-
Notifications
You must be signed in to change notification settings - Fork 139
/
DefaultCryptoBackend.cs
66 lines (60 loc) · 2 KB
/
DefaultCryptoBackend.cs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
using System.IO;
using System.Security.Cryptography;
using Org.BouncyCastle.Asn1;
using Org.BouncyCastle.Crypto.Digests;
using Org.BouncyCastle.Crypto.Signers;
using Org.BouncyCastle.Math;
namespace Libplanet.Crypto
{
public class DefaultCryptoBackend<T> : ICryptoBackend<T>
where T : HashAlgorithm
{
public byte[] Sign(HashDigest<T> messageHash, PrivateKey privateKey)
{
var h = new Sha256Digest();
var kCalculator = new HMacDsaKCalculator(h);
var signer = new ECDsaSigner(kCalculator);
signer.Init(true, privateKey.KeyParam);
BigInteger[] rs = signer.GenerateSignature(messageHash.ToByteArray());
var r = rs[0];
var s = rs[1];
BigInteger otherS = privateKey.KeyParam.Parameters.N.Subtract(s);
if (s.CompareTo(otherS) == 1)
{
s = otherS;
}
var bos = new MemoryStream(72);
var seq = new DerSequenceGenerator(bos);
seq.AddObject(new DerInteger(r));
seq.AddObject(new DerInteger(s));
seq.Close();
return bos.ToArray();
}
public bool Verify(
HashDigest<T> messageHash,
byte[] signature,
PublicKey publicKey)
{
try
{
Asn1Sequence asn1Sequence = (Asn1Sequence)Asn1Object.FromByteArray(signature);
var rs = new[]
{
((DerInteger)asn1Sequence[0]).Value,
((DerInteger)asn1Sequence[1]).Value,
};
var verifier = new ECDsaSigner();
verifier.Init(false, publicKey.KeyParam);
return verifier.VerifySignature(messageHash.ToByteArray(), rs[0], rs[1]);
}
catch (IOException)
{
return false;
}
catch (Asn1ParsingException)
{
return false;
}
}
}
}