Line data Source code
1 : #ifndef HEADER_fd_src_ballet_secp256r1_fd_secp256r1_h 2 : #define HEADER_fd_src_ballet_secp256r1_fd_secp256r1_h 3 : 4 : /* fd_secp256r1 provides APIs for secp256r1 signature verification. */ 5 : 6 : #include "../fd_ballet_base.h" 7 : #include "../sha256/fd_sha256.h" 8 : 9 46008 : #define FD_SECP256R1_SUCCESS 1 10 63 : #define FD_SECP256R1_FAILURE 0 11 : 12 : FD_PROTOTYPES_BEGIN 13 : 14 : /* fd_secp256r1_public_key_compress validates and compresses an SEC1 15 : uncompressed public key. In particular, this validates both canonical 16 : coordinates and the curve equation before discarding the y coordinate. 17 : Returns FD_SECP256R1_SUCCESS on success and FD_SECP256R1_FAILURE on 18 : failure. */ 19 : 20 : int 21 : fd_secp256r1_public_key_compress( uchar compressed[ 33 ], 22 : uchar const uncompressed[ 65 ] ); 23 : 24 : /* fd_secp256r1_verify verifies a SECP256r1 signature. 25 : Enforces low-S malleability check (s <= (n-1)/2). */ 26 : int 27 : fd_secp256r1_verify( uchar const msg[], /* msg_sz */ 28 : ulong msg_sz, 29 : uchar const sig[ 64 ], 30 : uchar const public_key[ 33 ], 31 : fd_sha256_t * sha ); 32 : 33 : /* fd_secp256r1_verify_allow_high_s verifies a SECP256r1 signature the 34 : same way as fd_secp256r1_verify() but skips the low-S malleability 35 : check, thus additionally accepting high-S signatures (any s in 36 : (0, n)). */ 37 : int 38 : fd_secp256r1_verify_allow_high_s( uchar const msg[], /* msg_sz */ 39 : ulong msg_sz, 40 : uchar const sig[ 64 ], 41 : uchar const public_key[ 33 ], 42 : fd_sha256_t * sha ); 43 : 44 : FD_PROTOTYPES_END 45 : 46 : #endif /* HEADER_fd_src_ballet_secp256r1_fd_secp256r1_h */