These 50 commits are when the Protocol Buffers files have changed:
| Commit: | 1387cb7 | |
|---|---|---|
| Author: | ycen | |
eddsa/resharing: give the new committee something of its own to check round 1 against The ECDSA half of this got the session binding earlier; the EdDSA half did not, and it is the half where the whole package consumes no session value at all. A complete old->new transcript recorded in one execution was accepted by a different execution's new committee: every new party completed and persisted shares byte-equal to the recorded run's, in a session whose own nonce differed and in which no old-committee party existed. Nothing in the package could have caught it. There was no ssid to compare, and adding a unanimity check alone would not have been enough either -- unanimity compares the old committee's declarations only to EACH OTHER, so a recorded transcript agrees with itself. Nor can the new committee recompute the ssid: the pre-image of getSSID is the OLD committee's save data, which a new party does not hold. So DGRound1Message gains ssid and session_nonce_hash, mirroring the ECDSA message field for field. The old committee derives the ssid (curve, roster, BigXj, round, nonce -- eddsa/keygen's shape plus BigXj, so two re-shares of two different keys never collide) and declares SHA512_256 of the agreed nonce. Each new party compares that hash against its OWN Parameters before it adopts anything and before it ACKs. It is a hash rather than the nonce so the wire does not hand a passive observer the identifier of a session it is not in. ValidateBasic requires the field: an absent hash is exactly what a transcript recorded before the field existed carries, and it must not be laundered into "nothing to compare". The nonce requirement is stated once, before the role split in round 1, for both roles -- the old committee needs it to derive the ssid, the new committee needs it to check what the old committee declares -- so a party lacking it fails having exchanged nothing rather than after a full round. Attribution follows the ECDSA rule: a fault visible in a single message names its sender; a disagreement BETWEEN messages names nobody, because slot 0 is the array's first element and not a witness, and n_old = t+1 is a legal committee in which the tolerated corrupt parties are a strict majority. SCOPE, stated in the code too: this makes a transcript non-portable between sessions for a peer that cannot rewrite bytes. It does NOT authenticate the sender. Transport authentication remains the host's job, as for the rest of the protocol. BREAKING: EdDSA re-sharing round-1 messages carry two new required-ish fields, so old and new builds cannot re-share with each other, and every party must now have a session nonce set before Start(). Also regenerates ecdsa-resharing.pb.go with protoc-gen-go v1.36.11, which is what generated the other seven .pb.go files in the tree; an earlier commit had regenerated that one alone with a v1.28.0 binary. And replaces the five re-sharing line-number locators in doc/maintenance-invariants.md with declaration references: three of the five had already gone stale, one of them before this change. Tests cover the recorded-transcript rejection, its own-session negative control, the split committee, the empty declaration and the missing nonce. Full suite green. Co-Authored-By: Claude Code <noreply@anthropic.com>
| Commit: | b73eea7 | |
|---|---|---|
| Author: | ycen | |
resharing, signing: bind each execution's own session nonce into what receivers check Two places where a value that identifies the execution was believed to separate two runs and did not. Both were measured, not inferred; both fixes change bytes on the wire or the SSID value, which this v4 branch already accepts. RE-SHARING. A complete old->new transcript captured from one execution was accepted by a different execution's new committee: all its parties completed and persisted shares byte-equal to the captured run's, in a session whose own nonce was different and in which no old-committee party existed. The unanimity check added earlier does not reach this, and cannot: it compares the old committee's ssid declarations only to EACH OTHER, so a transcript is unanimous with itself. Nor can the new committee recompute the ssid to compare -- its pre-image is the OLD committee's save data, which a new party does not hold, and that was confirmed by calling the production getSSID() on the new side and watching it fail on an all-nil BigXj. So DGRound1Message gains a session_nonce_hash, the old committee declares SHA512_256 of the agreed nonce, and each new party compares it against its OWN Parameters before anything is adopted. It is a hash rather than the nonce so the wire does not hand a passive observer the identifier of a session it is not in. ValidateBasic requires the field: an absent hash is exactly what a pre-existing transcript carries, and it must not be laundered into "nothing to compare". SCOPE, stated in the code as well: this makes a transcript non-portable between sessions for a peer that cannot forge messages. It does NOT authenticate the sender. Nothing here signs or MACs a message, so an adversary who can rewrite arbitrary bytes can substitute the expected hash and splice the rest of a captured transcript. Transport authentication remains the host's job, as it is for the rest of the protocol. SIGNING. fullBytesLen decides what is actually signed -- fixed-width FillBytes when set, m.Bytes() when not -- but the SSID pre-image hashes magnitudes only, so two executions differing ONLY in fullBytesLen shared an SSID while binding different byte strings. Measured on ed25519, where the two runs' signatures do not cross-verify; on secp256k1 both encodings reduce to the same integer, so the value signed is unchanged there and only the recorded data.M differs. Under the shared SSID a range proof and a commitment/Schnorr pair minted in one run were accepted by the other run's production verifiers, on both curves. fullBytesLen is now part of the pre-image on both curves. It is also a per-party argument that no message carries and nothing compares, so binding it here is what makes a disagreement observable at all. Tests cover both directions. Full suite green. Co-Authored-By: Claude Code <noreply@anthropic.com>
| Commit: | 61d2e85 | |
|---|---|---|
| Author: | ycen | |
docs: say what the NTilde ModProof attests, and cite gates by declaration Two corrections to comments across ECDSA keygen and re-sharing. Comment-only: no verifier's decision changes and no wire format changes. What the proof attests. ProofMod.Verify(Session, N) takes the modulus as its only statement input, so it can attest properties of N alone. Comments that described it as establishing safe-primality of NTilde's factors claimed more than that signature can deliver -- the factors never enter Verify, only their product does -- and it constrains neither h1 nor h2. What establishes <h1> == <h2> for a peer's ring is the two-directional DLN proof pair, verified in round 4. The comments now name that gate instead of the wrong one. How gates are cited. References that pointed at a file and a line number went stale as soon as an unrelated edit shifted the file: a comment-only change to one file invalidated seven such references elsewhere, generated mirrors included. Every one of them now cites the declaration (path#Decl) rather than a line number, so it survives edits above the target. Two costs are worth recording. A drift probe was run and did not separate the two reference forms at the window size chosen, so this commit does not claim symbolic references are measurably more drift-resistant -- only that the failure mode observed here cannot occur. And a declaration reference spans the whole declaration, so "off by N lines" is no longer expressible, and therefore no longer detectable either. Generated files are byte-identical apart from the comment text. Co-Authored-By: Claude Code <noreply@anthropic.com>
| Commit: | 726937a | |
|---|---|---|
| Author: | ycen | |
fix: bind resharing peer NTilde to ModProof ECDSA resharing was the last ⚠️ P1 item in the ZKP audit. Keygen already linked peer NTilde to a Blum-integer ModProof in `6ba5e0d` (via `KGRound2Message2.nTildeModProof`, verified in ecdsa/keygen/round_3.go before NTildej is saved). Resharing didn't carry the same binding: `DGRound2Message1` shipped Paillier ModProof + NTilde + H1 + H2 + two DLN proofs, and round_4_new_step_2 saved NTildej / H1j / H2j after the Paillier and DLN checks — leaving NTilde itself only "locally plausible" rather than proven to be the safe-prime product the QR-group argument assumes. This commit mirrors the keygen pattern in resharing: - protob/ecdsa-resharing.proto: `DGRound2Message1` gains a `repeated bytes nTildeModProof = 8` field. Optional on the wire so v3-vintage peers that omit it can be accepted under `params.NoProofMod()`; v4 default mode (the production setting in this branch's e2e test, see `0f67b50` removing the resharing SetNoProofMod) requires the proof. - ecdsa/resharing/messages.go: `NewDGRound2Message1` takes the new `nTildeModProof` argument; `UnmarshalNTildeModProof` mirrors the keygen helper. - ecdsa/resharing/round_2_new_step_1.go: generate the proof alongside the Paillier ModProof, using the safe-prime factors derived from `LocalPreParams.P/Q` (same fix shape as keygen's `6ba5e0d`). - ecdsa/resharing/round_4_new_step_2.go: verify the proof in the same goroutine as the Paillier ModProof, attributing failures to the peer via `paiProofCulprits`. Honors `NoProofMod()` for v3 backward compatibility. Other regenerated `.pb.go` diffs in the commit are protoc-tooling churn from `make protob` rebuilding all protos; no semantic changes to other messages. Full e2e ecdsa/resharing and eddsa/resharing suites still pass. Closes the last ⚠️ P1 row in `_local_only/ZKP_BASIC_PROPERTY_AUDIT.md`. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
| Commit: | 5946f07 | |
|---|---|---|
| Author: | ycen | |
fix: prove NTilde structure during keygen (SRC-2026-754 / #11) Add a ModProof for each party's own NTilde to KGRound2Message2 so the receiver can verify that NTilde is a Blum-integer product of safe primes — closing the smooth-subgroup NTilde injection path that the existing 2048-bit bit-length check cannot detect. - protob/ecdsa-keygen.proto: new repeated bytes field `nTildeModProof` on KGRound2Message2 (proto field 3). - ecdsa/keygen/round_2.go: each peer creates a second ModProof using LocalPreParams.{P, Q} (the safe primes of NTilde, NOT the Paillier SK primes) and includes it in the round-2 broadcast. - ecdsa/keygen/round_3.go: verify the NTildeModProof against round.save.NTildej[j]. Backward compatible — peers shipping an empty NTildeModProof are accepted under the existing NoProofMod() compatibility branch with a warning log, matching the Paillier-N ModProof's compatibility handling. - ecdsa/keygen/messages.go: NewKGRound2Message2 takes the new proof and writes it into the wire field; adds UnmarshalNTildeModProof. Resharing path is unaffected (NTilde comes from the existing keygen save data); the smooth-N concern there is mitigated by the resharing round_4 bit-length gate added in B21. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
| Commit: | 1a14f3a | |
|---|---|---|
| Author: | ZhAnGeek | |
| Committer: | GitHub | |
Ecdsa proof session byte (#256) * Add modProof in ECDSA-keygen * Reduce test param to reduce github workflow load * Add test fixtures * Fix EDDSA keygen example * Restore test fixtures * Compress modproof * use warning instead of fatal in logger to prevent panic * Add more checks in range proof * Regenerate preparams for older version * Reset test params and regenerate fixtures * Update ecdsa-resharing with Paillier key proofs * Add a switch to optional turn off Pai key proofs * Update README for caution of preparams updated * add: ecdsa proof session byte --------- Co-authored-by: ycen <yycen@live.com> Co-authored-by: ZhAnGeek <lecky.z@nodereal.io>
The documentation is generated from this commit.
| Commit: | 1f7785a | |
|---|---|---|
| Author: | ycen | |
Update ecdsa-resharing with Paillier key proofs
| Commit: | 4a3428b | |
|---|---|---|
| Author: | ycen | |
Add modProof in ECDSA-keygen
| Commit: | 3d95e54 | |
|---|---|---|
| Author: | ycen | |
| Committer: | GitHub | |
ECDSA protocol security updates (#252) * ECDSA protocol security updates * Update proofs.go * Limit y in Mta in range and prove * Add checks in proofFac * Add checks in MtA * Remove unnecessary assignments * Update unbiased reject sample * Make compatible for old parties with no facProof * Revert "Make compatible for old parties with no facProof" This reverts commit 4c9fa888180256f77380b4b49eebaa403dd783df. * Revised compatible for old parties with no facProof * Update facProof condition test * Allow empty proofFac, roll back rejectSample for compatibility --------- Co-authored-by: Wan Ziyi <40668033+Derrick-Wan@users.noreply.github.com>
| Commit: | 7308ecd | |
|---|---|---|
| Author: | ycen | |
Revert "Make compatible for old parties with no facProof" This reverts commit 4c9fa888180256f77380b4b49eebaa403dd783df.
| Commit: | 4c9fa88 | |
|---|---|---|
| Author: | ycen | |
Make compatible for old parties with no facProof
| Commit: | b19124e | |
|---|---|---|
| Author: | ycen | |
| Committer: | ycen | |
ECDSA protocol security updates
| Commit: | b1c4838 | |
|---|---|---|
| Author: | ycen | |
Add chaincode negoation in ecdsa-keygen
| Commit: | 76a51ee | |
|---|---|---|
| Author: | ycen | |
Add dlnp proof into internal-mobile-wrapper
| Commit: | dc233a9 | |
|---|---|---|
| Author: | Plamen Hristov | |
Fixed bad signature.proto
| Commit: | 05b0624 | |
|---|---|---|
| Author: | Plamen Hristov | |
Updated Google protobuf dependency and fixed type clash
| Commit: | 1aa0a75 | |
|---|---|---|
| Author: | Fitz | |
| Committer: | FitzLu | |
cherry pick > curve as parameter (#137) * move curve into tss.Parameters * regen proto with full package name * pass curve through parameter * add curve name in ecpoint json serialization
| Commit: | 856d77b | |
|---|---|---|
| Author: | Fitz | |
| Committer: | GitHub | |
Curve as parameter (#137) * move curve into tss.Parameters * regen proto with full package name * pass curve through parameter * add curve name in ecpoint json serialization
| Commit: | 78830ed | |
|---|---|---|
| Author: | FitzLu | |
regen proto with full package name
| Commit: | ed6f648 | |
|---|---|---|
| Author: | froyobin | |
| Committer: | GitHub | |
remove unused paillier sk and avoid sender choosing h_1,h_2,Ntilde (#129) * remove unused paillier sk and fix the error in choosing h_1,h_2,Ntilde * remove the witness in keysign as the verifier only trust its own Ntilde,h1,h2 Co-authored-by: Ford Betelgeuse <ford.betelgeusedent@gmail.com>
| Commit: | aa7164a | |
|---|---|---|
| Author: | ackratos | |
| Committer: | ackratos | |
fix things for binance tss product
| Commit: | f896de9 | |
|---|---|---|
| Author: | Ford Betelgeuse | |
| Committer: | Ford Betelgeuse | |
thorchain gg20
| Commit: | 9d8889d | |
|---|---|---|
| Author: | cong | |
| Committer: | GitHub | |
Internal mobile wrapper eddsa (#124) * [R4R] Add eddsa (#88) * [R4R] Add eddsa keygen and signing (#3) * add eddsa signing and keygen * contruct extended element from x,y * update dep * fix test * fix bug * delete unused code * add resharing * fix comments * refactor RejectionSampl;e * rename variable (#4) * delete printf * update dependency * resolve conflict * Update readme about EdDSA (#91) * update readme about eddsa * minor fix * S in eddsa signature is not encoded correctly * fix msg in eddsa hasn't to be a int. * fix unit test * register DGRound4Message for eddsa resharing (#99) Co-authored-by: yutianwu <wzxingbupt@gmail.com> Co-authored-by: dylenfu <dylenfu@126.com>
| Commit: | 6b19c75 | |
|---|---|---|
| Author: | yutianwu | |
| Committer: | ackratos | |
[R4R] Add eddsa (#88) * [R4R] Add eddsa keygen and signing (#3) * add eddsa signing and keygen * contruct extended element from x,y * update dep * fix test * fix bug * delete unused code * add resharing * fix comments * refactor RejectionSampl;e * rename variable (#4) * delete printf * update dependency * resolve conflict
| Commit: | b2335ba | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
ecdsa/signing: implement 'type 5' identified abort (blame)
| Commit: | 3e35a67 | |
|---|---|---|
| Author: | Luke Plaster | |
protob/eddsa-resharing: minor fix for eddsa protobuf name when regenerated
| Commit: | 232b11e | |
|---|---|---|
| Author: | Luke Plaster | |
ecdsa/signing: simplify, use rSigmaI in FinalizeGetOurSigShare
| Commit: | 90a8736 | |
|---|---|---|
| Author: | Luke Plaster | |
eddsa/signing: add identifable abort for phase 7
| Commit: | f380443 | |
|---|---|---|
| Author: | Luke Plaster | |
ecdsa/signing: add the one-round signing API
| Commit: | e03efd4 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
ecdsa/signing: populate and save the one-round state struct
| Commit: | 4d92512 | |
|---|---|---|
| Author: | Luke Plaster | |
ecdsa/signing: implement round 5 ZKP of consistency between Rdash_i and E_i(k_i) ported from the kzen impl: https://git.io/Jf69a
| Commit: | b88bfac | |
|---|---|---|
| Author: | Luke Plaster | |
ecdsa/signing: implement the remaining rounds for gg20
| Commit: | 51932c3 | |
|---|---|---|
| Author: | Luke Plaster | |
ecdsa/signing: implement gg20 round 3
| Commit: | 7ddac3f | |
|---|---|---|
| Author: | Luke Plaster | |
protob: update message defs for gg20
| Commit: | aad9998 | |
|---|---|---|
| Author: | Luke Plaster | |
ecdsa/signing: rename 'theta' to 'delta' for correctness
| Commit: | da6040f | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
protob: fix go package of signature protobuf source
| Commit: | abd66f8 | |
|---|---|---|
| Author: | yutianwu | |
| Committer: | GitHub | |
[R4R] Add eddsa (#88) * [R4R] Add eddsa keygen and signing (#3) * add eddsa signing and keygen * contruct extended element from x,y * update dep * fix test * fix bug * delete unused code * add resharing * fix comments * refactor RejectionSampl;e * rename variable (#4) * delete printf * update dependency * resolve conflict
| Commit: | 769ccf7 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
[security] ecdsa: add proof of discrete log to prove that the two elements h_1, h_2 generate the same group mod N
| Commit: | 1e5e2dd | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | GitHub | |
[security] resharing: wait for final acks from the new committee before ending (#75) This is the fix for a vulnerability reported by Omer Shlomovits of KZen Networks (ZenGo). It adds a final ack round to the re-sharing protocol where the new committee sends acks to members of both the old and new committees before they save any data to disk. Other Changes: * readme: mention the UpdateFromBytes bool arg changes, misc edits * resharing: edit a comment in round 4 * remove the confusing to committee bools * resharing: remove a redundant line in round 5
| Commit: | 570cd35 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
protob: add copyright headers
| Commit: | 641f146 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
add SignatureData protobuf message to replace LocalSignData and use it in the mobile interface
| Commit: | 69b9de0 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
docs: add comments about PartyIDs
| Commit: | c6f5674 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
protobuf: refactored message structure to include routing data in a wrapper message for mobile apps
| Commit: | e761090 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | GitHub | |
resharing: remove unused big-X_j data/commitments (#66) * ecdsa/resharing: remove unused big-X_j data/commitments fixes #60
| Commit: | 2629d2e | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
ecdsa/regroup: rename to resharing
| Commit: | bfd8c29 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
protob: improve messaging interfaces to abstract away protobufs
| Commit: | 6ece436 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
protob: WIP wire message format
| Commit: | d4d8eb1 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
protob: WIP protobuf conversion - working signing and regroup
| Commit: | 752ea52 | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
protob: WIP protobuf conversion
| Commit: | bcd330f | |
|---|---|---|
| Author: | Luke Plaster | |
| Committer: | Luke Plaster | |
protob: add initial protobuf defs