a1388b472fa56cec1945099dbf2a479638a9efa3
[openssl.git] / crypto / ec / ec_curve.c
1 /* crypto/ec/ec_curve.c */
2 /* ====================================================================
3  * Copyright (c) 1998-2002 The OpenSSL Project.  All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *
9  * 1. Redistributions of source code must retain the above copyright
10  *    notice, this list of conditions and the following disclaimer. 
11  *
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in
14  *    the documentation and/or other materials provided with the
15  *    distribution.
16  *
17  * 3. All advertising materials mentioning features or use of this
18  *    software must display the following acknowledgment:
19  *    "This product includes software developed by the OpenSSL Project
20  *    for use in the OpenSSL Toolkit. (http://www.openssl.org/)"
21  *
22  * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
23  *    endorse or promote products derived from this software without
24  *    prior written permission. For written permission, please contact
25  *    openssl-core@openssl.org.
26  *
27  * 5. Products derived from this software may not be called "OpenSSL"
28  *    nor may "OpenSSL" appear in their names without prior written
29  *    permission of the OpenSSL Project.
30  *
31  * 6. Redistributions of any form whatsoever must retain the following
32  *    acknowledgment:
33  *    "This product includes software developed by the OpenSSL Project
34  *    for use in the OpenSSL Toolkit (http://www.openssl.org/)"
35  *
36  * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
37  * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
38  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
39  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
40  * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
41  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
42  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
43  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
44  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
45  * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
46  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
47  * OF THE POSSIBILITY OF SUCH DAMAGE.
48  * ====================================================================
49  *
50  * This product includes cryptographic software written by Eric Young
51  * (eay@cryptsoft.com).  This product includes software written by Tim
52  * Hudson (tjh@cryptsoft.com).
53  *
54  */
55
56 #include "ec_lcl.h"
57 #include <openssl/err.h>
58 #include <openssl/obj_mac.h>
59 #include <openssl/asn1.h>
60 #include <openssl/asn1t.h>
61
62 static EC_GROUP *ec_group_new_GFp_from_hex(const char *prime_in,
63             const char *a_in, const char *b_in,
64             const char *x_in, const int y_bit, const char *order_in)
65         {
66         EC_GROUP *group=NULL;
67         EC_POINT *P=NULL;
68         BN_CTX   *ctx=NULL;
69         BIGNUM   *prime=NULL,*a=NULL,*b=NULL,*x=NULL,*order=NULL;
70         int      ok=0;
71
72         if ((ctx = BN_CTX_new()) == NULL) goto bn_err;
73         if ((prime = BN_new()) == NULL || (a = BN_new()) == NULL || (b = BN_new()) == NULL ||
74                 (x = BN_new()) == NULL || (order = BN_new()) == NULL) goto bn_err;
75         
76         if (!BN_hex2bn(&prime, prime_in)) goto bn_err;
77         if (!BN_hex2bn(&a, a_in)) goto bn_err;
78         if (!BN_hex2bn(&b, b_in)) goto bn_err;
79
80         if ((group = EC_GROUP_new_curve_GFp(prime, a, b, ctx)) == NULL) goto err;
81         if ((P = EC_POINT_new(group)) == NULL) goto err;
82         
83         if (!BN_hex2bn(&x, x_in)) goto bn_err;
84         if (!EC_POINT_set_compressed_coordinates_GFp(group, P, x, y_bit, ctx)) goto err;
85         if (!BN_hex2bn(&order, order_in)) goto bn_err;
86         if (!EC_GROUP_set_generator(group, P, order, BN_value_one())) goto err;
87         ok=1;
88 bn_err:
89         if (!ok)
90                 ECerr(EC_F_EC_GROUP_NEW_GFP_FROM_HEX, ERR_R_BN_LIB);
91 err:
92         if (!ok)
93                 {
94                 EC_GROUP_free(group);
95                 group = NULL;
96                 }
97         if (P)     EC_POINT_free(P);
98         if (ctx)   BN_CTX_free(ctx);
99         if (prime) BN_free(prime);
100         if (a)     BN_free(a);
101         if (b)     BN_free(b);
102         if (order) BN_free(order);
103         if (x)     BN_free(x);
104         return(group);
105         }
106
107 EC_GROUP *EC_GROUP_new_by_name(int name)
108         {
109         EC_GROUP *ret = NULL;
110         switch (name)
111                 {
112         case EC_GROUP_NO_CURVE:
113                 return NULL;
114
115         case EC_GROUP_NIST_PRIME_224:
116                 return ec_group_new_GFp_from_hex(
117                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001",
118                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE",
119                         "B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4",
120                         "B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21",0,
121                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D");
122
123         case EC_GROUP_NIST_PRIME_384:
124                 return ec_group_new_GFp_from_hex(
125                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF",
126                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFC",
127                         "B3312FA7E23EE7E4988E056BE3F82D19181D9C6EFE8141120314088F5013875AC656398D8A2ED19D2A85C8EDD3EC2AEF",
128                         "AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7",1,
129                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973");
130
131         case EC_GROUP_NIST_PRIME_521:
132                 return ec_group_new_GFp_from_hex(
133                         "1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF"
134                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF",
135                         "1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF"
136                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC",
137                         "051953EB9618E1C9A1F929A21A0B68540EEA2DA725B99B"
138                         "315F3B8B489918EF109E156193951EC7E937B1652C0BD3BB1BF073573DF883D2C34F1EF451FD46B503F00",
139                         "C6858E06B70404E9CD9E3ECB662395B4429C648139053F"
140                         "B521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66",0,
141                         "1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF"
142                         "FFFFFFFFFFFFFFFFFFFFA51868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409");
143
144         case EC_GROUP_NIST_PRIME_192:
145         case EC_GROUP_X9_62_PRIME_192V1:
146                 ret = ec_group_new_GFp_from_hex(
147                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",
148                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",
149                         "64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1",
150                         "188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012",1,
151                         "FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831");
152                 EC_GROUP_set_nid(ret, NID_X9_62_prime192v1);
153                 return ret;
154
155         case EC_GROUP_X9_62_PRIME_192V2:
156                 ret = ec_group_new_GFp_from_hex(
157                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",
158                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",
159                         "CC22D6DFB95C6B25E49C0D6364A4E5980C393AA21668D953",
160                         "EEA2BAE7E1497842F2DE7769CFE9C989C072AD696F48034A",1,
161                         "FFFFFFFFFFFFFFFFFFFFFFFE5FB1A724DC80418648D8DD31");
162                 EC_GROUP_set_nid(ret, NID_X9_62_prime192v2);
163                 return ret;
164
165         case EC_GROUP_X9_62_PRIME_192V3:
166                 ret = ec_group_new_GFp_from_hex(
167                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",
168                         "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",
169                         "22123DC2395A05CAA7423DAECCC94760A7D462256BD56916",
170                         "7D29778100C65A1DA1783716588DCE2B8B4AEE8E228F1896",0,
171                         "FFFFFFFFFFFFFFFFFFFFFFFF7A62D031C83F4294F640EC13");
172                 EC_GROUP_set_nid(ret, NID_X9_62_prime192v3);
173                 return ret;
174
175         case EC_GROUP_X9_62_PRIME_239V1:
176                 ret = ec_group_new_GFp_from_hex(
177                         "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",
178                         "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",
179                         "6B016C3BDCF18941D0D654921475CA71A9DB2FB27D1D37796185C2942C0A",
180                         "0FFA963CDCA8816CCC33B8642BEDF905C3D358573D3F27FBBD3B3CB9AAAF",0,
181                         "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFF9E5E9A9F5D9071FBD1522688909D0B");
182                 EC_GROUP_set_nid(ret, NID_X9_62_prime239v1);
183                 return ret;
184
185         case EC_GROUP_X9_62_PRIME_239V2:
186                 ret = ec_group_new_GFp_from_hex(
187                         "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",
188                         "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",
189                         "617FAB6832576CBBFED50D99F0249C3FEE58B94BA0038C7AE84C8C832F2C",
190                         "38AF09D98727705120C921BB5E9E26296A3CDCF2F35757A0EAFD87B830E7",0,
191                         "7FFFFFFFFFFFFFFFFFFFFFFF800000CFA7E8594377D414C03821BC582063");
192                 EC_GROUP_set_nid(ret, NID_X9_62_prime239v2);
193                 return ret;
194
195         case EC_GROUP_X9_62_PRIME_239V3:
196                 ret = ec_group_new_GFp_from_hex(
197                         "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",
198                         "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",
199                         "255705FA2A306654B1F4CB03D6A750A30C250102D4988717D9BA15AB6D3E",
200                         "6768AE8E18BB92CFCF005C949AA2C6D94853D0E660BBF854B1C9505FE95A",1,
201                         "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFF975DEB41B3A6057C3C432146526551");
202                 EC_GROUP_set_nid(ret, NID_X9_62_prime239v3);
203                 return ret;
204
205         case EC_GROUP_NIST_PRIME_256:
206         case EC_GROUP_X9_62_PRIME_256V1:
207                 ret = ec_group_new_GFp_from_hex(
208                         "FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF",
209                         "FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFC",
210                         "5AC635D8AA3A93E7B3EBBD55769886BC651D06B0CC53B0F63BCE3C3E27D2604B",
211                         "6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296",1,
212                         "FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551");
213                 EC_GROUP_set_nid(ret, NID_X9_62_prime256v1);
214                 return ret;
215                 }
216
217         ECerr(EC_F_EC_GROUP_NEW_BY_NAME, EC_R_UNKNOWN_GROUP);
218         return NULL;
219         }
220
221
222 EC_GROUP *EC_GROUP_new_by_nid(const int nid)
223         {
224         switch(nid)
225                 {
226         case NID_X9_62_prime192v1:
227                 return EC_GROUP_new_by_name(EC_GROUP_X9_62_PRIME_192V1);
228         case NID_X9_62_prime192v2:
229                 return EC_GROUP_new_by_name(EC_GROUP_X9_62_PRIME_192V2);
230         case NID_X9_62_prime192v3:
231                 return EC_GROUP_new_by_name(EC_GROUP_X9_62_PRIME_192V3);
232         case NID_X9_62_prime239v1:
233                 return EC_GROUP_new_by_name(EC_GROUP_X9_62_PRIME_239V1);
234         case NID_X9_62_prime239v2:
235                 return EC_GROUP_new_by_name(EC_GROUP_X9_62_PRIME_239V2);
236         case NID_X9_62_prime239v3:
237                 return EC_GROUP_new_by_name(EC_GROUP_X9_62_PRIME_239V3);
238         case NID_X9_62_prime256v1:
239                 return EC_GROUP_new_by_name(EC_GROUP_X9_62_PRIME_256V1);
240                 }
241         ECerr(EC_F_EC_GROUP_NEW_BY_NID, EC_R_UNKNOWN_NID);
242         return NULL;
243         }
244
245
246 #if 0
247 int EC_GROUP_group2nid(const EC_GROUP *group)
248         {
249         return EC_GROUP_get_nid(group);
250
251 #if 0   
252 /* TODO: a real compare function for EC_GROUPs */
253 #define EC_GROUP_cmp(a,b) ((a) != (b))
254
255         if (group == NULL)
256                 {
257                 ECerr(EC_F_EC_GROUP_GROUP2NID, EC_R_MISSING_PARAMETERS);
258                 return 0;
259                 }
260         if (!EC_GROUP_cmp(group, EC_GROUP_GET_X9_62_192V1_GROUP()))
261                 return NID_X9_62_prime192v1;
262         else if (!EC_GROUP_cmp(group, EC_GROUP_get_x9_62_192v2_group()))
263                 return NID_X9_62_prime192v2;
264         else if (!EC_GROUP_cmp(group, EC_GROUP_get_x9_62_192v3_group()))
265                 return NID_X9_62_prime192v3;
266         else if (!EC_GROUP_cmp(group, EC_GROUP_get_x9_62_239v1_group()))
267                 return NID_X9_62_prime239v1;
268         else if (!EC_GROUP_cmp(group, EC_GROUP_get_x9_62_239v2_group()))
269                 return NID_X9_62_prime239v2;
270         else if (!EC_GROUP_cmp(group, EC_GROUP_get_x9_62_239v3_group()))
271                 return NID_X9_62_prime239v3;
272         else if (!EC_GROUP_cmp(group, EC_GROUP_get_x9_62_256v1_group()))
273                 return NID_X9_62_prime256v1;
274         ECerr(EC_F_EC_GROUP_GROUP2NID, EC_R_UNKNOWN_GROUP);
275         return 0;
276 #endif
277         }
278 #endif