snarkvm_circuit_program/data/record/serial_number.rs
1// Copyright (c) 2019-2025 Provable Inc.
2// This file is part of the snarkVM library.
3
4// Licensed under the Apache License, Version 2.0 (the "License");
5// you may not use this file except in compliance with the License.
6// You may obtain a copy of the License at:
7
8// http://www.apache.org/licenses/LICENSE-2.0
9
10// Unless required by applicable law or agreed to in writing, software
11// distributed under the License is distributed on an "AS IS" BASIS,
12// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13// See the License for the specific language governing permissions and
14// limitations under the License.
15
16use super::*;
17
18impl<A: Aleo, Private: Visibility<A>> Record<A, Private> {
19 /// A helper method to derive the serial number from the private key and commitment.
20 pub fn serial_number(private_key: PrivateKey<A>, commitment: Field<A>) -> Field<A> {
21 // Compute the generator `H` as `HashToGroup(commitment)`.
22 let h = A::hash_to_group_psd2(&[A::serial_number_domain(), commitment.clone()]);
23 // Compute `gamma` as `sk_sig * H`.
24 let gamma = h * private_key.sk_sig();
25 // Compute the serial number from `gamma`.
26 Self::serial_number_from_gamma(&gamma, commitment)
27 }
28
29 /// A helper method to derive the serial number from the gamma and commitment.
30 pub fn serial_number_from_gamma(gamma: &Group<A>, commitment: Field<A>) -> Field<A> {
31 // Compute `sn_nonce` as `Hash(COFACTOR * gamma)`.
32 let sn_nonce = A::hash_to_scalar_psd2(&[A::serial_number_domain(), gamma.mul_by_cofactor().to_x_coordinate()]);
33 // Compute `serial_number` as `Commit(commitment, sn_nonce)`.
34 A::commit_bhp512(&(A::serial_number_domain(), commitment).to_bits_le(), &sn_nonce)
35 }
36}