╭╯ ECDSA384
Introduction
This library provides functionality for ECDSA verification over any 384-bit curve. Currently, this is the most efficient implementation out there, consuming ~8.9 million gas per call.
The approach is Strauss-Shamir double scalar multiplication with 6 bits of precompute + affine coordinates. For reference, naive implementation uses ~400 billion gas, which is 50000 times more expensive.
We also tried using projective coordinates, however, the gas consumption rose to ~9 million gas.
Functions
To use the ECDSA384 library, you need to import it.
import "@solarity/solidity-lib/libs/crypto/ECDSA384.sol";
And optionally bind it to the type with the using statement.
using ECDSA384 for *;
verify
function verify(
ECDSA384.Parameters memory curveParams_,
bytes memory hashedMessage_,
bytes memory signature_,
bytes memory pubKey_
) internal view returns (bool);
Description
The function to verify the ECDSA signature.
Parameters:
| Name | Type | Description |
|---|---|---|
curveParams | struct ECDSA384.Parameters | The 384-bit curve parameters |
hashedMessage | bytes | The already hashed message to be verified |
signature | bytes | The ECDSA signature. Equals to bytes(r) + bytes(s) |
pubKey | bytes | The full public key of a signer. Equals to bytes(x) + bytes(y). Note that signatures only from the lower part of the curve are accepted. If your s > n / 2, change it to s = n - s |
Example
function verifySECP384r1(
bytes calldata message_,
bytes calldata signature_,
bytes calldata pubKey_
) external view returns (bool) {
ECDSA384.Parameters memory curveParams_ = ECDSA384.Parameters({
a: hex"fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffeffffffff0000000000000000fffffffc",
b: hex"b3312fa7e23ee7e4988e056be3f82d19181d9c6efe8141120314088f5013875ac656398d8a2ed19d2a85c8edd3ec2aef",
gx: hex"aa87ca22be8b05378eb1c71ef320ad746e1d3b628ba79b9859f741e082542a385502f25dbf55296c3a545e3872760ab7",
gy: hex"3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5f",
p: hex"fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffeffffffff0000000000000000ffffffff",
n: hex"ffffffffffffffffffffffffffffffffffffffffffffffffc7634d81f4372ddf581a0db248b0a77aecec196accc52973"
});
return curveParams_.verify(abi.encodePacked(sha256(message_)), signature_, pubKey_);
}