diff --git a/AUDIT.md b/AUDIT.md index b26e161..6286a42 100644 --- a/AUDIT.md +++ b/AUDIT.md @@ -55,7 +55,7 @@ Legend: V = vanilla Go, C = cgo, G = GPU via lux/accel, T = tests. | kem | Y | Y | - | - | circl ML-KEM + hybrid X-Wing | | kzg4844 | Y | Y | G* | Y | gokzg (`!ckzg`) + ckzg (`cgo,ckzg`). GPU added (batch verify). | | lamport | Y | - | - | Y | Hash-based OTS — pure Go | -| mldsa | Y | - | G* | Y | circl FIPS-204. GPU added (batch sign/verify) when accel exposes Dilithium. | +| mldsa | Y | - | G* | Y | circl FIPS-204. GPU added (batch sign/verify) when accel exposes ML-DSA. | | mlkem | Y | * | G* | Y | circl FIPS-203. cgo file is currently a placeholder (mlkem_c.go). GPU added (batch encaps/decaps). | | pq | Y | - | - | - | Re-export aggregator over mldsa+mlkem+slhdsa | | precompile | Y | - | - | Y | EVM precompile impls — pure Go | @@ -65,7 +65,7 @@ Legend: V = vanilla Go, C = cgo, G = GPU via lux/accel, T = tests. | secp256r1 | Y | - | - | - | NIST P-256 verifier (RIP-7212) | | secret | Y | - | - | Y | Go 1.26 runtime/secret wrapper | | sign | - | - | - | - | Empty placeholder | -| signer | Y | - | - | Y | Hybrid BLS+Corona signer | +| signer | Y | - | - | Y | Hybrid BLS+Pulsar signer | | signify | Y | - | - | Y | OpenBSD-style signify | | slhdsa | Y | - | - | Y | circl FIPS-205 — pure Go | | threshold | Y | - | - | Y | Threshold scheme registry + BLS impl | @@ -138,7 +138,7 @@ alias `LUX_CRYPTO_BACKEND` is honored for one release. 2. **GPU coverage**: `lux/accel` exposes batch kernels for SHA256, Keccak256, Poseidon, ECDSA, Ed25519, BLS verify+aggregate, - Merkle, plus Kyber and Dilithium. Algorithms without a kernel + Merkle, plus ML-KEM and ML-DSA. Algorithms without a kernel (slhdsa, verkle, kzg4844 single-blob path) keep vanilla/cgo only — gpu.go in those packages reports `accel.ErrNotSupported` and the public API transparently falls back to the next backend. diff --git a/LLM.md b/LLM.md index 3b32478..17ce9e0 100644 --- a/LLM.md +++ b/LLM.md @@ -27,7 +27,7 @@ cd docs && pnpm build # Build static site ### Consensus Cryptography (Lux Quasar) | Package | Purpose | Notes | |---------|---------|-------| -| **signer/** | Hybrid BLS + Corona signing | Lux consensus | +| **signer/** | Hybrid BLS + Pulsar signing | Lux consensus | | **bls/** | BLS12-381 aggregatable signatures | Classical layer | | **corona/** | Lattice-based threshold signatures | Post-quantum layer | @@ -81,12 +81,12 @@ Key changes: | Type | Example | Use Case | |------|---------|----------| -| **Threshold** | Corona, BLS-Threshold, FROST, CGGMP21 | t-of-n validators sign collaboratively | +| **Threshold** | Pulsar, BLS-Threshold, FROST, CGGMP21 | t-of-n validators sign collaboratively | | **Regular** | ML-DSA, BLS | Single party signs | -Lux consensus uses **BLS + Corona**: +Lux consensus uses **BLS + Pulsar**: - BLS: Classical, aggregatable signatures -- Corona: Lattice-based threshold for post-quantum security +- Pulsar: Lattice-based threshold for post-quantum security ML-DSA is a separate NIST standard (not used in consensus, potential future validator messages). @@ -129,7 +129,7 @@ threshold/ | `SchemeFROST` | FROST (Schnorr) | Interface only | No | No | | `SchemeCMP` | CGGMP21 (ECDSA) | Partial in cggmp21/ | No | No | | `SchemeBLS` | BLS Threshold | Skeleton impl | No | Yes | -| `SchemeCorona` | Corona (Lattice) | Interface only | Yes | No | +| `SchemeCorona` | Pulsar (Lattice) | Interface only | Yes | No | ### Usage Pattern @@ -313,7 +313,7 @@ err := ring.VerifyAndRecord(sig, message, ringMembers, store) | TestLatticeSignatureInvalidMessage | Post-quantum wrong message | | TestLatticeSignatureInvalidRing | Post-quantum modified ring | -### Distinction from Corona +### Distinction from Pulsar | Package | Type | Purpose | |---------|------|---------| @@ -336,7 +336,7 @@ lux key ring generate --size 5 # Generate decoy keys ``` **Scheme Flags:** -- `--scheme lsag` (default) - Uses Corona keys from `~/.lux/keys//rt/` +- `--scheme lsag` (default) - Uses Pulsar keys from `~/.lux/keys//rt/` - `--scheme lattice` - Uses ML-DSA keys from `~/.lux/keys//mldsa/` **File Locations:** @@ -415,11 +415,11 @@ Static docs site at `docs/` using fumadocs: 5. hash-functions - SHA, BLAKE, Keccak 6. key-management - HD wallets, KDF 7. security - Best practices -8. ring-signatures - Corona (lattice threshold) +8. ring-signatures - Pulsar (lattice threshold) 9. lamport - One-time signatures 10. kzg4844 - Polynomial commitments 11. verkle-ipa - Inner product arguments -12. signer - Hybrid BLS + Corona +12. signer - Hybrid BLS + Pulsar 13. precompiles - EVM contracts ## Key Technologies @@ -433,7 +433,7 @@ Static docs site at `docs/` using fumadocs: | Algorithm | Security Level | Quantum Resistant | Type | |-----------|---------------|-------------------|------| -| Corona | Lattice-based | Yes | Threshold | +| Pulsar | Lattice-based | Yes | Threshold | | ML-DSA-65 | 192-bit (NIST Level 3) | Yes | Regular | | ML-KEM-768 | 192-bit (NIST Level 3) | Yes | KEM | | SLH-DSA-SHA2-128f | 128-bit (NIST Level 1) | Yes | Regular | @@ -447,7 +447,7 @@ Static docs site at `docs/` using fumadocs: 3. Follow Go coding standards 4. Test all implementations before claiming completion 5. Cross-reference LPs when discussing specifications -6. Corona = lattice threshold (NOT ring signatures, NOT ML-DSA) +6. Pulsar = lattice threshold (NOT ring signatures, NOT ML-DSA) 7. ML-DSA = NIST FIPS 204 regular signatures (NOT threshold) --- @@ -917,7 +917,7 @@ consensus/protocol/quasar/ `crypto/threshold/corona/scheme.go` is an **adapter layer** that: 1. Imports `github.com/luxfi/corona/sign` and `github.com/luxfi/corona/primitives` -2. Creates wrapper types (KeyShare, PublicKey, Signer, etc.) that wrap real Corona types +2. Creates wrapper types (KeyShare, PublicKey, Signer, etc.) that wrap real Pulsar types 3. Translates between `threshold.*` interfaces and `corona.sign.*` types 4. Duplicates type definitions with conversion logic @@ -954,7 +954,7 @@ This violates the design goal of having implementations be **native** to the int └─────────────┘ └─────────────┘ └───────────────┘ │ No more adapter layer! - Corona implements threshold.Scheme + Pulsar implements threshold.Scheme directly in the corona repo ``` @@ -974,7 +974,7 @@ The entire `crypto/threshold/corona/` directory was removed. **Created:** `corona/threshold/threshold.go` -The Corona package now implements threshold signatures natively (2-round protocol): +The Pulsar package now implements threshold signatures natively (2-round protocol): ```go // corona/threshold/threshold.go @@ -1032,9 +1032,9 @@ import ( **Key additions:** - `HybridConfig` struct with `CoronaShares` and `CoronaGroupKey` fields -- `DualSignRound1()` - Returns BLS share + Corona Round1 data in parallel +- `DualSignRound1()` - Returns BLS share + Pulsar Round1 data in parallel - `CoronaRound1/Round2/Finalize()` - Exposes 2-round protocol methods -- `GenerateDualKeys()` - Generates both BLS and Corona threshold keys +- `GenerateDualKeys()` - Generates both BLS and Pulsar threshold keys ### ARCHITECTURE DIAGRAM (Clean State) @@ -1121,12 +1121,12 @@ Move and adapt tests. Change: ```go -_ "github.com/luxfi/crypto/threshold/corona" // Register Corona threshold scheme +_ "github.com/luxfi/crypto/threshold/corona" // Register Pulsar threshold scheme ``` To: ```go -_ "github.com/luxfi/corona/threshold" // Register Corona threshold scheme +_ "github.com/luxfi/corona/threshold" // Register Pulsar threshold scheme ``` #### 4. MODIFY (corona repo go.mod) @@ -1142,12 +1142,12 @@ require github.com/luxfi/crypto v1.x.x 1. **No Duplication**: Types are defined once, in corona, implementing threshold interfaces 2. **No Interpretation**: No translation layer between two type systems -3. **Single Source**: Corona logic lives in corona repo +3. **Single Source**: Pulsar logic lives in corona repo 4. **Clean Dependencies**: - crypto/threshold -> defines interfaces - corona -> implements interfaces - consensus -> uses interfaces -5. **Consistent Pattern**: Both BLS and Corona now follow same pattern +5. **Consistent Pattern**: Both BLS and Pulsar now follow same pattern ### WHAT TO KEEP (Unchanged) @@ -1179,7 +1179,7 @@ The `adapter.go` file is confusingly named but it's actually a **convenience wra ### TEST RESULTS (2025-12-19) -**Corona Threshold Tests (4 tests):** +**Pulsar Threshold Tests (4 tests):** - TestGenerateKeys ✅ - TestThresholdSigningFlow ✅ (2-round protocol verified) - TestThresholdWrongMessage ✅ @@ -1190,15 +1190,15 @@ The `adapter.go` file is confusingly named but it's actually a **convenience wra - TestBLSThresholdInsufficientShares ✅ - TestBLSThresholdWrongMessage ✅ - TestDualThresholdKeyGeneration ✅ -- **TestDualSigningFlow ✅** - Full BLS + Corona 2-round protocol +- **TestDualSigningFlow ✅** - Full BLS + Pulsar 2-round protocol ### KEY ACHIEVEMENT **Dual Threshold Signing Flow** - Validators can now sign blocks with both: 1. **BLS** (1 round): Immediate aggregation for classical security -2. **Corona** (2 rounds): Post-quantum security via lattice-based threshold signatures +2. **Pulsar** (2 rounds): Post-quantum security via lattice-based threshold signatures -Both run in parallel, with BLS completing in Round 1 while Corona completes after Round 2. +Both run in parallel, with BLS completing in Round 1 while Pulsar completes after Round 2. ### PENDING WORK @@ -1210,7 +1210,7 @@ Both run in parallel, with BLS completing in Round 1 while Corona completes afte ### Overview -The `EpochManager` in `consensus/protocol/quasar/epoch.go` manages Corona key epochs for validator sets with rate limiting to prevent excessive key churn while still rotating frequently enough to frustrate quantum attacks. +The `EpochManager` in `consensus/protocol/quasar/epoch.go` manages Pulsar key epochs for validator sets with rate limiting to prevent excessive key churn while still rotating frequently enough to frustrate quantum attacks. ### Key Constants @@ -1230,7 +1230,7 @@ The epoch uses `uint64` which supports values up to 18,446,744,073,709,551,615. ### Core Types ```go -// EpochManager manages Corona key epochs for the validator set. +// EpochManager manages Pulsar key epochs for the validator set. type EpochManager struct { mu sync.RWMutex currentEpoch uint64 @@ -1242,7 +1242,7 @@ type EpochManager struct { threshold int } -// EpochKeys holds the Corona keys for a specific epoch. +// EpochKeys holds the Pulsar keys for a specific epoch. type EpochKeys struct { Epoch uint64 CreatedAt time.Time @@ -1314,9 +1314,9 @@ func (q *Quasar) AddValidator(validatorID string, coronaShare ...) error { } ``` -### Critical Bug Fix: Corona Verify Function +### Critical Bug Fix: Pulsar Verify Function -**Issue**: The Corona `Verify` function in `/Users/z/work/lux/corona/sign/sign.go:290` was **destructive** - it modified the input signature's `z` vector in-place with `utils.ConvertVectorFromNTT(r, z)`. +**Issue**: The Pulsar `Verify` function in `/Users/z/work/lux/corona/sign/sign.go:290` was **destructive** - it modified the input signature's `z` vector in-place with `utils.ConvertVectorFromNTT(r, z)`. **Symptom**: Epoch 0 signatures failed to verify after rotation because the first verification call mutated the signature. @@ -1336,7 +1336,7 @@ utils.MatrixVectorMul(r, A, zCopy, Az_bc) // ... ``` -### 3-Second Quantum Bundles (Parallel BLS + Corona) +### 3-Second Quantum Bundles (Parallel BLS + Pulsar) **Architecture (parallel execution):** ``` @@ -1345,10 +1345,10 @@ BLS Layer: [B1]--[B2]--[B3]--[B4]--[B5]--[B6]--[B7]--[B8]--... |___________________________________| | Quantum Layer: [QB1: Merkle(B1-B6)]--------[QB2: Merkle(B7-B12)] - | 3-second interval, async Corona signing + | 3-second interval, async Pulsar signing ``` -**NTT Corona benchmarks (IEEE S&P 2025):** +**NTT Pulsar benchmarks (IEEE S&P 2025):** - 0.6s online signing phase (2-round protocol) - 2.5s total including offline prep across 5 continents - Our 3-second interval provides comfortable margin @@ -1388,7 +1388,7 @@ valid := bs.VerifyBundle(bundle) **Async Signing (for production):** ```go -// AsyncBundleSigner runs Corona signing in background +// AsyncBundleSigner runs Pulsar signing in background signer := NewAsyncBundleSigner(epochManager) // BundleRunner automates the 3-second production loop @@ -1405,7 +1405,7 @@ runner.Stop() **Key Features:** - BLS finality continues at 500ms - no latency impact -- Corona signing runs async, doesn't block BLS +- Pulsar signing runs async, doesn't block BLS - ~6 BLS blocks per quantum bundle (3s / 500ms) - Merkle root provides compact proof of all BLS blocks - Bundle chain via `PreviousHash` linkage diff --git a/README.md b/README.md index b526a0b..7e93c4c 100644 --- a/README.md +++ b/README.md @@ -14,9 +14,9 @@ go get github.com/luxfi/crypto | Package | Algorithm | Standard | Security | Key Sizes | |---------|-----------|----------|----------|-----------| -| `mldsa/` | ML-DSA (Dilithium) | FIPS 204 | 128/192/256-bit (Levels 2/3/5) | 44: 1312/2560 B, 65: 1952/4032 B, 87: 2592/4896 B | -| `mlkem/` | ML-KEM (Kyber) | FIPS 203 | 128/192/256-bit | 512: 800/1632 B, 768: 1184/2400 B, 1024: 1568/3168 B | -| `slhdsa/` | SLH-DSA (SPHINCS+) | FIPS 205 | 128/192/256-bit (12 variants) | SHA2/SHAKE, fast/small tradeoff | +| `mldsa/` | ML-DSA | FIPS 204 | 128/192/256-bit (Levels 2/3/5) | 44: 1312/2560 B, 65: 1952/4032 B, 87: 2592/4896 B | +| `mlkem/` | ML-KEM | FIPS 203 | 128/192/256-bit | 512: 800/1632 B, 768: 1184/2400 B, 1024: 1568/3168 B | +| `slhdsa/` | SLH-DSA (FIPS 205, formerly SPHINCS+) | FIPS 205 | 128/192/256-bit (12 variants) | SHA2/SHAKE, fast/small tradeoff | | `pq/` | Unified PQ interface | -- | Wraps mldsa, mlkem, slhdsa | Mode selection at runtime | ML-DSA and ML-KEM wrap Cloudflare's circl with ergonomic key serialization. SLH-DSA provides hash-based signatures as a conservative fallback (no lattice assumptions). @@ -136,7 +136,7 @@ Compiled test binaries are provided for quick verification: - [Lux PQ Crypto Suite](https://github.com/luxfi/papers/blob/main/lux-pq-crypto-suite.pdf) -- parameter selection and security analysis for ML-DSA, ML-KEM, SLH-DSA - [Lux Hybrid PQ Architecture](https://github.com/luxfi/papers/blob/main/lux-hybrid-pq-architecture.pdf) -- hybrid classical/PQ transition strategy - [Lux Crypto Agility](https://github.com/luxfi/papers/blob/main/lux-crypto-agility.pdf) -- algorithm negotiation and migration framework -- [Lux Corona PQ](https://github.com/luxfi/papers/blob/main/lux-corona-pq.pdf) -- post-quantum ring signatures +- [Lux Pulsar PQ](https://github.com/luxfi/papers/blob/main/lux-corona-pq.pdf) -- post-quantum ring signatures - [Lux Universal Threshold Signatures](https://github.com/luxfi/papers/blob/main/lux-universal-threshold-signatures.pdf) -- multi-curve threshold framework ## References diff --git a/docs/content/docs/cpp-libraries.mdx b/docs/content/docs/cpp-libraries.mdx index 6afda4c..458e546 100644 --- a/docs/content/docs/cpp-libraries.mdx +++ b/docs/content/docs/cpp-libraries.mdx @@ -144,8 +144,8 @@ Core cryptography with GPU-accelerated BLS pairings. **Features**: - BLS12-381 pairings with GPU acceleration -- ML-DSA (CRYSTALS-Dilithium) post-quantum signatures -- ML-KEM (CRYSTALS-Kyber) post-quantum key encapsulation +- ML-DSA (FIPS 204, formerly CRYSTALS-Dilithium) post-quantum signatures +- ML-KEM (FIPS 203, formerly CRYSTALS-Kyber) post-quantum key encapsulation - secp256k1 for Ethereum compatibility **Installation**: @@ -284,5 +284,5 @@ done ## Next Steps - [BLS Signatures](/docs/bls) - BLS cryptography with Go -- [Post-Quantum Crypto](/docs/post-quantum) - Dilithium and Kyber +- [Post-Quantum Crypto](/docs/post-quantum) - ML-DSA and ML-KEM - [Precompiles](/docs/precompiles) - EVM precompiled contracts diff --git a/docs/content/docs/index.mdx b/docs/content/docs/index.mdx index c67723f..ef65928 100644 --- a/docs/content/docs/index.mdx +++ b/docs/content/docs/index.mdx @@ -10,7 +10,7 @@ A comprehensive cryptographic library providing BLS signatures, post-quantum alg ## Features - **BLS Signatures**: Efficient signature aggregation for consensus -- **Post-Quantum Cryptography**: ML-DSA (Dilithium) signatures and ML-KEM (Kyber) key exchange +- **Post-Quantum Cryptography**: ML-DSA signatures and ML-KEM key exchange - **Fully Homomorphic Encryption**: Compute on encrypted data (TFHE, CKKS, BGV) - **GPU Acceleration**: Metal (Apple Silicon) and CUDA (NVIDIA) backends - **Hash Functions**: SHA-256, SHA-3, BLAKE2b, Keccak @@ -52,7 +52,7 @@ func main() { } ``` -### Post-Quantum Signatures (Dilithium) +### Post-Quantum Signatures (ML-DSA) ```go package main @@ -74,7 +74,7 @@ func main() { } ``` -### Key Exchange (Kyber) +### Key Exchange (ML-KEM) ```go package main @@ -99,9 +99,9 @@ func main() { ### Cryptographic Primitives -1. **Signatures**: BLS, ECDSA, Ed25519, Dilithium +1. **Signatures**: BLS, ECDSA, Ed25519, ML-DSA 2. **Hash Functions**: SHA-256, SHA-3, BLAKE2b, Keccak -3. **Key Exchange**: ECDH, Kyber +3. **Key Exchange**: ECDH, ML-KEM 4. **Encryption**: AES-GCM, ChaCha20-Poly1305 5. **Random Number Generation**: CSPRNG @@ -146,7 +146,7 @@ func AggregatePublicKeys(pks []PublicKey) (PublicKey, error) func VerifyAggregate(pks []PublicKey, message []byte, sig Signature) bool ``` -### Dilithium Package (Post-Quantum) +### ML-DSA Package (Post-Quantum) ```go // Generate key pair @@ -159,7 +159,7 @@ func Sign(sk PrivateKey, message []byte) ([]byte, error) func Verify(pk PublicKey, message []byte, sig []byte) bool ``` -### Kyber Package (Post-Quantum Key Exchange) +### ML-KEM Package (Post-Quantum Key Exchange) ```go // Generate key pair @@ -224,7 +224,7 @@ for _, pk := range publicKeys { // Use hybrid signatures during transition period type HybridSignature struct { BLS bls.Signature - Dilithium []byte + ML-DSA []byte } func SignHybrid(message []byte, blsKey *bls.PrivateKey, pqKey dilithium.PrivateKey) (*HybridSignature, error) { @@ -236,7 +236,7 @@ func SignHybrid(message []byte, blsKey *bls.PrivateKey, pqKey dilithium.PrivateK return &HybridSignature{ BLS: blsSig, - Dilithium: pqSig, + ML-DSA: pqSig, }, nil } ``` @@ -256,10 +256,10 @@ func SignHybrid(message []byte, blsKey *bls.PrivateKey, pqKey dilithium.PrivateK | Operation | Time | Size | |-----------|------|------| -| Dilithium Sign | 0.8 ms | 2.4 KB | -| Dilithium Verify | 0.3 ms | - | -| Kyber Encapsulate | 0.1 ms | 1.1 KB | -| Kyber Decapsulate | 0.1 ms | - | +| ML-DSA Sign | 0.8 ms | 2.4 KB | +| ML-DSA Verify | 0.3 ms | - | +| ML-KEM Encapsulate | 0.1 ms | 1.1 KB | +| ML-KEM Decapsulate | 0.1 ms | - | ## Testing diff --git a/docs/content/docs/post-quantum.mdx b/docs/content/docs/post-quantum.mdx index 49963ec..96e138c 100644 --- a/docs/content/docs/post-quantum.mdx +++ b/docs/content/docs/post-quantum.mdx @@ -18,7 +18,7 @@ Post-quantum cryptography protects against attacks from both classical and quant ## ML-DSA (Module Lattice Digital Signature Algorithm) -ML-DSA, formerly known as CRYSTALS-Dilithium, provides quantum-resistant digital signatures based on lattice problems. +ML-DSA, formerly known as ML-DSA (FIPS 204, formerly CRYSTALS-Dilithium), provides quantum-resistant digital signatures based on lattice problems. ### Security Parameters @@ -119,7 +119,7 @@ func exampleMLDSA() { ## ML-KEM (Module Lattice Key Encapsulation Mechanism) -ML-KEM, formerly known as CRYSTALS-Kyber, provides quantum-resistant key exchange using lattice-based cryptography. +ML-KEM, formerly known as ML-KEM (FIPS 203, formerly CRYSTALS-Kyber), provides quantum-resistant key exchange using lattice-based cryptography. ### Security Parameters @@ -239,7 +239,7 @@ func (hke *HybridKeyExchange) Encapsulate(peerMLKEM *mlkem.PublicKey, peerECDH * ## SLH-DSA (Stateless Hash-Based Digital Signature Algorithm) -SLH-DSA, also known as SPHINCS+, provides hash-based signatures that don't require state management. +SLH-DSA, also known as SLH-DSA (FIPS 205, formerly SPHINCS+), provides hash-based signatures that don't require state management. ### Security Parameters diff --git a/docs/content/docs/ring-signatures.mdx b/docs/content/docs/ring-signatures.mdx index 0d9f6df..51305b0 100644 --- a/docs/content/docs/ring-signatures.mdx +++ b/docs/content/docs/ring-signatures.mdx @@ -1,15 +1,15 @@ --- -title: Corona (Lattice Threshold Signatures) +title: Pulsar (Lattice Threshold Signatures) description: Lattice-based threshold signature scheme for post-quantum consensus --- -# Corona +# Pulsar -Corona is a lattice-based threshold signature scheme used in Lux consensus for post-quantum security. It enables t-of-n validators to collaboratively create signatures without any single party controlling the signing key. +Pulsar is a lattice-based threshold signature scheme used in Lux consensus for post-quantum security. It enables t-of-n validators to collaboratively create signatures without any single party controlling the signing key. ## Overview -Corona provides: +Pulsar provides: - **Threshold Security**: Requires t-of-n participants to sign - **Post-Quantum Resistance**: Based on lattice hard problems @@ -65,7 +65,7 @@ import ( ) func main() { - // Get the threshold scheme (BLS for now, Corona when available) + // Get the threshold scheme (BLS for now, Pulsar when available) scheme, err := threshold.GetScheme(threshold.SchemeBLS) if err != nil { panic(err) @@ -95,7 +95,7 @@ func main() { ### Threshold Operations -Corona threshold operations are coordinated through the consensus layer: +Pulsar threshold operations are coordinated through the consensus layer: ```go // In consensus layer (github.com/luxfi/consensus) @@ -150,12 +150,12 @@ type FinalizedBlock struct { ### Dual-Layer Security -Lux uses both BLS and Corona: +Lux uses both BLS and Pulsar: | Layer | Purpose | Security | |-------|---------|----------| | BLS | Fast aggregation, classical | 128-bit classical | -| Corona | Threshold, post-quantum | Lattice hard problems | +| Pulsar | Threshold, post-quantum | Lattice hard problems | Both must be valid for block finalization. @@ -197,7 +197,7 @@ Precomputed shares enable: | ECDSA | Classical | No | With MPC | | BLS | Classical | No | Native | | ML-DSA | Post-Quantum | Yes | No | -| Corona | Post-Quantum | Yes | Yes | +| Pulsar | Post-Quantum | Yes | Yes | ## Integration with Signer Package diff --git a/docs/content/docs/signer.mdx b/docs/content/docs/signer.mdx index e7da11e..8367cb3 100644 --- a/docs/content/docs/signer.mdx +++ b/docs/content/docs/signer.mdx @@ -1,17 +1,17 @@ --- title: Signer -description: Hybrid BLS and Corona signing for Lux consensus +description: Hybrid BLS and Pulsar signing for Lux consensus --- # Signer -Hybrid signing combining BLS with Corona (lattice-based threshold signatures) for Lux consensus. +Hybrid signing combining BLS with Pulsar (lattice-based threshold signatures) for Lux consensus. ## Overview -- **Hybrid Signatures**: BLS + Corona threshold signing +- **Hybrid Signatures**: BLS + Pulsar threshold signing - **Classical Security**: BLS provides efficient, aggregatable signatures -- **Post-Quantum Ready**: Corona lattice-based threshold scheme +- **Post-Quantum Ready**: Pulsar lattice-based threshold scheme - **Consensus Optimized**: Designed for Lux's Quasar consensus ## Architecture @@ -21,7 +21,7 @@ Lux consensus uses two cryptographic layers: | Layer | Algorithm | Purpose | |-------|-----------|---------| | Classical | BLS12-381 | Efficient aggregatable signatures | -| Threshold | Corona | Lattice-based threshold signatures | +| Threshold | Pulsar | Lattice-based threshold signatures | ## Implementation @@ -42,7 +42,7 @@ func main() { } fmt.Printf("BLS Public Key: %x\n", s.GetBLSPublicKey()) - fmt.Printf("Corona Public Key: %x\n", s.GetCoronaPublicKey().Bytes()) + fmt.Printf("Pulsar Public Key: %x\n", s.GetCoronaPublicKey().Bytes()) } ``` @@ -60,12 +60,12 @@ func verify(s *signer.Signer, msg, sig []byte) bool { } ``` -### Corona Threshold Signing +### Pulsar Threshold Signing -Corona is a lattice-based threshold signature scheme used for post-quantum security in consensus: +Pulsar is a lattice-based threshold signature scheme used for post-quantum security in consensus: ```go -// Corona threshold signing requires coordination through consensus +// Pulsar threshold signing requires coordination through consensus // The signer package provides key management pk := s.GetCoronaPublicKey() @@ -77,7 +77,7 @@ pk := s.GetCoronaPublicKey() ### Quasar Consensus -The Lux Quasar consensus uses both BLS and Corona: +The Lux Quasar consensus uses both BLS and Pulsar: ```go type ConsensusMessage struct { @@ -93,7 +93,7 @@ func aggregateBLS(sigs [][]byte) ([]byte, error) { return bls.AggregateSignatures(sigs) } -// Corona uses threshold aggregation +// Pulsar uses threshold aggregation // Requires t-of-n validators to create final signature ``` @@ -120,7 +120,7 @@ type FinalizedBlock struct { | Signature Size | 96 B | Constant | | Public Key Size | 48 B | Compressed | -Corona threshold operations depend on the consensus layer. +Pulsar threshold operations depend on the consensus layer. ## Key Management @@ -149,8 +149,8 @@ coronaKey := s.CoronaPrivateKey() The hybrid approach provides security even if one algorithm is compromised: -- **BLS only broken**: Corona threshold maintains security -- **Corona only broken**: BLS maintains classical security +- **BLS only broken**: Pulsar threshold maintains security +- **Pulsar only broken**: BLS maintains classical security - **Both secure**: Defense in depth ### Key Generation @@ -168,7 +168,7 @@ func secureKeyGeneration() (*signer.Signer, error) { return nil, errors.New("BLS key generation failed") } if s.GetCoronaPublicKey() == nil { - return nil, errors.New("Corona key generation failed") + return nil, errors.New("Pulsar key generation failed") } return s, nil @@ -192,7 +192,7 @@ func TestSigner(t *testing.T) { // Wrong message should fail require.False(t, s.VerifyBLS([]byte("wrong"), blsSig)) - // Corona key should exist + // Pulsar key should exist require.NotNil(t, s.GetCoronaPublicKey()) } ``` diff --git a/mldsa/README.md b/mldsa/README.md index ff7ac43..c5a18e0 100644 --- a/mldsa/README.md +++ b/mldsa/README.md @@ -1,6 +1,6 @@ # ML-DSA (Module-Lattice Digital Signature Algorithm) for Lux -FIPS 204 compliant implementation of ML-DSA (formerly known as CRYSTALS-Dilithium) post-quantum signatures. +FIPS 204 compliant implementation of ML-DSA (formerly known as ML-DSA (FIPS 204, formerly CRYSTALS-Dilithium)) post-quantum signatures. ## Overview diff --git a/rust/lux-crypto-mldsa/README.md b/rust/lux-crypto-mldsa/README.md index 7953b52..66a65b1 100644 --- a/rust/lux-crypto-mldsa/README.md +++ b/rust/lux-crypto-mldsa/README.md @@ -1,7 +1,7 @@ # lux-crypto-mldsa Canonical Rust binding for Lux ML-DSA (FIPS 204, final standardized form of -CRYSTALS-Dilithium). +ML-DSA (FIPS 204, formerly CRYSTALS-Dilithium)). | Mode | NIST level | pk | sk | sig | |-------------|------------|--------|-------|--------| diff --git a/rust/lux-crypto-mlkem/README.md b/rust/lux-crypto-mlkem/README.md index a1561f4..cd72010 100644 --- a/rust/lux-crypto-mlkem/README.md +++ b/rust/lux-crypto-mlkem/README.md @@ -1,7 +1,7 @@ # lux-crypto-mlkem Canonical Rust binding for Lux ML-KEM (FIPS 203, final standardized form of -CRYSTALS-Kyber). +ML-KEM (FIPS 203, formerly CRYSTALS-Kyber)). | Mode | NIST level | pk | sk | ct | ss | |-------------|------------|--------|-------|-------|----| diff --git a/rust/lux-crypto-poly_mul/README.md b/rust/lux-crypto-poly_mul/README.md index 0e4faba..65f84e0 100644 --- a/rust/lux-crypto-poly_mul/README.md +++ b/rust/lux-crypto-poly_mul/README.md @@ -9,7 +9,7 @@ Wraps the C-ABI exposed by `luxcpp/crypto/poly_mul`. - **Polynomial multiplication** in `Z_Q[X] / (X^n + 1)` (negacyclic ring) - Built on top of `lux-crypto-ntt` -- Used as a primitive for lattice-based schemes (ML-DSA, ML-KEM, Corona) +- Used as a primitive for lattice-based schemes (ML-DSA, ML-KEM, Pulsar) ## Build diff --git a/rust/lux-crypto-slhdsa/README.md b/rust/lux-crypto-slhdsa/README.md index f5f237b..5044b18 100644 --- a/rust/lux-crypto-slhdsa/README.md +++ b/rust/lux-crypto-slhdsa/README.md @@ -1,7 +1,7 @@ # lux-crypto-slhdsa Canonical Rust binding for Lux SLH-DSA (FIPS 205, the final standardized form -of SPHINCS+). +of SLH-DSA (FIPS 205, formerly SPHINCS+)). **Status: stub — luxcpp/crypto/slhdsa/c-abi/c_slhdsa.cpp returns `CRYPTO_ERR_NOTIMPL`.** The Rust binding is shipped against the canonical