2014-08-17 01:11:28 +00:00
|
|
|
var assert = require('assert')
|
2014-05-28 15:10:54 +00:00
|
|
|
var CryptoJS = require('crypto-js')
|
2014-05-28 15:10:11 +00:00
|
|
|
var crypto = require('crypto')
|
2014-06-23 07:56:08 +00:00
|
|
|
var secureRandom = require('secure-random')
|
2014-03-10 02:49:53 +00:00
|
|
|
|
2014-07-04 04:33:49 +00:00
|
|
|
var DEFAULT_WORDLIST = require('./wordlists/en.json')
|
2014-06-23 03:40:38 +00:00
|
|
|
|
2014-08-17 00:38:11 +00:00
|
|
|
function mnemonicToSeedHex(mnemonic, password) {
|
2014-08-17 00:37:14 +00:00
|
|
|
var options = { iterations: 2048, hasher: CryptoJS.algo.SHA512, keySize: 512/32 }
|
2014-05-28 15:10:54 +00:00
|
|
|
return CryptoJS.PBKDF2(mnemonic, salt(password), options).toString(CryptoJS.enc.Hex)
|
2014-03-10 02:49:53 +00:00
|
|
|
}
|
|
|
|
|
2014-08-17 01:11:28 +00:00
|
|
|
function mnemonicToEntropy(mnemonic, wordlist) {
|
|
|
|
wordlist = wordlist || DEFAULT_WORDLIST
|
|
|
|
|
|
|
|
var words = mnemonic.split(' ')
|
|
|
|
assert(words.length % 3 === 0, 'Invalid mnemonic')
|
|
|
|
|
|
|
|
var belongToList = words.every(function(word) {
|
|
|
|
return wordlist.indexOf(word) > -1
|
|
|
|
})
|
|
|
|
|
|
|
|
assert(belongToList, 'Invalid mnemonic')
|
|
|
|
|
|
|
|
// convert word indices to 11 bit binary strings
|
|
|
|
var bits = words.map(function(word) {
|
|
|
|
var index = wordlist.indexOf(word)
|
|
|
|
return lpad(index.toString(2), '0', 11)
|
|
|
|
}).join('')
|
|
|
|
|
|
|
|
// split the binary string into ENT/CS
|
|
|
|
var dividerIndex = Math.floor(bits.length / 33) * 32
|
|
|
|
var entropy = bits.slice(0, dividerIndex)
|
|
|
|
var checksum = bits.slice(dividerIndex)
|
|
|
|
|
|
|
|
// calculate the checksum and compare
|
|
|
|
var entropyBytes = entropy.match(/(.{1,8})/g).map(function(bin) {
|
|
|
|
return parseInt(bin, 2)
|
|
|
|
})
|
|
|
|
var entropyBuffer = new Buffer(entropyBytes)
|
|
|
|
var newChecksum = checksumBits(entropyBuffer)
|
|
|
|
|
|
|
|
assert(newChecksum === checksum, 'Invalid mnemonic checksum')
|
|
|
|
|
|
|
|
return entropyBuffer.toString('hex')
|
|
|
|
}
|
|
|
|
|
2014-08-17 00:37:14 +00:00
|
|
|
function entropyToMnemonic(entropy, wordlist) {
|
|
|
|
wordlist = wordlist || DEFAULT_WORDLIST
|
|
|
|
|
2014-05-28 15:10:11 +00:00
|
|
|
var entropyBuffer = new Buffer(entropy, 'hex')
|
2014-06-23 05:49:54 +00:00
|
|
|
var entropyBits = bytesToBinary([].slice.call(entropyBuffer))
|
|
|
|
var checksum = checksumBits(entropyBuffer)
|
2014-03-11 08:01:14 +00:00
|
|
|
|
2014-06-23 05:49:54 +00:00
|
|
|
var bits = entropyBits + checksum
|
|
|
|
var chunks = bits.match(/(.{1,11})/g)
|
2014-03-11 08:01:14 +00:00
|
|
|
|
2014-06-23 05:49:54 +00:00
|
|
|
var words = chunks.map(function(binary) {
|
2014-03-11 08:01:14 +00:00
|
|
|
var index = parseInt(binary, 2)
|
2014-06-23 05:49:54 +00:00
|
|
|
|
2014-08-17 00:37:14 +00:00
|
|
|
return wordlist[index]
|
|
|
|
})
|
2014-06-23 05:49:54 +00:00
|
|
|
|
|
|
|
return words.join(' ')
|
2014-03-11 08:01:14 +00:00
|
|
|
}
|
|
|
|
|
2014-08-17 00:37:14 +00:00
|
|
|
function generateMnemonic(strength, rng, wordlist) {
|
2014-03-31 07:11:03 +00:00
|
|
|
strength = strength || 128
|
2014-06-25 13:47:30 +00:00
|
|
|
rng = rng || secureRandom.randomBuffer
|
2014-06-23 07:56:08 +00:00
|
|
|
|
2014-06-25 13:47:30 +00:00
|
|
|
var hex = rng(strength / 8).toString('hex')
|
2014-08-17 00:37:14 +00:00
|
|
|
return entropyToMnemonic(hex, wordlist)
|
2014-03-31 06:07:34 +00:00
|
|
|
}
|
|
|
|
|
2014-08-17 00:37:14 +00:00
|
|
|
function validateMnemonic(mnemonic, wordlist) {
|
2014-08-17 01:11:28 +00:00
|
|
|
try {
|
|
|
|
mnemonicToEntropy(mnemonic, wordlist)
|
|
|
|
} catch (e) {
|
|
|
|
return false
|
|
|
|
}
|
2014-06-23 05:49:54 +00:00
|
|
|
|
2014-08-17 01:11:28 +00:00
|
|
|
return true
|
2014-06-23 05:49:54 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
function checksumBits(entropyBuffer) {
|
|
|
|
var hash = crypto.createHash('sha256').update(entropyBuffer).digest()
|
|
|
|
|
|
|
|
// Calculated constants from BIP39
|
|
|
|
var ENT = entropyBuffer.length * 8
|
|
|
|
var CS = ENT / 32
|
2014-04-05 04:44:16 +00:00
|
|
|
|
2014-06-23 06:19:32 +00:00
|
|
|
return bytesToBinary([].slice.call(hash)).slice(0, CS)
|
2014-04-05 04:44:16 +00:00
|
|
|
}
|
|
|
|
|
2014-03-10 02:49:53 +00:00
|
|
|
function salt(password) {
|
|
|
|
return encode_utf8('mnemonic' + (password || ''))
|
|
|
|
}
|
|
|
|
|
2014-06-23 03:35:21 +00:00
|
|
|
function encode_utf8(s) {
|
2014-03-10 02:49:53 +00:00
|
|
|
return unescape(encodeURIComponent(s))
|
|
|
|
}
|
2014-03-11 08:01:14 +00:00
|
|
|
|
|
|
|
//=========== helper methods from bitcoinjs-lib ========
|
|
|
|
|
|
|
|
function bytesToBinary(bytes) {
|
|
|
|
return bytes.map(function(x) {
|
|
|
|
return lpad(x.toString(2), '0', 8)
|
|
|
|
}).join('');
|
|
|
|
}
|
|
|
|
|
|
|
|
function lpad(str, padString, length) {
|
|
|
|
while (str.length < length) str = padString + str;
|
|
|
|
return str;
|
|
|
|
}
|
|
|
|
|
2014-08-17 00:37:14 +00:00
|
|
|
module.exports = {
|
2014-08-17 00:38:11 +00:00
|
|
|
mnemonicToSeedHex: mnemonicToSeedHex,
|
2014-08-17 01:11:28 +00:00
|
|
|
mnemonicToEntropy: mnemonicToEntropy,
|
2014-08-17 00:37:14 +00:00
|
|
|
entropyToMnemonic: entropyToMnemonic,
|
|
|
|
generateMnemonic: generateMnemonic,
|
|
|
|
validateMnemonic: validateMnemonic
|
|
|
|
}
|