Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ cmake_minimum_required(VERSION 3.16)

project(
CBMPC
VERSION 0.1.0
VERSION 0.3.0
LANGUAGES CXX)

set(CMAKE_CXX_STANDARD 17)
Expand Down Expand Up @@ -122,7 +122,7 @@ if(NOT DEFINED CBMPC_OPENSSL_ROOT)
if(DEFINED ENV{CBMPC_OPENSSL_ROOT})
set(CBMPC_OPENSSL_ROOT $ENV{CBMPC_OPENSSL_ROOT})
else()
set(CBMPC_OPENSSL_ROOT "/usr/local/opt/openssl@3.6.3")
set(CBMPC_OPENSSL_ROOT "/usr/local/opt/openssl@3.6.4")
endif()
endif()

Expand Down
6 changes: 3 additions & 3 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -37,9 +37,9 @@ WORKDIR /build
COPY scripts/openssl/build-static-openssl-linux.sh .
RUN sh build-static-openssl-linux.sh \
&& mkdir -p /usr/local/lib64 /usr/local/lib /usr/local/include \
&& ln -sf /usr/local/opt/openssl@3.6.1/lib64/libcrypto.a /usr/local/lib64/libcrypto.a \
&& ln -sf /usr/local/opt/openssl@3.6.1/lib64/libcrypto.a /usr/local/lib/libcrypto.a \
&& ln -sf /usr/local/opt/openssl@3.6.1/include/openssl /usr/local/include/openssl \
&& ln -sf /usr/local/opt/openssl@3.6.4/lib64/libcrypto.a /usr/local/lib64/libcrypto.a \
&& ln -sf /usr/local/opt/openssl@3.6.4/lib64/libcrypto.a /usr/local/lib/libcrypto.a \
&& ln -sf /usr/local/opt/openssl@3.6.4/include/openssl /usr/local/include/openssl \
&& rm -rf /build

WORKDIR /code
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -168,7 +168,7 @@ There are three build modes available:

### OpenSSL

The library depends on a **custom build of OpenSSL 3.6.3** with specific modifications (see [External Dependencies](#external-dependencies)). You must build this custom version before compiling the library.
The library depends on a **custom build of OpenSSL 3.6.4** with specific modifications (see [External Dependencies](#external-dependencies)). You must build this custom version before compiling the library.

**Quick Start:**
```bash
Expand All @@ -190,7 +190,7 @@ scripts/openssl/build-static-openssl-macos.sh # for x86_64
scripts/openssl/build-static-openssl-macos-m1.sh # for ARM64
```

**Note:** These scripts install OpenSSL to `/usr/local/opt/openssl@3.6.3` and may require `sudo` permission.
**Note:** These scripts install OpenSSL to `/usr/local/opt/openssl@3.6.4` and may require `sudo` permission.

**Custom Install Location:**
If you prefer a different installation path, you can set the `CBMPC_OPENSSL_ROOT` variable:
Expand Down
4 changes: 2 additions & 2 deletions cmake/openssl.cmake
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
# The OpenSSL path can be customized via:
# 1. CMake variable: -DCBMPC_OPENSSL_ROOT=/path/to/openssl
# 2. Environment variable: export CBMPC_OPENSSL_ROOT=/path/to/openssl
# 3. Default: /usr/local/opt/openssl@3.6.3
# 3. Default: /usr/local/opt/openssl@3.6.4
#
# To build the custom OpenSSL, run the appropriate script:
# - macOS (x86_64): scripts/openssl/build-static-openssl-macos.sh
Expand All @@ -16,7 +16,7 @@ macro(link_openssl TARGET_NAME)
if(DEFINED ENV{CBMPC_OPENSSL_ROOT})
set(CBMPC_OPENSSL_ROOT $ENV{CBMPC_OPENSSL_ROOT})
else()
set(CBMPC_OPENSSL_ROOT "/usr/local/opt/openssl@3.6.3")
set(CBMPC_OPENSSL_ROOT "/usr/local/opt/openssl@3.6.4")
endif()
endif()

Expand Down
4 changes: 2 additions & 2 deletions include-internal/cbmpc/internal/crypto/base_bn.h
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,8 @@

#include <cbmpc/core/buf.h>

#if OPENSSL_VERSION_MAJOR != 3 || OPENSSL_VERSION_MINOR != 6 || OPENSSL_VERSION_PATCH != 3
#error "cb-mpc copied OpenSSL BN internals require OpenSSL 3.6.3"
#if OPENSSL_VERSION_MAJOR != 3 || OPENSSL_VERSION_MINOR != 6 || OPENSSL_VERSION_PATCH != 4
#error "cb-mpc copied OpenSSL BN internals require OpenSSL 3.6.4"
#endif

struct bignum_st {
Expand Down
13 changes: 8 additions & 5 deletions include-internal/cbmpc/internal/protocol/mpc_job.h
Original file line number Diff line number Diff line change
Expand Up @@ -144,14 +144,16 @@ class job_mp_t {
return unpack_msgs(std::get<1>(msg_ctx), bufs, std::get<2>(msg_ctx));
}
template <typename Tuple1, typename Tuple2, std::size_t... Is>
void unpack_multi_sets_msgs_helper(Tuple1& t1, Tuple2& t2, std::index_sequence<Is...>) {
error_t unpack_multi_sets_msgs_helper(Tuple1& t1, Tuple2& t2, std::index_sequence<Is...>) {
error_t rv = UNINITIALIZED_ERROR;
// Use the index sequence to access elements from both tuples
(unpack_msg_ctx(std::get<Is>(t1), std::get<Is>(t2)), ...);
((rv = unpack_msg_ctx(std::get<Is>(t1), std::get<Is>(t2))) || ...);
return rv;
}
template <typename... Ts1, typename... Ts2>
void unpack_multi_sets_tupled_msgs(std::tuple<Ts1...>& t1, std::tuple<Ts2&...> t2) {
error_t unpack_multi_sets_tupled_msgs(std::tuple<Ts1...>& t1, std::tuple<Ts2&...> t2) {
static_assert(sizeof...(Ts1) == sizeof...(Ts2), "Tuples must have the same length to unpack");
unpack_multi_sets_msgs_helper(t1, t2, std::index_sequence_for<Ts1...>{});
return unpack_multi_sets_msgs_helper(t1, t2, std::index_sequence_for<Ts1...>{});
}

/* functions to send and received serialized multi-party messages */
Expand Down Expand Up @@ -291,6 +293,7 @@ class job_mp_t {
// multiple times.
template <typename... MSG_TUPLES>
error_t group_message(const MSG_TUPLES&... msg_tuples) {
static_assert(sizeof...(MSG_TUPLES) > 0, "group_message requires at least one message tuple");
error_t rv = UNINITIALIZED_ERROR;
auto packed_msgs_tuple = std::make_tuple(pack_multi_sets_msgs(msg_tuples)...);
std::vector<buf_t> packed_msgs = combine_packed_msgs(packed_msgs_tuple);
Expand All @@ -299,7 +302,7 @@ class job_mp_t {
if (rv = receive_from_parties(party_set_t::all(), packed_msgs)) return rv;

if (rv = split_packed_msgs(packed_msgs, packed_msgs_tuple)) return rv;
unpack_multi_sets_tupled_msgs(packed_msgs_tuple, std::tie(msg_tuples...));
if (rv = unpack_multi_sets_tupled_msgs(packed_msgs_tuple, std::tie(msg_tuples...))) return rv;

return SUCCESS;
}
Expand Down
7 changes: 7 additions & 0 deletions include/cbmpc/api/tdh2.h
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,10 @@ error_t verify(mem_t public_key, mem_t ciphertext, mem_t label);
error_t partial_decrypt(mem_t private_share, mem_t ciphertext, mem_t label, buf_t& partial_decryption);

// Combine additive shares + partial decryptions to decrypt.
//
// `public_shares` must be the complete, ordered public-share output from the
// same DKG operation as `public_key`. The function rejects a share set whose
// sum does not equal the public key.
error_t combine_additive(mem_t public_key, const std::vector<mem_t>& public_shares, mem_t label,
const std::vector<mem_t>& partial_decryptions, mem_t ciphertext, buf_t& plaintext);

Expand All @@ -67,6 +71,9 @@ error_t combine_additive(mem_t public_key, const std::vector<mem_t>& public_shar
// - `party_names.size() == public_shares.size()`
// - `partial_decryption_party_names.size() == partial_decryptions.size()`
// - The leaf set of `access_structure` must match `party_names` exactly.
// - `public_key`, `public_shares`, and `access_structure` must correspond to
// the same DKG operation. The public shares selected by the partial-
// decryption quorum must reconstruct to the public key.
error_t combine_ac(const access_structure_t& access_structure, mem_t public_key,
const std::vector<std::string_view>& party_names, const std::vector<mem_t>& public_shares,
mem_t label, const std::vector<std::string_view>& partial_decryption_party_names,
Expand Down
12 changes: 12 additions & 0 deletions include/cbmpc/c_api/tdh2.h
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,14 @@ cbmpc_error_t cbmpc_tdh2_partial_decrypt(cmem_t private_share, cmem_t ciphertext

// Combine additive shares / partial decryptions to recover the plaintext.
//
// Requirements:
// - `public_shares` must be the complete, ordered public-share output from the
// same `cbmpc_tdh2_dkg_additive` operation as `public_key`.
// - `partial_decryptions` must contain exactly one partial decryption for each
// role represented in `public_shares`.
// - The function returns an error if the public shares do not sum to the public
// key or if a partial-decryption role is missing or duplicated.
//
// Ownership:
// - On success, `out_plaintext->data` is allocated by the library and must be
// freed with `cbmpc_cmem_free(*out_plaintext)`.
Expand All @@ -78,6 +86,10 @@ cbmpc_error_t cbmpc_tdh2_combine_additive(cmem_t public_key, cmems_t public_shar
// - `party_names_count == public_shares.count`
// - `partial_decryption_party_names_count == partial_decryptions.count`
// - The leaf set of `access_structure` must match `party_names` exactly.
// - `public_key`, `public_shares`, and `access_structure` must correspond to
// the same `cbmpc_tdh2_dkg_ac` operation.
// - The public shares selected by the partial-decryption quorum must
// reconstruct to the public key; otherwise, the function returns an error.
//
// Ownership: same as `cbmpc_tdh2_combine_additive`.
cbmpc_error_t cbmpc_tdh2_combine_ac(const cbmpc_access_structure_t* access_structure, cmem_t public_key,
Expand Down
12 changes: 6 additions & 6 deletions scripts/openssl/build-static-openssl-linux.sh
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,9 @@
set -e

cd /tmp
curl -L https://github.com/openssl/openssl/releases/download/openssl-3.6.3/openssl-3.6.3.tar.gz --output openssl-3.6.3.tar.gz
expectedHash='243a86649cf6f23eeb6a2ff2456e09e5d77dd9018a54d3d96b0c6bdd6ba6c7f1'
fileHash=$(sha256sum openssl-3.6.3.tar.gz | cut -d " " -f 1 )
curl -L https://github.com/openssl/openssl/releases/download/openssl-3.6.4/openssl-3.6.4.tar.gz --output openssl-3.6.4.tar.gz
expectedHash='9bffaa1ad1e07b354c21bd3324ec02fa15579f45a7d0494b3e74bc449b7333ef'
fileHash=$(sha256sum openssl-3.6.4.tar.gz | cut -d " " -f 1 )

if [ $expectedHash != $fileHash ]
then
Expand All @@ -18,8 +18,8 @@ fi
echo "LINUX Start"
uname -r

tar -xzf openssl-3.6.3.tar.gz
cd openssl-3.6.3
tar -xzf openssl-3.6.4.tar.gz
cd openssl-3.6.4
sed -i -e 's/^static//' crypto/ec/curve25519.c


Expand All @@ -29,7 +29,7 @@ sed -i -e 's/^static//' crypto/ec/curve25519.c
no-gost no-http no-idea no-mdc2 no-md2 no-md4 no-module no-nextprotoneg no-ocb no-ocsp no-psk no-padlockeng no-poly1305 \
no-quic no-rc2 no-rc4 no-rc5 no-rfc3779 no-scrypt no-sctp no-seed no-siphash no-sm2 no-sm3 no-sm4 no-sock no-srtp no-srp \
no-ssl-trace no-ssl3 no-stdio no-tests no-tls no-ts no-unit-test no-uplink no-whirlpool no-zlib \
--prefix="${CBMPC_OPENSSL_ROOT:-/usr/local/opt/openssl@3.6.3}" --libdir=lib64
--prefix="${CBMPC_OPENSSL_ROOT:-/usr/local/opt/openssl@3.6.4}" --libdir=lib64

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The script now installs OpenSSL under openssl@3.6.4, while Dockerfile:40-42 still creates the /usr/local compatibility links against openssl@3.6.1. Is that divergence intentional?

The CMake paths use the new 3.6.4 prefix directly, but consumers relying on the conventional /usr/local include and library paths would still resolve through the older targets. If this is not intentional, could the Dockerfile links be updated as part of the version bump?


make build_generated install_sw -j4

Expand Down
12 changes: 6 additions & 6 deletions scripts/openssl/build-static-openssl-macos-m1.sh
Original file line number Diff line number Diff line change
Expand Up @@ -20,9 +20,9 @@ fi
export MACOSX_DEPLOYMENT_TARGET="${MACOSX_DEPLOYMENT_TARGET:-16.0}"

cd /tmp
curl -L https://github.com/openssl/openssl/releases/download/openssl-3.6.3/openssl-3.6.3.tar.gz --output openssl-3.6.3.tar.gz
expectedHash='243a86649cf6f23eeb6a2ff2456e09e5d77dd9018a54d3d96b0c6bdd6ba6c7f1'
fileHash=$(sha256sum openssl-3.6.3.tar.gz | cut -d " " -f 1 )
curl -L https://github.com/openssl/openssl/releases/download/openssl-3.6.4/openssl-3.6.4.tar.gz --output openssl-3.6.4.tar.gz
expectedHash='9bffaa1ad1e07b354c21bd3324ec02fa15579f45a7d0494b3e74bc449b7333ef'
fileHash=$(sha256sum openssl-3.6.4.tar.gz | cut -d " " -f 1 )


if [ $expectedHash != $fileHash ]
Expand All @@ -34,8 +34,8 @@ then
fi


tar -xzf openssl-3.6.3.tar.gz
cd openssl-3.6.3
tar -xzf openssl-3.6.4.tar.gz
cd openssl-3.6.4
sed -i -e 's/^static//' crypto/ec/curve25519.c


Expand All @@ -45,7 +45,7 @@ sed -i -e 's/^static//' crypto/ec/curve25519.c
no-gost no-http no-idea no-mdc2 no-md2 no-md4 no-module no-nextprotoneg no-ocb no-ocsp no-psk no-padlockeng no-poly1305 \
no-quic no-rc2 no-rc4 no-rc5 no-rfc3779 no-scrypt no-sctp no-seed no-siphash no-sm2 no-sm3 no-sm4 no-sock no-srtp no-srp \
no-ssl-trace no-ssl3 no-stdio no-tests no-tls no-ts no-unit-test no-uplink no-whirlpool no-zlib \
--prefix="${CBMPC_OPENSSL_ROOT:-/usr/local/opt/openssl@3.6.3}" darwin64-arm64-cc
--prefix="${CBMPC_OPENSSL_ROOT:-/usr/local/opt/openssl@3.6.4}" darwin64-arm64-cc

make -j
make install_sw
Expand Down
12 changes: 6 additions & 6 deletions scripts/openssl/build-static-openssl-macos.sh
Original file line number Diff line number Diff line change
Expand Up @@ -20,9 +20,9 @@ fi
export MACOSX_DEPLOYMENT_TARGET="${MACOSX_DEPLOYMENT_TARGET:-16.0}"

cd /tmp
curl -L https://github.com/openssl/openssl/releases/download/openssl-3.6.3/openssl-3.6.3.tar.gz --output openssl-3.6.3.tar.gz
expectedHash='243a86649cf6f23eeb6a2ff2456e09e5d77dd9018a54d3d96b0c6bdd6ba6c7f1'
fileHash=$(sha256sum openssl-3.6.3.tar.gz | cut -d " " -f 1 )
curl -L https://github.com/openssl/openssl/releases/download/openssl-3.6.4/openssl-3.6.4.tar.gz --output openssl-3.6.4.tar.gz
expectedHash='9bffaa1ad1e07b354c21bd3324ec02fa15579f45a7d0494b3e74bc449b7333ef'
fileHash=$(sha256sum openssl-3.6.4.tar.gz | cut -d " " -f 1 )

if [ $expectedHash != $fileHash ]
then
Expand All @@ -33,8 +33,8 @@ then
fi


tar -xzf openssl-3.6.3.tar.gz
cd openssl-3.6.3
tar -xzf openssl-3.6.4.tar.gz
cd openssl-3.6.4
sed -i -e 's/^static//' crypto/ec/curve25519.c


Expand All @@ -44,7 +44,7 @@ sed -i -e 's/^static//' crypto/ec/curve25519.c
no-gost no-http no-idea no-mdc2 no-md2 no-md4 no-module no-nextprotoneg no-ocb no-ocsp no-psk no-padlockeng no-poly1305 \
no-quic no-rc2 no-rc4 no-rc5 no-rfc3779 no-scrypt no-sctp no-seed no-siphash no-sm2 no-sm3 no-sm4 no-sock no-srtp no-srp \
no-ssl-trace no-ssl3 no-stdio no-tests no-tls no-ts no-unit-test no-uplink no-whirlpool no-zlib \
--prefix="${CBMPC_OPENSSL_ROOT:-/usr/local/opt/openssl@3.6.3}" darwin64-x86_64-cc
--prefix="${CBMPC_OPENSSL_ROOT:-/usr/local/opt/openssl@3.6.4}" darwin64-x86_64-cc

make -j
make install_sw
Expand Down
2 changes: 1 addition & 1 deletion scripts/run-demos.sh
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ CBMPC_PREFIX_PUBLIC="${CBMPC_PREFIX_PUBLIC:-${ROOT_PATH}/build/install/public}"
CBMPC_PREFIX_FULL="${CBMPC_PREFIX_FULL:-${ROOT_PATH}/build/install/full}"
# OpenSSL path is used by demos (C++ via CMake; Go via CGO_LDFLAGS). Keep it
# configurable and consistent with `cmake/openssl.cmake`.
CBMPC_OPENSSL_ROOT="${CBMPC_OPENSSL_ROOT:-/usr/local/opt/openssl@3.6.3}"
CBMPC_OPENSSL_ROOT="${CBMPC_OPENSSL_ROOT:-/usr/local/opt/openssl@3.6.4}"

CPP_DEMOS=("basic_primitive" "zk" "parallel_transport")
API_DEMOS=("pve" "hd_keyset_ecdsa_2p" "ecdsa_mp_pve_backup" "schnorr_2p_pve_batch_backup")
Expand Down
20 changes: 19 additions & 1 deletion src/cbmpc/crypto/tdh2.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -130,19 +130,25 @@ error_t combine_additive(const public_key_t& pub_key, const pub_shares_t& Qi, me
error_t rv = UNINITIALIZED_ERROR;
const auto& curve = pub_key.Q.get_curve();
int n = int(Qi.size());
ecc_point_t reconstructed_Q = curve.infinity();
for (const auto& _Qi : Qi) {
if (rv = curve.check(_Qi)) return coinbase::error(rv, "combine_additive: check Qi failed");
reconstructed_Q += _Qi;
}
if (reconstructed_Q != pub_key.Q) return coinbase::error(E_CRYPTO, "combine_additive: public shares mismatch");
if ((int)partial_decryptions.size() != n) return coinbase::error(E_CRYPTO);

if (rv = ciphertext.verify(pub_key, label)) return rv;

ecc_point_t V = curve.infinity();
std::vector<bool> seen_rids(n, false);
for (int i = 0; i < n; i++) {
const partial_decryption_t& partial_decryption = partial_decryptions[i];

const int rid = partial_decryption.rid;
if (rid < 1 || rid > n) return coinbase::error(E_CRYPTO);
if (seen_rids[rid - 1]) return coinbase::error(E_CRYPTO, "combine_additive: duplicate rid");
seen_rids[rid - 1] = true;
if (rv = partial_decryption.check_partial_decryption_helper(Qi[rid - 1], ciphertext, curve)) return rv;

V += partial_decryption.Xi;
Expand All @@ -161,9 +167,21 @@ error_t combine(const ss::ac_t& ac, const public_key_t& pub_key, ss::ac_pub_shar

if (rv = ciphertext.verify(pub_key, label)) return rv;

ss::ac_pub_shares_t selected_pub_shares;
for (const auto& [name, partial_decryption] : partial_decryptions) {
const auto it = pub_shares.find(name);
if (it == pub_shares.end()) return coinbase::error(E_CRYPTO, "combine: missing public share");
selected_pub_shares[name] = it->second;
}

ecc_point_t reconstructed_Q;
if (rv = ac.reconstruct_exponent(selected_pub_shares, reconstructed_Q)) return rv;
if (reconstructed_Q != pub_key.Q) return coinbase::error(E_CRYPTO, "combine: public shares mismatch");

ss::ac_pub_shares_t Vs;
for (const auto& [name, partial_decryption] : partial_decryptions) {
if (rv = partial_decryption.check_partial_decryption_helper(pub_shares[name], ciphertext, pub_key.Q.get_curve()))
if (rv = partial_decryption.check_partial_decryption_helper(selected_pub_shares.at(name), ciphertext,
pub_key.Q.get_curve()))
return rv;
if (rv = pub_key.Q.get_curve().check(partial_decryption.Xi)) return rv;

Expand Down
12 changes: 6 additions & 6 deletions src/cbmpc/protocol/ecdsa_mp.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -228,18 +228,18 @@ error_t sign(job_mp_t& job, key_t& key, mem_t msg, const party_idx_t sig_receive
for (int t = 0; t < 4; t++) X[l][j][t] = bn_t::from_bin(X_bin[l * 4 + t]);
}

// Initialize the view
crypto::sha256_t view;
view.update(E_i, eK_i._js, eRHO_i._js, pi_eK._js, pi_eRHO._js);

// Proceed with message 4 of the signing protocol
// Validate received round-3 broadcast payloads before hashing them into the transcript.
for (int j = 0; j < n; j++) {
if (i == j) continue;
// The check for validating eK_i and eRHO_i is done in the verify function
if (rv = pi_eK._j.verify(E, eK_i._j, sid, n_uc_elgamal_com_proofs * j + 0)) return rv;
if (rv = pi_eRHO._j.verify(E, eRHO_i._j, sid, n_uc_elgamal_com_proofs * j + 1)) return rv;
}

// Initialize the view
crypto::sha256_t view;
view.update(E_i, eK_i._js, eRHO_i._js, pi_eK._js, pi_eRHO._js);

// Proceed with message 4 of the signing protocol
auto seed = job.nonuniform_msg<buf256_t>();
auto v_theta = job.nonuniform_msg<std::array<bn_t, 4>>();

Expand Down
7 changes: 7 additions & 0 deletions src/cbmpc/protocol/ot.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,11 @@ error_t base_ot_protocol_pvw_ctx_t::step2_S2R(const std::vector<buf_t>& x0, cons
this->x0 = x0;
this->x1 = x1;

for (int i = 0; i < m; i++) {
if (coinbase::bytes_to_bits(x0[i].size()) != l || coinbase::bytes_to_bits(x1[i].size()) != l)
return coinbase::error(E_BADARG, "base_ot_protocol_pvw_ctx_t::step2_S2R: x0/x1 size mismatch");
}

const mod_t& q = curve.order();
ecc_point_t G0, G1, H0, H1;
G0 = curve.generator();
Expand Down Expand Up @@ -86,6 +91,8 @@ error_t base_ot_protocol_pvw_ctx_t::output_R(std::vector<buf_t>& x) {
x.resize(m);

for (int i = 0; i < m; i++) {
if (coinbase::bytes_to_bits(V0[i].size()) != l || coinbase::bytes_to_bits(V1[i].size()) != l)
return coinbase::error(E_FORMAT, "base_ot_protocol_pvw_ctx_t::output_R: V0/V1 size mismatch");
if (rv = curve.check(U0[i])) return coinbase::error(rv, "base_ot_protocol_pvw_ctx_t::output_R: check U0[i] failed");
if (rv = curve.check(U1[i])) return coinbase::error(rv, "base_ot_protocol_pvw_ctx_t::output_R: check U1[i] failed");
// Optimization: if the curve backend supports constant-time point cmov, select U_b and V_b and do
Expand Down
Loading
Loading