writeonce/runtime/test/ecdsa_sign_vectors.h
shoney.arickathil df5054b07d feat(crypto): ECDSA-P256 signing, RFC 6979 nonce (rv2 9 phase G1b)
- wo_ecdsa_p256_sha256_sign: deterministic nonce (RFC 6979 HMAC-DRBG over
  the key + message — no RNG, no nonce-reuse/bias risk), then r = (k*G).x
  mod n and s = k^-1 (z + r*d) mod n
- constant-time in the secret: jmul_ct (double-and-add-always + point
  cmov) for k*G, and bn_modexp_ct for k^-1 mod n and the affine inversion.
  Known residual (documented): the ladder leaks k's leading-zero count (a
  bit-length hint, not the key) — a complete-formula/Montgomery-ladder
  upgrade is the named follow-up
- KAT: byte-for-byte vs the RFC 6979 A.2.5 P-256/SHA-256 vectors ("sample"
  + "test"), our sign verifies with our verify, determinism checked.
  test_crypto 115, ASan/UBSan clean

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 1bc6d04f9e18180dc7d0a6e5e7021dbd588e499a)
2026-09-15 01:15:52 +02:00

56 lines
2.1 KiB
C

/* RFC 6979 A.2.5 ECDSA P-256/SHA-256 KAT (deterministic nonce). */
static const unsigned char ecs_d[] = {
0xc9,0xaf,0xa9,0xd8,0x45,0xba,0x75,0x16,0x6b,0x5c,0x21,0x57,
0x67,0xb1,0xd6,0x93,0x4e,0x50,0xc3,0xdb,0x36,0xe8,0x9b,0x12,
0x7b,0x8a,0x62,0x2b,0x12,0x0f,0x67,0x21,
};
static const unsigned char ecs_qx[] = {
0x60,0xfe,0xd4,0xba,0x25,0x5a,0x9d,0x31,0xc9,0x61,0xeb,0x74,
0xc6,0x35,0x6d,0x68,0xc0,0x49,0xb8,0x92,0x3b,0x61,0xfa,0x6c,
0xe6,0x69,0x62,0x2e,0x60,0xf2,0x9f,0xb6,
};
static const unsigned char ecs_qy[] = {
0x79,0x03,0xfe,0x10,0x08,0xb8,0xbc,0x99,0xa4,0x1a,0xe9,0xe9,
0x56,0x28,0xbc,0x64,0xf2,0xf1,0xb2,0x0c,0x2d,0x7e,0x9f,0x51,
0x77,0xa3,0xc2,0x94,0xd4,0x46,0x22,0x99,
};
static const unsigned char ecs_sample_mhash[] = {
0xaf,0x2b,0xdb,0xe1,0xaa,0x9b,0x6e,0xc1,0xe2,0xad,0xe1,0xd6,
0x94,0xf4,0x1f,0xc7,0x1a,0x83,0x1d,0x02,0x68,0xe9,0x89,0x15,
0x62,0x11,0x3d,0x8a,0x62,0xad,0xd1,0xbf,
};
static const unsigned char ecs_sample_r[] = {
0xef,0xd4,0x8b,0x2a,0xac,0xb6,0xa8,0xfd,0x11,0x40,0xdd,0x9c,
0xd4,0x5e,0x81,0xd6,0x9d,0x2c,0x87,0x7b,0x56,0xaa,0xf9,0x91,
0xc3,0x4d,0x0e,0xa8,0x4e,0xaf,0x37,0x16,
};
static const unsigned char ecs_sample_s[] = {
0xf7,0xcb,0x1c,0x94,0x2d,0x65,0x7c,0x41,0xd4,0x36,0xc7,0xa1,
0xb6,0xe2,0x9f,0x65,0xf3,0xe9,0x00,0xdb,0xb9,0xaf,0xf4,0x06,
0x4d,0xc4,0xab,0x2f,0x84,0x3a,0xcd,0xa8,
};
static const unsigned char ecs_test_mhash[] = {
0x9f,0x86,0xd0,0x81,0x88,0x4c,0x7d,0x65,0x9a,0x2f,0xea,0xa0,
0xc5,0x5a,0xd0,0x15,0xa3,0xbf,0x4f,0x1b,0x2b,0x0b,0x82,0x2c,
0xd1,0x5d,0x6c,0x15,0xb0,0xf0,0x0a,0x08,
};
static const unsigned char ecs_test_r[] = {
0xf1,0xab,0xb0,0x23,0x51,0x83,0x51,0xcd,0x71,0xd8,0x81,0x56,
0x7b,0x1e,0xa6,0x63,0xed,0x3e,0xfc,0xf6,0xc5,0x13,0x2b,0x35,
0x4f,0x28,0xd3,0xb0,0xb7,0xd3,0x83,0x67,
};
static const unsigned char ecs_test_s[] = {
0x01,0x9f,0x41,0x13,0x74,0x2a,0x2b,0x14,0xbd,0x25,0x92,0x6b,
0x49,0xc6,0x49,0x15,0x5f,0x26,0x7e,0x60,0xd3,0x81,0x4b,0x4c,
0x0c,0xc8,0x42,0x50,0xe4,0x6f,0x00,0x83,
};
/* (published r,s cross-verified against Q by python) */