Documentation Index
Fetch the complete documentation index at: https://mintlify.com/octra-labs/pvac_hfhe_cpp/llms.txt
Use this file to discover all available pages before exploring further.
Overview
The commitment module provides cryptographic commitment functions for binding to ciphertext values. Commitments allow proving that a ciphertext was generated before a certain point without revealing the encrypted value.Core commitment function
commit_ct
Generates a SHA-256 commitment hash of a ciphertext.
Public key associated with the ciphertext
Ciphertext to commit to
256-bit SHA-256 commitment digest
Description
Computes a cryptographic commitment to a ciphertext by hashing all of its components using SHA-256:- Domain separator:
Dom::COMMITstring - Public key binding:
pk.H_digest(32 bytes) andpk.canon_tag(8 bytes) - Layer structure: For each layer in
C.L:- Layer rule type (BASE or PROD)
- For BASE layers: seed tag, nonce (lo, hi)
- For PROD layers: parent layer indices (pa, pb)
- Slot count:
C.slots - Constant term: Each field element in
C.c0(lo, hi words) - Edges: For each edge in
C.E:- Layer ID, position index, charge/sign
- Weight vector
w(all field elements) - Sigma bitvector
s(all bits)
The commitment includes the full ciphertext structure, making it binding to both the encrypted value and the specific encryption instance.
Commitment properties
Binding
The commitment is binding: Given a commitmenth = commit_ct(pk, C), it is computationally infeasible to find a different ciphertext C' such that commit_ct(pk, C') = h.
This is guaranteed by the collision resistance of SHA-256.
Hiding
The commitment is NOT hiding: The commitment reveals structural information about the ciphertext (number of layers, edges, slots). However, it does not reveal the encrypted plaintext value.Deterministic
The commitment is deterministic: Committing to the same ciphertext with the same public key always produces the same hash.Use cases
Timestamping
Commit to a ciphertext and publish the commitment hash to prove the ciphertext existed at a certain time:Verifiable encryption
Prove that an encrypted value was produced without modifying it later:Ciphertext integrity
Detect if a ciphertext has been modified:Implementation details
Domain separation
The commitment uses the domain separatorDom::COMMIT to prevent hash collision attacks across different protocol contexts. This ensures commitments cannot be confused with other hash-based operations.
Field element encoding
Field elements (Fp) are encoded as two 64-bit words:
lo: Lower 64 bitshi: Upper 63 bits (withMASK63applied)
Bitvector encoding
Sigma bitvectors (BitVec) are encoded byte-by-byte:
- Compute byte count:
bytes = (s.nbits + 7) / 8 - Encode full 8-byte words from
s.w[]in little-endian - Encode remaining bytes if
bytes % 8 != 0
Example usage
Security considerations
Public key binding: The commitment includes
pk.H_digest and pk.canon_tag. Ciphertexts encrypted under different public keys will have different commitments even if they encrypt the same value.Performance
Commitment computation time is proportional to the ciphertext size:- Fixed cost: ~1 KB hashed for public key and metadata
- Per layer: ~50-100 bytes (depending on rule type)
- Per edge: ~200-500 bytes (depending on slot count and sigma bits)
- Small ciphertexts (few edges): < 1 microsecond
- Large ciphertexts (100s of edges): < 100 microseconds
Comparison with other commitments
| Property | commit_ct | Pedersen commitment | Hash commitment |
|---|---|---|---|
| Binding | ✓ | ✓ | ✓ |
| Hiding | ✗ | ✓ | ✓ (with randomness) |
| Homomorphic | ✗ | ✓ | ✗ |
| Deterministic | ✓ | ✗ | ✗ (typically) |
| Quantum-safe | ✓ | ✗ | ✓ |
commit_ct is optimized for binding to the full ciphertext structure rather than just the encrypted value. For value-only commitments, consider committing to the decrypted result with added randomness.