Skip to content

fix: use modular inverse in deriveInterpolatingValue - #11

Open
rdubois-crypto wants to merge 1 commit into
Railgun-Community:mainfrom
ZKNoxHQ:fix/lagrange-modular-inverse
Open

fix: use modular inverse in deriveInterpolatingValue#11
rdubois-crypto wants to merge 1 commit into
Railgun-Community:mainfrom
ZKNoxHQ:fix/lagrange-modular-inverse

Conversation

@rdubois-crypto

Copy link
Copy Markdown
Collaborator

BigInt integer division truncates toward zero, so the Lagrange coefficients were only correct when the divisor happened to divide the numerator exactly. This holds for any consecutive identifier set {1, ..., t} (which is all the existing tests exercised) but fails for every other quorum: with 2-of-3 and quorum {1, 3} the coefficients came out as lambda_1 = 1 and lambda_3 = 0, producing signature shares that aggregate into an invalid signature.

Compute the coefficient in the scalar field instead, reusing the existing invModOrder, and reduce the partial products mod order along the way. Adds a regression test signing with all three 2-of-3 quorums from a trusted dealer keygen; {1, 3} fails without this fix.

Fix #9

BigInt integer division truncates toward zero, so the Lagrange
coefficients were only correct when the divisor happened to divide the
numerator exactly. This holds for any consecutive identifier set
{1, ..., t} (which is all the existing tests exercised) but fails for
every other quorum: with 2-of-3 and quorum {1, 3} the coefficients came
out as lambda_1 = 1 and lambda_3 = 0, producing signature shares that
aggregate into an invalid signature.

Compute the coefficient in the scalar field instead, reusing the
existing invModOrder, and reduce the partial products mod order along
the way. Adds a regression test signing with all three 2-of-3 quorums
from a trusted dealer keygen; {1, 3} fails without this fix.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DeriveInterpolatingValue uses integer division instead of modular inverse

1 participant