Add WebAuthn (secp256r1/P-256) signature verification for passkey support
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 25/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Da chiarire
- Stato di attività
- Ferma
- Stack tecnologico
- rust
- Ambito
- authentication, backend-api-design, cryptography
Direzione di ricerca
La issue non indica file, test o punti di ingresso. Inizia esaminando STF e l’implementazione esistente dell’autenticazione ECDSA secp256k1, quindi confronta la specifica WebAuthn, EIP-7212 e il crate p256 di RustCrypto. Il lavoro è completo quando sono presenti la verifica deterministica P-256, payload WebAuthn validati, una misurazione appropriata del gas e il supporto per il modello di firmatario k1/r1 previsto.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
Add support for secp256r1 (P-256/prime256v1) signature verification to enable WebAuthn/passkey-based authentication alongside the existing secp256k1 ECDSA scheme.
Passkeys eliminate seed phrases and leverage device-native authentication (biometrics, PIN), significantly improving UX for end users.
Motivation
- UX: Passkeys are the industry direction for wallet auth — no seed phrases, no browser extensions, built into every modern OS and device.
- Adoption: WebAuthn is supported by all major browsers and platforms (Apple, Google, Microsoft). Billions of devices already have P-256 hardware support.
- Account Abstraction alignment: Supporting multiple signature schemes is a natural fit for account-driven architectures.
Scope
- P-256 signature verification — Add
ecrecoverequivalent for secp256r1 in the STF. - WebAuthn payload parsing — Decode authenticator data + client data JSON per the WebAuthn spec.
- Gas/fee metering — Price r1 verification appropriately (see tradeoffs).
- Authentication module — Extend or create an auth account that supports both k1 and r1 signers.
Performance Tradeoffs
secp256r1 is slower than secp256k1 in pure software
On-chain verification is pure software (deterministic STF), so hardware acceleration is not available. Expected overhead:
| Aspect | secp256k1 | secp256r1 |
|---|---|---|
| Point doubling | Faster (a=0 in y²=x³+7) | Slower (a=-3 in y²=x³-3x+b) |
| Scalar multiplication | GLV endomorphism (~30% speedup) | No equivalent optimization |
| Software verification | Baseline | ~20-40% slower |
| Library maturity | libsecp256k1 (extremely optimized) | Good (p256, RustCrypto) but less specialized |
Implications
- Gas pricing: r1
ecrecovermust be priced higher than k1 to reflect actual compute cost. Underpricing creates a DoS vector. - Throughput: At sub-millisecond per verification, the per-tx overhead is small. Becomes relevant only at very high TPS where signature verification dominates block processing time.
- Block gas limits: If r1 txs consume more gas per signature, fewer r1-signed txs fit per block compared to k1.
Where r1 wins (client side, not on-chain)
- Signing happens in secure enclave/TPM with hardware P-256 — effectively instant from user perspective.
- No private key management burden on the user.
Implementation Considerations
- Use
p256crate (RustCrypto) for verification — pure Rust, no C dependencies, audited. - WebAuthn payloads include additional fields (challenge, origin, authenticator data) that must be parsed and validated deterministically.
- Consider whether to support both raw P-256 ECDSA and full WebAuthn envelope, or only WebAuthn.
- Signature malleability: enforce low-S normalization same as k1.
References
- Lingua principale
- Rust
- Stelle
- 4
- Fork
- 0
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di evstack/ev-rs
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 30/100
-
enhancement
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 20/100
-
enhancement
Difficoltà 5/5 Più di una settimana Idoneità per principianti 20/100
Tutte le issue di evstack/ev-rs
Issue simili
-
[Bug]: Web chat input doesn't regain focus after a reply finishesForse già presa @GaijinSystems l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
zeroclaw-labs/zeroclaw#11658 ·
I maintainer di solito rispondono entro 2 giorni
-
good first issue help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
bytecodealliance/wasm-tools#2768 ·
I maintainer di solito rispondono entro 1 giorno
-
documentation
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
NuSkooler/enigma-bbs#907 ·
I maintainer di solito rispondono entro 1 giorno