This package is abandoned and no longer maintained. The author suggests using the paragonie/ecc package instead.

PHP Elliptic Curve Cryptography library

Package info

github.com/phpecc/phpecc

pkg:composer/mdanter/ecc

Statistics

Installs: 5 772 445

Dependents: 96

Suggesters: 4

Stars: 342

Open Issues: 20

v1.0.0 2021-01-16 19:42 UTC

Requires

Requires (Dev)

Suggests

None

Provides

None

Conflicts

None

Replaces

None

MIT 34e2eec096bf3dcda814e8f66dd91ae87a2db7cd

DiffieHellmanECDSAellipticcurvesecp256k1ecdhphpeccnistp192nistp224nistp256nistp521secp256r1nistp384


README

👁 Build Status

👁 Scrutinizer Code Quality
👁 Code Coverage

👁 Latest Stable Version
👁 Total Downloads
👁 Latest Unstable Version
👁 License

Information

This library is a rewrite/update of Matyas Danter's ECC library. All credit goes to him.

For more information on Elliptic Curve Cryptography please read this fine article.

The library supports the following curves:

  • secp112r1
  • secp256k1
  • nistp192
  • nistp224
  • nistp256 / secp256r1
  • nistp384 / secp384r1
  • nistp521

During ECDSA, a random value k is required. It is acceptable to use a true RNG to generate this value, but should the same k value ever be repeatedly used for a key, an attacker can recover that signing key. The HMAC random generator can derive a deterministic k value from the message hash and private key, voiding this concern.

The library uses a non-branching Montgomery ladder for scalar multiplication, as it's constant time and avoids secret dependant branches.

License

This package is released under the MIT license.

Requirements

  • PHP 7.0+ or PHP 8.0+
  • composer
  • ext-gmp

Support for older PHP versions:

  • v0.4.x: php ^5.6|<7.2
  • v0.5.x: php ^7.0
  • v1.0.x: php ^7.0|^8.0

Installation

You can install this library via Composer :

composer require mdanter/ecc:^1.0

Contribute

When sending in pull requests, please make sure to run the make command.

The default target runs all PHPUnit and PHPCS tests. All tests must validate for your contribution to be accepted.

It's also always a good idea to check the results of the Scrutinizer analysis for your pull requests.

Usage

Examples: