Struct frost_schnorrkel::frost::curve::Ristretto
source · pub struct Ristretto;
Available on crate feature
ristretto
only.Expand description
Ciphersuite for Ristretto.
hash_to_F is implemented with a naive concatenation of the dst and data, allowing transposition
between the two. This means dst: b"abc", data: b"def"
, will produce the same scalar as
dst: "abcdef", data: b""
. Please use carefully, not letting dsts be substrings of each other.
Trait Implementations§
source§impl Algorithm<Ristretto> for Schnorrkel
impl Algorithm<Ristretto> for Schnorrkel
§type Transcript = MerlinTranscript
type Transcript = MerlinTranscript
The transcript format this algorithm uses. This likely should NOT be the IETF-compatible
transcript included in this crate.
§type Addendum = ()
type Addendum = ()
Serializable addendum, used in algorithms requiring more data than just the nonces.
source§fn transcript(&mut self) -> &mut Self::Transcript
fn transcript(&mut self) -> &mut Self::Transcript
Obtain a mutable borrow of the underlying transcript.
source§fn nonces(&self) -> Vec<Vec<<Ristretto as Ciphersuite>::G>>
fn nonces(&self) -> Vec<Vec<<Ristretto as Ciphersuite>::G>>
Obtain the list of nonces to generate, as specified by the generators to create commitments
against per-nonce. Read more
source§fn preprocess_addendum<R: RngCore + CryptoRng>(
&mut self,
_: &mut R,
_: &ThresholdKeys<Ristretto>,
)
fn preprocess_addendum<R: RngCore + CryptoRng>( &mut self, _: &mut R, _: &ThresholdKeys<Ristretto>, )
Generate an addendum to FROST“s preprocessing stage.
source§fn read_addendum<R: Read>(&self, _: &mut R) -> Result<Self::Addendum>
fn read_addendum<R: Read>(&self, _: &mut R) -> Result<Self::Addendum>
Read an addendum from a reader.
source§fn process_addendum(
&mut self,
_: &ThresholdView<Ristretto>,
_: Participant,
(): (),
) -> Result<(), FrostError>
fn process_addendum( &mut self, _: &ThresholdView<Ristretto>, _: Participant, (): (), ) -> Result<(), FrostError>
Process the addendum for the specified participant. Guaranteed to be called in order.
Sign a share with the given secret/nonce.
The secret will already have been its lagrange coefficient applied so it is the necessary
key share.
The nonce will already have been processed into the combined form d + (e * p).
source§fn verify(
&self,
group_key: <Ristretto as Ciphersuite>::G,
nonces: &[Vec<<Ristretto as Ciphersuite>::G>],
sum: <Ristretto as Ciphersuite>::F,
) -> Option<Self::Signature>
fn verify( &self, group_key: <Ristretto as Ciphersuite>::G, nonces: &[Vec<<Ristretto as Ciphersuite>::G>], sum: <Ristretto as Ciphersuite>::F, ) -> Option<Self::Signature>
Verify a signature.
Verify a specific share given as a response.
This function should return a series of pairs whose products should sum to zero for a valid
share. Any error raised is treated as the share being invalid.
source§impl Ciphersuite for Ristretto
impl Ciphersuite for Ristretto
§type G = RistrettoPoint
type G = RistrettoPoint
Group element type.
§type H = CoreWrapper<CtVariableCoreWrapper<Sha512VarCore, UInt<UInt<UInt<UInt<UInt<UInt<UInt<UTerm, B1>, B0>, B0>, B0>, B0>, B0>, B0>, OidSha512>>
type H = CoreWrapper<CtVariableCoreWrapper<Sha512VarCore, UInt<UInt<UInt<UInt<UInt<UInt<UInt<UTerm, B1>, B0>, B0>, B0>, B0>, B0>, B0>, OidSha512>>
Hash algorithm used with this curve.
source§fn hash_to_F(dst: &[u8], data: &[u8]) -> <Ristretto as Ciphersuite>::F
fn hash_to_F(dst: &[u8], data: &[u8]) -> <Ristretto as Ciphersuite>::F
Hash the provided domain-separation tag and message to a scalar. Ciphersuites MAY naively
prefix the tag to the message, enabling transpotion between the two. Accordingly, this
function should NOT be used in any scheme where one tag is a valid substring of another
UNLESS the specific Ciphersuite is verified to handle the DST securely. Read more
source§fn random_nonzero_F<R>(rng: &mut R) -> Self::F
fn random_nonzero_F<R>(rng: &mut R) -> Self::F
Generate a random non-zero scalar.
source§impl Curve for Ristretto
impl Curve for Ristretto
source§fn hash(
dst: &[u8],
data: &[u8],
) -> GenericArray<u8, <Self::H as OutputSizeUser>::OutputSize>
fn hash( dst: &[u8], data: &[u8], ) -> GenericArray<u8, <Self::H as OutputSizeUser>::OutputSize>
Hash the given dst and data to a byte vector. Used to instantiate H4 and H5.
source§fn hash_to_F(dst: &[u8], msg: &[u8]) -> Self::F
fn hash_to_F(dst: &[u8], msg: &[u8]) -> Self::F
Field element from hash. Used during key gen and by other crates under Serai as a general
utility. Used to instantiate H1 and H3.
source§fn hash_msg(
msg: &[u8],
) -> GenericArray<u8, <Self::H as OutputSizeUser>::OutputSize>
fn hash_msg( msg: &[u8], ) -> GenericArray<u8, <Self::H as OutputSizeUser>::OutputSize>
Hash the message for the binding factor. H4 from the IETF draft.
source§fn hash_commitments(
commitments: &[u8],
) -> GenericArray<u8, <Self::H as OutputSizeUser>::OutputSize>
fn hash_commitments( commitments: &[u8], ) -> GenericArray<u8, <Self::H as OutputSizeUser>::OutputSize>
Hash the commitments for the binding factor. H5 from the IETF draft.
source§fn hash_binding_factor(binding: &[u8]) -> Self::F
fn hash_binding_factor(binding: &[u8]) -> Self::F
Hash the commitments and message to calculate the binding factor. H1 from the IETF draft.
source§impl Hram<Ristretto> for IetfRistrettoHram
impl Hram<Ristretto> for IetfRistrettoHram
source§impl PartialEq for Ristretto
impl PartialEq for Ristretto
impl Copy for Ristretto
impl Eq for Ristretto
impl StructuralPartialEq for Ristretto
Auto Trait Implementations§
impl Freeze for Ristretto
impl RefUnwindSafe for Ristretto
impl Send for Ristretto
impl Sync for Ristretto
impl Unpin for Ristretto
impl UnwindSafe for Ristretto
Blanket Implementations§
source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
source§impl<T> CloneToUninit for Twhere
T: Copy,
impl<T> CloneToUninit for Twhere
T: Copy,
source§unsafe fn clone_to_uninit(&self, dst: *mut T)
unsafe fn clone_to_uninit(&self, dst: *mut T)
🔬This is a nightly-only experimental API. (
clone_to_uninit
)source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
source§default unsafe fn clone_to_uninit(&self, dst: *mut T)
default unsafe fn clone_to_uninit(&self, dst: *mut T)
🔬This is a nightly-only experimental API. (
clone_to_uninit
)source§impl<T> FmtForward for T
impl<T> FmtForward for T
source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
Causes
self
to use its Binary
implementation when Debug
-formatted.source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
Causes
self
to use its Display
implementation when
Debug
-formatted.source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
Causes
self
to use its LowerExp
implementation when
Debug
-formatted.source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
Causes
self
to use its LowerHex
implementation when
Debug
-formatted.source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
Causes
self
to use its Octal
implementation when Debug
-formatted.source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
Causes
self
to use its Pointer
implementation when
Debug
-formatted.source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
Causes
self
to use its UpperExp
implementation when
Debug
-formatted.source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
Causes
self
to use its UpperHex
implementation when
Debug
-formatted.source§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Pipes by value. This is generally the method you want to use. Read more
source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
Borrows
self
and passes that borrow into the pipe function. Read moresource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
Mutably borrows
self
and passes that borrow into the pipe function. Read moresource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
Borrows
self
, then passes self.as_ref()
into the pipe function.source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
Mutably borrows
self
, then passes self.as_mut()
into the pipe
function.source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
Borrows
self
, then passes self.deref()
into the pipe function.source§impl<T> Tap for T
impl<T> Tap for T
source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Immutable access to the
Borrow<B>
of a value. Read moresource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
Mutable access to the
BorrowMut<B>
of a value. Read moresource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
Immutable access to the
AsRef<R>
view of a value. Read moresource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
Mutable access to the
AsMut<R>
view of a value. Read moresource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Immutable access to the
Deref::Target
of a value. Read moresource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Mutable access to the
Deref::Target
of a value. Read moresource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
Calls
.tap()
only in debug builds, and is erased in release builds.source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
Calls
.tap_mut()
only in debug builds, and is erased in release
builds.source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
Calls
.tap_borrow()
only in debug builds, and is erased in release
builds.source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
Calls
.tap_borrow_mut()
only in debug builds, and is erased in release
builds.source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
Calls
.tap_ref()
only in debug builds, and is erased in release
builds.source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
Calls
.tap_ref_mut()
only in debug builds, and is erased in release
builds.source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
Calls
.tap_deref()
only in debug builds, and is erased in release
builds.