Commit graph

181 commits

Author SHA1 Message Date
Isis Lovecruft
a065bee381
Enable Rust 2018. 2019-10-07 23:01:10 +00:00
isis agora lovecruft
29622ec10b
Merge pull request #96 from Arnaz87/master
Drop the static lifetime for context in sign_prehashed
2019-10-07 20:06:48 +00:00
Isis Lovecruft
2d5fe86f30
Document anti-malleability features/functionality. 2019-10-07 19:03:15 +00:00
Isis Lovecruft
ce2260afab
Implement stricter scalar malleability checking for signatures.
Previously, we were checking that the highest 3 bits were unset, which still
leaves 2^253 - 2^252 + 27742317777372353535851937790883648493 potential scalars
for the `s` component of a signature which are not strictly mod \ell.

This change fixes that.

Note: This change makes ed25519-dalek incompatible with ed25519-donna in that
some signatures produced by donna will be verifiable by donna but NOT VERIFIABLE
by dalek.  On the other hand, libsodium exports a -DED25519_COMPAT feature,
which when enabled, means it is compatible with dalek with the
`legacy_compatibility` feature disabled.  Otherwise, libsodium's behaviour is
identical to the behaviour enabled by default in this patch.
2019-10-04 19:34:00 +00:00
Isis Lovecruft
28eed1cba0
Add PublicKey::verify_strict() and Keypair::verify_strict() methods. 2019-10-04 02:54:13 +00:00
Isis Lovecruft
7dd99afb67
Remove most of the rand_os crate, which is only used for testing. 2019-10-04 02:46:02 +00:00
Isis Lovecruft
1342e2a3a4
Fix no_std+alloc builds. 2019-10-04 02:05:20 +00:00
Isis Lovecruft
aa49b4cd8d
Fix two failing doctests. 2019-10-04 01:19:23 +00:00
Arnaud Castellanos Galea
1c9f484d97 Drop the static lifetime for context in sign_prehashed 2019-09-30 16:42:52 +08:00
Isis Lovecruft
d31df0aaa8
Remove sha2 dep; limit rand depends; fixes after PR#68 merge.
* ADD new "batch" feature for feature-gating ed25519 batch verification; off by
   default. The "batch" feature is the only thing which depends on all of the
   `rand` crate, since it requires the functionality of `rand::thread_rng()`.
   Without batch verification, the rest of ed25519-dalek only depends on
   `rand_os` and `rand_core`.
2019-04-02 01:46:23 +00:00
Isis Lovecruft
1bec256418
Merge remote-tracking branch 'newpavlov/rand_core' into develop 2019-03-12 22:22:19 +00:00
Nicolas Stalder
1dfe00b79d Fix rand dependency, deal with unusedness warnings 2019-01-27 03:06:18 +01:00
Isis Lovecruft
ae8764fbef
Update copyright year to 2019 and destroy capitalism. 2019-01-18 04:59:12 +00:00
Артём Павлов [Artyom Pavlov]
762eb0c470 use rand_core 2019-01-05 15:58:59 +03:00
Isis Lovecruft
0ddf39e443
Revise some module descriptions. 2018-12-30 04:27:40 +00:00
Isis Lovecruft
8b30d4084a
Run rustfmt on src/ed25519.rs. 2018-12-30 04:16:03 +00:00
Isis Lovecruft
fa726cfdcc
Run rustfmt on src/lib.rs. 2018-12-30 04:12:33 +00:00
Isis Lovecruft
ad49d31bbc
Run rustfmt on src/errors.rs. 2018-12-30 04:10:59 +00:00
Isis Lovecruft
811793ba2b
Run rustfmt on src/secret.rs. 2018-12-30 04:10:09 +00:00
Isis Lovecruft
d853856c36
Run rustfmt on src/public.rs. 2018-12-30 04:07:50 +00:00
Isis Lovecruft
a141863542
Run rustfmt on src/signature.rs. 2018-12-30 04:05:20 +00:00
Isis Lovecruft
e6528bd683
Create new module for public key code. 2018-12-30 03:53:42 +00:00
Isis Lovecruft
e3d7c16aac
Make errors module private. 2018-12-30 03:53:42 +00:00
Isis Lovecruft
6fea2e1ea0
Realphabetise extern crates. 2018-12-30 03:53:42 +00:00
Isis Lovecruft
f6ec28c077
Create module for secret key types. 2018-12-30 03:53:42 +00:00
Isis Lovecruft
1cf581d67d
Add lints (and fix warnings) for Rust 2018 code. 2018-12-30 03:27:01 +00:00
Isis Lovecruft
ce857a50e7
Remove unnecessary #![allow(unused_features)] lint. 2018-12-30 03:11:28 +00:00
Isis Lovecruft
d748a41894
Create new module for Signature type. 2018-12-30 03:03:40 +00:00
Isis Lovecruft
80e72db677
Create new module for constants. 2018-12-30 02:36:49 +00:00
Isis Lovecruft
e88da5ea85
Move integration tests to their own directory. 2018-12-30 02:32:21 +00:00
Isis Lovecruft
4ee77b915e
Avoid using deprecated import path for rand::rngs::OsRng. 2018-12-30 02:31:47 +00:00
Isis Lovecruft
486f23f1ad
Fix some inconsistent terminology in docstrings. 2018-12-30 02:31:47 +00:00
Isis Lovecruft
d81d43e3ae
Hardcode use of sha2::Sha512 in most cases.
This implements https://github.com/dalek-cryptography/ed25519-dalek/issues/64

You can still choose the "prehash" algorithm, as long as it has 64 bytes of
output.  Otherwise, everything is hardcoded to use sha2::Sha512.  To use a
different implementation you'll need a [patch.crates-io] section in cargo
config.
2018-12-30 00:40:01 +00:00
Isis Lovecruft
7877a7fa00
WARNING: Remove #[repr(C)] from all types. 2018-12-23 12:00:59 +00:00
Isis Lovecruft
8dbaf9a8d2
Move PublicKey point decompression into initialisation.
This caches the public key internally so that we effectively get a free
speedup on key reuse in regular signature verification, similar to that in
batch verification.  (However, this also "speeds up"¹ batch verifications.)

¹ Less of a speed up than moving the computation elsewhere, but the speed up
on reuse still also applies to key reuse for batch verification.
2018-12-23 12:00:59 +00:00
Isis Lovecruft
3d697bf27a
Fix doctests which relied on the sha2 feature being enabled. 2018-12-22 13:13:21 +00:00
Isis Lovecruft
a9e5410f69
Fix serialised size assumptions from #48.
Unfortunately the serialised size is likely never going to be the same
as the type's size in memory, as most serialisation formats define
additional headers for parsing safety reasons, such as buffer lengths
and type information.
2018-12-22 13:13:21 +00:00
Isis Lovecruft
80ae5d0683
Cleanup RNG usage after merging #57. 2018-12-22 12:20:59 +00:00
isis agora lovecruft
85285576a7
Merge pull request #57 from IronCoreLabs/rand-0.6
Rand 0.6 version bump
2018-12-18 01:33:57 +00:00
Isis Lovecruft
0dab8943a1
Merge remote-tracking branch 'garious/add-as-ref' into develop 2018-12-18 01:13:13 +00:00
isis agora lovecruft
26e017df7c
Revert "Add AsRef instances for PublicKey and SecretKey" 2018-12-18 01:09:00 +00:00
isis agora lovecruft
60dea0b3b1
Merge pull request #48 from garious/serialized-size
Add tests for upgraded generic_array
2018-12-18 00:46:05 +00:00
Colt Frederickson
42b5d6ada9 Rand 0.6 version bump 2018-11-14 17:08:32 -07:00
Greg Fitzgerald
680f68be31 Add tests for generic_array serialized size
generic_array v0.12 no longer serializes GenericArray as a Vec,
which reduces the serialized size of PublicKey, Signature, and
SecretKey by 8 bytes. Now that generic_array has been upgraded,
these tests simply ensure the serialization size doesn't change
in the future.
2018-11-09 10:16:14 -07:00
Greg Fitzgerald
a3cfc7e294 Add AsRef instances for PublicKey and SecretKey
This just makes it a little easier to migrate to this library from
alternatives such as 'ring'.
2018-11-09 10:13:16 -07:00
Greg Fitzgerald
82948f0dd6 Fix serde doc tests
And let latest rustfmt reorder imports.
2018-11-09 10:12:32 -07:00
Isis Lovecruft
b97fa08900
Update curve25519-dalek dependency to 1.0.0-pre.0. 2018-11-06 01:40:21 +00:00
Henry de Valence
1e8b9f962b Remove unused features 2018-09-26 11:38:41 -07:00
isis agora lovecruft
da8e609dc2
Merge pull request #36 from sunhuachuang/develop
fix doc code
2018-09-14 19:04:51 +00:00
Isis Lovecruft
49ebfa13de
Implement From<ExpandedSecretKey> for PublicKey.
* CLOSES https://github.com/dalek-cryptography/ed25519-dalek/issues/39
2018-09-14 18:28:16 +00:00
sun
0ea12f922e fix doc code 2018-08-24 11:27:15 +08:00
Isis Lovecruft
3ad616a23c
Remove unused csprng parameter from verify_batch() function. 2018-07-27 17:30:57 +00:00
Isis Lovecruft
e35323412d
Merge remote-tracking branch 'hdevalence/feature/27-batch' into develop 2018-07-27 17:24:37 +00:00
Henry de Valence
4c838decd8 Use 128-bit scalars 2018-07-26 21:09:52 -07:00
Henry de Valence
f60987dee5 Try optional_multiscalar_mul 2018-07-26 20:58:11 -07:00
Isis Lovecruft
318898fac1
Merge branch 'feature/drop-with-clear' into develop 2018-07-27 03:56:13 +00:00
Isis Lovecruft
a92a5b73a1
It's 2018 and nothing's gotten any better outside. 2018-07-27 03:48:37 +00:00
Isis Lovecruft
81a3d3298b
Leave a comment explaining why we derive Default. 2018-07-26 20:15:13 +00:00
Isis Lovecruft
6513d4980a
Implement Drop for secret key material using clear_on_drop. 2018-07-20 23:08:08 +00:00
Isis Lovecruft
d896886691
Overwrite secret key material with zeroes on drop. 2018-07-20 20:20:40 +00:00
Isis Lovecruft
ce46a12d92
Implement batch verification.
The API for this isn't the greatest and I apologise for that.  Suggestions for
improvement welcome.  One thing which @hdevalence and I considered was to
change the function signature to:

    pub fn verify_batch<D, C, M, S, K>(messages: M,
                                       signatures: S,
                                       public_keys: K,
                                       csprng: &mut C) -> Result<(), SignatureError>
        where D: Digest<OutputSize = U64> + Default,
              C: Rng + CryptoRng,
              M: IntoIterator<Item = &[u8]>,
              S: IntoIterator,
              S::Item: Borrow<Signature>,
              K: IntoIterator,
              K::Item: Borrow<Signature>,

The other improvement which could be made is to implement 128-bit scalars for
the randomnesses.

 * CLOSES #27
2018-07-17 19:03:46 +00:00
Isis Lovecruft
b32e39c801
Fix match statements on public key decompression. 2018-07-15 22:21:32 +00:00
Isis Lovecruft
cdebf245cc
Merge branch 'feature/cleanup-sig-code' into develop 2018-07-15 22:13:37 +00:00
Isis Lovecruft
2e5363c679
Cleanup verification variable declarations. 2018-07-15 22:04:55 +00:00
Isis Lovecruft
cdbc302da7
Fix a couple docstrings which mentioned r instead of R. 2018-07-15 21:51:23 +00:00
Isis Lovecruft
5c26349b6c
Derive Eq, PartialEq for Signature. 2018-07-15 21:50:20 +00:00
Isis Lovecruft
80075a0b41
Cleanup signing code to use new dalek APIs and Rust syntax. 2018-07-15 21:41:44 +00:00
Henry de Valence
030eff547f Make verify return a Result.
This also simplifies the verification logic.  Because the verification check
happens in variable time, we don't need to do a constant-time eq check at the
end, so we can drop the `subtle` dependency entirely.

The `DecodingError` type becomes `SignatureError` and is also used to
signal failing verifications.
2018-07-15 13:07:58 -07:00
Isis Lovecruft
fad39851aa
Add doctests for sign_prehashed() and verify_prehashed(). 2018-07-13 23:07:07 +00:00
Isis Lovecruft
68d2ff93f5
Implement ed25519ph from RFC8032 §5.1.
* FIXES #21: https://github.com/dalek-cryptography/ed25519-dalek/issues/21
2018-07-13 23:06:39 +00:00
Isis Lovecruft
9d58954578
Avoid compressing R twice. 2018-07-12 21:47:52 +00:00
Isis Lovecruft
164303eeac
Switch to using criterion for benchmarks. 2018-07-11 22:46:32 +00:00
Isis Lovecruft
a7c318da6e
Fix benchmarks to use new rand_core traits. 2018-05-30 21:01:21 +00:00
Isis Lovecruft
47c1d869ec
Make key generation work with no_std. 2018-05-16 22:09:31 +00:00
Isis Lovecruft
f6a631c229
WIP Update curve25519-dalek dependency to 0.17. 2018-05-15 23:34:01 +00:00
Isis Lovecruft
f790bd2ce1
Update subtle and curve25519-dalek dependencies. 2018-03-26 02:13:39 +00:00
Isis Lovecruft
e648c641cc
Fix typo in benchmark variable name. 2018-02-02 22:17:01 +00:00
Isis Lovecruft
08a5fc34ae
Fix serde expecting() string for Keypair. 2018-01-26 22:19:55 +00:00
Isis Lovecruft
36399cb1ad
Merge remote-tracking branch 'chain/feature/pubkey_no_std' into develop 2018-01-20 02:51:02 +00:00
Isis Lovecruft
04c8574106
Bump versions for several dependencies. 2018-01-20 02:49:34 +00:00
Isis Lovecruft
c7b69c6562
Expand boats' error types to give more detailed reasons for failures.
This code was significantly based off without boats' error types in
commit 6c1acaca7c, and also upon
conversation with them.  Please target them with praise, and blame me
for whatever mistakes I might have made.
2017-12-24 00:16:52 +00:00
Oleg Andreev
f64b20b351 Do not require feature=std for PublicKey::from_secret 2017-12-12 15:41:39 -08:00
Isis Lovecruft
510a1f89c0
Merge remote-tracking branch 'withoutboats/custom-error-type' into develop 2017-12-09 02:12:39 +00:00
Without Boats
6c1acaca7c
Use failure instead of std::error::Error.
failure is no_std compatible, whereas std::error::Error is not.
2017-12-06 15:25:12 -08:00
Without Boats
b5b295e414
Use a custom error type instead of &'static str.
Advantages of a custom error type:

- It can be more easily integrated into other error types by clients;
  they can implement From<FromBytesError> for their error types, or
  they can use a library like failure.
- It is a zero-sized type, which can enable some representational
  optimizations.
- It can be easier and more stable to test for.
2017-12-05 18:13:43 -08:00
Isis Lovecruft
9d89e2f660
Upgrade to using curve25519-dalek-0.14.0. 2017-12-04 17:47:06 +00:00
Isis Lovecruft
65b7a21062
Make the Keypair struct inherit repr(C). 2017-12-04 00:50:39 +00:00
Isis Lovecruft
7888bfe3f8
Fix serde expecting string. 2017-12-04 00:50:17 +00:00
Isis Lovecruft
8d0dda0847
Implement serde serialisation support and pre-expanded secret keys.
* ADD support for serialisation with serde.
 * ADD a new pre-expanded secret key type, `ExpandedSecretKey`.
 * FIXES Issue #13:
   https://github.com/isislovecruft/ed25519-dalek/issues/13
2017-11-06 03:51:07 +00:00
Isis Lovecruft
e9cd9a2264
Changes for bumping curve25519-dalek dependency to 0.12.0. 2017-10-05 07:03:35 +00:00
Isis Lovecruft
3596e5ec87
Add licence. 2017-10-05 06:19:55 +00:00
Isis Lovecruft
e706b35d92
Merge remote-tracking branch 'greyspectrum/license-typo' into develop 2017-10-05 06:12:03 +00:00
Zaki Manian
8accff36b3
Replaces the depracted rustc_serialize with hex 2017-10-05 05:20:24 +00:00
greyspectrum
52ecf1669e Fix a small typo in the license url. 2017-09-06 13:31:52 -04:00
Isis Lovecruft
039533d349
Add additional benchmark for further comparison with ed25519-donna.
ed25519-donna includes a "curved25519_scalarmult_basepoint" [sic]
function. See https://github.com/isislovecruft/dalek-benchmarks.
2017-08-16 04:19:04 +00:00
Isis Lovecruft
07dc9f4ba7
Bump curve25519-dalek dependency to 0.11.0. 2017-08-15 05:30:53 +00:00
Isis Lovecruft
27753235ae
Upgrade curve25519-dalek, generic-array, and digest dependencies.
As well as adding a dependency on subtle and upgrading dev-dependency sha2.
2017-08-01 18:05:58 +00:00
Isis Lovecruft
df3834c03d
Change SecretKey bytes to only include the secret, not also public, key. 2017-08-01 06:23:46 +00:00
Isis Lovecruft
99d3426569
Refactor to use new curve25519-dalek APIs. 2017-05-14 10:57:59 +00:00
Isis Lovecruft
a195249468
Switch to using new digest v0.5 API. 2017-05-08 07:54:56 +00:00