2019-03-25 07:02:37 +00:00
|
|
|
use super::{AggregatePublicKey, Signature, BLS_AGG_SIG_BYTE_SIZE};
|
2019-03-03 00:10:38 +00:00
|
|
|
use bls_aggregates::{
|
|
|
|
AggregatePublicKey as RawAggregatePublicKey, AggregateSignature as RawAggregateSignature,
|
|
|
|
};
|
2019-03-15 02:31:30 +00:00
|
|
|
use serde::de::{Deserialize, Deserializer};
|
2019-02-14 01:09:18 +00:00
|
|
|
use serde::ser::{Serialize, Serializer};
|
2019-03-26 05:45:25 +00:00
|
|
|
use serde_hex::{encode as hex_encode, HexVisitor};
|
|
|
|
use ssz::{decode, hash, Decodable, DecodeError, Encodable, SszStream, TreeHash};
|
2019-02-14 01:09:18 +00:00
|
|
|
|
|
|
|
/// A BLS aggregate signature.
|
|
|
|
///
|
|
|
|
/// This struct is a wrapper upon a base type and provides helper functions (e.g., SSZ
|
|
|
|
/// serialization).
|
|
|
|
#[derive(Debug, PartialEq, Clone, Default, Eq)]
|
2019-03-25 07:02:37 +00:00
|
|
|
pub struct AggregateSignature {
|
|
|
|
aggregate_signature: RawAggregateSignature,
|
|
|
|
is_empty: bool,
|
|
|
|
}
|
2019-02-14 01:09:18 +00:00
|
|
|
|
|
|
|
impl AggregateSignature {
|
|
|
|
/// Instantiate a new AggregateSignature.
|
2019-03-25 07:02:37 +00:00
|
|
|
///
|
|
|
|
/// is_empty is false
|
|
|
|
/// AggregateSiganture is point at infinity
|
2019-02-14 01:09:18 +00:00
|
|
|
pub fn new() -> Self {
|
2019-03-25 07:02:37 +00:00
|
|
|
Self {
|
|
|
|
aggregate_signature: RawAggregateSignature::new(),
|
|
|
|
is_empty: false,
|
|
|
|
}
|
2019-02-14 01:09:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/// Add (aggregate) a signature to the `AggregateSignature`.
|
|
|
|
pub fn add(&mut self, signature: &Signature) {
|
2019-03-25 07:02:37 +00:00
|
|
|
if !self.is_empty {
|
|
|
|
self.aggregate_signature.add(signature.as_raw())
|
|
|
|
}
|
2019-02-14 01:09:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/// Verify the `AggregateSignature` against an `AggregatePublicKey`.
|
|
|
|
///
|
|
|
|
/// Only returns `true` if the set of keys in the `AggregatePublicKey` match the set of keys
|
|
|
|
/// that signed the `AggregateSignature`.
|
2019-02-17 23:50:40 +00:00
|
|
|
pub fn verify(
|
|
|
|
&self,
|
|
|
|
msg: &[u8],
|
|
|
|
domain: u64,
|
|
|
|
aggregate_public_key: &AggregatePublicKey,
|
|
|
|
) -> bool {
|
2019-03-25 07:02:37 +00:00
|
|
|
if self.is_empty {
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
self.aggregate_signature
|
|
|
|
.verify(msg, domain, aggregate_public_key.as_raw())
|
2019-03-03 00:10:38 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/// Verify this AggregateSignature against multiple AggregatePublickeys with multiple Messages.
|
|
|
|
///
|
|
|
|
/// All PublicKeys related to a Message should be aggregated into one AggregatePublicKey.
|
|
|
|
/// Each AggregatePublicKey has a 1:1 ratio with a 32 byte Message.
|
|
|
|
pub fn verify_multiple(
|
|
|
|
&self,
|
|
|
|
messages: &[&[u8]],
|
|
|
|
domain: u64,
|
|
|
|
aggregate_public_keys: &[&AggregatePublicKey],
|
|
|
|
) -> bool {
|
2019-03-25 07:02:37 +00:00
|
|
|
if self.is_empty {
|
|
|
|
return false;
|
|
|
|
}
|
2019-03-12 06:19:35 +00:00
|
|
|
let aggregate_public_keys: Vec<&RawAggregatePublicKey> =
|
|
|
|
aggregate_public_keys.iter().map(|pk| pk.as_raw()).collect();
|
2019-03-03 00:10:38 +00:00
|
|
|
|
|
|
|
// Messages are concatenated into one long message.
|
|
|
|
let mut msg: Vec<u8> = vec![];
|
|
|
|
for message in messages {
|
|
|
|
msg.extend_from_slice(message);
|
|
|
|
}
|
|
|
|
|
2019-03-25 07:02:37 +00:00
|
|
|
self.aggregate_signature
|
2019-03-03 00:10:38 +00:00
|
|
|
.verify_multiple(&msg[..], domain, &aggregate_public_keys[..])
|
2019-02-14 01:09:18 +00:00
|
|
|
}
|
2019-03-25 07:02:37 +00:00
|
|
|
|
|
|
|
/// Return AggregateSiganture as bytes
|
|
|
|
pub fn as_bytes(&self) -> Vec<u8> {
|
|
|
|
if self.is_empty {
|
|
|
|
return vec![0; BLS_AGG_SIG_BYTE_SIZE];
|
|
|
|
}
|
|
|
|
self.aggregate_signature.as_bytes()
|
|
|
|
}
|
|
|
|
|
|
|
|
/// Convert bytes to AggregateSiganture
|
|
|
|
pub fn from_bytes(bytes: &[u8]) -> Result<Self, DecodeError> {
|
|
|
|
for byte in bytes {
|
|
|
|
if *byte != 0 {
|
|
|
|
let sig =
|
|
|
|
RawAggregateSignature::from_bytes(&bytes).map_err(|_| DecodeError::Invalid)?;
|
|
|
|
return Ok(Self {
|
|
|
|
aggregate_signature: sig,
|
|
|
|
is_empty: false,
|
|
|
|
});
|
|
|
|
}
|
|
|
|
}
|
|
|
|
Ok(Self::empty_signature())
|
|
|
|
}
|
|
|
|
|
|
|
|
/// Returns if the AggregateSiganture `is_empty`
|
|
|
|
pub fn is_empty(&self) -> bool {
|
|
|
|
self.is_empty
|
|
|
|
}
|
|
|
|
|
|
|
|
/// Creates a new AggregateSignature
|
|
|
|
///
|
|
|
|
/// aggregate_signature set to the point infinity
|
|
|
|
/// is_empty set to true
|
|
|
|
pub fn empty_signature() -> Self {
|
|
|
|
Self {
|
|
|
|
aggregate_signature: RawAggregateSignature::new(),
|
|
|
|
is_empty: true,
|
|
|
|
}
|
|
|
|
}
|
2019-02-14 01:09:18 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
impl Encodable for AggregateSignature {
|
|
|
|
fn ssz_append(&self, s: &mut SszStream) {
|
2019-03-26 05:45:25 +00:00
|
|
|
s.append_encoded_raw(&self.as_bytes());
|
2019-02-14 01:09:18 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl Decodable for AggregateSignature {
|
|
|
|
fn ssz_decode(bytes: &[u8], i: usize) -> Result<(Self, usize), DecodeError> {
|
2019-03-26 05:45:25 +00:00
|
|
|
if bytes.len() - i < BLS_AGG_SIG_BYTE_SIZE {
|
|
|
|
return Err(DecodeError::TooShort);
|
|
|
|
}
|
|
|
|
let agg_sig = AggregateSignature::from_bytes(&bytes[i..(i + BLS_AGG_SIG_BYTE_SIZE)])
|
|
|
|
.map_err(|_| DecodeError::Invalid)?;
|
|
|
|
Ok((agg_sig, i + BLS_AGG_SIG_BYTE_SIZE))
|
2019-02-14 01:09:18 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl Serialize for AggregateSignature {
|
2019-03-25 07:02:37 +00:00
|
|
|
/// Serde serialization is compliant the Ethereum YAML test format.
|
2019-02-14 01:09:18 +00:00
|
|
|
fn serialize<S>(&self, serializer: S) -> Result<S::Ok, S::Error>
|
|
|
|
where
|
|
|
|
S: Serializer,
|
|
|
|
{
|
2019-03-25 07:02:37 +00:00
|
|
|
serializer.serialize_str(&hex_encode(self.as_bytes()))
|
2019-03-15 02:31:30 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl<'de> Deserialize<'de> for AggregateSignature {
|
2019-03-25 07:02:37 +00:00
|
|
|
/// Serde serialization is compliant the Ethereum YAML test format.
|
2019-03-15 02:31:30 +00:00
|
|
|
fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>
|
|
|
|
where
|
|
|
|
D: Deserializer<'de>,
|
|
|
|
{
|
2019-03-26 05:45:25 +00:00
|
|
|
let bytes = deserializer.deserialize_str(HexVisitor)?;
|
|
|
|
let agg_sig = decode(&bytes[..])
|
2019-03-15 02:31:30 +00:00
|
|
|
.map_err(|e| serde::de::Error::custom(format!("invalid ssz ({:?})", e)))?;
|
2019-03-25 07:02:37 +00:00
|
|
|
Ok(agg_sig)
|
2019-02-14 01:09:18 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl TreeHash for AggregateSignature {
|
2019-03-08 23:24:07 +00:00
|
|
|
fn hash_tree_root(&self) -> Vec<u8> {
|
2019-03-25 07:02:37 +00:00
|
|
|
hash(&self.as_bytes())
|
2019-02-14 01:09:18 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
#[cfg(test)]
|
|
|
|
mod tests {
|
|
|
|
use super::super::{Keypair, Signature};
|
|
|
|
use super::*;
|
2019-03-18 07:11:46 +00:00
|
|
|
use ssz::{decode, ssz_encode};
|
2019-02-14 01:09:18 +00:00
|
|
|
|
|
|
|
#[test]
|
|
|
|
pub fn test_ssz_round_trip() {
|
|
|
|
let keypair = Keypair::random();
|
|
|
|
|
|
|
|
let mut original = AggregateSignature::new();
|
2019-02-15 02:58:14 +00:00
|
|
|
original.add(&Signature::new(&[42, 42], 0, &keypair.sk));
|
2019-02-14 01:09:18 +00:00
|
|
|
|
|
|
|
let bytes = ssz_encode(&original);
|
2019-03-18 07:11:46 +00:00
|
|
|
let decoded = decode::<AggregateSignature>(&bytes).unwrap();
|
2019-02-14 01:09:18 +00:00
|
|
|
|
|
|
|
assert_eq!(original, decoded);
|
|
|
|
}
|
|
|
|
}
|