Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
45 changes: 36 additions & 9 deletions rust-src/concordium_base/src/id/identity_attributes_credentials.rs
Original file line number Diff line number Diff line change
Expand Up @@ -26,9 +26,10 @@ pub fn prove_identity_attributes<
AttributeType: Clone + Attribute<C::Scalar>,
>(
context: IpContext<'_, P, C>,
id_object: &impl HasIdentityObjectFields<P, C, AttributeType>,
id_object: &(impl HasIdentityObjectFields<P, C, AttributeType> + ?Sized),
id_object_use_data: &IdObjectUseData<P, C>,
policy: Policy<C, AttributeType>,
transcript: &mut RandomOracle,
) -> anyhow::Result<(
IdentityAttributesCredentialsInfo<P, C, AttributeType>,
IdentityAttributesCredentialsRandomness<C>,
Expand Down Expand Up @@ -114,12 +115,12 @@ pub fn prove_identity_attributes<
policy,
};

// The transcript has domain separator "IdentityAttributesCredentials" followed by appending all
// values of the identity attributes to the transcript, specifically appending the
// The label "IdentityAttributesCredentials" is appended to the transcript followed all
// values of the identity attributes, specifically appending the
// IdentityAttributesCommitmentValues struct.
// This should make the proof non-reusable.
let mut transcript = RandomOracle::domain("IdentityAttributesCredentials");
// We should add the genesis hash also at some point
transcript.add_bytes(b"IdentityAttributesCredentials");
transcript.append_message(b"identity_attribute_values", &id_attribute_values);
transcript.append_message(b"global_context", &context.global_context);

Expand Down Expand Up @@ -179,7 +180,7 @@ pub fn prove_identity_attributes<
};

let secret = (secret_sig, id_cred_pub_secrets);
let proof = match prove(&mut transcript, &prover, secret, &mut csprng) {
let proof = match prove(transcript, &prover, secret, &mut csprng) {
Some(x) => x,
None => bail!("Cannot produce zero knowledge proof."),
};
Expand Down Expand Up @@ -459,6 +460,7 @@ pub fn verify_identity_attributes<
// in the identity attribute values.
known_ars: &BTreeMap<ArIdentity, A>,
id_attr_info: &IdentityAttributesCredentialsInfo<P, C, AttributeType>,
transcript: &mut RandomOracle,
) -> Result<(), AttributeCommitmentVerificationError> {
if ip_info.ip_identity != id_attr_info.values.ip_identity {
return Err(AttributeCommitmentVerificationError::Signature);
Expand All @@ -479,9 +481,9 @@ pub fn verify_identity_attributes<
let on_chain_commitment_key = global_context.on_chain_commitment_key;
let ip_verify_key = &ip_info.ip_verify_key;
// Compute the challenge prefix by hashing the values.
let mut ro = RandomOracle::domain("IdentityAttributesCredentials");
ro.append_message(b"identity_attribute_values", &id_attr_info.values);
ro.append_message(b"global_context", &global_context);
transcript.add_bytes(b"IdentityAttributesCredentials");
transcript.append_message(b"identity_attribute_values", &id_attr_info.values);
transcript.append_message(b"global_context", &global_context);

let commitments = &id_attr_info.proofs.commitments;

Expand Down Expand Up @@ -528,7 +530,7 @@ pub fn verify_identity_attributes<
response,
};

if !verify(&mut ro, &verifier, &proof) {
if !verify(transcript, &verifier, &proof) {
return Err(AttributeCommitmentVerificationError::Proof);
}

Expand Down Expand Up @@ -676,6 +678,7 @@ mod test {
IpInfo, Policy,
};
use crate::id::{identity_provider, test};
use crate::random_oracle::RandomOracle;
use assert_matches::assert_matches;
use std::collections::BTreeMap;

Expand Down Expand Up @@ -747,19 +750,23 @@ mod test {
_phantom: Default::default(),
};

let mut transcript = RandomOracle::empty();
let (id_attr_info, _) = prove_identity_attributes(
ip_context(&id_object_fixture),
&id_object_fixture.id_object,
&id_object_fixture.id_use_data,
policy,
&mut transcript,
)
.expect("prove");

let mut transcript = RandomOracle::empty();
verify_identity_attributes(
&id_object_fixture.global_ctx,
&id_object_fixture.ip_info,
&id_object_fixture.ars_infos,
&id_attr_info,
&mut transcript,
)
.expect("verify");
}
Expand All @@ -782,19 +789,23 @@ mod test {
_phantom: Default::default(),
};

let mut transcript = RandomOracle::empty();
let (id_attr_info, _) = prove_identity_attributes(
ip_context(&id_object_fixture),
&id_object_fixture.id_object,
&id_object_fixture.id_use_data,
policy,
&mut transcript,
)
.expect("prove");

let mut transcript = RandomOracle::empty();
verify_identity_attributes(
&id_object_fixture.global_ctx,
&id_object_fixture.ip_info,
&id_object_fixture.ars_infos,
&id_attr_info,
&mut transcript,
)
.expect("verify");
}
Expand All @@ -812,11 +823,13 @@ mod test {
_phantom: Default::default(),
};

let mut transcript = RandomOracle::empty();
let (mut id_attr_info, _) = prove_identity_attributes(
ip_context(&id_object_fixture),
&id_object_fixture.id_object,
&id_object_fixture.id_use_data,
policy,
&mut transcript,
)
.expect("prove");

Expand All @@ -827,11 +840,13 @@ mod test {
.1
.plus_point(&ArCurve::one_point());

let mut transcript = RandomOracle::empty();
let res = verify_identity_attributes(
&id_object_fixture.global_ctx,
&id_object_fixture.ip_info,
&id_object_fixture.ars_infos,
&id_attr_info,
&mut transcript,
);

assert_matches!(res, Err(AttributeCommitmentVerificationError::Proof));
Expand All @@ -849,21 +864,25 @@ mod test {
_phantom: Default::default(),
};

let mut transcript = RandomOracle::empty();
let (mut id_attr_info, _) = prove_identity_attributes(
ip_context(&id_object_fixture),
&id_object_fixture.id_object,
&id_object_fixture.id_use_data,
policy,
&mut transcript,
)
.expect("prove");

id_attr_info.values.ip_identity.0 += 1;

let mut transcript = RandomOracle::empty();
let res = verify_identity_attributes(
&id_object_fixture.global_ctx,
&id_object_fixture.ip_info,
&id_object_fixture.ars_infos,
&id_attr_info,
&mut transcript,
);
assert_matches!(res, Err(AttributeCommitmentVerificationError::Signature));
}
Expand All @@ -881,11 +900,13 @@ mod test {
_phantom: Default::default(),
};

let mut transcript = RandomOracle::empty();
let (id_attr_info, _) = prove_identity_attributes(
ip_context(&id_object_fixture),
&id_object_fixture.id_object,
&id_object_fixture.id_use_data,
policy,
&mut transcript,
)
.expect("prove");

Expand All @@ -898,11 +919,13 @@ mod test {
.cmm_id_cred_sec_sharing_coeff
.pop();

let mut transcript = RandomOracle::empty();
let res = verify_identity_attributes(
&id_object_fixture.global_ctx,
&id_object_fixture.ip_info,
&id_object_fixture.ars_infos,
&id_attr_info_invalid,
&mut transcript,
);
assert_matches!(res, Err(AttributeCommitmentVerificationError::Proof));

Expand All @@ -915,11 +938,13 @@ mod test {
.proof_id_cred_pub
.remove(&ar_to_remove);

let mut transcript = RandomOracle::empty();
let res = verify_identity_attributes(
&id_object_fixture.global_ctx,
&id_object_fixture.ip_info,
&id_object_fixture.ars_infos,
&id_attr_info_invalid,
&mut transcript,
);
assert_matches!(res, Err(AttributeCommitmentVerificationError::Proof));

Expand All @@ -934,11 +959,13 @@ mod test {
.unwrap();
attr_cmm.0 = attr_cmm.0.plus_point(&ArCurve::one_point());

let mut transcript = RandomOracle::empty();
let res = verify_identity_attributes(
&id_object_fixture.global_ctx,
&id_object_fixture.ip_info,
&id_object_fixture.ars_infos,
&id_attr_info_invalid,
&mut transcript,
);
assert_matches!(res, Err(AttributeCommitmentVerificationError::Proof));
}
Expand Down
7 changes: 6 additions & 1 deletion rust-src/concordium_base/src/random_oracle/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
//! with the context used to produce the proof. Any verification of sub-proofs
//! needs to be performed in the same order as when producing the proof.

use crate::{common::*, curve_arithmetic::Curve};
use crate::{common::*, curve_arithmetic::Curve, web3id::IsChallenge};
use sha3::{Digest, Sha3_256};
use std::io::Write;

Expand Down Expand Up @@ -112,6 +112,11 @@ impl RandomOracle {
self.add(message)
}

/// Append a challenge to the state of the random oracle.
pub fn append_challenge<Challenge: IsChallenge>(&mut self, challenge: &Challenge) {
challenge.append_to_transcript(self)
}

/// Append all items from an iterator to the random oracle. Equivalent to
/// repeatedly calling append in sequence.
/// Returns the new state of the random oracle, consuming the initial state.
Expand Down
Loading