forked from coinbase/kryptology
-
Notifications
You must be signed in to change notification settings - Fork 0
/
participant.go
97 lines (87 loc) · 2.88 KB
/
participant.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
//
// Copyright Coinbase, Inc. All Rights Reserved.
//
// SPDX-License-Identifier: Apache-2.0
//
// Package gennaro is an implementation of the DKG part of https://eprint.iacr.org/2020/540.pdf
package gennaro
import (
"crypto/elliptic"
"fmt"
"github.com/coinbase/kryptology/internal"
"github.com/coinbase/kryptology/pkg/core/curves"
"github.com/coinbase/kryptology/pkg/sharing/v1"
)
// Participant is a DKG player that contains information needed to perform DKG rounds
// and yield a secret key share and public key when finished
type Participant struct {
round int
curve elliptic.Curve
scalar curves.EcScalar
otherParticipantShares map[uint32]*dkgParticipantData
id uint32
skShare *curves.Element
verificationKey *v1.ShareVerifier
feldman *v1.Feldman
pedersen *v1.Pedersen
pedersenResult *v1.PedersenResult
}
// NewParticipant creates a participant ready to perform a DKG
// `id` is the integer value identifier for this participant
// `threshold` is the minimum bound for the secret sharing scheme
// `generator` is the blinding factor generator used by pedersen's verifiable secret sharing
// `otherParticipants` is the integer value identifiers for the other participants
// `id` and `otherParticipants` must be the set of integers 1,2,....,n
func NewParticipant(id, threshold uint32, generator *curves.EcPoint, scalar curves.EcScalar, otherParticipants ...uint32) (*Participant, error) {
if generator == nil || len(otherParticipants) == 0 {
return nil, internal.ErrNilArguments
}
err := validIds(append(otherParticipants, id))
if err != nil {
return nil, err
}
limit := uint32(len(otherParticipants)) + 1
feldman, err := v1.NewFeldman(threshold, limit, generator.Curve)
if err != nil {
return nil, err
}
pedersen, err := v1.NewPedersen(threshold, limit, generator)
if err != nil {
return nil, err
}
otherParticipantShares := make(map[uint32]*dkgParticipantData, len(otherParticipants))
for _, id := range otherParticipants {
otherParticipantShares[id] = &dkgParticipantData{
Id: id,
}
}
return &Participant{
id: id,
round: 1,
curve: generator.Curve,
scalar: scalar,
feldman: feldman,
pedersen: pedersen,
otherParticipantShares: otherParticipantShares,
}, nil
}
// Determines if the SSIDs are exactly the values 1..n.
func validIds(ids []uint32) error {
// Index
idMap := make(map[uint32]bool, len(ids))
for _, id := range ids {
idMap[id] = true
}
// Check
for i := 1; i <= len(ids); i++ {
if ok := idMap[uint32(i)]; !ok {
return fmt.Errorf("the ID list %v is invalid. Values must be 1,2,..,n.", ids)
}
}
return nil
}
type dkgParticipantData struct {
Id uint32
Share *v1.ShamirShare
Verifiers []*v1.ShareVerifier
}