Repository navigation
Conversation
The interface spec and the management canister reference gained the `secp256r1` curve in #394. The concept and cycle cost pages still described threshold ECDSA as secp256k1 only. - The scheme table on the chain-key cryptography page gets a `secp256r1` (NIST P-256) row. Its use cases are web standards that require ES256: JSON Web Tokens, and VAPID web push (RFC 8292, section 2). - The key derivation paragraph names SLIP-10 for P-256, matching the `ecdsa_public_key` section of the spec. - The deployed keys table and the cycle costs table list `(secp256r1, test_key_1)` and `(secp256r1, key_1)` next to the secp256k1 keys, on the same subnets and at the same fees. `ic0.cost_sign_with_ecdsa` prices a signature by the subnet that holds the key, not by the curve.
|
🤖 Here's your preview: https://kwnd6-zaaaa-aaaam-ai7va-cai.icp0.io |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
secp256r1(NIST P-256) row. Its use cases are web standards that require ES256: JSON Web Tokens, and VAPID web push (RFC 8292, section 2).ecdsa_public_keysection of the spec from feat: add secp256r1 to the ECDSA curves in the interface spec #394.(secp256r1, test_key_1)and(secp256r1, key_1)next to thesecp256k1keys. The fees are the same, becauseic0.cost_sign_with_ecdsaprices a signature by the subnet that holds the key, not by the curve (system_api.rs).Merge condition
The pages describe the end state: both
secp256r1keys enabled for signing on mainnet, on the same signing subnets as the other keys (test_key_1onfuqsr,key_1onpzp6e). Keep this a draft until that holds. If a key ends up on a different subnet, adjust its cycle costs row.Rust canisters get
EcdsaCurve::Secp256r1fromic-cdk-management-canister0.3.0 (dfinity/cdk-rs#716), and PocketIC 16.1.0 holds the same keys for tests. The offline key derivation guide stays as it is:@dfinity/ic-pub-keyv1.0.2 supports onlysecp256k1anded25519.Tests
node scripts/validate.jspasses on both pages.npm run buildwas not run locally (Node 18 here; Astro needs 22.12).