Pedersen Hash Base Points Calculation

This commit is contained in:
Jordi Baylina
2018-11-11 19:52:07 +01:00
parent c4c5b66021
commit 81981a142c
22 changed files with 669 additions and 87 deletions

View File

@@ -1,6 +1,6 @@
const chai = require("chai");
const path = require("path");
const zkSnark = require("zksnark");
const snarkjs = require("snarkjs");
const compiler = require("circom");
const assert = chai.assert;
@@ -17,15 +17,15 @@ describe("Baby Jub test", () => {
// assert.equal(cirDef.nVars, 2);
const circuit = new zkSnark.Circuit(cirDef);
const circuit = new snarkjs.Circuit(cirDef);
console.log("NConstrains: " + circuit.nConstraints);
const input={
x1: zkSnark.bigInt(0),
y1: zkSnark.bigInt(1),
x2: zkSnark.bigInt(0),
y2: zkSnark.bigInt(1)
x1: snarkjs.bigInt(0),
y1: snarkjs.bigInt(1),
x2: snarkjs.bigInt(0),
y2: snarkjs.bigInt(1)
}
const w = circuit.calculateWitness(input);
@@ -45,15 +45,15 @@ describe("Baby Jub test", () => {
// assert.equal(cirDef.nVars, 2);
const circuit = new zkSnark.Circuit(cirDef);
const circuit = new snarkjs.Circuit(cirDef);
console.log("NConstrains: " + circuit.nConstraints);
const input={
x1: zkSnark.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
y1: zkSnark.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475"),
x2: zkSnark.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
y2: zkSnark.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")
x1: snarkjs.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
y1: snarkjs.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475"),
x2: snarkjs.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
y2: snarkjs.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")
}
const w = circuit.calculateWitness(input);
@@ -61,8 +61,8 @@ describe("Baby Jub test", () => {
const xout = w[circuit.getSignalIdx("main.xout")];
const yout = w[circuit.getSignalIdx("main.yout")];
assert(xout.equals(zkSnark.bigInt("6890855772600357754907169075114257697580319025794532037257385534741338397365")));
assert(yout.equals(zkSnark.bigInt("4338620300185947561074059802482547481416142213883829469920100239455078257889")));
assert(xout.equals(snarkjs.bigInt("6890855772600357754907169075114257697580319025794532037257385534741338397365")));
assert(yout.equals(snarkjs.bigInt("4338620300185947561074059802482547481416142213883829469920100239455078257889")));
});
it("Should add 2 different numbers", async () => {
@@ -73,15 +73,15 @@ describe("Baby Jub test", () => {
// assert.equal(cirDef.nVars, 2);
const circuit = new zkSnark.Circuit(cirDef);
const circuit = new snarkjs.Circuit(cirDef);
console.log("NConstrains: " + circuit.nConstraints);
const input={
x1: zkSnark.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
y1: zkSnark.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475"),
x2: zkSnark.bigInt("16540640123574156134436876038791482806971768689494387082833631921987005038935"),
y2: zkSnark.bigInt("20819045374670962167435360035096875258406992893633759881276124905556507972311")
x1: snarkjs.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
y1: snarkjs.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475"),
x2: snarkjs.bigInt("16540640123574156134436876038791482806971768689494387082833631921987005038935"),
y2: snarkjs.bigInt("20819045374670962167435360035096875258406992893633759881276124905556507972311")
}
const w = circuit.calculateWitness(input);
@@ -92,7 +92,7 @@ describe("Baby Jub test", () => {
console.log(xout.toString());
console.log(yout.toString());
assert(xout.equals(zkSnark.bigInt("7916061937171219682591368294088513039687205273691143098332585753343424131937")));
assert(yout.equals(zkSnark.bigInt("14035240266687799601661095864649209771790948434046947201833777492504781204499")));
assert(xout.equals(snarkjs.bigInt("7916061937171219682591368294088513039687205273691143098332585753343424131937")));
assert(yout.equals(snarkjs.bigInt("14035240266687799601661095864649209771790948434046947201833777492504781204499")));
});
});

View File

@@ -0,0 +1,26 @@
include "../../circuit/escalarmul.circom";
template Main() {
signal input in[256];
signal output out[2];
var i;
var base = [17777552123799933955779906779655732241715742912184938656739573121738514868268,
2626589144620713026669568689430873010625803728049924121243784502389097019475]
component escalarMul = EscalarMul(256, base);
escalarMul.inp[0] <== 0;
escalarMul.inp[1] <== 1;
for (i=0; i<256; i++) {
in[i] ==> escalarMul.in[i];
}
escalarMul.out[0] ==> out[0];
escalarMul.out[1] ==> out[1];
}
component main = Main();

View File

@@ -0,0 +1,31 @@
include "../../circuit/escalarmul.circom";
include "../../node_modules/circom/circuits/bitify.circom";
template Main() {
signal input in;
signal output out[2];
var base = [17777552123799933955779906779655732241715742912184938656739573121738514868268,
2626589144620713026669568689430873010625803728049924121243784502389097019475]
component n2b = Num2Bits(253);
component escalarMul = EscalarMul(253, base);
escalarMul.inp[0] <== 0;
escalarMul.inp[1] <== 1;
var i;
in ==> n2b.in;
for (i=0; i<253; i++) {
n2b.out[i] ==> escalarMul.in[i];
}
escalarMul.out[0] ==> out[0];
escalarMul.out[1] ==> out[1];
}
component main = Main();

View File

@@ -0,0 +1,26 @@
include "../../circuit/escalarmul.circom";
template Main() {
signal input in[256];
signal output out[2];
var i;
var base = [17777552123799933955779906779655732241715742912184938656739573121738514868268,
2626589144620713026669568689430873010625803728049924121243784502389097019475]
component escalarMul = EscalarMul(256, base);
escalarMul.inp[0] <== 0;
escalarMul.inp[1] <== 1;
for (i=0; i<256; i++) {
in[i] ==> escalarMul.in[i];
}
escalarMul.out[0] ==> out[0];
escalarMul.out[1] ==> out[1];
}
component main = Main();

View File

@@ -0,0 +1,6 @@
include "../../circuit/escalarmulw4table.circom";
var base = [17777552123799933955779906779655732241715742912184938656739573121738514868268,
2626589144620713026669568689430873010625803728049924121243784502389097019475]
component main = EscalarMulW4Table(base, 0);

View File

@@ -0,0 +1,6 @@
include "../../circuit/escalarmulw4table.circom";
var base = [17777552123799933955779906779655732241715742912184938656739573121738514868268,
2626589144620713026669568689430873010625803728049924121243784502389097019475];
component main = EscalarMulW4Table(base, 0);

View File

@@ -0,0 +1,6 @@
include "../../circuit/escalarmulw4table.circom";
var base = [17777552123799933955779906779655732241715742912184938656739573121738514868268,
2626589144620713026669568689430873010625803728049924121243784502389097019475]
component main = EscalarMulW4Table(base, 3);

View File

@@ -1,4 +1,4 @@
include "../../circuit/exp.circom";
include "../../circuit/escalarmul.circom";
include "../../node_modules/circom/circuits/sha256/bitify.circom";
@@ -7,18 +7,18 @@ template Main() {
signal output out[2];
component n2b = Num2Bits(253);
component exp = Exp(253);
component escalarMul = EscalarMul(253);
var i;
in ==> n2b.in;
for (i=0; i<253; i++) {
n2b.out[i] ==> exp.in[i];
n2b.out[i] ==> escalarMul.in[i];
}
exp.out[0] ==> out[0];
exp.out[1] ==> out[1];
escalarMul.out[0] ==> out[0];
escalarMul.out[1] ==> out[1];
}
component main = Main();

View File

@@ -1,4 +1,4 @@
include "../../circuit/exp.circom";
include "../../circuit/escalarmul.circom";
template Main() {
@@ -7,14 +7,14 @@ template Main() {
var i;
component exp = Exp(256);
component escalarMul = EscalarMul(256);
for (i=0; i<256; i++) {
in[i] ==> exp.in[i];
in[i] ==> escalarMul.in[i];
}
exp.out[0] ==> out[0];
exp.out[1] ==> out[1];
escalarMul.out[0] ==> out[0];
escalarMul.out[1] ==> out[1];
}
component main = Main();

View File

@@ -1,3 +0,0 @@
include "../../circuit/ExpW4Table.circom";
component main = ExpW4Table(0);

View File

@@ -1,3 +0,0 @@
include "../../circuit/ExpW4Table.circom";
component main = ExpW4Table(3);

View File

@@ -1,5 +1,5 @@
include "../../circuit/mux4.circom";
include "../../node_modules/circom/circuits/sha256/bitify.circom";
include "../../node_modules/circom/circuits/bitify.circom";
template Constants() {

View File

@@ -1,6 +1,6 @@
const chai = require("chai");
const path = require("path");
const zkSnark = require("zksnark");
const snarkjs = require("snarkjs");
const compiler = require("circom");
const assert = chai.assert;
@@ -26,22 +26,22 @@ function print(circuit, w, s) {
describe("Exponentioation test", () => {
it("Should generate the Exponentiation table in k=0", async () => {
const cirDef = await compiler(path.join(__dirname, "circuits", "expw4table_test.circom"));
const cirDef = await compiler(path.join(__dirname, "circuits", "escalarmulw4table_test.circom"));
// console.log(JSON.stringify(cirDef, null, 1));
// assert.equal(cirDef.nVars, 2);
const circuit = new zkSnark.Circuit(cirDef);
const circuit = new snarkjs.Circuit(cirDef);
console.log("NConstrains: " + circuit.nConstraints);
const w = circuit.calculateWitness({});
let g = [zkSnark.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
zkSnark.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")]
let g = [snarkjs.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
snarkjs.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")]
dbl= [zkSnark.bigInt("0"), zkSnark.bigInt("1")];
dbl= [snarkjs.bigInt("0"), snarkjs.bigInt("1")];
for (let i=0; i<16; i++) {
const xout1 = w[circuit.getSignalIdx(`main.out[${i}][0]`)];
@@ -62,26 +62,26 @@ describe("Exponentioation test", () => {
it("Should generate the Exponentiation table in k=3", async () => {
const cirDef = await compiler(path.join(__dirname, "circuits", "expw4table_test3.circom"));
const cirDef = await compiler(path.join(__dirname, "circuits", "escalarmulw4table_test3.circom"));
// console.log(JSON.stringify(cirDef, null, 1));
// assert.equal(cirDef.nVars, 2);
const circuit = new zkSnark.Circuit(cirDef);
const circuit = new snarkjs.Circuit(cirDef);
console.log("NConstrains: " + circuit.nConstraints);
const w = circuit.calculateWitness({});
let g = [zkSnark.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
zkSnark.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")]
let g = [snarkjs.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
snarkjs.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")]
for (let i=0; i<12;i++) {
g = addPoint(g,g);
}
dbl= [zkSnark.bigInt("0"), zkSnark.bigInt("1")];
dbl= [snarkjs.bigInt("0"), snarkjs.bigInt("1")];
for (let i=0; i<16; i++) {
const xout1 = w[circuit.getSignalIdx(`main.out[${i}][0]`)];
@@ -102,13 +102,13 @@ describe("Exponentioation test", () => {
});
it("Should exponentiate g^31", async () => {
const cirDef = await compiler(path.join(__dirname, "circuits", "exp_test.circom"));
const cirDef = await compiler(path.join(__dirname, "circuits", "escalarmul_test.circom"));
// console.log(JSON.stringify(cirDef, null, 1));
// assert.equal(cirDef.nVars, 2);
const circuit = new zkSnark.Circuit(cirDef);
const circuit = new snarkjs.Circuit(cirDef);
console.log("NConstrains: " + circuit.nConstraints);
@@ -116,8 +116,8 @@ describe("Exponentioation test", () => {
assert(circuit.checkWitness(w));
let g = [zkSnark.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
zkSnark.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")]
let g = [snarkjs.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
snarkjs.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")]
let c = [0n, 1n];
@@ -158,9 +158,9 @@ describe("Exponentioation test", () => {
}).timeout(10000000);
it("Number of constrains for 256 bits", async () => {
const cirDef = await compiler(path.join(__dirname, "circuits", "exp_test_min.circom"));
const cirDef = await compiler(path.join(__dirname, "circuits", "escalarmul_test_min.circom"));
const circuit = new zkSnark.Circuit(cirDef);
const circuit = new snarkjs.Circuit(cirDef);
console.log("NConstrains: " + circuit.nConstraints);
}).timeout(10000000);

View File

@@ -1,6 +1,6 @@
const chai = require("chai");
const path = require("path");
const zkSnark = require("zksnark");
const snarkjs = require("snarkjs");
const compiler = require("circom");
const assert = chai.assert;
@@ -17,17 +17,17 @@ describe("Mux4 test", () => {
// assert.equal(cirDef.nVars, 2);
const circuit = new zkSnark.Circuit(cirDef);
const circuit = new snarkjs.Circuit(cirDef);
console.log("NConstrains: " + circuit.nConstraints);
for (i=0; i<16; i++) {
const w = circuit.calculateWitness({ "selector": zkSnark.bigInt(i).toString() });
const w = circuit.calculateWitness({ "selector": snarkjs.bigInt(i).toString() });
assert(w[0].equals(zkSnark.bigInt(1)));
assert(w[0].equals(snarkjs.bigInt(1)));
console.log(i + " -> " + w[circuit.getSignalIdx("main.out")].toString());
// assert(w[circuit.getSignalIdx("main.out")].equals(zkSnark.bigInt("100").add(zkSnark.bigInt(i))));
// assert(w[circuit.getSignalIdx("main.out")].equals(snarkjs.bigInt("100").add(snarkjs.bigInt(i))));
}
});
});