mirror of
https://github.com/sonr-io/sonr.git
synced 2026-08-04 10:21:40 +00:00
(no commit message provided)
This commit is contained in:
committed by
Prad Nukala (aider)
parent
5fd43dfd6b
commit
2f976209db
@@ -1,83 +0,0 @@
|
||||
//
|
||||
// Copyright Coinbase, Inc. All Rights Reserved.
|
||||
//
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
//
|
||||
|
||||
// Package dealer implements key generation via a trusted dealer for the protocol [DKLs18](https://eprint.iacr.org/2018/499.pdf).
|
||||
// The trusted dealer produces the same output as the corresponding DKG protocol and can be used for signing without
|
||||
// additional modifications.
|
||||
// Note that running actual DKG is ALWAYS recommended over a trusted dealer.
|
||||
package dealer
|
||||
|
||||
import (
|
||||
"crypto/rand"
|
||||
|
||||
"github.com/pkg/errors"
|
||||
|
||||
"github.com/onsonr/hway/crypto/core/curves"
|
||||
"github.com/onsonr/hway/crypto/ot/base/simplest"
|
||||
"github.com/onsonr/hway/crypto/ot/extension/kos"
|
||||
"github.com/onsonr/hway/crypto/tecdsa/dklsv1/dkg"
|
||||
)
|
||||
|
||||
// GenerationAndDeal produces private key material for alice and bob which they can later use in signing.
|
||||
// Running actual DKG is ALWAYS recommended over using this function, as this function breaks the security guarantees of DKG.
|
||||
// only use this function if you have a very good reason to.
|
||||
func GenerateAndDeal(curve *curves.Curve) (*dkg.AliceOutput, *dkg.BobOutput, error) {
|
||||
aliceSecretShare, bobSecretShare, publicKey := produceKeyShares(curve)
|
||||
aliceOTOutput, bobOTOutput, err := produceOTResults(curve)
|
||||
if err != nil {
|
||||
return nil, nil, errors.Wrap(err, "couldn't produce OT results")
|
||||
}
|
||||
alice := &dkg.AliceOutput{
|
||||
PublicKey: publicKey,
|
||||
SecretKeyShare: aliceSecretShare,
|
||||
SeedOtResult: aliceOTOutput,
|
||||
}
|
||||
bob := &dkg.BobOutput{
|
||||
PublicKey: publicKey,
|
||||
SecretKeyShare: bobSecretShare,
|
||||
SeedOtResult: bobOTOutput,
|
||||
}
|
||||
return alice, bob, nil
|
||||
}
|
||||
|
||||
func produceKeyShares(curve *curves.Curve) (aliceSecretShare curves.Scalar, bobSecretShare curves.Scalar, publicKey curves.Point) {
|
||||
aliceSecretShare = curve.Scalar.Random(rand.Reader)
|
||||
bobSecretShare = curve.Scalar.Random(rand.Reader)
|
||||
publicKey = curve.ScalarBaseMult(aliceSecretShare.Mul(bobSecretShare))
|
||||
return aliceSecretShare, bobSecretShare, publicKey
|
||||
}
|
||||
|
||||
func produceOTResults(curve *curves.Curve) (*simplest.ReceiverOutput, *simplest.SenderOutput, error) {
|
||||
oneTimePadEncryptionKeys := make([]simplest.OneTimePadEncryptionKeys, kos.Kappa)
|
||||
oneTimePadDecryptionKey := make([]simplest.OneTimePadDecryptionKey, kos.Kappa)
|
||||
|
||||
// we'll need a receiver because in its constructor random bits will be selected.
|
||||
receiver, err := simplest.NewReceiver(curve, kos.Kappa, [simplest.DigestSize]byte{})
|
||||
if err != nil {
|
||||
return nil, nil, errors.Wrap(err, "couldn't initialize a receiver")
|
||||
}
|
||||
packedRandomChoiceBits, randomChoiceBits := receiver.Output.PackedRandomChoiceBits, receiver.Output.RandomChoiceBits
|
||||
|
||||
for i := 0; i < kos.Kappa; i++ {
|
||||
if _, err := rand.Read(oneTimePadEncryptionKeys[i][0][:]); err != nil {
|
||||
return nil, nil, errors.WithStack(err)
|
||||
}
|
||||
if _, err := rand.Read(oneTimePadEncryptionKeys[i][1][:]); err != nil {
|
||||
return nil, nil, errors.WithStack(err)
|
||||
}
|
||||
oneTimePadDecryptionKey[i] = oneTimePadEncryptionKeys[i][randomChoiceBits[i]]
|
||||
}
|
||||
|
||||
senderOutput := &simplest.SenderOutput{
|
||||
OneTimePadEncryptionKeys: oneTimePadEncryptionKeys,
|
||||
}
|
||||
receiverOutput := &simplest.ReceiverOutput{
|
||||
PackedRandomChoiceBits: packedRandomChoiceBits,
|
||||
RandomChoiceBits: randomChoiceBits,
|
||||
OneTimePadDecryptionKey: oneTimePadDecryptionKey,
|
||||
}
|
||||
return receiverOutput, senderOutput, nil
|
||||
}
|
||||
@@ -1,49 +0,0 @@
|
||||
package dealer_test
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/require"
|
||||
"golang.org/x/crypto/sha3"
|
||||
|
||||
"github.com/onsonr/hway/crypto/core/curves"
|
||||
"github.com/onsonr/hway/crypto/tecdsa/dklsv1/dealer"
|
||||
"github.com/onsonr/hway/crypto/tecdsa/dklsv1/sign"
|
||||
)
|
||||
|
||||
func Test_DealerCanGenerateKeysThatSign(t *testing.T) {
|
||||
curveInstances := []*curves.Curve{
|
||||
curves.K256(),
|
||||
curves.P256(),
|
||||
}
|
||||
for _, curve := range curveInstances {
|
||||
aliceOutput, bobOutput, err := dealer.GenerateAndDeal(curve)
|
||||
require.NoError(t, err)
|
||||
|
||||
alice := sign.NewAlice(curve, sha3.New256(), aliceOutput)
|
||||
bob := sign.NewBob(curve, sha3.New256(), bobOutput)
|
||||
|
||||
message := []byte("A message.")
|
||||
seed, err := alice.Round1GenerateRandomSeed()
|
||||
require.NoError(t, err)
|
||||
round3Output, err := bob.Round2Initialize(seed)
|
||||
require.NoError(t, err)
|
||||
round4Output, err := alice.Round3Sign(message, round3Output)
|
||||
require.NoError(t, err)
|
||||
err = bob.Round4Final(message, round4Output)
|
||||
require.NoError(t, err, "curve: %s", curve.Name)
|
||||
}
|
||||
}
|
||||
|
||||
func Test_DealerGeneratesDifferentResultsEachTime(t *testing.T) {
|
||||
curve := curves.K256()
|
||||
aliceOutput1, bobOutput1, err := dealer.GenerateAndDeal(curve)
|
||||
require.NoError(t, err)
|
||||
aliceOutput2, bobOutput2, err := dealer.GenerateAndDeal(curve)
|
||||
require.NoError(t, err)
|
||||
|
||||
require.NotEqual(t, aliceOutput1.SecretKeyShare, aliceOutput2.SecretKeyShare)
|
||||
require.NotEqual(t, bobOutput1.SecretKeyShare, bobOutput2.SecretKeyShare)
|
||||
require.NotEqualValues(t, aliceOutput1.SeedOtResult.RandomChoiceBits, aliceOutput2.SeedOtResult.RandomChoiceBits)
|
||||
require.NotEqualValues(t, bobOutput1.SeedOtResult.OneTimePadEncryptionKeys, bobOutput2.SeedOtResult.OneTimePadEncryptionKeys)
|
||||
}
|
||||
Reference in New Issue
Block a user