Skip to main content

Crate ic_ec

Crate ic_ec 

Source
Expand description

§ic-ec — elliptic-curve cryptography

Curve25519 in two guises:

  • X25519 — RFC 7748 key agreement.
  • Ed25519 — RFC 8032 signatures.

Both are built on a shared constant-time field implementation (field::Fe) with 51-bit limbs.

use ic_ec::X25519;
use ic_core::traits::KeyAgreement;

let alice_sk = [0x11u8; 32];
let bob_sk = [0x22u8; 32];
let (mut alice_pk, mut bob_pk) = ([0u8; 32], [0u8; 32]);
X25519::public_key(&alice_sk, &mut alice_pk)?;
X25519::public_key(&bob_sk, &mut bob_pk)?;

let (mut s1, mut s2) = ([0u8; 32], [0u8; 32]);
X25519::agree(&alice_sk, &bob_pk, &mut s1)?;
X25519::agree(&bob_sk, &alice_pk, &mut s2)?;
assert_eq!(s1, s2);

§FIPS position

Curve25519 is not on the FIPS 186-5 / SP 800-186 approved list for signatures, and X25519 is not an approved SP 800-56A scheme. They are here because modern protocols require them, and the ontology marks them accordingly so ic-fips blocks them in approved mode. The approved curves (P-256/384/521, ECDSA, ECDH) and the post-quantum FIPS 203/204 schemes are registered in the ontology with implementation_status: Planned — an agent querying for an approved signature scheme gets an honest “not available here” rather than a silent substitution.

Re-exports§

pub use ed25519::Ed25519;
pub use ed25519::Ed25519Key;
pub use ed25519::Ed25519VerifyKey;
pub use p256::EcdhP256;
pub use p256::EcdsaP256Sha256;
pub use p384::EcdhP384;
pub use p384::EcdsaP384Sha384;
pub use x25519::X25519;

Modules§

ed25519
RFC 8032 Ed25519 signatures.
p256
NIST P-256 (secp256r1, prime256v1).
p384
NIST P-384 (secp384r1).
p521
NIST P-521 (secp521r1).
x25519
RFC 7748 X25519 key agreement.

Constants§

EC_IDS
Ontology identifiers for the schemes implemented here.
PREHASH_LENS
Digest widths ECDSA’s verify_prehash accepts. Digest widths verify_prehash accepts, on every curve (for instance crate::p256::EcdsaP256Sha256::verify_prehash): those of SHA-224, SHA-256, SHA-384 and SHA-512, and of SHA-3 and SHA-512/t at the same widths.

Functions§

prepare
Build every precomputed table now, rather than on first use.