Cosmos 中的账户采用分层确定性(HD)钱包。HD 钱包最早在比特币的 BIP32 中定义,它是一类特殊的钱包,允许用户从同一个种子派生出任意数量的账户。要理解这意味着什么,先定义一些术语:
- 钱包:由给定种子生成的一组账户。
- 账户:一对公钥/私钥。
- 私钥:私钥是一段用于对消息签名的秘密信息。在区块链语境中,私钥用于标识账户的所有者。用户的私钥绝不能泄露给他人。
- 公钥:公钥是对私钥应用单向数学函数后得到的一段信息。地址可以由公钥派生得到。无法从公钥反推出私钥。
- 地址:地址是一个带有人类可读前缀的公开字符串,用于标识账户。它通过对公钥进行数学变换得到。
- 数字签名:数字签名是一段密码学信息,用于证明某个私钥的持有者在不泄露私钥的前提下认可了一条特定消息。
- 种子:与助记词相同。
- 助记词:助记词是一串单词,用作派生私钥的种子。助记词是每个钱包的核心。千万不要丢失你的助记词。请把它写在纸上,并保存在安全的地方。一旦丢失,将无法恢复。如果有人获得了它,就等于获得了所有关联账户的访问权限。
HD 钱包的核心是一个种子。用户可以从这个种子中确定性地生成账户。要从种子生成账户,需要应用单向数学变换。要决定生成哪个账户,用户需要指定一个 path,通常是一个 integer(0、1、2,……)。
例如,将 path 指定为 0 时,钱包会从种子生成 Private Key 0。然后,可以由 Private Key 0 生成 Public Key 0。最后,可以由 Public Key 0 生成 Address 0。这些步骤全部都是单向的,也就是说,无法从 Address 反推出 Public Key,也无法从 Public Key 反推出 Private Key,等等。
账户 0 账户 1 账户 2
+------------------+ +------------------+ +------------------+
| | | | | |
| 地址 0 | | 地址 1 | | 地址 2 |
| ^ | | ^ | | ^ |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| + | | + | | + |
| 公钥 0 | | 公钥 1 | | 公钥 2 |
| ^ | | ^ | | ^ |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| + | | + | | + |
| 私钥 0 | | 私钥 1 | | 私钥 2 |
| ^ | | ^ | | ^ |
+------------------+ +------------------+ +------------------+
| | |
| | |
| | |
+--------------------------------------------------------------------+
|
|
+---------+---------+
| |
| 助记词(种子) |
| |
+-------------------+
从种子派生账户的过程是确定性的。这意味着在相同路径下,派生出的私钥始终相同。
账户中的资金由私钥控制。这个私钥通过对助记词应用单向函数生成。如果你丢失了私钥,可以通过助记词将其恢复。然而,如果你丢失了助记词,就会失去对所有已派生私钥的访问权限。同样地,如果有人获得了你的助记词,他们也就获得了所有关联账户的访问权限。
不要丢失你的 24 个助记词,也不要与任何人分享。为了防止资金被盗或丢失,最好将助记词备份多份,并分别保存在安全、可靠的地方。如果有人能够获取你的助记词,他们将完全控制与之关联的账户。
Accounts in Cosmos are Hierarchical Deterministic (HD) Wallets. Originally specified in Bitcoin’s BIP32, HD wallets are a special kind of wallet that let users derive any number of accounts from a single seed. To understand what that means, let us first define some terminology:
- Wallet: Set of accounts obtained from a given seed.
- Account: A pair of public key/private key.
- Private Key: A private key is a secret piece of information used to sign messages. In the blockchain context, a private key identifies the owner of an account. The private key of a user should never be revealed to others.
- Public Key: A public key is a piece of information obtained by applying a one-way mathematical function on a private key. From it, an address can be derived. A private key cannot be found from a public key.
- Address: An address is a public string with a human-readable prefix that identifies an account. It is obtained by applying mathematical transformations to a public key.
- Digital Signature: A digital signature is a piece of cryptographic information that proves the owner of a given private key approved of a given message without revealing the private key.
- Seed: Same as Mnemonic.
- Mnemonic: A mnemonic is a sequence of words that is used as seed to derive private keys. The mnemonic is at the core of each wallet. NEVER LOSE YOUR MNEMONIC. WRITE IT DOWN ON A PIECE OF PAPER AND STORE IT SOMEWHERE SAFE. IF YOU LOSE IT, THERE IS NO WAY TO RETRIEVE IT. IF SOMEONE GAINS ACCESS TO IT, THEY GAIN ACCESS TO ALL THE ASSOCIATED ACCOUNTS.
At the core of a HD wallet, there is a seed. From this seed, users can deterministically generate accounts. To generate an account from a seed, one-way mathematical transformations are applied. To decide which account to generate, the user specifies a path, generally an integer (0, 1, 2, …).
By specifying path to be 0 for example, the Wallet will generate Private Key 0 from the seed. Then, Public Key 0 can be generated from Private Key 0. Finally, Address 0 can be generated from Public Key 0. All these steps are one way only, meaning the Public Key cannot be found from the Address, the Private Key cannot be found from the Public Key, …
Account 0 Account 1 Account 2
+------------------+ +------------------+ +------------------+
| | | | | |
| Address 0 | | Address 1 | | Address 2 |
| ^ | | ^ | | ^ |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| + | | + | | + |
| Public key 0 | | Public key 1 | | Public key 2 |
| ^ | | ^ | | ^ |
| | | | | | | | |
| | | | | | | | |
| | | | | | | | |
| + | | + | | + |
| Private key 0 | | Private key 1 | | Private key 2 |
| ^ | | ^ | | ^ |
+------------------+ +------------------+ +------------------+
| | |
| | |
| | |
+--------------------------------------------------------------------+
|
|
+---------+---------+
| |
| Mnemonic (Seed) |
| |
+-------------------+
The process of derivating accounts from the seed is deterministic. This means that given the same path, the derived private key will always be the same.
The funds stored in an account are controlled by the private key. This private key is generated using a one-way function from the mnemonic. If you lose the private key, you can retrieve it using the mnemonic. However, if you lose the mnemonic, you will lose access to all the derived private keys. Likewise, if someone gains access to your mnemonic, they gain access to all the associated accounts.
Do not lose or share your 24 words with anyone. To prevent theft or loss of funds, it is best to keep multiple copies of your mnemonic stored in safe, secure places. If someone is able to gain access to your mnemonic, they will fully control the accounts associated with them.