This SIP adds a new SIP-7932 algorithm of type 0x01 for supporting P256 signatures.
Motivation
P256 (a.k.a secp256r1) is a widely-used NIST standardized algorithm that already has a presence within the Sila codebase. This makes it a great algorithm to write test
cases against implementations of SIP-7932.
Specification
This SIP defines a new SIP-7932 algorithmic type with the following parameters:
Constant
Value
ALG_TYPE
Bytes1(0x01)
SIZE
129
N=0xffffffff00000000ffffffffffffffffbce6faada7179e84f3b9cac2fc632551defgas_cost(signing_data:Bytes)->Uint64:# This is the precompile cost from [SIP-7951](/SIPS/sip-7951) with 3000 gas
# subtracted (the cost of the secp256k1 precompile)
BASE_GAS=Uint64(3900)# Calculate extra overhead for keccak256 hashing
iflen(signing_data)==32:returnBASE_GASelse:minimum_word_size=(len(signing_data)+31)//32returnBASE_GAS+Uint64(30+(6*minimum_word_size))defvalidate(signature:Bytes)->None|Error:# This function is a noop as there is no
# exposed function defined in [SIP-7951](/SIPS/sip-7951)
defverify(signature:Bytes,signing_data:Bytes)->Bytes|Error:iflen(signing_data)!=32:# Hash if non-standard size
signing_data=keccak256(signing_data)# Ignore initial alg_type byte
signature=signature[1:](r,s,x,y)=(signature[0:32],signature[32:64],signature[64:96],signature[96:128])# This is similar to [SIP-2](/SIPS/sip-2)'s malleability verification.
assert(s<=N/2)# This is defined in [P256Verify Function](#p256verify-function)
assert(P256Verify(signing_data,r,s,x,y)==Bytes("0x0000000000000000000000000000000000000000000000000000000000000001"))# Return 64 byte public key
returnx||ydefmerge_detached_signature(detached_signature:bytes,public_key:bytes)->bytes:# Concatenate r,s || x,y
returndetached_signature+public_key
P256Verify Function
The P256Verify function is the logic of the precompile defined in SIP-7951, the only exception is that this function MUST NOT charge any gas.
Rationale
Why P256?
P256 or secp256r1, is used globally but (more importantly) has an existing implementation in all execution clients. This allows easy implementation of a known-safe algorithm, which is perfect for a test algorithm.
James Kempton (@SirSpudlington), "SIP-8030: P256 algorithm support [DRAFT]," Sila Improvement Proposals, no. 8030, September 2025. Available: https://sips.sila.org/SIPS/sip-8030.