2022-05-03 08:49:46 -04:00
|
|
|
#[cfg(feature = "multisig")]
|
2022-06-05 07:33:15 -04:00
|
|
|
use std::sync::{Arc, RwLock};
|
2022-04-30 04:32:19 -04:00
|
|
|
|
2022-07-27 05:43:23 -04:00
|
|
|
use rand_core::{RngCore, OsRng};
|
2022-04-21 21:36:18 -04:00
|
|
|
|
2022-04-30 01:41:05 -04:00
|
|
|
use curve25519_dalek::{constants::ED25519_BASEPOINT_TABLE, scalar::Scalar};
|
2022-04-21 21:36:18 -04:00
|
|
|
|
2022-06-24 18:58:24 -04:00
|
|
|
#[cfg(feature = "multisig")]
|
2022-07-12 01:28:01 -04:00
|
|
|
use transcript::{Transcript, RecommendedTranscript};
|
2022-06-24 19:47:19 -04:00
|
|
|
#[cfg(feature = "multisig")]
|
|
|
|
|
use frost::curve::Ed25519;
|
2022-06-24 18:58:24 -04:00
|
|
|
|
2022-05-21 20:26:28 -04:00
|
|
|
use crate::{
|
2022-07-15 01:26:07 -04:00
|
|
|
Commitment, random_scalar,
|
2022-05-21 20:26:28 -04:00
|
|
|
wallet::Decoys,
|
2022-07-15 01:26:07 -04:00
|
|
|
ringct::{
|
|
|
|
|
generate_key_image,
|
|
|
|
|
clsag::{ClsagInput, Clsag},
|
|
|
|
|
},
|
2022-05-21 15:33:35 -04:00
|
|
|
};
|
2022-05-03 08:49:46 -04:00
|
|
|
#[cfg(feature = "multisig")]
|
2022-07-15 01:26:07 -04:00
|
|
|
use crate::{
|
|
|
|
|
frost::MultisigError,
|
|
|
|
|
ringct::clsag::{ClsagDetails, ClsagMultisig},
|
|
|
|
|
};
|
2022-04-21 21:36:18 -04:00
|
|
|
|
|
|
|
|
#[cfg(feature = "multisig")]
|
2022-05-25 00:30:51 -04:00
|
|
|
use frost::tests::{key_gen, algorithm_machines, sign};
|
2022-04-21 21:36:18 -04:00
|
|
|
|
|
|
|
|
const RING_LEN: u64 = 11;
|
|
|
|
|
const AMOUNT: u64 = 1337;
|
|
|
|
|
|
2022-05-14 00:45:13 -04:00
|
|
|
#[cfg(feature = "multisig")]
|
|
|
|
|
const RING_INDEX: u8 = 3;
|
|
|
|
|
|
2022-04-21 21:36:18 -04:00
|
|
|
#[test]
|
2022-05-13 20:26:29 -04:00
|
|
|
fn clsag() {
|
2022-05-14 00:45:13 -04:00
|
|
|
for real in 0 .. RING_LEN {
|
|
|
|
|
let msg = [1; 32];
|
2022-04-21 21:36:18 -04:00
|
|
|
|
2022-05-14 00:45:13 -04:00
|
|
|
let mut secrets = [Scalar::zero(), Scalar::zero()];
|
|
|
|
|
let mut ring = vec![];
|
|
|
|
|
for i in 0 .. RING_LEN {
|
|
|
|
|
let dest = random_scalar(&mut OsRng);
|
|
|
|
|
let mask = random_scalar(&mut OsRng);
|
|
|
|
|
let amount;
|
|
|
|
|
if i == u64::from(real) {
|
|
|
|
|
secrets = [dest, mask];
|
|
|
|
|
amount = AMOUNT;
|
|
|
|
|
} else {
|
|
|
|
|
amount = OsRng.next_u64();
|
|
|
|
|
}
|
|
|
|
|
ring.push([&dest * &ED25519_BASEPOINT_TABLE, Commitment::new(mask, amount).calculate()]);
|
2022-04-21 21:36:18 -04:00
|
|
|
}
|
|
|
|
|
|
2022-07-10 16:11:55 -04:00
|
|
|
let image = generate_key_image(secrets[0]);
|
2022-05-21 15:33:35 -04:00
|
|
|
let (clsag, pseudo_out) = Clsag::sign(
|
2022-05-14 00:45:13 -04:00
|
|
|
&mut OsRng,
|
|
|
|
|
&vec![(
|
|
|
|
|
secrets[0],
|
|
|
|
|
image,
|
2022-05-21 15:33:35 -04:00
|
|
|
ClsagInput::new(
|
2022-05-14 00:45:13 -04:00
|
|
|
Commitment::new(secrets[1], AMOUNT),
|
|
|
|
|
Decoys {
|
|
|
|
|
i: u8::try_from(real).unwrap(),
|
2022-05-21 15:33:35 -04:00
|
|
|
offsets: (1 ..= RING_LEN).into_iter().collect(),
|
2022-07-15 01:26:07 -04:00
|
|
|
ring: ring.clone(),
|
|
|
|
|
},
|
|
|
|
|
)
|
|
|
|
|
.unwrap(),
|
2022-05-14 00:45:13 -04:00
|
|
|
)],
|
|
|
|
|
random_scalar(&mut OsRng),
|
2022-07-15 01:26:07 -04:00
|
|
|
msg,
|
|
|
|
|
)
|
|
|
|
|
.swap_remove(0);
|
2022-05-21 15:33:35 -04:00
|
|
|
clsag.verify(&ring, &image, &pseudo_out, &msg).unwrap();
|
2022-05-14 00:45:13 -04:00
|
|
|
}
|
2022-04-21 21:36:18 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
#[cfg(feature = "multisig")]
|
|
|
|
|
#[test]
|
2022-05-13 20:26:29 -04:00
|
|
|
fn clsag_multisig() -> Result<(), MultisigError> {
|
2022-05-25 00:30:51 -04:00
|
|
|
let keys = key_gen::<_, Ed25519>(&mut OsRng);
|
2022-04-21 21:36:18 -04:00
|
|
|
|
|
|
|
|
let randomness = random_scalar(&mut OsRng);
|
|
|
|
|
let mut ring = vec![];
|
|
|
|
|
for i in 0 .. RING_LEN {
|
|
|
|
|
let dest;
|
2022-04-28 12:01:20 -04:00
|
|
|
let mask;
|
2022-04-21 21:36:18 -04:00
|
|
|
let amount;
|
2022-04-27 22:48:58 -04:00
|
|
|
if i != u64::from(RING_INDEX) {
|
2022-05-25 00:30:51 -04:00
|
|
|
dest = &random_scalar(&mut OsRng) * &ED25519_BASEPOINT_TABLE;
|
2022-04-28 12:01:20 -04:00
|
|
|
mask = random_scalar(&mut OsRng);
|
2022-04-21 21:36:18 -04:00
|
|
|
amount = OsRng.next_u64();
|
|
|
|
|
} else {
|
2022-05-25 00:30:51 -04:00
|
|
|
dest = keys[&1].group_key().0;
|
2022-04-28 12:01:20 -04:00
|
|
|
mask = randomness;
|
2022-04-21 21:36:18 -04:00
|
|
|
amount = AMOUNT;
|
|
|
|
|
}
|
2022-05-25 00:30:51 -04:00
|
|
|
ring.push([dest, Commitment::new(mask, amount).calculate()]);
|
2022-04-21 21:36:18 -04:00
|
|
|
}
|
|
|
|
|
|
2022-05-06 19:07:37 -04:00
|
|
|
let mask_sum = random_scalar(&mut OsRng);
|
2022-05-25 00:30:51 -04:00
|
|
|
sign(
|
|
|
|
|
&mut OsRng,
|
|
|
|
|
algorithm_machines(
|
|
|
|
|
&mut OsRng,
|
|
|
|
|
ClsagMultisig::new(
|
2022-06-24 18:58:24 -04:00
|
|
|
RecommendedTranscript::new(b"Monero Serai CLSAG Test"),
|
2022-07-12 01:28:01 -04:00
|
|
|
keys[&1].group_key().0,
|
2022-07-15 01:26:07 -04:00
|
|
|
Arc::new(RwLock::new(Some(ClsagDetails::new(
|
|
|
|
|
ClsagInput::new(
|
|
|
|
|
Commitment::new(randomness, AMOUNT),
|
|
|
|
|
Decoys {
|
|
|
|
|
i: RING_INDEX,
|
|
|
|
|
offsets: (1 ..= RING_LEN).into_iter().collect(),
|
|
|
|
|
ring: ring.clone(),
|
|
|
|
|
},
|
2022-05-25 00:30:51 -04:00
|
|
|
)
|
2022-07-15 01:26:07 -04:00
|
|
|
.unwrap(),
|
|
|
|
|
mask_sum,
|
|
|
|
|
)))),
|
|
|
|
|
)
|
|
|
|
|
.unwrap(),
|
|
|
|
|
&keys,
|
2022-05-25 00:30:51 -04:00
|
|
|
),
|
2022-07-15 01:26:07 -04:00
|
|
|
&[1; 32],
|
2022-05-25 00:30:51 -04:00
|
|
|
);
|
2022-04-21 21:36:18 -04:00
|
|
|
|
|
|
|
|
Ok(())
|
|
|
|
|
}
|