10.02.2016 Views

Bitcoin and Cryptocurrency Technologies

1Qqc4BN

1Qqc4BN

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The cryptographic magic that makes this useful is that for every ​i​, the ​i​’th address <strong>and</strong> ​i​’th secret key<br />

“match up” — that is, the ​i​’th secret key controls, <strong>and</strong> can be used to spend, bitcoins from the ​i​’th<br />

address just as if the pair were generated the old fashioned way. So it’s as if we have a sequence of<br />

regular key pairs.<br />

The other important cryptographic property here is security: the address generation info doesn't leak<br />

any information about the private keys. That means that it's safe to give the address generation info<br />

to anybody, <strong>and</strong> so that anybody can be enabled to generate the 'i'th key.<br />

Now, not all digital signature schemes that exist can be modified to support hierarchical key<br />

generation. Some can <strong>and</strong> some can't, but the good news is that the digital signature scheme used by<br />

<strong>Bitcoin</strong>, ECDSA, does support hierarchical key generation, allowing this trick. That is, the cold side<br />

generates arbitrarily many keys <strong>and</strong> the hot side generates the corresponding addresses.<br />

Figure 4.2: Schema of a hierarchical wallet​. The cold side creates <strong>and</strong> saves private key generation<br />

info <strong>and</strong> address generation info. It does a one-time transfer of the latter to the hot side. The hot side<br />

generates a new address sequentially every time it wants to send coins to the cold side. When the<br />

cold side reconnects, it generates addresses sequentially <strong>and</strong> checks the block chain for transfers to<br />

those addresses until it reaches an address that hasn’t received any coins. It can also generate private<br />

keys sequentially if it wants to send some coins back to the hot side or spend them some other way.<br />

Here’s how it works. Recall that normally an ECDSA private key is a r<strong>and</strong>om number ​x​<strong>and</strong> the<br />

corresponding public key is ​g​ x​ . For hierarchical key generation, we’ll need two other r<strong>and</strong>om values ​k<br />

<strong>and</strong> ​y​.<br />

105

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!