๐งฎ EC256
Introductionโ
This library provides elliptic curve arithmetic over a 256-bit prime field (Weierstrass curve y^2 = x^3 + ax + b (mod p)).
Functionsโ
To use the EC256 library, you need to import it.
import "@solarity/solidity-lib/libs/crypto/EC256.sol";
And optionally bind it to the type with the using statement.
using EC256 for *;
basepointโ
function basepoint(
EC256.Curve memory ec
) internal pure returns (EC256.APoint memory aPoint_);
Descriptionโ
Returns the generator (base) point of the curve in affine form.
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
jbasepointโ
function jbasepoint(
EC256.Curve memory ec
) internal pure returns (EC256.JPoint memory jPoint_);
Descriptionโ
Returns the generator (base) point of the curve in jacobian form.
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
toScalarโ
function toScalar(
EC256.Curve memory ec,
uint256 u256_
) internal pure returns (uint256 scalar_);
Descriptionโ
Reduces an arbitrary uint256 into the scalar field [0, n).
Returns the result of u256_ mod n.
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
u256 | uint256 | The integer to reduce |
isOnCurveโ
function isOnCurve(
EC256.Curve memory ec,
EC256.APoint memory aPoint_
) internal pure returns (bool result_);
Descriptionโ
Checks whether an affine point lies on the curve.
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
aPoint | struct EC256.APoint | The affine point to test |
isValidScalarโ
function isValidScalar(
EC256.Curve memory ec,
uint256 scalar_
) internal pure returns (bool result_);
Descriptionโ
Checks whether a scalar is in the valid range [0, n).
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
scalar | uint256 | The scalar to test |
toAffineโ
function toAffine(
EC256.Curve memory ec,
EC256.JPoint memory jPoint_
) internal view returns (EC256.APoint memory aPoint_);
Descriptionโ
Converts a point from Jacobian to affine coordinates.
Returns the equivalent affine point (x, y).
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
jPoint | struct EC256.JPoint | The Jacobian point (X, Y, Z) |
toJacobianโ
function toJacobian(
EC256.APoint memory aPoint_
) internal pure returns (EC256.JPoint memory jPoint_);
Descriptionโ
Converts an affine point to Jacobian coordinates.
Returns the point in Jacobian representation (x, y, 1).
Parameters:โ
| Name | Type | Description |
|---|---|---|
aPoint | struct EC256.APoint | The affine point (x, y) |
isJacobianInfinityโ
function isJacobianInfinity(
EC256.JPoint memory jPoint_
) internal pure returns (bool result_);
Descriptionโ
Checks whether a Jacobian point is the point at infinity.
Parameters:โ
| Name | Type | Description |
|---|---|---|
jPoint | struct EC256.JPoint | The Jacobian point to test |
jinfinityโ
function jinfinity() internal pure returns (EC256.JPoint memory jPoint_);
Descriptionโ
Returns the Jacobian representation of the point at infinity.
Returns the point at infinity (0, 0, 0).
jEqualโ
function jEqual(
EC256.Curve memory ec,
EC256.JPoint memory jPoint1_,
EC256.JPoint memory jPoint2_
) internal view returns (bool result_);
Descriptionโ
Compares two Jacobian points for equality in affine coordinates.
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
jPoint1 | struct EC256.JPoint | The first Jacobian point |
jPoint2 | struct EC256.JPoint | The second Jacobian point |
jMultShamirโ
function jMultShamir(
EC256.Curve memory ec,
EC256.JPoint memory jPoint_,
uint256 scalar_
) internal pure returns (EC256.JPoint memory jPoint2_);
Descriptionโ
Point multiplication: R = u*P using 4-bit windowed method.
Returns the Jacobian representation of result point R.
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
jPoint | struct EC256.JPoint | TThe Jacobian point P |
scalar | uint256 | The scalar u |
jMultShamir2โ
function jMultShamir2(
EC256.Curve memory ec,
EC256.JPoint memory jPoint1_,
EC256.JPoint memory jPoint2_,
uint256 scalar1_,
uint256 scalar2_
) internal pure returns (EC256.JPoint memory jPoint3_);
Descriptionโ
Simultaneous double-scalar multiplication: R = u1P1 + u2P2 via StraussโShamir.
Returns the Jacobian representation of result point R.
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
jPoint1 | struct EC256.JPoint | The first Jacobian point P1 |
jPoint2 | struct EC256.JPoint | The second Jacobian point P2 |
scalar1 | uint256 | The first scalar u1 |
scalar2 | uint256 | The second scalar u2 |
jAddPointโ
function jAddPoint(
EC256.Curve memory ec,
EC256.JPoint memory jPoint1_,
EC256.JPoint memory jPoint2_
) internal pure returns (EC256.JPoint memory jPoint3_);
Descriptionโ
Adds two Jacobian points: R = P1 + P2.
Returns the Jacobian representation of result point R.
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
jPoint1 | struct EC256.JPoint | The first Jacobian point P1 |
jPoint2 | struct EC256.JPoint | The second Jacobian point P2 |
jDoublePointโ
function jDoublePoint(
EC256.Curve memory ec,
EC256.JPoint memory jPoint1_
) internal pure returns (EC256.JPoint memory jPoint2_);
Descriptionโ
Doubles a Jacobian point: R = 2*P.
Returns the Jacobian representation of result point R.
Parameters:โ
| Name | Type | Description |
|---|---|---|
ec | struct EC256.Curve | The curve parameters |
jPoint | struct EC256.JPoint | The Jacobian point P to double |
Exampleโ
EC256.Curve public secp256k1CurveParams =
EC256.Curve({
a: 0x0000000000000000000000000000000000000000000000000000000000000000,
b: 0x0000000000000000000000000000000000000000000000000000000000000007,
gx: 0x79be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798,
gy: 0x483ada7726a3c4655da4fbfc0e1108a8fd17b448a68554199c47d08ffb10d4b8,
p: 0xfffffffffffffffffffffffffffffffffffffffffffffffffffffffefffffc2f,
n: 0xfffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141
});
function affineInfinity() external view returns (EC256.APoint memory) {
return secp256k1CurveParams.toAffine(EC256.jinfinity());
}
function basepoint() external view returns (EC256.APoint memory) {
return secp256k1CurveParams.basepoint();
}
function checkBasepointAddition() external view returns (bool) {
EC256.JPoint memory G_ = secp256k1CurveParams.jbasepoint();
EC256.JPoint memory doubledG_ = secp256k1CurveParams.jDoublePoint(G_);
EC256.JPoint memory scalarMultipliedG_ = secp256k1CurveParams.jMultShamir(G_, 2);
return secp256k1CurveParams.jEqual(scalarMultipliedG_, doubledG_);
}