You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否在NEAR Rust智能合约中实现NIST P-256曲线验证及多签适配?

Can I implement NIST P-256 signature verification in a Rust NEAR smart contract?

Absolutely! You can absolutely implement NIST P-256 (secp256r1) signature verification directly in your Rust-based NEAR smart contract—this is totally doable despite the protocol not natively supporting the curve. Here’s a practical breakdown of how to get started:

1. Pick a compatible Rust cryptography library

You’ll need a no_std-compatible Rust library that supports secp256r1 ECDSA verification, since NEAR contracts compile to WebAssembly (Wasm) and run in a constrained no_std environment. The best choice here is the p256 crate from the RustCrypto project—it’s well-maintained, audited, and explicitly supports secp256r1 with ECDSA verification.

2. Configure your contract’s Cargo.toml

Add the p256 dependency to your contract’s Cargo.toml, making sure to enable the features you need (and disable default std support):

[dependencies]
near-sdk = "4.0"
p256 = { version = "0.13", features = ["ecdsa", "verify", "der"], default-features = false }
  • ecdsa: Enables ECDSA functionality
  • verify: Enables signature verification (we don’t need signing in the contract)
  • der: Adds support for parsing ASN.1 DER-formatted signatures (common for iOS Secure Enclave outputs)
  • default-features = false: Switches the crate to no_std mode, which is required for NEAR contracts

3. Implement the verification logic

Write a contract method that takes the public key, signature, and message hash (since Secure Enclave typically signs a SHA-256 hash of the original message) as inputs, then validates the signature using the p256 library. Here’s a simplified example:

use p256::ecdsa::{VerifyingKey, Signature, signature::Verifier};
use p256::ecdsa::der::Signature as DerSignature;
use near_sdk::{near_bindgen, env};

#[near_bindgen]
#[derive(Default)]
pub struct MultiSigContract;

#[near_bindgen]
impl MultiSigContract {
    /// Verifies a P-256 signature generated by iOS Secure Enclave
    /// - pub_key_bytes: SEC1-formatted public key (compressed or uncompressed)
    /// - signature_bytes: ASN.1 DER-formatted signature from Secure Enclave
    /// - message_hash: SHA-256 hash of the original message that was signed
    pub fn verify_p256_signature(
        &self,
        pub_key_bytes: Vec<u8>,
        signature_bytes: Vec<u8>,
        message_hash: Vec<u8>,
    ) -> bool {
        // Parse the public key from SEC1 bytes
        let verifying_key = match VerifyingKey::from_sec1_bytes(&pub_key_bytes) {
            Ok(key) => key,
            Err(_) => return false,
        };

        // Parse the DER-formatted signature
        let der_signature = match DerSignature::from_bytes(&signature_bytes) {
            Ok(sig) => sig,
            Err(_) => return false,
        };
        let signature = Signature::from(der_signature);

        // Verify the signature against the message hash
        verifying_key.verify(&message_hash, &signature).is_ok()
    }
}

Key notes on format compatibility:

  • Public keys: iOS Secure Enclave exports public keys in SEC1 format (either compressed ~33 bytes or uncompressed ~65 bytes)—VerifyingKey::from_sec1_bytes handles both.
  • Signatures: Secure Enclave generates ASN.1 DER-formatted signatures (~70-72 bytes). If you’re working with compact (64-byte) signatures instead, skip the DER parsing step and use Signature::from_bytes directly.
  • Message hashing: Secure Enclave requires signing a SHA-256 hash of your message. If your contract receives the raw message instead of the hash, add the sha2 crate to compute the hash on-chain:
    sha2 = { version = "0.10", features = ["digest"], default-features = false }
    
    Then compute the hash inside your method:
    use sha2::{Sha256, Digest};
    
    let mut hasher = Sha256::new();
    hasher.update(raw_message);
    let message_hash = hasher.finalize().to_vec();
    

4. Test and optimize for gas

  • Use the near-sdk-sim crate to write unit tests for your verification logic—test valid signatures, invalid signatures, malformed keys, etc., to ensure correctness.
  • Be mindful of gas costs: Cryptographic operations consume gas, so optimize by minimizing memory allocations (use references where possible) and avoiding unnecessary computations. The p256 library is optimized for Wasm, but always test gas usage with realistic inputs to stay under NEAR’s block gas limits.

5. Integrate with your multi-sig flow

Once the verification method works, you can integrate it into your multi-sig logic:

  • Track which signers are using P-256 vs NEAR’s native ed25519
  • Collect signatures from both types
  • Verify each signature using the appropriate method
  • Approve actions once your threshold of valid signatures is met

内容的提问来源于stack exchange,提问作者Vlad Grichina

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 20:22:39