
감사된 & 최소한의 타원 곡선 암호화 JS 구현.
감사된 & 최소한의 타원 곡선 암호 구현 JS.
곡선에는 5kb 자매 프로젝트가 있습니다 secp256k1 & ed25519. 이들은 공격 표면이 더 작지만 기능이 적습니다.
noble 암호학 — 높은 보안성, 쉽게 감사할 수 있는 포함된 암호 라이브러리 및 도구 세트.
npm install @noble/curves
deno add jsr:@noble/curves
우리는 모든 주요 플랫폼과 런타임을 지원합니다. React Native의 경우 getRandomValues용 폴리필이 필요할 수 있습니다. 독립 실행형 파일 noble-curves.js도 사용할 수 있습니다.```js // import * from '@noble/curves'; // Error: use sub-imports, to ensure small app size import { secp256k1 } from '@noble/curves/secp256k1.js'; const { secretKey, publicKey } = secp256k1.keygen(); const msg = new TextEncoder().encode('hello noble'); const sig = secp256k1.sign(msg, secretKey); const isValid = secp256k1.verify(sig, msg, publicKey);
- [ECDSA, EdDSA, Schnorr 서명](#ecdsa-eddsa-schnorr-signatures)
- [ECDH: Diffie-Hellman 공유 비밀](#ecdh-diffie-hellman-shared-secrets)
- [webcrypto: 친화적 래퍼](#webcrypto-friendly-wrapper)
- [BLS 서명, bls12-381, bn254 aka alt\_bn128](#bls-signatures-bls12-381-bn254-aka-alt_bn128)
- [hash-to-curve: 곡선 점으로 해싱](#hash-to-curve-hashing-to-curve-points)
- [OPRFs](#oprfs) | [FROST 임계 서명](#frost-threshold-signatures)
- [poseidon: Poseidon 해시](#poseidon-poseidon-hash) | [fft: 고속 푸리에 변환](#fft-fast-fourier-transform) | [utils](#utils-byte-shuffling-conversion)
- 내부: [점 수학](#elliptic-curve-point-math) | [모듈러](#modular-modular-arithmetics--finite-fields) | [사용자 정의 곡선](#weierstrass-custom-weierstrass-curve--ecdsa)
- [사양](#specs)
- [보안](#security) | [속도](#speed) | [업그레이드](#upgrading) | [기여 및 테스트](#contributing--testing) | [라이선스](#license)
### ECDSA, EdDSA, Schnorr 서명
#### secp256k1, p256, p384, p521, ed25519, ed448, brainpool```js
import { secp256k1, schnorr } from '@noble/curves/secp256k1.js';
import { p256, p384, p521 } from '@noble/curves/nist.js';
import { ed25519 } from '@noble/curves/ed25519.js';
import { ed448 } from '@noble/curves/ed448.js';
import { brainpoolP256r1, brainpoolP384r1, brainpoolP512r1 } from '@noble/curves/misc.js';
for (const curve of [
secp256k1, schnorr,
p256, p384, p521,
ed25519, ed448,
brainpoolP256r1, brainpoolP384r1, brainpoolP512r1
]) {
const { secretKey, publicKey } = curve.keygen();
const msg = new TextEncoder().encode('hello noble');
const sig = curve.sign(msg, secretKey);
const isValid = curve.verify(sig, msg, publicKey);
console.log(curve, secretKey, publicKey, sig, isValid);
}
// Specific private key
import { hexToBytes } from '@noble/curves/utils.js';
const secret2 = hexToBytes('46c930bc7bb4db7f55da20798697421b98c4175a52c630294d75a84b9c126236');
const pub2 = secp256k1.getPublicKey(secret2);
Messages는 항상 먼저 해시됩니다: prehashed signing을 참조하세요. ECDSA는 결정적 k를 사용하고, EdDSA는 RFC 8032를 따르며, Schnorr(secp256k1 전용)는 BIP 340을 따릅니다: Specs를 참조하세요.
MuSig2 서명 방식과 secp256k1용 BIP324 ElligatorSwift 매핑은 별도 패키지에서 사용할 수 있습니다.
import { ristretto255, ristretto255_hasher, ristretto255_oprf } from '@noble/curves/ed25519.js'; import { decaf448, decaf448_hasher, decaf448_oprf } from '@noble/curves/ed448.js';
console.log(ristretto255.Point, decaf448.Point);
[RFC 9496](https://www.rfc-editor.org/rfc/rfc9496)에서 ristretto255 및 decaf448에 대한 더 많은 정보를 확인하세요.
[Point](#elliptic-curve-point-math), [hasher](#hash-to-curve-hashing-to-curve-points) 및 [oprf](#oprfs)에 대한 별도 문서를 확인하세요.
#### 사전 해시 서명```js
import { secp256k1 } from '@noble/curves/secp256k1.js';
import { keccak_256 } from '@noble/hashes/sha3.js';
const { secretKey } = secp256k1.keygen();
const msg = new TextEncoder().encode('hello noble');
// prehash: true (default) - hash using secp256k1.hash (sha256)
const sig = secp256k1.sign(msg, secretKey);
// prehash: false - hash using custom hash
const sigKeccak = secp256k1.sign(keccak_256(msg), secretKey, { prehash: false });
기본적으로(prehash: true), sign()과 verify()는 먼저 메시지에 곡선의 내장 해시를 적용합니다:
secp256k1에는 sha256, p521에는 sha512. prehash: false를 사용하면 사용자 정의 해시를 사용할 수 있습니다
(예: secp256k1 + keccak_256). noble-curves v1에서는 prehash: false가 기본값이었습니다.
import { secp256k1 } from '@noble/curves/secp256k1.js'; const { secretKey, publicKey } = secp256k1.keygen(); const msg = new TextEncoder().encode('hello noble'); const sigRec = secp256k1.sign(msg, secretKey, { format: 'recovered' }); const publicKey_ = secp256k1.recoverPublicKey(sigRec, msg); // == publicKey
// recovered sig is compact sig with an extra byte const sigNoRec = secp256k1.sign(msg, secretKey, { format: 'compact' }); // sigNoRec == sigRec.slice(1)
// Signature instance const sigInstance = secp256k1.Signature.fromBytes(sigRec, 'recovered');
Public key recovery는 ECDSA에서만 지원됩니다. 이는 단순한 수학 연산입니다:
서명이 실제로 수행되었다는 보장은 없습니다. 위조된 (r, s, h)는
임의의 공개 키로 복구되지만, 이 특정 위조된 h로 이어질 m을 찾는 것은 실행 가능하지 않습니다.
#### 노이즈를 사용한 Hedged ECDSA```js
import { secp256k1 } from '@noble/curves/secp256k1.js';
const { secretKey } = secp256k1.keygen();
const msg = new TextEncoder().encode('hello noble');
// extraEntropy: false - default, hedging disabled
const sigNoisy = secp256k1.sign(msg, secretKey);
// extraEntropy: true - fetch 32 random bytes from CSPRNG
const sigNoisyA = secp256k1.sign(msg, secretKey, { extraEntropy: true });
// extraEntropy: bytes - specific extra entropy
const ent = Uint8Array.from([0xca, 0xfe, 0x01, 0x23]);
const sigNoisy2 = secp256k1.sign(msg, secretKey, { extraEntropy: ent });
기본적으로 ECDSA 서명은 결정적입니다(RFC 6979). 순수하게 결정적인 서명은
폴트 공격에 취약하므로, BIP340 schnorr과 같은 최신 방식은 서명 생성에
무작위성을 도입합니다 - 일명 헤징(hedging)이라고 합니다. extraEntropy는 헤지드 모드를 활성화합니다. 더 많은 정보는
Deterministic signatures are not your friends를 확인하세요.
import { ed25519 } from '@noble/curves/ed25519.js'; const { secretKey, publicKey } = ed25519.keygen(); const msg = new TextEncoder().encode('hello noble'); const sig = ed25519.sign(msg, secretKey); // zip215: true const isValid = ed25519.verify(sig, msg, publicKey); // SBS / e-voting / RFC8032 / FIPS 186-5 const isValidRfc = ed25519.verify(sig, msg, publicKey, { zip215: false });
* `zip215: true` (기본값)는 [ZIP215](https://zips.z.cash/zip-0215)에 정의된 더 관대하고 [합의 친화적인](https://hdevalence.ca/blog/2020-10-04-its-25519am) 검증 규칙을 사용합니다.
* `zip215: false`는 엄격한 RFC 8032 / FIPS 186-5 검증을 적용하고 SBS 기반
부인 방지를 추가하는데, 이는 계약 서명, 전자 투표 및 블록체인에 유용합니다.
두 모드 모두 SUF-CMA(선택 메시지 공격에 대한 강한 위조 불가능성)를 갖추고 있습니다;
대부분의 다른 라이브러리는 SUF-CMA도 SBS도 갖추고 있지 않습니다.
자세한 내용은 [Taming the many EdDSAs](https://eprint.iacr.org/2020/1244)를 참조하세요.