1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
use crate::{MessageGenerators, Signature, MAX_MSGS};
use blake2::Blake2b;
use bls12_381_plus::{G1Projective, Scalar};
use digest::Digest;
use ff::Field;
use group::Curve;
use hmac_drbg::HmacDRBG;
use serde::{Deserialize, Deserializer, Serialize, Serializer};
use signature_bls::SecretKey;
use signature_core::{error::Error, lib::*};
use subtle::CtOption;
use typenum::U64;
#[derive(Debug, Copy, Clone, PartialEq, Eq)]
pub struct BlindSignature {
pub(crate) a: G1Projective,
pub(crate) e: Scalar,
pub(crate) s: Scalar,
}
impl Serialize for BlindSignature {
fn serialize<S>(&self, s: S) -> Result<S::Ok, S::Error>
where
S: Serializer,
{
let sig = Signature {
a: self.a,
e: self.e,
s: self.s,
};
sig.serialize(s)
}
}
impl<'de> Deserialize<'de> for BlindSignature {
fn deserialize<D>(d: D) -> Result<BlindSignature, D::Error>
where
D: Deserializer<'de>,
{
let sig = Signature::deserialize(d)?;
Ok(Self {
a: sig.a,
e: sig.e,
s: sig.s,
})
}
}
impl BlindSignature {
pub const BYTES: usize = 112;
pub fn new(
commitment: Commitment,
sk: &SecretKey,
generators: &MessageGenerators,
msgs: &[(usize, Message)],
) -> Result<Self, Error> {
if generators.len() < msgs.len() {
return Err(Error::new(1, "not enough message generators"));
}
if sk.0.is_zero() {
return Err(Error::new(2, "invalid secret key"));
}
let mut hasher = Blake2b::new();
hasher.update(generators.h0.to_affine().to_uncompressed());
for i in 0..generators.len() {
hasher.update(generators.get(i).to_affine().to_uncompressed());
}
for (_, m) in msgs.iter() {
hasher.update(m.to_bytes())
}
let nonce = hasher.finalize();
let mut drbg = HmacDRBG::<Blake2b>::new(&sk.to_bytes()[..], &nonce[..], &[]);
let e = Scalar::from_bytes_wide(
&<[u8; 64]>::try_from(&drbg.generate::<U64>(Some(&[1u8]))[..]).unwrap(),
);
let s = Scalar::from_bytes_wide(
&<[u8; 64]>::try_from(&drbg.generate::<U64>(Some(&[2u8]))[..]).unwrap(),
);
let mut points = [G1Projective::identity(); MAX_MSGS];
let mut scalars = [Scalar::one(); MAX_MSGS];
points[0] = commitment.0;
points[1] = G1Projective::generator();
points[2] = generators.h0;
scalars[2] = s;
let mut i = 3;
for (idx, m) in msgs.iter() {
points[i] = generators.get(*idx);
scalars[i] = m.0;
i += 1;
}
let b = G1Projective::sum_of_products(&points[..i], &scalars[..i]);
let exp = (e + sk.0).invert().unwrap();
Ok(Self { a: b * exp, e, s })
}
pub fn to_unblinded(self, blinding: SignatureBlinding) -> Signature {
Signature {
a: self.a,
e: self.e,
s: self.s + blinding.0,
}
}
pub fn to_bytes(&self) -> [u8; Self::BYTES] {
let sig = Signature {
a: self.a,
e: self.e,
s: self.s,
};
sig.to_bytes()
}
pub fn from_bytes(data: &[u8; Self::BYTES]) -> CtOption<Self> {
Signature::from_bytes(data).map(|sig| Self {
a: sig.a,
e: sig.e,
s: sig.s,
})
}
}