.. DO NOT EDIT. .. THIS FILE WAS AUTOMATICALLY GENERATED BY SPHINX-GALLERY. .. TO MAKE CHANGES, EDIT THE SOURCE PYTHON FILE: .. "api/gallery/crypto/commitments/plot_02_pedersen.py" .. LINE NUMBERS ARE GIVEN BELOW. .. only:: html .. note:: :class: sphx-glr-download-link-note :ref:`Go to the end ` to download the full example code or to run this example in your browser via JupyterLite. .. rst-class:: sphx-glr-example-title .. _sphx_glr_api_gallery_crypto_commitments_plot_02_pedersen.py: Pedersen commitments: perfectly hiding and additive (1991) ========================================================== Pedersen committed to a value v as C = g**v * h**r, with a random blinding factor r and a second generator h whose logarithm nobody knows. For any other value there is a blinding factor giving the same C, so the commitment hides v perfectly; opening it to a different value would reveal log_g(h). And commitments multiply to a commitment of the sum. What to look for ---------------- Two commitments multiply into a commitment to the total, without anyone seeing the amounts. This homomorphism is how confidential transactions (Monero, Mimblewimble) let anyone check that inputs equal outputs. The history behind this experiment: :doc:`/history/crypto_breakthroughs`. .. GENERATED FROM PYTHON SOURCE LINES 22-24 Commit and add -------------- .. GENERATED FROM PYTHON SOURCE LINES 24-39 .. code-block:: Python import matplotlib.pyplot as plt import blockchainkit as bk G = bk.crypto.TEACHING_GROUP g, h = bk.crypto.pedersen_generators(G) inputs = [(40, 1111), (2, 2222)] # (amount, blinding factor) outputs = [(30, 1500), (12, 1833)] c_in = [bk.crypto.pedersen_commit(v, r) for v, r in inputs] c_out = [bk.crypto.pedersen_commit(v, r) for v, r in outputs] balance_in = c_in[0] * c_in[1] % G.p balance_out = c_out[0] * c_out[1] % G.p assert balance_in == balance_out # 40 + 2 == 30 + 12, blindings also balance. print("Inputs and outputs balance without revealing any amount") .. rst-class:: sphx-glr-script-out .. code-block:: none Inputs and outputs balance without revealing any amount .. GENERATED FROM PYTHON SOURCE LINES 40-42 Perfect hiding in a group small enough to search ------------------------------------------------ .. GENERATED FROM PYTHON SOURCE LINES 42-50 .. code-block:: Python small = bk.crypto.DHGroup(1019, 509, 4) target = bk.crypto.pedersen_commit(7, 100, small) for value in (7, 8, 500): blinding = next( r for r in range(small.q) if bk.crypto.pedersen_commit(value, r, small) == target ) print(f"the same commitment opens as value {value} with blinding {blinding}") .. rst-class:: sphx-glr-script-out .. code-block:: none the same commitment opens as value 7 with blinding 100 the same commitment opens as value 8 with blinding 272 the same commitment opens as value 500 with blinding 402 .. GENERATED FROM PYTHON SOURCE LINES 51-53 Commitments look uniform whatever the value ------------------------------------------- .. GENERATED FROM PYTHON SOURCE LINES 53-64 .. code-block:: Python from random import Random rng = Random(1991) zeros = [bk.crypto.pedersen_commit(0, rng.randrange(small.q), small) for _ in range(2000)] hundreds = [bk.crypto.pedersen_commit(100, rng.randrange(small.q), small) for _ in range(2000)] fig, ax = plt.subplots(figsize=(7, 3.5)) ax.hist([zeros, hundreds], bins=20, label=["commit(0, r)", "commit(100, r)"]) ax.set(xlabel="commitment value", ylabel="count", title="Random blinding hides the amount") ax.legend() fig.tight_layout() .. image-sg:: /api/gallery/crypto/commitments/images/sphx_glr_plot_02_pedersen_001.png :alt: Random blinding hides the amount :srcset: /api/gallery/crypto/commitments/images/sphx_glr_plot_02_pedersen_001.png :class: sphx-glr-single-img .. GENERATED FROM PYTHON SOURCE LINES 65-70 Exercise -------- Suppose a dishonest committer knew x = log_g(h). Show how they could open C = g**v * h**r as any other value v' by choosing r'. Why must h be derived by hashing rather than chosen by a participant? .. rst-class:: sphx-glr-timing **Total running time of the script:** (0 minutes 0.200 seconds) .. _sphx_glr_download_api_gallery_crypto_commitments_plot_02_pedersen.py: .. only:: html .. container:: sphx-glr-footer sphx-glr-footer-example .. container:: lite-badge .. image:: images/jupyterlite_badge_logo.svg :target: ../../../../lite/lab/index.html?path=api/gallery/crypto/commitments/plot_02_pedersen.ipynb :alt: Launch JupyterLite :width: 150 px .. container:: sphx-glr-download sphx-glr-download-jupyter :download:`Download Jupyter notebook: plot_02_pedersen.ipynb ` .. container:: sphx-glr-download sphx-glr-download-python :download:`Download Python source code: plot_02_pedersen.py ` .. container:: sphx-glr-download sphx-glr-download-zip :download:`Download zipped: plot_02_pedersen.zip ` .. only:: html .. rst-class:: sphx-glr-signature `Gallery generated by Sphinx-Gallery `_