprf_blind_evaluate::<NistP521>(&p521_poprf_tvs)?;
|
||||||
|
test_poprf_finalize::<NistP521>(&p521_poprf_tvs)?;
|
||||||
|
test_poprf_evaluate::<NistP521>(&p521_poprf_tvs)?;
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
fn test_oprf_seed_to_key<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_oprf_seed_to_key<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
let server = OprfServer::<CS>::new_from_seed(¶meters.seed, ¶meters.key_info)?;
|
let server = OprfServer::<CS>::new_from_seed(¶meters.seed, ¶meters.key_info)?;
|
||||||
|
|
||||||
@@ -207,11 +226,7 @@ where
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
fn test_voprf_seed_to_key<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_voprf_seed_to_key<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
let server = VoprfServer::<CS>::new_from_seed(¶meters.seed, ¶meters.key_info)?;
|
let server = VoprfServer::<CS>::new_from_seed(¶meters.seed, ¶meters.key_info)?;
|
||||||
|
|
||||||
@@ -227,11 +242,7 @@ where
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
fn test_poprf_seed_to_key<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_poprf_seed_to_key<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
let server = PoprfServer::<CS>::new_from_seed(¶meters.seed, ¶meters.key_info)?;
|
let server = PoprfServer::<CS>::new_from_seed(¶meters.seed, ¶meters.key_info)?;
|
||||||
|
|
||||||
@@ -248,11 +259,7 @@ where
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Tests input -> blind, blinded_element
|
// Tests input -> blind, blinded_element
|
||||||
fn test_oprf_blind<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_oprf_blind<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
for i in 0..parameters.input.len() {
|
for i in 0..parameters.input.len() {
|
||||||
let blind = CS::Group::deserialize_scalar(¶meters.blind[i])?;
|
let blind = CS::Group::deserialize_scalar(¶meters.blind[i])?;
|
||||||
@@ -273,11 +280,7 @@ where
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Tests input -> blind, blinded_element
|
// Tests input -> blind, blinded_element
|
||||||
fn test_voprf_blind<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_voprf_blind<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
for i in 0..parameters.input.len() {
|
for i in 0..parameters.input.len() {
|
||||||
let blind = CS::Group::deserialize_scalar(¶meters.blind[i])?;
|
let blind = CS::Group::deserialize_scalar(¶meters.blind[i])?;
|
||||||
@@ -298,11 +301,7 @@ where
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Tests input -> blind, blinded_element
|
// Tests input -> blind, blinded_element
|
||||||
fn test_poprf_blind<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_poprf_blind<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
for i in 0..parameters.input.len() {
|
for i in 0..parameters.input.len() {
|
||||||
let blind = CS::Group::deserialize_scalar(¶meters.blind[i])?;
|
let blind = CS::Group::deserialize_scalar(¶meters.blind[i])?;
|
||||||
@@ -323,11 +322,7 @@ where
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Tests sksm, blinded_element -> evaluation_element
|
// Tests sksm, blinded_element -> evaluation_element
|
||||||
fn test_oprf_blind_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_oprf_blind_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
for i in 0..parameters.input.len() {
|
for i in 0..parameters.input.len() {
|
||||||
let server = OprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
let server = OprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
||||||
@@ -344,13 +339,7 @@ where
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
fn test_voprf_blind_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_voprf_blind_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ScalarLen>,
|
|
||||||
Sum<<CS::Group as Group>::ScalarLen, <CS::Group as Group>::ScalarLen>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
let mut rng = CycleRng::new(parameters.proof_random_scalar.clone());
|
let mut rng = CycleRng::new(parameters.proof_random_scalar.clone());
|
||||||
let server = VoprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
let server = VoprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
||||||
@@ -376,13 +365,7 @@ where
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
fn test_poprf_blind_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_poprf_blind_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ScalarLen>,
|
|
||||||
Sum<<CS::Group as Group>::ScalarLen, <CS::Group as Group>::ScalarLen>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
let mut rng = CycleRng::new(parameters.proof_random_scalar.clone());
|
let mut rng = CycleRng::new(parameters.proof_random_scalar.clone());
|
||||||
let server = PoprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
let server = PoprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
||||||
@@ -418,11 +401,7 @@ where
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Tests input, blind, evaluation_element -> output
|
// Tests input, blind, evaluation_element -> output
|
||||||
fn test_oprf_finalize<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_oprf_finalize<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
for i in 0..parameters.input.len() {
|
for i in 0..parameters.input.len() {
|
||||||
let client =
|
let client =
|
||||||
@@ -439,11 +418,7 @@ where
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
fn test_voprf_finalize<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_voprf_finalize<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
let mut clients = vec![];
|
let mut clients = vec![];
|
||||||
for i in 0..parameters.input.len() {
|
for i in 0..parameters.input.len() {
|
||||||
@@ -478,11 +453,7 @@ where
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
fn test_poprf_finalize<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_poprf_finalize<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
let mut clients = vec![];
|
let mut clients = vec![];
|
||||||
for i in 0..parameters.input.len() {
|
for i in 0..parameters.input.len() {
|
||||||
@@ -516,11 +487,7 @@ where
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Tests input, sksm -> output
|
// Tests input, sksm -> output
|
||||||
fn test_oprf_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_oprf_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
for i in 0..parameters.input.len() {
|
for i in 0..parameters.input.len() {
|
||||||
let server = OprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
let server = OprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
||||||
@@ -533,11 +500,7 @@ where
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
fn test_voprf_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_voprf_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
for i in 0..parameters.input.len() {
|
for i in 0..parameters.input.len() {
|
||||||
let server = VoprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
let server = VoprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
||||||
@@ -550,11 +513,7 @@ where
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
fn test_poprf_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()>
|
fn test_poprf_evaluate<CS: CipherSuite>(tvs: &[VOPRFTestVectorParameters]) -> Result<()> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
for parameters in tvs {
|
for parameters in tvs {
|
||||||
for i in 0..parameters.input.len() {
|
for i in 0..parameters.input.len() {
|
||||||
let server = PoprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
let server = PoprfServer::<CS>::new_with_key(¶meters.sksm)?;
|
||||||
|
|||||||
+33
-101
@@ -13,9 +13,8 @@ use alloc::vec::Vec;
|
|||||||
use core::iter::{self, Map, Repeat, Zip};
|
use core::iter::{self, Map, Repeat, Zip};
|
||||||
|
|
||||||
use derive_where::derive_where;
|
use derive_where::derive_where;
|
||||||
use digest::core_api::BlockSizeUser;
|
use digest::{Digest, Output};
|
||||||
use digest::{Digest, Output, OutputSizeUser};
|
use generic_array::typenum::Unsigned;
|
||||||
use generic_array::typenum::{IsLess, IsLessOrEqual, Unsigned, U256};
|
|
||||||
use generic_array::GenericArray;
|
use generic_array::GenericArray;
|
||||||
use rand_core::{CryptoRng, RngCore};
|
use rand_core::{CryptoRng, RngCore};
|
||||||
|
|
||||||
@@ -42,11 +41,7 @@ use crate::{CipherSuite, Error, Group, Result};
|
|||||||
derive(serde::Deserialize, serde::Serialize),
|
derive(serde::Deserialize, serde::Serialize),
|
||||||
serde(bound = "")
|
serde(bound = "")
|
||||||
)]
|
)]
|
||||||
pub struct VoprfClient<CS: CipherSuite>
|
pub struct VoprfClient<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
||||||
pub(crate) blind: <CS::Group as Group>::Scalar,
|
pub(crate) blind: <CS::Group as Group>::Scalar,
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
||||||
@@ -62,11 +57,7 @@ where
|
|||||||
derive(serde::Deserialize, serde::Serialize),
|
derive(serde::Deserialize, serde::Serialize),
|
||||||
serde(bound = "")
|
serde(bound = "")
|
||||||
)]
|
)]
|
||||||
pub struct VoprfServer<CS: CipherSuite>
|
pub struct VoprfServer<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Scalar::<CS::Group>"))]
|
||||||
pub(crate) sk: <CS::Group as Group>::Scalar,
|
pub(crate) sk: <CS::Group as Group>::Scalar,
|
||||||
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
#[cfg_attr(feature = "serde", serde(with = "Element::<CS::Group>"))]
|
||||||
@@ -78,11 +69,7 @@ where
|
|||||||
// =================== //
|
// =================== //
|
||||||
/////////////////////////
|
/////////////////////////
|
||||||
|
|
||||||
impl<CS: CipherSuite> VoprfClient<CS>
|
impl<CS: CipherSuite> VoprfClient<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Computes the first step for the multiplicative blinding version of
|
/// Computes the first step for the multiplicative blinding version of
|
||||||
/// DH-OPRF.
|
/// DH-OPRF.
|
||||||
///
|
///
|
||||||
@@ -161,7 +148,7 @@ where
|
|||||||
///
|
///
|
||||||
/// The resulting messages can each fail individually with [`Error::Input`]
|
/// The resulting messages can each fail individually with [`Error::Input`]
|
||||||
/// if the `input` is empty or longer then [`u16::MAX`].
|
/// if the `input` is empty or longer then [`u16::MAX`].
|
||||||
pub fn batch_finalize<'a, I: 'a, II, IC, IM>(
|
pub fn batch_finalize<'a, I, II, IC, IM>(
|
||||||
inputs: &'a II,
|
inputs: &'a II,
|
||||||
clients: &'a IC,
|
clients: &'a IC,
|
||||||
messages: &'a IM,
|
messages: &'a IM,
|
||||||
@@ -170,7 +157,7 @@ where
|
|||||||
) -> Result<VoprfClientBatchFinalizeResult<'a, CS, I, II, IC, IM>>
|
) -> Result<VoprfClientBatchFinalizeResult<'a, CS, I, II, IC, IM>>
|
||||||
where
|
where
|
||||||
CS: 'a,
|
CS: 'a,
|
||||||
I: AsRef<[u8]>,
|
I: 'a + AsRef<[u8]>,
|
||||||
&'a II: 'a + IntoIterator<Item = I>,
|
&'a II: 'a + IntoIterator<Item = I>,
|
||||||
<&'a II as IntoIterator>::IntoIter: ExactSizeIterator,
|
<&'a II as IntoIterator>::IntoIter: ExactSizeIterator,
|
||||||
&'a IC: 'a + IntoIterator<Item = &'a VoprfClient<CS>>,
|
&'a IC: 'a + IntoIterator<Item = &'a VoprfClient<CS>>,
|
||||||
@@ -197,18 +184,14 @@ where
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Only used for test functions
|
/// Only used for test functions
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
pub fn get_blind(&self) -> <CS::Group as Group>::Scalar {
|
pub fn get_blind(&self) -> <CS::Group as Group>::Scalar {
|
||||||
self.blind
|
self.blind
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<CS: CipherSuite> VoprfServer<CS>
|
impl<CS: CipherSuite> VoprfServer<CS> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// Produces a new instance of a [VoprfServer] using a supplied RNG
|
/// Produces a new instance of a [VoprfServer] using a supplied RNG
|
||||||
///
|
///
|
||||||
/// # Errors
|
/// # Errors
|
||||||
@@ -246,7 +229,7 @@ where
|
|||||||
Ok(Self { sk, pk })
|
Ok(Self { sk, pk })
|
||||||
}
|
}
|
||||||
|
|
||||||
// Only used for tests
|
/// Only used for tests
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
pub fn get_private_key(&self) -> <CS::Group as Group>::Scalar {
|
pub fn get_private_key(&self) -> <CS::Group as Group>::Scalar {
|
||||||
self.sk
|
self.sk
|
||||||
@@ -402,11 +385,7 @@ where
|
|||||||
|
|
||||||
/// Contains the fields that are returned by a verifiable client blind
|
/// Contains the fields that are returned by a verifiable client blind
|
||||||
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
||||||
pub struct VoprfClientBlindResult<CS: CipherSuite>
|
pub struct VoprfClientBlindResult<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// The state to be persisted on the client
|
/// The state to be persisted on the client
|
||||||
pub state: VoprfClient<CS>,
|
pub state: VoprfClient<CS>,
|
||||||
/// The message to send to the server
|
/// The message to send to the server
|
||||||
@@ -423,11 +402,7 @@ pub type VoprfClientBatchFinalizeResult<'a, C, I, II, IC, IM> = FinalizeAfterUnb
|
|||||||
|
|
||||||
/// Contains the fields that are returned by a verifiable server evaluate
|
/// Contains the fields that are returned by a verifiable server evaluate
|
||||||
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
||||||
pub struct VoprfServerEvaluateResult<CS: CipherSuite>
|
pub struct VoprfServerEvaluateResult<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// The message to send to the client
|
/// The message to send to the client
|
||||||
pub message: EvaluationElement<CS>,
|
pub message: EvaluationElement<CS>,
|
||||||
/// The proof for the client to verify
|
/// The proof for the client to verify
|
||||||
@@ -437,11 +412,7 @@ where
|
|||||||
/// Contains the fields that are returned by a verifiable server batch evaluate
|
/// Contains the fields that are returned by a verifiable server batch evaluate
|
||||||
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
#[derive_where(Debug; <CS::Group as Group>::Scalar, <CS::Group as Group>::Elem)]
|
||||||
#[cfg(feature = "alloc")]
|
#[cfg(feature = "alloc")]
|
||||||
pub struct VoprfServerBatchEvaluateResult<CS: CipherSuite>
|
pub struct VoprfServerBatchEvaluateResult<CS: CipherSuite> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
/// The messages to send to the client
|
/// The messages to send to the client
|
||||||
pub messages: Vec<EvaluationElement<CS>>,
|
pub messages: Vec<EvaluationElement<CS>>,
|
||||||
/// The proof for the client to verify
|
/// The proof for the client to verify
|
||||||
@@ -472,8 +443,6 @@ pub type VoprfServerBatchEvaluateFinishedMessages<'a, CS, I> = Map<
|
|||||||
#[derive_where(Debug; <&'a I as IntoIterator>::IntoIter, <CS::Group as Group>::Scalar)]
|
#[derive_where(Debug; <&'a I as IntoIterator>::IntoIter, <CS::Group as Group>::Scalar)]
|
||||||
pub struct VoprfServerBatchEvaluateFinishResult<'a, CS: 'a + CipherSuite, I>
|
pub struct VoprfServerBatchEvaluateFinishResult<'a, CS: 'a + CipherSuite, I>
|
||||||
where
|
where
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
&'a I: IntoIterator<Item = &'a PreparedEvaluationElement<CS>>,
|
&'a I: IntoIterator<Item = &'a PreparedEvaluationElement<CS>>,
|
||||||
{
|
{
|
||||||
/// The [`EvaluationElement`]s to send to the client
|
/// The [`EvaluationElement`]s to send to the client
|
||||||
@@ -511,8 +480,6 @@ fn verifiable_unblind<'a, CS: 'a + CipherSuite, IC, IM>(
|
|||||||
proof: &Proof<CS>,
|
proof: &Proof<CS>,
|
||||||
) -> Result<VoprfUnblindResult<'a, CS, IC, IM>>
|
) -> Result<VoprfUnblindResult<'a, CS, IC, IM>>
|
||||||
where
|
where
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
&'a IC: 'a + IntoIterator<Item = &'a VoprfClient<CS>>,
|
&'a IC: 'a + IntoIterator<Item = &'a VoprfClient<CS>>,
|
||||||
<&'a IC as IntoIterator>::IntoIter: ExactSizeIterator,
|
<&'a IC as IntoIterator>::IntoIter: ExactSizeIterator,
|
||||||
&'a IM: 'a + IntoIterator<Item = &'a EvaluationElement<CS>>,
|
&'a IM: 'a + IntoIterator<Item = &'a EvaluationElement<CS>>,
|
||||||
@@ -537,7 +504,7 @@ where
|
|||||||
)?;
|
)?;
|
||||||
|
|
||||||
Ok(blinds
|
Ok(blinds
|
||||||
.zip(messages.into_iter())
|
.zip(messages)
|
||||||
.map(|(blind, x)| x.0 * &CS::Group::invert_scalar(blind)))
|
.map(|(blind, x)| x.0 * &CS::Group::invert_scalar(blind)))
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -554,11 +521,7 @@ fn finalize_after_unblind<
|
|||||||
IE: 'a + Iterator<Item = (I, <CS::Group as Group>::Elem)>,
|
IE: 'a + Iterator<Item = (I, <CS::Group as Group>::Elem)>,
|
||||||
>(
|
>(
|
||||||
inputs_and_unblinded_elements: IE,
|
inputs_and_unblinded_elements: IE,
|
||||||
) -> FinalizeAfterUnblindResult<'a, CS, I, IE>
|
) -> FinalizeAfterUnblindResult<'a, CS, I, IE> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
inputs_and_unblinded_elements.map(|(input, unblinded_element)| {
|
inputs_and_unblinded_elements.map(|(input, unblinded_element)| {
|
||||||
let elem_len = <CS::Group as Group>::ElemLen::U16.to_be_bytes();
|
let elem_len = <CS::Group as Group>::ElemLen::U16.to_be_bytes();
|
||||||
|
|
||||||
@@ -583,13 +546,10 @@ where
|
|||||||
|
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
mod tests {
|
mod tests {
|
||||||
use core::ops::Add;
|
|
||||||
use core::ptr;
|
use core::ptr;
|
||||||
|
|
||||||
use ::alloc::vec;
|
use ::alloc::vec;
|
||||||
use ::alloc::vec::Vec;
|
use ::alloc::vec::Vec;
|
||||||
use generic_array::typenum::Sum;
|
|
||||||
use generic_array::ArrayLength;
|
|
||||||
use rand::rngs::OsRng;
|
use rand::rngs::OsRng;
|
||||||
|
|
||||||
use super::*;
|
use super::*;
|
||||||
@@ -600,11 +560,7 @@ mod tests {
|
|||||||
input: &[u8],
|
input: &[u8],
|
||||||
key: <CS::Group as Group>::Scalar,
|
key: <CS::Group as Group>::Scalar,
|
||||||
mode: Mode,
|
mode: Mode,
|
||||||
) -> Output<CS::Hash>
|
) -> Output<CS::Hash> {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let dst = Dst::new::<CS, _, _>(STR_HASH_TO_GROUP, mode);
|
let dst = Dst::new::<CS, _, _>(STR_HASH_TO_GROUP, mode);
|
||||||
let point = CS::Group::hash_to_curve::<CS::Hash>(&[input], &dst.as_dst()).unwrap();
|
let point = CS::Group::hash_to_curve::<CS::Hash>(&[input], &dst.as_dst()).unwrap();
|
||||||
|
|
||||||
@@ -616,11 +572,7 @@ mod tests {
|
|||||||
.unwrap()
|
.unwrap()
|
||||||
}
|
}
|
||||||
|
|
||||||
fn verifiable_retrieval<CS: CipherSuite>()
|
fn verifiable_retrieval<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let client_blind_result = VoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
let client_blind_result = VoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
||||||
@@ -639,11 +591,7 @@ mod tests {
|
|||||||
assert_eq!(client_finalize_result, res2);
|
assert_eq!(client_finalize_result, res2);
|
||||||
}
|
}
|
||||||
|
|
||||||
fn verifiable_batch_retrieval<CS: CipherSuite>()
|
fn verifiable_batch_retrieval<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let mut inputs = vec![];
|
let mut inputs = vec![];
|
||||||
let mut client_states = vec![];
|
let mut client_states = vec![];
|
||||||
@@ -687,11 +635,7 @@ mod tests {
|
|||||||
assert_eq!(client_finalize_result, res2);
|
assert_eq!(client_finalize_result, res2);
|
||||||
}
|
}
|
||||||
|
|
||||||
fn verifiable_batch_bad_public_key<CS: CipherSuite>()
|
fn verifiable_batch_bad_public_key<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let mut inputs = vec![];
|
let mut inputs = vec![];
|
||||||
let mut client_states = vec![];
|
let mut client_states = vec![];
|
||||||
@@ -727,11 +671,7 @@ mod tests {
|
|||||||
assert!(client_finalize_result.is_err());
|
assert!(client_finalize_result.is_err());
|
||||||
}
|
}
|
||||||
|
|
||||||
fn verifiable_bad_public_key<CS: CipherSuite>()
|
fn verifiable_bad_public_key<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let client_blind_result = VoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
let client_blind_result = VoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
||||||
@@ -751,11 +691,7 @@ mod tests {
|
|||||||
assert!(client_finalize_result.is_err());
|
assert!(client_finalize_result.is_err());
|
||||||
}
|
}
|
||||||
|
|
||||||
fn verifiable_server_evaluate<CS: CipherSuite>()
|
fn verifiable_server_evaluate<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let client_blind_result = VoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
let client_blind_result = VoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
||||||
@@ -784,13 +720,7 @@ mod tests {
|
|||||||
assert!(client_finalize != server_evaluate);
|
assert!(client_finalize != server_evaluate);
|
||||||
}
|
}
|
||||||
|
|
||||||
fn zeroize_voprf_client<CS: CipherSuite>()
|
fn zeroize_voprf_client<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ElemLen>,
|
|
||||||
Sum<<CS::Group as Group>::ScalarLen, <CS::Group as Group>::ElemLen>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let client_blind_result = VoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
let client_blind_result = VoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
||||||
@@ -804,15 +734,7 @@ mod tests {
|
|||||||
assert!(message.serialize().iter().all(|&x| x == 0));
|
assert!(message.serialize().iter().all(|&x| x == 0));
|
||||||
}
|
}
|
||||||
|
|
||||||
fn zeroize_voprf_server<CS: CipherSuite>()
|
fn zeroize_voprf_server<CS: CipherSuite>() {
|
||||||
where
|
|
||||||
<CS::Hash as OutputSizeUser>::OutputSize:
|
|
||||||
IsLess<U256> + IsLessOrEqual<<CS::Hash as BlockSizeUser>::BlockSize>,
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ElemLen>,
|
|
||||||
Sum<<CS::Group as Group>::ScalarLen, <CS::Group as Group>::ElemLen>: ArrayLength<u8>,
|
|
||||||
<CS::Group as Group>::ScalarLen: Add<<CS::Group as Group>::ScalarLen>,
|
|
||||||
Sum<<CS::Group as Group>::ScalarLen, <CS::Group as Group>::ScalarLen>: ArrayLength<u8>,
|
|
||||||
{
|
|
||||||
let input = b"input";
|
let input = b"input";
|
||||||
let mut rng = OsRng;
|
let mut rng = OsRng;
|
||||||
let client_blind_result = VoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
let client_blind_result = VoprfClient::<CS>::blind(input, &mut rng).unwrap();
|
||||||
@@ -836,6 +758,7 @@ mod tests {
|
|||||||
fn test_functionality() -> Result<()> {
|
fn test_functionality() -> Result<()> {
|
||||||
use p256::NistP256;
|
use p256::NistP256;
|
||||||
use p384::NistP384;
|
use p384::NistP384;
|
||||||
|
use p521::NistP521;
|
||||||
|
|
||||||
#[cfg(feature = "ristretto255")]
|
#[cfg(feature = "ristretto255")]
|
||||||
{
|
{
|
||||||
@@ -869,6 +792,15 @@ mod tests {
|
|||||||
zeroize_voprf_client::<NistP384>();
|
zeroize_voprf_client::<NistP384>();
|
||||||
zeroize_voprf_server::<NistP384>();
|
zeroize_voprf_server::<NistP384>();
|
||||||
|
|
||||||
|
verifiable_retrieval::<NistP521>();
|
||||||
|
verifiable_batch_retrieval::<NistP521>();
|
||||||
|
verifiable_bad_public_key::<NistP521>();
|
||||||
|
verifiable_batch_bad_public_key::<NistP521>();
|
||||||
|
verifiable_server_evaluate::<NistP521>();
|
||||||
|
|
||||||
|
zeroize_voprf_client::<NistP521>();
|
||||||
|
zeroize_voprf_server::<NistP521>();
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user