2022-11-10 22:35:09 -05:00
|
|
|
use core::ops::Deref;
|
2022-06-30 05:42:29 -04:00
|
|
|
|
|
|
|
|
use hex_literal::hex;
|
2022-11-10 22:35:09 -05:00
|
|
|
|
2022-06-30 05:42:29 -04:00
|
|
|
use rand_core::OsRng;
|
|
|
|
|
|
2022-11-10 22:35:09 -05:00
|
|
|
use zeroize::Zeroizing;
|
|
|
|
|
|
2022-06-30 05:42:29 -04:00
|
|
|
use ff::Field;
|
|
|
|
|
use group::GroupEncoding;
|
|
|
|
|
|
|
|
|
|
use k256::{Scalar, ProjectivePoint};
|
|
|
|
|
|
2022-07-12 03:38:59 -04:00
|
|
|
use transcript::{Transcript, RecommendedTranscript};
|
2022-06-30 05:42:29 -04:00
|
|
|
|
2022-07-13 23:29:48 -04:00
|
|
|
use crate::DLEqProof;
|
2022-06-30 05:42:29 -04:00
|
|
|
|
2022-11-10 22:35:09 -05:00
|
|
|
#[cfg(feature = "experimental")]
|
|
|
|
|
mod cross_group;
|
|
|
|
|
|
2022-06-30 05:42:29 -04:00
|
|
|
#[test]
|
|
|
|
|
fn test_dleq() {
|
|
|
|
|
let transcript = || RecommendedTranscript::new(b"DLEq Proof Test");
|
|
|
|
|
|
2022-07-13 23:29:48 -04:00
|
|
|
let generators = [
|
2022-06-30 05:42:29 -04:00
|
|
|
ProjectivePoint::GENERATOR,
|
|
|
|
|
ProjectivePoint::from_bytes(
|
2022-07-15 01:26:07 -04:00
|
|
|
&(hex!("0250929b74c1a04954b78b4b6035e97a5e078a5a0f28ec96d547bfee9ace803ac0").into()),
|
|
|
|
|
)
|
|
|
|
|
.unwrap(),
|
2022-07-13 23:29:48 -04:00
|
|
|
// Just an increment of the last byte from the previous, where the previous two are valid
|
|
|
|
|
ProjectivePoint::from_bytes(
|
2022-07-15 01:26:07 -04:00
|
|
|
&(hex!("0250929b74c1a04954b78b4b6035e97a5e078a5a0f28ec96d547bfee9ace803ac4").into()),
|
|
|
|
|
)
|
|
|
|
|
.unwrap(),
|
2022-07-13 23:29:48 -04:00
|
|
|
ProjectivePoint::from_bytes(
|
2022-07-15 01:26:07 -04:00
|
|
|
&(hex!("0250929b74c1a04954b78b4b6035e97a5e078a5a0f28ec96d547bfee9ace803aca").into()),
|
|
|
|
|
)
|
|
|
|
|
.unwrap(),
|
2022-07-13 23:29:48 -04:00
|
|
|
ProjectivePoint::from_bytes(
|
2022-07-15 01:26:07 -04:00
|
|
|
&(hex!("0250929b74c1a04954b78b4b6035e97a5e078a5a0f28ec96d547bfee9ace803acb").into()),
|
|
|
|
|
)
|
|
|
|
|
.unwrap(),
|
2022-07-13 23:29:48 -04:00
|
|
|
];
|
|
|
|
|
|
|
|
|
|
for i in 0 .. 5 {
|
2022-11-10 22:35:09 -05:00
|
|
|
let key = Zeroizing::new(Scalar::random(&mut OsRng));
|
|
|
|
|
let proof = DLEqProof::prove(&mut OsRng, &mut transcript(), &generators[.. i], &key);
|
2022-07-13 23:29:48 -04:00
|
|
|
|
|
|
|
|
let mut keys = [ProjectivePoint::GENERATOR; 5];
|
|
|
|
|
for k in 0 .. 5 {
|
2022-11-10 22:35:09 -05:00
|
|
|
keys[k] = generators[k] * key.deref();
|
2022-07-13 23:29:48 -04:00
|
|
|
}
|
|
|
|
|
proof.verify(&mut transcript(), &generators[.. i], &keys[.. i]).unwrap();
|
2022-12-24 17:08:22 -05:00
|
|
|
// Different challenge
|
|
|
|
|
assert!(proof
|
|
|
|
|
.verify(
|
|
|
|
|
&mut RecommendedTranscript::new(b"different challenge"),
|
|
|
|
|
&generators[.. i],
|
|
|
|
|
&keys[.. i]
|
|
|
|
|
)
|
|
|
|
|
.is_err());
|
|
|
|
|
|
|
|
|
|
// We could edit these tests to always test with at least two generators
|
|
|
|
|
// Then we don't test proofs with zero/one generator(s)
|
|
|
|
|
// While those are stupid, and pointless, and potentially point to a failure in the caller,
|
|
|
|
|
// it could also be part of a dynamic system which deals with variable amounts of generators
|
|
|
|
|
// Not panicking in such use cases, even if they're inefficient, provides seamless behavior
|
|
|
|
|
if i >= 2 {
|
|
|
|
|
// Different generators
|
|
|
|
|
assert!(proof
|
|
|
|
|
.verify(
|
|
|
|
|
&mut transcript(),
|
|
|
|
|
generators[.. i].iter().cloned().rev().collect::<Vec<_>>().as_ref(),
|
|
|
|
|
&keys[.. i]
|
|
|
|
|
)
|
|
|
|
|
.is_err());
|
|
|
|
|
// Different keys
|
|
|
|
|
assert!(proof
|
|
|
|
|
.verify(
|
|
|
|
|
&mut transcript(),
|
|
|
|
|
&generators[.. i],
|
|
|
|
|
keys[.. i].iter().cloned().rev().collect::<Vec<_>>().as_ref()
|
|
|
|
|
)
|
|
|
|
|
.is_err());
|
|
|
|
|
}
|
2022-07-13 23:29:48 -04:00
|
|
|
|
|
|
|
|
#[cfg(feature = "serialize")]
|
|
|
|
|
{
|
|
|
|
|
let mut buf = vec![];
|
|
|
|
|
proof.serialize(&mut buf).unwrap();
|
2022-07-15 01:26:07 -04:00
|
|
|
let deserialized =
|
|
|
|
|
DLEqProof::<ProjectivePoint>::deserialize(&mut std::io::Cursor::new(&buf)).unwrap();
|
2022-07-13 23:29:48 -04:00
|
|
|
assert_eq!(proof, deserialized);
|
|
|
|
|
}
|
2022-06-30 05:42:29 -04:00
|
|
|
}
|
|
|
|
|
}
|