2022-05-25 01:41:14 +00:00
use core::{convert::TryFrom, fmt};
use std::collections::HashMap;
2022-04-22 01:36:18 +00:00
use rand_core::{RngCore, CryptoRng};
use ff::{Field, PrimeField};
use group::Group;
2022-05-25 01:41:14 +00:00
use crate::{Curve, MultisigParams, MultisigKeys, FrostError, validate_map};
2022-04-22 01:36:18 +00:00
2022-04-23 07:49:30 +00:00
2022-05-25 01:41:14 +00:00
fn challenge<C: Curve>(l: u16, context: &str, R: &[u8], Am: &[u8]) -> C::F {
2022-05-06 11:49:18 +00:00
let mut c = Vec::with_capacity(2 + context.len() + R.len() + Am.len());
2022-05-25 01:41:14 +00:00
2022-04-23 07:49:30 +00:00
c.extend(R); // R
c.extend(Am); // A of the first commitment, which is what we're proving we have the private key
// for
// m of the rest of the commitments, authenticating them
2022-04-22 01:36:18 +00:00
// Implements steps 1 through 3 of round 1 of FROST DKG. Returns the coefficients, commitments, and
// the serialized commitments to be broadcasted over an authenticated channel to all parties
fn generate_key_r1<R: RngCore + CryptoRng, C: Curve>(
rng: &mut R,
params: &MultisigParams,
context: &str,
2022-05-25 01:41:14 +00:00
) -> (Vec<C::F>, Vec<u8>) {
let t = usize::from(params.t);
let mut coefficients = Vec::with_capacity(t);
let mut commitments = Vec::with_capacity(t);
let mut serialized = Vec::with_capacity((C::G_len() * t) + C::G_len() + C::F_len());
for i in 0 .. t {
2022-04-22 01:36:18 +00:00
// Step 1: Generate t random values to form a polynomial with
coefficients.push(C::F::random(&mut *rng));
// Step 3: Generate public commitments
2022-05-25 01:41:14 +00:00
commitments.push(C::generator_table() * coefficients[i]);
2022-04-22 01:36:18 +00:00
// Serialize them for publication
2022-05-25 01:41:14 +00:00
2022-04-22 01:36:18 +00:00
// Step 2: Provide a proof of knowledge
// This can be deterministic as the PoK is a singleton never opened up to cooperative discussion
// There's also no reason to spend the time and effort to make this deterministic besides a
// general obsession with canonicity and determinism
2022-05-25 01:41:14 +00:00
let r = C::F::random(rng);
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
let R = C::generator_table() * r;
let s = r + (
coefficients[0] * challenge::<C>(params.i(), context, &C::G_to_bytes(&R), &serialized)
2022-04-22 01:36:18 +00:00
2022-05-06 11:49:18 +00:00
2022-04-22 01:36:18 +00:00
// Step 4: Broadcast
2022-05-25 01:41:14 +00:00
(coefficients, serialized)
2022-04-22 01:36:18 +00:00
// Verify the received data from the first round of key generation
fn verify_r1<R: RngCore + CryptoRng, C: Curve>(
rng: &mut R,
params: &MultisigParams,
context: &str,
2022-05-25 01:41:14 +00:00
our_commitments: Vec<u8>,
mut serialized: HashMap<u16, Vec<u8>>,
) -> Result<HashMap<u16, Vec<C::G>>, FrostError> {
&mut serialized,
&(1 ..= params.n()).into_iter().collect::<Vec<_>>(),
(params.i(), our_commitments)
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
let commitments_len = usize::from(params.t()) * C::G_len();
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
let mut commitments = HashMap::new();
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
let R_bytes = |l| &serialized[&l][commitments_len .. commitments_len + C::G_len()];
let R = |l| C::G_from_slice(R_bytes(l)).map_err(|_| FrostError::InvalidProofOfKnowledge(l));
let Am = |l| &serialized[&l][0 .. commitments_len];
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
let s = |l| C::F_from_slice(
&serialized[&l][commitments_len + C::G_len() ..]
).map_err(|_| FrostError::InvalidProofOfKnowledge(l));
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
let mut first = true;
let mut scalars = Vec::with_capacity((usize::from(params.n()) - 1) * 3);
let mut points = Vec::with_capacity((usize::from(params.n()) - 1) * 3);
for l in 1 ..= params.n() {
let mut these_commitments = vec![];
for c in 0 .. usize::from(params.t()) {
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
&serialized[&l][(c * C::G_len()) .. ((c + 1) * C::G_len())]
).map_err(|_| FrostError::InvalidCommitment(l.try_into().unwrap()))?
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
commitments.insert(l, these_commitments);
// Don't bother validating our own proof of knowledge
if l == params.i() {
2022-04-22 01:36:18 +00:00
// Step 5: Validate each proof of knowledge (prep)
let mut u = C::F::one();
if !first {
u = C::F::random(&mut *rng);
2022-05-25 01:41:14 +00:00
// uR
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
// -usG
scalars.push(-s(l)? * u);
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
// ucA
let c = challenge::<C>(l, context, R_bytes(l), Am(l));
scalars.push(if first { first = false; c } else { c * u});
2022-04-22 01:36:18 +00:00
// Step 5: Implementation
// Uses batch verification to optimize the success case dramatically
// On failure, the cost is now this + blame, yet that should happen infrequently
2022-05-25 01:41:14 +00:00
// s = r + ca
// sG == R + cA
// R + cA - sG == 0
2022-04-22 01:36:18 +00:00
if C::multiexp_vartime(&scalars, &points) != C::G::identity() {
2022-05-25 01:41:14 +00:00
for l in 1 ..= params.n() {
if l == params.i() {
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
if (C::generator_table() * s(l)?) != (
R(l)? + (commitments[&l][0] * challenge::<C>(l, context, R_bytes(l), Am(l)))
) {
2022-04-22 01:36:18 +00:00
Err(FrostError::InternalError("batch validation is broken".to_string()))?;
fn polynomial<F: PrimeField>(
coefficients: &[F],
2022-05-25 01:41:14 +00:00
l: u16
2022-04-22 01:36:18 +00:00
) -> F {
2022-05-25 01:41:14 +00:00
let l = F::from(u64::from(l));
2022-04-22 01:36:18 +00:00
let mut share = F::zero();
for (idx, coefficient) in coefficients.iter().rev().enumerate() {
share += coefficient;
if idx != (coefficients.len() - 1) {
2022-05-25 01:41:14 +00:00
share *= l;
2022-04-22 01:36:18 +00:00
// Implements round 1, step 5 and round 2, step 1 of FROST key generation
// Returns our secret share part, commitments for the next step, and a vector for each
// counterparty to receive
fn generate_key_r2<R: RngCore + CryptoRng, C: Curve>(
rng: &mut R,
params: &MultisigParams,
context: &str,
coefficients: Vec<C::F>,
2022-05-25 01:41:14 +00:00
our_commitments: Vec<u8>,
commitments: HashMap<u16, Vec<u8>>,
) -> Result<(C::F, HashMap<u16, Vec<C::G>>, HashMap<u16, Vec<u8>>), FrostError> {
2022-04-22 01:36:18 +00:00
let commitments = verify_r1::<R, C>(rng, params, context, our_commitments, commitments)?;
// Step 1: Generate secret shares for all other parties
2022-05-25 01:41:14 +00:00
let mut res = HashMap::new();
for l in 1 ..= params.n() {
// Don't insert our own shares to the byte buffer which is meant to be sent around
2022-04-22 01:36:18 +00:00
// An app developer could accidentally send it. Best to keep this black boxed
2022-05-25 01:41:14 +00:00
if l == params.i() {
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
res.insert(l, C::F_to_bytes(&polynomial(&coefficients, l)));
2022-04-22 01:36:18 +00:00
// Calculate our own share
2022-05-25 01:41:14 +00:00
let share = polynomial(&coefficients, params.i());
2022-04-22 01:36:18 +00:00
// The secret shares are discarded here, not cleared. While any system which leaves its memory
// accessible is likely totally lost already, making the distinction meaningless when the key gen
// system acts as the signer system and therefore actively holds the signing key anyways, it
// should be overwritten with /dev/urandom in the name of security (which still doesn't meet
// requirements for secure data deletion yet those requirements expect hardware access which is
// far past what this library can reasonably counter)
// TODO: Zero out the coefficients
Ok((share, commitments, res))
/// Finishes round 2 and returns both the secret share and the serialized public key.
/// This key is not usable until all parties confirm they have completed the protocol without
/// issue, yet simply confirming protocol completion without issue is enough to confirm the same
/// key was generated as long as a lack of duplicated commitments was also confirmed when they were
/// broadcasted initially
fn complete_r2<C: Curve>(
params: MultisigParams,
share: C::F,
2022-05-25 01:41:14 +00:00
commitments: HashMap<u16, Vec<C::G>>,
2022-04-22 01:36:18 +00:00
// Vec to preserve ownership
2022-05-25 01:41:14 +00:00
mut serialized: HashMap<u16, Vec<u8>>,
2022-04-22 01:36:18 +00:00
) -> Result<MultisigKeys<C>, FrostError> {
2022-05-25 01:41:14 +00:00
&mut serialized,
&(1 ..= params.n()).into_iter().collect::<Vec<_>>(),
(params.i(), C::F_to_bytes(&share))
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
// Step 2. Verify each share
let mut shares = HashMap::new();
for (l, share) in serialized {
shares.insert(l, C::F_from_slice(&share).map_err(|_| FrostError::InvalidShare(params.i()))?);
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
for (l, share) in &shares {
if *l == params.i() {
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
let i_scalar = C::F::from(params.i.into());
2022-04-22 01:36:18 +00:00
let mut exp = C::F::one();
2022-05-25 01:41:14 +00:00
let mut exps = Vec::with_capacity(usize::from(params.t()));
for _ in 0 .. params.t() {
2022-04-22 01:36:18 +00:00
exp *= i_scalar;
// Doesn't use multiexp_vartime with -shares[l] due to not being able to push to commitments
2022-05-25 01:41:14 +00:00
if C::multiexp_vartime(&exps, &commitments[&l]) != (C::generator_table() * *share) {
2022-04-22 01:36:18 +00:00
// TODO: Clear the original share
2022-05-25 01:41:14 +00:00
let mut secret_share = C::F::zero();
for (_, share) in shares {
secret_share += share;
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
let mut verification_shares = HashMap::new();
for l in 1 ..= params.n() {
2022-04-22 01:36:18 +00:00
let mut exps = vec![];
let mut cs = vec![];
2022-05-25 01:41:14 +00:00
for i in 1 ..= params.n() {
for j in 0 .. params.t() {
2022-04-22 01:36:18 +00:00
let mut exp = C::F::one();
2022-05-25 01:41:14 +00:00
for _ in 0 .. j {
exp *= C::F::from(u64::try_from(l).unwrap());
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
verification_shares.insert(l, C::multiexp_vartime(&exps, &cs));
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
debug_assert_eq!(C::generator_table() * secret_share, verification_shares[¶ms.i()]);
2022-04-22 01:36:18 +00:00
2022-05-25 01:41:14 +00:00
let group_key = commitments.iter().map(|(_, commitments)| commitments[0]).sum();
2022-04-22 01:36:18 +00:00
// TODO: Clear serialized and shares
Ok(MultisigKeys { params, secret_share, group_key, verification_shares, offset: None } )
/// State of a Key Generation machine
#[derive(Clone, Copy, PartialEq, Eq, Debug)]
pub enum State {
impl fmt::Display for State {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
write!(f, "{:?}", self)
/// State machine which manages key generation
2022-04-23 07:49:30 +00:00
2022-04-22 01:36:18 +00:00
pub struct StateMachine<C: Curve> {
params: MultisigParams,
context: String,
state: State,
coefficients: Option<Vec<C::F>>,
2022-05-25 01:41:14 +00:00
our_commitments: Option<Vec<u8>>,
2022-04-22 01:36:18 +00:00
secret: Option<C::F>,
2022-05-25 01:41:14 +00:00
commitments: Option<HashMap<u16, Vec<C::G>>>
2022-04-22 01:36:18 +00:00
impl<C: Curve> StateMachine<C> {
/// Creates a new machine to generate a key for the specified curve in the specified multisig
// The context string must be unique among multisigs
pub fn new(params: MultisigParams, context: String) -> StateMachine<C> {
StateMachine {
state: State::Fresh,
coefficients: None,
our_commitments: None,
secret: None,
2022-04-23 07:49:30 +00:00
commitments: None
2022-04-22 01:36:18 +00:00
/// Start generating a key according to the FROST DKG spec
/// Returns a serialized list of commitments to be sent to all parties over an authenticated
/// channel. If any party submits multiple sets of commitments, they MUST be treated as malicious
pub fn generate_coefficients<R: RngCore + CryptoRng>(
&mut self,
rng: &mut R
) -> Result<Vec<u8>, FrostError> {
if self.state != State::Fresh {
Err(FrostError::InvalidKeyGenTransition(State::Fresh, self.state))?;
2022-05-25 01:41:14 +00:00
let (coefficients, serialized) = generate_key_r1::<R, C>(
2022-04-22 01:36:18 +00:00
self.coefficients = Some(coefficients);
2022-05-25 01:41:14 +00:00
self.our_commitments = Some(serialized.clone());
2022-04-22 01:36:18 +00:00
self.state = State::GeneratedCoefficients;
/// Continue generating a key
/// Takes in everyone else's commitments, which are expected to be in a Vec where participant
/// index = Vec index. An empty vector is expected at index 0 to allow for this. An empty vector
/// is also expected at index i which is locally handled. Returns a byte vector representing a
/// secret share for each other participant which should be encrypted before sending
pub fn generate_secret_shares<R: RngCore + CryptoRng>(
&mut self,
rng: &mut R,
2022-05-25 01:41:14 +00:00
commitments: HashMap<u16, Vec<u8>>,
) -> Result<HashMap<u16, Vec<u8>>, FrostError> {
2022-04-22 01:36:18 +00:00
if self.state != State::GeneratedCoefficients {
Err(FrostError::InvalidKeyGenTransition(State::GeneratedCoefficients, self.state))?;
let (secret, commitments, shares) = generate_key_r2::<R, C>(
2022-05-25 01:41:14 +00:00
2022-04-22 01:36:18 +00:00
self.secret = Some(secret);
self.commitments = Some(commitments);
self.state = State::GeneratedSecretShares;
/// Complete key generation
/// Takes in everyone elses' shares submitted to us as a Vec, expecting participant index =
/// Vec index with an empty vector at index 0 and index i. Returns a byte vector representing the
/// group's public key, while setting a valid secret share inside the machine. > t participants
/// must report completion without issue before this key can be considered usable, yet you should
/// wait for all participants to report as such
pub fn complete(
&mut self,
2022-05-25 01:41:14 +00:00
shares: HashMap<u16, Vec<u8>>,
) -> Result<MultisigKeys<C>, FrostError> {
2022-04-22 01:36:18 +00:00
if self.state != State::GeneratedSecretShares {
Err(FrostError::InvalidKeyGenTransition(State::GeneratedSecretShares, self.state))?;
let keys = complete_r2(
2022-05-25 01:41:14 +00:00
2022-04-22 01:36:18 +00:00
self.state = State::Complete;
pub fn params(&self) -> MultisigParams {
pub fn state(&self) -> State {