2022-03-14 20:58:13 +00:00
|
|
|
//go:build ((linux && amd64) || (linux && arm64) || (darwin && amd64) || (darwin && arm64) || (windows && amd64)) && !blst_disabled
|
2020-09-16 13:28:28 +00:00
|
|
|
|
|
|
|
package blst
|
|
|
|
|
|
|
|
import (
|
2021-07-02 19:27:08 +00:00
|
|
|
"bytes"
|
2020-09-16 13:28:28 +00:00
|
|
|
"fmt"
|
2021-04-07 15:18:19 +00:00
|
|
|
"sync"
|
2020-09-16 13:28:28 +00:00
|
|
|
|
|
|
|
"github.com/pkg/errors"
|
2022-08-16 12:20:13 +00:00
|
|
|
fieldparams "github.com/prysmaticlabs/prysm/v3/config/fieldparams"
|
|
|
|
"github.com/prysmaticlabs/prysm/v3/crypto/bls/common"
|
|
|
|
"github.com/prysmaticlabs/prysm/v3/crypto/rand"
|
2020-09-16 13:28:28 +00:00
|
|
|
blst "github.com/supranational/blst/bindings/go"
|
|
|
|
)
|
|
|
|
|
|
|
|
var dst = []byte("BLS_SIG_BLS12381G2_XMD:SHA-256_SSWU_RO_POP_")
|
|
|
|
|
|
|
|
const scalarBytes = 32
|
|
|
|
const randBitsEntropy = 64
|
|
|
|
|
|
|
|
// Signature used in the BLS signature scheme.
|
|
|
|
type Signature struct {
|
|
|
|
s *blstSignature
|
|
|
|
}
|
|
|
|
|
|
|
|
// SignatureFromBytes creates a BLS signature from a LittleEndian byte slice.
|
2020-10-30 19:06:33 +00:00
|
|
|
func SignatureFromBytes(sig []byte) (common.Signature, error) {
|
2021-12-15 20:14:30 +00:00
|
|
|
if len(sig) != fieldparams.BLSSignatureLength {
|
|
|
|
return nil, fmt.Errorf("signature must be %d bytes", fieldparams.BLSSignatureLength)
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|
|
|
|
signature := new(blstSignature).Uncompress(sig)
|
|
|
|
if signature == nil {
|
|
|
|
return nil, errors.New("could not unmarshal bytes into signature")
|
|
|
|
}
|
2020-12-04 06:46:08 +00:00
|
|
|
// Group check signature. Do not check for infinity since an aggregated signature
|
|
|
|
// could be infinite.
|
|
|
|
if !signature.SigValidate(false) {
|
|
|
|
return nil, errors.New("signature not in group")
|
|
|
|
}
|
2020-09-16 13:28:28 +00:00
|
|
|
return &Signature{s: signature}, nil
|
|
|
|
}
|
|
|
|
|
2022-05-04 04:47:53 +00:00
|
|
|
// AggregateCompressedSignatures converts a list of compressed signatures into a single, aggregated sig.
|
|
|
|
func AggregateCompressedSignatures(multiSigs [][]byte) (common.Signature, error) {
|
|
|
|
signature := new(blstAggregateSignature)
|
|
|
|
valid := signature.AggregateCompressed(multiSigs, true)
|
|
|
|
if !valid {
|
|
|
|
return nil, errors.New("provided signatures fail the group check and cannot be compressed")
|
|
|
|
}
|
|
|
|
return &Signature{s: signature.ToAffine()}, nil
|
|
|
|
}
|
|
|
|
|
2022-01-21 22:57:29 +00:00
|
|
|
// MultipleSignaturesFromBytes creates a group of BLS signatures from a LittleEndian 2d-byte slice.
|
|
|
|
func MultipleSignaturesFromBytes(multiSigs [][]byte) ([]common.Signature, error) {
|
|
|
|
if len(multiSigs) == 0 {
|
|
|
|
return nil, fmt.Errorf("0 signatures provided to the method")
|
|
|
|
}
|
|
|
|
for _, s := range multiSigs {
|
|
|
|
if len(s) != fieldparams.BLSSignatureLength {
|
|
|
|
return nil, fmt.Errorf("signature must be %d bytes", fieldparams.BLSSignatureLength)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
multiSignatures := new(blstSignature).BatchUncompress(multiSigs)
|
|
|
|
if len(multiSignatures) == 0 {
|
|
|
|
return nil, errors.New("could not unmarshal bytes into signature")
|
|
|
|
}
|
|
|
|
if len(multiSignatures) != len(multiSigs) {
|
|
|
|
return nil, errors.Errorf("wanted %d decompressed signatures but got %d", len(multiSigs), len(multiSignatures))
|
|
|
|
}
|
|
|
|
wrappedSigs := make([]common.Signature, len(multiSignatures))
|
|
|
|
for i, signature := range multiSignatures {
|
|
|
|
// Group check signature. Do not check for infinity since an aggregated signature
|
|
|
|
// could be infinite.
|
|
|
|
if !signature.SigValidate(false) {
|
|
|
|
return nil, errors.New("signature not in group")
|
|
|
|
}
|
|
|
|
copiedSig := signature
|
|
|
|
wrappedSigs[i] = &Signature{s: copiedSig}
|
|
|
|
}
|
|
|
|
return wrappedSigs, nil
|
|
|
|
}
|
|
|
|
|
2020-09-16 13:28:28 +00:00
|
|
|
// Verify a bls signature given a public key, a message.
|
|
|
|
//
|
|
|
|
// In IETF draft BLS specification:
|
|
|
|
// Verify(PK, message, signature) -> VALID or INVALID: a verification
|
2022-11-18 19:12:19 +00:00
|
|
|
//
|
|
|
|
// algorithm that outputs VALID if signature is a valid signature of
|
|
|
|
// message under public key PK, and INVALID otherwise.
|
2020-09-16 13:28:28 +00:00
|
|
|
//
|
2021-06-26 19:00:33 +00:00
|
|
|
// In the Ethereum proof of stake specification:
|
2020-09-16 13:28:28 +00:00
|
|
|
// def Verify(PK: BLSPubkey, message: Bytes, signature: BLSSignature) -> bool
|
2020-10-30 19:06:33 +00:00
|
|
|
func (s *Signature) Verify(pubKey common.PublicKey, msg []byte) bool {
|
2020-12-04 06:46:08 +00:00
|
|
|
// Signature and PKs are assumed to have been validated upon decompression!
|
|
|
|
return s.s.Verify(false, pubKey.(*PublicKey).p, false, msg, dst)
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|
|
|
|
|
2021-04-02 15:53:08 +00:00
|
|
|
// AggregateVerify verifies each public key against its respective message. This is vulnerable to
|
|
|
|
// rogue public-key attack. Each user must provide a proof-of-knowledge of the public key.
|
|
|
|
//
|
|
|
|
// Note: The msgs must be distinct. For maximum performance, this method does not ensure distinct
|
|
|
|
// messages.
|
2020-09-16 13:28:28 +00:00
|
|
|
//
|
|
|
|
// In IETF draft BLS specification:
|
|
|
|
// AggregateVerify((PK_1, message_1), ..., (PK_n, message_n),
|
2022-11-18 19:12:19 +00:00
|
|
|
//
|
|
|
|
// signature) -> VALID or INVALID: an aggregate verification
|
|
|
|
// algorithm that outputs VALID if signature is a valid aggregated
|
|
|
|
// signature for a collection of public keys and messages, and
|
|
|
|
// outputs INVALID otherwise.
|
2020-09-16 13:28:28 +00:00
|
|
|
//
|
2021-06-26 19:00:33 +00:00
|
|
|
// In the Ethereum proof of stake specification:
|
2021-04-02 15:53:08 +00:00
|
|
|
// def AggregateVerify(pairs: Sequence[PK: BLSPubkey, message: Bytes], signature: BLSSignature) -> bool
|
|
|
|
//
|
|
|
|
// Deprecated: Use FastAggregateVerify or use this method in spectests only.
|
2020-10-30 19:06:33 +00:00
|
|
|
func (s *Signature) AggregateVerify(pubKeys []common.PublicKey, msgs [][32]byte) bool {
|
2020-09-16 13:28:28 +00:00
|
|
|
size := len(pubKeys)
|
|
|
|
if size == 0 {
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
if size != len(msgs) {
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
msgSlices := make([][]byte, len(msgs))
|
|
|
|
rawKeys := make([]*blstPublicKey, len(msgs))
|
|
|
|
for i := 0; i < size; i++ {
|
|
|
|
msgSlices[i] = msgs[i][:]
|
|
|
|
rawKeys[i] = pubKeys[i].(*PublicKey).p
|
|
|
|
}
|
2020-12-04 06:46:08 +00:00
|
|
|
// Signature and PKs are assumed to have been validated upon decompression!
|
|
|
|
return s.s.AggregateVerify(false, rawKeys, false, msgSlices, dst)
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// FastAggregateVerify verifies all the provided public keys with their aggregated signature.
|
|
|
|
//
|
|
|
|
// In IETF draft BLS specification:
|
|
|
|
// FastAggregateVerify(PK_1, ..., PK_n, message, signature) -> VALID
|
2022-11-18 19:12:19 +00:00
|
|
|
//
|
|
|
|
// or INVALID: a verification algorithm for the aggregate of multiple
|
|
|
|
// signatures on the same message. This function is faster than
|
|
|
|
// AggregateVerify.
|
2020-09-16 13:28:28 +00:00
|
|
|
//
|
2021-06-26 19:00:33 +00:00
|
|
|
// In the Ethereum proof of stake specification:
|
2020-09-16 13:28:28 +00:00
|
|
|
// def FastAggregateVerify(PKs: Sequence[BLSPubkey], message: Bytes, signature: BLSSignature) -> bool
|
2020-10-30 19:06:33 +00:00
|
|
|
func (s *Signature) FastAggregateVerify(pubKeys []common.PublicKey, msg [32]byte) bool {
|
2020-09-16 13:28:28 +00:00
|
|
|
if len(pubKeys) == 0 {
|
|
|
|
return false
|
|
|
|
}
|
2021-10-06 02:48:56 +00:00
|
|
|
rawKeys := make([]*blstPublicKey, len(pubKeys))
|
|
|
|
for i := 0; i < len(pubKeys); i++ {
|
|
|
|
rawKeys[i] = pubKeys[i].(*PublicKey).p
|
|
|
|
}
|
|
|
|
return s.s.FastAggregateVerify(true, rawKeys, msg[:], dst)
|
2021-07-02 19:27:08 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Eth2FastAggregateVerify implements a wrapper on top of bls's FastAggregateVerify. It accepts G2_POINT_AT_INFINITY signature
|
|
|
|
// when pubkeys empty.
|
|
|
|
//
|
|
|
|
// Spec code:
|
|
|
|
// def eth2_fast_aggregate_verify(pubkeys: Sequence[BLSPubkey], message: Bytes32, signature: BLSSignature) -> bool:
|
2022-11-18 19:12:19 +00:00
|
|
|
//
|
|
|
|
// """
|
|
|
|
// Wrapper to ``bls.FastAggregateVerify`` accepting the ``G2_POINT_AT_INFINITY`` signature when ``pubkeys`` is empty.
|
|
|
|
// """
|
|
|
|
// if len(pubkeys) == 0 and signature == G2_POINT_AT_INFINITY:
|
|
|
|
// return True
|
|
|
|
// return bls.FastAggregateVerify(pubkeys, message, signature)
|
2021-07-02 19:27:08 +00:00
|
|
|
func (s *Signature) Eth2FastAggregateVerify(pubKeys []common.PublicKey, msg [32]byte) bool {
|
2021-07-14 11:12:50 +00:00
|
|
|
if len(pubKeys) == 0 && bytes.Equal(s.Marshal(), common.InfiniteSignature[:]) {
|
2021-07-02 19:27:08 +00:00
|
|
|
return true
|
|
|
|
}
|
2021-10-06 02:48:56 +00:00
|
|
|
return s.FastAggregateVerify(pubKeys, msg)
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// NewAggregateSignature creates a blank aggregate signature.
|
2020-10-30 19:06:33 +00:00
|
|
|
func NewAggregateSignature() common.Signature {
|
2020-09-16 13:28:28 +00:00
|
|
|
sig := blst.HashToG2([]byte{'m', 'o', 'c', 'k'}, dst).ToAffine()
|
|
|
|
return &Signature{s: sig}
|
|
|
|
}
|
|
|
|
|
|
|
|
// AggregateSignatures converts a list of signatures into a single, aggregated sig.
|
2020-10-30 19:06:33 +00:00
|
|
|
func AggregateSignatures(sigs []common.Signature) common.Signature {
|
2020-09-16 13:28:28 +00:00
|
|
|
if len(sigs) == 0 {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
rawSigs := make([]*blstSignature, len(sigs))
|
|
|
|
for i := 0; i < len(sigs); i++ {
|
|
|
|
rawSigs[i] = sigs[i].(*Signature).s
|
|
|
|
}
|
|
|
|
|
2020-12-04 06:46:08 +00:00
|
|
|
// Signature and PKs are assumed to have been validated upon decompression!
|
|
|
|
signature := new(blstAggregateSignature)
|
|
|
|
signature.Aggregate(rawSigs, false)
|
2020-09-16 13:28:28 +00:00
|
|
|
return &Signature{s: signature.ToAffine()}
|
|
|
|
}
|
|
|
|
|
|
|
|
// VerifyMultipleSignatures verifies a non-singular set of signatures and its respective pubkeys and messages.
|
|
|
|
// This method provides a safe way to verify multiple signatures at once. We pick a number randomly from 1 to max
|
|
|
|
// uint64 and then multiply the signature by it. We continue doing this for all signatures and its respective pubkeys.
|
|
|
|
// S* = S_1 * r_1 + S_2 * r_2 + ... + S_n * r_n
|
|
|
|
// P'_{i,j} = P_{i,j} * r_i
|
|
|
|
// e(S*, G) = \prod_{i=1}^n \prod_{j=1}^{m_i} e(P'_{i,j}, M_{i,j})
|
|
|
|
// Using this we can verify multiple signatures safely.
|
2020-10-30 19:06:33 +00:00
|
|
|
func VerifyMultipleSignatures(sigs [][]byte, msgs [][32]byte, pubKeys []common.PublicKey) (bool, error) {
|
2020-09-16 13:28:28 +00:00
|
|
|
if len(sigs) == 0 || len(pubKeys) == 0 {
|
|
|
|
return false, nil
|
|
|
|
}
|
|
|
|
rawSigs := new(blstSignature).BatchUncompress(sigs)
|
|
|
|
|
|
|
|
length := len(sigs)
|
|
|
|
if length != len(pubKeys) || length != len(msgs) {
|
|
|
|
return false, errors.Errorf("provided signatures, pubkeys and messages have differing lengths. S: %d, P: %d,M %d",
|
|
|
|
length, len(pubKeys), len(msgs))
|
|
|
|
}
|
|
|
|
mulP1Aff := make([]*blstPublicKey, length)
|
|
|
|
rawMsgs := make([]blst.Message, length)
|
|
|
|
|
|
|
|
for i := 0; i < length; i++ {
|
|
|
|
mulP1Aff[i] = pubKeys[i].(*PublicKey).p
|
|
|
|
rawMsgs[i] = msgs[i][:]
|
|
|
|
}
|
|
|
|
// Secure source of RNG
|
|
|
|
randGen := rand.NewGenerator()
|
2021-04-07 15:18:19 +00:00
|
|
|
randLock := new(sync.Mutex)
|
2020-09-16 13:28:28 +00:00
|
|
|
|
|
|
|
randFunc := func(scalar *blst.Scalar) {
|
|
|
|
var rbytes [scalarBytes]byte
|
2021-04-07 15:18:19 +00:00
|
|
|
randLock.Lock()
|
2021-12-09 19:40:48 +00:00
|
|
|
randGen.Read(rbytes[:]) // #nosec G104 -- Error will always be nil in `read` in math/rand
|
2021-04-07 15:18:19 +00:00
|
|
|
randLock.Unlock()
|
2021-06-28 09:53:03 +00:00
|
|
|
// Protect against the generator returning 0. Since the scalar value is
|
|
|
|
// derived from a big endian byte slice, we take the last byte.
|
|
|
|
rbytes[len(rbytes)-1] |= 0x01
|
2020-09-16 13:28:28 +00:00
|
|
|
scalar.FromBEndian(rbytes[:])
|
|
|
|
}
|
|
|
|
dummySig := new(blstSignature)
|
2020-12-04 06:46:08 +00:00
|
|
|
|
|
|
|
// Validate signatures since we uncompress them here. Public keys should already be validated.
|
|
|
|
return dummySig.MultipleAggregateVerify(rawSigs, true, mulP1Aff, false, rawMsgs, dst, randFunc, randBitsEntropy), nil
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Marshal a signature into a LittleEndian byte slice.
|
|
|
|
func (s *Signature) Marshal() []byte {
|
|
|
|
return s.s.Compress()
|
|
|
|
}
|
|
|
|
|
|
|
|
// Copy returns a full deep copy of a signature.
|
2020-10-30 19:06:33 +00:00
|
|
|
func (s *Signature) Copy() common.Signature {
|
2020-09-17 16:18:19 +00:00
|
|
|
sign := *s.s
|
|
|
|
return &Signature{s: &sign}
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// VerifyCompressed verifies that the compressed signature and pubkey
|
|
|
|
// are valid from the message provided.
|
2021-04-13 19:56:28 +00:00
|
|
|
func VerifyCompressed(signature, pub, msg []byte) bool {
|
2020-12-04 06:46:08 +00:00
|
|
|
// Validate signature and PKs since we will uncompress them here
|
|
|
|
return new(blstSignature).VerifyCompressed(signature, true, pub, true, msg, dst)
|
2020-09-16 13:28:28 +00:00
|
|
|
}
|