feat: 해시 기반 간이 DRBG, 그에 기반한 RandUtil (#208)

기존의 Util 내의 함수는 mt_rand에 기반하고 있어서 일반적으론 충분하지만,
게임 내부에서 랜덤 값을 정교하게 제어하고 싶은 경우에는 적절하지 않았음.

따라서 직접 seed를 제어할 수 있는 난수생성기를 추가.
SHA512(seed || blockIdx) 의 형태로 동작하는 DRBG이며, FIPS 표준을 따르는 RNG는 아니지만 암호학적으로 안전한 형태로 구현함.

PHP, TS 두가지 형태로 구현.

Reviewed-on: https://storage.hided.net/gitea/devsam/core/pulls/208
Co-authored-by: hide_d <hided62@gmail.com>
Co-committed-by: hide_d <hided62@gmail.com>
This commit is contained in:
2022-03-12 23:53:16 +09:00
parent c220b3d511
commit 0ab485f122
15 changed files with 1620 additions and 4 deletions
+2
View File
@@ -0,0 +1,2 @@
export type Bytes = ArrayBuffer | DataView | Uint8Array;
export type BytesLike = Bytes | string;
+232
View File
@@ -0,0 +1,232 @@
import { RNG } from "./RNG";
import { sha512 } from 'js-sha512';
import { convertBytesLikeToUint8Array } from "./convertBytesLikeToUint8Array";
import { BytesLike } from "./BytesLike";
const maxRngSupportBit = 53;
const maxInt = 0x1f_ffff_ffff_ffff; // NOTE: b 0, 10000110011, 11...11
const maxIntMore1 = 0x20_0000_0000_0000n; //NOTE: b 0, 10000110100, 00...00
const maxIntMore1f = Number(maxIntMore1);
export const bufferByteSize = 512 / 8; //SHA512
const intBitMapMask = new Map([
[0x1n, 1],
[0x3n, 2],
[0x7n, 3],
[0xfn, 4],
[0x1fn, 5],
[0x3fn, 6],
[0x7fn, 7],
[0xffn, 8],
[0x1ffn, 9],
[0x3ffn, 10],
[0x7ffn, 11],
[0xfffn, 12],
[0x1fffn, 13],
[0x3fffn, 14],
[0x7fffn, 15],
[0xffffn, 16],
[0x1ffffn, 17],
[0x3ffffn, 18],
[0x7ffffn, 19],
[0xfffffn, 20],
[0x1fffffn, 21],
[0x3fffffn, 22],
[0x7fffffn, 23],
[0xffffffn, 24],
[0x1ffffffn, 25],
[0x3ffffffn, 26],
[0x7ffffffn, 27],
[0xfffffffn, 28],
[0x1fffffffn, 29],
[0x3fffffffn, 30],
[0x7fffffffn, 31],
[0xffffffffn, 32],
[0x1ffffffffn, 33],
[0x3ffffffffn, 34],
[0x7ffffffffn, 35],
[0xfffffffffn, 36],
[0x1fffffffffn, 37],
[0x3fffffffffn, 38],
[0x7fffffffffn, 39],
[0xffffffffffn, 40],
[0x1ffffffffffn, 41],
[0x3ffffffffffn, 42],
[0x7ffffffffffn, 43],
[0xfffffffffffn, 44],
[0x1fffffffffffn, 45],
[0x3fffffffffffn, 46],
[0x7fffffffffffn, 47],
[0xffffffffffffn, 48],
[0x1ffffffffffffn, 49],
[0x3ffffffffffffn, 50],
[0x7ffffffffffffn, 51],
[0xfffffffffffffn, 52],
[0x1fffffffffffffn, 53],
]);
function calcBitMask(n: bigint): bigint {
n |= n >> 1n;
n |= n >> 2n;
n |= n >> 4n;
n |= n >> 8n;
n |= n >> 16n;
n |= n >> 32n;
return n;
}
export class LiteHashDRBG implements RNG {
protected buffer!: ArrayBuffer;
protected bufferIdx!: number;
protected hq: DataView;
protected hqIdxPos: number;
public constructor(protected seed: BytesLike, protected stateIdx = 0, bufferIdx = 0) {
if(bufferIdx < 0){
throw new Error(`bufferIdx ${bufferIdx} < 0`);
}
if(bufferIdx >= bufferByteSize){
throw new Error(`bufferidx ${bufferIdx} >= ${bufferByteSize}`);
}
if(stateIdx < 0){
throw new Error(`stateIdx ${stateIdx} < 0`);
}
const seedU8 = convertBytesLikeToUint8Array(seed);
const hqBuffer = new ArrayBuffer(seedU8.byteLength + 4);
const hqU8 = new Uint8Array(hqBuffer);
hqU8.set(seedU8, 0);
this.hq = new DataView(hqBuffer);
this.hqIdxPos = seedU8.byteLength;
this.genNextBlock();
this.bufferIdx = bufferIdx;
}
protected genNextBlock(): void {
this.hq.setUint32(this.hqIdxPos, this.stateIdx, true);
const digest = sha512.arrayBuffer(this.hq.buffer);
this.buffer = digest;
this.bufferIdx = 0;
this.stateIdx += 1;
}
public getMaxInt(): number {
return maxInt;
}
public nextBytes(bytes: number, baseBytes?: number): Uint8Array {
bytes |= 0;
if (bytes <= 0) {
throw new Error(`${bytes} <= 0`);
}
if (this.bufferIdx + bytes <= bufferByteSize) {
if(baseBytes === undefined || bytes >= baseBytes){
const result = this.buffer.slice(this.bufferIdx, this.bufferIdx + bytes);
this.bufferIdx += bytes;
if (this.bufferIdx === bufferByteSize) {
this.genNextBlock();
}
return new Uint8Array(result);
}
const resultBuffer = new ArrayBuffer(Math.max(bytes, baseBytes));
const result = new Uint8Array(resultBuffer);
result.set(new Uint8Array(this.buffer, this.bufferIdx, bytes));
this.bufferIdx += bytes;
if( this.bufferIdx === bufferByteSize){
this.genNextBlock();
}
return result;
}
const resultBuffer = new ArrayBuffer(baseBytes ? Math.max(bytes, baseBytes) : bytes);
const result = new Uint8Array(resultBuffer);
result.set(new Uint8Array(this.buffer, this.bufferIdx));
let offset = bufferByteSize - this.bufferIdx;
let remain = bytes - offset;
while (remain > bufferByteSize) {
this.genNextBlock();
result.set(new Uint8Array(this.buffer), offset);
offset += bufferByteSize;
remain -= bufferByteSize;
}
this.genNextBlock();
if (remain === 0) {
return result;
}
result.set(new Uint8Array(this.buffer, 0, remain), offset);
this.bufferIdx = remain;
return result;
}
public nextBits(bits: number, baseBytes?: number): Uint8Array {
bits |= 0;
const bytes = (bits + 7) >> 3;
const headBits = bits & 0x7;
const result = this.nextBytes(bytes, baseBytes);
if (headBits === 0) {
return result;
}
result[bytes - 1] &= 0xff >> (8 - headBits);
return result;
}
protected _nextInt(bits: number): bigint{
const buffer = this.nextBits(bits, 8);
const dataView = new DataView(buffer.buffer);
return dataView.getBigUint64(0, true);
}
public nextInt(max?: number): number {
if (max === undefined || max === maxInt) {
return Number(this._nextInt(maxRngSupportBit));
}
if (max > maxInt) {
throw new Error('Over max int');
}
if (max === 0) {
return 0;
}
if (max < 0) {
return -this.nextInt(-max);
}
const mask = calcBitMask(BigInt(max));
const bits = intBitMapMask.get(mask) as number;
let n = Number(this._nextInt(bits));
while (n > max){
n = Number(this._nextInt(bits));
}
return n;
}
public nextFloat1(): number {
// eslint-disable-next-line no-constant-condition
while(true){
const nInt = this._nextInt(maxRngSupportBit + 1);
if(nInt < maxIntMore1){
return Number(nInt) / maxIntMore1f;
}
if(nInt === maxIntMore1){
return 1;
}
}
}
public static build(seed: BytesLike, stateIdx = 0): LiteHashDRBG{
return new LiteHashDRBG(seed, stateIdx);
}
}
+13
View File
@@ -0,0 +1,13 @@
export interface RNG {
/**
* nextInt()가 반환 가능한 최대값
*/
getMaxInt(): number;
nextBytes(bytes: number): Uint8Array;
nextBits(bits: number): Uint8Array;
nextInt(max?: number): number;
nextFloat1(): number;
}
+138
View File
@@ -0,0 +1,138 @@
import { RNG } from './RNG';
export class RandUtil {
constructor(protected rng: RNG) {
}
public nextFloat1(): number {
return this.rng.nextFloat1();
}
public nextRange(min: number, max: number): number {
const range = max - min;
return this.nextFloat1() * (range) + min;
}
public nextRangeInt(min: number, max: number): number {
const range = max - min;
return this.rng.nextInt(range) + min;
}
public nextInt(max?: number): number {
return this.rng.nextInt(max);
}
public nextBit(): boolean {
const view = new DataView(this.rng.nextBits(1));
return view.getUint8(0) != 0;
}
public nextBool(prob = 0.5): boolean {
if (prob >= 1) {
return true;
}
return this.nextFloat1() < prob;
}
public shuffle<T>(srcArray: T[]): T[] {
const cnt = srcArray.length;
if(cnt === 0){
return [];
}
if (cnt > this.rng.getMaxInt()) {
throw 'Invalid random int range';
}
const result: T[] = Array.from(srcArray);
for (let srcIdx = 0; srcIdx < cnt; srcIdx += 1) {
const destIdx = this.rng.nextInt(cnt - srcIdx - 1) + srcIdx;
if(srcIdx === destIdx){
continue;
}
[result[srcIdx], result[destIdx]] = [result[destIdx], result[srcIdx]];
}
return result;
}
//Object는 integer key에 예외가 있어 shuffleAssoc은 없음
public choice<T>(items: T[] | Record<string | number, T> | Set<T>): T {
if (items instanceof Array) {
if(items.length === 0){
throw new Error('Empty items');
}
const idx = this.rng.nextInt(items.length - 1);
return items[idx];
}
if (items instanceof Set) {
return this.choice(Array.from(items.values()));
}
return items[this.choice(Array.from(Object.keys(items)))];
}
public choiceUsingWeight(items: Record<string | number, number>): string | number {
if(Object.keys(items).length === 0){
throw new Error('Empty items');
}
let sum = 0;
for (const value of Object.values(items)) {
if (value <= 0) {
continue;
}
sum += value;
}
let rd = this.nextFloat1() * sum;
for (const [item, value] of Object.entries(items)) {
if (value <= 0) {
if (rd <= 0) {
return item;
}
continue;
}
if (rd <= value) {
return item;
}
rd -= value;
}
throw new Error('Unreacheable');
}
public choiceUsingWeightPair<T>(items: [T, number][]): T {
if(items.length === 0){
throw new Error('Empty items');
}
let sum = 0;
for (const [, value] of items) {
if (value <= 0) {
continue;
}
sum += value;
}
let rd = this.nextFloat1() * sum;
for (const [item, value] of items) {
if (value <= 0) {
if (rd <= 0) {
return item;
}
continue;
}
if (rd <= value) {
return item;
}
rd -= value;
}
throw new Error('Unreacheable');
}
}
@@ -0,0 +1,17 @@
import { BytesLike } from "./BytesLike";
export function convertBytesLikeToArrayBuffer(data: BytesLike, encodeUTF8 = true): ArrayBuffer{
if (data instanceof ArrayBuffer) {
return data;
}
if (data instanceof Uint8Array) {
return data.buffer;
}
if (typeof(data) === 'string'){
if(encodeUTF8){
return (new TextEncoder()).encode(data);
}
return new Uint8Array(data.split('').map(s=>s.codePointAt(0) as number));
}
return data.buffer;
}
@@ -0,0 +1,17 @@
import { BytesLike } from "./BytesLike";
export function convertBytesLikeToUint8Array(data: BytesLike, encodeUTF8 = true): Uint8Array {
if (data instanceof Uint8Array) {
return data;
}
if (data instanceof ArrayBuffer) {
return new Uint8Array(data);
}
if (typeof (data) === 'string') {
if(encodeUTF8){
return (new TextEncoder()).encode(data);
}
return new Uint8Array(data.split('').map(s=>s.codePointAt(0) as number));
}
return new Uint8Array(data.buffer);
}