3 * $Id: rsa-pub.c,v 1.3 2004/04/08 01:36:15 mdw Exp $
5 * [RSA encryption with padding *
6 * (c) 2000 Straylight/Edgeware
9 /*----- Licensing notice --------------------------------------------------*
11 * This file is part of Catacomb.
13 * Catacomb is free software; you can redistribute it and/or modify
14 * it under the terms of the GNU Library General Public License as
15 * published by the Free Software Foundation; either version 2 of the
16 * License, or (at your option) any later version.
18 * Catacomb is distributed in the hope that it will be useful,
19 * but WITHOUT ANY WARRANTY; without even the implied warranty of
20 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21 * GNU Library General Public License for more details.
23 * You should have received a copy of the GNU Library General Public
24 * License along with Catacomb; if not, write to the Free
25 * Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
29 /*----- Header files ------------------------------------------------------*/
31 #include <mLib/alloc.h>
32 #include <mLib/bits.h>
33 #include <mLib/dstr.h>
39 /*----- Public key operations ---------------------------------------------*/
41 /* --- @rsa_pubcreate@ --- *
43 * Arguments: @rsa_pubctx *rd@ = pointer to an RSA public key context
44 * @rsa_pub *rp@ = pointer to RSA public key
48 * Use: Initializes an RSA public-key context.
51 void rsa_pubcreate(rsa_pubctx
*rd
, rsa_pub
*rp
)
54 mpmont_create(&rd
->mm
, rp
->n
);
57 /* --- @rsa_pubdestroy@ --- *
59 * Arguments: @rsa_pubctx *rd@ = pointer to an RSA public key context
63 * Use: Destroys an RSA public-key context.
66 void rsa_pubdestroy(rsa_pubctx
*rd
)
68 mpmont_destroy(&rd
->mm
);
71 /* --- @rsa_pubop@ --- *
73 * Arguments: @rsa_pubctx *rd@ = pointer to an RSA public key context
74 * @mp *d@ = destination
75 * @mp *p@ = input message
77 * Returns: The transformed output message.
79 * Use: Performs an RSA public key operation.
82 mp
*rsa_pubop(rsa_pubctx
*rd
, mp
*d
, mp
*p
)
84 return (mpmont_exp(&rd
->mm
, d
, p
, rd
->rp
->e
));
87 /* --- @rsa_qpubop@ --- *
89 * Arguments: @rsa_pub *rp@ = pointer to RSA parameters
90 * @mp *d@ = destination
91 * @mp *p@ = input message
93 * Returns: Correctly transformed output message.
95 * Use: Performs an RSA public key operation.
98 mp
*rsa_qpubop(rsa_pub
*rp
, mp
*d
, mp
*c
)
101 rsa_pubcreate(&rd
, rp
);
102 d
= rsa_pubop(&rd
, d
, c
);
107 /*----- Operations with padding -------------------------------------------*/
109 /* --- @rsa_encrypt@ --- *
111 * Arguments: @rsa_pubctx *rp@ = pointer to an RSA public key context
112 * @mp *d@ = proposed destination integer
113 * @const void *m@ = pointer to input message
114 * @size_t msz@ = size of input message
115 * @rsa_pad *e@ = encoding procedure
116 * @void *earg@ = argument pointer for encoding procedure
118 * Returns: The encrypted message, as a multiprecision integer, or null
121 * Use: Does RSA encryption.
124 mp
*rsa_encrypt(rsa_pubctx
*rp
, mp
*d
, const void *m
, size_t msz
,
125 rsa_pad
*e
, void *earg
)
128 unsigned long nb
= mp_bits(rp
->rp
->n
);
129 size_t n
= (nb
+ 7)/8;
130 arena
*a
= d
&& d
->a ? d
->a
->a
: arena_global
;
133 d
= e(d
, m
, msz
, p
, n
, nb
, earg
);
135 return (d ?
rsa_pubop(rp
, d
, d
) : 0);
138 /* --- @rsa_verify@ --- *
140 * Arguments: @rsa_pubctx *rp@ = pointer to an RSA public key contxt
141 * @mp *s@ = the signature, as a multiprecision integer
142 * @const void *m@ = pointer to message to verify, or null
143 * @size_t msz@ = size of input message
144 * @dstr *d@ = pointer to output string, or null
145 * @rsa_vfrunpad *e@ = decoding procedure
146 * @void *earg@ = argument pointer for decoding procedure
148 * Returns: The length of the output string if successful (0 if no output
149 * was wanted); negative on failure.
151 * Use: Does RSA signature verification. To use a signature scheme
152 * with recovery, pass in @m == 0@ and @d != 0@: the recovered
153 * message should appear in @d@. To use a signature scheme with
154 * appendix, provide @m != 0@ and @d == 0@; the result should be
158 int rsa_verify(rsa_pubctx
*rp
, mp
*s
, const void *m
, size_t msz
,
159 dstr
*d
, rsa_vrfunpad
*e
, void *earg
)
161 mp
*p
= rsa_pubop(rp
, MP_NEW
, s
);
162 unsigned long nb
= mp_bits(rp
->rp
->n
);
163 size_t n
= (nb
+ 7)/8;
167 /* --- Decoder protocol --- *
169 * We deal with two kinds of decoders: ones with message recovery and ones
170 * with appendix. A decoder with recovery will leave a message in the
171 * buffer and exit nonzero: we'll check that against @m@ if provided and
172 * just leave it otherwise. A decoder with appendix will inspect @m@ and
173 * return zero or @-1@ itself.
178 rc
= e(p
, m
, msz
, (octet
*)d
->buf
+ d
->len
, n
, nb
, earg
);
180 if (rc
!= msz
|| memcmp(d
->buf
+ d
->len
, m
, msz
) != 0)
192 /*----- That's all, folks -------------------------------------------------*/