Skip to content

feat: Add ed25519 key derivation and signature functions - #10506

Merged
FrederikBolding merged 6 commits into
mainfrom
fb/ed25519
Sep 29, 2026
Merged

FrederikBolding merged 6 commits into
mainfrom
fb/ed25519

Conversation

@FrederikBolding

@FrederikBolding FrederikBolding commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Explanation

Add public key derivation and signing utilities for Ed25519.

React Native benchmarks:

Finished ed25519 public key benchmark (cold): WebCrypto = 38 ms JS = 1167 ms

Finished ed25519 signing benchmark using 1000 bytes of data: WebCrypto = 2 ms JS = 102 ms
Finished ed25519 signing benchmark using 5000 bytes of data: WebCrypto = 9 ms JS = 279 ms
Finished ed25519 signing benchmark using 10000 bytes of data: WebCrypto = 2 ms JS = 504 ms

Finished ed25519 verification benchmark using 1000 bytes of data: WebCrypto = 2 ms JS = 89 ms
Finished ed25519 verification benchmark using 5000 bytes of data: WebCrypto = 2 ms JS = 180 ms
Finished ed25519 verification benchmark using 10000 bytes of data: WebCrypto = 1 ms JS = 295 ms

References

https://consensyssoftware.atlassian.net/browse/WPC-1344

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

Medium Risk
Introduces new signing and verification primitives in a cryptography package; behavior is WebCrypto-backed and test-vector covered, but consumers must handle keys and signatures correctly.

Overview
Adds a new @metamask/cryptography/ed25519 export with getPublicKey, sign, and verify, implemented on crypto.subtle with raw 32-byte keys and 64-byte signatures, PKCS#8 wrapping for private keys, and strict length checks.

Shared buildPKCS8Header / toPKCS8 helpers in utils.ts replace the inline X25519 PKCS8 construction so X25519 and Ed25519 use the same envelope pattern. Changelog and package.json exports document the new subpath; tests cover RFC 8032 vector 3 plus BufferSource variants and invalid key/signature sizes.

Reviewed by Cursor Bugbot for commit 3b53a55. Bugbot is set up for automated code reviews on this repo. Configure here.

@FrederikBolding
FrederikBolding changed the base branch from main to fb/x25519 September 28, 2026 13:45
Base automatically changed from fb/x25519 to main September 29, 2026 09:38
@FrederikBolding
FrederikBolding marked this pull request as ready for review September 29, 2026 10:25
@FrederikBolding
FrederikBolding requested a review from a team as a code owner September 29, 2026 10:25
// Intentionally discarding private key from JWK (`d`).
const subtlePublicKey = await globalThis.crypto.subtle.importKey(
'jwk',
{ kty: jwk.kty, crv: jwk.crv, x: jwk.x },

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could parse jwk.x manually, but it seemed cleaner to let the WebCrypto API deal with it instead. Potentially faster too?

Comment thread packages/cryptography/src/utils.ts Outdated
* @param oid - The 3-byte curve OID.
* @returns The PKCS8 header.
*/
export function buildPKCS8Header(

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe this?

Suggested change
export function buildPKCS8Header(
export function buildPkcs8Header(

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I had it cased like this before but kinda preferred the uppercase option 🤔

@FrederikBolding
FrederikBolding added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit 561acdf Sep 29, 2026
44 checks passed
@FrederikBolding
FrederikBolding deleted the fb/ed25519 branch September 29, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants