1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
use super::{dlog_group::EcPoint, FirstProverMessage, ProverMessage};
use crate::serialization::SigmaSerializable;
use k256::Scalar;
#[derive(PartialEq, Eq, Debug, Clone)]
pub struct FirstDlogProverMessage(pub EcPoint);
impl From<EcPoint> for FirstDlogProverMessage {
fn from(ecp: EcPoint) -> Self {
FirstDlogProverMessage(ecp)
}
}
impl ProverMessage for FirstDlogProverMessage {
fn bytes(&self) -> Vec<u8> {
self.0.sigma_serialize_bytes()
}
}
impl From<FirstDlogProverMessage> for FirstProverMessage {
fn from(v: FirstDlogProverMessage) -> Self {
FirstProverMessage::FirstDlogProverMessage(v)
}
}
#[derive(PartialEq, Debug, Clone)]
pub struct SecondDlogProverMessage {
pub z: Scalar,
}
impl From<Scalar> for SecondDlogProverMessage {
fn from(z: Scalar) -> Self {
SecondDlogProverMessage { z }
}
}
pub mod interactive_prover {
use super::{FirstDlogProverMessage, SecondDlogProverMessage};
use crate::sigma_protocol::{dlog_group, Challenge, DlogProverInput, ProveDlog};
use dlog_group::EcPoint;
use k256::Scalar;
pub fn simulate(
_public_input: &ProveDlog,
_challenge: &Challenge,
) -> (FirstDlogProverMessage, SecondDlogProverMessage) {
todo!()
}
pub fn first_message() -> (Scalar, FirstDlogProverMessage) {
let r = dlog_group::random_scalar_in_group_range();
let g = dlog_group::generator();
let a = dlog_group::exponentiate(&g, &r);
(r, FirstDlogProverMessage(a))
}
pub fn second_message(
private_input: &DlogProverInput,
rnd: Scalar,
challenge: &Challenge,
) -> SecondDlogProverMessage {
let e: Scalar = challenge.clone().into();
let ew = e.mul(&private_input.w);
let z = rnd.add(&ew);
z.into()
}
pub fn compute_commitment(
proposition: &ProveDlog,
challenge: &Challenge,
second_message: &SecondDlogProverMessage,
) -> EcPoint {
let g = dlog_group::generator();
let h = *proposition.h.clone();
let e: Scalar = challenge.clone().into();
let g_z = dlog_group::exponentiate(&g, &second_message.z);
let h_e = dlog_group::exponentiate(&h, &e);
g_z * &dlog_group::inverse(&h_e)
}
}
#[cfg(test)]
mod tests {
use super::super::*;
use super::*;
use crate::sigma_protocol::DlogProverInput;
use proptest::prelude::*;
proptest! {
#![proptest_config(ProptestConfig::with_cases(16))]
#[test]
fn test_compute_commitment(secret in any::<DlogProverInput>(), challenge in any::<Challenge>()) {
let pk = secret.public_image();
let (r, commitment) = interactive_prover::first_message();
let second_message = interactive_prover::second_message(&secret, r, &challenge);
let a = interactive_prover::compute_commitment(&pk, &challenge, &second_message);
prop_assert_eq!(a, commitment.0);
}
}
}