Ed25519
Ed25519 digital signatures (RFC 8032). Header: pkc/ed25519/noxtls_ed25519.h.
Algorithm overview
Ed25519 is an EdDSA signature scheme over Curve25519. It is designed for high speed, deterministic signing, and strong security properties with compact keys/signatures.
Pros and cons
Pros
- Very fast verification/signing with small keys and signatures.
- Deterministic signing avoids many nonce-generation failure classes.
- Widely adopted across modern protocols and tooling.
Cons
- Signature algorithm only (not key agreement).
- Compatibility with legacy RSA/ECDSA-only systems can be limited.
- Requires careful domain separation/protocol framing, like all signature schemes.
When to use
- Strong default for modern software signing and identity/authentication.
- Good choice when performance and compact signatures matter.
- Prefer when interoperability targets support Ed25519 natively.
Constants
NOXTLS_ED25519_PRIVATE_KEY_SIZE= 32NOXTLS_ED25519_PUBLIC_KEY_SIZE= 32NOXTLS_ED25519_SIGNATURE_SIZE= 64
API
noxtls_ed25519_generate_key
noxtls_return_t noxtls_ed25519_generate_key(uint8_t private_key[32], uint8_t public_key[32]);
Generate private/public key pair.
noxtls_ed25519_public_key
noxtls_return_t noxtls_ed25519_public_key(const uint8_t private_key[32], uint8_t public_key[32]);
Derive public key from private key seed.
noxtls_ed25519_sign
noxtls_return_t noxtls_ed25519_sign(const uint8_t private_key[32],
const uint8_t *message,
uint32_t message_len,
uint8_t signature[64]);
Sign message with Ed25519.
noxtls_ed25519_verify
noxtls_return_t noxtls_ed25519_verify(const uint8_t public_key[32],
const uint8_t *message,
uint32_t message_len,
const uint8_t signature[64]);
Verify Ed25519 signature.
Streaming verification
Use the streaming form when the signed message arrives in pieces or should not be assembled in one contiguous buffer. The context retains the public key, signature, and SHA-512 state; it contains no private signing key.
noxtls_ed25519_verify_stream_ctx_t verify_ctx;
rc = noxtls_ed25519_verify_stream_init(&verify_ctx, public_key, signature);
if (rc == NOXTLS_RETURN_SUCCESS) {
rc = noxtls_ed25519_verify_stream_update(&verify_ctx, part_a, part_a_len);
}
if (rc == NOXTLS_RETURN_SUCCESS) {
rc = noxtls_ed25519_verify_stream_update(&verify_ctx, part_b, part_b_len);
}
if (rc == NOXTLS_RETURN_SUCCESS) {
rc = noxtls_ed25519_verify_stream_final(&verify_ctx);
}
noxtls_ed25519_verify_stream_final() returns NOXTLS_RETURN_SUCCESS only
when the signature is valid. Do not call update() after final(); initialize
a new context for another message.
noxtls_ed25519_verify_split
noxtls_return_t noxtls_ed25519_verify_split(const uint8_t public_key[32],
const uint8_t *message_part_a,
uint32_t message_part_a_len,
const uint8_t *message_part_b,
uint32_t message_part_b_len,
const uint8_t signature[64]);
Convenience verification for exactly two consecutive message segments. It has the same validity result as verifying their concatenation.