Expand description
WOTS (Winternitz one-time signature) with target-sum encoding.
There are no checksum chains. Instead the signer grinds the signature randomness until the
encoding’s digits sum to TARGET_SUM, and a verifier that checks the sum knows no digit can
have been lowered without another being raised.
Functions§
- chain_
step - One chain step.
- circuit_
recover_ public_ key - In-circuit form of
recover_public_key, spending only the hashes a verifier walks. - circuit_
wots_ encode - In-circuit form of
wots_encode, returning the digits and constraining them to be a valid encoding. - circuit_
wots_ public_ key_ hash - In-circuit form of
wots_public_key_hash. - find_
randomness_ for_ wots_ encoding - Draws randomness until it encodes validly.
- iterate_
hash - Walks chain
chain_indexfornsteps starting at chain valuestart_step. - recover_
public_ key - Walks every chain from its tip to the public-key end.
- wots_
encode - The target-sum encoding.
- wots_
public_ key_ hash - The Merkle leaf: the hash over the public parameter and the
Vconcatenated chain ends.