miden_crypto/hash/eidos/
domains.rs1use super::domain::{ByteString, Custom, DomainVersion, FeltSequence, namespace};
7
8crate::eidos_domain_registry! {
9 pub registry MidenCryptoDomainRegistry {
11 namespace: namespace::MIDEN_CRYPTO;
12 domains: {
13 pub SMT_BUCKET_LEAF: SmtBucketLeafDomain {
14 local_id: 0x0001,
15 version: DomainVersion::numbered(1),
16 encoding: Custom,
17 description: "Reserved domain for sparse Merkle tree bucket-leaf commitments.",
18 schema: "param0 = number of entries; param1 = 0; param2 = 0; payload = sorted key/value pairs",
19 }
20 pub MMR_PEAKS: MmrPeaksDomain {
21 local_id: 0x0002,
22 version: DomainVersion::numbered(1),
23 encoding: Custom,
24 description: "Reserved domain for Merkle mountain range peak commitments.",
25 schema: "param0/param1 = low/high u32 limbs of num_leaves; param2 = 0; payload = canonical padded peak vector",
26 }
27 pub GENERIC_BYTE_STRING: GenericByteStringDomain {
28 local_id: 0x0003,
29 version: DomainVersion::numbered(1),
30 encoding: ByteString,
31 description: "Generic exact-length byte string.",
32 schema: "param0 = number of bytes; param1 = 0; param2 = 0; zero-pad one final 64-byte block",
33 }
34 pub FALCON_HASH_TO_POINT: FalconHashToPointDomain {
35 local_id: 0x0004,
36 version: DomainVersion::numbered(1),
37 encoding: Custom,
38 description: "Falcon512-Eidos hash-to-point construction.",
39 schema: "params = [0, 0, 0]; absorb the eight-Felt nonce, then the four-Felt message padded with four zeros; repeat 128 times: compress an all-zero block, continue the chain from the Eidos CV without Falcon-field reduction, and emit its four Felts reduced modulo 12289 in order; 2^63 mod 12289 = 2832",
40 }
41 pub FALCON_PUBLIC_KEY: FalconPublicKeyDomain {
42 local_id: 0x0005,
43 version: DomainVersion::numbered(1),
44 encoding: FeltSequence,
45 description: "Falcon512-Eidos public-key commitment.",
46 schema: "param0 = coefficient count; param1 = 0; param2 = 0; payload = 512 Falcon public-key coefficients",
47 }
48 pub AEAD_CTR_KEY: AeadCtrKeyDomain {
49 local_id: 0x0006,
50 version: DomainVersion::numbered(1),
51 encoding: Custom,
52 description: "Eidos AEAD counter-mode key derivation.",
53 schema: "params = [0, 0, 0]; one fixed key || nonce block",
54 }
55 pub AEAD_MAC_KEY: AeadMacKeyDomain {
56 local_id: 0x0007,
57 version: DomainVersion::numbered(1),
58 encoding: Custom,
59 description: "Eidos AEAD polynomial-MAC key derivation.",
60 schema: "params = [0, 0, 0]; one fixed key || nonce block",
61 }
62 pub RANDOM_COIN_STATE: RandomCoinStateDomain {
63 local_id: 0x0008,
64 version: DomainVersion::numbered(1),
65 encoding: FeltSequence,
66 description: "Eidos random-coin state derivation and reseeding.",
67 schema: "param0 = 4 for initialization or 10 for reseeding; param1 = 0; param2 = 0; initialization payload = four-Felt seed; reseed payload = four-Felt coin state, low/high u32 next-block-counter limbs, and four-Felt reseed data",
68 }
69 pub RANDOM_COIN_OUTPUT: RandomCoinOutputDomain {
70 local_id: 0x0009,
71 version: DomainVersion::numbered(1),
72 encoding: FeltSequence,
73 description: "Eidos random-coin counter-mode output generation.",
74 schema: "param0 = 6; param1 = 0; param2 = 0; payload = four-Felt coin state followed by low/high u32 next-block-counter limbs",
75 }
76 pub GENERIC_FELT_SEQUENCE: GenericFeltSequenceDomain {
77 local_id: 0x000a,
78 version: DomainVersion::numbered(1),
79 encoding: FeltSequence,
80 description: "Generic exact-length sequence of Goldilocks field elements.",
81 schema: "param0 = number of Felts; param1 = 0; param2 = 0; zero-pad one final block",
82 }
83 pub LMCS_LEAF: LmcsLeafDomain {
84 local_id: 0x000b,
85 version: DomainVersion::numbered(1),
86 encoding: Custom,
87 description: "Canonical Eidos LMCS leaf hashing.",
88 schema: "param0 = sum of matrix-row and salt widths after each is independently padded to 8 Felts; param1 = 0; param2 = 0; absorb rows in commitment order; the verifier fixes the row boundaries and widths",
89 }
90 }
91 }
92}