Browse Source

integration: clean up single-key stealth derivation

hk-custom-address
Daniel Cousens 10 years ago
parent
commit
2ccf00f4be
  1. 53
      test/integration/crypto.js

53
test/integration/crypto.js

@ -9,35 +9,42 @@ var crypto = require('crypto')
describe('bitcoinjs-lib (crypto)', function () { describe('bitcoinjs-lib (crypto)', function () {
it('can generate a single-key stealth address', function () { it('can generate a single-key stealth address', function () {
var receiver = bitcoin.ECPair.fromWIF('5KYZdUEo39z3FPrtuX2QbbwGnNP5zTd7yyr2SC1j299sBCnWjss')
// XXX: ephemeral, must be random (and secret to sender) to preserve privacy
var sender = bitcoin.ECPair.fromWIF('Kxr9tQED9H44gCmp6HAdmemAzU3n84H3dGkuWTKvE23JgHMW8gct')
var G = bitcoin.ECPair.curve.G var G = bitcoin.ECPair.curve.G
var d = receiver.d // secret (receiver only) var n = bitcoin.ECPair.curve.n
var Q = receiver.Q // shared
function stealthSend (Q, nonce) {
var e = sender.d // secret (sender only) var noncePair = new bitcoin.ECPair(bigi.fromBuffer(nonce))
var P = sender.Q // shared var e = noncePair.d
var eQ = Q.multiply(e)
var c = bigi.fromBuffer(bitcoin.crypto.sha256(eQ.getEncoded()))
var cG = G.multiply(c)
var Qprime = Q.add(cG)
return {
address: new bitcoin.ECPair(null, Qprime).getAddress(),
nonceQ: noncePair.Q
}
}
// derived shared secret function stealthReceive (d, P) {
var eQ = Q.multiply(e) // sender var dP = P.multiply(d)
var dP = P.multiply(d) // receiver var c = bigi.fromBuffer(bitcoin.crypto.sha256(dP.getEncoded()))
assert.deepEqual(eQ.getEncoded(), dP.getEncoded()) var derived = new bitcoin.ECPair(d.add(c).mod(n))
var c = bigi.fromBuffer(bitcoin.crypto.sha256(eQ.getEncoded())) return {
var cG = G.multiply(c) keyPair: derived
}
}
// derived public key // receiver private key
var QprimeS = Q.add(cG) var receiver = bitcoin.ECPair.fromWIF('5KYZdUEo39z3FPrtuX2QbbwGnNP5zTd7yyr2SC1j299sBCnWjss')
var QprimeR = G.multiply(d.add(c)) var nonce = crypto.randomBytes(32)
assert.deepEqual(QprimeR.getEncoded(), QprimeS.getEncoded())
// derived shared-secret address var stealthS = stealthSend(receiver.Q, nonce)
var address = new bitcoin.ECPair(null, QprimeS).getAddress() var stealthR = stealthReceive(receiver.d, stealthS.nonceQ)
assert.strictEqual(address, '1EwCNJNZM5q58YPPTnjR1H5BvYRNeyZi47') // and check that we derived both sides correctly
assert.equal(stealthS.address, stealthR.keyPair.getAddress())
}) })
// TODO // TODO

Loading…
Cancel
Save