~/bend-docscommunity

src/crypto/secp256k1/schnorr.bend checks

raw source on the hub · import bend-collections-laws-crypto@1.0.0.0/src/crypto/secp256k1/schnorr.bend as Schnorr

7 imports
import Base
import ../sha/sha256.bend as SHA
import ./limbs.bend as L
import ./field.bend as F
import ./scalar.bend as S
import ./point.bend as P
import ./bytes.bend as B

Definitions

def cat source · line 15 · raw

@xs:List<&2, U32> -> @ys:List<&2, U32> -> List<&2, U32>

def tag_prefix source · line 19 · raw

@rest:List<&2, U32> -> List<&2, U32>

"BIP0340/aux", "BIP0340/nonce", "BIP0340/challenge" in ASCII

def tag_aux source · line 22 · raw

List<&2, U32>

def tag_nonce source · line 25 · raw

List<&2, U32>

def tag_challenge source · line 28 · raw

List<&2, U32>

def tagged_h source · line 32 · raw

@+th:List<&2, U32> -> @x:List<&2, U32> -> List<&2, U32>

hash_tag(x) = SHA256(SHA256(tag) || SHA256(tag) || x)

def tagged source · line 35 · raw

@tag:List<&2, U32> -> @x:List<&2, U32> -> List<&2, U32>

def xor_bytes source · line 38 · raw

@xs:List<&2, U32> -> @ys:List<&2, U32> -> List<&2, U32>

def is_odd source · line 43 · raw

@+y:List<&2, Nat> -> Nat

def verify_aff source · line 46 · raw

@+r:List<&2, Nat> -> @inf:Bool -> @a:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Affine -> Bool

def verify_r source · line 53 · raw

@+r:List<&2, Nat> -> @+rr:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Point -> Bool

R = [s] G - [e] P must be finite, with even y and x(R) = r

def verify_ok source · line 56 · raw

@+r:List<&2, Nat> -> @+s:List<&2, Nat> -> @+e:List<&2, Nat> -> @+pp:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Point -> @ok:Bool -> Bool

def verify_p source · line 61 · raw

@+pk:List<&2, U32> -> @+m:List<&2, U32> -> @+sig:List<&2, U32> -> @mp:Maybe<&2, 0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Point> -> Bool

def lift_if source · line 71 · raw

@+x:List<&2, Nat> -> @ok:Bool -> Maybe<&2, 0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Point>

def lift_x source · line 77 · raw

@+x:List<&2, Nat> -> Maybe<&2, 0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Point>

lift_x: the point with x-coordinate x and even y, if any

def verify_len source · line 80 · raw

@+pk:List<&2, U32> -> @+m:List<&2, U32> -> @+sig:List<&2, U32> -> @ok:Bool -> Bool

def verify source · line 86 · raw

@+pk:List<&2, U32> -> @+m:List<&2, U32> -> @+sig:List<&2, U32> -> Bool

BIP-340 Verify(pk, m, sig) for a 32-byte x-only key and a 64-byte signature

def secret_if source · line 92 · raw

@+d:List<&2, Nat> -> @ok:Bool -> Maybe<&2, List<&2, Nat>>

the secret key d', when 1 <= d' < n

def secret source · line 97 · raw

@+sk:List<&2, U32> -> Maybe<&2, List<&2, Nat>>

def pubkey_aff source · line 101 · raw

@a:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Affine -> List<&2, U32>

def pubkey_d source · line 105 · raw

@m:Maybe<&2, List<&2, Nat>> -> Maybe<&2, List<&2, U32>>

def pubkey source · line 111 · raw

@+sk:List<&2, U32> -> Maybe<&2, List<&2, U32>>

PubKey(sk) = bytes(d' G), the 32-byte x-only public key

def sign_ok source · line 115 · raw

@+sig:List<&2, U32> -> @ok:Bool -> Maybe<&2, List<&2, U32>>

sig = bytes(R) || bytes((k + e d) mod n), then Verify(bytes(P), m, sig)

def sign_fin source · line 120 · raw

@+pb:List<&2, U32> -> @+m:List<&2, U32> -> @+sig:List<&2, U32> -> Maybe<&2, List<&2, U32>>

def sign_k source · line 123 · raw

@+d:List<&2, Nat> -> @+pb:List<&2, U32> -> @+m:List<&2, U32> -> @+k0:List<&2, Nat> -> @ra:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Affine -> Maybe<&2, List<&2, U32>>

def sign_nz source · line 131 · raw

@+d:List<&2, Nat> -> @+pb:List<&2, U32> -> @+m:List<&2, U32> -> @+k0:List<&2, Nat> -> @ok:Bool -> Maybe<&2, List<&2, U32>>

def sign_p source · line 136 · raw

@+d0:List<&2, Nat> -> @+m:List<&2, U32> -> @+aux:List<&2, U32> -> @pa:0xa7e654f9780078ca65bf9e187da99d3e/src/crypto/secp256k1/point.Affine -> Maybe<&2, List<&2, U32>>

def sign_d source · line 145 · raw

@+m:List<&2, U32> -> @+aux:List<&2, U32> -> @md:Maybe<&2, List<&2, Nat>> -> Maybe<&2, List<&2, U32>>

def sign_len source · line 150 · raw

@+sk:List<&2, U32> -> @+m:List<&2, U32> -> @+aux:List<&2, U32> -> @ok:Bool -> Maybe<&2, List<&2, U32>>

def sign source · line 158 · raw

@+sk:List<&2, U32> -> @+m:List<&2, U32> -> @+aux:List<&2, U32> -> Maybe<&2, List<&2, U32>>

BIP-340 Sign(sk, m, a) for a 32-byte secret key and 32 bytes of auxiliary randomness; None for an invalid key (or, with negligible probability, a zero nonce or a failed self-check)