
تنفيذ JavaScript مُدقَّق ومُصغَّر لتشفير المنحنيات الإهليلجية.
تطبيق JS مُدقَّق ومصغَّر لتشفير المنحنيات الإهليلجية.
للمنحنيات مشاريع شقيقة بحجم 5kb secp256k1 و ed25519. لديها سطح هجوم أصغر، لكن ميزات أقل.
noble cryptography — مجموعة عالية الأمان وقابلة للتدقيق بسهولة من مكتبات وأدوات التشفير المُحتواة.
npm install @noble/curves
deno add jsr:@noble/curves
ندعم جميع المنصات وبيئات التشغيل الرئيسية. بالنسبة لـ React Native، قد تحتاج إلى polyfill لـ getRandomValues. ملف مستقل noble-curves.js متاح أيضًا.```js // import * from '@noble/curves'; // Error: use sub-imports, to ensure small app size import { secp256k1 } from '@noble/curves/secp256k1.js'; const { secretKey, publicKey } = secp256k1.keygen(); const msg = new TextEncoder().encode('hello noble'); const sig = secp256k1.sign(msg, secretKey); const isValid = secp256k1.verify(sig, msg, publicKey);
- [توقيعات ECDSA و EdDSA و Schnorr](#ecdsa-eddsa-schnorr-signatures)
- [ECDH: أسرار Diffie-Hellman المشتركة](#ecdh-diffie-hellman-shared-secrets)
- [webcrypto: غلاف ودّي](#webcrypto-friendly-wrapper)
- [توقيعات BLS، bls12-381، bn254 المعروفة بـ alt\_bn128](#bls-signatures-bls12-381-bn254-aka-alt_bn128)
- [hash-to-curve: تجزئة إلى نقاط المنحنى](#hash-to-curve-hashing-to-curve-points)
- [OPRFs](#oprfs) | [توقيعات FROST العتبية](#frost-threshold-signatures)
- [poseidon: تجزئة Poseidon](#poseidon-poseidon-hash) | [fft: تحويل فورييه السريع](#fft-fast-fourier-transform) | [utils](#utils-byte-shuffling-conversion)
- البنية الداخلية: [رياضيات النقاط](#elliptic-curve-point-math) | [modular](#modular-modular-arithmetics--finite-fields) | [منحنيات مخصصة](#weierstrass-custom-weierstrass-curve--ecdsa)
- [المواصفات](#specs)
- [الأمان](#security) | [السرعة](#speed) | [الترقية](#upgrading) | [المساهمة والاختبار](#contributing--testing) | [الترخيص](#license)
### توقيعات ECDSA و EdDSA و Schnorr
#### secp256k1، p256، p384، p521، ed25519، ed448، brainpool```js
import { secp256k1, schnorr } from '@noble/curves/secp256k1.js';
import { p256, p384, p521 } from '@noble/curves/nist.js';
import { ed25519 } from '@noble/curves/ed25519.js';
import { ed448 } from '@noble/curves/ed448.js';
import { brainpoolP256r1, brainpoolP384r1, brainpoolP512r1 } from '@noble/curves/misc.js';
for (const curve of [
secp256k1, schnorr,
p256, p384, p521,
ed25519, ed448,
brainpoolP256r1, brainpoolP384r1, brainpoolP512r1
]) {
const { secretKey, publicKey } = curve.keygen();
const msg = new TextEncoder().encode('hello noble');
const sig = curve.sign(msg, secretKey);
const isValid = curve.verify(sig, msg, publicKey);
console.log(curve, secretKey, publicKey, sig, isValid);
}
// Specific private key
import { hexToBytes } from '@noble/curves/utils.js';
const secret2 = hexToBytes('46c930bc7bb4db7f55da20798697421b98c4175a52c630294d75a84b9c126236');
const pub2 = secp256k1.getPublicKey(secret2);
يتم تجزئة الرسائل دائمًا أولاً: راجع التوقيع المُجزأ مسبقًا. يستخدم ECDSA قيمة k حتمية، ويتبع EdDSA معيار RFC 8032، ويتبع Schnorr (secp256k1 فقط) معيار BIP 340: راجع المواصفات.
مخطط التوقيع MuSig2 وتعيين BIP324 ElligatorSwift لمنحنى secp256k1 متاحان في حزمة منفصلة.
import { ristretto255, ristretto255_hasher, ristretto255_oprf } from '@noble/curves/ed25519.js'; import { decaf448, decaf448_hasher, decaf448_oprf } from '@noble/curves/ed448.js';
console.log(ristretto255.Point, decaf448.Point);
تحقق من [RFC 9496](https://www.rfc-editor.org/rfc/rfc9496) لمزيد من المعلومات حول ristretto255 و decaf448.
تحقق من الوثائق المنفصلة لـ [Point](#elliptic-curve-point-math)، و[hasher](#hash-to-curve-hashing-to-curve-points) و[oprf](#oprfs).
#### التوقيع المُسبق التجزئة```js
import { secp256k1 } from '@noble/curves/secp256k1.js';
import { keccak_256 } from '@noble/hashes/sha3.js';
const { secretKey } = secp256k1.keygen();
const msg = new TextEncoder().encode('hello noble');
// prehash: true (default) - hash using secp256k1.hash (sha256)
const sig = secp256k1.sign(msg, secretKey);
// prehash: false - hash using custom hash
const sigKeccak = secp256k1.sign(keccak_256(msg), secretKey, { prehash: false });
بشكل افتراضي (prehash: true)، تطبق الدالتان sign() و verify() التجزئة المدمجة للمنحنى على الرسالة أولاً:
sha256 لـ secp256k1، و sha512 لـ p521. يسمح prehash: false باستخدام تجزئة مخصصة
(مثل secp256k1 + keccak_256). في noble-curves v1، كان prehash: false هو الافتراضي.
import { secp256k1 } from '@noble/curves/secp256k1.js'; const { secretKey, publicKey } = secp256k1.keygen(); const msg = new TextEncoder().encode('hello noble'); const sigRec = secp256k1.sign(msg, secretKey, { format: 'recovered' }); const publicKey_ = secp256k1.recoverPublicKey(sigRec, msg); // == publicKey
// recovered sig is compact sig with an extra byte const sigNoRec = secp256k1.sign(msg, secretKey, { format: 'compact' }); // sigNoRec == sigRec.slice(1)
// Signature instance const sigInstance = secp256k1.Signature.fromBytes(sigRec, 'recovered');
استعادة المفتاح العام مدعومة فقط مع ECDSA. إنها عملية رياضية بسيطة:
لا توجد ضمانات بأن التوقيع قد تم فعلاً. إن (r, s, h) المزوّر يُستعاد إلى
مفتاح عام عشوائي، لكن ليس من الممكن إيجاد m الذي سيؤدي إلى هذا h المزوّر المحدد.
#### ECDSA المُحصّن مع التشويش```js
import { secp256k1 } from '@noble/curves/secp256k1.js';
const { secretKey } = secp256k1.keygen();
const msg = new TextEncoder().encode('hello noble');
// extraEntropy: false - default, hedging disabled
const sigNoisy = secp256k1.sign(msg, secretKey);
// extraEntropy: true - fetch 32 random bytes from CSPRNG
const sigNoisyA = secp256k1.sign(msg, secretKey, { extraEntropy: true });
// extraEntropy: bytes - specific extra entropy
const ent = Uint8Array.from([0xca, 0xfe, 0x01, 0x23]);
const sigNoisy2 = secp256k1.sign(msg, secretKey, { extraEntropy: ent });
بشكل افتراضي، توقيعات ECDSA حتمية (RFC 6979). التوقيعات الحتمية البحتة
عرضة لهجمات الأخطاء، لذا فإن المخططات الأحدث، مثل BIP340 schnorr، تُدمج العشوائية
في توليد التوقيع - المعروف أيضًا باسم التحوّط. يُفعّل extraEntropy الوضع المتحوّط. لمزيد من المعلومات، اطّلع على
التوقيعات الحتمية ليست صديقتك.