Struct schnorrkel::vrf::VRFInOut [−][src]
pub struct VRFInOut { pub input: RistrettoBoth, pub output: RistrettoBoth, }
VRF input and output paired together, possibly unverified.
Internally, we keep both RistrettoPoint
and CompressedRistretto
forms using RistrettoBoth
.
Fields
input: RistrettoBoth
VRF input point
output: RistrettoBoth
VRF output point
Implementations
impl VRFInOut
[src]
impl VRFInOut
[src]pub fn as_output_bytes(&self) -> &[u8; 32]
[src]
VRF output point bytes for serialization.
pub fn to_output(&self) -> VRFOutput
[src]
VRF output point bytes for serialization.
pub fn commit<T: SigningTranscript>(&self, t: &mut T)
[src]
Commit VRF input and output to a transcript.
We commit both the input and output to provide the 2Hash-DH construction from Theorem 2 on page 32 in appendix C of “Ouroboros Praos: An adaptively-secure, semi-synchronous proof-of-stake blockchain” by Bernardo David, Peter Gazi, Aggelos Kiayias, and Alexander Russell.
We use this construction both for the VRF usage methods
VRFInOut::make_*
as well as for signer side batching.
pub fn make_bytes<B: Default + AsMut<[u8]>>(&self, context: &[u8]) -> B
[src]
Raw bytes output from the VRF.
If you are not the signer then you must verify the VRF before calling this method.
If called with distinct contexts then outputs should be independent.
We incorporate both the input and output to provide the 2Hash-DH construction from Theorem 2 on page 32 in appendex C of “Ouroboros Praos: An adaptively-secure, semi-synchronous proof-of-stake blockchain” by Bernardo David, Peter Gazi, Aggelos Kiayias, and Alexander Russell.
pub fn make_rng<R: SeedableRng>(&self, context: &[u8]) -> R
[src]
VRF output converted into any SeedableRng
.
If you are not the signer then you must verify the VRF before calling this method.
We expect most users would prefer the less generic VRFInOut::make_chacharng
method.
pub fn make_merlin_rng(&self, context: &[u8]) -> TranscriptRng
[src]
VRF output converted into Merlin’s Keccek based Rng
.
If you are not the signer then you must verify the VRF before calling this method.
We think this might be marginally slower than ChaChaRng
when considerable output is required, but it should reduce
the final linked binary size slightly, and improves domain
separation.
Trait Implementations
impl PartialOrd<VRFInOut> for VRFInOut
[src]
impl PartialOrd<VRFInOut> for VRFInOut
[src]