| 172 | } |
| 173 | |
| 174 | pub fn aggregate(sig_shares: Vec<Self>) -> Result<SignatureG1<E>, BBSPlusError> { |
| 175 | // TODO: Ensure correct threshold. Share should contain threshold and share id |
| 176 | let mut sum_R = E::G1::zero(); |
| 177 | let mut sum_u = E::ScalarField::zero(); |
| 178 | let mut expected_e = E::ScalarField::zero(); |
| 179 | let mut expected_s = E::ScalarField::zero(); |
| 180 | for (i, share) in sig_shares.into_iter().enumerate() { |
| 181 | if i == 0 { |
| 182 | expected_e = share.e; |
| 183 | expected_s = share.s; |
| 184 | } else { |
| 185 | if expected_e != share.e { |
| 186 | return Err(BBSPlusError::IncorrectEByParticipant(share.id)); |
| 187 | } |
| 188 | if expected_s != share.s { |
| 189 | return Err(BBSPlusError::IncorrectSByParticipant(share.id)); |
| 190 | } |
| 191 | } |
| 192 | sum_u += share.u; |
| 193 | sum_R += share.R; |
| 194 | } |
| 195 | let A = sum_R * sum_u.inverse().unwrap(); |
| 196 | Ok(SignatureG1 { |
| 197 | A: A.into_affine(), |
| 198 | e: expected_e, |
| 199 | s: expected_s, |
| 200 | }) |
| 201 | } |
| 202 | } |
| 203 | |
| 204 | #[cfg(test)] |