如何在Python中基于P256曲线实现ECDSA数字签名并通过曲线点W重建公钥完成签名验证?
Great question! Let's walk through exactly how to implement ECDSA with the P256 (NIST P-256) curve in Python, including the key part you're asking about: reconstructing a public key from an elliptic curve point W and verifying signatures without needing the private key. I'll cover both libraries you mentioned, with clear, actionable examples.
Using the ecdsa Library
The ecdsa library is lightweight and straightforward for ECDSA operations. Here's a complete workflow that covers your use case:
Step 1: Install the library
First, install it via pip:
pip install ecdsa
Step 2: Generate a key pair (for demonstration)
We'll start by generating a private/public key pair to simulate having a private key for signing, but remember—for verification, you won't need this private key later.
import ecdsa import hashlib # Use the P256 curve (NIST P-256) curve = ecdsa.NIST256p # Generate private key private_key = ecdsa.SigningKey.generate(curve=curve) # Get the corresponding public key public_key = private_key.get_verifying_key() # Extract the elliptic curve point W (x and y coordinates) w_x = public_key.point.x() w_y = public_key.point.y() print(f"Elliptic Curve Point W: (x={w_x}, y={w_y})")
Step 3: Sign data with the private key
Let's sign some sample data—this would be your "signature operation" step:
# Original data to sign data = b"Hello, ECDSA with P256!" # Sign the data (uses SHA-256 by default for NIST256p) signature = private_key.sign(data)
Step 4: Reconstruct the public key from point W
Now, this is the critical part you're interested in. Using just the x and y coordinates of point W, we can rebuild the public key without ever touching the private key:
# Reconstruct the public key from the W point coordinates reconstructed_public_key = ecdsa.VerifyingKey.from_public_point( ecdsa.ellipticcurve.Point(curve.curve, w_x, w_y), curve=curve )
Step 5: Verify the signature
Finally, use the reconstructed public key to verify the signature against the original data:
try: reconstructed_public_key.verify(signature, data) print("Signature verified successfully!") except ecdsa.BadSignatureError: print("Invalid signature!")
Using PyCryptodome
PyCryptodome is a more comprehensive cryptography library with broader support for different algorithms. Here's how to implement the same workflow:
Step 1: Install the library
Install it via pip:
pip install pycryptodome
Step 2: Generate a key pair and extract point W
from Crypto.PublicKey import ECC from Crypto.Signature import DSS from Crypto.Hash import SHA256 # Use P256 curve curve = "P-256" # Generate private key private_key = ECC.generate(curve=curve) # Get public key and extract point W coordinates public_key = private_key.public_key() w_point = public_key.pointQ w_x = w_point.x w_y = w_point.y print(f"Elliptic Curve Point W: (x={w_x}, y={w_y})")
Step 3: Sign the data
# Original data data = b"Hello, ECDSA with P256 via PyCryptodome!" # Create SHA-256 hash of the data hash_obj = SHA256.new(data) # Sign using DSA (ECDSA) signer = DSS.new(private_key, 'fips-186-3') signature = signer.sign(hash_obj)
Step 4: Reconstruct public key from point W
To reconstruct the public key in PyCryptodome, we need to encode the point W into the appropriate uncompressed point format (standard for ECDSA):
# Convert x and y to 32-byte big-endian bytes x_bytes = w_x.to_bytes(32, byteorder='big') y_bytes = w_y.to_bytes(32, byteorder='big') # Uncompressed format starts with 0x04, followed by x and y bytes encoded_point = b'\x04' + x_bytes + y_bytes # Reconstruct the public key from the encoded point import binascii pem_format = f"-----BEGIN PUBLIC KEY-----\n{binascii.b2a_base64(encoded_point).decode().strip()}\n-----END PUBLIC KEY-----" reconstructed_public_key = ECC.import_key(pem_format)
Step 5: Verify the signature
# Hash the original data again hash_obj = SHA256.new(data) # Verify the signature verifier = DSS.new(reconstructed_public_key, 'fips-186-3') try: verifier.verify(hash_obj, signature) print("Signature verified successfully!") except ValueError: print("Invalid signature!")
Key Notes on Public Key Reconstruction
The reason you can reconstruct a public key from point W is that an ECDSA public key is exactly an elliptic curve point—it's calculated by multiplying the private key (a scalar) by the curve's base point G. As long as you have the valid x and y coordinates of that point (W), you can rebuild the public key and use it to verify signatures. You never need the private key for this step, which aligns perfectly with your workflow.
Which Library to Choose?
- Use
ecdsaif you want a minimal, easy-to-use library focused specifically on ECDSA operations. Its API is more intuitive for this exact use case. - Use PyCryptodome if you need a full-featured cryptography library that supports other algorithms (AES, RSA, etc.) alongside ECDSA.
内容的提问来源于stack exchange,提问作者LozCodes

