Skip to main content

Module hashing

Module hashing 

Source
Expand description

The XMSS hash layer: tweak_hash is the BLAKE3 keyed hash of the payload under pp | tweak, truncated to 16 bytes, for chain steps, Merkle nodes, WOTS public keys and message encodings alike.

The 16-byte tweak makes every call site a distinct hash function, which is what separates the many targets an attacker may aim at, and the public parameter separates users. Together they are 32 bytes, exactly a BLAKE3 key, so the whole of the domain fits the key with nothing left to pad — two distinct (pp, tweak) pairs are two distinct keys.

Keying is BLAKE3’s own domain separation: the key replaces the initial chaining value and every compression carries KEYED_HASH. The payload is then the entire message, and the full construction binds its length, so no digest extends into the digest of a longer payload.

Constants§

TWEAK_LEN
Tweak length in bytes.
TWEAK_TYPE_CHAIN
Tweak type for a chain step.
TWEAK_TYPE_ENCODING
Tweak type for the message encoding.
TWEAK_TYPE_MERKLE
Tweak type for an internal Merkle node.
TWEAK_TYPE_WOTS_PK
Tweak type for a WOTS public-key (Merkle leaf) hash.

Functions§

circuit_tweak_hash
In-circuit form of tweak_hash, returning the truncated digest as 64-bit little-endian wires.
circuit_tweak_hash_2x
Two independent tweak hashes evaluated as the two lanes of one core.
make_key
The key a call site hashes under: pp | tweak, the full 32 bytes of a BLAKE3 key.
make_tweak
Builds a tweak.
tweak_hash
The BLAKE3 keyed hash of payload under pp | tweak, truncated to DIGEST_LEN.

Type Aliases§

Tweak
A tweak: [tweak_type (1) | sub_position (4) | index (4) | zeros (7)], little-endian.