pub struct Secret<S: Suite> { /* private fields */ }Expand description
Secret key for VRF operations.
Contains the private scalar and cached public key.
Implements automatic zeroization on drop. The Debug output redacts
the scalar, and equality is evaluated in constant time.
Implementations§
Source§impl<S: Suite> Secret<S>
impl<S: Suite> Secret<S>
Sourcepub fn from_scalar(scalar: ScalarField<S>) -> Self
pub fn from_scalar(scalar: ScalarField<S>) -> Self
Construct a Secret from the given scalar.
Sourcepub fn from_seed(seed: [u8; 32]) -> Self
pub fn from_seed(seed: [u8; 32]) -> Self
Derives a Secret scalar deterministically from a seed.
The seed is hashed using the suite’s transcript, and the output is
reduced modulo the curve’s order to produce a valid scalar in the
range [1, n - 1]. No clamping or multiplication by the cofactor is
performed, regardless of the curve.
The caller is responsible for ensuring that the resulting scalar is used safely with respect to the target curve’s cofactor and subgroup properties.
Sourcepub fn from_rand(rng: &mut impl RngCore) -> Self
pub fn from_rand(rng: &mut impl RngCore) -> Self
Construct an ephemeral Secret using the provided randomness source.
Sourcepub fn scalar(&self) -> &ScalarField<S>
pub fn scalar(&self) -> &ScalarField<S>
Get the secret scalar.
Trait Implementations§
Source§impl<S: Suite> CanonicalDeserialize for Secret<S>
impl<S: Suite> CanonicalDeserialize for Secret<S>
Source§fn deserialize_with_mode<R: Read>(
reader: R,
compress: Compress,
validate: Validate,
) -> Result<Self, SerializationError>
fn deserialize_with_mode<R: Read>( reader: R, compress: Compress, validate: Validate, ) -> Result<Self, SerializationError>
Source§fn deserialize_compressed<R>(reader: R) -> Result<Self, SerializationError>where
R: Read,
fn deserialize_compressed<R>(reader: R) -> Result<Self, SerializationError>where
R: Read,
Self from reader using the compressed form if applicable.
Performs validation if applicable.Source§fn deserialize_compressed_unchecked<R>(
reader: R,
) -> Result<Self, SerializationError>where
R: Read,
fn deserialize_compressed_unchecked<R>(
reader: R,
) -> Result<Self, SerializationError>where
R: Read,
Self from reader using the compressed form if applicable, without validating the
deserialized value. Read moreSource§fn deserialize_uncompressed<R>(reader: R) -> Result<Self, SerializationError>where
R: Read,
fn deserialize_uncompressed<R>(reader: R) -> Result<Self, SerializationError>where
R: Read,
Self from reader using the uncompressed form. Performs validation if applicable.Source§fn deserialize_uncompressed_unchecked<R>(
reader: R,
) -> Result<Self, SerializationError>where
R: Read,
fn deserialize_uncompressed_unchecked<R>(
reader: R,
) -> Result<Self, SerializationError>where
R: Read,
Self from reader using the uncompressed form, without validating the deserialized
value. Read moreSource§impl<S: Suite> CanonicalSerialize for Secret<S>
impl<S: Suite> CanonicalSerialize for Secret<S>
Source§fn serialize_with_mode<W: Write>(
&self,
writer: W,
compress: Compress,
) -> Result<(), SerializationError>
fn serialize_with_mode<W: Write>( &self, writer: W, compress: Compress, ) -> Result<(), SerializationError>
Source§fn serialized_size(&self, compress: Compress) -> usize
fn serialized_size(&self, compress: Compress) -> usize
self with the given compression mode.Source§fn serialize_compressed<W>(&self, writer: W) -> Result<(), SerializationError>where
W: Write,
fn serialize_compressed<W>(&self, writer: W) -> Result<(), SerializationError>where
W: Write,
self into writer using the compressed form if applicable.Source§fn compressed_size(&self) -> usize
fn compressed_size(&self) -> usize
self.Source§fn serialize_uncompressed<W>(&self, writer: W) -> Result<(), SerializationError>where
W: Write,
fn serialize_uncompressed<W>(&self, writer: W) -> Result<(), SerializationError>where
W: Write,
self into writer using the uncompressed form.Source§fn uncompressed_size(&self) -> usize
fn uncompressed_size(&self) -> usize
self.Source§impl<S: PedersenSuite> Prover<S> for Secret<S>
impl<S: PedersenSuite> Prover<S> for Secret<S>
Source§impl<S: TinySuite> Prover<S> for Secret<S>
impl<S: TinySuite> Prover<S> for Secret<S>
Source§fn prove(&self, ios: impl AsRef<[VrfIo<S>]>, ad: impl AsRef<[u8]>) -> Proof<S>
fn prove(&self, ios: impl AsRef<[VrfIo<S>]>, ad: impl AsRef<[u8]>) -> Proof<S>
Tiny VRF proving algorithm.
Prepends the Schnorr pair (G, Y) to the I/O list and proves a single DLEQ on the delinearized merged pair:
- Generate a deterministic nonce
k - Compute nonce commitment
R = k * I_m - Compute the challenge
c - Compute the response
s = k + c * x
Source§impl<S: Suite> Valid for Secret<S>
impl<S: Suite> Valid for Secret<S>
Source§fn check(&self) -> Result<(), SerializationError>
fn check(&self) -> Result<(), SerializationError>
self is valid. If self is valid, returns Ok(()). Otherwise, returns
an error describing the failure.
This method is called by deserialize_with_mode if validate is Validate::Yes.Source§const TRIVIAL_CHECK: bool = false
const TRIVIAL_CHECK: bool = false
check method is trivial (i.e. always returns Ok(())). If this is true,
the batch_check method will skip all checks and return Ok(()).
This should be set to true for types where check is trivial, e.g.
integers, field elements, etc.
This is false by default.
This is primarily an optimization to skip unnecessary checks in batch_check.Source§fn batch_check<'a>(
batch: impl Iterator<Item = &'a Self> + Send,
) -> Result<(), SerializationError>where
Self: 'a,
fn batch_check<'a>(
batch: impl Iterator<Item = &'a Self> + Send,
) -> Result<(), SerializationError>where
Self: 'a,
batch are valid. If all items are valid, returns Ok(()).
Otherwise, returns an error describing the first failure.Auto Trait Implementations§
impl<S> Freeze for Secret<S>
impl<S> RefUnwindSafe for Secret<S>where
<<S as Suite>::Affine as AffineRepr>::ScalarField: RefUnwindSafe,
<S as Suite>::Affine: RefUnwindSafe,
impl<S> Send for Secret<S>
impl<S> Sync for Secret<S>
impl<S> Unpin for Secret<S>
impl<S> UnsafeUnpin for Secret<S>where
<<S as Suite>::Affine as AffineRepr>::ScalarField: UnsafeUnpin,
<S as Suite>::Affine: UnsafeUnpin,
impl<S> UnwindSafe for Secret<S>where
<<S as Suite>::Affine as AffineRepr>::ScalarField: UnwindSafe,
<S as Suite>::Affine: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CanonicalSerializeHashExt for Twhere
T: CanonicalSerialize,
impl<T> CanonicalSerializeHashExt for Twhere
T: CanonicalSerialize,
fn hash<H>(&self) -> GenericArray<u8, <H as OutputSizeUser>::OutputSize>where
H: Digest,
fn hash_uncompressed<H>(
&self,
) -> GenericArray<u8, <H as OutputSizeUser>::OutputSize>where
H: Digest,
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more