2022-09-29 08:47:55 +00:00
|
|
|
#![cfg_attr(docsrs, feature(doc_auto_cfg))]
|
2022-06-28 08:02:56 +00:00
|
|
|
#![no_std]
|
2022-05-03 11:20:24 +00:00
|
|
|
|
2022-06-28 08:02:56 +00:00
|
|
|
#[cfg(feature = "merlin")]
|
2022-05-03 11:20:24 +00:00
|
|
|
mod merlin;
|
2022-06-28 08:02:56 +00:00
|
|
|
#[cfg(feature = "merlin")]
|
|
|
|
pub use crate::merlin::MerlinTranscript;
|
2022-05-03 11:20:24 +00:00
|
|
|
|
2023-03-02 15:57:22 +00:00
|
|
|
use digest::{
|
|
|
|
typenum::{
|
|
|
|
consts::U32, marker_traits::NonZero, type_operators::IsGreaterOrEqual, operator_aliases::GrEq,
|
|
|
|
},
|
|
|
|
Digest, Output, HashMarker,
|
|
|
|
};
|
2022-05-03 11:20:24 +00:00
|
|
|
|
|
|
|
pub trait Transcript {
|
2022-06-28 08:02:56 +00:00
|
|
|
type Challenge: Clone + Send + Sync + AsRef<[u8]>;
|
|
|
|
|
2022-09-29 09:25:29 +00:00
|
|
|
/// Create a new transcript with the specified name.
|
2022-07-12 05:28:01 +00:00
|
|
|
fn new(name: &'static [u8]) -> Self;
|
|
|
|
|
2022-09-29 09:25:29 +00:00
|
|
|
/// Apply a domain separator to the transcript.
|
2022-06-03 05:37:12 +00:00
|
|
|
fn domain_separate(&mut self, label: &'static [u8]);
|
2022-07-09 04:37:39 +00:00
|
|
|
|
2022-09-29 09:25:29 +00:00
|
|
|
/// Append a message to the transcript.
|
2022-11-05 22:43:36 +00:00
|
|
|
fn append_message<M: AsRef<[u8]>>(&mut self, label: &'static [u8], message: M);
|
2022-07-09 04:37:39 +00:00
|
|
|
|
2023-03-02 16:19:26 +00:00
|
|
|
/// Produce a challenge.
|
|
|
|
///
|
|
|
|
/// Implementors MUST update the transcript as it does so, preventing the same challenge from
|
|
|
|
/// being generated multiple times.
|
2022-06-28 08:02:56 +00:00
|
|
|
fn challenge(&mut self, label: &'static [u8]) -> Self::Challenge;
|
2022-07-09 04:37:39 +00:00
|
|
|
|
2023-03-02 16:19:26 +00:00
|
|
|
/// Produce a RNG seed.
|
|
|
|
///
|
|
|
|
/// Helper function for parties needing to generate random data from an agreed upon state.
|
|
|
|
///
|
|
|
|
/// Implementors MAY internally call the challenge function for the needed bytes, and accordingly
|
|
|
|
/// produce a transcript conflict between two transcripts, one which called challenge(label) and
|
|
|
|
/// one which called rng_seed(label) at the same point.
|
2022-05-31 06:12:14 +00:00
|
|
|
fn rng_seed(&mut self, label: &'static [u8]) -> [u8; 32];
|
2022-05-03 11:20:24 +00:00
|
|
|
}
|
|
|
|
|
2022-06-24 12:42:38 +00:00
|
|
|
enum DigestTranscriptMember {
|
|
|
|
Name,
|
|
|
|
Domain,
|
|
|
|
Label,
|
|
|
|
Value,
|
2022-07-15 05:26:07 +00:00
|
|
|
Challenge,
|
2022-06-24 12:42:38 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
impl DigestTranscriptMember {
|
|
|
|
fn as_u8(&self) -> u8 {
|
|
|
|
match self {
|
|
|
|
DigestTranscriptMember::Name => 0,
|
|
|
|
DigestTranscriptMember::Domain => 1,
|
|
|
|
DigestTranscriptMember::Label => 2,
|
|
|
|
DigestTranscriptMember::Value => 3,
|
2022-07-15 05:26:07 +00:00
|
|
|
DigestTranscriptMember::Challenge => 4,
|
2022-06-24 12:42:38 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-03-06 12:16:04 +00:00
|
|
|
/// A trait defining cryptographic Digests with at least a 256-bit output size, assuming at least a
|
|
|
|
/// 128-bit level of security accordingly.
|
2022-09-29 09:33:46 +00:00
|
|
|
pub trait SecureDigest: Digest + HashMarker {}
|
2023-03-02 15:57:22 +00:00
|
|
|
impl<D: Digest + HashMarker> SecureDigest for D
|
|
|
|
where
|
|
|
|
// This just lets us perform the comparison
|
|
|
|
D::OutputSize: IsGreaterOrEqual<U32>,
|
|
|
|
// Perform the comparison and make sure it's true (not zero), meaning D::OutputSize is >= U32
|
|
|
|
// This should be U32 as it's length in bytes, not bits
|
|
|
|
GrEq<D::OutputSize, U32>: NonZero,
|
|
|
|
{
|
|
|
|
}
|
2022-06-28 08:02:56 +00:00
|
|
|
|
2022-09-29 09:25:29 +00:00
|
|
|
/// A simple transcript format constructed around the specified hash algorithm.
|
2022-05-03 11:20:24 +00:00
|
|
|
#[derive(Clone, Debug)]
|
2022-09-29 09:33:46 +00:00
|
|
|
pub struct DigestTranscript<D: Clone + SecureDigest>(D);
|
2022-05-03 11:20:24 +00:00
|
|
|
|
2022-09-29 09:33:46 +00:00
|
|
|
impl<D: Clone + SecureDigest> DigestTranscript<D> {
|
2022-06-24 12:42:38 +00:00
|
|
|
fn append(&mut self, kind: DigestTranscriptMember, value: &[u8]) {
|
2022-09-05 01:23:38 +00:00
|
|
|
self.0.update([kind.as_u8()]);
|
2022-06-24 12:42:38 +00:00
|
|
|
// Assumes messages don't exceed 16 exabytes
|
2022-06-24 22:43:32 +00:00
|
|
|
self.0.update(u64::try_from(value.len()).unwrap().to_le_bytes());
|
|
|
|
self.0.update(value);
|
2022-06-24 12:42:38 +00:00
|
|
|
}
|
2022-07-12 05:28:01 +00:00
|
|
|
}
|
|
|
|
|
2022-09-29 09:33:46 +00:00
|
|
|
impl<D: Clone + SecureDigest> Transcript for DigestTranscript<D> {
|
2022-07-12 05:28:01 +00:00
|
|
|
type Challenge = Output<D>;
|
2022-06-24 12:42:38 +00:00
|
|
|
|
2022-07-12 05:28:01 +00:00
|
|
|
fn new(name: &'static [u8]) -> Self {
|
2022-06-24 22:49:04 +00:00
|
|
|
let mut res = DigestTranscript(D::new());
|
2022-06-24 12:42:38 +00:00
|
|
|
res.append(DigestTranscriptMember::Name, name);
|
|
|
|
res
|
2022-05-06 11:33:08 +00:00
|
|
|
}
|
2022-06-28 08:02:56 +00:00
|
|
|
|
2022-11-05 22:43:36 +00:00
|
|
|
fn domain_separate(&mut self, label: &'static [u8]) {
|
2022-06-24 12:42:38 +00:00
|
|
|
self.append(DigestTranscriptMember::Domain, label);
|
2022-05-03 11:20:24 +00:00
|
|
|
}
|
|
|
|
|
2022-11-05 22:43:36 +00:00
|
|
|
fn append_message<M: AsRef<[u8]>>(&mut self, label: &'static [u8], message: M) {
|
2022-06-24 12:42:38 +00:00
|
|
|
self.append(DigestTranscriptMember::Label, label);
|
2022-11-05 22:43:36 +00:00
|
|
|
self.append(DigestTranscriptMember::Value, message.as_ref());
|
2022-05-03 11:20:24 +00:00
|
|
|
}
|
|
|
|
|
2022-06-28 08:02:56 +00:00
|
|
|
fn challenge(&mut self, label: &'static [u8]) -> Self::Challenge {
|
2022-06-24 12:42:38 +00:00
|
|
|
self.append(DigestTranscriptMember::Challenge, label);
|
2022-06-28 08:02:56 +00:00
|
|
|
self.0.clone().finalize()
|
2022-05-03 11:20:24 +00:00
|
|
|
}
|
|
|
|
|
2022-05-31 06:12:14 +00:00
|
|
|
fn rng_seed(&mut self, label: &'static [u8]) -> [u8; 32] {
|
2022-05-03 11:20:24 +00:00
|
|
|
let mut seed = [0; 32];
|
2022-06-28 08:02:56 +00:00
|
|
|
seed.copy_from_slice(&self.challenge(label)[.. 32]);
|
2022-05-06 11:33:08 +00:00
|
|
|
seed
|
2022-05-03 11:20:24 +00:00
|
|
|
}
|
|
|
|
}
|
2022-06-24 22:58:24 +00:00
|
|
|
|
2022-12-08 01:23:25 +00:00
|
|
|
/// The recommended transcript, secure against length-extension attacks.
|
2022-06-24 22:58:24 +00:00
|
|
|
#[cfg(feature = "recommended")]
|
|
|
|
pub type RecommendedTranscript = DigestTranscript<blake2::Blake2b512>;
|