mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-12-06 19:41:15 +01:00
Merge branch 'asn_bug22006_final_squashed'
This commit is contained in:
@@ -30,4 +30,9 @@ int ed25519_donna_blind_public_key(unsigned char *out, const unsigned char *inp,
|
||||
int ed25519_donna_pubkey_from_curve25519_pubkey(unsigned char *out,
|
||||
const unsigned char *inp, int signbit);
|
||||
|
||||
|
||||
int
|
||||
ed25519_donna_scalarmult_with_group_order(unsigned char *out,
|
||||
const unsigned char *pubkey);
|
||||
|
||||
#endif
|
||||
|
||||
@@ -340,5 +340,32 @@ ed25519_donna_pubkey_from_curve25519_pubkey(unsigned char *out,
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Do the scalar multiplication of <b>pubkey</b> with the group order
|
||||
* <b>modm_m</b>. Place the result in <b>out</b> which must be at least 32
|
||||
* bytes long. */
|
||||
int
|
||||
ed25519_donna_scalarmult_with_group_order(unsigned char *out,
|
||||
const unsigned char *pubkey)
|
||||
{
|
||||
static const bignum256modm ALIGN(16) zero = { 0 };
|
||||
unsigned char pkcopy[32];
|
||||
ge25519 ALIGN(16) Point, Result;
|
||||
|
||||
/* No "ge25519_unpack", negate the public key and unpack it back.
|
||||
* See ed25519_donna_blind_public_key() */
|
||||
memcpy(pkcopy, pubkey, 32);
|
||||
pkcopy[31] ^= (1<<7);
|
||||
if (!ge25519_unpack_negative_vartime(&Point, pkcopy)) {
|
||||
return -1; /* error: bail out */
|
||||
}
|
||||
|
||||
/* There is no regular scalarmult function so we have to do:
|
||||
* Result = l*P + 0*B */
|
||||
ge25519_double_scalarmult_vartime(&Result, &Point, modm_m, zero);
|
||||
ge25519_pack(out, &Result);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
#include "test-internals.c"
|
||||
|
||||
|
||||
@@ -74,3 +74,40 @@ int ed25519_ref10_blind_public_key(unsigned char *out,
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* This is the group order encoded in a format that
|
||||
* ge_double_scalarmult_vartime() understands. The group order m is:
|
||||
* m = 2^252 + 27742317777372353535851937790883648493 =
|
||||
* 0x1000000000000000000000000000000014def9dea2f79cd65812631a5cf5d3ed
|
||||
*/
|
||||
static const uint8_t modm_m[32] = {0xed,0xd3,0xf5,0x5c,0x1a,0x63,0x12,0x58,
|
||||
0xd6,0x9c,0xf7,0xa2,0xde,0xf9,0xde,0x14,
|
||||
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
|
||||
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x10};
|
||||
|
||||
/* Do the scalar multiplication of <b>pubkey</b> with the group order
|
||||
* <b>modm_m</b>. Place the result in <b>out</b> which must be at least 32
|
||||
* bytes long. */
|
||||
int
|
||||
ed25519_ref10_scalarmult_with_group_order(unsigned char *out,
|
||||
const unsigned char *pubkey)
|
||||
{
|
||||
unsigned char pkcopy[32];
|
||||
unsigned char zero[32] = {0};
|
||||
ge_p3 Point;
|
||||
ge_p2 Result;
|
||||
|
||||
/* All this is done to fit 'pubkey' in 'Point' so that it can be used by
|
||||
* ed25519 ref code. Same thing as in blinding function */
|
||||
memcpy(pkcopy, pubkey, 32);
|
||||
pkcopy[31] ^= (1<<7);
|
||||
if (ge_frombytes_negate_vartime(&Point, pkcopy) != 0) {
|
||||
return -1; /* error: bail out */
|
||||
}
|
||||
|
||||
/* There isn't a regular scalarmult -- we have to do r = l*P + 0*B */
|
||||
ge_double_scalarmult_vartime(&Result, modm_m, &Point, zero);
|
||||
ge_tobytes(out, &Result);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -27,4 +27,8 @@ int ed25519_ref10_blind_public_key(unsigned char *out,
|
||||
const unsigned char *inp,
|
||||
const unsigned char *param);
|
||||
|
||||
int
|
||||
ed25519_ref10_scalarmult_with_group_order(unsigned char *out,
|
||||
const unsigned char *pubkey);
|
||||
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user