mirror of
https://github.com/sonr-io/sonr.git
synced 2026-08-02 17:31:39 +00:00
feature/1121 implement ucan validation (#1176)
- **refactor: remove unused auth components** - **refactor: improve devbox configuration and deployment process** - **refactor: improve devnet and testnet setup** - **fix: update templ version to v0.2.778** - **refactor: rename pkl/net.matrix to pkl/matrix.net** - **refactor: migrate webapp components to nebula** - **refactor: protobuf types** - **chore: update dependencies for improved security and stability** - **feat: implement landing page and vault gateway servers** - **refactor: Migrate data models to new module structure and update related files** - **feature/1121-implement-ucan-validation** - **refactor: Replace hardcoded constants with model types in attns.go** - **feature/1121-implement-ucan-validation** - **chore: add origin Host struct and update main function to handle multiple hosts** - **build: remove unused static files from dwn module** - **build: remove unused static files from dwn module** - **refactor: Move DWN models to common package** - **refactor: move models to pkg/common** - **refactor: move vault web app assets to embed module** - **refactor: update session middleware import path** - **chore: configure port labels and auto-forwarding behavior** - **feat: enhance devcontainer configuration** - **feat: Add UCAN middleware for Echo with flexible token validation** - **feat: add JWT middleware for UCAN authentication** - **refactor: update package URI and versioning in PklProject files** - **fix: correct sonr.pkl import path** - **refactor: move JWT related code to auth package** - **feat: introduce vault configuration retrieval and management** - **refactor: Move vault components to gateway module and update file paths** - **refactor: remove Dexie and SQLite database implementations** - **feat: enhance frontend with PWA features and WASM integration** - **feat: add Devbox features and streamline Dockerfile** - **chore: update dependencies to include TigerBeetle** - **chore(deps): update go version to 1.23** - **feat: enhance devnet setup with PATH environment variable and updated PWA manifest** - **fix: upgrade tigerbeetle-go dependency and remove indirect dependency** - **feat: add PostgreSQL support to devnet and testnet deployments** - **refactor: rename keyshare cookie to token cookie** - **feat: upgrade Go version to 1.23.3 and update dependencies** - **refactor: update devnet and testnet configurations** - **feat: add IPFS configuration for devnet** - **I'll help you update the ipfs.config.pkl to include all the peers from the shell script. Here's the updated configuration:** - **refactor: move mpc package to crypto directory** - **feat: add BIP32 support for various cryptocurrencies** - **feat: enhance ATN.pkl with additional capabilities** - **refactor: simplify smart account and vault attenuation creation** - **feat: add new capabilities to the Attenuation type** - **refactor: Rename MPC files for clarity and consistency** - **feat: add DIDKey support for cryptographic operations** - **feat: add devnet and testnet deployment configurations** - **fix: correct key derivation in bip32 package** - **refactor: rename crypto/bip32 package to crypto/accaddr** - **fix: remove duplicate indirect dependency** - **refactor: move vault package to root directory** - **refactor: update routes for gateway and vault** - **refactor: remove obsolete web configuration file** - **refactor: remove unused TigerBeetle imports and update host configuration** - **refactor: adjust styles directory path** - **feat: add broadcastTx and simulateTx functions to gateway** - **feat: add PinVault handler**
This commit is contained in:
Executable
+14
@@ -0,0 +1,14 @@
|
||||
//
|
||||
// Copyright Coinbase, Inc. All Rights Reserved.
|
||||
//
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
//
|
||||
|
||||
package common
|
||||
|
||||
import (
|
||||
"github.com/onsonr/sonr/crypto/core/curves"
|
||||
)
|
||||
|
||||
// Challenge generated by fiat-shamir heuristic
|
||||
type Challenge = curves.Scalar
|
||||
Executable
+15
@@ -0,0 +1,15 @@
|
||||
//
|
||||
// Copyright Coinbase, Inc. All Rights Reserved.
|
||||
//
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
//
|
||||
|
||||
package common
|
||||
|
||||
import (
|
||||
"github.com/onsonr/sonr/crypto/core/curves"
|
||||
)
|
||||
|
||||
// Commitment represents a point Pedersen commitment of one or more
|
||||
// points multiplied by scalars
|
||||
type Commitment = curves.Point
|
||||
Executable
+99
@@ -0,0 +1,99 @@
|
||||
//
|
||||
// Copyright Coinbase, Inc. All Rights Reserved.
|
||||
//
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
//
|
||||
|
||||
package common
|
||||
|
||||
import (
|
||||
"crypto/hmac"
|
||||
"hash"
|
||||
)
|
||||
|
||||
// HmacDrbg is an HMAC deterministic random bit generator
|
||||
// that can use any hash function. Handles reseeding
|
||||
// automatically
|
||||
type HmacDrbg struct {
|
||||
k, v []byte
|
||||
count int
|
||||
hasher func() hash.Hash
|
||||
}
|
||||
|
||||
func NewHmacDrbg(entropy, nonce, pers []byte, hasher func() hash.Hash) *HmacDrbg {
|
||||
drbg := new(HmacDrbg)
|
||||
h := hasher()
|
||||
drbg.k = make([]byte, h.Size())
|
||||
drbg.v = make([]byte, h.Size())
|
||||
drbg.count = 0
|
||||
drbg.hasher = hasher
|
||||
|
||||
for i := range drbg.v {
|
||||
drbg.v[i] = 1
|
||||
}
|
||||
|
||||
drbg.update([][]byte{entropy, nonce, pers})
|
||||
drbg.count += 1
|
||||
return drbg
|
||||
}
|
||||
|
||||
func (drbg *HmacDrbg) Read(dst []byte) (n int, err error) {
|
||||
toRead := len(dst)
|
||||
if toRead == 0 {
|
||||
return 0, nil
|
||||
}
|
||||
i := 0
|
||||
for i < toRead {
|
||||
vmac := drbg.getHmac()
|
||||
_, _ = vmac.Write(drbg.v)
|
||||
drbg.v = vmac.Sum(nil)
|
||||
|
||||
for j, b := range drbg.v {
|
||||
dst[i+j] = b
|
||||
}
|
||||
i += len(drbg.v)
|
||||
}
|
||||
drbg.update(nil)
|
||||
drbg.count++
|
||||
return i, nil
|
||||
}
|
||||
|
||||
func (drbg *HmacDrbg) Reseed(entropy []byte) {
|
||||
drbg.update([][]byte{entropy})
|
||||
}
|
||||
|
||||
func (drbg *HmacDrbg) getHmac() hash.Hash {
|
||||
return hmac.New(drbg.hasher, drbg.k)
|
||||
}
|
||||
|
||||
func (drbg *HmacDrbg) update(seeds [][]byte) {
|
||||
kmac := drbg.getHmac()
|
||||
_, _ = kmac.Write(drbg.v)
|
||||
_, _ = kmac.Write([]byte{0})
|
||||
if len(seeds) > 0 {
|
||||
for _, seed := range seeds {
|
||||
_, _ = kmac.Write(seed)
|
||||
}
|
||||
}
|
||||
drbg.k = kmac.Sum(nil)
|
||||
|
||||
vmac := drbg.getHmac()
|
||||
_, _ = vmac.Write(drbg.v)
|
||||
drbg.v = vmac.Sum(nil)
|
||||
|
||||
if len(seeds) == 0 {
|
||||
return
|
||||
}
|
||||
|
||||
kmac = drbg.getHmac()
|
||||
_, _ = kmac.Write(drbg.v)
|
||||
_, _ = kmac.Write([]byte{1})
|
||||
for _, seed := range seeds {
|
||||
_, _ = kmac.Write(seed)
|
||||
}
|
||||
drbg.k = kmac.Sum(nil)
|
||||
|
||||
vmac = drbg.getHmac()
|
||||
_, _ = vmac.Write(drbg.v)
|
||||
drbg.v = vmac.Sum(nil)
|
||||
}
|
||||
Executable
+15
@@ -0,0 +1,15 @@
|
||||
//
|
||||
// Copyright Coinbase, Inc. All Rights Reserved.
|
||||
//
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
//
|
||||
|
||||
package common
|
||||
|
||||
import (
|
||||
"github.com/onsonr/sonr/crypto/core/curves"
|
||||
)
|
||||
|
||||
// Nonce is used for zero-knowledge proofs to prevent replay attacks
|
||||
// and prove freshness
|
||||
type Nonce = curves.Scalar
|
||||
+86
@@ -0,0 +1,86 @@
|
||||
//
|
||||
// Copyright Coinbase, Inc. All Rights Reserved.
|
||||
//
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
//
|
||||
|
||||
package common
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"io"
|
||||
|
||||
"github.com/onsonr/sonr/crypto/core/curves"
|
||||
)
|
||||
|
||||
const limit = 65535
|
||||
|
||||
// ProofCommittedBuilder is used to create
|
||||
// proofs from multiple commitments where
|
||||
// each secret is committed with a random blinding factor
|
||||
// and turned into a Schnorr proof
|
||||
type ProofCommittedBuilder struct {
|
||||
points []curves.Point
|
||||
scalars []curves.Scalar
|
||||
curve *curves.Curve
|
||||
}
|
||||
|
||||
// NewProofCommittedBuilder creates a new builder using the specified curve
|
||||
func NewProofCommittedBuilder(curve *curves.Curve) *ProofCommittedBuilder {
|
||||
return &ProofCommittedBuilder{
|
||||
points: []curves.Point{},
|
||||
scalars: []curves.Scalar{},
|
||||
curve: curve,
|
||||
}
|
||||
}
|
||||
|
||||
// CommitRandom uses the specified point and commits a random value to it
|
||||
func (pcb *ProofCommittedBuilder) CommitRandom(point curves.Point, reader io.Reader) error {
|
||||
if len(pcb.points) > limit {
|
||||
return fmt.Errorf("limit for commitments reached")
|
||||
}
|
||||
pcb.points = append(pcb.points, point)
|
||||
pcb.scalars = append(pcb.scalars, pcb.curve.Scalar.Random(reader))
|
||||
return nil
|
||||
}
|
||||
|
||||
// Commit uses the specified point and scalar to create a commitment
|
||||
func (pcb *ProofCommittedBuilder) Commit(point curves.Point, scalar curves.Scalar) error {
|
||||
if len(pcb.points) > limit {
|
||||
return fmt.Errorf("limit for commitments reached")
|
||||
}
|
||||
pcb.points = append(pcb.points, point)
|
||||
pcb.scalars = append(pcb.scalars, scalar)
|
||||
return nil
|
||||
}
|
||||
|
||||
// Get returns the point and scalar at the specified index
|
||||
func (pcb *ProofCommittedBuilder) Get(index int) (curves.Point, curves.Scalar) {
|
||||
if index >= len(pcb.points) || index < 0 {
|
||||
return nil, nil
|
||||
}
|
||||
return pcb.points[index], pcb.scalars[index]
|
||||
}
|
||||
|
||||
// GetChallengeContribution returns the bytes that should be added to
|
||||
// a sigma protocol transcript for generating the challenge
|
||||
func (pcb ProofCommittedBuilder) GetChallengeContribution() []byte {
|
||||
commitment := pcb.curve.Point.SumOfProducts(pcb.points, pcb.scalars)
|
||||
if commitment == nil {
|
||||
return nil
|
||||
}
|
||||
return commitment.ToAffineCompressed()
|
||||
}
|
||||
|
||||
// GenerateProof converts the blinding factors and secrets into Schnorr proofs
|
||||
func (pcb ProofCommittedBuilder) GenerateProof(challenge curves.Scalar, secrets []curves.Scalar) ([]curves.Scalar, error) {
|
||||
if len(secrets) != len(pcb.scalars) {
|
||||
return nil, fmt.Errorf("secrets is not equal to blinding factors")
|
||||
}
|
||||
|
||||
proofs := make([]curves.Scalar, len(pcb.scalars))
|
||||
for i, sc := range pcb.scalars {
|
||||
proofs[i] = secrets[i].MulAdd(challenge, sc)
|
||||
}
|
||||
return proofs, nil
|
||||
}
|
||||
Executable
+79
@@ -0,0 +1,79 @@
|
||||
//
|
||||
// Copyright Coinbase, Inc. All Rights Reserved.
|
||||
//
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
//
|
||||
|
||||
package common
|
||||
|
||||
import (
|
||||
"io"
|
||||
|
||||
"github.com/onsonr/sonr/crypto/core/curves"
|
||||
)
|
||||
|
||||
// ProofMessage classifies how a message is presented in a proof
|
||||
// Either Revealed or Hidden. Hidden has two sub categories:
|
||||
// proof specific i.e. the message is only used for this proof or
|
||||
// shared i.e. the message should be proved to be common across proofs
|
||||
type ProofMessage interface {
|
||||
// IsHidden indicates the message should be hidden
|
||||
IsHidden() bool
|
||||
// GetBlinding is used for hidden messages
|
||||
// blindings can either be proof specific to a signature
|
||||
// or involved with other proofs like boundchecks,
|
||||
// set memberships, or inequalities so the blinding
|
||||
// factor is shared among proofs to produce a common
|
||||
// schnorr linking proof
|
||||
GetBlinding(reader io.Reader) curves.Scalar
|
||||
// GetMessage returns the underlying message
|
||||
GetMessage() curves.Scalar
|
||||
}
|
||||
|
||||
type RevealedMessage struct {
|
||||
Message curves.Scalar
|
||||
}
|
||||
|
||||
func (r RevealedMessage) IsHidden() bool {
|
||||
return false
|
||||
}
|
||||
|
||||
func (r RevealedMessage) GetBlinding(reader io.Reader) curves.Scalar {
|
||||
return nil
|
||||
}
|
||||
|
||||
func (r RevealedMessage) GetMessage() curves.Scalar {
|
||||
return r.Message
|
||||
}
|
||||
|
||||
type ProofSpecificMessage struct {
|
||||
Message curves.Scalar
|
||||
}
|
||||
|
||||
func (ps ProofSpecificMessage) IsHidden() bool {
|
||||
return true
|
||||
}
|
||||
|
||||
func (ps ProofSpecificMessage) GetBlinding(reader io.Reader) curves.Scalar {
|
||||
return ps.Message.Random(reader)
|
||||
}
|
||||
|
||||
func (ps ProofSpecificMessage) GetMessage() curves.Scalar {
|
||||
return ps.Message
|
||||
}
|
||||
|
||||
type SharedBlindingMessage struct {
|
||||
Message, Blinding curves.Scalar
|
||||
}
|
||||
|
||||
func (ps SharedBlindingMessage) IsHidden() bool {
|
||||
return true
|
||||
}
|
||||
|
||||
func (ps SharedBlindingMessage) GetBlinding(reader io.Reader) curves.Scalar {
|
||||
return ps.Blinding
|
||||
}
|
||||
|
||||
func (ps SharedBlindingMessage) GetMessage() curves.Scalar {
|
||||
return ps.Message
|
||||
}
|
||||
+14
@@ -0,0 +1,14 @@
|
||||
//
|
||||
// Copyright Coinbase, Inc. All Rights Reserved.
|
||||
//
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
//
|
||||
|
||||
package common
|
||||
|
||||
import (
|
||||
"github.com/onsonr/sonr/crypto/core/curves"
|
||||
)
|
||||
|
||||
// SignatureBlinding is a value used for computing blind signatures
|
||||
type SignatureBlinding = curves.PairingScalar
|
||||
Reference in New Issue
Block a user