You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

47 lines
1.8 KiB

  1. include "escalarmul.circom";
  2. component Pedersen(n) {
  3. signal input in[n];
  4. signal output out[2];
  5. var nexps = ((n-1) \ 253) + 1;
  6. var nlastbits = n - (nexps-1)*253;
  7. component escalarMuls[nexps];
  8. var PBASE = [
  9. [17777552123799933955779906779655732241715742912184938656739573121738514868268,
  10. 2626589144620713026669568689430873010625803728049924121243784502389097019475],
  11. [17777552123799933955779906779655732241715742912184938656739573121738514868268,
  12. 2626589144620713026669568689430873010625803728049924121243784502389097019475],
  13. [17777552123799933955779906779655732241715742912184938656739573121738514868268,
  14. 2626589144620713026669568689430873010625803728049924121243784502389097019475],
  15. [17777552123799933955779906779655732241715742912184938656739573121738514868268,
  16. 2626589144620713026669568689430873010625803728049924121243784502389097019475],
  17. [17777552123799933955779906779655732241715742912184938656739573121738514868268,
  18. 2626589144620713026669568689430873010625803728049924121243784502389097019475]
  19. ];
  20. var i;
  21. var j;
  22. for (i=0; i<nexps; i++) {
  23. var nexpbits = (i == nexps-1) ? nlastbits : 253;
  24. escalarMuls[i] = EscalarMul(nexpbits, PBASE[i][0], PBAS[i][1]);
  25. for (j=0; j<nexpbits; j++) {
  26. escalarMuls[i].in[j] <== in[253*i + j];
  27. }
  28. if (i==0) {
  29. escalarMuls[i].inp[0] <== 0;
  30. escalarMuls[i].inp[1] <== 0;
  31. } else {
  32. escalarMuls[i].inp[0] <== escalarMuls[i-1].out[0];
  33. escalarMuls[i].inp[1] <== escalarMuls[i-1].out[1];
  34. }
  35. }
  36. escalarMuls[nexps-1].out[0] ==> out[0];
  37. escalarMuls[nexps-1].out[1] ==> out[1];
  38. }