Elliptic curve

@webbuf/rfc6979

RFC6979 HMAC-SHA256 deterministic nonces using existing WebBuf primitives.

Install

npm install @webbuf/rfc6979

Usage

import { FixedBuf } from "@webbuf/fixedbuf";
import { rfc6979Sha256, Rfc6979Sha256 } from "@webbuf/rfc6979";

// Public test inputs only; never log real private keys or nonces.
const key = FixedBuf.fromHex(32, "01".padStart(64, "0"));
const digest = FixedBuf.alloc(32);
const order = FixedBuf.fromHex(
  32,
  "fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141",
);
const nonce = rfc6979Sha256(key, digest, order);
nonce.wipe();
const candidates = new Rfc6979Sha256(key, digest, order);
try {
  const first = candidates.next();
  first.wipe();
  // Request another only if the signer rejected the previous candidate.
  const retry = candidates.next();
  retry.wipe();
} finally {
  candidates.wipe();
  key.wipe();
}

API reference (2 exports)

Functions

rfc6979Sha256

function

First RFC6979 nonce for a SHA256 digest, not an unhashed message. All inputs are 32-byte big-endian; order must have its high bit set. Wrong kinds throw TypeError; invalid lengths, keys or orders throw RangeError. Use Rfc6979Sha256 when signing must retry. Inputs are never modified.

rfc6979Sha256(privateKey: FixedBuf<32>, digest: FixedBuf<32>, order: FixedBuf<32>): FixedBuf<32>

Classes

Rfc6979Sha256

class

RFC6979 HMAC-SHA256 for trusted 256-bit group orders (big-endian). Each next() after the first rejects the previous nonce, including for zero ECDSA r/s. Inputs are copied; outputs own storage. Call wipe() when done. No constant-time or complete runtime zeroization guarantee is made.

constructor(privateKey: FixedBuf<32>, digest: FixedBuf<32>, order: FixedBuf<32>): Rfc6979Sha256
next(): FixedBuf<32>
wipe(): void