RFC 6979 - Deterministic Usage of the Digital Signature Algorithm (DSA) and Elliptic Curve Digital Signature Algorithm (ECDSA)
- Status: Informational
- Published: August 2013
- Stream: Independent
- Errata: RFC Editor Errata
Document Information
- RFC Number: 6979
- Title: Deterministic Usage of the Digital Signature Algorithm (DSA) and Elliptic Curve Digital Signature Algorithm (ECDSA)
- Authors: T. Pornin
- Date: August 2013
- Category: Informational
- ISSN: 2070-1721
Abstract
This document defines a deterministic digital signature generation procedure. Such signatures are compatible with standard Digital Signature Algorithm (DSA) and Elliptic Curve Digital Signature Algorithm (ECDSA) digital signatures and can be processed with unmodified verifiers, which need not be aware of the procedure described therein. Deterministic signatures retain the cryptographic security features associated with digital signatures but can be more easily implemented in various environments, since they do not need access to a source of high-quality randomness.
Status of This Memo
This document is not an Internet Standards Track specification; it is published for informational purposes.
This is a contribution to the RFC Series, independently of any other RFC stream. The RFC Editor has chosen to publish this document at its discretion and makes no statement about its value for implementation or deployment. Documents approved for publication by the RFC Editor are not a candidate for any level of Internet Standard; see Section 2 of RFC 5741.
Information about the current status of this document, any errata, and how to provide feedback on it may be obtained at http://www.rfc-editor.org/info/rfc6979.
Copyright Notice
Copyright (c) 2013 IETF Trust and the persons identified as the document authors. All rights reserved.
This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (http://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document.
Table of Contents
- 1. Introduction
- 2. DSA and ECDSA Notations
- 3. Deterministic DSA and ECDSA
- 4. Security Considerations
- 5. Intellectual Property Status
- 6. References
- A.1. Detailed Example
- A.2. Test Vectors
- A.2.1. DSA, 1024 Bits
- A.2.2. DSA, 2048 Bits
- A.2.3. ECDSA, 192 Bits (Prime Field)
- A.2.4. ECDSA, 224 Bits (Prime Field)
- A.2.5. ECDSA, 256 Bits (Prime Field)
- A.2.6. ECDSA, 384 Bits (Prime Field)
- A.2.7. ECDSA, 521 Bits (Prime Field)
- A.2.8. ECDSA, 163 Bits (Binary Field, Koblitz Curve)
- A.2.9. ECDSA, 233 Bits (Binary Field, Koblitz Curve)
- A.2.10. ECDSA, 283 Bits (Binary Field, Koblitz Curve)
- A.2.11. ECDSA, 409 Bits (Binary Field, Koblitz Curve)
- A.2.12. ECDSA, 571 Bits (Binary Field, Koblitz Curve)
- A.2.13. ECDSA, 163 Bits (Binary Field, Pseudorandom Curve)
- A.2.14. ECDSA, 233 Bits (Binary Field, Pseudorandom Curve)
- A.2.15. ECDSA, 283 Bits (Binary Field, Pseudorandom Curve)
- A.2.16. ECDSA, 409 Bits (Binary Field, Pseudorandom Curve)
- A.2.17. ECDSA, 571 Bits (Binary Field, Pseudorandom Curve)
- A.3. Sample Code
- Author's Address