ade_crypto
BLUE- Purpose
Pure cryptographic verification — Praos VRF (draft-03) verify, the Ade-owned BLUE Sum6KES algorithm (
kes_sum/), Ed25519 DSIGN verify, blake2b hashing, and the v2 UTxO-fingerprint primitiveutxo_set_commitment::UtxoSetCommitment(a Ristretto255 ECMH set commitment). UNTOUCHED across the span —ade_cryptois 22. The new self-sustaining-ledger + native-Mithril paths reuseblake2b::blake2b_256(the bound-view canonical-hash identity, the frozen-leadership / bootstrap-bridge canonical commitments, the nativetablesUTxOfingerprint_utxo_v2binding, the reduced-checkpoint fingerprint chain) but add noade_cryptotype.- Creates
KesError,KesParseError, VRF/KES/DSIGN verify types,Sum6key/signature representations,UtxoSetCommitment(the v2 ECMH set commitment). 22 public types.- Interprets
VRF proofs, KES signatures + the expanded
Sum6KESenvelope, Ed25519 signatures;blake2b_256/blake2b_224; the v2 UTxO set commitment.- MUST NOT
(1,
T-KEY-01) Sign anything — verification only; signing custody lives in the REDade_runtime::producershell. (2) Perform I/O / read a clock / use float. (3) Re-implement Sum6KES divergently from Haskellcardano-base. (4) Depend on any workspace crate exceptade_types. (5,DC-MEM-10)utxo_set_commitment— the v2 set commitment stays a NAMED, domain-separated, version-tagged construction; commutative + add/remove-exact-inverse + value-binding; golden-vectors FROZEN; INTERNAL replay-contract only.- Inbound deps
ade_core,ade_ledger,ade_plutus,ade_runtime,ade_node,ade_core_interop,ade_testkit.- Outbound deps
ade_types,blake2,ed25519-dalek,cardano-crypto,curve25519-dalek(v4).- Entry points
ade_crypto::vrf::*,ade_crypto::kes_sum::{Sum6Kes, *},ade_crypto::dsign::*,ade_crypto::blake2b::{blake2b_256, blake2b_224},ade_crypto::utxo_set_commitment::UtxoSetCommitment.- Key modules
vrf/,kes_sum/,dsign/,blake2b.rs,utxo_set_commitment.rs.
Depends on
—
Depended on by
—
CI guards — 6
| Script | Enforces |
|---|---|
| ci_check_crypto_vectors.sh | DC-CRYPTO-01 |
| ci_check_kes_envelope_closed.sh | DC-CRYPTO-06, DC-CRYPTO-07, OP-OPS-04 |
| ci_check_kes_sum_compatibility.sh | DC-CRYPTO-04, DC-CRYPTO-05, DC-CRYPTO-07, DC-CRYPTO-08, DC-CRYPTO-09, OP-OPS-04 |
| ci_check_no_signing_in_blue.sh | DC-CRYPTO-02 |
| ci_check_private_key_custody.sh | DC-CRYPTO-03, DC-CRYPTO-04, DC-CRYPTO-05, DC-CRYPTO-08, OP-OPS-04 |
| ci_check_utxo_fp_v2.sh | DC-MEM-10 |
Related invariants — 8
| ID | Status | Statement |
|---|---|---|
| DC-CRYPTO-01 | enforced | Crypto verification is pure and matches Haskell node on all test vectors |
| DC-CRYPTO-02 | enforced | All signing operations confined to shell |
| DC-CRYPTO-04 | enforced | KES signing transcript equivalence and verification symmetry. For canonical inputs (kes_secret, period, msg) the RED signer produces a KesSignature by… |
| DC-CRYPTO-05 | enforced | KES evolution discipline: evolve(k_i) -> k_{i+1} is one-way. The evolved key signs period i+1 and MUST NOT sign for period i. RED kes_sign is forbidde… |
| DC-CRYPTO-08 | enforced | Ade-owned Sum6KES algorithm is Haskell-equivalent. `ade_crypto::kes_sum::Sum6Kes` is byte-identical to Haskell `cardano-base`'s `Sum6KES Ed25519DSIGN`… |
| DC-CRYPTO-09 | enforced | Sum6KES expanded signing-key serde and period inference. `raw_serialize_signing_key_kes` / `raw_deserialize_signing_key_kes` are byte-identical to Has… |
| DC-MEM-10 | enforced | The v2 UTxO fingerprint component is a NAMED commutative set commitment (Ristretto255 ECMH) binding (TxIn, TxOut) over the canonical encodings, domain… |
| OP-OPS-04 | enforced | Operator-supplied keys. Ade supports both KES key flows: (a) Ade-native `ade_node --mode key_gen_kes --out-file PATH` emitting an `ade.kes.seed.v1` en… |