wolfSSL SSL/TLS library, support up to TLS1.3
Dependents: CyaSSL-Twitter-OAuth4Tw Example-client-tls-cert TwitterReader TweetTest ... more
wolfssl/wolfcrypt/ge_operations.h@13:f67a6c6013ca, 2017-08-22 (annotated)
- Committer:
- wolfSSL
- Date:
- Tue Aug 22 10:48:22 2017 +0000
- Revision:
- 13:f67a6c6013ca
wolfSSL3.12.0 with TLS1.3
Who changed what in which revision?
User | Revision | Line number | New contents of line |
---|---|---|---|
wolfSSL | 13:f67a6c6013ca | 1 | /* ge_operations.h |
wolfSSL | 13:f67a6c6013ca | 2 | * |
wolfSSL | 13:f67a6c6013ca | 3 | * Copyright (C) 2006-2016 wolfSSL Inc. |
wolfSSL | 13:f67a6c6013ca | 4 | * |
wolfSSL | 13:f67a6c6013ca | 5 | * This file is part of wolfSSL. |
wolfSSL | 13:f67a6c6013ca | 6 | * |
wolfSSL | 13:f67a6c6013ca | 7 | * wolfSSL is free software; you can redistribute it and/or modify |
wolfSSL | 13:f67a6c6013ca | 8 | * it under the terms of the GNU General Public License as published by |
wolfSSL | 13:f67a6c6013ca | 9 | * the Free Software Foundation; either version 2 of the License, or |
wolfSSL | 13:f67a6c6013ca | 10 | * (at your option) any later version. |
wolfSSL | 13:f67a6c6013ca | 11 | * |
wolfSSL | 13:f67a6c6013ca | 12 | * wolfSSL is distributed in the hope that it will be useful, |
wolfSSL | 13:f67a6c6013ca | 13 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
wolfSSL | 13:f67a6c6013ca | 14 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
wolfSSL | 13:f67a6c6013ca | 15 | * GNU General Public License for more details. |
wolfSSL | 13:f67a6c6013ca | 16 | * |
wolfSSL | 13:f67a6c6013ca | 17 | * You should have received a copy of the GNU General Public License |
wolfSSL | 13:f67a6c6013ca | 18 | * along with this program; if not, write to the Free Software |
wolfSSL | 13:f67a6c6013ca | 19 | * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA |
wolfSSL | 13:f67a6c6013ca | 20 | */ |
wolfSSL | 13:f67a6c6013ca | 21 | |
wolfSSL | 13:f67a6c6013ca | 22 | |
wolfSSL | 13:f67a6c6013ca | 23 | /* Based On Daniel J Bernstein's ed25519 Public Domain ref10 work. */ |
wolfSSL | 13:f67a6c6013ca | 24 | |
wolfSSL | 13:f67a6c6013ca | 25 | #ifndef WOLF_CRYPT_GE_OPERATIONS_H |
wolfSSL | 13:f67a6c6013ca | 26 | #define WOLF_CRYPT_GE_OPERATIONS_H |
wolfSSL | 13:f67a6c6013ca | 27 | |
wolfSSL | 13:f67a6c6013ca | 28 | #include <wolfssl/wolfcrypt/settings.h> |
wolfSSL | 13:f67a6c6013ca | 29 | |
wolfSSL | 13:f67a6c6013ca | 30 | #ifdef HAVE_ED25519 |
wolfSSL | 13:f67a6c6013ca | 31 | |
wolfSSL | 13:f67a6c6013ca | 32 | #include <wolfssl/wolfcrypt/fe_operations.h> |
wolfSSL | 13:f67a6c6013ca | 33 | |
wolfSSL | 13:f67a6c6013ca | 34 | /* |
wolfSSL | 13:f67a6c6013ca | 35 | ge means group element. |
wolfSSL | 13:f67a6c6013ca | 36 | |
wolfSSL | 13:f67a6c6013ca | 37 | Here the group is the set of pairs (x,y) of field elements (see fe.h) |
wolfSSL | 13:f67a6c6013ca | 38 | satisfying -x^2 + y^2 = 1 + d x^2y^2 |
wolfSSL | 13:f67a6c6013ca | 39 | where d = -121665/121666. |
wolfSSL | 13:f67a6c6013ca | 40 | |
wolfSSL | 13:f67a6c6013ca | 41 | Representations: |
wolfSSL | 13:f67a6c6013ca | 42 | ge_p2 (projective): (X:Y:Z) satisfying x=X/Z, y=Y/Z |
wolfSSL | 13:f67a6c6013ca | 43 | ge_p3 (extended): (X:Y:Z:T) satisfying x=X/Z, y=Y/Z, XY=ZT |
wolfSSL | 13:f67a6c6013ca | 44 | ge_p1p1 (completed): ((X:Z),(Y:T)) satisfying x=X/Z, y=Y/T |
wolfSSL | 13:f67a6c6013ca | 45 | ge_precomp (Duif): (y+x,y-x,2dxy) |
wolfSSL | 13:f67a6c6013ca | 46 | */ |
wolfSSL | 13:f67a6c6013ca | 47 | |
wolfSSL | 13:f67a6c6013ca | 48 | #ifdef ED25519_SMALL |
wolfSSL | 13:f67a6c6013ca | 49 | typedef byte ge[F25519_SIZE]; |
wolfSSL | 13:f67a6c6013ca | 50 | #elif defined(CURVED25519_128BIT) |
wolfSSL | 13:f67a6c6013ca | 51 | typedef int64_t ge[5]; |
wolfSSL | 13:f67a6c6013ca | 52 | #else |
wolfSSL | 13:f67a6c6013ca | 53 | typedef int32_t ge[10]; |
wolfSSL | 13:f67a6c6013ca | 54 | #endif |
wolfSSL | 13:f67a6c6013ca | 55 | |
wolfSSL | 13:f67a6c6013ca | 56 | typedef struct { |
wolfSSL | 13:f67a6c6013ca | 57 | ge X; |
wolfSSL | 13:f67a6c6013ca | 58 | ge Y; |
wolfSSL | 13:f67a6c6013ca | 59 | ge Z; |
wolfSSL | 13:f67a6c6013ca | 60 | } ge_p2; |
wolfSSL | 13:f67a6c6013ca | 61 | |
wolfSSL | 13:f67a6c6013ca | 62 | typedef struct { |
wolfSSL | 13:f67a6c6013ca | 63 | ge X; |
wolfSSL | 13:f67a6c6013ca | 64 | ge Y; |
wolfSSL | 13:f67a6c6013ca | 65 | ge Z; |
wolfSSL | 13:f67a6c6013ca | 66 | ge T; |
wolfSSL | 13:f67a6c6013ca | 67 | } ge_p3; |
wolfSSL | 13:f67a6c6013ca | 68 | |
wolfSSL | 13:f67a6c6013ca | 69 | |
wolfSSL | 13:f67a6c6013ca | 70 | WOLFSSL_LOCAL int ge_compress_key(byte* out, const byte* xIn, const byte* yIn, |
wolfSSL | 13:f67a6c6013ca | 71 | word32 keySz); |
wolfSSL | 13:f67a6c6013ca | 72 | WOLFSSL_LOCAL int ge_frombytes_negate_vartime(ge_p3 *,const unsigned char *); |
wolfSSL | 13:f67a6c6013ca | 73 | |
wolfSSL | 13:f67a6c6013ca | 74 | WOLFSSL_LOCAL int ge_double_scalarmult_vartime(ge_p2 *,const unsigned char *, |
wolfSSL | 13:f67a6c6013ca | 75 | const ge_p3 *,const unsigned char *); |
wolfSSL | 13:f67a6c6013ca | 76 | WOLFSSL_LOCAL void ge_scalarmult_base(ge_p3 *,const unsigned char *); |
wolfSSL | 13:f67a6c6013ca | 77 | WOLFSSL_LOCAL void sc_reduce(byte* s); |
wolfSSL | 13:f67a6c6013ca | 78 | WOLFSSL_LOCAL void sc_muladd(byte* s, const byte* a, const byte* b, |
wolfSSL | 13:f67a6c6013ca | 79 | const byte* c); |
wolfSSL | 13:f67a6c6013ca | 80 | WOLFSSL_LOCAL void ge_tobytes(unsigned char *,const ge_p2 *); |
wolfSSL | 13:f67a6c6013ca | 81 | WOLFSSL_LOCAL void ge_p3_tobytes(unsigned char *,const ge_p3 *); |
wolfSSL | 13:f67a6c6013ca | 82 | |
wolfSSL | 13:f67a6c6013ca | 83 | |
wolfSSL | 13:f67a6c6013ca | 84 | #ifndef ED25519_SMALL |
wolfSSL | 13:f67a6c6013ca | 85 | typedef struct { |
wolfSSL | 13:f67a6c6013ca | 86 | ge X; |
wolfSSL | 13:f67a6c6013ca | 87 | ge Y; |
wolfSSL | 13:f67a6c6013ca | 88 | ge Z; |
wolfSSL | 13:f67a6c6013ca | 89 | ge T; |
wolfSSL | 13:f67a6c6013ca | 90 | } ge_p1p1; |
wolfSSL | 13:f67a6c6013ca | 91 | |
wolfSSL | 13:f67a6c6013ca | 92 | typedef struct { |
wolfSSL | 13:f67a6c6013ca | 93 | ge yplusx; |
wolfSSL | 13:f67a6c6013ca | 94 | ge yminusx; |
wolfSSL | 13:f67a6c6013ca | 95 | ge xy2d; |
wolfSSL | 13:f67a6c6013ca | 96 | } ge_precomp; |
wolfSSL | 13:f67a6c6013ca | 97 | |
wolfSSL | 13:f67a6c6013ca | 98 | typedef struct { |
wolfSSL | 13:f67a6c6013ca | 99 | ge YplusX; |
wolfSSL | 13:f67a6c6013ca | 100 | ge YminusX; |
wolfSSL | 13:f67a6c6013ca | 101 | ge Z; |
wolfSSL | 13:f67a6c6013ca | 102 | ge T2d; |
wolfSSL | 13:f67a6c6013ca | 103 | } ge_cached; |
wolfSSL | 13:f67a6c6013ca | 104 | |
wolfSSL | 13:f67a6c6013ca | 105 | WOLFSSL_LOCAL void ge_p2_0(ge_p2 *); |
wolfSSL | 13:f67a6c6013ca | 106 | WOLFSSL_LOCAL void ge_p3_0(ge_p3 *); |
wolfSSL | 13:f67a6c6013ca | 107 | WOLFSSL_LOCAL void ge_precomp_0(ge_precomp *); |
wolfSSL | 13:f67a6c6013ca | 108 | WOLFSSL_LOCAL void ge_p3_to_p2(ge_p2 *,const ge_p3 *); |
wolfSSL | 13:f67a6c6013ca | 109 | WOLFSSL_LOCAL void ge_p3_to_cached(ge_cached *,const ge_p3 *); |
wolfSSL | 13:f67a6c6013ca | 110 | WOLFSSL_LOCAL void ge_p1p1_to_p2(ge_p2 *,const ge_p1p1 *); |
wolfSSL | 13:f67a6c6013ca | 111 | WOLFSSL_LOCAL void ge_p1p1_to_p3(ge_p3 *,const ge_p1p1 *); |
wolfSSL | 13:f67a6c6013ca | 112 | WOLFSSL_LOCAL void ge_p2_dbl(ge_p1p1 *,const ge_p2 *); |
wolfSSL | 13:f67a6c6013ca | 113 | WOLFSSL_LOCAL void ge_p3_dbl(ge_p1p1 *,const ge_p3 *); |
wolfSSL | 13:f67a6c6013ca | 114 | |
wolfSSL | 13:f67a6c6013ca | 115 | WOLFSSL_LOCAL void ge_madd(ge_p1p1 *,const ge_p3 *,const ge_precomp *); |
wolfSSL | 13:f67a6c6013ca | 116 | WOLFSSL_LOCAL void ge_msub(ge_p1p1 *,const ge_p3 *,const ge_precomp *); |
wolfSSL | 13:f67a6c6013ca | 117 | WOLFSSL_LOCAL void ge_add(ge_p1p1 *,const ge_p3 *,const ge_cached *); |
wolfSSL | 13:f67a6c6013ca | 118 | WOLFSSL_LOCAL void ge_sub(ge_p1p1 *,const ge_p3 *,const ge_cached *); |
wolfSSL | 13:f67a6c6013ca | 119 | |
wolfSSL | 13:f67a6c6013ca | 120 | #endif /* !ED25519_SMALL */ |
wolfSSL | 13:f67a6c6013ca | 121 | |
wolfSSL | 13:f67a6c6013ca | 122 | #endif /* HAVE_ED25519 */ |
wolfSSL | 13:f67a6c6013ca | 123 | |
wolfSSL | 13:f67a6c6013ca | 124 | #endif /* WOLF_CRYPT_GE_OPERATIONS_H */ |
wolfSSL | 13:f67a6c6013ca | 125 |