blob: 2e83bbb8b69c1d219b3532561676e7fef6c5c672 [file] [log] [blame]
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "https://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/xhtml;charset=UTF-8"/>
<meta http-equiv="X-UA-Compatible" content="IE=9"/>
<meta name="generator" content="Doxygen 1.9.1"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<title>libmpc: factoring_zk.h File Reference</title>
<link href="tabs.css" rel="stylesheet" type="text/css"/>
<script type="text/javascript" src="jquery.js"></script>
<script type="text/javascript" src="dynsections.js"></script>
<link href="search/search.css" rel="stylesheet" type="text/css"/>
<script type="text/javascript" src="search/searchdata.js"></script>
<script type="text/javascript" src="search/search.js"></script>
<script type="text/x-mathjax-config">
MathJax.Hub.Config({
extensions: ["tex2jax.js"],
jax: ["input/TeX","output/HTML-CSS"],
});
</script>
<script type="text/javascript" async="async" src="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.5/MathJax.js"></script>
<link href="doxygen.css" rel="stylesheet" type="text/css" />
</head>
<body>
<div id="top"><!-- do not remove this div, it is closed by doxygen! -->
<div id="titlearea">
<table cellspacing="0" cellpadding="0">
<tbody>
<tr style="height: 56px;">
<td id="projectalign" style="padding-left: 0.5em;">
<div id="projectname">libmpc
</div>
</td>
</tr>
</tbody>
</table>
</div>
<!-- end header part -->
<!-- Generated by Doxygen 1.9.1 -->
<script type="text/javascript">
/* @license magnet:?xt=urn:btih:cf05388f2679ee054f2beb29a391d25f4e673ac3&amp;dn=gpl-2.0.txt GPL-v2 */
var searchBox = new SearchBox("searchBox", "search",false,'Search','.html');
/* @license-end */
</script>
<script type="text/javascript" src="menudata.js"></script>
<script type="text/javascript" src="menu.js"></script>
<script type="text/javascript">
/* @license magnet:?xt=urn:btih:cf05388f2679ee054f2beb29a391d25f4e673ac3&amp;dn=gpl-2.0.txt GPL-v2 */
$(function() {
initMenu('',true,false,'search.php','Search');
$(document).ready(function() { init_search(); });
});
/* @license-end */</script>
<div id="main-nav"></div>
<!-- window showing the filter options -->
<div id="MSearchSelectWindow"
onmouseover="return searchBox.OnSearchSelectShow()"
onmouseout="return searchBox.OnSearchSelectHide()"
onkeydown="return searchBox.OnSearchSelectKey(event)">
</div>
<!-- iframe showing the search results (closed by default) -->
<div id="MSearchResultsWindow">
<iframe src="javascript:void(0)" frameborder="0"
name="MSearchResults" id="MSearchResults">
</iframe>
</div>
<div id="nav-path" class="navpath">
<ul>
<li class="navelem"><a class="el" href="dir_d44c64559bbebec7f509842c48db8b23.html">include</a></li><li class="navelem"><a class="el" href="dir_a166689341c37329f24f96bdba87a08b.html">amcl</a></li> </ul>
</div>
</div><!-- top -->
<div class="header">
<div class="summary">
<a href="#nested-classes">Data Structures</a> &#124;
<a href="#define-members">Macros</a> &#124;
<a href="#func-members">Functions</a> </div>
<div class="headertitle">
<div class="title">factoring_zk.h File Reference</div> </div>
</div><!--header-->
<div class="contents">
<p>ZK proof of knowledge of factoring declarations.
<a href="#details">More...</a></p>
<div class="textblock"><code>#include &quot;amcl/amcl.h&quot;</code><br />
<code>#include &quot;amcl/big_1024_58.h&quot;</code><br />
<code>#include &quot;amcl/ff_2048.h&quot;</code><br />
</div>
<p><a href="factoring__zk_8h_source.html">Go to the source code of this file.</a></p>
<table class="memberdecls">
<tr class="heading"><td colspan="2"><h2 class="groupheader"><a name="nested-classes"></a>
Data Structures</h2></td></tr>
<tr class="memitem:"><td class="memItemLeft" align="right" valign="top">struct &#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="structFACTORING__ZK__modulus.html">FACTORING_ZK_modulus</a></td></tr>
<tr class="memdesc:"><td class="mdescLeft">&#160;</td><td class="mdescRight">Modulus to prove knowledge of factoring. <a href="structFACTORING__ZK__modulus.html#details">More...</a><br /></td></tr>
<tr class="separator:"><td class="memSeparator" colspan="2">&#160;</td></tr>
</table><table class="memberdecls">
<tr class="heading"><td colspan="2"><h2 class="groupheader"><a name="define-members"></a>
Macros</h2></td></tr>
<tr class="memitem:ae3ce9abc99cec679346a7d38bed96d9b"><td class="memItemLeft" align="right" valign="top">#define&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#ae3ce9abc99cec679346a7d38bed96d9b">FS_2048</a>&#160;&#160;&#160;MODBYTES_1024_58 * FFLEN_2048</td></tr>
<tr class="separator:ae3ce9abc99cec679346a7d38bed96d9b"><td class="memSeparator" colspan="2">&#160;</td></tr>
<tr class="memitem:af12daa3ccdbe8c973ca455b53f58f13b"><td class="memItemLeft" align="right" valign="top">#define&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#af12daa3ccdbe8c973ca455b53f58f13b">HFS_2048</a>&#160;&#160;&#160;MODBYTES_1024_58 * HFLEN_2048</td></tr>
<tr class="separator:af12daa3ccdbe8c973ca455b53f58f13b"><td class="memSeparator" colspan="2">&#160;</td></tr>
<tr class="memitem:a6882d3f80db9156ee393363643dbaeb5"><td class="memItemLeft" align="right" valign="top">#define&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#a6882d3f80db9156ee393363643dbaeb5">FACTORING_ZK_A</a>&#160;&#160;&#160;<a class="el" href="factoring__zk_8h.html#ae3ce9abc99cec679346a7d38bed96d9b">FS_2048</a></td></tr>
<tr class="separator:a6882d3f80db9156ee393363643dbaeb5"><td class="memSeparator" colspan="2">&#160;</td></tr>
<tr class="memitem:a2f229a79cea7ffb93931b5af6a05c373"><td class="memItemLeft" align="right" valign="top">#define&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#a2f229a79cea7ffb93931b5af6a05c373">FACTORING_ZK_B</a>&#160;&#160;&#160;16</td></tr>
<tr class="separator:a2f229a79cea7ffb93931b5af6a05c373"><td class="memSeparator" colspan="2">&#160;</td></tr>
<tr class="memitem:a1c4e961cde47625be283dc1c59cec7c0"><td class="memItemLeft" align="right" valign="top">#define&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#a1c4e961cde47625be283dc1c59cec7c0">FACTORING_ZK_OK</a>&#160;&#160;&#160;0</td></tr>
<tr class="separator:a1c4e961cde47625be283dc1c59cec7c0"><td class="memSeparator" colspan="2">&#160;</td></tr>
<tr class="memitem:a48af2c32b3215046f4b708877c34b11d"><td class="memItemLeft" align="right" valign="top">#define&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#a48af2c32b3215046f4b708877c34b11d">FACTORING_ZK_FAIL</a>&#160;&#160;&#160;91</td></tr>
<tr class="separator:a48af2c32b3215046f4b708877c34b11d"><td class="memSeparator" colspan="2">&#160;</td></tr>
<tr class="memitem:ad78ee9209748e3f16fb0bb48a622a0c6"><td class="memItemLeft" align="right" valign="top">#define&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#ad78ee9209748e3f16fb0bb48a622a0c6">FACTORING_ZK_OUT_OF_BOUNDS</a>&#160;&#160;&#160;92</td></tr>
<tr class="separator:ad78ee9209748e3f16fb0bb48a622a0c6"><td class="memSeparator" colspan="2">&#160;</td></tr>
</table><table class="memberdecls">
<tr class="heading"><td colspan="2"><h2 class="groupheader"><a name="func-members"></a>
Functions</h2></td></tr>
<tr class="memitem:aff201c3031798a0f0027dadf929190d7"><td class="memItemLeft" align="right" valign="top">void&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#aff201c3031798a0f0027dadf929190d7">FACTORING_ZK_prove</a> (csprng *RNG, <a class="el" href="structFACTORING__ZK__modulus.html">FACTORING_ZK_modulus</a> *m, const octet *ID, const octet *AD, octet *R, octet *E, octet *Y)</td></tr>
<tr class="memdesc:aff201c3031798a0f0027dadf929190d7"><td class="mdescLeft">&#160;</td><td class="mdescRight">Prove knowledge of the modulus m in ZK. <a href="factoring__zk_8h.html#aff201c3031798a0f0027dadf929190d7">More...</a><br /></td></tr>
<tr class="separator:aff201c3031798a0f0027dadf929190d7"><td class="memSeparator" colspan="2">&#160;</td></tr>
<tr class="memitem:abc6d5b3c3df4c98b36d7f3abe8f69a03"><td class="memItemLeft" align="right" valign="top">int&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#abc6d5b3c3df4c98b36d7f3abe8f69a03">FACTORING_ZK_verify</a> (octet *N, octet *E, octet *Y, const octet *ID, const octet *AD)</td></tr>
<tr class="memdesc:abc6d5b3c3df4c98b36d7f3abe8f69a03"><td class="mdescLeft">&#160;</td><td class="mdescRight">Verify ZK proof of knowledge of factoring of N. <a href="factoring__zk_8h.html#abc6d5b3c3df4c98b36d7f3abe8f69a03">More...</a><br /></td></tr>
<tr class="separator:abc6d5b3c3df4c98b36d7f3abe8f69a03"><td class="memSeparator" colspan="2">&#160;</td></tr>
<tr class="memitem:afba5dd5398192722440f724c3ce6c37a"><td class="memItemLeft" align="right" valign="top">void&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#afba5dd5398192722440f724c3ce6c37a">FACTORING_ZK_modulus_fromOctets</a> (<a class="el" href="structFACTORING__ZK__modulus.html">FACTORING_ZK_modulus</a> *m, octet *P, octet *Q)</td></tr>
<tr class="memdesc:afba5dd5398192722440f724c3ce6c37a"><td class="mdescLeft">&#160;</td><td class="mdescRight">Read a modulus from octets. <a href="factoring__zk_8h.html#afba5dd5398192722440f724c3ce6c37a">More...</a><br /></td></tr>
<tr class="separator:afba5dd5398192722440f724c3ce6c37a"><td class="memSeparator" colspan="2">&#160;</td></tr>
<tr class="memitem:a40183656099267b7b20980fd5c2e8dcd"><td class="memItemLeft" align="right" valign="top">void&#160;</td><td class="memItemRight" valign="bottom"><a class="el" href="factoring__zk_8h.html#a40183656099267b7b20980fd5c2e8dcd">FACTORING_ZK_modulus_kill</a> (<a class="el" href="structFACTORING__ZK__modulus.html">FACTORING_ZK_modulus</a> *m)</td></tr>
<tr class="memdesc:a40183656099267b7b20980fd5c2e8dcd"><td class="mdescLeft">&#160;</td><td class="mdescRight">Clean memory associated to a modulus. <a href="factoring__zk_8h.html#a40183656099267b7b20980fd5c2e8dcd">More...</a><br /></td></tr>
<tr class="separator:a40183656099267b7b20980fd5c2e8dcd"><td class="memSeparator" colspan="2">&#160;</td></tr>
</table>
<h2 class="groupheader">Macro Definition Documentation</h2>
<a id="a6882d3f80db9156ee393363643dbaeb5"></a>
<h2 class="memtitle"><span class="permalink"><a href="#a6882d3f80db9156ee393363643dbaeb5">&#9670;&nbsp;</a></span>FACTORING_ZK_A</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">#define FACTORING_ZK_A&#160;&#160;&#160;<a class="el" href="factoring__zk_8h.html#ae3ce9abc99cec679346a7d38bed96d9b">FS_2048</a></td>
</tr>
</table>
</div><div class="memdoc">
<p>Proof, length in bytes </p>
</div>
</div>
<a id="a2f229a79cea7ffb93931b5af6a05c373"></a>
<h2 class="memtitle"><span class="permalink"><a href="#a2f229a79cea7ffb93931b5af6a05c373">&#9670;&nbsp;</a></span>FACTORING_ZK_B</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">#define FACTORING_ZK_B&#160;&#160;&#160;16</td>
</tr>
</table>
</div><div class="memdoc">
<p>Security parameter, length in bytes </p>
</div>
</div>
<a id="a48af2c32b3215046f4b708877c34b11d"></a>
<h2 class="memtitle"><span class="permalink"><a href="#a48af2c32b3215046f4b708877c34b11d">&#9670;&nbsp;</a></span>FACTORING_ZK_FAIL</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">#define FACTORING_ZK_FAIL&#160;&#160;&#160;91</td>
</tr>
</table>
</div><div class="memdoc">
<p>Invalid proof </p>
</div>
</div>
<a id="a1c4e961cde47625be283dc1c59cec7c0"></a>
<h2 class="memtitle"><span class="permalink"><a href="#a1c4e961cde47625be283dc1c59cec7c0">&#9670;&nbsp;</a></span>FACTORING_ZK_OK</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">#define FACTORING_ZK_OK&#160;&#160;&#160;0</td>
</tr>
</table>
</div><div class="memdoc">
<p>Proof successfully verified </p>
</div>
</div>
<a id="ad78ee9209748e3f16fb0bb48a622a0c6"></a>
<h2 class="memtitle"><span class="permalink"><a href="#ad78ee9209748e3f16fb0bb48a622a0c6">&#9670;&nbsp;</a></span>FACTORING_ZK_OUT_OF_BOUNDS</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">#define FACTORING_ZK_OUT_OF_BOUNDS&#160;&#160;&#160;92</td>
</tr>
</table>
</div><div class="memdoc">
<p>Invalid proof bounds </p>
</div>
</div>
<a id="ae3ce9abc99cec679346a7d38bed96d9b"></a>
<h2 class="memtitle"><span class="permalink"><a href="#ae3ce9abc99cec679346a7d38bed96d9b">&#9670;&nbsp;</a></span>FS_2048</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">#define FS_2048&#160;&#160;&#160;MODBYTES_1024_58 * FFLEN_2048</td>
</tr>
</table>
</div><div class="memdoc">
<p>2048 field size in bytes </p>
</div>
</div>
<a id="af12daa3ccdbe8c973ca455b53f58f13b"></a>
<h2 class="memtitle"><span class="permalink"><a href="#af12daa3ccdbe8c973ca455b53f58f13b">&#9670;&nbsp;</a></span>HFS_2048</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">#define HFS_2048&#160;&#160;&#160;MODBYTES_1024_58 * HFLEN_2048</td>
</tr>
</table>
</div><div class="memdoc">
<p>Half 2048 field size in bytes </p>
</div>
</div>
<h2 class="groupheader">Function Documentation</h2>
<a id="afba5dd5398192722440f724c3ce6c37a"></a>
<h2 class="memtitle"><span class="permalink"><a href="#afba5dd5398192722440f724c3ce6c37a">&#9670;&nbsp;</a></span>FACTORING_ZK_modulus_fromOctets()</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">void FACTORING_ZK_modulus_fromOctets </td>
<td>(</td>
<td class="paramtype"><a class="el" href="structFACTORING__ZK__modulus.html">FACTORING_ZK_modulus</a> *&#160;</td>
<td class="paramname"><em>m</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">octet *&#160;</td>
<td class="paramname"><em>P</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">octet *&#160;</td>
<td class="paramname"><em>Q</em>&#160;</td>
</tr>
<tr>
<td></td>
<td>)</td>
<td></td><td></td>
</tr>
</table>
</div><div class="memdoc">
<dl class="params"><dt>Parameters</dt><dd>
<table class="params">
<tr><td class="paramname">m</td><td>The destination modulus </td></tr>
<tr><td class="paramname">P</td><td>The first factor of the modulus </td></tr>
<tr><td class="paramname">Q</td><td>The second factor of the modulus </td></tr>
</table>
</dd>
</dl>
</div>
</div>
<a id="a40183656099267b7b20980fd5c2e8dcd"></a>
<h2 class="memtitle"><span class="permalink"><a href="#a40183656099267b7b20980fd5c2e8dcd">&#9670;&nbsp;</a></span>FACTORING_ZK_modulus_kill()</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">void FACTORING_ZK_modulus_kill </td>
<td>(</td>
<td class="paramtype"><a class="el" href="structFACTORING__ZK__modulus.html">FACTORING_ZK_modulus</a> *&#160;</td>
<td class="paramname"><em>m</em></td><td>)</td>
<td></td>
</tr>
</table>
</div><div class="memdoc">
<dl class="params"><dt>Parameters</dt><dd>
<table class="params">
<tr><td class="paramname">m</td><td>The modulus to clean </td></tr>
</table>
</dd>
</dl>
</div>
</div>
<a id="aff201c3031798a0f0027dadf929190d7"></a>
<h2 class="memtitle"><span class="permalink"><a href="#aff201c3031798a0f0027dadf929190d7">&#9670;&nbsp;</a></span>FACTORING_ZK_prove()</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">void FACTORING_ZK_prove </td>
<td>(</td>
<td class="paramtype">csprng *&#160;</td>
<td class="paramname"><em>RNG</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype"><a class="el" href="structFACTORING__ZK__modulus.html">FACTORING_ZK_modulus</a> *&#160;</td>
<td class="paramname"><em>m</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">const octet *&#160;</td>
<td class="paramname"><em>ID</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">const octet *&#160;</td>
<td class="paramname"><em>AD</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">octet *&#160;</td>
<td class="paramname"><em>R</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">octet *&#160;</td>
<td class="paramname"><em>E</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">octet *&#160;</td>
<td class="paramname"><em>Y</em>&#160;</td>
</tr>
<tr>
<td></td>
<td>)</td>
<td></td><td></td>
</tr>
</table>
</div><div class="memdoc">
<dl class="params"><dt>Parameters</dt><dd>
<table class="params">
<tr><td class="paramname">RNG</td><td>Cryptographically secure PRNG </td></tr>
<tr><td class="paramname">m</td><td>Modulus to prove knowldege of factoring </td></tr>
<tr><td class="paramname">ID</td><td>Prover unique identifier </td></tr>
<tr><td class="paramname">AD</td><td>Additional data to bind in the proof - Optional </td></tr>
<tr><td class="paramname">R</td><td>Random value used in the proof. If RNG is NULL this is read </td></tr>
<tr><td class="paramname">E</td><td>First component of the ZK proof </td></tr>
<tr><td class="paramname">Y</td><td>Second component of the ZK proof </td></tr>
</table>
</dd>
</dl>
</div>
</div>
<a id="abc6d5b3c3df4c98b36d7f3abe8f69a03"></a>
<h2 class="memtitle"><span class="permalink"><a href="#abc6d5b3c3df4c98b36d7f3abe8f69a03">&#9670;&nbsp;</a></span>FACTORING_ZK_verify()</h2>
<div class="memitem">
<div class="memproto">
<table class="memname">
<tr>
<td class="memname">int FACTORING_ZK_verify </td>
<td>(</td>
<td class="paramtype">octet *&#160;</td>
<td class="paramname"><em>N</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">octet *&#160;</td>
<td class="paramname"><em>E</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">octet *&#160;</td>
<td class="paramname"><em>Y</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">const octet *&#160;</td>
<td class="paramname"><em>ID</em>, </td>
</tr>
<tr>
<td class="paramkey"></td>
<td></td>
<td class="paramtype">const octet *&#160;</td>
<td class="paramname"><em>AD</em>&#160;</td>
</tr>
<tr>
<td></td>
<td>)</td>
<td></td><td></td>
</tr>
</table>
</div><div class="memdoc">
<p>Verify that (E, Y) is a valid proof of knowledge of factoring of N</p>
<dl class="params"><dt>Parameters</dt><dd>
<table class="params">
<tr><td class="paramname">N</td><td>Public integer, the RSA modulus </td></tr>
<tr><td class="paramname">E</td><td>Fisrt component of the ZK proof </td></tr>
<tr><td class="paramname">Y</td><td>Second component of the ZK proof </td></tr>
<tr><td class="paramname">ID</td><td>Prover unique identifier </td></tr>
<tr><td class="paramname">AD</td><td>Additional data to bind in the proof - Optional </td></tr>
</table>
</dd>
</dl>
<dl class="section return"><dt>Returns</dt><dd>1 if the proof is valid, 0 otherwise </dd></dl>
</div>
</div>
</div><!-- contents -->
<!-- start footer part -->
<hr class="footer"/><address class="footer"><small>
Generated by&#160;<a href="https://www.doxygen.org/index.html"><img class="footer" src="doxygen.svg" width="104" height="31" alt="doxygen"/></a> 1.9.1
</small></address>
</body>
</html>