# Cryptographic Schemes ## `PoseidonHash` Function Poseidon is a circuit friendly permutation hash function described in the paper GKRRS2019. | Parameter | Setting | |-------------------|--------------------------------| | S-box | $x โ†’ xโต$ | | Full rounds | 8 | | Partial rounds | 56 | Our usage matches that of the halo2 library. Namely using a sponge configuration with addition which defines the function $$\textrm{PoseidonHash} : ๐”ฝโ‚š ร— โ‹ฏ ร— ๐”ฝโ‚š โ†’ ๐”ฝโ‚š$$ ## Bulla Commitments Given an abstract hash function such as [`PoseidonHash`](#poseidonhash-function), we use a variant of the commit-and-reveal scheme to define anonymized representations of objects on chain. Contracts then operate with these anonymous representations which we call bullas. Let $\textrm{Params} โˆˆ ๐”ฝโ‚šโฟ$ represent object parameters, then we can define $$ \textrm{Bulla} : ๐”ฝโ‚šโฟ ร— ๐”ฝโ‚š โ†’ ๐”ฝโ‚š $$ $$ \textrm{Bulla}(\textrm{Params}, r) = \textrm{PoseidonHash}(\textrm{Params}, r) $$ where $r โˆˆ ๐”ฝโ‚š$ is a random blinding factor. Then the bulla (on chain anonymized representation) can be used in contracts with ZK proofs to construct statements on $\textrm{Params}$. ## Pallas and Vesta DarkFi uses the elliptic curves Pallas and Vesta that form a 2-cycle. We denote Pallas by $โ‚š$ and Vesta by $แตฅ$. Set the following values: $$ p = 0x40000000000000000000000000000000224698fc094cf91b992d30ed00000001 $$ $$ q = 0x40000000000000000000000000000000224698fc0994a8dd8c46eb2100000001 $$ We now construct the base field for each curve $Kโ‚š$ and $Kแตฅ$ as $Kโ‚š = ๐”ฝโ‚š$ and $Kแตฅ = ๐”ฝ_q$. Let $f = yยฒ - (xยฒ + 5) โˆˆ โ„ค[x, y]$ be the Weierstrauss normal form of an elliptic curve. We define $fโ‚š = f \mod{Kโ‚š}$ and $fแตฅ = f \mod{Kแตฅ}$. Then we instantiate Pallas as $Eโ‚š = V(fโ‚š)$ and $Eแตฅ = V(fแตฅ)$. Now we note the 2-cycle behaviour as $$ \#V(fโ‚š) = q $$ $$ \#V(fแตฅ) = p $$ An additional projective point at infinity $โˆž$ is added to the curve. Let $โ„™โ‚š$ be the group of points with $โˆž$ on $Eโ‚š$. Let $โ„™แตฅ$ be the group of points with $โˆž$ on $Eแตฅ$. Arithmetic is mainly done in circuits with $๐”ฝโ‚š$ and $Eโ‚š$. ### Coordinate Extractor for Pallas Let $โ„™โ‚š, โˆž, ๐”ฝโ‚š$ be defined as [above](#pallas-and-vesta). Define $\mathcal{X} : โ„™โ‚š โ†’ ๐”ฝโ‚š$ such that $$ \mathcal{X}(โˆž_{Eโ‚š}) = 0 $$ $$ \mathcal{X}((x, y)) = x $$ $$ \mathcal{Y}(โˆž_{Eโ‚š}) = 0 $$ $$ \mathcal{Y}((x, y)) = y $$ **Note:** There is no $P = (0, y) โˆˆ Eโ‚š$ so $\mathcal{X}(P) = 0 โŸน P = โˆž$. Likewise there is no $P = (x, 0) โˆˆ Eโ‚š$ so $\mathcal{Y}(P) = 0 โŸน P = โˆž$. ### Encoding and Decoding for $๐”ฝโ‚š$ Define $๐”ฝโ‚š2๐”นยณยฒ : ๐”ฝโ‚š โ†’ ๐”นยณยฒ$ as encoding the canonical representation of $๐”ฝโ‚š$ in little endian byte format. Define $๐”นยณยฒ2๐”ฝโ‚š : ๐”นยณยฒ โ†’ ๐”ฝโ‚š$ as the matching decoding of $๐”ฝโ‚š$ modulo the canonical class in little endian byte format. ## BLAKE3 Hash Function BLAKE3 is defined by [CANW2021](https://raw.githubusercontent.com/BLAKE3-team/BLAKE3-specs/master/blake3.pdf). $$ \t{BLAKE3}: ๐”น^* โ†’ ๐”นยณยฒ $$