|
| 1 | +/*********************************************************************** |
| 2 | + * Copyright (c) 2013, 2014 Pieter Wuille * |
| 3 | + * Distributed under the MIT software license, see the accompanying * |
| 4 | + * file COPYING or https://www.opensource.org/licenses/mit-license.php.* |
| 5 | + ***********************************************************************/ |
| 6 | + |
| 7 | +#ifndef SECP256K1_ECKEY_IMPL_H |
| 8 | +#define SECP256K1_ECKEY_IMPL_H |
| 9 | + |
| 10 | +#include "eckey.h" |
| 11 | + |
| 12 | +#include "scalar.h" |
| 13 | +#include "field.h" |
| 14 | +#include "group.h" |
| 15 | +#if 0 |
| 16 | +#include "ecmult_gen.h" |
| 17 | + |
| 18 | +static int secp256k1_eckey_pubkey_parse(secp256k1_ge *elem, const unsigned char *pub, size_t size) { |
| 19 | + if (size == 33 && (pub[0] == SECP256K1_TAG_PUBKEY_EVEN || pub[0] == SECP256K1_TAG_PUBKEY_ODD)) { |
| 20 | + secp256k1_fe x; |
| 21 | + return secp256k1_fe_set_b32(&x, pub+1) && secp256k1_ge_set_xo_var(elem, &x, pub[0] == SECP256K1_TAG_PUBKEY_ODD); |
| 22 | + } else if (size == 65 && (pub[0] == SECP256K1_TAG_PUBKEY_UNCOMPRESSED || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_EVEN || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_ODD)) { |
| 23 | + secp256k1_fe x, y; |
| 24 | + if (!secp256k1_fe_set_b32(&x, pub+1) || !secp256k1_fe_set_b32(&y, pub+33)) { |
| 25 | + return 0; |
| 26 | + } |
| 27 | + secp256k1_ge_set_xy(elem, &x, &y); |
| 28 | + if ((pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_EVEN || pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_ODD) && |
| 29 | + secp256k1_fe_is_odd(&y) != (pub[0] == SECP256K1_TAG_PUBKEY_HYBRID_ODD)) { |
| 30 | + return 0; |
| 31 | + } |
| 32 | + return secp256k1_ge_is_valid_var(elem); |
| 33 | + } else { |
| 34 | + return 0; |
| 35 | + } |
| 36 | +} |
| 37 | + |
| 38 | +static int secp256k1_eckey_pubkey_serialize(secp256k1_ge *elem, unsigned char *pub, size_t *size, int compressed) { |
| 39 | + if (secp256k1_ge_is_infinity(elem)) { |
| 40 | + return 0; |
| 41 | + } |
| 42 | + secp256k1_fe_normalize_var(&elem->x); |
| 43 | + secp256k1_fe_normalize_var(&elem->y); |
| 44 | + secp256k1_fe_get_b32(&pub[1], &elem->x); |
| 45 | + if (compressed) { |
| 46 | + *size = 33; |
| 47 | + pub[0] = secp256k1_fe_is_odd(&elem->y) ? SECP256K1_TAG_PUBKEY_ODD : SECP256K1_TAG_PUBKEY_EVEN; |
| 48 | + } else { |
| 49 | + *size = 65; |
| 50 | + pub[0] = SECP256K1_TAG_PUBKEY_UNCOMPRESSED; |
| 51 | + secp256k1_fe_get_b32(&pub[33], &elem->y); |
| 52 | + } |
| 53 | + return 1; |
| 54 | +} |
| 55 | + |
| 56 | +static int secp256k1_eckey_privkey_tweak_add(secp256k1_scalar *key, const secp256k1_scalar *tweak) { |
| 57 | + secp256k1_scalar_add(key, key, tweak); |
| 58 | + return !secp256k1_scalar_is_zero(key); |
| 59 | +} |
| 60 | +#endif |
| 61 | + |
| 62 | +static int secp256k1_eckey_pubkey_tweak_add(secp256k1_ge *key, const secp256k1_scalar *tweak) { |
| 63 | + secp256k1_gej pt; |
| 64 | + secp256k1_scalar one; |
| 65 | + secp256k1_gej_set_ge(&pt, key); |
| 66 | + secp256k1_scalar_set_int(&one, 1); |
| 67 | + secp256k1_ecmult(&pt, &pt, &one, tweak); |
| 68 | + |
| 69 | + if (secp256k1_gej_is_infinity(&pt)) { |
| 70 | + return 0; |
| 71 | + } |
| 72 | + secp256k1_ge_set_gej_var(key, &pt); |
| 73 | + return 1; |
| 74 | +} |
| 75 | + |
| 76 | +#if 0 |
| 77 | +static int secp256k1_eckey_privkey_tweak_mul(secp256k1_scalar *key, const secp256k1_scalar *tweak) { |
| 78 | + int ret; |
| 79 | + ret = !secp256k1_scalar_is_zero(tweak); |
| 80 | + |
| 81 | + secp256k1_scalar_mul(key, key, tweak); |
| 82 | + return ret; |
| 83 | +} |
| 84 | + |
| 85 | +static int secp256k1_eckey_pubkey_tweak_mul(secp256k1_ge *key, const secp256k1_scalar *tweak) { |
| 86 | + secp256k1_scalar zero; |
| 87 | + secp256k1_gej pt; |
| 88 | + if (secp256k1_scalar_is_zero(tweak)) { |
| 89 | + return 0; |
| 90 | + } |
| 91 | + |
| 92 | + secp256k1_scalar_set_int(&zero, 0); |
| 93 | + secp256k1_gej_set_ge(&pt, key); |
| 94 | + secp256k1_ecmult(&pt, &pt, tweak, &zero); |
| 95 | + secp256k1_ge_set_gej(key, &pt); |
| 96 | + return 1; |
| 97 | +} |
| 98 | +#endif |
| 99 | + |
| 100 | +#endif /* SECP256K1_ECKEY_IMPL_H */ |
0 commit comments