pub struct DLogProof<C: DklsCurve> {
pub point: C::AffinePoint,
pub rand_commitments: Vec<C::AffinePoint>,
pub proofs: Vec<InteractiveDLogProof<C>>,
}Expand description
Schnorr’s protocol (non-interactive via randomized Fischlin transform).
In order to remove interaction, we employ the “randomized Fischlin transform” described in Figure 9 of https://eprint.iacr.org/2022/393.pdf. However, we will follow the approach in Figure 27 of https://eprint.iacr.org/2022/1525.pdf. It seems to come from Section 5.1 of the first paper.
There are some errors in this description (for example, xi_i and xi_{i+r/2}
are always the empty set), and thus we adapt Figure 9 of the first article. There is
still a problem: the paper says to choose r and l such that, in particular, rl = 2^lambda.
If lambda = 256, then r or l are astronomically large and the protocol becomes
computationally infeasible. We will use instead the condition rl = lambda.
We believe this is what the authors wanted, since this condition appears
in most of the rest of the first paper.
With lambda = 256, we chose r = 64 and l = 4 (higher values of l were too slow).
In this case, the constant t from the paper is equal to 32.
Fields§
§point: C::AffinePoint§rand_commitments: Vec<C::AffinePoint>§proofs: Vec<InteractiveDLogProof<C>>Implementations§
Source§impl<C: DklsCurve> DLogProof<C>
impl<C: DklsCurve> DLogProof<C>
Sourcepub fn prove(
scalar: &C::Scalar,
session_id: &[u8],
) -> Result<DLogProof<C>, ProofSearchExhausted>
pub fn prove( scalar: &C::Scalar, session_id: &[u8], ) -> Result<DLogProof<C>, ProofSearchExhausted>
Computes a proof for the witness scalar.
Returns an error if the Fischlin proof-of-work search is exhausted without finding all required hash collisions. This is astronomically unlikely with a correct RNG but must not be silently ignored.
Sourcepub fn verify(proof: &DLogProof<C>, session_id: &[u8]) -> bool
pub fn verify(proof: &DLogProof<C>, session_id: &[u8]) -> bool
Verification of a proof of discrete logarithm.
Note that the point to be verified is in proof.
Sourcepub fn prove_commit(
scalar: &C::Scalar,
session_id: &[u8],
) -> Result<(DLogProof<C>, HashOutput), ProofSearchExhausted>
pub fn prove_commit( scalar: &C::Scalar, session_id: &[u8], ) -> Result<(DLogProof<C>, HashOutput), ProofSearchExhausted>
Produces an instance of DLogProof (for the witness scalar)
together with a commitment (its hash).
The commitment is transmitted first and the proof is sent later when needed. Computes a proof with a commitment, propagating proof generation errors.
Sourcepub fn decommit_verify(
proof: &DLogProof<C>,
commitment: &HashOutput,
session_id: &[u8],
) -> bool
pub fn decommit_verify( proof: &DLogProof<C>, commitment: &HashOutput, session_id: &[u8], ) -> bool
Verifies a proof and checks it against the commitment.
Trait Implementations§
Source§impl<'de, C: DklsCurve> Deserialize<'de> for DLogProof<C>
impl<'de, C: DklsCurve> Deserialize<'de> for DLogProof<C>
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Auto Trait Implementations§
impl<C> Freeze for DLogProof<C>where
<C as CurveArithmetic>::ProjectivePoint: Sized,
<C as CurveArithmetic>::Scalar: Sized,
<C as CurveArithmetic>::AffinePoint: Sized + Freeze,
impl<C> RefUnwindSafe for DLogProof<C>where
<C as CurveArithmetic>::ProjectivePoint: Sized,
<C as CurveArithmetic>::Scalar: Sized + RefUnwindSafe,
<C as CurveArithmetic>::AffinePoint: Sized + RefUnwindSafe,
C: RefUnwindSafe,
impl<C> Send for DLogProof<C>where
<C as CurveArithmetic>::ProjectivePoint: Sized,
<C as CurveArithmetic>::Scalar: Sized,
<C as CurveArithmetic>::AffinePoint: Sized,
impl<C> Sync for DLogProof<C>where
<C as CurveArithmetic>::ProjectivePoint: Sized,
<C as CurveArithmetic>::Scalar: Sized,
<C as CurveArithmetic>::AffinePoint: Sized,
impl<C> Unpin for DLogProof<C>where
<C as CurveArithmetic>::ProjectivePoint: Sized,
<C as CurveArithmetic>::Scalar: Sized + Unpin,
<C as CurveArithmetic>::AffinePoint: Sized + Unpin,
C: Unpin,
impl<C> UnsafeUnpin for DLogProof<C>where
<C as CurveArithmetic>::ProjectivePoint: Sized,
<C as CurveArithmetic>::Scalar: Sized,
<C as CurveArithmetic>::AffinePoint: Sized + UnsafeUnpin,
impl<C> UnwindSafe for DLogProof<C>where
<C as CurveArithmetic>::ProjectivePoint: Sized,
<C as CurveArithmetic>::Scalar: Sized + UnwindSafe,
<C as CurveArithmetic>::AffinePoint: Sized + UnwindSafe,
C: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.