ecp 49.5 KB
Newer Older
ROOL's avatar
ROOL committed
1 2 3
/**
 * \file ecp.h
 *
ROOL's avatar
ROOL committed
4 5 6 7 8 9 10 11 12 13 14
 * \brief This file provides an API for Elliptic Curves over GF(P) (ECP).
 *
 * The use of ECP in cryptography and TLS is defined in
 * <em>Standards for Efficient Cryptography Group (SECG): SEC1
 * Elliptic Curve Cryptography</em> and
 * <em>RFC-4492: Elliptic Curve Cryptography (ECC) Cipher Suites
 * for Transport Layer Security (TLS)</em>.
 *
 * <em>RFC-2409: The Internet Key Exchange (IKE)</em> defines ECP
 * group types.
 *
ROOL's avatar
ROOL committed
15
 */
ROOL's avatar
ROOL committed
16

ROOL's avatar
ROOL committed
17
/*
ROOL's avatar
ROOL committed
18
 *  Copyright (C) 2006-2018, Arm Limited (or its affiliates), All Rights Reserved
ROOL's avatar
ROOL committed
19 20 21 22 23 24 25 26 27 28 29 30 31 32
 *  SPDX-License-Identifier: Apache-2.0
 *
 *  Licensed under the Apache License, Version 2.0 (the "License"); you may
 *  not use this file except in compliance with the License.
 *  You may obtain a copy of the License at
 *
 *  http://www.apache.org/licenses/LICENSE-2.0
 *
 *  Unless required by applicable law or agreed to in writing, software
 *  distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
 *  WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 *  See the License for the specific language governing permissions and
 *  limitations under the License.
 *
ROOL's avatar
ROOL committed
33
 *  This file is part of Mbed TLS (https://tls.mbed.org)
ROOL's avatar
ROOL committed
34
 */
ROOL's avatar
ROOL committed
35

ROOL's avatar
ROOL committed
36 37 38
#ifndef MBEDTLS_ECP_H
#define MBEDTLS_ECP_H

ROOL's avatar
ROOL committed
39 40 41 42 43 44
#if !defined(MBEDTLS_CONFIG_FILE)
#include "config.h"
#else
#include MBEDTLS_CONFIG_FILE
#endif

ROOL's avatar
ROOL committed
45 46 47 48 49 50 51
#include "bignum.h"

/*
 * ECP error codes
 */
#define MBEDTLS_ERR_ECP_BAD_INPUT_DATA                    -0x4F80  /**< Bad input parameters to function. */
#define MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL                  -0x4F00  /**< The buffer is too small to write to. */
ROOL's avatar
ROOL committed
52
#define MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE               -0x4E80  /**< The requested feature is not available, for example, the requested curve is not supported. */
ROOL's avatar
ROOL committed
53 54
#define MBEDTLS_ERR_ECP_VERIFY_FAILED                     -0x4E00  /**< The signature is not valid. */
#define MBEDTLS_ERR_ECP_ALLOC_FAILED                      -0x4D80  /**< Memory allocation failed. */
ROOL's avatar
ROOL committed
55
#define MBEDTLS_ERR_ECP_RANDOM_FAILED                     -0x4D00  /**< Generation of random value, such as ephemeral key, failed. */
ROOL's avatar
ROOL committed
56
#define MBEDTLS_ERR_ECP_INVALID_KEY                       -0x4C80  /**< Invalid private or public key. */
ROOL's avatar
ROOL committed
57
#define MBEDTLS_ERR_ECP_SIG_LEN_MISMATCH                  -0x4C00  /**< The buffer contains a valid signature followed by more data. */
ROOL's avatar
ROOL committed
58 59

/* MBEDTLS_ERR_ECP_HW_ACCEL_FAILED is deprecated and should not be used. */
ROOL's avatar
ROOL committed
60
#define MBEDTLS_ERR_ECP_HW_ACCEL_FAILED                   -0x4B80  /**< The ECP hardware accelerator failed. */
ROOL's avatar
ROOL committed
61

ROOL's avatar
ROOL committed
62 63
#define MBEDTLS_ERR_ECP_IN_PROGRESS                       -0x4B00  /**< Operation in progress, call again with the same parameters to continue. */

ROOL's avatar
ROOL committed
64 65 66 67 68
#ifdef __cplusplus
extern "C" {
#endif

/**
ROOL's avatar
ROOL committed
69
 * Domain-parameter identifiers: curve, subgroup, and generator.
ROOL's avatar
ROOL committed
70
 *
ROOL's avatar
ROOL committed
71
 * \note Only curves over prime fields are supported.
ROOL's avatar
ROOL committed
72 73
 *
 * \warning This library does not support validation of arbitrary domain
ROOL's avatar
ROOL committed
74
 * parameters. Therefore, only standardized domain parameters from trusted
ROOL's avatar
ROOL committed
75 76 77 78
 * sources should be used. See mbedtls_ecp_group_load().
 */
typedef enum
{
ROOL's avatar
ROOL committed
79 80 81 82 83 84 85 86 87 88 89 90 91 92
    MBEDTLS_ECP_DP_NONE = 0,       /*!< Curve not defined. */
    MBEDTLS_ECP_DP_SECP192R1,      /*!< Domain parameters for the 192-bit curve defined by FIPS 186-4 and SEC1. */
    MBEDTLS_ECP_DP_SECP224R1,      /*!< Domain parameters for the 224-bit curve defined by FIPS 186-4 and SEC1. */
    MBEDTLS_ECP_DP_SECP256R1,      /*!< Domain parameters for the 256-bit curve defined by FIPS 186-4 and SEC1. */
    MBEDTLS_ECP_DP_SECP384R1,      /*!< Domain parameters for the 384-bit curve defined by FIPS 186-4 and SEC1. */
    MBEDTLS_ECP_DP_SECP521R1,      /*!< Domain parameters for the 521-bit curve defined by FIPS 186-4 and SEC1. */
    MBEDTLS_ECP_DP_BP256R1,        /*!< Domain parameters for 256-bit Brainpool curve. */
    MBEDTLS_ECP_DP_BP384R1,        /*!< Domain parameters for 384-bit Brainpool curve. */
    MBEDTLS_ECP_DP_BP512R1,        /*!< Domain parameters for 512-bit Brainpool curve. */
    MBEDTLS_ECP_DP_CURVE25519,     /*!< Domain parameters for Curve25519. */
    MBEDTLS_ECP_DP_SECP192K1,      /*!< Domain parameters for 192-bit "Koblitz" curve. */
    MBEDTLS_ECP_DP_SECP224K1,      /*!< Domain parameters for 224-bit "Koblitz" curve. */
    MBEDTLS_ECP_DP_SECP256K1,      /*!< Domain parameters for 256-bit "Koblitz" curve. */
    MBEDTLS_ECP_DP_CURVE448,       /*!< Domain parameters for Curve448. */
ROOL's avatar
ROOL committed
93 94 95
} mbedtls_ecp_group_id;

/**
ROOL's avatar
ROOL committed
96
 * The number of supported curves, plus one for #MBEDTLS_ECP_DP_NONE.
ROOL's avatar
ROOL committed
97
 *
ROOL's avatar
ROOL committed
98
 * \note Montgomery curves are currently excluded.
ROOL's avatar
ROOL committed
99 100 101 102
 */
#define MBEDTLS_ECP_DP_MAX     12

/**
ROOL's avatar
ROOL committed
103
 * Curve information, for use by other modules.
ROOL's avatar
ROOL committed
104
 */
ROOL's avatar
ROOL committed
105
typedef struct mbedtls_ecp_curve_info
ROOL's avatar
ROOL committed
106
{
ROOL's avatar
ROOL committed
107 108 109 110
    mbedtls_ecp_group_id grp_id;    /*!< An internal identifier. */
    uint16_t tls_id;                /*!< The TLS NamedCurve identifier. */
    uint16_t bit_size;              /*!< The curve size in bits. */
    const char *name;               /*!< A human-friendly name. */
ROOL's avatar
ROOL committed
111 112 113
} mbedtls_ecp_curve_info;

/**
ROOL's avatar
ROOL committed
114
 * \brief           The ECP point structure, in Jacobian coordinates.
ROOL's avatar
ROOL committed
115 116
 *
 * \note            All functions expect and return points satisfying
ROOL's avatar
ROOL committed
117 118 119 120 121 122
 *                  the following condition: <code>Z == 0</code> or
 *                  <code>Z == 1</code>. Other values of \p Z are
 *                  used only by internal functions.
 *                  The point is zero, or "at infinity", if <code>Z == 0</code>.
 *                  Otherwise, \p X and \p Y are its standard (affine)
 *                  coordinates.
ROOL's avatar
ROOL committed
123
 */
ROOL's avatar
ROOL committed
124
typedef struct mbedtls_ecp_point
ROOL's avatar
ROOL committed
125
{
ROOL's avatar
ROOL committed
126 127 128
    mbedtls_mpi X;          /*!< The X coordinate of the ECP point. */
    mbedtls_mpi Y;          /*!< The Y coordinate of the ECP point. */
    mbedtls_mpi Z;          /*!< The Z coordinate of the ECP point. */
ROOL's avatar
ROOL committed
129 130 131
}
mbedtls_ecp_point;

ROOL's avatar
ROOL committed
132 133 134
#if !defined(MBEDTLS_ECP_ALT)
/*
 * default mbed TLS elliptic curve arithmetic implementation
ROOL's avatar
ROOL committed
135
 *
ROOL's avatar
ROOL committed
136 137 138
 * (in case MBEDTLS_ECP_ALT is defined then the developer has to provide an
 * alternative implementation for the whole module and it will replace this
 * one.)
ROOL's avatar
ROOL committed
139 140 141
 */

/**
ROOL's avatar
ROOL committed
142 143 144 145 146 147 148 149
 * \brief           The ECP group structure.
 *
 * We consider two types of curve equations:
 * <ul><li>Short Weierstrass: <code>y^2 = x^3 + A x + B mod P</code>
 * (SEC1 + RFC-4492)</li>
 * <li>Montgomery: <code>y^2 = x^3 + A x^2 + x mod P</code> (Curve25519,
 * Curve448)</li></ul>
 * In both cases, the generator (\p G) for a prime-order subgroup is fixed.
ROOL's avatar
ROOL committed
150
 *
ROOL's avatar
ROOL committed
151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166
 * For Short Weierstrass, this subgroup is the whole curve, and its
 * cardinality is denoted by \p N. Our code requires that \p N is an
 * odd prime as mbedtls_ecp_mul() requires an odd number, and
 * mbedtls_ecdsa_sign() requires that it is prime for blinding purposes.
 *
 * For Montgomery curves, we do not store \p A, but <code>(A + 2) / 4</code>,
 * which is the quantity used in the formulas. Additionally, \p nbits is
 * not the size of \p N but the required size for private keys.
 *
 * If \p modp is NULL, reduction modulo \p P is done using a generic algorithm.
 * Otherwise, \p modp must point to a function that takes an \p mbedtls_mpi in the
 * range of <code>0..2^(2*pbits)-1</code>, and transforms it in-place to an integer
 * which is congruent mod \p P to the given MPI, and is close enough to \p pbits
 * in size, so that it may be efficiently brought in the 0..P-1 range by a few
 * additions or subtractions. Therefore, it is only an approximative modular
 * reduction. It must return 0 on success and non-zero on failure.
ROOL's avatar
ROOL committed
167
 *
ROOL's avatar
ROOL committed
168 169 170 171
 * \note        Alternative implementations must keep the group IDs distinct. If
 *              two group structures have the same ID, then they must be
 *              identical.
 *
ROOL's avatar
ROOL committed
172
 */
ROOL's avatar
ROOL committed
173
typedef struct mbedtls_ecp_group
ROOL's avatar
ROOL committed
174
{
ROOL's avatar
ROOL committed
175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194
    mbedtls_ecp_group_id id;    /*!< An internal group identifier. */
    mbedtls_mpi P;              /*!< The prime modulus of the base field. */
    mbedtls_mpi A;              /*!< For Short Weierstrass: \p A in the equation. For
                                     Montgomery curves: <code>(A + 2) / 4</code>. */
    mbedtls_mpi B;              /*!< For Short Weierstrass: \p B in the equation.
                                     For Montgomery curves: unused. */
    mbedtls_ecp_point G;        /*!< The generator of the subgroup used. */
    mbedtls_mpi N;              /*!< The order of \p G. */
    size_t pbits;               /*!< The number of bits in \p P.*/
    size_t nbits;               /*!< For Short Weierstrass: The number of bits in \p P.
                                     For Montgomery curves: the number of bits in the
                                     private keys. */
    unsigned int h;             /*!< \internal 1 if the constants are static. */
    int (*modp)(mbedtls_mpi *); /*!< The function for fast pseudo-reduction
                                     mod \p P (see above).*/
    int (*t_pre)(mbedtls_ecp_point *, void *);  /*!< Unused. */
    int (*t_post)(mbedtls_ecp_point *, void *); /*!< Unused. */
    void *t_data;               /*!< Unused. */
    mbedtls_ecp_point *T;       /*!< Pre-computed points for ecp_mul_comb(). */
    size_t T_size;              /*!< The number of pre-computed points. */
ROOL's avatar
ROOL committed
195
}
ROOL's avatar
ROOL committed
196
mbedtls_ecp_group;
ROOL's avatar
ROOL committed
197

ROOL's avatar
ROOL committed
198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259
/**
 * \name SECTION: Module settings
 *
 * The configuration options you can set for this module are in this section.
 * Either change them in config.h, or define them using the compiler command line.
 * \{
 */

#if !defined(MBEDTLS_ECP_MAX_BITS)
/**
 * The maximum size of the groups, that is, of \c N and \c P.
 */
#define MBEDTLS_ECP_MAX_BITS     521   /**< The maximum size of groups, in bits. */
#endif

#define MBEDTLS_ECP_MAX_BYTES    ( ( MBEDTLS_ECP_MAX_BITS + 7 ) / 8 )
#define MBEDTLS_ECP_MAX_PT_LEN   ( 2 * MBEDTLS_ECP_MAX_BYTES + 1 )

#if !defined(MBEDTLS_ECP_WINDOW_SIZE)
/*
 * Maximum "window" size used for point multiplication.
 * Default: 6.
 * Minimum value: 2. Maximum value: 7.
 *
 * Result is an array of at most ( 1 << ( MBEDTLS_ECP_WINDOW_SIZE - 1 ) )
 * points used for point multiplication. This value is directly tied to EC
 * peak memory usage, so decreasing it by one should roughly cut memory usage
 * by two (if large curves are in use).
 *
 * Reduction in size may reduce speed, but larger curves are impacted first.
 * Sample performances (in ECDHE handshakes/s, with FIXED_POINT_OPTIM = 1):
 *      w-size:     6       5       4       3       2
 *      521       145     141     135     120      97
 *      384       214     209     198     177     146
 *      256       320     320     303     262     226
 *      224       475     475     453     398     342
 *      192       640     640     633     587     476
 */
#define MBEDTLS_ECP_WINDOW_SIZE    6   /**< The maximum window size used. */
#endif /* MBEDTLS_ECP_WINDOW_SIZE */

#if !defined(MBEDTLS_ECP_FIXED_POINT_OPTIM)
/*
 * Trade memory for speed on fixed-point multiplication.
 *
 * This speeds up repeated multiplication of the generator (that is, the
 * multiplication in ECDSA signatures, and half of the multiplications in
 * ECDSA verification and ECDHE) by a factor roughly 3 to 4.
 *
 * The cost is increasing EC peak memory usage by a factor roughly 2.
 *
 * Change this value to 0 to reduce peak memory usage.
 */
#define MBEDTLS_ECP_FIXED_POINT_OPTIM  1   /**< Enable fixed-point speed-up. */
#endif /* MBEDTLS_ECP_FIXED_POINT_OPTIM */

/* \} name SECTION: Module settings */

#else  /* MBEDTLS_ECP_ALT */
#include "ecp_alt.h"
#endif /* MBEDTLS_ECP_ALT */

ROOL's avatar
ROOL committed
260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323
#if defined(MBEDTLS_ECP_RESTARTABLE)

/**
 * \brief           Internal restart context for multiplication
 *
 * \note            Opaque struct
 */
typedef struct mbedtls_ecp_restart_mul mbedtls_ecp_restart_mul_ctx;

/**
 * \brief           Internal restart context for ecp_muladd()
 *
 * \note            Opaque struct
 */
typedef struct mbedtls_ecp_restart_muladd mbedtls_ecp_restart_muladd_ctx;

/**
 * \brief           General context for resuming ECC operations
 */
typedef struct
{
    unsigned ops_done;                  /*!<  current ops count             */
    unsigned depth;                     /*!<  call depth (0 = top-level)    */
    mbedtls_ecp_restart_mul_ctx *rsm;   /*!<  ecp_mul_comb() sub-context    */
    mbedtls_ecp_restart_muladd_ctx *ma; /*!<  ecp_muladd() sub-context      */
} mbedtls_ecp_restart_ctx;

/*
 * Operation counts for restartable functions
 */
#define MBEDTLS_ECP_OPS_CHK   3 /*!< basic ops count for ecp_check_pubkey()  */
#define MBEDTLS_ECP_OPS_DBL   8 /*!< basic ops count for ecp_double_jac()    */
#define MBEDTLS_ECP_OPS_ADD  11 /*!< basic ops count for see ecp_add_mixed() */
#define MBEDTLS_ECP_OPS_INV 120 /*!< empirical equivalent for mpi_mod_inv()  */

/**
 * \brief           Internal; for restartable functions in other modules.
 *                  Check and update basic ops budget.
 *
 * \param grp       Group structure
 * \param rs_ctx    Restart context
 * \param ops       Number of basic ops to do
 *
 * \return          \c 0 if doing \p ops basic ops is still allowed,
 * \return          #MBEDTLS_ERR_ECP_IN_PROGRESS otherwise.
 */
int mbedtls_ecp_check_budget( const mbedtls_ecp_group *grp,
                              mbedtls_ecp_restart_ctx *rs_ctx,
                              unsigned ops );

/* Utility macro for checking and updating ops budget */
#define MBEDTLS_ECP_BUDGET( ops )   \
    MBEDTLS_MPI_CHK( mbedtls_ecp_check_budget( grp, rs_ctx, \
                                               (unsigned) (ops) ) );

#else /* MBEDTLS_ECP_RESTARTABLE */

#define MBEDTLS_ECP_BUDGET( ops )   /* no-op; for compatibility */

/* We want to declare restartable versions of existing functions anyway */
typedef void mbedtls_ecp_restart_ctx;

#endif /* MBEDTLS_ECP_RESTARTABLE */

ROOL's avatar
ROOL committed
324 325 326 327 328 329 330 331
/**
 * \brief    The ECP key-pair structure.
 *
 * A generic key-pair that may be used for ECDSA and fixed ECDH, for example.
 *
 * \note    Members are deliberately in the same order as in the
 *          ::mbedtls_ecdsa_context structure.
 */
ROOL's avatar
ROOL committed
332
typedef struct mbedtls_ecp_keypair
ROOL's avatar
ROOL committed
333 334 335 336 337 338 339
{
    mbedtls_ecp_group grp;      /*!<  Elliptic curve and base point     */
    mbedtls_mpi d;              /*!<  our secret value                  */
    mbedtls_ecp_point Q;        /*!<  our public value                  */
}
mbedtls_ecp_keypair;

ROOL's avatar
ROOL committed
340 341 342
/*
 * Point formats, from RFC 4492's enum ECPointFormat
 */
ROOL's avatar
ROOL committed
343 344
#define MBEDTLS_ECP_PF_UNCOMPRESSED    0   /**< Uncompressed point format. */
#define MBEDTLS_ECP_PF_COMPRESSED      1   /**< Compressed point format. */
ROOL's avatar
ROOL committed
345 346 347 348

/*
 * Some other constants from RFC 4492
 */
ROOL's avatar
ROOL committed
349
#define MBEDTLS_ECP_TLS_NAMED_CURVE    3   /**< The named_curve of ECCurveType. */
ROOL's avatar
ROOL committed
350

ROOL's avatar
ROOL committed
351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419
#if defined(MBEDTLS_ECP_RESTARTABLE)
/**
 * \brief           Set the maximum number of basic operations done in a row.
 *
 *                  If more operations are needed to complete a computation,
 *                  #MBEDTLS_ERR_ECP_IN_PROGRESS will be returned by the
 *                  function performing the computation. It is then the
 *                  caller's responsibility to either call again with the same
 *                  parameters until it returns 0 or an error code; or to free
 *                  the restart context if the operation is to be aborted.
 *
 *                  It is strictly required that all input parameters and the
 *                  restart context be the same on successive calls for the
 *                  same operation, but output parameters need not be the
 *                  same; they must not be used until the function finally
 *                  returns 0.
 *
 *                  This only applies to functions whose documentation
 *                  mentions they may return #MBEDTLS_ERR_ECP_IN_PROGRESS (or
 *                  #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS for functions in the
 *                  SSL module). For functions that accept a "restart context"
 *                  argument, passing NULL disables restart and makes the
 *                  function equivalent to the function with the same name
 *                  with \c _restartable removed. For functions in the ECDH
 *                  module, restart is disabled unless the function accepts
 *                  an "ECDH context" argument and
 *                  mbedtls_ecdh_enable_restart() was previously called on
 *                  that context. For function in the SSL module, restart is
 *                  only enabled for specific sides and key exchanges
 *                  (currently only for clients and ECDHE-ECDSA).
 *
 * \param max_ops   Maximum number of basic operations done in a row.
 *                  Default: 0 (unlimited).
 *                  Lower (non-zero) values mean ECC functions will block for
 *                  a lesser maximum amount of time.
 *
 * \note            A "basic operation" is defined as a rough equivalent of a
 *                  multiplication in GF(p) for the NIST P-256 curve.
 *                  As an indication, with default settings, a scalar
 *                  multiplication (full run of \c mbedtls_ecp_mul()) is:
 *                  - about 3300 basic operations for P-256
 *                  - about 9400 basic operations for P-384
 *
 * \note            Very low values are not always respected: sometimes
 *                  functions need to block for a minimum number of
 *                  operations, and will do so even if max_ops is set to a
 *                  lower value.  That minimum depends on the curve size, and
 *                  can be made lower by decreasing the value of
 *                  \c MBEDTLS_ECP_WINDOW_SIZE.  As an indication, here is the
 *                  lowest effective value for various curves and values of
 *                  that parameter (w for short):
 *                          w=6     w=5     w=4     w=3     w=2
 *                  P-256   208     208     160     136     124
 *                  P-384   682     416     320     272     248
 *                  P-521  1364     832     640     544     496
 *
 * \note            This setting is currently ignored by Curve25519.
 */
void mbedtls_ecp_set_max_ops( unsigned max_ops );

/**
 * \brief           Check if restart is enabled (max_ops != 0)
 *
 * \return          \c 0 if \c max_ops == 0 (restart disabled)
 * \return          \c 1 otherwise (restart enabled)
 */
int mbedtls_ecp_restart_is_enabled( void );
#endif /* MBEDTLS_ECP_RESTARTABLE */

ROOL's avatar
ROOL committed
420
/**
ROOL's avatar
ROOL committed
421 422 423
 * \brief           This function retrieves the information defined in
 *                  mbedtls_ecp_curve_info() for all supported curves in order
 *                  of preference.
ROOL's avatar
ROOL committed
424
 *
ROOL's avatar
ROOL committed
425
 * \return          A statically allocated array. The last entry is 0.
ROOL's avatar
ROOL committed
426 427 428 429
 */
const mbedtls_ecp_curve_info *mbedtls_ecp_curve_list( void );

/**
ROOL's avatar
ROOL committed
430 431 432
 * \brief           This function retrieves the list of internal group
 *                  identifiers of all supported curves in the order of
 *                  preference.
ROOL's avatar
ROOL committed
433 434 435 436 437 438 439
 *
 * \return          A statically allocated array,
 *                  terminated with MBEDTLS_ECP_DP_NONE.
 */
const mbedtls_ecp_group_id *mbedtls_ecp_grp_id_list( void );

/**
ROOL's avatar
ROOL committed
440 441
 * \brief           This function retrieves curve information from an internal
 *                  group identifier.
ROOL's avatar
ROOL committed
442
 *
ROOL's avatar
ROOL committed
443
 * \param grp_id    An \c MBEDTLS_ECP_DP_XXX value.
ROOL's avatar
ROOL committed
444
 *
ROOL's avatar
ROOL committed
445 446
 * \return          The associated curve information on success.
 * \return          NULL on failure.
ROOL's avatar
ROOL committed
447 448 449 450
 */
const mbedtls_ecp_curve_info *mbedtls_ecp_curve_info_from_grp_id( mbedtls_ecp_group_id grp_id );

/**
ROOL's avatar
ROOL committed
451 452
 * \brief           This function retrieves curve information from a TLS
 *                  NamedCurve value.
ROOL's avatar
ROOL committed
453
 *
ROOL's avatar
ROOL committed
454
 * \param tls_id    An \c MBEDTLS_ECP_DP_XXX value.
ROOL's avatar
ROOL committed
455
 *
ROOL's avatar
ROOL committed
456 457
 * \return          The associated curve information on success.
 * \return          NULL on failure.
ROOL's avatar
ROOL committed
458 459 460 461
 */
const mbedtls_ecp_curve_info *mbedtls_ecp_curve_info_from_tls_id( uint16_t tls_id );

/**
ROOL's avatar
ROOL committed
462 463
 * \brief           This function retrieves curve information from a
 *                  human-readable name.
ROOL's avatar
ROOL committed
464
 *
ROOL's avatar
ROOL committed
465
 * \param name      The human-readable name.
ROOL's avatar
ROOL committed
466
 *
ROOL's avatar
ROOL committed
467 468
 * \return          The associated curve information on success.
 * \return          NULL on failure.
ROOL's avatar
ROOL committed
469 470 471 472
 */
const mbedtls_ecp_curve_info *mbedtls_ecp_curve_info_from_name( const char *name );

/**
ROOL's avatar
ROOL committed
473 474 475
 * \brief           This function initializes a point as zero.
 *
 * \param pt        The point to initialize.
ROOL's avatar
ROOL committed
476 477 478 479
 */
void mbedtls_ecp_point_init( mbedtls_ecp_point *pt );

/**
ROOL's avatar
ROOL committed
480 481 482 483 484
 * \brief           This function initializes an ECP group context
 *                  without loading any domain parameters.
 *
 * \note            After this function is called, domain parameters
 *                  for various ECP groups can be loaded through the
ROOL's avatar
ROOL committed
485
 *                  mbedtls_ecp_group_load() or mbedtls_ecp_tls_read_group()
ROOL's avatar
ROOL committed
486
 *                  functions.
ROOL's avatar
ROOL committed
487 488 489 490
 */
void mbedtls_ecp_group_init( mbedtls_ecp_group *grp );

/**
ROOL's avatar
ROOL committed
491 492 493
 * \brief           This function initializes a key pair as an invalid one.
 *
 * \param key       The key pair to initialize.
ROOL's avatar
ROOL committed
494 495 496 497
 */
void mbedtls_ecp_keypair_init( mbedtls_ecp_keypair *key );

/**
ROOL's avatar
ROOL committed
498 499 500
 * \brief           This function frees the components of a point.
 *
 * \param pt        The point to free.
ROOL's avatar
ROOL committed
501 502 503 504
 */
void mbedtls_ecp_point_free( mbedtls_ecp_point *pt );

/**
ROOL's avatar
ROOL committed
505
 * \brief           This function frees the components of an ECP group.
ROOL's avatar
ROOL committed
506 507 508 509
 *
 * \param grp       The group to free. This may be \c NULL, in which
 *                  case this function returns immediately. If it is not
 *                  \c NULL, it must point to an initialized ECP group.
ROOL's avatar
ROOL committed
510 511 512 513
 */
void mbedtls_ecp_group_free( mbedtls_ecp_group *grp );

/**
ROOL's avatar
ROOL committed
514
 * \brief           This function frees the components of a key pair.
ROOL's avatar
ROOL committed
515 516 517 518
 *
 * \param key       The key pair to free. This may be \c NULL, in which
 *                  case this function returns immediately. If it is not
 *                  \c NULL, it must point to an initialized ECP key pair.
ROOL's avatar
ROOL committed
519 520 521
 */
void mbedtls_ecp_keypair_free( mbedtls_ecp_keypair *key );

ROOL's avatar
ROOL committed
522 523
#if defined(MBEDTLS_ECP_RESTARTABLE)
/**
ROOL's avatar
ROOL committed
524 525 526 527
 * \brief           Initialize a restart context.
 *
 * \param ctx       The restart context to initialize. This must
 *                  not be \c NULL.
ROOL's avatar
ROOL committed
528 529 530 531
 */
void mbedtls_ecp_restart_init( mbedtls_ecp_restart_ctx *ctx );

/**
ROOL's avatar
ROOL committed
532 533 534 535 536
 * \brief           Free the components of a restart context.
 *
 * \param ctx       The restart context to free. This may be \c NULL, in which
 *                  case this function returns immediately. If it is not
 *                  \c NULL, it must point to an initialized restart context.
ROOL's avatar
ROOL committed
537 538 539 540
 */
void mbedtls_ecp_restart_free( mbedtls_ecp_restart_ctx *ctx );
#endif /* MBEDTLS_ECP_RESTARTABLE */

ROOL's avatar
ROOL committed
541
/**
ROOL's avatar
ROOL committed
542 543
 * \brief           This function copies the contents of point \p Q into
 *                  point \p P.
ROOL's avatar
ROOL committed
544
 *
ROOL's avatar
ROOL committed
545 546
 * \param P         The destination point. This must be initialized.
 * \param Q         The source point. This must be initialized.
ROOL's avatar
ROOL committed
547
 *
ROOL's avatar
ROOL committed
548 549
 * \return          \c 0 on success.
 * \return          #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
ROOL's avatar
ROOL committed
550
 * \return          Another negative error code for other kinds of failure.
ROOL's avatar
ROOL committed
551 552 553 554
 */
int mbedtls_ecp_copy( mbedtls_ecp_point *P, const mbedtls_ecp_point *Q );

/**
ROOL's avatar
ROOL committed
555 556
 * \brief           This function copies the contents of group \p src into
 *                  group \p dst.
ROOL's avatar
ROOL committed
557
 *
ROOL's avatar
ROOL committed
558 559
 * \param dst       The destination group. This must be initialized.
 * \param src       The source group. This must be initialized.
ROOL's avatar
ROOL committed
560
 *
ROOL's avatar
ROOL committed
561 562
 * \return          \c 0 on success.
 * \return          #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
ROOL's avatar
ROOL committed
563
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
564
 */
ROOL's avatar
ROOL committed
565 566
int mbedtls_ecp_group_copy( mbedtls_ecp_group *dst,
                            const mbedtls_ecp_group *src );
ROOL's avatar
ROOL committed
567 568

/**
ROOL's avatar
ROOL committed
569
 * \brief           This function sets a point to the point at infinity.
ROOL's avatar
ROOL committed
570
 *
ROOL's avatar
ROOL committed
571
 * \param pt        The point to set. This must be initialized.
ROOL's avatar
ROOL committed
572
 *
ROOL's avatar
ROOL committed
573 574
 * \return          \c 0 on success.
 * \return          #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
ROOL's avatar
ROOL committed
575
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
576 577 578 579
 */
int mbedtls_ecp_set_zero( mbedtls_ecp_point *pt );

/**
ROOL's avatar
ROOL committed
580
 * \brief           This function checks if a point is the point at infinity.
ROOL's avatar
ROOL committed
581
 *
ROOL's avatar
ROOL committed
582
 * \param pt        The point to test. This must be initialized.
ROOL's avatar
ROOL committed
583
 *
ROOL's avatar
ROOL committed
584 585
 * \return          \c 1 if the point is zero.
 * \return          \c 0 if the point is non-zero.
ROOL's avatar
ROOL committed
586
 * \return          A negative error code on failure.
ROOL's avatar
ROOL committed
587 588 589 590
 */
int mbedtls_ecp_is_zero( mbedtls_ecp_point *pt );

/**
ROOL's avatar
ROOL committed
591
 * \brief           This function compares two points.
ROOL's avatar
ROOL committed
592
 *
ROOL's avatar
ROOL committed
593
 * \note            This assumes that the points are normalized. Otherwise,
ROOL's avatar
ROOL committed
594 595
 *                  they may compare as "not equal" even if they are.
 *
ROOL's avatar
ROOL committed
596 597
 * \param P         The first point to compare. This must be initialized.
 * \param Q         The second point to compare. This must be initialized.
ROOL's avatar
ROOL committed
598
 *
ROOL's avatar
ROOL committed
599 600
 * \return          \c 0 if the points are equal.
 * \return          #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if the points are not equal.
ROOL's avatar
ROOL committed
601 602 603 604 605
 */
int mbedtls_ecp_point_cmp( const mbedtls_ecp_point *P,
                           const mbedtls_ecp_point *Q );

/**
ROOL's avatar
ROOL committed
606 607
 * \brief           This function imports a non-zero point from two ASCII
 *                  strings.
ROOL's avatar
ROOL committed
608
 *
ROOL's avatar
ROOL committed
609
 * \param P         The destination point. This must be initialized.
ROOL's avatar
ROOL committed
610 611 612
 * \param radix     The numeric base of the input.
 * \param x         The first affine coordinate, as a null-terminated string.
 * \param y         The second affine coordinate, as a null-terminated string.
ROOL's avatar
ROOL committed
613
 *
ROOL's avatar
ROOL committed
614 615
 * \return          \c 0 on success.
 * \return          An \c MBEDTLS_ERR_MPI_XXX error code on failure.
ROOL's avatar
ROOL committed
616 617 618 619 620
 */
int mbedtls_ecp_point_read_string( mbedtls_ecp_point *P, int radix,
                           const char *x, const char *y );

/**
ROOL's avatar
ROOL committed
621
 * \brief           This function exports a point into unsigned binary data.
ROOL's avatar
ROOL committed
622
 *
ROOL's avatar
ROOL committed
623
 * \param grp       The group to which the point should belong.
ROOL's avatar
ROOL committed
624 625 626 627 628 629 630 631 632 633
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param P         The point to export. This must be initialized.
 * \param format    The point format. This must be either
 *                  #MBEDTLS_ECP_PF_COMPRESSED or #MBEDTLS_ECP_PF_UNCOMPRESSED.
 * \param olen      The address at which to store the length of
 *                  the output in Bytes. This must not be \c NULL.
 * \param buf       The output buffer. This must be a writable buffer
 *                  of length \p buflen Bytes.
 * \param buflen    The length of the output buffer \p buf in Bytes.
ROOL's avatar
ROOL committed
634
 *
ROOL's avatar
ROOL committed
635
 * \return          \c 0 on success.
ROOL's avatar
ROOL committed
636 637 638
 * \return          #MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL if the output buffer
 *                  is too small to hold the point.
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
639 640 641 642 643 644
 */
int mbedtls_ecp_point_write_binary( const mbedtls_ecp_group *grp, const mbedtls_ecp_point *P,
                            int format, size_t *olen,
                            unsigned char *buf, size_t buflen );

/**
ROOL's avatar
ROOL committed
645
 * \brief           This function imports a point from unsigned binary data.
ROOL's avatar
ROOL committed
646
 *
ROOL's avatar
ROOL committed
647 648 649
 * \note            This function does not check that the point actually
 *                  belongs to the given group, see mbedtls_ecp_check_pubkey()
 *                  for that.
ROOL's avatar
ROOL committed
650
 *
ROOL's avatar
ROOL committed
651
 * \param grp       The group to which the point should belong.
ROOL's avatar
ROOL committed
652 653 654 655 656 657 658
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param P         The destination context to import the point to.
 *                  This must be initialized.
 * \param buf       The input buffer. This must be a readable buffer
 *                  of length \p ilen Bytes.
 * \param ilen      The length of the input buffer \p buf in Bytes.
ROOL's avatar
ROOL committed
659 660
 *
 * \return          \c 0 on success.
ROOL's avatar
ROOL committed
661
 * \return          #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if the input is invalid.
ROOL's avatar
ROOL committed
662 663
 * \return          #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
 * \return          #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if the point format
ROOL's avatar
ROOL committed
664 665
 *                  is not implemented.
 */
ROOL's avatar
ROOL committed
666 667 668
int mbedtls_ecp_point_read_binary( const mbedtls_ecp_group *grp,
                                   mbedtls_ecp_point *P,
                                   const unsigned char *buf, size_t ilen );
ROOL's avatar
ROOL committed
669 670

/**
ROOL's avatar
ROOL committed
671
 * \brief           This function imports a point from a TLS ECPoint record.
ROOL's avatar
ROOL committed
672
 *
ROOL's avatar
ROOL committed
673
 * \note            On function return, \p *buf is updated to point immediately
ROOL's avatar
ROOL committed
674
 *                  after the ECPoint record.
ROOL's avatar
ROOL committed
675
 *
ROOL's avatar
ROOL committed
676 677 678
 * \param grp       The ECP group to use.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
ROOL's avatar
ROOL committed
679 680 681
 * \param pt        The destination point.
 * \param buf       The address of the pointer to the start of the input buffer.
 * \param len       The length of the buffer.
ROOL's avatar
ROOL committed
682
 *
ROOL's avatar
ROOL committed
683
 * \return          \c 0 on success.
ROOL's avatar
ROOL committed
684 685
 * \return          An \c MBEDTLS_ERR_MPI_XXX error code on initialization
 *                  failure.
ROOL's avatar
ROOL committed
686
 * \return          #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if input is invalid.
ROOL's avatar
ROOL committed
687
 */
ROOL's avatar
ROOL committed
688 689 690
int mbedtls_ecp_tls_read_point( const mbedtls_ecp_group *grp,
                                mbedtls_ecp_point *pt,
                                const unsigned char **buf, size_t len );
ROOL's avatar
ROOL committed
691 692

/**
ROOL's avatar
ROOL committed
693 694 695 696 697 698 699 700 701 702 703 704 705 706
 * \brief           This function exports a point as a TLS ECPoint record
 *                  defined in RFC 4492, Section 5.4.
 *
 * \param grp       The ECP group to use.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param pt        The point to be exported. This must be initialized.
 * \param format    The point format to use. This must be either
 *                  #MBEDTLS_ECP_PF_COMPRESSED or #MBEDTLS_ECP_PF_UNCOMPRESSED.
 * \param olen      The address at which to store the length in Bytes
 *                  of the data written.
 * \param buf       The target buffer. This must be a writable buffer of
 *                  length \p blen Bytes.
 * \param blen      The length of the target buffer \p buf in Bytes.
ROOL's avatar
ROOL committed
707
 *
ROOL's avatar
ROOL committed
708
 * \return          \c 0 on success.
ROOL's avatar
ROOL committed
709 710 711 712
 * \return          #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if the input is invalid.
 * \return          #MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL if the target buffer
 *                  is too small to hold the exported point.
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
713
 */
ROOL's avatar
ROOL committed
714 715 716 717
int mbedtls_ecp_tls_write_point( const mbedtls_ecp_group *grp,
                                 const mbedtls_ecp_point *pt,
                                 int format, size_t *olen,
                                 unsigned char *buf, size_t blen );
ROOL's avatar
ROOL committed
718 719

/**
ROOL's avatar
ROOL committed
720 721
 * \brief           This function sets up an ECP group context
 *                  from a standardized set of domain parameters.
ROOL's avatar
ROOL committed
722
 *
ROOL's avatar
ROOL committed
723 724 725 726
 * \note            The index should be a value of the NamedCurve enum,
 *                  as defined in <em>RFC-4492: Elliptic Curve Cryptography
 *                  (ECC) Cipher Suites for Transport Layer Security (TLS)</em>,
 *                  usually in the form of an \c MBEDTLS_ECP_DP_XXX macro.
ROOL's avatar
ROOL committed
727
 *
ROOL's avatar
ROOL committed
728
 * \param grp       The group context to setup. This must be initialized.
ROOL's avatar
ROOL committed
729
 * \param id        The identifier of the domain parameter set to load.
ROOL's avatar
ROOL committed
730
 *
ROOL's avatar
ROOL committed
731 732 733 734
 * \return          \c 0 on success.
 * \return          #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if \p id doesn't
 *                  correspond to a known group.
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
735 736 737 738
 */
int mbedtls_ecp_group_load( mbedtls_ecp_group *grp, mbedtls_ecp_group_id id );

/**
ROOL's avatar
ROOL committed
739 740
 * \brief           This function sets up an ECP group context from a TLS
 *                  ECParameters record as defined in RFC 4492, Section 5.4.
ROOL's avatar
ROOL committed
741
 *
ROOL's avatar
ROOL committed
742 743
 * \note            The read pointer \p buf is updated to point right after
 *                  the ECParameters record on exit.
ROOL's avatar
ROOL committed
744
 *
ROOL's avatar
ROOL committed
745
 * \param grp       The group context to setup. This must be initialized.
ROOL's avatar
ROOL committed
746
 * \param buf       The address of the pointer to the start of the input buffer.
ROOL's avatar
ROOL committed
747
 * \param len       The length of the input buffer \c *buf in Bytes.
ROOL's avatar
ROOL committed
748
 *
ROOL's avatar
ROOL committed
749 750
 * \return          \c 0 on success.
 * \return          #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if input is invalid.
ROOL's avatar
ROOL committed
751 752 753
 * \return          #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if the group is not
 *                  recognized.
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
754
 */
ROOL's avatar
ROOL committed
755 756
int mbedtls_ecp_tls_read_group( mbedtls_ecp_group *grp,
                                const unsigned char **buf, size_t len );
ROOL's avatar
ROOL committed
757 758

/**
ROOL's avatar
ROOL committed
759 760 761 762 763
 * \brief           This function extracts an elliptic curve group ID from a
 *                  TLS ECParameters record as defined in RFC 4492, Section 5.4.
 *
 * \note            The read pointer \p buf is updated to point right after
 *                  the ECParameters record on exit.
ROOL's avatar
ROOL committed
764
 *
ROOL's avatar
ROOL committed
765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790
 * \param grp       The address at which to store the group id.
 *                  This must not be \c NULL.
 * \param buf       The address of the pointer to the start of the input buffer.
 * \param len       The length of the input buffer \c *buf in Bytes.
 *
 * \return          \c 0 on success.
 * \return          #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if input is invalid.
 * \return          #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if the group is not
 *                  recognized.
 * \return          Another negative error code on other kinds of failure.
 */
int mbedtls_ecp_tls_read_group_id( mbedtls_ecp_group_id *grp,
                                   const unsigned char **buf,
                                   size_t len );
/**
 * \brief           This function exports an elliptic curve as a TLS
 *                  ECParameters record as defined in RFC 4492, Section 5.4.
 *
 * \param grp       The ECP group to be exported.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param olen      The address at which to store the number of Bytes written.
 *                  This must not be \c NULL.
 * \param buf       The buffer to write to. This must be a writable buffer
 *                  of length \p blen Bytes.
 * \param blen      The length of the output buffer \p buf in Bytes.
ROOL's avatar
ROOL committed
791
 *
ROOL's avatar
ROOL committed
792
 * \return          \c 0 on success.
ROOL's avatar
ROOL committed
793 794 795
 * \return          #MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL if the output
 *                  buffer is too small to hold the exported group.
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
796
 */
ROOL's avatar
ROOL committed
797 798 799
int mbedtls_ecp_tls_write_group( const mbedtls_ecp_group *grp,
                                 size_t *olen,
                                 unsigned char *buf, size_t blen );
ROOL's avatar
ROOL committed
800 801

/**
ROOL's avatar
ROOL committed
802 803
 * \brief           This function performs a scalar multiplication of a point
 *                  by an integer: \p R = \p m * \p P.
ROOL's avatar
ROOL committed
804
 *
ROOL's avatar
ROOL committed
805
 *                  It is not thread-safe to use same group in multiple threads.
ROOL's avatar
ROOL committed
806
 *
ROOL's avatar
ROOL committed
807 808 809 810
 * \note            To prevent timing attacks, this function
 *                  executes the exact same sequence of base-field
 *                  operations for any valid \p m. It avoids any if-branch or
 *                  array index depending on the value of \p m.
ROOL's avatar
ROOL committed
811
 *
ROOL's avatar
ROOL committed
812 813 814 815
 * \note            If \p f_rng is not NULL, it is used to randomize
 *                  intermediate results to prevent potential timing attacks
 *                  targeting these results. We recommend always providing
 *                  a non-NULL \p f_rng. The overhead is negligible.
ROOL's avatar
ROOL committed
816
 *
ROOL's avatar
ROOL committed
817 818 819 820 821 822 823 824 825 826
 * \param grp       The ECP group to use.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param R         The point in which to store the result of the calculation.
 *                  This must be initialized.
 * \param m         The integer by which to multiply. This must be initialized.
 * \param P         The point to multiply. This must be initialized.
 * \param f_rng     The RNG function. This may be \c NULL if randomization
 *                  of intermediate results isn't desired (discouraged).
 * \param p_rng     The RNG context to be passed to \p p_rng.
ROOL's avatar
ROOL committed
827 828 829 830 831
 *
 * \return          \c 0 on success.
 * \return          #MBEDTLS_ERR_ECP_INVALID_KEY if \p m is not a valid private
 *                  key, or \p P is not a valid public key.
 * \return          #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
ROOL's avatar
ROOL committed
832
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
833 834 835 836 837
 */
int mbedtls_ecp_mul( mbedtls_ecp_group *grp, mbedtls_ecp_point *R,
             const mbedtls_mpi *m, const mbedtls_ecp_point *P,
             int (*f_rng)(void *, unsigned char *, size_t), void *p_rng );

ROOL's avatar
ROOL committed
838 839 840 841 842 843 844 845 846 847
/**
 * \brief           This function performs multiplication of a point by
 *                  an integer: \p R = \p m * \p P in a restartable way.
 *
 * \see             mbedtls_ecp_mul()
 *
 * \note            This function does the same as \c mbedtls_ecp_mul(), but
 *                  it can return early and restart according to the limit set
 *                  with \c mbedtls_ecp_set_max_ops() to reduce blocking.
 *
ROOL's avatar
ROOL committed
848 849 850 851 852 853 854 855 856 857
 * \param grp       The ECP group to use.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param R         The point in which to store the result of the calculation.
 *                  This must be initialized.
 * \param m         The integer by which to multiply. This must be initialized.
 * \param P         The point to multiply. This must be initialized.
 * \param f_rng     The RNG function. This may be \c NULL if randomization
 *                  of intermediate results isn't desired (discouraged).
 * \param p_rng     The RNG context to be passed to \p p_rng.
ROOL's avatar
ROOL committed
858 859 860 861 862 863 864 865
 * \param rs_ctx    The restart context (NULL disables restart).
 *
 * \return          \c 0 on success.
 * \return          #MBEDTLS_ERR_ECP_INVALID_KEY if \p m is not a valid private
 *                  key, or \p P is not a valid public key.
 * \return          #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
 * \return          #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
 *                  operations was reached: see \c mbedtls_ecp_set_max_ops().
ROOL's avatar
ROOL committed
866
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
867 868 869 870 871 872
 */
int mbedtls_ecp_mul_restartable( mbedtls_ecp_group *grp, mbedtls_ecp_point *R,
             const mbedtls_mpi *m, const mbedtls_ecp_point *P,
             int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
             mbedtls_ecp_restart_ctx *rs_ctx );

ROOL's avatar
ROOL committed
873
/**
ROOL's avatar
ROOL committed
874 875 876 877
 * \brief           This function performs multiplication and addition of two
 *                  points by integers: \p R = \p m * \p P + \p n * \p Q
 *
 *                  It is not thread-safe to use same group in multiple threads.
ROOL's avatar
ROOL committed
878
 *
ROOL's avatar
ROOL committed
879 880
 * \note            In contrast to mbedtls_ecp_mul(), this function does not
 *                  guarantee a constant execution flow and timing.
ROOL's avatar
ROOL committed
881
 *
ROOL's avatar
ROOL committed
882 883 884 885 886
 * \param grp       The ECP group to use.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param R         The point in which to store the result of the calculation.
 *                  This must be initialized.
ROOL's avatar
ROOL committed
887
 * \param m         The integer by which to multiply \p P.
ROOL's avatar
ROOL committed
888 889
 *                  This must be initialized.
 * \param P         The point to multiply by \p m. This must be initialized.
ROOL's avatar
ROOL committed
890
 * \param n         The integer by which to multiply \p Q.
ROOL's avatar
ROOL committed
891
 *                  This must be initialized.
ROOL's avatar
ROOL committed
892
 * \param Q         The point to be multiplied by \p n.
ROOL's avatar
ROOL committed
893
 *                  This must be initialized.
ROOL's avatar
ROOL committed
894
 *
ROOL's avatar
ROOL committed
895 896 897 898 899
 * \return          \c 0 on success.
 * \return          #MBEDTLS_ERR_ECP_INVALID_KEY if \p m or \p n are not
 *                  valid private keys, or \p P or \p Q are not valid public
 *                  keys.
 * \return          #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
ROOL's avatar
ROOL committed
900
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
901 902 903 904 905
 */
int mbedtls_ecp_muladd( mbedtls_ecp_group *grp, mbedtls_ecp_point *R,
             const mbedtls_mpi *m, const mbedtls_ecp_point *P,
             const mbedtls_mpi *n, const mbedtls_ecp_point *Q );

ROOL's avatar
ROOL committed
906 907 908 909 910 911 912 913 914 915 916
/**
 * \brief           This function performs multiplication and addition of two
 *                  points by integers: \p R = \p m * \p P + \p n * \p Q in a
 *                  restartable way.
 *
 * \see             \c mbedtls_ecp_muladd()
 *
 * \note            This function works the same as \c mbedtls_ecp_muladd(),
 *                  but it can return early and restart according to the limit
 *                  set with \c mbedtls_ecp_set_max_ops() to reduce blocking.
 *
ROOL's avatar
ROOL committed
917 918 919 920 921
 * \param grp       The ECP group to use.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param R         The point in which to store the result of the calculation.
 *                  This must be initialized.
ROOL's avatar
ROOL committed
922
 * \param m         The integer by which to multiply \p P.
ROOL's avatar
ROOL committed
923 924
 *                  This must be initialized.
 * \param P         The point to multiply by \p m. This must be initialized.
ROOL's avatar
ROOL committed
925
 * \param n         The integer by which to multiply \p Q.
ROOL's avatar
ROOL committed
926
 *                  This must be initialized.
ROOL's avatar
ROOL committed
927
 * \param Q         The point to be multiplied by \p n.
ROOL's avatar
ROOL committed
928
 *                  This must be initialized.
ROOL's avatar
ROOL committed
929 930 931 932 933 934 935 936 937
 * \param rs_ctx    The restart context (NULL disables restart).
 *
 * \return          \c 0 on success.
 * \return          #MBEDTLS_ERR_ECP_INVALID_KEY if \p m or \p n are not
 *                  valid private keys, or \p P or \p Q are not valid public
 *                  keys.
 * \return          #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
 * \return          #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
 *                  operations was reached: see \c mbedtls_ecp_set_max_ops().
ROOL's avatar
ROOL committed
938
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
939 940 941 942 943 944 945
 */
int mbedtls_ecp_muladd_restartable(
             mbedtls_ecp_group *grp, mbedtls_ecp_point *R,
             const mbedtls_mpi *m, const mbedtls_ecp_point *P,
             const mbedtls_mpi *n, const mbedtls_ecp_point *Q,
             mbedtls_ecp_restart_ctx *rs_ctx );

ROOL's avatar
ROOL committed
946
/**
ROOL's avatar
ROOL committed
947 948
 * \brief           This function checks that a point is a valid public key
 *                  on this curve.
ROOL's avatar
ROOL committed
949
 *
ROOL's avatar
ROOL committed
950 951 952 953 954 955 956
 *                  It only checks that the point is non-zero, has
 *                  valid coordinates and lies on the curve. It does not verify
 *                  that it is indeed a multiple of \p G. This additional
 *                  check is computationally more expensive, is not required
 *                  by standards, and should not be necessary if the group
 *                  used has a small cofactor. In particular, it is useless for
 *                  the NIST groups which all have a cofactor of 1.
ROOL's avatar
ROOL committed
957
 *
ROOL's avatar
ROOL committed
958 959 960 961
 * \note            This function uses bare components rather than an
 *                  ::mbedtls_ecp_keypair structure, to ease use with other
 *                  structures, such as ::mbedtls_ecdh_context or
 *                  ::mbedtls_ecdsa_context.
ROOL's avatar
ROOL committed
962
 *
ROOL's avatar
ROOL committed
963 964 965 966
 * \param grp       The ECP group the point should belong to.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param pt        The point to check. This must be initialized.
ROOL's avatar
ROOL committed
967
 *
ROOL's avatar
ROOL committed
968
 * \return          \c 0 if the point is a valid public key.
ROOL's avatar
ROOL committed
969 970 971
 * \return          #MBEDTLS_ERR_ECP_INVALID_KEY if the point is not
 *                  a valid public key for the given curve.
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
972
 */
ROOL's avatar
ROOL committed
973 974
int mbedtls_ecp_check_pubkey( const mbedtls_ecp_group *grp,
                              const mbedtls_ecp_point *pt );
ROOL's avatar
ROOL committed
975 976

/**
ROOL's avatar
ROOL committed
977 978
 * \brief           This function checks that an \p mbedtls_mpi is a
 *                  valid private key for this curve.
ROOL's avatar
ROOL committed
979
 *
ROOL's avatar
ROOL committed
980 981 982 983
 * \note            This function uses bare components rather than an
 *                  ::mbedtls_ecp_keypair structure to ease use with other
 *                  structures, such as ::mbedtls_ecdh_context or
 *                  ::mbedtls_ecdsa_context.
ROOL's avatar
ROOL committed
984
 *
ROOL's avatar
ROOL committed
985 986 987 988
 * \param grp       The ECP group the private key should belong to.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param d         The integer to check. This must be initialized.
ROOL's avatar
ROOL committed
989
 *
ROOL's avatar
ROOL committed
990
 * \return          \c 0 if the point is a valid private key.
ROOL's avatar
ROOL committed
991 992 993
 * \return          #MBEDTLS_ERR_ECP_INVALID_KEY if the point is not a valid
 *                  private key for the given curve.
 * \return          Another negative error code on other kinds of failure.
ROOL's avatar
ROOL committed
994
 */
ROOL's avatar
ROOL committed
995 996
int mbedtls_ecp_check_privkey( const mbedtls_ecp_group *grp,
                               const mbedtls_mpi *d );
ROOL's avatar
ROOL committed
997

ROOL's avatar
ROOL committed
998 999 1000
/**
 * \brief           This function generates a private key.
 *
ROOL's avatar
ROOL committed
1001 1002 1003 1004 1005 1006 1007
 * \param grp       The ECP group to generate a private key for.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param d         The destination MPI (secret part). This must be initialized.
 * \param f_rng     The RNG function. This must not be \c NULL.
 * \param p_rng     The RNG parameter to be passed to \p f_rng. This may be
 *                  \c NULL if \p f_rng doesn't need a context argument.
ROOL's avatar
ROOL committed
1008 1009 1010 1011 1012 1013 1014 1015 1016 1017
 *
 * \return          \c 0 on success.
 * \return          An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX error code
 *                  on failure.
 */
int mbedtls_ecp_gen_privkey( const mbedtls_ecp_group *grp,
                     mbedtls_mpi *d,
                     int (*f_rng)(void *, unsigned char *, size_t),
                     void *p_rng );

ROOL's avatar
ROOL committed
1018
/**
ROOL's avatar
ROOL committed
1019 1020
 * \brief           This function generates a keypair with a configurable base
 *                  point.
ROOL's avatar
ROOL committed
1021
 *
ROOL's avatar
ROOL committed
1022 1023 1024 1025
 * \note            This function uses bare components rather than an
 *                  ::mbedtls_ecp_keypair structure to ease use with other
 *                  structures, such as ::mbedtls_ecdh_context or
 *                  ::mbedtls_ecdsa_context.
ROOL's avatar
ROOL committed
1026
 *
ROOL's avatar
ROOL committed
1027 1028 1029 1030 1031 1032
 * \param grp       The ECP group to generate a key pair for.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
 * \param G         The base point to use. This must be initialized
 *                  and belong to \p grp. It replaces the default base
 *                  point \c grp->G used by mbedtls_ecp_gen_keypair().
ROOL's avatar
ROOL committed
1033
 * \param d         The destination MPI (secret part).
ROOL's avatar
ROOL committed
1034
 *                  This must be initialized.
ROOL's avatar
ROOL committed
1035
 * \param Q         The destination point (public part).
ROOL's avatar
ROOL committed
1036 1037 1038 1039
 *                  This must be initialized.
 * \param f_rng     The RNG function. This must not be \c NULL.
 * \param p_rng     The RNG context to be passed to \p f_rng. This may
 *                  be \c NULL if \p f_rng doesn't need a context argument.
ROOL's avatar
ROOL committed
1040
 *
ROOL's avatar
ROOL committed
1041 1042 1043
 * \return          \c 0 on success.
 * \return          An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX error code
 *                  on failure.
ROOL's avatar
ROOL committed
1044 1045
 */
int mbedtls_ecp_gen_keypair_base( mbedtls_ecp_group *grp,
ROOL's avatar
ROOL committed
1046 1047 1048 1049
                                  const mbedtls_ecp_point *G,
                                  mbedtls_mpi *d, mbedtls_ecp_point *Q,
                                  int (*f_rng)(void *, unsigned char *, size_t),
                                  void *p_rng );
ROOL's avatar
ROOL committed
1050 1051

/**
ROOL's avatar
ROOL committed
1052
 * \brief           This function generates an ECP keypair.
ROOL's avatar
ROOL committed
1053
 *
ROOL's avatar
ROOL committed
1054 1055 1056 1057
 * \note            This function uses bare components rather than an
 *                  ::mbedtls_ecp_keypair structure to ease use with other
 *                  structures, such as ::mbedtls_ecdh_context or
 *                  ::mbedtls_ecdsa_context.
ROOL's avatar
ROOL committed
1058
 *
ROOL's avatar
ROOL committed
1059 1060 1061
 * \param grp       The ECP group to generate a key pair for.
 *                  This must be initialized and have group parameters
 *                  set, for example through mbedtls_ecp_group_load().
ROOL's avatar
ROOL committed
1062
 * \param d         The destination MPI (secret part).
ROOL's avatar
ROOL committed
1063
 *                  This must be initialized.
ROOL's avatar
ROOL committed
1064
 * \param Q         The destination point (public part).
ROOL's avatar
ROOL committed
1065 1066 1067 1068
 *                  This must be initialized.
 * \param f_rng     The RNG function. This must not be \c NULL.
 * \param p_rng     The RNG context to be passed to \p f_rng. This may
 *                  be \c NULL if \p f_rng doesn't need a context argument.
ROOL's avatar
ROOL committed
1069
 *
ROOL's avatar
ROOL committed
1070 1071 1072
 * \return          \c 0 on success.
 * \return          An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX error code
 *                  on failure.
ROOL's avatar
ROOL committed
1073
 */
ROOL's avatar
ROOL committed
1074 1075 1076 1077
int mbedtls_ecp_gen_keypair( mbedtls_ecp_group *grp, mbedtls_mpi *d,
                             mbedtls_ecp_point *Q,
                             int (*f_rng)(void *, unsigned char *, size_t),
                             void *p_rng );
ROOL's avatar
ROOL committed
1078 1079

/**
ROOL's avatar
ROOL committed
1080
 * \brief           This function generates an ECP key.
ROOL's avatar
ROOL committed
1081
 *
ROOL's avatar
ROOL committed
1082
 * \param grp_id    The ECP group identifier.
ROOL's avatar
ROOL committed
1083 1084 1085 1086
 * \param key       The destination key. This must be initialized.
 * \param f_rng     The RNG function to use. This must not be \c NULL.
 * \param p_rng     The RNG context to be passed to \p f_rng. This may
 *                  be \c NULL if \p f_rng doesn't need a context argument.
ROOL's avatar
ROOL committed
1087
 *
ROOL's avatar
ROOL committed
1088 1089 1090
 * \return          \c 0 on success.
 * \return          An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX error code
 *                  on failure.
ROOL's avatar
ROOL committed
1091 1092
 */
int mbedtls_ecp_gen_key( mbedtls_ecp_group_id grp_id, mbedtls_ecp_keypair *key,
ROOL's avatar
ROOL committed
1093 1094
                         int (*f_rng)(void *, unsigned char *, size_t),
                         void *p_rng );
ROOL's avatar
ROOL committed
1095 1096

/**
ROOL's avatar
ROOL committed
1097 1098 1099 1100
 * \brief           This function checks that the keypair objects
 *                  \p pub and \p prv have the same group and the
 *                  same public point, and that the private key in
 *                  \p prv is consistent with the public key.
ROOL's avatar
ROOL committed
1101
 *
ROOL's avatar
ROOL committed
1102 1103 1104
 * \param pub       The keypair structure holding the public key. This
 *                  must be initialized. If it contains a private key, that
 *                  part is ignored.
ROOL's avatar
ROOL committed
1105
 * \param prv       The keypair structure holding the full keypair.
ROOL's avatar
ROOL committed
1106
 *                  This must be initialized.
ROOL's avatar
ROOL committed
1107
 *
ROOL's avatar
ROOL committed
1108 1109 1110 1111
 * \return          \c 0 on success, meaning that the keys are valid and match.
 * \return          #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if the keys are invalid or do not match.
 * \return          An \c MBEDTLS_ERR_ECP_XXX or an \c MBEDTLS_ERR_MPI_XXX
 *                  error code on calculation failure.
ROOL's avatar
ROOL committed
1112
 */
ROOL's avatar
ROOL committed
1113 1114
int mbedtls_ecp_check_pub_priv( const mbedtls_ecp_keypair *pub,
                                const mbedtls_ecp_keypair *prv );
ROOL's avatar
ROOL committed
1115 1116 1117 1118

#if defined(MBEDTLS_SELF_TEST)

/**
ROOL's avatar
ROOL committed
1119
 * \brief          The ECP checkup routine.
ROOL's avatar
ROOL committed
1120
 *
ROOL's avatar
ROOL committed
1121 1122
 * \return         \c 0 on success.
 * \return         \c 1 on failure.
ROOL's avatar
ROOL committed
1123 1124 1125 1126 1127 1128 1129 1130 1131 1132
 */
int mbedtls_ecp_self_test( int verbose );

#endif /* MBEDTLS_SELF_TEST */

#ifdef __cplusplus
}
#endif

#endif /* ecp.h */