1616//!
1717
1818use core:: ptr;
19- use core:: ops :: Deref ;
19+ use core:: borrow :: Borrow ;
2020
2121use key:: { SecretKey , PublicKey } ;
2222use ffi:: { self , CPtr } ;
@@ -39,90 +39,18 @@ use secp256k1_sys::types::{c_int, c_uchar, c_void};
3939/// assert_eq!(sec1, sec2);
4040/// # }
4141// ```
42- #[ derive( Copy , Clone ) ]
43- pub struct SharedSecret {
44- data : [ u8 ; 256 ] ,
45- len : usize ,
46- }
47- impl_raw_debug ! ( SharedSecret ) ;
48-
49-
50- // This implementes `From<N>` for all `[u8; N]` arrays from 128bits(16 byte) to 2048bits allowing known hash lengths.
51- // Lower than 128 bits isn't resistant to collisions any more.
52- impl_from_array_len ! ( SharedSecret , 256 , ( 16 20 28 32 48 64 96 128 256 ) ) ;
53-
54- impl SharedSecret {
55-
56- /// Creates an empty `SharedSecret`.
57- pub ( crate ) fn empty ( ) -> SharedSecret {
58- SharedSecret {
59- data : [ 0u8 ; 256 ] ,
60- len : 0 ,
61- }
62- }
63-
64- /// Gets a pointer to the underlying data with the specified capacity.
65- pub ( crate ) fn get_data_mut_ptr ( & mut self ) -> * mut u8 {
66- self . data . as_mut_ptr ( )
67- }
68-
69- /// Gets the capacity of the underlying data buffer.
70- pub fn capacity ( & self ) -> usize {
71- self . data . len ( )
72- }
73-
74- /// Gets the len of the used data.
75- pub fn len ( & self ) -> usize {
76- self . len
77- }
78-
79- /// Returns true if the underlying data buffer is empty.
80- pub fn is_empty ( & self ) -> bool {
81- self . data . is_empty ( )
82- }
83-
84- /// Sets the length of the object.
85- pub ( crate ) fn set_len ( & mut self , len : usize ) {
86- debug_assert ! ( len <= self . data. len( ) ) ;
87- self . len = len;
88- }
89- }
90-
91- impl PartialEq for SharedSecret {
92- fn eq ( & self , other : & SharedSecret ) -> bool {
93- self . as_ref ( ) == other. as_ref ( )
94- }
95- }
96-
97- impl AsRef < [ u8 ] > for SharedSecret {
98- fn as_ref ( & self ) -> & [ u8 ] {
99- & self . data [ ..self . len ]
100- }
101- }
102-
103- impl Deref for SharedSecret {
104- type Target = [ u8 ] ;
105- fn deref ( & self ) -> & [ u8 ] {
106- & self . data [ ..self . len ]
107- }
108- }
109-
110-
111- unsafe extern "C" fn c_callback ( output : * mut c_uchar , x : * const c_uchar , y : * const c_uchar , _data : * mut c_void ) -> c_int {
112- ptr:: copy_nonoverlapping ( x, output, 32 ) ;
113- ptr:: copy_nonoverlapping ( y, output. offset ( 32 ) , 32 ) ;
114- 1
115- }
42+ #[ derive( Copy , Clone , Debug , PartialEq , Eq , PartialOrd , Ord , Hash ) ]
43+ pub struct SharedSecret ( [ u8 ; 32 ] ) ;
11644
11745impl SharedSecret {
11846 /// Creates a new shared secret from a pubkey and secret key.
11947 #[ inline]
12048 pub fn new ( point : & PublicKey , scalar : & SecretKey ) -> SharedSecret {
121- let mut ss = SharedSecret :: empty ( ) ;
49+ let mut buf = [ 0u8 ; 32 ] ;
12250 let res = unsafe {
12351 ffi:: secp256k1_ecdh (
12452 ffi:: secp256k1_context_no_precomp,
125- ss . get_data_mut_ptr ( ) ,
53+ buf . as_mut_ptr ( ) ,
12654 point. as_c_ptr ( ) ,
12755 scalar. as_c_ptr ( ) ,
12856 ffi:: secp256k1_ecdh_hash_function_default,
@@ -132,13 +60,21 @@ impl SharedSecret {
13260 // The default `secp256k1_ecdh_hash_function_default` should always return 1.
13361 // and the scalar was verified to be valid(0 > scalar > group_order) via the type system
13462 debug_assert_eq ! ( res, 1 ) ;
135- ss. set_len ( 32 ) ; // The default hash function is SHA256, which is 32 bytes long.
136- ss
63+ SharedSecret ( buf)
64+ }
65+ }
66+
67+ impl Borrow < [ u8 ] > for SharedSecret {
68+ fn borrow ( & self ) -> & [ u8 ] {
69+ & self . 0
13770 }
13871}
13972
14073/// Creates a shared point from public key and secret key.
14174///
75+ /// **Important: use of a strong cryptographic hash function may be critical to security! Do NOT use
76+ /// unless you understand cryptographical implications.** If not, use SharedSecret instead.
77+ ///
14278/// Can be used like `SharedSecret` but caller is responsible for then hashing the returned buffer.
14379/// This allows for the use of a custom hash function since `SharedSecret` uses SHA256.
14480///
@@ -183,6 +119,12 @@ pub fn shared_secret_point(point: &PublicKey, scalar: &SecretKey) -> [u8; 64] {
183119 xy
184120}
185121
122+ unsafe extern "C" fn c_callback ( output : * mut c_uchar , x : * const c_uchar , y : * const c_uchar , _data : * mut c_void ) -> c_int {
123+ ptr:: copy_nonoverlapping ( x, output, 32 ) ;
124+ ptr:: copy_nonoverlapping ( y, output. offset ( 32 ) , 32 ) ;
125+ 1
126+ }
127+
186128#[ cfg( test) ]
187129#[ allow( unused_imports) ]
188130mod tests {
0 commit comments