Vitaly Buka | 9ba72a8 | 2015-08-06 17:36:17 -0700 | [diff] [blame] | 1 | // Copyright 2012 The Chromium OS Authors. All rights reserved. |
Vitaly Buka | 6ca6a23 | 2015-08-06 17:32:43 -0700 | [diff] [blame] | 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
Vitaly Buka | 9e5b683 | 2015-10-14 15:57:14 -0700 | [diff] [blame] | 5 | #ifndef LIBWEAVE_THIRD_PARTY_CHROMIUM_P224_H_ |
| 6 | #define LIBWEAVE_THIRD_PARTY_CHROMIUM_P224_H_ |
Vitaly Buka | 6ca6a23 | 2015-08-06 17:32:43 -0700 | [diff] [blame] | 7 | |
| 8 | #include <string> |
| 9 | |
Vitaly Buka | 9ba72a8 | 2015-08-06 17:36:17 -0700 | [diff] [blame] | 10 | #include <base/basictypes.h> |
Vitaly Buka | 6ca6a23 | 2015-08-06 17:32:43 -0700 | [diff] [blame] | 11 | |
| 12 | namespace crypto { |
| 13 | |
| 14 | // P224 implements an elliptic curve group, commonly known as P224 and defined |
| 15 | // in FIPS 186-3, section D.2.2. |
| 16 | namespace p224 { |
| 17 | |
| 18 | // An element of the field (ℤ/pℤ) is represented with 8, 28-bit limbs in |
| 19 | // little endian order. |
| 20 | typedef uint32 FieldElement[8]; |
| 21 | |
Vitaly Buka | 9ba72a8 | 2015-08-06 17:36:17 -0700 | [diff] [blame] | 22 | struct Point { |
Vitaly Buka | 6ca6a23 | 2015-08-06 17:32:43 -0700 | [diff] [blame] | 23 | // SetFromString the value of the point from the 56 byte, external |
| 24 | // representation. The external point representation is an (x, y) pair of a |
| 25 | // point on the curve. Each field element is represented as a big-endian |
| 26 | // number < p. |
Vitaly Buka | 0d50107 | 2015-08-18 18:09:46 -0700 | [diff] [blame] | 27 | bool SetFromString(const std::string& in); |
Vitaly Buka | 6ca6a23 | 2015-08-06 17:32:43 -0700 | [diff] [blame] | 28 | |
| 29 | // ToString returns an external representation of the Point. |
| 30 | std::string ToString() const; |
| 31 | |
| 32 | // An Point is represented in Jacobian form (x/z², y/z³). |
| 33 | FieldElement x, y, z; |
| 34 | }; |
| 35 | |
| 36 | // kScalarBytes is the number of bytes needed to represent an element of the |
| 37 | // P224 field. |
| 38 | static const size_t kScalarBytes = 28; |
| 39 | |
| 40 | // ScalarMult computes *out = in*scalar where scalar is a 28-byte, big-endian |
| 41 | // number. |
Vitaly Buka | 9ba72a8 | 2015-08-06 17:36:17 -0700 | [diff] [blame] | 42 | void ScalarMult(const Point& in, const uint8* scalar, Point* out); |
Vitaly Buka | 6ca6a23 | 2015-08-06 17:32:43 -0700 | [diff] [blame] | 43 | |
| 44 | // ScalarBaseMult computes *out = g*scalar where g is the base point of the |
| 45 | // curve and scalar is a 28-byte, big-endian number. |
Vitaly Buka | 9ba72a8 | 2015-08-06 17:36:17 -0700 | [diff] [blame] | 46 | void ScalarBaseMult(const uint8* scalar, Point* out); |
Vitaly Buka | 6ca6a23 | 2015-08-06 17:32:43 -0700 | [diff] [blame] | 47 | |
| 48 | // Add computes *out = a+b. |
Vitaly Buka | 9ba72a8 | 2015-08-06 17:36:17 -0700 | [diff] [blame] | 49 | void Add(const Point& a, const Point& b, Point* out); |
Vitaly Buka | 6ca6a23 | 2015-08-06 17:32:43 -0700 | [diff] [blame] | 50 | |
| 51 | // Negate calculates out = -a; |
Vitaly Buka | 9ba72a8 | 2015-08-06 17:36:17 -0700 | [diff] [blame] | 52 | void Negate(const Point& a, Point* out); |
Vitaly Buka | 6ca6a23 | 2015-08-06 17:32:43 -0700 | [diff] [blame] | 53 | |
| 54 | } // namespace p224 |
Vitaly Buka | 6ca6a23 | 2015-08-06 17:32:43 -0700 | [diff] [blame] | 55 | } // namespace crypto |
| 56 | |
Vitaly Buka | 9e5b683 | 2015-10-14 15:57:14 -0700 | [diff] [blame] | 57 | #endif // LIBWEAVE_THIRD_PARTY_CHROMIUM_P224_H_ |