2014-07-10 08:39:09 -07:00
|
|
|
var coinUtil = require('../util');
|
|
|
|
var sjcl = require('./sjcl');
|
2014-06-20 19:09:21 -07:00
|
|
|
var SecureRandom = require('./SecureRandom');
|
|
|
|
|
2014-06-23 10:57:02 -07:00
|
|
|
var hmacSHA512 = function(key) {
|
2014-06-20 19:09:21 -07:00
|
|
|
var hasher = new sjcl.misc.hmac(key, sjcl.hash.sha512);
|
2014-06-23 10:57:02 -07:00
|
|
|
this.encrypt = function() {
|
|
|
|
return hasher.encrypt.apply(hasher, arguments);
|
2014-06-20 19:09:21 -07:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
var pbkdf2Sync_sha512 = function(password, salt, iterations, keylen) {
|
|
|
|
var derivedKey = sjcl.misc.pbkdf2(password, salt, iterations, 512, hmacSHA512);
|
|
|
|
return sjcl.codec.hex.fromBits(derivedKey)
|
|
|
|
};
|
|
|
|
|
2014-06-23 10:57:02 -07:00
|
|
|
var BIP39 = function() {};
|
2014-04-14 07:42:23 -07:00
|
|
|
|
|
|
|
BIP39.mnemonic = function(wordlist, bits) {
|
|
|
|
if (!bits)
|
|
|
|
bits = 128;
|
|
|
|
if (bits % 32 != 0)
|
|
|
|
throw new Error("bits must be multiple of 32");
|
2014-06-20 19:09:21 -07:00
|
|
|
var buf = SecureRandom.getRandomBuffer(bits / 8);
|
|
|
|
return BIP39.entropy2mnemonic(wordlist, buf);
|
2014-04-14 07:42:23 -07:00
|
|
|
}
|
|
|
|
|
2014-06-20 19:09:21 -07:00
|
|
|
BIP39.entropy2mnemonic = function(wordlist, buf) {
|
|
|
|
var hash = coinUtil.sha256(buf);
|
2014-04-14 07:42:23 -07:00
|
|
|
var bin = "";
|
2014-06-20 19:09:21 -07:00
|
|
|
var bits = buf.length * 8;
|
2014-06-23 10:57:02 -07:00
|
|
|
for (var i = 0; i < buf.length; i++) {
|
2014-06-20 19:09:21 -07:00
|
|
|
bin = bin + ("00000000" + buf[i].toString(2)).slice(-8);
|
2014-04-14 07:42:23 -07:00
|
|
|
}
|
|
|
|
var hashbits = hash[0].toString(2);
|
2014-06-23 10:57:02 -07:00
|
|
|
hashbits = ("00000000" + hashbits).slice(-8).slice(0, bits / 32);
|
2014-04-14 07:42:23 -07:00
|
|
|
bin = bin + hashbits;
|
|
|
|
if (bin.length % 11 != 0)
|
2014-06-20 19:09:21 -07:00
|
|
|
throw new Error("internal error - entropy not an even multiple of 11 bits - " + bin.length);
|
2014-04-14 07:42:23 -07:00
|
|
|
var mnemonic = "";
|
2014-06-20 19:09:21 -07:00
|
|
|
for (var i = 0; i < bin.length / 11; i++) {
|
2014-04-14 07:42:23 -07:00
|
|
|
if (mnemonic != "")
|
|
|
|
mnemonic = mnemonic + " ";
|
2014-06-23 10:57:02 -07:00
|
|
|
var wi = parseInt(bin.slice(i * 11, (i + 1) * 11), 2);
|
2014-04-14 07:42:23 -07:00
|
|
|
mnemonic = mnemonic + wordlist[wi];
|
|
|
|
}
|
|
|
|
return mnemonic;
|
|
|
|
}
|
|
|
|
|
2014-07-01 13:56:07 -07:00
|
|
|
BIP39.check = function(wordlist, mnemonic) {
|
|
|
|
var words = mnemonic.split(' ');
|
|
|
|
var bin = "";
|
|
|
|
for (var i = 0; i < words.length; i++) {
|
|
|
|
var ind = wordlist.indexOf(words[i]);
|
|
|
|
if (ind < 0)
|
|
|
|
return false;
|
|
|
|
bin = bin + ("00000000000" + ind.toString(2)).slice(-11);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (bin.length % 11 != 0) {
|
|
|
|
throw new Error("internal error - entropy not an even multiple of 11 bits - " + bin.length);
|
|
|
|
}
|
|
|
|
var cs = bin.length / 33;
|
|
|
|
var hash_bits = bin.slice(-cs);
|
|
|
|
var nonhash_bits = bin.slice(0, bin.length - cs);
|
|
|
|
var buf = new Buffer(nonhash_bits.length / 8);
|
|
|
|
for (var i = 0; i < nonhash_bits.length / 8; i++) {
|
|
|
|
buf.writeUInt8(parseInt(bin.slice(i * 8, (i + 1) * 8), 2), i);
|
|
|
|
}
|
|
|
|
var hash = coinUtil.sha256(buf);
|
|
|
|
var expected_hash_bits = hash[0].toString(2);
|
|
|
|
expected_hash_bits = ("00000000" + expected_hash_bits).slice(-8).slice(0, cs);
|
|
|
|
return expected_hash_bits == hash_bits;
|
|
|
|
}
|
|
|
|
|
2014-06-20 19:09:21 -07:00
|
|
|
BIP39.mnemonic2seed = function(mnemonic, passphrase) {
|
|
|
|
if (!passphrase)
|
|
|
|
passphrase = "";
|
|
|
|
var hex = pbkdf2Sync_sha512(mnemonic, "mnemonic" + passphrase, 2048, 64);
|
|
|
|
var buf = new Buffer(hex, 'hex');
|
|
|
|
return buf;
|
2014-04-14 07:42:23 -07:00
|
|
|
}
|
|
|
|
|
2014-07-10 12:08:42 -07:00
|
|
|
module.exports = BIP39;
|