Documentation
¶
Overview ¶
Package blindrsa implements the RSA Blind Signature Protocol as defined in [RFC9474].
The RSA Blind Signature protocol, and its variant RSABSSA (RSA Blind Signature Scheme with Appendix) is a two-party protocol between a Client and Server where they interact to compute
sig = Sign(sk, input_msg),
where `input_msg = Prepare(msg)` is a prepared version of a private message `msg` provided by the Client, and `sk` is the private signing key provided by the server.
Supported Variants ¶
This package is compliant with the RFC-9474 document and supports the following variants:
- RSABSSA-SHA384-PSS-Deterministic
- RSABSSA-SHA384-PSSZERO-Deterministic
- RSABSSA-SHA384-PSS-Randomized
- RSABSSA-SHA384-PSSZERO-Randomized
Security considerations for deterministic variants ¶
The deterministic variants (RSABSSA-SHA384-PSS-Deterministic and RSABSSA-SHA384-PSSZERO-Deterministic) use an empty Prepare prefix and, in the PSSZERO case, a zero-length salt, so the EMSA-PSS encoding of a given message is fixed. Blind enforces the RFC 9474 coprimality check (rejecting encoded messages that share a factor with the modulus), which prevents a malicious signer with an invalid modulus from learning gcd(m, N) from a single blinded request. Nevertheless, deployments that sign low-entropy deterministic messages in a malicious-signer setting should still prefer the randomized variants (or otherwise ensure high-entropy encodings) and verify that the signer's key is honestly generated.
Example (Blindrsa) ¶
// Setup (offline)
// Server: generate an RSA keypair.
sk, err := rsa.GenerateKey(rand.Reader, 2048)
if err != nil {
fmt.Printf("failed to generate RSA key: %v", err)
return
}
pk := &sk.PublicKey
server := NewSigner(sk)
// Client: stores Server's public key.
client, err := NewClient(SHA384PSSRandomized, pk)
if err != nil {
fmt.Printf("failed to invoke a client: %v", err)
return
}
// Protocol (online)
// Client prepares the message to be signed.
msg := []byte("alice and bob")
preparedMessage, err := client.Prepare(rand.Reader, msg)
if err != nil {
fmt.Printf("client failed to prepare the message: %v", err)
return
}
// Client blinds a message.
blindedMsg, state, err := client.Blind(rand.Reader, preparedMessage)
if err != nil {
fmt.Printf("client failed to generate blinded message: %v", err)
return
}
// Server signs a blinded message, and produces a blinded signature.
blindedSignature, err := server.BlindSign(blindedMsg)
if err != nil {
fmt.Printf("server failed to sign: %v", err)
return
}
// Client build a signature from the previous state and blinded signature.
signature, err := client.Finalize(state, blindedSignature)
if err != nil {
fmt.Printf("client failed to obtain signature: %v", err)
return
}
// Client build a signature from the previous state and blinded signature.
ok := client.Verify(preparedMessage, signature)
fmt.Printf("Valid signature: %v", ok == nil)
Output: Valid signature: true
Index ¶
- Variables
- type Client
- func (c Client) Blind(random io.Reader, preparedMessage []byte) (blindedMsg []byte, state State, err error)
- func (c Client) Finalize(state State, blindedSig []byte) ([]byte, error)
- func (c Client) Prepare(random io.Reader, message []byte) ([]byte, error)
- func (c Client) Verify(message, signature []byte) error
- type Signer
- type State
- type Variant
- type Verifier
Examples ¶
Constants ¶
This section is empty.
Variables ¶
var ( ErrInvalidVariant = common.ErrInvalidVariant ErrUnexpectedSize = common.ErrUnexpectedSize ErrInvalidMessageLength = common.ErrInvalidMessageLength ErrInvalidBlind = common.ErrInvalidBlind ErrInvalidRandomness = common.ErrInvalidRandomness ErrUnsupportedHashFunction = common.ErrUnsupportedHashFunction ErrInvalidMessage = common.ErrInvalidMessage )
Functions ¶
This section is empty.
Types ¶
type Client ¶ added in v1.3.8
type Client struct {
// contains filtered or unexported fields
}
Client is a type that implements the client side of the blind RSA protocol, described in https://www.rfc-editor.org/rfc/rfc9474.html#name-rsabssa-variants
func (Client) Blind ¶ added in v1.3.8
func (c Client) Blind(random io.Reader, preparedMessage []byte) (blindedMsg []byte, state State, err error)
Blind initializes the blind RSA protocol using an input message and source of randomness. This function fails if randomness was not provided.
type Signer ¶ added in v1.3.4
type Signer struct {
// contains filtered or unexported fields
}
Signer structure represents the signing server in the blind RSA protocol. It carries the raw RSA private key used for signing blinded messages.
func NewSigner ¶ added in v1.3.4
func NewSigner(sk *rsa.PrivateKey) Signer
NewSigner creates a new Signer for the blind RSA protocol using an RSA private key.
func (Signer) BlindSign ¶ added in v1.3.4
BlindSign blindly computes the RSA operation using the Signer's private key on the blinded message input, if it's of valid length, and returns an error should the function fail.
See the specification for more details: https://www.rfc-editor.org/rfc/rfc9474.html#name-blindsign
type Verifier ¶ added in v1.3.4
type Verifier struct {
rsa.PSSOptions
// contains filtered or unexported fields
}
Directories
¶
| Path | Synopsis |
|---|---|
|
internal
|
|
|
Package partiallyblindrsa implements a partially blind RSA protocol.
|
Package partiallyblindrsa implements a partially blind RSA protocol. |