Skip to main content

Module wots

Module wots 

Source
Expand description

WOTS (Winternitz one-time signature) with target-sum encoding.

There are no checksum chains. Instead the signer grinds the signature randomness until the encoding’s digits sum to TARGET_SUM, and a verifier that checks the sum knows no digit can have been lowered without another being raised.

Functions§

chain_step
One chain step.
circuit_recover_public_key
In-circuit form of recover_public_key, spending only the hashes a verifier walks.
circuit_wots_encode
In-circuit form of wots_encode, returning the digits and constraining them to be a valid encoding.
circuit_wots_public_key_hash
In-circuit form of wots_public_key_hash.
find_randomness_for_wots_encoding
Draws randomness until it encodes validly.
iterate_hash
Walks chain chain_index for n steps starting at chain value start_step.
recover_public_key
Walks every chain from its tip to the public-key end.
wots_encode
The target-sum encoding.
wots_public_key_hash
The Merkle leaf: the hash over the public parameter and the V concatenated chain ends.