Expand description
§RustCrypto: BIGN P-256 (bign-curve256v1) elliptic curve
Pure Rust implementation of the BIGN P-256 (a.k.a. bign-curve256v1) elliptic curve
with support for ECDSA signing/verification, and general purpose curve
arithmetic support implemented in terms of traits from the elliptic-curve
crate.
§⚠️ Security Warning
The elliptic curve arithmetic contained in this crate has never been independently audited!
This crate has been designed with the goal of ensuring that secret-dependent
operations are performed in constant time (using the subtle crate and
constant-time formulas). However, it has not been thoroughly assessed to ensure
that generated assembly is constant time on common CPU architectures.
USE AT YOUR OWN RISK!
§Supported Algorithms
§PKCS#8 Key Encoding
PKCS#8 is a private key format with support for multiple algorithms. It can be encoded as binary DER or text PEM.
You can recognize PEM encoded PKCS#8 private keys because they do not have an algorithm name in the type label, e.g.:
-----BEGIN PRIVATE KEY-----PKCS#8 support is gated under the pkcs8 feature. The pem feature, which is
enabled by default, adds PEM decoding and also enables pkcs8.
The same pattern is used by the other curve crates in this repository which
re-export pkcs8.
The following traits can be used to decode/encode secret and public keys as
PKCS#8/SPKI. Note that pkcs8 is re-exported from bignp256 when the pkcs8
feature is enabled:
pkcs8::DecodePrivateKey: decode private keys from PKCS#8pkcs8::EncodePrivateKey: encode private keys to PKCS#8pkcs8::DecodePublicKey: decode public keys from SPKIpkcs8::EncodePublicKey: encode public keys to SPKI
For private keys, [SecretKey::from_der] and [SecretKey::from_pem] provide
convenience methods which can decode PKCS#8 keys. Use the trait methods above
when the input is expected to be specifically PKCS#8.
§Example
use bignp256::SecretKey;
use bignp256::pkcs8::DecodePrivateKey;
// WARNING: Do not hardcode private keys in your source code. This is for demonstration purposes only.
let pem = r#"-----BEGIN PRIVATE KEY-----
MD8CAQAwGAYKKnAAAgAiZS0CAQYKKnAAAgAiZS0DAQQgAQEBAQEBAQEBAQEBAQEB
AQEBAQEBAQEBAQEBAQEBAQE=
-----END PRIVATE KEY-----"#;
let secret_key = SecretKey::from_pkcs8_pem(pem)?;§About BIGN P-256
BIGN P-256 is a Weierstrass curve specified in STB 34.101.45-2013. Also known as bign-curve256v1.
§License
All crates licensed under either of
at your option.
§Contribution
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.
Re-exports§
pub use arithmetic::AffinePoint;arithmeticpub use arithmetic::ProjectivePoint;arithmeticpub use public_key::PublicKey;arithmeticpub use secret_key::SecretKey;arithmeticpub use elliptic_curve;pub use elliptic_curve::pkcs8;pkcs8
Modules§
- arithmetic
arithmetic - Pure Rust implementation of group operations on bign-curve256v1.
- ecdh
ecdh - Elliptic Curve Diffie-Hellman (Ephemeral) Support.
- ecdsa
ecdsa - BignP256 Digital Signature Algorithm as defined in STB 34.101.45-2013 § 7.
- public_
key arithmetic - Public key types and traits
- secret_
key arithmetic - Bign256 secret key.
- swu
swu - SWU implementation for
BignP256 - test_
vectors test-vectors - bignp256 test vectors.
Structs§
- Bign
P256 - BIGN P-256 elliptic curve.
- Scalar
arithmetic - Element in the bign-curve256v1 scalar field modulo n
Type Aliases§
- Field
Bytes - BIGN P-256 field element serialized as bytes.
- NonZero
Scalar arithmetic - Non-zero scalar field element.
- Result
- Bign256 result type
- Scalar
Value arithmetic - Generic scalar type with primitive functionality.#
- Sec1
Point - SEC1 encoded point.
- U256
- 256-bit unsigned big integer.