2022-03-14 20:58:13 +00:00
|
|
|
//go:build ((linux && amd64) || (linux && arm64) || (darwin && amd64) || (darwin && arm64) || (windows && amd64)) && !blst_disabled
|
2020-09-16 13:28:28 +00:00
|
|
|
|
|
|
|
package blst
|
|
|
|
|
|
|
|
import (
|
2021-06-11 18:48:57 +00:00
|
|
|
"crypto/subtle"
|
2020-09-16 13:28:28 +00:00
|
|
|
"fmt"
|
|
|
|
|
2022-08-16 12:20:13 +00:00
|
|
|
"github.com/prysmaticlabs/prysm/v3/config/params"
|
|
|
|
"github.com/prysmaticlabs/prysm/v3/crypto/bls/common"
|
|
|
|
"github.com/prysmaticlabs/prysm/v3/crypto/rand"
|
2020-09-16 13:28:28 +00:00
|
|
|
blst "github.com/supranational/blst/bindings/go"
|
|
|
|
)
|
|
|
|
|
|
|
|
// bls12SecretKey used in the BLS signature scheme.
|
|
|
|
type bls12SecretKey struct {
|
|
|
|
p *blst.SecretKey
|
|
|
|
}
|
|
|
|
|
|
|
|
// RandKey creates a new private key using a random method provided as an io.Reader.
|
2020-10-30 19:06:33 +00:00
|
|
|
func RandKey() (common.SecretKey, error) {
|
2020-09-16 13:28:28 +00:00
|
|
|
// Generate 32 bytes of randomness
|
|
|
|
var ikm [32]byte
|
|
|
|
_, err := rand.NewGenerator().Read(ikm[:])
|
|
|
|
if err != nil {
|
2020-10-30 19:06:33 +00:00
|
|
|
return nil, err
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|
2020-10-30 19:06:33 +00:00
|
|
|
// Defensive check, that we have not generated a secret key,
|
|
|
|
secKey := &bls12SecretKey{blst.KeyGen(ikm[:])}
|
2021-06-11 18:48:57 +00:00
|
|
|
if IsZero(secKey.Marshal()) {
|
2020-10-30 19:06:33 +00:00
|
|
|
return nil, common.ErrZeroKey
|
|
|
|
}
|
|
|
|
return secKey, nil
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// SecretKeyFromBytes creates a BLS private key from a BigEndian byte slice.
|
2020-10-30 19:06:33 +00:00
|
|
|
func SecretKeyFromBytes(privKey []byte) (common.SecretKey, error) {
|
2020-09-16 13:28:28 +00:00
|
|
|
if len(privKey) != params.BeaconConfig().BLSSecretKeyLength {
|
|
|
|
return nil, fmt.Errorf("secret key must be %d bytes", params.BeaconConfig().BLSSecretKeyLength)
|
|
|
|
}
|
|
|
|
secKey := new(blst.SecretKey).Deserialize(privKey)
|
|
|
|
if secKey == nil {
|
2020-11-17 04:12:23 +00:00
|
|
|
return nil, common.ErrSecretUnmarshal
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|
2020-10-30 19:06:33 +00:00
|
|
|
wrappedKey := &bls12SecretKey{p: secKey}
|
2021-06-11 18:48:57 +00:00
|
|
|
if IsZero(privKey) {
|
2020-10-30 19:06:33 +00:00
|
|
|
return nil, common.ErrZeroKey
|
|
|
|
}
|
|
|
|
return wrappedKey, nil
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// PublicKey obtains the public key corresponding to the BLS secret key.
|
2020-10-30 19:06:33 +00:00
|
|
|
func (s *bls12SecretKey) PublicKey() common.PublicKey {
|
2020-09-16 13:28:28 +00:00
|
|
|
return &PublicKey{p: new(blstPublicKey).From(s.p)}
|
|
|
|
}
|
|
|
|
|
2020-10-30 19:06:33 +00:00
|
|
|
// IsZero checks if the secret key is a zero key.
|
2021-06-11 18:48:57 +00:00
|
|
|
func IsZero(sKey []byte) bool {
|
|
|
|
b := byte(0)
|
|
|
|
for _, s := range sKey {
|
|
|
|
b |= s
|
|
|
|
}
|
|
|
|
return subtle.ConstantTimeByteEq(b, 0) == 1
|
2020-10-30 19:06:33 +00:00
|
|
|
}
|
|
|
|
|
2020-09-16 13:28:28 +00:00
|
|
|
// Sign a message using a secret key - in a beacon/validator client.
|
|
|
|
//
|
|
|
|
// In IETF draft BLS specification:
|
|
|
|
// Sign(SK, message) -> signature: a signing algorithm that generates
|
2022-11-18 19:12:19 +00:00
|
|
|
//
|
|
|
|
// a deterministic signature given a secret key SK and a message.
|
2020-09-16 13:28:28 +00:00
|
|
|
//
|
2021-06-26 19:00:33 +00:00
|
|
|
// In Ethereum proof of stake specification:
|
2020-09-16 13:28:28 +00:00
|
|
|
// def Sign(SK: int, message: Bytes) -> BLSSignature
|
2020-10-30 19:06:33 +00:00
|
|
|
func (s *bls12SecretKey) Sign(msg []byte) common.Signature {
|
2020-09-16 13:28:28 +00:00
|
|
|
signature := new(blstSignature).Sign(s.p, msg, dst)
|
|
|
|
return &Signature{s: signature}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Marshal a secret key into a LittleEndian byte slice.
|
|
|
|
func (s *bls12SecretKey) Marshal() []byte {
|
|
|
|
keyBytes := s.p.Serialize()
|
|
|
|
return keyBytes
|
|
|
|
}
|