Sample code for 30+ languages & platforms
PHP ActiveX

Create ECSDA Signature using Raw r and s Format (not ASN.1)

See more ECC Examples

Demonstrates how to create an ECDSA signature using the raw r/s format.

ECDSA signatures have two equal sized parts, r and s. There are two common formats for encoding the signature:

(a) Concatenating the raw byte array of r and s
(b) Encoding both into a structured ASN.1 / DER sequence.

This example demonstrates how to create a signature that is a byte array of r and s concatenated.

Note: This example requires Chilkat v9.5.0.97 or greater.

Chilkat PHP ActiveX Downloads

PHP ActiveX
<?php

$success = 0;

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// To create an ECDSA signature, the data first needs to be hashed.  Then the hash
// is signed.

$sb = new COM("Chilkat.StringBuilder");
$sb->Append('The quick brown fox jumps over the lazy dog');
$hash = $sb->getHash('sha256','base64','utf-8');

// Load the ECDSA key to be used for signing.
$privKey = new COM("Chilkat.PrivateKey");
$success = $privKey->LoadPemFile('qa_data/ecc/secp256r1-key-pkcs8.pem');
if ($success != 1) {
    print $privKey->LastErrorText . "\n";
    exit;
}

$prng = new COM("Chilkat.Prng");
$ecdsa = new COM("Chilkat.Ecc");

// Produce a signature that is not ASN.1, but is instead the concatenation
// of the raw r and s signature parts.
// This feature was added in Chilkat v9.5.0.97
$ecdsa->AsnFormat = 0;

$ecdsaSigBase64 = $ecdsa->signHashENC($hash,'base64',$privKey,$prng);
if ($ecdsa->LastMethodSuccess != 1) {
    print $ecdsa->LastErrorText . "\n";
    exit;
}

print 'ECDSA signature = ' . $ecdsaSigBase64 . "\n";

// -----------------------------------------------------------
// Now let's verify the signature using the public key.

$pubKey = new COM("Chilkat.PublicKey");
$success = $pubKey->LoadFromFile('qa_data/ecc/secp256r1-pubkey.pem');
if ($success != 1) {
    print $pubKey->LastErrorText . "\n";
    exit;
}

// Note: When verifying, Chilkat will auto-detect the format for both kinds of ECDSA signatures (ASN.1 or binary r+s)
$result = $ecdsa->VerifyHashENC($hash,$ecdsaSigBase64,'base64',$pubKey);
if ($result == 1) {
    print 'Signature is valid.' . "\n";
    exit;
}

if ($result == 0) {
    print 'Signature is invalid.' . "\n";
    exit;
}

if ($result < 0) {
    print $ecdsa->LastErrorText . "\n";
    print 'The VerifyHashENC method call failed.' . "\n";
    exit;
}


?>