Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions ooniauth-core/benches/bench_client.rs
Original file line number Diff line number Diff line change
Expand Up @@ -96,6 +96,7 @@ fn bench_user_submit_request(c: &mut Criterion) {
let today = ServerState::today();
let age_range = (today - 30)..(today + 1);
let measurement_count_range = 0..100;
let measurement_hash = [1u8; 32];

c.bench_function("user.submit_request", |b| {
b.iter_batched(
Expand All @@ -112,6 +113,7 @@ fn bench_user_submit_request(c: &mut Criterion) {
&mut rng,
"US".to_string(),
"AS1234".to_string(),
&measurement_hash,
age_range.clone(),
measurement_count_range.clone(),
)
Expand All @@ -129,6 +131,7 @@ fn bench_user_handle_submit_response(c: &mut Criterion) {
let today = ServerState::today();
let age_range = (today - 30)..(today + 1);
let measurement_count_range = 0..100;
let measurement_hash = [1u8; 32];

c.bench_function("user.handle_submit_response", |b| {
b.iter_batched(
Expand All @@ -144,6 +147,7 @@ fn bench_user_handle_submit_response(c: &mut Criterion) {
&mut rng,
"US".to_string(),
"AS1234".to_string(),
&measurement_hash,
age_range.clone(),
measurement_count_range.clone(),
)
Expand All @@ -155,6 +159,7 @@ fn bench_user_handle_submit_response(c: &mut Criterion) {
&nym,
"US",
"AS1234",
&measurement_hash,
age_range.clone(),
measurement_count_range.clone(),
)
Expand Down
3 changes: 3 additions & 0 deletions ooniauth-core/benches/bench_server.rs
Original file line number Diff line number Diff line change
Expand Up @@ -38,11 +38,13 @@ fn bench_submit(c: &mut Criterion) {

let age_range = (today - 30)..(today + 1);
let msm_range = 0..100;
let measurement_hash = [1u8; 32];
let ((req, _), nym) = user
.submit_request(
&mut rng,
cc.into(),
asn.into(),
&measurement_hash,
age_range.clone(),
msm_range.clone(),
)
Expand All @@ -54,6 +56,7 @@ fn bench_submit(c: &mut Criterion) {
black_box(&nym),
black_box(cc),
black_box(asn),
black_box(&measurement_hash),
black_box(age_range.clone()),
black_box(msm_range.clone()),
)
Expand Down
7 changes: 7 additions & 0 deletions ooniauth-core/examples/basic_usage.rs
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
use std::time::Instant;

use ooniauth_core::submit::submit_measurement_hash;
use ooniauth_core::{scalar_u32, ServerState, UserState};
use tracing_forest::util::LevelFilter;
use tracing_forest::ForestLayer;
Expand Down Expand Up @@ -97,12 +98,14 @@ fn main() -> Result<(), Box<dyn std::error::Error>> {
let today = ServerState::today();
let age_range = (today - 30)..(today + 1);
let measurement_count_range = 0..100;
let measurement_hash = submit_measurement_hash(b"measurement:US:AS1234");

let now = Instant::now();
let ((submit_request, submit_state), nym) = user.submit_request(
&mut rng,
probe_cc.clone(),
probe_asn.clone(),
&measurement_hash,
age_range.clone(),
measurement_count_range.clone(),
)?;
Expand Down Expand Up @@ -130,6 +133,7 @@ fn main() -> Result<(), Box<dyn std::error::Error>> {
&nym,
&probe_cc,
&probe_asn,
&measurement_hash,
age_range,
measurement_count_range,
)?;
Expand Down Expand Up @@ -175,12 +179,14 @@ fn main() -> Result<(), Box<dyn std::error::Error>> {

let age_range2 = (today - 30)..(today + 1);
let measurement_count_range2 = 0..100;
let measurement_hash2 = submit_measurement_hash(b"measurement:UK:AS5678");

let now = Instant::now();
let ((submit_request2, submit_state2), nym2) = user.submit_request(
&mut rng,
probe_cc2.clone(),
probe_asn2.clone(),
&measurement_hash2,
age_range2.clone(),
measurement_count_range2.clone(),
)?;
Expand All @@ -203,6 +209,7 @@ fn main() -> Result<(), Box<dyn std::error::Error>> {
&nym2,
&probe_cc2,
&probe_asn2,
&measurement_hash2,
age_range2,
measurement_count_range2,
)?;
Expand Down
2 changes: 1 addition & 1 deletion ooniauth-core/src/registration.rs
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ use rand::{CryptoRng, RngCore};
use sha2::Sha512;
use tracing::{instrument, trace};

const SESSION_ID: &[u8] = b"registration";
const SESSION_ID: &[u8] = b"ooni.org/userauth/v1/reg";

CMZ! { UserAuthCredential:
nym_id,
Expand Down
112 changes: 107 additions & 5 deletions ooniauth-core/src/submit.rs
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,29 @@ use serde::{Deserialize, Serialize};
use sha2::{Digest, Sha256, Sha512};
use tracing::{debug, instrument, trace};

const SESSION_ID: &[u8] = b"submit";
const PROBE_ID_SALT: &[u8] = b"ooni.org/userauth/v1";
const PROBE_ID_SALT: &[u8] = b"ooni.org/userauth/v1/pid";
const SUBMIT_SESSION_ID_SALT: &[u8] = b"ooni.org/v1/sid";
pub type MeasurementHash = [u8; 32];
pub type SubmitSessionId = [u8; 32];

/// Hash measurement material for submit proof binding.
pub fn submit_measurement_hash(measurement: &[u8]) -> MeasurementHash {
let measurement_hash = Sha256::digest(measurement);
let mut out = [0u8; 32];
out.copy_from_slice(&measurement_hash);
out
}

/// Derive the submit proof session ID from a 32-byte measurement hash.
pub fn submit_session_id(measurement_hash: &MeasurementHash) -> SubmitSessionId {
let mut hasher = Sha256::new();
hasher.update(SUBMIT_SESSION_ID_SALT);
hasher.update(measurement_hash);
let digest = hasher.finalize();
let mut out = [0u8; 32];
out.copy_from_slice(&digest);
out
}

muCMZProtocol!(submit<min_age_today, max_age, min_measurement_count,
max_measurement_count, @DOMAIN, @NYM>,
Expand Down Expand Up @@ -57,12 +78,21 @@ fn digest_point(point: RistrettoPoint) -> [u8; 32] {
}

impl UserState {
#[instrument(skip(self, rng, probe_cc, probe_asn, age_range, measurement_count_range))]
#[instrument(skip(
self,
rng,
probe_cc,
probe_asn,
measurement_hash,
age_range,
measurement_count_range
))]
pub fn submit_request(
&self,
rng: &mut (impl RngCore + CryptoRng),
probe_cc: String,
probe_asn: String,
measurement_hash: &MeasurementHash,
age_range: std::ops::Range<u32>,
measurement_count_range: std::ops::Range<u32>,
) -> Result<((SubmitRequest, submit::ClientState), [u8; 32]), CredentialError> {
Expand Down Expand Up @@ -153,7 +183,8 @@ impl UserState {
};

trace!("Preparing submit proof with params");
match submit::prepare(rng, SESSION_ID, Old, New, &params) {
let session_id = submit_session_id(measurement_hash);
match submit::prepare(rng, &session_id, Old, New, &params) {
Ok((core_request, client_state)) => {
debug!("Submit request prepared successfully");
let probe_id = digest_point(NYM);
Expand Down Expand Up @@ -196,6 +227,7 @@ impl ServerState {
probe_id,
probe_cc,
probe_asn,
measurement_hash,
age_range,
measurement_count_range
))]
Expand All @@ -206,6 +238,7 @@ impl ServerState {
probe_id: &[u8; 32],
probe_cc: &str,
probe_asn: &str,
measurement_hash: &MeasurementHash,
age_range: std::ops::Range<u32>,
measurement_count_range: std::ops::Range<u32>,
) -> Result<submit::Reply, CMZError> {
Expand Down Expand Up @@ -238,9 +271,10 @@ impl ServerState {

let server_sk = self.sk.clone();
let server_pp = self.pp.clone();
let session_id = submit_session_id(measurement_hash);
match submit::handle(
rng,
SESSION_ID,
&session_id,
recvreq,
move |Old: &mut UserAuthCredential, New: &mut UserAuthCredential| {
// Set the private key for the credentials - this is essential for the protocol
Expand Down Expand Up @@ -336,11 +370,13 @@ mod tests {
let today = ServerState::today();
let age_range = (today - 30)..(today + 1); // Credential valid for 30 days
let measurement_count_range = 0..100;
let measurement_hash = submit_measurement_hash(b"measurement:US:AS1234");

let result = user_state.submit_request(
rng,
probe_cc.clone(),
probe_asn.clone(),
&measurement_hash,
age_range.clone(),
measurement_count_range.clone(),
);
Expand All @@ -367,6 +403,7 @@ mod tests {
&nym,
&probe_cc,
&probe_asn,
&measurement_hash,
age_range,
measurement_count_range,
);
Expand Down Expand Up @@ -394,4 +431,69 @@ mod tests {
let new_count = scalar_u32(&updated_cred.measurement_count.unwrap()).unwrap();
assert_eq!(new_count, 1, "Measurement count should be incremented to 1");
}

#[test]
fn test_submit_request_rejects_replaced_measurement() {
let rng = &mut rand::thread_rng();

let server_state = ServerState::new(rng);
let mut user_state = UserState::new(server_state.public_parameters());

let (reg_request, reg_client_state) = user_state.request(rng).unwrap();
let reg_response = server_state.open_registration(reg_request).unwrap();
user_state
.handle_response(reg_client_state, reg_response)
.unwrap();

let probe_cc = "US".to_string();
let probe_asn = "AS1234".to_string();
let today = ServerState::today();
let age_range = (today - 30)..(today + 1);
let measurement_count_range = 0..100;
let original_measurement_hash = submit_measurement_hash(b"measurement:US:AS1234");
let replaced_measurement_hash = submit_measurement_hash(b"measurement:US:AS1234:replaced");

let ((request, _client_state), nym) = user_state
.submit_request(
rng,
probe_cc.clone(),
probe_asn.clone(),
&original_measurement_hash,
age_range.clone(),
measurement_count_range.clone(),
)
.unwrap();

assert_ne!(original_measurement_hash, replaced_measurement_hash);

let replaced_result = server_state.handle_submit(
rng,
request.clone(),
&nym,
&probe_cc,
&probe_asn,
&replaced_measurement_hash,
age_range.clone(),
measurement_count_range.clone(),
);
assert!(
replaced_result.is_err(),
"Server should reject a submit request verified against a replaced measurement"
);

let original_result = server_state.handle_submit(
rng,
request,
&nym,
&probe_cc,
&probe_asn,
&original_measurement_hash,
age_range,
measurement_count_range,
);
assert!(
original_result.is_ok(),
"Server should accept the submit request with the original measurement session ID"
);
}
}
2 changes: 1 addition & 1 deletion ooniauth-core/src/update.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ use group::Group;
use rand::{CryptoRng, RngCore};
use sha2::Sha512;

const SESSION_ID: &[u8] = b"update";
const SESSION_ID: &[u8] = b"ooni.org/userauth/v1/upd";

muCMZProtocol!(update,
Old: UserAuthCredential { nym_id: H, age: H, measurement_count: H},
Expand Down
7 changes: 7 additions & 0 deletions ooniauth-ffi/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ use std::sync::Once;
use std::time::Instant;

use ooniauth_core::registration::UserAuthCredential;
use ooniauth_core::submit::submit_measurement_hash;
use ooniauth_core::{scalar_u32, ServerState, UserState};
use tracing_forest::util::LevelFilter;
use tracing_forest::ForestLayer;
Expand Down Expand Up @@ -159,13 +160,15 @@ fn run_basic_usage_demo() -> Result<String, String> {
let today = ServerState::today();
let age_range = (today - 30)..(today + 1);
let measurement_count_range = 0..100;
let measurement_hash = submit_measurement_hash(b"measurement:US:AS1234");

let now = Instant::now();
let ((submit_request, submit_state), nym) = user
.submit_request(
&mut rng,
probe_cc.clone(),
probe_asn.clone(),
&measurement_hash,
age_range.clone(),
measurement_count_range.clone(),
)
Expand Down Expand Up @@ -193,6 +196,7 @@ fn run_basic_usage_demo() -> Result<String, String> {
&nym,
&probe_cc,
&probe_asn,
&measurement_hash,
age_range,
measurement_count_range,
)
Expand Down Expand Up @@ -234,13 +238,15 @@ fn run_basic_usage_demo() -> Result<String, String> {

let age_range2 = (today - 30)..(today + 1);
let measurement_count_range2 = 0..100;
let measurement_hash2 = submit_measurement_hash(b"measurement:UK:AS5678");

let now = Instant::now();
let ((submit_request2, submit_state2), nym2) = user
.submit_request(
&mut rng,
probe_cc2.clone(),
probe_asn2.clone(),
&measurement_hash2,
age_range2.clone(),
measurement_count_range2.clone(),
)
Expand All @@ -264,6 +270,7 @@ fn run_basic_usage_demo() -> Result<String, String> {
&nym2,
&probe_cc2,
&probe_asn2,
&measurement_hash2,
age_range2,
measurement_count_range2,
)
Expand Down
2 changes: 2 additions & 0 deletions ooniauth-py/ooniauth_py.pyi
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,7 @@ class ServerState:
request: str,
probe_cc: str,
probe_asn: str,
measurement_hash: str,
age_range: tuple[builtins.int, builtins.int],
min_measurement_count: builtins.int,
) -> str: ...
Expand Down Expand Up @@ -78,6 +79,7 @@ class UserState:
self,
probe_cc: str,
probe_asn: str,
measurement_hash: str,
age_range: tuple[builtins.int, builtins.int],
min_measurement_count: builtins.int,
) -> SubmitRequest: ...
Expand Down
Loading
Loading