circomlib/test/escalarmul.js

169 lines
5.1 KiB
JavaScript
Raw Normal View History

2018-10-21 20:51:38 +03:00
const chai = require("chai");
const path = require("path");
2018-11-11 21:52:07 +03:00
const snarkjs = require("snarkjs");
2018-10-21 20:51:38 +03:00
const compiler = require("circom");
const assert = chai.assert;
2018-12-06 19:32:49 +03:00
const bigInt = snarkjs.bigInt;
2018-10-21 20:51:38 +03:00
2018-12-06 19:32:49 +03:00
const q=bigInt("21888242871839275222246405745257275088548364400416034343698204186575808495617");
2018-10-21 20:51:38 +03:00
function addPoint(a,b) {
2018-12-06 19:32:49 +03:00
const cta = bigInt("168700");
const d = bigInt("168696");
2018-10-21 20:51:38 +03:00
const res = [];
2018-12-06 19:32:49 +03:00
res[0] = bigInt((a[0]*b[1] + b[0]*a[1]) * bigInt(bigInt.one + d*a[0]*b[0]*a[1]*b[1]).inverse(q)).affine(q);
res[1] = bigInt((a[1]*b[1] - cta*a[0]*b[0]) * bigInt(bigInt.one - d*a[0]*b[0]*a[1]*b[1]).inverse(q)).affine(q);
2018-10-21 20:51:38 +03:00
return res;
}
function print(circuit, w, s) {
console.log(s + ": " + w[circuit.getSignalIdx(s)]);
}
describe("Exponentioation test", () => {
it("Should generate the Exponentiation table in k=0", async () => {
2018-11-11 21:52:07 +03:00
const cirDef = await compiler(path.join(__dirname, "circuits", "escalarmulw4table_test.circom"));
2018-10-21 20:51:38 +03:00
// console.log(JSON.stringify(cirDef, null, 1));
// assert.equal(cirDef.nVars, 2);
2018-11-11 21:52:07 +03:00
const circuit = new snarkjs.Circuit(cirDef);
2018-10-21 20:51:38 +03:00
console.log("NConstrains: " + circuit.nConstraints);
const w = circuit.calculateWitness({});
2018-12-06 19:32:49 +03:00
let g = [bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")]
2018-10-21 20:51:38 +03:00
2018-12-06 19:32:49 +03:00
dbl= [bigInt("0"), snarkjs.bigInt("1")];
2018-10-21 20:51:38 +03:00
for (let i=0; i<16; i++) {
const xout1 = w[circuit.getSignalIdx(`main.out[${i}][0]`)];
const yout1 = w[circuit.getSignalIdx(`main.out[${i}][1]`)];
/*
console.log(xout1.toString());
console.log(yout1.toString());
console.log(dbl[0]);
console.log(dbl[1]);
*/
assert(xout1.equals(dbl[0]));
assert(yout1.equals(dbl[1]));
dbl = addPoint([xout1, yout1],g);
}
});
it("Should generate the Exponentiation table in k=3", async () => {
2018-11-11 21:52:07 +03:00
const cirDef = await compiler(path.join(__dirname, "circuits", "escalarmulw4table_test3.circom"));
2018-10-21 20:51:38 +03:00
// console.log(JSON.stringify(cirDef, null, 1));
// assert.equal(cirDef.nVars, 2);
2018-11-11 21:52:07 +03:00
const circuit = new snarkjs.Circuit(cirDef);
2018-10-21 20:51:38 +03:00
console.log("NConstrains: " + circuit.nConstraints);
const w = circuit.calculateWitness({});
2018-11-11 21:52:07 +03:00
let g = [snarkjs.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
snarkjs.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")]
2018-10-21 20:51:38 +03:00
for (let i=0; i<12;i++) {
g = addPoint(g,g);
}
2018-11-11 21:52:07 +03:00
dbl= [snarkjs.bigInt("0"), snarkjs.bigInt("1")];
2018-10-21 20:51:38 +03:00
for (let i=0; i<16; i++) {
const xout1 = w[circuit.getSignalIdx(`main.out[${i}][0]`)];
const yout1 = w[circuit.getSignalIdx(`main.out[${i}][1]`)];
/*
console.log(xout1.toString());
console.log(yout1.toString());
console.log(dbl[0]);
console.log(dbl[1]);
*/
assert(xout1.equals(dbl[0]));
assert(yout1.equals(dbl[1]));
dbl = addPoint([xout1, yout1],g);
}
});
it("Should exponentiate g^31", async () => {
2018-11-11 21:52:07 +03:00
const cirDef = await compiler(path.join(__dirname, "circuits", "escalarmul_test.circom"));
2018-10-21 20:51:38 +03:00
// console.log(JSON.stringify(cirDef, null, 1));
// assert.equal(cirDef.nVars, 2);
2018-11-11 21:52:07 +03:00
const circuit = new snarkjs.Circuit(cirDef);
2018-10-21 20:51:38 +03:00
console.log("NConstrains: " + circuit.nConstraints);
const w = circuit.calculateWitness({"in": 31});
assert(circuit.checkWitness(w));
2018-11-11 21:52:07 +03:00
let g = [snarkjs.bigInt("17777552123799933955779906779655732241715742912184938656739573121738514868268"),
snarkjs.bigInt("2626589144620713026669568689430873010625803728049924121243784502389097019475")]
2018-10-21 20:51:38 +03:00
let c = [0n, 1n];
for (let i=0; i<31;i++) {
c = addPoint(c,g);
}
const xout = w[circuit.getSignalIdx(`main.out[0]`)];
const yout = w[circuit.getSignalIdx(`main.out[1]`)];
/*
console.log(xout.toString());
console.log(yout.toString());
*/
assert(xout.equals(c[0]));
assert(yout.equals(c[1]));
console.log("-------")
const w2 = circuit.calculateWitness({"in": (1n<<252n)+1n});
const xout2 = w2[circuit.getSignalIdx(`main.out[0]`)];
const yout2 = w2[circuit.getSignalIdx(`main.out[1]`)];
c = [g[0], g[1]];
for (let i=0; i<252;i++) {
c = addPoint(c,c);
}
c = addPoint(c,g);
/*
console.log(xout2.toString());
console.log(yout2.toString());
console.log(c[0].toString());
console.log(c[1].toString());
*/
assert(xout2.equals(c[0]));
assert(yout2.equals(c[1]));
}).timeout(10000000);
it("Number of constrains for 256 bits", async () => {
2018-11-11 21:52:07 +03:00
const cirDef = await compiler(path.join(__dirname, "circuits", "escalarmul_test_min.circom"));
2018-10-21 20:51:38 +03:00
2018-11-11 21:52:07 +03:00
const circuit = new snarkjs.Circuit(cirDef);
2018-10-21 20:51:38 +03:00
console.log("NConstrains: " + circuit.nConstraints);
}).timeout(10000000);
});