2022-04-28 21:12:54 +00:00
|
|
|
use rand::{RngCore, SeedableRng, rngs::OsRng};
|
|
|
|
use rand_chacha::ChaCha12Rng;
|
2022-04-22 01:36:18 +00:00
|
|
|
|
|
|
|
use curve25519_dalek::{constants::ED25519_BASEPOINT_TABLE, scalar::Scalar};
|
|
|
|
|
2022-04-28 21:29:56 +00:00
|
|
|
use monero_serai::{random_scalar, Commitment, frost::MultisigError, key_image, clsag};
|
2022-04-22 01:36:18 +00:00
|
|
|
|
|
|
|
#[cfg(feature = "multisig")]
|
|
|
|
mod frost;
|
|
|
|
#[cfg(feature = "multisig")]
|
2022-04-29 01:47:25 +00:00
|
|
|
use crate::frost::{THRESHOLD, PARTICIPANTS, generate_keys, sign};
|
2022-04-22 01:36:18 +00:00
|
|
|
|
|
|
|
const RING_INDEX: u8 = 3;
|
|
|
|
const RING_LEN: u64 = 11;
|
|
|
|
const AMOUNT: u64 = 1337;
|
|
|
|
|
|
|
|
#[test]
|
2022-04-28 07:31:09 +00:00
|
|
|
fn test_single() {
|
2022-04-22 01:36:18 +00:00
|
|
|
let msg = [1; 32];
|
|
|
|
|
|
|
|
let mut secrets = [Scalar::zero(), Scalar::zero()];
|
|
|
|
let mut ring = vec![];
|
|
|
|
for i in 0 .. RING_LEN {
|
|
|
|
let dest = random_scalar(&mut OsRng);
|
2022-04-28 07:31:09 +00:00
|
|
|
let mask = random_scalar(&mut OsRng);
|
2022-04-22 01:36:18 +00:00
|
|
|
let amount;
|
2022-04-28 02:48:58 +00:00
|
|
|
if i == u64::from(RING_INDEX) {
|
2022-04-28 07:31:09 +00:00
|
|
|
secrets = [dest, mask];
|
2022-04-22 01:36:18 +00:00
|
|
|
amount = AMOUNT;
|
|
|
|
} else {
|
|
|
|
amount = OsRng.next_u64();
|
|
|
|
}
|
2022-04-28 07:31:09 +00:00
|
|
|
ring.push([&dest * &ED25519_BASEPOINT_TABLE, Commitment::new(mask, amount).calculate()]);
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
2022-04-28 07:31:09 +00:00
|
|
|
let image = key_image::generate(&secrets[0]);
|
2022-04-22 01:36:18 +00:00
|
|
|
let (clsag, pseudo_out) = clsag::sign(
|
|
|
|
&mut OsRng,
|
|
|
|
msg,
|
2022-04-28 07:31:09 +00:00
|
|
|
&vec![(
|
|
|
|
secrets[0],
|
2022-04-28 21:29:56 +00:00
|
|
|
clsag::Input::new(
|
2022-04-28 07:31:09 +00:00
|
|
|
image,
|
|
|
|
ring.clone(),
|
|
|
|
RING_INDEX,
|
|
|
|
Commitment::new(secrets[1], AMOUNT)
|
|
|
|
).unwrap()
|
|
|
|
)],
|
|
|
|
Scalar::zero()
|
|
|
|
).unwrap().swap_remove(0);
|
2022-04-28 16:01:20 +00:00
|
|
|
assert!(clsag::verify(&clsag, &msg, image, &ring, pseudo_out));
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
#[cfg(feature = "multisig")]
|
|
|
|
#[test]
|
2022-04-28 16:01:20 +00:00
|
|
|
fn test_multisig() -> Result<(), MultisigError> {
|
2022-04-29 01:47:25 +00:00
|
|
|
let (keys, group_private) = generate_keys();
|
2022-04-22 01:36:18 +00:00
|
|
|
let t = keys[0].params().t();
|
|
|
|
|
|
|
|
let mut images = vec![];
|
|
|
|
images.resize(PARTICIPANTS + 1, None);
|
|
|
|
let included = (1 ..= THRESHOLD).collect::<Vec<usize>>();
|
|
|
|
for i in &included {
|
|
|
|
let i = *i;
|
|
|
|
images[i] = Some(
|
|
|
|
(
|
|
|
|
keys[0].verification_shares()[i].0,
|
|
|
|
key_image::multisig(&mut OsRng, &keys[i - 1], &included)
|
|
|
|
)
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
|
|
|
let msg = [1; 32];
|
|
|
|
|
|
|
|
images.push(None);
|
|
|
|
let ki_used = images.swap_remove(1).unwrap().1;
|
|
|
|
let image = ki_used.resolve(images).unwrap();
|
|
|
|
|
|
|
|
let randomness = random_scalar(&mut OsRng);
|
|
|
|
let mut ring = vec![];
|
|
|
|
for i in 0 .. RING_LEN {
|
|
|
|
let dest;
|
2022-04-28 16:01:20 +00:00
|
|
|
let mask;
|
2022-04-22 01:36:18 +00:00
|
|
|
let amount;
|
2022-04-28 02:48:58 +00:00
|
|
|
if i != u64::from(RING_INDEX) {
|
2022-04-22 01:36:18 +00:00
|
|
|
dest = random_scalar(&mut OsRng);
|
2022-04-28 16:01:20 +00:00
|
|
|
mask = random_scalar(&mut OsRng);
|
2022-04-22 01:36:18 +00:00
|
|
|
amount = OsRng.next_u64();
|
|
|
|
} else {
|
|
|
|
dest = group_private.0;
|
2022-04-28 16:01:20 +00:00
|
|
|
mask = randomness;
|
2022-04-22 01:36:18 +00:00
|
|
|
amount = AMOUNT;
|
|
|
|
}
|
2022-04-28 16:01:20 +00:00
|
|
|
ring.push([&dest * &ED25519_BASEPOINT_TABLE, Commitment::new(mask, amount).calculate()]);
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
2022-04-29 01:47:25 +00:00
|
|
|
let mut algorithms = Vec::with_capacity(t);
|
|
|
|
for _ in 1 ..= t {
|
|
|
|
algorithms.push(
|
|
|
|
clsag::Multisig::new(
|
|
|
|
&mut ChaCha12Rng::seed_from_u64(1),
|
|
|
|
msg,
|
|
|
|
clsag::Input::new(image, ring.clone(), RING_INDEX, Commitment::new(randomness, AMOUNT)).unwrap()
|
2022-04-22 01:36:18 +00:00
|
|
|
).unwrap()
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
2022-04-29 01:47:25 +00:00
|
|
|
let mut signatures = sign(algorithms, keys);
|
|
|
|
let signature = signatures.swap_remove(0);
|
|
|
|
for s in 0 .. (t - 1) {
|
|
|
|
// Verify the commitments and the non-decoy s scalar are identical to every other signature
|
|
|
|
// FROST will already have called verify on the produced signature, before checking individual
|
|
|
|
// key shares. For FROST Schnorr, it's cheaper. For CLSAG, it may be more expensive? Yet it
|
|
|
|
// ensures we have usable signatures, not just signatures we think are usable
|
|
|
|
assert_eq!(signatures[s].1, signature.1);
|
|
|
|
assert_eq!(signatures[s].0.s[RING_INDEX as usize], signature.0.s[RING_INDEX as usize]);
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
Ok(())
|
|
|
|
}
|