|
| 1 | +from __future__ import annotations |
| 2 | +from Crypto.Util.number import inverse |
| 3 | +from secrets import randbits |
| 4 | +from mife.common import getStrongPrime |
| 5 | +from math import gcd |
| 6 | +from gmpy2 import mpz |
| 7 | + |
| 8 | + |
| 9 | +class PaillierKey: |
| 10 | + def __init__(self, n, g, lcm=None): |
| 11 | + self.n = n |
| 12 | + self.g = g |
| 13 | + self.lcm = lcm |
| 14 | + self.n2 = self.n ** 2 |
| 15 | + if lcm is not None: |
| 16 | + self.u = inverse(lcm, n) |
| 17 | + |
| 18 | + def getPublicKey(self): |
| 19 | + return PaillierKey(self.n, self.g) |
| 20 | + |
| 21 | + def hasPrivateKey(self): |
| 22 | + return self.u is not None |
| 23 | + |
| 24 | + def encrypt(self, m: int): |
| 25 | + while True: |
| 26 | + r = randbits(self.n.bit_length()) |
| 27 | + if r < self.n and gcd(r, self.n) == 1: |
| 28 | + break |
| 29 | + return PaillierElem(self.getPublicKey(), (pow(self.g, m, self.n2) * pow(r, self.n, self.n2)) % self.n2) |
| 30 | + |
| 31 | + def decrypt(self, c: PaillierElem) -> int: |
| 32 | + if not self.hasPrivateKey(): |
| 33 | + raise ValueError("No private key") |
| 34 | + return (((pow(c.c, self.lcm, self.n2) - 1) // self.n) * self.u) % self.n |
| 35 | + |
| 36 | + |
| 37 | +class PaillierElem: |
| 38 | + def __init__(self, pk: PaillierKey, c: int): |
| 39 | + self.pk = pk |
| 40 | + self.c = c |
| 41 | + |
| 42 | + def __add__(self, other): |
| 43 | + if self.pk.n != other.pk.n: |
| 44 | + raise ValueError("Different public keys") |
| 45 | + return PaillierElem(self.pk, (self.c * other.c) % self.pk.n2) |
| 46 | + |
| 47 | + def __radd__(self, other): |
| 48 | + if other == 0: |
| 49 | + return self |
| 50 | + raise ValueError("Invalid operation") |
| 51 | + |
| 52 | + def __rmul__(self, other: int): |
| 53 | + return PaillierElem(self.pk, pow(self.c, other, self.pk.n2)) |
| 54 | + |
| 55 | + |
| 56 | +class Paillier: |
| 57 | + @staticmethod |
| 58 | + def generate(bits=1024, p=None, q=None): |
| 59 | + if p is None: |
| 60 | + p = getStrongPrime(bits) |
| 61 | + if q is None: |
| 62 | + q = getStrongPrime(bits) |
| 63 | + n = p * q |
| 64 | + g = n + 1 |
| 65 | + lcm = (p - 1) * (q - 1) // gcd(p - 1, q - 1) |
| 66 | + return PaillierKey(mpz(n), mpz(g), mpz(lcm)) |
| 67 | + |
| 68 | + |
| 69 | + |
| 70 | + |
| 71 | + |
0 commit comments