Expand description
BIP32 hierarchical-deterministic key derivation as a Binius64 circuit gadget.
bip32_derive_compressed derives a compressed secp256k1 public key at a BIP32 derivation
path, supporting both hardened and non-hardened child steps. The derivation is run for the full
maximum tree depth and the public key at the actual path depth is selected with a multiplexer,
so the circuit shape is independent of the (witness) depth.
BIP32 spec: https://en.bitcoin.it/wiki/BIP_0032.
§Word conventions
HMAC-SHA512 (and SHA-512) consume and produce big-endian 64-bit words: word i holds
u64::from_be_bytes(bytes[8*i .. 8*i + 8]). A BigUint stores little-endian 64-bit limbs,
and limb values are plain integers. The numeric value of a SHA-512 word therefore equals the
corresponding 64-bit limb of the big-endian-parsed integer, so converting between a 256-bit
hash half and a BigUint is just a limb reversal — no per-byte swapping is required.
Structs§
- Bip32
Example - Example circuit proving knowledge of a BIP32 seed and derivation path whose derived compressed secp256k1 public key hashes (SHA-256) to a public digest.
- Instance
- Params
Functions§
- bip32_
derive_ compressed - Derive the BIP32 compressed secp256k1 public key at
depthalongpath.