2022-06-08 01:36:46 +02:00
|
|
|
// Copyright (c) 2018-2022 The Dash Core developers
|
2018-10-03 14:53:21 +02:00
|
|
|
// Distributed under the MIT software license, see the accompanying
|
|
|
|
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
|
|
|
|
|
|
|
|
#ifndef DASH_CRYPTO_BLS_H
|
|
|
|
#define DASH_CRYPTO_BLS_H
|
|
|
|
|
2020-03-19 23:46:56 +01:00
|
|
|
#include <hash.h>
|
|
|
|
#include <serialize.h>
|
|
|
|
#include <uint256.h>
|
2021-06-27 08:33:13 +02:00
|
|
|
#include <util/strencodings.h>
|
2021-12-21 13:05:29 +01:00
|
|
|
#include <util/ranges.h>
|
2018-10-03 14:53:21 +02:00
|
|
|
|
2021-03-26 13:32:31 +01:00
|
|
|
// bls-dash uses relic, which may define DEBUG and ERROR, which leads to many warnings in some build setups
|
|
|
|
#undef ERROR
|
|
|
|
#undef DEBUG
|
2022-11-22 18:34:46 +01:00
|
|
|
#include <dashbls/bls.hpp>
|
|
|
|
#include <dashbls/privatekey.hpp>
|
|
|
|
#include <dashbls/elements.hpp>
|
|
|
|
#include <dashbls/schemes.hpp>
|
|
|
|
#include <dashbls/threshold.hpp>
|
2018-10-31 10:58:02 +01:00
|
|
|
#undef DOUBLE
|
2021-12-22 07:07:44 +01:00
|
|
|
#undef SEED
|
2018-10-03 14:53:21 +02:00
|
|
|
|
|
|
|
#include <array>
|
2019-04-11 22:11:39 +02:00
|
|
|
#include <mutex>
|
2018-10-03 14:53:21 +02:00
|
|
|
#include <unistd.h>
|
|
|
|
|
2022-09-30 17:29:51 +02:00
|
|
|
#include <atomic>
|
|
|
|
|
|
|
|
namespace bls {
|
|
|
|
extern std::atomic<bool> bls_legacy_scheme;
|
|
|
|
}
|
2021-03-26 13:32:31 +01:00
|
|
|
|
2018-10-03 14:53:21 +02:00
|
|
|
// reversed BLS12-381
|
2021-10-01 13:44:40 +02:00
|
|
|
constexpr int BLS_CURVE_ID_SIZE{32};
|
|
|
|
constexpr int BLS_CURVE_SECKEY_SIZE{32};
|
|
|
|
constexpr int BLS_CURVE_PUBKEY_SIZE{48};
|
|
|
|
constexpr int BLS_CURVE_SIG_SIZE{96};
|
2018-10-03 14:53:21 +02:00
|
|
|
|
|
|
|
class CBLSSignature;
|
|
|
|
class CBLSPublicKey;
|
|
|
|
|
|
|
|
template <typename ImplType, size_t _SerSize, typename C>
|
|
|
|
class CBLSWrapper
|
|
|
|
{
|
|
|
|
friend class CBLSSecretKey;
|
|
|
|
friend class CBLSPublicKey;
|
|
|
|
friend class CBLSSignature;
|
|
|
|
|
|
|
|
protected:
|
|
|
|
ImplType impl;
|
|
|
|
bool fValid{false};
|
|
|
|
mutable uint256 cachedHash;
|
|
|
|
|
|
|
|
public:
|
2021-10-10 23:41:53 +02:00
|
|
|
static constexpr size_t SerSize = _SerSize;
|
2018-10-03 14:53:21 +02:00
|
|
|
|
2022-09-30 17:29:51 +02:00
|
|
|
explicit CBLSWrapper() = default;
|
|
|
|
explicit CBLSWrapper(const std::vector<unsigned char>& vecBytes) : CBLSWrapper<ImplType, _SerSize, C>()
|
2020-12-15 00:26:30 +01:00
|
|
|
{
|
2021-02-27 08:36:00 +01:00
|
|
|
SetByteVector(vecBytes);
|
2020-12-15 00:26:30 +01:00
|
|
|
}
|
2018-10-03 14:53:21 +02:00
|
|
|
|
|
|
|
CBLSWrapper(const CBLSWrapper& ref) = default;
|
|
|
|
CBLSWrapper& operator=(const CBLSWrapper& ref) = default;
|
2021-06-06 22:43:44 +02:00
|
|
|
CBLSWrapper(CBLSWrapper&& ref) noexcept
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
|
|
|
std::swap(impl, ref.impl);
|
|
|
|
std::swap(fValid, ref.fValid);
|
|
|
|
std::swap(cachedHash, ref.cachedHash);
|
|
|
|
}
|
2021-06-06 22:43:44 +02:00
|
|
|
CBLSWrapper& operator=(CBLSWrapper&& ref) noexcept
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
|
|
|
std::swap(impl, ref.impl);
|
|
|
|
std::swap(fValid, ref.fValid);
|
|
|
|
std::swap(cachedHash, ref.cachedHash);
|
|
|
|
return *this;
|
|
|
|
}
|
|
|
|
|
2021-07-31 20:29:12 +02:00
|
|
|
virtual ~CBLSWrapper() = default;
|
2021-07-28 22:13:26 +02:00
|
|
|
|
2018-10-03 14:53:21 +02:00
|
|
|
bool operator==(const C& r) const
|
|
|
|
{
|
|
|
|
return fValid == r.fValid && impl == r.impl;
|
|
|
|
}
|
|
|
|
bool operator!=(const C& r) const
|
|
|
|
{
|
|
|
|
return !((*this) == r);
|
|
|
|
}
|
|
|
|
|
|
|
|
bool IsValid() const
|
|
|
|
{
|
|
|
|
return fValid;
|
|
|
|
}
|
|
|
|
|
2021-02-27 08:36:00 +01:00
|
|
|
void Reset()
|
|
|
|
{
|
2022-09-30 17:29:51 +02:00
|
|
|
*(static_cast<C*>(this)) = C();
|
2021-02-27 08:36:00 +01:00
|
|
|
}
|
|
|
|
|
2022-09-30 17:29:51 +02:00
|
|
|
void SetByteVector(const std::vector<uint8_t>& vecBytes, const bool specificLegacyScheme)
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
2021-02-27 08:36:00 +01:00
|
|
|
if (vecBytes.size() != SerSize) {
|
2018-10-20 16:08:40 +02:00
|
|
|
Reset();
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2021-12-21 13:05:29 +01:00
|
|
|
if (ranges::all_of(vecBytes, [](uint8_t c) { return c == 0; })) {
|
2018-10-03 14:53:21 +02:00
|
|
|
Reset();
|
|
|
|
} else {
|
2020-12-12 10:45:43 +01:00
|
|
|
try {
|
2022-09-30 17:29:51 +02:00
|
|
|
impl = ImplType::FromBytes(bls::Bytes(vecBytes), specificLegacyScheme);
|
2020-12-12 10:45:43 +01:00
|
|
|
fValid = true;
|
|
|
|
} catch (...) {
|
2018-10-03 14:53:21 +02:00
|
|
|
Reset();
|
|
|
|
}
|
|
|
|
}
|
2021-03-12 23:54:20 +01:00
|
|
|
cachedHash.SetNull();
|
2018-10-03 14:53:21 +02:00
|
|
|
}
|
|
|
|
|
2022-09-30 17:29:51 +02:00
|
|
|
void SetByteVector(const std::vector<uint8_t>& vecBytes)
|
|
|
|
{
|
|
|
|
SetByteVector(vecBytes, bls::bls_legacy_scheme.load());
|
|
|
|
}
|
|
|
|
|
|
|
|
std::vector<uint8_t> ToByteVector(const bool specificLegacyScheme) const
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
|
|
|
if (!fValid) {
|
2021-02-27 08:36:00 +01:00
|
|
|
return std::vector<uint8_t>(SerSize, 0);
|
2018-10-03 14:53:21 +02:00
|
|
|
}
|
2022-09-30 17:29:51 +02:00
|
|
|
return impl.Serialize(specificLegacyScheme);
|
|
|
|
}
|
|
|
|
|
|
|
|
std::vector<uint8_t> ToByteVector() const
|
|
|
|
{
|
|
|
|
return ToByteVector(bls::bls_legacy_scheme.load());
|
2018-10-03 14:53:21 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
const uint256& GetHash() const
|
|
|
|
{
|
2021-03-12 23:54:20 +01:00
|
|
|
if (cachedHash.IsNull()) {
|
|
|
|
cachedHash = ::SerializeHash(*this);
|
|
|
|
}
|
2018-10-03 14:53:21 +02:00
|
|
|
return cachedHash;
|
|
|
|
}
|
|
|
|
|
2022-12-30 06:45:31 +01:00
|
|
|
bool SetHexStr(const std::string& str, const bool specificLegacyScheme)
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
2019-04-08 07:07:26 +02:00
|
|
|
if (!IsHex(str)) {
|
|
|
|
Reset();
|
|
|
|
return false;
|
|
|
|
}
|
2018-10-03 14:53:21 +02:00
|
|
|
auto b = ParseHex(str);
|
|
|
|
if (b.size() != SerSize) {
|
2019-04-08 07:07:26 +02:00
|
|
|
Reset();
|
2018-10-03 14:53:21 +02:00
|
|
|
return false;
|
|
|
|
}
|
2022-12-30 06:45:31 +01:00
|
|
|
SetByteVector(b, specificLegacyScheme);
|
2018-10-03 14:53:21 +02:00
|
|
|
return IsValid();
|
|
|
|
}
|
|
|
|
|
2022-12-30 06:45:31 +01:00
|
|
|
bool SetHexStr(const std::string& str)
|
|
|
|
{
|
|
|
|
return SetHexStr(str, bls::bls_legacy_scheme.load());
|
|
|
|
}
|
|
|
|
|
2019-07-02 06:16:27 +02:00
|
|
|
inline void Serialize(CSizeComputer& s) const
|
|
|
|
{
|
|
|
|
s.seek(SerSize);
|
|
|
|
}
|
|
|
|
|
2022-09-30 17:29:51 +02:00
|
|
|
template <typename Stream>
|
|
|
|
inline void Serialize(Stream& s, const bool specificLegacyScheme) const
|
|
|
|
{
|
|
|
|
s.write(reinterpret_cast<const char*>(ToByteVector(specificLegacyScheme).data()), SerSize);
|
|
|
|
}
|
|
|
|
|
2018-10-03 14:53:21 +02:00
|
|
|
template <typename Stream>
|
|
|
|
inline void Serialize(Stream& s) const
|
|
|
|
{
|
2022-09-30 17:29:51 +02:00
|
|
|
Serialize(s, bls::bls_legacy_scheme.load());
|
2018-10-03 14:53:21 +02:00
|
|
|
}
|
2022-09-30 17:29:51 +02:00
|
|
|
|
2018-10-03 14:53:21 +02:00
|
|
|
template <typename Stream>
|
2022-09-30 17:29:51 +02:00
|
|
|
inline void Unserialize(Stream& s, const bool specificLegacyScheme, bool checkMalleable = true)
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
2021-02-27 08:36:00 +01:00
|
|
|
std::vector<uint8_t> vecBytes(SerSize, 0);
|
2022-08-11 01:05:44 +02:00
|
|
|
s.read(reinterpret_cast<char*>(vecBytes.data()), SerSize);
|
2022-09-30 17:29:51 +02:00
|
|
|
SetByteVector(vecBytes, specificLegacyScheme);
|
2018-10-03 14:53:21 +02:00
|
|
|
|
2022-12-30 06:45:31 +01:00
|
|
|
if (checkMalleable && !CheckMalleable(vecBytes, specificLegacyScheme)) {
|
2023-03-09 09:13:00 +01:00
|
|
|
// If CheckMalleable failed with specificLegacyScheme, we need to try again with the opposite scheme.
|
|
|
|
// Probably we received the BLS object sent with legacy scheme, but in the meanwhile the fork activated.
|
|
|
|
SetByteVector(vecBytes, !specificLegacyScheme);
|
|
|
|
if (!CheckMalleable(vecBytes, !specificLegacyScheme)) {
|
|
|
|
// Both attempts failed
|
|
|
|
throw std::ios_base::failure("malleable BLS object");
|
|
|
|
} else {
|
|
|
|
// Indeed the received vecBytes was in opposite scheme. But we can't keep it (mixing with the new scheme will lead to undefined behavior)
|
|
|
|
// Therefore, resetting current object (basically marking it as invalid).
|
|
|
|
Reset();
|
|
|
|
}
|
2018-10-26 15:51:11 +02:00
|
|
|
}
|
2018-10-03 14:53:21 +02:00
|
|
|
}
|
|
|
|
|
2022-09-30 17:29:51 +02:00
|
|
|
template <typename Stream>
|
|
|
|
inline void Unserialize(Stream& s, bool checkMalleable = true)
|
|
|
|
{
|
|
|
|
Unserialize(s, bls::bls_legacy_scheme.load(), checkMalleable);
|
|
|
|
}
|
|
|
|
|
|
|
|
inline bool CheckMalleable(const std::vector<uint8_t>& vecBytes, const bool specificLegacyScheme) const
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
2022-09-30 17:29:51 +02:00
|
|
|
if (memcmp(vecBytes.data(), ToByteVector(specificLegacyScheme).data(), SerSize)) {
|
2018-10-03 14:53:21 +02:00
|
|
|
// TODO not sure if this is actually possible with the BLS libs. I'm assuming here that somewhere deep inside
|
|
|
|
// these libs masking might happen, so that 2 different binary representations could result in the same object
|
|
|
|
// representation
|
2019-04-11 22:11:39 +02:00
|
|
|
return false;
|
2018-10-03 14:53:21 +02:00
|
|
|
}
|
2019-04-11 22:11:39 +02:00
|
|
|
return true;
|
2018-10-03 14:53:21 +02:00
|
|
|
}
|
|
|
|
|
2022-09-30 17:29:51 +02:00
|
|
|
inline bool CheckMalleable(const std::vector<uint8_t>& vecBytes) const
|
|
|
|
{
|
|
|
|
return CheckMalleable(vecBytes, bls::bls_legacy_scheme.load());
|
|
|
|
}
|
|
|
|
|
|
|
|
inline std::string ToString(const bool specificLegacyScheme) const
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
2022-09-30 17:29:51 +02:00
|
|
|
std::vector<uint8_t> buf = ToByteVector(specificLegacyScheme);
|
2021-05-18 19:17:10 +02:00
|
|
|
return HexStr(buf);
|
2018-10-03 14:53:21 +02:00
|
|
|
}
|
2022-09-30 17:29:51 +02:00
|
|
|
|
|
|
|
inline std::string ToString() const
|
|
|
|
{
|
|
|
|
return ToString(bls::bls_legacy_scheme.load());
|
|
|
|
}
|
2018-10-03 14:53:21 +02:00
|
|
|
};
|
|
|
|
|
2020-12-12 10:45:43 +01:00
|
|
|
struct CBLSIdImplicit : public uint256
|
|
|
|
{
|
2021-06-06 22:43:44 +02:00
|
|
|
CBLSIdImplicit() = default;
|
2020-12-12 10:45:43 +01:00
|
|
|
CBLSIdImplicit(const uint256& id)
|
|
|
|
{
|
|
|
|
memcpy(begin(), id.begin(), sizeof(uint256));
|
|
|
|
}
|
2022-09-30 17:29:51 +02:00
|
|
|
static CBLSIdImplicit FromBytes(const uint8_t* buffer, const bool fLegacy)
|
2020-12-12 10:45:43 +01:00
|
|
|
{
|
|
|
|
CBLSIdImplicit instance;
|
|
|
|
memcpy(instance.begin(), buffer, sizeof(CBLSIdImplicit));
|
|
|
|
return instance;
|
|
|
|
}
|
2022-09-30 17:29:51 +02:00
|
|
|
[[nodiscard]] std::vector<uint8_t> Serialize(const bool fLegacy) const
|
2020-12-12 10:45:43 +01:00
|
|
|
{
|
2021-02-27 08:36:00 +01:00
|
|
|
return {begin(), end()};
|
2020-12-12 10:45:43 +01:00
|
|
|
}
|
|
|
|
};
|
|
|
|
|
|
|
|
class CBLSId : public CBLSWrapper<CBLSIdImplicit, BLS_CURVE_ID_SIZE, CBLSId>
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
|
|
|
public:
|
|
|
|
using CBLSWrapper::operator=;
|
|
|
|
using CBLSWrapper::operator==;
|
|
|
|
using CBLSWrapper::operator!=;
|
2020-12-15 00:26:30 +01:00
|
|
|
using CBLSWrapper::CBLSWrapper;
|
2018-10-03 14:53:21 +02:00
|
|
|
|
2021-06-06 22:43:44 +02:00
|
|
|
CBLSId() = default;
|
|
|
|
explicit CBLSId(const uint256& nHash);
|
2018-10-03 14:53:21 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
class CBLSSecretKey : public CBLSWrapper<bls::PrivateKey, BLS_CURVE_SECKEY_SIZE, CBLSSecretKey>
|
|
|
|
{
|
|
|
|
public:
|
|
|
|
using CBLSWrapper::operator=;
|
|
|
|
using CBLSWrapper::operator==;
|
|
|
|
using CBLSWrapper::operator!=;
|
2020-12-15 00:26:30 +01:00
|
|
|
using CBLSWrapper::CBLSWrapper;
|
2018-10-03 14:53:21 +02:00
|
|
|
|
2021-06-06 22:43:44 +02:00
|
|
|
CBLSSecretKey() = default;
|
2021-04-28 16:44:01 +02:00
|
|
|
CBLSSecretKey(const CBLSSecretKey&) = default;
|
|
|
|
CBLSSecretKey& operator=(const CBLSSecretKey&) = default;
|
2018-12-10 08:31:09 +01:00
|
|
|
|
2018-10-03 14:53:21 +02:00
|
|
|
void AggregateInsecure(const CBLSSecretKey& o);
|
|
|
|
static CBLSSecretKey AggregateInsecure(const std::vector<CBLSSecretKey>& sks);
|
|
|
|
|
|
|
|
#ifndef BUILD_BITCOIN_INTERNAL
|
|
|
|
void MakeNewKey();
|
|
|
|
#endif
|
|
|
|
bool SecretKeyShare(const std::vector<CBLSSecretKey>& msk, const CBLSId& id);
|
|
|
|
|
2022-05-12 23:11:39 +02:00
|
|
|
[[nodiscard]] CBLSPublicKey GetPublicKey() const;
|
|
|
|
[[nodiscard]] CBLSSignature Sign(const uint256& hash) const;
|
2018-10-03 14:53:21 +02:00
|
|
|
};
|
|
|
|
|
2021-03-26 13:32:31 +01:00
|
|
|
class CBLSPublicKey : public CBLSWrapper<bls::G1Element, BLS_CURVE_PUBKEY_SIZE, CBLSPublicKey>
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
|
|
|
friend class CBLSSecretKey;
|
|
|
|
friend class CBLSSignature;
|
|
|
|
|
|
|
|
public:
|
|
|
|
using CBLSWrapper::operator=;
|
|
|
|
using CBLSWrapper::operator==;
|
|
|
|
using CBLSWrapper::operator!=;
|
2020-12-15 00:26:30 +01:00
|
|
|
using CBLSWrapper::CBLSWrapper;
|
2018-10-03 14:53:21 +02:00
|
|
|
|
2021-06-06 22:43:44 +02:00
|
|
|
CBLSPublicKey() = default;
|
2018-12-10 08:31:09 +01:00
|
|
|
|
2018-10-03 14:53:21 +02:00
|
|
|
void AggregateInsecure(const CBLSPublicKey& o);
|
2022-09-30 17:29:51 +02:00
|
|
|
static CBLSPublicKey AggregateInsecure(const std::vector<CBLSPublicKey>& pks);
|
2018-10-03 14:53:21 +02:00
|
|
|
|
|
|
|
bool PublicKeyShare(const std::vector<CBLSPublicKey>& mpk, const CBLSId& id);
|
|
|
|
bool DHKeyExchange(const CBLSSecretKey& sk, const CBLSPublicKey& pk);
|
|
|
|
|
|
|
|
};
|
|
|
|
|
2022-12-30 06:45:31 +01:00
|
|
|
class ConstCBLSPublicKeyVersionWrapper {
|
|
|
|
private:
|
|
|
|
const CBLSPublicKey& obj;
|
2023-02-10 13:14:57 +01:00
|
|
|
bool legacy;
|
2022-12-30 06:45:31 +01:00
|
|
|
public:
|
2023-02-10 13:14:57 +01:00
|
|
|
ConstCBLSPublicKeyVersionWrapper(const CBLSPublicKey& obj, bool legacy)
|
2022-12-30 06:45:31 +01:00
|
|
|
: obj(obj)
|
|
|
|
, legacy(legacy)
|
|
|
|
{}
|
|
|
|
template <typename Stream>
|
|
|
|
inline void Serialize(Stream& s) const {
|
|
|
|
obj.Serialize(s, legacy);
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
|
|
|
class CBLSPublicKeyVersionWrapper {
|
|
|
|
private:
|
2023-02-10 13:14:57 +01:00
|
|
|
CBLSPublicKey& obj;
|
2022-12-30 06:45:31 +01:00
|
|
|
bool legacy;
|
|
|
|
bool checkMalleable;
|
|
|
|
public:
|
|
|
|
CBLSPublicKeyVersionWrapper(CBLSPublicKey& obj, bool legacy, bool checkMalleable = true)
|
|
|
|
: obj(obj)
|
|
|
|
, legacy(legacy)
|
|
|
|
, checkMalleable(checkMalleable)
|
|
|
|
{}
|
|
|
|
template <typename Stream>
|
|
|
|
inline void Serialize(Stream& s) const {
|
|
|
|
obj.Serialize(s, legacy);
|
|
|
|
}
|
|
|
|
template <typename Stream>
|
|
|
|
inline void Unserialize(Stream& s) {
|
|
|
|
obj.Unserialize(s, legacy, checkMalleable);
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
2021-03-26 13:32:31 +01:00
|
|
|
class CBLSSignature : public CBLSWrapper<bls::G2Element, BLS_CURVE_SIG_SIZE, CBLSSignature>
|
2018-10-03 14:53:21 +02:00
|
|
|
{
|
|
|
|
friend class CBLSSecretKey;
|
|
|
|
|
|
|
|
public:
|
|
|
|
using CBLSWrapper::operator==;
|
|
|
|
using CBLSWrapper::operator!=;
|
2018-12-10 08:31:09 +01:00
|
|
|
using CBLSWrapper::CBLSWrapper;
|
2018-10-03 14:53:21 +02:00
|
|
|
|
2021-06-06 22:43:44 +02:00
|
|
|
CBLSSignature() = default;
|
2018-10-03 14:53:21 +02:00
|
|
|
CBLSSignature(const CBLSSignature&) = default;
|
|
|
|
CBLSSignature& operator=(const CBLSSignature&) = default;
|
|
|
|
|
|
|
|
void AggregateInsecure(const CBLSSignature& o);
|
2022-09-30 17:29:51 +02:00
|
|
|
static CBLSSignature AggregateInsecure(const std::vector<CBLSSignature>& sigs);
|
|
|
|
static CBLSSignature AggregateSecure(const std::vector<CBLSSignature>& sigs, const std::vector<CBLSPublicKey>& pks, const uint256& hash);
|
2018-10-03 14:53:21 +02:00
|
|
|
|
|
|
|
void SubInsecure(const CBLSSignature& o);
|
2023-03-11 18:44:35 +01:00
|
|
|
[[nodiscard]] bool VerifyInsecure(const CBLSPublicKey& pubKey, const uint256& hash, const bool specificLegacyScheme) const;
|
2022-05-12 23:11:39 +02:00
|
|
|
[[nodiscard]] bool VerifyInsecure(const CBLSPublicKey& pubKey, const uint256& hash) const;
|
|
|
|
[[nodiscard]] bool VerifyInsecureAggregated(const std::vector<CBLSPublicKey>& pubKeys, const std::vector<uint256>& hashes) const;
|
2018-10-03 14:53:21 +02:00
|
|
|
|
2022-05-12 23:11:39 +02:00
|
|
|
[[nodiscard]] bool VerifySecureAggregated(const std::vector<CBLSPublicKey>& pks, const uint256& hash) const;
|
2018-10-03 14:53:21 +02:00
|
|
|
|
|
|
|
bool Recover(const std::vector<CBLSSignature>& sigs, const std::vector<CBLSId>& ids);
|
|
|
|
};
|
|
|
|
|
2022-12-30 06:45:31 +01:00
|
|
|
class CBLSSignatureVersionWrapper {
|
|
|
|
private:
|
2023-02-10 13:14:57 +01:00
|
|
|
CBLSSignature& obj;
|
2022-12-30 06:45:31 +01:00
|
|
|
bool legacy;
|
|
|
|
bool checkMalleable;
|
|
|
|
public:
|
|
|
|
CBLSSignatureVersionWrapper(CBLSSignature& obj, bool legacy, bool checkMalleable = true)
|
|
|
|
: obj(obj)
|
|
|
|
, legacy(legacy)
|
|
|
|
, checkMalleable(checkMalleable)
|
|
|
|
{}
|
|
|
|
template <typename Stream>
|
|
|
|
inline void Serialize(Stream& s) const {
|
|
|
|
obj.Serialize(s, legacy);
|
|
|
|
}
|
|
|
|
template <typename Stream>
|
2023-02-10 13:14:57 +01:00
|
|
|
inline void Unserialize(Stream& s) {
|
2022-12-30 06:45:31 +01:00
|
|
|
obj.Unserialize(s, legacy, checkMalleable);
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
2019-04-11 22:11:39 +02:00
|
|
|
#ifndef BUILD_BITCOIN_INTERNAL
|
2019-06-13 11:01:26 +02:00
|
|
|
template<typename BLSObject>
|
|
|
|
class CBLSLazyWrapper
|
2019-02-15 14:11:47 +01:00
|
|
|
{
|
|
|
|
private:
|
2019-04-11 22:11:39 +02:00
|
|
|
mutable std::mutex mutex;
|
|
|
|
|
2021-02-27 08:36:00 +01:00
|
|
|
mutable std::vector<uint8_t> vecBytes;
|
2019-02-15 14:11:47 +01:00
|
|
|
mutable bool bufValid{false};
|
2022-12-30 06:45:31 +01:00
|
|
|
mutable bool bufLegacyScheme{true};
|
2019-02-15 14:11:47 +01:00
|
|
|
|
2019-06-13 11:01:26 +02:00
|
|
|
mutable BLSObject obj;
|
|
|
|
mutable bool objInitialized{false};
|
|
|
|
|
|
|
|
mutable uint256 hash;
|
2019-02-15 14:11:47 +01:00
|
|
|
|
|
|
|
public:
|
2021-02-27 08:36:00 +01:00
|
|
|
CBLSLazyWrapper() :
|
2022-12-30 06:45:31 +01:00
|
|
|
vecBytes(BLSObject::SerSize, 0),
|
|
|
|
bufLegacyScheme(bls::bls_legacy_scheme.load())
|
2019-04-11 22:11:39 +02:00
|
|
|
{
|
2019-06-13 11:01:26 +02:00
|
|
|
// the all-zero buf is considered a valid buf, but the resulting object will return false for IsValid
|
|
|
|
bufValid = true;
|
2019-04-11 22:11:39 +02:00
|
|
|
}
|
|
|
|
|
2021-12-28 22:54:50 +01:00
|
|
|
explicit CBLSLazyWrapper(const CBLSLazyWrapper& r)
|
2019-04-11 22:11:39 +02:00
|
|
|
{
|
|
|
|
*this = r;
|
|
|
|
}
|
2021-07-31 20:29:12 +02:00
|
|
|
virtual ~CBLSLazyWrapper() = default;
|
2019-04-11 22:11:39 +02:00
|
|
|
|
2019-06-13 11:01:26 +02:00
|
|
|
CBLSLazyWrapper& operator=(const CBLSLazyWrapper& r)
|
2019-04-11 22:11:39 +02:00
|
|
|
{
|
|
|
|
std::unique_lock<std::mutex> l(r.mutex);
|
|
|
|
bufValid = r.bufValid;
|
2022-12-30 06:45:31 +01:00
|
|
|
bufLegacyScheme = r.bufLegacyScheme;
|
2019-04-11 22:11:39 +02:00
|
|
|
if (r.bufValid) {
|
2021-02-27 08:36:00 +01:00
|
|
|
vecBytes = r.vecBytes;
|
2019-04-11 22:11:39 +02:00
|
|
|
} else {
|
2021-02-27 08:36:00 +01:00
|
|
|
std::fill(vecBytes.begin(), vecBytes.end(), 0);
|
2019-04-11 22:11:39 +02:00
|
|
|
}
|
2019-06-13 11:01:26 +02:00
|
|
|
objInitialized = r.objInitialized;
|
|
|
|
if (r.objInitialized) {
|
|
|
|
obj = r.obj;
|
2019-04-11 22:11:39 +02:00
|
|
|
} else {
|
2019-06-13 11:01:26 +02:00
|
|
|
obj.Reset();
|
2019-04-11 22:11:39 +02:00
|
|
|
}
|
2019-06-13 11:01:26 +02:00
|
|
|
hash = r.hash;
|
2019-04-11 22:11:39 +02:00
|
|
|
return *this;
|
|
|
|
}
|
|
|
|
|
2019-07-02 06:16:27 +02:00
|
|
|
inline void Serialize(CSizeComputer& s) const
|
|
|
|
{
|
|
|
|
s.seek(BLSObject::SerSize);
|
|
|
|
}
|
|
|
|
|
2019-02-15 14:11:47 +01:00
|
|
|
template<typename Stream>
|
2022-12-30 06:45:31 +01:00
|
|
|
inline void Serialize(Stream& s, const bool specificLegacyScheme) const
|
2019-02-15 14:11:47 +01:00
|
|
|
{
|
2019-04-11 22:11:39 +02:00
|
|
|
std::unique_lock<std::mutex> l(mutex);
|
2019-06-13 11:01:26 +02:00
|
|
|
if (!objInitialized && !bufValid) {
|
2022-12-30 06:45:31 +01:00
|
|
|
// the all-zero buf is considered a valid buf
|
|
|
|
std::fill(vecBytes.begin(), vecBytes.end(), 0);
|
|
|
|
bufLegacyScheme = specificLegacyScheme;
|
|
|
|
bufValid = true;
|
2019-02-15 14:11:47 +01:00
|
|
|
}
|
2022-12-30 06:45:31 +01:00
|
|
|
if (!bufValid || (bufLegacyScheme != specificLegacyScheme)) {
|
|
|
|
vecBytes = obj.ToByteVector(specificLegacyScheme);
|
2019-02-15 14:11:47 +01:00
|
|
|
bufValid = true;
|
2022-12-30 06:45:31 +01:00
|
|
|
bufLegacyScheme = specificLegacyScheme;
|
2021-03-12 23:54:20 +01:00
|
|
|
hash.SetNull();
|
2019-02-15 14:11:47 +01:00
|
|
|
}
|
2022-08-11 01:05:44 +02:00
|
|
|
s.write(reinterpret_cast<const char*>(vecBytes.data()), vecBytes.size());
|
2019-02-15 14:11:47 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
template<typename Stream>
|
2022-12-30 06:45:31 +01:00
|
|
|
inline void Serialize(Stream& s) const
|
|
|
|
{
|
|
|
|
Serialize(s, bls::bls_legacy_scheme.load());
|
|
|
|
}
|
|
|
|
|
|
|
|
template<typename Stream>
|
|
|
|
inline void Unserialize(Stream& s, const bool specificLegacyScheme) const
|
2019-02-15 14:11:47 +01:00
|
|
|
{
|
2019-04-11 22:11:39 +02:00
|
|
|
std::unique_lock<std::mutex> l(mutex);
|
2022-08-11 01:05:44 +02:00
|
|
|
s.read(reinterpret_cast<char*>(vecBytes.data()), BLSObject::SerSize);
|
2019-02-15 14:11:47 +01:00
|
|
|
bufValid = true;
|
2022-12-30 06:45:31 +01:00
|
|
|
bufLegacyScheme = specificLegacyScheme;
|
2019-06-13 11:01:26 +02:00
|
|
|
objInitialized = false;
|
2021-03-12 23:54:20 +01:00
|
|
|
hash.SetNull();
|
2019-06-13 11:01:26 +02:00
|
|
|
}
|
|
|
|
|
2022-12-30 06:45:31 +01:00
|
|
|
template<typename Stream>
|
|
|
|
inline void Unserialize(Stream& s) const
|
|
|
|
{
|
|
|
|
Unserialize(s, bls::bls_legacy_scheme.load());
|
|
|
|
}
|
|
|
|
|
2019-06-13 11:01:26 +02:00
|
|
|
void Set(const BLSObject& _obj)
|
|
|
|
{
|
|
|
|
std::unique_lock<std::mutex> l(mutex);
|
|
|
|
bufValid = false;
|
|
|
|
objInitialized = true;
|
|
|
|
obj = _obj;
|
2021-03-12 23:54:20 +01:00
|
|
|
hash.SetNull();
|
2019-06-13 11:01:26 +02:00
|
|
|
}
|
|
|
|
const BLSObject& Get() const
|
|
|
|
{
|
|
|
|
std::unique_lock<std::mutex> l(mutex);
|
|
|
|
static BLSObject invalidObj;
|
|
|
|
if (!bufValid && !objInitialized) {
|
|
|
|
return invalidObj;
|
|
|
|
}
|
|
|
|
if (!objInitialized) {
|
2022-12-30 06:45:31 +01:00
|
|
|
obj.SetByteVector(vecBytes, bufLegacyScheme);
|
|
|
|
if (!obj.IsValid()) {
|
|
|
|
// If setting of BLS object using one scheme failed, then we need to attempt again with the opposite scheme.
|
|
|
|
// This is due to the fact that LazyBLSWrapper receives a serialised buffer but attempts to create actual BLS object when needed.
|
|
|
|
// That could happen when the fork has been activated and the enforced scheme has switched.
|
|
|
|
obj.SetByteVector(vecBytes, !bufLegacyScheme);
|
|
|
|
if (obj.IsValid()) {
|
|
|
|
bufLegacyScheme = !bufLegacyScheme;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if (!obj.CheckMalleable(vecBytes, bufLegacyScheme)) {
|
2019-06-13 11:01:26 +02:00
|
|
|
bufValid = false;
|
|
|
|
objInitialized = false;
|
|
|
|
obj = invalidObj;
|
|
|
|
} else {
|
|
|
|
objInitialized = true;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return obj;
|
2019-02-15 14:11:47 +01:00
|
|
|
}
|
|
|
|
|
2019-06-13 11:01:26 +02:00
|
|
|
bool operator==(const CBLSLazyWrapper& r) const
|
|
|
|
{
|
2022-12-30 06:45:31 +01:00
|
|
|
if (bufValid && r.bufValid && bufLegacyScheme == r.bufLegacyScheme) {
|
2021-02-27 08:36:00 +01:00
|
|
|
return vecBytes == r.vecBytes;
|
2019-06-13 11:01:26 +02:00
|
|
|
}
|
|
|
|
if (objInitialized && r.objInitialized) {
|
|
|
|
return obj == r.obj;
|
|
|
|
}
|
|
|
|
return Get() == r.Get();
|
|
|
|
}
|
|
|
|
|
|
|
|
bool operator!=(const CBLSLazyWrapper& r) const
|
|
|
|
{
|
|
|
|
return !(*this == r);
|
|
|
|
}
|
|
|
|
|
2022-12-30 06:45:31 +01:00
|
|
|
uint256 GetHash(const bool specificLegacyScheme = bls::bls_legacy_scheme.load()) const
|
2019-06-13 11:01:26 +02:00
|
|
|
{
|
|
|
|
std::unique_lock<std::mutex> l(mutex);
|
2022-12-30 06:45:31 +01:00
|
|
|
if (!bufValid || bufLegacyScheme != specificLegacyScheme) {
|
|
|
|
vecBytes = obj.ToByteVector(specificLegacyScheme);
|
2019-06-13 11:01:26 +02:00
|
|
|
bufValid = true;
|
2022-12-30 06:45:31 +01:00
|
|
|
bufLegacyScheme = specificLegacyScheme;
|
2021-03-12 23:54:20 +01:00
|
|
|
hash.SetNull();
|
2019-06-13 11:01:26 +02:00
|
|
|
}
|
|
|
|
if (hash.IsNull()) {
|
2021-03-12 23:54:20 +01:00
|
|
|
CHashWriter ss(SER_GETHASH, PROTOCOL_VERSION);
|
2022-08-11 01:05:44 +02:00
|
|
|
ss.write(reinterpret_cast<const char*>(vecBytes.data()), vecBytes.size());
|
2021-03-12 23:54:20 +01:00
|
|
|
hash = ss.GetHash();
|
2019-06-13 11:01:26 +02:00
|
|
|
}
|
|
|
|
return hash;
|
|
|
|
}
|
2019-02-15 14:11:47 +01:00
|
|
|
};
|
2021-10-05 23:26:29 +02:00
|
|
|
using CBLSLazySignature = CBLSLazyWrapper<CBLSSignature>;
|
|
|
|
using CBLSLazyPublicKey = CBLSLazyWrapper<CBLSPublicKey>;
|
2022-12-30 06:45:31 +01:00
|
|
|
|
|
|
|
class CBLSLazyPublicKeyVersionWrapper {
|
|
|
|
private:
|
|
|
|
CBLSLazyPublicKey& obj;
|
2023-02-10 13:14:57 +01:00
|
|
|
bool legacy;
|
2022-12-30 06:45:31 +01:00
|
|
|
public:
|
|
|
|
CBLSLazyPublicKeyVersionWrapper(CBLSLazyPublicKey& obj, bool legacy)
|
|
|
|
: obj(obj)
|
|
|
|
, legacy(legacy)
|
|
|
|
{}
|
|
|
|
template <typename Stream>
|
|
|
|
inline void Serialize(Stream& s) const {
|
|
|
|
obj.Serialize(s, legacy);
|
|
|
|
}
|
|
|
|
template <typename Stream>
|
|
|
|
inline void Unserialize(Stream& s) {
|
|
|
|
obj.Unserialize(s, legacy);
|
|
|
|
}
|
|
|
|
};
|
2019-04-11 22:11:39 +02:00
|
|
|
#endif
|
2019-02-15 14:11:47 +01:00
|
|
|
|
2021-10-05 23:26:29 +02:00
|
|
|
using BLSIdVector = std::vector<CBLSId>;
|
|
|
|
using BLSVerificationVector = std::vector<CBLSPublicKey>;
|
|
|
|
using BLSPublicKeyVector = std::vector<CBLSPublicKey>;
|
|
|
|
using BLSSecretKeyVector = std::vector<CBLSSecretKey>;
|
|
|
|
using BLSSignatureVector = std::vector<CBLSSignature>;
|
|
|
|
|
|
|
|
using BLSVerificationVectorPtr = std::shared_ptr<BLSVerificationVector>;
|
2018-10-03 14:53:21 +02:00
|
|
|
|
2018-12-10 06:04:48 +01:00
|
|
|
bool BLSInit();
|
|
|
|
|
2018-10-03 14:53:21 +02:00
|
|
|
#endif // DASH_CRYPTO_BLS_H
|