如何将ECC公钥的DER或PEM格式转换为RAW格式(基于OpenSSL/WolfSSL)
Let's walk through how to convert your DER (or PEM) ECC public key to RAW format—whether using OpenSSL, WolfSSL, or even manually parsing the hex DER you provided.
First, quick background: RAW ECC public key typically refers to the uncompressed public key (prefixed with 0x04) which is just the concatenation of the x and y coordinates of the ECC point, stripped of all ASN.1 wrapping from DER/PEM. For secp521r1 (the curve used in your DER), each coordinate is 66 bytes (521 bits), so the full RAW key is 1 + 66 + 66 = 133 bytes.
1. Using OpenSSL
Your input is a hex-encoded DER key, so first we need to convert it to a binary DER file, then extract the RAW key:
Step 1: Convert hex DER to binary file
Run this command to save your hex string as a binary DER file:
echo "30 81 9b 30 10 06 07 2a 86 48 ce 3d 02 01 06 05 2b 81 04 00 23 03 81 86 00 04 00 e8 ff 35 e0 32 6e 57 9b 43 f9 05 97 d0 e1 e5 df 1e 63 51 ed 30 e3 11 22 c3 47 bf 8b a0 1d f0 bc 0a 74 38 ea ee 47 4e 0e 9e ba 87 ad 17 2a 2c ee 25 81 40 54 63 93 63 a0 38 1c cd b7 5b e7 8b a7 b5 00 ea 60 94 44 aa 85 ee e8 af 15 e2 d8 0d 1a 07 8a 3d 9e 9f 97 17 53 d9 58 26 b9 a9 0a 33 92 d9 93 3b 39 a5 d6 cb 87 88 97 59 71 88 e0 81 db 31 4e 73 80 1d 8b c8 13 bc 34 54 71 01 1b b0 be ed 22 a6" | xxd -r -p > ecc_pub.der
Step 2: Extract RAW public key with OpenSSL
Use the openssl ec command to strip the ASN.1 wrapping:
openssl ec -in ecc_pub.der -inform DER -pubin -outform RAW -out ecc_pub.raw
The output file ecc_pub.raw will contain the uncompressed RAW key (starting with 0x04 followed by x and y coordinates). If you just need the raw x+y without the 0x04 prefix, you can skip the first byte with:
tail -c +2 ecc_pub.raw > ecc_pub_x_y.raw
2. Using WolfSSL
WolfSSL provides the eccutil tool for ECC key operations. Here's how to use it:
Step 1: Convert hex DER to binary (same as OpenSSL step 1)
Use the same xxd command to create ecc_pub.der.
Step 2: Extract RAW key with eccutil
Run this command to convert the DER key to RAW format:
eccutil -d ecc_pub.der -raw ecc_pub.raw
By default, this outputs the uncompressed key (with 0x04 prefix). Check the WolfSSL docs if you need compressed RAW format (but your example uses uncompressed).
3. Manual Parsing (For Your Specific Hex DER)
Let's break down your 158-byte hex DER to get the RAW key directly:
- The DER is an ASN.1
SEQUENCEstarting with30 81 9b(length 155 bytes). - Inside the sequence:
30 10: Algorithm Identifier (length 16 bytes) – this tells us the curve is secp521r1 (OID1.3.132.0.35).03 81 86: BIT STRING (length 134 bytes) – this is the actual public key data.- The first byte
00indicates no unused bits in the BIT STRING. - The rest starting with
04is the uncompressed RAW key:
- The first byte
Here's your RAW key (hex format):
04 00 e8 ff 35 e0 32 6e 57 9b 43 f9 05 97 d0 e1 e5 df 1e 63 51 ed 30 e3 11 22 c3 47 bf 8b a0 1d f0 bc 0a 74 38 ea ee 47 4e 0e 9e ba 87 ad 17 2a 2c ee 25 81 40 54 63 93 63 a0 38 1c cd b7 5b e7 8b a7 b5 00 ea 60 94 44 aa 85 ee e8 af 15 e2 d8 0d 1a 07 8a 3d 9e 9f 97 17 53 d9 58 26 b9 a9 0a 33 92 d9 93 3b 39 a5 d6 cb 87 88 97 59 71 88 e0 81 db 31 4e 73 80 1d 8b c8 13 bc 34 54 71 01 1b b0 be ed 22 a6
- If you need just the x and y coordinates (without the
04prefix), split it into:- X coordinate (first 66 bytes after
04):00 e8 ff 35 e0 32 6e 57 9b 43 f9 05 97 d0 e1 e5 df 1e 63 51 ed 30 e3 11 22 c3 47 bf 8b a0 1d f0 bc 0a 74 38 ea ee 47 4e 0e 9e ba 87 ad 17 2a 2c ee 25 81 40 54 63 93 63 a0 38 1c cd b7 5b e7 8b a7 b5 00 ea 60 94 44 aa 85 ee e8 af 15 e2 d8 0d - Y coordinate (last 66 bytes):
1a 07 8a 3d 9e 9f 97 17 53 d9 58 26 b9 a9 0a 33 92 d9 93 3b 39 a5 d6 cb 87 88 97 59 71 88 e0 81 db 31 4e 73 80 1d 8b c8 13 bc 34 54 71 01 1b b0 be ed 22 a6
- X coordinate (first 66 bytes after
内容的提问来源于stack exchange,提问作者Tang Jiye

