]> git.ipfire.org Git - thirdparty/openssl.git/blame - crypto/ec/ec_curve.c
Add more curves.
[thirdparty/openssl.git] / crypto / ec / ec_curve.c
CommitLineData
945e15a2
BM
1/* crypto/ec/ec_curve.c */
2/* ====================================================================
3 * Copyright (c) 1998-2002 The OpenSSL Project. All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 *
9 * 1. Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer.
11 *
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in
14 * the documentation and/or other materials provided with the
15 * distribution.
16 *
17 * 3. All advertising materials mentioning features or use of this
18 * software must display the following acknowledgment:
19 * "This product includes software developed by the OpenSSL Project
20 * for use in the OpenSSL Toolkit. (http://www.openssl.org/)"
21 *
22 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
23 * endorse or promote products derived from this software without
24 * prior written permission. For written permission, please contact
25 * openssl-core@openssl.org.
26 *
27 * 5. Products derived from this software may not be called "OpenSSL"
28 * nor may "OpenSSL" appear in their names without prior written
29 * permission of the OpenSSL Project.
30 *
31 * 6. Redistributions of any form whatsoever must retain the following
32 * acknowledgment:
33 * "This product includes software developed by the OpenSSL Project
34 * for use in the OpenSSL Toolkit (http://www.openssl.org/)"
35 *
36 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
37 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
38 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
39 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
40 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
41 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
42 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
43 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
44 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
45 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
46 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
47 * OF THE POSSIBILITY OF SUCH DAMAGE.
48 * ====================================================================
49 *
50 * This product includes cryptographic software written by Eric Young
51 * (eay@cryptsoft.com). This product includes software written by Tim
52 * Hudson (tjh@cryptsoft.com).
53 *
54 */
55
56#include "ec_lcl.h"
57#include <openssl/err.h>
58#include <openssl/obj_mac.h>
59#include <openssl/asn1.h>
60#include <openssl/asn1t.h>
61
9bc44854
BM
62/* #define _EC_GROUP_EXAMPLE_PRIME_CURVE \
63 * "the prime number p", "a", "b", "the compressed base point", "y-bit", "order", "cofacor"
64 */
65/* the nist prime curves */
66#define _EC_GROUP_NIST_PRIME_192 \
67 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",\
68 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",\
69 "64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1",\
70 "188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012",1,\
71 "FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831",1
72#define _EC_GROUP_NIST_PRIME_224 \
73 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001",\
74 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE",\
75 "B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4",\
76 "B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21",0,\
77 "FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D",1
78#define _EC_GROUP_NIST_PRIME_384 \
79 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF",\
80 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFC",\
81 "B3312FA7E23EE7E4988E056BE3F82D19181D9C6EFE8141120314088F5013875AC656398D8A2ED19D2A85C8EDD3EC2AEF",\
82 "AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7",1,\
83 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973",1
84#define _EC_GROUP_NIST_PRIME_521 \
85 "1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF"\
86 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF",\
87 "1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF"\
88 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC",\
89 "051953EB9618E1C9A1F929A21A0B68540EEA2DA725B99B"\
90 "315F3B8B489918EF109E156193951EC7E937B1652C0BD3BB1BF073573DF883D2C34F1EF451FD46B503F00",\
91 "C6858E06B70404E9CD9E3ECB662395B4429C648139053F"\
92 "B521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66",0,\
93 "1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF"\
94 "FFFFFFFFFFFFFFFFFFFFA51868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409",1
95/* the x9.62 prime curves ( minus the nist prime curves ) */
96#define _EC_GROUP_X9_62_PRIME_192V2 \
97 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",\
98 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",\
99 "CC22D6DFB95C6B25E49C0D6364A4E5980C393AA21668D953",\
100 "EEA2BAE7E1497842F2DE7769CFE9C989C072AD696F48034A",1,\
101 "FFFFFFFFFFFFFFFFFFFFFFFE5FB1A724DC80418648D8DD31",1
102#define _EC_GROUP_X9_62_PRIME_192V3 \
103 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",\
104 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",\
105 "22123DC2395A05CAA7423DAECCC94760A7D462256BD56916",\
106 "7D29778100C65A1DA1783716588DCE2B8B4AEE8E228F1896",0,\
107 "FFFFFFFFFFFFFFFFFFFFFFFF7A62D031C83F4294F640EC13",1
108#define _EC_GROUP_X9_62_PRIME_239V1 \
109 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",\
110 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",\
111 "6B016C3BDCF18941D0D654921475CA71A9DB2FB27D1D37796185C2942C0A",\
112 "0FFA963CDCA8816CCC33B8642BEDF905C3D358573D3F27FBBD3B3CB9AAAF",0,\
113 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFF9E5E9A9F5D9071FBD1522688909D0B",1
114#define _EC_GROUP_X9_62_PRIME_239V2 \
115 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",\
116 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",\
117 "617FAB6832576CBBFED50D99F0249C3FEE58B94BA0038C7AE84C8C832F2C",\
118 "38AF09D98727705120C921BB5E9E26296A3CDCF2F35757A0EAFD87B830E7",0,\
119 "7FFFFFFFFFFFFFFFFFFFFFFF800000CFA7E8594377D414C03821BC582063",1
120#define _EC_GROUP_X9_62_PRIME_239V3 \
121 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",\
122 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",\
123 "255705FA2A306654B1F4CB03D6A750A30C250102D4988717D9BA15AB6D3E",\
124 "6768AE8E18BB92CFCF005C949AA2C6D94853D0E660BBF854B1C9505FE95A",1,\
125 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFF975DEB41B3A6057C3C432146526551",1
126#define _EC_GROUP_X9_62_PRIME_256V1 \
127 "FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF",\
128 "FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFC",\
129 "5AC635D8AA3A93E7B3EBBD55769886BC651D06B0CC53B0F63BCE3C3E27D2604B",\
130 "6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296",1,\
131 "FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551",1
132/* the secg prime curves ( minus the nist and x9.62 prime curves ) */
133#define _EC_GROUP_SECG_PRIME_112R1 \
134 "DB7C2ABF62E35E668076BEAD208B",\
135 "DB7C2ABF62E35E668076BEAD2088",\
136 "659EF8BA043916EEDE8911702B22",\
137 "09487239995A5EE76B55F9C2F098",0,\
138 "DB7C2ABF62E35E7628DFAC6561C5",1
139#define _EC_GROUP_SECG_PRIME_112R2 \
140 "DB7C2ABF62E35E668076BEAD208B",\
141 "6127C24C05F38A0AAAF65C0EF02C",\
142 "51DEF1815DB5ED74FCC34C85D709",\
143 "4BA30AB5E892B4E1649DD0928643",1,\
144 "36DF0AAFD8B8D7597CA10520D04B",4
145#define _EC_GROUP_SECG_PRIME_128R1 \
146 "FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF",\
147 "FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFC",\
148 "E87579C11079F43DD824993C2CEE5ED3",\
149 "161FF7528B899B2D0C28607CA52C5B86",1,\
150 "FFFFFFFE0000000075A30D1B9038A115",1
151#define _EC_GROUP_SECG_PRIME_128R2 \
152 "FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF",\
153 "D6031998D1B3BBFEBF59CC9BBFF9AEE1",\
154 "5EEEFCA380D02919DC2C6558BB6D8A5D",\
155 "7B6AA5D85E572983E6FB32A7CDEBC140",0,\
156 "3FFFFFFF 7FFFFFFF BE002472 0613B5A3",4
157#define _EC_GROUP_SECG_PRIME_160K1 \
158 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73",\
159 "0",\
160 "7",\
161 "3B4C382CE37AA192A4019E763036F4F5DD4D7EBB",0,\
162 "0100000000000000000001B8FA16DFAB9ACA16B6B3",1
163#define _EC_GROUP_SECG_PRIME_160R1 \
164 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFF",\
165 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFC",\
166 "1C97BEFC54BD7A8B65ACF89F81D4D4ADC565FA45",\
167 "4A96B5688EF573284664698968C38BB913CBFC82",0,\
168 "0100000000000000000001F4C8F927AED3CA752257",1
169#define _EC_GROUP_SECG_PRIME_160R2 \
170 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73",\
171 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC70",\
172 "B4E134D3FB59EB8BAB57274904664D5AF50388BA",\
173 "52DCB034293A117E1F4FF11B30F7199D3144CE6D",0,\
174 "0100000000000000000000351EE786A818F3A1A16B",1
175#define _EC_GROUP_SECG_PRIME_192K1 \
176 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFEE37",\
177 "0",\
178 "3",\
179 "DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D",1,\
180 "FFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D",1
181#define _EC_GROUP_SECG_PRIME_224K1 \
182 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFE56D",\
183 "0",\
184 "5",\
185 "A1455B334DF099DF30FC28A169A467E9E47075A90F7E650EB6B7A45C",1,\
186 "010000000000000000000000000001DCE8D2EC6184CAF0A971769FB1F7",1
187#define _EC_GROUP_SECG_PRIME_256K1 \
188 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F",\
189 "0",\
190 "7",\
191 "79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798",0,\
192 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141",1
193
60d8bae3 194static EC_GROUP *ec_group_new_GFp_from_hex(const char *prime_in,
945e15a2 195 const char *a_in, const char *b_in,
9bc44854 196 const char *x_in, const int y_bit, const char *order_in, const BN_ULONG cofac_in)
945e15a2
BM
197 {
198 EC_GROUP *group=NULL;
199 EC_POINT *P=NULL;
200 BN_CTX *ctx=NULL;
201 BIGNUM *prime=NULL,*a=NULL,*b=NULL,*x=NULL,*order=NULL;
202 int ok=0;
203
204 if ((ctx = BN_CTX_new()) == NULL) goto bn_err;
205 if ((prime = BN_new()) == NULL || (a = BN_new()) == NULL || (b = BN_new()) == NULL ||
206 (x = BN_new()) == NULL || (order = BN_new()) == NULL) goto bn_err;
207
208 if (!BN_hex2bn(&prime, prime_in)) goto bn_err;
209 if (!BN_hex2bn(&a, a_in)) goto bn_err;
210 if (!BN_hex2bn(&b, b_in)) goto bn_err;
211
212 if ((group = EC_GROUP_new_curve_GFp(prime, a, b, ctx)) == NULL) goto err;
213 if ((P = EC_POINT_new(group)) == NULL) goto err;
214
215 if (!BN_hex2bn(&x, x_in)) goto bn_err;
216 if (!EC_POINT_set_compressed_coordinates_GFp(group, P, x, y_bit, ctx)) goto err;
217 if (!BN_hex2bn(&order, order_in)) goto bn_err;
9bc44854
BM
218 if (!BN_set_word(x, cofac_in)) goto bn_err;
219 if (!EC_GROUP_set_generator(group, P, order, x)) goto err;
945e15a2
BM
220 ok=1;
221bn_err:
222 if (!ok)
60d8bae3 223 ECerr(EC_F_EC_GROUP_NEW_GFP_FROM_HEX, ERR_R_BN_LIB);
945e15a2
BM
224err:
225 if (!ok)
226 {
227 EC_GROUP_free(group);
228 group = NULL;
229 }
230 if (P) EC_POINT_free(P);
231 if (ctx) BN_CTX_free(ctx);
232 if (prime) BN_free(prime);
233 if (a) BN_free(a);
234 if (b) BN_free(b);
235 if (order) BN_free(order);
236 if (x) BN_free(x);
237 return(group);
60d8bae3 238 }
945e15a2 239
60d8bae3 240EC_GROUP *EC_GROUP_new_by_name(int name)
945e15a2
BM
241 {
242 EC_GROUP *ret = NULL;
243 switch (name)
244 {
245 case EC_GROUP_NO_CURVE:
246 return NULL;
9bc44854
BM
247 /* some nist curves */
248 case EC_GROUP_NIST_PRIME_224: /* EC_GROUP_NIST_PRIME_224 == EC_GROUP_SECG_PRIME_224R1 */
249 ret = ec_group_new_GFp_from_hex(_EC_GROUP_NIST_PRIME_224);
250 break;
945e15a2 251
9bc44854
BM
252 case EC_GROUP_NIST_PRIME_384: /* EC_GROUP_NIST_PRIME_384 == EC_GROUP_SECG_PRIME_384R1 */
253 ret = ec_group_new_GFp_from_hex(_EC_GROUP_NIST_PRIME_384);
254 break;
945e15a2 255
9bc44854
BM
256 case EC_GROUP_NIST_PRIME_521: /* EC_GROUP_NIST_PRIME_521 == EC_GROUP_SECG_PRIME_521R1 */
257 ret = ec_group_new_GFp_from_hex(_EC_GROUP_NIST_PRIME_521);
258 break;
259 /* x9.62 prime curves */
260 case EC_GROUP_NIST_PRIME_192: /* EC_GROUP_NIST_PRIME_192 == EC_GROUP_SECG_PRIME_192R1 */
945e15a2 261 case EC_GROUP_X9_62_PRIME_192V1:
9bc44854
BM
262 ret = ec_group_new_GFp_from_hex(_EC_GROUP_NIST_PRIME_192);
263 break;
945e15a2
BM
264
265 case EC_GROUP_X9_62_PRIME_192V2:
9bc44854
BM
266 ret = ec_group_new_GFp_from_hex(_EC_GROUP_X9_62_PRIME_192V2);
267 break;
945e15a2
BM
268
269 case EC_GROUP_X9_62_PRIME_192V3:
9bc44854
BM
270 ret = ec_group_new_GFp_from_hex(_EC_GROUP_X9_62_PRIME_192V3);
271 break;
945e15a2
BM
272
273 case EC_GROUP_X9_62_PRIME_239V1:
9bc44854
BM
274 ret = ec_group_new_GFp_from_hex(_EC_GROUP_X9_62_PRIME_239V1);
275 break;
945e15a2
BM
276
277 case EC_GROUP_X9_62_PRIME_239V2:
9bc44854
BM
278 ret = ec_group_new_GFp_from_hex(_EC_GROUP_X9_62_PRIME_239V2);
279 break;
945e15a2
BM
280
281 case EC_GROUP_X9_62_PRIME_239V3:
9bc44854
BM
282 ret = ec_group_new_GFp_from_hex(_EC_GROUP_X9_62_PRIME_239V3);
283 break;
945e15a2 284
9bc44854 285 case EC_GROUP_NIST_PRIME_256: /* EC_GROUP_NIST_PRIME_256 == EC_GROUP_SECG_PRIME_256R1 */
945e15a2 286 case EC_GROUP_X9_62_PRIME_256V1:
9bc44854
BM
287 ret = ec_group_new_GFp_from_hex(_EC_GROUP_X9_62_PRIME_256V1);
288 break;
289 /* the remaining secg curves */
290 case EC_GROUP_SECG_PRIME_112R1:
291 ret = ec_group_new_GFp_from_hex(_EC_GROUP_SECG_PRIME_112R1);
292 break;
293 case EC_GROUP_SECG_PRIME_112R2:
294 ret = ec_group_new_GFp_from_hex(_EC_GROUP_SECG_PRIME_112R2);
295 break;
296 case EC_GROUP_SECG_PRIME_128R1:
297 ret = ec_group_new_GFp_from_hex(_EC_GROUP_SECG_PRIME_128R1);
298 break;
299 case EC_GROUP_SECG_PRIME_128R2:
300 ret = ec_group_new_GFp_from_hex(_EC_GROUP_SECG_PRIME_128R2);
301 break;
302 case EC_GROUP_SECG_PRIME_160K1:
303 ret = ec_group_new_GFp_from_hex(_EC_GROUP_SECG_PRIME_160K1);
304 break;
305 case EC_GROUP_SECG_PRIME_160R1:
306 ret = ec_group_new_GFp_from_hex(_EC_GROUP_SECG_PRIME_160R1);
307 break;
308 case EC_GROUP_SECG_PRIME_160R2:
309 ret = ec_group_new_GFp_from_hex(_EC_GROUP_SECG_PRIME_160R2);
310 break;
311 case EC_GROUP_SECG_PRIME_192K1:
312 ret = ec_group_new_GFp_from_hex(_EC_GROUP_SECG_PRIME_192K1);
313 break;
314 case EC_GROUP_SECG_PRIME_224K1:
315 ret = ec_group_new_GFp_from_hex(_EC_GROUP_SECG_PRIME_224K1);
316 break;
317 case EC_GROUP_SECG_PRIME_256K1:
318 ret = ec_group_new_GFp_from_hex(_EC_GROUP_SECG_PRIME_256K1);
319 break;
60d8bae3 320
9bc44854
BM
321 }
322 if (ret == NULL)
60d8bae3 323 {
9bc44854
BM
324 ECerr(EC_F_EC_GROUP_NEW_BY_NAME, EC_R_UNKNOWN_GROUP);
325 return NULL;
60d8bae3 326 }
9bc44854
BM
327 EC_GROUP_set_nid(ret, name);
328 return ret;
60d8bae3
BM
329 }
330
331
9bc44854 332EC_GROUP *EC_GROUP_new_by_nid(int nid)
60d8bae3 333 {
9bc44854 334 return EC_GROUP_new_by_name(nid);
60d8bae3 335 }