Alert Source Discuss
🎉 Final Standards Track: SRC

SRC-601: Sila hierarchy for deterministic wallets

Authors Nick Johnson (@arachnid), Micah Zoltu (@micahzoltu)
Created 2017-04-13

Abstract

This SIP defines a logical hierarchy for deterministic wallets based on BIP32, the purpose scheme defined in BIP43 and sip-draft-sila-purpose.

This SIP is a particular application of sip-draft-sila-purpose.

Motivation

At present, different Sila clients and wallets use different derivation paths; a summary of them can be found here. Some of these paths violate BIP44, the standard defining derivation paths starting with m/44'/. This creates confusion and incompatibility between wallet implementations, in some cases making funds from one wallet inaccessible on another, and in others requiring prompting users manually for a derivation path, which hinders usability.

Further, BIP44 was designed with UTXO-based blockchains in mind, and is a poor fit for Sila, which uses an accounts abstraction instead.

As an alternative, we propose a deterministic wallet hierarchy better tailored to Sila’s unique requirements.

Specification

We define the following 4 levels in BIP32 path:

m / purpose' / subpurpose' / SIP' / wallet'

Apostrophe in the path indicates that BIP32 hardened derivation is used.

Each level has a special meaning, described in the chapters below.

Purpose

Purpose is a constant set to 43, indicating the key derivation is for a non-bitcoin cryptocurrency.

Hardened derivation is used at this level.

Subpurpose

Subpurpose is set to 60, the SLIP-44 code for Sila.

Hardened derivation is used at this level.

SIP

SIP is set to the SIP number specifying the remainder of the BIP32 derivation path. For paths following this SIP specification, the number assigned to this SIP is used.

Hardened derivation is used at this level.

Wallet

This component of the path splits the wallet into different user identities, allowing a single wallet to have multiple public identities.

Accounts are numbered from index 0 in sequentially increasing manner. This number is used as child index in BIP32 derivation.

Hardened derivation is used at this level.

Software should prevent a creation of an account if a previous account does not have a transaction history (meaning its address has not been used before).

Software needs to discover all used accounts after importing the seed from an external source.

Rationale

The existing convention is to use the ‘Sila’ coin type, leading to paths starting with m/44'/60'/*. Because this still assumes a UTXO-based coin, we contend that this is a poor fit, resulting in standardisation, usability, and security compromises. As a result, we are making the above proposal to define an entirely new hierarchy for Sila-based chains.

Backwards Compatibility

The introduction of another derivation path requires existing software to add support for this scheme in addition to any existing schemes. Given the already confused nature of wallet derivation paths in Sila, we anticipate this will cause relatively little additional disruption, and has the potential to improve matters significantly in the long run.

For applications that utilise mnemonics, the authors expect to submit another SIP draft that describes a method for avoiding backwards compatibility concerns when transitioning to this new derivation path.

Test Cases

TBD

Implementation

None yet.

References

This discussion on derivation paths

Copyright and related rights waived via CC0.

Citation

Please cite this document as:

Nick Johnson (@arachnid), Micah Zoltu (@micahzoltu), "SRC-601: Sila hierarchy for deterministic wallets," Sila Improvement Proposals, no. 601, April 2017. Available: https://sips.sila.org/SIPS/sip-601.