1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
mod expander;
use crate::{Field, PrimeField};
use ark_std::vec::Vec;
use digest::DynDigest;
use expander::Expander;
use self::expander::ExpanderXmd;
pub trait HashToField<F: Field>: Sized {
fn new(domain: &[u8]) -> Self;
fn hash_to_field(&self, msg: &[u8], count: usize) -> Vec<F>;
}
pub struct DefaultFieldHasher<H: Default + DynDigest + Clone, const SEC_PARAM: usize = 128> {
expander: ExpanderXmd<H>,
len_per_base_elem: usize,
}
impl<F: Field, H: Default + DynDigest + Clone, const SEC_PARAM: usize> HashToField<F>
for DefaultFieldHasher<H, SEC_PARAM>
{
fn new(dst: &[u8]) -> Self {
let len_per_base_elem = get_len_per_elem::<F, SEC_PARAM>();
let expander = ExpanderXmd {
hasher: H::default(),
dst: dst.to_vec(),
block_size: len_per_base_elem,
};
DefaultFieldHasher {
expander,
len_per_base_elem,
}
}
fn hash_to_field(&self, message: &[u8], count: usize) -> Vec<F> {
let m = F::extension_degree() as usize;
let len_in_bytes = count * m * self.len_per_base_elem;
let uniform_bytes = self.expander.expand(message, len_in_bytes);
let mut output = Vec::with_capacity(count);
let mut base_prime_field_elems = Vec::with_capacity(m);
for i in 0..count {
base_prime_field_elems.clear();
for j in 0..m {
let elm_offset = self.len_per_base_elem * (j + i * m);
let val = F::BasePrimeField::from_be_bytes_mod_order(
&uniform_bytes[elm_offset..][..self.len_per_base_elem],
);
base_prime_field_elems.push(val);
}
let f = F::from_base_prime_field_elems(&base_prime_field_elems).unwrap();
output.push(f);
}
output
}
}
fn get_len_per_elem<F: Field, const SEC_PARAM: usize>() -> usize {
let base_field_size_in_bits = F::BasePrimeField::MODULUS_BIT_SIZE as usize;
let base_field_size_with_security_padding_in_bits = base_field_size_in_bits + SEC_PARAM;
let bytes_per_base_field_elem =
((base_field_size_with_security_padding_in_bits + 7) / 8) as u64;
bytes_per_base_field_elem as usize
}