pcpngrsamontstuff.h 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229
  1. /*
  2. * Copyright (C) 2016 Intel Corporation. All rights reserved.
  3. *
  4. * Redistribution and use in source and binary forms, with or without
  5. * modification, are permitted provided that the following conditions
  6. * are met:
  7. *
  8. * * Redistributions of source code must retain the above copyright
  9. * notice, this list of conditions and the following disclaimer.
  10. * * Redistributions in binary form must reproduce the above copyright
  11. * notice, this list of conditions and the following disclaimer in
  12. * the documentation and/or other materials provided with the
  13. * distribution.
  14. * * Neither the name of Intel Corporation nor the names of its
  15. * contributors may be used to endorse or promote products derived
  16. * from this software without specific prior written permission.
  17. *
  18. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
  19. * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
  20. * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
  21. * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
  22. * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  23. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
  24. * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
  25. * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
  26. * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
  27. * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
  28. * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  29. *
  30. */
  31. #if !defined(_CP_NG_RSA_MONT_STUFF_H)
  32. #define _CP_NG_RSA_MONT_STUFF_H
  33. #include "pcpbn.h"
  34. #include "pcpmontgomery.h"
  35. /*
  36. // Montgomery engine preparation (GetSize/init/Set)
  37. */
  38. void gsMontGetSize(IppsExpMethod method, int length, int* pSize);
  39. void gsMontInit(IppsExpMethod method, int length, IppsMontState* pCtx);
  40. void gsMontSet(const Ipp32u* pModulo, int size, IppsMontState* pCtx);
  41. /*
  42. // optimal size of fixed window exponentiation
  43. */
  44. __INLINE cpSize gsMontExp_WinSize(cpSize bitsize)
  45. {
  46. return
  47. bitsize> 4096? 6 : /* 4096- .. . */
  48. bitsize> 2666? 5 : /* 2666 - 4095 */
  49. bitsize> 717? 4 : /* 717 - 2665 */
  50. bitsize> 178? 3 : /* 178 - 716 */
  51. bitsize> 41? 2 : 1; /* 41 - 177 */
  52. }
  53. /*
  54. // Montgomery encoding/decoding
  55. */
  56. __INLINE cpSize gsMontEnc_BNU(BNU_CHUNK_T* pR,
  57. const BNU_CHUNK_T* pXreg, cpSize nsX,
  58. const IppsMontState* pMont,
  59. BNU_CHUNK_T* pBuffer)
  60. {
  61. cpSize nsM = MNT_SIZE(pMont);
  62. BNU_CHUNK_T* pProduct = pBuffer;
  63. BNU_CHUNK_T* pBufferKmul = NULL;
  64. cpMontMul_BNU(pR,
  65. pXreg, nsX, MNT_SQUARE_R(pMont), nsM,
  66. MNT_MODULUS(pMont), nsM, MNT_HELPER(pMont),
  67. pProduct, pBufferKmul);
  68. return nsM;
  69. }
  70. __INLINE cpSize gsMontDec_BNU(BNU_CHUNK_T* pR,
  71. const BNU_CHUNK_T* pXmont, cpSize nsX,
  72. const IppsMontState* pMont,
  73. BNU_CHUNK_T* pBuffer)
  74. {
  75. cpSize nsM = MNT_SIZE(pMont);
  76. ZEXPAND_COPY_BNU(pBuffer, 2*nsM, pXmont, nsX);
  77. cpMontRed_BNU(pR, pBuffer, MNT_MODULUS(pMont), nsM, MNT_HELPER(pMont));
  78. return nsM;
  79. }
  80. __INLINE void gsMontEnc_BN(IppsBigNumState* pRbn,
  81. const IppsBigNumState* pXbn,
  82. const IppsMontState* pMont,
  83. BNU_CHUNK_T* pBuffer)
  84. {
  85. BNU_CHUNK_T* pR = BN_NUMBER(pRbn);
  86. cpSize nsM = MNT_SIZE(pMont);
  87. gsMontEnc_BNU(pR, BN_NUMBER(pXbn), BN_SIZE(pXbn), pMont, pBuffer);
  88. FIX_BNU(pR, nsM);
  89. BN_SIZE(pRbn) = nsM;
  90. BN_SIGN(pRbn) = ippBigNumPOS;
  91. }
  92. __INLINE void gsMontDec_BN(IppsBigNumState* pRbn,
  93. const IppsBigNumState* pXbn,
  94. const IppsMontState* pMont,
  95. BNU_CHUNK_T* pBuffer)
  96. {
  97. BNU_CHUNK_T* pR = BN_NUMBER(pRbn);
  98. cpSize nsM = MNT_SIZE(pMont);
  99. gsMontDec_BNU(pR, BN_NUMBER(pXbn), BN_SIZE(pXbn), pMont, pBuffer);
  100. FIX_BNU(pR, nsM);
  101. BN_SIZE(pRbn) = nsM;
  102. BN_SIGN(pRbn) = ippBigNumPOS;
  103. }
  104. /*
  105. // binary montgomery exponentiation ("fast" version)
  106. */
  107. cpSize gsMontExpBin_BNU(BNU_CHUNK_T* dataY,
  108. const BNU_CHUNK_T* dataX, cpSize nsX,
  109. const BNU_CHUNK_T* dataE, cpSize nsE,
  110. const IppsMontState* pMont,
  111. BNU_CHUNK_T* pBuffer);
  112. __INLINE void gsMontExpBin_BN(IppsBigNumState* pY,
  113. const IppsBigNumState* pX,
  114. const BNU_CHUNK_T* dataE, cpSize nsE,
  115. const IppsMontState* pMont,
  116. BNU_CHUNK_T* pBuffer)
  117. {
  118. BNU_CHUNK_T* dataY = BN_NUMBER(pY);
  119. cpSize nsY = gsMontExpBin_BNU(dataY,
  120. BN_NUMBER(pX), BN_SIZE(pX),
  121. dataE, nsE,
  122. pMont, pBuffer);
  123. FIX_BNU(dataY, nsY);
  124. BN_SIZE(pY) = nsY;
  125. BN_SIGN(pY) = ippBigNumPOS;
  126. }
  127. /*
  128. // fixed-size window montgomery exponentiation ("fast" version)
  129. */
  130. cpSize gsMontExpWin_BNU(BNU_CHUNK_T* pY,
  131. const BNU_CHUNK_T* pX, cpSize nsX,
  132. const BNU_CHUNK_T* dataE, cpSize nsE, cpSize bitsieW,
  133. const IppsMontState* pMont,
  134. BNU_CHUNK_T* pBuffer);
  135. __INLINE void gsMontExpWin_BN(IppsBigNumState* pY,
  136. const IppsBigNumState* pX,
  137. const BNU_CHUNK_T* dataE, cpSize nsE, cpSize bitsieW,
  138. const IppsMontState* pMont,
  139. BNU_CHUNK_T* pBuffer)
  140. {
  141. BNU_CHUNK_T* dataY = BN_NUMBER(pY);
  142. cpSize nsY = gsMontExpWin_BNU(dataY,
  143. BN_NUMBER(pX), BN_SIZE(pX),
  144. dataE, nsE, bitsieW,
  145. pMont, pBuffer);
  146. FIX_BNU(dataY, nsY);
  147. BN_SIZE(pY) = nsY;
  148. BN_SIGN(pY) = ippBigNumPOS;
  149. }
  150. /*
  151. // binary montgomery exponentiation ("safe" version)
  152. */
  153. __INLINE cpSize gsPrecompResourcelen(int n, cpSize nsM)
  154. {
  155. cpSize nsR = sizeof(BNU_CHUNK_T)*nsM*n + (CACHE_LINE_SIZE-1);
  156. nsR /=CACHE_LINE_SIZE; /* num of cashe lines */
  157. nsR *= (CACHE_LINE_SIZE/sizeof(BNU_CHUNK_T));
  158. return nsR;
  159. }
  160. cpSize gsMontExpBin_BNU_sscm(BNU_CHUNK_T* pY,
  161. const BNU_CHUNK_T* pX, cpSize nsX,
  162. const BNU_CHUNK_T* pE, cpSize nsE,
  163. const IppsMontState* pMont,
  164. BNU_CHUNK_T* pBuffer);
  165. __INLINE void gsMontExpBin_BN_sscm(IppsBigNumState* pY,
  166. const IppsBigNumState* pX,
  167. const BNU_CHUNK_T* dataE, cpSize nsE,
  168. const IppsMontState* pMont,
  169. BNU_CHUNK_T* pBuffer)
  170. {
  171. BNU_CHUNK_T* dataY = BN_NUMBER(pY);
  172. cpSize nsY = gsMontExpBin_BNU_sscm(dataY,
  173. BN_NUMBER(pX), BN_SIZE(pX),
  174. dataE, nsE,
  175. pMont, pBuffer);
  176. FIX_BNU(dataY, nsY);
  177. BN_SIZE(pY) = nsY;
  178. BN_SIGN(pY) = ippBigNumPOS;
  179. }
  180. /*
  181. // fixed-size window montgomery exponentiation ("safe" version)
  182. */
  183. cpSize gsMontExpWin_BNU_sscm(BNU_CHUNK_T* dataY,
  184. const BNU_CHUNK_T* dataX, cpSize nsX,
  185. const BNU_CHUNK_T* dataE, cpSize nsE, cpSize bitsieEwin,
  186. const IppsMontState* pMont,
  187. BNU_CHUNK_T* pBuffer);
  188. __INLINE void gsMontExpWin_BN_sscm(IppsBigNumState* pY,
  189. const IppsBigNumState* pX,
  190. const BNU_CHUNK_T* dataE, cpSize nsE, cpSize bitsieEwin,
  191. const IppsMontState* pMont,
  192. BNU_CHUNK_T* pBuffer)
  193. {
  194. BNU_CHUNK_T* dataY = BN_NUMBER(pY);
  195. cpSize nsY = gsMontExpWin_BNU_sscm(dataY,
  196. BN_NUMBER(pX), BN_SIZE(pX),
  197. dataE, nsE, bitsieEwin,
  198. pMont, pBuffer);
  199. FIX_BNU(dataY, nsY);
  200. BN_SIZE(pY) = nsY;
  201. BN_SIGN(pY) = ippBigNumPOS;
  202. }
  203. #endif /* _CP_NG_RSA_MONT_STUFF_H */