2010-01-14 00:19:10 -07:00
|
|
|
// Copyright 2007,2008 Segher Boessenkool <segher@kernel.crashing.org>
|
2021-07-04 19:54:29 -06:00
|
|
|
// SPDX-License-Identifier: GPL-2.0-or-later
|
2010-01-14 00:19:10 -07:00
|
|
|
|
2021-12-09 19:22:16 -07:00
|
|
|
#include "Common/Crypto/bn.h"
|
|
|
|
|
2023-03-23 09:42:37 -06:00
|
|
|
#include <cstddef>
|
2014-02-17 03:18:15 -07:00
|
|
|
#include <cstdio>
|
2018-05-15 16:27:43 -06:00
|
|
|
#include <cstring>
|
2014-02-17 03:18:15 -07:00
|
|
|
|
2014-09-07 19:06:58 -06:00
|
|
|
#include "Common/CommonTypes.h"
|
2010-01-14 00:19:10 -07:00
|
|
|
|
2023-03-23 09:42:37 -06:00
|
|
|
static void bn_zero(u8* d, const size_t n)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
2018-05-15 16:27:43 -06:00
|
|
|
std::memset(d, 0, n);
|
2010-01-14 00:19:10 -07:00
|
|
|
}
|
|
|
|
|
2023-03-23 09:42:37 -06:00
|
|
|
static void bn_copy(u8* d, const u8* a, const size_t n)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
2018-05-15 16:27:43 -06:00
|
|
|
std::memcpy(d, a, n);
|
2010-01-14 00:19:10 -07:00
|
|
|
}
|
|
|
|
|
2023-03-23 09:42:37 -06:00
|
|
|
int bn_compare(const u8* a, const u8* b, const size_t n)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
2018-05-15 16:27:43 -06:00
|
|
|
return std::memcmp(a, b, n);
|
2010-01-14 00:19:10 -07:00
|
|
|
}
|
|
|
|
|
2023-03-23 09:42:37 -06:00
|
|
|
void bn_sub_modulus(u8* a, const u8* N, const size_t n)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
2018-05-15 16:27:43 -06:00
|
|
|
u8 c = 0;
|
2023-03-23 09:42:37 -06:00
|
|
|
for (size_t i = n; i > 0;)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
2023-03-23 09:42:37 -06:00
|
|
|
--i;
|
2018-05-15 16:27:43 -06:00
|
|
|
u32 dig = N[i] + c;
|
2010-01-14 00:19:10 -07:00
|
|
|
c = (a[i] < dig);
|
|
|
|
a[i] -= dig;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-03-23 09:42:37 -06:00
|
|
|
void bn_add(u8* d, const u8* a, const u8* b, const u8* N, const size_t n)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
2018-05-15 16:27:43 -06:00
|
|
|
u8 c = 0;
|
2023-03-23 09:42:37 -06:00
|
|
|
for (size_t i = n; i > 0;)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
2023-03-23 09:42:37 -06:00
|
|
|
--i;
|
2018-05-15 16:27:43 -06:00
|
|
|
u32 dig = a[i] + b[i] + c;
|
2010-01-14 00:19:10 -07:00
|
|
|
c = (dig >= 0x100);
|
|
|
|
d[i] = dig;
|
|
|
|
}
|
2016-06-24 02:43:46 -06:00
|
|
|
|
2010-01-14 00:19:10 -07:00
|
|
|
if (c)
|
|
|
|
bn_sub_modulus(d, N, n);
|
2016-06-24 02:43:46 -06:00
|
|
|
|
2010-01-14 00:19:10 -07:00
|
|
|
if (bn_compare(d, N, n) >= 0)
|
|
|
|
bn_sub_modulus(d, N, n);
|
|
|
|
}
|
|
|
|
|
2023-03-23 09:42:37 -06:00
|
|
|
void bn_mul(u8* d, const u8* a, const u8* b, const u8* N, const size_t n)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
|
|
|
bn_zero(d, n);
|
2016-06-24 02:43:46 -06:00
|
|
|
|
2023-03-23 09:42:37 -06:00
|
|
|
for (size_t i = 0; i < n; i++)
|
2018-05-15 16:27:43 -06:00
|
|
|
{
|
|
|
|
for (u8 mask = 0x80; mask != 0; mask >>= 1)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
|
|
|
bn_add(d, d, d, N, n);
|
|
|
|
if ((a[i] & mask) != 0)
|
|
|
|
bn_add(d, d, b, N, n);
|
|
|
|
}
|
2018-05-15 16:27:43 -06:00
|
|
|
}
|
2010-01-14 00:19:10 -07:00
|
|
|
}
|
|
|
|
|
2023-03-23 09:42:37 -06:00
|
|
|
void bn_exp(u8* d, const u8* a, const u8* N, const size_t n, const u8* e, const size_t en)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
|
|
|
u8 t[512];
|
2016-06-24 02:43:46 -06:00
|
|
|
|
2010-01-14 00:19:10 -07:00
|
|
|
bn_zero(d, n);
|
|
|
|
d[n - 1] = 1;
|
2023-03-23 09:42:37 -06:00
|
|
|
for (size_t i = 0; i < en; i++)
|
2018-05-15 16:27:43 -06:00
|
|
|
{
|
|
|
|
for (u8 mask = 0x80; mask != 0; mask >>= 1)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
|
|
|
bn_mul(t, d, d, N, n);
|
|
|
|
if ((e[i] & mask) != 0)
|
|
|
|
bn_mul(d, t, a, N, n);
|
|
|
|
else
|
|
|
|
bn_copy(d, t, n);
|
|
|
|
}
|
2018-05-15 16:27:43 -06:00
|
|
|
}
|
2010-01-14 00:19:10 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
// only for prime N -- stupid but lazy, see if I care
|
2023-03-23 09:42:37 -06:00
|
|
|
void bn_inv(u8* d, const u8* a, const u8* N, const size_t n)
|
2010-01-14 00:19:10 -07:00
|
|
|
{
|
|
|
|
u8 t[512], s[512];
|
|
|
|
|
|
|
|
bn_copy(t, N, n);
|
|
|
|
bn_zero(s, n);
|
|
|
|
s[n - 1] = 2;
|
|
|
|
bn_sub_modulus(t, s, n);
|
|
|
|
bn_exp(d, a, N, n, t, n);
|
|
|
|
}
|