mirror of
https://github.com/ElementsProject/elements.git
synced 2026-08-13 12:33:42 +02:00
53ad841 Add explanation about how BIP32 unhardened derivation can be used to simplify whitelisting 71c5fe0 Add comment to explain effect of max_n_iterations in surjectionproof_init 85fd42f add unit test for generator and pedersen commitment roundtripping 2ccf885 rangeproof: fix serialization of pedersen commintments 60c173b rangeproof: verify correctness of pedersen commitments when parsing 32d7526 generator: verify correctness of point when parsing ae14e8a rangeproof: check that points deserialize correctly when verifying rangeproof 44fe43d rangeproof: add fixed vector test case e065d7d Expose generator in shared library fb1ba32 fix spelling in documentation fb75faa Test for rejection of trailing bytes in range proofs 9b2cf17 Test for rejection of trailing bytes in surjection proofs a3a1800 Reject surjection proofs with trailing garbage 0c77ae9 Minor bugfix. Wrong length due to NUL character. b1f31bc Add whitelisting benchmark 52a9f8f add whitelist_impl.h to include for dist a707865 generator: add API tests ec1ef04 generator: remove unnecessary ARG_CHECK from generate() b0e9aa8 Fix generator makefile 526c654 Fix pedersen_blind_generator_blind_sum return value documentation b51886e Add n_keys argument to whitelist_verify 37c57de Fix checks of whitelist serialize/parse arguments 9b8a9d9 whitelist: fix serialize/parse API to take serialized length 7f17515 Fix include/secp256k1_rangeproof.h function argument documentation. 0d81702 rangeproof: add API tests 417bb06 surjectionproof: rename unit test functions to be more consistent with other modules 1e2d5c1 surjectionproof: add API unit tests 7878a29 surjectionproof: tests_impl.h s/assert/CHECK/g e609591 rangeproof: fix memory leak in unit tests 0c17f79 add surjection proof module c174f0c Implement ring-signature based whitelist delegation scheme a2bc660 rangeproof: several API changes 21bfb3c Expose generator in pedersen/rangeproof API f4620de Constant-time generator module d46fc3c rangeproof: expose sidechannel message field in the signing API cf40b1b [RANGEPROOF BREAK] Use quadratic residue for tie break and modularity cleanup 6d28767 Get rid of precomputed H tables (Pieter Wuille) ae1e576 Pedersen commitments, borromean ring signatures, and ZK range proofs. efc61dc Add 64-bit integer utilities e34ceb3 Merge #557: Eliminate scratch memory used when generating contexts b3bf5f9 ecmult_impl: expand comment to explain how effective affine interacts with everything efa783f Store z-ratios in the 'x' coord they'll recover ffd3b34 add `secp256k1_ge_set_all_gej_var` test which deals with many infinite points 84740ac ecmult_impl: save one fe_inv_var 4704527 ecmult_impl: eliminate scratch memory used when generating context 7f7a2ed ecmult_gen_impl: eliminate scratch memory used when generating context 314a61d Merge #553: add static context object which has no capabilities 1086fda Merge #354: [ECDH API change] Support custom hash function 40fde61 prevent attempts to modify `secp256k1_context_no_precomp` ed7c084 add static context object which has no capabilities 1e6f1f5 Merge #529: fix tests.c in the count == 0 case c8fbc3c [ECDH API change] Allow pass arbitrary data to hash function b00be65 [ECDH API change] Support custom hash function 95e99f1 fix tests.c in the count == 0 case 452d8e4 Merge #523: scratch: add stack frame support 6fe5043 scratch: add stack frame support 9bc2e26 Merge #522: parameterize ecmult_const over input size 7c1b91b parameterize ecmult_const over input size dbc3ddd Merge #513: Increase sparsity of pippenger fixed window naf representation fb9271d Merge #510: add a couple missing `const`s to ecmult_pippenger_wnaf cd5f602 Merge #515: Fix typo 09146ae Merge #512: secp256k1_ec_privkey_negate - fix documentation ec0a7b3 Don't touch leading zeros in wnaf_fixed. 9e36d1b Fix bug in wnaf_fixed where the wnaf array is not completely zeroed when given a 0 scalar. 96f68a0 Don't invert scalar in wnaf_fixed when it is even because a caller might intentionally give a scalar with many leading zeros. 9b7c47a Fix typo 6dbb007 Increase sparsity of pippenger fixed window naf representation 1646ace secp256k1_ec_privkey_negate - fix documentation 9b3ff03 add a couple missing `const`s to ecmult_pippenger_wnaf cd329db Merge #460: [build] Update ax_jni_include_dir.m4 macro 7f9c1a1 Merge #498: tests: Avoid calling fclose(...) with an invalid argument f99aa8d Merge #499: tests: Make sure we get the requested number of bytes from /dev/urandom b549d3d Merge #472: [build] Set --enable-jni to no by default instead of auto. d333521 Merge #494: Support OpenSSL versions >= 1.1 for ENABLE_OPENSSL_TESTS 2ef8ea5 Merge #495: Add bench_ecmult to .gitignore 82a96e4 tests: Make sure we get the requested number of bytes from /dev/urandom 5aae5b5 Avoid calling fclose(...) with an invalid argument cb32940 Add bench_ecmult to .gitignore 31abd3a Support OpenSSL versions >= 1.1 for ENABLE_OPENSSL_TESTS c95f6f1 Merge #487: fix tests typo, s/changed/unchanged fb46c83 Merge #463: Reduce usage of hardcoded size constants 02f5001 Merge #490: Disambiguate bench functions and types 1f46d60 Disambiguate bench functions and types f54c6c5 Merge #480: Enable benchmark building by default c77fc08 Merge #486: Add pippenger_wnaf for multi-multiplication d2f9c6b Use more precise pippenger bucket windows 4c950bb Save some additions per window in _pippenger_wnaf a58f543 Add flags for choosing algorithm in ecmult_multi benchmark 36b22c9 Use scratch space dependent batching in ecmult_multi 355a38f Add pippenger_wnaf ecmult_multi bc65aa7 Add bench_ecmult dba5471 Add ecmult_multi tests 8c1c831 Generalize Strauss to support multiple points 548de42 add resizeable scratch space API 0e96cdc fix typo, s/changed/unchanged c7680e5 Reduce usage of hardcoded size constants 6ad5cdb Merge #479: Get rid of reserved _t in type names 7a78f60 Print whether we're building benchmarks 4afec9f Build benchmarks by default d1dc9df Get rid of reserved _t in type names 57752d2 [build] Set --enable-jni to no by default instead of auto. e7daa9b [build] Tweak JNI macro to warn instead of error for JNI not found. 5b22977 [build] Update ax_jni_include_dir.m4 macro to deal with recent versions of macOS git-subtree-dir: src/secp256k1 git-subtree-split: 53ad841cafa3bcb94b65409aec91fd7043533cf7
232 lines
6.5 KiB
C++
232 lines
6.5 KiB
C++
// Copyright (c) 2009-2010 Satoshi Nakamoto
|
|
// Copyright (c) 2009-2018 The Bitcoin Core developers
|
|
// Distributed under the MIT software license, see the accompanying
|
|
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
|
|
|
|
#ifndef BITCOIN_HASH_H
|
|
#define BITCOIN_HASH_H
|
|
|
|
#include <crypto/ripemd160.h>
|
|
#include <crypto/sha256.h>
|
|
#include <prevector.h>
|
|
#include <serialize.h>
|
|
#include <uint256.h>
|
|
#include <version.h>
|
|
|
|
#include <vector>
|
|
|
|
typedef uint256 ChainCode;
|
|
|
|
/** A hasher class for Bitcoin's 256-bit hash (double SHA-256). */
|
|
class CHash256 {
|
|
private:
|
|
CSHA256 sha;
|
|
public:
|
|
static const size_t OUTPUT_SIZE = CSHA256::OUTPUT_SIZE;
|
|
|
|
void Finalize(unsigned char hash[OUTPUT_SIZE]) {
|
|
unsigned char buf[CSHA256::OUTPUT_SIZE];
|
|
sha.Finalize(buf);
|
|
sha.Reset().Write(buf, CSHA256::OUTPUT_SIZE).Finalize(hash);
|
|
}
|
|
|
|
CHash256& Write(const unsigned char *data, size_t len) {
|
|
sha.Write(data, len);
|
|
return *this;
|
|
}
|
|
|
|
CHash256& Reset() {
|
|
sha.Reset();
|
|
return *this;
|
|
}
|
|
};
|
|
|
|
/** A hasher class for Bitcoin's 160-bit hash (SHA-256 + RIPEMD-160). */
|
|
class CHash160 {
|
|
private:
|
|
CSHA256 sha;
|
|
public:
|
|
static const size_t OUTPUT_SIZE = CRIPEMD160::OUTPUT_SIZE;
|
|
|
|
void Finalize(unsigned char hash[OUTPUT_SIZE]) {
|
|
unsigned char buf[CSHA256::OUTPUT_SIZE];
|
|
sha.Finalize(buf);
|
|
CRIPEMD160().Write(buf, CSHA256::OUTPUT_SIZE).Finalize(hash);
|
|
}
|
|
|
|
CHash160& Write(const unsigned char *data, size_t len) {
|
|
sha.Write(data, len);
|
|
return *this;
|
|
}
|
|
|
|
CHash160& Reset() {
|
|
sha.Reset();
|
|
return *this;
|
|
}
|
|
};
|
|
|
|
/** Compute the 256-bit hash of an object. */
|
|
template<typename T1>
|
|
inline uint256 Hash(const T1 pbegin, const T1 pend)
|
|
{
|
|
static const unsigned char pblank[1] = {};
|
|
uint256 result;
|
|
CHash256().Write(pbegin == pend ? pblank : (const unsigned char*)&pbegin[0], (pend - pbegin) * sizeof(pbegin[0]))
|
|
.Finalize((unsigned char*)&result);
|
|
return result;
|
|
}
|
|
|
|
/** Compute the 256-bit hash of the concatenation of two objects. */
|
|
template<typename T1, typename T2>
|
|
inline uint256 Hash(const T1 p1begin, const T1 p1end,
|
|
const T2 p2begin, const T2 p2end) {
|
|
static const unsigned char pblank[1] = {};
|
|
uint256 result;
|
|
CHash256().Write(p1begin == p1end ? pblank : (const unsigned char*)&p1begin[0], (p1end - p1begin) * sizeof(p1begin[0]))
|
|
.Write(p2begin == p2end ? pblank : (const unsigned char*)&p2begin[0], (p2end - p2begin) * sizeof(p2begin[0]))
|
|
.Finalize((unsigned char*)&result);
|
|
return result;
|
|
}
|
|
|
|
/** Compute the 160-bit hash an object. */
|
|
template<typename T1>
|
|
inline uint160 Hash160(const T1 pbegin, const T1 pend)
|
|
{
|
|
static unsigned char pblank[1] = {};
|
|
uint160 result;
|
|
CHash160().Write(pbegin == pend ? pblank : (const unsigned char*)&pbegin[0], (pend - pbegin) * sizeof(pbegin[0]))
|
|
.Finalize((unsigned char*)&result);
|
|
return result;
|
|
}
|
|
|
|
/** Compute the 160-bit hash of a vector. */
|
|
inline uint160 Hash160(const std::vector<unsigned char>& vch)
|
|
{
|
|
return Hash160(vch.begin(), vch.end());
|
|
}
|
|
|
|
/** Compute the 160-bit hash of a vector. */
|
|
template<unsigned int N>
|
|
inline uint160 Hash160(const prevector<N, unsigned char>& vch)
|
|
{
|
|
return Hash160(vch.begin(), vch.end());
|
|
}
|
|
|
|
/** A writer stream (for serialization) that computes a 256-bit hash. */
|
|
class CHashWriter
|
|
{
|
|
private:
|
|
CHash256 ctx;
|
|
|
|
const int nType;
|
|
const int nVersion;
|
|
public:
|
|
|
|
CHashWriter(int nTypeIn, int nVersionIn) : nType(nTypeIn), nVersion(nVersionIn) {}
|
|
|
|
int GetType() const { return nType; }
|
|
int GetVersion() const { return nVersion; }
|
|
|
|
void write(const char *pch, size_t size) {
|
|
ctx.Write((const unsigned char*)pch, size);
|
|
}
|
|
|
|
// invalidates the object
|
|
uint256 GetHash() {
|
|
uint256 result;
|
|
ctx.Finalize((unsigned char*)&result);
|
|
return result;
|
|
}
|
|
|
|
template<typename T>
|
|
CHashWriter& operator<<(const T& obj) {
|
|
// Serialize to this stream
|
|
::Serialize(*this, obj);
|
|
return (*this);
|
|
}
|
|
};
|
|
|
|
/** Reads data from an underlying stream, while hashing the read data. */
|
|
template<typename Source>
|
|
class CHashVerifier : public CHashWriter
|
|
{
|
|
private:
|
|
Source* source;
|
|
|
|
public:
|
|
explicit CHashVerifier(Source* source_) : CHashWriter(source_->GetType(), source_->GetVersion()), source(source_) {}
|
|
|
|
void read(char* pch, size_t nSize)
|
|
{
|
|
source->read(pch, nSize);
|
|
this->write(pch, nSize);
|
|
}
|
|
|
|
void ignore(size_t nSize)
|
|
{
|
|
char data[1024];
|
|
while (nSize > 0) {
|
|
size_t now = std::min<size_t>(nSize, 1024);
|
|
read(data, now);
|
|
nSize -= now;
|
|
}
|
|
}
|
|
|
|
template<typename T>
|
|
CHashVerifier<Source>& operator>>(T&& obj)
|
|
{
|
|
// Unserialize from this stream
|
|
::Unserialize(*this, obj);
|
|
return (*this);
|
|
}
|
|
};
|
|
|
|
/** Compute the 256-bit hash of an object's serialization. */
|
|
template<typename T>
|
|
uint256 SerializeHash(const T& obj, int nType=SER_GETHASH, int nVersion=PROTOCOL_VERSION)
|
|
{
|
|
CHashWriter ss(nType, nVersion);
|
|
ss << obj;
|
|
return ss.GetHash();
|
|
}
|
|
|
|
unsigned int MurmurHash3(unsigned int nHashSeed, const std::vector<unsigned char>& vDataToHash);
|
|
|
|
void BIP32Hash(const ChainCode &chainCode, unsigned int nChild, unsigned char header, const unsigned char data[32], unsigned char output[64]);
|
|
|
|
/** SipHash-2-4 */
|
|
class CSipHasher
|
|
{
|
|
private:
|
|
uint64_t v[4];
|
|
uint64_t tmp;
|
|
int count;
|
|
|
|
public:
|
|
/** Construct a SipHash calculator initialized with 128-bit key (k0, k1) */
|
|
CSipHasher(uint64_t k0, uint64_t k1);
|
|
/** Hash a 64-bit integer worth of data
|
|
* It is treated as if this was the little-endian interpretation of 8 bytes.
|
|
* This function can only be used when a multiple of 8 bytes have been written so far.
|
|
*/
|
|
CSipHasher& Write(uint64_t data);
|
|
/** Hash arbitrary bytes. */
|
|
CSipHasher& Write(const unsigned char* data, size_t size);
|
|
/** Compute the 64-bit SipHash-2-4 of the data written so far. The object remains untouched. */
|
|
uint64_t Finalize() const;
|
|
};
|
|
|
|
/** Optimized SipHash-2-4 implementation for uint256.
|
|
*
|
|
* It is identical to:
|
|
* SipHasher(k0, k1)
|
|
* .Write(val.GetUint64(0))
|
|
* .Write(val.GetUint64(1))
|
|
* .Write(val.GetUint64(2))
|
|
* .Write(val.GetUint64(3))
|
|
* .Finalize()
|
|
*/
|
|
uint64_t SipHashUint256(uint64_t k0, uint64_t k1, const uint256& val);
|
|
uint64_t SipHashUint256Extra(uint64_t k0, uint64_t k1, const uint256& val, uint32_t extra);
|
|
|
|
#endif // BITCOIN_HASH_H
|