登录
首页 >  Golang >  Go问答

实现JavaScript的elliptic库与Golang的ecdsa库之间的互通性

来源:stackoverflow

时间:2024-03-10 21:48:27 352浏览 收藏

哈喽!大家好,很高兴又见面了,我是golang学习网的一名作者,今天由我给大家带来一篇《实现JavaScript的elliptic库与Golang的ecdsa库之间的互通性》,本文主要会讲到等等知识点,希望大家一起学习进步,也欢迎大家关注、点赞、收藏、转发! 下面就一起来看看吧!

问题内容

我在使用 golang 的 ecdsa 库验证椭圆 javascript 库生成的签名时遇到困难。使用的椭圆曲线是 secp256k1。

以下是一些代码片段:

打字稿实用函数:

import * as bigint from 'big-integer';
declare const require: any;
var ec = require('elliptic').ec;
var ec = new ec('secp256k1');
const sha256 = require("crypto-js/sha256");


const generateprivatekey = function(): string {
    return ec.genkeypair().getprivate().tostring();
}

const generatepublickey = function(privatekey: string): publickey {
    const publickey: any = ec.keyfromprivate(privatekey).getpublic();
    return new publickey(
        publickey.getx().tostring("hex"),
        publickey.gety().tostring("hex")
    );
}

const signmessage = function(message: string, privatekey: string): signature {
    message = sha256(message).tostring();
    const key = ec.keyfromprivate(privatekey);
    const signature: signature = json.parse(json.stringify(key.sign(message)));
    return new signature(signature.r, signature.s, signature.recoveryparam);
}

const verifymessage = function(message: string, publickey: publickey, signature: signature): boolean {
    message = sha256(message).tostring();
    const key = ec.keyfrompublic(publickey, 'hex');
    return key.verify(message, signature);
}

class publickey {
    constructor(
        public x: string,
        public y: string
    ) { }
}

class signature {
    constructor(
        public r: string,
        public s: string,
        public recoveryparam: number
    ) { }
}

使用上面的函数生成的示例签名:

// private key
const privatekey = "87447468790127269743127941512029311682561810964950681691418579250915022213638"

// public key
const publickey = {
  x: 'fe0f1982436d08bfc2a603d85738bc874cbc4d2108e63eca0264afd8e62244df',
  y: '199b6155f2532aa5d6404c32ea5fb7de1c9af741b99d75dcb73285bfd8525176'
}

// sample message
const message = "hello world"

// generated signature
const signature = {
  r: 'be4022f929aa1aef40e563a0e30e1b23b9ca5a73d510cf9d95a2a51db4f52965',
  s: 'c27b747099192bda25985fdd5dd588de44c40b15aa038aa65399aa5e9e5ec7b',
  recoveryparam: 1
}

用于验证签名的go代码:

xval := new(big.int)
xval.setstring("fe0f1982436d08bfc2a603d85738bc874cbc4d2108e63eca0264afd8e62244df", 16)
yval := new(big.int)
yval.setstring("199b6155f2532aa5d6404c32ea5fb7de1c9af741b99d75dcb73285bfd8525176", 16)

rval := new(big.int)
rval.setstring("be4022f929aa1aef40e563a0e30e1b23b9ca5a73d510cf9d95a2a51db4f52965", 16)
sval := new(big.int)
sval.setstring("c27b747099192bda25985fdd5dd588de44c40b15aa038aa65399aa5e9e5ec7b", 16)


hash := fmt.sprintf(
    "%x",
    sha256.sum256([]byte("hello world")),
)

pubkey := ecdsa.publickey{
    curve: secp256k1.s256(),
    x:     xval,
    y:     yval,
}

fmt.printf("sig verification: %v", ecdsa.verify(&pubkey, []byte(hash), rval, sval))

输出为:

SIG VERIFICATION: false

输出应该是正确的。如果对更多详细信息有任何疑问,请通知我。

javascript 椭圆库

golang edcsa 库


解决方案


解决方案是使用 decodestring 函数对消息哈希进行哈希处理。以下是解决方案的更新代码:

xVal := new(big.Int)
xVal.SetString("fe0f1982436d08bfc2a603d85738bc874cbc4d2108e63eca0264afd8e62244df", 16)
yVal := new(big.Int)
yVal.SetString("199b6155f2532aa5d6404c32ea5fb7de1c9af741b99d75dcb73285bfd8525176", 16)

rVal := new(big.Int)
rVal.SetString("be4022f929aa1aef40e563a0e30e1b23b9ca5a73d510cf9d95a2a51db4f52965", 16)
sVal := new(big.Int)
sVal.SetString("c27b747099192bda25985fdd5dd588de44c40b15aa038aa65399aa5e9e5ec7b", 16)

msgHash := fmt.Sprintf(
    "%x",
    sha256.Sum256([]byte("hello world")),
)
    
pubKey := ecdsa.PublicKey{
    Curve: secp256k1.S256(),
    X:     xVal,
    Y:     yVal,
}

hash, hashDecodeError := hex.DecodeString(msgHash)

if hashDecodeError != nil {
    log.Println(hashDecodeError)
    panic("internal server error")
}

fmt.Printf("SIG VERIFICATION: %v", ecdsa.Verify(&pubKey, hash, rVal, sVal))

使用上述代码进行的验证将评估为 true。

感谢用户 mh-cbon 提供的解决方案。

以上就是《实现JavaScript的elliptic库与Golang的ecdsa库之间的互通性》的详细内容,更多关于的资料请关注golang学习网公众号!

声明:本文转载于:stackoverflow 如有侵犯,请联系study_golang@163.com删除
相关阅读
更多>
最新阅读
更多>
课程推荐
更多>