forked from ANSSI-FR/libecc
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathec_montgomery.c
76 lines (61 loc) · 1.8 KB
/
ec_montgomery.c
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
/*
* Copyright (C) 2021 - This file is part of libecc project
*
* Authors:
* Ryad BENADJILA <ryadbenadjila@gmail.com>
* Arnaud EBALARD <arnaud.ebalard@ssi.gouv.fr>
*
* This software is licensed under a dual BSD and GPL v2 license.
* See LICENSE file at the root folder of the project.
*/
#include "ec_montgomery.h"
#define EC_MONTGOMERY_CRV_MAGIC ((word_t)(0x83734673a0443720ULL))
/*
* Check pointed Montgomery curve structure has already been
* initialized.
*/
int ec_montgomery_crv_is_initialized(ec_montgomery_crv_src_t crv)
{
return !!((crv != NULL) && (crv->magic == EC_MONTGOMERY_CRV_MAGIC));
}
void ec_montgomery_crv_check_initialized(ec_montgomery_crv_src_t crv)
{
MUST_HAVE((crv != NULL) && (crv->magic == EC_MONTGOMERY_CRV_MAGIC));
}
/*
* Initialize pointed Montgomery curve structure using given A and B
* Fp elements representing curve equation (B v^2 = u^3 + A u^2 + u) parameters.
*/
void ec_montgomery_crv_init(ec_montgomery_crv_t crv, fp_src_t A, fp_src_t B, nn_src_t order)
{
fp tmp;
MUST_HAVE(crv != NULL);
fp_check_initialized(A);
fp_check_initialized(B);
MUST_HAVE(A->ctx == B->ctx);
fp_init(&tmp, A->ctx);
/* A and B elements of Fp, A unequal to (+/-)2 and B non zero */
fp_set_word_value(&tmp, 2);
fp_add(&tmp, A, &tmp);
MUST_HAVE(!fp_iszero(&tmp));
/**/
fp_set_word_value(&tmp, 2);
fp_sub(&tmp, A, &tmp);
MUST_HAVE(!fp_iszero(&tmp));
/**/
MUST_HAVE(!fp_iszero(B));
nn_check_initialized(order);
fp_init(&(crv->A), A->ctx);
fp_init(&(crv->B), B->ctx);
fp_copy(&(crv->A), A);
fp_copy(&(crv->B), B);
nn_copy(&(crv->order), order);
crv->magic = EC_MONTGOMERY_CRV_MAGIC;
fp_uninit(&tmp);
}
/* Uninitialize curve */
void ec_montgomery_crv_uninit(ec_montgomery_crv_t crv)
{
ec_montgomery_crv_check_initialized(crv);
crv->magic = WORD(0);
}