Expand description
The XMSS hash layer: tweak_hash is the BLAKE3 keyed hash of the payload under pp | tweak,
truncated to 16 bytes, for chain steps, Merkle nodes, WOTS public keys and message encodings
alike.
The 16-byte tweak makes every call site a distinct hash function, which is what separates the
many targets an attacker may aim at, and the public parameter separates users. Together they
are 32 bytes, exactly a BLAKE3 key, so the whole of the domain fits the key with nothing left
to pad — two distinct (pp, tweak) pairs are two distinct keys.
Keying is BLAKE3’s own domain separation: the key replaces the initial chaining value and every
compression carries KEYED_HASH. The payload is then the entire message, and the full
construction binds its length, so no digest extends into the digest of a longer payload.
Constants§
- TWEAK_
LEN - Tweak length in bytes.
- TWEAK_
TYPE_ CHAIN - Tweak type for a chain step.
- TWEAK_
TYPE_ ENCODING - Tweak type for the message encoding.
- TWEAK_
TYPE_ MERKLE - Tweak type for an internal Merkle node.
- TWEAK_
TYPE_ WOTS_ PK - Tweak type for a WOTS public-key (Merkle leaf) hash.
Functions§
- circuit_
tweak_ hash - In-circuit form of
tweak_hash, returning the truncated digest as 64-bit little-endian wires. - circuit_
tweak_ hash_ 2x - Two independent tweak hashes evaluated as the two lanes of one core.
- make_
key - The key a call site hashes under:
pp | tweak, the full 32 bytes of a BLAKE3 key. - make_
tweak - Builds a tweak.
- tweak_
hash - The BLAKE3 keyed hash of
payloadunderpp | tweak, truncated toDIGEST_LEN.
Type Aliases§
- Tweak
- A tweak:
[tweak_type (1) | sub_position (4) | index (4) | zeros (7)], little-endian.