Model
Let $\t{Bulla}$ be defined as in the section Bulla Commitments.
Let $ℙₚ, 𝔽ₚ$ be defined as in the section Pallas and Vesta.
Coin
The coin contains the main parameters that define the Money::transfer() operation:
- The public key $\t{PK}$ serves a dual role.
- Protects receiver privacy from the sender since the corresponding secret
key is used in the nullifier.
- Authorizes the creation of the nullifier by the receiver.
- The core parameters are the value $v$ and the token ID $τ$.
- The serial $ζ$ is randomly selected, and guarantees uniqueness of the coin
which is used in the nullifier. This simultaneously acts as the coin's random
blinding factor.
- To enable protocol owned liquidity, we define the spend hook $\t{SH}$
which adds a constraint that when the coin is spent, it must be called by
the contract specified. The user data $\t{UD}$ can then be used by the parent
contract to store additional parameters in the coin. If the parameter length
exceeds the size of $𝔽ₚ$ then a commit can be used here instead.
Define the coin attributes
$$ \begin{aligned}
\t{Attrs}\t{Coin}.\t{PK} &∈ ℙₚ \
\t{Attrs}\t{Coin}.v &∈ ℕ₆₄ \
\t{Attrs}\t{Coin}.τ &∈ 𝔽ₚ \
\t{Attrs}\t{Coin}.ζ &∈ 𝔽ₚ \
\t{Attrs}\t{Coin}.\t{SH} &∈ 𝔽ₚ \
\t{Attrs}\t{Coin}.\t{UD} &∈ 𝔽ₚ \
\end{aligned} $$
{{#include ../../../../../src/contract/money/src/model.rs:coin-attributes}}
$$ \t{Coin} : \t{Attrs}_\t{Coin} → 𝔽ₚ $$
$$ \t{Coin}(p) = \t{Bulla}(\mathcal{X}(p.\t{PK}), \mathcal{Y}(p.\t{PK}), ℕ₆₄2𝔽ₚ(p.v), p.τ, p.ζ, p.\t{SH}, p.\t{UD}) $$