-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
pairing: Adds support for BLS12381 using CIRCL library #49
Changes from 2 commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,48 @@ | ||
package bls12381 | ||
|
||
import ( | ||
"github.com/drand/kyber" | ||
) | ||
|
||
// SuiteBLS12381 is an adapter that implements the suites.Suite interface so that | ||
// bls12381 can be used as a common suite to generate key pairs for instance but | ||
// still preserves the properties of the pairing (e.g. the Pair function). | ||
// | ||
// It's important to note that the Point function will generate a point | ||
// compatible with public keys only (group G2) where the signature must be | ||
// used as a point from the group G1. | ||
type SuiteBLS12381 struct { | ||
Suite | ||
kyber.Group | ||
} | ||
|
||
// NewSuiteBLS12381 makes a new BN256 suite | ||
func NewSuiteBLS12381() *SuiteBLS12381 { | ||
return &SuiteBLS12381{} | ||
} | ||
|
||
// Point generates a point from the G2 group that can only be used | ||
// for public keys | ||
func (s *SuiteBLS12381) Point() kyber.Point { | ||
return s.G2().Point() | ||
} | ||
|
||
// PointLen returns the length of a G2 point | ||
func (s *SuiteBLS12381) PointLen() int { | ||
return s.G2().PointLen() | ||
} | ||
|
||
// Scalar generates a scalar | ||
func (s *SuiteBLS12381) Scalar() kyber.Scalar { | ||
return s.G1().Scalar() | ||
} | ||
|
||
// ScalarLen returns the lenght of a scalar | ||
func (s *SuiteBLS12381) ScalarLen() int { | ||
return s.G1().ScalarLen() | ||
} | ||
|
||
// String returns the name of the suite | ||
func (s *SuiteBLS12381) String() string { | ||
return "bls12381.adapter" | ||
} |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,28 @@ | ||
package bls12381 | ||
|
||
import ( | ||
"testing" | ||
|
||
"github.com/drand/kyber/util/key" | ||
"github.com/stretchr/testify/require" | ||
) | ||
|
||
func TestAdapter_SuiteBLS12381(t *testing.T) { | ||
suite := NewSuiteBLS12381() | ||
|
||
pair := key.NewKeyPair(suite) | ||
pubkey, err := pair.Public.MarshalBinary() | ||
require.Nil(t, err) | ||
privkey, err := pair.Private.MarshalBinary() | ||
require.Nil(t, err) | ||
|
||
pubhex := suite.Point() | ||
err = pubhex.UnmarshalBinary(pubkey) | ||
require.Nil(t, err) | ||
|
||
privhex := suite.Scalar() | ||
err = privhex.UnmarshalBinary(privkey) | ||
require.Nil(t, err) | ||
|
||
require.Equal(t, "bls12381.adapter", suite.String()) | ||
} |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,95 @@ | ||
package bls12381 | ||
|
||
import ( | ||
"crypto/cipher" | ||
"io" | ||
|
||
circl "github.com/cloudflare/circl/ecc/bls12381" | ||
"github.com/drand/kyber" | ||
) | ||
|
||
var _ kyber.SubGroupElement = &G1Elt{} | ||
|
||
type G1Elt struct{ inner circl.G1 } | ||
|
||
func (p *G1Elt) MarshalBinary() (data []byte, err error) { return p.inner.BytesCompressed(), nil } | ||
|
||
func (p *G1Elt) UnmarshalBinary(data []byte) error { return p.inner.SetBytes(data) } | ||
|
||
func (p *G1Elt) String() string { return p.inner.String() } | ||
|
||
func (p *G1Elt) MarshalSize() int { return circl.G1SizeCompressed } | ||
|
||
func (p *G1Elt) MarshalTo(w io.Writer) (int, error) { | ||
buf, err := p.MarshalBinary() | ||
if err != nil { | ||
return 0, err | ||
} | ||
return w.Write(buf) | ||
} | ||
|
||
func (p *G1Elt) UnmarshalFrom(r io.Reader) (int, error) { | ||
buf := make([]byte, p.MarshalSize()) | ||
n, err := io.ReadFull(r, buf) | ||
if err != nil { | ||
return n, err | ||
} | ||
return n, p.UnmarshalBinary(buf) | ||
} | ||
|
||
func (p *G1Elt) Equal(p2 kyber.Point) bool { x := p2.(*G1Elt); return p.inner.IsEqual(&x.inner) } | ||
|
||
func (p *G1Elt) Null() kyber.Point { p.inner.SetIdentity(); return p } | ||
|
||
func (p *G1Elt) Base() kyber.Point { p.inner = *circl.G1Generator(); return p } | ||
|
||
func (p *G1Elt) Pick(rand cipher.Stream) kyber.Point { | ||
var buf [32]byte | ||
rand.XORKeyStream(buf[:], buf[:]) | ||
p.inner.Hash(buf[:], nil) | ||
return p | ||
} | ||
|
||
func (p *G1Elt) Set(p2 kyber.Point) kyber.Point { p.inner = p2.(*G1Elt).inner; return p } | ||
|
||
func (p *G1Elt) Clone() kyber.Point { return new(G1Elt).Set(p) } | ||
|
||
func (p *G1Elt) EmbedLen() int { | ||
panic("bls12-381: unsupported operation") | ||
} | ||
|
||
func (p *G1Elt) Embed(data []byte, r cipher.Stream) kyber.Point { | ||
panic("bls12-381: unsupported operation") | ||
} | ||
|
||
func (p *G1Elt) Data() ([]byte, error) { | ||
panic("bls12-381: unsupported operation") | ||
} | ||
|
||
func (p *G1Elt) Add(a, b kyber.Point) kyber.Point { | ||
aa, bb := a.(*G1Elt), b.(*G1Elt) | ||
p.inner.Add(&aa.inner, &bb.inner) | ||
return p | ||
} | ||
|
||
func (p *G1Elt) Sub(a, b kyber.Point) kyber.Point { return p.Add(a, new(G1Elt).Neg(b)) } | ||
|
||
func (p *G1Elt) Neg(a kyber.Point) kyber.Point { | ||
p.Set(a) | ||
p.inner.Neg() | ||
return p | ||
} | ||
|
||
func (p *G1Elt) Mul(s kyber.Scalar, q kyber.Point) kyber.Point { | ||
if q == nil { | ||
q = new(G1Elt).Base() | ||
} | ||
ss, qq := s.(*Scalar), q.(*G1Elt) | ||
p.inner.ScalarMult(&ss.inner, &qq.inner) | ||
return p | ||
} | ||
|
||
func (p *G1Elt) IsInCorrectGroup() bool { return p.inner.IsOnG1() } | ||
|
||
func (p *G1Elt) Hash(msg []byte) kyber.Point { p.inner.Hash(msg, nil); return p } | ||
func (p *G1Elt) Hash2(msg, dst []byte) kyber.Point { p.inner.Hash(msg, dst); return p } | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. If we want to make that generic, could we put the "dst" as a field in the struct, to avoid having multiple hash functions ? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Once #50 get fixed, there will be only one (correct) API for hashes. |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,95 @@ | ||
package bls12381 | ||
|
||
import ( | ||
"crypto/cipher" | ||
"io" | ||
|
||
circl "github.com/cloudflare/circl/ecc/bls12381" | ||
"github.com/drand/kyber" | ||
) | ||
|
||
var _ kyber.SubGroupElement = &G2Elt{} | ||
|
||
type G2Elt struct{ inner circl.G2 } | ||
|
||
func (p *G2Elt) MarshalBinary() (data []byte, err error) { return p.inner.BytesCompressed(), nil } | ||
|
||
func (p *G2Elt) UnmarshalBinary(data []byte) error { return p.inner.SetBytes(data) } | ||
|
||
func (p *G2Elt) String() string { return p.inner.String() } | ||
|
||
func (p *G2Elt) MarshalSize() int { return circl.G2SizeCompressed } | ||
|
||
func (p *G2Elt) MarshalTo(w io.Writer) (int, error) { | ||
buf, err := p.MarshalBinary() | ||
if err != nil { | ||
return 0, err | ||
} | ||
return w.Write(buf) | ||
} | ||
|
||
func (p *G2Elt) UnmarshalFrom(r io.Reader) (int, error) { | ||
buf := make([]byte, p.MarshalSize()) | ||
n, err := io.ReadFull(r, buf) | ||
if err != nil { | ||
return n, err | ||
} | ||
return n, p.UnmarshalBinary(buf) | ||
} | ||
|
||
func (p *G2Elt) Equal(p2 kyber.Point) bool { x := p2.(*G2Elt); return p.inner.IsEqual(&x.inner) } | ||
|
||
func (p *G2Elt) Null() kyber.Point { p.inner.SetIdentity(); return p } | ||
|
||
func (p *G2Elt) Base() kyber.Point { p.inner = *circl.G2Generator(); return p } | ||
|
||
func (p *G2Elt) Pick(rand cipher.Stream) kyber.Point { | ||
var buf [32]byte | ||
rand.XORKeyStream(buf[:], buf[:]) | ||
p.inner.Hash(buf[:], nil) | ||
return p | ||
} | ||
|
||
func (p *G2Elt) Set(p2 kyber.Point) kyber.Point { p.inner = p2.(*G2Elt).inner; return p } | ||
|
||
func (p *G2Elt) Clone() kyber.Point { return new(G2Elt).Set(p) } | ||
|
||
func (p *G2Elt) EmbedLen() int { | ||
panic("bls12-381: unsupported operation") | ||
} | ||
|
||
func (p *G2Elt) Embed(data []byte, r cipher.Stream) kyber.Point { | ||
panic("bls12-381: unsupported operation") | ||
} | ||
|
||
func (p *G2Elt) Data() ([]byte, error) { | ||
panic("bls12-381: unsupported operation") | ||
} | ||
|
||
func (p *G2Elt) Add(a, b kyber.Point) kyber.Point { | ||
aa, bb := a.(*G2Elt), b.(*G2Elt) | ||
p.inner.Add(&aa.inner, &bb.inner) | ||
return p | ||
} | ||
|
||
func (p *G2Elt) Sub(a, b kyber.Point) kyber.Point { return p.Add(a, new(G2Elt).Neg(b)) } | ||
|
||
func (p *G2Elt) Neg(a kyber.Point) kyber.Point { | ||
p.Set(a) | ||
p.inner.Neg() | ||
return p | ||
} | ||
|
||
func (p *G2Elt) Mul(s kyber.Scalar, q kyber.Point) kyber.Point { | ||
if q == nil { | ||
q = new(G2Elt).Base() | ||
} | ||
ss, qq := s.(*Scalar), q.(*G2Elt) | ||
p.inner.ScalarMult(&ss.inner, &qq.inner) | ||
return p | ||
} | ||
|
||
func (p *G2Elt) IsInCorrectGroup() bool { return p.inner.IsOnG2() } | ||
|
||
func (p *G2Elt) Hash(msg []byte) kyber.Point { p.inner.Hash(msg, nil); return p } | ||
func (p *G2Elt) Hash2(msg, dst []byte) kyber.Point { p.inner.Hash(msg, dst); return p } |
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,23 @@ | ||
package bls12381 | ||
|
||
import ( | ||
circl "github.com/cloudflare/circl/ecc/bls12381" | ||
"github.com/drand/kyber" | ||
) | ||
|
||
var ( | ||
G1 kyber.Group = &groupBls{name: "bls12-381.G1", newPoint: func() kyber.Point { return new(G1Elt).Null() }} | ||
G2 kyber.Group = &groupBls{name: "bls12-381.G2", newPoint: func() kyber.Point { return new(G2Elt).Null() }} | ||
GT kyber.Group = &groupBls{name: "bls12-381.GT", newPoint: func() kyber.Point { return new(GTElt).Null() }} | ||
) | ||
|
||
type groupBls struct { | ||
name string | ||
newPoint func() kyber.Point | ||
} | ||
|
||
func (g groupBls) String() string { return g.name } | ||
func (g groupBls) ScalarLen() int { return circl.ScalarSize } | ||
func (g groupBls) Scalar() kyber.Scalar { return new(Scalar).SetInt64(0) } | ||
func (g groupBls) PointLen() int { return g.newPoint().MarshalSize() } | ||
func (g groupBls) Point() kyber.Point { return g.newPoint() } |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm confused by the need for this struct - why do you have it ? Why not just "Suite" is enough ?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
it is enough, I was just mimicking what is already done in the other pairing package.