begin static method

Future<({MlDsaSigningMessage round1, MlDsaSigningSession session})> begin({
  1. required MlDsaShare share,
  2. required Uint8List message,
  3. required MlDsaPublicKey publicKey,
  4. required List<int> activePartyIdsZeroBased,
  5. String? mithrilBridgePath,
})

Starts Round1 for share against publicKey and activePartyIdsZeroBased.

Implementation

static Future<({
  MlDsaSigningMessage round1,
  MlDsaSigningSession session,
})> begin({
  required MlDsaShare share,
  required Uint8List message,
  required MlDsaPublicKey publicKey,
  required List<int> activePartyIdsZeroBased,
  String? mithrilBridgePath,
}) async {
  if (paramsSchemeMismatch(share, publicKey)) {
    throw WrongCeremony('Share/publicKey ceremony mismatch');
  }
  if (share.params.scheme != SchemeId.mlDsa44ThresholdV1) {
    throw SchemeNotImplemented('Distributed ML-DSA supports mlDsa44ThresholdV1');
  }
  final active = [...activePartyIdsZeroBased]..sort();
  if (active.length < share.params.t) {
    throw InvalidParams('active set must have at least t=${share.params.t} parties');
  }
  if (!active.contains(share.mithrilPartyId)) {
    throw InvalidParams('Share party ${share.mithrilPartyId} not in active set');
  }

  final binding = mlDsaMessageBinding(
    ceremonyId: share.ceremonyId,
    jointPublicKey: publicKey.bytes,
    message: message,
  );
  final sessionId = await mithrilDeriveSessionId(
    t: share.params.t,
    n: share.params.n,
    publicKey: publicKey.bytes,
    activePartyIdsZeroBased: active,
    message: message,
    binding: binding,
    executablePath: mithrilBridgePath,
  );
  final hash = await mithrilRound1Party(
    t: share.params.t,
    n: share.params.n,
    ceremonySeed: share.ceremonySeedBytes(),
    partyIdZeroBased: share.mithrilPartyId,
    activePartyIdsZeroBased: active,
    message: message,
    sessionId: sessionId,
    executablePath: mithrilBridgePath,
  );
  final round1 = MlDsaSigningMessage.round1(
    params: share.params,
    ceremonyId: share.ceremonyId,
    senderIndex: share.index,
    sessionId: sessionId,
    commitmentHash: hash,
  );
  final session = MlDsaSigningSession._(
    params: share.params,
    ceremonyId: Uint8List.fromList(share.ceremonyId),
    signerIndex: share.index,
    message: Uint8List.fromList(message),
    sessionId: Uint8List.fromList(sessionId),
    activePartyIdsZeroBased: active,
    publicKeyFingerprint: Uint8List.fromList(publicKey.fingerprint),
    ceremonySeed: SecretBuffer(share.ceremonySeedBytes()),
  );
  return (round1: round1, session: session);
}