Magnetar v1.0.0 closes the permissionless-threshold story at ONE
construction --- THBS-SE (Threshold Hash-Based Signatures with
Selected-Element Reconstruction) --- and removes every legacy
seed-recombine path from the codebase.
The two production primitives at v1.0:
1. Per-validator standalone (standalone.go, unchanged from v0.5.x) ---
the public-BFT primary primitive. Each validator holds its own FIPS
205 keypair, signs independently, consensus collects N signatures
into a ValidatorAggregateCert.
2. THBS-SE (thbsse.go + thbsse_field.go) --- the permissionless
threshold companion. t-of-n committee, slot-bound commit-and-reveal,
PUBLIC COMBINER role (anyone-can-combine, no host in TCB at sign
time), slashable equivocation and malformed-share evidence.
Both emit byte-identical FIPS 205 signatures that unmodified verifiers
accept (TestMagnetar_Wire_FIPS205Verifiable +
TestThbsSE_Wire_FIPS205Verifiable across all 3 SHAKE modes).
Hard invariant (THBS-SE): a revealed value is allowed only if it is
also present in the final SLH-DSA signature. Forbidden reveals:
SK.seed in any party-local persistent form, SK.prf, future-slot share
material. The slot guard refuses any same-slot re-emission.
v1.0 honest open item: the strict "no transient seed at any moment"
invariant requires a v1.1 strict-atom-assembly path
(BLOCKERS.md::MAGNETAR-STRICT-ATOM-V11) that re-implements FIPS 205
sec 5/6/7/8 internally. v1.0 ships a PUBLIC COMBINER that holds the
seed for one slhdsa.SignDeterministic call and zeroizes; materially
stronger than TEE-attested privileged-aggregator constructions,
materially weaker than the strict refinement.
8 test gates + 2 bonus correctness checks:
- TestThbsSE_Wire_FIPS205Verifiable (3 modes) -- byte identity
- TestThbsSE_RejectSeedReveal
- TestThbsSE_RejectUnselectedFORS
- TestThbsSE_RejectUnselectedWOTS
- TestThbsSE_SlotReuseRejected
- TestThbsSE_OverselectedCommittee
- TestThbsSE_SlotBindingDomainSeparation
- BenchmarkThbsSE_Sign_5of7
- TestThbsSE_PublicCombiner_Determinism (bonus)
- TestKAT_ThbsSe (n=7, t=4, 3 modes, 3 messages)
Removed (legacy seed-recombine path + the proofs/CT scaffolding that
modeled it):
- ref/go/pkg/magnetar/{threshold,aggregate,combine,shamir,dkg}.go
+ tests
- ref/go/pkg/magnetar/{e2e,fuzz,n1_byte_equality}_test.go
- ref/go/pkg/thbs/ (entire subtree including dkg2/ PVSS skeleton)
- vectors/{threshold-sign,dkg}.json
- jasmin/{threshold,lib}/ (legacy seed-recombine model)
- proofs/easycrypt/ (entire tree; v1.1 ports to THBS-SE)
- ct/dudect/ (entire tree; v1.1 lands with strict-atom path)
- scripts/{check-lean-bridge,checks/ec-*,checks/jasmin,checks/extraction}.sh
Added:
- ref/go/pkg/magnetar/thbsse.go (1054 LOC; the THBS-SE construction)
- ref/go/pkg/magnetar/thbsse_field.go (GF(257) internal share math)
- ref/go/pkg/magnetar/thbsse_test.go (8 gates + 2 bonus)
- vectors/thbsse-sign.json (deterministic (n=7,t=4) KAT)
- v1.0 supersede notices on v0.x archival docs
Verification:
- GOWORK=off go build ./... && go vet ./...: clean
- go test -count=1 -short: PASS (all gates)
- go test -count=1 -race -short: PASS
- grep "reveal-and-aggregate|seed.*recombin|THBS over.*seed|aggregator.*reconstruct.*seed" *.go: 0 matches
- find ref/go/pkg -type d -name thbs: empty
7.0 KiB
Magnetar v1.0 --- Normative specification
This document is the normative specification of the two primitives
shipped by luxfi/magnetar v1.0.
Companion documents:
README.md--- introduction and headline tests.THBS-SPEC.md--- detailed THBS-SE construction spec.DEPLOYMENT-RUNBOOK.md--- operator runbook.BLOCKERS.md--- v1.1 roadmap.
1. Primitives
Magnetar v1.0 ships TWO primitives. Both produce FIPS 205 wire bytes that an unmodified verifier accepts.
1.1 Per-validator standalone (public-BFT primary)
API at ref/go/pkg/magnetar/standalone.go:
PerValidatorKeypair(params, rng) -> (sk, pk, error)
ValidatorSign(sk, rng, message) -> ([]byte, error)
ValidatorBatchVerify(params, pubs, msgs, sigs) -> ([]bool, error)
BuildAggregateCert(params, signers, pubKeys, sigs) -> (*ValidatorAggregateCert, error)
VerifyAggregateCert(cert, message, knownValidators) -> (count, error)
Semantics:
- Each validator runs
PerValidatorKeypairONCE on its own host with its own RNG; persists(sk_i, pk_i); registerspk_iin the validator-set commitment. - To sign message
m: validatoricomputessigma_i = ValidatorSign(sk_i, nil, m). Output is the raw FIPS 205 signature bytes; deterministic whenrngis nil (FIPS 205 SignDeterministic). - The consensus layer collects N
(sigma_i, pk_i, ValidatorID_i)triples into aValidatorAggregateCertviaBuildAggregateCert. VerifyAggregateCertreturns the COUNT of valid signers. The quorum policy decision (count >= threshold) lives at the CONSUMER, NOT in the primitive.
Trust model:
- No DKG, no shared seed, no aggregator-in-TCB.
- Per-validator slashing is attributable.
- Z-Chain Groth16 rollup compresses
N x |sigma|to ~192 bytes; the rollup is a separate primitive (lux-zchain spec).
1.2 THBS-SE (permissionless threshold)
API at ref/go/pkg/magnetar/thbsse.go:
NewThbsSeKey(params, threshold, committee, rng) -> (*ThbsSeKey, error)
ThbsSeRound1(params, share, binding, msg, guard, rng) -> (r1, r2, error)
Combine(input ThbsSeCombineInput) -> (*Signature, []ThbsSeShareEvidence, error)
NewThbsSeSlotGuard() -> *ThbsSeSlotGuard
VerifyThbsSeEvidence(params, ev, msgPrior, msgNew, bindingPrior, bindingNew) -> bool
VerifyThbsSeShareEvidence(params, ev, binding, msg) -> bool
Semantics: see THBS-SPEC.md for the full construction. Highlights:
- t-of-n committee with
n > tover-selection. - Slot binding flows into the cSHAKE256 commit transcript AND into the FIPS 205 ctx string.
- PUBLIC COMBINER role; anyone with the public ThbsSeKey, the slot binding, the message, and >= t valid Round-1/Round-2 pairs can produce the FIPS 205 signature.
- Equivocation and malformed-share evidence are wire-shaped typed blobs; pure-function third-party verifiers.
2. Parameter sets
Per FIPS 205 sec 10.1 Table 2:
| Mode | n (WOTS+ msg len) | PK | SK | Sig | Seed |
|---|---|---|---|---|---|
ModeM192s (Magnetar-SHAKE-192s) |
24 | 48 | 96 | 16224 | 96 |
ModeM192f (Magnetar-SHAKE-192f) |
24 | 48 | 96 | 35664 | 96 |
ModeM256s (Magnetar-SHAKE-256s) |
32 | 64 | 128 | 29792 | 128 |
Recommended production target: ModeM192s (smallest signatures at
NIST PQ category 3, >=192-bit classical security).
3. Hash domain separation
All cSHAKE calls use function-name "Magnetar" and one of the
following customisation tags:
| Tag | Purpose | Defined in |
|---|---|---|
MAGNETAR-THBSSE-SHARE-DEAL-V1 |
Shamir coefficient stream + EvalPointFromID hash | transcript.go |
MAGNETAR-THBSSE-SLOT-V1 |
Slot binding -> 32-byte slot_id; message digest | thbsse.go |
MAGNETAR-THBSSE-R1-COMMIT-V1 |
Round-1 commit D_i; setup transcript | thbsse.go |
MAGNETAR-THBSSE-SHARE-MAC-V1 |
(reserved for share-MAC envelope) | thbsse.go |
The protocol-wide domain-separation context is the ASCII string
"lux-magnetar-v1" (tagDomainSep).
The FIPS 205 ctx prefix for THBS-SE signatures is "lux-magnetar-thbsse-v1"
followed by the 32-byte slot_id; total length 56 bytes, well under
the FIPS 205 sec 10.2 limit of 255 bytes.
4. Byte-identity claims
4.1 Per-validator standalone
TestMagnetar_Wire_FIPS205Verifiable pins:
For any (sk, message) pair: stripping the canonical 11-byte MAGS
wire header from MarshalBinary(ValidatorSign(sk, nil, message))
recovers the unmodified FIPS 205 bytes that
cloudflare/circl/sign/slhdsa.Verify accepts under
(sk.Pub, message, nil_ctx).
4.2 THBS-SE
TestThbsSE_Wire_FIPS205Verifiable pins:
For any (key, binding, message) triple and any t valid
Round-1/Round-2 pairs: Combine(...) emits a *Signature whose
Bytes field, fed DIRECTLY to cloudflare/circl/sign/slhdsa.Verify
under (key.PublicKey, message, ctxFromSlot(binding)), is accepted.
Additionally, TestThbsSE_PublicCombiner_Determinism pins that any
two disjoint t-sized sub-quora of valid Round-2 reveals produce
byte-equal final signatures. The public combiner is a PURE function
of its inputs.
5. Slashing evidence wire shape
5.1 Equivocation evidence (ThbsSeEvidence)
type ThbsSeEvidence struct {
SlotID [32]byte
PartyID NodeID // [32]byte
PriorDigest [32]byte
PriorR1 ThbsSeRound1Msg
PriorR2 ThbsSeRound2Msg
NewDigest [32]byte
NewR1 ThbsSeRound1Msg
NewR2 ThbsSeRound2Msg
}
Third-party verifier:
VerifyThbsSeEvidence(params, ev, msgPrior, msgNew, bindingPrior, bindingNew) -> bool.
5.2 Malformed-share evidence (ThbsSeShareEvidence)
type ThbsSeShareEvidence struct {
PartyID NodeID
Reason ThbsSeShareEvidenceReason // {slot-mismatch, wire-size, commit-mismatch}
ExpectedD [32]byte // for commit-mismatch
ObservedD [32]byte // for commit-mismatch
PartialSig []byte // for commit-mismatch / wire-size
}
Third-party verifier:
VerifyThbsSeShareEvidence(params, ev, binding, msg) -> bool.
6. Wire codec
Magnetar v1.0 ships canonical MAGS (signature) and MAGG (group key)
frames per wire.go:
Signature: GroupKey:
magic(4) = 'M' 'A' 'G' 'S' magic(4) = 'M' 'A' 'G' 'G'
version(2) = 0x0001 version(2) = 0x0001
mode(1) = {0x01..0x03} mode(1) = {0x01..0x03}
len(4) = FIPS 205 sig size len(4) = FIPS 205 pk size
payload = FIPS 205 sigEncode payload = FIPS 205 (seed||root)
Magic bytes are distinct from sibling protocols (pulsar PULS/PULG, corona CORS/CORG) so cross-protocol frames fail at the first dispatch. Stripping the 11-byte header recovers the unmodified FIPS 205 bytes any verifier accepts.
7. v1.0 open items
See BLOCKERS.md:
MAGNETAR-STRICT-ATOM-V11--- the strict-invariant lift (no seed reconstruction even transiently).MAGNETAR-PVSS-DKG-V11--- the leaderless PVSS-DKG setup variant (v1.0 ships deterministic-dealer reference; production routes through siblingluxfi/thresholdDKG).MAGNETAR-PROOF-TRACK-V11--- EasyCrypt + Lean track for the THBS-SE construction shape.MAGNETAR-DUDECT-V11--- v1.1 dudect harness.MAGNETAR-EXTERNAL-AUDIT-V11--- external cryptographer review.