pub struct ProverState<H = StdHash, R = StdRng>{
pub duplex_sponge_state: H,
/* private fields */
}Expand description
ProverState is the prover state in the non-interactive transformation.
It provides the secret coins of the prover for zero-knowledge, and the hash function state for the verifier’s public coins.
The internal random number generator is instantiated with sha3::Shake128,
seeded via rand::rngs::StdRng.
§Safety
Leaking ProverState is equivalent to leaking the prover’s private coins, and therefore zero-knowledge.
ProverState does not implement Clone or Copy to prevent accidental state-restoration attacks.
Fields§
§duplex_sponge_state: HThe public coins for the protocol.
§Safety
Copying this object will break the soundness guarantees installed at the ProverState level.
Implementations§
Source§impl<H, R> ProverState<H, R>
impl<H, R> ProverState<H, R>
Sourcepub const fn rng(&mut self) -> &mut ReseedableRng<R>
pub const fn rng(&mut self) -> &mut ReseedableRng<R>
Returns the reseedable RNG bound to this transcript.
Sourcepub const fn narg_string(&self) -> &[u8] ⓘ
pub const fn narg_string(&self) -> &[u8] ⓘ
Returns the current serialized NARG string.
Sourcepub fn public_message<T: Encoding<[H::U]> + ?Sized>(&mut self, message: &T)
pub fn public_message<T: Encoding<[H::U]> + ?Sized>(&mut self, message: &T)
Input a public message to the Fiat–Shamir transformation.
A public message in this context is a message that is shared among prover and verifier outside of the NARG, and is to be included in the Fiat–Shamir transformation but not in the final NARG string.
use spongefish::ProverState;
let mut prover_state = spongefish::domain_separator!("examples"; "ProverState::public_message")
.instance(&0u32)
.std_prover();
prover_state.public_message(&123u32);
assert_eq!(prover_state.narg_string(), b"");Sourcepub fn prover_message<T: Encoding<[H::U]> + NargSerialize + ?Sized>(
&mut self,
message: &T,
)
pub fn prover_message<T: Encoding<[H::U]> + NargSerialize + ?Sized>( &mut self, message: &T, )
Input a prover message of type T into the Fiat–Shamir transformation.
T must implement Encoding<[H::U]> to be encoded in the domain of the
duplex sponge, and NargSerialize to be serialized into the NARG string.
use spongefish::ProverState;
let mut prover_state = spongefish::domain_separator!("examples"; "ProverState::prover_message")
.instance(&0u32)
.std_prover();
prover_state.prover_message(&42u32);
let expected = 42u32.to_le_bytes();
assert_eq!(prover_state.narg_string(), expected.as_slice());Sourcepub fn verifier_message<T: Decoding<[H::U]>>(&mut self) -> T
pub fn verifier_message<T: Decoding<[H::U]>>(&mut self) -> T
Returns a verifier message T that is uniformly distributed.
T must implement Decoding<[H::U]>.
Sourcepub const fn transcript(&self) -> &[u8] ⓘ
👎Deprecated: Please use ProverState::narg_string instead.
pub const fn transcript(&self) -> &[u8] ⓘ
Please use ProverState::narg_string instead.
Alias for narg_string.
Sourcepub fn challenge<T: Decoding<[H::U]>>(&mut self) -> T
👎Deprecated: Please use ProverState::verifier_message instead.
pub fn challenge<T: Decoding<[H::U]>>(&mut self) -> T
Please use ProverState::verifier_message instead.
Alias for verifier_message.
Sourcepub fn public_messages<T: Encoding<[H::U]>>(&mut self, messages: &[T])
pub fn public_messages<T: Encoding<[H::U]>>(&mut self, messages: &[T])
Input to the Fiat–Shamir transformation an array of public messages.
Sourcepub fn public_messages_iter<J>(&mut self, messages: J)
pub fn public_messages_iter<J>(&mut self, messages: J)
Input to the Fiat–Shamir transformation an iterator of public messages.
Sourcepub fn prover_messages<T: Encoding<[H::U]> + NargSerialize>(
&mut self,
messages: &[T],
)
pub fn prover_messages<T: Encoding<[H::U]> + NargSerialize>( &mut self, messages: &[T], )
Absorbs a list of prover messages at once.
Sourcepub fn prover_messages_iter<J>(&mut self, messages: J)
pub fn prover_messages_iter<J>(&mut self, messages: J)
Absorbs an iterator of prover messages.
Trait Implementations§
Source§impl<H, R> Debug for ProverState<H, R>
impl<H, R> Debug for ProverState<H, R>
Source§impl<H: DuplexSpongeInterface + Default, R: RngCore + CryptoRng + SeedableRng> Default for ProverState<H, R>
Available on crate feature yolocrypto only.Creates a new ProverState seeded using rand::SeedableRng::from_entropy.
impl<H: DuplexSpongeInterface + Default, R: RngCore + CryptoRng + SeedableRng> Default for ProverState<H, R>
yolocrypto only.Creates a new ProverState seeded using rand::SeedableRng::from_entropy.
Default provides alternative initialization methods than the one via
DomainSeparator.
ProverState::default is only available with the yolocrypto feature and its support in
future releases is not guaranteed.
Source§impl<H: DuplexSpongeInterface, R: RngCore + CryptoRng + SeedableRng> From<H> for ProverState<H, R>
Creates a new ProverState using the given duplex sponge interface.
impl<H: DuplexSpongeInterface, R: RngCore + CryptoRng + SeedableRng> From<H> for ProverState<H, R>
Creates a new ProverState using the given duplex sponge interface.
Auto Trait Implementations§
impl<H, R> Freeze for ProverState<H, R>
impl<H, R> RefUnwindSafe for ProverState<H, R>where
H: RefUnwindSafe,
R: RefUnwindSafe,
impl<H, R> Send for ProverState<H, R>
impl<H, R> Sync for ProverState<H, R>
impl<H, R> Unpin for ProverState<H, R>
impl<H, R> UnsafeUnpin for ProverState<H, R>where
H: UnsafeUnpin,
R: UnsafeUnpin,
impl<H, R> UnwindSafe for ProverState<H, R>where
H: UnwindSafe,
R: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.