Sample code for 30+ languages & platforms
PHP Extension

Create ECSDA Signature using Raw r and s Format (not ASN.1)

See more ECC Examples

Demonstrates how to create an ECDSA signature using the raw r/s format.

ECDSA signatures have two equal sized parts, r and s. There are two common formats for encoding the signature:

(a) Concatenating the raw byte array of r and s
(b) Encoding both into a structured ASN.1 / DER sequence.

This example demonstrates how to create a signature that is a byte array of r and s concatenated.

Note: This example requires Chilkat v9.5.0.97 or greater.

Chilkat PHP Extension Downloads

PHP Extension
<?php

include("chilkat.php");

$success = false;

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// To create an ECDSA signature, the data first needs to be hashed.  Then the hash
// is signed.

$sb = new CkStringBuilder();
$sb->Append('The quick brown fox jumps over the lazy dog');
$hash = $sb->getHash('sha256','base64','utf-8');

// Load the ECDSA key to be used for signing.
$privKey = new CkPrivateKey();
$success = $privKey->LoadPemFile('qa_data/ecc/secp256r1-key-pkcs8.pem');
if ($success != true) {
    print $privKey->lastErrorText() . "\n";
    exit;
}

$prng = new CkPrng();
$ecdsa = new CkEcc();

// Produce a signature that is not ASN.1, but is instead the concatenation
// of the raw r and s signature parts.
// This feature was added in Chilkat v9.5.0.97
$ecdsa->put_AsnFormat(false);

$ecdsaSigBase64 = $ecdsa->signHashENC($hash,'base64',$privKey,$prng);
if ($ecdsa->get_LastMethodSuccess() != true) {
    print $ecdsa->lastErrorText() . "\n";
    exit;
}

print 'ECDSA signature = ' . $ecdsaSigBase64 . "\n";

// -----------------------------------------------------------
// Now let's verify the signature using the public key.

$pubKey = new CkPublicKey();
$success = $pubKey->LoadFromFile('qa_data/ecc/secp256r1-pubkey.pem');
if ($success != true) {
    print $pubKey->lastErrorText() . "\n";
    exit;
}

// Note: When verifying, Chilkat will auto-detect the format for both kinds of ECDSA signatures (ASN.1 or binary r+s)
$result = $ecdsa->VerifyHashENC($hash,$ecdsaSigBase64,'base64',$pubKey);
if ($result == 1) {
    print 'Signature is valid.' . "\n";
    exit;
}

if ($result == 0) {
    print 'Signature is invalid.' . "\n";
    exit;
}

if ($result < 0) {
    print $ecdsa->lastErrorText() . "\n";
    print 'The VerifyHashENC method call failed.' . "\n";
    exit;
}


?>