diff options
Diffstat (limited to 'nizk/commit')
-rw-r--r-- | nizk/commit/commit.go | 65 | ||||
-rw-r--r-- | nizk/commit/commit_test.go | 24 |
2 files changed, 43 insertions, 46 deletions
diff --git a/nizk/commit/commit.go b/nizk/commit/commit.go index 1fa653e..49690f2 100644 --- a/nizk/commit/commit.go +++ b/nizk/commit/commit.go @@ -6,42 +6,41 @@ import ( ) // This is a construction of a proof of a statement of the form -// [(C = g^(ab)) && (A = g^a) && (Β = g^b)] -// || [(C = g^(ab+1)) && (A = g^a) && (Β = g^b)] +// [(C = g^(αβ)) && (A = g^α) && (Β = g^β)] +// || [(C = g^(αβ+1)) && (A = g^α) && (Β = g^β)] // // for given C, A and B -type Statement struct { +type Bid struct { bitSet bool - a *Scalar - b *Scalar + α *Scalar + β *Scalar Commitment } type Commitment struct { - C *Point - A *Point - B *Point - Proof *Proof + A *Point // g^α + B *Point // g^β + C *Point // g^(ab)g^(bitSet) } -func NewStatement(bitSet bool) *Statement { - a, b := Curve.RandomScalar(), Curve.RandomScalar() - return NewStatementFromScalars(bitSet, a, b) +func NewBid(bitSet bool) *Bid { + α, β := Curve.RandomScalar(), Curve.RandomScalar() + return NewBidFromScalars(bitSet, α, β) } -func NewStatementFromScalars(bitSet bool, a, b *Scalar) *Statement { - return &Statement{ - a: a, - b: b, +func NewBidFromScalars(bitSet bool, α, β *Scalar) *Bid { + return &Bid{ + α: α, + β: β, bitSet: bitSet, - Commitment: commitment(a, b, bitSet), + Commitment: commitment(α, β, bitSet), } } -func commitment(a, b *Scalar, bitSet bool) Commitment { +func commitment(α, β *Scalar, bitSet bool) Commitment { var C *Point - c := a.Mul(b) + c := α.Mul(β) if bitSet { C = G.Exp(c.Add(One)) @@ -50,27 +49,26 @@ func commitment(a, b *Scalar, bitSet bool) Commitment { } return Commitment{ C: C, - A: G.Exp(a), - B: G.Exp(b), + A: G.Exp(α), + B: G.Exp(β), } } -func (s *Statement) Commit(id Bytes) *Commitment { - s.Commitment.Proof = s.Proof(id) - return &s.Commitment +func (s *Bid) Commit(id Bytes) (*Commitment, *Proof) { + return &s.Commitment, s.Proof(id) } type Proof struct { Id Bytes - A *schnorr.Proof // Proof for knowledge of a in A = G^a - B *schnorr.Proof // Proof for knowledge of b in B = G^b + A *schnorr.Proof // Proof for knowledge of α in A = G^α + B *schnorr.Proof // Proof for knowledge of β in B = G^β C struct { // Proof for knowledge of statement above Ch [2]*Scalar R [2]*Scalar } } -func (s *Statement) Proof(id Bytes) *Proof { +func (s *Bid) Proof(id Bytes) *Proof { var e [2][2]*Point var r1, r2, w *Scalar r1 = Curve.RandomScalar() @@ -95,23 +93,22 @@ func (s *Statement) Proof(id Bytes) *Proof { if s.bitSet { pr.C.Ch[0] = w pr.C.Ch[1] = ch.Sub(w) - pr.C.R[0] = r1.Sub(s.a.Mul(pr.C.Ch[0])) - pr.C.R[1] = r2.Sub(s.a.Mul(pr.C.Ch[1])) + pr.C.R[0] = r1.Sub(s.α.Mul(pr.C.Ch[0])) + pr.C.R[1] = r2.Sub(s.α.Mul(pr.C.Ch[1])) } else { pr.C.Ch[0] = ch.Sub(w) pr.C.Ch[1] = w - pr.C.R[0] = r1.Sub(s.a.Mul(pr.C.Ch[0])) + pr.C.R[0] = r1.Sub(s.α.Mul(pr.C.Ch[0])) pr.C.R[1] = r2 } - pr.A = (*schnorr.Statement)(s.a).Proof(id) - pr.B = (*schnorr.Statement)(s.b).Proof(id) + pr.A = (*schnorr.Statement)(s.α).Proof(id) + pr.B = (*schnorr.Statement)(s.β).Proof(id) return pr } -func (c *Commitment) Verify() bool { +func (c *Commitment) Verify(p *Proof) bool { var e [2][2]*Point - p := c.Proof e[0][0] = G.Exp(p.C.R[0]).Mul(c.A.Exp(p.C.Ch[0])) e[0][1] = c.B.Exp(p.C.R[0]).Mul(c.C.Exp(p.C.Ch[0])) diff --git a/nizk/commit/commit_test.go b/nizk/commit/commit_test.go index 4ea5964..111ab68 100644 --- a/nizk/commit/commit_test.go +++ b/nizk/commit/commit_test.go @@ -10,18 +10,18 @@ func TestStatement(t *testing.T) { id := Curve.RandomScalar() Id := G.Exp(id) - st1, st2 := NewStatement(true), NewStatement(false) - c1, c2 := st1.Commit(Id), st2.Commit(Id) - if !c1.Verify() { + st1, st2 := NewBid(true), NewBid(false) + c1, p1 := st1.Commit(Id) + c2, p2 := st2.Commit(Id) + if !c1.Verify(p1) { t.Fatal("Could not verify st1 with c1, plus=true case") } - if !c2.Verify() { + if !c2.Verify(p2) { t.Fatal("Could not verify st2 with c2, plus=false case") } // Use the wrong proof - c2.Proof = c1.Proof - if c2.Verify() { + if c2.Verify(p1) { t.Fatal("Verify with wrong proof should have failed!") } } @@ -31,18 +31,18 @@ func TestStatementFromScalar(t *testing.T) { Id := G.Exp(id) - st1, st2 := NewStatementFromScalars(true, α, β), NewStatementFromScalars(false, α, β) - c1, c2 := st1.Commit(Id), st2.Commit(Id) - if !c1.Verify() { + st1, st2 := NewBidFromScalars(true, α, β), NewBidFromScalars(false, α, β) + c1, p1 := st1.Commit(Id) + c2, p2 := st2.Commit(Id) + if !c1.Verify(p1) { t.Fatal("Could not verify st1 with c1, plus=true case") } - if !c2.Verify() { + if !c2.Verify(p2) { t.Fatal("Could not verify st2 with c2, plus=false case") } // Use the wrong proof - c2.Proof = c1.Proof - if c2.Verify() { + if c2.Verify(p1) { t.Fatal("Verify with wrong proof should have failed!") } } |