commonware_cryptography/secp256r1/
scheme.rs

1use crate::{Array, Error, Scheme};
2use commonware_utils::{hex, union_unique, SizedSerialize};
3use p256::{
4    ecdsa::{
5        signature::{Signer, Verifier},
6        SigningKey, VerifyingKey,
7    },
8    elliptic_curve::scalar::IsHigh,
9};
10use rand::{CryptoRng, Rng};
11use std::{
12    borrow::Cow,
13    fmt::{Debug, Display},
14    hash::{Hash, Hasher},
15    ops::Deref,
16};
17
18const PRIVATE_KEY_LENGTH: usize = 32;
19const PUBLIC_KEY_LENGTH: usize = 33; // Y-Parity || X
20const SIGNATURE_LENGTH: usize = 64; // R || S
21
22/// Secp256r1 Signer.
23#[derive(Clone)]
24pub struct Secp256r1 {
25    signer: SigningKey,
26    verifier: VerifyingKey,
27}
28
29impl Scheme for Secp256r1 {
30    type PrivateKey = PrivateKey;
31    type PublicKey = PublicKey;
32    type Signature = Signature;
33
34    fn new<R: CryptoRng + Rng>(r: &mut R) -> Self {
35        let signer = SigningKey::random(r);
36        let verifier = signer.verifying_key().to_owned();
37        Self { signer, verifier }
38    }
39
40    fn from(private_key: PrivateKey) -> Option<Self> {
41        let signer = private_key.key;
42        let verifier = signer.verifying_key().to_owned();
43        Some(Self { signer, verifier })
44    }
45
46    fn private_key(&self) -> PrivateKey {
47        PrivateKey::from(self.signer.clone())
48    }
49
50    fn public_key(&self) -> PublicKey {
51        PublicKey::from(self.verifier)
52    }
53
54    fn sign(&mut self, namespace: Option<&[u8]>, message: &[u8]) -> Signature {
55        let signature: p256::ecdsa::Signature = match namespace {
56            Some(namespace) => self.signer.sign(&union_unique(namespace, message)),
57            None => self.signer.sign(message),
58        };
59        let signature = match signature.normalize_s() {
60            Some(normalized) => normalized,
61            None => signature,
62        };
63        Signature::from(signature)
64    }
65
66    fn verify(
67        namespace: Option<&[u8]>,
68        message: &[u8],
69        public_key: &PublicKey,
70        signature: &Signature,
71    ) -> bool {
72        let payload = match namespace {
73            Some(namespace) => Cow::Owned(union_unique(namespace, message)),
74            None => Cow::Borrowed(message),
75        };
76        public_key
77            .key
78            .verify(&payload, &signature.signature)
79            .is_ok()
80    }
81}
82
83/// Secp256r1 Private Key.
84#[derive(Clone, Eq, PartialEq)]
85pub struct PrivateKey {
86    raw: [u8; PRIVATE_KEY_LENGTH],
87    key: SigningKey,
88}
89
90impl Array for PrivateKey {}
91
92impl SizedSerialize for PrivateKey {
93    const SERIALIZED_LEN: usize = PRIVATE_KEY_LENGTH;
94}
95
96impl Hash for PrivateKey {
97    fn hash<H: Hasher>(&self, state: &mut H) {
98        self.raw.hash(state);
99    }
100}
101
102impl Ord for PrivateKey {
103    fn cmp(&self, other: &Self) -> std::cmp::Ordering {
104        self.raw.cmp(&other.raw)
105    }
106}
107
108impl PartialOrd for PrivateKey {
109    fn partial_cmp(&self, other: &Self) -> Option<std::cmp::Ordering> {
110        Some(self.cmp(other))
111    }
112}
113
114impl AsRef<[u8]> for PrivateKey {
115    fn as_ref(&self) -> &[u8] {
116        &self.raw
117    }
118}
119
120impl Deref for PrivateKey {
121    type Target = [u8];
122    fn deref(&self) -> &[u8] {
123        &self.raw
124    }
125}
126
127impl From<SigningKey> for PrivateKey {
128    fn from(signer: SigningKey) -> Self {
129        let raw = signer.to_bytes().into();
130        Self { raw, key: signer }
131    }
132}
133
134impl TryFrom<&[u8]> for PrivateKey {
135    type Error = Error;
136    fn try_from(value: &[u8]) -> Result<Self, Self::Error> {
137        let raw: [u8; PRIVATE_KEY_LENGTH] = value
138            .try_into()
139            .map_err(|_| Error::InvalidPrivateKeyLength)?;
140        let key = SigningKey::from_slice(&raw).map_err(|_| Error::InvalidPrivateKey)?;
141        Ok(Self { raw, key })
142    }
143}
144
145impl TryFrom<&Vec<u8>> for PrivateKey {
146    type Error = Error;
147    fn try_from(value: &Vec<u8>) -> Result<Self, Self::Error> {
148        Self::try_from(value.as_slice())
149    }
150}
151
152impl TryFrom<Vec<u8>> for PrivateKey {
153    type Error = Error;
154    fn try_from(value: Vec<u8>) -> Result<Self, Self::Error> {
155        Self::try_from(value.as_slice())
156    }
157}
158
159impl Debug for PrivateKey {
160    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
161        write!(f, "{}", hex(&self.raw))
162    }
163}
164
165impl Display for PrivateKey {
166    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
167        write!(f, "{}", hex(&self.raw))
168    }
169}
170
171/// Secp256r1 Public Key.
172#[derive(Clone, Eq, PartialEq, Ord, PartialOrd)]
173pub struct PublicKey {
174    raw: [u8; PUBLIC_KEY_LENGTH],
175    key: VerifyingKey,
176}
177
178impl Array for PublicKey {}
179
180impl SizedSerialize for PublicKey {
181    const SERIALIZED_LEN: usize = PUBLIC_KEY_LENGTH;
182}
183
184impl Hash for PublicKey {
185    fn hash<H: Hasher>(&self, state: &mut H) {
186        self.raw.hash(state);
187    }
188}
189
190impl AsRef<[u8]> for PublicKey {
191    fn as_ref(&self) -> &[u8] {
192        &self.raw
193    }
194}
195
196impl Deref for PublicKey {
197    type Target = [u8];
198    fn deref(&self) -> &[u8] {
199        &self.raw
200    }
201}
202
203impl From<VerifyingKey> for PublicKey {
204    fn from(verifier: VerifyingKey) -> Self {
205        let encoded = verifier.to_encoded_point(true);
206        let raw: [u8; PUBLIC_KEY_LENGTH] = encoded.as_bytes().try_into().unwrap();
207        Self { raw, key: verifier }
208    }
209}
210
211impl TryFrom<&[u8]> for PublicKey {
212    type Error = Error;
213    fn try_from(value: &[u8]) -> Result<Self, Self::Error> {
214        let raw: [u8; PUBLIC_KEY_LENGTH] = value
215            .try_into()
216            .map_err(|_| Error::InvalidPublicKeyLength)?;
217        let key = VerifyingKey::from_sec1_bytes(&raw).map_err(|_| Error::InvalidPublicKey)?;
218        Ok(Self { raw, key })
219    }
220}
221
222impl TryFrom<&Vec<u8>> for PublicKey {
223    type Error = Error;
224    fn try_from(value: &Vec<u8>) -> Result<Self, Self::Error> {
225        Self::try_from(value.as_slice())
226    }
227}
228
229impl TryFrom<Vec<u8>> for PublicKey {
230    type Error = Error;
231    fn try_from(value: Vec<u8>) -> Result<Self, Self::Error> {
232        Self::try_from(value.as_slice())
233    }
234}
235
236impl Debug for PublicKey {
237    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
238        write!(f, "{}", hex(&self.raw))
239    }
240}
241
242impl Display for PublicKey {
243    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
244        write!(f, "{}", hex(&self.raw))
245    }
246}
247
248/// Secp256r1 Signature.
249#[derive(Clone, Eq, PartialEq)]
250pub struct Signature {
251    raw: [u8; SIGNATURE_LENGTH],
252    signature: p256::ecdsa::Signature,
253}
254
255impl Array for Signature {}
256
257impl SizedSerialize for Signature {
258    const SERIALIZED_LEN: usize = SIGNATURE_LENGTH;
259}
260
261impl Hash for Signature {
262    fn hash<H: Hasher>(&self, state: &mut H) {
263        self.raw.hash(state);
264    }
265}
266
267impl Ord for Signature {
268    fn cmp(&self, other: &Self) -> std::cmp::Ordering {
269        self.raw.cmp(&other.raw)
270    }
271}
272
273impl PartialOrd for Signature {
274    fn partial_cmp(&self, other: &Self) -> Option<std::cmp::Ordering> {
275        Some(self.cmp(other))
276    }
277}
278
279impl AsRef<[u8]> for Signature {
280    fn as_ref(&self) -> &[u8] {
281        &self.raw
282    }
283}
284
285impl Deref for Signature {
286    type Target = [u8];
287    fn deref(&self) -> &[u8] {
288        &self.raw
289    }
290}
291
292impl From<p256::ecdsa::Signature> for Signature {
293    fn from(signature: p256::ecdsa::Signature) -> Self {
294        let raw = signature.to_bytes().into();
295        Self { raw, signature }
296    }
297}
298
299impl TryFrom<&[u8]> for Signature {
300    type Error = Error;
301    fn try_from(value: &[u8]) -> Result<Self, Self::Error> {
302        let raw: [u8; SIGNATURE_LENGTH] = value
303            .try_into()
304            .map_err(|_| Error::InvalidSignatureLength)?;
305        let signature =
306            p256::ecdsa::Signature::from_slice(&raw).map_err(|_| Error::InvalidSignature)?;
307        if signature.s().is_high().into() {
308            // Reject any signatures with a `s` value in the upper half of the curve order.
309            return Err(Error::InvalidSignature);
310        }
311        Ok(Self { raw, signature })
312    }
313}
314
315impl TryFrom<&Vec<u8>> for Signature {
316    type Error = Error;
317    fn try_from(value: &Vec<u8>) -> Result<Self, Self::Error> {
318        Self::try_from(value.as_slice())
319    }
320}
321
322impl TryFrom<Vec<u8>> for Signature {
323    type Error = Error;
324    fn try_from(value: Vec<u8>) -> Result<Self, Self::Error> {
325        Self::try_from(value.as_slice())
326    }
327}
328
329impl Debug for Signature {
330    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
331        write!(f, "{}", hex(&self.raw))
332    }
333}
334
335impl Display for Signature {
336    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
337        write!(f, "{}", hex(&self.raw))
338    }
339}
340
341/// Test vectors sourced from (FIPS 186-4)
342/// https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/digital-signatures.
343#[cfg(test)]
344mod tests {
345    use super::*;
346
347    fn parse_vector_keypair(private_key: &str, qx: &str, qy: &str) -> (PrivateKey, PublicKey) {
348        let public_key = parse_public_key_as_compressed(qx, qy);
349        (
350            commonware_utils::from_hex_formatted(private_key)
351                .unwrap()
352                .try_into()
353                .unwrap(),
354            public_key,
355        )
356    }
357
358    fn parse_vector_sig_verification(
359        qx: &str,
360        qy: &str,
361        r: &str,
362        s: &str,
363        m: &str,
364    ) -> (PublicKey, Vec<u8>, Vec<u8>) {
365        let public_key = parse_public_key_as_compressed(qx, qy);
366        let signature = parse_signature(r, s);
367        let message = commonware_utils::from_hex_formatted(m).unwrap();
368        (public_key, signature, message)
369    }
370
371    fn parse_signature(r: &str, s: &str) -> Vec<u8> {
372        let vec_r = commonware_utils::from_hex_formatted(r).unwrap();
373        let vec_s = commonware_utils::from_hex_formatted(s).unwrap();
374        let f1 = p256::FieldBytes::from_slice(&vec_r);
375        let f2 = p256::FieldBytes::from_slice(&vec_s);
376        let s = p256::ecdsa::Signature::from_scalars(*f1, *f2).unwrap();
377        s.to_vec()
378    }
379
380    fn parse_public_key_as_compressed(qx: &str, qy: &str) -> PublicKey {
381        parse_public_key_as_compressed_vector(qx, qy)
382            .try_into()
383            .unwrap()
384    }
385
386    fn parse_public_key_as_compressed_vector(qx: &str, qy: &str) -> Vec<u8> {
387        let qx = commonware_utils::from_hex_formatted(&padding_odd_length_hex(qx)).unwrap();
388        let qy = commonware_utils::from_hex_formatted(&padding_odd_length_hex(qy)).unwrap();
389        let mut compressed = Vec::with_capacity(qx.len() + 1);
390        if qy.last().unwrap() % 2 == 0 {
391            compressed.push(0x02);
392        } else {
393            compressed.push(0x03);
394        }
395        compressed.extend_from_slice(&qx);
396        compressed
397    }
398
399    fn parse_public_key_as_uncompressed_vector(qx: &str, qy: &str) -> Vec<u8> {
400        let qx = commonware_utils::from_hex_formatted(qx).unwrap();
401        let qy = commonware_utils::from_hex_formatted(qy).unwrap();
402        let mut uncompressed_public_key = Vec::with_capacity(65);
403        uncompressed_public_key.push(0x04);
404        uncompressed_public_key.extend_from_slice(&qx);
405        uncompressed_public_key.extend_from_slice(&qy);
406        uncompressed_public_key
407    }
408
409    fn padding_odd_length_hex(value: &str) -> String {
410        if value.len() % 2 != 0 {
411            return format!("0{}", value);
412        }
413        value.to_string()
414    }
415
416    #[test]
417    fn test_scheme_sign() {
418        let private_key: PrivateKey = commonware_utils::from_hex_formatted(
419            "519b423d715f8b581f4fa8ee59f4771a5b44c8130b4e3eacca54a56dda72b464",
420        )
421        .unwrap()
422        .try_into()
423        .unwrap();
424        let message = commonware_utils::from_hex_formatted(
425            "5905238877c77421f73e43ee3da6f2d9e2ccad5fc942dcec0cbd25482935faaf416983fe165b1a045e
426            e2bcd2e6dca3bdf46c4310a7461f9a37960ca672d3feb5473e253605fb1ddfd28065b53cb5858a8ad28175bf
427            9bd386a5e471ea7a65c17cc934a9d791e91491eb3754d03799790fe2d308d16146d5c9b0d0debd97d79ce8",
428        )
429        .unwrap();
430        let mut signer = <Secp256r1 as Scheme>::from(private_key).unwrap();
431        let signature = signer.sign(None, &message);
432        assert_eq!(SIGNATURE_LENGTH, signature.len());
433        assert!(Secp256r1::verify(
434            None,
435            &message,
436            &signer.public_key(),
437            &signature
438        ));
439    }
440
441    #[test]
442    fn test_scheme_private_key() {
443        let private_key_hex = "519b423d715f8b581f4fa8ee59f4771a5b44c8130b4e3eacca54a56dda72b464";
444        let private_key: PrivateKey = commonware_utils::from_hex_formatted(private_key_hex)
445            .unwrap()
446            .try_into()
447            .unwrap();
448        let signer = <Secp256r1 as Scheme>::from(private_key).unwrap();
449        let exported_private_key = signer.private_key();
450        assert_eq!(
451            private_key_hex,
452            commonware_utils::hex(&exported_private_key).as_str(),
453        );
454    }
455
456    // Ensure RFC6979 compliance (should also be tested by underlying library)
457    #[test]
458    fn test_rfc6979() {
459        let private_key: PrivateKey = commonware_utils::from_hex_formatted(
460            "c9afa9d845ba75166b5c215767b1d6934e50c3db36e89b127b8a622b120f6721",
461        )
462        .unwrap()
463        .try_into()
464        .unwrap();
465
466        let (message, exp_sig) = (
467            b"sample",
468            p256::ecdsa::Signature::from_slice(
469                &commonware_utils::from_hex_formatted(
470                    "efd48b2aacb6a8fd1140dd9cd45e81d69d2c877b56aaf991c34d0ea84eaf3716
471                    f7cb1c942d657c41d436c7a1b6e29f65f3e900dbb9aff4064dc4ab2f843acda8",
472                )
473                .unwrap(),
474            )
475            .unwrap(),
476        );
477        let mut signer = <Secp256r1 as Scheme>::from(private_key).unwrap();
478        let signature = signer.sign(None, message);
479        assert_eq!(signature.to_vec(), exp_sig.normalize_s().unwrap().to_vec());
480
481        let (message, exp_sig) = (
482            b"test",
483            p256::ecdsa::Signature::from_slice(
484                &commonware_utils::from_hex_formatted(
485                    "f1abb023518351cd71d881567b1ea663ed3efcf6c5132b354f28d3b0b7d38367
486                    019f4113742a2b14bd25926b49c649155f267e60d3814b4c0cc84250e46f0083",
487                )
488                .unwrap(),
489            )
490            .unwrap(),
491        );
492
493        let signature = signer.sign(None, message);
494        assert_eq!(signature.to_vec(), exp_sig.to_vec());
495    }
496
497    #[test]
498    fn test_scheme_validate_public_key_too_long() {
499        let qx_hex = "d0720dc691aa80096ba32fed1cb97c2b620690d06de0317b8618d5ce65eb728f";
500        let qy_hex = "d0720dc691aa80096ba32fed1cb97c2b620690d06de0317b8618d5ce65eb728f";
501
502        let uncompressed_public_key = parse_public_key_as_uncompressed_vector(qx_hex, qy_hex);
503        let public_key = <Secp256r1 as Scheme>::PublicKey::try_from(&uncompressed_public_key);
504        assert_eq!(public_key, Err(Error::InvalidPublicKeyLength));
505
506        let compressed_public_key = parse_public_key_as_compressed_vector(qx_hex, qy_hex);
507        let public_key = <Secp256r1 as Scheme>::PublicKey::try_from(&compressed_public_key);
508        assert!(public_key.is_ok());
509    }
510
511    #[test]
512    fn test_scheme_verify_signature_r0() {
513        // Generate bad signature
514        let private_key: PrivateKey = commonware_utils::from_hex_formatted(
515            "c9806898a0334916c860748880a541f093b579a9b1f32934d86c363c39800357",
516        )
517        .unwrap()
518        .try_into()
519        .unwrap();
520        let message = b"sample";
521        let mut signer = <Secp256r1 as Scheme>::from(private_key).unwrap();
522        let signature = signer.sign(None, message);
523        let (_, s) = signature.split_at(32);
524        let mut signature: Vec<u8> = vec![0x00; 32];
525        signature.extend_from_slice(s);
526
527        // Try to parse signature
528        assert!(Signature::try_from(&signature).is_err());
529    }
530
531    #[test]
532    fn test_scheme_verify_signature_s0() {
533        // Generate bad signature
534        let private_key: PrivateKey = commonware_utils::from_hex_formatted(
535            "c9806898a0334916c860748880a541f093b579a9b1f32934d86c363c39800357",
536        )
537        .unwrap()
538        .try_into()
539        .unwrap();
540        let message = b"sample";
541        let mut signer = <Secp256r1 as Scheme>::from(private_key).unwrap();
542        let signature = signer.sign(None, message);
543        let (r, _) = signature.split_at(32);
544        let s: Vec<u8> = vec![0x00; 32];
545        let mut signature = r.to_vec();
546        signature.extend(s);
547
548        // Try to parse signature
549        assert!(Signature::try_from(&signature).is_err());
550    }
551
552    #[test]
553    fn test_keypairs() {
554        let cases = [
555            vector_keypair_1(),
556            vector_keypair_2(),
557            vector_keypair_3(),
558            vector_keypair_4(),
559            vector_keypair_5(),
560            vector_keypair_6(),
561            vector_keypair_7(),
562            vector_keypair_8(),
563            vector_keypair_9(),
564            vector_keypair_10(),
565        ];
566
567        for (index, test) in cases.into_iter().enumerate() {
568            let (private_key, exp_public_key) = test;
569            let signer = <Secp256r1 as Scheme>::from(private_key).unwrap();
570            assert_eq!(
571                exp_public_key,
572                signer.public_key(),
573                "vector_keypair_{}",
574                index + 1
575            );
576            assert!(signer.public_key().len() == PUBLIC_KEY_LENGTH);
577        }
578    }
579
580    #[test]
581    fn test_public_key_validation() {
582        // We use SEC 1-encoded public keys (only include y-parity) whereas vectors
583        // assume public keys are uncompressed (both x and y packed in encoding).
584        //
585        // For this reason, test vector 2 (y out of range) and 11 (y not on curve) are skipped.
586        let cases = [
587            (1, vector_public_key_validation_1()),
588            (3, vector_public_key_validation_3()),
589            (4, vector_public_key_validation_4()),
590            (5, vector_public_key_validation_5()),
591            (6, vector_public_key_validation_6()),
592            (7, vector_public_key_validation_7()),
593            (8, vector_public_key_validation_8()),
594            (9, vector_public_key_validation_9()),
595            (10, vector_public_key_validation_10()),
596            (12, vector_public_key_validation_12()),
597        ];
598
599        for (n, test) in cases.iter() {
600            let (public_key, exp_valid) = test;
601            let res = <Secp256r1 as Scheme>::PublicKey::try_from(public_key);
602            assert_eq!(
603                *exp_valid,
604                res.is_ok(),
605                "vector_public_key_validation_{}",
606                n
607            );
608        }
609    }
610
611    #[test]
612    fn test_signature_verification() {
613        let cases = [
614            vector_sig_verification_1(),
615            vector_sig_verification_2(),
616            vector_sig_verification_3(),
617            vector_sig_verification_4(),
618            vector_sig_verification_5(),
619            vector_sig_verification_6(),
620            vector_sig_verification_7(),
621            vector_sig_verification_8(),
622            vector_sig_verification_9(),
623            vector_sig_verification_10(),
624            vector_sig_verification_11(),
625            vector_sig_verification_12(),
626            vector_sig_verification_13(),
627            vector_sig_verification_14(),
628            vector_sig_verification_15(),
629        ];
630
631        for (index, test) in cases.into_iter().enumerate() {
632            let (public_key, sig, message, expected) = test;
633            let expected = if expected {
634                let mut ecdsa_signature = p256::ecdsa::Signature::from_slice(&sig).unwrap();
635                if ecdsa_signature.s().is_high().into() {
636                    // Valid signatures not normalized must be considered invalid.
637                    assert!(Signature::try_from(sig).is_err());
638
639                    // Normalizing sig to test its validity.
640                    if let Some(normalized_sig) = ecdsa_signature.normalize_s() {
641                        ecdsa_signature = normalized_sig;
642                    }
643                }
644                let signature = Signature::from(ecdsa_signature);
645                Secp256r1::verify(None, &message, &public_key, &signature)
646            } else {
647                let signature = Signature::try_from(sig);
648                signature.is_err()
649                    || !Secp256r1::verify(None, &message, &public_key, &signature.unwrap())
650            };
651            assert!(expected, "vector_signature_verification_{}", index + 1);
652        }
653    }
654
655    fn vector_keypair_1() -> (PrivateKey, PublicKey) {
656        parse_vector_keypair(
657            "c9806898a0334916c860748880a541f093b579a9b1f32934d86c363c39800357",
658            "d0720dc691aa80096ba32fed1cb97c2b620690d06de0317b8618d5ce65eb728f",
659            "9681b517b1cda17d0d83d335d9c4a8a9a9b0b1b3c7106d8f3c72bc5093dc275f",
660        )
661    }
662
663    fn vector_keypair_2() -> (PrivateKey, PublicKey) {
664        parse_vector_keypair(
665            "710735c8388f48c684a97bd66751cc5f5a122d6b9a96a2dbe73662f78217446d",
666            "f6836a8add91cb182d8d258dda6680690eb724a66dc3bb60d2322565c39e4ab9",
667            "1f837aa32864870cb8e8d0ac2ff31f824e7beddc4bb7ad72c173ad974b289dc2",
668        )
669    }
670
671    fn vector_keypair_3() -> (PrivateKey, PublicKey) {
672        parse_vector_keypair(
673            "78d5d8b7b3e2c16b3e37e7e63becd8ceff61e2ce618757f514620ada8a11f6e4",
674            "76711126cbb2af4f6a5fe5665dad4c88d27b6cb018879e03e54f779f203a854e",
675            "a26df39960ab5248fd3620fd018398e788bd89a3cea509b352452b69811e6856",
676        )
677    }
678
679    fn vector_keypair_4() -> (PrivateKey, PublicKey) {
680        parse_vector_keypair(
681            "2a61a0703860585fe17420c244e1de5a6ac8c25146b208ef88ad51ae34c8cb8c",
682            "e1aa7196ceeac088aaddeeba037abb18f67e1b55c0a5c4e71ec70ad666fcddc8",
683            "d7d35bdce6dedc5de98a7ecb27a9cd066a08f586a733b59f5a2cdb54f971d5c8",
684        )
685    }
686
687    fn vector_keypair_5() -> (PrivateKey, PublicKey) {
688        parse_vector_keypair(
689            "01b965b45ff386f28c121c077f1d7b2710acc6b0cb58d8662d549391dcf5a883",
690            "1f038c5422e88eec9e88b815e8f6b3e50852333fc423134348fc7d79ef8e8a10",
691            "43a047cb20e94b4ffb361ef68952b004c0700b2962e0c0635a70269bc789b849",
692        )
693    }
694
695    fn vector_keypair_6() -> (PrivateKey, PublicKey) {
696        parse_vector_keypair(
697            "fac92c13d374c53a085376fe4101618e1e181b5a63816a84a0648f3bdc24e519",
698            "7258f2ab96fc84ef6ccb33e308cd392d8b568ea635730ceb4ebd72fa870583b9",
699            "489807ca55bdc29ca5c8fe69b94f227b0345cccdbe89975e75d385cc2f6bb1e2",
700        )
701    }
702
703    fn vector_keypair_7() -> (PrivateKey, PublicKey) {
704        parse_vector_keypair(
705            "f257a192dde44227b3568008ff73bcf599a5c45b32ab523b5b21ca582fef5a0a",
706            "d2e01411817b5512b79bbbe14d606040a4c90deb09e827d25b9f2fc068997872",
707            "503f138f8bab1df2c4507ff663a1fdf7f710e7adb8e7841eaa902703e314e793",
708        )
709    }
710
711    fn vector_keypair_8() -> (PrivateKey, PublicKey) {
712        parse_vector_keypair(
713            "add67e57c42a3d28708f0235eb86885a4ea68e0d8cfd76eb46134c596522abfd",
714            "55bed2d9c029b7f230bde934c7124ed52b1330856f13cbac65a746f9175f85d7",
715            "32805e311d583b4e007c40668185e85323948e21912b6b0d2cda8557389ae7b0",
716        )
717    }
718
719    fn vector_keypair_9() -> (PrivateKey, PublicKey) {
720        parse_vector_keypair(
721            "4494860fd2c805c5c0d277e58f802cff6d731f76314eb1554142a637a9bc5538",
722            "5190277a0c14d8a3d289292f8a544ce6ea9183200e51aec08440e0c1a463a4e4",
723            "ecd98514821bd5aaf3419ab79b71780569470e4fed3da3c1353b28fe137f36eb",
724        )
725    }
726
727    fn vector_keypair_10() -> (PrivateKey, PublicKey) {
728        parse_vector_keypair(
729            "d40b07b1ea7b86d4709ef9dc634c61229feb71abd63dc7fc85ef46711a87b210",
730            "fbcea7c2827e0e8085d7707b23a3728823ea6f4878b24747fb4fd2842d406c73",
731            "2393c85f1f710c5afc115a39ba7e18abe03f19c9d4bb3d47d19468b818efa535",
732        )
733    }
734
735    fn vector_public_key_validation_1() -> (Vec<u8>, bool) {
736        (
737            parse_public_key_as_compressed_vector(
738                "e0f7449c5588f24492c338f2bc8f7865f755b958d48edb0f2d0056e50c3fd5b7",
739                "86d7e9255d0f4b6f44fa2cd6f8ba3c0aa828321d6d8cc430ca6284ce1d5b43a0",
740            ),
741            true,
742        )
743    }
744
745    fn vector_public_key_validation_3() -> (Vec<u8>, bool) {
746        (
747            parse_public_key_as_compressed_vector(
748                "17875397ae87369365656d490e8ce956911bd97607f2aff41b56f6f3a61989826",
749                "980a3c4f61b9692633fbba5ef04c9cb546dd05cdec9fa8428b8849670e2fba92",
750            ),
751            false, // x out of range
752        )
753    }
754
755    fn vector_public_key_validation_4() -> (Vec<u8>, bool) {
756        (
757            parse_public_key_as_compressed_vector(
758                "f2d1c0dc0852c3d8a2a2500a23a44813ccce1ac4e58444175b440469ffc12273",
759                "32bfe992831b305d8c37b9672df5d29fcb5c29b4a40534683e3ace23d24647dd",
760            ),
761            false, // point not on the curve
762        )
763    }
764
765    fn vector_public_key_validation_5() -> (Vec<u8>, bool) {
766        (
767            parse_public_key_as_compressed_vector(
768                "10b0ca230fff7c04768f4b3d5c75fa9f6c539bea644dffbec5dc796a213061b58",
769                "f5edf37c11052b75f771b7f9fa050e353e464221fec916684ed45b6fead38205",
770            ),
771            false, // x out of range
772        )
773    }
774
775    fn vector_public_key_validation_6() -> (Vec<u8>, bool) {
776        (
777            parse_public_key_as_compressed_vector(
778                "2c1052f25360a15062d204a056274e93cbe8fc4c4e9b9561134ad5c15ce525da",
779                "ced9783713a8a2a09eff366987639c625753295d9a85d0f5325e32dedbcada0b",
780            ),
781            true,
782        )
783    }
784
785    fn vector_public_key_validation_7() -> (Vec<u8>, bool) {
786        (
787            parse_public_key_as_compressed_vector(
788                "a40d077a87dae157d93dcccf3fe3aca9c6479a75aa2669509d2ef05c7de6782f",
789                "503d86b87d743ba20804fd7e7884aa017414a7b5b5963e0d46e3a9611419ddf3",
790            ),
791            false, // point not on the curve
792        )
793    }
794
795    fn vector_public_key_validation_8() -> (Vec<u8>, bool) {
796        (
797            parse_public_key_as_compressed_vector(
798                "2633d398a3807b1895548adbb0ea2495ef4b930f91054891030817df87d4ac0a",
799                "d6b2f738e3873cc8364a2d364038ce7d0798bb092e3dd77cbdae7c263ba618d2",
800            ),
801            true,
802        )
803    }
804
805    fn vector_public_key_validation_9() -> (Vec<u8>, bool) {
806        (
807            parse_public_key_as_compressed_vector(
808                "14bf57f76c260b51ec6bbc72dbd49f02a56eaed070b774dc4bad75a54653c3d56",
809                "7a231a23bf8b3aa31d9600d888a0678677a30e573decd3dc56b33f365cc11236",
810            ),
811            false, // x out of range
812        )
813    }
814
815    fn vector_public_key_validation_10() -> (Vec<u8>, bool) {
816        (
817            parse_public_key_as_compressed_vector(
818                "2fa74931ae816b426f484180e517f5050c92decfc8daf756cd91f54d51b302f1",
819                "5b994346137988c58c14ae2152ac2f6ad96d97decb33099bd8a0210114cd1141",
820            ),
821            true,
822        )
823    }
824
825    fn vector_public_key_validation_12() -> (Vec<u8>, bool) {
826        (
827            parse_public_key_as_compressed_vector(
828                "7a81a7e0b015252928d8b36e4ca37e92fdc328eb25c774b4f872693028c4be38",
829                "08862f7335147261e7b1c3d055f9a316e4cab7daf99cc09d1c647f5dd6e7d5bb",
830            ),
831            false, // point not on the curve
832        )
833    }
834
835    fn vector_sig_verification_1() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
836        let (public_key, sig, message) = parse_vector_sig_verification(
837            "87f8f2b218f49845f6f10eec3877136269f5c1a54736dbdf69f89940cad41555",
838            "e15f369036f49842fac7a86c8a2b0557609776814448b8f5e84aa9f4395205e9",
839            "d19ff48b324915576416097d2544f7cbdf8768b1454ad20e0baac50e211f23b0",
840            "a3e81e59311cdfff2d4784949f7a2cb50ba6c3a91fa54710568e61aca3e847c6",
841            "e4796db5f785f207aa30d311693b3702821dff1168fd2e04c0836825aefd850d9aa60326d88cde1a23c7
842            745351392ca2288d632c264f197d05cd424a30336c19fd09bb229654f0222fcb881a4b35c290a093ac159ce1
843            3409111ff0358411133c24f5b8e2090d6db6558afc36f06ca1f6ef779785adba68db27a409859fc4c4a0",
844        );
845        (public_key, sig, message, false)
846    }
847
848    fn vector_sig_verification_2() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
849        let (public_key, sig, message) = parse_vector_sig_verification(
850            "5cf02a00d205bdfee2016f7421807fc38ae69e6b7ccd064ee689fc1a94a9f7d2",
851            "ec530ce3cc5c9d1af463f264d685afe2b4db4b5828d7e61b748930f3ce622a85",
852            "dc23d130c6117fb5751201455e99f36f59aba1a6a21cf2d0e7481a97451d6693",
853            "d6ce7708c18dbf35d4f8aa7240922dc6823f2e7058cbc1484fcad1599db5018c",
854            "069a6e6b93dfee6df6ef6997cd80dd2182c36653cef10c655d524585655462d683877f95ecc6d6c81623
855            d8fac4e900ed0019964094e7de91f1481989ae1873004565789cbf5dc56c62aedc63f62f3b894c9c6f7788c8
856            ecaadc9bd0e81ad91b2b3569ea12260e93924fdddd3972af5273198f5efda0746219475017557616170e",
857        );
858        (public_key, sig, message, false)
859    }
860
861    fn vector_sig_verification_3() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
862        let (public_key, sig, message) = parse_vector_sig_verification(
863            "2ddfd145767883ffbb0ac003ab4a44346d08fa2570b3120dcce94562422244cb",
864            "5f70c7d11ac2b7a435ccfbbae02c3df1ea6b532cc0e9db74f93fffca7c6f9a64",
865            "9913111cff6f20c5bf453a99cd2c2019a4e749a49724a08774d14e4c113edda8",
866            "9467cd4cd21ecb56b0cab0a9a453b43386845459127a952421f5c6382866c5cc",
867            "df04a346cf4d0e331a6db78cca2d456d31b0a000aa51441defdb97bbeb20b94d8d746429a393ba88840d
868            661615e07def615a342abedfa4ce912e562af714959896858af817317a840dcff85a057bb91a3c2bf9010550
869            0362754a6dd321cdd86128cfc5f04667b57aa78c112411e42da304f1012d48cd6a7052d7de44ebcc01de",
870        );
871        (public_key, sig, message, false)
872    }
873
874    fn vector_sig_verification_4() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
875        let (public_key, sig, message) = parse_vector_sig_verification(
876            "e424dc61d4bb3cb7ef4344a7f8957a0c5134e16f7a67c074f82e6e12f49abf3c",
877            "970eed7aa2bc48651545949de1dddaf0127e5965ac85d1243d6f60e7dfaee927",
878            "bf96b99aa49c705c910be33142017c642ff540c76349b9dab72f981fd9347f4f",
879            "17c55095819089c2e03b9cd415abdf12444e323075d98f31920b9e0f57ec871c",
880            "e1130af6a38ccb412a9c8d13e15dbfc9e69a16385af3c3f1e5da954fd5e7c45fd75e2b8c36699228e928
881            40c0562fbf3772f07e17f1add56588dd45f7450e1217ad239922dd9c32695dc71ff2424ca0dec1321aa47064
882            a044b7fe3c2b97d03ce470a592304c5ef21eed9f93da56bb232d1eeb0035f9bf0dfafdcc4606272b20a3",
883        );
884        (public_key, sig, message, true)
885    }
886
887    fn vector_sig_verification_5() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
888        let (public_key, sig, message) = parse_vector_sig_verification(
889            "e0fc6a6f50e1c57475673ee54e3a57f9a49f3328e743bf52f335e3eeaa3d2864",
890            "7f59d689c91e463607d9194d99faf316e25432870816dde63f5d4b373f12f22a",
891            "1d75830cd36f4c9aa181b2c4221e87f176b7f05b7c87824e82e396c88315c407",
892            "cb2acb01dac96efc53a32d4a0d85d0c2e48955214783ecf50a4f0414a319c05a",
893            "73c5f6a67456ae48209b5f85d1e7de7758bf235300c6ae2bdceb1dcb27a7730fb68c950b7fcada0ecc46
894            61d3578230f225a875e69aaa17f1e71c6be5c831f22663bac63d0c7a9635edb0043ff8c6f26470f02a7bc565
895            56f1437f06dfa27b487a6c4290d8bad38d4879b334e341ba092dde4e4ae694a9c09302e2dbf443581c08",
896        );
897        // Valid vector we switch to invalid as the signature is not normalized.
898        (public_key, sig, message, true)
899    }
900
901    fn vector_sig_verification_6() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
902        let (public_key, sig, message) = parse_vector_sig_verification(
903            "a849bef575cac3c6920fbce675c3b787136209f855de19ffe2e8d29b31a5ad86",
904            "bf5fe4f7858f9b805bd8dcc05ad5e7fb889de2f822f3d8b41694e6c55c16b471",
905            "25acc3aa9d9e84c7abf08f73fa4195acc506491d6fc37cb9074528a7db87b9d6",
906            "9b21d5b5259ed3f2ef07dfec6cc90d3a37855d1ce122a85ba6a333f307d31537",
907            "666036d9b4a2426ed6585a4e0fd931a8761451d29ab04bd7dc6d0c5b9e38e6c2b263ff6cb837bd04399d
908            e3d757c6c7005f6d7a987063cf6d7e8cb38a4bf0d74a282572bd01d0f41e3fd066e3021575f0fa04f27b700d
909            5b7ddddf50965993c3f9c7118ed78888da7cb221849b3260592b8e632d7c51e935a0ceae15207bedd548",
910        );
911        (public_key, sig, message, false)
912    }
913
914    fn vector_sig_verification_7() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
915        let (public_key, sig, message) = parse_vector_sig_verification(
916            "3dfb6f40f2471b29b77fdccba72d37c21bba019efa40c1c8f91ec405d7dcc5df",
917            "f22f953f1e395a52ead7f3ae3fc47451b438117b1e04d613bc8555b7d6e6d1bb",
918            "548886278e5ec26bed811dbb72db1e154b6f17be70deb1b210107decb1ec2a5a",
919            "e93bfebd2f14f3d827ca32b464be6e69187f5edbd52def4f96599c37d58eee75",
920            "7e80436bce57339ce8da1b5660149a20240b146d108deef3ec5da4ae256f8f894edcbbc57b34ce37089c
921            0daa17f0c46cd82b5a1599314fd79d2fd2f446bd5a25b8e32fcf05b76d644573a6df4ad1dfea707b479d9723
922            7a346f1ec632ea5660efb57e8717a8628d7f82af50a4e84b11f21bdff6839196a880ae20b2a0918d58cd",
923        );
924        (public_key, sig, message, false)
925    }
926
927    fn vector_sig_verification_8() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
928        let (public_key, sig, message) = parse_vector_sig_verification(
929            "69b7667056e1e11d6caf6e45643f8b21e7a4bebda463c7fdbc13bc98efbd0214",
930            "d3f9b12eb46c7c6fda0da3fc85bc1fd831557f9abc902a3be3cb3e8be7d1aa2f",
931            "288f7a1cd391842cce21f00e6f15471c04dc182fe4b14d92dc18910879799790",
932            "247b3c4e89a3bcadfea73c7bfd361def43715fa382b8c3edf4ae15d6e55e9979",
933            "1669bfb657fdc62c3ddd63269787fc1c969f1850fb04c933dda063ef74a56ce13e3a649700820f0061ef
934            abf849a85d474326c8a541d99830eea8131eaea584f22d88c353965dabcdc4bf6b55949fd529507dfb803ab6
935            b480cd73ca0ba00ca19c438849e2cea262a1c57d8f81cd257fb58e19dec7904da97d8386e87b84948169",
936        );
937        (public_key, sig, message, false)
938    }
939
940    fn vector_sig_verification_9() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
941        let (public_key, sig, message) = parse_vector_sig_verification(
942            "bf02cbcf6d8cc26e91766d8af0b164fc5968535e84c158eb3bc4e2d79c3cc682",
943            "069ba6cb06b49d60812066afa16ecf7b51352f2c03bd93ec220822b1f3dfba03",
944            "f5acb06c59c2b4927fb852faa07faf4b1852bbb5d06840935e849c4d293d1bad",
945            "049dab79c89cc02f1484c437f523e080a75f134917fda752f2d5ca397addfe5d",
946            "3fe60dd9ad6caccf5a6f583b3ae65953563446c4510b70da115ffaa0ba04c076115c7043ab8733403cd6
947            9c7d14c212c655c07b43a7c71b9a4cffe22c2684788ec6870dc2013f269172c822256f9e7cc674791bf2d848
948            6c0f5684283e1649576efc982ede17c7b74b214754d70402fb4bb45ad086cf2cf76b3d63f7fce39ac970",
949        );
950        (public_key, sig, message, false)
951    }
952
953    fn vector_sig_verification_10() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
954        let (public_key, sig, message) = parse_vector_sig_verification(
955            "224a4d65b958f6d6afb2904863efd2a734b31798884801fcab5a590f4d6da9de",
956            "178d51fddada62806f097aa615d33b8f2404e6b1479f5fd4859d595734d6d2b9",
957            "87b93ee2fecfda54deb8dff8e426f3c72c8864991f8ec2b3205bb3b416de93d2",
958            "4044a24df85be0cc76f21a4430b75b8e77b932a87f51e4eccbc45c263ebf8f66",
959            "983a71b9994d95e876d84d28946a041f8f0a3f544cfcc055496580f1dfd4e312a2ad418fe69dbc61db23
960            0cc0c0ed97e360abab7d6ff4b81ee970a7e97466acfd9644f828ffec538abc383d0e92326d1c88c55e1f46a6
961            68a039beaa1be631a89129938c00a81a3ae46d4aecbf9707f764dbaccea3ef7665e4c4307fa0b0a3075c",
962        );
963        (public_key, sig, message, false)
964    }
965
966    fn vector_sig_verification_11() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
967        let (public_key, sig, message) = parse_vector_sig_verification(
968            "43691c7795a57ead8c5c68536fe934538d46f12889680a9cb6d055a066228369",
969            "f8790110b3c3b281aa1eae037d4f1234aff587d903d93ba3af225c27ddc9ccac",
970            "8acd62e8c262fa50dd9840480969f4ef70f218ebf8ef9584f199031132c6b1ce",
971            "cfca7ed3d4347fb2a29e526b43c348ae1ce6c60d44f3191b6d8ea3a2d9c92154",
972            "4a8c071ac4fd0d52faa407b0fe5dab759f7394a5832127f2a3498f34aac287339e043b4ffa79528faf19
973            9dc917f7b066ad65505dab0e11e6948515052ce20cfdb892ffb8aa9bf3f1aa5be30a5bbe85823bddf70b39fd
974            7ebd4a93a2f75472c1d4f606247a9821f1a8c45a6cb80545de2e0c6c0174e2392088c754e9c8443eb5af",
975        );
976        (public_key, sig, message, false)
977    }
978
979    fn vector_sig_verification_12() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
980        let (public_key, sig, message) = parse_vector_sig_verification(
981            "9157dbfcf8cf385f5bb1568ad5c6e2a8652ba6dfc63bc1753edf5268cb7eb596",
982            "972570f4313d47fc96f7c02d5594d77d46f91e949808825b3d31f029e8296405",
983            "dfaea6f297fa320b707866125c2a7d5d515b51a503bee817de9faa343cc48eeb",
984            "8f780ad713f9c3e5a4f7fa4c519833dfefc6a7432389b1e4af463961f09764f2",
985            "0a3a12c3084c865daf1d302c78215d39bfe0b8bf28272b3c0b74beb4b7409db0718239de700785581514
986            321c6440a4bbaea4c76fa47401e151e68cb6c29017f0bce4631290af5ea5e2bf3ed742ae110b04ade83a5dbd
987            7358f29a85938e23d87ac8233072b79c94670ff0959f9c7f4517862ff829452096c78f5f2e9a7e4e9216",
988        );
989        (public_key, sig, message, false)
990    }
991
992    fn vector_sig_verification_13() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
993        let (public_key, sig, message) = parse_vector_sig_verification(
994            "072b10c081a4c1713a294f248aef850e297991aca47fa96a7470abe3b8acfdda",
995            "9581145cca04a0fb94cedce752c8f0370861916d2a94e7c647c5373ce6a4c8f5",
996            "09f5483eccec80f9d104815a1be9cc1a8e5b12b6eb482a65c6907b7480cf4f19",
997            "a4f90e560c5e4eb8696cb276e5165b6a9d486345dedfb094a76e8442d026378d",
998            "785d07a3c54f63dca11f5d1a5f496ee2c2f9288e55007e666c78b007d95cc28581dce51f490b30fa73dc
999            9e2d45d075d7e3a95fb8a9e1465ad191904124160b7c60fa720ef4ef1c5d2998f40570ae2a870ef3e894c2bc
1000            617d8a1dc85c3c55774928c38789b4e661349d3f84d2441a3b856a76949b9f1f80bc161648a1cad5588e",
1001        );
1002        (public_key, sig, message, false)
1003    }
1004
1005    fn vector_sig_verification_14() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
1006        let (public_key, sig, message) = parse_vector_sig_verification(
1007            "09308ea5bfad6e5adf408634b3d5ce9240d35442f7fe116452aaec0d25be8c24",
1008            "f40c93e023ef494b1c3079b2d10ef67f3170740495ce2cc57f8ee4b0618b8ee5",
1009            "5cc8aa7c35743ec0c23dde88dabd5e4fcd0192d2116f6926fef788cddb754e73",
1010            "9c9c045ebaa1b828c32f82ace0d18daebf5e156eb7cbfdc1eff4399a8a900ae7",
1011            "76f987ec5448dd72219bd30bf6b66b0775c80b394851a43ff1f537f140a6e7229ef8cd72ad58b1d2d202
1012            98539d6347dd5598812bc65323aceaf05228f738b5ad3e8d9fe4100fd767c2f098c77cb99c2992843ba3eed9
1013            1d32444f3b6db6cd212dd4e5609548f4bb62812a920f6e2bf1581be1ebeebdd06ec4e971862cc42055ca",
1014        );
1015        (public_key, sig, message, false)
1016    }
1017
1018    fn vector_sig_verification_15() -> (PublicKey, Vec<u8>, Vec<u8>, bool) {
1019        let (public_key, sig, message) = parse_vector_sig_verification(
1020            "2d98ea01f754d34bbc3003df5050200abf445ec728556d7ed7d5c54c55552b6d",
1021            "9b52672742d637a32add056dfd6d8792f2a33c2e69dafabea09b960bc61e230a",
1022            "06108e525f845d0155bf60193222b3219c98e3d49424c2fb2a0987f825c17959",
1023            "62b5cdd591e5b507e560167ba8f6f7cda74673eb315680cb89ccbc4eec477dce",
1024            "60cd64b2cd2be6c33859b94875120361a24085f3765cb8b2bf11e026fa9d8855dbe435acf7882e84f3c7
1025            857f96e2baab4d9afe4588e4a82e17a78827bfdb5ddbd1c211fbc2e6d884cddd7cb9d90d5bf4a7311b83f352
1026            508033812c776a0e00c003c7e0d628e50736c7512df0acfa9f2320bd102229f46495ae6d0857cc452a84",
1027        );
1028        (public_key, sig, message, true)
1029    }
1030}