You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
DateKeys/internal/testkit/ibe.go

74 lines
2.5 KiB

package testkit
import (
"crypto/sha256"
"encoding/hex"
bls "github.com/drand/kyber-bls12381"
"github.com/drand/kyber/encrypt/ibe"
)
// H2Len is the length of H2 in tlock: that of V, of W and of the file key it
// wraps (spec §63 step 11).
const H2Len = 16
// GTLen is the length of the serialization of an element of GT: twelve
// coordinates of Fp, 48 bytes each.
const GTLen = 576
// H2 is the H2 of the IBE-CCA of tlock (spec §63 step 11): SHA-256 of the
// tag IBE-H2 and the serialization of an element of GT, truncated to 16
// bytes. It restates the unexported gtToHash of drand/kyber encrypt/ibe, with
// its exported tag.
func H2(gt []byte) []byte {
h := sha256.New()
h.Write(ibe.H2Tag())
h.Write(gt)
return h.Sum(nil)[:H2Len]
}
// IBEVector is one vector of H2 (spec §63 step 11): two points, the
// serialization of their pairing and its H2.
type IBEVector struct {
Name string `json:"name"`
G1 string `json:"g1"` // a point of G1, compressed (spec §12.2)
G2 string `json:"g2"` // a point of G2, compressed (spec §12.2)
GT string `json:"gt"` // e(g1, g2), 576 bytes in the order of kilic/bls12-381
H2 string `json:"h2"` // H2(gt), 16 bytes
}
// IBEVectorFile is testdata/vectors/tlock_ibe.json.
type IBEVectorFile struct {
Spec string `json:"spec"`
Description string `json:"description"`
Vectors []IBEVector `json:"vectors"`
}
// IBEVectors computes the vectors of H2 with drand/kyber-bls12381, the
// pairing and the serialization of GT that tlock uses.
func IBEVectors() (IBEVectorFile, error) {
s := bls.NewBLS12381Suite()
g1, g2 := s.G1().Point().Base(), s.G2().Point().Base()
var enc [3][]byte
for i, m := range []interface{ MarshalBinary() ([]byte, error) }{g1, g2, s.Pair(g1, g2)} {
b, err := m.MarshalBinary()
if err != nil {
return IBEVectorFile{}, err
}
enc[i] = b
}
return IBEVectorFile{
Spec: SpecVersion,
Description: "H2 of the IBE-CCA of tlock (spec §63 step 11): SHA-256 of \"IBE-H2\" and the 576 bytes of an element of GT, " +
"c1 before c0 at every level of the tower and each coordinate of Fp in 48 bytes big-endian (the order of kilic/bls12-381), " +
"truncated to 16 bytes. Generated by the reference implementation with drand/kyber-bls12381, the pairing of tlock.",
Vectors: []IBEVector{{
Name: "H2(e(G1, G2)), the generators of G1 and G2",
G1: hex.EncodeToString(enc[0]),
G2: hex.EncodeToString(enc[1]),
GT: hex.EncodeToString(enc[2]),
H2: hex.EncodeToString(H2(enc[2])),
}},
}, nil
}

Powered by TurnKey Linux.