OpenSSL 1.1.1-pre2
This commit is contained in:
+37
-17
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2011-2016 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 2011-2018 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the OpenSSL license (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
@@ -40,12 +40,12 @@ NON_EMPTY_TRANSLATION_UNIT
|
||||
# include <openssl/err.h>
|
||||
# include "ec_lcl.h"
|
||||
|
||||
# if defined(__GNUC__) && (__GNUC__ > 3 || (__GNUC__ == 3 && __GNUC_MINOR__ >= 1))
|
||||
# if defined(__SIZEOF_INT128__) && __SIZEOF_INT128__==16
|
||||
/* even with gcc, the typedef won't work for 32-bit platforms */
|
||||
typedef __uint128_t uint128_t; /* nonstandard; implemented by gcc on 64-bit
|
||||
* platforms */
|
||||
# else
|
||||
# error "Need GCC 3.1 or later to define type uint128_t"
|
||||
# error "Need GCC 4.0 or later to define type uint128_t"
|
||||
# endif
|
||||
|
||||
typedef uint8_t u8;
|
||||
@@ -1156,9 +1156,9 @@ static void copy_conditional(felem out, const felem in, limb mask)
|
||||
* adapted for mixed addition (z2 = 1, or z2 = 0 for the point at infinity).
|
||||
*
|
||||
* This function includes a branch for checking whether the two input points
|
||||
* are equal (while not equal to the point at infinity). This case never
|
||||
* happens during single point multiplication, so there is no timing leak for
|
||||
* ECDH or ECDSA signing. */
|
||||
* are equal (while not equal to the point at infinity). See comment below
|
||||
* on constant-time.
|
||||
*/
|
||||
static void point_add(felem x3, felem y3, felem z3,
|
||||
const felem x1, const felem y1, const felem z1,
|
||||
const int mixed, const felem x2, const felem y2,
|
||||
@@ -1252,6 +1252,22 @@ static void point_add(felem x3, felem y3, felem z3,
|
||||
/* ftmp5[i] < 2^61 */
|
||||
|
||||
if (x_equal && y_equal && !z1_is_zero && !z2_is_zero) {
|
||||
/*
|
||||
* This is obviously not constant-time but it will almost-never happen
|
||||
* for ECDH / ECDSA. The case where it can happen is during scalar-mult
|
||||
* where the intermediate value gets very close to the group order.
|
||||
* Since |ec_GFp_nistp_recode_scalar_bits| produces signed digits for
|
||||
* the scalar, it's possible for the intermediate value to be a small
|
||||
* negative multiple of the base point, and for the final signed digit
|
||||
* to be the same value. We believe that this only occurs for the scalar
|
||||
* 1fffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
|
||||
* ffffffa51868783bf2f966b7fcc0148f709a5d03bb5c9b8899c47aebb6fb
|
||||
* 71e913863f7, in that case the penultimate intermediate is -9G and
|
||||
* the final digit is also -9G. Since this only happens for a single
|
||||
* scalar, the timing leak is irrelevent. (Any attacker who wanted to
|
||||
* check whether a secret scalar was that exact value, can already do
|
||||
* so.)
|
||||
*/
|
||||
point_double(x3, y3, z3, x1, y1, z1);
|
||||
return;
|
||||
}
|
||||
@@ -1587,7 +1603,7 @@ static void batch_mul(felem x_out, felem y_out, felem z_out,
|
||||
/* Precomputation for the group generator. */
|
||||
struct nistp521_pre_comp_st {
|
||||
felem g_pre_comp[16][3];
|
||||
int references;
|
||||
CRYPTO_REF_COUNT references;
|
||||
CRYPTO_RWLOCK *lock;
|
||||
};
|
||||
|
||||
@@ -1677,7 +1693,7 @@ NISTP521_PRE_COMP *EC_nistp521_pre_comp_dup(NISTP521_PRE_COMP *p)
|
||||
{
|
||||
int i;
|
||||
if (p != NULL)
|
||||
CRYPTO_atomic_add(&p->references, 1, &i, p->lock);
|
||||
CRYPTO_UP_REF(&p->references, &i, p->lock);
|
||||
return p;
|
||||
}
|
||||
|
||||
@@ -1688,7 +1704,7 @@ void EC_nistp521_pre_comp_free(NISTP521_PRE_COMP *p)
|
||||
if (p == NULL)
|
||||
return;
|
||||
|
||||
CRYPTO_atomic_add(&p->references, -1, &i, p->lock);
|
||||
CRYPTO_DOWN_REF(&p->references, &i, p->lock);
|
||||
REF_PRINT_COUNT("EC_nistp521", x);
|
||||
if (i > 0)
|
||||
return;
|
||||
@@ -1723,9 +1739,10 @@ int ec_GFp_nistp521_group_set_curve(EC_GROUP *group, const BIGNUM *p,
|
||||
if ((ctx = new_ctx = BN_CTX_new()) == NULL)
|
||||
return 0;
|
||||
BN_CTX_start(ctx);
|
||||
if (((curve_p = BN_CTX_get(ctx)) == NULL) ||
|
||||
((curve_a = BN_CTX_get(ctx)) == NULL) ||
|
||||
((curve_b = BN_CTX_get(ctx)) == NULL))
|
||||
curve_p = BN_CTX_get(ctx);
|
||||
curve_a = BN_CTX_get(ctx);
|
||||
curve_b = BN_CTX_get(ctx);
|
||||
if (curve_b == NULL)
|
||||
goto err;
|
||||
BN_bin2bn(nistp521_curve_params[0], sizeof(felem_bytearray), curve_p);
|
||||
BN_bin2bn(nistp521_curve_params[1], sizeof(felem_bytearray), curve_a);
|
||||
@@ -1854,10 +1871,11 @@ int ec_GFp_nistp521_points_mul(const EC_GROUP *group, EC_POINT *r,
|
||||
if ((ctx = new_ctx = BN_CTX_new()) == NULL)
|
||||
return 0;
|
||||
BN_CTX_start(ctx);
|
||||
if (((x = BN_CTX_get(ctx)) == NULL) ||
|
||||
((y = BN_CTX_get(ctx)) == NULL) ||
|
||||
((z = BN_CTX_get(ctx)) == NULL) ||
|
||||
((tmp_scalar = BN_CTX_get(ctx)) == NULL))
|
||||
x = BN_CTX_get(ctx);
|
||||
y = BN_CTX_get(ctx);
|
||||
z = BN_CTX_get(ctx);
|
||||
tmp_scalar = BN_CTX_get(ctx);
|
||||
if (tmp_scalar == NULL)
|
||||
goto err;
|
||||
|
||||
if (scalar != NULL) {
|
||||
@@ -2041,7 +2059,9 @@ int ec_GFp_nistp521_precompute_mult(EC_GROUP *group, BN_CTX *ctx)
|
||||
if ((ctx = new_ctx = BN_CTX_new()) == NULL)
|
||||
return 0;
|
||||
BN_CTX_start(ctx);
|
||||
if (((x = BN_CTX_get(ctx)) == NULL) || ((y = BN_CTX_get(ctx)) == NULL))
|
||||
x = BN_CTX_get(ctx);
|
||||
y = BN_CTX_get(ctx);
|
||||
if (y == NULL)
|
||||
goto err;
|
||||
/* get the generator */
|
||||
if (group->generator == NULL)
|
||||
|
||||
Reference in New Issue
Block a user