You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
74 lines
2.5 KiB
74 lines
2.5 KiB
package testkit
|
|
|
|
import (
|
|
"crypto/sha256"
|
|
"encoding/hex"
|
|
|
|
bls "github.com/drand/kyber-bls12381"
|
|
"github.com/drand/kyber/encrypt/ibe"
|
|
)
|
|
|
|
// H2Len is the length of H2 in tlock: that of V, of W and of the file key it
|
|
// wraps (spec §63 step 11).
|
|
const H2Len = 16
|
|
|
|
// GTLen is the length of the serialization of an element of GT: twelve
|
|
// coordinates of Fp, 48 bytes each.
|
|
const GTLen = 576
|
|
|
|
// H2 is the H2 of the IBE-CCA of tlock (spec §63 step 11): SHA-256 of the
|
|
// tag IBE-H2 and the serialization of an element of GT, truncated to 16
|
|
// bytes. It restates the unexported gtToHash of drand/kyber encrypt/ibe, with
|
|
// its exported tag.
|
|
func H2(gt []byte) []byte {
|
|
h := sha256.New()
|
|
h.Write(ibe.H2Tag())
|
|
h.Write(gt)
|
|
return h.Sum(nil)[:H2Len]
|
|
}
|
|
|
|
// IBEVector is one vector of H2 (spec §63 step 11): two points, the
|
|
// serialization of their pairing and its H2.
|
|
type IBEVector struct {
|
|
Name string `json:"name"`
|
|
G1 string `json:"g1"` // a point of G1, compressed (spec §12.2)
|
|
G2 string `json:"g2"` // a point of G2, compressed (spec §12.2)
|
|
GT string `json:"gt"` // e(g1, g2), 576 bytes in the order of kilic/bls12-381
|
|
H2 string `json:"h2"` // H2(gt), 16 bytes
|
|
}
|
|
|
|
// IBEVectorFile is testdata/vectors/tlock_ibe.json.
|
|
type IBEVectorFile struct {
|
|
Spec string `json:"spec"`
|
|
Description string `json:"description"`
|
|
Vectors []IBEVector `json:"vectors"`
|
|
}
|
|
|
|
// IBEVectors computes the vectors of H2 with drand/kyber-bls12381, the
|
|
// pairing and the serialization of GT that tlock uses.
|
|
func IBEVectors() (IBEVectorFile, error) {
|
|
s := bls.NewBLS12381Suite()
|
|
g1, g2 := s.G1().Point().Base(), s.G2().Point().Base()
|
|
var enc [3][]byte
|
|
for i, m := range []interface{ MarshalBinary() ([]byte, error) }{g1, g2, s.Pair(g1, g2)} {
|
|
b, err := m.MarshalBinary()
|
|
if err != nil {
|
|
return IBEVectorFile{}, err
|
|
}
|
|
enc[i] = b
|
|
}
|
|
return IBEVectorFile{
|
|
Spec: SpecVersion,
|
|
Description: "H2 of the IBE-CCA of tlock (spec §63 step 11): SHA-256 of \"IBE-H2\" and the 576 bytes of an element of GT, " +
|
|
"c1 before c0 at every level of the tower and each coordinate of Fp in 48 bytes big-endian (the order of kilic/bls12-381), " +
|
|
"truncated to 16 bytes. Generated by the reference implementation with drand/kyber-bls12381, the pairing of tlock.",
|
|
Vectors: []IBEVector{{
|
|
Name: "H2(e(G1, G2)), the generators of G1 and G2",
|
|
G1: hex.EncodeToString(enc[0]),
|
|
G2: hex.EncodeToString(enc[1]),
|
|
GT: hex.EncodeToString(enc[2]),
|
|
H2: hex.EncodeToString(H2(enc[2])),
|
|
}},
|
|
}, nil
|
|
}
|