Skip to content
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ pg-curve = { version = "0.2.0", features = [
subtle = { version = "2.4.1", default-features = false }
tiny-keccak = { version = "2.0.2", features = ["sha3", "shake"] }
aes-gcm = { version = "0.10", optional = true }
zeroize = { version = "1.7", default-features = false, features = ["derive"], optional = true }

[target.wasm32-unknown-unknown.dependencies]
getrandom = { version = "0.2", features = ["js"] }
Expand All @@ -42,6 +43,7 @@ kv1 = []
waters = []
waters_naccache = []
mkem = ["aes-gcm"]
zeroize = ["dep:zeroize", "pg-curve/zeroize"]

[lib]
bench = false
Expand Down
2 changes: 2 additions & 0 deletions src/ibe/boyen_waters.rs
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@ pub struct PublicKey {

/// Secret key parameter generated by the PKG used to extract user secret keys.
#[derive(Debug, Clone, Copy, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct SecretKey {
alpha: Scalar,
t1: Scalar,
Expand All @@ -60,6 +61,7 @@ pub struct SecretKey {

/// Points on the paired curves that form the user secret key.
#[derive(Debug, Clone, Copy, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
Comment thread
dobby-coder[bot] marked this conversation as resolved.
pub struct UserSecretKey {
d: [G2Affine; 5],
}
Expand Down
2 changes: 2 additions & 0 deletions src/ibe/cgw.rs
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@ pub struct PublicKey {
/// Secret key parameter generated by the PKG used to extract user secret keys.
/// Also known as MSK.
#[derive(Debug, Clone, Copy, Eq, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct SecretKey {
b: [Scalar; 2],
k: [Scalar; 2],
Expand All @@ -59,6 +60,7 @@ pub struct SecretKey {
/// User secret key. Can be used to decrypt the corresponding ciphertext.
/// Also known as USK_{id}.
#[derive(Debug, Clone, Copy, Eq, PartialEq, Default)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct UserSecretKey {
d0: [G2Affine; 2],
d1: [G2Affine; 2],
Expand Down
2 changes: 2 additions & 0 deletions src/ibe/waters.rs
Original file line number Diff line number Diff line change
Expand Up @@ -49,12 +49,14 @@ pub struct PublicKey {

/// Secret key parameter generated by the PKG used to extract user secret keys.
#[derive(Debug, Clone, Copy, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct SecretKey {
g1prime: G1Affine,
}

/// Points on the paired curves that form the user secret key.
#[derive(Debug, Clone, Copy, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct UserSecretKey {
d1: G1Affine,
d2: G2Affine,
Expand Down
2 changes: 2 additions & 0 deletions src/ibe/waters_naccache.rs
Original file line number Diff line number Diff line change
Expand Up @@ -59,12 +59,14 @@ pub struct Identity([Scalar; CHUNKS]);

/// Secret key parameter generated by the PKG used to extract user secret keys.
#[derive(Clone, Copy, Debug, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct SecretKey {
g2prime: G2Affine,
}

/// Points on the paired curves that form the user secret key.
#[derive(Clone, Copy, Debug, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct UserSecretKey {
d1: G2Affine,
d2: G1Affine,
Expand Down
1 change: 1 addition & 0 deletions src/kem/cgw_fo.rs
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@ pub const USK_BYTES: usize = CPA_USK_BYTES + ID_BYTES;
/// User secret key. Can be used to decaps the corresponding ciphertext.
/// Also known as USK_{id}.
#[derive(Debug, Clone, Copy, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct UserSecretKey {
usk: crate::ibe::cgw::UserSecretKey,
id: Identity,
Expand Down
35 changes: 35 additions & 0 deletions src/kem/cgw_kv.rs
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,7 @@ pub struct PublicKey {
/// Secret key parameter generated by the PKG used to extract user secret keys.
/// Also known as MSK.
#[derive(Debug, Clone, Copy, Eq, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct SecretKey {
b: [Scalar; 2],
k: [Scalar; 2],
Expand All @@ -59,6 +60,7 @@ pub struct SecretKey {
/// User secret key. Can be used to decaps the corresponding ciphertext.
/// Also known as USK_{id}.
#[derive(Debug, Clone, Copy, Eq, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct UserSecretKey {
d0: [G2Affine; 2],
d1: [G2Affine; 2],
Expand Down Expand Up @@ -516,4 +518,37 @@ mod tests {

#[cfg(feature = "mkem")]
test_multi_kem!(CGWKV);

#[cfg(feature = "zeroize")]
#[test]
fn secret_types_zeroize() {
use zeroize::Zeroize;
let mut rng = rand::thread_rng();
let id = <CGWKV as IBKEM>::Id::derive_str("alice@example.com");
let (pk, mut sk) = CGWKV::setup(&mut rng);
let mut usk = CGWKV::extract_usk(Some(&pk), &sk, &id, &mut rng);
let (_ct, mut ss) = CGWKV::encaps(&pk, &id, &mut rng);

// Snapshot serialized form so we can assert zeroization actually blanks it.
let sk_bytes_before = sk.to_bytes();
let usk_bytes_before = usk.to_bytes();
let ss_bytes_before = ss.0;

sk.zeroize();
usk.zeroize();
ss.zeroize();

assert_ne!(sk.to_bytes(), sk_bytes_before, "SecretKey did not zeroize");
assert_ne!(
usk.to_bytes(),
usk_bytes_before,
"UserSecretKey did not zeroize"
);
assert_ne!(ss.0, ss_bytes_before, "SharedSecret did not zeroize");
assert_eq!(
ss.0,
[0u8; crate::kem::SS_BYTES],
"SharedSecret bytes should be zero"
);
}
}
2 changes: 2 additions & 0 deletions src/kem/kiltz_vahlis_one.rs
Original file line number Diff line number Diff line change
Expand Up @@ -45,12 +45,14 @@ pub struct PublicKey {

/// Secret key parameter generated by the PKG used to extract user secret keys.
#[derive(Debug, Clone, Copy, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct SecretKey {
alpha: G1Affine,
}

/// Points on the paired curves that form the user secret key.
#[derive(Debug, Clone, Copy, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct UserSecretKey {
d1: G1Affine,
d2: G2Affine,
Expand Down
1 change: 1 addition & 0 deletions src/kem/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ pub const SS_BYTES: usize = 32;
/// This shared secret has roughly a 127 bits of security.
/// This is due to the fact that BLS12-381 targets this security level (optimistically).
#[derive(Clone, Copy, Debug, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct SharedSecret(pub [u8; SS_BYTES]);

/// Uses SHAKE256 to derive a 32-byte shared secret from a target group element.
Expand Down
1 change: 1 addition & 0 deletions src/util.rs
Original file line number Diff line number Diff line change
Expand Up @@ -99,6 +99,7 @@ pub fn rpc<Gr: UncompressedEncoding>(k: &[u8; 32], gs: &[Gr]) -> Scalar {
///
/// This identity is obtained by hashing using sha3_512.
#[derive(Copy, Clone, Debug, PartialEq)]
#[cfg_attr(feature = "zeroize", derive(zeroize::Zeroize))]
pub struct Identity(pub [u8; ID_BYTES]);

impl Default for Identity {
Expand Down
Loading