Skip to main content

bip32_derive_compressed

Function bip32_derive_compressed 

Source
pub fn bip32_derive_compressed(
    b: &mut CircuitBuilder,
    seed: &[Wire; 8],
    path: &[Wire],
    depth: Wire,
) -> Vec<Wire>
Expand description

Derive the BIP32 compressed secp256k1 public key at depth along path.

The maximum tree depth is the circuit parameter path.len().

§Arguments

  • b - circuit builder
  • seed - the 512-bit BIP32 seed as eight big-endian 64-bit words
  • path - max_depth derivation-index words. Only the low 32 bits are significant; bit 31 set means a hardened child. Entries beyond depth are still derived but never selected.
  • depth - the actual path depth (<= max_depth) selecting which level’s public key to output

§Returns

The 33-byte compressed public key as nine four-byte big-endian words (the layout produced by compress_pubkey).

§Assumptions

The negligible-probability BIP32 invalid-key cases (parse256(I_L) >= n, or a derived key equal to zero) are not constrained; the gadget assumes a valid witness.