Testing a Compact Version of secp256k1

15 replies 505 views
Posts: 18 · Reputation: 209
#1Jan 19, 2022, 11:37 AM
Just getting into this stuff, so bear with me. I made a smaller secp256k1 with p=43, n=31. Took point G(2, 31) as the generator and got all valid points. I printed them out and stuck the paper on my wall. When working from home, I often glance at it looking for something interesting.
13 Reply Quote Share
Posts: 23 · Reputation: 204
#2Jan 19, 2022, 12:35 PM
That's cool! So every Y has 3 corresponding X values, right? And if you check G for those points, you get a lot of connections. Pretty neat how this can apply to the usual secp256k1 that Bitcoin uses.
5 Reply Quote Share
5am23Member
Posts: 17 · Reputation: 44
#3Jan 20, 2022, 09:10 PM
Yeah, exactly! Using the cube root of unity, each Y indeed has 3 X values (those are endomorphism points), and each X has 2 Y values (symmetry points). It's all interlinked and used in various tools for faster scanning, like VanitySearch.
6 Reply Quote Share
Posts: 18 · Reputation: 209
#4Jan 20, 2022, 10:12 PM
I’m curious, how did you come up with G = (2, 31) for this curve? Is there some theorem that helps with this kind of setup?
8 Reply Quote Share
alex.byteLegendary
Posts: 182 · Reputation: 5910
#5Jan 23, 2022, 02:41 AM
Honestly, I just messed around with some prime numbers and values. I ended up finding that if you add all X values of the points and take mod p, it goes to 0.
10 Reply Quote Share
Posts: 5 · Reputation: 30
#6Jan 23, 2022, 02:54 AM
Interesting! Like, if you use P=97, you get n=79? And then for Gx points, you can get some cool results too?
3 Reply Quote Share
Posts: 18 · Reputation: 209
#7Jan 23, 2022, 06:08 AM
Exactly! I used G=(1, 69) and found that if I added the valid points, it cycles back to 0 when you mod it. Kinda funky, right? Maybe there's something useful here.
7 Reply Quote Share
0xNodeMember
Posts: 680 · Reputation: 80
#8Jan 23, 2022, 08:01 AM
What’s the smallest example you’ve tried? I’ve been playing around with a curve p=7, n=13, and it’s wild how it rotates, plus that 13th point at infinity.
3 Reply Quote Share
Posts: 18 · Reputation: 209
#9Jan 23, 2022, 09:16 AM
Smallest I've got is with p=7 and G=(1, 1). Just brute-forced some X values to get valid points. Then I saw that if (n-1) mod 6 = 0, it mirrors the bigger secp256k1.
8 Reply Quote Share
boss2009Newbie
Posts: 20 · Reputation: 15
#10Jan 23, 2022, 12:01 PM
Nice! So you’re saying the properties can be scaled? How do you ensure the points are all valid for that kind of construction?
7 Reply Quote Share
RogueProtoFull Member
Posts: 4 · Reputation: 526
#11Jan 23, 2022, 06:18 PM
I used a site that lets you input random p-prime numbers and find valid points. If you follow the rule for (n-1) mod 6, you get those sets of Y values.
9 Reply Quote Share
0xWizardMember
Posts: 37 · Reputation: 224
#12Jan 24, 2022, 09:32 AM
Endomorphism is the key here! You can generate multiple public keys from one point using some constants. Got a script that does it all in one go.
5 Reply Quote Share
tonyc0br4Member
Posts: 4 · Reputation: 160
#13Jan 24, 2022, 10:14 AM
Please share that script! I’d love to see how it works. The way you’ve described it sounds super useful.
11 Reply Quote Share
0xWizardMember
Posts: 37 · Reputation: 224
#14Jan 24, 2022, 11:38 AM
Sure, here’s a snippet: from ecdsa.ellipticcurve import Point from ecdsa.curves import SECP256k1 # Secp256k1 parameters curve = SECP256k1.curve p = curve.p() n = SECP256k1.order G = SECP256k1.generator # Endomorphism constants beta =... lmbda =... # Function to apply endomorphism Let me know if you want the full code!
4 Reply Quote Share
Posts: 3546 · Reputation: 35
#15Jan 24, 2022, 02:36 PM
Thanks for sharing! This is great info. I think I’ll play around with it a bit more. Curious to see what else can come from this smaller secp256k1.
2 Reply Quote Share
Posts: 2 · Reputation: 37
#16Jan 24, 2022, 03:19 PM
idk if scaling down secp256k1 this way really reflects how it works at full scale tho... smaller primes might miss some edge cases or weird behaviors. still cool to experiment but gotta be careful with what conclusions you draw
9 Reply Quote Share

Related topics