Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,23 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [0.5.2] - Unreleased

### Added

- `RingContext::new_without_blinding(ring_size)`: runtime replacement for the
removed `test-vectors` feature. Provers built from such a context generate
deterministic (non zero-knowledge) proofs, still valid for verifiers using
a regular context for the same ring size.

### Changed

- arkworks dependencies bumped to 0.6.

### Removed

- `test-vectors` feature. Cargo features are additive: any crate in the
dependency graph could enable it, silently disabling ring proof blinding
for every other user of the same build.

### Security

- The group identity is now rejected as a public key: its secret scalar is
Expand Down
32 changes: 15 additions & 17 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -11,29 +11,30 @@ categories = ["cryptography", "no-std"]
autobenches = false

[dependencies]
ark-ec = { version = "0.5", default-features = false }
ark-ff = { version = "0.5", default-features = false }
ark-std = { version = "0.5", default-features = false }
ark-serialize = { version = "0.5", default-features = false }
ark-ec = { version = "0.6", default-features = false }
ark-ff = { version = "0.6", default-features = false }
ark-std = { version = "0.6", default-features = false }
ark-serialize = { version = "0.6", default-features = false }
zeroize = { version = "1.8", default-features = false }
digest = { version = "0.10", default-features = false }
generic-array = { version = "0.14", default-features = false }
sha2 = { version = "0.10", default-features = false }
sha3 = { version = "0.10", default-features = false, optional = true }
rayon = { version = "1.10", default-features = false, optional = true }
w3f-ring-proof = { version = "0.0.8", default-features = false, optional = true }
# TODO: switch back to a crates.io version once `Domain::without_blinding` is released
w3f-ring-proof = { git = "https://github.com/paritytech/ring-proof", rev = "501c18a58c383a8f38abe7f4ae0648a0a68583e9", default-features = false, optional = true }
# Curves
ark-secp256r1 = { version = "0.5", default-features = false, optional = true }
ark-ed25519 = { version = "0.5", default-features = false, optional = true }
ark-ed-on-bls12-381 = { version = "0.5", default-features = false, optional = true }
ark-ed-on-bls12-381-bandersnatch = { version = "0.5", default-features = false, optional = true }
ark-bls12-381 = { version = "0.5", default-features = false, optional = true }
ark-ed-on-bn254 = { version = "0.5", default-features = false, optional = true }
ark-bn254 = { version = "0.5", default-features = false, optional = true }
ark-secp256r1 = { version = "0.6", default-features = false, optional = true }
ark-ed25519 = { version = "0.6", default-features = false, optional = true }
ark-ed-on-bls12-381 = { version = "0.6", default-features = false, optional = true }
ark-ed-on-bls12-381-bandersnatch = { version = "0.6", default-features = false, optional = true }
ark-bls12-381 = { version = "0.6", default-features = false, optional = true }
ark-ed-on-bn254 = { version = "0.6", default-features = false, optional = true }
ark-bn254 = { version = "0.6", default-features = false, optional = true }

[dev-dependencies]
ark-std = { version = "0.5", default-features = false, features = ["getrandom"] }
ark-ed25519 = { version = "0.5" }
ark-std = { version = "0.6", default-features = false, features = ["getrandom"] }
ark-ed25519 = { version = "0.6" }
hex = { version = "0.4" }
serde = { version = "1.0", features = ["derive"] }
serde_json = { version = "1.0" }
Expand Down Expand Up @@ -106,8 +107,5 @@ asm = [
"sha2/asm",
"sha3?/asm"
]
# Deterministic, no-zk, ring-proof (unsafe)
test-vectors = [ "w3f-ring-proof?/test-vectors" ]

[package.metadata.docs.rs]
features = [ "full" ]
3 changes: 1 addition & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -233,12 +233,11 @@ let verifier_key = ring_setup.verifier_key_from_commitment(ring_commitment);
## Features

- `default`: `std`
- `full`: Enables all features listed below except `secret-split`, `parallel`, `asm`, `test-vectors`.
- `full`: Enables all features listed below except `secret-split`, `parallel`, `asm`.
- `secret-split`: Split-secret scalar multiplication. Secret scalar is split into the sum
of two scalars, which randomly mutate but retain the same sum. Incurs 2x penalty in some internal
sensible scalar multiplications, but provides side channel defenses.
- `ring`: Ring-VRF for the curves supporting it.
- `test-vectors`: Deterministic ring-vrf proof. Useful for reproducible test vectors generation.

### Curves

Expand Down
2 changes: 1 addition & 1 deletion data/vectors-generate.sh
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ mkdir -p vectors
cargo test \
--lib \
--release \
--features full,shake128,test-vectors \
--features full,shake128 \
-- \
--nocapture \
--ignored
3 changes: 1 addition & 2 deletions src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -65,12 +65,11 @@
//! ## Features
//!
//! - `default`: `std`
//! - `full`: Enables all features listed below except `secret-split`, `parallel`, `asm`, `test-vectors`.
//! - `full`: Enables all features listed below except `secret-split`, `parallel`, `asm`.
//! - `secret-split`: Split-secret scalar multiplication. Secret scalar is split into the sum
//! of two scalars, which randomly mutate but retain the same sum. Incurs 2x penalty in some internal
//! sensible scalar multiplications, but provides side channel defenses.
//! - `ring`: Ring-VRF for the curves supporting it.
//! - `test-vectors`: Deterministic ring-vrf proof. Useful for reproducible test vectors generation.
//!
//! ### Curves
//!
Expand Down
39 changes: 28 additions & 11 deletions src/ring.rs
Original file line number Diff line number Diff line change
Expand Up @@ -95,8 +95,7 @@ pub trait RingSuite:
pub type Kzg<S> = ring_proof::pcs::kzg::KZG<<S as RingSuite>::Pairing>;

/// KZG commitment.
pub type PcsCommitment<S> =
ring_proof::pcs::kzg::commitment::KzgCommitment<<S as RingSuite>::Pairing>;
pub type PcsCommitment<S> = <Kzg<S> as ring_proof::pcs::PCS<BaseField<S>>>::C;

/// KZG Polynomial Commitment Scheme parameters.
///
Expand All @@ -115,7 +114,7 @@ pub type PcsVerifierParams<S> = <PcsParams<S> as ring_proof::pcs::PcsParams>::RV
///
/// Basically all the application specific parameters required to construct and
/// verify the ring proof.
pub type PiopParams<S> = ring_proof::PiopParams<BaseField<S>, CurveConfig<S>>;
pub type PiopParams<S> = ring_proof::PiopParams<TEAffine<CurveConfig<S>>>;

/// Ring keys commitment.
pub type RingCommitment<S> = ring_proof::FixedColumnsCommitted<BaseField<S>, PcsCommitment<S>>;
Expand Down Expand Up @@ -261,9 +260,27 @@ pub struct RingContext<S: RingSuite> {
impl<S: RingSuite> RingContext<S> {
/// Construct context for the given ring size.
pub fn new(ring_size: usize) -> Self {
Self::construct(ring_size, true)
}

/// Construct a context whose provers generate deterministic proofs.
///
/// Column blinding is disabled: proofs are reproducible, thus NOT zero-knowledge,
/// but remain valid for verifiers using a regular context for the same ring size.
/// Useful for reproducible test vectors generation.
pub fn new_without_blinding(ring_size: usize) -> Self {
Self::construct(ring_size, false)
}

fn construct(ring_size: usize, blinding: bool) -> Self {
let domain_size = piop_domain_size::<S>(ring_size);
let mut domain =
ring_proof::Domain::with_zk_rows(domain_size, ring_proof::piop::params::ZK_ROWS);
if !blinding {
domain = domain.without_blinding();
}
let piop_params = PiopParams::<S>::setup(
ring_proof::Domain::new(domain_size, true),
domain,
S::BLINDING_BASE
.into_te()
.expect("BLINDING_BASE must not be identity"),
Expand Down Expand Up @@ -508,7 +525,7 @@ pub struct RingBuilderPcsParams<S: RingSuite>(pub Vec<G1Affine<S>>);

// Under construction ring commitment.
type PartialRingCommitment<S> =
ring_proof::ring::Ring<BaseField<S>, <S as RingSuite>::Pairing, CurveConfig<S>>;
ring_proof::ring::Ring<BaseField<S>, <S as RingSuite>::Pairing, TEAffine<CurveConfig<S>>>;

/// Builder for incremental construction of ring verifier keys.
///
Expand Down Expand Up @@ -1421,9 +1438,10 @@ pub(crate) mod testing {
let mut ring_pks = common::random_vec::<AffinePoint<S>>(TEST_RING_SIZE, Some(rng));
ring_pks[prover_idx] = public.0;

let ring_ctx = ring_setup.ring_context();
// Blinding is disabled to make the proof reproducible
let ring_ctx = RingContext::<S>::new_without_blinding(TEST_RING_SIZE);
let prover_key = ring_setup.prover_key(&ring_pks).unwrap();
let prover = ring_ctx.ring_prover(prover_key, prover_idx);
let prover = ring_ctx.into_ring_prover(prover_key, prover_idx);
let proof = secret.prove(io, ad, &prover);

let verifier_key = ring_setup.verifier_key(&ring_pks).unwrap();
Expand Down Expand Up @@ -1483,7 +1501,8 @@ pub(crate) mod testing {

let prover_idx = self.ring_pks.iter().position(|&pk| pk == public.0).unwrap();

let ring_ctx = ring_setup.ring_context();
// Blinding is disabled to reproduce the exact proof in the vector
let ring_ctx = RingContext::<S>::new_without_blinding(TEST_RING_SIZE);
let prover_key = ring_setup.prover_key(&self.ring_pks).unwrap();
let prover = ring_ctx.ring_prover(prover_key, prover_idx);

Expand All @@ -1500,10 +1519,8 @@ pub(crate) mod testing {
assert_eq!(p.0, p.1);
}

#[cfg(feature = "test-vectors")]
{
// Verify if the ring-proof matches. This check is performed only when
// deterministic proof generation is required for test vectors.
// Check if the (deterministic) ring proof matches
let mut p = (Vec::new(), Vec::new());
self.ring_proof.serialize_compressed(&mut p.0).unwrap();
proof.ring_proof.serialize_compressed(&mut p.1).unwrap();
Expand Down
Loading