Class VoucherSignatureService
This service provides cryptographic operations for vouchers using the same signature scheme as Nostr (BIP-340 Schnorr signatures over secp256k1):
- Signing voucher secrets with issuer private keys (secp256k1/Schnorr)
- Verifying signatures with issuer public keys (secp256k1 x-only)
- Creating complete
SignedVoucherinstances
Cryptographic Details
Uses BIP-340 Schnorr signatures over the NUT-10 serialized representation of the voucher secret. The canonical bytes for signing are obtained by serializing the VoucherSecret without the signature tag, then hashing with SHA-256.
Key Format
Keys are expected as hex-encoded strings (matching Nostr format):
- Private key: 64 hex characters (32 bytes) - secp256k1 scalar
- Public key: 64 hex characters (32 bytes) - x-only secp256k1 point
Signature Format
Signatures are 64 bytes (BIP-340 Schnorr format).
Thread Safety
All methods are stateless and thread-safe.
- See Also:
-
Method Summary
Modifier and TypeMethodDescriptionstatic SignedVouchercreateSigned(@NonNull xyz.tcheeric.cashu.common.VoucherSecret secret, @NonNull String issuerPrivateKeyHex, @NonNull String issuerPublicKeyHex) Creates a signed voucher by signing the secret and setting the signature/pubkey tags.static byte[]Signs a voucher secret with an issuer's private key using Schnorr signatures.static booleanverify(@NonNull xyz.tcheeric.cashu.common.VoucherSecret secret) Verifies a voucher secret's signature using the signature and public key from its tags.static booleanverify(@NonNull xyz.tcheeric.cashu.common.VoucherSecret secret, @lombok.NonNull byte[] signature, @NonNull String issuerPublicKeyHex) Verifies a voucher signature using the issuer's public key.
-
Method Details
-
sign
public static byte[] sign(@NonNull @NonNull xyz.tcheeric.cashu.common.VoucherSecret secret, @NonNull @NonNull String issuerPrivateKeyHex) Signs a voucher secret with an issuer's private key using Schnorr signatures.The signature is generated over the canonical representation of the voucher secret (NUT-10 format without signature tag) using BIP-340 Schnorr signatures. The resulting signature is 64 bytes.
- Parameters:
secret- the voucher secret to sign (must not be null)issuerPrivateKeyHex- the issuer's private key as hex string (64 chars, must not be null)- Returns:
- the Schnorr signature (64 bytes)
- Throws:
IllegalArgumentException- if the private key format is invalid
-
verify
public static boolean verify(@NonNull @NonNull xyz.tcheeric.cashu.common.VoucherSecret secret) Verifies a voucher secret's signature using the signature and public key from its tags.- Parameters:
secret- the voucher secret with signature and public key tags set- Returns:
- true if the signature is valid, false otherwise
-
verify
public static boolean verify(@NonNull @NonNull xyz.tcheeric.cashu.common.VoucherSecret secret, @NonNull @lombok.NonNull byte[] signature, @NonNull @NonNull String issuerPublicKeyHex) Verifies a voucher signature using the issuer's public key.Verifies that the signature is valid for the voucher secret's canonical bytes using BIP-340 Schnorr signature verification.
- Parameters:
secret- the voucher secret (must not be null)signature- the signature to verify (must not be null, 64 bytes)issuerPublicKeyHex- the issuer's public key as hex string (64 chars, must not be null)- Returns:
- true if the signature is valid, false otherwise
-
createSigned
public static SignedVoucher createSigned(@NonNull @NonNull xyz.tcheeric.cashu.common.VoucherSecret secret, @NonNull @NonNull String issuerPrivateKeyHex, @NonNull @NonNull String issuerPublicKeyHex) Creates a signed voucher by signing the secret and setting the signature/pubkey tags.This is a convenience method that:
- Signs the voucher secret with the private key using Schnorr
- Sets the signature and public key tags on the secret
- Creates a
SignedVoucherwrapping the secret
- Parameters:
secret- the voucher secret to sign (must not be null)issuerPrivateKeyHex- the issuer's private key as hex string (must not be null)issuerPublicKeyHex- the issuer's public key as hex string (must not be null)- Returns:
- a new SignedVoucher instance
- Throws:
IllegalArgumentException- if key formats are invalid
-