Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
noble-curves — 감사된 & 최소한의 타원 곡선 암호화 JS 구현. | Kitploit
도구/GitHubGitHub/paulmillr/noble-curves
Encryption/Decryption ToolsHash AnalysisCryptographyUtilities & FrameworksLearning & Education
GitHubpaulmillr/noble-curves

noble-curves

감사된 & 최소한의 타원 곡선 암호화 JS 구현.

저장소 보기
9601036627일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트

noble-curves

감사된 & 최소한의 타원 곡선 암호 구현 JS.

  • 🔒 독립적인 보안 회사에 의해 감사됨
  • 🪶 최소한: 15KB (gzip 압축) secp256k1, 사용되지 않는 코드는 빌드에서 제외됨
  • 🏎 빠름: JS 엔진의 특성을 고려하여 수작업으로 최적화됨
  • 🔍 신뢰할 수 있음: 교차 라이브러리 / wycheproof 테스트로 정확성 보장
  • ➰ Weierstrass, Edwards 곡선; ECDSA, EdDSA, Schnorr, BLS 서명
  • ✍️ ECDH, hash-to-curve, OPRF, FROST, Poseidon 해시, FFT
  • 🔖 ed25519, ed448에서 부인 방지 (SUF-CMA, SBS) & 합의 친화성 (ZIP215)
  • 🥈 네이티브 WebCrypto 위에 동일한 API를 가진 래퍼

곡선에는 5kb 자매 프로젝트가 있습니다 secp256k1 & ed25519. 이들은 공격 표면이 더 작지만 기능이 적습니다.

이 라이브러리는 noble 암호학에 속합니다

noble 암호학 — 높은 보안성, 쉽게 감사할 수 있는 포함된 암호 라이브러리 및 도구 세트.

  • 의존성 없음 또는 최소
  • 매우 읽기 쉬운 TypeScript / JS 코드
  • PGP 서명된 릴리스 및 투명한 NPM 빌드
  • 모든 라이브러리: ciphers, curves, hashes, post-quantum, 5kb secp256k1 / ed25519
  • WASM 버전: awasm-noble
  • 홈페이지를 확인하세요 읽기 자료, 문서, noble로 만든 앱을 위해

사용법

npm install @noble/curves

deno add jsr:@noble/curves

우리는 모든 주요 플랫폼과 런타임을 지원합니다. React Native의 경우 getRandomValues용 폴리필이 필요할 수 있습니다. 독립 실행형 파일 noble-curves.js도 사용할 수 있습니다.```js // import * from '@noble/curves'; // Error: use sub-imports, to ensure small app size import { secp256k1 } from '@noble/curves/secp256k1.js'; const { secretKey, publicKey } = secp256k1.keygen(); const msg = new TextEncoder().encode('hello noble'); const sig = secp256k1.sign(msg, secretKey); const isValid = secp256k1.verify(sig, msg, publicKey);

- [ECDSA, EdDSA, Schnorr 서명](#ecdsa-eddsa-schnorr-signatures)
- [ECDH: Diffie-Hellman 공유 비밀](#ecdh-diffie-hellman-shared-secrets)
- [webcrypto: 친화적 래퍼](#webcrypto-friendly-wrapper)
- [BLS 서명, bls12-381, bn254 aka alt\_bn128](#bls-signatures-bls12-381-bn254-aka-alt_bn128)
- [hash-to-curve: 곡선 점으로 해싱](#hash-to-curve-hashing-to-curve-points)
- [OPRFs](#oprfs) | [FROST 임계 서명](#frost-threshold-signatures)
- [poseidon: Poseidon 해시](#poseidon-poseidon-hash) | [fft: 고속 푸리에 변환](#fft-fast-fourier-transform) | [utils](#utils-byte-shuffling-conversion)
- 내부: [점 수학](#elliptic-curve-point-math) | [모듈러](#modular-modular-arithmetics--finite-fields) | [사용자 정의 곡선](#weierstrass-custom-weierstrass-curve--ecdsa)
- [사양](#specs)
- [보안](#security) | [속도](#speed) | [업그레이드](#upgrading) | [기여 및 테스트](#contributing--testing) | [라이선스](#license)

### ECDSA, EdDSA, Schnorr 서명

#### secp256k1, p256, p384, p521, ed25519, ed448, brainpool```js
import { secp256k1, schnorr } from '@noble/curves/secp256k1.js';
import { p256, p384, p521 } from '@noble/curves/nist.js';
import { ed25519 } from '@noble/curves/ed25519.js';
import { ed448 } from '@noble/curves/ed448.js';
import { brainpoolP256r1, brainpoolP384r1, brainpoolP512r1 } from '@noble/curves/misc.js';
for (const curve of [
  secp256k1, schnorr,
  p256, p384, p521,
  ed25519, ed448,
  brainpoolP256r1, brainpoolP384r1, brainpoolP512r1
]) {
  const { secretKey, publicKey } = curve.keygen();
  const msg = new TextEncoder().encode('hello noble');
  const sig = curve.sign(msg, secretKey);
  const isValid = curve.verify(sig, msg, publicKey);
  console.log(curve, secretKey, publicKey, sig, isValid);
}

// Specific private key
import { hexToBytes } from '@noble/curves/utils.js';
const secret2 = hexToBytes('46c930bc7bb4db7f55da20798697421b98c4175a52c630294d75a84b9c126236');
const pub2 = secp256k1.getPublicKey(secret2);

Messages는 항상 먼저 해시됩니다: prehashed signing을 참조하세요. ECDSA는 결정적 k를 사용하고, EdDSA는 RFC 8032를 따르며, Schnorr(secp256k1 전용)는 BIP 340을 따릅니다: Specs를 참조하세요.

MuSig2 서명 방식과 secp256k1용 BIP324 ElligatorSwift 매핑은 별도 패키지에서 사용할 수 있습니다.

ristretto255, decaf448```ts

import { ristretto255, ristretto255_hasher, ristretto255_oprf } from '@noble/curves/ed25519.js'; import { decaf448, decaf448_hasher, decaf448_oprf } from '@noble/curves/ed448.js';

console.log(ristretto255.Point, decaf448.Point);

[RFC 9496](https://www.rfc-editor.org/rfc/rfc9496)에서 ristretto255 및 decaf448에 대한 더 많은 정보를 확인하세요.
[Point](#elliptic-curve-point-math), [hasher](#hash-to-curve-hashing-to-curve-points) 및 [oprf](#oprfs)에 대한 별도 문서를 확인하세요.

#### 사전 해시 서명```js
import { secp256k1 } from '@noble/curves/secp256k1.js';
import { keccak_256 } from '@noble/hashes/sha3.js';
const { secretKey } = secp256k1.keygen();
const msg = new TextEncoder().encode('hello noble');
// prehash: true (default) - hash using secp256k1.hash (sha256)
const sig = secp256k1.sign(msg, secretKey);
// prehash: false - hash using custom hash
const sigKeccak = secp256k1.sign(keccak_256(msg), secretKey, { prehash: false });

기본적으로(prehash: true), sign()과 verify()는 먼저 메시지에 곡선의 내장 해시를 적용합니다: secp256k1에는 sha256, p521에는 sha512. prehash: false를 사용하면 사용자 정의 해시를 사용할 수 있습니다 (예: secp256k1 + keccak_256). noble-curves v1에서는 prehash: false가 기본값이었습니다.

서명에서 공개 키 복구하기```js

import { secp256k1 } from '@noble/curves/secp256k1.js'; const { secretKey, publicKey } = secp256k1.keygen(); const msg = new TextEncoder().encode('hello noble'); const sigRec = secp256k1.sign(msg, secretKey, { format: 'recovered' }); const publicKey_ = secp256k1.recoverPublicKey(sigRec, msg); // == publicKey

// recovered sig is compact sig with an extra byte const sigNoRec = secp256k1.sign(msg, secretKey, { format: 'compact' }); // sigNoRec == sigRec.slice(1)

// Signature instance const sigInstance = secp256k1.Signature.fromBytes(sigRec, 'recovered');

Public key recovery는 ECDSA에서만 지원됩니다. 이는 단순한 수학 연산입니다:
서명이 실제로 수행되었다는 보장은 없습니다. 위조된 (r, s, h)는
임의의 공개 키로 복구되지만, 이 특정 위조된 h로 이어질 m을 찾는 것은 실행 가능하지 않습니다.

#### 노이즈를 사용한 Hedged ECDSA```js
import { secp256k1 } from '@noble/curves/secp256k1.js';
const { secretKey } = secp256k1.keygen();
const msg = new TextEncoder().encode('hello noble');
// extraEntropy: false - default, hedging disabled
const sigNoisy = secp256k1.sign(msg, secretKey);
// extraEntropy: true - fetch 32 random bytes from CSPRNG
const sigNoisyA = secp256k1.sign(msg, secretKey, { extraEntropy: true });
// extraEntropy: bytes - specific extra entropy
const ent = Uint8Array.from([0xca, 0xfe, 0x01, 0x23]);
const sigNoisy2 = secp256k1.sign(msg, secretKey, { extraEntropy: ent });

기본적으로 ECDSA 서명은 결정적입니다(RFC 6979). 순수하게 결정적인 서명은 폴트 공격에 취약하므로, BIP340 schnorr과 같은 최신 방식은 서명 생성에 무작위성을 도입합니다 - 일명 헤징(hedging)이라고 합니다. extraEntropy는 헤지드 모드를 활성화합니다. 더 많은 정보는 Deterministic signatures are not your friends를 확인하세요.

합의 친화성 vs 전자 투표```js

import { ed25519 } from '@noble/curves/ed25519.js'; const { secretKey, publicKey } = ed25519.keygen(); const msg = new TextEncoder().encode('hello noble'); const sig = ed25519.sign(msg, secretKey); // zip215: true const isValid = ed25519.verify(sig, msg, publicKey); // SBS / e-voting / RFC8032 / FIPS 186-5 const isValidRfc = ed25519.verify(sig, msg, publicKey, { zip215: false });

* `zip215: true` (기본값)는 [ZIP215](https://zips.z.cash/zip-0215)에 정의된 더 관대하고 [합의 친화적인](https://hdevalence.ca/blog/2020-10-04-its-25519am) 검증 규칙을 사용합니다.
* `zip215: false`는 엄격한 RFC 8032 / FIPS 186-5 검증을 적용하고 SBS 기반
  부인 방지를 추가하는데, 이는 계약 서명, 전자 투표 및 블록체인에 유용합니다.

두 모드 모두 SUF-CMA(선택 메시지 공격에 대한 강한 위조 불가능성)를 갖추고 있습니다;
대부분의 다른 라이브러리는 SUF-CMA도 SBS도 갖추고 있지 않습니다.
자세한 내용은 [Taming the many EdDSAs](https://eprint.iacr.org/2020/1244)를 참조하세요.
도구 다운로드