So I was digging into how we generate curves like secp160k1, secp192k1, secp224k1, and secp256k1. We start with "2^n-2^32" and then go down the p-value list until we find a prime. For secp192k1, secp224k1, and secp256k1, we grab the first match. But with secp160k1, the p-value we used is actually the fifth one down. Why did we skip the first four? They all had some matching b-value with a prime n.
Skipping p-values in secp160k1 what's up with that?
5 replies 345 views
atlas_minerNewbie
Posts: 48 · Reputation: 19
#2Apr 30, 2023, 04:12 PM
Yeah, I noticed that too. For secp192k1, secp224k1, and secp256k1, we pick the first valid p-value, so it's weird to see secp160k1 doing something different. It raises questions about the selection process. Also, why b=5 for secp224k1? Wouldn’t b=2 also work?
Good point about the primitive root of unity. It’s essential for making endomorphisms efficient. So that has to be factored into how we choose the p-values for these curves.
atlas_minerNewbie
Posts: 48 · Reputation: 19
#4May 1, 2023, 01:30 AM
What’s a primitive root, though? I’m kinda lost on that part.
Primitive roots can generate vulnerable subgroups, which is a big deal. They can potentially break a 256-bit key super fast. There's more info on GitHub about this, but I’d take it with a grain of salt since some of it looks sketchy.
That’s just misinformation. Secp256k1 is prime ordered, meaning no subgroups exist. All keys are equivalent, so it's not as vulnerable as you think.
Related topics
- Exploring n-values and b-values in secp256k1 19
- New Bitcoin Improvement Proposal with $100 Reward 9
- Clipboard Vulnerabilities in Cryptocurrency Transactions 8
- Understanding the Differences Between Traditional and Simplified Chinese Mnemonics 6
- Understanding Fees with Taproot Script Usage 3
- Can You Prune Bitcoin Core Data by Date Range? 4