2022-04-22 01:36:18 +00:00
|
|
|
use core::convert::TryInto;
|
|
|
|
|
2022-04-23 07:49:30 +00:00
|
|
|
use ff::PrimeField;
|
|
|
|
use group::GroupEncoding;
|
2022-04-22 01:36:18 +00:00
|
|
|
|
2022-05-03 11:20:24 +00:00
|
|
|
use sha2::{Digest, Sha256, Sha512};
|
2022-04-23 07:49:30 +00:00
|
|
|
|
|
|
|
use k256::{
|
|
|
|
elliptic_curve::{generic_array::GenericArray, bigint::{ArrayEncoding, U512}, ops::Reduce},
|
|
|
|
Scalar,
|
|
|
|
ProjectivePoint
|
|
|
|
};
|
|
|
|
|
|
|
|
use frost::{CurveError, Curve, multiexp_vartime, algorithm::Hram};
|
2022-04-22 01:36:18 +00:00
|
|
|
|
|
|
|
#[derive(Clone, Copy, PartialEq, Eq, Debug)]
|
2022-04-23 07:49:30 +00:00
|
|
|
pub struct Secp256k1;
|
|
|
|
impl Curve for Secp256k1 {
|
|
|
|
type F = Scalar;
|
|
|
|
type G = ProjectivePoint;
|
|
|
|
type T = ProjectivePoint;
|
2022-04-22 01:36:18 +00:00
|
|
|
|
|
|
|
fn id() -> String {
|
2022-04-23 07:49:30 +00:00
|
|
|
"secp256k1".to_string()
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
fn id_len() -> u8 {
|
|
|
|
Self::id().len() as u8
|
|
|
|
}
|
|
|
|
|
|
|
|
fn generator() -> Self::G {
|
2022-04-23 07:49:30 +00:00
|
|
|
Self::G::GENERATOR
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
fn generator_table() -> Self::T {
|
2022-04-23 07:49:30 +00:00
|
|
|
Self::G::GENERATOR
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
fn multiexp_vartime(scalars: &[Self::F], points: &[Self::G]) -> Self::G {
|
2022-04-23 07:49:30 +00:00
|
|
|
multiexp_vartime::<Secp256k1>(scalars, points)
|
|
|
|
}
|
|
|
|
|
|
|
|
// The IETF draft doesn't specify a secp256k1 ciphersuite
|
|
|
|
// This test just uses the simplest ciphersuite which would still be viable to deploy
|
|
|
|
fn hash_msg(msg: &[u8]) -> Vec<u8> {
|
|
|
|
(&Sha256::digest(msg)).to_vec()
|
|
|
|
}
|
|
|
|
|
|
|
|
// Use wide reduction for security
|
|
|
|
fn hash_to_F(data: &[u8]) -> Self::F {
|
|
|
|
Scalar::from_uint_reduced(
|
|
|
|
U512::from_be_byte_array(Sha512::new().chain_update("rho").chain_update(data).finalize())
|
|
|
|
)
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
fn F_len() -> usize {
|
|
|
|
32
|
|
|
|
}
|
|
|
|
|
|
|
|
fn G_len() -> usize {
|
2022-04-23 07:49:30 +00:00
|
|
|
33
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
fn F_from_le_slice(slice: &[u8]) -> Result<Self::F, CurveError> {
|
2022-04-23 07:49:30 +00:00
|
|
|
let mut bytes: [u8; 32] = slice.try_into().map_err(
|
|
|
|
|_| CurveError::InvalidLength(32, slice.len())
|
|
|
|
)?;
|
|
|
|
bytes.reverse();
|
|
|
|
let scalar = Scalar::from_repr(bytes.into());
|
|
|
|
if scalar.is_none().unwrap_u8() == 1 {
|
|
|
|
Err(CurveError::InvalidScalar)?;
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
2022-04-23 07:49:30 +00:00
|
|
|
Ok(scalar.unwrap())
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
fn G_from_slice(slice: &[u8]) -> Result<Self::G, CurveError> {
|
2022-04-23 07:49:30 +00:00
|
|
|
let point = ProjectivePoint::from_bytes(GenericArray::from_slice(slice));
|
|
|
|
if point.is_none().unwrap_u8() == 1 {
|
|
|
|
Err(CurveError::InvalidScalar)?;
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
2022-04-23 07:49:30 +00:00
|
|
|
Ok(point.unwrap())
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
fn F_to_le_bytes(f: &Self::F) -> Vec<u8> {
|
2022-04-23 07:49:30 +00:00
|
|
|
let mut res: [u8; 32] = f.to_bytes().into();
|
|
|
|
res.reverse();
|
|
|
|
res.to_vec()
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
fn G_to_bytes(g: &Self::G) -> Vec<u8> {
|
2022-04-23 07:49:30 +00:00
|
|
|
(&g.to_bytes()).to_vec()
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
2022-04-23 07:49:30 +00:00
|
|
|
}
|
2022-04-22 01:36:18 +00:00
|
|
|
|
2022-04-23 07:49:30 +00:00
|
|
|
#[allow(non_snake_case)]
|
|
|
|
#[derive(Clone)]
|
|
|
|
pub struct TestHram {}
|
|
|
|
impl Hram<Secp256k1> for TestHram {
|
|
|
|
#[allow(non_snake_case)]
|
|
|
|
fn hram(R: &ProjectivePoint, A: &ProjectivePoint, m: &[u8]) -> Scalar {
|
|
|
|
Scalar::from_uint_reduced(
|
|
|
|
U512::from_be_byte_array(
|
|
|
|
Sha512::new()
|
|
|
|
.chain_update(Secp256k1::G_to_bytes(R))
|
|
|
|
.chain_update(Secp256k1::G_to_bytes(A))
|
|
|
|
.chain_update(m)
|
|
|
|
.finalize()
|
|
|
|
)
|
|
|
|
)
|
2022-04-22 01:36:18 +00:00
|
|
|
}
|
|
|
|
}
|