Skip to main content

ecrecover

Function ecrecover 

Source
pub fn ecrecover(
    b: &CircuitBuilder,
    z: &BigUint,
    r: &BigUint,
    s: &BigUint,
    recid_odd: Wire,
) -> Secp256k1Affine
Expand description

EcRecover - an “Ethereum-style” verification of ECDSA signatures over secp256k1.

§Arguments

  • z - hash of the signed message as an integer
  • r - R part of the signature, the x coordinate of the nonce point
  • s - S part of the signature
  • recid_odd - parity flag of the y coordinate of the assumed nonce point R with R.x = r; note that we do not support r being greater or equal than the scalar field modulus, and thus only need parity; some implementations assume 0-3 bitmask which encodes both y parity and r scalar field overflow, but that’s not needed for Ethereum.

§Outputs

The recovered public key pk in affine form.