You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
DateKeys-App/scripts/tlock-ts-samples.mjs

35 lines
1.8 KiB

Phase 2, step 7: tlock encryption, checked against Go both ways - ibe.ts gains encryptOnG2RFC9380, EncryptCCAonG2 of kyber with the suite of tlock for Quicknet. Qid is H(id) on G1 with the RFC 9380 DST, sigma comes from crypto.getRandomValues, U = r·G2, V = sigma XOR H2(e(Qid, key)^r) and W = msg XOR H4(sigma). The key passes the canonical gate, and sigma and the masks are wiped. encryptOnG2WithSigma takes a given sigma, for the vectors only; index.ts exports neither. - tlock.ts adds timeRecipient, the age-encryption Recipient of OUTER_TIME_AGE, as Go's agewrap.TimeRecipient. It writes the stanza "tlock <round> <chain hash>" with the checks and texts of NewTimeRecipient: the scheme and the pinned key, then the round range. age-encryption has no labels, so the writer of phase 3 adds it alone. Vectors, in src/lib/dkc/testing/tlock-vectors.json from scripts/tlock-go-vectors.go: - Fixed-sigma encryptions of 1, 16 and 32 bytes for rounds 1000 and 1001. Go restates EncryptCCAonG2, since kyber draws sigma itself, and checks the restatement with ibe.DecryptCCAonG2 and tlock.TimeUnlock. encryptOnG2WithSigma reproduces them byte for byte. - The samples of scripts/tlock-ts-samples.mjs, which Node runs on the TypeScript sources: IBE bodies and age files that this library made for rounds 1000 and 1001. Go opened every one: the bodies with tlock.TimeUnlock and the age files with age.Decrypt and agewrap.NewTimeIdentity, the identity of step 11. It got the same file keys and plaintexts, and the samples are frozen with those verdicts. tlock.test.ts replays both blocks, the random round trip, the rejections with their texts, and an age file sealed with timeRecipient and opened with the step-11 identity of open.ts. Coverage of ibe.ts and tlock.ts is 100 %, now a threshold for tlock.ts too. Step 6 of the plan is recorded as done: the canonicality amendment is in spec-v0.8.2. npm run verify is green: 2,567 tests. The site does not change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
#!/usr/bin/env node
// Writes, as JSON, tlock ciphertexts made by the TypeScript library of this
// repository, for scripts/tlock-go-vectors.go to open with the Go reference
// (plan of phase 2, section 8, points 4 and 5):
//
// - IBE: a random 16-byte file key encrypted with encryptOnG2RFC9380 for
// rounds 1000 and 1001 of Quicknet, as the tlock stanza body U || V || W;
// - age: an age file whose only stanza timeRecipient wrote, through the
// Encrypter of age-encryption, for rounds 1000 and 1001.
//
// The randomness makes every run different: the output is generated once and
// frozen, with the verdicts of Go, in src/lib/dkc/testing/tlock-vectors.json.
// Node runs the TypeScript sources directly (type stripping, Node 22.6+):
//
// node scripts/tlock-ts-samples.mjs > ts-samples.json
import { Encrypter } from 'age-encryption';
import { ciphertextToBody, encryptOnG2RFC9380, roundIdentity } from '../src/lib/dkc/ibe.ts';
import { quicknet } from '../src/lib/dkc/profile.ts';
import { timeRecipient } from '../src/lib/dkc/tlock.ts';
const hex = (b) => Buffer.from(b).toString('hex');
const p = quicknet();
const samples = [];
for (const round of [1000, 1001]) {
const fileKey = crypto.getRandomValues(new Uint8Array(16));
const body = ciphertextToBody(encryptOnG2RFC9380(p.publicKey, roundIdentity(round), fileKey));
samples.push({ name: `IBE, round ${round}`, kind: 'ibe', round, file_key: hex(fileKey), body: hex(body) });
const e = new Encrypter();
e.addRecipient(timeRecipient(p, round));
const plaintext = new TextEncoder().encode(`DateKeys: sealed by the TypeScript library for round ${round}`);
samples.push({ name: `age file, round ${round}`, kind: 'age', round, plaintext: hex(plaintext), file: hex(await e.encrypt(plaintext)) });
}
process.stdout.write(`${JSON.stringify({ generator: 'scripts/tlock-ts-samples.mjs', samples }, null, 1)}\n`);

Powered by TurnKey Linux.