|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Ed25519 signatures (RFC 8032) for ssh-ed25519 host keys + client auth. More...
#include "protocore_config.h"Go to the source code of this file.
Classes | |
| struct | Ed25519Ns |
| Dispatch table. Addressed by offset, so the layout is asserted below. More... | |
Macros | |
| #define | PROTOCORE_ED25519_SEED_LEN 32 |
| Ed25519 seed (private key) length. | |
| #define | PROTOCORE_ED25519_PUBKEY_LEN 32 |
| Ed25519 public key length. | |
| #define | PROTOCORE_ED25519_SIG_LEN 64 |
| Ed25519 signature length (R || S). | |
Functions | |
| PROTOCORE_NS_LAYOUT (Ed25519Ns, pubkey, sign, verify) | |
| proto_bool | protocore_ed25519_pubkey (uint8_t *work, const uint8_t *seed, uint8_t *pub) |
| Derive the 32-byte public key A from the seed. | |
| proto_bool | protocore_ed25519_sign (uint8_t *work, const uint8_t *seed, const uint8_t *msg, size_t msg_len, uint8_t *sig) |
| Sign deterministically (RFC 8032 §5.1.6), writing R || S. | |
| proto_bool | protocore_ed25519_verify (uint8_t *work, const uint8_t *pub, const uint8_t *msg, size_t msg_len, const uint8_t *sig) |
| Check a signature (RFC 8032 §5.1.7); the answer is Ed25519Ns::ok. | |
Variables | |
| PROTOCORE_NS Ed25519Ns Ed25519 | PROTOCORE_UNUSED |
| Module namespace. | |
Ed25519 signatures (RFC 8032) for ssh-ed25519 host keys + client auth.
PureEdDSA over edwards25519. Deterministic signing (RFC 8032 §5.1.6) - no RNG - and verification, built on the shared Curve25519 field arithmetic (protocore_curve25519) and the Sha512Ns entries, so which arm hashes is not visible here. Correctness is pinned to the RFC 8032 §7.1 vectors and to a reference implementation (test_ed25519).
The server signs the KEX exchange hash with its ssh-ed25519 host key, and verifies a client's ed25519 public-key authentication signature.
work is PROTOCORE_ED25519_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call, so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes it. That is what keeps the expanded seed, the nonce and the challenge from outliving the caller.
Definition in file ed25519.h.
| #define PROTOCORE_ED25519_SEED_LEN 32 |
| #define PROTOCORE_ED25519_PUBKEY_LEN 32 |
| #define PROTOCORE_ED25519_SIG_LEN 64 |
| PROTOCORE_NS_LAYOUT | ( | Ed25519Ns | , |
| pubkey | , | ||
| sign | , | ||
| verify | |||
| ) |
| proto_bool protocore_ed25519_pubkey | ( | uint8_t * | work, |
| const uint8_t * | seed, | ||
| uint8_t * | pub | ||
| ) |
Derive the 32-byte public key A from the seed.
| work | PROTOCORE_ED25519_BORROW bytes the caller took. Not held past the call. |
| seed | PROTOCORE_ED25519_SEED_LEN bytes |
| pub | PROTOCORE_ED25519_PUBKEY_LEN bytes |
| proto_bool protocore_ed25519_sign | ( | uint8_t * | work, |
| const uint8_t * | seed, | ||
| const uint8_t * | msg, | ||
| size_t | msg_len, | ||
| uint8_t * | sig | ||
| ) |
Sign deterministically (RFC 8032 §5.1.6), writing R || S.
| work | PROTOCORE_ED25519_BORROW bytes the caller took. Not held past the call. |
| seed | PROTOCORE_ED25519_SEED_LEN bytes |
| msg | the message |
| msg_len | its length |
| sig | PROTOCORE_ED25519_SIG_LEN bytes, R || S |
| proto_bool protocore_ed25519_verify | ( | uint8_t * | work, |
| const uint8_t * | pub, | ||
| const uint8_t * | msg, | ||
| size_t | msg_len, | ||
| const uint8_t * | sig | ||
| ) |
Check a signature (RFC 8032 §5.1.7); the answer is Ed25519Ns::ok.
| work | PROTOCORE_ED25519_BORROW bytes the caller took. Not held past the call. |
| pub | PROTOCORE_ED25519_PUBKEY_LEN bytes |
| msg | the message |
| msg_len | its length |
| sig | PROTOCORE_ED25519_SIG_LEN bytes, R || S |
| PROTOCORE_NS Ed25519Ns Ed25519 PROTOCORE_UNUSED |
Module namespace.