Elliptic curve
@webbuf/rfc6979
RFC6979 HMAC-SHA256 deterministic nonces using existing WebBuf primitives.
Install
npm install @webbuf/rfc6979Usage
import { FixedBuf } from "@webbuf/fixedbuf";
import { rfc6979Sha256, Rfc6979Sha256 } from "@webbuf/rfc6979";
// Public test inputs only; never log real private keys or nonces.
const key = FixedBuf.fromHex(32, "01".padStart(64, "0"));
const digest = FixedBuf.alloc(32);
const order = FixedBuf.fromHex(
32,
"fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141",
);
const nonce = rfc6979Sha256(key, digest, order);
nonce.wipe();
const candidates = new Rfc6979Sha256(key, digest, order);
try {
const first = candidates.next();
first.wipe();
// Request another only if the signer rejected the previous candidate.
const retry = candidates.next();
retry.wipe();
} finally {
candidates.wipe();
key.wipe();
}API reference (2 exports)
Functions
rfc6979Sha256
functionFirst RFC6979 nonce for a SHA256 digest, not an unhashed message. All inputs are 32-byte big-endian; order must have its high bit set. Wrong kinds throw TypeError; invalid lengths, keys or orders throw RangeError. Use Rfc6979Sha256 when signing must retry. Inputs are never modified.
rfc6979Sha256(privateKey: FixedBuf<32>, digest: FixedBuf<32>, order: FixedBuf<32>): FixedBuf<32>Classes
Rfc6979Sha256
classRFC6979 HMAC-SHA256 for trusted 256-bit group orders (big-endian). Each next() after the first rejects the previous nonce, including for zero ECDSA r/s. Inputs are copied; outputs own storage. Call wipe() when done. No constant-time or complete runtime zeroization guarantee is made.
constructor(privateKey: FixedBuf<32>, digest: FixedBuf<32>, order: FixedBuf<32>): Rfc6979Sha256
next(): FixedBuf<32>
wipe(): void