ocrypto_curve_p256.h 4.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136
  1. /**
  2. * Copyright (c) 2019 - 2020, Nordic Semiconductor ASA
  3. *
  4. * All rights reserved.
  5. *
  6. * Redistribution and use in source and binary forms, with or without modification,
  7. * are permitted provided that the following conditions are met:
  8. *
  9. * 1. Redistributions of source code must retain the above copyright notice, this
  10. * list of conditions and the following disclaimer.
  11. *
  12. * 2. Redistributions in binary form, except as embedded into a Nordic
  13. * Semiconductor ASA integrated circuit in a product or a software update for
  14. * such product, must reproduce the above copyright notice, this list of
  15. * conditions and the following disclaimer in the documentation and/or other
  16. * materials provided with the distribution.
  17. *
  18. * 3. Neither the name of Nordic Semiconductor ASA nor the names of its
  19. * contributors may be used to endorse or promote products derived from this
  20. * software without specific prior written permission.
  21. *
  22. * 4. This software, with or without modification, must only be used with a
  23. * Nordic Semiconductor ASA integrated circuit.
  24. *
  25. * 5. Any software provided in binary form under this license must not be reverse
  26. * engineered, decompiled, modified and/or disassembled.
  27. *
  28. * THIS SOFTWARE IS PROVIDED BY NORDIC SEMICONDUCTOR ASA "AS IS" AND ANY EXPRESS
  29. * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
  30. * OF MERCHANTABILITY, NONINFRINGEMENT, AND FITNESS FOR A PARTICULAR PURPOSE ARE
  31. * DISCLAIMED. IN NO EVENT SHALL NORDIC SEMICONDUCTOR ASA OR CONTRIBUTORS BE
  32. * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
  33. * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE
  34. * GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
  35. * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
  36. * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
  37. * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  38. *
  39. */
  40. /**@file
  41. * @defgroup nrf_oberon_p256 ECC secp256r1 low-level APIs
  42. * @ingroup nrf_oberon
  43. * @{
  44. * @brief Type declarations and APIs for low-level elliptic curve point operations
  45. * based on the NIST secp256r1 curve.
  46. */
  47. #ifndef OCRYPTO_CURVE_P256_H
  48. #define OCRYPTO_CURVE_P256_H
  49. #include "ocrypto_sc_p256.h"
  50. #ifdef __cplusplus
  51. extern "C" {
  52. #endif
  53. // (x,y) only jacobian coordinates
  54. /**@cond */
  55. typedef struct {
  56. ocrypto_mod_p256 x;
  57. ocrypto_mod_p256 y;
  58. } ocrypto_cp_p256;
  59. /**@endcond */
  60. /** Load r.x from bytes, keep r.y.
  61. *
  62. * @param[out] r Point with r.x loaded, r.y kept.
  63. * @param p x as as array of bytes.
  64. *
  65. * @retval 0 If @p r is a valid curve point.
  66. * @retval -1 Otherwise.
  67. */
  68. int ocrypto_curve_p256_from32bytes(ocrypto_cp_p256 *r, const uint8_t p[32]);
  69. /** Load point from bytes.
  70. *
  71. * @param[out] r Loaded point.
  72. * @param p Point as array of bytes.
  73. *
  74. * @retval 0 If @p r is a valid curve point.
  75. * @retval -1 Otherwise.
  76. */
  77. int ocrypto_curve_p256_from64bytes(ocrypto_cp_p256 *r, const uint8_t p[64]);
  78. /** Store p.x to bytes.
  79. *
  80. * @param[out] r x stored as array.
  81. * @param p Point with x to be stored.
  82. */
  83. void ocrypto_curve_p256_to32bytes(uint8_t r[32], ocrypto_cp_p256 *p);
  84. /** Store p.x to bytes.
  85. *
  86. * @param[out] r Point stored as array.
  87. * @param p Point to be stored.
  88. */
  89. void ocrypto_curve_p256_to64bytes(uint8_t r[64], ocrypto_cp_p256 *p);
  90. /** P256 scalar multiplication.
  91. *
  92. * r = p * s
  93. * r = [0,0] if p = [0,0] or s mod q = 0
  94. *
  95. * @param[out] r Output point.
  96. * @param p Input point.
  97. * @param s Scalar.
  98. *
  99. * @retval -1 If r = [0,0].
  100. * @retval 0 If 0 < s < q.
  101. * @retval 1 If s > q.
  102. */
  103. int ocrypto_curve_p256_scalarmult(ocrypto_cp_p256 *r, const ocrypto_cp_p256 *p, const ocrypto_sc_p256 *s);
  104. /** P256 scalar base multiplication.
  105. *
  106. * r = basePoint * s
  107. * r = [0,0] if s mod q = 0
  108. *
  109. * @param[out] r Output point.
  110. * @param s Scalar.
  111. *
  112. * @retval -1 If r = [0,0].
  113. * @retval 0 If 0 < s < q.
  114. * @retval 1 If s > q.
  115. */
  116. int ocrypto_curve_p256_scalarmult_base(ocrypto_cp_p256 *r, const ocrypto_sc_p256 *s);
  117. #ifdef __cplusplus
  118. }
  119. #endif
  120. #endif /* #ifndef OCRYPTO_CURVE_P256_H */
  121. /** @} */