mbedtls ported to mbed-classic

Fork of mbedtls by Christopher Haster

Embed: (wiki syntax)

« Back to documentation index

ecp.h File Reference

ecp.h File Reference

Elliptic curves over GF(p) More...

Go to the source code of this file.

Data Structures

struct  mbedtls_ecp_curve_info
 Curve information for use by other modules. More...
struct  mbedtls_ecp_point
 ECP point structure (jacobian coordinates) More...
struct  mbedtls_ecp_group
 ECP group structure. More...
struct  mbedtls_ecp_keypair
 ECP key pair structure. More...

Enumerations

enum  mbedtls_ecp_group_id { ,
  MBEDTLS_ECP_DP_SECP192R1, MBEDTLS_ECP_DP_SECP224R1, MBEDTLS_ECP_DP_SECP256R1, MBEDTLS_ECP_DP_SECP384R1,
  MBEDTLS_ECP_DP_SECP521R1, MBEDTLS_ECP_DP_BP256R1, MBEDTLS_ECP_DP_BP384R1, MBEDTLS_ECP_DP_BP512R1,
  MBEDTLS_ECP_DP_CURVE25519, MBEDTLS_ECP_DP_SECP192K1, MBEDTLS_ECP_DP_SECP224K1, MBEDTLS_ECP_DP_SECP256K1
}
 

Domain parameters (curve, subgroup and generator) identifiers.

More...

Functions

const mbedtls_ecp_curve_infombedtls_ecp_curve_list (void)
 Get the list of supported curves in order of preferrence (full information)
const mbedtls_ecp_group_idmbedtls_ecp_grp_id_list (void)
 Get the list of supported curves in order of preferrence (grp_id only)
const mbedtls_ecp_curve_infombedtls_ecp_curve_info_from_grp_id (mbedtls_ecp_group_id grp_id)
 Get curve information from an internal group identifier.
const mbedtls_ecp_curve_infombedtls_ecp_curve_info_from_tls_id (uint16_t tls_id)
 Get curve information from a TLS NamedCurve value.
const mbedtls_ecp_curve_infombedtls_ecp_curve_info_from_name (const char *name)
 Get curve information from a human-readable name.
void mbedtls_ecp_point_init (mbedtls_ecp_point *pt)
 Initialize a point (as zero)
void mbedtls_ecp_group_init (mbedtls_ecp_group *grp)
 Initialize a group (to something meaningless)
void mbedtls_ecp_keypair_init (mbedtls_ecp_keypair *key)
 Initialize a key pair (as an invalid one)
void mbedtls_ecp_point_free (mbedtls_ecp_point *pt)
 Free the components of a point.
void mbedtls_ecp_group_free (mbedtls_ecp_group *grp)
 Free the components of an ECP group.
void mbedtls_ecp_keypair_free (mbedtls_ecp_keypair *key)
 Free the components of a key pair.
int mbedtls_ecp_copy (mbedtls_ecp_point *P, const mbedtls_ecp_point *Q)
 Copy the contents of point Q into P.
int mbedtls_ecp_group_copy (mbedtls_ecp_group *dst, const mbedtls_ecp_group *src)
 Copy the contents of a group object.
int mbedtls_ecp_set_zero (mbedtls_ecp_point *pt)
 Set a point to zero.
int mbedtls_ecp_is_zero (mbedtls_ecp_point *pt)
 Tell if a point is zero.
int mbedtls_ecp_point_cmp (const mbedtls_ecp_point *P, const mbedtls_ecp_point *Q)
 Compare two points.
int mbedtls_ecp_point_read_string (mbedtls_ecp_point *P, int radix, const char *x, const char *y)
 Import a non-zero point from two ASCII strings.
int mbedtls_ecp_point_write_binary (const mbedtls_ecp_group *grp, const mbedtls_ecp_point *P, int format, size_t *olen, unsigned char *buf, size_t buflen)
 Export a point into unsigned binary data.
int mbedtls_ecp_point_read_binary (const mbedtls_ecp_group *grp, mbedtls_ecp_point *P, const unsigned char *buf, size_t ilen)
 Import a point from unsigned binary data.
int mbedtls_ecp_tls_read_point (const mbedtls_ecp_group *grp, mbedtls_ecp_point *pt, const unsigned char **buf, size_t len)
 Import a point from a TLS ECPoint record.
int mbedtls_ecp_tls_write_point (const mbedtls_ecp_group *grp, const mbedtls_ecp_point *pt, int format, size_t *olen, unsigned char *buf, size_t blen)
 Export a point as a TLS ECPoint record.
int mbedtls_ecp_group_load (mbedtls_ecp_group *grp, mbedtls_ecp_group_id index)
 Set a group using well-known domain parameters.
int mbedtls_ecp_tls_read_group (mbedtls_ecp_group *grp, const unsigned char **buf, size_t len)
 Set a group from a TLS ECParameters record.
int mbedtls_ecp_tls_write_group (const mbedtls_ecp_group *grp, size_t *olen, unsigned char *buf, size_t blen)
 Write the TLS ECParameters record for a group.
int mbedtls_ecp_mul (mbedtls_ecp_group *grp, mbedtls_ecp_point *R, const mbedtls_mpi *m, const mbedtls_ecp_point *P, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng)
 Multiplication by an integer: R = m * P (Not thread-safe to use same group in multiple threads)
int mbedtls_ecp_muladd (mbedtls_ecp_group *grp, mbedtls_ecp_point *R, const mbedtls_mpi *m, const mbedtls_ecp_point *P, const mbedtls_mpi *n, const mbedtls_ecp_point *Q)
 Multiplication and addition of two points by integers: R = m * P + n * Q (Not thread-safe to use same group in multiple threads)
int mbedtls_ecp_check_pubkey (const mbedtls_ecp_group *grp, const mbedtls_ecp_point *pt)
 Check that a point is a valid public key on this curve.
int mbedtls_ecp_check_privkey (const mbedtls_ecp_group *grp, const mbedtls_mpi *d)
 Check that an mbedtls_mpi is a valid private key for this curve.
int mbedtls_ecp_gen_keypair_base (mbedtls_ecp_group *grp, const mbedtls_ecp_point *G, mbedtls_mpi *d, mbedtls_ecp_point *Q, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng)
 Generate a keypair with configurable base point.
int mbedtls_ecp_gen_keypair (mbedtls_ecp_group *grp, mbedtls_mpi *d, mbedtls_ecp_point *Q, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng)
 Generate a keypair.
int mbedtls_ecp_gen_key (mbedtls_ecp_group_id grp_id, mbedtls_ecp_keypair *key, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng)
 Generate a keypair.
int mbedtls_ecp_check_pub_priv (const mbedtls_ecp_keypair *pub, const mbedtls_ecp_keypair *prv)
 Check a public-private key pair.
int mbedtls_ecp_self_test (int verbose)
 Checkup routine.

Detailed Description

Elliptic curves over GF(p)

Copyright (C) 2006-2015, ARM Limited, All Rights Reserved SPDX-License-Identifier: Apache-2.0

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

This file is part of mbed TLS (https://tls.mbed.org)

Definition in file ecp.h.


Enumeration Type Documentation

Domain parameters (curve, subgroup and generator) identifiers.

Only curves over prime fields are supported.

Warning:
This library does not support validation of arbitrary domain parameters. Therefore, only well-known domain parameters from trusted sources should be used. See mbedtls_ecp_group_load().
Enumerator:
MBEDTLS_ECP_DP_SECP192R1 

192-bits NIST curve

MBEDTLS_ECP_DP_SECP224R1 

224-bits NIST curve

MBEDTLS_ECP_DP_SECP256R1 

256-bits NIST curve

MBEDTLS_ECP_DP_SECP384R1 

384-bits NIST curve

MBEDTLS_ECP_DP_SECP521R1 

521-bits NIST curve

MBEDTLS_ECP_DP_BP256R1 

256-bits Brainpool curve

MBEDTLS_ECP_DP_BP384R1 

384-bits Brainpool curve

MBEDTLS_ECP_DP_BP512R1 

512-bits Brainpool curve

MBEDTLS_ECP_DP_CURVE25519 

Curve25519

MBEDTLS_ECP_DP_SECP192K1 

192-bits "Koblitz" curve

MBEDTLS_ECP_DP_SECP224K1 

224-bits "Koblitz" curve

MBEDTLS_ECP_DP_SECP256K1 

256-bits "Koblitz" curve

Definition at line 53 of file ecp.h.


Function Documentation

int mbedtls_ecp_check_privkey ( const mbedtls_ecp_group grp,
const mbedtls_mpi d 
)

Check that an mbedtls_mpi is a valid private key for this curve.

Parameters:
grpGroup used
dInteger to check
Returns:
0 if point is a valid private key, MBEDTLS_ERR_ECP_INVALID_KEY otherwise.
Note:
Uses bare components rather than an mbedtls_ecp_keypair structure in order to ease use with other structures such as mbedtls_ecdh_context of mbedtls_ecdsa_context.

Definition at line 1782 of file ecp.c.

int mbedtls_ecp_check_pub_priv ( const mbedtls_ecp_keypair pub,
const mbedtls_ecp_keypair prv 
)

Check a public-private key pair.

Parameters:
pubKeypair structure holding a public key
prvKeypair structure holding a private (plus public) key
Returns:
0 if successful (keys are valid and match), or MBEDTLS_ERR_ECP_BAD_INPUT_DATA, or a MBEDTLS_ERR_ECP_XXX or MBEDTLS_ERR_MPI_XXX code.

Definition at line 1920 of file ecp.c.

int mbedtls_ecp_check_pubkey ( const mbedtls_ecp_group grp,
const mbedtls_ecp_point pt 
)

Check that a point is a valid public key on this curve.

Parameters:
grpCurve/group the point should belong to
ptPoint to check
Returns:
0 if point is a valid public key, MBEDTLS_ERR_ECP_INVALID_KEY otherwise.
Note:
This function only checks the point is non-zero, has valid coordinates and lies on the curve, but not that it is indeed a multiple of G. This is additional check is more expensive, isn't required by standards, and shouldn't be necessary if the group used has a small cofactor. In particular, it is useless for the NIST groups which all have a cofactor of 1.
Uses bare components rather than an mbedtls_ecp_keypair structure in order to ease use with other structures such as mbedtls_ecdh_context of mbedtls_ecdsa_context.

Definition at line 1762 of file ecp.c.

int mbedtls_ecp_copy ( mbedtls_ecp_point P,
const mbedtls_ecp_point Q 
)

Copy the contents of point Q into P.

Parameters:
PDestination point
QSource point
Returns:
0 if successful, MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed

Definition at line 363 of file ecp.c.

const mbedtls_ecp_curve_info* mbedtls_ecp_curve_info_from_grp_id ( mbedtls_ecp_group_id  grp_id )

Get curve information from an internal group identifier.

Parameters:
grp_idA MBEDTLS_ECP_DP_XXX value
Returns:
The associated curve information or NULL

Definition at line 203 of file ecp.c.

const mbedtls_ecp_curve_info* mbedtls_ecp_curve_info_from_name ( const char *  name )

Get curve information from a human-readable name.

Parameters:
nameThe name
Returns:
The associated curve information or NULL

Definition at line 239 of file ecp.c.

const mbedtls_ecp_curve_info* mbedtls_ecp_curve_info_from_tls_id ( uint16_t  tls_id )

Get curve information from a TLS NamedCurve value.

Parameters:
tls_idA MBEDTLS_ECP_DP_XXX value
Returns:
The associated curve information or NULL

Definition at line 221 of file ecp.c.

const mbedtls_ecp_curve_info* mbedtls_ecp_curve_list ( void   )

Get the list of supported curves in order of preferrence (full information)

Returns:
A statically allocated array, the last entry is 0.

Definition at line 169 of file ecp.c.

int mbedtls_ecp_gen_key ( mbedtls_ecp_group_id  grp_id,
mbedtls_ecp_keypair key,
int(*)(void *, unsigned char *, size_t)  f_rng,
void *  p_rng 
)

Generate a keypair.

Parameters:
grp_idECP group identifier
keyDestination keypair
f_rngRNG function
p_rngRNG parameter
Returns:
0 if successful, or a MBEDTLS_ERR_ECP_XXX or MBEDTLS_MPI_XXX error code

Definition at line 1906 of file ecp.c.

int mbedtls_ecp_gen_keypair ( mbedtls_ecp_group grp,
mbedtls_mpi d,
mbedtls_ecp_point Q,
int(*)(void *, unsigned char *, size_t)  f_rng,
void *  p_rng 
)

Generate a keypair.

Parameters:
grpECP group
dDestination MPI (secret part)
QDestination point (public part)
f_rngRNG function
p_rngRNG parameter
Returns:
0 if successful, or a MBEDTLS_ERR_ECP_XXX or MBEDTLS_MPI_XXX error code
Note:
Uses bare components rather than an mbedtls_ecp_keypair structure in order to ease use with other structures such as mbedtls_ecdh_context of mbedtls_ecdsa_context.

Definition at line 1895 of file ecp.c.

int mbedtls_ecp_gen_keypair_base ( mbedtls_ecp_group grp,
const mbedtls_ecp_point G,
mbedtls_mpi d,
mbedtls_ecp_point Q,
int(*)(void *, unsigned char *, size_t)  f_rng,
void *  p_rng 
)

Generate a keypair with configurable base point.

Parameters:
grpECP group
GChosen base point
dDestination MPI (secret part)
QDestination point (public part)
f_rngRNG function
p_rngRNG parameter
Returns:
0 if successful, or a MBEDTLS_ERR_ECP_XXX or MBEDTLS_MPI_XXX error code
Note:
Uses bare components rather than an mbedtls_ecp_keypair structure in order to ease use with other structures such as mbedtls_ecdh_context of mbedtls_ecdsa_context.

Definition at line 1815 of file ecp.c.

int mbedtls_ecp_group_copy ( mbedtls_ecp_group dst,
const mbedtls_ecp_group src 
)

Copy the contents of a group object.

Parameters:
dstDestination group
srcSource group
Returns:
0 if successful, MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed

Definition at line 378 of file ecp.c.

void mbedtls_ecp_group_free ( mbedtls_ecp_group grp )

Free the components of an ECP group.

Definition at line 321 of file ecp.c.

void mbedtls_ecp_group_init ( mbedtls_ecp_group grp )

Initialize a group (to something meaningless)

Definition at line 284 of file ecp.c.

int mbedtls_ecp_group_load ( mbedtls_ecp_group grp,
mbedtls_ecp_group_id  index 
)

Set a group using well-known domain parameters.

Parameters:
grpDestination group
indexIndex in the list of well-known domain parameters
Returns:
0 if successful, MBEDTLS_ERR_MPI_XXX if initialization failed MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE for unkownn groups
Note:
Index should be a value of RFC 4492's enum NamedCurve, usually in the form of a MBEDTLS_ECP_DP_XXX macro.

Definition at line 691 of file ecp_curves.c.

const mbedtls_ecp_group_id* mbedtls_ecp_grp_id_list ( void   )

Get the list of supported curves in order of preferrence (grp_id only)

Returns:
A statically allocated array, terminated with MBEDTLS_ECP_DP_NONE.

Definition at line 177 of file ecp.c.

int mbedtls_ecp_is_zero ( mbedtls_ecp_point pt )

Tell if a point is zero.

Parameters:
ptPoint to test
Returns:
1 if point is zero, 0 otherwise

Definition at line 401 of file ecp.c.

void mbedtls_ecp_keypair_free ( mbedtls_ecp_keypair key )

Free the components of a key pair.

Definition at line 350 of file ecp.c.

void mbedtls_ecp_keypair_init ( mbedtls_ecp_keypair key )

Initialize a key pair (as an invalid one)

Definition at line 295 of file ecp.c.

int mbedtls_ecp_mul ( mbedtls_ecp_group grp,
mbedtls_ecp_point R,
const mbedtls_mpi m,
const mbedtls_ecp_point P,
int(*)(void *, unsigned char *, size_t)  f_rng,
void *  p_rng 
)

Multiplication by an integer: R = m * P (Not thread-safe to use same group in multiple threads)

Note:
In order to prevent timing attacks, this function executes the exact same sequence of (base field) operations for any valid m. It avoids any if-branch or array index depending on the value of m.
If f_rng is not NULL, it is used to randomize intermediate results in order to prevent potential timing attacks targeting these results. It is recommended to always provide a non-NULL f_rng (the overhead is negligible).
Parameters:
grpECP group
RDestination point
mInteger by which to multiply
PPoint to multiply
f_rngRNG function (see notes)
p_rngRNG parameter
Returns:
0 if successful, MBEDTLS_ERR_ECP_INVALID_KEY if m is not a valid privkey or P is not a valid pubkey, MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed

Definition at line 1611 of file ecp.c.

int mbedtls_ecp_muladd ( mbedtls_ecp_group grp,
mbedtls_ecp_point R,
const mbedtls_mpi m,
const mbedtls_ecp_point P,
const mbedtls_mpi n,
const mbedtls_ecp_point Q 
)

Multiplication and addition of two points by integers: R = m * P + n * Q (Not thread-safe to use same group in multiple threads)

Note:
In contrast to mbedtls_ecp_mul(), this function does not guarantee a constant execution flow and timing.
Parameters:
grpECP group
RDestination point
mInteger by which to multiply P
PPoint to multiply by m
nInteger by which to multiply Q
QPoint to be multiplied by n
Returns:
0 if successful, MBEDTLS_ERR_ECP_INVALID_KEY if m or n is not a valid privkey or P or Q is not a valid pubkey, MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed

Definition at line 1720 of file ecp.c.

int mbedtls_ecp_point_cmp ( const mbedtls_ecp_point P,
const mbedtls_ecp_point Q 
)

Compare two points.

Note:
This assumes the points are normalized. Otherwise, they may compare as "not equal" even if they are.
Parameters:
PFirst point to compare
QSecond point to compare
Returns:
0 if the points are equal, MBEDTLS_ERR_ECP_BAD_INPUT_DATA otherwise

Definition at line 409 of file ecp.c.

void mbedtls_ecp_point_free ( mbedtls_ecp_point pt )

Free the components of a point.

Definition at line 308 of file ecp.c.

void mbedtls_ecp_point_init ( mbedtls_ecp_point pt )

Initialize a point (as zero)

Definition at line 271 of file ecp.c.

int mbedtls_ecp_point_read_binary ( const mbedtls_ecp_group grp,
mbedtls_ecp_point P,
const unsigned char *  buf,
size_t  ilen 
)

Import a point from unsigned binary data.

Parameters:
grpGroup to which the point should belong
PPoint to import
bufInput buffer
ilenActual length of input
Returns:
0 if successful, MBEDTLS_ERR_ECP_BAD_INPUT_DATA if input is invalid, MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed, MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if the point format is not implemented.
Note:
This function does NOT check that the point actually belongs to the given group, see mbedtls_ecp_check_pubkey() for that.

Definition at line 497 of file ecp.c.

int mbedtls_ecp_point_read_string ( mbedtls_ecp_point P,
int  radix,
const char *  x,
const char *  y 
)

Import a non-zero point from two ASCII strings.

Parameters:
PDestination point
radixInput numeric base
xFirst affine coordinate as a null-terminated string
ySecond affine coordinate as a null-terminated string
Returns:
0 if successful, or a MBEDTLS_ERR_MPI_XXX error code

Definition at line 425 of file ecp.c.

int mbedtls_ecp_point_write_binary ( const mbedtls_ecp_group grp,
const mbedtls_ecp_point P,
int  format,
size_t *  olen,
unsigned char *  buf,
size_t  buflen 
)

Export a point into unsigned binary data.

Parameters:
grpGroup to which the point should belong
PPoint to export
formatPoint format, should be a MBEDTLS_ECP_PF_XXX macro
olenLength of the actual output
bufOutput buffer
buflenLength of the output buffer
Returns:
0 if successful, or MBEDTLS_ERR_ECP_BAD_INPUT_DATA or MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL

Definition at line 441 of file ecp.c.

int mbedtls_ecp_self_test ( int  verbose )

Checkup routine.

Returns:
0 if successful, or 1 if a test failed

Definition at line 1964 of file ecp.c.

int mbedtls_ecp_set_zero ( mbedtls_ecp_point pt )

Set a point to zero.

Parameters:
ptDestination point
Returns:
0 if successful, MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed

Definition at line 386 of file ecp.c.

int mbedtls_ecp_tls_read_group ( mbedtls_ecp_group grp,
const unsigned char **  buf,
size_t  len 
)

Set a group from a TLS ECParameters record.

Parameters:
grpDestination group
buf&(Start of input buffer)
lenBuffer length
Note:
buf is updated to point right after ECParameters on exit
Returns:
0 if successful, MBEDTLS_ERR_MPI_XXX if initialization failed MBEDTLS_ERR_ECP_BAD_INPUT_DATA if input is invalid

Definition at line 595 of file ecp.c.

int mbedtls_ecp_tls_read_point ( const mbedtls_ecp_group grp,
mbedtls_ecp_point pt,
const unsigned char **  buf,
size_t  len 
)

Import a point from a TLS ECPoint record.

Parameters:
grpECP group used
ptDestination point
buf$(Start of input buffer)
lenBuffer length
Note:
buf is updated to point right after the ECPoint on exit
Returns:
0 if successful, MBEDTLS_ERR_MPI_XXX if initialization failed MBEDTLS_ERR_ECP_BAD_INPUT_DATA if input is invalid

Definition at line 536 of file ecp.c.

int mbedtls_ecp_tls_write_group ( const mbedtls_ecp_group grp,
size_t *  olen,
unsigned char *  buf,
size_t  blen 
)

Write the TLS ECParameters record for a group.

Parameters:
grpECP group used
olenNumber of bytes actually written
bufBuffer to write to
blenBuffer length
Returns:
0 if successful, or MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL

Definition at line 628 of file ecp.c.

int mbedtls_ecp_tls_write_point ( const mbedtls_ecp_group grp,
const mbedtls_ecp_point pt,
int  format,
size_t *  olen,
unsigned char *  buf,
size_t  blen 
)

Export a point as a TLS ECPoint record.

Parameters:
grpECP group used
ptPoint to export
formatExport format
olenlength of data written
bufBuffer to write to
blenBuffer length
Returns:
0 if successful, or MBEDTLS_ERR_ECP_BAD_INPUT_DATA or MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL

Definition at line 567 of file ecp.c.