Skip to main content

circuit_xmss_verify

Function circuit_xmss_verify 

Source
pub fn circuit_xmss_verify(
    builder: &CircuitBuilder,
    public_param: &[Wire; 2],
    merkle_root: &[Wire; 2],
    message: &[Wire; 4],
    epoch: Wire,
    signature: &XmssSignatureWires,
)
Expand description

In-circuit form of xmss_verify.

Three checks are stacked:

  1. the randomness encodes to a valid codeword, and the chains walk from their tips to the Winternitz public key,
  2. those chain ends hash into the Merkle leaf,
  3. the authentication path links that leaf to the committed root.

Every digest is derived from the inputs, so this emits constraints and returns nothing.

§Arguments

  • builder: circuit builder.
  • public_param: the signer’s public parameter.
  • merkle_root: the signer’s committed root.
  • message: the 32-byte message.
  • epoch: the leaf index the signature is at.
  • signature: the signature’s witness wires.