-
Notifications
You must be signed in to change notification settings - Fork 10
/
expstep.go
136 lines (106 loc) · 3.98 KB
/
expstep.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
package keyproof
import (
"github.com/privacybydesign/gabi/big"
"github.com/privacybydesign/gabi/internal/common"
"github.com/privacybydesign/gabi/zkproof"
)
type (
expStepStructure struct {
bitname string
stepa expStepAStructure
stepb expStepBStructure
}
expStepCommit struct {
isTypeA bool
acommit expStepACommit
aproof ExpStepAProof
achallenge *big.Int
bcommit expStepBCommit
bproof ExpStepBProof
bchallenge *big.Int
}
ExpStepProof struct {
Achallenge *big.Int
Aproof ExpStepAProof
Bchallenge *big.Int
Bproof ExpStepBProof
}
)
func newExpStepStructure(bitname, prename, postname, mulname, modname string, bitlen uint) expStepStructure {
return expStepStructure{
bitname: bitname,
stepa: newExpStepAStructure(bitname, prename, postname),
stepb: newExpStepBStructure(bitname, prename, postname, mulname, modname, bitlen),
}
}
func (s *expStepStructure) commitmentsFromSecrets(g zkproof.Group, list []*big.Int, bases zkproof.BaseLookup, secretdata zkproof.SecretLookup) ([]*big.Int, expStepCommit) {
var commit expStepCommit
if secretdata.Secret(s.bitname).Cmp(big.NewInt(0)) == 0 {
commit.isTypeA = true
// prove a
list, commit.acommit = s.stepa.commitmentsFromSecrets(g, list, bases, secretdata)
// fake b
commit.bchallenge = common.FastRandomBigInt(new(big.Int).Lsh(big.NewInt(1), 256))
commit.bproof = s.stepb.fakeProof(g)
list = s.stepb.commitmentsFromProof(g, list, commit.bchallenge, bases, commit.bproof)
} else {
commit.isTypeA = false
// fake a
commit.achallenge = common.FastRandomBigInt(new(big.Int).Lsh(big.NewInt(1), 256))
commit.aproof = s.stepa.fakeProof(g)
list = s.stepa.commitmentsFromProof(g, list, commit.achallenge, bases, commit.aproof)
// prove b
list, commit.bcommit = s.stepb.commitmentsFromSecrets(g, list, bases, secretdata)
}
return list, commit
}
func (s *expStepStructure) buildProof(g zkproof.Group, challenge *big.Int, commit expStepCommit, secretdata zkproof.SecretLookup) ExpStepProof {
var proof ExpStepProof
if commit.isTypeA {
// Build a proof
proof.Achallenge = new(big.Int).Xor(challenge, commit.bchallenge)
proof.Aproof = s.stepa.buildProof(g, proof.Achallenge, commit.acommit, secretdata)
// Copy b proof
proof.Bchallenge = commit.bchallenge
proof.Bproof = commit.bproof
} else {
// Copy a proof
proof.Achallenge = commit.achallenge
proof.Aproof = commit.aproof
// Build b proof
proof.Bchallenge = new(big.Int).Xor(challenge, commit.achallenge)
proof.Bproof = s.stepb.buildProof(g, proof.Bchallenge, commit.bcommit, secretdata)
}
return proof
}
func (s *expStepStructure) fakeProof(g zkproof.Group, challenge *big.Int) ExpStepProof {
var proof ExpStepProof
proof.Achallenge = common.FastRandomBigInt(new(big.Int).Lsh(big.NewInt(1), 256))
proof.Bchallenge = new(big.Int).Xor(challenge, proof.Achallenge)
proof.Aproof = s.stepa.fakeProof(g)
proof.Bproof = s.stepb.fakeProof(g)
return proof
}
func (s *expStepStructure) verifyProofStructure(challenge *big.Int, proof ExpStepProof) bool {
if proof.Achallenge == nil || proof.Bchallenge == nil {
return false
}
if challenge.Cmp(new(big.Int).Xor(proof.Achallenge, proof.Bchallenge)) != 0 {
return false
}
return s.stepa.verifyProofStructure(proof.Aproof) && s.stepb.verifyProofStructure(proof.Bproof)
}
func (s *expStepStructure) commitmentsFromProof(g zkproof.Group, list []*big.Int, _ *big.Int, bases zkproof.BaseLookup, proof ExpStepProof) []*big.Int {
list = s.stepa.commitmentsFromProof(g, list, proof.Achallenge, bases, proof.Aproof)
list = s.stepb.commitmentsFromProof(g, list, proof.Bchallenge, bases, proof.Bproof)
return list
}
func (s *expStepStructure) isTrue(secretdata zkproof.SecretLookup) bool {
return s.stepa.isTrue(secretdata) || s.stepb.isTrue(secretdata)
}
func (s *expStepStructure) numRangeProofs() int {
return s.stepa.numRangeProofs() + s.stepb.numRangeProofs()
}
func (s *expStepStructure) numCommitments() int {
return s.stepa.numCommitments() + s.stepb.numCommitments()
}