pub struct Secp256k1EndosplitHint { /* private fields */ }Implementations§
Source§impl Secp256k1EndosplitHint
impl Secp256k1EndosplitHint
pub fn new() -> Self
Sourcepub fn call(
builder: &CircuitBuilder,
k: &[Wire],
) -> (Wire, Wire, [Wire; 2], [Wire; 2])
pub fn call( builder: &CircuitBuilder, k: &[Wire], ) -> (Wire, Wire, [Wire; 2], [Wire; 2])
Secp256k1 endomorphism split.
The curve has an endomorphism λ (x, y) = (βx, y) where λ³=1 (mod n)
and β³=1 (mod p) (n being the scalar field modulus and p coordinate field one).
For a 256-bit scalar k it is possible to split it into k1 and k2 such that
k1 + λ k2 = k (mod n) and both k1 and k2 are no farther than 2^128 from zero.
The k scalar is represented by four 64-bit limbs in little endian order. The return value
is quadruple of (k1_neg, k2_neg, k1_abs, k2_abs) where k1_neg and k2_neg are
MSB-bools indicating whether k1_abs or k2_abs, respectively, should be negated.
k1_abs and k2_abs are at most 128 bits and are represented with two 64-bit limbs.
When k cannot be represented in this way (any valid scalar can, so it has to be modulus
or above), both k1_abs and k2_abs are assigned zero values.
This is a hint - a deterministic computation that happens only on the prover side.
The result should be additionally constrained by using bignum circuits to check that
k1 + λ k2 = k (mod n).
Trait Implementations§
Source§impl Default for Secp256k1EndosplitHint
impl Default for Secp256k1EndosplitHint
Source§impl Hint for Secp256k1EndosplitHint
impl Hint for Secp256k1EndosplitHint
Auto Trait Implementations§
impl Freeze for Secp256k1EndosplitHint
impl RefUnwindSafe for Secp256k1EndosplitHint
impl Send for Secp256k1EndosplitHint
impl Sync for Secp256k1EndosplitHint
impl Unpin for Secp256k1EndosplitHint
impl UnsafeUnpin for Secp256k1EndosplitHint
impl UnwindSafe for Secp256k1EndosplitHint
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more