Tcl
Tcl
Create ECSDA Signature using Raw r and s Format (not ASN.1)
See more ECC Examples
Demonstrates how to create an ECDSA signature using the raw r/s format.ECDSA signatures have two equal sized parts, r and s. There are two common formats for encoding the signature:
(a) Concatenating the raw byte array of r and s
(b) Encoding both into a structured ASN.1 / DER sequence.
This example demonstrates how to create a signature that is a byte array of r and s concatenated.
Note: This example requires Chilkat v9.5.0.97 or greater.
Chilkat Tcl Downloads
load ./chilkat.dll
set success 0
# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.
# To create an ECDSA signature, the data first needs to be hashed. Then the hash
# is signed.
set sb [new_CkStringBuilder]
CkStringBuilder_Append $sb "The quick brown fox jumps over the lazy dog"
set hash [CkStringBuilder_getHash $sb "sha256" "base64" "utf-8"]
# Load the ECDSA key to be used for signing.
set privKey [new_CkPrivateKey]
set success [CkPrivateKey_LoadPemFile $privKey "qa_data/ecc/secp256r1-key-pkcs8.pem"]
if {$success != 1} then {
puts [CkPrivateKey_lastErrorText $privKey]
delete_CkStringBuilder $sb
delete_CkPrivateKey $privKey
exit
}
set prng [new_CkPrng]
set ecdsa [new_CkEcc]
# Produce a signature that is not ASN.1, but is instead the concatenation
# of the raw r and s signature parts.
# This feature was added in Chilkat v9.5.0.97
CkEcc_put_AsnFormat $ecdsa 0
set ecdsaSigBase64 [CkEcc_signHashENC $ecdsa $hash "base64" $privKey $prng]
if {[CkEcc_get_LastMethodSuccess $ecdsa] != 1} then {
puts [CkEcc_lastErrorText $ecdsa]
delete_CkStringBuilder $sb
delete_CkPrivateKey $privKey
delete_CkPrng $prng
delete_CkEcc $ecdsa
exit
}
puts "ECDSA signature = $ecdsaSigBase64"
# -----------------------------------------------------------
# Now let's verify the signature using the public key.
set pubKey [new_CkPublicKey]
set success [CkPublicKey_LoadFromFile $pubKey "qa_data/ecc/secp256r1-pubkey.pem"]
if {$success != 1} then {
puts [CkPublicKey_lastErrorText $pubKey]
delete_CkStringBuilder $sb
delete_CkPrivateKey $privKey
delete_CkPrng $prng
delete_CkEcc $ecdsa
delete_CkPublicKey $pubKey
exit
}
# Note: When verifying, Chilkat will auto-detect the format for both kinds of ECDSA signatures (ASN.1 or binary r+s)
set result [CkEcc_VerifyHashENC $ecdsa $hash $ecdsaSigBase64 "base64" $pubKey]
if {$result == 1} then {
puts "Signature is valid."
delete_CkStringBuilder $sb
delete_CkPrivateKey $privKey
delete_CkPrng $prng
delete_CkEcc $ecdsa
delete_CkPublicKey $pubKey
exit
}
if {$result == 0} then {
puts "Signature is invalid."
delete_CkStringBuilder $sb
delete_CkPrivateKey $privKey
delete_CkPrng $prng
delete_CkEcc $ecdsa
delete_CkPublicKey $pubKey
exit
}
if {$result < 0} then {
puts [CkEcc_lastErrorText $ecdsa]
puts "The VerifyHashENC method call failed."
delete_CkStringBuilder $sb
delete_CkPrivateKey $privKey
delete_CkPrng $prng
delete_CkEcc $ecdsa
delete_CkPublicKey $pubKey
exit
}
delete_CkStringBuilder $sb
delete_CkPrivateKey $privKey
delete_CkPrng $prng
delete_CkEcc $ecdsa
delete_CkPublicKey $pubKey