Sitelet https://github.com/Vectorized/solady/blob/main/docs/utils/p256.md
Skip to content

Latest commit

 

History

History
143 lines (100 loc) · 3.53 KB

File metadata and controls

143 lines (100 loc) · 3.53 KB

P256

Gas optimized P256 wrapper.

Constants

VERIFIER

address internal constant VERIFIER =
    0x000000000000D01eA45F9eFD5c54f037Fa57Ea1a

Address of the Solidity P256 verifier.
Please make sure the contract is deployed onto the chain you are working on.
See: https://gist.github.com/Vectorized/599b0d8a94d21bc74700eb1354e2f55c
Unlike RIP-7212, this verifier returns uint256(0) on failure, to
facilitate easier existence check. This verifier will also never revert.

CANARY

address internal constant CANARY =
    0x0000000000001Ab2e8006Fd8B71907bf06a5BDEE

The existence of this contract, as determined by non-empty bytecode,
implies the existence of the RIP-7212 precompile.
See: https://gist.github.com/Vectorized/3c69dcf4604b9e1216525cabcd06ee34
This is to enable the optimization to skip the VERIFIER entirely
when the RIP_PRECOMPILE returns empty returndata for an invalid signature.

RIP_PRECOMPILE

address internal constant RIP_PRECOMPILE =
    0x0000000000000000000000000000000000000100

Address of the RIP-7212 P256 verifier precompile.
Currently, we don't support EIP-7212's precompile at 0x0b as it has not been finalized.
See: https://github.com/ethereum/RIPs/blob/master/RIPS/rip-7212.md

N

uint256 internal constant N =
    0xFFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551

The order of the secp256r1 elliptic curve.

P256 Verification Operations

verifySignatureAllowMalleability(bytes32,bytes32,bytes32,bytes32,bytes32)

function verifySignatureAllowMalleability(
    bytes32 hash,
    bytes32 r,
    bytes32 s,
    bytes32 x,
    bytes32 y
) internal view returns (bool isValid)

Returns if the signature (r, s) is valid for hash and public key (x, y).
Does NOT include the malleability check.

verifySignature(bytes32,bytes32,bytes32,bytes32,bytes32)

function verifySignature(
    bytes32 hash,
    bytes32 r,
    bytes32 s,
    bytes32 x,
    bytes32 y
) internal view returns (bool isValid)

Returns if the signature (r, s) is valid for hash and public key (x, y).
Includes the malleability check.

hasPrecompile()

function hasPrecompile() internal view returns (bool result)

Returns if the RIP-7212 precompile exists.

hasPrecompileOrVerifier()

function hasPrecompileOrVerifier() internal view returns (bool result)

Returns if either the RIP-7212 precompile or the verifier exists.
Since verifySignature is made not reverting, this function can be used to
manually implement a revert if the current chain does not have the contracts
to support secp256r1 signature recovery.

Other Operations

normalized(bytes32)

function normalized(bytes32 s) internal pure returns (bytes32 result)

Returns s normalized to the lower half of the curve.

tryDecodePoint(bytes)

function tryDecodePoint(bytes memory encoded)
    internal
    pure
    returns (bytes32 x, bytes32 y)

Helper function for abi.decode(encoded, (bytes32, bytes32)).
If encoded.length < 64, (x, y) will be (0, 0), which is an invalid point.

tryDecodePointCalldata(bytes)

function tryDecodePointCalldata(bytes calldata encoded)
    internal
    pure
    returns (bytes32 x, bytes32 y)

Helper function for abi.decode(encoded, (bytes32, bytes32)).
If encoded.length < 64, (x, y) will be (0, 0), which is an invalid point.