Skip to content

Harden cryptographic primitive contracts - #209

Draft
wangxiao1254 wants to merge 6 commits into
audit/core-contractsfrom
audit/crypto-foundations
Draft

wangxiao1254 wants to merge 6 commits into
audit/core-contractsfrom
audit/crypto-foundations

Conversation

@wangxiao1254

Copy link
Copy Markdown
Member

Summary

Harden the contracts of the runtime cryptographic primitives and correct their benchmark coverage and accounting.

Changes

AES and PRG

  • use unsigned AES-CTR counters across the signed boundary;
  • reject negative and overflowing runtime dimensions;
  • define empty compile-time AES shapes;
  • invalidate buffered operator() words on PRG::reseed();
  • cover unaligned output, guard bytes, and counter wrap.

CCRH, F2K, and MITCCRH

  • validate runtime vector lengths and compile-time hash shapes;
  • define empty CCRH vector operations;
  • retain typed byte-bool selectors;
  • initialize MITCCRH state deterministically.

EC and random oracle

  • generate nonzero private scalars;
  • add bounded/padded scalar encodings and const-safe BIGNUM access;
  • use deterministic test-mode rejection sampling;
  • validate output sizes, DST bounds, point encodings, and supported curves;
  • clear stale OpenSSL errors before retryable map-to-curve operations.

Half gates and SessionID

  • separate the shared public half-gate hash seed from the secret free-XOR delta;
  • pin the shared gid schedule and batch-size invariance with tests;
  • mark SessionID::derive() [[nodiscard]] and document copy/counter behavior.

Benchmarks

  • prevent runtime AES work from being hoisted;
  • report active SIMD tiers;
  • correct F2K byte/cycle and half-gate gate accounting;
  • use aligned PRG storage and cover alignment/size boundaries;
  • compare MITCCRH in-place, out-of-place, and unaligned-gid shapes.

The benchmark changes make the existing measurements faithful.

Compatibility

The stricter size/shape contracts fail before pointer arithmetic. Scalar::n() becomes const-safe, and half-gate callers must provide the same public hash seed to garbler and evaluator independently of the delta.

Tests

  • clean Apple Clang 17 Release/Ninja build completed;
  • full CTest suite: 72/72 passed;
  • focused AES, PRG, CCRH, F2K, MITCCRH, ECC, RO, half-gate, SessionID, and no-exceptions suite: 10/10 passed;
  • expected AES/crypto compile-failure contracts: 16/16 passed;
  • portable Release (EMP_TOOL_NATIVE_ARCH=OFF): focused suite 10/10 and compile-failure contracts 16/16 passed.

Coverage includes AES and crypto compile-fail probes, AES/PRG/CCRH/F2K/MITCCRH boundary and reference tests, EC/RO malformed-input tests, exhaustive half-gate truth tables, seed/gid invariants, and SessionID derivation streams.

Stack

This is PR 4 of 6 and targets audit/core-contracts.

Use unsigned counters throughout AES-CTR expansion, reject negative and overflowing dimensions, and define empty compile-time shapes without dereferencing their buffers.

Reset PRG buffered-word state on reseed and cover aligned and unaligned output across counter wrap, canary preservation, zero lengths, and byte-bool state parity. Add compile-fail probes for invalid AES shapes.
Reject negative vector lengths and invalid compile-time hash dimensions before pointer arithmetic or template instantiation. Define empty CCRH vector operations and preserve byte-bool selector support.

Add compile-fail probes for invalid shapes plus focused zero-length, tail, and reference-equivalence tests.
Prevent loop-invariant motion in runtime AES measurements, report the active SIMD tier, and include small-vector and alignment boundaries.

Correct F2K byte and cycle accounting, half-gate gate counts, and PRG alignment. Retain benchmark outputs against dead-code elimination and compare MITCCRH in-place, out-of-place, and unaligned-gid call shapes.
Use nonzero private scalar generation, bounded and padded scalar encodings, const-safe BIGNUM access, and deterministic test-mode rejection sampling.

Validate random-oracle output sizes and domain-separation tags, clear stale OpenSSL errors before retryable map-to-curve operations, and reject unsupported curves and malformed encodings with focused tests.
Initialize MITCCRH state deterministically and require callers to install one shared public hash seed that is independent of the free-XOR delta.

Pin the shared gid schedule and seed-independence contract across garbling and evaluation. Cover in-place and out-of-place hashing, reuse buckets, batch-size invariance, exhaustive gate truth tables, and secret-delta changes under a fixed public seed.
Mark derive() nodiscard so accidentally discarded child identifiers are diagnosed while value() remains the non-advancing accessor.

Document copy and counter semantics and add direct tests for default, seeded, sequential, copied, and independently advanced derivation streams.
@wangxiao1254
wangxiao1254 force-pushed the audit/crypto-foundations branch from ad590de to b3c2173 Compare August 22, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant