如何在Hyperledger Indy-SDK钱包中导入外部生成的ED25519密钥对?
Importing Pre-Generated ED25519 Key Pairs into Hyperledger Indy-SDK Wallets
Got it, let's break down exactly how to import your existing ED25519 key pair into a Hyperledger Indy-SDK wallet, plus cover the general workflow for importing any external key into an Indy wallet.
Prerequisites
- You already have a valid ED25519 key pair: a 32-byte private key (or Base58-encoded seed) and corresponding 32-byte public key (verkey)
- You've already created and opened an Indy-SDK wallet (with the necessary write permissions)
Step-by-Step Import (Python SDK Example)
The core method here is wallet_import_key—this is how you inject external keys into the wallet. Here's a practical implementation:
import indy async def import_ed25519_key(wallet_handle, private_key_seed, key_metadata=None): # Build the import configuration for your ED25519 key import_config = { "key_type": "ed25519", "seed": private_key_seed, # Use your 32-byte Base58 seed or raw binary "metadata": key_metadata # Optional: add context like associated DID } # Execute the import key_id = await indy.wallet_import_key(wallet_handle, import_config) print(f"Successfully imported key with ID: {key_id}") return key_id # Example usage (replace with your actual wallet handle and seed) # wallet_handle = await indy.open_wallet(wallet_config, wallet_credentials) # my_seed = "your_base58_encoded_32_byte_ed25519_seed" # await import_ed25519_key(wallet_handle, my_seed, metadata={"purpose": "did_authentication"})
Key Details to Note:
- Seed Format: Indy expects the private key seed as either raw 32-byte binary or a Base58-encoded string. If you have a PEM-formatted private key, you'll need to extract the seed first (see the note section below).
- Key Type: Always specify
"ed25519"for this algorithm—this tells the SDK how to handle the key material. - Key ID: The returned
key_idis your reference for using this key in future operations (like signing, encrypting, or associating with a DID).
Associating the Key with a DID (Optional but Common)
Once imported, you'll likely want to link this key to a DID for identity operations. Here are two ways to do this:
1. Link to an Existing DID
async def link_key_to_existing_did(wallet_handle, did, key_id): # Store the key ID in the DID's metadata for easy reference await indy.set_did_metadata(wallet_handle, did, f'{{"auth_key_id": "{key_id}"}}') print(f"Linked key {key_id} to DID {did}")
2. Create a New DID Using the Imported Key
If you don't have a DID yet, you can create one directly tied to your imported key:
async def create_did_from_imported_key(wallet_handle, key_id): did_config = { "method": "sov", "key_type": "ed25519", "key_id": key_id } did, verkey = await indy.create_and_store_my_did(wallet_handle, did_config) print(f"Created DID {did} with verkey {verkey}") return did, verkey
General Workflow for Importing External Keys into Indy Wallets
No matter the key algorithm (ED25519, BLS, etc.), the process follows these universal steps:
- Prepare Key Material: Extract the raw private key/seed and confirm the algorithm type.
- Build Import Config: Construct a dictionary with
key_type, the private key/seed field (e.g.,"seed"for ED25519), and optional metadata. - Call Import API: Use your SDK's wallet import method (like
wallet_import_keyin Python) with the open wallet handle and config. - Validate the Import: Verify the key exists with
wallet_list_keysor test it with a signature operation to ensure it works as expected.
Important Notes
- Converting PEM to Seed: If your ED25519 key is in PEM format, use this snippet to extract the Base58 seed:
from cryptography.hazmat.primitives import serialization import base58 def extract_ed25519_seed(pem_str): private_key = serialization.load_pem_private_key( pem_str.encode(), password=None ) raw_seed = private_key.private_bytes_raw() return base58.b58encode(raw_seed).decode() - Wallet Permissions: Make sure you open the wallet with credentials that have write access—read-only access will fail the import.
- Metadata Organization: Adding metadata to your imported keys helps you track their purpose (e.g., "authentication", "encryption") or associated DIDs later on.
内容的提问来源于stack exchange,提问作者0xSHA1001
相关产品推荐
相关产品推荐

