src/crypto/secp256k1/schnorr.bend checks
raw source on the hub · import bend-collections-laws-crypto@1.0.0.0/src/crypto/secp256k1/schnorr.bend as Schnorr
7 imports
import Base import ../sha/sha256.bend as SHA import ./limbs.bend as L import ./field.bend as F import ./scalar.bend as S import ./point.bend as P import ./bytes.bend as B
Definitions
def cat source · line 15 · raw
@xs:List<&2, U32> -> @ys:List<&2, U32> -> List<&2, U32>
def tag_prefix source · line 19 · raw
@rest:List<&2, U32> -> List<&2, U32>
"BIP0340/aux", "BIP0340/nonce", "BIP0340/challenge" in ASCII
def tag_aux source · line 22 · raw
List<&2, U32>
def tag_nonce source · line 25 · raw
List<&2, U32>
def tag_challenge source · line 28 · raw
List<&2, U32>
def tagged_h source · line 32 · raw
@+th:List<&2, U32> -> @x:List<&2, U32> -> List<&2, U32>
hash_tag(x) = SHA256(SHA256(tag) || SHA256(tag) || x)
def tagged source · line 35 · raw
@tag:List<&2, U32> -> @x:List<&2, U32> -> List<&2, U32>
def xor_bytes source · line 38 · raw
@xs:List<&2, U32> -> @ys:List<&2, U32> -> List<&2, U32>
def is_odd source · line 43 · raw
@+y:List<&2, Nat> -> Nat
def verify_aff source · line 46 · raw
@+r:List<&2, Nat> -> @inf:Bool -> @a:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Affine -> Bool
def verify_r source · line 53 · raw
@+r:List<&2, Nat> -> @+rr:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Point -> Bool
R = [s] G - [e] P must be finite, with even y and x(R) = r
def verify_ok source · line 56 · raw
@+r:List<&2, Nat> -> @+s:List<&2, Nat> -> @+e:List<&2, Nat> -> @+pp:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Point -> @ok:Bool -> Bool
def verify_p source · line 61 · raw
@+pk:List<&2, U32> -> @+m:List<&2, U32> -> @+sig:List<&2, U32> -> @mp:Maybe<&2, 0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Point> -> Bool
def lift_if source · line 71 · raw
@+x:List<&2, Nat> -> @ok:Bool -> Maybe<&2, 0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Point>
def lift_x source · line 77 · raw
@+x:List<&2, Nat> -> Maybe<&2, 0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Point>
lift_x: the point with x-coordinate x and even y, if any
def verify_len source · line 80 · raw
@+pk:List<&2, U32> -> @+m:List<&2, U32> -> @+sig:List<&2, U32> -> @ok:Bool -> Bool
def verify source · line 86 · raw
@+pk:List<&2, U32> -> @+m:List<&2, U32> -> @+sig:List<&2, U32> -> Bool
BIP-340 Verify(pk, m, sig) for a 32-byte x-only key and a 64-byte signature
def secret_if source · line 92 · raw
@+d:List<&2, Nat> -> @ok:Bool -> Maybe<&2, List<&2, Nat>>
the secret key d', when 1 <= d' < n
def secret source · line 97 · raw
@+sk:List<&2, U32> -> Maybe<&2, List<&2, Nat>>
def pubkey_aff source · line 101 · raw
@a:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Affine -> List<&2, U32>
def pubkey_d source · line 105 · raw
@m:Maybe<&2, List<&2, Nat>> -> Maybe<&2, List<&2, U32>>
def pubkey source · line 111 · raw
@+sk:List<&2, U32> -> Maybe<&2, List<&2, U32>>
PubKey(sk) = bytes(d' G), the 32-byte x-only public key
def sign_ok source · line 115 · raw
@+sig:List<&2, U32> -> @ok:Bool -> Maybe<&2, List<&2, U32>>
sig = bytes(R) || bytes((k + e d) mod n), then Verify(bytes(P), m, sig)
def sign_fin source · line 120 · raw
@+pb:List<&2, U32> -> @+m:List<&2, U32> -> @+sig:List<&2, U32> -> Maybe<&2, List<&2, U32>>
def sign_k source · line 123 · raw
@+d:List<&2, Nat> -> @+pb:List<&2, U32> -> @+m:List<&2, U32> -> @+k0:List<&2, Nat> -> @ra:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Affine -> Maybe<&2, List<&2, U32>>
def sign_nz source · line 131 · raw
@+d:List<&2, Nat> -> @+pb:List<&2, U32> -> @+m:List<&2, U32> -> @+k0:List<&2, Nat> -> @ok:Bool -> Maybe<&2, List<&2, U32>>
def sign_p source · line 136 · raw
@+d0:List<&2, Nat> -> @+m:List<&2, U32> -> @+aux:List<&2, U32> -> @pa:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Affine -> Maybe<&2, List<&2, U32>>
def sign_d source · line 145 · raw
@+m:List<&2, U32> -> @+aux:List<&2, U32> -> @md:Maybe<&2, List<&2, Nat>> -> Maybe<&2, List<&2, U32>>
def sign_len source · line 150 · raw
@+sk:List<&2, U32> -> @+m:List<&2, U32> -> @+aux:List<&2, U32> -> @ok:Bool -> Maybe<&2, List<&2, U32>>
def sign source · line 158 · raw
@+sk:List<&2, U32> -> @+m:List<&2, U32> -> @+aux:List<&2, U32> -> Maybe<&2, List<&2, U32>>
BIP-340 Sign(sk, m, a) for a 32-byte secret key and 32 bytes of auxiliary randomness; None for an invalid key (or, with negligible probability, a zero nonce or a failed self-check)