Skip to content

Commit 898c9f0

Browse files
jonasnickapoelstra
authored andcommitted
Clarify how to derive alternative generator H
1 parent 15d9278 commit 898c9f0

1 file changed

Lines changed: 8 additions & 3 deletions

File tree

src/modules/rangeproof/main_impl.h

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -15,9 +15,14 @@
1515

1616
/** Alternative generator for secp256k1.
1717
* This is the sha256 of 'g' after DER encoding (without compression),
18-
* which happens to be a point on the curve.
19-
* sage: G2 = EllipticCurve ([F (0), F (7)]).lift_x(F(int(hashlib.sha256('0479be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798483ada7726a3c4655da4fbfc0e1108a8fd17b448a68554199c47d08ffb10d4b8'.decode('hex')).hexdigest(),16)))
20-
* sage: '%x %x' % G2.xy()
18+
* which happens to be a point on the curve. More precisely, the generator is
19+
* derived by running the following script with the sage mathematics software.
20+
21+
import hashlib
22+
F = FiniteField (0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F)
23+
G_DER = '0479be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798483ada7726a3c4655da4fbfc0e1108a8fd17b448a68554199c47d08ffb10d4b8'
24+
G2 = EllipticCurve ([F (0), F (7)]).lift_x(F(int(hashlib.sha256(G_DER.decode('hex')).hexdigest(),16)))
25+
print('%x %x' % G2.xy())
2126
*/
2227
static const secp256k1_generator secp256k1_generator_h_internal = {{
2328
0x50, 0x92, 0x9b, 0x74, 0xc1, 0xa0, 0x49, 0x54, 0xb7, 0x8b, 0x4b, 0x60, 0x35, 0xe9, 0x7a, 0x5e,

0 commit comments

Comments
 (0)