Replace `Ciphersuite::hash_to_F`
The prior-present `Ciphersuite::hash_to_F` was a sin. Implementations took a
DST, yet were not require to securely handle it. It was also biased towards the
requirements of `modular-frost` as `ciphersuite` was originally written all
those years ago, when `modular-frost` had needs exceeding what `ff`, `group`
satisfied.
Now, the hash is bound to produce an output which can be converted to a scalar
with `ff::FromUniformBytes`. A new `hash_to_F`, which accepts a single argument
of the value to hash (removing the potential to insecurely handle the DST by
removing the DST entirely). Due to `digest` yielding a `GenericArray`, yet
`FromUniformBytes` taking a `const usize`, the `ciphersuite` crate now defines
a `FromUniformBytes` trait taking an array (then implemented for all satisfiers
of `ff::FromUniformBytes`). In order to get the array type from the
`GenericArray`, the output of the hash, `digest` is updated to the `0.11`
release candidate which moves to `flexible-array` which solves that problem.
The existing, specific `hash_to_F` functions have been moved to `modular-frost`
as necessary.
`flexible-array` itself is patched to a fork due to
https://github.com/RustCrypto/hybrid-array/issues/131.
2025-08-29 05:04:03 -04:00
|
|
|
pub use ciphersuite::{digest::Digest, group::GroupEncoding, FromUniformBytes, Ciphersuite};
|
2022-10-29 03:54:42 -05:00
|
|
|
use minimal_ed448::{Scalar, Point};
|
2025-08-20 04:50:37 -04:00
|
|
|
pub use minimal_ed448::Ed448;
|
2022-08-29 02:32:59 -05:00
|
|
|
|
|
|
|
|
use crate::{curve::Curve, algorithm::Hram};
|
|
|
|
|
|
2023-07-19 15:47:30 -04:00
|
|
|
const CONTEXT: &[u8] = b"FROST-ED448-SHAKE256-v1";
|
2022-08-29 02:32:59 -05:00
|
|
|
|
|
|
|
|
impl Curve for Ed448 {
|
2022-10-29 03:54:42 -05:00
|
|
|
const CONTEXT: &'static [u8] = CONTEXT;
|
Replace `Ciphersuite::hash_to_F`
The prior-present `Ciphersuite::hash_to_F` was a sin. Implementations took a
DST, yet were not require to securely handle it. It was also biased towards the
requirements of `modular-frost` as `ciphersuite` was originally written all
those years ago, when `modular-frost` had needs exceeding what `ff`, `group`
satisfied.
Now, the hash is bound to produce an output which can be converted to a scalar
with `ff::FromUniformBytes`. A new `hash_to_F`, which accepts a single argument
of the value to hash (removing the potential to insecurely handle the DST by
removing the DST entirely). Due to `digest` yielding a `GenericArray`, yet
`FromUniformBytes` taking a `const usize`, the `ciphersuite` crate now defines
a `FromUniformBytes` trait taking an array (then implemented for all satisfiers
of `ff::FromUniformBytes`). In order to get the array type from the
`GenericArray`, the output of the hash, `digest` is updated to the `0.11`
release candidate which moves to `flexible-array` which solves that problem.
The existing, specific `hash_to_F` functions have been moved to `modular-frost`
as necessary.
`flexible-array` itself is patched to a fork due to
https://github.com/RustCrypto/hybrid-array/issues/131.
2025-08-29 05:04:03 -04:00
|
|
|
fn hash_to_F(dst: &[u8], msg: &[u8]) -> Self::F {
|
|
|
|
|
let mut digest = <Self as Ciphersuite>::H::new();
|
|
|
|
|
digest.update(Self::CONTEXT);
|
|
|
|
|
digest.update(dst);
|
|
|
|
|
digest.update(msg);
|
|
|
|
|
Self::F::from_uniform_bytes(&digest.finalize().into())
|
|
|
|
|
}
|
2022-08-29 02:32:59 -05:00
|
|
|
}
|
|
|
|
|
|
2023-03-20 20:10:00 -04:00
|
|
|
// The RFC-8032 Ed448 challenge function.
|
2022-08-29 02:32:59 -05:00
|
|
|
#[derive(Copy, Clone)]
|
2023-03-20 20:10:00 -04:00
|
|
|
pub(crate) struct Ietf8032Ed448Hram;
|
2022-08-29 02:32:59 -05:00
|
|
|
impl Ietf8032Ed448Hram {
|
|
|
|
|
#[allow(non_snake_case)]
|
2023-03-20 20:10:00 -04:00
|
|
|
pub(crate) fn hram(context: &[u8], R: &Point, A: &Point, m: &[u8]) -> Scalar {
|
Replace `Ciphersuite::hash_to_F`
The prior-present `Ciphersuite::hash_to_F` was a sin. Implementations took a
DST, yet were not require to securely handle it. It was also biased towards the
requirements of `modular-frost` as `ciphersuite` was originally written all
those years ago, when `modular-frost` had needs exceeding what `ff`, `group`
satisfied.
Now, the hash is bound to produce an output which can be converted to a scalar
with `ff::FromUniformBytes`. A new `hash_to_F`, which accepts a single argument
of the value to hash (removing the potential to insecurely handle the DST by
removing the DST entirely). Due to `digest` yielding a `GenericArray`, yet
`FromUniformBytes` taking a `const usize`, the `ciphersuite` crate now defines
a `FromUniformBytes` trait taking an array (then implemented for all satisfiers
of `ff::FromUniformBytes`). In order to get the array type from the
`GenericArray`, the output of the hash, `digest` is updated to the `0.11`
release candidate which moves to `flexible-array` which solves that problem.
The existing, specific `hash_to_F` functions have been moved to `modular-frost`
as necessary.
`flexible-array` itself is patched to a fork due to
https://github.com/RustCrypto/hybrid-array/issues/131.
2025-08-29 05:04:03 -04:00
|
|
|
let mut digest = <Ed448 as Ciphersuite>::H::new();
|
|
|
|
|
digest.update(b"SigEd448");
|
|
|
|
|
digest.update([0, u8::try_from(context.len()).unwrap()]);
|
|
|
|
|
digest.update(context);
|
|
|
|
|
digest.update(R.to_bytes());
|
|
|
|
|
digest.update(A.to_bytes());
|
|
|
|
|
digest.update(m);
|
|
|
|
|
Scalar::from_uniform_bytes(&digest.finalize().into())
|
2022-08-29 02:32:59 -05:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2023-03-20 20:10:00 -04:00
|
|
|
/// The challenge function for FROST's Ed448 ciphersuite.
|
2022-08-29 02:32:59 -05:00
|
|
|
#[derive(Copy, Clone)]
|
2022-10-13 00:38:36 -04:00
|
|
|
pub struct IetfEd448Hram;
|
|
|
|
|
impl Hram<Ed448> for IetfEd448Hram {
|
2022-08-29 02:32:59 -05:00
|
|
|
#[allow(non_snake_case)]
|
|
|
|
|
fn hram(R: &Point, A: &Point, m: &[u8]) -> Scalar {
|
2022-09-16 12:16:37 -04:00
|
|
|
Ietf8032Ed448Hram::hram(&[], R, A, m)
|
2022-08-29 02:32:59 -05:00
|
|
|
}
|
|
|
|
|
}
|