Comments (1)
I came up with a solution to this by using the elliptic package in conjunction with the web crypto package. I used the elliptic package to create a PrivateKey using the 32 bytes of the private key ('d'). I then generated the PublicKey from the PrivateKey and converted both keys to PKCS#8 format. I was then able to use the PKCS#8 constructor in web crypto to create an EcdsaPrivateKey which I could then use for ECDSA (sign). I hard-coded the PKCS#8 format, as I am only using a single curve (NIST P256 / secp256r1 / prime256v1). Here is my code in case it is useful for anyone who finds this issue. The integerListFromHexString
is external to this code. You could use the hex
package instead.
import 'dart:typed_data';
import 'package:elliptic/elliptic.dart' hide EllipticCurve;
import 'package:webcrypto/webcrypto.dart';
import 'package:zcrypto/src/convert.dart';
/// ECDSA sign/verify using NIST-P256 algorithm
class Ecdsa {
/// We need to convert elliptic.PrivateKey and elliptic.PublicKey -> webcrypto.EcdsaPrivateKey
static Future<Uint8List> sign({required Uint8List message, required PrivateKey privateKey}) async {
final pkcs8 = await
'308187020100301306072a8648ce3d020106082a8648ce3d030107046d306b0201010420'
'${privateKey.toHex()}'
'a144034200'
'${privateKey.publicKey.toHex()}'.integerListFromHexString();
final signingKey = await EcdsaPrivateKey.importPkcs8Key(pkcs8, EllipticCurve.p256);
return await signingKey.signBytes(message, Hash.sha256);
}
/// For verification we can convert directly from elliptic.PublicKey -> webcrypto.EcdsaPublicKey
static Future<bool> verify({required Uint8List message, required Uint8List signature, required PublicKey publicKey}) async {
final publicKeyBytes = await publicKey.toHex().integerListFromHexString();
final verifyingKey = await EcdsaPublicKey.importRawKey(publicKeyBytes, EllipticCurve.p256);
return await verifyingKey.verifyBytes(signature, message, Hash.sha256);
}
}
from webcrypto.dart.
Related Issues (20)
- Dart (server) apps support HOT 1
- Fix intermittents tests for macos desktop HOT 5
- 0.5.4 Exception after upload to Google Play HOT 4
- Migrate lib/src/crypto_subtle.dart to use `dart:js_interop`
- Support for Gradle 8 HOT 4
- Upgrade ffigen HOT 1
- Upgrade flutter_lints
- debug intermittent iOS integration tests HOT 1
- Figure out how to enable LTO on Android
- Give access to the authorization tag in AES-GCM mode HOT 2
- Make dartdoc examples self-contained. HOT 1
- Documentation for AES-GCM should discourage AES-192 and encourage nonce size 96 (12 bytes) HOT 1
- Add .toString() methods on all private classes HOT 7
- Avoid @sealed annotation, using `final class` for everything HOT 3
- Validate JWK for HmacSecretKey Class HOT 2
- Upgrade BoringSSL
- Declare privacy manifest file for Apple HOT 3
- Consider using [!NOTE] blockquote for browser/platform compatibility notes HOT 4
- Re-enable `flutter test --platform chrome` on Windows
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from webcrypto.dart.