Merge branch 'asn_bug22006_final_squashed'

This commit is contained in:
Nick Mathewson
2017-06-27 17:19:08 -04:00
10 changed files with 239 additions and 2 deletions
@@ -30,4 +30,9 @@ int ed25519_donna_blind_public_key(unsigned char *out, const unsigned char *inp,
int ed25519_donna_pubkey_from_curve25519_pubkey(unsigned char *out,
const unsigned char *inp, int signbit);
int
ed25519_donna_scalarmult_with_group_order(unsigned char *out,
const unsigned char *pubkey);
#endif
+27
View File
@@ -340,5 +340,32 @@ ed25519_donna_pubkey_from_curve25519_pubkey(unsigned char *out,
return 0;
}
/* Do the scalar multiplication of <b>pubkey</b> with the group order
* <b>modm_m</b>. Place the result in <b>out</b> which must be at least 32
* bytes long. */
int
ed25519_donna_scalarmult_with_group_order(unsigned char *out,
const unsigned char *pubkey)
{
static const bignum256modm ALIGN(16) zero = { 0 };
unsigned char pkcopy[32];
ge25519 ALIGN(16) Point, Result;
/* No "ge25519_unpack", negate the public key and unpack it back.
* See ed25519_donna_blind_public_key() */
memcpy(pkcopy, pubkey, 32);
pkcopy[31] ^= (1<<7);
if (!ge25519_unpack_negative_vartime(&Point, pkcopy)) {
return -1; /* error: bail out */
}
/* There is no regular scalarmult function so we have to do:
* Result = l*P + 0*B */
ge25519_double_scalarmult_vartime(&Result, &Point, modm_m, zero);
ge25519_pack(out, &Result);
return 0;
}
#include "test-internals.c"
+37
View File
@@ -74,3 +74,40 @@ int ed25519_ref10_blind_public_key(unsigned char *out,
return 0;
}
/* This is the group order encoded in a format that
* ge_double_scalarmult_vartime() understands. The group order m is:
* m = 2^252 + 27742317777372353535851937790883648493 =
* 0x1000000000000000000000000000000014def9dea2f79cd65812631a5cf5d3ed
*/
static const uint8_t modm_m[32] = {0xed,0xd3,0xf5,0x5c,0x1a,0x63,0x12,0x58,
0xd6,0x9c,0xf7,0xa2,0xde,0xf9,0xde,0x14,
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x10};
/* Do the scalar multiplication of <b>pubkey</b> with the group order
* <b>modm_m</b>. Place the result in <b>out</b> which must be at least 32
* bytes long. */
int
ed25519_ref10_scalarmult_with_group_order(unsigned char *out,
const unsigned char *pubkey)
{
unsigned char pkcopy[32];
unsigned char zero[32] = {0};
ge_p3 Point;
ge_p2 Result;
/* All this is done to fit 'pubkey' in 'Point' so that it can be used by
* ed25519 ref code. Same thing as in blinding function */
memcpy(pkcopy, pubkey, 32);
pkcopy[31] ^= (1<<7);
if (ge_frombytes_negate_vartime(&Point, pkcopy) != 0) {
return -1; /* error: bail out */
}
/* There isn't a regular scalarmult -- we have to do r = l*P + 0*B */
ge_double_scalarmult_vartime(&Result, modm_m, &Point, zero);
ge_tobytes(out, &Result);
return 0;
}
+4
View File
@@ -27,4 +27,8 @@ int ed25519_ref10_blind_public_key(unsigned char *out,
const unsigned char *inp,
const unsigned char *param);
int
ed25519_ref10_scalarmult_with_group_order(unsigned char *out,
const unsigned char *pubkey);
#endif