Skip to main content
This is unreleased documentation for the main (development) branch of crypto-glue.

DigestSigner

Trait DigestSigner 

Source
pub trait DigestSigner<D, S>
where D: Update,
{ // Required method fn try_sign_digest<F>(&self, f: F) -> Result<S, Error> where F: Fn(&mut D) -> Result<(), Error>; // Provided method fn sign_digest<F>(&self, f: F) -> S where F: Fn(&mut D) { ... } }
Expand description

Sign the given prehashed message Digest using Self.

§Notes

This trait is primarily intended for signature algorithms based on the Fiat-Shamir heuristic, a method for converting an interactive challenge/response-based proof-of-knowledge protocol into an offline digital signature through the use of a random oracle, i.e. a digest function.

The security of such protocols critically rests upon the inability of an attacker to solve for the output of the random oracle, as generally otherwise such signature algorithms are a system of linear equations and therefore doing so would allow the attacker to trivially forge signatures.

To prevent misuse which would potentially allow this to be possible, this API accepts a Digest instance, rather than a raw digest value.

Required Methods§

Source

fn try_sign_digest<F>(&self, f: F) -> Result<S, Error>
where F: Fn(&mut D) -> Result<(), Error>,

Attempt to sign a message by updating the received Digest with it, returning a digital signature on success, or an error if something went wrong.

The given function can be invoked multiple times. It is expected that in each invocation the Digest is updated with the entire equal message.

§Errors

Returns implementation-specific errors in the event signing failed (e.g. KMS or HSM communication error).

Provided Methods§

Source

fn sign_digest<F>(&self, f: F) -> S
where F: Fn(&mut D),

Sign a message by updating the received Digest with it, returning a signature.

The given function can be invoked multiple times. It is expected that in each invocation the Digest is updated with the entire equal message.

§Panics

In the event of a signing error.

Dyn Compatibility§

This trait is not dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementations on Foreign Types§

Source§

impl<C, D> DigestSigner<D, (Signature<C>, RecoveryId)> for SigningKey<C>

Available on crate feature algorithm only.
Source§

fn try_sign_digest<F>(&self, f: F) -> Result<(Signature<C>, RecoveryId), Error>
where F: Fn(&mut D) -> Result<(), Error>,

Source§

impl<C, D> DigestSigner<D, Signature<C>> for SigningKey<C>

Sign message digest using a deterministic ephemeral scalar (k) computed using the algorithm described in RFC6979 § 3.2.

Source§

fn try_sign_digest<F>(&self, f: F) -> Result<Signature<C>, Error>
where F: Fn(&mut D) -> Result<(), Error>,

Source§

impl<C, D> DigestSigner<D, SignatureWithOid<C>> for SigningKey<C>

Source§

fn try_sign_digest<F>(&self, f: F) -> Result<SignatureWithOid<C>, Error>
where F: Fn(&mut D) -> Result<(), Error>,

Source§

impl<D, C> DigestSigner<D, Signature<C>> for SigningKey<C>

Available on crate feature der only.
Source§

fn try_sign_digest<F>(&self, f: F) -> Result<Signature<C>, Error>
where F: Fn(&mut D) -> Result<(), Error>,

Implementors§

Source§

impl<D> DigestSigner<D, Signature> for crypto_glue::rsa::pkcs1v15::SigningKey<D>