elements/src/pubkey.cpp

136 lines
4.6 KiB
C++
Raw Normal View History

// Copyright (c) 2009-2014 The Bitcoin developers
// Distributed under the MIT software license, see the accompanying
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
#include "pubkey.h"
#include <secp256k1.h>
2015-08-05 23:15:10 +02:00
#include <secp256k1_rangeproof.h>
#include <secp256k1_schnorr.h>
2016-02-02 21:34:46 +01:00
#include <secp256k1_recovery.h>
2015-05-14 18:02:48 -07:00
2016-02-02 21:34:46 +01:00
secp256k1_context* secp256k1_bitcoin_verify_context = NULL;
bool CPubKey::Verify(const uint256 &hash, const std::vector<unsigned char>& vchSig) const {
if (!IsValid())
return false;
if (vchSig.size() != 64)
return false;
2016-02-02 21:34:46 +01:00
secp256k1_pubkey pubkey;
if (!secp256k1_ec_pubkey_parse(secp256k1_bitcoin_verify_context, &pubkey, begin(), size()))
2015-08-05 23:15:10 +02:00
return false;
2016-02-02 21:34:46 +01:00
if (secp256k1_schnorr_verify(secp256k1_bitcoin_verify_context, &vchSig[0], (const unsigned char*)&hash, &pubkey) != 1)
return false;
return true;
}
bool CPubKey::RecoverCompact(const uint256 &hash, const std::vector<unsigned char>& vchSig) {
if (vchSig.size() != 65)
return false;
int recid = (vchSig[0] - 27) & 3;
bool fComp = ((vchSig[0] - 27) & 4) != 0;
2016-02-02 21:34:46 +01:00
secp256k1_pubkey pubkey;
secp256k1_ecdsa_recoverable_signature sig;
if (!secp256k1_ecdsa_recoverable_signature_parse_compact(secp256k1_bitcoin_verify_context, &sig, &vchSig[1], recid)) {
2015-08-05 23:15:10 +02:00
return false;
}
2016-02-02 21:34:46 +01:00
if (!secp256k1_ecdsa_recover(secp256k1_bitcoin_verify_context, &pubkey, &sig, hash.begin())) {
return false;
2015-08-05 23:15:10 +02:00
}
unsigned char pub[65];
2016-02-02 21:34:46 +01:00
size_t publen = 65;
secp256k1_ec_pubkey_serialize(secp256k1_bitcoin_verify_context, pub, &publen, &pubkey, fComp ? SECP256K1_EC_COMPRESSED : SECP256K1_EC_UNCOMPRESSED);
2015-08-05 23:15:10 +02:00
Set(pub, pub + publen);
return true;
}
bool CPubKey::IsFullyValid() const {
if (!IsValid())
return false;
2016-02-02 21:34:46 +01:00
secp256k1_pubkey pubkey;
if (!secp256k1_ec_pubkey_parse(secp256k1_bitcoin_verify_context, &pubkey, begin(), size()))
return false;
return true;
}
bool CPubKey::Decompress() {
if (!IsValid())
return false;
2016-02-02 21:34:46 +01:00
secp256k1_pubkey pubkey;
if (!secp256k1_ec_pubkey_parse(secp256k1_bitcoin_verify_context, &pubkey, &(*this)[0], size())) {
2015-08-05 23:15:10 +02:00
return false;
}
unsigned char pub[65];
2016-02-02 21:34:46 +01:00
size_t publen = 0;
secp256k1_ec_pubkey_serialize(secp256k1_bitcoin_verify_context, pub, &publen, &pubkey, SECP256K1_EC_UNCOMPRESSED);
2015-08-05 23:15:10 +02:00
Set(pub, pub + publen);
return true;
}
bool CPubKey::Derive(CPubKey& pubkeyChild, unsigned char ccChild[32], unsigned int nChild, const unsigned char cc[32]) const {
assert(IsValid());
assert((nChild >> 31) == 0);
assert(begin() + 33 == end());
unsigned char out[64];
BIP32Hash(cc, nChild, *begin(), begin()+1, out);
memcpy(ccChild, out+32, 32);
2016-02-02 21:34:46 +01:00
secp256k1_pubkey pubkey;
if (!secp256k1_ec_pubkey_parse(secp256k1_bitcoin_verify_context, &pubkey, &(*this)[0], size())) {
2015-08-05 23:15:10 +02:00
return false;
}
2016-02-02 21:34:46 +01:00
if (!secp256k1_ec_pubkey_tweak_add(secp256k1_bitcoin_verify_context, &pubkey, out)) {
2015-08-05 23:15:10 +02:00
return false;
}
unsigned char pub[33];
2016-02-02 21:34:46 +01:00
size_t publen = 0;
secp256k1_ec_pubkey_serialize(secp256k1_bitcoin_verify_context, pub, &publen, &pubkey, SECP256K1_EC_COMPRESSED);
2015-08-05 23:15:10 +02:00
pubkeyChild.Set(pub, pub + publen);
return true;
}
void CExtPubKey::Encode(unsigned char code[74]) const {
code[0] = nDepth;
memcpy(code+1, vchFingerprint, 4);
code[5] = (nChild >> 24) & 0xFF; code[6] = (nChild >> 16) & 0xFF;
code[7] = (nChild >> 8) & 0xFF; code[8] = (nChild >> 0) & 0xFF;
memcpy(code+9, vchChainCode, 32);
assert(pubkey.size() == 33);
memcpy(code+41, pubkey.begin(), 33);
}
void CExtPubKey::Decode(const unsigned char code[74]) {
nDepth = code[0];
memcpy(vchFingerprint, code+1, 4);
nChild = (code[5] << 24) | (code[6] << 16) | (code[7] << 8) | code[8];
memcpy(vchChainCode, code+9, 32);
pubkey.Set(code+41, code+74);
}
bool CExtPubKey::Derive(CExtPubKey &out, unsigned int nChild) const {
out.nDepth = nDepth + 1;
CKeyID id = pubkey.GetID();
memcpy(&out.vchFingerprint[0], &id, 4);
out.nChild = nChild;
return pubkey.Derive(out.pubkey, out.vchChainCode, nChild, vchChainCode);
}
2015-05-14 18:02:48 -07:00
void ECC_Verify_Start() {
2016-02-02 21:34:46 +01:00
assert(secp256k1_bitcoin_verify_context == NULL);
2015-05-14 18:02:48 -07:00
2016-02-02 21:34:46 +01:00
secp256k1_context *ctx = secp256k1_context_create(SECP256K1_CONTEXT_VERIFY);
2015-05-14 18:02:48 -07:00
assert(ctx != NULL);
2015-08-05 23:15:10 +02:00
secp256k1_pedersen_context_initialize(ctx);
secp256k1_rangeproof_context_initialize(ctx);
2015-05-14 18:02:48 -07:00
2016-02-02 21:34:46 +01:00
secp256k1_bitcoin_verify_context = ctx;
2015-05-14 18:02:48 -07:00
}
void ECC_Verify_Stop() {
2016-02-02 21:34:46 +01:00
secp256k1_context *ctx = secp256k1_bitcoin_verify_context;
secp256k1_bitcoin_verify_context = NULL;
2015-05-14 18:02:48 -07:00
if (ctx) {
secp256k1_context_destroy(ctx);
}
}