Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
noble-curves — 经过审计且极简的椭圆曲线密码学 JS 实现。 | Kitploit
工具/GitHubGitHub/paulmillr/noble-curves
加密/解密工具哈希分析密码学实用工具与框架学习与教育
GitHubpaulmillr/noble-curves

noble-curves

经过审计且极简的椭圆曲线密码学 JS 实现。

查看仓库
9601036628天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

noble-curves

经过审计且极简的椭圆曲线密码学 JS 实现。

  • 🔒 由独立安全公司审计
  • 🪶 极简:secp256k1 仅 15KB(gzip 压缩后),未使用的代码会从你的构建中排除
  • 🏎 快速:针对 JS 引擎的特性手工优化
  • 🔍 可靠:跨库 / wycheproof 测试确保正确性
  • ➰ Weierstrass、Edwards 曲线;ECDSA、EdDSA、Schnorr、BLS 签名
  • ✍️ ECDH、hash-to-curve、OPRF、FROST、Poseidon 哈希、FFT
  • 🔖 ed25519、ed448 中的不可否认性(SUF-CMA、SBS)与共识友好性(ZIP215)
  • 🥈 基于原生 WebCrypto 的相同 API 封装

曲线有 5kb 的姊妹项目 secp256k1 和 ed25519。 它们攻击面更小,但功能也更少。

本库属于 noble 密码学

noble cryptography — 高安全性、易于审计的独立密码学库与工具集。

  • 零依赖或极少依赖
  • 高度可读的 TypeScript / JS 代码
  • PGP 签名的发布版本与透明的 NPM 构建
  • 所有库: ciphers、 curves、 hashes、 post-quantum、 5kb secp256k1 / ed25519
  • WASM 版本:awasm-noble
  • 查看主页 获取阅读资源、文档以及使用 noble 构建的应用

用法

npm install @noble/curves

deno add jsr:@noble/curves

我们支持所有主流平台和运行时。 对于 React Native,你可能需要 getRandomValues 的 polyfill。 也提供独立文件 noble-curves.js。```js // import * from '@noble/curves'; // Error: use sub-imports, to ensure small app size import { secp256k1 } from '@noble/curves/secp256k1.js'; const { secretKey, publicKey } = secp256k1.keygen(); const msg = new TextEncoder().encode('hello noble'); const sig = secp256k1.sign(msg, secretKey); const isValid = secp256k1.verify(sig, msg, publicKey);

- [ECDSA、EdDSA、Schnorr 签名](#ecdsa-eddsa-schnorr-signatures)
- [ECDH:Diffie-Hellman 共享密钥](#ecdh-diffie-hellman-shared-secrets)
- [webcrypto:友好封装](#webcrypto-friendly-wrapper)
- [BLS 签名、bls12-381、bn254 又名 alt\_bn128](#bls-signatures-bls12-381-bn254-aka-alt_bn128)
- [hash-to-curve:哈希到曲线点](#hash-to-curve-hashing-to-curve-points)
- [OPRF](#oprfs) | [FROST 门限签名](#frost-threshold-signatures)
- [poseidon:Poseidon 哈希](#poseidon-poseidon-hash) | [fft:快速傅里叶变换](#fft-fast-fourier-transform) | [utils](#utils-byte-shuffling-conversion)
- 内部实现:[点运算](#elliptic-curve-point-math) | [模运算](#modular-modular-arithmetics--finite-fields) | [自定义曲线](#weierstrass-custom-weierstrass-curve--ecdsa)
- [规范](#specs)
- [安全性](#security) | [速度](#speed) | [升级](#upgrading) | [贡献与测试](#contributing--testing) | [许可证](#license)

### ECDSA、EdDSA、Schnorr 签名

#### secp256k1、p256、p384、p521、ed25519、ed448、brainpool```js
import { secp256k1, schnorr } from '@noble/curves/secp256k1.js';
import { p256, p384, p521 } from '@noble/curves/nist.js';
import { ed25519 } from '@noble/curves/ed25519.js';
import { ed448 } from '@noble/curves/ed448.js';
import { brainpoolP256r1, brainpoolP384r1, brainpoolP512r1 } from '@noble/curves/misc.js';
for (const curve of [
  secp256k1, schnorr,
  p256, p384, p521,
  ed25519, ed448,
  brainpoolP256r1, brainpoolP384r1, brainpoolP512r1
]) {
  const { secretKey, publicKey } = curve.keygen();
  const msg = new TextEncoder().encode('hello noble');
  const sig = curve.sign(msg, secretKey);
  const isValid = curve.verify(sig, msg, publicKey);
  console.log(curve, secretKey, publicKey, sig, isValid);
}

// Specific private key
import { hexToBytes } from '@noble/curves/utils.js';
const secret2 = hexToBytes('46c930bc7bb4db7f55da20798697421b98c4175a52c630294d75a84b9c126236');
const pub2 = secp256k1.getPublicKey(secret2);

消息始终先进行哈希:参见预哈希签名。 ECDSA 使用确定性 k,EdDSA 遵循 RFC 8032,Schnorr(仅限 secp256k1)遵循 BIP 340:参见规范。

MuSig2 签名方案以及用于 secp256k1 的 BIP324 ElligatorSwift 映射 可在单独的包中获取。

ristretto255, decaf448```ts

import { ristretto255, ristretto255_hasher, ristretto255_oprf } from '@noble/curves/ed25519.js'; import { decaf448, decaf448_hasher, decaf448_oprf } from '@noble/curves/ed448.js';

console.log(ristretto255.Point, decaf448.Point);

查看 [RFC 9496](https://www.rfc-editor.org/rfc/rfc9496) 以获取有关 ristretto255 和 decaf448 的更多信息。
查看关于 [Point](#elliptic-curve-point-math)、[hasher](#hash-to-curve-hashing-to-curve-points) 和 [oprf](#oprfs) 的单独文档。

#### 预哈希签名```js
import { secp256k1 } from '@noble/curves/secp256k1.js';
import { keccak_256 } from '@noble/hashes/sha3.js';
const { secretKey } = secp256k1.keygen();
const msg = new TextEncoder().encode('hello noble');
// prehash: true (default) - hash using secp256k1.hash (sha256)
const sig = secp256k1.sign(msg, secretKey);
// prehash: false - hash using custom hash
const sigKeccak = secp256k1.sign(keccak_256(msg), secretKey, { prehash: false });

默认情况下(prehash: true),sign() 和 verify() 会先对消息应用曲线内置的哈希: secp256k1 使用 sha256,p521 使用 sha512。prehash: false 允许使用自定义哈希 (例如 secp256k1 + keccak_256)。在 noble-curves v1 中,prehash: false 是默认值。

从签名中恢复公钥```js

import { secp256k1 } from '@noble/curves/secp256k1.js'; const { secretKey, publicKey } = secp256k1.keygen(); const msg = new TextEncoder().encode('hello noble'); const sigRec = secp256k1.sign(msg, secretKey, { format: 'recovered' }); const publicKey_ = secp256k1.recoverPublicKey(sigRec, msg); // == publicKey

// recovered sig is compact sig with an extra byte const sigNoRec = secp256k1.sign(msg, secretKey, { format: 'compact' }); // sigNoRec == sigRec.slice(1)

// Signature instance const sigInstance = secp256k1.Signature.fromBytes(sigRec, 'recovered');

公钥恢复仅支持 ECDSA。这是一个简单的数学运算:
无法保证签名确实已完成。伪造的 (r, s, h) 会恢复出一个
随机公钥,但要找到能导致这个特定伪造 h 的 m 是不可行的。

#### 带噪声的对冲 ECDSA```js
import { secp256k1 } from '@noble/curves/secp256k1.js';
const { secretKey } = secp256k1.keygen();
const msg = new TextEncoder().encode('hello noble');
// extraEntropy: false - default, hedging disabled
const sigNoisy = secp256k1.sign(msg, secretKey);
// extraEntropy: true - fetch 32 random bytes from CSPRNG
const sigNoisyA = secp256k1.sign(msg, secretKey, { extraEntropy: true });
// extraEntropy: bytes - specific extra entropy
const ent = Uint8Array.from([0xca, 0xfe, 0x01, 0x23]);
const sigNoisy2 = secp256k1.sign(msg, secretKey, { extraEntropy: ent });

默认情况下,ECDSA 签名是确定性的(RFC 6979)。纯确定性签名容易受到故障攻击,因此较新的方案(如 BIP340 schnorr)在签名生成中引入了随机性——也称为对冲。extraEntropy 启用对冲模式。更多信息,请查看确定性签名不是你的朋友。

共识友好性与电子投票```js

import { ed25519 } from '@noble/curves/ed25519.js'; const { secretKey, publicKey } = ed25519.keygen(); const msg = new TextEncoder().encode('hello noble'); const sig = ed25519.sign(msg, secretKey); // zip215: true const isValid = ed25519.verify(sig, msg, publicKey); // SBS / e-voting / RFC8032 / FIPS 186-5 const isValidRfc = ed25519.verify(sig, msg, publicKey, { zip215: false });

* `zip215: true`(默认)使用 [ZIP215](https://zips.z.cash/zip-0215) 中定义的更宽松、[共识友好](https://hdevalence.ca/blog/2020-10-04-its-25519am)的验证规则。
* `zip215: false` 强制执行严格的 RFC 8032 / FIPS 186-5 验证,并添加基于 SBS 的
  不可否认性,这对于合同签署、电子投票和区块链非常有用。

两种模式都具有 SUF-CMA(选择消息攻击下的强不可伪造性);
大多数其他库既没有 SUF-CMA 也没有 SBS。
更多信息请参见 [Taming the many EdDSAs](https://eprint.iacr.org/2020/1244)。

### ECDH:Diffie-Hellman 共享密钥```js
import { x25519 } from '@noble/curves/ed25519.js';
const alice = x25519.keygen();
const bob = x25519.keygen();
const sharedKey = x25519.getSharedSecret(alice.secretKey, bob.publicKey);
// Same API: secp256k1, p256, p384, p521, x448

// converting ed25519 keys to x25519
import { ed25519 } from '@noble/curves/ed25519.js';
const alice2 = ed25519.keygen();
const bob2 = ed25519.keygen();
const aliceSecX = ed25519.utils.toMontgomerySecret(alice2.secretKey);
const bobPubX = ed25519.utils.toMontgomery(bob2.publicKey);
const sharedKey2 = x25519.getSharedSecret(aliceSecX, bobPubX);

我们为所有 Weierstrass 曲线以及 2 条 Montgomery 曲线 X25519(Curve25519)和 X448(Curve448)提供 ECDH,符合 RFC 7748。

在 Weierstrass 曲线中,共享密钥:

下载工具