server.hpp 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538
  1. #ifndef __PRSONA_SERVER_HPP
  2. #define __PRSONA_SERVER_HPP
  3. #include <vector>
  4. #include "BGN.hpp"
  5. #include "Curvepoint.hpp"
  6. #include "Bipoint.hpp"
  7. #include "base.hpp"
  8. #include "EGCiphertext.hpp"
  9. #include "proof.hpp"
  10. class PrsonaServer : public PrsonaBase {
  11. public:
  12. // CONSTRUCTORS
  13. PrsonaServer(
  14. size_t numServers);
  15. PrsonaServer(
  16. size_t numServers,
  17. const BGN& other_bgn);
  18. // BASIC PUBLIC SYSTEM INFO GETTERS
  19. BGNPublicKey get_bgn_public_key() const;
  20. size_t get_num_clients() const;
  21. size_t get_num_servers() const;
  22. Twistpoint get_fresh_generator(
  23. std::vector<Proof>& pi
  24. ) const;
  25. // FRESH GENERATOR CALCULATION
  26. Twistpoint add_curr_seed_to_generator(
  27. std::vector<Proof>& pi,
  28. const Twistpoint& currGenerator
  29. ) const;
  30. Twistpoint add_next_seed_to_generator(
  31. std::vector<Proof>& pi,
  32. const Twistpoint& currGenerator
  33. ) const;
  34. Twistpoint add_rand_seed_to_generator(
  35. std::vector<Proof>& pi,
  36. const Twistpoint& currGenerator
  37. ) const;
  38. // ENCRYPTED DATA GETTERS
  39. std::vector<TwistBipoint> get_current_votes_by(
  40. Proof& pi,
  41. const Twistpoint& shortTermPublicKey
  42. ) const;
  43. std::vector<std::vector<TwistBipoint>> get_all_current_votes(
  44. Proof& pi
  45. ) const;
  46. EGCiphertext get_current_user_encrypted_tally(
  47. Proof& pi,
  48. const Twistpoint& shortTermPublicKey
  49. ) const;
  50. CurveBipoint get_current_server_encrypted_tally(
  51. Proof& pi,
  52. const Twistpoint& shortTermPublicKey
  53. ) const;
  54. std::vector<Twistpoint> get_current_pseudonyms(
  55. Proof& pi
  56. ) const;
  57. std::vector<Twistpoint> get_current_pseudonyms() const;
  58. // PROOF COMMITMENT GETTERS
  59. Proof get_vote_row_commitment(
  60. const Twistpoint& request
  61. ) const;
  62. Proof get_vote_matrix_commitment() const;
  63. Proof get_user_tally_commitment(
  64. const Twistpoint& request
  65. ) const;
  66. Proof get_server_tally_commitment(
  67. const Twistpoint& request
  68. ) const;
  69. Proof get_pseudonyms_commitment() const;
  70. void print_current_commitments() const;
  71. // CLIENT INTERACTIONS
  72. void add_new_client(
  73. std::vector<Proof>& proofOfValidAddition,
  74. const Proof& proofOfValidKey,
  75. const Twistpoint& shortTermPublicKey);
  76. bool receive_vote(
  77. const std::vector<Proof>& pi,
  78. const std::vector<TwistBipoint>& newVotes,
  79. const Twistpoint& shortTermPublicKey);
  80. void print_scores(
  81. const std::vector<CurveBipoint>& scores);
  82. // CONSTRUCTOR HELPERS
  83. const BGN& get_bgn_details() const;
  84. bool initialize_fresh_generator(
  85. const std::vector<Proof>& pi,
  86. const Twistpoint& firstGenerator);
  87. bool set_EG_blind_generator(
  88. const std::vector<Proof>& pi,
  89. const Twistpoint& currGenerator);
  90. // EPOCH ROUNDS
  91. void build_up_midway_pseudonyms(
  92. std::vector<std::vector<std::vector<Proof>>>& pi,
  93. std::vector<std::vector<std::vector<Twistpoint>>>& permutationCommits,
  94. std::vector<std::vector<std::vector<Twistpoint>>>& freshPseudonymCommits,
  95. std::vector<std::vector<std::vector<Twistpoint>>>& freshPseudonymSeedCommits,
  96. std::vector<std::vector<std::vector<CurveBipoint>>>& serverTallyCommits,
  97. std::vector<std::vector<std::vector<std::vector<TwistBipoint>>>>& partwayVoteMatrixCommits,
  98. std::vector<std::vector<std::vector<std::vector<TwistBipoint>>>>& finalVoteMatrixCommits,
  99. Twistpoint& nextGenerator);
  100. void break_down_midway_pseudonyms(
  101. const std::vector<Proof>& generatorProof,
  102. std::vector<std::vector<std::vector<Proof>>>& pi,
  103. std::vector<std::vector<std::vector<Twistpoint>>>& permutationCommits,
  104. std::vector<std::vector<std::vector<Twistpoint>>>& freshPseudonymCommits,
  105. std::vector<std::vector<std::vector<Twistpoint>>>& freshPseudonymSeedCommits,
  106. std::vector<std::vector<std::vector<CurveBipoint>>>& serverTallyCommits,
  107. std::vector<std::vector<std::vector<std::vector<TwistBipoint>>>>& partwayVoteMatrixCommits,
  108. std::vector<std::vector<std::vector<std::vector<TwistBipoint>>>>& finalVoteMatrixCommits,
  109. std::vector<std::vector<std::vector<Twistpoint>>>& userTallyMaskCommits,
  110. std::vector<std::vector<std::vector<Twistpoint>>>& userTallyMessageCommits,
  111. std::vector<std::vector<std::vector<Twistpoint>>>& userTallySeedCommits,
  112. const Twistpoint& nextGenerator);
  113. bool accept_epoch_updates(
  114. const std::vector<std::vector<Proof>>& pi,
  115. const std::vector<std::vector<Twistpoint>>& permutationCommits,
  116. const std::vector<std::vector<Twistpoint>>& freshPseudonymCommits,
  117. const std::vector<std::vector<Twistpoint>>& freshPseudonymSeedCommits,
  118. const std::vector<std::vector<CurveBipoint>>& serverTallyCommits,
  119. const std::vector<std::vector<std::vector<TwistBipoint>>>& partwayVoteMatrixCommits,
  120. const std::vector<std::vector<std::vector<TwistBipoint>>>& finalVoteMatrixCommits,
  121. const std::vector<std::vector<Twistpoint>>& userTallyMaskCommits,
  122. const std::vector<std::vector<Twistpoint>>& userTallyMessageCommits,
  123. const std::vector<std::vector<Twistpoint>>& userTallySeedCommits,
  124. const Twistpoint& nextGenerator,
  125. bool doUserTallies);
  126. // DATA MAINTENANCE
  127. void export_new_user_update(
  128. std::vector<CurveBipoint>& otherPreviousVoteTallies,
  129. std::vector<Twistpoint>& otherCurrentPseudonyms,
  130. std::vector<EGCiphertext>& otherCurrentUserEncryptedTallies,
  131. std::vector<std::vector<TwistBipoint>>& otherVoteMatrix
  132. ) const;
  133. bool import_new_user_update(
  134. const std::vector<Proof>& pi,
  135. const std::vector<CurveBipoint>& otherPreviousVoteTallies,
  136. const std::vector<Twistpoint>& otherCurrentPseudonyms,
  137. const std::vector<EGCiphertext>& otherCurrentUserEncryptedTallies,
  138. const std::vector<std::vector<TwistBipoint>>& otherVoteMatrix);
  139. // SCORE TALLYING
  140. std::vector<Scalar> tally_scores();
  141. Scalar get_max_possible_score();
  142. void receive_tallied_scores(
  143. const std::vector<EGCiphertext>& userTallyScores,
  144. const std::vector<CurveBipoint>& serverTallyScores);
  145. void encrypt(
  146. CurveBipoint& element,
  147. const Scalar& value);
  148. // MULTI-THREADING
  149. friend void generate_permutation_commitment_r(
  150. const void *a,
  151. void *b,
  152. const void *c,
  153. void *d);
  154. friend void generate_pseudonym_commitment_r(
  155. const void *a,
  156. void *b,
  157. const void *c,
  158. const void *d,
  159. void *e,
  160. void *f);
  161. friend void generate_server_tally_commitment_r(
  162. const void *a,
  163. void *b,
  164. const void *c,
  165. void *d);
  166. friend void generate_matrix_commitment_r(
  167. const void *a,
  168. void *b,
  169. void *c,
  170. void *d,
  171. const void *e,
  172. const void *f,
  173. void *g,
  174. void *h);
  175. friend void generate_user_tally_commitment_r(
  176. const void *a,
  177. const void *b,
  178. const void *c,
  179. const void *d,
  180. const void *e,
  181. void *f,
  182. void *g,
  183. void *h,
  184. void *i,
  185. void *j,
  186. void *k);
  187. friend void generate_permutation_proof_r(
  188. const void *a,
  189. void *b,
  190. const void *c,
  191. const void *d,
  192. const void *e);
  193. friend void generate_pseudonym_proof_r(
  194. const void *a,
  195. void *b,
  196. const void *c,
  197. const void *d,
  198. const void *e,
  199. const void *f,
  200. const void *g,
  201. const void *h,
  202. const void *i,
  203. const void *j);
  204. friend void generate_server_tally_proof_r(
  205. const void *a,
  206. void *b,
  207. const void *c,
  208. const void *d,
  209. const void *e,
  210. const void *f,
  211. const void *g,
  212. const void *h,
  213. const void *i,
  214. const void *j);
  215. friend void generate_first_half_matrix_proof_r(
  216. const void *a,
  217. void *b,
  218. const void *c,
  219. const void *d,
  220. const void *e,
  221. const void *f,
  222. const void *g,
  223. const void *h);
  224. friend void generate_second_half_matrix_proof_r(
  225. const void *a,
  226. void *b,
  227. const void *c,
  228. const void *d,
  229. const void *e,
  230. const void *f,
  231. const void *g,
  232. const void *h);
  233. friend void generate_user_tally_proof_r(
  234. const void *a,
  235. void *b,
  236. const void *c,
  237. const void *d,
  238. const void *e,
  239. const void *f,
  240. const void *g,
  241. const void *h,
  242. const void *i,
  243. const void *j,
  244. const void *k,
  245. const void *l,
  246. const void *m,
  247. const void *n);
  248. friend void generate_tensor_r(
  249. const void *a,
  250. void *b,
  251. const void *c,
  252. const void *d,
  253. const void *e,
  254. const void *f,
  255. const void *g,
  256. const void *h,
  257. const void *i,
  258. const void *j);
  259. friend void verify_permutation_r(
  260. const void *a,
  261. void *b,
  262. const void *c,
  263. const void *d);
  264. friend void verify_pseudonym_r(
  265. const void *a,
  266. void *b,
  267. const void *c,
  268. const void *d,
  269. const void *e,
  270. const void *f,
  271. const void *g);
  272. friend void verify_server_tally_r(
  273. const void *a,
  274. void *b,
  275. const void *c,
  276. const void *d,
  277. const void *e,
  278. const void *f,
  279. const void *g,
  280. const void *h);
  281. friend void verify_first_half_matrix_r(
  282. const void *a,
  283. void *b,
  284. const void *c,
  285. const void *d,
  286. const void *e,
  287. const void *f,
  288. const void *g);
  289. friend void verify_second_half_matrix_r(
  290. const void *a,
  291. void *b,
  292. const void *c,
  293. const void *d,
  294. const void *e,
  295. const void *f,
  296. const void *g);
  297. friend void verify_user_tally_r(
  298. const void *a,
  299. void *b,
  300. const void *c,
  301. const void *d,
  302. const void *e,
  303. const void *f,
  304. const void *g,
  305. const void *h,
  306. const void *i,
  307. const void *j);
  308. friend void verify_tensor_r(
  309. const void *a,
  310. void *b,
  311. const void *c,
  312. const void *d,
  313. const void *e,
  314. const void *f,
  315. const void *g,
  316. const void *h);
  317. private:
  318. // constants for servers
  319. const size_t numServers;
  320. // Identical between all servers (but collaboratively constructed)
  321. BGN bgnSystem;
  322. // Private; different for each server
  323. Scalar currentSeed;
  324. Scalar nextSeed;
  325. // The actual data, which is collaboratively updated by all servers
  326. std::vector<Proof> currentGeneratorProof;
  327. Twistpoint currentFreshGenerator;
  328. std::vector<CurveBipoint> previousVoteTallies;
  329. std::vector<Twistpoint> currentPseudonyms;
  330. std::vector<EGCiphertext> currentUserEncryptedTallies;
  331. std::vector<std::vector<TwistBipoint>> voteMatrix;
  332. /**
  333. * NOTE: voteMatrix structure:
  334. * Each element represents a vote by <rowID> applied to <colID>.
  335. * The outer vector is a vector of rows and the inner vector is
  336. * a vector of encrypted votes.
  337. */
  338. // An imaginary class; it's just used right now to coordinate servers
  339. // in memory instead of via network action.
  340. friend class PrsonaServerEntity;
  341. // EPOCH HELPERS
  342. std::vector<std::vector<Proof>> epoch_calculations(
  343. std::vector<std::vector<Twistpoint>>& permutationCommits,
  344. std::vector<std::vector<Twistpoint>>& freshPseudonymCommits,
  345. std::vector<std::vector<Twistpoint>>& freshPseudonymSeedCommits,
  346. std::vector<std::vector<CurveBipoint>>& serverTallyCommits,
  347. std::vector<std::vector<std::vector<TwistBipoint>>>& partwayVoteMatrixCommits,
  348. std::vector<std::vector<std::vector<TwistBipoint>>>& finalVoteMatrixCommits,
  349. std::vector<std::vector<Twistpoint>>& userTallyMaskCommits,
  350. std::vector<std::vector<Twistpoint>>& userTallyMessageCommits,
  351. std::vector<std::vector<Twistpoint>>& userTallySeedCommits,
  352. const Scalar& power,
  353. const Twistpoint& nextGenerator,
  354. bool doUserTallies);
  355. std::vector<std::vector<Scalar>> generate_permutation_matrix(
  356. const Scalar& reorderSeed
  357. ) const;
  358. std::vector<std::vector<Twistpoint>> generate_commitment_matrix(
  359. const std::vector<std::vector<Scalar>>& permutations,
  360. std::vector<std::vector<Scalar>>& seeds
  361. ) const;
  362. std::vector<std::vector<Twistpoint>> generate_pseudonym_matrix(
  363. const std::vector<std::vector<Scalar>>& permutations,
  364. const Scalar& power,
  365. std::vector<std::vector<Scalar>>& seeds,
  366. std::vector<std::vector<Twistpoint>>& seedCommits
  367. ) const;
  368. std::vector<std::vector<CurveBipoint>> generate_server_tally_matrix(
  369. const std::vector<std::vector<Scalar>>& permutations,
  370. std::vector<std::vector<Scalar>>& seeds
  371. ) const;
  372. std::vector<std::vector<std::vector<TwistBipoint>>> generate_vote_tensor(
  373. const std::vector<std::vector<Scalar>>& permutations,
  374. const std::vector<std::vector<TwistBipoint>>& currVoteMatrix,
  375. std::vector<std::vector<std::vector<Scalar>>>& seeds,
  376. bool inverted
  377. ) const;
  378. std::vector<std::vector<TwistBipoint>> calculate_next_vote_matrix(
  379. const std::vector<std::vector<std::vector<TwistBipoint>>>& voteTensor
  380. ) const;
  381. void generate_vote_tensor_proofs(
  382. std::vector<std::vector<Proof>>& pi,
  383. const std::vector<std::vector<Scalar>>& permutations,
  384. const std::vector<std::vector<Scalar>>& permutationSeeds,
  385. const std::vector<std::vector<std::vector<Scalar>>>& matrixSeeds,
  386. const std::vector<std::vector<TwistBipoint>>& currMatrix,
  387. const std::vector<std::vector<Twistpoint>>& permutationCommits,
  388. const std::vector<std::vector<std::vector<TwistBipoint>>>& matrixCommits,
  389. bool inverted
  390. ) const;
  391. bool verify_vote_tensor_proofs(
  392. const std::vector<std::vector<Proof>>& pi,
  393. size_t start_offset,
  394. const std::vector<std::vector<TwistBipoint>>& currMatrix,
  395. const std::vector<std::vector<Twistpoint>>& permutationCommits,
  396. const std::vector<std::vector<std::vector<TwistBipoint>>>& matrixCommits,
  397. bool inverted
  398. ) const;
  399. void generate_user_tally_matrix(
  400. const std::vector<std::vector<Scalar>>& permutations,
  401. const Scalar& power,
  402. const Twistpoint& nextGenerator,
  403. const std::vector<Twistpoint>& currPseudonyms,
  404. std::vector<Twistpoint>& masks,
  405. std::vector<std::vector<Twistpoint>>& maskCommits,
  406. std::vector<Twistpoint>& messages,
  407. std::vector<std::vector<Twistpoint>>& messageCommits,
  408. std::vector<std::vector<Scalar>>& userTallySeeds,
  409. std::vector<std::vector<Twistpoint>>& userTallySeedCommits
  410. ) const;
  411. template <typename T>
  412. std::vector<std::vector<T>> generate_reordered_plus_power_matrix(
  413. const std::vector<std::vector<Scalar>>& permutations,
  414. const Scalar& power,
  415. const std::vector<T>& oldValues,
  416. std::vector<std::vector<Scalar>>& seeds,
  417. std::vector<std::vector<Twistpoint>>& seedCommits,
  418. const T& h
  419. ) const;
  420. template <typename T>
  421. std::vector<std::vector<T>> generate_reordered_matrix(
  422. const std::vector<std::vector<Scalar>>& permutations,
  423. const std::vector<T>& oldValues,
  424. std::vector<std::vector<Scalar>>& seeds,
  425. const T& h,
  426. bool cancelOut
  427. ) const;
  428. template <typename T>
  429. std::vector<std::vector<T>> transpose_matrix(
  430. const std::vector<std::vector<T>>& input
  431. ) const;
  432. std::vector<size_t> sort_data(
  433. const std::vector<Twistpoint>& inputs
  434. ) const;
  435. // A helper class for "ordering" data and for binary search
  436. struct SortingType {
  437. Twistpoint pseudonym;
  438. size_t index;
  439. bool operator<( const SortingType& rhs ) const
  440. { return pseudonym < rhs.pseudonym; }
  441. };
  442. template <typename T>
  443. T encrypt(
  444. const T& g,
  445. const T& h,
  446. const Scalar& plaintext,
  447. const Scalar& lambda
  448. ) const;
  449. bool update_data(
  450. const std::vector<std::vector<Twistpoint>>& freshPseudonymCommits,
  451. const std::vector<std::vector<CurveBipoint>>& serverTallyCommits,
  452. const std::vector<std::vector<std::vector<TwistBipoint>>>& voteMatrixCommits,
  453. const std::vector<std::vector<Twistpoint>>& userTallyMaskCommits,
  454. const std::vector<std::vector<Twistpoint>>& userTallyMessageCommits);
  455. bool pseudonyms_sorted(
  456. const std::vector<Twistpoint> newPseudonyms
  457. ) const;
  458. // DATA SAFEKEEPING
  459. std::vector<size_t> order_data();
  460. // BINARY SEARCH
  461. size_t binary_search(
  462. const Twistpoint& index
  463. ) const;
  464. // VALID VOTE PROOFS
  465. bool verify_vote_proof(
  466. const std::vector<Proof>& pi,
  467. const std::vector<TwistBipoint>& oldVotes,
  468. const std::vector<TwistBipoint>& newVotes,
  469. const Twistpoint& shortTermPublicKey
  470. ) const;
  471. };
  472. #endif