2022-08-09 12:45:47 +02:00
|
|
|
/*
|
2022-08-19 13:09:17 +02:00
|
|
|
* Core bignum functions
|
2022-08-09 12:45:47 +02:00
|
|
|
*
|
|
|
|
* Copyright The Mbed TLS Contributors
|
|
|
|
* SPDX-License-Identifier: Apache-2.0
|
|
|
|
*
|
|
|
|
* Licensed under the Apache License, Version 2.0 (the "License"); you may
|
|
|
|
* not use this file except in compliance with the License.
|
|
|
|
* You may obtain a copy of the License at
|
|
|
|
*
|
|
|
|
* http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
*
|
|
|
|
* Unless required by applicable law or agreed to in writing, software
|
|
|
|
* distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
|
|
|
|
* WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
* See the License for the specific language governing permissions and
|
|
|
|
* limitations under the License.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include "common.h"
|
|
|
|
|
|
|
|
#if defined(MBEDTLS_BIGNUM_C)
|
|
|
|
|
|
|
|
#include <string.h>
|
|
|
|
|
|
|
|
#include "mbedtls/error.h"
|
|
|
|
#include "mbedtls/platform_util.h"
|
|
|
|
|
|
|
|
#if defined(MBEDTLS_PLATFORM_C)
|
|
|
|
#include "mbedtls/platform.h"
|
|
|
|
#else
|
|
|
|
#include <stdio.h>
|
|
|
|
#include <stdlib.h>
|
|
|
|
#define mbedtls_printf printf
|
|
|
|
#define mbedtls_calloc calloc
|
|
|
|
#define mbedtls_free free
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#include "bignum_core.h"
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
size_t mbedtls_mpi_core_clz( const mbedtls_mpi_uint a )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
|
|
|
size_t j;
|
|
|
|
mbedtls_mpi_uint mask = (mbedtls_mpi_uint) 1 << (biL - 1);
|
|
|
|
|
|
|
|
for( j = 0; j < biL; j++ )
|
|
|
|
{
|
2022-08-19 13:24:40 +02:00
|
|
|
if( a & mask ) break;
|
2022-08-09 12:45:47 +02:00
|
|
|
|
|
|
|
mask >>= 1;
|
|
|
|
}
|
|
|
|
|
2022-08-12 15:36:56 +02:00
|
|
|
return( j );
|
2022-08-09 12:45:47 +02:00
|
|
|
}
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
size_t mbedtls_mpi_core_bitlen( const mbedtls_mpi_uint *A, size_t A_limbs )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
|
|
|
size_t i, j;
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
if( A_limbs == 0 )
|
2022-08-09 12:45:47 +02:00
|
|
|
return( 0 );
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
for( i = A_limbs - 1; i > 0; i-- )
|
|
|
|
if( A[i] != 0 )
|
2022-08-09 12:45:47 +02:00
|
|
|
break;
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
j = biL - mbedtls_mpi_core_clz( A[i] );
|
2022-08-09 12:45:47 +02:00
|
|
|
|
|
|
|
return( ( i * biL ) + j );
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Convert a big-endian byte array aligned to the size of mbedtls_mpi_uint
|
|
|
|
* into the storage form used by mbedtls_mpi. */
|
2022-08-19 13:24:40 +02:00
|
|
|
static mbedtls_mpi_uint mpi_bigendian_to_host_c( mbedtls_mpi_uint a )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
|
|
|
uint8_t i;
|
2022-08-19 13:24:40 +02:00
|
|
|
unsigned char *a_ptr;
|
2022-08-09 12:45:47 +02:00
|
|
|
mbedtls_mpi_uint tmp = 0;
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
for( i = 0, a_ptr = (unsigned char *) &a; i < ciL; i++, a_ptr++ )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
|
|
|
tmp <<= CHAR_BIT;
|
2022-08-19 13:24:40 +02:00
|
|
|
tmp |= (mbedtls_mpi_uint) *a_ptr;
|
2022-08-09 12:45:47 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
return( tmp );
|
|
|
|
}
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
static mbedtls_mpi_uint mpi_bigendian_to_host( mbedtls_mpi_uint a )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
|
|
|
#if defined(__BYTE_ORDER__)
|
|
|
|
|
|
|
|
/* Nothing to do on bigendian systems. */
|
|
|
|
#if ( __BYTE_ORDER__ == __ORDER_BIG_ENDIAN__ )
|
2022-08-19 13:24:40 +02:00
|
|
|
return( a );
|
2022-08-09 12:45:47 +02:00
|
|
|
#endif /* __BYTE_ORDER__ == __ORDER_BIG_ENDIAN__ */
|
|
|
|
|
|
|
|
#if ( __BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__ )
|
|
|
|
|
|
|
|
/* For GCC and Clang, have builtins for byte swapping. */
|
|
|
|
#if defined(__GNUC__) && defined(__GNUC_PREREQ)
|
|
|
|
#if __GNUC_PREREQ(4,3)
|
|
|
|
#define have_bswap
|
|
|
|
#endif
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#if defined(__clang__) && defined(__has_builtin)
|
|
|
|
#if __has_builtin(__builtin_bswap32) && \
|
|
|
|
__has_builtin(__builtin_bswap64)
|
|
|
|
#define have_bswap
|
|
|
|
#endif
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#if defined(have_bswap)
|
|
|
|
/* The compiler is hopefully able to statically evaluate this! */
|
|
|
|
switch( sizeof(mbedtls_mpi_uint) )
|
|
|
|
{
|
|
|
|
case 4:
|
2022-08-19 13:24:40 +02:00
|
|
|
return( __builtin_bswap32(a) );
|
2022-08-09 12:45:47 +02:00
|
|
|
case 8:
|
2022-08-19 13:24:40 +02:00
|
|
|
return( __builtin_bswap64(a) );
|
2022-08-09 12:45:47 +02:00
|
|
|
}
|
|
|
|
#endif
|
|
|
|
#endif /* __BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__ */
|
|
|
|
#endif /* __BYTE_ORDER__ */
|
|
|
|
|
|
|
|
/* Fall back to C-based reordering if we don't know the byte order
|
|
|
|
* or we couldn't use a compiler-specific builtin. */
|
2022-08-19 13:24:40 +02:00
|
|
|
return( mpi_bigendian_to_host_c( a ) );
|
2022-08-09 12:45:47 +02:00
|
|
|
}
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
void mbedtls_mpi_core_bigendian_to_host( mbedtls_mpi_uint *A,
|
2022-08-22 11:01:27 +02:00
|
|
|
size_t A_limbs )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
|
|
|
mbedtls_mpi_uint *cur_limb_left;
|
|
|
|
mbedtls_mpi_uint *cur_limb_right;
|
2022-08-22 11:01:27 +02:00
|
|
|
if( A_limbs == 0 )
|
2022-08-09 12:45:47 +02:00
|
|
|
return;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Traverse limbs and
|
|
|
|
* - adapt byte-order in each limb
|
|
|
|
* - swap the limbs themselves.
|
|
|
|
* For that, simultaneously traverse the limbs from left to right
|
|
|
|
* and from right to left, as long as the left index is not bigger
|
|
|
|
* than the right index (it's not a problem if limbs is odd and the
|
|
|
|
* indices coincide in the last iteration).
|
|
|
|
*/
|
2022-08-22 11:01:27 +02:00
|
|
|
for( cur_limb_left = A, cur_limb_right = A + ( A_limbs - 1 );
|
2022-08-09 12:45:47 +02:00
|
|
|
cur_limb_left <= cur_limb_right;
|
|
|
|
cur_limb_left++, cur_limb_right-- )
|
|
|
|
{
|
|
|
|
mbedtls_mpi_uint tmp;
|
|
|
|
/* Note that if cur_limb_left == cur_limb_right,
|
|
|
|
* this code effectively swaps the bytes only once. */
|
|
|
|
tmp = mpi_bigendian_to_host( *cur_limb_left );
|
|
|
|
*cur_limb_left = mpi_bigendian_to_host( *cur_limb_right );
|
|
|
|
*cur_limb_right = tmp;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
int mbedtls_mpi_core_read_le( mbedtls_mpi_uint *X,
|
2022-08-19 13:24:40 +02:00
|
|
|
size_t X_limbs,
|
|
|
|
const unsigned char *input,
|
|
|
|
size_t input_length )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
2022-08-19 13:24:40 +02:00
|
|
|
const size_t limbs = CHARS_TO_LIMBS( input_length );
|
2022-08-09 12:45:47 +02:00
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
if( X_limbs < limbs )
|
2022-08-11 17:13:53 +02:00
|
|
|
return( MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL );
|
|
|
|
|
|
|
|
if( X != NULL )
|
2022-08-12 14:11:56 +02:00
|
|
|
{
|
2022-08-19 13:24:40 +02:00
|
|
|
memset( X, 0, X_limbs * ciL );
|
2022-08-09 12:45:47 +02:00
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
for( size_t i = 0; i < input_length; i++ )
|
2022-08-19 13:05:28 +02:00
|
|
|
{
|
|
|
|
size_t offset = ( ( i % ciL ) << 3 );
|
|
|
|
X[i / ciL] |= ( (mbedtls_mpi_uint) input[i] ) << offset;
|
|
|
|
}
|
2022-08-12 14:11:56 +02:00
|
|
|
}
|
2022-08-09 12:45:47 +02:00
|
|
|
|
2022-08-11 17:13:53 +02:00
|
|
|
return( 0 );
|
2022-08-09 12:45:47 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
int mbedtls_mpi_core_read_be( mbedtls_mpi_uint *X,
|
2022-08-19 13:24:40 +02:00
|
|
|
size_t X_limbs,
|
|
|
|
const unsigned char *input,
|
|
|
|
size_t input_length )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
2022-08-19 13:24:40 +02:00
|
|
|
const size_t limbs = CHARS_TO_LIMBS( input_length );
|
2022-08-09 12:45:47 +02:00
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
if( X_limbs < limbs )
|
2022-08-11 17:13:53 +02:00
|
|
|
return( MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL );
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
/* If X_limbs is 0, input_length must also be 0 (from previous test).
|
|
|
|
* Nothing to do. */
|
|
|
|
if( X_limbs == 0 )
|
2022-08-12 17:47:39 +02:00
|
|
|
return( 0 );
|
2022-08-09 12:45:47 +02:00
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
memset( X, 0, X_limbs * ciL );
|
2022-08-09 12:45:47 +02:00
|
|
|
|
2022-08-12 17:47:39 +02:00
|
|
|
/* memcpy() with (NULL, 0) is undefined behaviour */
|
2022-08-19 13:24:40 +02:00
|
|
|
if( input_length != 0 )
|
2022-08-12 17:47:39 +02:00
|
|
|
{
|
2022-08-19 13:24:40 +02:00
|
|
|
size_t overhead = ( X_limbs * ciL ) - input_length;
|
2022-08-12 17:47:39 +02:00
|
|
|
unsigned char *Xp = (unsigned char *) X;
|
2022-08-19 13:24:40 +02:00
|
|
|
memcpy( Xp + overhead, input, input_length );
|
2022-08-09 12:45:47 +02:00
|
|
|
}
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
mbedtls_mpi_core_bigendian_to_host( X, X_limbs );
|
2022-08-12 17:47:39 +02:00
|
|
|
|
2022-08-11 17:13:53 +02:00
|
|
|
return( 0 );
|
2022-08-09 12:45:47 +02:00
|
|
|
}
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
int mbedtls_mpi_core_write_le( const mbedtls_mpi_uint *A,
|
|
|
|
size_t A_limbs,
|
|
|
|
unsigned char *output,
|
|
|
|
size_t output_length )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
2022-08-19 13:24:40 +02:00
|
|
|
size_t stored_bytes = A_limbs * ciL;
|
2022-08-09 12:45:47 +02:00
|
|
|
size_t bytes_to_copy;
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
if( stored_bytes < output_length )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
|
|
|
bytes_to_copy = stored_bytes;
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2022-08-19 13:24:40 +02:00
|
|
|
bytes_to_copy = output_length;
|
2022-08-09 12:45:47 +02:00
|
|
|
|
2022-08-22 10:06:32 +02:00
|
|
|
/* The output buffer is smaller than the allocated size of A.
|
2022-08-19 13:24:40 +02:00
|
|
|
* However A may fit if its leading bytes are zero. */
|
2022-08-15 13:08:49 +02:00
|
|
|
for( size_t i = bytes_to_copy; i < stored_bytes; i++ )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
2022-08-19 13:24:40 +02:00
|
|
|
if( GET_BYTE( A, i ) != 0 )
|
2022-08-09 12:45:47 +02:00
|
|
|
return( MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL );
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-08-15 13:08:49 +02:00
|
|
|
for( size_t i = 0; i < bytes_to_copy; i++ )
|
2022-08-19 13:24:40 +02:00
|
|
|
output[i] = GET_BYTE( A, i );
|
2022-08-09 12:45:47 +02:00
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
if( stored_bytes < output_length )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
|
|
|
/* Write trailing 0 bytes */
|
2022-08-19 13:24:40 +02:00
|
|
|
memset( output + stored_bytes, 0, output_length - stored_bytes );
|
2022-08-09 12:45:47 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
return( 0 );
|
|
|
|
}
|
|
|
|
|
|
|
|
int mbedtls_mpi_core_write_be( const mbedtls_mpi_uint *X,
|
2022-08-19 13:24:40 +02:00
|
|
|
size_t X_limbs,
|
|
|
|
unsigned char *output,
|
|
|
|
size_t output_length )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
|
|
|
size_t stored_bytes;
|
|
|
|
size_t bytes_to_copy;
|
|
|
|
unsigned char *p;
|
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
stored_bytes = X_limbs * ciL;
|
2022-08-09 12:45:47 +02:00
|
|
|
|
2022-08-19 13:24:40 +02:00
|
|
|
if( stored_bytes < output_length )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
2022-08-22 10:06:32 +02:00
|
|
|
/* There is enough space in the output buffer. Write initial
|
2022-08-09 12:45:47 +02:00
|
|
|
* null bytes and record the position at which to start
|
|
|
|
* writing the significant bytes. In this case, the execution
|
|
|
|
* trace of this function does not depend on the value of the
|
|
|
|
* number. */
|
|
|
|
bytes_to_copy = stored_bytes;
|
2022-08-19 13:24:40 +02:00
|
|
|
p = output + output_length - stored_bytes;
|
|
|
|
memset( output, 0, output_length - stored_bytes );
|
2022-08-09 12:45:47 +02:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2022-08-22 10:06:32 +02:00
|
|
|
/* The output buffer is smaller than the allocated size of X.
|
2022-08-09 12:45:47 +02:00
|
|
|
* However X may fit if its leading bytes are zero. */
|
2022-08-19 13:24:40 +02:00
|
|
|
bytes_to_copy = output_length;
|
|
|
|
p = output;
|
2022-08-15 13:08:49 +02:00
|
|
|
for( size_t i = bytes_to_copy; i < stored_bytes; i++ )
|
2022-08-09 12:45:47 +02:00
|
|
|
{
|
|
|
|
if( GET_BYTE( X, i ) != 0 )
|
|
|
|
return( MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL );
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-08-15 13:08:49 +02:00
|
|
|
for( size_t i = 0; i < bytes_to_copy; i++ )
|
2022-08-09 12:45:47 +02:00
|
|
|
p[bytes_to_copy - i - 1] = GET_BYTE( X, i );
|
|
|
|
|
|
|
|
return( 0 );
|
|
|
|
}
|
|
|
|
|
|
|
|
#endif /* MBEDTLS_BIGNUM_C */
|