xrpld
Loading...
Searching...
No Matches
include/xrpl/protocol/ConfidentialTransfer.h
1#pragma once
2
3#include <xrpl/basics/Buffer.h>
4#include <xrpl/basics/Slice.h>
5#include <xrpl/basics/base_uint.h>
6#include <xrpl/protocol/AccountID.h>
7#include <xrpl/protocol/SField.h>
8#include <xrpl/protocol/STInteger.h> // IWYU pragma: keep
9#include <xrpl/protocol/STLedgerEntry.h>
10#include <xrpl/protocol/STObject.h>
11#include <xrpl/protocol/TER.h>
12#include <xrpl/protocol/UintTypes.h>
13#include <xrpl/protocol/detail/secp256k1.h>
14
15#include <secp256k1.h>
16
17#include <cstdint>
18#include <limits>
19#include <optional>
20
21namespace xrpl {
22
43
48struct EcPair
49{
53 secp256k1_pubkey c1;
54
58 secp256k1_pubkey c2;
59};
60
70inline void
72{
73 // Retrieve current version and increment, wrapping back to 0 at UINT32_MAX.
74 // The wrap is computed explicitly rather than relying on unsigned overflow
75 // of `+ 1u`, as it trips the unsigned-integer-overflow sanitizer in the UBSan CI build.
76 auto const current = mptoken[~sfConfidentialBalanceVersion].valueOr(0u);
77 mptoken[sfConfidentialBalanceVersion] =
78 current == std::numeric_limits<std::uint32_t>::max() ? 0u : current + 1u;
79}
80
96 AccountID const& account,
97 UInt192 const& issuanceID,
98 std::uint32_t sequence,
99 AccountID const& destination,
100 std::uint32_t version);
101
116 AccountID const& account,
117 UInt192 const& issuanceID,
118 std::uint32_t sequence,
119 AccountID const& holder);
120
133getConvertContextHash(AccountID const& account, UInt192 const& issuanceID, std::uint32_t sequence);
134
149 AccountID const& account,
150 UInt192 const& issuanceID,
151 std::uint32_t sequence,
152 std::uint32_t version);
153
166makeEcPair(Slice const& buffer);
167
180serializeEcPair(EcPair const& pair);
181
188bool
189isValidCiphertext(Slice const& buffer);
190
201bool
202isValidCompressedECPoint(Slice const& buffer);
203
215homomorphicAdd(Slice const& a, Slice const& b);
216
228homomorphicSubtract(Slice const& a, Slice const& b);
229
245rerandomizeCiphertext(Slice const& ciphertext, Slice const& pubKeySlice, Slice const& randomness);
246
260encryptAmount(uint64_t const amt, Slice const& pubKeySlice, Slice const& blindingFactor);
261
275encryptCanonicalZeroAmount(Slice const& pubKeySlice, AccountID const& account, MPTID const& mptId);
276
288TER
289verifySchnorrProof(Slice const& pubKeySlice, Slice const& proofSlice, UInt256 const& contextHash);
290
302NotTEC
303checkEncryptedAmountFormat(STObject const& object);
304
317[[nodiscard]] bool
318isIssuerMirrorCurrent(SLE const& issuance, SLE const& mptoken);
319
332[[nodiscard]] bool
333isAuditorMirrorCurrent(SLE const& issuance, SLE const& mptoken);
334
347[[nodiscard]] bool
348areMirrorsCurrent(SLE const& issuance, SLE const& mptoken);
349
359void
360setIssuerMirrorEpoch(SLE const& issuance, SLE& mptoken);
361
371void
372setAuditorMirrorEpoch(SLE const& issuance, SLE& mptoken);
373
383void
384setMirrorEpochs(SLE const& issuance, SLE& mptoken);
385
400TER
402 uint64_t const amount,
403 Slice const& blindingFactor,
404 ConfidentialRecipient const& holder,
405 ConfidentialRecipient const& issuer,
407
417constexpr uint8_t
419{
420 return hasAuditor ? 4 : 3;
421}
422
438TER
440 uint64_t const amount,
441 Slice const& proof,
442 Slice const& pubKeySlice,
443 Slice const& ciphertext,
444 UInt256 const& contextHash);
445
456Buffer
458
481TER
483 Slice const& proof,
484 ConfidentialRecipient const& sender,
485 ConfidentialRecipient const& destination,
486 ConfidentialRecipient const& issuer,
488 Slice const& spendingBalance,
489 Slice const& amountCommitment,
490 Slice const& balanceCommitment,
491 UInt256 const& contextHash);
492
509TER
511 Slice const& proof,
512 Slice const& pubKeySlice,
513 Slice const& spendingBalance,
514 Slice const& balanceCommitment,
515 uint64_t amount,
516 UInt256 const& contextHash);
517
518} // namespace xrpl
An immutable linear range of bytes.
Definition Slice.h:28
T max(T... args)
Use hash_* containers for keys that do not need a cryptographically secure hashing algorithm.
Definition algorithm.h:5
bool areMirrorsCurrent(SLE const &issuance, SLE const &mptoken)
Checks whether each mirror a holder is required to have is encrypted under the issuance's currently r...
NotTEC checkEncryptedAmountFormat(STObject const &object)
Validates the format of encrypted amount fields in a transaction.
void setMirrorEpochs(SLE const &issuance, SLE &mptoken)
Set the holder's MPToken mirror epochs to match the issuance's current key epochs.
std::optional< Buffer > rerandomizeCiphertext(Slice const &ciphertext, Slice const &pubKeySlice, Slice const &randomness)
Re-randomizes an ElGamal ciphertext without changing its plaintext.
std::optional< Buffer > encryptCanonicalZeroAmount(Slice const &pubKeySlice, AccountID const &account, MPTID const &mptId)
Generates the canonical zero encryption for a specific MPToken.
UInt256 getConvertContextHash(AccountID const &account, UInt192 const &issuanceID, std::uint32_t sequence)
Generates the context hash for ConfidentialMPTConvert transactions.
UInt256 getSendContextHash(AccountID const &account, UInt192 const &issuanceID, std::uint32_t sequence, AccountID const &destination, std::uint32_t version)
Generates the context hash for ConfidentialMPTSend transactions.
bool isIssuerMirrorCurrent(SLE const &issuance, SLE const &mptoken)
Checks whether a holder's issuer mirror is encrypted under the issuance's currently registered issuer...
UInt256 getConvertBackContextHash(AccountID const &account, UInt192 const &issuanceID, std::uint32_t sequence, std::uint32_t version)
Generates the context hash for ConfidentialMPTConvertBack transactions.
std::optional< Buffer > encryptAmount(uint64_t const amt, Slice const &pubKeySlice, Slice const &blindingFactor)
Encrypts an amount using ElGamal encryption.
bool isValidCompressedECPoint(Slice const &buffer)
Verifies that a buffer contains a valid, parsable compressed EC point.
bool isAuditorMirrorCurrent(SLE const &issuance, SLE const &mptoken)
Checks whether a holder's auditor mirror is encrypted under the issuance's currently registered audit...
constexpr uint8_t getConfidentialRecipientCount(bool hasAuditor)
Returns the number of recipients in a confidential transfer.
std::optional< EcPair > makeEcPair(Slice const &buffer)
Parses an ElGamal ciphertext into two secp256k1 public key components.
TER verifySendProof(Slice const &proof, ConfidentialRecipient const &sender, ConfidentialRecipient const &destination, ConfidentialRecipient const &issuer, std::optional< ConfidentialRecipient > const &auditor, Slice const &spendingBalance, Slice const &amountCommitment, Slice const &balanceCommitment, UInt256 const &contextHash)
Verifies all zero-knowledge proofs for a ConfidentialMPTSend transaction.
TER verifyClawbackProof(uint64_t const amount, Slice const &proof, Slice const &pubKeySlice, Slice const &ciphertext, UInt256 const &contextHash)
Verifies a compact sigma clawback proof.
std::optional< Buffer > serializeEcPair(EcPair const &pair)
Serializes an EcPair into compressed form.
BaseUInt< 192 > UInt192
Definition base_uint.h:581
TER verifyRevealedAmount(uint64_t const amount, Slice const &blindingFactor, ConfidentialRecipient const &holder, ConfidentialRecipient const &issuer, std::optional< ConfidentialRecipient > const &auditor)
Verifies revealed amount encryptions for all recipients.
STLedgerEntry SLE
bool isValidCiphertext(Slice const &buffer)
Verifies that a buffer contains two valid, parsable EC public keys.
TER verifyConvertBackProof(Slice const &proof, Slice const &pubKeySlice, Slice const &spendingBalance, Slice const &balanceCommitment, uint64_t amount, UInt256 const &contextHash)
Verifies all zero-knowledge proofs for a ConfidentialMPTConvertBack transaction.
BaseUInt< 256 > UInt256
Definition base_uint.h:580
TERSubset< CanCvtToNotTEC > NotTEC
Definition TER.h:614
std::optional< Buffer > homomorphicSubtract(Slice const &a, Slice const &b)
Homomorphically subtracts two ElGamal ciphertexts.
BaseUInt< 192 > MPTID
MPTID is a 192-bit value representing MPT Issuance ID, which is a concatenation of a 32-bit sequence ...
Definition UintTypes.h:54
void setAuditorMirrorEpoch(SLE const &issuance, SLE &mptoken)
Set the holder's auditor mirror epoch to match the issuance's current auditor key epoch.
void setIssuerMirrorEpoch(SLE const &issuance, SLE &mptoken)
Set the holder's issuer mirror epoch to match the issuance's current issuer key epoch.
UInt256 getClawbackContextHash(AccountID const &account, UInt192 const &issuanceID, std::uint32_t sequence, AccountID const &holder)
Generates the context hash for ConfidentialMPTClawback transactions.
Buffer generateBlindingFactor()
Generates a cryptographically secure blinding factor (size=xrpl::kEcBlindingFactorLength).
BaseUInt< 160, detail::AccountIDTag > AccountID
A 160-bit unsigned that uniquely identifies an account.
Definition AccountID.h:34
TERSubset< CanCvtToTER > TER
Definition TER.h:654
TER verifySchnorrProof(Slice const &pubKeySlice, Slice const &proofSlice, UInt256 const &contextHash)
Verifies a Schnorr proof of knowledge of an ElGamal private key.
void incrementConfidentialVersion(STObject &mptoken)
Increments the confidential balance version counter on an MPToken.
std::optional< Buffer > homomorphicAdd(Slice const &a, Slice const &b)
Homomorphically adds two ElGamal ciphertexts.
Bundles an ElGamal public key with its associated encrypted amount.
Slice encryptedAmount
The encrypted amount ciphertext (size=xrpl::kEcGamalEncryptedTotalLength).
Slice publicKey
The recipient's ElGamal public key (size=xrpl::kEcPubKeyLength).
Holds two secp256k1 public key components representing an ElGamal ciphertext (C1, C2).
secp256k1_pubkey c2
Second ElGamal ciphertext component.
secp256k1_pubkey c1
First ElGamal ciphertext component.