mbed TLS v2.3.0
ecp.h
Go to the documentation of this file.
1 
23 #ifndef MBEDTLS_ECP_H
24 #define MBEDTLS_ECP_H
25 
26 #include "bignum.h"
27 
28 /*
29  * ECP error codes
30  */
31 #define MBEDTLS_ERR_ECP_BAD_INPUT_DATA -0x4F80
32 #define MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL -0x4F00
33 #define MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE -0x4E80
34 #define MBEDTLS_ERR_ECP_VERIFY_FAILED -0x4E00
35 #define MBEDTLS_ERR_ECP_ALLOC_FAILED -0x4D80
36 #define MBEDTLS_ERR_ECP_RANDOM_FAILED -0x4D00
37 #define MBEDTLS_ERR_ECP_INVALID_KEY -0x4C80
38 #define MBEDTLS_ERR_ECP_SIG_LEN_MISMATCH -0x4C00
40 #ifdef __cplusplus
41 extern "C" {
42 #endif
43 
53 typedef enum
54 {
69 
75 #define MBEDTLS_ECP_DP_MAX 12
76 
80 typedef struct
81 {
82  mbedtls_ecp_group_id grp_id;
83  uint16_t tls_id;
84  uint16_t bit_size;
85  const char *name;
87 
97 typedef struct
98 {
102 }
104 
129 typedef struct
130 {
131  mbedtls_ecp_group_id id;
137  size_t pbits;
138  size_t nbits;
139  unsigned int h;
140  int (*modp)(mbedtls_mpi *);
141  int (*t_pre)(mbedtls_ecp_point *, void *);
142  int (*t_post)(mbedtls_ecp_point *, void *);
143  void *t_data;
145  size_t T_size;
146 }
148 
156 typedef struct
157 {
161 }
163 
172 #if !defined(MBEDTLS_ECP_MAX_BITS)
173 
176 #define MBEDTLS_ECP_MAX_BITS 521
177 #endif
178 
179 #define MBEDTLS_ECP_MAX_BYTES ( ( MBEDTLS_ECP_MAX_BITS + 7 ) / 8 )
180 #define MBEDTLS_ECP_MAX_PT_LEN ( 2 * MBEDTLS_ECP_MAX_BYTES + 1 )
181 
182 #if !defined(MBEDTLS_ECP_WINDOW_SIZE)
183 /*
184  * Maximum "window" size used for point multiplication.
185  * Default: 6.
186  * Minimum value: 2. Maximum value: 7.
187  *
188  * Result is an array of at most ( 1 << ( MBEDTLS_ECP_WINDOW_SIZE - 1 ) )
189  * points used for point multiplication. This value is directly tied to EC
190  * peak memory usage, so decreasing it by one should roughly cut memory usage
191  * by two (if large curves are in use).
192  *
193  * Reduction in size may reduce speed, but larger curves are impacted first.
194  * Sample performances (in ECDHE handshakes/s, with FIXED_POINT_OPTIM = 1):
195  * w-size: 6 5 4 3 2
196  * 521 145 141 135 120 97
197  * 384 214 209 198 177 146
198  * 256 320 320 303 262 226
199 
200  * 224 475 475 453 398 342
201  * 192 640 640 633 587 476
202  */
203 #define MBEDTLS_ECP_WINDOW_SIZE 6
204 #endif /* MBEDTLS_ECP_WINDOW_SIZE */
205 
206 #if !defined(MBEDTLS_ECP_FIXED_POINT_OPTIM)
207 /*
208  * Trade memory for speed on fixed-point multiplication.
209  *
210  * This speeds up repeated multiplication of the generator (that is, the
211  * multiplication in ECDSA signatures, and half of the multiplications in
212  * ECDSA verification and ECDHE) by a factor roughly 3 to 4.
213  *
214  * The cost is increasing EC peak memory usage by a factor roughly 2.
215  *
216  * Change this value to 0 to reduce peak memory usage.
217  */
218 #define MBEDTLS_ECP_FIXED_POINT_OPTIM 1
219 #endif /* MBEDTLS_ECP_FIXED_POINT_OPTIM */
220 
221 /* \} name SECTION: Module settings */
222 
223 /*
224  * Point formats, from RFC 4492's enum ECPointFormat
225  */
226 #define MBEDTLS_ECP_PF_UNCOMPRESSED 0
227 #define MBEDTLS_ECP_PF_COMPRESSED 1
229 /*
230  * Some other constants from RFC 4492
231  */
232 #define MBEDTLS_ECP_TLS_NAMED_CURVE 3
240 const mbedtls_ecp_curve_info *mbedtls_ecp_curve_list( void );
241 
249 const mbedtls_ecp_group_id *mbedtls_ecp_grp_id_list( void );
250 
258 const mbedtls_ecp_curve_info *mbedtls_ecp_curve_info_from_grp_id( mbedtls_ecp_group_id grp_id );
259 
268 
277 
282 
287 
292 
297 
302 
307 
318 
329 
339 
348 
362  const mbedtls_ecp_point *Q );
363 
375  const char *x, const char *y );
376 
392  int format, size_t *olen,
393  unsigned char *buf, size_t buflen );
394 
414  const unsigned char *buf, size_t ilen );
415 
431  const unsigned char **buf, size_t len );
432 
448  int format, size_t *olen,
449  unsigned char *buf, size_t blen );
450 
464 int mbedtls_ecp_group_load( mbedtls_ecp_group *grp, mbedtls_ecp_group_id index );
465 
479 int mbedtls_ecp_tls_read_group( mbedtls_ecp_group *grp, const unsigned char **buf, size_t len );
480 
492 int mbedtls_ecp_tls_write_group( const mbedtls_ecp_group *grp, size_t *olen,
493  unsigned char *buf, size_t blen );
494 
522  const mbedtls_mpi *m, const mbedtls_ecp_point *P,
523  int (*f_rng)(void *, unsigned char *, size_t), void *p_rng );
524 
546  const mbedtls_mpi *m, const mbedtls_ecp_point *P,
547  const mbedtls_mpi *n, const mbedtls_ecp_point *Q );
548 
571 
585 int mbedtls_ecp_check_privkey( const mbedtls_ecp_group *grp, const mbedtls_mpi *d );
586 
605  const mbedtls_ecp_point *G,
607  int (*f_rng)(void *, unsigned char *, size_t),
608  void *p_rng );
609 
627  int (*f_rng)(void *, unsigned char *, size_t),
628  void *p_rng );
629 
641 int mbedtls_ecp_gen_key( mbedtls_ecp_group_id grp_id, mbedtls_ecp_keypair *key,
642  int (*f_rng)(void *, unsigned char *, size_t), void *p_rng );
643 
655 
656 #if defined(MBEDTLS_SELF_TEST)
657 
662 int mbedtls_ecp_self_test( int verbose );
663 #endif
664 
665 #ifdef __cplusplus
666 }
667 #endif
668 
669 #endif /* ecp.h */
uint16_t tls_id
Definition: ecp.h:83
int mbedtls_ecp_is_zero(mbedtls_ecp_point *pt)
Tell if a point is zero.
mbedtls_mpi N
Definition: ecp.h:136
mbedtls_mpi Z
Definition: ecp.h:101
int mbedtls_ecp_muladd(mbedtls_ecp_group *grp, mbedtls_ecp_point *R, const mbedtls_mpi *m, const mbedtls_ecp_point *P, const mbedtls_mpi *n, const mbedtls_ecp_point *Q)
Multiplication and addition of two points by integers: R = m * P + n * Q (Not thread-safe to use same...
int mbedtls_ecp_check_pub_priv(const mbedtls_ecp_keypair *pub, const mbedtls_ecp_keypair *prv)
Check a public-private key pair.
int mbedtls_ecp_point_read_binary(const mbedtls_ecp_group *grp, mbedtls_ecp_point *P, const unsigned char *buf, size_t ilen)
Import a point from unsigned binary data.
mbedtls_mpi Y
Definition: ecp.h:100
mbedtls_ecp_group grp
Definition: ecp.h:158
int mbedtls_ecp_group_load(mbedtls_ecp_group *grp, mbedtls_ecp_group_id index)
Set a group using well-known domain parameters.
ECP key pair structure.
Definition: ecp.h:156
int mbedtls_ecp_set_zero(mbedtls_ecp_point *pt)
Set a point to zero.
int mbedtls_ecp_copy(mbedtls_ecp_point *P, const mbedtls_ecp_point *Q)
Copy the contents of point Q into P.
const mbedtls_ecp_group_id * mbedtls_ecp_grp_id_list(void)
Get the list of supported curves in order of preferrence (grp_id only)
int mbedtls_ecp_group_copy(mbedtls_ecp_group *dst, const mbedtls_ecp_group *src)
Copy the contents of a group object.
size_t nbits
Definition: ecp.h:138
int mbedtls_ecp_gen_keypair(mbedtls_ecp_group *grp, mbedtls_mpi *d, mbedtls_ecp_point *Q, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng)
Generate a keypair.
void mbedtls_ecp_point_free(mbedtls_ecp_point *pt)
Free the components of a point.
void mbedtls_ecp_keypair_init(mbedtls_ecp_keypair *key)
Initialize a key pair (as an invalid one)
size_t pbits
Definition: ecp.h:137
mbedtls_mpi X
Definition: ecp.h:99
Curve information for use by other modules.
Definition: ecp.h:80
Multi-precision integer library.
int mbedtls_ecp_gen_key(mbedtls_ecp_group_id grp_id, mbedtls_ecp_keypair *key, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng)
Generate a keypair.
ECP group structure.
Definition: ecp.h:129
int mbedtls_ecp_check_privkey(const mbedtls_ecp_group *grp, const mbedtls_mpi *d)
Check that an mbedtls_mpi is a valid private key for this curve.
mbedtls_ecp_group_id id
Definition: ecp.h:131
const mbedtls_ecp_curve_info * mbedtls_ecp_curve_info_from_grp_id(mbedtls_ecp_group_id grp_id)
Get curve information from an internal group identifier.
int mbedtls_ecp_tls_write_group(const mbedtls_ecp_group *grp, size_t *olen, unsigned char *buf, size_t blen)
Write the TLS ECParameters record for a group.
void mbedtls_ecp_group_free(mbedtls_ecp_group *grp)
Free the components of an ECP group.
int mbedtls_ecp_mul(mbedtls_ecp_group *grp, mbedtls_ecp_point *R, const mbedtls_mpi *m, const mbedtls_ecp_point *P, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng)
Multiplication by an integer: R = m * P (Not thread-safe to use same group in multiple threads) ...
int mbedtls_ecp_check_pubkey(const mbedtls_ecp_group *grp, const mbedtls_ecp_point *pt)
Check that a point is a valid public key on this curve.
mbedtls_mpi A
Definition: ecp.h:133
mbedtls_mpi P
Definition: ecp.h:132
void mbedtls_ecp_keypair_free(mbedtls_ecp_keypair *key)
Free the components of a key pair.
int mbedtls_ecp_tls_read_group(mbedtls_ecp_group *grp, const unsigned char **buf, size_t len)
Set a group from a TLS ECParameters record.
mbedtls_ecp_point Q
Definition: ecp.h:160
void * t_data
Definition: ecp.h:143
void mbedtls_ecp_point_init(mbedtls_ecp_point *pt)
Initialize a point (as zero)
mbedtls_ecp_group_id
Domain parameters (curve, subgroup and generator) identifiers.
Definition: ecp.h:53
int mbedtls_ecp_point_read_string(mbedtls_ecp_point *P, int radix, const char *x, const char *y)
Import a non-zero point from two ASCII strings.
int mbedtls_ecp_self_test(int verbose)
Checkup routine.
int mbedtls_ecp_point_write_binary(const mbedtls_ecp_group *grp, const mbedtls_ecp_point *P, int format, size_t *olen, unsigned char *buf, size_t buflen)
Export a point into unsigned binary data.
const mbedtls_ecp_curve_info * mbedtls_ecp_curve_info_from_tls_id(uint16_t tls_id)
Get curve information from a TLS NamedCurve value.
int mbedtls_ecp_tls_read_point(const mbedtls_ecp_group *grp, mbedtls_ecp_point *pt, const unsigned char **buf, size_t len)
Import a point from a TLS ECPoint record.
mbedtls_ecp_group_id grp_id
Definition: ecp.h:82
int mbedtls_ecp_gen_keypair_base(mbedtls_ecp_group *grp, const mbedtls_ecp_point *G, mbedtls_mpi *d, mbedtls_ecp_point *Q, int(*f_rng)(void *, unsigned char *, size_t), void *p_rng)
Generate a keypair with configurable base point.
mbedtls_mpi d
Definition: ecp.h:159
unsigned int h
Definition: ecp.h:139
int mbedtls_ecp_point_cmp(const mbedtls_ecp_point *P, const mbedtls_ecp_point *Q)
Compare two points.
int mbedtls_ecp_tls_write_point(const mbedtls_ecp_group *grp, const mbedtls_ecp_point *pt, int format, size_t *olen, unsigned char *buf, size_t blen)
Export a point as a TLS ECPoint record.
size_t T_size
Definition: ecp.h:145
mbedtls_ecp_point * T
Definition: ecp.h:144
mbedtls_ecp_point G
Definition: ecp.h:135
MPI structure.
Definition: bignum.h:144
ECP point structure (jacobian coordinates)
Definition: ecp.h:97
const mbedtls_ecp_curve_info * mbedtls_ecp_curve_info_from_name(const char *name)
Get curve information from a human-readable name.
const char * name
Definition: ecp.h:85
uint16_t bit_size
Definition: ecp.h:84
mbedtls_mpi B
Definition: ecp.h:134
void mbedtls_ecp_group_init(mbedtls_ecp_group *grp)
Initialize a group (to something meaningless)