-
Notifications
You must be signed in to change notification settings - Fork 12
/
keys.go
77 lines (64 loc) · 1.69 KB
/
keys.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
package main
import (
"crypto/ed25519"
crand "crypto/rand"
"crypto/sha256"
"errors"
"fmt"
"io"
libp2p "github.com/libp2p/go-libp2p/core/crypto"
peer "github.com/libp2p/go-libp2p/core/peer"
"github.com/mr-tron/base58"
"golang.org/x/crypto/hkdf"
)
const seedBytes = 32
// newSeed returns a b58 encoded random seed.
func newSeed() (string, error) {
bs := make([]byte, seedBytes)
_, err := io.ReadFull(crand.Reader, bs)
if err != nil {
return "", err
}
return base58.Encode(bs), nil
}
// deriveKey derives libp2p keys from a b58-encoded seed.
func deriveKey(b58secret string, info []byte) (libp2p.PrivKey, error) {
secret, err := base58.Decode(b58secret)
if err != nil {
return nil, err
}
if len(secret) < seedBytes {
return nil, errors.New("derivation seed is too short")
}
hash := sha256.New
hkdf := hkdf.New(hash, secret, nil, info)
keySeed := make([]byte, ed25519.SeedSize)
if _, err := io.ReadFull(hkdf, keySeed); err != nil {
return nil, err
}
key := ed25519.NewKeyFromSeed(keySeed)
return libp2p.UnmarshalEd25519PrivateKey(key)
}
// derivePeerIDs derives the peer IDs of all the peers with the same seed up to
// maxIndex. Our peer ID (with index 'ourIndex') is not generated.
func derivePeerIDs(seed string, ourIndex int, maxIndex int) ([]peer.ID, error) {
peerIDs := []peer.ID{}
for i := 0; i <= maxIndex; i++ {
if i == ourIndex {
continue
}
peerPriv, err := deriveKey(seed, deriveKeyInfo(i))
if err != nil {
return nil, err
}
pid, err := peer.IDFromPrivateKey(peerPriv)
if err != nil {
return nil, err
}
peerIDs = append(peerIDs, pid)
}
return peerIDs, nil
}
func deriveKeyInfo(index int) []byte {
return []byte(fmt.Sprintf("rainbow-%d", index))
}