Update 1.1.1-pre8
This commit is contained in:
@@ -150,7 +150,7 @@ void x25519_fe51_mul121666(fe51 h, fe51 f);
|
||||
|
||||
typedef uint64_t fe64[4];
|
||||
|
||||
int x25519_fe64_eligible();
|
||||
int x25519_fe64_eligible(void);
|
||||
|
||||
/*
|
||||
* There are no reference C implementations for this radix.
|
||||
|
||||
+4
-4
@@ -174,8 +174,8 @@ struct ec_method_st {
|
||||
int (*ecdh_compute_key)(unsigned char **pout, size_t *poutlen,
|
||||
const EC_POINT *pub_key, const EC_KEY *ecdh);
|
||||
/* Inverse modulo order */
|
||||
int (*field_inverse_mod_ord)(const EC_GROUP *, BIGNUM *r, BIGNUM *x,
|
||||
BN_CTX *ctx);
|
||||
int (*field_inverse_mod_ord)(const EC_GROUP *, BIGNUM *r,
|
||||
const BIGNUM *x, BN_CTX *);
|
||||
int (*blind_coordinates)(const EC_GROUP *group, EC_POINT *p, BN_CTX *ctx);
|
||||
};
|
||||
|
||||
@@ -636,7 +636,7 @@ int X25519(uint8_t out_shared_key[32], const uint8_t private_key[32],
|
||||
void X25519_public_from_private(uint8_t out_public_value[32],
|
||||
const uint8_t private_key[32]);
|
||||
|
||||
int EC_GROUP_do_inverse_ord(const EC_GROUP *group, BIGNUM *res,
|
||||
BIGNUM *x, BN_CTX *ctx);
|
||||
int ec_group_do_inverse_ord(const EC_GROUP *group, BIGNUM *res,
|
||||
const BIGNUM *x, BN_CTX *ctx);
|
||||
|
||||
int ec_point_blind_coordinates(const EC_GROUP *group, EC_POINT *p, BN_CTX *ctx);
|
||||
+57
-3
@@ -1017,13 +1017,67 @@ int ec_group_simple_order_bits(const EC_GROUP *group)
|
||||
return BN_num_bits(group->order);
|
||||
}
|
||||
|
||||
int EC_GROUP_do_inverse_ord(const EC_GROUP *group, BIGNUM *res,
|
||||
BIGNUM *x, BN_CTX *ctx)
|
||||
static int ec_field_inverse_mod_ord(const EC_GROUP *group, BIGNUM *r,
|
||||
const BIGNUM *x, BN_CTX *ctx)
|
||||
{
|
||||
BIGNUM *e = NULL;
|
||||
BN_CTX *new_ctx = NULL;
|
||||
int ret = 0;
|
||||
|
||||
if (group->mont_data == NULL)
|
||||
return 0;
|
||||
|
||||
if (ctx == NULL && (ctx = new_ctx = BN_CTX_secure_new()) == NULL)
|
||||
return 0;
|
||||
|
||||
BN_CTX_start(ctx);
|
||||
if ((e = BN_CTX_get(ctx)) == NULL)
|
||||
goto err;
|
||||
|
||||
/*-
|
||||
* We want inverse in constant time, therefore we utilize the fact
|
||||
* order must be prime and use Fermats Little Theorem instead.
|
||||
*/
|
||||
if (!BN_set_word(e, 2))
|
||||
goto err;
|
||||
if (!BN_sub(e, group->order, e))
|
||||
goto err;
|
||||
/*-
|
||||
* Exponent e is public.
|
||||
* No need for scatter-gather or BN_FLG_CONSTTIME.
|
||||
*/
|
||||
if (!BN_mod_exp_mont(r, x, e, group->order, ctx, group->mont_data))
|
||||
goto err;
|
||||
|
||||
ret = 1;
|
||||
|
||||
err:
|
||||
if (ctx != NULL)
|
||||
BN_CTX_end(ctx);
|
||||
BN_CTX_free(new_ctx);
|
||||
return ret;
|
||||
}
|
||||
|
||||
/*-
|
||||
* Default behavior, if group->meth->field_inverse_mod_ord is NULL:
|
||||
* - When group->order is even, this function returns an error.
|
||||
* - When group->order is otherwise composite, the correctness
|
||||
* of the output is not guaranteed.
|
||||
* - When x is outside the range [1, group->order), the correctness
|
||||
* of the output is not guaranteed.
|
||||
* - Otherwise, this function returns the multiplicative inverse in the
|
||||
* range [1, group->order).
|
||||
*
|
||||
* EC_METHODs must implement their own field_inverse_mod_ord for
|
||||
* other functionality.
|
||||
*/
|
||||
int ec_group_do_inverse_ord(const EC_GROUP *group, BIGNUM *res,
|
||||
const BIGNUM *x, BN_CTX *ctx)
|
||||
{
|
||||
if (group->meth->field_inverse_mod_ord != NULL)
|
||||
return group->meth->field_inverse_mod_ord(group, res, x, ctx);
|
||||
else
|
||||
return 0;
|
||||
return ec_field_inverse_mod_ord(group, res, x, ctx);
|
||||
}
|
||||
|
||||
/*-
|
||||
|
||||
+9
-35
@@ -136,34 +136,10 @@ static int ecdsa_sign_setup(EC_KEY *eckey, BN_CTX *ctx_in,
|
||||
}
|
||||
while (BN_is_zero(r));
|
||||
|
||||
/* Check if optimized inverse is implemented */
|
||||
if (EC_GROUP_do_inverse_ord(group, k, k, ctx) == 0) {
|
||||
/* compute the inverse of k */
|
||||
if (group->mont_data != NULL) {
|
||||
/*
|
||||
* We want inverse in constant time, therefore we utilize the fact
|
||||
* order must be prime and use Fermats Little Theorem instead.
|
||||
*/
|
||||
if (!BN_set_word(X, 2)) {
|
||||
ECerr(EC_F_ECDSA_SIGN_SETUP, ERR_R_BN_LIB);
|
||||
goto err;
|
||||
}
|
||||
if (!BN_mod_sub(X, order, X, order, ctx)) {
|
||||
ECerr(EC_F_ECDSA_SIGN_SETUP, ERR_R_BN_LIB);
|
||||
goto err;
|
||||
}
|
||||
BN_set_flags(X, BN_FLG_CONSTTIME);
|
||||
if (!BN_mod_exp_mont_consttime(k, k, X, order, ctx,
|
||||
group->mont_data)) {
|
||||
ECerr(EC_F_ECDSA_SIGN_SETUP, ERR_R_BN_LIB);
|
||||
goto err;
|
||||
}
|
||||
} else {
|
||||
if (!BN_mod_inverse(k, k, order, ctx)) {
|
||||
ECerr(EC_F_ECDSA_SIGN_SETUP, ERR_R_BN_LIB);
|
||||
goto err;
|
||||
}
|
||||
}
|
||||
/* compute the inverse of k */
|
||||
if (!ec_group_do_inverse_ord(group, k, k, ctx)) {
|
||||
ECerr(EC_F_ECDSA_SIGN_SETUP, ERR_R_BN_LIB);
|
||||
goto err;
|
||||
}
|
||||
|
||||
/* clear old values if necessary */
|
||||
@@ -360,7 +336,8 @@ ECDSA_SIG *ossl_ecdsa_sign_sig(const unsigned char *dgst, int dgst_len,
|
||||
ECDSA_SIG_free(ret);
|
||||
ret = NULL;
|
||||
}
|
||||
BN_CTX_end(ctx);
|
||||
if (ctx != NULL)
|
||||
BN_CTX_end(ctx);
|
||||
BN_CTX_free(ctx);
|
||||
BN_clear_free(kinv);
|
||||
return ret;
|
||||
@@ -449,12 +426,9 @@ int ossl_ecdsa_verify_sig(const unsigned char *dgst, int dgst_len,
|
||||
goto err;
|
||||
}
|
||||
/* calculate tmp1 = inv(S) mod order */
|
||||
/* Check if optimized inverse is implemented */
|
||||
if (EC_GROUP_do_inverse_ord(group, u2, sig->s, ctx) == 0) {
|
||||
if (!BN_mod_inverse(u2, sig->s, order, ctx)) {
|
||||
ECerr(EC_F_OSSL_ECDSA_VERIFY_SIG, ERR_R_BN_LIB);
|
||||
goto err;
|
||||
}
|
||||
if (!ec_group_do_inverse_ord(group, u2, sig->s, ctx)) {
|
||||
ECerr(EC_F_OSSL_ECDSA_VERIFY_SIG, ERR_R_BN_LIB);
|
||||
goto err;
|
||||
}
|
||||
/* digest -> m */
|
||||
i = BN_num_bits(order);
|
||||
|
||||
@@ -1212,7 +1212,7 @@ static void batch_mul(felem x_out, felem y_out, felem z_out,
|
||||
* FUNCTIONS TO MANAGE PRECOMPUTATION
|
||||
*/
|
||||
|
||||
static NISTP224_PRE_COMP *nistp224_pre_comp_new()
|
||||
static NISTP224_PRE_COMP *nistp224_pre_comp_new(void)
|
||||
{
|
||||
NISTP224_PRE_COMP *ret = OPENSSL_zalloc(sizeof(*ret));
|
||||
|
||||
|
||||
@@ -1832,7 +1832,7 @@ const EC_METHOD *EC_GFp_nistp256_method(void)
|
||||
* FUNCTIONS TO MANAGE PRECOMPUTATION
|
||||
*/
|
||||
|
||||
static NISTP256_PRE_COMP *nistp256_pre_comp_new()
|
||||
static NISTP256_PRE_COMP *nistp256_pre_comp_new(void)
|
||||
{
|
||||
NISTP256_PRE_COMP *ret = OPENSSL_zalloc(sizeof(*ret));
|
||||
|
||||
|
||||
@@ -1671,7 +1671,7 @@ const EC_METHOD *EC_GFp_nistp521_method(void)
|
||||
* FUNCTIONS TO MANAGE PRECOMPUTATION
|
||||
*/
|
||||
|
||||
static NISTP521_PRE_COMP *nistp521_pre_comp_new()
|
||||
static NISTP521_PRE_COMP *nistp521_pre_comp_new(void)
|
||||
{
|
||||
NISTP521_PRE_COMP *ret = OPENSSL_zalloc(sizeof(*ret));
|
||||
|
||||
|
||||
@@ -1512,7 +1512,7 @@ void ecp_nistz256_ord_sqr_mont(BN_ULONG res[P256_LIMBS],
|
||||
int rep);
|
||||
|
||||
static int ecp_nistz256_inv_mod_ord(const EC_GROUP *group, BIGNUM *r,
|
||||
BIGNUM *x, BN_CTX *ctx)
|
||||
const BIGNUM *x, BN_CTX *ctx)
|
||||
{
|
||||
/* RR = 2^512 mod ord(p256) */
|
||||
static const BN_ULONG RR[P256_LIMBS] = {
|
||||
|
||||
Reference in New Issue
Block a user