Class Ed448

java.lang.Object
org.bouncycastle.math.ec.rfc8032.Ed448

public abstract class Ed448 extends Object
A low-level implementation of the Ed448 and Ed448ph instantiations of the Edwards-Curve Digital Signature Algorithm specified in RFC 8032.

The implementation uses the "signed mult-comb" algorithm (for scalar multiplication by a fixed point) from Mike Hamburg, "Fast and compact elliptic-curve cryptography". Standard projective coordinates are used for most point arithmetic.

Algorithm map.

  • Key generation — generatePrivateKey returns a 57-byte seed; generatePublicKey (via scalarMultBaseEncoded) computes A = s * B where s is the SHAKE-256-expanded clamped secret scalar (RFC 8032 sec. 5.2.5), using the constant-time signed multi-comb scalarMultBase.
  • Signing — sign computes R = r * B (signed multi-comb) where r = SHAKE-256(dom4(F, C) || prefix || M, 912 bits) mod L, then S = (r + k * s) mod L (RFC 8032 sec. 5.2.6). Reduction modulo L uses Scalar448.reduce912 (Barrett-style, straight-line). No variable-base scalar multiplication is performed.
  • Verification — verify uses the basis reduction algorithm of Pornin via Scalar448.reduceBasisVar then evaluates the combined relation with Strauss-Shamir's trick in scalarMultStraus225Var. Both routines are deliberately variable-time and operate only on public material (signature, message, public key).
  • Coordinates — the precomputed base-point comb table lives in affine form (matching PointAffine in pointLookup); the signing-side accumulator is projective (X : Y : Z). Verification uses projective coordinates throughout.

Side-channel scope. The signing path (which operates on the secret seed, the derived secret scalar, and the secret per-message nonce) is written to be constant-time at the Java level: the comb scalarMultBase walks all precomputed entries via mask-based cmov rather than a secret-indexed array load, conditional sign application uses XOR-with-mask cnegate, scalar recoding via toSignedDigits uses mask-driven caddTo, and Scalar448.reduce912 is fully unrolled straight-line arithmetic. This is sufficient against a remote network timing attacker but is not a substitute for a constant-time native implementation against a co-located cache-line-resolution adversary — JVM-level timing variance from JIT, GC and cache eviction is not addressable in pure Java. Verification routines (those suffixed Var) are deliberately variable-time and operate only on public material.

  • Field Details

  • Constructor Details

    • Ed448

      public Ed448()
  • Method Details

    • createPrehash

      public static Xof createPrehash()
    • encodePublicPoint

      public static void encodePublicPoint(Ed448.PublicPoint publicPoint, byte[] pk, int pkOff)
    • generatePrivateKey

      public static void generatePrivateKey(SecureRandom random, byte[] k)
    • generatePublicKey

      public static void generatePublicKey(byte[] sk, int skOff, byte[] pk, int pkOff)
    • generatePublicKey

      public static Ed448.PublicPoint generatePublicKey(byte[] sk, int skOff)
    • precompute

      public static void precompute()
    • scalarMultBaseXY

      public static void scalarMultBaseXY(X448.Friend friend, byte[] k, int kOff, int[] x, int[] y)
      NOTE: Only for use by X448
    • sign

      public static void sign(byte[] sk, int skOff, byte[] ctx, byte[] m, int mOff, int mLen, byte[] sig, int sigOff)
    • sign

      public static void sign(byte[] sk, int skOff, byte[] pk, int pkOff, byte[] ctx, byte[] m, int mOff, int mLen, byte[] sig, int sigOff)
    • signPrehash

      public static void signPrehash(byte[] sk, int skOff, byte[] ctx, byte[] ph, int phOff, byte[] sig, int sigOff)
    • signPrehash

      public static void signPrehash(byte[] sk, int skOff, byte[] pk, int pkOff, byte[] ctx, byte[] ph, int phOff, byte[] sig, int sigOff)
    • signPrehash

      public static void signPrehash(byte[] sk, int skOff, byte[] ctx, Xof ph, byte[] sig, int sigOff)
    • signPrehash

      public static void signPrehash(byte[] sk, int skOff, byte[] pk, int pkOff, byte[] ctx, Xof ph, byte[] sig, int sigOff)
    • validatePublicKeyFull

      public static boolean validatePublicKeyFull(byte[] pk, int pkOff)
    • validatePublicKeyFullExport

      public static Ed448.PublicPoint validatePublicKeyFullExport(byte[] pk, int pkOff)
    • validatePublicKeyPartial

      public static boolean validatePublicKeyPartial(byte[] pk, int pkOff)
    • validatePublicKeyPartialExport

      public static Ed448.PublicPoint validatePublicKeyPartialExport(byte[] pk, int pkOff)
    • verify

      public static boolean verify(byte[] sig, int sigOff, byte[] pk, int pkOff, byte[] ctx, byte[] m, int mOff, int mLen)
    • verify

      public static boolean verify(byte[] sig, int sigOff, Ed448.PublicPoint publicPoint, byte[] ctx, byte[] m, int mOff, int mLen)
    • verifyPrehash

      public static boolean verifyPrehash(byte[] sig, int sigOff, byte[] pk, int pkOff, byte[] ctx, byte[] ph, int phOff)
    • verifyPrehash

      public static boolean verifyPrehash(byte[] sig, int sigOff, Ed448.PublicPoint publicPoint, byte[] ctx, byte[] ph, int phOff)
    • verifyPrehash

      public static boolean verifyPrehash(byte[] sig, int sigOff, byte[] pk, int pkOff, byte[] ctx, Xof ph)
    • verifyPrehash

      public static boolean verifyPrehash(byte[] sig, int sigOff, Ed448.PublicPoint publicPoint, byte[] ctx, Xof ph)