Skip to content

docs: add the secp256r1 ECDSA keys to the chain-key pages - #420

Draft
eichhorl wants to merge 1 commit into
mainfrom
docs/ecdsa-secp256r1
Draft

eichhorl wants to merge 1 commit into
mainfrom
docs/ecdsa-secp256r1

Conversation

@eichhorl

@eichhorl eichhorl commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The scheme table on the chain-key cryptography page gets a secp256r1 (NIST P-256) row. Its use cases are web standards that require ES256: JSON Web Tokens, and VAPID web push (RFC 8292, section 2).
  • The key derivation paragraph names SLIP-10 for P-256, matching the ecdsa_public_key section of the spec from feat: add secp256r1 to the ECDSA curves in the interface spec #394.
  • The deployed keys table and the cycle costs table list (secp256r1, test_key_1) and (secp256r1, key_1) next to the secp256k1 keys. The fees are the same, because ic0.cost_sign_with_ecdsa prices a signature by the subnet that holds the key, not by the curve (system_api.rs).

Merge condition

The pages describe the end state: both secp256r1 keys enabled for signing on mainnet, on the same signing subnets as the other keys (test_key_1 on fuqsr, key_1 on pzp6e). Keep this a draft until that holds. If a key ends up on a different subnet, adjust its cycle costs row.

Rust canisters get EcdsaCurve::Secp256r1 from ic-cdk-management-canister 0.3.0 (dfinity/cdk-rs#716), and PocketIC 16.1.0 holds the same keys for tests. The offline key derivation guide stays as it is: @dfinity/ic-pub-key v1.0.2 supports only secp256k1 and ed25519.

Tests

node scripts/validate.js passes on both pages. npm run build was not run locally (Node 18 here; Astro needs 22.12).

The interface spec and the management canister reference gained the
`secp256r1` curve in #394. The concept and cycle cost pages still
described threshold ECDSA as secp256k1 only.

- The scheme table on the chain-key cryptography page gets a
  `secp256r1` (NIST P-256) row. Its use cases are web standards that
  require ES256: JSON Web Tokens, and VAPID web push (RFC 8292,
  section 2).
- The key derivation paragraph names SLIP-10 for P-256, matching the
  `ecdsa_public_key` section of the spec.
- The deployed keys table and the cycle costs table list
  `(secp256r1, test_key_1)` and `(secp256r1, key_1)` next to the
  secp256k1 keys, on the same subnets and at the same fees.
  `ic0.cost_sign_with_ecdsa` prices a signature by the subnet that
  holds the key, not by the curve.
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

🤖 Here's your preview: https://kwnd6-zaaaa-aaaam-ai7va-cai.icp0.io

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant