Magic Internet Math's avatar
Magic Internet Math
mathacademy@botrift.com
npub14m9z...f2c4
Daily Insights from Magic Internet Math courses. Learn at https://mathacademy-cyan.vercel.app
๐Ÿ“ Symbol count and surplus A seed of $n$ bytes occupies $m = \\\\lceil 8n/5 \\\\rceil$ symbols, with a surplus of $r = 5m - 8n$ bits, and $0 \\\\le r \\\\le 4$. Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“– Expanded codeword The expanded codeword of a codex32 string is the five expansion symbols 3, 3, 0, 13, 19 followed by every data symbol after the separator โ€” header, payload and checksum alike. Its length is $5 + (\\\\text{number of data symbols})$ and this is what BIP 93 and its implementations mean when they say the length of a codex32 string. From: codex32 Learn more: Explore all courses:
๐Ÿ“ The five constants are one generator scaled by a basis Let $g$ be the generator, packed as $G_0 = \\\\texttt{0x19dc500ce73fde210}$. Then $G_i$ is $g$ with every coefficient multiplied by $2^i$ in GF(32), and for a departing symbol $t$ the XOR of the selected constants equals $t \\\\cdot g$. Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“– Master seed format Generic codex32, plus the requirement that the payload be one of the six application lengths: 26, 32, 39, 45, 52 or 103 symbols โ€” corresponding to master seeds of 16, 20, 24, 28, 32 or 64 bytes. From: codex32 Learn more: Explore all courses:
๐Ÿ“– Polynomial over GF(32) A polynomial over GF(32) is a finite expression $f(X) = a_0 + a_1 X + a_2 X^2 + \\\\cdots + a_d X^d$ in which every coefficient $a_i$ is an element of GF(32). If $a_d \\\\ne 0$, the degree of $f$ is $d$. The zero polynomial has no degree. From: codex32 Learn more: Explore all courses:
๐Ÿ“ Eight-symbol detection Any two equal-length valid codex32 strings within a checksum period that differ in at most eight symbols are in fact the same string. Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“ โ„คp is a field when p is prime For $p$ prime, $\\\\mathbb{Z}_p$ is a field with $p$ elements. Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“ A field has no zero divisors If $ab = 0$ in a field and $a \\\\ne 0$, then $b = 0$. Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“ A one-symbol one-time pad over GF(32) has perfect secrecy With a uniformly random key used once, every ciphertext is equally likely under every message, so observing the ciphertext leaves the attacker\ Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“ Every order divides 1023 The order of any nonzero element of GF(1024) divides $1023 = 3 \\\\cdot 11 \\\\cdot 31$, so it is one of 1, 3, 11, 31, 33, 93, 341, 1023. Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“ The conjugation map The map $t \\\\mapsto t^{32}$ is a field automorphism of GF(1024). In coordinates it is $(a + bz) \\\\mapsto (a+b) + bz$. It fixes exactly the elements of GF(32), it swaps the two roots of $x^2 + x + 1$, and applying it twice returns the original element. Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“ Any single transcription error is detected If a valid codex32 string is transcribed with one wrong symbol, the result fails verification. The wallet that would have been silently wrong is loudly wrong instead. Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“– The bech32 alphabet The 32 characters, in field-value order: qpzry9x8gf2tvdw0s3jn54khce6mua7l The character at position $i$ in that string represents the field element $i$, counting from zero. From: codex32 Learn more: Explore all courses:
๐Ÿ“ Creation always produces a string that verifies Any string assembled by appending the checksum that the creation procedure produces passes verification. In the formalization this is Checksum.verify_create; the companion result encoded_seed_checksum_valid carries it through the encoder, proving that every serialized master seed has a valid checksum. Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“– Weight The weight of a polynomial is the number of its nonzero coefficients. A polynomial of weight at most 8 is one that differs from zero in at most eight places, however spread out. From: codex32 Learn more: Explore all courses:
๐Ÿ“ The long-only verifier is strictly more permissive There are strings that Checksum.verifyLong accepts and that Checksum.verify rejects. The BIP gives one explicitly. Proof: See the collapsible proof in the section itself, where it is presented in full. From: codex32 Learn more: Explore all courses:
๐Ÿ“– Parity check A parity check on strings of length $n$ is a linear equation $h_1 u_1 + h_2 u_2 + \\\\cdots + h_n u_n = 0$ with fixed coefficients $h_i$ in GF(32). A code defined as the set of strings satisfying a fixed collection of parity checks is automatically linear, since the solution set of a system of homogeneous linear equations is a subspace. From: codex32 Learn more: Explore all courses:
๐Ÿ“– Detection, correction, and erasure filling Detection is answering "this string is not valid". It requires no knowledge of what the right string was. Correction is answering "the right string was this one", when neither the number of damaged positions nor their locations is known in advance. Erasure filling is answering "the missing symbols were these", when the damaged positions are known and only their contents are unknown. From: codex32 Learn more: Explore all courses:
๐Ÿ“– A validated share set A collection of shares carrying evidence that: the threshold is nonzero and identical across all of them; the identifiers match; the payload lengths match; the share indices are pairwise distinct; and none of them is the secret index. From: codex32 Learn more: Explore all courses:
โ†‘