cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
Loading...
Searching...
No Matches
eth_sig.h File Reference

The recovery bit of a secp256k1 signature, computed on the device. More...

#include <stdint.h>
#include <stdbool.h>
Include dependency graph for eth_sig.h:
This graph shows which files directly or indirectly include this file:

Go to the source code of this file.

Functions

bool eth_sig_parity (const uint8_t hash[32], const uint8_t r[32], const uint8_t s[32], const uint8_t pub64[64], uint8_t *v_out)
 Verify (r, s) over hash against pub64 and return its y-parity.

Detailed Description

The recovery bit of a secp256k1 signature, computed on the device.

Definition in file eth_sig.h.

Function Documentation

◆ eth_sig_parity()

bool eth_sig_parity ( const uint8_t hash[32],
const uint8_t r[32],
const uint8_t s[32],
const uint8_t pub64[64],
uint8_t * v_out )

Verify (r, s) over hash against pub64 and return its y-parity.

The card signs but does not say which of the two candidate points it used, and an Ethereum transaction has to carry that bit (v). It used to come from the RPC node: two eth_calls to the ecrecover precompile, compared against the card's address — a network round-trip per sale, and a node's word on it. The card's public key is already in hand, so this does the verification locally: R = (e/s)·G + (r/s)·Q, check R.x ≡ r (mod n), and v is the parity of R.y.

Refuses the rare signature whose R.x is at or above the group order (recovery ids 2 and 3), which an Ethereum transaction cannot express.

Parameters
[in]hash32-byte message digest that was signed.
[in]r32-byte big-endian r.
[in]s32-byte big-endian s.
[in]pub64Signer's uncompressed public key, X || Y (no 0x04).
[out]v_out0 or 1 on success; untouched otherwise.
Returns
true if the signature verifies under pub64; false otherwise — including a key that is not on the curve.

Definition at line 16 of file eth_sig.cpp.

References ok().

Referenced by sign_and_broadcast().