Class Ed448


  • public abstract class Ed448
    extends java.lang.Object
    A low-level implementation of the Ed448 and Ed448ph instantiations of the Edwards-Curve Digital Signature Algorithm specified in RFC 8032.

    The implementation uses the "signed mult-comb" algorithm (for scalar multiplication by a fixed point) from Mike Hamburg, "Fast and compact elliptic-curve cryptography". Standard projective coordinates are used for most point arithmetic.

    Algorithm map.

    • Key generation — generatePrivateKey returns a 57-byte seed; generatePublicKey (via scalarMultBaseEncoded) computes A = s * B where s is the SHAKE-256-expanded clamped secret scalar (RFC 8032 sec. 5.2.5), using the constant-time signed multi-comb scalarMultBase.
    • Signing — sign computes R = r * B (signed multi-comb) where r = SHAKE-256(dom4(F, C) || prefix || M, 912 bits) mod L, then S = (r + k * s) mod L (RFC 8032 sec. 5.2.6). Reduction modulo L uses Scalar448.reduce912 (Barrett-style, straight-line). No variable-base scalar multiplication is performed.
    • Verification — verify uses the basis reduction algorithm of Pornin via Scalar448.reduceBasisVar then evaluates the combined relation with Strauss-Shamir's trick in scalarMultStraus225Var. Both routines are deliberately variable-time and operate only on public material (signature, message, public key).
    • Coordinates — the precomputed base-point comb table lives in affine form (matching PointAffine in pointLookup); the signing-side accumulator is projective (X : Y : Z). Verification uses projective coordinates throughout.

    Side-channel scope. The signing path (which operates on the secret seed, the derived secret scalar, and the secret per-message nonce) is written to be constant-time at the Java level: the comb scalarMultBase walks all precomputed entries via mask-based cmov rather than a secret-indexed array load, conditional sign application uses XOR-with-mask cnegate, scalar recoding via toSignedDigits uses mask-driven caddTo, and Scalar448.reduce912 is fully unrolled straight-line arithmetic. This is sufficient against a remote network timing attacker but is not a substitute for a constant-time native implementation against a co-located cache-line-resolution adversary — JVM-level timing variance from JIT, GC and cache eviction is not addressable in pure Java. Verification routines (those suffixed Var) are deliberately variable-time and operate only on public material.

    • Constructor Detail

      • Ed448

        public Ed448()
    • Method Detail

      • createPrehash

        public static Xof createPrehash()
      • encodePublicPoint

        public static void encodePublicPoint​(Ed448.PublicPoint publicPoint,
                                             byte[] pk,
                                             int pkOff)
      • generatePrivateKey

        public static void generatePrivateKey​(java.security.SecureRandom random,
                                              byte[] k)
      • generatePublicKey

        public static void generatePublicKey​(byte[] sk,
                                             int skOff,
                                             byte[] pk,
                                             int pkOff)
      • generatePublicKey

        public static Ed448.PublicPoint generatePublicKey​(byte[] sk,
                                                          int skOff)
      • precompute

        public static void precompute()
      • scalarMultBaseXY

        public static void scalarMultBaseXY​(X448.Friend friend,
                                            byte[] k,
                                            int kOff,
                                            int[] x,
                                            int[] y)
        NOTE: Only for use by X448
      • sign

        public static void sign​(byte[] sk,
                                int skOff,
                                byte[] ctx,
                                byte[] m,
                                int mOff,
                                int mLen,
                                byte[] sig,
                                int sigOff)
      • sign

        public static void sign​(byte[] sk,
                                int skOff,
                                byte[] pk,
                                int pkOff,
                                byte[] ctx,
                                byte[] m,
                                int mOff,
                                int mLen,
                                byte[] sig,
                                int sigOff)
      • signPrehash

        public static void signPrehash​(byte[] sk,
                                       int skOff,
                                       byte[] ctx,
                                       byte[] ph,
                                       int phOff,
                                       byte[] sig,
                                       int sigOff)
      • signPrehash

        public static void signPrehash​(byte[] sk,
                                       int skOff,
                                       byte[] pk,
                                       int pkOff,
                                       byte[] ctx,
                                       byte[] ph,
                                       int phOff,
                                       byte[] sig,
                                       int sigOff)
      • signPrehash

        public static void signPrehash​(byte[] sk,
                                       int skOff,
                                       byte[] ctx,
                                       Xof ph,
                                       byte[] sig,
                                       int sigOff)
      • signPrehash

        public static void signPrehash​(byte[] sk,
                                       int skOff,
                                       byte[] pk,
                                       int pkOff,
                                       byte[] ctx,
                                       Xof ph,
                                       byte[] sig,
                                       int sigOff)
      • validatePublicKeyFull

        public static boolean validatePublicKeyFull​(byte[] pk,
                                                    int pkOff)
      • validatePublicKeyFullExport

        public static Ed448.PublicPoint validatePublicKeyFullExport​(byte[] pk,
                                                                    int pkOff)
      • validatePublicKeyPartial

        public static boolean validatePublicKeyPartial​(byte[] pk,
                                                       int pkOff)
      • validatePublicKeyPartialExport

        public static Ed448.PublicPoint validatePublicKeyPartialExport​(byte[] pk,
                                                                       int pkOff)
      • verify

        public static boolean verify​(byte[] sig,
                                     int sigOff,
                                     byte[] pk,
                                     int pkOff,
                                     byte[] ctx,
                                     byte[] m,
                                     int mOff,
                                     int mLen)
      • verify

        public static boolean verify​(byte[] sig,
                                     int sigOff,
                                     Ed448.PublicPoint publicPoint,
                                     byte[] ctx,
                                     byte[] m,
                                     int mOff,
                                     int mLen)
      • verifyPrehash

        public static boolean verifyPrehash​(byte[] sig,
                                            int sigOff,
                                            byte[] pk,
                                            int pkOff,
                                            byte[] ctx,
                                            byte[] ph,
                                            int phOff)
      • verifyPrehash

        public static boolean verifyPrehash​(byte[] sig,
                                            int sigOff,
                                            Ed448.PublicPoint publicPoint,
                                            byte[] ctx,
                                            byte[] ph,
                                            int phOff)
      • verifyPrehash

        public static boolean verifyPrehash​(byte[] sig,
                                            int sigOff,
                                            byte[] pk,
                                            int pkOff,
                                            byte[] ctx,
                                            Xof ph)
      • verifyPrehash

        public static boolean verifyPrehash​(byte[] sig,
                                            int sigOff,
                                            Ed448.PublicPoint publicPoint,
                                            byte[] ctx,
                                            Xof ph)