core/crypto/ecdsa
ecdsa
Types
3Curve
Curve :: enum int {
Invalid = 0,
SECP256R1 = 1,
SECP384R1 = 2,
}SourceCurve the curve identifier associated with a given Private_Key or Public_Key
Private_Key
Private_Key :: struct {
// WARNING: All of the members are to be treated as internal (ie:
// the Private_Key structure is intended to be opaque).
_curve: Curve,
_impl: union {
secec.Scalar_p256r1,
secec.Scalar_p384r1,
},
_pub_key: Public_Key,
}SourcePrivate_Key is an ECDSA private key.
Public_Key
Public_Key :: struct {
// WARNING: All of the members are to be treated as internal (ie:
// the Public_Key structure is intended to be opaque).
_curve: Curve,
_impl: union {
secec.Point_p256r1,
secec.Point_p384r1,
},
}SourcePublic_Key is an ECDSA public key.
Variables
4CURVE_NAMES
CURVE_NAMES :: [3]string = [Curve]string {
.Invalid = "Invalid",
.SECP256R1 = "secp256r1",
.SECP384R1 = "secp384r1",
}SourceCURVE_NAMES is the Curve to curve name string.
PRIVATE_KEY_SIZES
PRIVATE_KEY_SIZES :: [3]int = [Curve]int {
.Invalid = 0,
.SECP256R1 = secec.SC_SIZE_P256R1,
.SECP384R1 = secec.SC_SIZE_P384R1,
}SourcePRIVATE_KEY_SIZES is the Curve to private key size in bytes.
PUBLIC_KEY_SIZES
PUBLIC_KEY_SIZES :: [3]int = [Curve]int {
.Invalid = 0,
.SECP256R1 = 1 + 2 * secec.FE_SIZE_P256R1,
.SECP384R1 = 1 + 2 * secec.FE_SIZE_P384R1,
}SourcePUBLIC_KEY_SIZES is the Curve to public key size in bytes.
RAW_SIGNATURE_SIZES
RAW_SIGNATURE_SIZES :: [3]int = [Curve]int {
.Invalid = 0,
.SECP256R1 = 2 * secec.SC_SIZE_P256R1,
.SECP384R1 = 2 * secec.SC_SIZE_P384R1,
}SourceRAW_SIGNATURE_SIZES is the Curve to "raw" signature size in bytes.
Procedures
19curve
curve :: proc(k: ^T) -> (Curve)Sourcecurve returns the Curve used by a Private_Key or Public_Key instance.
key_size
key_size :: proc(k: ^T) -> (int)Sourcekey_size returns the key size of a Private_Key or Public_Key in bytes.
private_key_bytes
private_key_bytes :: proc(priv_key: ^Private_Key, dst: []u8)Sourceprivate_key_bytes sets dst to byte-encoding of priv_key.
private_key_clear
private_key_clear :: proc(priv_key: ^Private_Key)Sourceprivate_key_clear clears priv_key to the uninitialized state.
private_key_equal
private_key_equal :: proc(p: ^Private_Key, q: ^Private_Key) -> (bool)Sourceprivate_key_equal returns true if and only if (⟺) the private keys are equal, in constant time.
private_key_generate
private_key_generate :: proc(priv_key: ^Private_Key, curve: Curve) -> (bool)Sourceprivate_key_generate uses the system entropy source to generate a new Private_Key. This will only fail if and only if (⟺) the system entropy source is missing or broken.
private_key_public_bytes
private_key_public_bytes :: proc(priv_key: ^Private_Key, dst: []u8)Sourceprivate_key_public_bytes sets dst to the byte-encoding of the public key corresponding to priv_key.
private_key_set
private_key_set :: proc(priv_key: ^Private_Key, src: ^Private_Key)Sourceprivate_key_set sets priv_key to src.
private_key_set_bytes
private_key_set_bytes :: proc(priv_key: ^Private_Key, curve: Curve, b: []u8) -> (bool)Sourceprivate_key_set_bytes decodes a byte-encoded private key, and returns true if and only if (⟺) the operation was successful.
public_key_bytes
public_key_bytes :: proc(pub_key: ^Public_Key, dst: []u8)Sourcepublic_key_bytes sets dst to byte-encoding of pub_key.
public_key_clear
public_key_clear :: proc(pub_key: ^Public_Key)Sourcepublic_key_clear clears pub_key to the uninitialized state.
public_key_equal
public_key_equal :: proc(p: ^Public_Key, q: ^Public_Key) -> (bool)Sourcepublic_key_equal returns true if and only if (⟺) the public keys are equal, in constant time.
public_key_set
public_key_set :: proc(pub_key: ^Public_Key, src: ^Public_Key)Sourcepublic_key_set sets pub_key to src.
public_key_set_bytes
public_key_set_bytes :: proc(pub_key: ^Public_Key, curve: Curve, b: []u8) -> (bool)Sourcepublic_key_set_bytes decodes a byte-encoded public key, and returns true if and only if (⟺) the operation was successful.
public_key_set_priv
public_key_set_priv :: proc(pub_key: ^Public_Key, priv_key: ^Private_Key)Sourcepublic_key_set_priv sets pub_key to the public component of priv_key.
sign_asn1
sign_asn1 :: proc(priv_key: ^Private_Key, hash_algo: hash.Algorithm, msg: []u8, allocator: runtime.Allocator, deterministic = !crypto.HAS_RAND_BYTES) -> ([]u8, bool)Sourcesign_asn1 returns the signature by priv_key over msg hased using hash_algo using the signing procedure as specified in SEC 1, Version 2.0, Section 4.1.3. ASN.1 DER requires minimal encoding, and the format is clunky and variable-length so for simplicity we allocate the signature.
The signature format is ASN1. SEQUECE { r INTEGER, s INTEGER }`.
sign_raw
sign_raw :: proc(priv_key: ^Private_Key, hash_algo: hash.Algorithm, msg: []u8, sig: []u8, deterministic = !crypto.HAS_RAND_BYTES) -> (bool)Sourcesign_raw writes the signature by priv_key over msg hased using hash_algo to sig, using the signing procedure as specified in SEC 1, Version 2.0, Section 4.1.3.
The signature format is r | s.
verify_asn1
verify_asn1 :: proc(pub_key: ^Public_Key, hash_algo: hash.Algorithm, msg: []u8, sig: []u8) -> (bool)Sourceverify_asn1 returns true if and only if (⟺) sig is a valid signature by pub_key over msg, hased using hash_algo, per the verification procedure specifed in SEC 1, Version 2.0, Section 4.1.4.
The signature format is ASN.1 SEQUENCE { r INTEGER, s INTEGER }.
verify_raw
verify_raw :: proc(pub_key: ^Public_Key, hash_algo: hash.Algorithm, msg: []u8, sig: []u8) -> (bool)Sourceverify_raw returns true if and only if (⟺) sig is a valid signature by pub_key over msg, hased using hash_algo, per the verification procedure specifed in SEC 1, Version 2.0, Section 4.1.4.
The signature format is r | s.