Bitcoin Core  22.99.0
P2P Digital Currency
main_impl.h
Go to the documentation of this file.
1 /***********************************************************************
2  * Copyright (c) 2020 Jonas Nick *
3  * Distributed under the MIT software license, see the accompanying *
4  * file COPYING or https://www.opensource.org/licenses/mit-license.php.*
5  ***********************************************************************/
6 
7 #ifndef SECP256K1_MODULE_EXTRAKEYS_MAIN_H
8 #define SECP256K1_MODULE_EXTRAKEYS_MAIN_H
9 
10 #include "include/secp256k1.h"
12 
14  return secp256k1_pubkey_load(ctx, ge, (const secp256k1_pubkey *) pubkey);
15 }
16 
19 }
20 
21 int secp256k1_xonly_pubkey_parse(const secp256k1_context* ctx, secp256k1_xonly_pubkey *pubkey, const unsigned char *input32) {
22  secp256k1_ge pk;
23  secp256k1_fe x;
24 
25  VERIFY_CHECK(ctx != NULL);
26  ARG_CHECK(pubkey != NULL);
27  memset(pubkey, 0, sizeof(*pubkey));
28  ARG_CHECK(input32 != NULL);
29 
30  if (!secp256k1_fe_set_b32(&x, input32)) {
31  return 0;
32  }
33  if (!secp256k1_ge_set_xo_var(&pk, &x, 0)) {
34  return 0;
35  }
37  return 0;
38  }
39  secp256k1_xonly_pubkey_save(pubkey, &pk);
40  return 1;
41 }
42 
43 int secp256k1_xonly_pubkey_serialize(const secp256k1_context* ctx, unsigned char *output32, const secp256k1_xonly_pubkey *pubkey) {
44  secp256k1_ge pk;
45 
46  VERIFY_CHECK(ctx != NULL);
47  ARG_CHECK(output32 != NULL);
48  memset(output32, 0, 32);
49  ARG_CHECK(pubkey != NULL);
50 
51  if (!secp256k1_xonly_pubkey_load(ctx, &pk, pubkey)) {
52  return 0;
53  }
54  secp256k1_fe_get_b32(output32, &pk.x);
55  return 1;
56 }
57 
62  int y_parity = 0;
64 
65  if (secp256k1_fe_is_odd(&r->y)) {
66  secp256k1_fe_negate(&r->y, &r->y, 1);
67  y_parity = 1;
68  }
69  return y_parity;
70 }
71 
72 int secp256k1_xonly_pubkey_from_pubkey(const secp256k1_context* ctx, secp256k1_xonly_pubkey *xonly_pubkey, int *pk_parity, const secp256k1_pubkey *pubkey) {
73  secp256k1_ge pk;
74  int tmp;
75 
76  VERIFY_CHECK(ctx != NULL);
77  ARG_CHECK(xonly_pubkey != NULL);
78  ARG_CHECK(pubkey != NULL);
79 
80  if (!secp256k1_pubkey_load(ctx, &pk, pubkey)) {
81  return 0;
82  }
84  if (pk_parity != NULL) {
85  *pk_parity = tmp;
86  }
87  secp256k1_xonly_pubkey_save(xonly_pubkey, &pk);
88  return 1;
89 }
90 
91 int secp256k1_xonly_pubkey_tweak_add(const secp256k1_context* ctx, secp256k1_pubkey *output_pubkey, const secp256k1_xonly_pubkey *internal_pubkey, const unsigned char *tweak32) {
92  secp256k1_ge pk;
93 
94  VERIFY_CHECK(ctx != NULL);
95  ARG_CHECK(output_pubkey != NULL);
96  memset(output_pubkey, 0, sizeof(*output_pubkey));
98  ARG_CHECK(internal_pubkey != NULL);
99  ARG_CHECK(tweak32 != NULL);
100 
101  if (!secp256k1_xonly_pubkey_load(ctx, &pk, internal_pubkey)
102  || !secp256k1_ec_pubkey_tweak_add_helper(&ctx->ecmult_ctx, &pk, tweak32)) {
103  return 0;
104  }
105  secp256k1_pubkey_save(output_pubkey, &pk);
106  return 1;
107 }
108 
109 int secp256k1_xonly_pubkey_tweak_add_check(const secp256k1_context* ctx, const unsigned char *tweaked_pubkey32, int tweaked_pk_parity, const secp256k1_xonly_pubkey *internal_pubkey, const unsigned char *tweak32) {
110  secp256k1_ge pk;
111  unsigned char pk_expected32[32];
112 
113  VERIFY_CHECK(ctx != NULL);
115  ARG_CHECK(internal_pubkey != NULL);
116  ARG_CHECK(tweaked_pubkey32 != NULL);
117  ARG_CHECK(tweak32 != NULL);
118 
119  if (!secp256k1_xonly_pubkey_load(ctx, &pk, internal_pubkey)
120  || !secp256k1_ec_pubkey_tweak_add_helper(&ctx->ecmult_ctx, &pk, tweak32)) {
121  return 0;
122  }
125  secp256k1_fe_get_b32(pk_expected32, &pk.x);
126 
127  return secp256k1_memcmp_var(&pk_expected32, tweaked_pubkey32, 32) == 0
128  && secp256k1_fe_is_odd(&pk.y) == tweaked_pk_parity;
129 }
130 
132  secp256k1_scalar_get_b32(&keypair->data[0], sk);
133  secp256k1_pubkey_save((secp256k1_pubkey *)&keypair->data[32], pk);
134 }
135 
136 
138  int ret;
139 
140  ret = secp256k1_scalar_set_b32_seckey(sk, &keypair->data[0]);
141  /* We can declassify ret here because sk is only zero if a keypair function
142  * failed (which zeroes the keypair) and its return value is ignored. */
143  secp256k1_declassify(ctx, &ret, sizeof(ret));
144  ARG_CHECK(ret);
145  return ret;
146 }
147 
148 /* Load a keypair into pk and sk (if non-NULL). This function declassifies pk
149  * and ARG_CHECKs that the keypair is not invalid. It always initializes sk and
150  * pk with dummy values. */
152  int ret;
153  const secp256k1_pubkey *pubkey = (const secp256k1_pubkey *)&keypair->data[32];
154 
155  /* Need to declassify the pubkey because pubkey_load ARG_CHECKs if it's
156  * invalid. */
157  secp256k1_declassify(ctx, pubkey, sizeof(*pubkey));
158  ret = secp256k1_pubkey_load(ctx, pk, pubkey);
159  if (sk != NULL) {
160  ret = ret && secp256k1_keypair_seckey_load(ctx, sk, keypair);
161  }
162  if (!ret) {
163  *pk = secp256k1_ge_const_g;
164  if (sk != NULL) {
165  *sk = secp256k1_scalar_one;
166  }
167  }
168  return ret;
169 }
170 
171 int secp256k1_keypair_create(const secp256k1_context* ctx, secp256k1_keypair *keypair, const unsigned char *seckey32) {
172  secp256k1_scalar sk;
173  secp256k1_ge pk;
174  int ret = 0;
175  VERIFY_CHECK(ctx != NULL);
176  ARG_CHECK(keypair != NULL);
177  memset(keypair, 0, sizeof(*keypair));
179  ARG_CHECK(seckey32 != NULL);
180 
181  ret = secp256k1_ec_pubkey_create_helper(&ctx->ecmult_gen_ctx, &sk, &pk, seckey32);
182  secp256k1_keypair_save(keypair, &sk, &pk);
183  secp256k1_memczero(keypair, sizeof(*keypair), !ret);
184 
186  return ret;
187 }
188 
189 int secp256k1_keypair_sec(const secp256k1_context* ctx, unsigned char *seckey, const secp256k1_keypair *keypair) {
190  VERIFY_CHECK(ctx != NULL);
191  ARG_CHECK(seckey != NULL);
192  memset(seckey, 0, 32);
193  ARG_CHECK(keypair != NULL);
194 
195  memcpy(seckey, &keypair->data[0], 32);
196  return 1;
197 }
198 
200  VERIFY_CHECK(ctx != NULL);
201  ARG_CHECK(pubkey != NULL);
202  memset(pubkey, 0, sizeof(*pubkey));
203  ARG_CHECK(keypair != NULL);
204 
205  memcpy(pubkey->data, &keypair->data[32], sizeof(*pubkey));
206  return 1;
207 }
208 
209 int secp256k1_keypair_xonly_pub(const secp256k1_context* ctx, secp256k1_xonly_pubkey *pubkey, int *pk_parity, const secp256k1_keypair *keypair) {
210  secp256k1_ge pk;
211  int tmp;
212 
213  VERIFY_CHECK(ctx != NULL);
214  ARG_CHECK(pubkey != NULL);
215  memset(pubkey, 0, sizeof(*pubkey));
216  ARG_CHECK(keypair != NULL);
217 
218  if (!secp256k1_keypair_load(ctx, NULL, &pk, keypair)) {
219  return 0;
220  }
222  if (pk_parity != NULL) {
223  *pk_parity = tmp;
224  }
225  secp256k1_xonly_pubkey_save(pubkey, &pk);
226 
227  return 1;
228 }
229 
230 int secp256k1_keypair_xonly_tweak_add(const secp256k1_context* ctx, secp256k1_keypair *keypair, const unsigned char *tweak32) {
231  secp256k1_ge pk;
232  secp256k1_scalar sk;
233  int y_parity;
234  int ret;
235 
236  VERIFY_CHECK(ctx != NULL);
238  ARG_CHECK(keypair != NULL);
239  ARG_CHECK(tweak32 != NULL);
240 
241  ret = secp256k1_keypair_load(ctx, &sk, &pk, keypair);
242  memset(keypair, 0, sizeof(*keypair));
243 
244  y_parity = secp256k1_extrakeys_ge_even_y(&pk);
245  if (y_parity == 1) {
246  secp256k1_scalar_negate(&sk, &sk);
247  }
248 
249  ret &= secp256k1_ec_seckey_tweak_add_helper(&sk, tweak32);
250  ret &= secp256k1_ec_pubkey_tweak_add_helper(&ctx->ecmult_ctx, &pk, tweak32);
251 
252  secp256k1_declassify(ctx, &ret, sizeof(ret));
253  if (ret) {
254  secp256k1_keypair_save(keypair, &sk, &pk);
255  }
256 
258  return ret;
259 }
260 
261 #endif
secp256k1_ecmult_context_is_built
static int secp256k1_ecmult_context_is_built(const secp256k1_ecmult_context *ctx)
secp256k1_scalar_negate
static void secp256k1_scalar_negate(secp256k1_scalar *r, const secp256k1_scalar *a)
Compute the complement of a scalar (modulo the group order).
secp256k1_keypair_load
static int secp256k1_keypair_load(const secp256k1_context *ctx, secp256k1_scalar *sk, secp256k1_ge *pk, const secp256k1_keypair *keypair)
Definition: main_impl.h:151
VERIFY_CHECK
#define VERIFY_CHECK(cond)
Definition: util.h:68
secp256k1_ge_is_in_correct_subgroup
static int secp256k1_ge_is_in_correct_subgroup(const secp256k1_ge *ge)
Determine if a point (which is assumed to be on the curve) is in the correct (sub)group of the curve.
secp256k1_ge::y
secp256k1_fe y
Definition: group.h:19
secp256k1_scalar_get_b32
static void secp256k1_scalar_get_b32(unsigned char *bin, const secp256k1_scalar *a)
Convert a scalar to a byte array.
secp256k1_pubkey_load
static int secp256k1_pubkey_load(const secp256k1_context *ctx, secp256k1_ge *ge, const secp256k1_pubkey *pubkey)
Definition: secp256k1.c:245
secp256k1_context_struct
Definition: secp256k1.c:69
secp256k1_declassify
static SECP256K1_INLINE void secp256k1_declassify(const secp256k1_context *ctx, const void *p, size_t len)
Definition: secp256k1.c:235
secp256k1_fe_normalize_var
static void secp256k1_fe_normalize_var(secp256k1_fe *r)
Normalize a field element, without constant-time guarantee.
secp256k1_fe_set_b32
static int secp256k1_fe_set_b32(secp256k1_fe *r, const unsigned char *a)
Set a field element equal to 32-byte big endian value.
secp256k1_xonly_pubkey_serialize
int secp256k1_xonly_pubkey_serialize(const secp256k1_context *ctx, unsigned char *output32, const secp256k1_xonly_pubkey *pubkey)
Serialize an xonly_pubkey object into a 32-byte sequence.
Definition: main_impl.h:43
secp256k1_memcmp_var
static SECP256K1_INLINE int secp256k1_memcmp_var(const void *s1, const void *s2, size_t n)
Semantics like memcmp.
Definition: util.h:224
secp256k1_ec_pubkey_tweak_add_helper
static int secp256k1_ec_pubkey_tweak_add_helper(const secp256k1_ecmult_context *ecmult_ctx, secp256k1_ge *p, const unsigned char *tweak32)
Definition: secp256k1.c:656
ARG_CHECK
#define ARG_CHECK(cond)
Definition: secp256k1.c:28
secp256k1_keypair_create
int secp256k1_keypair_create(const secp256k1_context *ctx, secp256k1_keypair *keypair, const unsigned char *seckey32)
Compute the keypair for a secret key.
Definition: main_impl.h:171
secp256k1_xonly_pubkey_parse
int secp256k1_xonly_pubkey_parse(const secp256k1_context *ctx, secp256k1_xonly_pubkey *pubkey, const unsigned char *input32)
Parse a 32-byte sequence into a xonly_pubkey object.
Definition: main_impl.h:21
secp256k1_xonly_pubkey_from_pubkey
int secp256k1_xonly_pubkey_from_pubkey(const secp256k1_context *ctx, secp256k1_xonly_pubkey *xonly_pubkey, int *pk_parity, const secp256k1_pubkey *pubkey)
Converts a secp256k1_pubkey into a secp256k1_xonly_pubkey.
Definition: main_impl.h:72
secp256k1_pubkey_save
static void secp256k1_pubkey_save(secp256k1_pubkey *pubkey, secp256k1_ge *ge)
Definition: secp256k1.c:264
secp256k1_keypair
Opaque data structure that holds a keypair consisting of a secret and a public key.
Definition: secp256k1_extrakeys.h:33
secp256k1_scalar
A scalar modulo the group order of the secp256k1 curve.
Definition: scalar_4x64.h:13
secp256k1_ge_const_g
static const secp256k1_ge secp256k1_ge_const_g
Generator for secp256k1, value 'g' defined in "Standards for Efficient Cryptography" (SEC2) 2....
Definition: group_impl.h:52
secp256k1.h
secp256k1_fe_is_odd
static int secp256k1_fe_is_odd(const secp256k1_fe *a)
Check the "oddness" of a field element.
secp256k1_keypair_sec
int secp256k1_keypair_sec(const secp256k1_context *ctx, unsigned char *seckey, const secp256k1_keypair *keypair)
Get the secret key from a keypair.
Definition: main_impl.h:189
secp256k1_fe
Definition: field_10x26.h:12
secp256k1_context_struct::ecmult_gen_ctx
secp256k1_ecmult_gen_context ecmult_gen_ctx
Definition: secp256k1.c:71
secp256k1_keypair_seckey_load
static int secp256k1_keypair_seckey_load(const secp256k1_context *ctx, secp256k1_scalar *sk, const secp256k1_keypair *keypair)
Definition: main_impl.h:137
secp256k1_context_struct::ecmult_ctx
secp256k1_ecmult_context ecmult_ctx
Definition: secp256k1.c:70
secp256k1_xonly_pubkey_load
static SECP256K1_INLINE int secp256k1_xonly_pubkey_load(const secp256k1_context *ctx, secp256k1_ge *ge, const secp256k1_xonly_pubkey *pubkey)
Definition: main_impl.h:13
secp256k1_keypair_save
static void secp256k1_keypair_save(secp256k1_keypair *keypair, const secp256k1_scalar *sk, secp256k1_ge *pk)
Definition: main_impl.h:131
secp256k1_fe_get_b32
static void secp256k1_fe_get_b32(unsigned char *r, const secp256k1_fe *a)
Convert a field element to a 32-byte big endian value.
secp256k1_keypair_pub
int secp256k1_keypair_pub(const secp256k1_context *ctx, secp256k1_pubkey *pubkey, const secp256k1_keypair *keypair)
Get the public key from a keypair.
Definition: main_impl.h:199
secp256k1_ecmult_gen_context_is_built
static int secp256k1_ecmult_gen_context_is_built(const secp256k1_ecmult_gen_context *ctx)
secp256k1_xonly_pubkey_save
static SECP256K1_INLINE void secp256k1_xonly_pubkey_save(secp256k1_xonly_pubkey *pubkey, secp256k1_ge *ge)
Definition: main_impl.h:17
secp256k1_scalar_one
static const secp256k1_scalar secp256k1_scalar_one
Definition: scalar_impl.h:31
secp256k1_memczero
static SECP256K1_INLINE void secp256k1_memczero(void *s, size_t len, int flag)
Definition: util.h:205
secp256k1_keypair_xonly_pub
int secp256k1_keypair_xonly_pub(const secp256k1_context *ctx, secp256k1_xonly_pubkey *pubkey, int *pk_parity, const secp256k1_keypair *keypair)
Get the x-only public key from a keypair.
Definition: main_impl.h:209
secp256k1_xonly_pubkey_tweak_add_check
int secp256k1_xonly_pubkey_tweak_add_check(const secp256k1_context *ctx, const unsigned char *tweaked_pubkey32, int tweaked_pk_parity, const secp256k1_xonly_pubkey *internal_pubkey, const unsigned char *tweak32)
Checks that a tweaked pubkey is the result of calling secp256k1_xonly_pubkey_tweak_add with internal_...
Definition: main_impl.h:109
secp256k1_scalar_clear
static void secp256k1_scalar_clear(secp256k1_scalar *r)
Clear a scalar to prevent the leak of sensitive data.
secp256k1_extrakeys_ge_even_y
static int secp256k1_extrakeys_ge_even_y(secp256k1_ge *r)
Keeps a group element as is if it has an even Y and otherwise negates it.
Definition: main_impl.h:61
secp256k1_keypair_xonly_tweak_add
int secp256k1_keypair_xonly_tweak_add(const secp256k1_context *ctx, secp256k1_keypair *keypair, const unsigned char *tweak32)
Tweak a keypair by adding tweak32 to the secret key and updating the public key accordingly.
Definition: main_impl.h:230
secp256k1_ge_set_xo_var
static int secp256k1_ge_set_xo_var(secp256k1_ge *r, const secp256k1_fe *x, int odd)
Set a group element (affine) equal to the point with the given X coordinate, and given oddness for Y.
secp256k1_fe_negate
static void secp256k1_fe_negate(secp256k1_fe *r, const secp256k1_fe *a, int m)
Set a field element equal to the additive inverse of another.
secp256k1_scalar_set_b32_seckey
static int secp256k1_scalar_set_b32_seckey(secp256k1_scalar *r, const unsigned char *bin)
Set a scalar from a big endian byte array and returns 1 if it is a valid seckey and 0 otherwise.
secp256k1_keypair::data
unsigned char data[96]
Definition: secp256k1_extrakeys.h:34
SECP256K1_INLINE
#define SECP256K1_INLINE
Definition: secp256k1.h:124
secp256k1_ge::x
secp256k1_fe x
Definition: group.h:18
secp256k1_ge_is_infinity
static int secp256k1_ge_is_infinity(const secp256k1_ge *a)
Check whether a group element is the point at infinity.
secp256k1_extrakeys.h
secp256k1_pubkey::data
unsigned char data[64]
Definition: secp256k1.h:68
secp256k1_ec_seckey_tweak_add_helper
static int secp256k1_ec_seckey_tweak_add_helper(secp256k1_scalar *sec, const unsigned char *tweak32)
Definition: secp256k1.c:625
secp256k1_pubkey
Opaque data structure that holds a parsed and valid public key.
Definition: secp256k1.h:67
secp256k1_ge
A group element of the secp256k1 curve, in affine coordinates.
Definition: group.h:13
secp256k1_xonly_pubkey_tweak_add
int secp256k1_xonly_pubkey_tweak_add(const secp256k1_context *ctx, secp256k1_pubkey *output_pubkey, const secp256k1_xonly_pubkey *internal_pubkey, const unsigned char *tweak32)
Tweak an x-only public key by adding the generator multiplied with tweak32 to it.
Definition: main_impl.h:91
ctx
static secp256k1_context * ctx
Definition: tests.c:42
secp256k1_xonly_pubkey
Opaque data structure that holds a parsed and valid "x-only" public key.
Definition: secp256k1_extrakeys.h:22
secp256k1_ec_pubkey_create_helper
static int secp256k1_ec_pubkey_create_helper(const secp256k1_ecmult_gen_context *ecmult_gen_ctx, secp256k1_scalar *seckey_scalar, secp256k1_ge *p, const unsigned char *seckey)
Definition: secp256k1.c:560