1 /***********************************************************************
2  * Copyright (c) 2015 Andrew Poelstra *
3  * Distributed under the MIT software license, see the accompanying *
4  * file COPYING or*
5  ***********************************************************************/
10 #include "../../../include/secp256k1_ecdh.h"
11 #include "../../ecmult_const_impl.h"
13 static int ecdh_hash_function_sha256(unsigned char *output, const unsigned char *x32, const unsigned char *y32, void *data) {
14  unsigned char version = (y32[31] & 0x01) | 0x02;
15  secp256k1_sha256 sha;
16  (void)data;
19  secp256k1_sha256_write(&sha, &version, 1);
20  secp256k1_sha256_write(&sha, x32, 32);
21  secp256k1_sha256_finalize(&sha, output);
23  return 1;
24 }
29 int secp256k1_ecdh(const secp256k1_context* ctx, unsigned char *output, const secp256k1_pubkey *point, const unsigned char *scalar, secp256k1_ecdh_hash_function hashfp, void *data) {
30  int ret = 0;
31  int overflow = 0;
32  secp256k1_gej res;
33  secp256k1_ge pt;
35  unsigned char x[32];
36  unsigned char y[32];
38  VERIFY_CHECK(ctx != NULL);
39  ARG_CHECK(output != NULL);
40  ARG_CHECK(point != NULL);
41  ARG_CHECK(scalar != NULL);
43  if (hashfp == NULL) {
45  }
47  secp256k1_pubkey_load(ctx, &pt, point);
48  secp256k1_scalar_set_b32(&s, scalar, &overflow);
50  overflow |= secp256k1_scalar_is_zero(&s);
53  secp256k1_ecmult_const(&res, &pt, &s);
54  secp256k1_ge_set_gej(&pt, &res);
56  /* Compute a hash of the point */
59  secp256k1_fe_get_b32(x, &pt.x);
60  secp256k1_fe_get_b32(y, &pt.y);
62  ret = hashfp(output, x, y, data);
64  memset(x, 0, 32);
65  memset(y, 0, 32);
68  return !!ret & !overflow;
69 }
71 #endif /* SECP256K1_MODULE_ECDH_MAIN_H */
