1use hkdf::Hkdf;
26use nostr_sdk::prelude::nip44::v2::ConversationKey;
27use nostr_sdk::prelude::{Keys, PublicKey, SecretKey};
28use sha2::{Digest, Sha256};
29
30use super::super::{ChannelId, CommunityId, Epoch};
31
32const LABEL_CHANNEL: &str = "concord/channel";
34const LABEL_CONTROL: &str = "concord/control";
35const LABEL_REKEY_PSEUDONYM: &str = "concord/rekey-pseudonym";
36const LABEL_BASE_REKEY_PSEUDONYM: &str = "concord/base-rekey-pseudonym";
37const LABEL_RECIPIENT_PSEUDONYM: &str = "concord/recipient-pseudonym";
38const LABEL_GUESTBOOK: &str = "concord/guestbook";
39const LABEL_VOICE_SIGNER: &str = "concord/voice-signer";
40const LABEL_VOICE_MEDIA: &str = "concord/voice-media";
41const LABEL_VOICE_SENDER: &str = "concord/voice-sender";
42const LABEL_DISSOLVED: &str = "concord/dissolved";
43const LABEL_GRANT: &str = "concord/grant";
44const LABEL_BANLIST: &str = "concord/banlist";
45const LABEL_PINS: &str = "concord/pins";
46const LABEL_INVITE_LINKS: &str = "concord/invite-links";
47const LABEL_INVITE_KEY: &str = "concord/invite-key";
48const LABEL_COMMUNITY: &str = "concord/community";
50const LABEL_EPOCH_COMMITMENT: &str = "concord/epoch-key-commitment";
52
53const ZERO32: [u8; 32] = [0u8; 32];
54
55pub const TOKEN_LEN: usize = 16;
58
59fn build_info(label: &str, id32: &[u8; 32], epoch: Option<u64>) -> Vec<u8> {
62 let mut info = Vec::with_capacity(label.len() + 1 + 32 + 8);
63 info.extend_from_slice(label.as_bytes());
64 info.push(0x00);
65 info.extend_from_slice(id32);
66 if let Some(e) = epoch {
67 info.extend_from_slice(&e.to_be_bytes());
68 }
69 info
70}
71
72fn hkdf32(ikm: &[u8], info: &[u8]) -> [u8; 32] {
76 let hk = Hkdf::<Sha256>::new(None, ikm);
77 let mut okm = [0u8; 32];
78 hk.expand(info, &mut okm)
79 .expect("HKDF expand of 32 bytes is infallible");
80 okm
81}
82
83fn hkdf_to_secret_key(ikm: &[u8], base_info: &[u8]) -> SecretKey {
88 if let Ok(sk) = SecretKey::from_slice(&hkdf32(ikm, base_info)) {
89 return sk;
90 }
91 for counter in 0u8..=255 {
92 let mut info = base_info.to_vec();
93 info.push(counter);
94 if let Ok(sk) = SecretKey::from_slice(&hkdf32(ikm, &info)) {
95 return sk;
96 }
97 }
98 unreachable!("secp256k1 scalar rejection 257 times running is impossible")
99}
100
101#[derive(Clone)]
107pub struct GroupKey {
108 keys: Keys,
109 conv_key: ConversationKey,
110}
111
112impl GroupKey {
113 fn derive(label: &str, secret: &[u8], id32: &[u8; 32], epoch: Option<u64>) -> Self {
114 let info = build_info(label, id32, epoch);
115 let sk = hkdf_to_secret_key(secret, &info);
116 let keys = Keys::new(sk);
117 let conv_key = ConversationKey::derive(keys.secret_key(), &keys.public_key())
118 .expect("self-ECDH of a valid keypair cannot fail");
119 GroupKey { keys, conv_key }
120 }
121
122 pub fn pk(&self) -> PublicKey {
124 self.keys.public_key()
125 }
126
127 pub fn pk_hex(&self) -> String {
129 self.keys.public_key().to_hex()
130 }
131
132 pub fn keys(&self) -> &Keys {
134 &self.keys
135 }
136
137 pub fn conv_key(&self) -> &ConversationKey {
139 &self.conv_key
140 }
141}
142
143impl std::fmt::Debug for GroupKey {
144 fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
146 f.debug_struct("GroupKey").field("pk", &self.pk_hex()).finish()
147 }
148}
149
150pub fn channel_group_key(secret: &[u8; 32], channel_id: &ChannelId, epoch: Epoch) -> GroupKey {
158 GroupKey::derive(LABEL_CHANNEL, secret, &channel_id.0, Some(epoch.0))
159}
160
161pub fn control_group_key(community_root: &[u8; 32], community_id: &CommunityId, epoch: Epoch) -> GroupKey {
163 GroupKey::derive(LABEL_CONTROL, community_root, &community_id.0, Some(epoch.0))
164}
165
166pub fn guestbook_group_key(community_root: &[u8; 32], community_id: &CommunityId, epoch: Epoch) -> GroupKey {
168 GroupKey::derive(LABEL_GUESTBOOK, community_root, &community_id.0, Some(epoch.0))
169}
170
171pub fn channel_rekey_group_key(root: &[u8; 32], channel_id: &ChannelId, new_epoch: Epoch) -> GroupKey {
176 GroupKey::derive(LABEL_REKEY_PSEUDONYM, root, &channel_id.0, Some(new_epoch.0))
177}
178
179pub fn base_rekey_group_key(prior_root: &[u8; 32], community_id: &CommunityId, new_epoch: Epoch) -> GroupKey {
183 GroupKey::derive(LABEL_BASE_REKEY_PSEUDONYM, prior_root, &community_id.0, Some(new_epoch.0))
184}
185
186pub fn dissolved_group_key(community_id: &CommunityId) -> GroupKey {
190 GroupKey::derive(LABEL_DISSOLVED, &community_id.0, &ZERO32, None)
191}
192
193pub fn voice_group_key(secret: &[u8; 32], channel_id: &ChannelId, epoch: Epoch) -> GroupKey {
200 GroupKey::derive(LABEL_VOICE_SIGNER, secret, &channel_id.0, Some(epoch.0))
201}
202
203pub fn voice_media_key(secret: &[u8; 32], channel_id: &ChannelId, epoch: Epoch) -> [u8; 32] {
206 hkdf32(secret, &build_info(LABEL_VOICE_MEDIA, &channel_id.0, Some(epoch.0)))
207}
208
209pub fn voice_sender_key(media_key: &[u8; 32], identity: &str) -> [u8; 32] {
214 let id: [u8; 32] = Sha256::digest(identity.as_bytes()).into();
215 hkdf32(media_key, &build_info(LABEL_VOICE_SENDER, &id, None))
216}
217
218pub fn grant_locator(community_id: &CommunityId, member_xonly: &[u8; 32]) -> [u8; 32] {
223 hkdf32(&community_id.0, &build_info(LABEL_GRANT, member_xonly, None))
224}
225
226pub fn banlist_locator(community_id: &CommunityId) -> [u8; 32] {
228 hkdf32(&community_id.0, &build_info(LABEL_BANLIST, &ZERO32, None))
229}
230
231pub fn pins_locator(community_id: &CommunityId, channel_id: &ChannelId) -> [u8; 32] {
233 hkdf32(&community_id.0, &build_info(LABEL_PINS, &channel_id.0, None))
234}
235
236pub fn invite_links_locator(community_id: &CommunityId, creator_xonly: &[u8; 32]) -> [u8; 32] {
239 hkdf32(&community_id.0, &build_info(LABEL_INVITE_LINKS, creator_xonly, None))
240}
241
242pub fn recipient_locator(
251 rotator_xonly: &[u8; 32],
252 recipient_xonly: &[u8; 32],
253 scope_id: &[u8; 32],
254 new_epoch: Epoch,
255) -> [u8; 32] {
256 let mut ikm = [0u8; 64];
257 ikm[..32].copy_from_slice(rotator_xonly);
258 ikm[32..].copy_from_slice(recipient_xonly);
259 hkdf32(&ikm, &build_info(LABEL_RECIPIENT_PSEUDONYM, scope_id, Some(new_epoch.0)))
260}
261
262pub fn invite_bundle_key(token: &[u8; TOKEN_LEN]) -> [u8; 32] {
265 hkdf32(token, &build_info(LABEL_INVITE_KEY, &ZERO32, None))
266}
267
268pub fn community_id_of(owner_xonly: &[u8; 32], owner_salt: &[u8; 32]) -> CommunityId {
276 let mut h = Sha256::new();
277 h.update(LABEL_COMMUNITY.as_bytes());
278 h.update(owner_xonly);
279 h.update(owner_salt);
280 CommunityId(h.finalize().into())
281}
282
283pub fn verify_community_id(community_id: &CommunityId, owner_xonly: &[u8; 32], owner_salt: &[u8; 32]) -> bool {
287 community_id_of(owner_xonly, owner_salt) == *community_id
288}
289
290pub fn epoch_key_commitment(prev_epoch: Epoch, prev_key: &[u8; 32]) -> [u8; 32] {
296 let mut h = Sha256::new();
297 h.update(LABEL_EPOCH_COMMITMENT.as_bytes());
298 h.update(prev_epoch.0.to_be_bytes());
299 h.update(prev_key);
300 h.finalize().into()
301}
302
303#[cfg(test)]
304mod tests {
305 use super::*;
306
307 fn secret() -> [u8; 32] {
315 let mut k = [0u8; 32];
317 for (i, b) in k.iter_mut().enumerate() {
318 *b = i as u8;
319 }
320 k
321 }
322
323 fn id32() -> [u8; 32] {
324 let mut id = [0u8; 32];
326 for (i, b) in id.iter_mut().enumerate() {
327 *b = (255 - i) as u8;
328 }
329 id
330 }
331
332 fn alt() -> [u8; 32] {
333 [0x11u8; 32]
334 }
335
336 fn cid() -> CommunityId {
337 CommunityId(id32())
338 }
339
340 fn chan() -> ChannelId {
341 ChannelId(id32())
342 }
343
344 const EPOCH_MULTI: u64 = 0x0102030405060708;
346
347 const GOLDEN_CHANNEL_E0_SEED: &str = "1a99a5958bf9fcc5336e6e19db42aabf36ffbfa12f38a1d5fbde2ae383ed751b";
348 const GOLDEN_CHANNEL_E0_PK: &str = "7a5c5dff759a63f1fc2779864487432bae3d1ea72c4ffabd39f4c1fdaf62097a";
349 const GOLDEN_CHANNEL_EMULTI_PK: &str = "f20c7d192cc87615d7341e86f38f85303f4708b40232d4fea521ab8217767391";
350 const GOLDEN_CONTROL_E0_PK: &str = "c43df20bf4d6eeaea5149619662ffe9b211f31e11bb4a59f56b6e906f702d46f";
351 const GOLDEN_GUESTBOOK_E0_PK: &str = "ad09de582026fa7a052db18bb5827fa24c15e929d59aadcc91efb8508f5368ad";
352 const GOLDEN_CHANNEL_REKEY_E1_PK: &str = "7c55cdb957e9db2b4800d687b2a07d3f7066b1a35824a1e86ba871f55e87e8b5";
353 const GOLDEN_BASE_REKEY_E1_PK: &str = "fb2fa44fba66ba15595f784255a1cb569531db8784432ac0e4fe838498dd9dea";
354 const GOLDEN_DISSOLVED_PK: &str = "4d3d55d88fdf9d9c2089651e5cbb0dfa93b6b9b10cdcb2319b0dce1a1398096a";
355 const GOLDEN_GRANT_LOCATOR: &str = "fd2f88cc7f1eb8d7d862c91dc22afe700c358d1845158b3f353b769ce4898e35";
356 const GOLDEN_BANLIST_LOCATOR: &str = "88089214afae6d3c412fd817ada44d6df4d485a53565646471e74476397693c9";
357 const GOLDEN_INVITE_LINKS_LOCATOR: &str = "f4ae29994165767bac23e8dce630f81b926d2c8aa150e5cbf0bdf75865e8379a";
358 const GOLDEN_RECIPIENT_LOCATOR: &str = "342deb400e191f0f52c81f27600934552550beb85aa9bf169f02d0e7f826cf74";
359 const GOLDEN_INVITE_KEY: &str = "94bf8b0d89e579ddaeccf8d9db3f5de5c86a1259c597f2560ff0120173bc5e1f";
360 const GOLDEN_VOICE_MEDIA_E0: &str = "8ab5b935c5e17f156563860ae6263f3700bfd836c326f8b3d7082be2fbaef6a0";
361 const GOLDEN_VOICE_SIGNER_E0_PK: &str = "7591f1306c265ee1dce6a07b72c76fadb3af13bf9ccce0d284cb3af6134211a1";
362 const GOLDEN_VOICE_SENDER: &str = "9ce1c11a39ce16a84b72c2697724a39e5c41ec07f4d703dcb01241271837599e";
363 const GOLDEN_COMMUNITY_ID: &str = "2b790bd59df98bdc52092b74ebd6933a89ef8eaeecc9030861cbdeae7c814c46";
364 const GOLDEN_EPOCH_COMMITMENT: &str = "3e6d6a3c9973c16d1ca7c5602d36979927c55c21a7e2c840f883af3f047e80a4";
365
366 fn hex(bytes: &[u8]) -> String {
367 crate::simd::hex::bytes_to_hex_32(bytes.try_into().expect("32 bytes"))
368 }
369
370 #[test]
371 fn channel_group_key_golden_vector() {
372 let gk = channel_group_key(&secret(), &chan(), Epoch(0));
373 assert_eq!(hex(gk.keys().secret_key().as_secret_bytes()), GOLDEN_CHANNEL_E0_SEED);
376 assert_eq!(gk.pk_hex(), GOLDEN_CHANNEL_E0_PK);
377 }
378
379 #[test]
380 fn channel_group_key_golden_multibyte_epoch_is_big_endian() {
381 let gk = channel_group_key(&secret(), &chan(), Epoch(EPOCH_MULTI));
382 assert_eq!(gk.pk_hex(), GOLDEN_CHANNEL_EMULTI_PK);
383 }
384
385 #[test]
386 fn control_group_key_golden_vector() {
387 assert_eq!(control_group_key(&secret(), &cid(), Epoch(0)).pk_hex(), GOLDEN_CONTROL_E0_PK);
388 }
389
390 #[test]
391 fn guestbook_group_key_golden_vector() {
392 assert_eq!(guestbook_group_key(&secret(), &cid(), Epoch(0)).pk_hex(), GOLDEN_GUESTBOOK_E0_PK);
393 }
394
395 #[test]
396 fn rekey_group_keys_golden_vectors() {
397 assert_eq!(
398 channel_rekey_group_key(&secret(), &chan(), Epoch(1)).pk_hex(),
399 GOLDEN_CHANNEL_REKEY_E1_PK
400 );
401 assert_eq!(
402 base_rekey_group_key(&secret(), &cid(), Epoch(1)).pk_hex(),
403 GOLDEN_BASE_REKEY_E1_PK
404 );
405 }
406
407 #[test]
408 fn dissolved_group_key_golden_and_is_epoch_free() {
409 assert_eq!(dissolved_group_key(&cid()).pk_hex(), GOLDEN_DISSOLVED_PK);
410 let with_epoch = GroupKey::derive(LABEL_DISSOLVED, &cid().0, &ZERO32, Some(0));
413 assert_ne!(with_epoch.pk_hex(), GOLDEN_DISSOLVED_PK);
414 }
415
416 #[test]
417 fn locator_golden_vectors() {
418 assert_eq!(hex(&grant_locator(&cid(), &alt())), GOLDEN_GRANT_LOCATOR);
419 assert_eq!(hex(&banlist_locator(&cid())), GOLDEN_BANLIST_LOCATOR);
420 assert_eq!(hex(&invite_links_locator(&cid(), &alt())), GOLDEN_INVITE_LINKS_LOCATOR);
421 assert_eq!(
422 hex(&recipient_locator(&secret(), &alt(), &id32(), Epoch(3))),
423 GOLDEN_RECIPIENT_LOCATOR
424 );
425 assert_eq!(hex(&invite_bundle_key(&[0x07u8; TOKEN_LEN])), GOLDEN_INVITE_KEY);
426 }
427
428 #[test]
429 fn voice_golden_vectors() {
430 let media = voice_media_key(&secret(), &chan(), Epoch(0));
431 assert_eq!(hex(&media), GOLDEN_VOICE_MEDIA_E0);
432 assert_eq!(voice_group_key(&secret(), &chan(), Epoch(0)).pk_hex(), GOLDEN_VOICE_SIGNER_E0_PK);
433 assert_eq!(
434 hex(&voice_sender_key(&media, "00112233445566778899aabbccddeeff")),
435 GOLDEN_VOICE_SENDER
436 );
437 }
438
439 #[test]
440 fn community_id_golden_and_verifies() {
441 let id = community_id_of(&secret(), &alt());
442 assert_eq!(hex(&id.0), GOLDEN_COMMUNITY_ID);
443 assert!(verify_community_id(&id, &secret(), &alt()));
444 assert!(!verify_community_id(&id, &alt(), &alt()));
446 assert!(!verify_community_id(&id, &secret(), &id32()));
447 }
448
449 #[test]
450 fn epoch_key_commitment_golden_and_binds_both_inputs() {
451 assert_eq!(hex(&epoch_key_commitment(Epoch(2), &secret())), GOLDEN_EPOCH_COMMITMENT);
452 assert_ne!(hex(&epoch_key_commitment(Epoch(3), &secret())), GOLDEN_EPOCH_COMMITMENT);
453 assert_ne!(hex(&epoch_key_commitment(Epoch(2), &alt())), GOLDEN_EPOCH_COMMITMENT);
454 }
455
456 #[test]
457 fn labels_domain_separate_every_plane() {
458 let pks = [
461 channel_group_key(&secret(), &chan(), Epoch(0)).pk_hex(),
462 control_group_key(&secret(), &cid(), Epoch(0)).pk_hex(),
463 guestbook_group_key(&secret(), &cid(), Epoch(0)).pk_hex(),
464 channel_rekey_group_key(&secret(), &chan(), Epoch(0)).pk_hex(),
465 base_rekey_group_key(&secret(), &cid(), Epoch(0)).pk_hex(),
466 voice_group_key(&secret(), &chan(), Epoch(0)).pk_hex(),
467 ];
468 let unique: std::collections::HashSet<_> = pks.iter().collect();
469 assert_eq!(unique.len(), pks.len(), "two labels collided on one address");
470 }
471
472 #[test]
473 fn epoch_rotates_every_keyed_address() {
474 assert_ne!(
475 channel_group_key(&secret(), &chan(), Epoch(0)).pk_hex(),
476 channel_group_key(&secret(), &chan(), Epoch(1)).pk_hex()
477 );
478 assert_ne!(
479 control_group_key(&secret(), &cid(), Epoch(0)).pk_hex(),
480 control_group_key(&secret(), &cid(), Epoch(1)).pk_hex()
481 );
482 assert_ne!(
483 guestbook_group_key(&secret(), &cid(), Epoch(0)).pk_hex(),
484 guestbook_group_key(&secret(), &cid(), Epoch(1)).pk_hex()
485 );
486 }
487
488 #[test]
489 fn recipient_locator_binds_direction_scope_and_epoch() {
490 let base = recipient_locator(&secret(), &alt(), &id32(), Epoch(1));
491 assert_ne!(recipient_locator(&alt(), &secret(), &id32(), Epoch(1)), base);
493 assert_ne!(recipient_locator(&secret(), &alt(), &id32(), Epoch(2)), base);
494 assert_ne!(recipient_locator(&secret(), &alt(), &ZERO32, Epoch(1)), base);
495 }
496
497 #[test]
498 fn conv_key_is_deterministic_self_ecdh() {
499 let a = channel_group_key(&secret(), &chan(), Epoch(0));
500 let b = channel_group_key(&secret(), &chan(), Epoch(0));
501 assert_eq!(a.conv_key().as_bytes(), b.conv_key().as_bytes());
502 }
503}