mirror of
https://github.com/ElementsProject/elements.git
synced 2026-08-19 13:27:35 +02:00
71ed475 Pedersen commitments, borromean ring signatures, and ZK range proofs. afd1379 Add 64-bit integer utilities 9d96e36 Merge pull request #280 432e1ce Merge pull request #283 14727fd Use correct name in gitignore 356b0e9 Actually test static precomputation in Travis ff3a5df Merge pull request #284 2587208 Merge pull request #212 a5a66c7 Add support for custom EC-Schnorr-SHA256 signatures d84a378 Merge pull request #252 72ae443 Improve perf. of cmov-based table lookup 92e53fc Implement endomorphism optimization for secp256k1_ecmult_const ed35d43 Make `secp256k1_scalar_add_bit` conditional; make `secp256k1_scalar_split_lambda_var` constant time 91c0ce9 Add benchmarks for ECDH and const-time multiplication 0739bbb Add ECDH module which works by hashing the output of ecmult_const 4401500 Add constant-time multiply `secp256k1_ecmult_const` for ECDH e4ce393 build: fix hard-coded usage of "gen_context" b8e39ac build: don't use BUILT_SOURCES for the static context header baa75da tests: add a couple tests ae4f0c6 Merge pull request #278 995c548 Introduce callback functions for dealing with errors. c333074 Merge pull request #282 18c329c Remove the internal secp256k1_ecdsa_sig_t type 74a2acd Add a secp256k1_ecdsa_signature_t type 23cfa91 Introduce secp256k1_pubkey_t type 4c63780 Merge pull request #269 3e6f1e2 Change rfc6979 implementation to be a generic PRNG ed5334a Update configure.ac to make it build on OpenBSD 1b68366 Merge pull request #274 a83bb48 Make ecmult static precomputation default 166b32f Merge pull request #276 c37812f Add gen_context src/ecmult_static_context.h to CLEANFILES to fix distclean. 125c15d Merge pull request #275 76f6769 Fix build with static ecmult altroot and make dist. 5133f78 Merge pull request #254 b0a60e6 Merge pull request #258 733c1e6 Add travis build to test the static context. fbecc38 Add ability to use a statically generated ecmult context. 4fb174d Merge pull request #263 4ab8990 Merge pull request #270 bdf0e0c Merge pull request #271 31d0c1f Merge pull request #273 eb2c8ff Add missing casts to SECP256K1_FE_CONST_INNER 55399c2 Further performance improvements to _ecmult_wnaf 99fd963 Add secp256k1_ec_pubkey_compress(), with test similar to the related decompress() function. 145cc6e Improve performance of _ecmult_wnaf 36b305a Verify the result of GMP modular inverse using non-GMP code 0cbc860 Merge pull request #266 06ff7fe Merge pull request #267 5a43124 Save 1 _fe_negate since s1 == -s2 a5d796e Update code comments 3f3964e Add specific VERIFY tests for _fe_cmov 7d054cd Refactor to save a _fe_negate b28d02a Refactor to remove a local var 55e7fc3 Perf. improvement in _gej_add_ge a0601cd Fix VERIFY calculations in _fe_cmov methods 17f7148 Merge pull request #261 7657420 Add tests for adding P+Q with P.x!=Q.x and P.y=-Q.y 8c5d5f7 tests: Add failing unit test for #257 (bad addition formula) 5de4c5d gej_add_ge: fix degenerate case when computing P + (-lambda)P bcf2fcf gej_add_ge: rearrange algebra e2a07c7 Fix compilation with C++ 873a453 Merge pull request #250 91eb0da Merge pull request #247 210ffed Use separate in and out pointers in `secp256k1_ec_pubkey_decompress` a1d5ae1 Tiny optimization 729badf Merge pull request #210 2d5a186 Apply effective-affine trick to precomp 4f9791a Effective affine addition in EC multiplication git-subtree-dir: src/secp256k1 git-subtree-split: 71ed475ea53ff4576b7344762584b752a824c60f
186 lines
9.4 KiB
C
186 lines
9.4 KiB
C
#ifndef _SECP256K1_RANGEPROOF_
|
|
# define _SECP256K1_RANGEPROOF_
|
|
|
|
# include "secp256k1.h"
|
|
|
|
# ifdef __cplusplus
|
|
extern "C" {
|
|
# endif
|
|
|
|
#include <stdint.h>
|
|
|
|
/** Initialize a context for usage with Pedersen commitments. */
|
|
int secp256k1_pedersen_context_initialize(secp256k1_context_t* ctx);
|
|
|
|
/** Generate a pedersen commitment.
|
|
* Returns 1: commitment successfully created.
|
|
* 0: error
|
|
* In: ctx: pointer to a context object, initialized for signing and Pedersen commitment (cannot be NULL)
|
|
* blind: pointer to a 32-byte blinding factor (cannot be NULL)
|
|
* value: unsigned 64-bit integer value to commit to.
|
|
* Out: commit: pointer to a 33-byte array for the commitment (cannot be NULL)
|
|
*
|
|
* Blinding factors can be generated and verified in the same way as secp256k1 private keys for ECDSA.
|
|
*/
|
|
SECP256K1_WARN_UNUSED_RESULT int secp256k1_pedersen_commit(
|
|
const secp256k1_context_t* ctx,
|
|
unsigned char *commit,
|
|
unsigned char *blind,
|
|
uint64_t value
|
|
) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3);
|
|
|
|
/** Computes the sum of multiple positive and negative blinding factors.
|
|
* Returns 1: sum successfully computed.
|
|
* 0: error
|
|
* In: ctx: pointer to a context object (cannot be NULL)
|
|
* blinds: pointer to pointers to 32-byte character arrays for blinding factors. (cannot be NULL)
|
|
* n: number of factors pointed to by blinds.
|
|
* nneg: how many of the initial factors should be treated with a positive sign.
|
|
* Out: blind_out: pointer to a 32-byte array for the sum (cannot be NULL)
|
|
*/
|
|
SECP256K1_WARN_UNUSED_RESULT int secp256k1_pedersen_blind_sum(
|
|
const secp256k1_context_t* ctx,
|
|
unsigned char *blind_out,
|
|
const unsigned char * const *blinds,
|
|
int n,
|
|
int npositive
|
|
) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3);
|
|
|
|
/** Verify a tally of pedersen commitments
|
|
* Returns 1: commitments successfully sum to zero.
|
|
* 0: Commitments do not sum to zero or other error.
|
|
* In: ctx: pointer to a context object, initialized for Pedersen commitment (cannot be NULL)
|
|
* commits: pointer to pointers to 33-byte character arrays for the commitments. (cannot be NULL if pcnt is non-zero)
|
|
* pcnt: number of commitments pointed to by commits.
|
|
* ncommits: pointer to pointers to 33-byte character arrays for negative commitments. (cannot be NULL if ncnt is non-zero)
|
|
* ncnt: number of commitments pointed to by ncommits.
|
|
* excess: signed 64bit amount to add to the total to bring it to zero, can be negative.
|
|
*
|
|
* This computes sum(commit[0..pcnt)) - sum(ncommit[0..ncnt)) - excess*H == 0.
|
|
*
|
|
* A pedersen commitment is xG + vH where G and H are generators for the secp256k1 group and x is a blinding factor,
|
|
* while v is the committed value. For a collection of commitments to sum to zero both their blinding factors and
|
|
* values must sum to zero.
|
|
*
|
|
*/
|
|
SECP256K1_WARN_UNUSED_RESULT int secp256k1_pedersen_verify_tally(
|
|
const secp256k1_context_t* ctx,
|
|
const unsigned char * const *commits,
|
|
int pcnt,
|
|
const unsigned char * const *ncommits,
|
|
int ncnt,
|
|
int64_t excess
|
|
) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(4);
|
|
|
|
/** Initialize a context for usage with Pedersen commitments. */
|
|
int secp256k1_rangeproof_context_initialize(secp256k1_context_t* ctx);
|
|
|
|
/** Verify a proof that a committed value is within a range.
|
|
* Returns 1: Value is within the range [0..2^64), the specifically proven range is in the min/max value outputs.
|
|
* 0: Proof failed or other error.
|
|
* In: ctx: pointer to a context object, initialized for range-proof and commitment (cannot be NULL)
|
|
* commit: the 33-byte commitment being proved. (cannot be NULL)
|
|
* proof: pointer to character array with the proof. (cannot be NULL)
|
|
* plen: length of proof in bytes.
|
|
* Out: min_value: pointer to a unsigned int64 which will be updated with the minimum value that commit could have. (cannot be NULL)
|
|
* max_value: pointer to a unsigned int64 which will be updated with the maximum value that commit could have. (cannot be NULL)
|
|
*/
|
|
SECP256K1_WARN_UNUSED_RESULT int secp256k1_rangeproof_verify(
|
|
const secp256k1_context_t* ctx,
|
|
uint64_t *min_value,
|
|
uint64_t *max_value,
|
|
const unsigned char *commit,
|
|
const unsigned char *proof,
|
|
int plen
|
|
) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3) SECP256K1_ARG_NONNULL(4) SECP256K1_ARG_NONNULL(5);
|
|
|
|
/** Verify a range proof proof and rewind the proof to recover information sent by its author.
|
|
* Returns 1: Value is within the range [0..2^64), the specifically proven range is in the min/max value outputs, and the value and blinding were recovered.
|
|
* 0: Proof failed, rewind failed, or other error.
|
|
* In: ctx: pointer to a context object, initialized for range-proof and Pedersen commitment (cannot be NULL)
|
|
* commit: the 33-byte commitment being proved. (cannot be NULL)
|
|
* proof: pointer to character array with the proof. (cannot be NULL)
|
|
* plen: length of proof in bytes.
|
|
* nonce: 32-byte secret nonce used by the prover (cannot be NULL)
|
|
* In/Out: blind_out: storage for the 32-byte blinding factor used for the commitment
|
|
* value_out: pointer to an unsigned int64 which has the exact value of the commitment.
|
|
* message_out: pointer to a 4096 byte character array to receive message data from the proof author.
|
|
* outlen: length of message data written to message_out.
|
|
* min_value: pointer to an unsigned int64 which will be updated with the minimum value that commit could have. (cannot be NULL)
|
|
* max_value: pointer to an unsigned int64 which will be updated with the maximum value that commit could have. (cannot be NULL)
|
|
*/
|
|
SECP256K1_WARN_UNUSED_RESULT int secp256k1_rangeproof_rewind(
|
|
const secp256k1_context_t* ctx,
|
|
unsigned char *blind_out,
|
|
uint64_t *value_out,
|
|
unsigned char *message_out,
|
|
int *outlen,
|
|
const unsigned char *nonce,
|
|
uint64_t *min_value,
|
|
uint64_t *max_value,
|
|
const unsigned char *commit,
|
|
const unsigned char *proof,
|
|
int plen
|
|
) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(6) SECP256K1_ARG_NONNULL(7) SECP256K1_ARG_NONNULL(8) SECP256K1_ARG_NONNULL(9) SECP256K1_ARG_NONNULL(10);
|
|
|
|
/** Author a proof that a committed value is within a range.
|
|
* Returns 1: Proof successfully created.
|
|
* 0: Error
|
|
* In: ctx: pointer to a context object, initialized for range-proof, signing, and Pedersen commitment (cannot be NULL)
|
|
* proof: pointer to array to receive the proof, can be up to 5134 bytes. (cannot be NULL)
|
|
* min_value: constructs a proof where the verifer can tell the minimum value is at least the specified amount.
|
|
* commit: 33-byte array with the commitment being proved.
|
|
* blind: 32-byte blinding factor used by commit.
|
|
* nonce: 32-byte secret nonce used to initialize the proof (value can be reverse-engineered out of the proof if this secret is known.)
|
|
* exp: Base-10 exponent. Digits below above will be made public, but the proof will be made smaller. Allowed range is -1 to 18.
|
|
* (-1 is a special case that makes the value public. 0 is the most private.)
|
|
* min_bits: Number of bits of the value to keep private. (0 = auto/minimal, - 64).
|
|
* value: Actual value of the commitment.
|
|
* In/out: plen: point to an integer with the size of the proof buffer and the size of the constructed proof.
|
|
*
|
|
* If min_value or exp is non-zero then the value must be on the range [0, 2^63) to prevent the proof range from spanning past 2^64.
|
|
*
|
|
* If exp is -1 the value is revealed by the proof (e.g. it proves that the proof is a blinding of a specific value, without revealing the blinding key.)
|
|
*
|
|
* This can randomly fail with probability around one in 2^100. If this happens, buy a lottery ticket and retry with a different nonce or blinding.
|
|
*
|
|
*/
|
|
SECP256K1_WARN_UNUSED_RESULT int secp256k1_rangeproof_sign(
|
|
const secp256k1_context_t* ctx,
|
|
unsigned char *proof,
|
|
int *plen,
|
|
uint64_t min_value,
|
|
const unsigned char *commit,
|
|
const unsigned char *blind,
|
|
const unsigned char *nonce,
|
|
int exp,
|
|
int min_bits,
|
|
uint64_t value
|
|
) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3) SECP256K1_ARG_NONNULL(5) SECP256K1_ARG_NONNULL(6) SECP256K1_ARG_NONNULL(7);
|
|
|
|
/** Extract some basic information from a range-proof.
|
|
* Returns 1: Information successfully extracted.
|
|
* 0: Decode failed.
|
|
* In: ctx: pointer to a context object
|
|
* proof: pointer to character array with the proof.
|
|
* plen: length of proof in bytes.
|
|
* Out: exp: Exponent used in the proof (-1 means the value isn't private).
|
|
* mantissa: Number of bits covered by the proof.
|
|
* min_value: pointer to an unsigned int64 which will be updated with the minimum value that commit could have. (cannot be NULL)
|
|
* max_value: pointer to an unsigned int64 which will be updated with the maximum value that commit could have. (cannot be NULL)
|
|
*/
|
|
SECP256K1_WARN_UNUSED_RESULT int secp256k1_rangeproof_info(
|
|
const secp256k1_context_t* ctx,
|
|
int *exp,
|
|
int *mantissa,
|
|
uint64_t *min_value,
|
|
uint64_t *max_value,
|
|
const unsigned char *proof,
|
|
int plen
|
|
) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3) SECP256K1_ARG_NONNULL(4) SECP256K1_ARG_NONNULL(5);
|
|
|
|
# ifdef __cplusplus
|
|
}
|
|
# endif
|
|
|
|
#endif
|