Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
43 changes: 15 additions & 28 deletions src/ec/suite_b/ops/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -351,7 +351,7 @@ impl PublicKeyOps {
) -> Result<Elem<R>, error::Unspecified> {
let _cpu = cpu::features();
let encoded_value = input.read_bytes(self.common.len())?;
let parsed = elem_parse_big_endian_fixed_consttime(q, encoded_value)?;
let parsed = parse_big_endian_fixed_consttime(q, encoded_value, AllowZero::Yes)?;
let mut r = Elem::zero();
let rr = Elem::from(&self.common.q.rr);
// Montgomery encode (elem_to_mont).
Expand Down Expand Up @@ -534,22 +534,6 @@ fn elem_sqr_mul_acc(
ops.elem_mul(acc, b, cpu)
}

#[inline]
pub(super) fn elem_parse_big_endian_fixed_consttime(
q: &Modulus<Q>,
bytes: untrusted::Input,
) -> Result<Elem<Unencoded>, error::Unspecified> {
parse_big_endian_fixed_consttime(q, bytes, AllowZero::Yes)
}

#[inline]
pub(super) fn scalar_parse_big_endian_fixed_consttime(
n: &Modulus<N>,
bytes: untrusted::Input,
) -> Result<Scalar, error::Unspecified> {
parse_big_endian_fixed_consttime(n, bytes, AllowZero::No)
}

#[inline]
pub(super) fn scalar_parse_big_endian_variable(
n: &Modulus<N>,
Expand Down Expand Up @@ -583,7 +567,7 @@ pub(super) fn scalar_parse_big_endian_partially_reduced_variable_consttime(
Ok(r)
}

fn parse_big_endian_fixed_consttime<M>(
pub(super) fn parse_big_endian_fixed_consttime<M>(
m: &Modulus<M>,
bytes: untrusted::Input,
allow_zero: AllowZero,
Expand Down Expand Up @@ -863,9 +847,9 @@ mod tests {
test::run(test_file, |section, test_case| {
assert_eq!(section, "");

let mut a = consume_elem(q, test_case, "a");
let b = consume_elem(q, test_case, "b");
let r = consume_elem(q, test_case, "r");
let mut a = consume_elem_mont(q, test_case, "a");
let b = consume_elem_mont(q, test_case, "b");
let r = consume_elem_mont(q, test_case, "r");
q.elem_mul(&mut a, &b);
assert_limbs_are_equal(ops, &a.limbs, &r.limbs);

Expand Down Expand Up @@ -1298,7 +1282,8 @@ mod tests {
let num_limbs = q.num_limbs.into();
let bytes = test::from_hex(elems[i]).unwrap();
let bytes = untrusted::Input::from(&bytes);
let r: Elem<Unencoded> = elem_parse_big_endian_fixed_consttime(q, bytes).unwrap();
let r: Elem<Unencoded> =
parse_big_endian_fixed_consttime(q, bytes, AllowZero::Yes).unwrap();
// XXX: “Transmute” this to `Elem<R>` limbs.
limbs_out[(i * num_limbs)..((i + 1) * num_limbs)].copy_from_slice(&r.limbs[..num_limbs]);
}
Expand All @@ -1318,7 +1303,7 @@ mod tests {
let bytes = test::from_hex(elems[i]).unwrap();
let bytes = untrusted::Input::from(&bytes);
let unencoded: Elem<Unencoded> =
elem_parse_big_endian_fixed_consttime(q, bytes).unwrap();
parse_big_endian_fixed_consttime(q, bytes, AllowZero::Yes).unwrap();
// XXX: “Transmute” this to `Elem<R>` limbs.
Elem {
limbs: unencoded.limbs,
Expand Down Expand Up @@ -1365,13 +1350,17 @@ mod tests {
}
}

fn consume_elem(q: &Modulus<Q>, test_case: &mut test::TestCase, name: &str) -> Elem<R> {
fn consume_elem(q: &Modulus<Q>, test_case: &mut test::TestCase, name: &str) -> Elem<Unencoded> {
let unpadded_bytes = test_case.consume_bytes(name);
let mut bytes = vec![0; q.bytes_len() - unpadded_bytes.len()];
bytes.extend(&unpadded_bytes);

let bytes = untrusted::Input::from(&bytes);
let r: Elem<Unencoded> = elem_parse_big_endian_fixed_consttime(q, bytes).unwrap();
parse_big_endian_fixed_consttime(q, bytes, AllowZero::Yes).unwrap()
}

fn consume_elem_mont(q: &Modulus<Q>, test_case: &mut test::TestCase, name: &str) -> Elem<R> {
let r = consume_elem(q, test_case, name);
// XXX: “Transmute” this to an `Elem<R>`.
Elem {
limbs: r.limbs,
Expand All @@ -1391,9 +1380,7 @@ mod tests {
test_case: &mut test::TestCase,
name: &str,
) -> Scalar<R> {
let bytes = test_case.consume_bytes(name);
let bytes = untrusted::Input::from(&bytes);
let s = scalar_parse_big_endian_variable(n, AllowZero::Yes, bytes).unwrap();
let s = consume_scalar(n, test_case, name);
// “Transmute” it to a `Scalar<R>`.
Scalar {
limbs: s.limbs,
Expand Down
9 changes: 7 additions & 2 deletions src/ec/suite_b/private_key.rs
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,12 @@
//! ECDSA signing).

use super::{ops::*, verify_affine_point_is_on_the_curve};
use crate::{arithmetic::montgomery::R, cpu, ec, error, limb, rand};
use crate::{
arithmetic::montgomery::R,
cpu, ec, error,
limb::{self, AllowZero},
rand,
};

/// Generates a random scalar in the range [1, n).
pub(super) fn random_scalar(
Expand Down Expand Up @@ -125,7 +130,7 @@ pub(super) fn scalar_from_big_endian_bytes(
// way, we avoid needing to compute or store the value (n - 1), we avoid the
// need to implement a function to add one to a scalar, and we avoid needing
// to convert the scalar back into an array of bytes.
scalar_parse_big_endian_fixed_consttime(n, untrusted::Input::from(bytes))
parse_big_endian_fixed_consttime(n, untrusted::Input::from(bytes), AllowZero::No)
}

pub(super) fn public_from_private(
Expand Down
Loading