pub fn ecrecover(
b: &CircuitBuilder,
z: &BigUint,
r: &BigUint,
s: &BigUint,
recid_odd: Wire,
) -> Secp256k1AffineExpand description
EcRecover - an “Ethereum-style” verification of ECDSA signatures over secp256k1.
§Arguments
z- hash of the signed message as an integerr- R part of the signature, the x coordinate of the nonce points- S part of the signaturerecid_odd- parity flag of the y coordinate of the assumed nonce point R with R.x = r; note that we do not supportrbeing greater or equal than the scalar field modulus, and thus only need parity; some implementations assume 0-3 bitmask which encodes both y parity and r scalar field overflow, but that’s not needed for Ethereum.
§Outputs
The recovered public key pk in affine form.