From 164ea9f0e361af6b1d64a17231a43953406e9011 Mon Sep 17 00:00:00 2001 From: Brandon Black Date: Fri, 22 Dec 2023 22:54:16 -0800 Subject: [PATCH] Add bip-csfs. --- bip-csfs.mediawiki | 90 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 90 insertions(+) create mode 100644 bip-csfs.mediawiki diff --git a/bip-csfs.mediawiki b/bip-csfs.mediawiki new file mode 100644 index 0000000000..526b7730b2 --- /dev/null +++ b/bip-csfs.mediawiki @@ -0,0 +1,90 @@ +
+  BIP: TBD
+  Layer: Consensus (soft fork)
+  Title: CHECKSIGFROMSTACK
+  Author: Brandon Black 
+  Comments-Summary: No comments yet.
+  Status: Draft
+  Type: Standards Track
+  Created: 2023-12-22
+  License: PD
+
+ +==Abstract== + +This BIP describes two new opcode for the purpose of checking cryptographic +signatures in bitcoin scripts against data other than bitcoin transactions. + +==Specification== + +We propose replacing OP_NOP5 in bitcoin script with +'''OP_CHECKSIGFROMSTACKVERIFY'''. When verifying taproot script spends having +leaf version 0xc0 (as defined in BIP342), we propose '''OP_CHECKSIGFROMSTACK''' +to replace '''OP_SUCCESS188''' (0xbc). + +'''OP_CHECKSIGFROMSTACK''' and '''OP_CHECKSIGFROMSTACKVERIFY''' have identical +semantics to '''OP_CHECKSIG''' and '''OP_CHECKSIGVERIFY''' respectively, +except: + +* On success the arguments to '''OP_CHECKSIGFROMSTACKVERIFY''' are left unchanged on the stack. +* They read (or pop, respectively) 3 arguments (rather than 2) from the stack in the following order: ''' lt;datagt; ''' +* Signatures must not have a sighash byte appended +* The message being verified is '''lt;datagt;''' +** '''lt;datagt;''' may be any length. +** For ECDSA signature verification '''lt;datagt;''' is SHA256 hashed before being used as the message. + +==Resource Limits== + +These opcodes are treated identically to other signature checking opcodes and +count against the various sigops limits in their respective script types. + +==Motivation== + +===LN Symmetry=== + +When combined with '''OP_CHECKTEMPLATEVERIFY''' (BIP119/CTV), +'''OP_CHECKSIGFROMSTACK''' (CSFS) can be used in Lightning Symmetry channels. +The construction '''OP_CHECKTEMPLATEVERIFY OP_CHECKSIGFROMSTACK''' is +logically equivalent to ''' OP_CHECKSIG''' and a signature over +'''SIGHASH_ALL|SIGHASH_ANYPREVOUTANYSCRIPT'''. The '''OP_CHECKSIGFROMSTACK''' +construction is 8 vBytes larger. + +===Delegation=== + +Using a script like: +'''OP_DUP OP_CHECKSIGFROMSTACK OP_DROP OP_CHECKSIG''' +A script can delegate signing to another key. + +==Reference Implementation== + +A reference implementation is provided in provided here: + +https://github.com/brandonblack/bitcoin/commit/fd57785b99442df092488135752112586597b756 + +==Backward Compatibility== + +By constraining the behavior of an OP_SUCCESS opcode and an OP_NOP opcode, +deployment of the BIP can be done in a backwards compatible, soft-fork manner. +If anyone were to rely on the OP_SUCCESS behavior of OP_SUCCESS188, +OP_CHECKSIGFROMSTACk would invalidate their spend. + +==Deployment== + +TBD + +==Credits== + +Reference implementation was made with reference to the implementation in +Elements and started by moonsettler. + +==References== + +[https://github.com/bitcoin/bips/blob/master/bip-0119.mediawiki BIP 119] CHECKTEMPLATEVERIFY + +[https://github.com/bitcoin/bips/blob/master/bip-0341.mediawiki BIP 341] Taproot + +[https://github.com/bitcoin/bips/blob/master/bip-0342.mediawiki BIP 342] Tapscript + +==Copyright== + +This document is placed in the public domain.