Proposal to add ECDSA secp256r1 (P-256) and secp256k1 signers

53 views
Skip to first unread message

Leigh McCulloch

unread,
Feb 8, 2022, 3:24:55 PM2/8/22
to Stellar Developers
Hi all,

I propose CAP-43, adding support for ECDSA account signers that use the secp256r1 (P-256) and secp256k1 curves. It would make it possible to store account keys in a wide range of HSMs (hardware security modules) since many HSMs, including many popular cloud key management solutions (MS, AWS, GCP, IBM), do not provide support for ed25519. Also, by supporting P-256, institutions who need to keep their account or issuer keys in FIPS approved security modules can do so.

The proposal doesn't change the keys available for identifying accounts. Therefore, account master keys would still be limited to ed25519.

Feedback appreciated. If you have a use case where this would be especially helpful, please share information about it here.

Cheers,
Leigh
Reply all
Reply to author
Forward
0 new messages