通过SubtleCrypto 对象可以使用公钥算法用私钥生成签名,或者用公钥验证签名。这两种操作
分别通过SubtleCrypto.sign()和SubtleCrypto.verify()方法完成。
签名消息需要传入参数对象以指定算法和必要的值、CryptoKey 和要签名的ArrayBuffer 或
ArrayBufferView。下面的例子会生成一个椭圆曲线密钥对,并使用私钥签名消息:
(async function() {
const keyParams = {
name: ‘ECDSA’,
namedCurve: ‘P-256’
};
const keyUsages = [‘sign’, ‘verify’];
const {publicKey, privateKey} = await crypto.subtle.generateKey(keyParams, true,
keyUsages);
const message = (new TextEncoder()).encode(‘I am Satoshi Nakamoto’);
const signParams = {
name: ‘ECDSA’,
hash: ‘SHA-256’
};
const signature = await crypto.subtle.sign(signParams, privateKey, message);
console.log(new Uint32Array(signature));
// Uint32Array(16) [2202267297, 698413658, 1501924384, 691450316, 778757775, … ]
})();
希望通过这个签名验证消息的人可以使用公钥和SubtleCrypto.verify()方法。这个方法的签名
几乎与sign()相同,只是必须提供公钥以及签名。下面的例子通过验证生成的签名扩展了前面的例子:
(async function() {
const keyParams = {
name: ‘ECDSA’,
namedCurve: ‘P-256’
};
const keyUsages = [‘sign’, ‘verify’];
const {publicKey, privateKey} = await crypto.subtle.generateKey(keyParams, true,
keyUsages);
const message = (new TextEncoder()).encode(‘I am Satoshi Nakamoto’);
const signParams = {
name: ‘ECDSA’,
hash: ‘SHA-256’
};
const signature = await crypto.subtle.sign(signParams, privateKey, message);
const verified = await crypto.subtle.verify(signParams, publicKey, signature,
message);
console.log(verified); // true
})();
javascript七基础学习系列一千三百九十五:使用非对称密钥签名和验证消息
最新推荐文章于 2024-10-30 18:24:25 发布