From 6fd40774e7ab0369496378c1a57a1b27ba9ebe0f Mon Sep 17 00:00:00 2001 From: Matheus Franco Date: Mon, 9 Oct 2023 13:28:23 +0100 Subject: [PATCH 1/6] RSA SIP --- all.md | 21 +++++----- networking.md | 5 ++- .../asymmetric_scheme_performance.png | Bin 0 -> 56936 bytes sips/rsa_network_authentication.md | 36 ++++++++++++++++++ 4 files changed, 50 insertions(+), 12 deletions(-) create mode 100644 sips/images/rsa_network_authentication/asymmetric_scheme_performance.png create mode 100644 sips/rsa_network_authentication.md diff --git a/all.md b/all.md index ba8c694..3bcd3ca 100644 --- a/all.md +++ b/all.md @@ -1,12 +1,13 @@ ## All SIPS -| SIP # | Title | Status | -|---------------------------------------|-----------------------------|--------| -| [1](./sips/dkg.md) | DKG | open-for-discussion | -| [2](./sips/msg_struct_encoding.md) | Message struct and encoding | open-for-discussion | -| [3](./sips/qbft_sync.md) | QBFT Sync | open-for-discussion | -| [4](./sips/change_operator.md) | Change operators set | open-for-discussion | -| [5](./sips/ecies_share_encryption.md) | ECIES Share Encryption | open-for-discussion | -| [6](./sips/constant_qbft_timeout.md) | Constant QBFT timeout | open-for-discussion | -| [7](./sips/fork_support.md) | Fork Support | open-for-discussion | -| [8](./sips/pre_consensus_livness.md) | Pre-Consensus livness fix | open-for-discussion | \ No newline at end of file +| SIP # | Title | Status | +|-------------------------------------------|-----------------------------|---------------------| +| [1](./sips/dkg.md) | DKG | open-for-discussion | +| [2](./sips/msg_struct_encoding.md) | Message struct and encoding | open-for-discussion | +| [3](./sips/qbft_sync.md) | QBFT Sync | open-for-discussion | +| [4](./sips/change_operator.md) | Change operators set | open-for-discussion | +| [5](./sips/ecies_share_encryption.md) | ECIES Share Encryption | open-for-discussion | +| [6](./sips/constant_qbft_timeout.md) | Constant QBFT timeout | open-for-discussion | +| [7](./sips/fork_support.md) | Fork Support | open-for-discussion | +| [8](./sips/pre_consensus_livness.md) | Pre-Consensus livness fix | open-for-discussion | +| [9](./sips/rsa_network_authentication.md) | RSA Network Authentication | open-for-discussion | \ No newline at end of file diff --git a/networking.md b/networking.md index d910ad7..74e2c30 100644 --- a/networking.md +++ b/networking.md @@ -1,4 +1,5 @@ ## Core -| SIP # | Title | Status | -|-------------------------------|-----------------------------|--------| +| SIP # | Title | Status | +| ----------------------------------------- | -------------------------- | ------------------- | +| [9](./sips/rsa_network_authentication.md) | RSA Network Authentication | open-for-discussion | \ No newline at end of file diff --git a/sips/images/rsa_network_authentication/asymmetric_scheme_performance.png b/sips/images/rsa_network_authentication/asymmetric_scheme_performance.png new file mode 100644 index 0000000000000000000000000000000000000000..a120af1b354192154fb4b43c1681be22366afae4 GIT binary patch literal 56936 zcmeFa2UwKpwk3>htKHg$R?LVAFo2*UDhQZEiHKy$Dhd)LBa*Rgvx1fgB2fX!AUT7! zA|fJ^g9H_jPz1>W0<(4rp6+w|-nnz;&fI67|F5S{9~+CWzVN<#uf5jVyRIHNynp)C zMN>IAIHofW?2+T(m{h>QF>&5clkpSo)A{1~KT(UlM=j)ybu6roo1Nm2K5k)RXl!Aq zcVgMuQ)cFR#zw+|TLd=>EIVysVPY;OBy{Hc8w8EbbcNPvG&tfQKbss-G3Vfzd7Szo5)z(K9EJsH>%N}3&;o5IW*VV2K{r1RBP0&LtH!$3A!n*Fw z#l_o1;?-j|#=m~I;*4d;A!DgCsYS2V%@_qHyz@DQPsz$I-?_tMVEBVe&aciZeh~hn z+f+l{y<1fGjdfu9LvSVe>|CeXs$yy7m0Aro2S#U z(ZstdGWYh%{lyV#TLuOPU!B~jR}!kInq>0e5Z@i=rQ0>@MeZNsllIsc_%dJ3b!tlX zDy!ZaVdfv#lomT}@#5Jqg`LBvZ<{-N_QOfj=4~x*{gRZl zRWU+U@xg-!gFQtu=G8&+L5C|7jeS4X)lI99Pa8>5PqAQVYHHr!YWh&qwoQcPprWFZ zVmA;|Rb72*qleK@TG`^whWA#iSmFB4rL(!Y+04}R_Vw#h=Y7j$@8LfCh!0$P+L3JD zSRAe*92gLA`mNtix=tpO8E4g@X+JvLUzutZW!X2-kn4VGvu8tlyJoQEySmD7jZ~$p zSFe_4-@bkO{x+*fzC-u?276g**^9Rrg-@Qoh_l6h8V85TD*lY^8dy48Z_(Y&$jG>M zV|K{C?4af>aw{>d831`$i&#YOq#?0J2R#GrjOR1u+(xR6si#NuuRid zdfGgJm(iC@vAla6NBbQs)2w4vYrxYXARq&t>G8ngc&eUdT^w&CO+S%JTG&BUxSR!^h*KOSv>%D=ieC_0Na&iVg zTwZEssD@vCtrP2W?&Hr4W`$v?m#BHM-_D8F=gtN1x;S;w#*dTLN(J&ZXt;g9~Zt=?!&t{$@+UWXaL$?Ik2l<1Bfk#|jP7J%VWDAP-piM7aTfI* z9YV&&#u8uNUl6nIs+Tsn9hp&!H!w8B%9^jGprquMw;?KXb7Ge&ZNioNZX6lt zYKVx+!h)S@vBs^c{atH6p5fx~j?4RQF4DsvnE`Y8m2gh`x;}qCa(&)9&bf2%)+J4u z$zA+x=5~SY+qcuBIhE@s>UNa&@T0@tp<20Y@IOEyZQ5%KNswp&=@fHg_>@Ajq$oln5=UT;3SILnt+RqlU5NvF|e7M~E zS~&lx`?jB_O_Rqd(1KtTVh6vop(%LDTQ?7Yk@nj0h-vc$X}!>8-b8je^~zNiD^Mv)Gh)KT$p@Hj zLRyh=ahs+u5mTUB?7U=KPkU-dOMT8A)eO7jco)Rq2t+!hg$ik{Zk$k4jcvzW7Z;Zo z&P(_avF$%UozhYs?Z4TmD!4R4?Op43yDuhp*QqJpStV22S(h!M`-W@!;?0M!JySne zmqu!YX=gj@y?=6^*75m?Q+lvbTb`VsIM|k0YbG$WFw@a-(xgdxgFVfI!~M0rxJdqG z%XSFsynfu?-5Q(U(w)D(%xS_z3Tne$xk4=!v5nHUZdlPVF)=+Ay1r{RZQ3N0pQE$c z6FE_+tvq@+?v-M?O>a-$mf8i}tN8h)s#C3$S)~!ZrE12_jlPbh?~F4e5VQ1}-agnO zp{1#L9eZiGKXbH1UPdA?wIf3f5&dUf zV{5A+*4)igt>w{fA_k>LHwp`zx2j?7NFk5+c7FcwY#ra7oY`~do?0Sx@LFMdY z`S~rALRvBB8nST_@4Axp?AbG>mzUv^ZRbAw?PZ?ArUX1VG0yEW!HHz&s;f5 z(_347s27*fD?N1c=FRv6F|Y57~~H*G3jk@HDHJNl>ql1^;g>4HCWS_f0Q2US}u<8xQ!Y&5Gs z;5q!qAAfZ9sHz(vqRwNu^|Hzu%g+wm8$^HYb|_D=46`)E@6Kb)laZ0}9O}9-Q}U&0 z>ri`YeqpfeN+}zg6wB9!o7E5&4G@c+EyEdi_}mc9KPAuP;Bb2Q!c34IIStApDROe# zecp*=ykA)NjY5BWwPLba1DDidbz`h;eXO(lo6qPk>F(~16;w1!fB*g%E8LXP)!$#H zVO1T7y{wWAq!kgnH#Q~)IVqqpP>L0q+Fsa^IqI<3d(pJ%)9(T;^mevar&`v({1rEE z2ZO;7v+WCi<0BDPT&w`BYF`rJ z{?N$;u&;USY&dtV!du+$o+!s*sm6TYvabW(B8VK5e*Ez?t~J?VwLt>HQ*KF#;)N+Q z6P%GD)`*K&eHKmbHE$bg+h^3L8m^hH$_y9Ih@HMvQd}lGQ{(B=r}Q*>P5ZQju#!|z zG~{mZsqQCml`E7P>^M3yIMk6D(UBSuz+>4_qp{zas{l`*M`KtWadt-2%iAmW77{#< zSV5J_>J`hEFISB|aS;$G3i$mrwj~{)_w%!v{9gGG&u7_Xwwe(gma5j0=(+)g|T0<2$$ha;l2jpA!t#p%Mlyu1{`l-79;o3XMEWL=vp zVq7Dhm7Ps-o6tPoEuvS*W8amt>Qep?l8$2ZiM`g=))hAvr`L*$ivv{o`ulpO>r`|N zs;WC`Eh>?J8yS^fR;J8UK!R7#j%7Jty?Q(AL;-(P8ne!R3&ILx)GoLyEGi=u!7SLQ zIz_)Y`1Xq%3;l8H=ILt@r1?#R>dF$Z)(ROX=o9;eFDcn-!Z215qkj zqIPOjwROn9vy|@+!;)31Se;^7600jy5+c8!!oCkc#SfwxvO$H$j_&Pdz3w?tVBo8YjhPQ7N5$xhU8iISVAz6uNz))7)qx~2U!fBR^h zisbVHeFEA*~sb||-XW!E8Pj(!2 zcvkTYXIS*%+2#1t1uGgp}@-IkVS%Z(INv z3~(#%i&=(Z51d?*=^ZGFJ1ZDl5$?a=rSi38euTT4Y^;tna8%!;jzlbRek5C+&4X=e zwMP5<41NV51THR5_epy-!u`Ib<$h3qA~wk68C=2G>n$I%uItxkq(3_3v5R;Dt{-xf zvAj6XQyLMA-DKO=xOkm>LAtHgnRf}&l-rzvINq4(SZZ$FwyiN(7kj!?N)X=zYzywZEI@)w0BTOCb7cJetL{< zFRDuL2P56SqxD;BZbs(BqgW}yJ82P!IebmB6yLBxR?1DF0QJDirAvLk#<|vsmz4=J z%s;)(>EB?B;);PiY?R@gY(I21@X@1B3u>daFC$hP4LYQvte}<8x>sSSv}eyApEnwB zV{}b3M@NP>*L7qJMM}KNiN!9kY%P~vio_V18JE;I>`m2H1nRj^jno9hvZ?8Zkx0{y z@qy>r@#_LfyChUx#X&Ml5!GdIn<|l_>FNQ;Phs*_&l#pi#6mdh^Hn`T&>hBS)zexiES9CX@F&sD?%*R|ukl z>Q`KE`=jg)9)}jKKju_(u5LO*xlB1j2|$l35NTgY4J;0&M5F5ZmX^?!`<+i?VGQOw zj`)Lf+UgQj717<-uRfafUArhoZ(9V^xq zwSNy_QDaKvS^O<>)7v~CgWQS=6&H!VqmhjcZSiGsXWLY(QDfQQIvPHHd^l6`%Z`N$ z7jBlSsWNhGdzV=D+C$iKpo>ii5GckD?Y4i7h1EhO5mH!Gef`P!Gw+lD@^iaeS^1Jf zhbY`&mHE$Gr}`4bn&a2b%aX%A@+db?|MC0Jm-5@HQxkEM0|^mdyLwfY3I{y;82-t9+WZI!jIDE^&6rS)%UU)y&tKlSO>_1 z^BAStXsxiYJW_oTQcx6~Oc1C%Km3an`@IJ~w35~RKvggmA*RM{Azx2yOW@DXr z=kqx>bvL)vx3~KkER%E`v7_t7K01%nSvG(Ed_~c0k zRoBo^jM9_gL>o&* zVBWJ?=}3ozSY9FyU(eC%)rnO>!BC2*9f{g>{!vGY8mN!v{`%|k>sb$xgPXILIw}Mn zyxV2}T4wt&;gvx!RYV0?0%L9e`gymHo8LkZMQLeiaYof*6oZI?%FN6}YJP+QH%ui~ z=Tg4q*|ViHw}15`z=1mpKy!zdTh5(TVH&At2W&E{BM~I|!G3}q2vmwx4-wQzIb9KR zDg|h{RZd28(v&F%jc>duC(IL655^J$SPaIoH%pD)z+*=IjUe25>g35_FdjD8C!2I$ zFW9C8ME`l_oh(_&Xrk;BPu9P@J^22@OpDHsS?@+nc5`e=z{T`77wz}lVl2qiN~?N} zM+`1W*dE)<=Ht~>tr|!XJEC9QCpyK-Ny=TYLj3T-gN4}BkAQ|Rb1YeXtSpmVUxOKV zm7Tpm&vQ$ntwdo-?+0%$uVOri6;S|`egVft=OZd^+u^zSOfi;vNtBir7}7ytdMav_ zHLbI10w-j>!2_T?8?RTi58Ij`Xo697=$4vuyM26o_G;#1dn1PmqO4>H3JMNlQ}@=n zY;Q?!^vNyi+KiJ-l3;U`CR6UMKmHr-B5!ePIY11YR~fcj3Fz=*zVRlwl z=heQk10C5ljD;F17kKSMAO6nP)>bNIa2Lq8^5jKhZ`mPxfWeT(R*zU1eH-u575V_y zd-r#Jg7EXF=#8gdtzN(W^P{EQHY>CE_Q*&{$qx_q_P$){(uBMpV#R_qsp&n)H>CK~@wCODMr=;rOo|03s0C zA*3AXm7crv*RGx(S02#fsuLzm7|^T?JZks22?dqK=l45%n+l%Q1djch$+8LqKU;wD z{bF3tr-iL;(MbEZ%a_qPYqt|0J1ZsXkNmWe}Vf*~Ox`h@{kL8u2{zkDjs zFs#^klUqU+P>{GNV#%mxL*|v+vBN22;L~Ct9%W$W5(KWcw-ZcCZY&gr9w5F>HSWOl zMVsEDx)DJ_$Jyy4R99w*B+Y2b50`Sr{oic;#7DS=E=*cs=!->-w{4!YUin3eH zICD5bC+~hBj?FJ3qL}Tn^!r&mF<-PVw?Uz1l=Mq3B>~Wj)48@DVQxY&A4Y9RGE8rw zlu&bGtwRy2{dl_pGs*+*LRxO11p#PXS)G7LuD5R=xA$T)S1?k{8m>jEC$C_bnVC^w z1S5}sENfdk!@~tUE3)?0p{yZ_y-stRpoVv{m%Ax41p>OK>75)NUEM}5kwrI)8x?;lPY6(@YRt*2XIsmUN0=gsrvSoFR7fb%S z#D{)wtW)c7)0C0s=gyrQh-*H;Ofal?2&CWg{^L|1)!Xwht*Qq5a=;%Cx;9#)C{Onn!0|%%yx5WNqC82~y z;(Zvan-98IyVO)mON#sW`vIk+9 zSK_wjfR<``~% zr*3d3Cjft5!_UupBr!bD=&N7;_`$=653w-AU%x)YC}c%t8cmOdKx+6yn_4r2Nz}u~ zk0;vJsP#>`uA`%)56oZM*=j4acI{f3vNtD_tF`<&m*J?mv!S3snE@oA0`-#&i@Y2@ zbaTlzB@o)hs4mX<_%3;v2_F1XNUt=NC3awhT%KmF-cBpE6=noSo z#v9j4O5a<*lX$0Ovp^8`o3vm20;PK|h`3@ZBS0|e%IE)TkB_}7FdN*D5`P+X+ z9A&^Yi{kPwKtB36A9c^cAx@sFwK5&3WJCl%5jzT*As$7$ zXa3FCxvj0ZzxaTL1^wVM0XZW0&)1i`gYH|^Snpb=SKeiXnUFD1aNFWqY7t2OTE zVJM5GhFi-tughQYSqe$DtG743dD^6^*VtGhfMeKdQWTv5u?RiqA=W~3s6b~VQ=7GN)ea`3JJyy3C0s+27r@A0zN|3KzMG>xBU0s zcb3SuJ^60Q!P>V=Kg>&6oCZ^xj6X7?%_k3C3-GcO5=oMRph#6faPVqU6H#DpZq#^u>^!Kd2jKgf zLA#VTs8gszF4WI|{_!~prGgtz*7N5Fm}`~7 zS2H$eclP%ay=i=o>)Va5T8Qo2gZyXk;g5@(W5ba0B9X!f$dVY1qB;m%9+;?8rGbu7 zq%Vblct@NijBz410+8gIi;Fw5Bvp}LzMPX7Z1NY?uSmB|1T2!I5&#jOLL5T$sbQ(} zsNV=AY_n=FMzsNtL;wV%qoW&_*}fp+DjbLKF9&i$r%x&5?C6O9x5V^`g z4IB1(!WdEGFm$G^Dp?+IdeNrSZ`Wm{B))mD+X4ZR$}@zwSZ9ws9bEq#9UZavKT*7_ zKRM*~YQ%g+bIULncu0t76|Lr9J|AaYzWzxEDgkrk=lpl^2CHzJM3Ghz-)*1Ojjhi& z8&1DnM(z&8nKf87q-gh+%9AV1sEJi!OQdBrc4$A75_94jDyhJNQhI> zy`)Ro=h!hnfNDtma~CW)t+D&7DhU**WqZMOgyF{Ozx6v$xuB~dSBgnDAIK^cAfHwW z75AVDWUz3UBLlxYF>83W2Kxw=x9FSO2*B3epY*UdS_=FxV-@rk>|dHwR3z_f*L5{7 z1F0rO%%aH;T1R?Mp%igB()kykwl5z<2^VkMZ)9*}0SGwUVKv=i(A26+?R##6SP0lY z@`bH7>g%_xiz=ANnV^|&(+refMwKA|g8>xQ`*7i)GSsft#quP6k;o`4x~BC0nj%Oc zK`2%=nHJzYL8MB9Yb->K*-KOe=uah(jU`E@+6+0+hrMri&uqRpU-K8G&m{duHC!iO+M_RH7{oV=>|Yk!0*5RC~~G!0Z~Kg z;?%jViW_f*;T9-IrFC8NaU8LxQUC>1A*tLT<5^hzJ;eMH$|LH-s@l>$V`R{P$RcLs z8>LYsP(sq6{6ewUh_1=2RA$DV>pVe>0$3?mz)yO#-^7>r1GZE%(|xi=9NYxu8br=% zX!SrZZuCAZPW_j+mM_|HVvlnpc&xm^j@I4+63zUpgjTC?qf|)?_a#>^sNu7 z(nvS)19O(Fl$4aDqS@@LC>%uey5>TXGCgbL5V{%SGe$`%%J5NR};L^c7*VJjCE zhsc{7Lii=#xd#ionFM>DGc{=yI!m$R88ML$d_3{g$h4rAU>Gf^jI3~K@4kKdpbjP# zGe#=xsg7sAb{r0raxe9FkqpHuAxgqejIU|RP=51&L_%-N2b2yEykPveX=u2)}T zkt?4(89)yYjG8hTJJPJXE&5tjC_9kB0L)=9k{xOHrFZwmfaG|IjYlg0o(q6Yb1#2X zTU4i$G=h5!ElQOrHC5I7K6pw$bTljdI_|}Dy1>p~NX}F|QLSxZdG-s+F-t_MYFIRo z|2&9duhzWPQW_EF>oCZ$?Q4}q#wva!y_m=xvV&n!z~T}Lq9)|{vrA;5Kyh@c+YVI- zMJS@L@PGp@bK9&g>rMkzMJtQEG7yc_VJcCL)wv1UQ|-M(_1ZfPItC$}^1uH2D@;E} zP~MKgaH{N6Nyw+yq}9+kqobo?HDLmuQtg{s&?^I8DJrT%I`+ftZF3|5Z4tcS7K^i5 z^X<1dIHo9`*!|s-Xmn}3Y=>b}uuqV~gtK{yPI>B&m){p0^GcT*`z5Z)!vEXmMw2Pz z!$RS5p4%M0CKE1x(%@;)cLh1XP7~sz?%$_qx z5tfh;kvMW*!DCBm$q!$(@8%D)_msCg)(QnIJ51*PNY|ung0s#;K9T z^99x4BCdxn6xIob97N783S3y#EZDtVUCl+^k^Vw~Ziy>El0ika76wUpC)Jp7$Dd8c zpYevnsE}OU-Q6jqA|Vo$VyJ|^Z?5n?h{x%|0vNrGA#hSjUEWhm^Rcmhg| zgV~1&P~4t1uib-Rx|V-`f?SGyH$G$kuUWaW?$J$rx5Kp`X8P@F^gL8S@q zpx)>APeuFaxFx9N7$5}F1AqZYyoX6Gxl|6%94XD#42c}9Ofh6Xx_{WorB5$R=>?t5 zzj31+-A*2MiGV{+$XL{ub!dEjn-FM_S6BDS817T6b{rk9e0==E{VlK?PZNKK(1vr< z_FR^Rdj=R?IVBN&&{UQ%kO2y;?BP-8gNyYVXB=Jn2I)+ClRP2Y^$z z?Qd5^-A*PfDB3L#E_1(%9)-Q>BsBIa^ZaJWH*ZmV^#DpT26Ypxk5fKRv1oqS=wo{r zOwYWdJ)j zSu`D?B#aDM7{Itg2B&8;e_6L0sjrmCB-DvSTNee%l!3vRI-IsQ>m;lzeS&}Z$jQmo zvshukitOmdRW3Vteqo>B)8*$jEzs?l{q01i9)cYO63tvrP6fkV)oH}9lN80fY86bZ zu`l1)cGWY;;!8y%&L?BVHe(|ri{bA3(}m}Z8?CRM2lNWV_77E0j_GTy@J9*?f#cyK zx8Eo-3E7YlwgZ5Nsl0^>a|B3fT5sB)?)$a#KpPa4e*XFA(4)~0xvlGeO$Q};(V+%t z#sCD8*xA;5P}fQTOi2Sbv$R~-V?O`l?8OiF@7c2&u?hS`pWwJ_+~^%>5FqdJ72A!0 zhf9F`@h4f+7^?|=vmwSbHJwIItxV^cx#2&11O9wy-pzYlfR9W}9>eI;sxcn5p6nzT@V^Fq z{@+;vf4%|#2haMy{oXFiCl@Tt@$hz#dl#V*2GYxheI%r!Fyn=5kxb-BcZC20XZl3J z;@R}It`QOvB8waWZ{JBWH>^sMMW`T& z2B~+`@jrfqa3T%#%;v`lITGhg9VpT)*wVV2ZfT-W^ptQR|V=eFmpWc)`*aHzkzVA(#z7di0RONd^$k`SXLO z&Ru(eNl*+~t{K!M8aIkyYU%}%)r_PAvlss>wxU9e z21SdKDl?8qYyIMvi~OYIkfw-egBkDulTa0j`^2dLu_`7SX^=+)*g|f()sN*T{&8T~ zdf83@7}Mcah^y!W{bB&`@j+?n67qmTwRnY6k_p}L*c?Bp7|Fv24&35_;pGq%XEy{k zQoBhuKy|JR?1QsA@?-S`rO2$VZJi&?Ud)}<~ z0JV=#h%;+ANJT74xK~ByPz)h?@i2(+1Pf&`*rUgiguRxG@*D3hxoAaU5}+gM8c$sTT*2lul>r;HUr?J9 zju59dy4w05*H(dI-POx095#FvFv|_L|haTtHu<}}!U>Y10IiZI z2ShJfL_ooops1FBht~#Py$UD3=e22>Lq39YM#pZsF${(hGDq8qVRKeIOx$BqZN2Af}huMjx?^`<=aRt-Aj zF(F7Ih2bi(aZuji{v?8qN;ykgkP)B}5DEqvbm~Bpy}+iS;J{1mCE*GoTMhL6)RB=P zWAE*b)K(EKnh$SWB=+nYR5p+_i6zj<_lW?J+NSpB2} zAmg+m7M^_SBOv}F=VT$cC&PqQe0*yK1P;-UP;R!vOuay4QTo+Fuxk;A4V%s_mMAc1F;1FzMN7oLMALO8Wu-6<*&6(E%zLgZZZNl_VSD9^qKPTG5`HzqDV%C~A2>yC_M0ob+T zWOH3cAlr z=Oj0T_gAl97lRKm^l|^D3o+zi_2y;3OJCXsuNN5u4nwcpbkncAv$yvyTwTswqU`n? zD#go8*D3`2Vfz|D(ji_5JnOV1c8N0S=FEAh1ZQNE<2(F(0~$1WG^STz2f&yq21Z7P zY0>m{IfSKM$O*T3@I>E;X$Bsg%P7QE6Cn!fI6YYH{DoB1u4pU@cR}|Ji3$3pMSIIZ;yawO~v;P96ET)EK}6xtI*bhbSRAn!VI7$F?bHie;p4K zCE2l!GX`{=1FzD8-^xvo|Hw(BEsuM8drPRe2QiQZz96Hg{RKN^)`}PQRt95pEE|Rc`Bf<}6 zc``%WG~87-blw2xh_ts@$zT!`MrHsSdR8N}G2`II0o|ek&p#U9dV9dbHH8HEtgUaS zljZyo8hUhj>QA<0w?oJPHw??Fc8A%q{ePu7kK8y@{&;!WvTfTQdm*iWB)Gfsu?2cv z+dZM;lA&`DdHU|{+YiXw2w;#X*tkMtxMK(ceH@lEH0}`aU2I<~V(&bLFFxLBW$s^M z^;x$v!+W#5XDu0Bx_nS^3~X>3|K6nh>%)~%73=>&yf~d7BMd+hLFxXdat_?sf0`NK zaGEgRmd(W1@Be3F#p%RNTIcmYpKnn7(T#4{k(kF`V{*ZNQEC1kHMG+wa{Tw!)Bl&M zsqes&<3H^1|NqJjnfe4+F9NQ-P-xUZkP1jxbI~eTZ4`Z!L^@)?;htzI47`p|%4AXJ zPjQ@{{5LK=^@`XIqwjdrk3)Q@HC8qCY=q=ct1yK*$eQwi4HhlMYZ!$H>LT#Q=lO2e z0tz9^d@))UVBu-pT8c7A5kGinG$A>uZg&rL)BvlJ@(Wce*hO;iWex8b`M>%&tW*Ky zAEH_ZNKP^J>=|;MASRarMS#uR1ksT4yG_#rHm|%+GwmphO$ftx^P(MKYC$ZMv0+6d zwif+jm{gwX^sb?;EdsPWS%=8l2aCmEUt1Vd=8Du!?4`iL!TTJr+x6~U>V@|-Mac_j zpaRhcsp|-?G5j6sjFJ>f1M0zm`TZWx8niVKKaL<&-_W2KAhFEK>gyp36sfE{xar_n zUV)OcF?8(st~@n0HPjLY=ldhLd{D_YQ+F&(SfsEZK``W?sv7zzKiD;iwHby~>T6|b zjmiOaT~C`*{|1USez%x(Obi|1yR#A!V*rx*afQQ&KPHiYLl%>J z8?+TN>;_hZqBWKMiX22=E^eYive~KR)Kr7^s$?6Oej4gs6BqQMyRU>641|{XW`Rj_ z&(186mzOUIV9bHiTAyN%#7a4XPsS%4Z_^;OiYgT{1?neY>H0bCWQfZ;9Q0UtiZ9j2~)xF4YLCGdn`rJ%ii zU8T;kQ~e?Z=ofjwEn&03$QRN)StUVpA7q!`1Xxi4gb;@EwC4vFfR@-qz5a00d;Qhr z*xYh|FHB^&d5})v5@Nu5t`l34V%&EQ8ekrC!(U8}3^2*oi>x3$BF8NRu?v;tjjVsc zR*CAgAc5GNNBdS4mDs;_OS`#ko65=PdP$>%18(9sJP*wi^*FiJ!T#pHy2E_e4^6Jy z!fLKGU|lH-*;-=@52Mu~nNJ@F>^qcfUpZ8B^@+{Rw#^R?Qg6@sXxFjuX1B1wKU{Lv zW-?~XhWp9!d>#!vu^-O4dGTs=3*U*U=aF(YU3Dsl=Xy-!buMp<`2FVG+1{3W=XsoT z>lX2!C(19S<8d;_@@uJWN?*KC6AM;o!#OmMjXIG@>b}bV# zGdXM<;xib^j`DR44ZMIpP!SA@9!Zm4{9!{7SSK9u(*l=k*QnK+hXIU7Qa` zsIH#Ou2Y^q_kZ+}({YO(**fR+5_7YSVS2~BM&6hxzZP|5C0))vHE9Y@OBJt>chY;^ zCH-e*l)cS#@0t|s|JiZqXm+l3V5p5p_aJ|AIJ5AeO7_Hbd4-&9d$ZrT7u7BtwcENk zeq*CT4Zrl|HBqaPDM%*s7r7u(G$ZQSzo~{V>+GyZS^9*T{NhbX4oh zRMf6o(mS?lnhYWh7)kv%Y+hxI{m^CHh}V3$W6jfe=Z{q_D%rVOBl02}tysUSX?t5n z7%ho%wLWrJaA~2ei_$^U8IPTn^RF;R@6Hixs@Uo7l@?KFS(uo!g%#IlW2x-c>{}ka zvr@<`R$WdZ#AmaFh}7^-4?dYCpIg4l$hh(AyY*d=^BT5%?w_|^!ednFf>h?}oWRf# z3uB!n{W)S0Db4S?N{X@!H0yp#IZQrVSXW^zKI|hNLO>X(xCD+rV!Wu-1h{1epdz8R zhtMMrej`hugi@a+xmRInS<65NS{aOCyv@!T{akIsQ1AlN)~j$e$#0eByF(ln`i!NR zc&HTU&Qzx;o~iuW{b(T?yJ+?SvX=q;a5m@y3SYW<5n$f(-Io^ltW5N1!igw?_p-B# z9C5ju?l@77%Q4J+RgY_m@gwP*yq0_^w!;Obru)+lXLZ*2ud+#zw>kK3d+yn^dv>*{ zB|b5kGGZ;3Yn}UjWMz`8?_>?s2rtV2+eczAtE=-cS0z#=d?3i}hm^x;iH)Z&AWUL- z1&~kX8I&msk?NxGR%^g92+g$w{V(Cjo=s2@3t*Vg)kxSIlkR{kk%vc%bK$}e$icOp z{XYKbzSJm8J}Obsiu=_#Oqr=*~K9faO43tAN2 zk*Bjm$1MT8=c{-3kS7v%p)}inzt-@v@j?dhA(;4D(6einFW-qgUxM;n5oy%+?k{7X zzj}Eq_d_c*32qrOEP`u9ul(`xy$avwODT)?u={D)?=HVntvfDR?U4P;efsSgf3$GH z$`va}R!2;+bsu+Bm>dC*k0eY6pA{=tLVO$hWVS}~{Wf?m{}0Aav47)VN9q61X>&WS zPX9lAFW;Mm$)FW@I~iVw(a$mn#C6xrjSm?Rp4~$g8fE;hje}`%}en^yjps!GO=EHp8BVDo{5$xFPyn zo;9E~0qb$dX;Q$knELh8@c6+mb&1RwrrvR|_q5yazEF51nB*Fez?_Fks>hE1{I~lJ zAC>|MT+^;Ii>nT<>6EtL#&3fO=fKngFc@~v$Zlhiac%t5p4_hI-{T1W#E@Gn!%hWO zb*MOZ+}-Do6aE~2M_-oRZ^Cql!~yazpamiT?RNXoA9!kK*`FRI|DJrXCzd^*JdHoy z3mmfta6Iu2eX`4f0T+-gEG|2_$J`bi9H}`tDs>CyX#?`(+Q@}N4#D%B;|t0uy@7uZ zW_cy%X`{ggOP3l|z}ubOSv>A;aH_^zws_`E(ip$z95aG;lzopiep_?QuZ-Z7Q0Pfn zS6ZR0qLEu&8sl~c4(Db0%WV+5fWID*rxhMie|CS$*@jnh$s7ohHiLXr`yp7W0+6P!viY^1)wJT=o6)+TC{b7#==+nCeF~fT=!d z82_vHTf5TuY)t3;`s)MOfiM34JKEyL{*G~BVWAx1~uT$KYf1uz2#CF zyLw=1&&kT#i#cz%AQD)9h1ru5)wDnD(j4CHGBh|LPA6{>3g#@GG)Nc}w5A1ozum3t zw1lZDJEP;L3#+*o=D8TBes_6r?ZhY1v@0@dOK$c!gw~JyqUMj#q@i#uYkavMlNnHb za|*Wh6!er6Vm^i56o`ak7=Q#1a1e}MoEA5~pZ(qporhb{N^^PU(o&l01#9I2)X^>P z5~Cpf!Dt)tTjcj#n)&R>bO>8wz_Ig1<1O?T_)dJWjNWxGD+jFU|fM({~3}>=Ysccu@$0L6}}^UQe| za&z`Pr}8}vQ=*P?S65DS7*?i^H9&AUO?;(%B?Emtlcd?08 z7A4g5y<^s7tKG)$e?J+SFx|K|gY+s0eZ`5!wTs(RAvL}e90yh$wz=k4+F2|EjSjDw zAAuX$FV`QfXB5nbu1&2*WE&+F`JTx56~CWlq$k~j+K)zGTvYtdgU)Dh+huV*OYW%U z_~U+WVzg$D`$>)YOE^p#JtXZ@;6JGcnS&~jMgpM$Gp3>uvJV(eMxuM7)Dk1Ve*J3nWfF(UA@n{dAUM!$KN3L6eh1e9 z#5PnK($dh|tI?%OlY3}#A#@4_=mD_(@iIU>5qpM^9YI9}ltJ1=mi=lTfk#0hkzUpkL{A}4(ezWqy{t|QfEMYln^BX zN~{T~*d1vNNwU7)qSq?=pHwny8cBoK#Rj+CJ=xs0htS`8QFa=K-xUpp z4FEev)!A6T2%yxvLiWTPH-15HmC8hHTk7cr;PDtUKyvaY#(7O+J(#$o^Y~wk1+MIw z3gp-z;T8RTaPhZ{jTvM|L11;IUAuk*!4rr=+#8~+P`9tN>d@Zc5$yZo`{+opVS7<{VVk3cTeU`E>Rn0tW9gBDHJ&7XGHD{?zjE^{;k(Hfu4P${rU9z zH#NNM_c_fDfBxpbxz_ss#g_l&r~4<*>3^l>_TBpWKl7JVJ^u@P&H!qOso(}6rSSkX z{OVn+Ja!t_5Vef#EeEuIIde?V<8bnqLJ~kj1lsYIVF2isGJ7(4pjYn6V0m@5M7AWH zN}*t*4eeXo+B80A{lMY$1A9aalyqsRuDdbSC+UMErZ|G`PWvDU1ihsi0c-0#H*~4-GML#D6Riy$8vgSfin+7j)t?T z5c;qP>~xsEup8y(9r)^bXu^zsOtglKr-QU800oo z1tH85b4>HGEiO*ra8ld%%^AC6!Zz@C811A0$@!T*+L6|w=@=du&f}-(s-nj<(JiK! z^8uRz^cS)f;N&rgE(m}DM6Cmv|L985Mmg3x>CQu{45?0-mPGIX|EX6TENg>#aMaCW z8;_^iHKss1d6uJl9(eeqy;pjMHHL74Gh=sx7ChXWV)EfPs_G%!>w$tSjemo-@p!NY zq(H&nNOu`Rv|%X&H_!R%w@ByY*@Tg*FqM7iLnf*EJV298P@pNjJ%wvu@#G)W(!Z`r zLdIeTKaQz#pB_4sYd`6t(POe&aZY>vz0Ui$qs+fW)<5mN|GFvZ|N5c1-u%s0L`%q2 zO3yHLVMi81{Ws@YiT)H=MKLJd>!7<}gv0P4RJZ8UR6Xv9-pO85Pd;F3B-@&K<;wah zhkS|t(@2Y#vKOE)4D+(K(R3yPcd+w8^HV#@i)HI~&n()Cz3oiWp(OI_g%R1>d?HLw&)@yb(M55C2NEHZ~JSQqlODNvc6R z2HaHI_FUf@VaY^7r%2wGkI#S3%F1G-EV?D7tm`*r^5jY03IyAF_jirdEl6*b5`yxntTLVyHn^eGUz7CWV)JGEtW&RCE9! zvMr%ti019B7(0g3>?hwQ&Gb|nM1^3sSMr|~Sh@=+NC3&*sh68YUU0Hzk`{|W90|b( z@x0hCPV*V*d^XU2$WMperk0I4i^QQ&2xmf=#`i8f0tdl@xhSQ117>Obo6$5UBrc=V z=G$DFykrcuBH8|WmRXT0#CJFsSf)`++ylbH!^LmXND%mvpvCfu(yYXS(_TJCHS%s1 zC*}R`G`C3VNY%XX_7;daYPNKX8jlqB3u(UVUWYbvWoGR2H(hmSFW-eu&t8kRc+2N3 z1+ET>XFgr$hOgzO>lVxRvFaYPh1`7-9#W<0x(Y*i?Tl2dppWM|7WTU4N~m~sNcfxX z|FW=jMUGwdsOnbMHGz#e0*way)|n}}z22C^WF_4ZD0|(#AxB`9$Mo#jdV%KqtRMl= z9Hw>^LuF&m!*G_qMPUhdR8;lpuR0PML-(sqJAyv;Nj&_$+IAoQTUD%{geGo@f+Fui z`3=JvR$&qzd0R$B-~Q@QlbZ43w~>XLhqwi0s zUX--*FkD8kLL5QT!A>9>neByQ8w1_%Ym2X4`)crb!2fA&R?XIp=f7Q<9T_mG+R?$O z*mbxdy1Svr>e6M)G*u7twH>X20;runYphMoAvu97?QEhPp`!DDOSZX9X% zt+s{Vq}m%cDSd-?fB&bSUCa2C;x_(6pRzU8^$`;_y(6^W{8>G{X<1eDHF1&p;9iEH zVsDVGFe^!>RIfz3_R)`JV%N;Wbe9M@4#kkx;D4*)=Bu?gM;T~(ZfhG> zsLI&y%D$T44K#)StaGl7tnD{S4l;01GOzdTkC|JV|F~kijN9{mdGs}Q{c$pRb4;S} zzdOukG))gf=)({z^%3(E?VPK09x9{f0b)Q`XR?ia<#q=`+QZ~ANR|f4sqX(4wk=~0?pja`eTrzbDPt5W5z+5=Idhf zb31GkL4aBJ8)z=h9=7fnTr_P^x4hMNmDI-}nyo^x1U|=z3KJtP8$KJ%9%+Ep;Q8}C zo}Ks?JQa(?Sua4(;!8+;w5ve<3JR8`-yR*^o2=P)-K(sV<>Kj!nOUx^B-xvZVuxjv zGesN3j9v{T<+u(d-C@X0xUsnOTv*+frshF|kEg#awD{Urz5Fx!YkFgBU$Odi+SC8& zSd++7rC_tjxZkI~hCj*2EVYKMJ6rwkdt5qYaC@p~_PS)}Z8Yd>US`(hV4@00>v{`p|f^_gi0X&qsqe{tkYC zx0}0YQ7EJ6sj35`kHrZjylTde*Wx-AkC$=flK+!BK=i^MUahX_e-`yN@c zu~3^jfE0v)P(ZK7FOLZ$v0qc~Lo-H-t`zve*YkfS`u?NQ_%EH3M^5bSxpL(vnqI}j z^ZffvI}R=dh?g*u&xK|F<;w&ABm{rE{MCZw%)$e%qsdq7uZcifmV)1o2D0y-DG>nw zSS7M_lJI!9VAThR$7pLZ9wvT=r}_4NZn%*#^#us@Ehck6K!JgTM$?9{4sjElnRp-~GZvv}frV^c20NNk8O>!WdDy-?vMra#$^*o(8;}?2;>H zuYiN<0XU=8m??!cs*z;!G-HzcED+X%__72Ml)fH^9&x>c_7D$F3Dj2zEbwQ8XK}O( zj4|NLw2TsdKLEvts$=vmKlM4~wiShTA*fFJJ|$r^V046my`pvqa_SM+3hRB}n%Nxf z%h+QgaWY*EI#O3|aEZ!MEB~bxk>MwYFkgedga(G79G$OMSNV{)o4UWy#xI4IqcW@^ z8Y&fZaKigHt%9Stn>Z*uH)HepQ^zVI??z z2jA(${r=N6XAC!|*{q8et)1`gxWbpdJ_D{f>iPjcZ3%-B4No2G20E5~4d;90gf6>f z`7aJ+r){b@duo+Pms(TcfNy~!b2{b%$1Lps{Fyx*VG8%T9b}5cypOf;R*}aA{K47K zc^vIryl44H>w+!-L(K{>i?;6U=lo;|f0Wb}KNBjn=3VE_J_kVALth*1jW3_&JUL9X|Wt;|z&@ zr5ESJzryroT5OQ+q>d1AkcQQQnq5Um0>gcwkHr~*WyUBx_LM067_&_GV%C1Nb`~A% z$Y-{__0}`AXMjxD2H~fLX3Rnfr727pgHoD86Hfo$+4?Tpj1IE;D0}5Pap}Ci_W)Z< zAIqgQ8s;Td=DK;;X?PTk0-h<+bBjk0b6&~Lgwd6OAnC(j8cgOWKloQG&ifhJ)HKEQ zBv)UEbG7eSDZ%|WzD5Iv323Xw3$Ryxo1Pa2|93+5U2*WqB9VthPJl2J*_ ze(_>095L*&lm=tssna(|NF1c4mKEWwYOTeq`pxxOUeLZ)3?Q9U|dI&!|Nf@Vk2!>Mn z#snIB2%bsD#Z2~xq@*N_T3cUs2BEM7zTo0eMSeyh1e$QG8teVgR6hFbd9dCyk0#Bt zXJyObwvYry24$p>vyp6V{@UTI-l*{^&Y$X|;b9T)XtD$b#D^h5(kLbB&7;|BIADx+ z*6Ma@I6)0YvrVW=mC9#U0!n=vBZhV!FH|KooCZ24Mv@meO!7Y(hUo=p_&f6g4Q9sa zLa~k??qKv;tPK3FAA~N@O?iKK&y^W|&sRMDeWe~oK+vEkWHJNX)@wI!mcS4YmWkQ4 zO!imNkT3;85GoEi)=q;gA(N~(|9(?izKHlQbz0G|NE1^q!+PT)l-79aDv6j;avHD; zWxO;6e!MP*JQr;I!S5tG!DuW7_0wS(6@8Tkji`QI;i33Ea5oAX@Qw&jWI9 z^wt8#(ZFs+e2>j=|7g5b?Quo*fu-5o=dYQ!C;G(oxiBI}zo-%UAHBT^SkL*}{{3YP zW~M z#{BO4KA!*m9MAv%KaTr8j_3LRW`_EHKcDyey3Xso&g;CYj*D1O^@ka8yQ1Is3_SXN zfO}BY84I><9pKh#dBD&H0U_;mi$JdPx|GnAhU9Ruiw43|{`8NlO zZiAy#)=a4FW88*t)lF;;Nnbv**i7I0Yf`+kJkyz?QP)?}PRu@UQg}-zUZh4rqpX=& zvhqUq*14k$Hi$xk zBZ=$s3#B`E6^pRp>7J&QeWy?Nl=&Su0%x3E%qDvB5IwI({GPIfn?l7NsySA)rrXA+ z?7>m|kMebTjEPGS`BdA38sEQkgI5oHKfK<=BEZc=1siMYuE8TmSDyMqOo?yGpYz;* zJEDDj1;V@w`rM60vVEH0+A>lp3g*b*f9o{#;`-TNFX#JP{59{F9NMCJ@3U^gL282w zS=;WL@|KDTA(-qxI=8g5E)~q|E~tXBc!+4k?t+INgCTnzao8^Q#*t}WlIhTEP8R0i zQm>jb3aa4ZiAnf9b|Y#_LrHISER|zSqZ-~fpn=3u|1>Lq04%Kwmx1GN%U-WRMI+6c zu)+oPDt*0Bi!Nm(*jLZZ`%%%aji2z(;~&ElciGt&F(!7H*ySi8g}|DazGP%7<3k12qfM;BN32Yto- zyZfI#XW@Y#4?|ioxK^7iIr!gtzFfN^F1oN-_tE(smtXq)IXlnG_-g^0;qAmCWpwJ} zdPV_*@D4LIlZw8v6PNQEI##I&QY$SQ&}I0C!qN?jxJJYHMt8Y!sf?~AVb$xr-foWd z3;By{;DOh5fyO5TkviL2yRxy{=f7o$pEfTez`3#Ov3{7XHfO|wB;}a$8!uP63~b#W zhetIgta_~*!UXg_r~O4A*I-C%*J(<8J;wBf2DKBcU8-nQg3B|k&i4$GeP1ZC39aPs zw;KPWl!;%J5#S)u#+$@2CT~URO)er`{7%g7g&aM4w0zy3JNTg1N~1&mal49j2v|J8 zJMY~DK?}9Cv1lpWbD8@B1K3Q)Oh~-1(JU6%RHMC5Z^*ppA+}#WX}JiCC zD{j4%_;u1{G<^&wujjf3z5D zSN#I7`7i(Fz{jVS`Q==vjB59v62 z*4wOmu5xDG0Xcj>y$ISF47mX;Ba6a14}Y2E^yy@?3W(_zEL;cPtdIO#TemPclKH;2 zXPt58SNg^3&8DZbNTn7KD)n&DrOi!6=)DQ?fvlgT+>^_`rX)BS&Sd?Iv$$;B{I%LR zOW3zTsn>D`U6lLjKX|Q}{EE?F3N-HexMzLzeeQcro-(B$P^aI%F-{swWe5}&`+C71 zuLb3;ER9$K1YImocuEWL`RwjvH)Qz!L2qfK9l!G%(?G^P$V%Lz&3O|CtrYb1Q){h8 zniIunx!e+S(oTQ3b3k+_KHYWLUVOb;=pV@nx@l9HxK$Suc+;1gG=3=hq!V2heU9}V z$`d870I9bzjcmgfw|c$T`~UXx&Ngsy2IoN?L#?9ZQxdRx$d(OAJM!5cK5z%m&sQmX zX&A3&Un&BSNb1M4ZY}tLufF=H#`r%yqWYS(tLlpB|I+?-|4sV%p{GjyIHH5s;1&Fv zavT4nq3}O+mCDt{ir$f|*KJkvZKV5+z#bWkXXUh;p0icGPD^93ZWGV?I$E#^y>0!M z6#M69r_GZ$Fk^Ex7p?*pheL>x!?H+y0)0T9qe8e@=U~dulMua#Po( zoq}`jpZrSl?QYBJ1Sx@W6xD0S^7GGz7fNK$vG~#ewOix9e-PGQ(}dWG;VUeM9-oD$ z#`s%JKu|>vY$O*AgfLHWdikT`x&HsOS!!R>Eg)ZLnaJLYp8LCf_FN%}a5a)C#X{=$ zZ={C5%ckPFCr(Z2zS?TIEPdWL8VuSicsymL%hXVtyZCN>}-M_+ht7UrL$5azb*{&lu# z^ns~gFoIo=Y(72~(ma|vR-`kSfZ)iH=YwsWBJ5GCOCLACOpWb8Sjx{%gJON6C3TYm zyydQ%C;s@iX2<&!zthr4L=Cuh4F6XR6$WdN69z1bKI!z=4;Oq}se!!Tf)pC%Ze9{bsEpd)2l~ zd@|u#c|-n+|M5#j?EfE5eu^jmEe`nKf0TcGY*bFYnzQWtY#`*Qq%bYE}GS|K0dM=G!jd zZhSi1A$Gt&sMmkYe|?H}F#F56GW8IsP!@D`>yZ{07gqFF%YM)2s`{UPwpV;!05(+V^&EfTN$$M-}&BP_gu>!Yu98k3A2s6EsdxR%U6E* zSHrj_L|)HlO%2yEC$ThA(f#FZbz-oFN{Dk-pPuoT4Q_v&zQ3@F!QaOU!v@BnLX$k5 z*R}W6ZUz*B`b&Q%d4{g7@&1MdZi4g;?GxGcN0#7d)d)(*KBVjkL#rD6{>&}2Aj~mfvCr>w ztqrl-L?M=#>X&JXzC2vFF^>|xKsb%JkV%R1q!|;@plx>7Vr8I5&~Z&Las+ zw)$~hJ6vFZo15_rk{vxl@93S~J5}!-u(aSPE6^3XZOzS%Y6u&hCMmz*KWay>rtZ)p~+ul_QR49$}4L)fa>*M-L;dGZDZognXl4*=N4|^|BLFn)ErOsXYKNe+1k9mC3|(G4qF=FsFWh8r*cp3Nz4KO zsJ-GAnz}lydohFRUtaj=rmvy(328Igqgwwza!GGTecw1bEUb7H0!g0o5(ZbO)1x=b z4?}29SkG+ZWzljC|B~5Gt=eItXvMU}f3&xm6Lz9>r#0ohdu7nZE^*Bhah`Ve$Y+UgpyX<3|=w6b)(m(aqt=1kMY2td|%sNOI`7( z%KQy*EnCN2jZj}n7)fTYUUy?3M3l;Mcxc-OT1llgS1%dNlh}dxg44@>L4`LZm&7m1 z$u6)DYzPOh#a$#x=dNA5hHUYn(XRCz^2o!mm#wIKy^{i-v92ZW(lm#5?b^L*yO}5? znFP-$N{+JdBr(<%UIo%$;6)@sp_7Qay0Q)L_2Y|CGDScok%S`X?dwO~_cp%yx6eIY z1+-G)D>afG|{L62E96H(>ABuIXOMCmD2Q!6n=WAbjE@-qzXdGgmJ-wFxvZcz_Ve;{I=05 z(B?~zREiYMsXe;1b}&_w_Kx{ZE|u#FPtcQ@xT|o(Enp+$szfamtZ+5}ss5j^5h4o- zIo;hHtKHpwu9xGjloT7d0CktjTXtQq%f#VmJM-f{%9Cz?E`D#GW=2rxC^sJMC*qK3 zzZoQMS3(eyo&ym%y8+itVL}P#4j)Wv*V#GbP#-EdtlL(rBC}p{2a+)%KjrFGCv6o9 zwlq$``)hE>LZ37eL(!&KniAmsXOL2wyH|k;ot}Y{qsKjJRp}%-_9H^-TKk7h;*w}1 z46&$Nc!#6J)s0XH_L&vhbbbHs-Ez1e$3U|Yizb=U4)5d;pCxF_tx#*u7z_o$%A?(U zs(PFx1q#OTH3Yft&dC`oU{(a-r+@mmpU=LTBP$`g7H8@cQ8;HpTgNo2P^%4`mCfSC zi$CH>C*;nIi?-9ZJm63wlWs#2!BO>q$AGk>+;rJ!6L%Va_VQ|z;NSyuCA_M@LT>SS zl2$t48(8yXVzxrB7*L%R*!bN@khYOhR3Rcw827GMSd$Hsy-~?@>K@yQyd~EX6~RWY z@LMT-BM$8rf}wn{Jnm6gZRgKO)TZ)f<3iJ$19!S`nsFvh@cn(&N;ke#VV)FL; zL<7{Lkd*d}xRmG_H{(@KX5X32e5p?%!9PpVqfnpDt`a$TrwhOKr7y9V>F5bgP1CHS zlIk%f$QYK^00-agU{lHVrOY@;Wiq1r(%&J%L}413f%y}hz5GLbGp+ANscK?&M?3|$ zd^1ye8LT(HHt(AX(iFIoEDWn=}K&2;<0eCTSxdvkIa zKd2vWv<$h{0W9D~MxOK*VS?O3J0&3h&fM8zzo5L_PI4Y!tX9os@xcVo{q^{}489!p zPM=?b$*Dz?y)cK(nyB4(0l5ag7#y*VY z;$>f6#&IUs0MK6VW^<>eWBDBZFtY&R&PifVt+w;(f4Tk$nNvzW<^Eu48=s@fu$v z7`lfNx@g@NuO?w_y8|Y1f6kpdmvzwFs<)YR>-A;3>Z8r(6D^yQcnDK6{L;)Ri$8X8 zXSxRi>dZlFoS@5RlF~MgHq^3-O7b+DKVm$e%9?Pqw6SZ4xa-%i58z$D%KtDqoqGKY zNiYb@@T%}c2fX(Oc!|&otkEtxgXTp_4BX~Mj)o%-ISBKxE}6B=%*;})%xjh|Teg)+ zTobxc?mJ*Btq1MfdX?yI0c^cfsba;EBQLE<$zYN?WF~9qJh76g6+Nt3+VX(O`$w3a z;Ufki-;8Tw;!c}n{>F_PA7o~ZrFUlrBXI^G5ya8eerb>LJ@L{z>qD2t6gz6OGpV+pxIedSs(TN6 z7+qyx{0C{?&HyhxM_yj{_d%ZFD?&#)UBc${`^UblR<2yRac|8hE;8$ja>5bDE|6}u^tP>OVeG6=x7#;z%zcwJyCo}kEl8_bYu?W(taSOt{f(od z2goE%uUuY|x?`FM%eb;ZT6n!Y?lmxP7_E(Eyl)cl@Mn8W%eJR!0>i8oUrB5r+k2E? z*wmym<7-Db5;nk!P|jYk7KueoGVNlvbeOr?dO(NsmoD|3KjIv*{|j&S=<#EZOEp0n zeIx7_gftu7^G%KNrrnk|sPb&~S82=7xlf{rqg^theI$G)4+?^c3J?^=S8dOM1Fg<( zCeXuu|Hwv-$#sT2Ot;BC9?-rHuVyD%QVUnQarZ6d)T@>!y&$tu6J}+;@NEn3^l&vM zEVU@rtA+U)`@l`Kj*xmxc|5gyytge>-R(W27AdR1tXg}g#ZNEDKZJ9x*GmSp1{s~s zw#`1yF3RcI_vZ)#V}7bN_gCL(GE!Fth3SPRCX+pyl)KKO+ys?4mUAN+R+~!^)x7wC zNw8ZoJygE|y>ZaRNv5T|N5*wI-^7Gz;4zdS(j~ve=O|OLj~{x2c7#}ZUgc6k6Nq)E zIy?l*m`2sS!%WAfEQ0*m4(?K&)Y9wj_zv%^jR3X&D8sd=k0lf~ty|x!^vJx-!h-|W zfx)zaodmw>#rzT0)K|*?@Ux>{x_f!;W=NqvGk<`Zy~e)-j+mc`q(7k$PB7H&%g4X> zWQ0&0mR22*20ilNlH^~2Lb?a+^W#p{ZOtcby~TzGNwYCmbn4_y_M4ga;((StYE)nT zi@b`fjK1yS2G-}hIdxd}XZgaS^)6X=e|qyC-0=(w)rnA2u;)12wFHqw4O0#rX6ZI# zEKHQv+*HfGg6#uR=OhSWU~^)OmPxRdqUcv)heg_vqpVf8kSpB0x4Ey}FQxi;b@=eG z0*f?yU@NRqjf?v~6ed7UX*2N9qtl&Pb=e!R;~w27-nmlT@RNQ0V)c3{h{l1wr^A+^ z3AQ}C_Enx*NATF!Qs4HkVA*x}g+8WbpYv)}gYl=WjOug}0;bY;;%RJ!Q1`e;AWvYv zQQM(*COA~rFO{~r&7_A?ORJqU=H>)3jD1m=)gcDs|eU z%*+p7c_mAf$RJyb*HaQC8UydF+(dFUAD7%fzRA9?AF`bN{YVIKs#bNUf>nnJyJD0i z&XR9~Yf1-<4}UK2UfwpHkWz10>_ORovI5zLG)ONF$I2_5w0^+2Y43bL=4^w&-bMCR zTkzexcU zL~YZyZMW%pyVd|V$00=_4upKjnecG(8xHhakjSWutDJ56ME>QR8Q|VJHEpA*cW=M^ z+~_`=d)Q>Y2)u^?#2C!CsaU?ed6zC-Bn*J6>`kkT_E+gEukP|&Xw9kIne^+gSF}ir z7+;_Kt!ReNsGeD#Un?~l;O!?eKGCt7Gk}D>ICY>+yh%r zqik5&!4gupS53tSja5Pm=TJ&fJpDoys{N~SyOQVtAQQZH?OI{W1-1*qMwrd#0B`2~ zNAb!C&z9ul@qv4PO?~-IrFlx5^SAj%MZ^kJVpS{y%ZdJqT|Ubm23ST(0HjNF?77dtgG`24DJoIQ%jl;c`3FTkkWx> zasIsycfZQ7VCvp9O+qDE@$p8V;#}*3c1$OWlixj9PXxp#I9BN0vQGB#b0Id%g#4&O z>m!WdO*aW&m_a`r@OAMRXH}$;dZz^A?&fBl689cBaFcpJBKFNmS_w?^Ug4i8_p3sY z^rgt}%e_>g@YC#qJ8Nd153}!4-zj1qCu57ukoYU8Hk^1Ns9qW&@z*j&-uhY*?JC@T zUZpv`8{NZv^Ss}GKY#M%&%D%Rel?b@KWWPvHCMNF?GN?Y(sM$|4AY+}i!O`2;dr&` z)-Jo3L-kbfSCVHE5|fbjzLR8%M@^*CNlAthhiDS_JP+XT=yJF#)8zO-{AkxDupMjB zWcI5eV#2(NE6Z&t1GK?XM-MH-SVS4RW6XwWcmsSsHtX(D>T>TjQ(rle>Xdzz>LjsP zl1@r@&=Mw!>#btyby5JA`kojnhg~>gux*%j>M`H#an)_#RH)OB0UFKyQ^%Zli&l1% zAv)Av2nI8BM-!HhvM94~z^(*tf7;1DP{5e1be@4BdTBS9|K-+HRaL95j}R+g&)#=s!^T!|dH0b5YuZ{- zpU!;~u)lqK)q5=)(TA)n?h+qs9z;=f6LG_!t_)^Ts z#+S25VLxj0=q#{kx5T+}twE?NKw zX#v&vyQPsB2K)58W?ocuT}vJHJ2c*UGP0J>cUx-yyL9p_$k_^&=QM11$@qBz=?|$5 z`|b7k#aP&OmSdS~FJ8QmZ=aIB^k0}WBwnsh3JGgKQE z4H_giF^M|}EMNL#=aT7&ROS=llRR7OaCzqXvQ~82a?7|yft)upKCeeAnInkbSB3Je zDMN)vtUqy$$Bn$O{33VQ5g_P(WJr87s<~zmtbu@%YV%*cGpkaw=ERBNNC%cuO2)ZG zn{jQTomWyEhA*1&_UWjDhYnTYU)eVGNF1a8jl5^!Z}+ga*vQ2{gJrqf#(wb?mY#jc z#Hk6=RSW*`d{UG*eD35_c$d2=Pk73X^fUv>%%_K)3}}Tno@ZpQ@Vf&rq#j}Bb@o0P zG7$P>Rk}AHZ~kdFTLRIj_8`KwmrH;DeNfUW(`gQVz1kDYmbUhG+erM%3OvMNtNPn- zzny_WxH#@PbY~UvShIzd8&59YJyJ5yv zZpJxtC#0P|NOtD&vSQgH?(*f!^PMd^)V4oc>Je0$BWNcOZr%*Q;*m!x3?eL4rLWU6 z)x2juBElvV0V89&RNnPfVZZoWs$D1>zM&i~nMuvm91jH#lWHv!pI4(2MSqh#fE}IQ zC?;0lSd^Pi5OU;01Q8p$j9t>Yr_|^3DZj5GwU`!D%yt7SmsRv7E?NPLQ4JK(f^#|k z&e0jI5-w&z?Ns4o>4~#}1iQ`Fvn}dyi_djMNf8bAn+|}s1-N=Vytw*(<0Ugud7L4^ z27*kxwCP#gb}Tbhj@&VGeTxllKvQdP?vEI`IBi1Z{)o? zQdtJ+-RTaYh!{H&FmmsEY-o8kar2$ck3AUZ;MW`0k4AhQsrUKx%Mrp`89}OjnVa2@ zW=YK1wd2ccfgt{nzzVnTZsnKwr+;FP7&w*j@HH}8rx37#$k$+~Y*_UJd18usa^2v+ zZi7xpSlJ9+QkUwi*sA&HJ)lki6X(tZ9g?Kouy6!tJ_1c=apxMlFQn*kM7<(}Yr=!SZO0WowR`_LUlh!!(X> zr3Gf1HkX|Wy-e^GQib$>i8nBqtCg8wuDeZ(h5Wx~VwbO-nVwajs2bIKk2g zj?iX3^($B32+WPc;TA2f6c_vbK1{+>pg+eibc7jy!TDb$zA2J99Xe!8iw(Mk-Z6K$ zS>f?nqkzKA*$9X7CyJbZn=XfdhKz4P`hEC%S`33cU?4H|rXDdj6W^-%srDYQgbE?HKDvi0i^=A^_w@>3gCwh5dq$&y4C#KDTuMM+cZsF& zT>n+iBDNrr(;dB8U}e{(N9k|ASxSbnwBfx{v#isw!YGgouV;DAZ-IwVEBaQp2kt&% zP*u5^qY`YkEWmf#%R5d0AZKpG-it{|s&>(Q1YWxdp#eqRkH?U>BCu&4(`E3VWUTdM zgmJ({QFMH{EmW5EIq6C#s$Qx0Gr^4Yh8+BhGdjLz_bN*Qj6_Kn6ht9tC{$2OIV2E6 z^N`4s5W9Kt!DyK%QMd4~1}_itsWK5_av(5Q|TI%%Yn}3$F@)rxpFvag0;mc6nr8Gr(ufD^~8F z0oW$KgZtXZC3K{ozPM>9BpaN}NQ7b4_?Q822bs=J4DWbP83y%D5Ivjo<4HS5mhxTF z`5f~{#O5t7z5Lgodx)Y_SRbDnb8&ngZQUT?O%((^&B&LddxUrRyX*1>E4>*$nH(PQ zXps4m&dYy2+3|>6*`~`-WQlQ!MSDHRvK5UE|jzak*P2x9y()GBltxgXN%7@0a|{d zD0b#pmRbIz_N0`X@S$$)GEK~X3O1vd9W|J8XFqhF9IJ`peR!IW*q+Eo=rAgER9&)+2i{M;Y|t( zZ5)l-lBsR)fQwAda6QP?l(UpD!Q!lc^2xRf&Vf>4l*Kxs^>SW{M~;~0RrKz(BC@^jYfT%_m?+c1Exxpv8?>@ZX$*ZI75^xO7@s2L;H3Cb@Rc{TU%{Prgu=?J1smlT<0soE#R_S@W}ibjN>(qpV^dEerXK0;;-yB@_G%o^X3 z4g_z#Aw??H=TN@VO*Lzwg=mB1udR09uE$@4b}E^{{|cnTDTrG9QjGm*tlDI_zf6E> zAZ_KT6!p2MKJ6#HG&lahD^~;HV`v|FY0?`|10eZP?V4`COo=}n@Li@9kH%ojFKsdP zs$>AHx5+5~lsAum0c`Xj6Kev3%Sm3d;gL)_Ynt^thvem*LrfZ)D;06qrP$!&s%K@C zn}B#l9fV*#1N5lF$QVoZylh;qg3>gN6l-|1Zo!rd)L(_iN^pxl*Th6}Xmkm3BW0Ga ziXZBj#cGSL!f8RdHvHr!g%N>vXgMwi3 zCcjAFfLGy=H0M#dGxE`{+dU}As$YLwu?Zi|<2k3p7(UReYSwjl)F7IHRn;9GVdiu;4b0=|M>oR}X!E_MBSHgO zPvmZ@in#ftEa8mAfkOFvWHZ)TO``|xbR;DRZqocr9Y6Z}De)ngm~7;;&Ijhv8JcZI zkErRSCzmFG`Qv|`Jh_>e;*IoR&p?-glV>FQL3q641;1%#ex^xwuTM$QFYqI6S-nP$ z@6l4Y6P4$K+#aA3*f&1q+QC_$4yWwKjY6LZn;^GnH$!eVQ!LSS+?HSFXA1gBC?lLR z>tkkJsUK*tUm+&T3s?V0CrV9$M^B$_$L^@7dfK|z{Dx;8zxM7Lf6#<)dRBgvVw9*e zyJ~2oXLyI5^v11ebqC9UZVWM&d=?6B-&)?Pn>D)2nEYntN=d+~b||M!Bav_sG8PJs zWK2ucor79*IH=>qJeBPHl#)H)6Ag9}N zX4iWi{bKLs4!T0Zq7?GyK$O8#K7E|3@sKvHy6hitEM^59tS}2(e+vq@GYCc^ z#@|DmMP2BG9(N;;h{EO!uO-N&N>j5+iyp0AdBUy-&~&*I>I4gG>vOjlU0hnvxt{2A z{aLEJqCZPlwkezX%tjsO`c{Pv-s^Baz}@_^Sy>a4=Cfyk=|g6LWY?`dcr2b>+Z@=9$;`e|H z=4V!ihlf9a@b#lUdmKZ3u&P(ufSoSsJWG8uZebwArWrL$lZkg@$4)F|us^+XV*IxR zI@Kqzv>FE!ESQ{1!K~0eDlyCnEnG6TiFJ+Y&xx93emHR8c%R)|_eidHeXy+vV_@6{ z-g-h46Qx)!M2Al|iR+D8D{5*L!*>pQ_U@}_6^0`7m6@T0wo$BzwmFuY_TAoI4{gijS5On4 zpq9LAXcT3Yh$8ZmI9D#}CeX_>a;j>;Z!204ui36)rS2gE0lZDVs$qKye;fmxvAEpk4G6m9Y%Wp5X32V(Lolsg+}X4?rQp(fPAN)0_1AL_U$ z?EG&u6uAe#5SEglDXpSo8oMPEj1aQbV<`OH+SP4mzk3q>o~D2b1oG~mQBlwG8vXDp zQF$W5{u{1xFX_Ul=)e0;?SAcJfUbf!_mogi(dZfNd^M&dOOwAYJNYEMg9Ua5OmH{X zThE;PuYXN}YZJIY(=VU`a`Ww0%JwC-UA;b$0gxDxT$a@@q@;z|l7Y5_wfau5DMG_Q z203M*8(KUmy_6xl5fZDzFkVqSA`MXp40BCarb2p7K?3&XJ3G+t_yIO)5r{<{znL22 zb#Ip%zxPkf366ve9fuG|U1F3*yY{`JGAu>IpZPgpFc9S(T~NY|FjqmttnZquQ(+I7KqNOZ6-zfwy$pM zHctQ!sJ5zc)QY>aZmxk4rrW4hH*H$C4r}~XDYt99HO(hVI;hh|=xB~SQ9326D;L0r z)zPChZy%YqTk0X?MVUxR`mJm4JATMd2EW{c2|w?+0OKXoTMEs7{PL@Gb`mGh6Vt2W zPId8LY<2+loKe(P36mN~6Ab&T>11OcdVBgGK-lhjoDw2phQh_|_CD)gT{=!P=#2BF zMi)%nKd1$A7)he}Ia>55C)o^;XK*BIy`-9;2kAvi;~}KIG(8F(h}zF6M5iF!W#33jYO3fUY7TvjP?RLF=&jUJM{QAkQ$reZbf(_6 zJA0Nsg+vG+v1}Jd0>#Iltc=t{6dz0CBLMU=4p`ORcaM+?@O0IMyuDZZWt(R4!Bb(pywyr$+E zV#Em{mo4nh=B2T&i2euY=qaj(!;_yZ=GJbKBpW(NW zs$-r<{-};;>fZf>c2{Spo)tN}C%@tpXsR0Id2Yy(*${P3r+&MX8u0z>w-2Y;KX+%R z8S}f6p@1=*p{(0D7C&(>zDo6$=?wbwLoUDx0PwXBcKp!tXYR z#D1ym4iB-DBq-ZH6_9X`u%o2s{i83}q$UqH)F>SAu=Z%^$5l;7Eu`G6jhIYGm;fVr zpD?+?m+bk7xBb9hk|CpF^m)?kP`NHWnwrGLp4)|~LnCDLBs*#7w_|evO&8i?oQs<4 zl)jid?Vp0!q|q_cDDyL8q`lw~C~H%Osw$sCx|;T}SqIY!<{sIOfya5&7d-caO5O~~ zXFQM~c4N(`VF(3~akotPZndQ0`5(?_0rON{((#lTDb^m`Yiqv3;-!Xc*ZU31tY+=N zO)yl5t-IsomZi$|B}3@G@_MW>SqWAUSAmFrcVYR+1LzXfaOdzh2T&QkR#aBkkpwj1 z!|2*&0;;bs3#_FWPZF_pb~M!LZvL0*MCA-*%3jBYaZdBSTdS003din`WW(s>P4Q#HPXsd6oML47I_OA8sDd5+PaP%t5-7}RKVWq1(WuU z<|uITLd9ppok*{B7!CBkysrv(p4)rY>(0RujlLT*dUWMc?XjY^0kG_LJ?;YQC2k#F zA?VNYEtf)XN{T&y#2DJzN{+yD*~Cg`45r&Zb%7!K>WDU#{mK#kBVzqa1sJK)`fxv| zFqJ8SjJR@>sITp&M`wK+gjj3go_!h#Y%wd}2Osv-~yP$Qs3MEa<))Ty+@=MhX7Qe-x zS-GrXnVRjlLPEgZ+M~o<$H5)GYfjDR*zd}vl0+i-PfvL)y2NzQx)F~GEj%L9=i2!% z4$FBmV=j$9llpz-#$%DKJMmH4uh+DM8!240(k3he~ZMlp;Pq%}1~5 zQl^&0EKuqmF(sO#N0ie1t0^8X=5_1?_d*tWQdGk!%~kVh;*tRiYa`y$pq)k-gn%S8 zU%U42c4r3^r=;d;Yq@<<ZDL`*V};d6TdB09}~#>`L|f@j#x`(F|nj@6%q% zNng@&)r%dQ7KULMzYz#5a}v+L55ILC){ihal)rZcj0dE&+Pn5j^{nnR&HI6@q~Hec zD&S~~BZNuUk2j}ZV+1>Z z3_KbcJjt7*$~u(a><_m`GJZ|zk5Luoi3Uqz0D#oG4m2vw%DlQus^neP!-qlWLN|>6 z{#0@`^rs@QNVeN~3MfEV?!4g8-W0i_g!d4tq>2@mD<9-)GKQwOHv4ijmr)kbMys@` zZ1#rxA4?hv+U%NVi2sJ?AXLlekhYApu#Eau4HESD+vs_5Ekl&s$=lCZQ_yO3WFAZ_ z?RUSE_JNW=6Wq*=AknqOix-#3g76)?x51ndX3~Q)_SeYh;Xl!=Hev}pLc-{bU z+jaVk{2cV_OrhIFm-wL5Xz}X-N>s>lmp60iWzi$6 zXb#ps0M`%Jz3q4p$s~{QLn*b+J$X#=!&dEI=;O&gK`SX4H#^7dgWv5P3EvI(DEa7aB$%0_J%Q*J`K5^C=7 zEm1!ydG@zyVH}itlyAY2z~Jo^gu2G~RUmJvJj(bln1^xHEDT@F47of!(sDRiD3tI?WyHQEr3Uz5~lG4*PA_jnlX^Zw;fwJ zVTo(oY452BmA*v@5#CKtNe-}~sIgYxSaPub>%Oia{Up=}Ik+94zkaf6Wzm7j7gACF%TM3)Xr zctbn^2XGup0qLUE*1quCw3Pj@2rKfJylTJ=A-Kf6dG!))$~Zp0Ij_=WW>Ej2u( zxdss1{#l=<4=$(@&>4|9~qfi%X`Onlk`?j zxZ1FDiTt5U&tBo=;Cv88^xjUz=MfHqRk;d7d=n5Oi@1wnwwmh#xA0n|ahnGOE@+P+i0USe0t- zdP58K&|K*(wbOecTi&{V-1VW}@ko49x z&W&`Gn&E*HIpq4#-C~Z_-9O0dlHyU7xsZ<{#y2zR43Vt~{;8~pq7QeX`jH)T${6hK zoc*D#f9oF!cB((Y6cR-NHZmIL!G796|2@tki7wgnEqYr9zj%y&X(>h?nA0o%7aGlX zy9TTLqx2q2!KE=E7SFiyk3kfObtWB@^jUca_Ed^(wSKwst3H{}AY~F0GyH0pjWG^yvZW6Z2F#o88Z3y4nE zXxN~A=lq;9ASE9nu0!#{F7^fqVX-sb?^3@43IK1lPLHp*b%_d1w{)8~!fg7x=PO~q zigv}L&oQZad2KrpIYH1I@O#pNi7^0zXTYNd{v12aG|T!Bq#!R!BL*>p8&rDp=pL~V z>io18QK=0H&*t~U2dkL0I=gNZi?>-iHwTqZShH&{m{MUJ?i1v`7(Tx3gYX6I+qH6Q zpnwY$>BB+R05P(riz}Nc<4O9>bdXUd4H_OMp0SPYwsp9KpD9cQl7Td_SDzv^*pew@ zW{5K>d$m^w5Ipi7iuwL1!jd5UgpSJha;WV=%}Nn3hI)EV#?q9#oDu0lzA9BlLUGny z+YUuoOD)}p>0CyUT2^xjI#@5wA;#2vVg{nI{_uBjc77r6=vZhR5#>*CByntIR$ze7 z&lq|Hqz=FwYt0l6yOadLXu9>D7y_=LVeVDgHTWC zmQd9VUJ=x~&g<__!LVggtxIbPF4)4ERGXAU7A61fL`JgYpCvWF@a^GU1Qm%noBB=at|A^y;C zP(PylAmo#BGUUoVWpGHX)=^$wjk*7$&i(l_iZqRCK^qPHss@=apd3fyHxR12roamq zLiPBeWzznnAqs?W(D|S_6e(sCvQ3jM3e8X-nY<3^q)p<0V1I-(7}yl8a>B`zCzBsp ztSim8XLGmAJY>K@A81*{w~v3Zv-5{g9Y4S-E%@9VMf9l!`M#fCUudi$1I07-tG`LI zI6{RZm`Xjhos&na`c*t{QLSnKL;^V-%;QYogce%U7G8IUTuXINhhBIHfkTa!z*rGY z0Vnww_~+uVX1Auxm<3@tBeqp73wPa@XO=i{ER1h5Q=3y!G{E?KX%5ZncBgnS{?=iv5g1N=qz zNK3^4&XU&>1RrzcIF>Wo}9@skFwIdx-!Jtc5`<5hUVesZ5f z#Ht$+{w^-RzI*JgN`*Zh8jgZ(1|6ETN!E|xA8S&RI#;SXbPj{nMOS#DLejEMiY^;w z12nx}evXyfC2qX@khq2yt8c`cQe~(*Bbq~?yi?!X$_RQ$24GXgSmK#+Bft6?3oMJO z-NO|xw=6Z9N?$N?_h8Vz#s=#1wKV%Il3r{OX;v*6I6)>=E`GvLcq_kmRruHOEom93 zbq8R-PR*@7F&GpO8IG9i3+WM2Ix5#%%1}wd5xTxbWf8iBV7+GXdDQVzwlgc|Ox)Ml z4XaMQJZ2D$a%lZ#K$VL1NqjUHu34Ii3+TMKaWVC<2KDoomzIBFZQ_cQ(m;&F7MrXx zDautqfb}+VW~H7d5*!rkKd+X?J)!LHVK#_dP@UAyf*YXodT*n$t_3VI0+c(GAC?# z$Jw*k4(hCn!#BHV>k&O5G5q?b?pvgmu3h_tNnMM3Q!EkHX;u-2a+9=ufV;r*>uK=! z4;Bm*A>8p(&N9Unp5%GY{h}@y+@n*}x)@GbO`_}Y|DWBN3K0IJNW})t{`h%wQi#aRL zuMF9(4jwrY#W$(i`q%Yz6zapgB3>^VC>KuVca22=rq)ML)Yty+>rV3Tz+*rKWmI}6 zdRiKZW!D7cL9~?jjw_eWB2E9~m)l!SqJf_RR>Q`57K|r-fM1`Id4eN>9CRUM-*|4i%P+Nb#nCV> zjjkDK%#+I_Y{r+hFlrbPI9A^n8)#y;h7;0MQAlG}AS&+6*$(jPfGJ50NR~xCuSP@L zas;2RJ$9nwRhlE(7y***t7k-ID-s@Q8W=ni!>U2(x-MaUHRIO9%yr&0UOan>+xW^4h#%% z__mlK;E#fO*#$=)Tmno8TL|f4jJZ-pJDkDM-F=GPpPLQF5*nZ=y2jn!_+lE$NhlW$ zE5Nnbj^0sWefrE>$nI39P)+GQdCZ9SE#U5`W>QH)36Md{9TH)9d$xfc|6SHsMh!bb ztoCCm6&l6+_uhSa^Ywcui7BWQ6uj`O$U4%`5YS@w)Qz@;LgKCyk3 z6NhfC%sU8#VJ}K7_i=@qyTQ|>-W&_r}sJJlRJV4 z*bT@(wxdWj^0!>j=_;knw9JGBzX^^Dg&VRCH~KGrZ$-7I^<$j9jS|<$w=?IrMD<_r z6X5Z!A;T!nAZf0kYj!-yE1C~?nMX}(P%oL+zKL2RgDto>iIP*FT&iKr+V!T|9J|tX zLn^khBPAT!+$($+9PsMY)qo(*&o<c2ugX(cf}w%~wfs9Fnsq zze5%jkP9OwUSP1Cn_8dvG;n8fVeSoXl-)>Kd;42{z7(R-31-PU>NpyxQ74HX5a@vS!t^9XIDDtpvZTm_kx=M)%mhBHz5LbP z73b2QbKq_t^xmk^D&SiJq8_v>`@Db0mC;>W)B+Be_nbpS=E^cXw^s!koK!by-)LEg zu28EN_@;0xQVt3LDWt)tP&r%kG>oi5K=T^Di3-?%>8GE55{gtI1v_+u+EgYn>h~bO zYnt~azKq+TDXlyT?#u$^$zxvQI^2vLgk!R}iyp}R3b4@qe%0yWch88gA|$hNUeQG1 zN8C6xd9;!uaN!D-7+88Y-W1lj2bjz^)NYgtKqhcT@m)QE>cNrdJ~be!X){4qL^AKt z@${p&BBm(DbiKvq21xmVxGqSfLir}vt@duLHhT8N<1_POl*sG9<&7QugZozQi9?wy zbs^m$!Ua$Csx8$efn~b#-!vOex9MKN5b*4uLJWC>E{O^^sk)?Vp?(5H6-?-Q31!tu zJSDJf{=C?)A6H83Kgc|a!50Y}Qr>4>(q__JSJ{iD1&QqkX9*57DulJjRqNE!T}_!+FZ3uUq@)S~DfC302ysQ(+|(k3fL3VDTN|2R>9U0sMCR@R0ZsR2E6phDpq0 zODU>ZTe;^*jteV>mm2zfi(VbcU+?F8nQ^^N;u@tx`Z!>bGEKw5W?A!7%B6Rj-%X{`K7k#rqy4YH0a5Kb4t~71XT#xFtC$ zqr)>{=@VA9h?4EVg-KwL>K~Ro3qfEa|ooqP!;Kf`Cw}s!P=e3#b4$ z^ot}*qhdh4kzu`grFBPK$R%IgzGCcHHewAvuNKN;iVdby#Mqk3kad@yGkX zpyGzqMv6qTO>@`g-x_jPz_W-PgJO1q(3gk55merWlX;zvrM8SAP928W>T!%F4(VyP zWhJ9#%_-sP@!hig9Jy?Vo|hx~^>~o_wW0Q4;suPbQI8p*AL|;;lsOVI! z0g`(BdkkC|{A#U7X{#$QEPmoRGi@SYHR?VnX1tB`9i!oX)OV5N0k23xCa0LXd;!YT zQ1~whK zrrjv-CZRHv3x@;`tc9sMDizC;Tbfxv#5^sc!UqucKH752KEw?^KoY zh8Ji-Lz#5gOUl7Khj(a>$gdiiN+3;CSwDGp6+;2Nf%p&|Zq4FCWhKT?fYOuisjp16 zx<&qK;2jwZF`F2{doD_H1LF2h)GxI6zx$cv>q^9w{#v$Px@6o8pV2|I%d$aBmu7mPTYJHwlE&br5d4YR!6WI`C^PWb1}1 zcNhJV3_3%c;;SS<=`^InX2APTj)FXmIrppbik#E~8fr~t{5QP9n-VDSO2+ZIp5ERc zr8cJ~HbikD_R0CL6c>8(5ih;WN~*GnuFV&hn-VjsROu1o(tuRg!TdS67r>487#DqzVsLY$7%PDC&}Ng=0aAstlxZa6_`sXN&v4ThHT%ns;Fze|Jd5_y5@ zlPP~K9foeV;#1IolqIx(?r26=B*=&PZUiX+5Ymj3$Pf}XL+QPg-h*>+@sV(ysCr#2 z9C;eDXwIga1odBJd|$h#_vFdf(bWRQ_A|Gls6Z=g&)&VVLZFp!(eUZ=xILuC_wJlD zn$yd)@f5<5e;qS7&F3*cFi?dMcHDgVaeAg_Vg#K(Dpjp-JUI} zzr3nmogc|@zD{)}zE*58CI9}ZMj9yHaavkoiRz^nsUkR{{WlDg@SCLk7s(KOcimZd zhlWMa%|*duc;EKll`;hEg)gHhY)IuxG`x`f2v5!|+NLCbtt?bDrXeR?N;CT<1Jdsx zfL7H*>3{EoNwN-3OcCh1u0#aNH@bb#4|lr&5hIW4zp2SV??NKD|7fDy*mQ1Az{EO68B&92n`>WJ=*beH|)y1aIJNNTpkbwvZs?w*VMx7tJ_J`tWRh;6=4YdwPcSm3R%X_={?)add7XbwH+yBG}MqY$mPAQJ)-No8hgq->Hi^Fd2 zS(U8nB2vye-7d^8f0atz*Vk7TT|%TFpD!w~l+?)!=ofTo-`;|!2mm^(JP0cXd6m=n zKx#^gd|oy0q8kNX&m{XJIxyUy+vW4J;N0*vt-Vj>r%(z&i!y}&SLA_amkTumCvgO1 zPGZZrCZ(?wGn^g&jG;YI=LzS@APPDK>MVg$Rk4My zR1rG|q~Eu)ck7wueR<`xFOc$N4y8Z>__0kzAH4;LDH|A=9~E71ulMSh$#J0bAlhA@ zmmic}o^@#1S0Ah{a>KvhQRX^rj^y*>Jn|I5L4ji^jyzhg;}pUzK4dJsY}vXx`L${s zJE}KlD3EqmWj>;9v7DbNYc)bd1wb=GXB573*wEksII4qV(J~}He5!&U+6fg6@=;|L zMYo8r3>DfnSaltfKT2>dcd=^ze)ty~@BIF1($XS+Moy8$f+j@6%omdyDrJ!)l-Zi~ z(@P6WNjY5f2~V80;>oDMl6+jU7qC%qr0xPw#KWH zKb&|Zd?s}O`bCT6!cTf%ZQCZ07FZaTTsTud-~IE)kKcn3-;*$p7*2z%o8YQGr4|62 zozV}6;3uH@0#eni(PwfA{2Hj{XCWaSLYrl5$O}F{-IzW==1_#gz}$KXlNxEt3j(>K znVI#X)8>$YEP-2@2LR2KGY#ljmAv$tk7KBakdlm1o0!o?1yVZKPvOXD3IKIaOZ^IE zpFv)GJWD?pmR7$>n^J(fGRP|ESeV5-H^i0|cV@6_Fqn=3)EY*cleSUi3_=TU5|?}7 zn3xX2x(p^HHzjyq-jZYsx_dv=`wg(>|VIZ4y;C8S9XzrFo*Omx*i` zE#P)=rMXd#Zv;84l6;wFcA*=gwGS(Q;NAL{UHrv5J#97EOJ-5Qk*YQcWCA+C*1MVQ zkh6%vHQ7h>+eRmQ4E2IXI9O^smrl9HvS_&fx94GXdal{ZCtdXkyt0c+5q6v@_rHq_ zNXh5R=$Nlwo!V~d4a|@8{g~U+;&ehNh03AC4n#i}Fsh}IH!ic+eJE1Z1`d{dIc)FC za2&u%5#j}bl`AZ<=6d2)(6}@&Ccft9n;Wg_RESvV->BFJd$@sb)+O~gB&^fzg8V#4 znTzY&c0#=kuXfsc0tI(o__IdzOFvAuzf!=H8Exzx}e)O>{a11gklR6L(9w;*B~vc4)Z&@b2h)TvWi8Y8(m z6;I1TUPcu;{}ZJBMu&4C&)>Y+s#|LK?90d}&^lM&^nwtXu)0;&Z0B$q`?Mtsqh=Ot zW9Br9!b=R8cmOmW@lTKIp6A!yQMAxHKA2RN!58`Xc(oV3$351m>QwUu$00Uyx_x9y zW(2c~q7${*ZPtfJl^Ip}DdD@;c@Xl{0$YE5aH_~!lcY12lLzbhezvnKSVeYP8n4h~ z4na7ywRc+Kr?Lg4%7ZfF+DfKJ-E>rwz>99bM?S7+daHCg5u|-_t$E;jY-`Rv zSm=G?OI0UIFio?haLe&GSzQ^DQl}VZswiLK|xiH{egz9`>IX{`~j8^!(AH|NFnrAo?l(WAbZVK6h literal 0 HcmV?d00001 diff --git a/sips/rsa_network_authentication.md b/sips/rsa_network_authentication.md new file mode 100644 index 0000000..2b1dfb6 --- /dev/null +++ b/sips/rsa_network_authentication.md @@ -0,0 +1,36 @@ +| Author | Title | Category | Status | Dependency SIP | Date | +| -------------- | -------------------------- | ---------- | ------------------- | -------------- | ---------- | +| Matheus Franco | RSA Network Authentication | Networking | open-for-discussion | - | 2023-10-08 | + +## Summary + +In the current setup, our company employs BLS signatures for message authentication in our peer-to-peer (P2P) network. However, this process is resource-intensive and significantly impacts the scalability of our network, especially when dealing with a large volume of messages. To address this challenge, this proposal suggests replacing BLS verification with RSA verification, aiming to enhance network scalability and reduce message processing time. + +## Motivation + +The primary motivation behind this proposal is the need to improve the scalability of our network. BLS verification, while secure, is a costly operation in terms of computational resources. As we anticipate an increase in the number of messages processed by our network, it is imperative to explore more efficient alternatives. + +## Rationale + +The rationale behind adopting RSA verification lies in its superior performance compared to BLS signatures. While BLS verification takes approximately 2300 microseconds, RSA verification completes in just $\approx$ 58 microseconds. This drastic reduction in processing time ensures that our network can handle a larger volume of messages within the same computational resources, enhancing overall network scalability without compromising security standards. Below, it's shown the results of a benchmark test in go for several authentication algorithms, using 4 cores of Apple M1 Pro processors. + + +

+ +

+ + +## Security Considerations + + +The adoption of RSA verification brings notable benefits in terms of efficiency and scalability. However, it also introduces specific security considerations that must be thoroughly addressed regarding the network messages and the implementation process: + +1. Key Length and Security: The security of RSA encryption is highly dependent on the length of the key used. Shorter keys are more vulnerable to brute-force attacks. The [US National Institute of Standard and Technology (NIST)](https://www.nist.gov) approves a minimum of 2048 bit RSA keys. Check the first table of section 1.5 of their [Security Policy](https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4172.pdf), released in 2023 July, for this reference. +2. Signature Size Concerns: Presently, BLS signatures occupy 96 bytes. Shifting to RSA with 2048-bit keys would expand signatures to 256 bytes ($\approx 2.6$ times larger). This enlargement could escalate the size of network messages, potentially affecting bandwidth and message transmission times. +3. Padding Schemes: RSA signatures require the use of padding schemes to ensure security. Poorly implemented or outdated padding schemes can expose the system to padding oracle attacks, where an attacker can gain unauthorized access to encrypted data. Employing secure padding schemes, such as Optimal Asymmetric Encryption Padding (OAEP) for encryption and PKCS#1 v1.5 (or PSS) padding for signatures, is essential to prevent these vulnerabilities. +4. Cryptographic Agility: While RSA is currently a widely accepted encryption and digital signature algorithm, the field of cryptography is constantly evolving. It's important to design the system with cryptographic agility in mind, allowing for the future transition to more secure algorithms if necessary. This flexibility ensures that the network can adapt to emerging security threats and maintain a robust security posture over time. It's worth noting that RSA, despite its prevalence, is among the most targeted cryptographic schemes. For instance, elliptic curve cryptography is often recommended due to its enhanced security features. However, even these might fall by the wayside with the impending rise of quantum computers, compelling a transition to advanced alternatives like Dilithium or Falcon. +5. Compliance and Standards: Ensure that the implementation adheres to industry standards and best practices, such as those outlined by NIST and other relevant regulatory bodies. Compliance with established standards helps validate the security of the RSA implementation and provides assurance against common vulnerabilities and exploits. + +## Specification + +At present, the operator employs their BLS private key share for verification. However, the operator also possesses an RSA key, which would replace the BLS key for signing messages. All other nodes store both BLS and RSA public keys of every node, eliminating the need for a key exchange protocol. From 025395af3d65375101fd74a207acb2974792abaa Mon Sep 17 00:00:00 2001 From: Matheus Franco Date: Tue, 10 Oct 2023 12:45:15 +0100 Subject: [PATCH 2/6] Update according to comments --- sips/rsa_network_authentication.md | 23 +++++++++++++---------- 1 file changed, 13 insertions(+), 10 deletions(-) diff --git a/sips/rsa_network_authentication.md b/sips/rsa_network_authentication.md index 2b1dfb6..6e8c3b1 100644 --- a/sips/rsa_network_authentication.md +++ b/sips/rsa_network_authentication.md @@ -4,7 +4,7 @@ ## Summary -In the current setup, our company employs BLS signatures for message authentication in our peer-to-peer (P2P) network. However, this process is resource-intensive and significantly impacts the scalability of our network, especially when dealing with a large volume of messages. To address this challenge, this proposal suggests replacing BLS verification with RSA verification, aiming to enhance network scalability and reduce message processing time. +In the current setup, our protocol employs BLS signatures for message authentication in our peer-to-peer (P2P) network. However, this process is resource-intensive and significantly impacts the scalability of our network, especially when dealing with a large volume of messages. To address this challenge, this proposal suggests replacing BLS verification with RSA verification, aiming to enhance network scalability and reduce message processing time. ## Motivation @@ -19,18 +19,21 @@ The rationale behind adopting RSA verification lies in its superior performance

+Other schemes also demonstrate better performance than BLS, like ECDSA and EdDSA. We chose RSA because operators already have a coupled RSA key and it showed great verification performance, which is the current bottleneck, even though the signing time is higher. -## Security Considerations +## Drawbacks +- Signature Size Concerns: Presently, BLS signatures occupy 96 bytes. Shifting to RSA with 2048-bit keys would expand signatures to 256 bytes ($\approx 2.6$ times larger). This enlargement could escalate the size of network messages, potentially affecting bandwidth and message transmission times. -The adoption of RSA verification brings notable benefits in terms of efficiency and scalability. However, it also introduces specific security considerations that must be thoroughly addressed regarding the network messages and the implementation process: - -1. Key Length and Security: The security of RSA encryption is highly dependent on the length of the key used. Shorter keys are more vulnerable to brute-force attacks. The [US National Institute of Standard and Technology (NIST)](https://www.nist.gov) approves a minimum of 2048 bit RSA keys. Check the first table of section 1.5 of their [Security Policy](https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4172.pdf), released in 2023 July, for this reference. -2. Signature Size Concerns: Presently, BLS signatures occupy 96 bytes. Shifting to RSA with 2048-bit keys would expand signatures to 256 bytes ($\approx 2.6$ times larger). This enlargement could escalate the size of network messages, potentially affecting bandwidth and message transmission times. -3. Padding Schemes: RSA signatures require the use of padding schemes to ensure security. Poorly implemented or outdated padding schemes can expose the system to padding oracle attacks, where an attacker can gain unauthorized access to encrypted data. Employing secure padding schemes, such as Optimal Asymmetric Encryption Padding (OAEP) for encryption and PKCS#1 v1.5 (or PSS) padding for signatures, is essential to prevent these vulnerabilities. -4. Cryptographic Agility: While RSA is currently a widely accepted encryption and digital signature algorithm, the field of cryptography is constantly evolving. It's important to design the system with cryptographic agility in mind, allowing for the future transition to more secure algorithms if necessary. This flexibility ensures that the network can adapt to emerging security threats and maintain a robust security posture over time. It's worth noting that RSA, despite its prevalence, is among the most targeted cryptographic schemes. For instance, elliptic curve cryptography is often recommended due to its enhanced security features. However, even these might fall by the wayside with the impending rise of quantum computers, compelling a transition to advanced alternatives like Dilithium or Falcon. -5. Compliance and Standards: Ensure that the implementation adheres to industry standards and best practices, such as those outlined by NIST and other relevant regulatory bodies. Compliance with established standards helps validate the security of the RSA implementation and provides assurance against common vulnerabilities and exploits. ## Specification -At present, the operator employs their BLS private key share for verification. However, the operator also possesses an RSA key, which would replace the BLS key for signing messages. All other nodes store both BLS and RSA public keys of every node, eliminating the need for a key exchange protocol. +At present, the operator employs their BLS private key share for verification. However, the operator also possesses an RSA key, which would replace the BLS key for signing messages. All other nodes store both the BLS and RSA public keys of every node, eliminating the need for a key exchange protocol. + +The following security and design considerations should be thoroughly addressed: + +1. Key Length and Security: The security of RSA encryption is highly dependent on the length of the key used. For instance, shorter keys are more vulnerable to brute-force attacks. The [US National Institute of Standard and Technology (NIST)](https://www.nist.gov) approves a minimum of 2048-bit RSA keys. Check the first table of section 1.5 of their [Security Policy](https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4172.pdf), released in 2023 July, for this reference. +2. Padding Schemes: RSA signatures require the use of padding schemes to ensure security. Poorly implemented or outdated padding schemes can expose the system to padding oracle attacks, where an attacker can gain unauthorized access to encrypted data. Employing secure padding schemes, such as PKCS#1 v1.5 or PSS, is essential to prevent these vulnerabilities. +3. Compliance and Standards: Ensure that the implementation adheres to industry standards and best practices, such as those outlined by NIST and other relevant regulatory bodies. Compliance with established standards helps validate the security of the RSA implementation and provides assurance against common vulnerabilities and exploits. +4. Abstraction to handle Cryptographic Agility: While RSA is currently a widely accepted encryption and digital signature algorithm, the field of cryptography is constantly evolving. It's important to design the system with cryptographic agility in mind, allowing for the future transition to more secure algorithms if necessary. It's worth noting that RSA, despite its prevalence, is among the most targeted cryptographic schemes. For instance, elliptic curve cryptography is often recommended due to its enhanced security features. However, even these might fall by the wayside with the impending rise of quantum computers, compelling a transition to advanced alternatives like Dilithium or Falcon. + From e6e05cf6acce983348ec28f0a957d96c4e8676e8 Mon Sep 17 00:00:00 2001 From: MatheusFranco99 <48058141+MatheusFranco99@users.noreply.github.com> Date: Mon, 11 Dec 2023 07:52:27 -0300 Subject: [PATCH 3/6] Update adding message verification steps. Appendix regarding performance results. --- sips/rsa_network_authentication.md | 57 ++++++++++++++++++++++++------ 1 file changed, 47 insertions(+), 10 deletions(-) diff --git a/sips/rsa_network_authentication.md b/sips/rsa_network_authentication.md index 6e8c3b1..00a981a 100644 --- a/sips/rsa_network_authentication.md +++ b/sips/rsa_network_authentication.md @@ -1,34 +1,62 @@ -| Author | Title | Category | Status | Dependency SIP | Date | -| -------------- | -------------------------- | ---------- | ------------------- | -------------- | ---------- | -| Matheus Franco | RSA Network Authentication | Networking | open-for-discussion | - | 2023-10-08 | +| Author | Title | Category | Status | Date | +| -------------- | -------------------------- | ---------- | ------------------- | ---------- | +| Matheus Franco | RSA Network Authentication | Networking | open-for-discussion | 2023-10-08 | ## Summary -In the current setup, our protocol employs BLS signatures for message authentication in our peer-to-peer (P2P) network. However, this process is resource-intensive and significantly impacts the scalability of our network, especially when dealing with a large volume of messages. To address this challenge, this proposal suggests replacing BLS verification with RSA verification, aiming to enhance network scalability and reduce message processing time. +In the current setup, our protocol employs BLS signatures for message authentication in the peer-to-peer (P2P) network. However, this process is resource-intensive and limits the scalability of the network, especially when dealing with a large volume of messages. To address this problem, this proposal suggests replacing BLS verification with RSA verification, in the message validation module, aiming to enhance network scalability and reduce message processing time. ## Motivation -The primary motivation behind this proposal is the need to improve the scalability of our network. BLS verification, while secure, is a costly operation in terms of computational resources. As we anticipate an increase in the number of messages processed by our network, it is imperative to explore more efficient alternatives. +The primary motivation behind this proposal is the need to improve the scalability of our network. More validators imply more messages and more signature verifications. As we anticipate an increase in the number of messages processed by our network, it is imperative to explore more efficient alternatives to the costly BLS verification operation. ## Rationale -The rationale behind adopting RSA verification lies in its superior performance compared to BLS signatures. While BLS verification takes approximately 2300 microseconds, RSA verification completes in just $\approx$ 58 microseconds. This drastic reduction in processing time ensures that our network can handle a larger volume of messages within the same computational resources, enhancing overall network scalability without compromising security standards. Below, it's shown the results of a benchmark test in go for several authentication algorithms, using 4 cores of Apple M1 Pro processors. +The rationale behind adopting a better message authentication algorithm lies in comparing multiple algorithms' performance and security. +Below, it's shown the results of a benchmark test in Go 1.19 for several authentication algorithms, using 4 cores of Apple M1 Pro processors.

-Other schemes also demonstrate better performance than BLS, like ECDSA and EdDSA. We chose RSA because operators already have a coupled RSA key and it showed great verification performance, which is the current bottleneck, even though the signing time is higher. +Besides the better performance of RSA, this scheme is also the most straightforward to implement due to the already existing operator's RSA network key. + +Its security is approved by the [US National Institute of Standard and Technology (NIST)](https://www.nist.gov) as in their [Security Policy](https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4172.pdf) released in 2023 July. + +This drastic reduction in processing time ensures that the network can handle a larger volume of messages for the same computational resources, enhancing overall network scalability without compromising security standards. ## Drawbacks -- Signature Size Concerns: Presently, BLS signatures occupy 96 bytes. Shifting to RSA with 2048-bit keys would expand signatures to 256 bytes ($\approx 2.6$ times larger). This enlargement could escalate the size of network messages, potentially affecting bandwidth and message transmission times. +- Signature Size Concerns: Currently, BLS signatures occupy 96 bytes. Including an RSA signature with 2048-bit keys would add an extra 256 bytes ($\approx 2.6$ times more). This enlargement could escalate the size of network messages, potentially affecting bandwidth and message transmission times. + +## Message Authentication Steps + +RSA signatures may be used for message authentication in the network but the protocol still needs to use the BLS scheme for the beacon duties. Therefore, message authentication is divided into two steps: +1. Once received in the message validation module, the message's **RSA signature** is verified using the **operator's network key**. +2. If the RSA signature is valid and the receiver node participates in the duty, the message's **BLS signature** is verified using the operator's **BLS public key**, in the protocol module. + +```mermaid + +flowchart LR + subgraph MessageValidation[Message Validation] + rsa[RSA Verification] + end + subgraph Protocol[Protocol] + bls[BLS Verification] + end + Message(Message):::bar + Message --> rsa + rsa -- Valid RSA --> bls -## Specification + classDef bar stroke:#FFD700 +``` -At present, the operator employs their BLS private key share for verification. However, the operator also possesses an RSA key, which would replace the BLS key for signing messages. All other nodes store both the BLS and RSA public keys of every node, eliminating the need for a key exchange protocol. + +## Appendix + +### A1 - Security Considerations The following security and design considerations should be thoroughly addressed: @@ -37,3 +65,12 @@ The following security and design considerations should be thoroughly addressed: 3. Compliance and Standards: Ensure that the implementation adheres to industry standards and best practices, such as those outlined by NIST and other relevant regulatory bodies. Compliance with established standards helps validate the security of the RSA implementation and provides assurance against common vulnerabilities and exploits. 4. Abstraction to handle Cryptographic Agility: While RSA is currently a widely accepted encryption and digital signature algorithm, the field of cryptography is constantly evolving. It's important to design the system with cryptographic agility in mind, allowing for the future transition to more secure algorithms if necessary. It's worth noting that RSA, despite its prevalence, is among the most targeted cryptographic schemes. For instance, elliptic curve cryptography is often recommended due to its enhanced security features. However, even these might fall by the wayside with the impending rise of quantum computers, compelling a transition to advanced alternatives like Dilithium or Falcon. +### A2 - Performance results + +The results presented in the rationale section were obtained using Go 1.19 with 4 cores of Apple M1 Pro processors. + +However, it's important to emphasize that values may change depending on the Go version. For example, Go 1.20 and 1.21 had a major impact on the RSA scheme, as can be seen here: +- [Issue: crypto/rsa: Some severe performance regressions in Go 1.20](https://github.com/golang/go/issues/59442) +- [Issue: crypto/rsa: severe VerifyPKCS1v15 performance regression in Go 1.20, Go 1.21](https://github.com/golang/go/issues/63516) + +To avoid the current hurdles with "crypto/rsa", we can also utilize [Microsoft's Go-Crypto-OpenSSL library](https://github.com/microsoft/go-crypto-openssl) which showed good performance results ($\approx 16 \mu s$ for signature verification). From 8b60e5bfb2f5b543c005c76660c2f0a9e91077ed Mon Sep 17 00:00:00 2001 From: MatheusFranco99 <48058141+MatheusFranco99@users.noreply.github.com> Date: Mon, 11 Dec 2023 07:55:14 -0300 Subject: [PATCH 4/6] Refactor SIP name --- all.md | 22 +++++++++--------- networking.md | 6 ++--- .../asymmetric_scheme_performance.png | Bin ...ation.md => rsa_message_authentication.md} | 4 ++-- 4 files changed, 16 insertions(+), 16 deletions(-) rename sips/images/{rsa_network_authentication => rsa_message_authentication}/asymmetric_scheme_performance.png (100%) rename sips/{rsa_network_authentication.md => rsa_message_authentication.md} (97%) diff --git a/all.md b/all.md index 3bcd3ca..14abdef 100644 --- a/all.md +++ b/all.md @@ -1,13 +1,13 @@ ## All SIPS -| SIP # | Title | Status | -|-------------------------------------------|-----------------------------|---------------------| -| [1](./sips/dkg.md) | DKG | open-for-discussion | -| [2](./sips/msg_struct_encoding.md) | Message struct and encoding | open-for-discussion | -| [3](./sips/qbft_sync.md) | QBFT Sync | open-for-discussion | -| [4](./sips/change_operator.md) | Change operators set | open-for-discussion | -| [5](./sips/ecies_share_encryption.md) | ECIES Share Encryption | open-for-discussion | -| [6](./sips/constant_qbft_timeout.md) | Constant QBFT timeout | open-for-discussion | -| [7](./sips/fork_support.md) | Fork Support | open-for-discussion | -| [8](./sips/pre_consensus_livness.md) | Pre-Consensus livness fix | open-for-discussion | -| [9](./sips/rsa_network_authentication.md) | RSA Network Authentication | open-for-discussion | \ No newline at end of file +| SIP # | Title | Status | +|-----------------------------------------|-----------------------------|---------------------| +| [1](./sips/dkg.md) | DKG | open-for-discussion | +| [2](./sips/msg_struct_encoding.md) | Message struct and encoding | open-for-discussion | +| [3](./sips/qbft_sync.md) | QBFT Sync | open-for-discussion | +| [4](./sips/change_operator.md) | Change operators set | open-for-discussion | +| [5](./sips/ecies_share_encryption.md) | ECIES Share Encryption | open-for-discussion | +| [6](./sips/constant_qbft_timeout.md) | Constant QBFT timeout | open-for-discussion | +| [7](./sips/fork_support.md) | Fork Support | open-for-discussion | +| [8](./sips/pre_consensus_livness.md) | Pre-Consensus livness fix | open-for-discussion | +| [9](sips/rsa_message_authentication.md) | RSA Message Authentication | open-for-discussion | \ No newline at end of file diff --git a/networking.md b/networking.md index 74e2c30..d1c4f9d 100644 --- a/networking.md +++ b/networking.md @@ -1,5 +1,5 @@ ## Core -| SIP # | Title | Status | -| ----------------------------------------- | -------------------------- | ------------------- | -| [9](./sips/rsa_network_authentication.md) | RSA Network Authentication | open-for-discussion | \ No newline at end of file +| SIP # | Title | Status | +| --------------------------------------- | -------------------------- | ------------------- | +| [9](sips/rsa_message_authentication.md) | RSA Message Authentication | open-for-discussion | \ No newline at end of file diff --git a/sips/images/rsa_network_authentication/asymmetric_scheme_performance.png b/sips/images/rsa_message_authentication/asymmetric_scheme_performance.png similarity index 100% rename from sips/images/rsa_network_authentication/asymmetric_scheme_performance.png rename to sips/images/rsa_message_authentication/asymmetric_scheme_performance.png diff --git a/sips/rsa_network_authentication.md b/sips/rsa_message_authentication.md similarity index 97% rename from sips/rsa_network_authentication.md rename to sips/rsa_message_authentication.md index 00a981a..294ba09 100644 --- a/sips/rsa_network_authentication.md +++ b/sips/rsa_message_authentication.md @@ -1,6 +1,6 @@ | Author | Title | Category | Status | Date | | -------------- | -------------------------- | ---------- | ------------------- | ---------- | -| Matheus Franco | RSA Network Authentication | Networking | open-for-discussion | 2023-10-08 | +| Matheus Franco | RSA Message Authentication | Networking | open-for-discussion | 2023-10-08 | ## Summary @@ -17,7 +17,7 @@ The rationale behind adopting a better message authentication algorithm lies in Below, it's shown the results of a benchmark test in Go 1.19 for several authentication algorithms, using 4 cores of Apple M1 Pro processors.

- +

Besides the better performance of RSA, this scheme is also the most straightforward to implement due to the already existing operator's RSA network key. From 04c3391b81e9bad199945b4939883ccc000798c8 Mon Sep 17 00:00:00 2001 From: MatheusFranco99 <48058141+MatheusFranco99@users.noreply.github.com> Date: Tue, 12 Dec 2023 05:40:17 -0300 Subject: [PATCH 5/6] Add padding scheme to be used --- sips/rsa_message_authentication.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sips/rsa_message_authentication.md b/sips/rsa_message_authentication.md index 294ba09..970d449 100644 --- a/sips/rsa_message_authentication.md +++ b/sips/rsa_message_authentication.md @@ -61,7 +61,7 @@ flowchart LR The following security and design considerations should be thoroughly addressed: 1. Key Length and Security: The security of RSA encryption is highly dependent on the length of the key used. For instance, shorter keys are more vulnerable to brute-force attacks. The [US National Institute of Standard and Technology (NIST)](https://www.nist.gov) approves a minimum of 2048-bit RSA keys. Check the first table of section 1.5 of their [Security Policy](https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4172.pdf), released in 2023 July, for this reference. -2. Padding Schemes: RSA signatures require the use of padding schemes to ensure security. Poorly implemented or outdated padding schemes can expose the system to padding oracle attacks, where an attacker can gain unauthorized access to encrypted data. Employing secure padding schemes, such as PKCS#1 v1.5 or PSS, is essential to prevent these vulnerabilities. +2. Padding Schemes: RSA signatures require the use of padding schemes to ensure security. Poorly implemented or outdated padding schemes can expose the system to padding oracle attacks, where an attacker can gain unauthorized access to encrypted data. Employing secure padding schemes, such as PKCS#1 v1.5 or PSS, is essential to prevent these vulnerabilities. For the current implementation, PKCS#1 v1.5 will be used. 3. Compliance and Standards: Ensure that the implementation adheres to industry standards and best practices, such as those outlined by NIST and other relevant regulatory bodies. Compliance with established standards helps validate the security of the RSA implementation and provides assurance against common vulnerabilities and exploits. 4. Abstraction to handle Cryptographic Agility: While RSA is currently a widely accepted encryption and digital signature algorithm, the field of cryptography is constantly evolving. It's important to design the system with cryptographic agility in mind, allowing for the future transition to more secure algorithms if necessary. It's worth noting that RSA, despite its prevalence, is among the most targeted cryptographic schemes. For instance, elliptic curve cryptography is often recommended due to its enhanced security features. However, even these might fall by the wayside with the impending rise of quantum computers, compelling a transition to advanced alternatives like Dilithium or Falcon. From 31a902d49ccdef0fe5215e853a329e46818ca2b7 Mon Sep 17 00:00:00 2001 From: MatheusFranco99 <48058141+MatheusFranco99@users.noreply.github.com> Date: Fri, 29 Dec 2023 16:38:07 -0300 Subject: [PATCH 6/6] Add new message structure --- sips/rsa_message_authentication.md | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/sips/rsa_message_authentication.md b/sips/rsa_message_authentication.md index 970d449..91c8926 100644 --- a/sips/rsa_message_authentication.md +++ b/sips/rsa_message_authentication.md @@ -53,6 +53,16 @@ flowchart LR classDef bar stroke:#FFD700 ``` +## Message Structure Change + +The previous message structure, `SSVMessage`, doesn't contain a field for an RSA signature and, therefore, it shall be encapsulated into a higher structure to support it. It can be done using the following byte message partition: + +| Field | Size (Bytes) | +|-----------|--------------| +| Signature | 256 | +| ID | 8 | +| Message | - | + ## Appendix