BoundedAuthorityProtocol.V3.EcJwk (Bounded Authority Protocol v0.6.2)

Copy Markdown View Source

Exact public P-256 EC JWK encoding, decoding, and RFC 7638 thumbprints for the BAP3-ES256-SHA256 suite.

The raw public key is the 65-byte uncompressed SEC1 point 0x04 || x || y; the wire JWK is exactly {"crv":"P-256","kty":"EC","x":…,"y":…}. The decoded point is validated on-curve by pure arithmetic before any crypto backend call, so the closed rejection is deterministic across backends.

Summary

Functions

Decodes an exact public EC JWK to the raw 65-byte uncompressed SEC1 point.

Encodes one raw 65-byte uncompressed SEC1 public key as the canonical public EC JWK.

Returns the canonical base64url RFC 7638 thumbprint.

Returns the exact RFC 7638 public EC thumbprint preimage.

Functions

decode_public(jwk, limits)

@spec decode_public(binary(), BoundedAuthorityProtocol.V1.Bounds.t() | map()) ::
  {:ok, binary()} | {:error, :invalid}

Decodes an exact public EC JWK to the raw 65-byte uncompressed SEC1 point.

encode_public(public_key, limits)

@spec encode_public(binary(), BoundedAuthorityProtocol.V1.Bounds.t() | map()) ::
  {:ok, binary()} | {:error, :invalid}

Encodes one raw 65-byte uncompressed SEC1 public key as the canonical public EC JWK.

thumbprint(jwk, limits)

@spec thumbprint(binary(), BoundedAuthorityProtocol.V1.Bounds.t() | map()) ::
  {:ok, binary()} | {:error, :invalid}

Returns the canonical base64url RFC 7638 thumbprint.

thumbprint_preimage(jwk, limits)

@spec thumbprint_preimage(binary(), BoundedAuthorityProtocol.V1.Bounds.t() | map()) ::
  {:ok, binary()} | {:error, :invalid}

Returns the exact RFC 7638 public EC thumbprint preimage.