3 * $Id: bbs-gen.c,v 1.3 2000/02/12 18:21:02 mdw Exp $
5 * Generate Blum integers
7 * (c) 1999 Straylight/Edgeware
10 /*----- Licensing notice --------------------------------------------------*
12 * This file is part of Catacomb.
14 * Catacomb is free software; you can redistribute it and/or modify
15 * it under the terms of the GNU Library General Public License as
16 * published by the Free Software Foundation; either version 2 of the
17 * License, or (at your option) any later version.
19 * Catacomb is distributed in the hope that it will be useful,
20 * but WITHOUT ANY WARRANTY; without even the implied warranty of
21 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
22 * GNU Library General Public License for more details.
24 * You should have received a copy of the GNU Library General Public
25 * License along with Catacomb; if not, write to the Free
26 * Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
30 /*----- Revision history --------------------------------------------------*
33 * Revision 1.3 2000/02/12 18:21:02 mdw
34 * Overhaul of key management (again).
36 * Revision 1.2 1999/12/22 15:52:28 mdw
37 * Reworking for new prime-search system.
39 * Revision 1.1 1999/12/10 23:14:59 mdw
40 * Blum-Blum-Shub generator, and Blum-Goldwasser encryption.
44 /*----- Header files ------------------------------------------------------*/
54 #include "strongprime.h"
56 /*----- Data structures ---------------------------------------------------*/
58 typedef struct gcdctx
{
64 /*----- Custom stepper ----------------------------------------------------*/
66 static int gcdstep(int rq
, pgen_event
*ev
, void *p
)
74 /* --- Set everything up --- */
78 if ((p
->v
[0] & 3) != 3)
79 p
= mp_add(p
, p
, g
->jp
.m
);
80 rc
= pfilt_create(&g
->p
, p
);
81 g
->q
= mp_lsr(MP_NEW
, p
, 1);
82 g
->jq
= MP_COPY(g
->jp
.m
);
83 pfilt_muladd(&g
->jp
, &g
->jp
, 2, 0);
84 g
->jq
= mp_lsr(MP_NEW
, p
, 1);
88 /* --- Grind through another iteration --- */
92 rc
= pfilt_jump(&g
->p
, &g
->jp
);
93 g
->q
= mp_add(g
->q
, g
->q
, g
->jq
);
96 /* --- Finished --- */
105 /* --- Step on until everything is OK --- */
108 if (rc
!= PGEN_FAIL
) {
109 mp_gcd(&z
, 0, 0, g
->r
, g
->q
);
110 if (MP_CMP(z
, !=, MP_ONE
))
115 rc
= pfilt_jump(&g
->p
, &g
->jp
);
116 g
->q
= mp_add(g
->q
, g
->q
, g
->jq
);
120 ev
->m
= MP_COPY(g
->p
.m
);
124 /*----- Main code ---------------------------------------------------------*/
126 /* --- @bbs_gen@ --- *
128 * Arguments: @bbs_param *bp@ = pointer to parameter block
129 * @unsigned nbits@ = number of bits in the modulus
130 * @grand *r@ = pointer to random number source
131 * @unsigned n@ = number of attempts to make
132 * @pgen_proc *event@ = event handler function
133 * @void *ectx@ = argument for event handler
135 * Returns: If it worked OK, @PGEN_DONE@, otherwise @PGEN_ABORT@.
137 * Use: Finds two prime numbers %$p'$% and %$q'$% such that both are
138 * congruent to %$3 \bmod 4$%, and $(p - 1)/2$% and
139 * %$(q - 1)/2$% have no common factors. The product %$n = pq$%
140 * is eminently suitable for use as a modulus in a Blum-Blum-
141 * Shub pseudorandom bit generator.
144 int bbs_gen(bbs_param
*bp
, unsigned nbits
, grand
*r
, unsigned n
,
145 pgen_proc
*event
, void *ectx
)
150 unsigned nb
= nbits
/2;
153 /* --- Generate @p@ --- */
155 if ((x
= strongprime_setup("p", x
, &j
.jq
, nb
, r
, n
, event
, ectx
)) == 0)
157 bp
->p
= pgen("p", MP_NEW
, x
, event
, ectx
, n
, pgen_safejump
, &j
,
158 rabin_iters(nb
), pgen_test
, &rb
);
159 pfilt_destroy(&j
.jq
);
163 /* --- Generate @q@ --- */
166 if ((x
= strongprime_setup("q", x
, &g
.jp
, nb
, r
, n
, event
, ectx
)) == 0)
168 g
.r
= mp_lsr(MP_NEW
, bp
->p
, 1);
169 bp
->q
= pgen("q", MP_NEW
, x
, event
, ectx
, n
, gcdstep
, &g
,
170 rabin_iters(nb
), pgen_test
, &rb
);
171 pfilt_destroy(&g
.jp
);
176 /* --- Compute @n@ --- */
178 bp
->n
= mp_mul(MP_NEW
, bp
->p
, bp
->q
);
182 /* --- Tidy up if things went wrong --- */
192 /*----- That's all, folks -------------------------------------------------*/