← BACK TO THE WIRE
N°0433Chain Fusion2 MIN4 SOURCES

ICP Tests the Next Step Toward P-256 Threshold ECDSA

A new NNS proposal points to the next practical step for secp256r1 threshold ECDSA on ICP: generating a test master key. The move could connect canisters to web-native identity standards, but it is not yet a production rollout.

ICP Tests the Next Step Toward P-256 Threshold ECDSA
IMAGE: AI-GENERATED

ICP’s long-discussed move toward secp256r1, also known as P-256, has reached a concrete testing milestone. An October 5 update in the Internet Computer Developer Forum says Proposal 144212 is live to generate a P-256 ECDSA master key for testing on subnet 2fq7c.

That matters because the gap is not simply about adding another elliptic curve. ICP’s current Chain Fusion signing stack is centered on threshold ECDSA over secp256k1, the curve used by Bitcoin and Ethereum. P-256 would target a different compatibility frontier: web authentication, enterprise identity, certificates, and protocols that commonly expect ES256 signatures.

The project’s earlier technical explanation is cautious. DFINITY said the underlying cryptographic protocol already supports P-256, while integration remains necessary across higher layers including consensus, execution, and governance. It also said that governance proposals would be required to generate and back up threshold keys, with no precise production timeline at that point.

Proposal 144212 therefore looks best understood as an infrastructure checkpoint. A test master key can validate key generation, subnet operation, signing behavior, and the operational path for future key backup. It does not by itself make P-256 available to arbitrary canisters or establish a production signing key.

That distinction is visible in the current documentation. The IC interface specification recognizes P-256 for ordinary ECDSA signatures and WebAuthn-related verification, but the Chain-key cryptography guide lists deployed threshold ECDSA keys only for secp256k1. In other words, ICP already speaks P-256 in parts of its interface and identity stack; the open Chain Fusion question is whether canisters can obtain threshold-generated P-256 signatures under the network’s distributed key-management model.

For developers building decentralized certificate authorities, OAuth-related flows, DPoP, JWT integrations, or other web-facing authentication systems, the test-key proposal is an encouraging signal—but not yet an API contract. The next meaningful evidence will be a successful test deployment followed by documented management-canister support, key backup, governance activation, and a clearly identified production key.

The October 5 forum update links the work to Proposal 144212. A separate NNS proposal, 144213, concerns an NNS canister upgrade and is adjacent governance activity rather than evidence that P-256 signing is already generally available.

The key takeaway is simple: P-256 has moved from roadmap discussion toward controlled network testing. Chain Fusion gains a possible bridge to mainstream web cryptography only after the test path becomes a supported, governed production service.

TAGSICPChain FusionThreshold ECDSAsecp256r1
Grounded sources4 REFS
  1. [01]Plans for secp256r1 (P-256) threshold ECDSA support?forum.dfinity.org ↗
  2. [02]Proposal: 144212 - ICP Dashboarddashboard.internetcomputer.org ↗
  3. [03]Chain-key cryptographydocs.internetcomputer.org ↗
  4. [04]IC interface specificationdocs.internetcomputer.org ↗
Read next

Get the wire in your inbox

Every new signal, straight from the generator. No noise, unsubscribe anytime.

RSS AVAILABLE · NO SPAM