crypto
← Back to practices Practice 08

Toy ECDSA

Generate keys, sign an integer and verify its signature. Change the message to see how verification responds.

Public parameters

E: y² = x³ + ax + b mod p · B = dA

Generator A = (x, y, 1)

Checks probable primes p and q, a nonsingular curve and qA = O. Large examples have order 4q; A generates the order-q subgroup.

1. Keys and signing

0 < m, d < q
R = k_E A · r = x_R mod q
s = (m + dr) k_E⁻¹ mod q

2. Verification

Enter the received public key B and signature. Uses message m from the previous panel.

3. Experiments

Alice and Bob generate independent keys, sign m and verify both signatures and a modified message. The exchange is simulated in this browser.

The search for d uses baby-step giant-step and searches 1 ≤ d ≤ min(q−1, 2³²−1). The 128–1024-bit examples exercise the arithmetic; these supersingular curves are not production parameters.

Educational C17 and WebAssembly implementation. Calculations and the private key stay in this browser. rand() and non-constant-time arithmetic are unsuitable for real signatures.