Expose XOFs like SHAKE128 and SHAKE256
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Ambito
- cryptography
Direzione di ricerca
Inizia tracciando la gestione di OpenSSL::Digest intorno a EVP_MD_CTX_size e al metodo digest, quindi verifica come EVP_DigestSqueeze potrebbe inserirsi nell’API proposta. Conferma il comportamento desiderato per SHAKE128 e SHAKE256, incluso digest(length); il lavoro è completato quando l’output a lunghezza variabile funziona senza rompere i digest a lunghezza fissa ed è coperto da test.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
SHAKE is a XOF from the Keccak family of algorithms. Loosely, you can consider them a digest. The thing that sets them apart though is that they have no fixed output size, instead callers indicate "How much data do you want from it?" The 128 and 256 are secure strengths, not output sizes like SHA-2-256.
Even though SHAKE is an EVP-MD, the ruby/openssl project assumes that all digests have a fixed length output.
digest = OpenSSL::Digest.new("SHAKE256") # Works
digest << "hello world" # Works
digest.digest # Fail: ArgumentError: negative string size (or size too big)
Largely because the gem is attempting to ask the EVP_MD how big the digest is using EVP_MD_CTX_size, which returns -1, which is where the ArgumentError comes from.
A small suggestion would be to recognize that when EVP_MD_CTX_size return -1, a length must be supplied to digest
digest = OpenSSL::Digest.new("SHAKE256")
digest << "hello world"
digest.digest(64)
This will allow using the SHAKE XOF.
As a further property of XOFs is "squeeze", exposed by OpenSSL's EVP_DigestSqueeze.
One could imagine doing something like
digest = OpenSSL::Digest.new("SHAKE256")
digest << "hello world"
digest.squeeze(32) + digest.squeeze(32) # Equivalent to digest(64)
Squeeze allows someone to "read" from the XOF in pieces, instead of reading it all out at at once with digest.
Why is this useful?
SHAKE-256 is used to compute the message representative, or mu, when using ML-DSA in external mu. Ruby's ML-DSA does support signing mu instead of the message, but the lack of SHAKE makes it difficult to compute mu. For example, using a made-up mu:
key = OpenSSL::PKey.generate_key("ML-DSA-65")
mu = "\x00" * 64 # This should actually be computed with SHAKE-256
signature = key.sign(nil, mu, "mu" => "1")
Because SHAKE-256 can absorb very large amounts of data, it works like signing a hash with combined with external mu. This is how you can sign very large amounts of data, like a file, without putting the whole file in memory.
This is distinct, and different than HashML-DSA which has largely failed to gain traction in many other standards, and instead recommend using external-mu.
For the purposes of external mu, the digest.squeeze functionality is not needed with EVP_DigestSqueeze, but having some means digest(64) is needed.
I will offer my time to contribute the work, however I would like to better understand what the maintainers would want this to look like before getting started.
- Lingua principale
- C
- Stelle
- 276
- Fork
- 200
- Merge medio
- 15h 27m
- PR unite (30g)
- 7
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ruby/openssl
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
ruby/openssl#1116 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
ruby/openssl#1118 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
ruby/openssl#1075 · 4 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Unchecked *_set_* callsAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
ruby/openssl#1038 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
ruby/openssl#988 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di ruby/openssl
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 2 giorni
-
Additional warning optionsAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
-
Missing zeroAperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 95/100
projecthorus/radiosonde_auto_rx#1116 · 1 commento ·