Testing a Compact Version of secp256k1

14 replies 181 views
Posts: 18 · Reputation: 209
#1Jan 19, 2022, 11:37 AM
Just getting into this stuff, so bear with me. I made a smaller secp256k1 with p=43, n=31. Took point G(2, 31) as the generator and got all valid points. I printed them out and stuck the paper on my wall. When working from home, I often glance at it looking for something interesting.
5 Reply Quote Share
Posts: 23 · Reputation: 204
#2Jan 19, 2022, 12:35 PM
That's cool! So every Y has 3 corresponding X values, right? And if you check G for those points, you get a lot of connections. Pretty neat how this can apply to the usual secp256k1 that Bitcoin uses.
0 Reply Quote Share
5am23Member
Posts: 17 · Reputation: 44
#3Jan 20, 2022, 09:10 PM
Yeah, exactly! Using the cube root of unity, each Y indeed has 3 X values (those are endomorphism points), and each X has 2 Y values (symmetry points). It's all interlinked and used in various tools for faster scanning, like VanitySearch.
4 Reply Quote Share
Posts: 18 · Reputation: 209
#4Jan 20, 2022, 10:12 PM
I’m curious, how did you come up with G = (2, 31) for this curve? Is there some theorem that helps with this kind of setup?
3 Reply Quote Share
alex.byteLegendary
Posts: 170 · Reputation: 5910
#5Jan 23, 2022, 02:41 AM
Honestly, I just messed around with some prime numbers and values. I ended up finding that if you add all X values of the points and take mod p, it goes to 0.
4 Reply Quote Share
Posts: 5 · Reputation: 30
#6Jan 23, 2022, 02:54 AM
Interesting! Like, if you use P=97, you get n=79? And then for Gx points, you can get some cool results too?
1 Reply Quote Share
Posts: 18 · Reputation: 209
#7Jan 23, 2022, 06:08 AM
Exactly! I used G=(1, 69) and found that if I added the valid points, it cycles back to 0 when you mod it. Kinda funky, right? Maybe there's something useful here.
5 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#8Jan 23, 2022, 08:01 AM
What’s the smallest example you’ve tried? I’ve been playing around with a curve p=7, n=13, and it’s wild how it rotates, plus that 13th point at infinity.
1 Reply Quote Share
Posts: 18 · Reputation: 209
#9Jan 23, 2022, 09:16 AM
Smallest I've got is with p=7 and G=(1, 1). Just brute-forced some X values to get valid points. Then I saw that if (n-1) mod 6 = 0, it mirrors the bigger secp256k1.
2 Reply Quote Share
boss2009Newbie
Posts: 20 · Reputation: 15
#10Jan 23, 2022, 12:01 PM
Nice! So you’re saying the properties can be scaled? How do you ensure the points are all valid for that kind of construction?
3 Reply Quote Share
RogueProtoFull Member
Posts: 4 · Reputation: 526
#11Jan 23, 2022, 06:18 PM
I used a site that lets you input random p-prime numbers and find valid points. If you follow the rule for (n-1) mod 6, you get those sets of Y values.
2 Reply Quote Share
0xWizardMember
Posts: 37 · Reputation: 224
#12Jan 24, 2022, 09:32 AM
Endomorphism is the key here! You can generate multiple public keys from one point using some constants. Got a script that does it all in one go.
0 Reply Quote Share
tonyc0br4Member
Posts: 4 · Reputation: 160
#13Jan 24, 2022, 10:14 AM
Please share that script! I’d love to see how it works. The way you’ve described it sounds super useful.
4 Reply Quote Share
0xWizardMember
Posts: 37 · Reputation: 224
#14Jan 24, 2022, 11:38 AM
Sure, here’s a snippet: from ecdsa.ellipticcurve import Point from ecdsa.curves import SECP256k1 # Secp256k1 parameters curve = SECP256k1.curve p = curve.p() n = SECP256k1.order G = SECP256k1.generator # Endomorphism constants beta =... lmbda =... # Function to apply endomorphism Let me know if you want the full code!
4 Reply Quote Share
Posts: 3523 · Reputation: 35
#15Jan 24, 2022, 02:36 PM
Thanks for sharing! This is great info. I think I’ll play around with it a bit more. Curious to see what else can come from this smaller secp256k1.
0 Reply Quote Share

Related topics