Read capsule format 2 of spec v0.9
Syncs testdata with datekeys-go at spec-v0.9 (7e2d83c) and moves the
reader to the DateKeys Protocol Specification v0.9. Both capsule formats
are read; a format 1 capsule keeps the verdict v0.8.2 gave it.
- framing: the VERSION of the prelude is the capsule format, 1 or 2
(Prelude.format, FORMAT_1, FORMAT_2, isFormat).
- control: decodeControl and encodeControl take the format; schema
version 2 adds payload_length (8 bytes, at most L_MAX) and padding
(1 or 2).
- padding.ts: the rules bloque256 and reforzado of spec §29.1, exact up
to L_MAX with BigInt bit lengths and ceil roundings, and the length of
PAYLOAD_AGE.
- open: exactly 16 stanzas in INNER_ACCESS_AGE of format 2 (step 12), P
at step 16, and at step 17 a plaintext of exactly P bytes whose
padding is zero; only the first L bytes are delivered, never the
padding. Step 17 is recorded when it passes, and step 18 gives the
bytes of content, as the reference does. Opened reports the format, L
and, in format 2, the rule and P.
- inspect: the JSON view carries format, as datekeys inspect -json.
- The page shows the format, warns about format 1, and gives the
padding rule and P once a format 2 capsule opens.
Tests: the twelve fixtures, the 125 mutation cases through open from
memory and from a Blob, the 4380 differential cases, padding.json, the
format 2 CBOR vectors, and padding.test.ts against a BigInt statement of
§29.1. The error texts of the 125 corpus cases were compared with
capsule.Open at spec-v0.9. ibe-vectors.json gains the seven format 2
fixtures from scripts/ibe-go-vectors.go; its frozen values are unchanged.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
|
|
|
{
|
|
|
|
|
"description": "format 2 time_and_key capsule for three known X25519 recipients and a portable .dkk, and 12 dummies",
|
Specification 0.14, approved: SPEC_VERSION 0.14, testdata at spec-v0.14, one drand scheme and tlock_steps.json
- SPEC_VERSION 0.14; testdata synced from datekeys-go at 39b2033
(spec-v0.14), which adds vectors/tlock_steps.json;
testing/mutation-texts.json regenerated with Go: only its spec field
changes.
- Decision 8: validateProfile admits only bls-unchained-g1-rfc9380, with
its public key in G2, in the order and with the texts of Go's
validateDrand at c041fa3; any other drand scheme fails with
ERR_UNKNOWN_PROFILE before the key and the chain hash.
- vectors.test.ts walks tlock_steps.json value by value with the code of
ibe.ts, release.ts and bls12381.ts, with its negative checks, and the
testdata guard requires it. ibe.ts exports h3Base, h3Try and hashToG1,
which h3, the encryption and release.ts now use.
- The comment of h3 said the top bit is cleared: the first byte is
shifted one bit to the right, as kyber does.
- README and CHANGELOG.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 days ago
|
|
|
"spec": "0.14",
|
Read capsule format 2 of spec v0.9
Syncs testdata with datekeys-go at spec-v0.9 (7e2d83c) and moves the
reader to the DateKeys Protocol Specification v0.9. Both capsule formats
are read; a format 1 capsule keeps the verdict v0.8.2 gave it.
- framing: the VERSION of the prelude is the capsule format, 1 or 2
(Prelude.format, FORMAT_1, FORMAT_2, isFormat).
- control: decodeControl and encodeControl take the format; schema
version 2 adds payload_length (8 bytes, at most L_MAX) and padding
(1 or 2).
- padding.ts: the rules bloque256 and reforzado of spec §29.1, exact up
to L_MAX with BigInt bit lengths and ceil roundings, and the length of
PAYLOAD_AGE.
- open: exactly 16 stanzas in INNER_ACCESS_AGE of format 2 (step 12), P
at step 16, and at step 17 a plaintext of exactly P bytes whose
padding is zero; only the first L bytes are delivered, never the
padding. Step 17 is recorded when it passes, and step 18 gives the
bytes of content, as the reference does. Opened reports the format, L
and, in format 2, the rule and P.
- inspect: the JSON view carries format, as datekeys inspect -json.
- The page shows the format, warns about format 1, and gives the
padding rule and P once a format 2 capsule opens.
Tests: the twelve fixtures, the 125 mutation cases through open from
memory and from a Blob, the 4380 differential cases, padding.json, the
format 2 CBOR vectors, and padding.test.ts against a BigInt statement of
§29.1. The error texts of the 125 corpus cases were compared with
capsule.Open at spec-v0.9. ibe-vectors.json gains the seven format 2
fixtures from scripts/ibe-go-vectors.go; its frozen values are unchanged.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1 week ago
|
|
|
"format": 2,
|
|
|
|
|
"file": "format2_time_and_key_recipients.dkc",
|
|
|
|
|
"sha256": "1a44fd8708c92e2e0a10cfcb1d864a71331ea9af25d97e1a42e969dc898959e3",
|
|
|
|
|
"release": {
|
|
|
|
|
"round": 1001,
|
|
|
|
|
"signature": "b33bf3667cbd5a82de3a24b4e0e9fe5513cc1a0e840368c6e31f5fcfa79bea03f73896b25883abf2853d10337fb8fa41"
|
|
|
|
|
},
|
|
|
|
|
"prelude": "444b4331020000000000007900000850",
|
|
|
|
|
"public_header": "a5006a646174656b657963617001010250ca3e8bfcae3ee19717fe3129ec9830b6037853646b315f65794a325a584a7a61573975496a6f784c434a755a58523362334a72496a6f695a4746305a57746c65584d3663585670593274755a585136646a45694c434a79623356755a4349364d5441774d58300401",
|
|
|
|
|
"datekey": "dk1_eyJ2ZXJzaW9uIjoxLCJuZXR3b3JrIjoiZGF0ZWtleXM6cXVpY2tuZXQ6djEiLCJyb3VuZCI6MTAwMX0",
|
|
|
|
|
"capsule_id": "ca3e8bfcae3ee19717fe3129ec9830b6",
|
|
|
|
|
"access_policy": "time_and_key",
|
|
|
|
|
"structure": "time_and_key",
|
|
|
|
|
"unlock_at": "2023-08-23T15:59:27Z",
|
|
|
|
|
"header_binding": "d58f5020ab127df352927bba6186ec6708edb3e26234803ac76f082c2d10751f",
|
|
|
|
|
"outer_stanzas": [
|
|
|
|
|
{
|
|
|
|
|
"type": "tlock",
|
|
|
|
|
"args": [
|
|
|
|
|
"1001",
|
|
|
|
|
"52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971"
|
|
|
|
|
]
|
|
|
|
|
}
|
|
|
|
|
],
|
|
|
|
|
"payload_stanzas": [
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"zwimuIAtSKu5jEPDc8Ze3RU9ekOQ2BXoQhBYnfs+hgc"
|
|
|
|
|
]
|
|
|
|
|
}
|
|
|
|
|
],
|
|
|
|
|
"inner_stanzas": [
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"rTpC8mQa3vIxdOHxJLfKIAFg+doIrbpwKT4s/2xoJ14"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"Y5VKnOKgh+/3eHCKX0mzTMMAkiM0jy6BQuOkZV3MwXA"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"UuqI7BCvGSBTc1jcOC9+cyuAD1dS+kIZfOMtiTK6UyM"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"EdcAEuz4sXrj2PgkVmYMhUeJA4ug4lj5FZ3h5kpwjk8"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"HtdphHaSk8HVcc5+eQHL1FtCgRZawHWJSBcKI4LSTRc"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"ptIvd9fZTT+7i2CtqZyGVpnX8JT/WfrTutG/HwQzHSE"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"6n1HeyrMMoMlcv7CmRJ+3tTi0snVz2eKGgAej9epLD8"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"7Z6bPBYl7Vp77EyDvcGtKenS2E4oYxMym3UzrVx1XEI"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"79VpVzXH3cG90UXPBTRgdEFgBF2vr66Oirm1GhmncwQ"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"gnUtu2RlmZCJDiBXybyUAdRR279VaRJ2KOw3qurphF8"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"FZfOfhUP4mAurdR80ZIbHzLsFvA4yf1oRfC/uGBXyGQ"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"O6nde4hw5/KEd/7YvpLQIHS50q/aaipCF6UgH3mtWjA"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"9NNLG5SyyVBqw6Xx0LVlnJwYB3xff8iwhMAqY0g8YGE"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"AWV9QKUm9eV9XbDc+mESUu38STDBGKo4D0extcQweik"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"nmr1ixKyrZnu0RS2BG+LrBCEsrnTra1ORrMVnK/ooV8"
|
|
|
|
|
]
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"type": "X25519",
|
|
|
|
|
"args": [
|
|
|
|
|
"7674vCSB9Xm9FZzQAK0YndMuEaq/dIrWFMalCLMQ6hw"
|
|
|
|
|
]
|
|
|
|
|
}
|
|
|
|
|
],
|
|
|
|
|
"access_key_stanza": 4,
|
|
|
|
|
"identity_stanzas": [
|
|
|
|
|
11,
|
|
|
|
|
12,
|
|
|
|
|
9
|
|
|
|
|
],
|
|
|
|
|
"access_key_file": "format2_time_and_key_recipients.dkk",
|
|
|
|
|
"identities": [
|
|
|
|
|
"AGE-SECRET-KEY-1DRV36ZLYW0GCZCJTMK0S025K3PLEQR7QAY574K4PGH5VFTZKKZMS3J3LNL",
|
|
|
|
|
"AGE-SECRET-KEY-1E92XVRNNUHQ9GD7D34P2XAD97MZGNE4DR990GJFGDYEX8WDE8E4ST8HHK2",
|
|
|
|
|
"AGE-SECRET-KEY-1C2K7R20E0GKLGJM60JFL63ZUL4G9HNSA7CYU3WLPZMKLYEKFFJRSSP7UTJ"
|
|
|
|
|
],
|
|
|
|
|
"control_cbor": "a60070646174656b6579732d636f6e74726f6c0102025820d58f5020ab127df352927bba6186ec6708edb3e26234803ac76f082c2d10751f0358206cff50465e2f76ee0452d5f4ba9f942d54edbf8a6c42fb70f85cc75bc52d8e54064800000000000000290702",
|
|
|
|
|
"payload_identity": "6cff50465e2f76ee0452d5f4ba9f942d54edbf8a6c42fb70f85cc75bc52d8e54",
|
|
|
|
|
"payload_length": 41,
|
|
|
|
|
"padding": 2,
|
|
|
|
|
"padded_length": 256,
|
|
|
|
|
"plaintext_file": "format2_time_and_key_recipients.plaintext",
|
|
|
|
|
"plaintext_sha256": "0e9fd50e98a85953aa9cf07a11ee3c62bb3d7622f344f1c6ce744d1ed111659f",
|
|
|
|
|
"stages": [
|
|
|
|
|
{
|
|
|
|
|
"step": 1,
|
|
|
|
|
"name": "parse DKC1",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 2,
|
|
|
|
|
"name": "prelude",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 3,
|
|
|
|
|
"name": "public header",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 4,
|
|
|
|
|
"name": "header validation",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 5,
|
|
|
|
|
"name": "sealed control structure",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 6,
|
|
|
|
|
"name": "payload structure",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 7,
|
|
|
|
|
"name": "condition",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 8,
|
|
|
|
|
"name": "tlock stanza",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 9,
|
|
|
|
|
"name": "access credential",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 9,
|
|
|
|
|
"name": "release",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 10,
|
|
|
|
|
"name": "release verification",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 11,
|
|
|
|
|
"name": "open sealed control",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 12,
|
|
|
|
|
"name": "policy structure",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 13,
|
|
|
|
|
"name": "open access layer",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 14,
|
|
|
|
|
"name": "control",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 15,
|
|
|
|
|
"name": "header binding",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 16,
|
|
|
|
|
"name": "payload identity",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 17,
|
|
|
|
|
"name": "open payload",
|
|
|
|
|
"ok": true
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"step": 18,
|
|
|
|
|
"name": "commit",
|
|
|
|
|
"ok": true
|
|
|
|
|
}
|
|
|
|
|
]
|
|
|
|
|
}
|