/* -*-c-*-
*
- * $Id: gdsa.c,v 1.1 2004/04/04 19:42:59 mdw Exp $
+ * $Id$
*
* Generalized version of DSA
*
* (c) 2004 Straylight/Edgeware
*/
-/*----- Licensing notice --------------------------------------------------*
+/*----- Licensing notice --------------------------------------------------*
*
* This file is part of Catacomb.
*
* it under the terms of the GNU Library General Public License as
* published by the Free Software Foundation; either version 2 of the
* License, or (at your option) any later version.
- *
+ *
* Catacomb is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Library General Public License for more details.
- *
+ *
* You should have received a copy of the GNU Library General Public
* License along with Catacomb; if not, write to the Free
* Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
* MA 02111-1307, USA.
*/
-/*----- Revision history --------------------------------------------------*
- *
- * $Log: gdsa.c,v $
- * Revision 1.1 2004/04/04 19:42:59 mdw
- * Add set -e.
- *
- */
-
/*----- Header files ------------------------------------------------------*/
+#include "dsa.h"
#include "gdsa.h"
#include "group.h"
#include "ghash.h"
* Returns: ---
*
* Use: Does any final thing that DSA wants to do when hashing a
- * message. (Actually, there's nothing.) The hashing context
+ * message. (Actually, there's nothing.) The hashing context
* isn't finalized.
*/
-void gdsa_endhash(gdsa *c, ghash *h) { ; }
+void gdsa_endhash(const gdsa *c, ghash *h) { ; }
/* --- @gdsa_sign@ --- *
*
void gdsa_sign(const gdsa *c, gdsa_sig *s, const void *m, mp *k)
{
group *g = c->g;
- mp *mr = mp_loadb(MP_NEW, m, c->h->hashsz);
+ mp *mr = dsa_h2n(MP_NEW, g->r, m, c->h->hashsz);
ge *z = G_CREATE(g);
mp *sr = s->r, *ss = s->s;
mpbarrett b;
new_k:
k = mprand_range(k, g->r, c->r, 0);
have_k:
- if (MP_ISZERO(k)) goto new_k;
+ if (MP_ZEROP(k)) goto new_k;
G_EXP(g, z, g->g, k);
sr = G_TOINT(g, sr, z); assert(sr);
- if (MP_ISZERO(sr)) goto new_k;
+ if (MP_ZEROP(sr)) goto new_k;
mp_div(0, &sr, sr, g->r);
mpbarrett_create(&b, g->r);
ss = mp_mul(ss, sr, c->u); ss = mpbarrett_reduce(&b, ss, ss);
ss = mp_add(ss, ss, mr); mp_div(0, &ss, ss, g->r);
- mp_gcd(0, 0, &k, g->r, k);
+ k = mp_modinv(k, k, g->r);
ss = mp_mul(ss, ss, k); ss = mpbarrett_reduce(&b, ss, ss);
s->r = sr; s->s = ss;
mp_drop(k); mp_drop(mr); mpbarrett_destroy(&b); G_DESTROY(g, z);
group *g = c->g;
group_expfactor e[2];
mpbarrett b;
- mp *h = MP_NEW, *t;
+ mp *h, *t;
ge *w;
int rc = -1;
if (MP_CMP(s->r, <, MP_ONE) || MP_CMP(s->r, >=, g->r) ||
MP_CMP(s->s, <, MP_ONE) || MP_CMP(s->s, >=, g->r))
return (-1);
- mpbarrett_create(&b, g->r); mp_gcd(0, 0, &h, g->r, s->s);
+ mpbarrett_create(&b, g->r); h = mp_modinv(MP_NEW, s->s, g->r);
e[0].base = g->g; e[1].base = c->p;
- t = mp_loadb(MP_NEW, m, c->h->hashsz); mp_div(0, &t, t, g->r);
+ t = dsa_h2n(MP_NEW, g->r, m, c->h->hashsz); mp_div(0, &t, t, g->r);
t = mp_mul(t, t, h); e[0].exp = t = mpbarrett_reduce(&b, t, t);
h = mp_mul(h, s->r, h); e[1].exp = h = mpbarrett_reduce(&b, h, h);
w = G_CREATE(g); G_MEXP(g, w, e, 2);
}
static void showmp(const char *p, mp *x, int r) {
- fprintf(stderr, "*** %s = ", p); mp_writefile(x, stderr, r);
+ fprintf(stderr, "*** %s = ", p); mp_writefile(x, stderr, r);
putc('\n', stderr);
}