X-Git-Url: https://git.distorted.org.uk/u/mdw/catacomb/blobdiff_plain/e9026a0a6d8fc5cbcfa8d658176bfd2776cb550e..02dfbd5b7af7816959dbd39c1fe628451204e35f:/gdsa.c diff --git a/gdsa.c b/gdsa.c index 8723847..f60fb2d 100644 --- a/gdsa.c +++ b/gdsa.c @@ -1,6 +1,6 @@ /* -*-c-*- * - * $Id: gdsa.c,v 1.1 2004/04/04 19:42:59 mdw Exp $ + * $Id$ * * Generalized version of DSA * @@ -27,14 +27,6 @@ * MA 02111-1307, USA. */ -/*----- Revision history --------------------------------------------------* - * - * $Log: gdsa.c,v $ - * Revision 1.1 2004/04/04 19:42:59 mdw - * Add set -e. - * - */ - /*----- Header files ------------------------------------------------------*/ #include "gdsa.h" @@ -69,7 +61,7 @@ ghash *gdsa_beginhash(const gdsa *c) { return (GH_INIT(c->h)); } * isn't finalized. */ -void gdsa_endhash(gdsa *c, ghash *h) { ; } +void gdsa_endhash(const gdsa *c, ghash *h) { ; } /* --- @gdsa_sign@ --- * * @@ -96,16 +88,16 @@ void gdsa_sign(const gdsa *c, gdsa_sig *s, const void *m, mp *k) new_k: k = mprand_range(k, g->r, c->r, 0); have_k: - if (MP_ISZERO(k)) goto new_k; + if (MP_ZEROP(k)) goto new_k; G_EXP(g, z, g->g, k); sr = G_TOINT(g, sr, z); assert(sr); - if (MP_ISZERO(sr)) goto new_k; + if (MP_ZEROP(sr)) goto new_k; mp_div(0, &sr, sr, g->r); mpbarrett_create(&b, g->r); ss = mp_mul(ss, sr, c->u); ss = mpbarrett_reduce(&b, ss, ss); ss = mp_add(ss, ss, mr); mp_div(0, &ss, ss, g->r); - mp_gcd(0, 0, &k, g->r, k); + k = mp_modinv(k, k, g->r); ss = mp_mul(ss, ss, k); ss = mpbarrett_reduce(&b, ss, ss); s->r = sr; s->s = ss; mp_drop(k); mp_drop(mr); mpbarrett_destroy(&b); G_DESTROY(g, z); @@ -127,14 +119,14 @@ int gdsa_verify(const gdsa *c, const gdsa_sig *s, const void *m) group *g = c->g; group_expfactor e[2]; mpbarrett b; - mp *h = MP_NEW, *t; + mp *h, *t; ge *w; int rc = -1; if (MP_CMP(s->r, <, MP_ONE) || MP_CMP(s->r, >=, g->r) || MP_CMP(s->s, <, MP_ONE) || MP_CMP(s->s, >=, g->r)) return (-1); - mpbarrett_create(&b, g->r); mp_gcd(0, 0, &h, g->r, s->s); + mpbarrett_create(&b, g->r); h = mp_modinv(MP_NEW, s->s, g->r); e[0].base = g->g; e[1].base = c->p; t = mp_loadb(MP_NEW, m, c->h->hashsz); mp_div(0, &t, t, g->r); t = mp_mul(t, t, h); e[0].exp = t = mpbarrett_reduce(&b, t, t);