Skip to main content

Secret

Struct Secret 

Source
pub struct Secret<S: Suite> { /* private fields */ }
Expand description

Secret key for VRF operations.

Contains the private scalar and cached public key. Implements automatic zeroization on drop. The Debug output redacts the scalar, and equality is evaluated in constant time.

Implementations§

Source§

impl<S: Suite> Secret<S>

Source

pub fn from_scalar(scalar: ScalarField<S>) -> Self

Construct a Secret from the given scalar.

Source

pub fn from_seed(seed: [u8; 32]) -> Self

Derives a Secret scalar deterministically from a seed.

The seed is hashed using the suite’s transcript, and the output is reduced modulo the curve’s order to produce a valid scalar in the range [1, n - 1]. No clamping or multiplication by the cofactor is performed, regardless of the curve.

The caller is responsible for ensuring that the resulting scalar is used safely with respect to the target curve’s cofactor and subgroup properties.

Source

pub fn from_rand(rng: &mut impl RngCore) -> Self

Construct an ephemeral Secret using the provided randomness source.

Source

pub fn scalar(&self) -> &ScalarField<S>

Get the secret scalar.

Source

pub fn public(&self) -> Public<S>

Get the associated public key.

Source

pub fn output(&self, input: Input<S>) -> Output<S>

Get the VRF output point relative to input.

Source

pub fn vrf_io(&self, input: Input<S>) -> VrfIo<S>

Get the VRF input-output pair relative to input.

Trait Implementations§

Source§

impl<S: Suite> CanonicalDeserialize for Secret<S>

Source§

fn deserialize_with_mode<R: Read>( reader: R, compress: Compress, validate: Validate, ) -> Result<Self, SerializationError>

The general deserialize method that takes in customization flags.
Source§

fn deserialize_compressed<R>(reader: R) -> Result<Self, SerializationError>
where R: Read,

Reads Self from reader using the compressed form if applicable. Performs validation if applicable.
Source§

fn deserialize_compressed_unchecked<R>( reader: R, ) -> Result<Self, SerializationError>
where R: Read,

Reads Self from reader using the compressed form if applicable, without validating the deserialized value. Read more
Source§

fn deserialize_uncompressed<R>(reader: R) -> Result<Self, SerializationError>
where R: Read,

Reads Self from reader using the uncompressed form. Performs validation if applicable.
Source§

fn deserialize_uncompressed_unchecked<R>( reader: R, ) -> Result<Self, SerializationError>
where R: Read,

Reads Self from reader using the uncompressed form, without validating the deserialized value. Read more
Source§

impl<S: Suite> CanonicalSerialize for Secret<S>

Source§

fn serialize_with_mode<W: Write>( &self, writer: W, compress: Compress, ) -> Result<(), SerializationError>

The general serialize method that takes in customization flags.
Source§

fn serialized_size(&self, compress: Compress) -> usize

Returns the size in bytes of the serialized version of self with the given compression mode.
Source§

fn serialize_compressed<W>(&self, writer: W) -> Result<(), SerializationError>
where W: Write,

Serializes self into writer using the compressed form if applicable.
Source§

fn compressed_size(&self) -> usize

Returns the size in bytes of the compressed serialized version of self.
Source§

fn serialize_uncompressed<W>(&self, writer: W) -> Result<(), SerializationError>
where W: Write,

Serializes self into writer using the uncompressed form.
Source§

fn uncompressed_size(&self) -> usize

Returns the size in bytes of the uncompressed serialized version of self.
Source§

impl<S: Clone + Suite> Clone for Secret<S>

Source§

fn clone(&self) -> Secret<S>

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<S: Suite> Debug for Secret<S>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<S: Suite> Drop for Secret<S>

Source§

fn drop(&mut self)

Executes the destructor for this type. Read more
Source§

fn pin_drop(self: Pin<&mut Self>)

🔬This is a nightly-only experimental API. (pin_ergonomics)
Execute the destructor for this type, but different to Drop::drop, it requires self to be pinned. Read more
Source§

impl<S: Suite> PartialEq for Secret<S>

Source§

fn eq(&self, other: &Self) -> bool

Timing does not depend on the scalars content or on where they differ.

1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl<S: PedersenSuite> Prover<S> for Secret<S>

Source§

fn prove( &self, ios: impl AsRef<[VrfIo<S>]>, ad: impl AsRef<[u8]>, ) -> (Proof<S>, ScalarField<S>)

Generate a proof for the given VRF I/O pairs and additional data. Read more
Source§

impl<S: ThinSuite> Prover<S> for Secret<S>

Source§

fn prove(&self, ios: impl AsRef<[VrfIo<S>]>, ad: impl AsRef<[u8]>) -> Proof<S>

Generate a proof for the given VRF I/O pairs and additional data. Read more
Source§

impl<S: TinySuite> Prover<S> for Secret<S>

Source§

fn prove(&self, ios: impl AsRef<[VrfIo<S>]>, ad: impl AsRef<[u8]>) -> Proof<S>

Tiny VRF proving algorithm.

Prepends the Schnorr pair (G, Y) to the I/O list and proves a single DLEQ on the delinearized merged pair:

  1. Generate a deterministic nonce k
  2. Compute nonce commitment R = k * I_m
  3. Compute the challenge c
  4. Compute the response s = k + c * x
Source§

impl<S: RingSuite> Prover<S> for Secret<S>

Source§

fn prove( &self, ios: impl AsRef<[VrfIo<S>]>, ad: impl AsRef<[u8]>, ring_prover: &RingProver<S>, ) -> Proof<S>

Generate a proof for the given VRF I/O pairs and additional data. Read more
Source§

impl<S: Suite> Valid for Secret<S>

Source§

fn check(&self) -> Result<(), SerializationError>

Checks whether self is valid. If self is valid, returns Ok(()). Otherwise, returns an error describing the failure. This method is called by deserialize_with_mode if validate is Validate::Yes.
Source§

const TRIVIAL_CHECK: bool = false

Whether the check method is trivial (i.e. always returns Ok(())). If this is true, the batch_check method will skip all checks and return Ok(()). This should be set to true for types where check is trivial, e.g. integers, field elements, etc. This is false by default. This is primarily an optimization to skip unnecessary checks in batch_check.
Source§

fn batch_check<'a>( batch: impl Iterator<Item = &'a Self> + Send, ) -> Result<(), SerializationError>
where Self: 'a,

Checks whether all items in batch are valid. If all items are valid, returns Ok(()). Otherwise, returns an error describing the first failure.

Auto Trait Implementations§

§

impl<S> Freeze for Secret<S>
where <<S as Suite>::Affine as AffineRepr>::ScalarField: Freeze, <S as Suite>::Affine: Freeze,

§

impl<S> RefUnwindSafe for Secret<S>

§

impl<S> Send for Secret<S>

§

impl<S> Sync for Secret<S>

§

impl<S> Unpin for Secret<S>
where <<S as Suite>::Affine as AffineRepr>::ScalarField: Unpin, <S as Suite>::Affine: Unpin,

§

impl<S> UnsafeUnpin for Secret<S>

§

impl<S> UnwindSafe for Secret<S>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CanonicalSerializeHashExt for T

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V