[{"data":1,"prerenderedAt":529},["ShallowReactive",2],{"navigation_docs":3,"-math-groups":44,"-math-groups-surround":524},[4,24],{"title":5,"path":6,"stem":7,"children":8,"icon":23},"Guide","\u002Fguide","1.guide\u002F01.index",[9,11,15,19],{"title":10,"path":6,"stem":7},"Getting started",{"title":12,"path":13,"stem":14},"CLI","\u002Fguide\u002Fcli","1.guide\u002F02.cli",{"title":16,"path":17,"stem":18},"Agents","\u002Fguide\u002Fagents","1.guide\u002F03.agents",{"title":20,"path":21,"stem":22},"Playground","\u002Fguide\u002Fplayground","1.guide\u002F04.playground","i-lucide-book-open",{"title":25,"path":26,"stem":27,"children":28,"icon":43},"Math","\u002Fmath","2.math\u002F00.index",[29,31,35,39],{"title":30,"path":26,"stem":27},"Overview",{"title":32,"path":33,"stem":34},"Curves and points","\u002Fmath\u002Fcurves","2.math\u002F01.curves",{"title":36,"path":37,"stem":38},"Orders and logs","\u002Fmath\u002Fgroups","2.math\u002F02.groups",{"title":40,"path":41,"stem":42},"secp256k1","\u002Fmath\u002Fsecp256k1","2.math\u002F03.secp256k1","i-lucide-sigma",{"id":45,"title":36,"body":46,"description":517,"extension":518,"links":519,"meta":520,"navigation":92,"path":37,"seo":522,"stem":38,"__hash__":523},"docs\u002F2.math\u002F02.groups.md",{"type":47,"value":48,"toc":511},"minimark",[49,54,154,163,170,218,221,225,266,269,320,323,327,377,388,395,403,407,410,495,498,504,507],[50,51,53],"h2",{"id":52},"how-many-points","How many points?",[55,56,61],"pre",{"className":57,"code":58,"language":59,"meta":60,"style":60},"language-ts shiki shiki-themes compressions compressions compressions","import { countPoints, defineCurve, listPoints } from \"@agntn\u002Fcurves\";\n\nconst curve = defineCurve({ a: 2n, b: 2n, p: 17n });\ncountPoints(curve); \u002F\u002F 19n\nlistPoints(curve, { limit: 3 }); \u002F\u002F [{ x: 0n, y: 6n }, { x: 0n, y: 11n }, { x: 3n, y: 1n }]\n","ts","",[62,63,64,87,94,129,142],"code",{"__ignoreMap":60},[65,66,69,73,77,80,84],"span",{"class":67,"line":68},"line",1,[65,70,72],{"class":71},"skH_V","import",[65,74,76],{"class":75},"s38Sx"," { countPoints, defineCurve, listPoints } ",[65,78,79],{"class":71},"from",[65,81,83],{"class":82},"shU9J"," \"@agntn\u002Fcurves\"",[65,85,86],{"class":75},";\n",[65,88,90],{"class":67,"line":89},2,[65,91,93],{"emptyLinePlaceholder":92},true,"\n",[65,95,97,100,103,106,110,113,116,119,121,124,126],{"class":67,"line":96},3,[65,98,99],{"class":71},"const",[65,101,102],{"class":75}," curve ",[65,104,105],{"class":71},"=",[65,107,109],{"class":108},"sK71F"," defineCurve",[65,111,112],{"class":75},"({ a: 2",[65,114,115],{"class":71},"n",[65,117,118],{"class":75},", b: 2",[65,120,115],{"class":71},[65,122,123],{"class":75},", p: 17",[65,125,115],{"class":71},[65,127,128],{"class":75}," });\n",[65,130,132,135,138],{"class":67,"line":131},4,[65,133,134],{"class":108},"countPoints",[65,136,137],{"class":75},"(curve); ",[65,139,141],{"class":140},"scIB-","\u002F\u002F 19n\n",[65,143,145,148,151],{"class":67,"line":144},5,[65,146,147],{"class":108},"listPoints",[65,149,150],{"class":75},"(curve, { limit: 3 }); ",[65,152,153],{"class":140},"\u002F\u002F [{ x: 0n, y: 6n }, { x: 0n, y: 11n }, { x: 3n, y: 1n }]\n",[155,156,157,159,160,162],"p",{},[62,158,134],{}," counts infinity too, so it gives the group order. ",[62,161,147],{}," leaves infinity out and goes by x, then y. It walks every x once, which is why p has a ceiling.",[155,164,165,166,169],{},"Want only the points of one order? Pass ",[62,167,168],{},"order",":",[55,171,173],{"className":57,"code":172,"language":59,"meta":60,"style":60},"const f23 = defineCurve({ a: 1n, b: 1n, p: 23n });\nlistPoints(f23, { order: 7n }); \u002F\u002F six points, (5, 4) to (17, 20)\n",[62,174,175,203],{"__ignoreMap":60},[65,176,177,179,182,184,186,189,191,194,196,199,201],{"class":67,"line":68},[65,178,99],{"class":71},[65,180,181],{"class":75}," f23 ",[65,183,105],{"class":71},[65,185,109],{"class":108},[65,187,188],{"class":75},"({ a: 1",[65,190,115],{"class":71},[65,192,193],{"class":75},", b: 1",[65,195,115],{"class":71},[65,197,198],{"class":75},", p: 23",[65,200,115],{"class":71},[65,202,128],{"class":75},[65,204,205,207,210,212,215],{"class":67,"line":89},[65,206,147],{"class":108},[65,208,209],{"class":75},"(f23, { order: 7",[65,211,115],{"class":71},[65,213,214],{"class":75}," }); ",[65,216,217],{"class":140},"\u002F\u002F six points, (5, 4) to (17, 20)\n",[155,219,220],{},"An order that doesn't divide the group order gives an empty list without multiplying a single point.",[50,222,224],{"id":223},"the-order-of-a-point","The order of a point",[55,226,228],{"className":57,"code":227,"language":59,"meta":60,"style":60},"import { pointOrder } from \"@agntn\u002Fcurves\";\n\npointOrder(curve, { x: 5n, y: 1n }); \u002F\u002F 19n\n",[62,229,230,243,247],{"__ignoreMap":60},[65,231,232,234,237,239,241],{"class":67,"line":68},[65,233,72],{"class":71},[65,235,236],{"class":75}," { pointOrder } ",[65,238,79],{"class":71},[65,240,83],{"class":82},[65,242,86],{"class":75},[65,244,245],{"class":67,"line":89},[65,246,93],{"emptyLinePlaceholder":92},[65,248,249,252,255,257,260,262,264],{"class":67,"line":96},[65,250,251],{"class":108},"pointOrder",[65,253,254],{"class":75},"(curve, { x: 5",[65,256,115],{"class":71},[65,258,259],{"class":75},", y: 1",[65,261,115],{"class":71},[65,263,214],{"class":75},[65,265,141],{"class":140},[155,267,268],{},"That's the smallest n with n times the point at infinity. Baby step giant step finds it inside the Hasse interval. The prime factors of that number trim it down. So it works far past what a walk could count:",[55,270,272],{"className":57,"code":271,"language":59,"meta":60,"style":60},"const wide = defineCurve({ a: 2n, b: 3n, p: 1099511627563n });\npointOrder(wide, { x: 1n, y: 727918651225n }); \u002F\u002F 1099513053442n\n",[62,273,274,301],{"__ignoreMap":60},[65,275,276,278,281,283,285,287,289,292,294,297,299],{"class":67,"line":68},[65,277,99],{"class":71},[65,279,280],{"class":75}," wide ",[65,282,105],{"class":71},[65,284,109],{"class":108},[65,286,112],{"class":75},[65,288,115],{"class":71},[65,290,291],{"class":75},", b: 3",[65,293,115],{"class":71},[65,295,296],{"class":75},", p: 1099511627563",[65,298,115],{"class":71},[65,300,128],{"class":75},[65,302,303,305,308,310,313,315,317],{"class":67,"line":89},[65,304,251],{"class":108},[65,306,307],{"class":75},"(wide, { x: 1",[65,309,115],{"class":71},[65,311,312],{"class":75},", y: 727918651225",[65,314,115],{"class":71},[65,316,214],{"class":75},[65,318,319],{"class":140},"\u002F\u002F 1099513053442n\n",[155,321,322],{},"A 40 bit field, a few milliseconds.",[50,324,326],{"id":325},"discrete-logs","Discrete logs",[55,328,330],{"className":57,"code":329,"language":59,"meta":60,"style":60},"import { discreteLog } from \"@agntn\u002Fcurves\";\n\ndiscreteLog(curve, { x: 5n, y: 1n }, { x: 16n, y: 4n }); \u002F\u002F 13n\n",[62,331,332,345,349],{"__ignoreMap":60},[65,333,334,336,339,341,343],{"class":67,"line":68},[65,335,72],{"class":71},[65,337,338],{"class":75}," { discreteLog } ",[65,340,79],{"class":71},[65,342,83],{"class":82},[65,344,86],{"class":75},[65,346,347],{"class":67,"line":89},[65,348,93],{"emptyLinePlaceholder":92},[65,350,351,354,356,358,360,362,365,367,370,372,374],{"class":67,"line":96},[65,352,353],{"class":108},"discreteLog",[65,355,254],{"class":75},[65,357,115],{"class":71},[65,359,259],{"class":75},[65,361,115],{"class":71},[65,363,364],{"class":75}," }, { x: 16",[65,366,115],{"class":71},[65,368,369],{"class":75},", y: 4",[65,371,115],{"class":71},[65,373,214],{"class":75},[65,375,376],{"class":140},"\u002F\u002F 13n\n",[155,378,379,380,383,384,387],{},"You get the smallest k below the order of the base with k times base equal to the target. No such k? You get ",[62,381,382],{},"undefined",", never a guess. In ",[62,385,386],{},"f23",", the point (4, 0) has order 2, and no multiple of a point of order 7 ever lands on it.",[155,389,390,391,394],{},"Over MCP, ",[62,392,393],{},"log"," also names the order it searched in, so a model knows what \"smallest\" meant:",[55,396,401],{"className":397,"code":399,"language":400,"meta":60},[398],"language-text","{\"operation\":\"log\",\"order\":\"19\",\"scalar\":\"13\"}\n","text",[62,402,399],{"__ignoreMap":60},[50,404,406],{"id":405},"limits","Limits",[155,408,409],{},"Each of these stops at a limit instead of running for ever. The numbers are exported, so you can check before you call.",[411,412,413,429],"table",{},[414,415,416],"thead",{},[417,418,419,423,426],"tr",{},[420,421,422],"th",{},"Function",[420,424,425],{},"Takes",[420,427,428],{},"Constant",[430,431,432,450,467,481],"tbody",{},[417,433,434,442,445],{},[435,436,437,439,440],"td",{},[62,438,134],{},", ",[62,441,147],{},[435,443,444],{},"p up to 2^20",[435,446,447],{},[62,448,449],{},"MAX_COUNTED_PRIME",[417,451,452,459,462],{},[435,453,454,456,457],{},[62,455,147],{}," with ",[62,458,168],{},[435,460,461],{},"p up to 2^16",[435,463,464],{},[62,465,466],{},"MAX_FILTERED_PRIME",[417,468,469,473,476],{},[435,470,471],{},[62,472,251],{},[435,474,475],{},"p up to 2^48",[435,477,478],{},[62,479,480],{},"MAX_ORDER_PRIME",[417,482,483,487,490],{},[435,484,485],{},[62,486,353],{},[435,488,489],{},"a base of order up to 2^36",[435,491,492],{},[62,493,494],{},"MAX_LOG_ORDER",[155,496,497],{},"Past one, the error says which:",[55,499,502],{"className":500,"code":501,"language":400,"meta":60},[398],"Counting and listing points takes p up to 1048576\nThe base has order 1099513053442, above the 68719476736 a search takes\n",[62,503,501],{"__ignoreMap":60},[155,505,506],{},"A log for a base of order near 2^36 takes under half a second. A real 256 bit curve? Nobody's search takes that, which is the whole point of elliptic curve cryptography.",[508,509,510],"style",{},"html pre.shiki code .skH_V, html code.shiki .skH_V{--shiki-light:var(--shiki-token-keyword);--shiki-default:var(--shiki-token-keyword);--shiki-dark:var(--shiki-token-keyword)}html pre.shiki code .s38Sx, html code.shiki .s38Sx{--shiki-light:var(--ui-text-highlighted);--shiki-default:var(--ui-text-highlighted);--shiki-dark:var(--ui-text-highlighted)}html pre.shiki code .shU9J, html code.shiki .shU9J{--shiki-light:var(--shiki-token-string);--shiki-default:var(--shiki-token-string);--shiki-dark:var(--shiki-token-string)}html pre.shiki code .sK71F, html code.shiki .sK71F{--shiki-light:var(--shiki-token-function);--shiki-default:var(--shiki-token-function);--shiki-dark:var(--shiki-token-function)}html pre.shiki code .scIB-, html code.shiki .scIB-{--shiki-light:var(--shiki-token-comment);--shiki-default:var(--shiki-token-comment);--shiki-dark:var(--shiki-token-comment)}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":60,"searchDepth":89,"depth":89,"links":512},[513,514,515,516],{"id":52,"depth":89,"text":53},{"id":223,"depth":89,"text":224},{"id":325,"depth":89,"text":326},{"id":405,"depth":89,"text":406},"Count and list the points of a curve and find the order of a point and a discrete log by baby step giant step","md",null,{"icon":521},"i-lucide-target",{"title":36,"description":517},"C7YozHcWPba8rIMbH5yZh6LbonELC_C6QZzB92ckIiE",[525,527],{"title":32,"path":33,"stem":34,"description":526,"children":-1},"Define a short Weierstrass curve over a prime and add and double and negate and multiply its points",{"title":40,"path":41,"stem":42,"description":528,"children":-1},"Points of secp256k1 as SEC1 hex and scalars mod n. Add and subtract and multiply and lift an x coordinate",1791293523357]