Class BLSSigner

java.lang.Object
org.bouncycastle.crypto.signers.BLSSigner
All Implemented Interfaces:
Signer

public class BLSSigner extends Object implements Signer
Generic BLS12-381 signer implementing the BC Signer interface.

Signs and verifies under a configurable BLS hash-to-curve domain separation tag, defaulting to the BasicScheme DST BLS_SIG_BLS12381G2_XMD:SHA-256_SSWU_RO_NUL_. The BLSSigner(byte[]) constructor lets callers select the ProofOfPossession DST (BLS12_381ProofOfPossession.DST) for Eth2 interop, or supply any other RFC 9380 DST.

Note that the MessageAugmentation suite is intentionally NOT supported here, since its hash input is pk || msg — the pubkey must be available at sign time, which doesn't fit the Signer "sk + buffered message" contract cleanly. Callers wanting AUG should use BLS12_381MessageAugmentation directly.

Produces and accepts 96-byte Zcash-format compressed G2 signatures, the same encoding used by Eth2 / IETF draft-irtf-cfrg-bls-signature.

  • Constructor Summary

    Constructors
    Constructor
    Description
    Construct a signer with the BasicScheme DST (BLS_SIG_BLS12381G2_XMD:SHA-256_SSWU_RO_NUL_).
    BLSSigner(byte[] dst)
    Construct a signer with an explicit hash-to-curve DST.
  • Method Summary

    Modifier and Type
    Method
    Description
    byte[]
    generate a signature for the message we've been loaded with using the key we were initialised with.
    void
    init(boolean forSigning, CipherParameters param)
    Initialise the signer for signing or verification.
    void
    reset the internal state
    void
    update(byte b)
    update the internal digest with the byte b
    void
    update(byte[] in, int off, int len)
    update the internal digest with the byte array in
    boolean
    verifySignature(byte[] signature)
    return true if the internal state represents the signature described in the passed in array.

    Methods inherited from class Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • BLSSigner

      public BLSSigner()
      Construct a signer with the BasicScheme DST (BLS_SIG_BLS12381G2_XMD:SHA-256_SSWU_RO_NUL_).
    • BLSSigner

      public BLSSigner(byte[] dst)
      Construct a signer with an explicit hash-to-curve DST. For Eth2 interop pass BLS12_381ProofOfPossession.DST.
  • Method Details

    • init

      public void init(boolean forSigning, CipherParameters param)
      Description copied from interface: Signer
      Initialise the signer for signing or verification.
      Specified by:
      init in interface Signer
      Parameters:
      forSigning - true if for signing, false otherwise
      param - necessary parameters.
    • update

      public void update(byte b)
      Description copied from interface: Signer
      update the internal digest with the byte b
      Specified by:
      update in interface Signer
    • update

      public void update(byte[] in, int off, int len)
      Description copied from interface: Signer
      update the internal digest with the byte array in
      Specified by:
      update in interface Signer
    • generateSignature

      public byte[] generateSignature() throws CryptoException
      Description copied from interface: Signer
      generate a signature for the message we've been loaded with using the key we were initialised with.
      Specified by:
      generateSignature in interface Signer
      Throws:
      CryptoException
    • verifySignature

      public boolean verifySignature(byte[] signature)
      Description copied from interface: Signer
      return true if the internal state represents the signature described in the passed in array.
      Specified by:
      verifySignature in interface Signer
    • reset

      public void reset()
      Description copied from interface: Signer
      reset the internal state
      Specified by:
      reset in interface Signer