diff options
author | kallewoof <karljohan-alm@garage.co.jp> | 2022-01-03 10:11:03 +0900 |
---|---|---|
committer | GitHub <noreply@github.com> | 2022-01-03 10:11:03 +0900 |
commit | a3a397c82384220fc871852c809f73898a4d547c (patch) | |
tree | d3c6f9b2ba3e30a6e74130ee09074932417cb720 | |
parent | 4c6389f8431f677847b115538a47ce8c826c6be8 (diff) | |
parent | d07e499d3f0768158b096ce30a07233fc665e5d3 (diff) | |
download | bips-a3a397c82384220fc871852c809f73898a4d547c.tar.xz |
Merge pull request #1245 from Mironenko/patch-1
Fix typo in BIP-32
-rw-r--r-- | bip-0032.mediawiki | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/bip-0032.mediawiki b/bip-0032.mediawiki index ee09b68..b441658 100644 --- a/bip-0032.mediawiki +++ b/bip-0032.mediawiki @@ -201,7 +201,7 @@ In addition to the expectations from the EC public-key cryptography itself: the intended security properties of this standard are: * Given a child extended private key (k<sub>i</sub>,c<sub>i</sub>) and the integer i, an attacker cannot find the parent private key k<sub>par</sub> more efficiently than a 2<sup>256</sup> brute force of HMAC-SHA512. * Given any number (2 ≤ N ≤ 2<sup>32</sup>-1) of (index, extended private key) tuples (i<sub>j</sub>,(k<sub>i<sub>j</sub></sub>,c<sub>i<sub>j</sub></sub>)), with distinct i<sub>j</sub>'s, determining whether they are derived from a common parent extended private key (i.e., whether there exists a (k<sub>par</sub>,c<sub>par</sub>) such that for each j in (0..N-1) CKDpriv((k<sub>par</sub>,c<sub>par</sub>),i<sub>j</sub>)=(k<sub>i<sub>j</sub></sub>,c<sub>i<sub>j</sub></sub>)), cannot be done more efficiently than a 2<sup>256</sup> brute force of HMAC-SHA512. -Note however that the following properties does not exist: +Note however that the following properties do not exist: * Given a parent extended public key (K<sub>par</sub>,c<sub>par</sub>) and a child public key (K<sub>i</sub>), it is hard to find i. * Given a parent extended public key (K<sub>par</sub>,c<sub>par</sub>) and a non-hardened child private key (k<sub>i</sub>), it is hard to find k<sub>par</sub>. |