ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
ed25519.h File Reference

Ed25519 signatures (RFC 8032) for ssh-ed25519 host keys + client auth. More...

#include "protocore_config.h"

Go to the source code of this file.

Classes

struct  Ed25519Ns
 Dispatch table. Addressed by offset, so the layout is asserted below. More...
 

Macros

#define PROTOCORE_ED25519_SEED_LEN   32
 Ed25519 seed (private key) length.
 
#define PROTOCORE_ED25519_PUBKEY_LEN   32
 Ed25519 public key length.
 
#define PROTOCORE_ED25519_SIG_LEN   64
 Ed25519 signature length (R || S).
 

Functions

 PROTOCORE_NS_LAYOUT (Ed25519Ns, pubkey, sign, verify)
 
proto_bool protocore_ed25519_pubkey (uint8_t *work, const uint8_t *seed, uint8_t *pub)
 Derive the 32-byte public key A from the seed.
 
proto_bool protocore_ed25519_sign (uint8_t *work, const uint8_t *seed, const uint8_t *msg, size_t msg_len, uint8_t *sig)
 Sign deterministically (RFC 8032 §5.1.6), writing R || S.
 
proto_bool protocore_ed25519_verify (uint8_t *work, const uint8_t *pub, const uint8_t *msg, size_t msg_len, const uint8_t *sig)
 Check a signature (RFC 8032 §5.1.7); the answer is Ed25519Ns::ok.
 

Variables

PROTOCORE_NS Ed25519Ns Ed25519 PROTOCORE_UNUSED
 Module namespace.
 

Detailed Description

Ed25519 signatures (RFC 8032) for ssh-ed25519 host keys + client auth.

PureEdDSA over edwards25519. Deterministic signing (RFC 8032 §5.1.6) - no RNG - and verification, built on the shared Curve25519 field arithmetic (protocore_curve25519) and the Sha512Ns entries, so which arm hashes is not visible here. Correctness is pinned to the RFC 8032 §7.1 vectors and to a reference implementation (test_ed25519).

The server signs the KEX exchange hash with its ssh-ed25519 host key, and verifies a client's ed25519 public-key authentication signature.

work is PROTOCORE_ED25519_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call, so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes it. That is what keeps the expanded seed, the nonce and the challenge from outliving the caller.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file ed25519.h.

Macro Definition Documentation

◆ PROTOCORE_ED25519_SEED_LEN

#define PROTOCORE_ED25519_SEED_LEN   32

Ed25519 seed (private key) length.

Definition at line 33 of file ed25519.h.

◆ PROTOCORE_ED25519_PUBKEY_LEN

#define PROTOCORE_ED25519_PUBKEY_LEN   32

Ed25519 public key length.

Definition at line 36 of file ed25519.h.

◆ PROTOCORE_ED25519_SIG_LEN

#define PROTOCORE_ED25519_SIG_LEN   64

Ed25519 signature length (R || S).

Definition at line 39 of file ed25519.h.

Function Documentation

◆ PROTOCORE_NS_LAYOUT()

PROTOCORE_NS_LAYOUT ( Ed25519Ns  ,
pubkey  ,
sign  ,
verify   
)

◆ protocore_ed25519_pubkey()

proto_bool protocore_ed25519_pubkey ( uint8_t *  work,
const uint8_t *  seed,
uint8_t *  pub 
)

Derive the 32-byte public key A from the seed.

Parameters
workPROTOCORE_ED25519_BORROW bytes the caller took. Not held past the call.
seedPROTOCORE_ED25519_SEED_LEN bytes
pubPROTOCORE_ED25519_PUBKEY_LEN bytes
Returns
PROTO_TRUE on success.

◆ protocore_ed25519_sign()

proto_bool protocore_ed25519_sign ( uint8_t *  work,
const uint8_t *  seed,
const uint8_t *  msg,
size_t  msg_len,
uint8_t *  sig 
)

Sign deterministically (RFC 8032 §5.1.6), writing R || S.

Parameters
workPROTOCORE_ED25519_BORROW bytes the caller took. Not held past the call.
seedPROTOCORE_ED25519_SEED_LEN bytes
msgthe message
msg_lenits length
sigPROTOCORE_ED25519_SIG_LEN bytes, R || S
Returns
PROTO_TRUE on success.

◆ protocore_ed25519_verify()

proto_bool protocore_ed25519_verify ( uint8_t *  work,
const uint8_t *  pub,
const uint8_t *  msg,
size_t  msg_len,
const uint8_t *  sig 
)

Check a signature (RFC 8032 §5.1.7); the answer is Ed25519Ns::ok.

Parameters
workPROTOCORE_ED25519_BORROW bytes the caller took. Not held past the call.
pubPROTOCORE_ED25519_PUBKEY_LEN bytes
msgthe message
msg_lenits length
sigPROTOCORE_ED25519_SIG_LEN bytes, R || S
Returns
PROTO_TRUE on success.

Variable Documentation

◆ PROTOCORE_UNUSED

PROTOCORE_NS Ed25519Ns Ed25519 PROTOCORE_UNUSED
Initial value:
= {
proto_bool protocore_ed25519_verify(uint8_t *work, const uint8_t *pub, const uint8_t *msg, size_t msg_len, const uint8_t *sig)
Check a signature (RFC 8032 §5.1.7); the answer is Ed25519Ns::ok.
proto_bool protocore_ed25519_sign(uint8_t *work, const uint8_t *seed, const uint8_t *msg, size_t msg_len, uint8_t *sig)
Sign deterministically (RFC 8032 §5.1.6), writing R || S.
proto_bool protocore_ed25519_pubkey(uint8_t *work, const uint8_t *seed, uint8_t *pub)
Derive the 32-byte public key A from the seed.

Module namespace.

Definition at line 81 of file ed25519.h.