2016-06-01 01:08:43 +02:00
|
|
|
/* This file is part of libbrandt.
|
|
|
|
* Copyright (C) 2016 GNUnet e.V.
|
|
|
|
*
|
|
|
|
* libbrandt is free software: you can redistribute it and/or modify it under
|
|
|
|
* the terms of the GNU General Public License as published by the Free Software
|
|
|
|
* Foundation, either version 3 of the License, or (at your option) any later
|
|
|
|
* version.
|
|
|
|
*
|
|
|
|
* libbrandt is distributed in the hope that it will be useful, but WITHOUT ANY
|
|
|
|
* WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
|
|
|
|
* A PARTICULAR PURPOSE. See the GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License along with
|
|
|
|
* libbrandt. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @file smc.c
|
|
|
|
* @brief Implementation of the smc primitives.
|
|
|
|
*/
|
|
|
|
|
2016-06-13 21:01:14 +02:00
|
|
|
#include <gcrypt.h>
|
|
|
|
|
|
|
|
#include "crypto.h"
|
|
|
|
#include "smc.h"
|
2016-06-13 21:09:41 +02:00
|
|
|
#include "util.h"
|
2016-06-13 21:01:14 +02:00
|
|
|
|
|
|
|
extern gcry_ctx_t ec_ctx;
|
|
|
|
|
2016-06-13 21:09:41 +02:00
|
|
|
/**
|
|
|
|
* smc_zkp_dl
|
|
|
|
*
|
|
|
|
* @param v TODO
|
|
|
|
* @param g TODO
|
|
|
|
* @param x TODO
|
|
|
|
* @param a TODO
|
|
|
|
* @param c TODO
|
|
|
|
* @param r TODO
|
|
|
|
*/
|
2016-06-13 21:01:14 +02:00
|
|
|
void
|
2016-06-13 21:09:41 +02:00
|
|
|
smc_zkp_dl (gcry_mpi_point_t v, gcry_mpi_point_t g, gcry_mpi_t x,
|
|
|
|
gcry_mpi_point_t *a, gcry_mpi_t *c,
|
|
|
|
gcry_mpi_t *r)
|
2016-06-13 21:01:14 +02:00
|
|
|
{
|
2016-06-13 21:09:41 +02:00
|
|
|
gcry_mpi_t z = gcry_mpi_new (0);
|
2016-06-13 21:01:14 +02:00
|
|
|
|
2016-06-13 21:09:41 +02:00
|
|
|
brandt_ec_keypair_create_base (a, &z, g);
|
2016-06-15 00:52:18 +02:00
|
|
|
|
|
|
|
/* compute challange c */
|
2016-06-13 21:01:14 +02:00
|
|
|
/**TODO: generate c from HASH(g,v,a) and don't output it */
|
2016-06-13 21:09:41 +02:00
|
|
|
brandt_ec_skey_create (c);
|
2016-06-15 00:52:18 +02:00
|
|
|
|
2016-06-13 21:09:41 +02:00
|
|
|
*r = gcry_mpi_new (0);
|
|
|
|
gcry_mpi_mul (*r, *c, x);
|
|
|
|
gcry_mpi_add (*r, *r, z);
|
2016-06-13 21:01:14 +02:00
|
|
|
|
2016-06-13 21:09:41 +02:00
|
|
|
gcry_mpi_release (z);
|
2016-06-13 21:01:14 +02:00
|
|
|
}
|
|
|
|
|
2016-06-15 00:52:18 +02:00
|
|
|
|
2016-06-13 21:09:41 +02:00
|
|
|
/**
|
|
|
|
* smc_zkp_dl_check
|
|
|
|
*
|
|
|
|
* @param v TODO
|
|
|
|
* @param g TODO
|
|
|
|
* @param a TODO
|
|
|
|
* @param c TODO
|
|
|
|
* @param r TODO
|
|
|
|
* @return 0 if the proof is correct, something else otherwise
|
|
|
|
*/
|
2016-06-13 21:01:14 +02:00
|
|
|
int
|
2016-06-13 21:09:41 +02:00
|
|
|
smc_zkp_dl_check (gcry_mpi_point_t v, gcry_mpi_point_t g, gcry_mpi_point_t a,
|
|
|
|
gcry_mpi_t c,
|
|
|
|
gcry_mpi_t r)
|
2016-06-13 21:01:14 +02:00
|
|
|
{
|
2016-06-13 21:09:41 +02:00
|
|
|
int ret;
|
|
|
|
gcry_mpi_point_t left = gcry_mpi_point_new (0);
|
|
|
|
gcry_mpi_point_t right = gcry_mpi_point_new (0);
|
2016-06-13 21:01:14 +02:00
|
|
|
|
2016-06-13 21:09:41 +02:00
|
|
|
gcry_mpi_ec_mul (left, r, g, ec_ctx);
|
|
|
|
gcry_mpi_ec_mul (right, c, v, ec_ctx);
|
|
|
|
gcry_mpi_ec_add (right, a, right, ec_ctx);
|
2016-06-07 15:49:22 +02:00
|
|
|
|
2016-06-13 21:09:41 +02:00
|
|
|
ret = brandt_ec_point_cmp (left, right);
|
|
|
|
gcry_mpi_point_release (left);
|
|
|
|
gcry_mpi_point_release (right);
|
2016-06-01 01:08:43 +02:00
|
|
|
|
2016-06-13 21:01:14 +02:00
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2016-06-15 00:52:18 +02:00
|
|
|
|
|
|
|
void
|
|
|
|
smc_zkp_2dle (gcry_mpi_point_t v, gcry_mpi_point_t w, gcry_mpi_point_t g1, gcry_mpi_point_t g2, gcry_mpi_t x, gcry_mpi_point_t *a, gcry_mpi_point_t *b, gcry_mpi_t *c, gcry_mpi_t *r)
|
|
|
|
{
|
|
|
|
gcry_mpi_t z = gcry_mpi_new (0);
|
|
|
|
|
|
|
|
brandt_ec_keypair_create_base (a, &z, g1);
|
|
|
|
*b = gcry_mpi_point_new(0);
|
|
|
|
gcry_mpi_ec_mul(*b, z, g2, ec_ctx);
|
|
|
|
|
|
|
|
/* compute challange c */
|
|
|
|
/**TODO: generate c from HASH(g1,g2,v,w,a,b) and don't output it */
|
|
|
|
brandt_ec_skey_create (c);
|
|
|
|
|
|
|
|
*r = gcry_mpi_new (0);
|
|
|
|
gcry_mpi_mul (*r, *c, x);
|
|
|
|
gcry_mpi_add (*r, *r, z);
|
|
|
|
|
|
|
|
gcry_mpi_release (z);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int
|
|
|
|
smc_zkp_2dle_check (gcry_mpi_point_t v, gcry_mpi_point_t w, gcry_mpi_point_t g1, gcry_mpi_point_t g2, gcry_mpi_point_t a, gcry_mpi_point_t b, gcry_mpi_t c, gcry_mpi_t r)
|
|
|
|
{
|
|
|
|
int ret;
|
|
|
|
gcry_mpi_point_t left = gcry_mpi_point_new (0);
|
|
|
|
gcry_mpi_point_t right = gcry_mpi_point_new (0);
|
|
|
|
|
|
|
|
gcry_mpi_ec_mul (left, r, g1, ec_ctx);
|
|
|
|
gcry_mpi_ec_mul (right, c, v, ec_ctx);
|
|
|
|
gcry_mpi_ec_add (right, a, right, ec_ctx);
|
|
|
|
ret = brandt_ec_point_cmp (left, right);
|
|
|
|
|
|
|
|
gcry_mpi_ec_mul (left, r, g2, ec_ctx);
|
|
|
|
gcry_mpi_ec_mul (right, c, w, ec_ctx);
|
|
|
|
gcry_mpi_ec_add (right, b, right, ec_ctx);
|
|
|
|
ret &= brandt_ec_point_cmp (left, right);
|
|
|
|
|
|
|
|
gcry_mpi_point_release (left);
|
|
|
|
gcry_mpi_point_release (right);
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2016-06-13 21:09:41 +02:00
|
|
|
//GEN
|
|
|
|
//smc_hextodec (const char *s)
|
|
|
|
//{
|
|
|
|
// size_t i;
|
|
|
|
// char c;
|
|
|
|
// pari_sp ltop = avma;
|
|
|
|
// GEN ret = gen_0;
|
|
|
|
//
|
|
|
|
// for (i = 0; i < strlen (s); i++)
|
|
|
|
// {
|
|
|
|
// errno = 0;
|
|
|
|
// if (1 != sscanf (&s[i], "%1hhx", &c))
|
|
|
|
// {
|
|
|
|
// brandt_eprintf ("failed to parse hex (\"%s\") to decimal:", s);
|
|
|
|
// return NULL;
|
|
|
|
// }
|
|
|
|
// ret = addis (shifti (ret, 4), c);
|
|
|
|
// }
|
|
|
|
// return gerepilecopy (ltop, ret);
|
|
|
|
//}
|