diff options
Diffstat (limited to 'src/lib/libcrypto/bn/bn_mod.c')
-rw-r--r-- | src/lib/libcrypto/bn/bn_mod.c | 251 |
1 files changed, 225 insertions, 26 deletions
diff --git a/src/lib/libcrypto/bn/bn_mod.c b/src/lib/libcrypto/bn/bn_mod.c index c351aac14f..5cf82480d7 100644 --- a/src/lib/libcrypto/bn/bn_mod.c +++ b/src/lib/libcrypto/bn/bn_mod.c | |||
@@ -1,4 +1,59 @@ | |||
1 | /* crypto/bn/bn_mod.c */ | 1 | /* crypto/bn/bn_mod.c */ |
2 | /* Includes code written by Lenka Fibikova <fibikova@exp-math.uni-essen.de> | ||
3 | * for the OpenSSL project. */ | ||
4 | /* ==================================================================== | ||
5 | * Copyright (c) 1998-2000 The OpenSSL Project. All rights reserved. | ||
6 | * | ||
7 | * Redistribution and use in source and binary forms, with or without | ||
8 | * modification, are permitted provided that the following conditions | ||
9 | * are met: | ||
10 | * | ||
11 | * 1. Redistributions of source code must retain the above copyright | ||
12 | * notice, this list of conditions and the following disclaimer. | ||
13 | * | ||
14 | * 2. Redistributions in binary form must reproduce the above copyright | ||
15 | * notice, this list of conditions and the following disclaimer in | ||
16 | * the documentation and/or other materials provided with the | ||
17 | * distribution. | ||
18 | * | ||
19 | * 3. All advertising materials mentioning features or use of this | ||
20 | * software must display the following acknowledgment: | ||
21 | * "This product includes software developed by the OpenSSL Project | ||
22 | * for use in the OpenSSL Toolkit. (http://www.openssl.org/)" | ||
23 | * | ||
24 | * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to | ||
25 | * endorse or promote products derived from this software without | ||
26 | * prior written permission. For written permission, please contact | ||
27 | * openssl-core@openssl.org. | ||
28 | * | ||
29 | * 5. Products derived from this software may not be called "OpenSSL" | ||
30 | * nor may "OpenSSL" appear in their names without prior written | ||
31 | * permission of the OpenSSL Project. | ||
32 | * | ||
33 | * 6. Redistributions of any form whatsoever must retain the following | ||
34 | * acknowledgment: | ||
35 | * "This product includes software developed by the OpenSSL Project | ||
36 | * for use in the OpenSSL Toolkit (http://www.openssl.org/)" | ||
37 | * | ||
38 | * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY | ||
39 | * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE | ||
40 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR | ||
41 | * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR | ||
42 | * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, | ||
43 | * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT | ||
44 | * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; | ||
45 | * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) | ||
46 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, | ||
47 | * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) | ||
48 | * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED | ||
49 | * OF THE POSSIBILITY OF SUCH DAMAGE. | ||
50 | * ==================================================================== | ||
51 | * | ||
52 | * This product includes cryptographic software written by Eric Young | ||
53 | * (eay@cryptsoft.com). This product includes software written by Tim | ||
54 | * Hudson (tjh@cryptsoft.com). | ||
55 | * | ||
56 | */ | ||
2 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) | 57 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) |
3 | * All rights reserved. | 58 | * All rights reserved. |
4 | * | 59 | * |
@@ -56,42 +111,186 @@ | |||
56 | * [including the GNU Public Licence.] | 111 | * [including the GNU Public Licence.] |
57 | */ | 112 | */ |
58 | 113 | ||
59 | #include <stdio.h> | ||
60 | #include "cryptlib.h" | 114 | #include "cryptlib.h" |
61 | #include "bn_lcl.h" | 115 | #include "bn_lcl.h" |
62 | 116 | ||
63 | /* rem != m */ | 117 | |
64 | int BN_mod(rem, m, d,ctx) | 118 | #if 0 /* now just a #define */ |
65 | BIGNUM *rem; | 119 | int BN_mod(BIGNUM *rem, const BIGNUM *m, const BIGNUM *d, BN_CTX *ctx) |
66 | BIGNUM *m; | 120 | { |
67 | BIGNUM *d; | 121 | return(BN_div(NULL,rem,m,d,ctx)); |
68 | BN_CTX *ctx; | 122 | /* note that rem->neg == m->neg (unless the remainder is zero) */ |
123 | } | ||
124 | #endif | ||
125 | |||
126 | |||
127 | int BN_nnmod(BIGNUM *r, const BIGNUM *m, const BIGNUM *d, BN_CTX *ctx) | ||
128 | { | ||
129 | /* like BN_mod, but returns non-negative remainder | ||
130 | * (i.e., 0 <= r < |d| always holds) */ | ||
131 | |||
132 | if (!(BN_mod(r,m,d,ctx))) | ||
133 | return 0; | ||
134 | if (!r->neg) | ||
135 | return 1; | ||
136 | /* now -|d| < r < 0, so we have to set r := r + |d| */ | ||
137 | return (d->neg ? BN_sub : BN_add)(r, r, d); | ||
138 | } | ||
139 | |||
140 | |||
141 | int BN_mod_add(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m, BN_CTX *ctx) | ||
142 | { | ||
143 | if (!BN_add(r, a, b)) return 0; | ||
144 | return BN_nnmod(r, r, m, ctx); | ||
145 | } | ||
146 | |||
147 | |||
148 | /* BN_mod_add variant that may be used if both a and b are non-negative | ||
149 | * and less than m */ | ||
150 | int BN_mod_add_quick(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m) | ||
151 | { | ||
152 | if (!BN_add(r, a, b)) return 0; | ||
153 | if (BN_ucmp(r, m) >= 0) | ||
154 | return BN_usub(r, r, m); | ||
155 | return 1; | ||
156 | } | ||
157 | |||
158 | |||
159 | int BN_mod_sub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m, BN_CTX *ctx) | ||
160 | { | ||
161 | if (!BN_sub(r, a, b)) return 0; | ||
162 | return BN_nnmod(r, r, m, ctx); | ||
163 | } | ||
164 | |||
165 | |||
166 | /* BN_mod_sub variant that may be used if both a and b are non-negative | ||
167 | * and less than m */ | ||
168 | int BN_mod_sub_quick(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m) | ||
169 | { | ||
170 | if (!BN_sub(r, a, b)) return 0; | ||
171 | if (r->neg) | ||
172 | return BN_add(r, r, m); | ||
173 | return 1; | ||
174 | } | ||
175 | |||
176 | |||
177 | /* slow but works */ | ||
178 | int BN_mod_mul(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m, | ||
179 | BN_CTX *ctx) | ||
69 | { | 180 | { |
70 | #if 0 /* The old slow way */ | 181 | BIGNUM *t; |
71 | int i,nm,nd; | 182 | int ret=0; |
72 | BIGNUM *dv; | 183 | |
184 | bn_check_top(a); | ||
185 | bn_check_top(b); | ||
186 | bn_check_top(m); | ||
187 | |||
188 | BN_CTX_start(ctx); | ||
189 | if ((t = BN_CTX_get(ctx)) == NULL) goto err; | ||
190 | if (a == b) | ||
191 | { if (!BN_sqr(t,a,ctx)) goto err; } | ||
192 | else | ||
193 | { if (!BN_mul(t,a,b,ctx)) goto err; } | ||
194 | if (!BN_nnmod(r,t,m,ctx)) goto err; | ||
195 | ret=1; | ||
196 | err: | ||
197 | BN_CTX_end(ctx); | ||
198 | return(ret); | ||
199 | } | ||
73 | 200 | ||
74 | if (BN_ucmp(m,d) < 0) | ||
75 | return((BN_copy(rem,m) == NULL)?0:1); | ||
76 | 201 | ||
77 | dv=ctx->bn[ctx->tos]; | 202 | int BN_mod_sqr(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx) |
203 | { | ||
204 | if (!BN_sqr(r, a, ctx)) return 0; | ||
205 | /* r->neg == 0, thus we don't need BN_nnmod */ | ||
206 | return BN_mod(r, r, m, ctx); | ||
207 | } | ||
78 | 208 | ||
79 | if (!BN_copy(rem,m)) return(0); | ||
80 | 209 | ||
81 | nm=BN_num_bits(rem); | 210 | int BN_mod_lshift1(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx) |
82 | nd=BN_num_bits(d); | 211 | { |
83 | if (!BN_lshift(dv,d,nm-nd)) return(0); | 212 | if (!BN_lshift1(r, a)) return 0; |
84 | for (i=nm-nd; i>=0; i--) | 213 | return BN_nnmod(r, r, m, ctx); |
214 | } | ||
215 | |||
216 | |||
217 | /* BN_mod_lshift1 variant that may be used if a is non-negative | ||
218 | * and less than m */ | ||
219 | int BN_mod_lshift1_quick(BIGNUM *r, const BIGNUM *a, const BIGNUM *m) | ||
220 | { | ||
221 | if (!BN_lshift1(r, a)) return 0; | ||
222 | if (BN_cmp(r, m) >= 0) | ||
223 | return BN_sub(r, r, m); | ||
224 | return 1; | ||
225 | } | ||
226 | |||
227 | |||
228 | int BN_mod_lshift(BIGNUM *r, const BIGNUM *a, int n, const BIGNUM *m, BN_CTX *ctx) | ||
229 | { | ||
230 | BIGNUM *abs_m = NULL; | ||
231 | int ret; | ||
232 | |||
233 | if (!BN_nnmod(r, a, m, ctx)) return 0; | ||
234 | |||
235 | if (m->neg) | ||
85 | { | 236 | { |
86 | if (BN_cmp(rem,dv) >= 0) | 237 | abs_m = BN_dup(m); |
238 | if (abs_m == NULL) return 0; | ||
239 | abs_m->neg = 0; | ||
240 | } | ||
241 | |||
242 | ret = BN_mod_lshift_quick(r, r, n, (abs_m ? abs_m : m)); | ||
243 | |||
244 | if (abs_m) | ||
245 | BN_free(abs_m); | ||
246 | return ret; | ||
247 | } | ||
248 | |||
249 | |||
250 | /* BN_mod_lshift variant that may be used if a is non-negative | ||
251 | * and less than m */ | ||
252 | int BN_mod_lshift_quick(BIGNUM *r, const BIGNUM *a, int n, const BIGNUM *m) | ||
253 | { | ||
254 | if (r != a) | ||
255 | { | ||
256 | if (BN_copy(r, a) == NULL) return 0; | ||
257 | } | ||
258 | |||
259 | while (n > 0) | ||
260 | { | ||
261 | int max_shift; | ||
262 | |||
263 | /* 0 < r < m */ | ||
264 | max_shift = BN_num_bits(m) - BN_num_bits(r); | ||
265 | /* max_shift >= 0 */ | ||
266 | |||
267 | if (max_shift < 0) | ||
268 | { | ||
269 | BNerr(BN_F_BN_MOD_LSHIFT_QUICK, BN_R_INPUT_NOT_REDUCED); | ||
270 | return 0; | ||
271 | } | ||
272 | |||
273 | if (max_shift > n) | ||
274 | max_shift = n; | ||
275 | |||
276 | if (max_shift) | ||
277 | { | ||
278 | if (!BN_lshift(r, r, max_shift)) return 0; | ||
279 | n -= max_shift; | ||
280 | } | ||
281 | else | ||
282 | { | ||
283 | if (!BN_lshift1(r, r)) return 0; | ||
284 | --n; | ||
285 | } | ||
286 | |||
287 | /* BN_num_bits(r) <= BN_num_bits(m) */ | ||
288 | |||
289 | if (BN_cmp(r, m) >= 0) | ||
87 | { | 290 | { |
88 | if (!BN_sub(rem,rem,dv)) return(0); | 291 | if (!BN_sub(r, r, m)) return 0; |
89 | } | 292 | } |
90 | if (!BN_rshift1(dv,dv)) return(0); | ||
91 | } | 293 | } |
92 | return(1); | 294 | |
93 | #else | 295 | return 1; |
94 | return(BN_div(NULL,rem,m,d,ctx)); | ||
95 | #endif | ||
96 | } | 296 | } |
97 | |||