Hanzo AI a049b9e5a1 crypto/rust: add 14 binder crates (sha256/ripemd160/blake2b/lamport/bls/kzg/mldsa/mlkem/evm256/ipa/ntt/poly_mul/pedersen/aead)
Fills the Rust binder gaps from CANONICAL_AUDIT.md (commit 8d98804). Each
crate is a thin extern-C binding to the corresponding luxcpp/crypto C-ABI
archive, mirroring the existing keccak/blake3/secp256k1/ed25519/slhdsa
pattern.

Per-crate layout: Cargo.toml + build.rs + src/lib.rs + tests/kat.rs.
build.rs resolves the luxcpp install dir via CRYPTO_DIR / CRYPTO_BUILD_DIR
with a fallback to ../../../../luxcpp/crypto/build-cto. Archives are linked
PRIVATE so blst/banderwagon/etc do not leak past the crate boundary.

Tests: 20 KATs pass across the 14 new crates against the live luxcpp
build at /Users/z/work/luxcpp/crypto/build-cto. Real-body algos (sha256,
ripemd160, blake2b, evm256, ipa, kzg, pedersen) are exercised against
known-answer vectors; algos whose c-abi shim returns CRYPTO_ERR_NOTIMPL
in this build (lamport, bls, mldsa, mlkem, ntt, poly_mul, aead) accept
either a successful round-trip or NOTIMPL coherently across all entry
points.

Workspace cargo build --release --workspace passes. The pre-existing
keccak/secp256k1/blake3 spec-vector tests fail at link time due to
unrelated lux_ prefix drift after the brand-neutral C-ABI rename; not
addressed in this batch.
2026-04-27 15:31:13 -07:00
2026-01-09 01:21:55 -08:00
2025-12-12 19:49:01 -08:00
2025-12-12 19:49:01 -08:00
2026-01-12 14:45:54 -08:00
2026-03-26 22:45:58 -07:00
2025-12-12 19:49:01 -08:00
2025-12-11 03:04:56 +00:00
2025-12-11 03:04:56 +00:00
2026-04-09 23:40:47 -07:00
2025-12-12 19:49:01 -08:00
2025-08-03 01:35:05 +00:00
2025-07-25 20:12:57 -05:00
2025-12-12 19:49:01 -08:00
2025-08-15 19:47:47 -05:00
2025-08-15 19:47:47 -05:00
2025-12-12 19:49:01 -08:00
2025-08-15 19:47:47 -05:00

Lux Crypto

Cryptographic primitives for the Lux Network -- post-quantum signatures, key encapsulation, BLS aggregation, threshold signing, ring signatures, and EVM-compatible secp256k1.

go get github.com/luxfi/crypto

Architecture

luxfi/crypto is the cryptographic foundation for all Lux software. It provides both classical and post-quantum primitives, with automatic CGO acceleration where available (blst for BLS, circl for lattice schemes). The pure-Go fallback path requires no C compiler.

Post-Quantum (NIST FIPS 203/204/205)

Package Algorithm Standard Security Key Sizes
mldsa/ ML-DSA (Dilithium) FIPS 204 128/192/256-bit (Levels 2/3/5) 44: 1312/2560 B, 65: 1952/4032 B, 87: 2592/4896 B
mlkem/ ML-KEM (Kyber) FIPS 203 128/192/256-bit 512: 800/1632 B, 768: 1184/2400 B, 1024: 1568/3168 B
slhdsa/ SLH-DSA (SPHINCS+) FIPS 205 128/192/256-bit (12 variants) SHA2/SHAKE, fast/small tradeoff
pq/ Unified PQ interface -- Wraps mldsa, mlkem, slhdsa Mode selection at runtime

ML-DSA and ML-KEM wrap Cloudflare's circl with ergonomic key serialization. SLH-DSA provides hash-based signatures as a conservative fallback (no lattice assumptions).

Classical

Package Algorithm Use
bls/ BLS12-381 (G1 keys, G2 signatures) Consensus signatures, aggregation, proof-of-possession
secp256k1/ secp256k1 ECDSA EVM transaction signing, Ethereum compatibility
secp256r1/ P-256 ECDSA TLS, WebAuthn, FIDO2
ecies/ ECIES (secp256k1) Asymmetric encryption for Ethereum-compatible keys

Threshold and Multi-Party

Package Protocol Use
threshold/ Threshold signature framework Interface + registry for pluggable threshold schemes
threshold/bls/ BLS threshold signatures t-of-n BLS signing for consensus
cggmp21/ CGGMP21 (ECDSA threshold) MPC key generation and signing, Paillier commitments

Advanced Constructions

Package Construction Use
ring/ Ring signatures (LSAG + lattice-based) Unlinkable signer anonymity
lamport/ Lamport one-time signatures Hash-based PQ signatures (stateful)
hpke/ Hybrid Public Key Encryption ML-KEM + X25519 hybrid, KEM factory
kem/ KEM abstraction ML-KEM, X25519, hybrid combiner
aead/ AEAD ciphers AES-256-GCM, ChaCha20-Poly1305
kdf/ Key derivation HKDF, SLIP-10 HD derivation
verkle/ Verkle tree commitments State proof compression
kzg4844/ KZG commitments (EIP-4844) Blob transaction proofs
ipa/ Inner product arguments Verkle proof backend

Infrastructure

Package Purpose
common/ Address, Hash types (20-byte, 32-byte)
hash/, hashing/ Keccak256, SHA256, RIPEMD160, Blake2b
rlp/ RLP encoding (Ethereum wire format)
cb58/ CB58 encoding (Lux address format)
cert/ TLS certificate management for node identity
signer/ Transaction signing abstraction
sign/ Signature scheme registry
secret/ Secret-safe memory operations (zeroing, constant-time)
address/ Multi-chain address derivation
gpu/ GPU-accelerated modular arithmetic bindings
bindings/ C/Rust FFI exports

BLS Signatures

import "github.com/luxfi/crypto/bls"

sk, _ := bls.NewSecretKey()
pk := bls.PublicFromSecretKey(sk)

sig := bls.Sign(sk, []byte("block hash"))
valid := bls.Verify(pk, sig, []byte("block hash"))

// Aggregation
aggSig, _ := bls.AggregateSignatures(sig1, sig2, sig3)
aggPK, _ := bls.AggregatePublicKeys(pk1, pk2, pk3)
valid = bls.Verify(aggPK, aggSig, msg)

Post-Quantum Signatures (ML-DSA)

import "github.com/luxfi/crypto/mldsa"

sk, pk, _ := mldsa.GenerateKey(mldsa.MLDSA87)  // NIST Level 5
sig, _ := sk.Sign(rand.Reader, data, nil)
valid := pk.VerifySignature(data, sig)

Post-Quantum Key Encapsulation (ML-KEM)

import "github.com/luxfi/crypto/mlkem"

sk, pk, _ := mlkem.GenerateKey(mlkem.MLKEM1024)  // NIST Level 5
ciphertext, sharedSecret, _ := pk.Encapsulate()
recovered, _ := sk.Decapsulate(ciphertext)
// sharedSecret == recovered (32 bytes, use as AES key)

Hybrid HPKE

import "github.com/luxfi/crypto/hpke"

// ML-KEM-1024 + X25519 hybrid
suite := hpke.NewHybridSuite()
enc, ct, _ := suite.Seal(recipientPK, plaintext, aad)
pt, _ := suite.Open(recipientSK, enc, ct, aad)

Testing

go test ./...          # 382 test functions
go test -bench=. ./... # benchmarks

Compiled test binaries are provided for quick verification:

  • bls.test -- BLS signature tests
  • mldsa.test -- ML-DSA tests
  • mlkem.test -- ML-KEM tests
  • slhdsa.test -- SLH-DSA tests
  • crypto.test -- Core crypto tests

Papers

References

  • NIST FIPS 203: ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism)
  • NIST FIPS 204: ML-DSA (Module-Lattice-Based Digital Signature Algorithm)
  • NIST FIPS 205: SLH-DSA (Stateless Hash-Based Digital Signature Algorithm)
  • Cloudflare circl -- underlying lattice implementations
  • BLS12-381 -- pairing-friendly curve specification

License

Lux Ecosystem License v1.2. See LICENSE.

S
Description
Core cryptographic primitives for Lux: high-performance hash functions (SHA-2/3), symmetric ciphers, ECDSA & BLS signatures, HKDF key derivation, and lattice-based post-quantum schemes.
Readme
167 MiB
Languages
C 48.2%
Go 41.3%
Rust 4%
Assembly 1.3%
Sage 0.9%
Other 4.2%