Bitcoin Core mirror and no, I don't give a fuck about Monero.
Find a file
Pieter Wuille b0295868f4
Merge pull request #82
8f9a307 Better .gitignore for bench binaries (Pieter Wuille)
fa5c13f Add bench_sign tool (Pieter Wuille)
2014-11-02 01:16:58 -07:00
include [API CHANGE] Use secp256k1_ec_ prefix for non-ECDSA key operations 2014-10-27 02:51:58 -07:00
m4 autotools: autotools'ify libsecp256k1 2014-01-17 23:24:12 -05:00
obj Add obj/ directory 2013-04-11 12:46:39 +02:00
src Merge pull request #82 2014-11-02 01:16:58 -07:00
.gitignore Better .gitignore for bench binaries 2014-11-01 06:01:40 -07:00
.travis.yml Remove OpenSSL bignum implementation 2014-10-31 02:10:13 -07:00
autogen.sh build: add autogen. How was this missing? 2014-06-19 14:56:23 -04:00
configure.ac Remove OpenSSL bignum implementation 2014-10-31 02:10:13 -07:00
COPYING MIT License 2013-05-09 15:24:32 +02:00
libsecp256k1.pc.in packaging: fixup pkg-config 2014-05-20 21:02:05 -04:00
Makefile.am Add bench_sign tool 2014-10-31 08:23:34 -07:00
nasm_lt.sh autotools: autotools'ify libsecp256k1 2014-01-17 23:24:12 -05:00
README.md Nothing-up-my-sleeving blinding for a*G 2014-09-01 14:56:12 +02:00
TODO updates 2013-05-06 13:28:46 +02:00

libsecp256k1

Build Status

Optimized C library for EC operations on curve secp256k1.

This library is experimental, so use at your own risk.

Features:

  • Low-level field and group operations on secp256k1.
  • ECDSA signing/verification and key generation.
  • Adding/multiplying private/public keys.
  • Serialization/parsing of private keys, public keys, signatures.
  • Very efficient implementation.

Implementation details

  • General
    • Avoid dynamic memory usage almost everywhere.
  • Field operations
    • Optimized implementation of arithmetic modulo the curve's field size (2^256 - 0x1000003D1).
      • Using 5 52-bit limbs (including hand-optimized assembly for x86_64, by Diederik Huys).
      • Using 10 26-bit limbs.
      • Using GMP.
    • Field inverses and square roots using a sliding window over blocks of 1s (by Peter Dettman).
  • Group operations
    • Point addition formula specifically simplified for the curve equation (y^2 = x^3 + 7).
    • Use addition between points in Jacobian and affine coordinates where possible.
  • Point multiplication for verification (aP + bG).
    • Use wNAF notation for point multiplicands.
    • Use a much larger window for multiples of G, using precomputed multiples.
    • Use Shamir's trick to do the multiplication with the public key and the generator simultaneously.
    • Optionally use secp256k1's efficiently-computable endomorphism to split the multiplicands into 4 half-sized ones first.
  • Point multiplication for signing
    • Use a precomputed table of multiples of powers of 16 multiplied with the generator, so general multiplication becomes a series of additions.
    • Slice the precomputed table in memory per byte, so memory access to the table becomes uniform.
    • Not fully constant-time, but the precomputed tables add and eventually subtract points for which no known scalar (private key) is known, blinding non-constant time effects even from an attacker with control over the private key used.

Build steps

libsecp256k1 is built using autotools:

$ ./autogen.sh
$ ./configure
$ make
$ sudo make install  # optional