/** * @file ed448goldilocks/eddsa.c * @author Mike Hamburg * * @copyright * Copyright (c) 2015-2016 Cryptography Research, Inc. \n * Released under the MIT License. See LICENSE.txt for license information. * * @cond internal * @brief EdDSA routines. * * @warning This file was automatically generated in Python. * Please do not edit it. */ #include #include "word.h" #include "ed448.h" #include "shake.h" #include #define API_NAME "decaf_448" #define hash_ctx_t decaf_shake256_ctx_t #define hash_init decaf_shake256_init #define hash_update decaf_shake256_update #define hash_final decaf_shake256_final #define hash_destroy decaf_shake256_destroy #define hash_hash decaf_shake256_hash #define NO_CONTEXT DECAF_EDDSA_448_SUPPORTS_CONTEXTLESS_SIGS #define EDDSA_USE_SIGMA_ISOGENY 0 #define COFACTOR 4 #define EDDSA_PREHASH_BYTES 64 #if NO_CONTEXT const uint8_t NO_CONTEXT_POINTS_HERE = 0; const uint8_t * const DECAF_ED448_NO_CONTEXT = &NO_CONTEXT_POINTS_HERE; #endif /* EDDSA_BASE_POINT_RATIO = 1 or 2 * Because EdDSA25519 is not on E_d but on the isogenous E_sigma_d, * its base point is twice ours. */ #define EDDSA_BASE_POINT_RATIO (1+EDDSA_USE_SIGMA_ISOGENY) /* TODO: remove */ static void clamp ( uint8_t secret_scalar_ser[DECAF_EDDSA_448_PRIVATE_BYTES] ) { /* Blarg */ secret_scalar_ser[0] &= -COFACTOR; uint8_t hibit = (1<<0)>>1; if (hibit == 0) { secret_scalar_ser[DECAF_EDDSA_448_PRIVATE_BYTES - 1] = 0; secret_scalar_ser[DECAF_EDDSA_448_PRIVATE_BYTES - 2] |= 0x80; } else { secret_scalar_ser[DECAF_EDDSA_448_PRIVATE_BYTES - 1] &= hibit-1; secret_scalar_ser[DECAF_EDDSA_448_PRIVATE_BYTES - 1] |= hibit; } } static void hash_init_with_dom( hash_ctx_t hash, uint8_t prehashed, uint8_t for_prehash, const uint8_t *context, uint8_t context_len ) { hash_init(hash); #if NO_CONTEXT if (context_len == 0 && context == DECAF_ED448_NO_CONTEXT) { (void)prehashed; (void)for_prehash; (void)context; (void)context_len; return; } #endif const char *dom_s = "SigEd448"; const uint8_t dom[2] = {2+word_is_zero(prehashed)+word_is_zero(for_prehash), context_len}; hash_update(hash,(const unsigned char *)dom_s, strlen(dom_s)); hash_update(hash,dom,2); hash_update(hash,context,context_len); } void decaf_ed448_prehash_init ( hash_ctx_t hash ) { hash_init(hash); } /* In this file because it uses the hash */ void decaf_ed448_convert_private_key_to_x448 ( uint8_t x[DECAF_X448_PRIVATE_BYTES], const uint8_t ed[DECAF_EDDSA_448_PRIVATE_BYTES] ) { /* pass the private key through hash_hash function */ /* and keep the first DECAF_X448_PRIVATE_BYTES bytes */ hash_hash( x, DECAF_X448_PRIVATE_BYTES, ed, DECAF_EDDSA_448_PRIVATE_BYTES ); } void decaf_ed448_derive_public_key ( uint8_t pubkey[DECAF_EDDSA_448_PUBLIC_BYTES], const uint8_t privkey[DECAF_EDDSA_448_PRIVATE_BYTES] ) { /* only this much used for keygen */ uint8_t secret_scalar_ser[DECAF_EDDSA_448_PRIVATE_BYTES]; hash_hash( secret_scalar_ser, sizeof(secret_scalar_ser), privkey, DECAF_EDDSA_448_PRIVATE_BYTES ); clamp(secret_scalar_ser); curve448_scalar_t secret_scalar; curve448_scalar_decode_long(secret_scalar, secret_scalar_ser, sizeof(secret_scalar_ser)); /* Since we are going to mul_by_cofactor during encoding, divide by it here. * However, the EdDSA base point is not the same as the decaf base point if * the sigma isogeny is in use: the EdDSA base point is on Etwist_d/(1-d) and * the decaf base point is on Etwist_d, and when converted it effectively * picks up a factor of 2 from the isogenies. So we might start at 2 instead of 1. */ for (unsigned int c=1; c