3.6 Digital signatures
All Application Manual Name SummaryHelp

  • Documentation
    • Reference manual
    • Packages
      • SWI-Prolog SSL Interface
        • library(crypto): Cryptography and authentication library
          • Digital signatures
            • ECDSA
            • RSA
            • Ed25519
              • ed25519_new_keypair/1
              • ed25519_seed_keypair/2
              • ed25519_keypair_public_key/2
              • ed25519_sign/4
              • ed25519_verify/4

3.6.3 Ed25519

Ed25519 (RFC 8032) is a signature scheme over a twisted Edwards curve that is birationally equivalent to Curve25519. A key pair is derived from 32 arbitrary bytes and is represented in PKCS#8 v2 format (RFC 8410), the format also used by openssl genpkey -algorithm ed25519.

Unlike ECDSA and RSA above, Ed25519 signs the data itself rather than a hash of it. The default encoding of Data is therefore utf8.

[det]ed25519_new_keypair(-KeyPair)
KeyPair is a new Ed25519 key pair, created from 32 random bytes obtained with crypto_n_random_bytes/2. It contains the private key and must be kept absolutely secret. See ed25519_seed_keypair/2.
[det]ed25519_seed_keypair(+Seed, -KeyPair)
Deterministically derive an Ed25519 key pair from Seed, 32 arbitrary bytes. Seed can be chosen at random using crypto_n_random_bytes/2 or derived from input keying material using crypto_data_hkdf/4.

KeyPair is a hexadecimal atom denoting the key pair in PKCS#8 v2 format (RFC 5958, RFC 8410), the format also used by openssl genpkey -algorithm ed25519. It contains the private key and must be kept absolutely secret. It can be used for signing with ed25519_sign/4, and its public key is obtained with ed25519_keypair_public_key/2.

[det]ed25519_keypair_public_key(+KeyPair, -PublicKey)
PublicKey is the public key of KeyPair, a hexadecimal atom. The public key is used for signature verification with ed25519_verify/4 and can be shared freely.
[det]ed25519_sign(+KeyPair, +Data, -Signature, +Options)
Create an Ed25519 (RFC 8032) signature for Data with the private key of KeyPair, as created by ed25519_new_keypair/1 or obtained with load_private_key/3. Signature is a hexadecimal atom.

Options:

encoding(+Encoding)
Encoding to use for Data. Default is utf8. Alternatives are octet, text and hex. Note that this differs from ecdsa_sign/4 and rsa_sign/4, which default to hex because they are typically applied to a hash of the data. Ed25519 signs the data itself.
[semidet]ed25519_verify(+PublicKey, +Data, +Signature, +Options)
True iff Signature can be verified as the Ed25519 signature for Data, using PublicKey.

Options are as for ed25519_sign/4.