Skip to main content

compress_pubkey

Function compress_pubkey 

Source
pub fn compress_pubkey(
    builder: &CircuitBuilder,
    x: &BigUint,
    y: &BigUint,
) -> Vec<Wire>
Expand description

Compresses a secp256k1 public key from uncompressed (x, y) format to compressed format.

Bitcoin uses compressed public keys which are 33 bytes instead of 65 bytes:

  • Uncompressed: [0x04] || x (32 bytes) || y (32 bytes) = 65 bytes
  • Compressed: [0x02 or 0x03] || x (32 bytes) = 33 bytes

The prefix byte indicates the parity of the y-coordinate:

  • 0x02 if y is even (LSB = 0)
  • 0x03 if y is odd (LSB = 1)

§Arguments

  • builder - Circuit builder for constructing constraints
  • x - x-coordinate of the public key (32 bytes, 4 limbs)
  • y - y-coordinate of the public key (32 bytes, 4 limbs)

§Returns

  • Vec<Wire> - Compressed public key as 33 bytes suitable for sha256_fixed input. Each wire contains 4 bytes (32-bit word) with high 32 bits zeroed.

§Panics

  • If x or y don’t have exactly 4 limbs (256 bits)