1*4882a593Smuzhiyun /*
2*4882a593Smuzhiyun * Elliptic curves over GF(p): curve-specific data and functions
3*4882a593Smuzhiyun *
4*4882a593Smuzhiyun * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
5*4882a593Smuzhiyun * SPDX-License-Identifier: Apache-2.0
6*4882a593Smuzhiyun *
7*4882a593Smuzhiyun * Licensed under the Apache License, Version 2.0 (the "License"); you may
8*4882a593Smuzhiyun * not use this file except in compliance with the License.
9*4882a593Smuzhiyun * You may obtain a copy of the License at
10*4882a593Smuzhiyun *
11*4882a593Smuzhiyun * http://www.apache.org/licenses/LICENSE-2.0
12*4882a593Smuzhiyun *
13*4882a593Smuzhiyun * Unless required by applicable law or agreed to in writing, software
14*4882a593Smuzhiyun * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
15*4882a593Smuzhiyun * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16*4882a593Smuzhiyun * See the License for the specific language governing permissions and
17*4882a593Smuzhiyun * limitations under the License.
18*4882a593Smuzhiyun *
19*4882a593Smuzhiyun * This file is part of mbed TLS (https://tls.mbed.org)
20*4882a593Smuzhiyun */
21*4882a593Smuzhiyun #define MBEDTLS_ECP_C
22*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_C)
23*4882a593Smuzhiyun
24*4882a593Smuzhiyun #include "ecp.h"
25*4882a593Smuzhiyun
26*4882a593Smuzhiyun #include <string.h>
27*4882a593Smuzhiyun
28*4882a593Smuzhiyun #if ( defined(__ARMCC_VERSION) || defined(_MSC_VER) ) && \
29*4882a593Smuzhiyun !defined(inline) && !defined(__cplusplus)
30*4882a593Smuzhiyun #define inline __inline
31*4882a593Smuzhiyun #endif
32*4882a593Smuzhiyun
33*4882a593Smuzhiyun /*
34*4882a593Smuzhiyun * Conversion macros for embedded constants:
35*4882a593Smuzhiyun * build lists of mbedtls_mpi_uint's from lists of unsigned char's grouped by 8, 4 or 2
36*4882a593Smuzhiyun */
37*4882a593Smuzhiyun #if defined(MBEDTLS_HAVE_INT32)
38*4882a593Smuzhiyun
39*4882a593Smuzhiyun #define BYTES_TO_T_UINT_4( a, b, c, d ) \
40*4882a593Smuzhiyun ( (mbedtls_mpi_uint) a << 0 ) | \
41*4882a593Smuzhiyun ( (mbedtls_mpi_uint) b << 8 ) | \
42*4882a593Smuzhiyun ( (mbedtls_mpi_uint) c << 16 ) | \
43*4882a593Smuzhiyun ( (mbedtls_mpi_uint) d << 24 )
44*4882a593Smuzhiyun
45*4882a593Smuzhiyun #define BYTES_TO_T_UINT_2( a, b ) \
46*4882a593Smuzhiyun BYTES_TO_T_UINT_4( a, b, 0, 0 )
47*4882a593Smuzhiyun
48*4882a593Smuzhiyun #define BYTES_TO_T_UINT_8( a, b, c, d, e, f, g, h ) \
49*4882a593Smuzhiyun BYTES_TO_T_UINT_4( a, b, c, d ), \
50*4882a593Smuzhiyun BYTES_TO_T_UINT_4( e, f, g, h )
51*4882a593Smuzhiyun
52*4882a593Smuzhiyun #else /* 64-bits */
53*4882a593Smuzhiyun
54*4882a593Smuzhiyun #define BYTES_TO_T_UINT_8( a, b, c, d, e, f, g, h ) \
55*4882a593Smuzhiyun ( (mbedtls_mpi_uint) a << 0 ) | \
56*4882a593Smuzhiyun ( (mbedtls_mpi_uint) b << 8 ) | \
57*4882a593Smuzhiyun ( (mbedtls_mpi_uint) c << 16 ) | \
58*4882a593Smuzhiyun ( (mbedtls_mpi_uint) d << 24 ) | \
59*4882a593Smuzhiyun ( (mbedtls_mpi_uint) e << 32 ) | \
60*4882a593Smuzhiyun ( (mbedtls_mpi_uint) f << 40 ) | \
61*4882a593Smuzhiyun ( (mbedtls_mpi_uint) g << 48 ) | \
62*4882a593Smuzhiyun ( (mbedtls_mpi_uint) h << 56 )
63*4882a593Smuzhiyun
64*4882a593Smuzhiyun #define BYTES_TO_T_UINT_4( a, b, c, d ) \
65*4882a593Smuzhiyun BYTES_TO_T_UINT_8( a, b, c, d, 0, 0, 0, 0 )
66*4882a593Smuzhiyun
67*4882a593Smuzhiyun #define BYTES_TO_T_UINT_2( a, b ) \
68*4882a593Smuzhiyun BYTES_TO_T_UINT_8( a, b, 0, 0, 0, 0, 0, 0 )
69*4882a593Smuzhiyun
70*4882a593Smuzhiyun #endif /* bits in mbedtls_mpi_uint */
71*4882a593Smuzhiyun
72*4882a593Smuzhiyun /*
73*4882a593Smuzhiyun * Note: the constants are in little-endian order
74*4882a593Smuzhiyun * to be directly usable in MPIs
75*4882a593Smuzhiyun */
76*4882a593Smuzhiyun
77*4882a593Smuzhiyun /*
78*4882a593Smuzhiyun * Domain parameters for secp192r1
79*4882a593Smuzhiyun */
80*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED)
81*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192r1_p[] = {
82*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
83*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFE, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
84*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
85*4882a593Smuzhiyun };
86*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192r1_b[] = {
87*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xB1, 0xB9, 0x46, 0xC1, 0xEC, 0xDE, 0xB8, 0xFE ),
88*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x49, 0x30, 0x24, 0x72, 0xAB, 0xE9, 0xA7, 0x0F ),
89*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xE7, 0x80, 0x9C, 0xE5, 0x19, 0x05, 0x21, 0x64 ),
90*4882a593Smuzhiyun };
91*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192r1_gx[] = {
92*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x12, 0x10, 0xFF, 0x82, 0xFD, 0x0A, 0xFF, 0xF4 ),
93*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x00, 0x88, 0xA1, 0x43, 0xEB, 0x20, 0xBF, 0x7C ),
94*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xF6, 0x90, 0x30, 0xB0, 0x0E, 0xA8, 0x8D, 0x18 ),
95*4882a593Smuzhiyun };
96*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192r1_gy[] = {
97*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x11, 0x48, 0x79, 0x1E, 0xA1, 0x77, 0xF9, 0x73 ),
98*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xD5, 0xCD, 0x24, 0x6B, 0xED, 0x11, 0x10, 0x63 ),
99*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x78, 0xDA, 0xC8, 0xFF, 0x95, 0x2B, 0x19, 0x07 ),
100*4882a593Smuzhiyun };
101*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192r1_n[] = {
102*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x31, 0x28, 0xD2, 0xB4, 0xB1, 0xC9, 0x6B, 0x14 ),
103*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x36, 0xF8, 0xDE, 0x99, 0xFF, 0xFF, 0xFF, 0xFF ),
104*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
105*4882a593Smuzhiyun };
106*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP192R1_ENABLED */
107*4882a593Smuzhiyun
108*4882a593Smuzhiyun /*
109*4882a593Smuzhiyun * Domain parameters for secp224r1
110*4882a593Smuzhiyun */
111*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED)
112*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224r1_p[] = {
113*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 ),
114*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF ),
115*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
116*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x00 ),
117*4882a593Smuzhiyun };
118*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224r1_b[] = {
119*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xB4, 0xFF, 0x55, 0x23, 0x43, 0x39, 0x0B, 0x27 ),
120*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xBA, 0xD8, 0xBF, 0xD7, 0xB7, 0xB0, 0x44, 0x50 ),
121*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x56, 0x32, 0x41, 0xF5, 0xAB, 0xB3, 0x04, 0x0C ),
122*4882a593Smuzhiyun BYTES_TO_T_UINT_4( 0x85, 0x0A, 0x05, 0xB4 ),
123*4882a593Smuzhiyun };
124*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224r1_gx[] = {
125*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x21, 0x1D, 0x5C, 0x11, 0xD6, 0x80, 0x32, 0x34 ),
126*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x22, 0x11, 0xC2, 0x56, 0xD3, 0xC1, 0x03, 0x4A ),
127*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xB9, 0x90, 0x13, 0x32, 0x7F, 0xBF, 0xB4, 0x6B ),
128*4882a593Smuzhiyun BYTES_TO_T_UINT_4( 0xBD, 0x0C, 0x0E, 0xB7 ),
129*4882a593Smuzhiyun };
130*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224r1_gy[] = {
131*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x34, 0x7E, 0x00, 0x85, 0x99, 0x81, 0xD5, 0x44 ),
132*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x64, 0x47, 0x07, 0x5A, 0xA0, 0x75, 0x43, 0xCD ),
133*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xE6, 0xDF, 0x22, 0x4C, 0xFB, 0x23, 0xF7, 0xB5 ),
134*4882a593Smuzhiyun BYTES_TO_T_UINT_4( 0x88, 0x63, 0x37, 0xBD ),
135*4882a593Smuzhiyun };
136*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224r1_n[] = {
137*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x3D, 0x2A, 0x5C, 0x5C, 0x45, 0x29, 0xDD, 0x13 ),
138*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x3E, 0xF0, 0xB8, 0xE0, 0xA2, 0x16, 0xFF, 0xFF ),
139*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
140*4882a593Smuzhiyun BYTES_TO_T_UINT_4( 0xFF, 0xFF, 0xFF, 0xFF ),
141*4882a593Smuzhiyun };
142*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP224R1_ENABLED */
143*4882a593Smuzhiyun
144*4882a593Smuzhiyun /*
145*4882a593Smuzhiyun * Domain parameters for secp256r1
146*4882a593Smuzhiyun */
147*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED)
148*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256r1_p[] = {
149*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
150*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x00 ),
151*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 ),
152*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x01, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF ),
153*4882a593Smuzhiyun };
154*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256r1_b[] = {
155*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x4B, 0x60, 0xD2, 0x27, 0x3E, 0x3C, 0xCE, 0x3B ),
156*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xF6, 0xB0, 0x53, 0xCC, 0xB0, 0x06, 0x1D, 0x65 ),
157*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xBC, 0x86, 0x98, 0x76, 0x55, 0xBD, 0xEB, 0xB3 ),
158*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xE7, 0x93, 0x3A, 0xAA, 0xD8, 0x35, 0xC6, 0x5A ),
159*4882a593Smuzhiyun };
160*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256r1_gx[] = {
161*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x96, 0xC2, 0x98, 0xD8, 0x45, 0x39, 0xA1, 0xF4 ),
162*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA0, 0x33, 0xEB, 0x2D, 0x81, 0x7D, 0x03, 0x77 ),
163*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xF2, 0x40, 0xA4, 0x63, 0xE5, 0xE6, 0xBC, 0xF8 ),
164*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x47, 0x42, 0x2C, 0xE1, 0xF2, 0xD1, 0x17, 0x6B ),
165*4882a593Smuzhiyun };
166*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256r1_gy[] = {
167*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xF5, 0x51, 0xBF, 0x37, 0x68, 0x40, 0xB6, 0xCB ),
168*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xCE, 0x5E, 0x31, 0x6B, 0x57, 0x33, 0xCE, 0x2B ),
169*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x16, 0x9E, 0x0F, 0x7C, 0x4A, 0xEB, 0xE7, 0x8E ),
170*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x9B, 0x7F, 0x1A, 0xFE, 0xE2, 0x42, 0xE3, 0x4F ),
171*4882a593Smuzhiyun };
172*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256r1_n[] = {
173*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x51, 0x25, 0x63, 0xFC, 0xC2, 0xCA, 0xB9, 0xF3 ),
174*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x84, 0x9E, 0x17, 0xA7, 0xAD, 0xFA, 0xE6, 0xBC ),
175*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
176*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF ),
177*4882a593Smuzhiyun };
178*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP256R1_ENABLED */
179*4882a593Smuzhiyun
180*4882a593Smuzhiyun /*
181*4882a593Smuzhiyun * Domain parameters for secp384r1
182*4882a593Smuzhiyun */
183*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED)
184*4882a593Smuzhiyun static const mbedtls_mpi_uint secp384r1_p[] = {
185*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x00 ),
186*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x00, 0x00, 0x00, 0x00, 0xFF, 0xFF, 0xFF, 0xFF ),
187*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFE, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
188*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
189*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
190*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
191*4882a593Smuzhiyun };
192*4882a593Smuzhiyun static const mbedtls_mpi_uint secp384r1_b[] = {
193*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xEF, 0x2A, 0xEC, 0xD3, 0xED, 0xC8, 0x85, 0x2A ),
194*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x9D, 0xD1, 0x2E, 0x8A, 0x8D, 0x39, 0x56, 0xC6 ),
195*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x5A, 0x87, 0x13, 0x50, 0x8F, 0x08, 0x14, 0x03 ),
196*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x12, 0x41, 0x81, 0xFE, 0x6E, 0x9C, 0x1D, 0x18 ),
197*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x19, 0x2D, 0xF8, 0xE3, 0x6B, 0x05, 0x8E, 0x98 ),
198*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xE4, 0xE7, 0x3E, 0xE2, 0xA7, 0x2F, 0x31, 0xB3 ),
199*4882a593Smuzhiyun };
200*4882a593Smuzhiyun static const mbedtls_mpi_uint secp384r1_gx[] = {
201*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xB7, 0x0A, 0x76, 0x72, 0x38, 0x5E, 0x54, 0x3A ),
202*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x6C, 0x29, 0x55, 0xBF, 0x5D, 0xF2, 0x02, 0x55 ),
203*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x38, 0x2A, 0x54, 0x82, 0xE0, 0x41, 0xF7, 0x59 ),
204*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x98, 0x9B, 0xA7, 0x8B, 0x62, 0x3B, 0x1D, 0x6E ),
205*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x74, 0xAD, 0x20, 0xF3, 0x1E, 0xC7, 0xB1, 0x8E ),
206*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x37, 0x05, 0x8B, 0xBE, 0x22, 0xCA, 0x87, 0xAA ),
207*4882a593Smuzhiyun };
208*4882a593Smuzhiyun static const mbedtls_mpi_uint secp384r1_gy[] = {
209*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x5F, 0x0E, 0xEA, 0x90, 0x7C, 0x1D, 0x43, 0x7A ),
210*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x9D, 0x81, 0x7E, 0x1D, 0xCE, 0xB1, 0x60, 0x0A ),
211*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xC0, 0xB8, 0xF0, 0xB5, 0x13, 0x31, 0xDA, 0xE9 ),
212*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x7C, 0x14, 0x9A, 0x28, 0xBD, 0x1D, 0xF4, 0xF8 ),
213*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x29, 0xDC, 0x92, 0x92, 0xBF, 0x98, 0x9E, 0x5D ),
214*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x6F, 0x2C, 0x26, 0x96, 0x4A, 0xDE, 0x17, 0x36 ),
215*4882a593Smuzhiyun };
216*4882a593Smuzhiyun static const mbedtls_mpi_uint secp384r1_n[] = {
217*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x73, 0x29, 0xC5, 0xCC, 0x6A, 0x19, 0xEC, 0xEC ),
218*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x7A, 0xA7, 0xB0, 0x48, 0xB2, 0x0D, 0x1A, 0x58 ),
219*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xDF, 0x2D, 0x37, 0xF4, 0x81, 0x4D, 0x63, 0xC7 ),
220*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
221*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
222*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
223*4882a593Smuzhiyun };
224*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP384R1_ENABLED */
225*4882a593Smuzhiyun
226*4882a593Smuzhiyun /*
227*4882a593Smuzhiyun * Domain parameters for secp521r1
228*4882a593Smuzhiyun */
229*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED)
230*4882a593Smuzhiyun static const mbedtls_mpi_uint secp521r1_p[] = {
231*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
232*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
233*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
234*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
235*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
236*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
237*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
238*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
239*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0xFF, 0x01 ),
240*4882a593Smuzhiyun };
241*4882a593Smuzhiyun static const mbedtls_mpi_uint secp521r1_b[] = {
242*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x00, 0x3F, 0x50, 0x6B, 0xD4, 0x1F, 0x45, 0xEF ),
243*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xF1, 0x34, 0x2C, 0x3D, 0x88, 0xDF, 0x73, 0x35 ),
244*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x07, 0xBF, 0xB1, 0x3B, 0xBD, 0xC0, 0x52, 0x16 ),
245*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x7B, 0x93, 0x7E, 0xEC, 0x51, 0x39, 0x19, 0x56 ),
246*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xE1, 0x09, 0xF1, 0x8E, 0x91, 0x89, 0xB4, 0xB8 ),
247*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xF3, 0x15, 0xB3, 0x99, 0x5B, 0x72, 0xDA, 0xA2 ),
248*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xEE, 0x40, 0x85, 0xB6, 0xA0, 0x21, 0x9A, 0x92 ),
249*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x1F, 0x9A, 0x1C, 0x8E, 0x61, 0xB9, 0x3E, 0x95 ),
250*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0x51, 0x00 ),
251*4882a593Smuzhiyun };
252*4882a593Smuzhiyun static const mbedtls_mpi_uint secp521r1_gx[] = {
253*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x66, 0xBD, 0xE5, 0xC2, 0x31, 0x7E, 0x7E, 0xF9 ),
254*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x9B, 0x42, 0x6A, 0x85, 0xC1, 0xB3, 0x48, 0x33 ),
255*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xDE, 0xA8, 0xFF, 0xA2, 0x27, 0xC1, 0x1D, 0xFE ),
256*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x28, 0x59, 0xE7, 0xEF, 0x77, 0x5E, 0x4B, 0xA1 ),
257*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xBA, 0x3D, 0x4D, 0x6B, 0x60, 0xAF, 0x28, 0xF8 ),
258*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x21, 0xB5, 0x3F, 0x05, 0x39, 0x81, 0x64, 0x9C ),
259*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x42, 0xB4, 0x95, 0x23, 0x66, 0xCB, 0x3E, 0x9E ),
260*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xCD, 0xE9, 0x04, 0x04, 0xB7, 0x06, 0x8E, 0x85 ),
261*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0xC6, 0x00 ),
262*4882a593Smuzhiyun };
263*4882a593Smuzhiyun static const mbedtls_mpi_uint secp521r1_gy[] = {
264*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x50, 0x66, 0xD1, 0x9F, 0x76, 0x94, 0xBE, 0x88 ),
265*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x40, 0xC2, 0x72, 0xA2, 0x86, 0x70, 0x3C, 0x35 ),
266*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x61, 0x07, 0xAD, 0x3F, 0x01, 0xB9, 0x50, 0xC5 ),
267*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x40, 0x26, 0xF4, 0x5E, 0x99, 0x72, 0xEE, 0x97 ),
268*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x2C, 0x66, 0x3E, 0x27, 0x17, 0xBD, 0xAF, 0x17 ),
269*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x68, 0x44, 0x9B, 0x57, 0x49, 0x44, 0xF5, 0x98 ),
270*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xD9, 0x1B, 0x7D, 0x2C, 0xB4, 0x5F, 0x8A, 0x5C ),
271*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x04, 0xC0, 0x3B, 0x9A, 0x78, 0x6A, 0x29, 0x39 ),
272*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0x18, 0x01 ),
273*4882a593Smuzhiyun };
274*4882a593Smuzhiyun static const mbedtls_mpi_uint secp521r1_n[] = {
275*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x09, 0x64, 0x38, 0x91, 0x1E, 0xB7, 0x6F, 0xBB ),
276*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xAE, 0x47, 0x9C, 0x89, 0xB8, 0xC9, 0xB5, 0x3B ),
277*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xD0, 0xA5, 0x09, 0xF7, 0x48, 0x01, 0xCC, 0x7F ),
278*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x6B, 0x96, 0x2F, 0xBF, 0x83, 0x87, 0x86, 0x51 ),
279*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFA, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
280*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
281*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
282*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
283*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0xFF, 0x01 ),
284*4882a593Smuzhiyun };
285*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP521R1_ENABLED */
286*4882a593Smuzhiyun
287*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED)
288*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192k1_p[] = {
289*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x37, 0xEE, 0xFF, 0xFF, 0xFE, 0xFF, 0xFF, 0xFF ),
290*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
291*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
292*4882a593Smuzhiyun };
293*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192k1_a[] = {
294*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0x00, 0x00 ),
295*4882a593Smuzhiyun };
296*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192k1_b[] = {
297*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0x03, 0x00 ),
298*4882a593Smuzhiyun };
299*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192k1_gx[] = {
300*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x7D, 0x6C, 0xE0, 0xEA, 0xB1, 0xD1, 0xA5, 0x1D ),
301*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x34, 0xF4, 0xB7, 0x80, 0x02, 0x7D, 0xB0, 0x26 ),
302*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xAE, 0xE9, 0x57, 0xC0, 0x0E, 0xF1, 0x4F, 0xDB ),
303*4882a593Smuzhiyun };
304*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192k1_gy[] = {
305*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x9D, 0x2F, 0x5E, 0xD9, 0x88, 0xAA, 0x82, 0x40 ),
306*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x34, 0x86, 0xBE, 0x15, 0xD0, 0x63, 0x41, 0x84 ),
307*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA7, 0x28, 0x56, 0x9C, 0x6D, 0x2F, 0x2F, 0x9B ),
308*4882a593Smuzhiyun };
309*4882a593Smuzhiyun static const mbedtls_mpi_uint secp192k1_n[] = {
310*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x8D, 0xFD, 0xDE, 0x74, 0x6A, 0x46, 0x69, 0x0F ),
311*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x17, 0xFC, 0xF2, 0x26, 0xFE, 0xFF, 0xFF, 0xFF ),
312*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
313*4882a593Smuzhiyun };
314*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP192K1_ENABLED */
315*4882a593Smuzhiyun
316*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED)
317*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224k1_p[] = {
318*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x6D, 0xE5, 0xFF, 0xFF, 0xFE, 0xFF, 0xFF, 0xFF ),
319*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
320*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
321*4882a593Smuzhiyun BYTES_TO_T_UINT_4( 0xFF, 0xFF, 0xFF, 0xFF ),
322*4882a593Smuzhiyun };
323*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224k1_a[] = {
324*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0x00, 0x00 ),
325*4882a593Smuzhiyun };
326*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224k1_b[] = {
327*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0x05, 0x00 ),
328*4882a593Smuzhiyun };
329*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224k1_gx[] = {
330*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x5C, 0xA4, 0xB7, 0xB6, 0x0E, 0x65, 0x7E, 0x0F ),
331*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA9, 0x75, 0x70, 0xE4, 0xE9, 0x67, 0xA4, 0x69 ),
332*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA1, 0x28, 0xFC, 0x30, 0xDF, 0x99, 0xF0, 0x4D ),
333*4882a593Smuzhiyun BYTES_TO_T_UINT_4( 0x33, 0x5B, 0x45, 0xA1 ),
334*4882a593Smuzhiyun };
335*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224k1_gy[] = {
336*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA5, 0x61, 0x6D, 0x55, 0xDB, 0x4B, 0xCA, 0xE2 ),
337*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x59, 0xBD, 0xB0, 0xC0, 0xF7, 0x19, 0xE3, 0xF7 ),
338*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xD6, 0xFB, 0xCA, 0x82, 0x42, 0x34, 0xBA, 0x7F ),
339*4882a593Smuzhiyun BYTES_TO_T_UINT_4( 0xED, 0x9F, 0x08, 0x7E ),
340*4882a593Smuzhiyun };
341*4882a593Smuzhiyun static const mbedtls_mpi_uint secp224k1_n[] = {
342*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xF7, 0xB1, 0x9F, 0x76, 0x71, 0xA9, 0xF0, 0xCA ),
343*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x84, 0x61, 0xEC, 0xD2, 0xE8, 0xDC, 0x01, 0x00 ),
344*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 ),
345*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x00, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00 ),
346*4882a593Smuzhiyun };
347*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP224K1_ENABLED */
348*4882a593Smuzhiyun
349*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED)
350*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256k1_p[] = {
351*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x2F, 0xFC, 0xFF, 0xFF, 0xFE, 0xFF, 0xFF, 0xFF ),
352*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
353*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
354*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
355*4882a593Smuzhiyun };
356*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256k1_a[] = {
357*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0x00, 0x00 ),
358*4882a593Smuzhiyun };
359*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256k1_b[] = {
360*4882a593Smuzhiyun BYTES_TO_T_UINT_2( 0x07, 0x00 ),
361*4882a593Smuzhiyun };
362*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256k1_gx[] = {
363*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x98, 0x17, 0xF8, 0x16, 0x5B, 0x81, 0xF2, 0x59 ),
364*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xD9, 0x28, 0xCE, 0x2D, 0xDB, 0xFC, 0x9B, 0x02 ),
365*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x07, 0x0B, 0x87, 0xCE, 0x95, 0x62, 0xA0, 0x55 ),
366*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xAC, 0xBB, 0xDC, 0xF9, 0x7E, 0x66, 0xBE, 0x79 ),
367*4882a593Smuzhiyun };
368*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256k1_gy[] = {
369*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xB8, 0xD4, 0x10, 0xFB, 0x8F, 0xD0, 0x47, 0x9C ),
370*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x19, 0x54, 0x85, 0xA6, 0x48, 0xB4, 0x17, 0xFD ),
371*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA8, 0x08, 0x11, 0x0E, 0xFC, 0xFB, 0xA4, 0x5D ),
372*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x65, 0xC4, 0xA3, 0x26, 0x77, 0xDA, 0x3A, 0x48 ),
373*4882a593Smuzhiyun };
374*4882a593Smuzhiyun static const mbedtls_mpi_uint secp256k1_n[] = {
375*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x41, 0x41, 0x36, 0xD0, 0x8C, 0x5E, 0xD2, 0xBF ),
376*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x3B, 0xA0, 0x48, 0xAF, 0xE6, 0xDC, 0xAE, 0xBA ),
377*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFE, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
378*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF ),
379*4882a593Smuzhiyun };
380*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP256K1_ENABLED */
381*4882a593Smuzhiyun
382*4882a593Smuzhiyun /*
383*4882a593Smuzhiyun * Domain parameters for brainpoolP256r1 (RFC 5639 3.4)
384*4882a593Smuzhiyun */
385*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_BP256R1_ENABLED)
386*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP256r1_p[] = {
387*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x77, 0x53, 0x6E, 0x1F, 0x1D, 0x48, 0x13, 0x20 ),
388*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x28, 0x20, 0x26, 0xD5, 0x23, 0xF6, 0x3B, 0x6E ),
389*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x72, 0x8D, 0x83, 0x9D, 0x90, 0x0A, 0x66, 0x3E ),
390*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xBC, 0xA9, 0xEE, 0xA1, 0xDB, 0x57, 0xFB, 0xA9 ),
391*4882a593Smuzhiyun };
392*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP256r1_a[] = {
393*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xD9, 0xB5, 0x30, 0xF3, 0x44, 0x4B, 0x4A, 0xE9 ),
394*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x6C, 0x5C, 0xDC, 0x26, 0xC1, 0x55, 0x80, 0xFB ),
395*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xE7, 0xFF, 0x7A, 0x41, 0x30, 0x75, 0xF6, 0xEE ),
396*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x57, 0x30, 0x2C, 0xFC, 0x75, 0x09, 0x5A, 0x7D ),
397*4882a593Smuzhiyun };
398*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP256r1_b[] = {
399*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xB6, 0x07, 0x8C, 0xFF, 0x18, 0xDC, 0xCC, 0x6B ),
400*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xCE, 0xE1, 0xF7, 0x5C, 0x29, 0x16, 0x84, 0x95 ),
401*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xBF, 0x7C, 0xD7, 0xBB, 0xD9, 0xB5, 0x30, 0xF3 ),
402*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x44, 0x4B, 0x4A, 0xE9, 0x6C, 0x5C, 0xDC, 0x26 ),
403*4882a593Smuzhiyun };
404*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP256r1_gx[] = {
405*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x62, 0x32, 0xCE, 0x9A, 0xBD, 0x53, 0x44, 0x3A ),
406*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xC2, 0x23, 0xBD, 0xE3, 0xE1, 0x27, 0xDE, 0xB9 ),
407*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xAF, 0xB7, 0x81, 0xFC, 0x2F, 0x48, 0x4B, 0x2C ),
408*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xCB, 0x57, 0x7E, 0xCB, 0xB9, 0xAE, 0xD2, 0x8B ),
409*4882a593Smuzhiyun };
410*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP256r1_gy[] = {
411*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x97, 0x69, 0x04, 0x2F, 0xC7, 0x54, 0x1D, 0x5C ),
412*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x54, 0x8E, 0xED, 0x2D, 0x13, 0x45, 0x77, 0xC2 ),
413*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xC9, 0x1D, 0x61, 0x14, 0x1A, 0x46, 0xF8, 0x97 ),
414*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFD, 0xC4, 0xDA, 0xC3, 0x35, 0xF8, 0x7E, 0x54 ),
415*4882a593Smuzhiyun };
416*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP256r1_n[] = {
417*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA7, 0x56, 0x48, 0x97, 0x82, 0x0E, 0x1E, 0x90 ),
418*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xF7, 0xA6, 0x61, 0xB5, 0xA3, 0x7A, 0x39, 0x8C ),
419*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x71, 0x8D, 0x83, 0x9D, 0x90, 0x0A, 0x66, 0x3E ),
420*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xBC, 0xA9, 0xEE, 0xA1, 0xDB, 0x57, 0xFB, 0xA9 ),
421*4882a593Smuzhiyun };
422*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_BP256R1_ENABLED */
423*4882a593Smuzhiyun
424*4882a593Smuzhiyun /*
425*4882a593Smuzhiyun * Domain parameters for brainpoolP384r1 (RFC 5639 3.6)
426*4882a593Smuzhiyun */
427*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_BP384R1_ENABLED)
428*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP384r1_p[] = {
429*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x53, 0xEC, 0x07, 0x31, 0x13, 0x00, 0x47, 0x87 ),
430*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x71, 0x1A, 0x1D, 0x90, 0x29, 0xA7, 0xD3, 0xAC ),
431*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x23, 0x11, 0xB7, 0x7F, 0x19, 0xDA, 0xB1, 0x12 ),
432*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xB4, 0x56, 0x54, 0xED, 0x09, 0x71, 0x2F, 0x15 ),
433*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xDF, 0x41, 0xE6, 0x50, 0x7E, 0x6F, 0x5D, 0x0F ),
434*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x28, 0x6D, 0x38, 0xA3, 0x82, 0x1E, 0xB9, 0x8C ),
435*4882a593Smuzhiyun };
436*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP384r1_a[] = {
437*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x26, 0x28, 0xCE, 0x22, 0xDD, 0xC7, 0xA8, 0x04 ),
438*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xEB, 0xD4, 0x3A, 0x50, 0x4A, 0x81, 0xA5, 0x8A ),
439*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x0F, 0xF9, 0x91, 0xBA, 0xEF, 0x65, 0x91, 0x13 ),
440*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x87, 0x27, 0xB2, 0x4F, 0x8E, 0xA2, 0xBE, 0xC2 ),
441*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA0, 0xAF, 0x05, 0xCE, 0x0A, 0x08, 0x72, 0x3C ),
442*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x0C, 0x15, 0x8C, 0x3D, 0xC6, 0x82, 0xC3, 0x7B ),
443*4882a593Smuzhiyun };
444*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP384r1_b[] = {
445*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x11, 0x4C, 0x50, 0xFA, 0x96, 0x86, 0xB7, 0x3A ),
446*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x94, 0xC9, 0xDB, 0x95, 0x02, 0x39, 0xB4, 0x7C ),
447*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xD5, 0x62, 0xEB, 0x3E, 0xA5, 0x0E, 0x88, 0x2E ),
448*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA6, 0xD2, 0xDC, 0x07, 0xE1, 0x7D, 0xB7, 0x2F ),
449*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x7C, 0x44, 0xF0, 0x16, 0x54, 0xB5, 0x39, 0x8B ),
450*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x26, 0x28, 0xCE, 0x22, 0xDD, 0xC7, 0xA8, 0x04 ),
451*4882a593Smuzhiyun };
452*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP384r1_gx[] = {
453*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x1E, 0xAF, 0xD4, 0x47, 0xE2, 0xB2, 0x87, 0xEF ),
454*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xAA, 0x46, 0xD6, 0x36, 0x34, 0xE0, 0x26, 0xE8 ),
455*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xE8, 0x10, 0xBD, 0x0C, 0xFE, 0xCA, 0x7F, 0xDB ),
456*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xE3, 0x4F, 0xF1, 0x7E, 0xE7, 0xA3, 0x47, 0x88 ),
457*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x6B, 0x3F, 0xC1, 0xB7, 0x81, 0x3A, 0xA6, 0xA2 ),
458*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFF, 0x45, 0xCF, 0x68, 0xF0, 0x64, 0x1C, 0x1D ),
459*4882a593Smuzhiyun };
460*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP384r1_gy[] = {
461*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x15, 0x53, 0x3C, 0x26, 0x41, 0x03, 0x82, 0x42 ),
462*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x11, 0x81, 0x91, 0x77, 0x21, 0x46, 0x46, 0x0E ),
463*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x28, 0x29, 0x91, 0xF9, 0x4F, 0x05, 0x9C, 0xE1 ),
464*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x64, 0x58, 0xEC, 0xFE, 0x29, 0x0B, 0xB7, 0x62 ),
465*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x52, 0xD5, 0xCF, 0x95, 0x8E, 0xEB, 0xB1, 0x5C ),
466*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA4, 0xC2, 0xF9, 0x20, 0x75, 0x1D, 0xBE, 0x8A ),
467*4882a593Smuzhiyun };
468*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP384r1_n[] = {
469*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x65, 0x65, 0x04, 0xE9, 0x02, 0x32, 0x88, 0x3B ),
470*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x10, 0xC3, 0x7F, 0x6B, 0xAF, 0xB6, 0x3A, 0xCF ),
471*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA7, 0x25, 0x04, 0xAC, 0x6C, 0x6E, 0x16, 0x1F ),
472*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xB3, 0x56, 0x54, 0xED, 0x09, 0x71, 0x2F, 0x15 ),
473*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xDF, 0x41, 0xE6, 0x50, 0x7E, 0x6F, 0x5D, 0x0F ),
474*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x28, 0x6D, 0x38, 0xA3, 0x82, 0x1E, 0xB9, 0x8C ),
475*4882a593Smuzhiyun };
476*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_BP384R1_ENABLED */
477*4882a593Smuzhiyun
478*4882a593Smuzhiyun /*
479*4882a593Smuzhiyun * Domain parameters for brainpoolP512r1 (RFC 5639 3.7)
480*4882a593Smuzhiyun */
481*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_BP512R1_ENABLED)
482*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP512r1_p[] = {
483*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xF3, 0x48, 0x3A, 0x58, 0x56, 0x60, 0xAA, 0x28 ),
484*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x85, 0xC6, 0x82, 0x2D, 0x2F, 0xFF, 0x81, 0x28 ),
485*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xE6, 0x80, 0xA3, 0xE6, 0x2A, 0xA1, 0xCD, 0xAE ),
486*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x42, 0x68, 0xC6, 0x9B, 0x00, 0x9B, 0x4D, 0x7D ),
487*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x71, 0x08, 0x33, 0x70, 0xCA, 0x9C, 0x63, 0xD6 ),
488*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x0E, 0xD2, 0xC9, 0xB3, 0xB3, 0x8D, 0x30, 0xCB ),
489*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x07, 0xFC, 0xC9, 0x33, 0xAE, 0xE6, 0xD4, 0x3F ),
490*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x8B, 0xC4, 0xE9, 0xDB, 0xB8, 0x9D, 0xDD, 0xAA ),
491*4882a593Smuzhiyun };
492*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP512r1_a[] = {
493*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xCA, 0x94, 0xFC, 0x77, 0x4D, 0xAC, 0xC1, 0xE7 ),
494*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xB9, 0xC7, 0xF2, 0x2B, 0xA7, 0x17, 0x11, 0x7F ),
495*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xB5, 0xC8, 0x9A, 0x8B, 0xC9, 0xF1, 0x2E, 0x0A ),
496*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA1, 0x3A, 0x25, 0xA8, 0x5A, 0x5D, 0xED, 0x2D ),
497*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xBC, 0x63, 0x98, 0xEA, 0xCA, 0x41, 0x34, 0xA8 ),
498*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x10, 0x16, 0xF9, 0x3D, 0x8D, 0xDD, 0xCB, 0x94 ),
499*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xC5, 0x4C, 0x23, 0xAC, 0x45, 0x71, 0x32, 0xE2 ),
500*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x89, 0x3B, 0x60, 0x8B, 0x31, 0xA3, 0x30, 0x78 ),
501*4882a593Smuzhiyun };
502*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP512r1_b[] = {
503*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x23, 0xF7, 0x16, 0x80, 0x63, 0xBD, 0x09, 0x28 ),
504*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xDD, 0xE5, 0xBA, 0x5E, 0xB7, 0x50, 0x40, 0x98 ),
505*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x67, 0x3E, 0x08, 0xDC, 0xCA, 0x94, 0xFC, 0x77 ),
506*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x4D, 0xAC, 0xC1, 0xE7, 0xB9, 0xC7, 0xF2, 0x2B ),
507*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xA7, 0x17, 0x11, 0x7F, 0xB5, 0xC8, 0x9A, 0x8B ),
508*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xC9, 0xF1, 0x2E, 0x0A, 0xA1, 0x3A, 0x25, 0xA8 ),
509*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x5A, 0x5D, 0xED, 0x2D, 0xBC, 0x63, 0x98, 0xEA ),
510*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xCA, 0x41, 0x34, 0xA8, 0x10, 0x16, 0xF9, 0x3D ),
511*4882a593Smuzhiyun };
512*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP512r1_gx[] = {
513*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x22, 0xF8, 0xB9, 0xBC, 0x09, 0x22, 0x35, 0x8B ),
514*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x68, 0x5E, 0x6A, 0x40, 0x47, 0x50, 0x6D, 0x7C ),
515*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x5F, 0x7D, 0xB9, 0x93, 0x7B, 0x68, 0xD1, 0x50 ),
516*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x8D, 0xD4, 0xD0, 0xE2, 0x78, 0x1F, 0x3B, 0xFF ),
517*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x8E, 0x09, 0xD0, 0xF4, 0xEE, 0x62, 0x3B, 0xB4 ),
518*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xC1, 0x16, 0xD9, 0xB5, 0x70, 0x9F, 0xED, 0x85 ),
519*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x93, 0x6A, 0x4C, 0x9C, 0x2E, 0x32, 0x21, 0x5A ),
520*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x64, 0xD9, 0x2E, 0xD8, 0xBD, 0xE4, 0xAE, 0x81 ),
521*4882a593Smuzhiyun };
522*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP512r1_gy[] = {
523*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x92, 0x08, 0xD8, 0x3A, 0x0F, 0x1E, 0xCD, 0x78 ),
524*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x06, 0x54, 0xF0, 0xA8, 0x2F, 0x2B, 0xCA, 0xD1 ),
525*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xAE, 0x63, 0x27, 0x8A, 0xD8, 0x4B, 0xCA, 0x5B ),
526*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x5E, 0x48, 0x5F, 0x4A, 0x49, 0xDE, 0xDC, 0xB2 ),
527*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x11, 0x81, 0x1F, 0x88, 0x5B, 0xC5, 0x00, 0xA0 ),
528*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x1A, 0x7B, 0xA5, 0x24, 0x00, 0xF7, 0x09, 0xF2 ),
529*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xFD, 0x22, 0x78, 0xCF, 0xA9, 0xBF, 0xEA, 0xC0 ),
530*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xEC, 0x32, 0x63, 0x56, 0x5D, 0x38, 0xDE, 0x7D ),
531*4882a593Smuzhiyun };
532*4882a593Smuzhiyun static const mbedtls_mpi_uint brainpoolP512r1_n[] = {
533*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x69, 0x00, 0xA9, 0x9C, 0x82, 0x96, 0x87, 0xB5 ),
534*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xDD, 0xDA, 0x5D, 0x08, 0x81, 0xD3, 0xB1, 0x1D ),
535*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x47, 0x10, 0xAC, 0x7F, 0x19, 0x61, 0x86, 0x41 ),
536*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x19, 0x26, 0xA9, 0x4C, 0x41, 0x5C, 0x3E, 0x55 ),
537*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x70, 0x08, 0x33, 0x70, 0xCA, 0x9C, 0x63, 0xD6 ),
538*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x0E, 0xD2, 0xC9, 0xB3, 0xB3, 0x8D, 0x30, 0xCB ),
539*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x07, 0xFC, 0xC9, 0x33, 0xAE, 0xE6, 0xD4, 0x3F ),
540*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x8B, 0xC4, 0xE9, 0xDB, 0xB8, 0x9D, 0xDD, 0xAA ),
541*4882a593Smuzhiyun };
542*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_BP512R1_ENABLED */
543*4882a593Smuzhiyun
544*4882a593Smuzhiyun /*
545*4882a593Smuzhiyun * Create an MPI from embedded constants
546*4882a593Smuzhiyun * (assumes len is an exact multiple of sizeof mbedtls_mpi_uint)
547*4882a593Smuzhiyun */
ecp_mpi_load(mbedtls_mpi * X,const mbedtls_mpi_uint * p,size_t len)548*4882a593Smuzhiyun static inline void ecp_mpi_load( mbedtls_mpi *X, const mbedtls_mpi_uint *p, size_t len )
549*4882a593Smuzhiyun {
550*4882a593Smuzhiyun X->s = 1;
551*4882a593Smuzhiyun X->n = len / sizeof( mbedtls_mpi_uint );
552*4882a593Smuzhiyun X->p = (mbedtls_mpi_uint *) p;
553*4882a593Smuzhiyun }
554*4882a593Smuzhiyun
555*4882a593Smuzhiyun /*
556*4882a593Smuzhiyun * Set an MPI to static value 1
557*4882a593Smuzhiyun */
ecp_mpi_set1(mbedtls_mpi * X)558*4882a593Smuzhiyun static inline void ecp_mpi_set1( mbedtls_mpi *X )
559*4882a593Smuzhiyun {
560*4882a593Smuzhiyun static mbedtls_mpi_uint one[] = { 1 };
561*4882a593Smuzhiyun X->s = 1;
562*4882a593Smuzhiyun X->n = 1;
563*4882a593Smuzhiyun X->p = one;
564*4882a593Smuzhiyun }
565*4882a593Smuzhiyun
566*4882a593Smuzhiyun /*
567*4882a593Smuzhiyun * Make group available from embedded constants
568*4882a593Smuzhiyun */
ecp_group_load(mbedtls_ecp_group * grp,const mbedtls_mpi_uint * p,size_t plen,const mbedtls_mpi_uint * a,size_t alen,const mbedtls_mpi_uint * b,size_t blen,const mbedtls_mpi_uint * gx,size_t gxlen,const mbedtls_mpi_uint * gy,size_t gylen,const mbedtls_mpi_uint * n,size_t nlen)569*4882a593Smuzhiyun static int ecp_group_load( mbedtls_ecp_group *grp,
570*4882a593Smuzhiyun const mbedtls_mpi_uint *p, size_t plen,
571*4882a593Smuzhiyun const mbedtls_mpi_uint *a, size_t alen,
572*4882a593Smuzhiyun const mbedtls_mpi_uint *b, size_t blen,
573*4882a593Smuzhiyun const mbedtls_mpi_uint *gx, size_t gxlen,
574*4882a593Smuzhiyun const mbedtls_mpi_uint *gy, size_t gylen,
575*4882a593Smuzhiyun const mbedtls_mpi_uint *n, size_t nlen)
576*4882a593Smuzhiyun {
577*4882a593Smuzhiyun ecp_mpi_load( &grp->P, p, plen );
578*4882a593Smuzhiyun if( a != NULL )
579*4882a593Smuzhiyun ecp_mpi_load( &grp->A, a, alen );
580*4882a593Smuzhiyun ecp_mpi_load( &grp->B, b, blen );
581*4882a593Smuzhiyun ecp_mpi_load( &grp->N, n, nlen );
582*4882a593Smuzhiyun
583*4882a593Smuzhiyun ecp_mpi_load( &grp->G.X, gx, gxlen );
584*4882a593Smuzhiyun ecp_mpi_load( &grp->G.Y, gy, gylen );
585*4882a593Smuzhiyun ecp_mpi_set1( &grp->G.Z );
586*4882a593Smuzhiyun
587*4882a593Smuzhiyun grp->pbits = mbedtls_mpi_bitlen( &grp->P );
588*4882a593Smuzhiyun grp->nbits = mbedtls_mpi_bitlen( &grp->N );
589*4882a593Smuzhiyun
590*4882a593Smuzhiyun grp->h = 1;
591*4882a593Smuzhiyun
592*4882a593Smuzhiyun return( 0 );
593*4882a593Smuzhiyun }
594*4882a593Smuzhiyun
595*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_NIST_OPTIM)
596*4882a593Smuzhiyun /* Forward declarations */
597*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED)
598*4882a593Smuzhiyun static int ecp_mod_p192( mbedtls_mpi * );
599*4882a593Smuzhiyun #endif
600*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED)
601*4882a593Smuzhiyun static int ecp_mod_p224( mbedtls_mpi * );
602*4882a593Smuzhiyun #endif
603*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED)
604*4882a593Smuzhiyun static int ecp_mod_p256( mbedtls_mpi * );
605*4882a593Smuzhiyun #endif
606*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED)
607*4882a593Smuzhiyun static int ecp_mod_p384( mbedtls_mpi * );
608*4882a593Smuzhiyun #endif
609*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED)
610*4882a593Smuzhiyun static int ecp_mod_p521( mbedtls_mpi * );
611*4882a593Smuzhiyun #endif
612*4882a593Smuzhiyun
613*4882a593Smuzhiyun #define NIST_MODP( P ) grp->modp = ecp_mod_ ## P;
614*4882a593Smuzhiyun #else
615*4882a593Smuzhiyun #define NIST_MODP( P )
616*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_NIST_OPTIM */
617*4882a593Smuzhiyun
618*4882a593Smuzhiyun /* Additional forward declarations */
619*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_CURVE25519_ENABLED)
620*4882a593Smuzhiyun static int ecp_mod_p255( mbedtls_mpi * );
621*4882a593Smuzhiyun #endif
622*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED)
623*4882a593Smuzhiyun static int ecp_mod_p192k1( mbedtls_mpi * );
624*4882a593Smuzhiyun #endif
625*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED)
626*4882a593Smuzhiyun static int ecp_mod_p224k1( mbedtls_mpi * );
627*4882a593Smuzhiyun #endif
628*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED)
629*4882a593Smuzhiyun static int ecp_mod_p256k1( mbedtls_mpi * );
630*4882a593Smuzhiyun #endif
631*4882a593Smuzhiyun
632*4882a593Smuzhiyun #define LOAD_GROUP_A( G ) ecp_group_load( grp, \
633*4882a593Smuzhiyun G ## _p, sizeof( G ## _p ), \
634*4882a593Smuzhiyun G ## _a, sizeof( G ## _a ), \
635*4882a593Smuzhiyun G ## _b, sizeof( G ## _b ), \
636*4882a593Smuzhiyun G ## _gx, sizeof( G ## _gx ), \
637*4882a593Smuzhiyun G ## _gy, sizeof( G ## _gy ), \
638*4882a593Smuzhiyun G ## _n, sizeof( G ## _n ) )
639*4882a593Smuzhiyun
640*4882a593Smuzhiyun #define LOAD_GROUP( G ) ecp_group_load( grp, \
641*4882a593Smuzhiyun G ## _p, sizeof( G ## _p ), \
642*4882a593Smuzhiyun NULL, 0, \
643*4882a593Smuzhiyun G ## _b, sizeof( G ## _b ), \
644*4882a593Smuzhiyun G ## _gx, sizeof( G ## _gx ), \
645*4882a593Smuzhiyun G ## _gy, sizeof( G ## _gy ), \
646*4882a593Smuzhiyun G ## _n, sizeof( G ## _n ) )
647*4882a593Smuzhiyun
648*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_CURVE25519_ENABLED)
649*4882a593Smuzhiyun /*
650*4882a593Smuzhiyun * Specialized function for creating the Curve25519 group
651*4882a593Smuzhiyun */
ecp_use_curve25519(mbedtls_ecp_group * grp)652*4882a593Smuzhiyun static int ecp_use_curve25519( mbedtls_ecp_group *grp )
653*4882a593Smuzhiyun {
654*4882a593Smuzhiyun int ret;
655*4882a593Smuzhiyun
656*4882a593Smuzhiyun /* Actually ( A + 2 ) / 4 */
657*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_read_string( &grp->A, 16, "01DB42" ) );
658*4882a593Smuzhiyun
659*4882a593Smuzhiyun /* P = 2^255 - 19 */
660*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_lset( &grp->P, 1 ) );
661*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_shift_l( &grp->P, 255 ) );
662*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_sub_int( &grp->P, &grp->P, 19 ) );
663*4882a593Smuzhiyun grp->pbits = mbedtls_mpi_bitlen( &grp->P );
664*4882a593Smuzhiyun
665*4882a593Smuzhiyun /* Y intentionaly not set, since we use x/z coordinates.
666*4882a593Smuzhiyun * This is used as a marker to identify Montgomery curves! */
667*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_lset( &grp->G.X, 9 ) );
668*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_lset( &grp->G.Z, 1 ) );
669*4882a593Smuzhiyun mbedtls_mpi_free( &grp->G.Y );
670*4882a593Smuzhiyun
671*4882a593Smuzhiyun /* Actually, the required msb for private keys */
672*4882a593Smuzhiyun grp->nbits = 254;
673*4882a593Smuzhiyun
674*4882a593Smuzhiyun cleanup:
675*4882a593Smuzhiyun if( ret != 0 )
676*4882a593Smuzhiyun mbedtls_ecp_group_free( grp );
677*4882a593Smuzhiyun
678*4882a593Smuzhiyun return( ret );
679*4882a593Smuzhiyun }
680*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_CURVE25519_ENABLED */
681*4882a593Smuzhiyun
682*4882a593Smuzhiyun /*
683*4882a593Smuzhiyun * Set a group using well-known domain parameters
684*4882a593Smuzhiyun */
mbedtls_ecp_group_load(mbedtls_ecp_group * grp,mbedtls_ecp_group_id id)685*4882a593Smuzhiyun int mbedtls_ecp_group_load( mbedtls_ecp_group *grp, mbedtls_ecp_group_id id )
686*4882a593Smuzhiyun {
687*4882a593Smuzhiyun mbedtls_ecp_group_free( grp );
688*4882a593Smuzhiyun
689*4882a593Smuzhiyun grp->id = id;
690*4882a593Smuzhiyun
691*4882a593Smuzhiyun switch( id )
692*4882a593Smuzhiyun {
693*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED)
694*4882a593Smuzhiyun case MBEDTLS_ECP_DP_SECP192R1:
695*4882a593Smuzhiyun NIST_MODP( p192 );
696*4882a593Smuzhiyun return( LOAD_GROUP( secp192r1 ) );
697*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP192R1_ENABLED */
698*4882a593Smuzhiyun
699*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED)
700*4882a593Smuzhiyun case MBEDTLS_ECP_DP_SECP224R1:
701*4882a593Smuzhiyun NIST_MODP( p224 );
702*4882a593Smuzhiyun return( LOAD_GROUP( secp224r1 ) );
703*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP224R1_ENABLED */
704*4882a593Smuzhiyun
705*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED)
706*4882a593Smuzhiyun case MBEDTLS_ECP_DP_SECP256R1:
707*4882a593Smuzhiyun NIST_MODP( p256 );
708*4882a593Smuzhiyun return( LOAD_GROUP( secp256r1 ) );
709*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP256R1_ENABLED */
710*4882a593Smuzhiyun
711*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED)
712*4882a593Smuzhiyun case MBEDTLS_ECP_DP_SECP384R1:
713*4882a593Smuzhiyun NIST_MODP( p384 );
714*4882a593Smuzhiyun return( LOAD_GROUP( secp384r1 ) );
715*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP384R1_ENABLED */
716*4882a593Smuzhiyun
717*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED)
718*4882a593Smuzhiyun case MBEDTLS_ECP_DP_SECP521R1:
719*4882a593Smuzhiyun NIST_MODP( p521 );
720*4882a593Smuzhiyun return( LOAD_GROUP( secp521r1 ) );
721*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP521R1_ENABLED */
722*4882a593Smuzhiyun
723*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED)
724*4882a593Smuzhiyun case MBEDTLS_ECP_DP_SECP192K1:
725*4882a593Smuzhiyun grp->modp = ecp_mod_p192k1;
726*4882a593Smuzhiyun return( LOAD_GROUP_A( secp192k1 ) );
727*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP192K1_ENABLED */
728*4882a593Smuzhiyun
729*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED)
730*4882a593Smuzhiyun case MBEDTLS_ECP_DP_SECP224K1:
731*4882a593Smuzhiyun grp->modp = ecp_mod_p224k1;
732*4882a593Smuzhiyun return( LOAD_GROUP_A( secp224k1 ) );
733*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP224K1_ENABLED */
734*4882a593Smuzhiyun
735*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED)
736*4882a593Smuzhiyun case MBEDTLS_ECP_DP_SECP256K1:
737*4882a593Smuzhiyun grp->modp = ecp_mod_p256k1;
738*4882a593Smuzhiyun return( LOAD_GROUP_A( secp256k1 ) );
739*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP256K1_ENABLED */
740*4882a593Smuzhiyun
741*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_BP256R1_ENABLED)
742*4882a593Smuzhiyun case MBEDTLS_ECP_DP_BP256R1:
743*4882a593Smuzhiyun return( LOAD_GROUP_A( brainpoolP256r1 ) );
744*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_BP256R1_ENABLED */
745*4882a593Smuzhiyun
746*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_BP384R1_ENABLED)
747*4882a593Smuzhiyun case MBEDTLS_ECP_DP_BP384R1:
748*4882a593Smuzhiyun return( LOAD_GROUP_A( brainpoolP384r1 ) );
749*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_BP384R1_ENABLED */
750*4882a593Smuzhiyun
751*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_BP512R1_ENABLED)
752*4882a593Smuzhiyun case MBEDTLS_ECP_DP_BP512R1:
753*4882a593Smuzhiyun return( LOAD_GROUP_A( brainpoolP512r1 ) );
754*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_BP512R1_ENABLED */
755*4882a593Smuzhiyun
756*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_CURVE25519_ENABLED)
757*4882a593Smuzhiyun case MBEDTLS_ECP_DP_CURVE25519:
758*4882a593Smuzhiyun grp->modp = ecp_mod_p255;
759*4882a593Smuzhiyun return( ecp_use_curve25519( grp ) );
760*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_CURVE25519_ENABLED */
761*4882a593Smuzhiyun
762*4882a593Smuzhiyun default:
763*4882a593Smuzhiyun mbedtls_ecp_group_free( grp );
764*4882a593Smuzhiyun return( MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE );
765*4882a593Smuzhiyun }
766*4882a593Smuzhiyun }
767*4882a593Smuzhiyun
768*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_NIST_OPTIM)
769*4882a593Smuzhiyun /*
770*4882a593Smuzhiyun * Fast reduction modulo the primes used by the NIST curves.
771*4882a593Smuzhiyun *
772*4882a593Smuzhiyun * These functions are critical for speed, but not needed for correct
773*4882a593Smuzhiyun * operations. So, we make the choice to heavily rely on the internals of our
774*4882a593Smuzhiyun * bignum library, which creates a tight coupling between these functions and
775*4882a593Smuzhiyun * our MPI implementation. However, the coupling between the ECP module and
776*4882a593Smuzhiyun * MPI remains loose, since these functions can be deactivated at will.
777*4882a593Smuzhiyun */
778*4882a593Smuzhiyun
779*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED)
780*4882a593Smuzhiyun /*
781*4882a593Smuzhiyun * Compared to the way things are presented in FIPS 186-3 D.2,
782*4882a593Smuzhiyun * we proceed in columns, from right (least significant chunk) to left,
783*4882a593Smuzhiyun * adding chunks to N in place, and keeping a carry for the next chunk.
784*4882a593Smuzhiyun * This avoids moving things around in memory, and uselessly adding zeros,
785*4882a593Smuzhiyun * compared to the more straightforward, line-oriented approach.
786*4882a593Smuzhiyun *
787*4882a593Smuzhiyun * For this prime we need to handle data in chunks of 64 bits.
788*4882a593Smuzhiyun * Since this is always a multiple of our basic mbedtls_mpi_uint, we can
789*4882a593Smuzhiyun * use a mbedtls_mpi_uint * to designate such a chunk, and small loops to handle it.
790*4882a593Smuzhiyun */
791*4882a593Smuzhiyun
792*4882a593Smuzhiyun /* Add 64-bit chunks (dst += src) and update carry */
add64(mbedtls_mpi_uint * dst,mbedtls_mpi_uint * src,mbedtls_mpi_uint * carry)793*4882a593Smuzhiyun static inline void add64( mbedtls_mpi_uint *dst, mbedtls_mpi_uint *src, mbedtls_mpi_uint *carry )
794*4882a593Smuzhiyun {
795*4882a593Smuzhiyun unsigned char i;
796*4882a593Smuzhiyun mbedtls_mpi_uint c = 0;
797*4882a593Smuzhiyun for( i = 0; i < 8 / sizeof( mbedtls_mpi_uint ); i++, dst++, src++ )
798*4882a593Smuzhiyun {
799*4882a593Smuzhiyun *dst += c; c = ( *dst < c );
800*4882a593Smuzhiyun *dst += *src; c += ( *dst < *src );
801*4882a593Smuzhiyun }
802*4882a593Smuzhiyun *carry += c;
803*4882a593Smuzhiyun }
804*4882a593Smuzhiyun
805*4882a593Smuzhiyun /* Add carry to a 64-bit chunk and update carry */
carry64(mbedtls_mpi_uint * dst,mbedtls_mpi_uint * carry)806*4882a593Smuzhiyun static inline void carry64( mbedtls_mpi_uint *dst, mbedtls_mpi_uint *carry )
807*4882a593Smuzhiyun {
808*4882a593Smuzhiyun unsigned char i;
809*4882a593Smuzhiyun for( i = 0; i < 8 / sizeof( mbedtls_mpi_uint ); i++, dst++ )
810*4882a593Smuzhiyun {
811*4882a593Smuzhiyun *dst += *carry;
812*4882a593Smuzhiyun *carry = ( *dst < *carry );
813*4882a593Smuzhiyun }
814*4882a593Smuzhiyun }
815*4882a593Smuzhiyun
816*4882a593Smuzhiyun #define WIDTH 8 / sizeof( mbedtls_mpi_uint )
817*4882a593Smuzhiyun #define A( i ) N->p + i * WIDTH
818*4882a593Smuzhiyun #define ADD( i ) add64( p, A( i ), &c )
819*4882a593Smuzhiyun #define NEXT p += WIDTH; carry64( p, &c )
820*4882a593Smuzhiyun #define LAST p += WIDTH; *p = c; while( ++p < end ) *p = 0
821*4882a593Smuzhiyun
822*4882a593Smuzhiyun /*
823*4882a593Smuzhiyun * Fast quasi-reduction modulo p192 (FIPS 186-3 D.2.1)
824*4882a593Smuzhiyun */
ecp_mod_p192(mbedtls_mpi * N)825*4882a593Smuzhiyun static int ecp_mod_p192( mbedtls_mpi *N )
826*4882a593Smuzhiyun {
827*4882a593Smuzhiyun int ret;
828*4882a593Smuzhiyun mbedtls_mpi_uint c = 0;
829*4882a593Smuzhiyun mbedtls_mpi_uint *p, *end;
830*4882a593Smuzhiyun
831*4882a593Smuzhiyun /* Make sure we have enough blocks so that A(5) is legal */
832*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_grow( N, 6 * WIDTH ) );
833*4882a593Smuzhiyun
834*4882a593Smuzhiyun p = N->p;
835*4882a593Smuzhiyun end = p + N->n;
836*4882a593Smuzhiyun
837*4882a593Smuzhiyun ADD( 3 ); ADD( 5 ); NEXT; // A0 += A3 + A5
838*4882a593Smuzhiyun ADD( 3 ); ADD( 4 ); ADD( 5 ); NEXT; // A1 += A3 + A4 + A5
839*4882a593Smuzhiyun ADD( 4 ); ADD( 5 ); LAST; // A2 += A4 + A5
840*4882a593Smuzhiyun
841*4882a593Smuzhiyun cleanup:
842*4882a593Smuzhiyun return( ret );
843*4882a593Smuzhiyun }
844*4882a593Smuzhiyun
845*4882a593Smuzhiyun #undef WIDTH
846*4882a593Smuzhiyun #undef A
847*4882a593Smuzhiyun #undef ADD
848*4882a593Smuzhiyun #undef NEXT
849*4882a593Smuzhiyun #undef LAST
850*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP192R1_ENABLED */
851*4882a593Smuzhiyun
852*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED) || \
853*4882a593Smuzhiyun defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED) || \
854*4882a593Smuzhiyun defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED)
855*4882a593Smuzhiyun /*
856*4882a593Smuzhiyun * The reader is advised to first understand ecp_mod_p192() since the same
857*4882a593Smuzhiyun * general structure is used here, but with additional complications:
858*4882a593Smuzhiyun * (1) chunks of 32 bits, and (2) subtractions.
859*4882a593Smuzhiyun */
860*4882a593Smuzhiyun
861*4882a593Smuzhiyun /*
862*4882a593Smuzhiyun * For these primes, we need to handle data in chunks of 32 bits.
863*4882a593Smuzhiyun * This makes it more complicated if we use 64 bits limbs in MPI,
864*4882a593Smuzhiyun * which prevents us from using a uniform access method as for p192.
865*4882a593Smuzhiyun *
866*4882a593Smuzhiyun * So, we define a mini abstraction layer to access 32 bit chunks,
867*4882a593Smuzhiyun * load them in 'cur' for work, and store them back from 'cur' when done.
868*4882a593Smuzhiyun *
869*4882a593Smuzhiyun * While at it, also define the size of N in terms of 32-bit chunks.
870*4882a593Smuzhiyun */
871*4882a593Smuzhiyun #define LOAD32 cur = A( i );
872*4882a593Smuzhiyun
873*4882a593Smuzhiyun #if defined(MBEDTLS_HAVE_INT32) /* 32 bit */
874*4882a593Smuzhiyun
875*4882a593Smuzhiyun #define MAX32 N->n
876*4882a593Smuzhiyun #define A( j ) N->p[j]
877*4882a593Smuzhiyun #define STORE32 N->p[i] = cur;
878*4882a593Smuzhiyun
879*4882a593Smuzhiyun #else /* 64-bit */
880*4882a593Smuzhiyun
881*4882a593Smuzhiyun #define MAX32 N->n * 2
882*4882a593Smuzhiyun #define A( j ) j % 2 ? (uint32_t)( N->p[j/2] >> 32 ) : (uint32_t)( N->p[j/2] )
883*4882a593Smuzhiyun #define STORE32 \
884*4882a593Smuzhiyun if( i % 2 ) { \
885*4882a593Smuzhiyun N->p[i/2] &= 0x00000000FFFFFFFF; \
886*4882a593Smuzhiyun N->p[i/2] |= ((mbedtls_mpi_uint) cur) << 32; \
887*4882a593Smuzhiyun } else { \
888*4882a593Smuzhiyun N->p[i/2] &= 0xFFFFFFFF00000000; \
889*4882a593Smuzhiyun N->p[i/2] |= (mbedtls_mpi_uint) cur; \
890*4882a593Smuzhiyun }
891*4882a593Smuzhiyun
892*4882a593Smuzhiyun #endif /* sizeof( mbedtls_mpi_uint ) */
893*4882a593Smuzhiyun
894*4882a593Smuzhiyun /*
895*4882a593Smuzhiyun * Helpers for addition and subtraction of chunks, with signed carry.
896*4882a593Smuzhiyun */
add32(uint32_t * dst,uint32_t src,signed char * carry)897*4882a593Smuzhiyun static inline void add32( uint32_t *dst, uint32_t src, signed char *carry )
898*4882a593Smuzhiyun {
899*4882a593Smuzhiyun *dst += src;
900*4882a593Smuzhiyun *carry += ( *dst < src );
901*4882a593Smuzhiyun }
902*4882a593Smuzhiyun
sub32(uint32_t * dst,uint32_t src,signed char * carry)903*4882a593Smuzhiyun static inline void sub32( uint32_t *dst, uint32_t src, signed char *carry )
904*4882a593Smuzhiyun {
905*4882a593Smuzhiyun *carry -= ( *dst < src );
906*4882a593Smuzhiyun *dst -= src;
907*4882a593Smuzhiyun }
908*4882a593Smuzhiyun
909*4882a593Smuzhiyun #define ADD( j ) add32( &cur, A( j ), &c );
910*4882a593Smuzhiyun #define SUB( j ) sub32( &cur, A( j ), &c );
911*4882a593Smuzhiyun
912*4882a593Smuzhiyun /*
913*4882a593Smuzhiyun * Helpers for the main 'loop'
914*4882a593Smuzhiyun * (see fix_negative for the motivation of C)
915*4882a593Smuzhiyun */
916*4882a593Smuzhiyun #define INIT( b ) \
917*4882a593Smuzhiyun int ret; \
918*4882a593Smuzhiyun signed char c = 0, cc; \
919*4882a593Smuzhiyun uint32_t cur; \
920*4882a593Smuzhiyun size_t i = 0, bits = b; \
921*4882a593Smuzhiyun mbedtls_mpi C; \
922*4882a593Smuzhiyun mbedtls_mpi_uint Cp[ b / 8 / sizeof( mbedtls_mpi_uint) + 1 ]; \
923*4882a593Smuzhiyun \
924*4882a593Smuzhiyun C.s = 1; \
925*4882a593Smuzhiyun C.n = b / 8 / sizeof( mbedtls_mpi_uint) + 1; \
926*4882a593Smuzhiyun C.p = Cp; \
927*4882a593Smuzhiyun memset( Cp, 0, C.n * sizeof( mbedtls_mpi_uint ) ); \
928*4882a593Smuzhiyun \
929*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_grow( N, b * 2 / 8 / sizeof( mbedtls_mpi_uint ) ) ); \
930*4882a593Smuzhiyun LOAD32;
931*4882a593Smuzhiyun
932*4882a593Smuzhiyun #define NEXT \
933*4882a593Smuzhiyun STORE32; i++; LOAD32; \
934*4882a593Smuzhiyun cc = c; c = 0; \
935*4882a593Smuzhiyun if( cc < 0 ) \
936*4882a593Smuzhiyun sub32( &cur, -cc, &c ); \
937*4882a593Smuzhiyun else \
938*4882a593Smuzhiyun add32( &cur, cc, &c ); \
939*4882a593Smuzhiyun
940*4882a593Smuzhiyun #define LAST \
941*4882a593Smuzhiyun STORE32; i++; \
942*4882a593Smuzhiyun cur = c > 0 ? c : 0; STORE32; \
943*4882a593Smuzhiyun cur = 0; while( ++i < MAX32 ) { STORE32; } \
944*4882a593Smuzhiyun if( c < 0 ) fix_negative( N, c, &C, bits );
945*4882a593Smuzhiyun
946*4882a593Smuzhiyun /*
947*4882a593Smuzhiyun * If the result is negative, we get it in the form
948*4882a593Smuzhiyun * c * 2^(bits + 32) + N, with c negative and N positive shorter than 'bits'
949*4882a593Smuzhiyun */
fix_negative(mbedtls_mpi * N,signed char c,mbedtls_mpi * C,size_t bits)950*4882a593Smuzhiyun static inline int fix_negative( mbedtls_mpi *N, signed char c, mbedtls_mpi *C, size_t bits )
951*4882a593Smuzhiyun {
952*4882a593Smuzhiyun int ret;
953*4882a593Smuzhiyun
954*4882a593Smuzhiyun /* C = - c * 2^(bits + 32) */
955*4882a593Smuzhiyun #if !defined(MBEDTLS_HAVE_INT64)
956*4882a593Smuzhiyun ((void) bits);
957*4882a593Smuzhiyun #else
958*4882a593Smuzhiyun if( bits == 224 )
959*4882a593Smuzhiyun C->p[ C->n - 1 ] = ((mbedtls_mpi_uint) -c) << 32;
960*4882a593Smuzhiyun else
961*4882a593Smuzhiyun #endif
962*4882a593Smuzhiyun C->p[ C->n - 1 ] = (mbedtls_mpi_uint) -c;
963*4882a593Smuzhiyun
964*4882a593Smuzhiyun /* N = - ( C - N ) */
965*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_sub_abs( N, C, N ) );
966*4882a593Smuzhiyun N->s = -1;
967*4882a593Smuzhiyun
968*4882a593Smuzhiyun cleanup:
969*4882a593Smuzhiyun
970*4882a593Smuzhiyun return( ret );
971*4882a593Smuzhiyun }
972*4882a593Smuzhiyun
973*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED)
974*4882a593Smuzhiyun /*
975*4882a593Smuzhiyun * Fast quasi-reduction modulo p224 (FIPS 186-3 D.2.2)
976*4882a593Smuzhiyun */
ecp_mod_p224(mbedtls_mpi * N)977*4882a593Smuzhiyun static int ecp_mod_p224( mbedtls_mpi *N )
978*4882a593Smuzhiyun {
979*4882a593Smuzhiyun INIT( 224 );
980*4882a593Smuzhiyun
981*4882a593Smuzhiyun SUB( 7 ); SUB( 11 ); NEXT; // A0 += -A7 - A11
982*4882a593Smuzhiyun SUB( 8 ); SUB( 12 ); NEXT; // A1 += -A8 - A12
983*4882a593Smuzhiyun SUB( 9 ); SUB( 13 ); NEXT; // A2 += -A9 - A13
984*4882a593Smuzhiyun SUB( 10 ); ADD( 7 ); ADD( 11 ); NEXT; // A3 += -A10 + A7 + A11
985*4882a593Smuzhiyun SUB( 11 ); ADD( 8 ); ADD( 12 ); NEXT; // A4 += -A11 + A8 + A12
986*4882a593Smuzhiyun SUB( 12 ); ADD( 9 ); ADD( 13 ); NEXT; // A5 += -A12 + A9 + A13
987*4882a593Smuzhiyun SUB( 13 ); ADD( 10 ); LAST; // A6 += -A13 + A10
988*4882a593Smuzhiyun
989*4882a593Smuzhiyun cleanup:
990*4882a593Smuzhiyun return( ret );
991*4882a593Smuzhiyun }
992*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP224R1_ENABLED */
993*4882a593Smuzhiyun
994*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED)
995*4882a593Smuzhiyun /*
996*4882a593Smuzhiyun * Fast quasi-reduction modulo p256 (FIPS 186-3 D.2.3)
997*4882a593Smuzhiyun */
ecp_mod_p256(mbedtls_mpi * N)998*4882a593Smuzhiyun static int ecp_mod_p256( mbedtls_mpi *N )
999*4882a593Smuzhiyun {
1000*4882a593Smuzhiyun INIT( 256 );
1001*4882a593Smuzhiyun
1002*4882a593Smuzhiyun ADD( 8 ); ADD( 9 );
1003*4882a593Smuzhiyun SUB( 11 ); SUB( 12 ); SUB( 13 ); SUB( 14 ); NEXT; // A0
1004*4882a593Smuzhiyun
1005*4882a593Smuzhiyun ADD( 9 ); ADD( 10 );
1006*4882a593Smuzhiyun SUB( 12 ); SUB( 13 ); SUB( 14 ); SUB( 15 ); NEXT; // A1
1007*4882a593Smuzhiyun
1008*4882a593Smuzhiyun ADD( 10 ); ADD( 11 );
1009*4882a593Smuzhiyun SUB( 13 ); SUB( 14 ); SUB( 15 ); NEXT; // A2
1010*4882a593Smuzhiyun
1011*4882a593Smuzhiyun ADD( 11 ); ADD( 11 ); ADD( 12 ); ADD( 12 ); ADD( 13 );
1012*4882a593Smuzhiyun SUB( 15 ); SUB( 8 ); SUB( 9 ); NEXT; // A3
1013*4882a593Smuzhiyun
1014*4882a593Smuzhiyun ADD( 12 ); ADD( 12 ); ADD( 13 ); ADD( 13 ); ADD( 14 );
1015*4882a593Smuzhiyun SUB( 9 ); SUB( 10 ); NEXT; // A4
1016*4882a593Smuzhiyun
1017*4882a593Smuzhiyun ADD( 13 ); ADD( 13 ); ADD( 14 ); ADD( 14 ); ADD( 15 );
1018*4882a593Smuzhiyun SUB( 10 ); SUB( 11 ); NEXT; // A5
1019*4882a593Smuzhiyun
1020*4882a593Smuzhiyun ADD( 14 ); ADD( 14 ); ADD( 15 ); ADD( 15 ); ADD( 14 ); ADD( 13 );
1021*4882a593Smuzhiyun SUB( 8 ); SUB( 9 ); NEXT; // A6
1022*4882a593Smuzhiyun
1023*4882a593Smuzhiyun ADD( 15 ); ADD( 15 ); ADD( 15 ); ADD( 8 );
1024*4882a593Smuzhiyun SUB( 10 ); SUB( 11 ); SUB( 12 ); SUB( 13 ); LAST; // A7
1025*4882a593Smuzhiyun
1026*4882a593Smuzhiyun cleanup:
1027*4882a593Smuzhiyun return( ret );
1028*4882a593Smuzhiyun }
1029*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP256R1_ENABLED */
1030*4882a593Smuzhiyun
1031*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED)
1032*4882a593Smuzhiyun /*
1033*4882a593Smuzhiyun * Fast quasi-reduction modulo p384 (FIPS 186-3 D.2.4)
1034*4882a593Smuzhiyun */
ecp_mod_p384(mbedtls_mpi * N)1035*4882a593Smuzhiyun static int ecp_mod_p384( mbedtls_mpi *N )
1036*4882a593Smuzhiyun {
1037*4882a593Smuzhiyun INIT( 384 );
1038*4882a593Smuzhiyun
1039*4882a593Smuzhiyun ADD( 12 ); ADD( 21 ); ADD( 20 );
1040*4882a593Smuzhiyun SUB( 23 ); NEXT; // A0
1041*4882a593Smuzhiyun
1042*4882a593Smuzhiyun ADD( 13 ); ADD( 22 ); ADD( 23 );
1043*4882a593Smuzhiyun SUB( 12 ); SUB( 20 ); NEXT; // A2
1044*4882a593Smuzhiyun
1045*4882a593Smuzhiyun ADD( 14 ); ADD( 23 );
1046*4882a593Smuzhiyun SUB( 13 ); SUB( 21 ); NEXT; // A2
1047*4882a593Smuzhiyun
1048*4882a593Smuzhiyun ADD( 15 ); ADD( 12 ); ADD( 20 ); ADD( 21 );
1049*4882a593Smuzhiyun SUB( 14 ); SUB( 22 ); SUB( 23 ); NEXT; // A3
1050*4882a593Smuzhiyun
1051*4882a593Smuzhiyun ADD( 21 ); ADD( 21 ); ADD( 16 ); ADD( 13 ); ADD( 12 ); ADD( 20 ); ADD( 22 );
1052*4882a593Smuzhiyun SUB( 15 ); SUB( 23 ); SUB( 23 ); NEXT; // A4
1053*4882a593Smuzhiyun
1054*4882a593Smuzhiyun ADD( 22 ); ADD( 22 ); ADD( 17 ); ADD( 14 ); ADD( 13 ); ADD( 21 ); ADD( 23 );
1055*4882a593Smuzhiyun SUB( 16 ); NEXT; // A5
1056*4882a593Smuzhiyun
1057*4882a593Smuzhiyun ADD( 23 ); ADD( 23 ); ADD( 18 ); ADD( 15 ); ADD( 14 ); ADD( 22 );
1058*4882a593Smuzhiyun SUB( 17 ); NEXT; // A6
1059*4882a593Smuzhiyun
1060*4882a593Smuzhiyun ADD( 19 ); ADD( 16 ); ADD( 15 ); ADD( 23 );
1061*4882a593Smuzhiyun SUB( 18 ); NEXT; // A7
1062*4882a593Smuzhiyun
1063*4882a593Smuzhiyun ADD( 20 ); ADD( 17 ); ADD( 16 );
1064*4882a593Smuzhiyun SUB( 19 ); NEXT; // A8
1065*4882a593Smuzhiyun
1066*4882a593Smuzhiyun ADD( 21 ); ADD( 18 ); ADD( 17 );
1067*4882a593Smuzhiyun SUB( 20 ); NEXT; // A9
1068*4882a593Smuzhiyun
1069*4882a593Smuzhiyun ADD( 22 ); ADD( 19 ); ADD( 18 );
1070*4882a593Smuzhiyun SUB( 21 ); NEXT; // A10
1071*4882a593Smuzhiyun
1072*4882a593Smuzhiyun ADD( 23 ); ADD( 20 ); ADD( 19 );
1073*4882a593Smuzhiyun SUB( 22 ); LAST; // A11
1074*4882a593Smuzhiyun
1075*4882a593Smuzhiyun cleanup:
1076*4882a593Smuzhiyun return( ret );
1077*4882a593Smuzhiyun }
1078*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP384R1_ENABLED */
1079*4882a593Smuzhiyun
1080*4882a593Smuzhiyun #undef A
1081*4882a593Smuzhiyun #undef LOAD32
1082*4882a593Smuzhiyun #undef STORE32
1083*4882a593Smuzhiyun #undef MAX32
1084*4882a593Smuzhiyun #undef INIT
1085*4882a593Smuzhiyun #undef NEXT
1086*4882a593Smuzhiyun #undef LAST
1087*4882a593Smuzhiyun
1088*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP224R1_ENABLED ||
1089*4882a593Smuzhiyun MBEDTLS_ECP_DP_SECP256R1_ENABLED ||
1090*4882a593Smuzhiyun MBEDTLS_ECP_DP_SECP384R1_ENABLED */
1091*4882a593Smuzhiyun
1092*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED)
1093*4882a593Smuzhiyun /*
1094*4882a593Smuzhiyun * Here we have an actual Mersenne prime, so things are more straightforward.
1095*4882a593Smuzhiyun * However, chunks are aligned on a 'weird' boundary (521 bits).
1096*4882a593Smuzhiyun */
1097*4882a593Smuzhiyun
1098*4882a593Smuzhiyun /* Size of p521 in terms of mbedtls_mpi_uint */
1099*4882a593Smuzhiyun #define P521_WIDTH ( 521 / 8 / sizeof( mbedtls_mpi_uint ) + 1 )
1100*4882a593Smuzhiyun
1101*4882a593Smuzhiyun /* Bits to keep in the most significant mbedtls_mpi_uint */
1102*4882a593Smuzhiyun #define P521_MASK 0x01FF
1103*4882a593Smuzhiyun
1104*4882a593Smuzhiyun /*
1105*4882a593Smuzhiyun * Fast quasi-reduction modulo p521 (FIPS 186-3 D.2.5)
1106*4882a593Smuzhiyun * Write N as A1 + 2^521 A0, return A0 + A1
1107*4882a593Smuzhiyun */
ecp_mod_p521(mbedtls_mpi * N)1108*4882a593Smuzhiyun static int ecp_mod_p521( mbedtls_mpi *N )
1109*4882a593Smuzhiyun {
1110*4882a593Smuzhiyun int ret;
1111*4882a593Smuzhiyun size_t i;
1112*4882a593Smuzhiyun mbedtls_mpi M;
1113*4882a593Smuzhiyun mbedtls_mpi_uint Mp[P521_WIDTH + 1];
1114*4882a593Smuzhiyun /* Worst case for the size of M is when mbedtls_mpi_uint is 16 bits:
1115*4882a593Smuzhiyun * we need to hold bits 513 to 1056, which is 34 limbs, that is
1116*4882a593Smuzhiyun * P521_WIDTH + 1. Otherwise P521_WIDTH is enough. */
1117*4882a593Smuzhiyun
1118*4882a593Smuzhiyun if( N->n < P521_WIDTH )
1119*4882a593Smuzhiyun return( 0 );
1120*4882a593Smuzhiyun
1121*4882a593Smuzhiyun /* M = A1 */
1122*4882a593Smuzhiyun M.s = 1;
1123*4882a593Smuzhiyun M.n = N->n - ( P521_WIDTH - 1 );
1124*4882a593Smuzhiyun if( M.n > P521_WIDTH + 1 )
1125*4882a593Smuzhiyun M.n = P521_WIDTH + 1;
1126*4882a593Smuzhiyun M.p = Mp;
1127*4882a593Smuzhiyun memcpy( Mp, N->p + P521_WIDTH - 1, M.n * sizeof( mbedtls_mpi_uint ) );
1128*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_shift_r( &M, 521 % ( 8 * sizeof( mbedtls_mpi_uint ) ) ) );
1129*4882a593Smuzhiyun
1130*4882a593Smuzhiyun /* N = A0 */
1131*4882a593Smuzhiyun N->p[P521_WIDTH - 1] &= P521_MASK;
1132*4882a593Smuzhiyun for( i = P521_WIDTH; i < N->n; i++ )
1133*4882a593Smuzhiyun N->p[i] = 0;
1134*4882a593Smuzhiyun
1135*4882a593Smuzhiyun /* N = A0 + A1 */
1136*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_add_abs( N, N, &M ) );
1137*4882a593Smuzhiyun
1138*4882a593Smuzhiyun cleanup:
1139*4882a593Smuzhiyun return( ret );
1140*4882a593Smuzhiyun }
1141*4882a593Smuzhiyun
1142*4882a593Smuzhiyun #undef P521_WIDTH
1143*4882a593Smuzhiyun #undef P521_MASK
1144*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP521R1_ENABLED */
1145*4882a593Smuzhiyun
1146*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_NIST_OPTIM */
1147*4882a593Smuzhiyun
1148*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_CURVE25519_ENABLED)
1149*4882a593Smuzhiyun
1150*4882a593Smuzhiyun /* Size of p255 in terms of mbedtls_mpi_uint */
1151*4882a593Smuzhiyun #define P255_WIDTH ( 255 / 8 / sizeof( mbedtls_mpi_uint ) + 1 )
1152*4882a593Smuzhiyun
1153*4882a593Smuzhiyun /*
1154*4882a593Smuzhiyun * Fast quasi-reduction modulo p255 = 2^255 - 19
1155*4882a593Smuzhiyun * Write N as A0 + 2^255 A1, return A0 + 19 * A1
1156*4882a593Smuzhiyun */
ecp_mod_p255(mbedtls_mpi * N)1157*4882a593Smuzhiyun static int ecp_mod_p255( mbedtls_mpi *N )
1158*4882a593Smuzhiyun {
1159*4882a593Smuzhiyun int ret;
1160*4882a593Smuzhiyun size_t i;
1161*4882a593Smuzhiyun mbedtls_mpi M;
1162*4882a593Smuzhiyun mbedtls_mpi_uint Mp[P255_WIDTH + 2];
1163*4882a593Smuzhiyun
1164*4882a593Smuzhiyun if( N->n < P255_WIDTH )
1165*4882a593Smuzhiyun return( 0 );
1166*4882a593Smuzhiyun
1167*4882a593Smuzhiyun /* M = A1 */
1168*4882a593Smuzhiyun M.s = 1;
1169*4882a593Smuzhiyun M.n = N->n - ( P255_WIDTH - 1 );
1170*4882a593Smuzhiyun if( M.n > P255_WIDTH + 1 )
1171*4882a593Smuzhiyun M.n = P255_WIDTH + 1;
1172*4882a593Smuzhiyun M.p = Mp;
1173*4882a593Smuzhiyun memset( Mp, 0, sizeof Mp );
1174*4882a593Smuzhiyun memcpy( Mp, N->p + P255_WIDTH - 1, M.n * sizeof( mbedtls_mpi_uint ) );
1175*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_shift_r( &M, 255 % ( 8 * sizeof( mbedtls_mpi_uint ) ) ) );
1176*4882a593Smuzhiyun M.n++; /* Make room for multiplication by 19 */
1177*4882a593Smuzhiyun
1178*4882a593Smuzhiyun /* N = A0 */
1179*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_set_bit( N, 255, 0 ) );
1180*4882a593Smuzhiyun for( i = P255_WIDTH; i < N->n; i++ )
1181*4882a593Smuzhiyun N->p[i] = 0;
1182*4882a593Smuzhiyun
1183*4882a593Smuzhiyun /* N = A0 + 19 * A1 */
1184*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_mul_int( &M, &M, 19 ) );
1185*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_add_abs( N, N, &M ) );
1186*4882a593Smuzhiyun
1187*4882a593Smuzhiyun cleanup:
1188*4882a593Smuzhiyun return( ret );
1189*4882a593Smuzhiyun }
1190*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_CURVE25519_ENABLED */
1191*4882a593Smuzhiyun
1192*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED) || \
1193*4882a593Smuzhiyun defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED) || \
1194*4882a593Smuzhiyun defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED)
1195*4882a593Smuzhiyun /*
1196*4882a593Smuzhiyun * Fast quasi-reduction modulo P = 2^s - R,
1197*4882a593Smuzhiyun * with R about 33 bits, used by the Koblitz curves.
1198*4882a593Smuzhiyun *
1199*4882a593Smuzhiyun * Write N as A0 + 2^224 A1, return A0 + R * A1.
1200*4882a593Smuzhiyun * Actually do two passes, since R is big.
1201*4882a593Smuzhiyun */
1202*4882a593Smuzhiyun #define P_KOBLITZ_MAX ( 256 / 8 / sizeof( mbedtls_mpi_uint ) ) // Max limbs in P
1203*4882a593Smuzhiyun #define P_KOBLITZ_R ( 8 / sizeof( mbedtls_mpi_uint ) ) // Limbs in R
ecp_mod_koblitz(mbedtls_mpi * N,mbedtls_mpi_uint * Rp,size_t p_limbs,size_t adjust,size_t shift,mbedtls_mpi_uint mask)1204*4882a593Smuzhiyun static inline int ecp_mod_koblitz( mbedtls_mpi *N, mbedtls_mpi_uint *Rp, size_t p_limbs,
1205*4882a593Smuzhiyun size_t adjust, size_t shift, mbedtls_mpi_uint mask )
1206*4882a593Smuzhiyun {
1207*4882a593Smuzhiyun int ret;
1208*4882a593Smuzhiyun size_t i;
1209*4882a593Smuzhiyun mbedtls_mpi M, R;
1210*4882a593Smuzhiyun mbedtls_mpi_uint Mp[P_KOBLITZ_MAX + P_KOBLITZ_R + 1];
1211*4882a593Smuzhiyun
1212*4882a593Smuzhiyun if( N->n < p_limbs )
1213*4882a593Smuzhiyun return( 0 );
1214*4882a593Smuzhiyun
1215*4882a593Smuzhiyun /* Init R */
1216*4882a593Smuzhiyun R.s = 1;
1217*4882a593Smuzhiyun R.p = Rp;
1218*4882a593Smuzhiyun R.n = P_KOBLITZ_R;
1219*4882a593Smuzhiyun
1220*4882a593Smuzhiyun /* Common setup for M */
1221*4882a593Smuzhiyun M.s = 1;
1222*4882a593Smuzhiyun M.p = Mp;
1223*4882a593Smuzhiyun
1224*4882a593Smuzhiyun /* M = A1 */
1225*4882a593Smuzhiyun M.n = N->n - ( p_limbs - adjust );
1226*4882a593Smuzhiyun if( M.n > p_limbs + adjust )
1227*4882a593Smuzhiyun M.n = p_limbs + adjust;
1228*4882a593Smuzhiyun memset( Mp, 0, sizeof Mp );
1229*4882a593Smuzhiyun memcpy( Mp, N->p + p_limbs - adjust, M.n * sizeof( mbedtls_mpi_uint ) );
1230*4882a593Smuzhiyun if( shift != 0 )
1231*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_shift_r( &M, shift ) );
1232*4882a593Smuzhiyun M.n += R.n; /* Make room for multiplication by R */
1233*4882a593Smuzhiyun
1234*4882a593Smuzhiyun /* N = A0 */
1235*4882a593Smuzhiyun if( mask != 0 )
1236*4882a593Smuzhiyun N->p[p_limbs - 1] &= mask;
1237*4882a593Smuzhiyun for( i = p_limbs; i < N->n; i++ )
1238*4882a593Smuzhiyun N->p[i] = 0;
1239*4882a593Smuzhiyun
1240*4882a593Smuzhiyun /* N = A0 + R * A1 */
1241*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_mul_mpi( &M, &M, &R ) );
1242*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_add_abs( N, N, &M ) );
1243*4882a593Smuzhiyun
1244*4882a593Smuzhiyun /* Second pass */
1245*4882a593Smuzhiyun
1246*4882a593Smuzhiyun /* M = A1 */
1247*4882a593Smuzhiyun M.n = N->n - ( p_limbs - adjust );
1248*4882a593Smuzhiyun if( M.n > p_limbs + adjust )
1249*4882a593Smuzhiyun M.n = p_limbs + adjust;
1250*4882a593Smuzhiyun memset( Mp, 0, sizeof Mp );
1251*4882a593Smuzhiyun memcpy( Mp, N->p + p_limbs - adjust, M.n * sizeof( mbedtls_mpi_uint ) );
1252*4882a593Smuzhiyun if( shift != 0 )
1253*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_shift_r( &M, shift ) );
1254*4882a593Smuzhiyun M.n += R.n; /* Make room for multiplication by R */
1255*4882a593Smuzhiyun
1256*4882a593Smuzhiyun /* N = A0 */
1257*4882a593Smuzhiyun if( mask != 0 )
1258*4882a593Smuzhiyun N->p[p_limbs - 1] &= mask;
1259*4882a593Smuzhiyun for( i = p_limbs; i < N->n; i++ )
1260*4882a593Smuzhiyun N->p[i] = 0;
1261*4882a593Smuzhiyun
1262*4882a593Smuzhiyun /* N = A0 + R * A1 */
1263*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_mul_mpi( &M, &M, &R ) );
1264*4882a593Smuzhiyun MBEDTLS_MPI_CHK( mbedtls_mpi_add_abs( N, N, &M ) );
1265*4882a593Smuzhiyun
1266*4882a593Smuzhiyun cleanup:
1267*4882a593Smuzhiyun return( ret );
1268*4882a593Smuzhiyun }
1269*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP192K1_ENABLED) ||
1270*4882a593Smuzhiyun MBEDTLS_ECP_DP_SECP224K1_ENABLED) ||
1271*4882a593Smuzhiyun MBEDTLS_ECP_DP_SECP256K1_ENABLED) */
1272*4882a593Smuzhiyun
1273*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED)
1274*4882a593Smuzhiyun /*
1275*4882a593Smuzhiyun * Fast quasi-reduction modulo p192k1 = 2^192 - R,
1276*4882a593Smuzhiyun * with R = 2^32 + 2^12 + 2^8 + 2^7 + 2^6 + 2^3 + 1 = 0x0100001119
1277*4882a593Smuzhiyun */
ecp_mod_p192k1(mbedtls_mpi * N)1278*4882a593Smuzhiyun static int ecp_mod_p192k1( mbedtls_mpi *N )
1279*4882a593Smuzhiyun {
1280*4882a593Smuzhiyun static mbedtls_mpi_uint Rp[] = {
1281*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xC9, 0x11, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00 ) };
1282*4882a593Smuzhiyun
1283*4882a593Smuzhiyun return( ecp_mod_koblitz( N, Rp, 192 / 8 / sizeof( mbedtls_mpi_uint ), 0, 0, 0 ) );
1284*4882a593Smuzhiyun }
1285*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP192K1_ENABLED */
1286*4882a593Smuzhiyun
1287*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED)
1288*4882a593Smuzhiyun /*
1289*4882a593Smuzhiyun * Fast quasi-reduction modulo p224k1 = 2^224 - R,
1290*4882a593Smuzhiyun * with R = 2^32 + 2^12 + 2^11 + 2^9 + 2^7 + 2^4 + 2 + 1 = 0x0100001A93
1291*4882a593Smuzhiyun */
ecp_mod_p224k1(mbedtls_mpi * N)1292*4882a593Smuzhiyun static int ecp_mod_p224k1( mbedtls_mpi *N )
1293*4882a593Smuzhiyun {
1294*4882a593Smuzhiyun static mbedtls_mpi_uint Rp[] = {
1295*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0x93, 0x1A, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00 ) };
1296*4882a593Smuzhiyun
1297*4882a593Smuzhiyun #if defined(MBEDTLS_HAVE_INT64)
1298*4882a593Smuzhiyun return( ecp_mod_koblitz( N, Rp, 4, 1, 32, 0xFFFFFFFF ) );
1299*4882a593Smuzhiyun #else
1300*4882a593Smuzhiyun return( ecp_mod_koblitz( N, Rp, 224 / 8 / sizeof( mbedtls_mpi_uint ), 0, 0, 0 ) );
1301*4882a593Smuzhiyun #endif
1302*4882a593Smuzhiyun }
1303*4882a593Smuzhiyun
1304*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP224K1_ENABLED */
1305*4882a593Smuzhiyun
1306*4882a593Smuzhiyun #if defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED)
1307*4882a593Smuzhiyun /*
1308*4882a593Smuzhiyun * Fast quasi-reduction modulo p256k1 = 2^256 - R,
1309*4882a593Smuzhiyun * with R = 2^32 + 2^9 + 2^8 + 2^7 + 2^6 + 2^4 + 1 = 0x01000003D1
1310*4882a593Smuzhiyun */
ecp_mod_p256k1(mbedtls_mpi * N)1311*4882a593Smuzhiyun static int ecp_mod_p256k1( mbedtls_mpi *N )
1312*4882a593Smuzhiyun {
1313*4882a593Smuzhiyun static mbedtls_mpi_uint Rp[] = {
1314*4882a593Smuzhiyun BYTES_TO_T_UINT_8( 0xD1, 0x03, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00 ) };
1315*4882a593Smuzhiyun return( ecp_mod_koblitz( N, Rp, 256 / 8 / sizeof( mbedtls_mpi_uint ), 0, 0, 0 ) );
1316*4882a593Smuzhiyun }
1317*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_DP_SECP256K1_ENABLED */
1318*4882a593Smuzhiyun
1319*4882a593Smuzhiyun #endif /* MBEDTLS_ECP_C */
1320