pub struct Rs256Verify {
pub message: ByteVec,
pub signature: ByteVec,
pub modulus: ByteVec,
pub rsa_intermediates: RsaIntermediates,
}Expand description
RS256 signature verification circuit (internal implementation)
This circuit verifies a signature for a given message according to the
signature verification algorithm RSASSA-PKCS1-v1_5, using SHA-256 as a
hash.
This signature verification algorithm is used in JWT signatures which have the “alg” header set to “RS256”. https://datatracker.ietf.org/doc/html/rfc7518#section-3.1
Fields§
§message: ByteVecThe message to verify (packed as 64-bit words, 8 bytes per wire)
signature: ByteVecThe RSA signature as a FixedByteVec (the primary input interface)
modulus: ByteVecThe RSA modulus as a FixedByteVec (the primary input interface)
rsa_intermediates: RsaIntermediatesWires associated with intermediate RSA computations
Implementations§
Source§impl Rs256Verify
impl Rs256Verify
Sourcepub fn new(
builder: &mut CircuitBuilder,
message: ByteVec,
signature: ByteVec,
modulus: ByteVec,
) -> Self
pub fn new( builder: &mut CircuitBuilder, message: ByteVec, signature: ByteVec, modulus: ByteVec, ) -> Self
Create a new RS256 verification circuit
This constructor accepts inputs with little-endian wire packing, which is convenient when composing with other circuits (e.g base64, concat) which use the same wire packing.
RS256 uses the public exponent 2^16 + 1 (65537). The circuit verifies that the encoded message (EM) has the following properties:
signature < modulusEM = signature^65537 mod modulusEMhas a valid PKCS#1 v1.5 prefix- The hash stored in
EMis equal to the SHA-256 hash of the provided message.
§Arguments
builder- Circuit buildermessage- A FixedByteVec containing the plaintext messagesignature- The RSA signature with little-endian wire packing (256 bytes for 2048-bit RSA)modulus- The RSA modulus with little-endian wire packing (256 bytes for 2048-bit RSA)
§Panics
- If signature or modulus don’t have at least 256 bytes
Sourcepub fn populate_len_bytes(&self, w: &mut WitnessFiller<'_>, len_bytes: usize)
pub fn populate_len_bytes(&self, w: &mut WitnessFiller<'_>, len_bytes: usize)
Populate the message length
Sourcepub fn populate_rsa(
&self,
w: &mut WitnessFiller<'_>,
signature: &[u8],
modulus: &[u8],
)
pub fn populate_rsa( &self, w: &mut WitnessFiller<'_>, signature: &[u8], modulus: &[u8], )
Populate the RSA signature, modulus and intermediate computations
pub fn populate_intermediates( &self, w: &mut WitnessFiller<'_>, signature: &[u8], modulus: &[u8], )
Sourcepub fn populate_message(&self, w: &mut WitnessFiller<'_>, message: &[u8])
pub fn populate_message(&self, w: &mut WitnessFiller<'_>, message: &[u8])
Sourcepub fn populate_modulus(&self, w: &mut WitnessFiller<'_>, modulus_bytes: &[u8])
pub fn populate_modulus(&self, w: &mut WitnessFiller<'_>, modulus_bytes: &[u8])
Sourcepub fn populate_signature(
&self,
w: &mut WitnessFiller<'_>,
signature_bytes: &[u8],
)
pub fn populate_signature( &self, w: &mut WitnessFiller<'_>, signature_bytes: &[u8], )
Auto Trait Implementations§
impl Freeze for Rs256Verify
impl RefUnwindSafe for Rs256Verify
impl Send for Rs256Verify
impl Sync for Rs256Verify
impl Unpin for Rs256Verify
impl UnsafeUnpin for Rs256Verify
impl UnwindSafe for Rs256Verify
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more