void run_point_times_order(void) { secp256k1_fe_t x; VERIFY_CHECK(secp256k1_fe_set_hex(&x, "02", 2)); for (int i=0; i<500; i++) { secp256k1_ge_t p; if (secp256k1_ge_set_xo(&p, &x, 1)) { CHECK(secp256k1_ge_is_valid(&p)); secp256k1_gej_t j; secp256k1_gej_set_ge(&j, &p); CHECK(secp256k1_gej_is_valid(&j)); test_point_times_order(&j); } secp256k1_fe_sqr(&x, &x); } char c[65]; int cl=65; secp256k1_fe_get_hex(c, &cl, &x); CHECK(strcmp(c, "7603CB59B0EF6C63FE6084792A0C378CDB3233A80F8A9A09A877DEAD31B38C45") == 0); }
void test_point_times_order(const secp256k1_gej_t *point) { /* X * (point + G) + (order-X) * (pointer + G) = 0 */ secp256k1_scalar_t x; random_scalar_order_test(&x); secp256k1_scalar_t nx; secp256k1_scalar_negate(&nx, &x); secp256k1_gej_t res1, res2; secp256k1_ecmult(&res1, point, &x, &x); /* calc res1 = x * point + x * G; */ secp256k1_ecmult(&res2, point, &nx, &nx); /* calc res2 = (order - x) * point + (order - x) * G; */ secp256k1_gej_add_var(&res1, &res1, &res2); CHECK(secp256k1_gej_is_infinity(&res1)); CHECK(secp256k1_gej_is_valid(&res1) == 0); secp256k1_ge_t res3; secp256k1_ge_set_gej(&res3, &res1); CHECK(secp256k1_ge_is_infinity(&res3)); CHECK(secp256k1_ge_is_valid(&res3) == 0); }
int main() { secp256k1_fe_start(); secp256k1_ge_start(); secp256k1_ecmult_start(); secp256k1_fe_t x; const secp256k1_num_t *order = &secp256k1_ge_consts->order; secp256k1_num_t r, s, m; secp256k1_num_init(&r); secp256k1_num_init(&s); secp256k1_num_init(&m); secp256k1_ecdsa_sig_t sig; secp256k1_ecdsa_sig_init(&sig); secp256k1_fe_set_hex(&x, "a357ae915c4a65281309edf20504740f0eb3343990216b4f81063cb65f2f7e0f", 64); int cnt = 0; int good = 0; for (int i=0; i<1000000; i++) { random_num_order(&r); random_num_order(&s); random_num_order(&m); secp256k1_ecdsa_sig_set_rs(&sig, &r, &s); secp256k1_ge_t pubkey; secp256k1_ge_set_xo(&pubkey, &x, 1); if (secp256k1_ge_is_valid(&pubkey)) { cnt++; good += secp256k1_ecdsa_sig_verify(&sig, &pubkey, &m); } } printf("%i/%i\n", good, cnt); secp256k1_num_free(&r); secp256k1_num_free(&s); secp256k1_num_free(&m); secp256k1_ecdsa_sig_free(&sig); secp256k1_ecmult_stop(); secp256k1_ge_stop(); secp256k1_fe_stop(); return 0; }