crypto/client/schnorr/sign/signature.go
(开头部分) 5KB这里只显示每个文件的开头 60 行。登录后可以解锁完整代码。
package sign
import (
"crypto/ecdsa"
"crypto/elliptic"
// "encoding/asn1"
"encoding/json"
"errors"
"fmt"
"math/big"
"github.com/xuperchain/xuperunion/crypto/common"
"github.com/xuperchain/xuperunion/crypto/hash"
)
// define errors
var (
ErrGenerateSignature = errors.New("Failed to generate the schnorr signature")
ErrEmptyMessage = errors.New("The message to be signed should not be empty")
)
// Sign : Schnorr signatures use a particular function, defined as:
// H'(m, s, e) = H(m || s * G + e * P)
//
// H is a hash function, for instance SHA256 or SM3.
// s and e are 2 numbers forming the signature itself.
// m is the message to sign.
// P is the public key.
//
// To verify the signature, check that the result of H'(m, s, e) is equal to e.
// Which means that: H(m || s * G + e * P) = e
//
// It's impossible for the others to find such a pair of (s, e) but the signer himself.
// This is because: P = x * G
// So the signer is able to get this equation: H(m || s * G + e * x * G) = e = H(m || (s + e * x) * G)
// It can be considered as: H(m || k * G) = e, where k = s + e * x
//
// This is the original process:
// 1. Choose a random number k
// 2. Compute e = H(m || k * G)
// 3. Because k = s + e * x, k and x (the key factor of the private key) are already known, we can compute s
// 4. Now we get the SchnorrSignature (e, s)
//
// Note there is a potential risk for privateKey, which also exists in the ECDSA algorithm:
// "The number k must be random enough. "
// If not, say the same k has been used twice or the second k can be predicted by the first k,
// the attacker will be able to retrieve the private key (x)
// This is because:
// 1. if the same k has been used twice:
// k = s0 + e0 * x = s1 + e1 * x
// the attacker knows: x = (s0 - s1) / (e1 - e0)
//
// 2. if the second k1 can be predicted by the first k0:
// k0 = s0 + e0 * x
// k1 = s1 + e1 * x
// the attacker knows: x = (k1 - k0 + s0 - s1) / (e1 - e0)
//
// So the final process is:
// 1. Compute k = H(m || x)
// This makes k unpredictable for anyone who do not know x,
后面还有 117 行代码,解锁后查看完整代码
24 小时内免费解锁 3 个项目,之后 1 积分/个。 规则说明
AI 解读
登录后可用,每次 10 积分,解读结果公开显示在下面。
还没有人解读过这个文件。
