nut02.rs 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355
  1. //! Keysets and keyset ID
  2. // https://github.com/cashubtc/nuts/blob/main/02.md
  3. use std::collections::HashSet;
  4. use base64::engine::general_purpose;
  5. use base64::Engine as _;
  6. use bitcoin::hashes::{sha256, Hash};
  7. use itertools::Itertools;
  8. use serde::{Deserialize, Serialize};
  9. use thiserror::Error;
  10. use super::nut01::Keys;
  11. #[derive(Debug, Error, PartialEq, Eq)]
  12. pub enum Error {
  13. #[error("`{0}`")]
  14. Base64(#[from] base64::DecodeError),
  15. #[error("NUT01: ID length invalid")]
  16. Length,
  17. }
  18. /// A keyset ID is an identifier for a specific keyset. It can be derived by
  19. /// anyone who knows the set of public keys of a mint. The keyset ID **CAN**
  20. /// be stored in a Cashu token such that the token can be used to identify
  21. /// which mint or keyset it was generated from.
  22. #[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
  23. pub struct Id([u8; Id::BYTES]);
  24. impl Id {
  25. const BYTES: usize = 9;
  26. const STRLEN: usize = 12;
  27. pub fn try_from_base64(b64: &str) -> Result<Self, Error> {
  28. use base64::engine::general_purpose::{STANDARD, URL_SAFE};
  29. use base64::Engine as _;
  30. if b64.len() != Self::STRLEN {
  31. return Err(Error::Length);
  32. }
  33. if let Ok(bytes) = URL_SAFE.decode(b64) {
  34. if bytes.len() == Self::BYTES {
  35. return Ok(Self(
  36. <[u8; Self::BYTES]>::try_from(bytes.as_slice()).unwrap(),
  37. ));
  38. }
  39. }
  40. match STANDARD.decode(b64) {
  41. Ok(bytes) if bytes.len() == Self::BYTES => Ok(Self(
  42. <[u8; Self::BYTES]>::try_from(bytes.as_slice()).unwrap(),
  43. )),
  44. Ok(_) => Err(Error::Length),
  45. Err(e) => Err(Error::Base64(e)),
  46. }
  47. }
  48. }
  49. impl std::fmt::Display for Id {
  50. fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
  51. let mut output = String::with_capacity(Self::STRLEN);
  52. general_purpose::STANDARD.encode_string(self.0.as_slice(), &mut output);
  53. f.write_str(&output)
  54. }
  55. }
  56. impl std::convert::TryFrom<String> for Id {
  57. type Error = Error;
  58. fn try_from(value: String) -> Result<Self, Self::Error> {
  59. Id::try_from_base64(&value)
  60. }
  61. }
  62. impl serde::ser::Serialize for Id {
  63. fn serialize<S>(&self, serializer: S) -> Result<S::Ok, S::Error>
  64. where
  65. S: serde::Serializer,
  66. {
  67. serializer.serialize_str(&self.to_string())
  68. }
  69. }
  70. impl<'de> serde::de::Deserialize<'de> for Id {
  71. fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>
  72. where
  73. D: serde::Deserializer<'de>,
  74. {
  75. struct IdVisitor;
  76. impl<'de> serde::de::Visitor<'de> for IdVisitor {
  77. type Value = Id;
  78. fn expecting(&self, formatter: &mut std::fmt::Formatter) -> std::fmt::Result {
  79. formatter.write_str("a 12-character Base64 string")
  80. }
  81. fn visit_str<E>(self, v: &str) -> Result<Self::Value, E>
  82. where
  83. E: serde::de::Error,
  84. {
  85. Id::try_from_base64(v).map_err(|e| match e {
  86. Error::Length => E::custom(format!(
  87. "Invalid Length: Expected {}, got {}",
  88. Id::STRLEN,
  89. v.len()
  90. )),
  91. Error::Base64(e) => E::custom(e),
  92. })
  93. }
  94. }
  95. deserializer.deserialize_str(IdVisitor)
  96. }
  97. }
  98. impl From<&Keys> for Id {
  99. fn from(map: &Keys) -> Self {
  100. /* NUT-02 § 2.2.2
  101. 1 - sort keyset by amount
  102. 2 - concatenate all (sorted) public keys to one string
  103. 3 - HASH_SHA256 the concatenated public keys
  104. 4 - take the first 12 characters of the base64-encoded hash
  105. */
  106. let pubkeys_concat = map
  107. .iter()
  108. .sorted_by(|(amt_a, _), (amt_b, _)| amt_a.cmp(amt_b))
  109. .map(|(_, pubkey)| pubkey)
  110. .join("");
  111. let hash = sha256::Hash::hash(pubkeys_concat.as_bytes());
  112. let bytes = hash.to_byte_array();
  113. // First 9 bytes of hash will encode as the first 12 Base64 characters later
  114. Self(<[u8; Self::BYTES]>::try_from(&bytes[0..Self::BYTES]).unwrap())
  115. }
  116. }
  117. /// Mint Keysets [NUT-02]
  118. /// Ids of mints keyset ids
  119. #[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
  120. pub struct Response {
  121. /// set of public key ids that the mint generates
  122. pub keysets: HashSet<Id>,
  123. }
  124. #[derive(Debug, Clone, PartialEq, Eq, Deserialize, Serialize)]
  125. pub struct KeySet {
  126. pub id: Id,
  127. pub keys: Keys,
  128. }
  129. impl From<mint::KeySet> for KeySet {
  130. fn from(keyset: mint::KeySet) -> Self {
  131. Self {
  132. id: keyset.id,
  133. keys: Keys::from(keyset.keys),
  134. }
  135. }
  136. }
  137. pub mod mint {
  138. use std::collections::BTreeMap;
  139. use bitcoin::hashes::sha256::Hash as Sha256;
  140. use bitcoin::hashes::{Hash, HashEngine};
  141. use itertools::Itertools;
  142. use k256::SecretKey;
  143. use serde::Serialize;
  144. use super::Id;
  145. use crate::nuts::nut01::mint::{KeyPair, Keys};
  146. use crate::Amount;
  147. #[derive(Debug, Clone, PartialEq, Eq, Serialize)]
  148. pub struct KeySet {
  149. pub id: Id,
  150. pub keys: Keys,
  151. }
  152. impl KeySet {
  153. pub fn generate(
  154. secret: impl Into<String>,
  155. derivation_path: impl Into<String>,
  156. max_order: u8,
  157. ) -> Self {
  158. // Elliptic curve math context
  159. /* NUT-02 § 2.1
  160. for i in range(MAX_ORDER):
  161. k_i = HASH_SHA256(s + D + i)[:32]
  162. */
  163. let mut map = BTreeMap::new();
  164. // SHA-256 midstate, for quicker hashing
  165. let mut engine = Sha256::engine();
  166. engine.input(secret.into().as_bytes());
  167. engine.input(derivation_path.into().as_bytes());
  168. for i in 0..max_order {
  169. let amount = Amount::from_sat(2_u64.pow(i as u32));
  170. // Reuse midstate
  171. let mut e = engine.clone();
  172. e.input(i.to_string().as_bytes());
  173. let hash = Sha256::from_engine(e);
  174. let secret_key = SecretKey::from_slice(&hash.to_byte_array()).unwrap();
  175. let keypair = KeyPair::from_secret_key(secret_key.into());
  176. map.insert(amount, keypair);
  177. }
  178. let keys = Keys(map);
  179. Self {
  180. id: (&keys).into(),
  181. keys,
  182. }
  183. }
  184. }
  185. impl From<KeySet> for Id {
  186. fn from(keyset: KeySet) -> Id {
  187. let keys: super::KeySet = keyset.into();
  188. Id::from(&keys.keys)
  189. }
  190. }
  191. impl From<&Keys> for Id {
  192. fn from(map: &Keys) -> Self {
  193. /* NUT-02 § 2.2.2
  194. 1 - sort keyset by amount
  195. 2 - concatenate all (sorted) public keys to one string
  196. 3 - HASH_SHA256 the concatenated public keys
  197. 4 - take the first 12 characters of the base64-encoded hash
  198. */
  199. let keys: super::Keys = map.clone().into();
  200. let pubkeys_concat = keys
  201. .iter()
  202. .sorted_by(|(amt_a, _), (amt_b, _)| amt_a.cmp(amt_b))
  203. .map(|(_, pubkey)| pubkey)
  204. .join("");
  205. let hash = Sha256::hash(pubkeys_concat.as_bytes());
  206. let bytes = hash.to_byte_array();
  207. // First 9 bytes of hash will encode as the first 12 Base64 characters later
  208. Self(<[u8; Self::BYTES]>::try_from(&bytes[0..Self::BYTES]).unwrap())
  209. }
  210. }
  211. }
  212. #[cfg(test)]
  213. mod test {
  214. use super::Keys;
  215. use crate::nuts::nut02::Id;
  216. const SHORT_KEYSET_ID: &str = "esom3oyNLLit";
  217. const SHORT_KEYSET: &str = r#"
  218. {
  219. "1":"03a40f20667ed53513075dc51e715ff2046cad64eb68960632269ba7f0210e38bc",
  220. "2":"03fd4ce5a16b65576145949e6f99f445f8249fee17c606b688b504a849cdc452de",
  221. "4":"02648eccfa4c026960966276fa5a4cae46ce0fd432211a4f449bf84f13aa5f8303",
  222. "8":"02fdfd6796bfeac490cbee12f778f867f0a2c68f6508d17c649759ea0dc3547528"
  223. }
  224. "#;
  225. const KEYSET_ID: &str = "I2yN+iRYfkzT";
  226. const KEYSET: &str = r#"
  227. {
  228. "1":"03ba786a2c0745f8c30e490288acd7a72dd53d65afd292ddefa326a4a3fa14c566",
  229. "2":"03361cd8bd1329fea797a6add1cf1990ffcf2270ceb9fc81eeee0e8e9c1bd0cdf5",
  230. "4":"036e378bcf78738ddf68859293c69778035740e41138ab183c94f8fee7572214c7",
  231. "8":"03909d73beaf28edfb283dbeb8da321afd40651e8902fcf5454ecc7d69788626c0",
  232. "16":"028a36f0e6638ea7466665fe174d958212723019ec08f9ce6898d897f88e68aa5d",
  233. "32":"03a97a40e146adee2687ac60c2ba2586a90f970de92a9d0e6cae5a4b9965f54612",
  234. "64":"03ce86f0c197aab181ddba0cfc5c5576e11dfd5164d9f3d4a3fc3ffbbf2e069664",
  235. "128":"0284f2c06d938a6f78794814c687560a0aabab19fe5e6f30ede38e113b132a3cb9",
  236. "256":"03b99f475b68e5b4c0ba809cdecaae64eade2d9787aa123206f91cd61f76c01459",
  237. "512":"03d4db82ea19a44d35274de51f78af0a710925fe7d9e03620b84e3e9976e3ac2eb",
  238. "1024":"031fbd4ba801870871d46cf62228a1b748905ebc07d3b210daf48de229e683f2dc",
  239. "2048":"0276cedb9a3b160db6a158ad4e468d2437f021293204b3cd4bf6247970d8aff54b",
  240. "4096":"02fc6b89b403ee9eb8a7ed457cd3973638080d6e04ca8af7307c965c166b555ea2",
  241. "8192":"0320265583e916d3a305f0d2687fcf2cd4e3cd03a16ea8261fda309c3ec5721e21",
  242. "16384":"036e41de58fdff3cb1d8d713f48c63bc61fa3b3e1631495a444d178363c0d2ed50",
  243. "32768":"0365438f613f19696264300b069d1dad93f0c60a37536b72a8ab7c7366a5ee6c04",
  244. "65536":"02408426cfb6fc86341bac79624ba8708a4376b2d92debdf4134813f866eb57a8d",
  245. "131072":"031063e9f11c94dc778c473e968966eac0e70b7145213fbaff5f7a007e71c65f41",
  246. "262144":"02f2a3e808f9cd168ec71b7f328258d0c1dda250659c1aced14c7f5cf05aab4328",
  247. "524288":"038ac10de9f1ff9395903bb73077e94dbf91e9ef98fd77d9a2debc5f74c575bc86",
  248. "1048576":"0203eaee4db749b0fc7c49870d082024b2c31d889f9bc3b32473d4f1dfa3625788",
  249. "2097152":"033cdb9d36e1e82ae652b7b6a08e0204569ec7ff9ebf85d80a02786dc7fe00b04c",
  250. "4194304":"02c8b73f4e3a470ae05e5f2fe39984d41e9f6ae7be9f3b09c9ac31292e403ac512",
  251. "8388608":"025bbe0cfce8a1f4fbd7f3a0d4a09cb6badd73ef61829dc827aa8a98c270bc25b0",
  252. "16777216":"037eec3d1651a30a90182d9287a5c51386fe35d4a96839cf7969c6e2a03db1fc21",
  253. "33554432":"03280576b81a04e6abd7197f305506476f5751356b7643988495ca5c3e14e5c262",
  254. "67108864":"03268bfb05be1dbb33ab6e7e00e438373ca2c9b9abc018fdb452d0e1a0935e10d3",
  255. "134217728":"02573b68784ceba9617bbcc7c9487836d296aa7c628c3199173a841e7a19798020",
  256. "268435456":"0234076b6e70f7fbf755d2227ecc8d8169d662518ee3a1401f729e2a12ccb2b276",
  257. "536870912":"03015bd88961e2a466a2163bd4248d1d2b42c7c58a157e594785e7eb34d880efc9",
  258. "1073741824":"02c9b076d08f9020ebee49ac8ba2610b404d4e553a4f800150ceb539e9421aaeee",
  259. "2147483648":"034d592f4c366afddc919a509600af81b489a03caf4f7517c2b3f4f2b558f9a41a",
  260. "4294967296":"037c09ecb66da082981e4cbdb1ac65c0eb631fc75d85bed13efb2c6364148879b5",
  261. "8589934592":"02b4ebb0dda3b9ad83b39e2e31024b777cc0ac205a96b9a6cfab3edea2912ed1b3",
  262. "17179869184":"026cc4dacdced45e63f6e4f62edbc5779ccd802e7fabb82d5123db879b636176e9",
  263. "34359738368":"02b2cee01b7d8e90180254459b8f09bbea9aad34c3a2fd98c85517ecfc9805af75",
  264. "68719476736":"037a0c0d564540fc574b8bfa0253cca987b75466e44b295ed59f6f8bd41aace754",
  265. "137438953472":"021df6585cae9b9ca431318a713fd73dbb76b3ef5667957e8633bca8aaa7214fb6",
  266. "274877906944":"02b8f53dde126f8c85fa5bb6061c0be5aca90984ce9b902966941caf963648d53a",
  267. "549755813888":"029cc8af2840d59f1d8761779b2496623c82c64be8e15f9ab577c657c6dd453785",
  268. "1099511627776":"03e446fdb84fad492ff3a25fc1046fb9a93a5b262ebcd0151caa442ea28959a38a",
  269. "2199023255552":"02d6b25bd4ab599dd0818c55f75702fde603c93f259222001246569018842d3258",
  270. "4398046511104":"03397b522bb4e156ec3952d3f048e5a986c20a00718e5e52cd5718466bf494156a",
  271. "8796093022208":"02d1fb9e78262b5d7d74028073075b80bb5ab281edcfc3191061962c1346340f1e",
  272. "17592186044416":"030d3f2ad7a4ca115712ff7f140434f802b19a4c9b2dd1c76f3e8e80c05c6a9310",
  273. "35184372088832":"03e325b691f292e1dfb151c3fb7cad440b225795583c32e24e10635a80e4221c06",
  274. "70368744177664":"03bee8f64d88de3dee21d61f89efa32933da51152ddbd67466bef815e9f93f8fd1",
  275. "140737488355328":"0327244c9019a4892e1f04ba3bf95fe43b327479e2d57c25979446cc508cd379ed",
  276. "281474976710656":"02fb58522cd662f2f8b042f8161caae6e45de98283f74d4e99f19b0ea85e08a56d",
  277. "562949953421312":"02adde4b466a9d7e59386b6a701a39717c53f30c4810613c1b55e6b6da43b7bc9a",
  278. "1125899906842624":"038eeda11f78ce05c774f30e393cda075192b890d68590813ff46362548528dca9",
  279. "2251799813685248":"02ec13e0058b196db80f7079d329333b330dc30c000dbdd7397cbbc5a37a664c4f",
  280. "4503599627370496":"02d2d162db63675bd04f7d56df04508840f41e2ad87312a3c93041b494efe80a73",
  281. "9007199254740992":"0356969d6aef2bb40121dbd07c68b6102339f4ea8e674a9008bb69506795998f49",
  282. "18014398509481984":"02f4e667567ebb9f4e6e180a4113bb071c48855f657766bb5e9c776a880335d1d6",
  283. "36028797018963968":"0385b4fe35e41703d7a657d957c67bb536629de57b7e6ee6fe2130728ef0fc90b0",
  284. "72057594037927936":"02b2bc1968a6fddbcc78fb9903940524824b5f5bed329c6ad48a19b56068c144fd",
  285. "144115188075855872":"02e0dbb24f1d288a693e8a49bc14264d1276be16972131520cf9e055ae92fba19a",
  286. "288230376151711744":"03efe75c106f931a525dc2d653ebedddc413a2c7d8cb9da410893ae7d2fa7d19cc",
  287. "576460752303423488":"02c7ec2bd9508a7fc03f73c7565dc600b30fd86f3d305f8f139c45c404a52d958a",
  288. "1152921504606846976":"035a6679c6b25e68ff4e29d1c7ef87f21e0a8fc574f6a08c1aa45ff352c1d59f06",
  289. "2305843009213693952":"033cdc225962c052d485f7cfbf55a5b2367d200fe1fe4373a347deb4cc99e9a099",
  290. "4611686018427387904":"024a4b806cf413d14b294719090a9da36ba75209c7657135ad09bc65328fba9e6f",
  291. "9223372036854775808":"0377a6fe114e291a8d8e991627c38001c8305b23b9e98b1c7b1893f5cd0dda6cad"
  292. }
  293. "#;
  294. #[test]
  295. fn deserialization_and_id_generation() {
  296. let keys: Keys = serde_json::from_str(SHORT_KEYSET).unwrap();
  297. let id: Id = (&keys).into();
  298. assert_eq!(id, Id::try_from_base64(SHORT_KEYSET_ID).unwrap());
  299. let keys: Keys = serde_json::from_str(KEYSET).unwrap();
  300. let id: Id = (&keys).into();
  301. assert_eq!(id, Id::try_from_base64(KEYSET_ID).unwrap());
  302. }
  303. }