17 const uint8_t s[32],
const uint8_t pub64[64],
20 if ((hash == NULL) || (r == NULL) || (s == NULL) || (pub64 == NULL) ||
25 mbedtls_ecp_group grp;
26 mbedtls_ecp_point Q, R;
27 mbedtls_mpi e, rr, ss, w, u1, u2, x;
28 mbedtls_ecp_group_init(&grp);
29 mbedtls_ecp_point_init(&Q);
30 mbedtls_ecp_point_init(&R);
31 mbedtls_mpi_init(&e); mbedtls_mpi_init(&rr); mbedtls_mpi_init(&ss);
32 mbedtls_mpi_init(&w); mbedtls_mpi_init(&u1); mbedtls_mpi_init(&u2);
41 for (
size_t i = 0U; i < 64U; i++) { q65[i + 1U] = pub64[i]; }
44 if ((mbedtls_ecp_group_load(&grp, MBEDTLS_ECP_DP_SECP256K1) == 0) &&
45 (mbedtls_ecp_point_read_binary(&grp, &Q, q65,
sizeof(q65)) == 0) &&
46 (mbedtls_ecp_check_pubkey(&grp, &Q) == 0) &&
47 (mbedtls_mpi_read_binary(&rr, r, 32U) == 0) &&
48 (mbedtls_mpi_read_binary(&ss, s, 32U) == 0) &&
50 (mbedtls_mpi_cmp_int(&rr, 1) >= 0) && (mbedtls_mpi_cmp_mpi(&rr, &grp.N) < 0) &&
51 (mbedtls_mpi_cmp_int(&ss, 1) >= 0) && (mbedtls_mpi_cmp_mpi(&ss, &grp.N) < 0) &&
53 (mbedtls_mpi_read_binary(&e, hash, 32U) == 0) &&
54 (mbedtls_mpi_mod_mpi(&e, &e, &grp.N) == 0) &&
56 (mbedtls_mpi_inv_mod(&w, &ss, &grp.N) == 0) &&
57 (mbedtls_mpi_mul_mpi(&u1, &e, &w) == 0) &&
58 (mbedtls_mpi_mod_mpi(&u1, &u1, &grp.N) == 0) &&
59 (mbedtls_mpi_mul_mpi(&u2, &rr, &w) == 0) &&
60 (mbedtls_mpi_mod_mpi(&u2, &u2, &grp.N) == 0) &&
62 (mbedtls_ecp_muladd(&grp, &R, &u1, &grp.G, &u2, &Q) == 0) &&
63 (mbedtls_ecp_point_write_binary(&grp, &R, MBEDTLS_ECP_PF_UNCOMPRESSED,
64 &olen, r65,
sizeof(r65)) == 0) &&
65 (olen ==
sizeof(r65)) &&
68 (mbedtls_mpi_read_binary(&x, &r65[1], 32U) == 0) &&
69 (mbedtls_mpi_cmp_mpi(&x, &rr) == 0)) {
70 *v_out =
static_cast<uint8_t
>(r65[64] & 1U);
74 mbedtls_mpi_free(&e); mbedtls_mpi_free(&rr); mbedtls_mpi_free(&ss);
75 mbedtls_mpi_free(&w); mbedtls_mpi_free(&u1); mbedtls_mpi_free(&u2);
77 mbedtls_ecp_point_free(&Q);
78 mbedtls_ecp_point_free(&R);
79 mbedtls_ecp_group_free(&grp);
bool eth_sig_parity(const uint8_t hash[32], const uint8_t r[32], const uint8_t s[32], const uint8_t pub64[64], uint8_t *v_out)
Verify (r, s) over hash against pub64 and return its y-parity.