ReactOS 0.4.17-dev-1005-g171e1de
symcrypt_low_level.h File Reference
This graph shows which files directly or indirectly include this file:

Go to the source code of this file.

Classes

struct  _SYMCRYPT_SCSTABLE
 

Macros

#define SYMCRYPT_FLAG_DATA_PUBLIC   (0x01)
 
#define SYMCRYPT_SIZEOF_INT_FROM_BITS(_bitsize)   SYMCRYPT_INTERNAL_SIZEOF_INT_FROM_BITS( _bitsize )
 
#define SYMCRYPT_SIZEOF_DIVISOR_FROM_BITS(_bitsize)   SYMCRYPT_INTERNAL_SIZEOF_DIVISOR_FROM_BITS( _bitsize )
 
#define SYMCRYPT_SIZEOF_MODULUS_FROM_BITS(_bitsize)   SYMCRYPT_INTERNAL_SIZEOF_MODULUS_FROM_BITS( _bitsize )
 
#define SYMCRYPT_SIZEOF_MODELEMENT_FROM_BITS(_bitsize)   SYMCRYPT_INTERNAL_SIZEOF_MODELEMENT_FROM_BITS( _bitsize )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_MUL(_nResultDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_MUL( _nResultDigits )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_TO_DIVISOR(_nDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_TO_DIVISOR( _nDigits )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_DIVMOD(_nSrcDigits, _nDivisorDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_DIVMOD( _nSrcDigits, _nDivisorDigits )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_EXTENDED_GCD(_nDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_EXTENDED_GCD( _nDigits )
 
#define SYMCRYPT_FLAG_GCD_INPUTS_NOT_BOTH_EVEN   (0x02)
 
#define SYMCRYPT_FLAG_GCD_PUBLIC   (0x04)
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_CRT_GENERATION(_nDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_CRT_GENERATION( _nDigits )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_CRT_SOLUTION(_nDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_CRT_SOLUTION( _nDigits )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_IS_PRIME(_nDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_IS_PRIME( _nDigits )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_PRIME_GEN(_nDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_PRIME_GEN( _nDigits )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_TO_MODULUS(_nDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_TO_MODULUS( _nDigits )
 
#define SYMCRYPT_FLAG_MODULUS_PARITY_PUBLIC   (0x02)
 
#define SYMCRYPT_FLAG_MODULUS_ADDITIVE_ONLY   (0x04)
 
#define SYMCRYPT_FLAG_MODULUS_PRIME   (0x08)
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_COMMON_MOD_OPERATIONS(_nDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_COMMON_MOD_OPERATIONS( _nDigits )
 
#define SYMCRYPT_FLAG_MODRANDOM_ALLOW_ZERO   (0x01)
 
#define SYMCRYPT_FLAG_MODRANDOM_ALLOW_ONE   (0x02)
 
#define SYMCRYPT_FLAG_MODRANDOM_ALLOW_MINUSONE   (0x04)
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_MODINV(_nDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_MODINV( _nDigits )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_MODEXP(_nDigits)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_MODEXP( _nDigits )
 
#define SYMCRYPT_MODMULTIEXP_MAX_NBASES   (8)
 
#define SYMCRYPT_MODMULTIEXP_MAX_NBITSEXP   (SYMCRYPT_INT_MAX_BITS)
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_MODMULTIEXP(_nDigits, _nBases, _nBitsExp)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_MODMULTIEXP( _nDigits, _nBases, _nBitsExp )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_RSA_OAEP(_hashAlgorithm, _nBytesOAEP)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_RSA_OAEP( _hashAlgorithm, _nBytesOAEP )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_RSA_PKCS1(_nBytesPKCS1)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_RSA_PKCS1( _nBytesPKCS1 )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_RSA_PSS(_hashAlgorithm, _nBytesMessage, _nBytesPSS)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_RSA_PSS( _hashAlgorithm, _nBytesMessage, _nBytesPSS )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_GETSET_VALUE_ECURVE_OPERATIONS(_pCurve)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_GETSET_VALUE_ECURVE_OPERATIONS( _pCurve )
 
#define SYMCRYPT_FLAG_ECC_LL_COFACTOR_MUL   (0x20)
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_COMMON_ECURVE_OPERATIONS(_pCurve)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_COMMON_ECURVE_OPERATIONS( _pCurve )
 
#define SYMCRYPT_FLAG_ECPOINT_EQUAL   (0x01)
 
#define SYMCRYPT_FLAG_ECPOINT_NEG_EQUAL   (0x02)
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_SCALAR_ECURVE_OPERATIONS(_pCurve)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_SCALAR_ECURVE_OPERATIONS( (_pCurve), 1 )
 
#define SYMCRYPT_SCRATCH_BYTES_FOR_MULTI_SCALAR_ECURVE_OPERATIONS(_pCurve, _nPoints)   SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_SCALAR_ECURVE_OPERATIONS( (_pCurve), (_nPoints) )
 
#define SYMCRYPT_ECURVE_MULTI_SCALAR_MUL_MAX_NPOINTS   (2)
 
#define SYMCRYPT_RNG_AES_INTERNAL_SEED_SIZE   (32 + 16)
 
#define SYMCRYPT_SAE_MAX_MOD_SIZE_BITS   384
 
#define SYMCRYPT_SAE_MAX_MOD_SIZE_BYTES   SYMCRYPT_BYTES_FROM_BITS( SYMCRYPT_SAE_MAX_MOD_SIZE_BITS )
 
#define SYMCRYPT_SAE_MAX_EC_POINT_SIZE_BYTES   ( 2 * SYMCRYPT_SAE_MAX_MOD_SIZE_BYTES )
 
#define SYMCRYPT_SAE_MAX_HMAC_OUTPUT_SIZE_BYTES   SYMCRYPT_BYTES_FROM_BITS( 384 )
 

Typedefs

typedef const struct _SYMCRYPT_TRIALDIVISION_CONTEXT * PCSYMCRYPT_TRIALDIVISION_CONTEXT
 
typedef struct _SYMCRYPT_SCSTABLE SYMCRYPT_SCSTABLE
 
typedef struct _SYMCRYPT_SCSTABLE * PSYMCRYPT_SCSTABLE
 
typedef enum _SYMCRYPT_802_11_SAE_GROUP SYMCRYPT_802_11_SAE_GROUP
 
typedef struct _SYMCRYPT_802_11_SAE_CUSTOM_STATE SYMCRYPT_802_11_SAE_CUSTOM_STATE
 
typedef struct _SYMCRYPT_802_11_SAE_CUSTOM_STATE * PSYMCRYPT_802_11_SAE_CUSTOM_STATE
 
typedef const SYMCRYPT_802_11_SAE_CUSTOM_STATE * PCSYMCRYPT_802_11_SAE_CUSTOM_STATE
 

Enumerations

enum  _SYMCRYPT_802_11_SAE_GROUP { SYMCRYPT_SAE_GROUP_19 = 19 , SYMCRYPT_SAE_GROUP_20 }
 

Functions

UINT32 SymCryptDigitsFromBits (UINT32 nBits)
 
PSYMCRYPT_INT SYMCRYPT_CALL SymCryptIntAllocate (UINT32 nDigits)
 
VOID SYMCRYPT_CALL SymCryptIntFree (_Out_ PSYMCRYPT_INT piObj)
 
UINT32 SYMCRYPT_CALL SymCryptSizeofIntFromDigits (UINT32 nDigits)
 
PSYMCRYPT_INT SYMCRYPT_CALL SymCryptIntCreate (_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, UINT32 nDigits)
 
VOID SYMCRYPT_CALL SymCryptIntWipe (_Out_ PSYMCRYPT_INT piObj)
 
VOID SYMCRYPT_CALL SymCryptIntCopy (_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst)
 
VOID SYMCRYPT_CALL SymCryptIntMaskedCopy (_In_ PCSYMCRYPT_INT piSrc, _Inout_ PSYMCRYPT_INT piDst, UINT32 mask)
 
VOID SYMCRYPT_CALL SymCryptIntConditionalCopy (_In_ PCSYMCRYPT_INT piSrc, _Inout_ PSYMCRYPT_INT piDst, UINT32 cond)
 
VOID SYMCRYPT_CALL SymCryptIntConditionalSwap (_Inout_ PSYMCRYPT_INT piSrc1, _Inout_ PSYMCRYPT_INT piSrc2, UINT32 cond)
 
UINT32 SYMCRYPT_CALL SymCryptIntBitsizeOfObject (_In_ PCSYMCRYPT_INT piSrc)
 
UINT32 SYMCRYPT_CALL SymCryptIntDigitsizeOfObject (_In_ PCSYMCRYPT_INT piSrc)
 
PSYMCRYPT_DIVISOR SYMCRYPT_CALL SymCryptDivisorAllocate (UINT32 nDigits)
 
VOID SYMCRYPT_CALL SymCryptDivisorFree (_Out_ PSYMCRYPT_DIVISOR pdObj)
 
UINT32 SYMCRYPT_CALL SymCryptSizeofDivisorFromDigits (UINT32 nDigits)
 
PSYMCRYPT_DIVISOR SYMCRYPT_CALL SymCryptDivisorCreate (_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, UINT32 nDigits)
 
VOID SYMCRYPT_CALL SymCryptDivisorWipe (_Out_ PSYMCRYPT_DIVISOR pdObj)
 
VOID SymCryptDivisorCopy (_In_ PCSYMCRYPT_DIVISOR pdSrc, _Out_ PSYMCRYPT_DIVISOR pdDst)
 
UINT32 SYMCRYPT_CALL SymCryptDivisorDigitsizeOfObject (_In_ PCSYMCRYPT_DIVISOR pdSrc)
 
PSYMCRYPT_MODULUS SYMCRYPT_CALL SymCryptModulusAllocate (UINT32 nDigits)
 
VOID SYMCRYPT_CALL SymCryptModulusFree (_Out_ PSYMCRYPT_MODULUS pmObj)
 
UINT32 SYMCRYPT_CALL SymCryptSizeofModulusFromDigits (UINT32 nDigits)
 
PSYMCRYPT_MODULUS SYMCRYPT_CALL SymCryptModulusCreate (_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, UINT32 nDigits)
 
VOID SYMCRYPT_CALL SymCryptModulusWipe (_Out_ PSYMCRYPT_MODULUS pmObj)
 
VOID SymCryptModulusCopy (_In_ PCSYMCRYPT_MODULUS pmSrc, _Out_ PSYMCRYPT_MODULUS pmDst)
 
UINT32 SYMCRYPT_CALL SymCryptModulusDigitsizeOfObject (_In_ PCSYMCRYPT_MODULUS pmSrc)
 
PSYMCRYPT_MODELEMENT SYMCRYPT_CALL SymCryptModElementAllocate (_In_ PCSYMCRYPT_MODULUS pmMod)
 
VOID SYMCRYPT_CALL SymCryptModElementFree (_In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peObj)
 
UINT32 SYMCRYPT_CALL SymCryptSizeofModElementFromModulus (PCSYMCRYPT_MODULUS pmMod)
 
PSYMCRYPT_MODELEMENT SYMCRYPT_CALL SymCryptModElementCreate (_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, _In_ PCSYMCRYPT_MODULUS pmMod)
 
VOID SYMCRYPT_CALL SymCryptModElementWipe (_In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst)
 
VOID SymCryptModElementCopy (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_MODELEMENT peDst)
 
VOID SymCryptModElementMaskedCopy (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_MODELEMENT peDst, UINT32 mask)
 
VOID SymCryptModElementConditionalSwap (_In_ PCSYMCRYPT_MODULUS pmMod, _Inout_ PSYMCRYPT_MODELEMENT peData1, _Inout_ PSYMCRYPT_MODELEMENT peData2, _In_ UINT32 cond)
 
BOOLEAN SYMCRYPT_CALL SymCryptEcurveBufferSizesFromParams (_In_ PCSYMCRYPT_ECURVE_PARAMS pParams, _Out_ SIZE_T *pcbCurve, _Out_ SIZE_T *pcbScratch)
 
PSYMCRYPT_ECURVE SYMCRYPT_CALL SymCryptEcurveCreate (_In_ PSYMCRYPT_ECURVE_PARAMS pParams, _In_ UINT32 flags, _Out_writes_bytes_(cbCurve) PBYTE pbCurve, SIZE_T cbCurve, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
PSYMCRYPT_ECPOINT SYMCRYPT_CALL SymCryptEcpointAllocate (_In_ PCSYMCRYPT_ECURVE pCurve)
 
VOID SYMCRYPT_CALL SymCryptEcpointFree (_In_ PCSYMCRYPT_ECURVE pCurve, _Out_ PSYMCRYPT_ECPOINT poDst)
 
UINT32 SYMCRYPT_CALL SymCryptSizeofEcpointFromCurve (PCSYMCRYPT_ECURVE pCurve)
 
PSYMCRYPT_ECPOINT SYMCRYPT_CALL SymCryptEcpointCreate (_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, _In_ PCSYMCRYPT_ECURVE pCurve)
 
PSYMCRYPT_ECPOINT SYMCRYPT_CALL SymCryptEcpointRetrieveHandle (_In_ PBYTE pbBuffer)
 
VOID SYMCRYPT_CALL SymCryptEcpointWipe (_In_ PCSYMCRYPT_ECURVE pCurve, _Out_ PSYMCRYPT_ECPOINT poDst)
 
VOID SymCryptEcpointCopy (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, _Out_ PSYMCRYPT_ECPOINT poDst)
 
VOID SymCryptEcpointMaskedCopy (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, _Out_ PSYMCRYPT_ECPOINT poDst, UINT32 mask)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptIntCopyMixedSize (_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst)
 
UINT32 SYMCRYPT_CALL SymCryptIntBitsizeOfValue (_In_ PCSYMCRYPT_INT piSrc)
 
VOID SYMCRYPT_CALL SymCryptIntSetValueUint32 (UINT32 u32Src, _Out_ PSYMCRYPT_INT piDst)
 
VOID SYMCRYPT_CALL SymCryptIntSetValueUint64 (UINT64 u64Src, _Out_ PSYMCRYPT_INT piDst)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptIntSetValue (_In_reads_bytes_(cbSrc) PCBYTE pbSrc, SIZE_T cbSrc, SYMCRYPT_NUMBER_FORMAT format, _Out_ PSYMCRYPT_INT piDst)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptIntGetValue (_In_ PCSYMCRYPT_INT piSrc, _Out_writes_bytes_(cbDst) PBYTE pbDst, SIZE_T cbDst, SYMCRYPT_NUMBER_FORMAT format)
 
UINT32 SYMCRYPT_CALL SymCryptIntGetValueLsbits32 (_In_ PCSYMCRYPT_INT piSrc)
 
UINT64 SYMCRYPT_CALL SymCryptIntGetValueLsbits64 (_In_ PCSYMCRYPT_INT piSrc)
 
UINT32 SYMCRYPT_CALL SymCryptIntIsEqualUint32 (_In_ PCSYMCRYPT_INT piSrc1, _In_ UINT32 u32Src2)
 
UINT32 SYMCRYPT_CALL SymCryptIntIsEqual (_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2)
 
UINT32 SYMCRYPT_CALL SymCryptIntIsLessThan (_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2)
 
UINT32 SYMCRYPT_CALL SymCryptIntAddUint32 (_In_ PCSYMCRYPT_INT piSrc1, UINT32 u32Src2, _Out_ PSYMCRYPT_INT piDst)
 
UINT32 SYMCRYPT_CALL SymCryptIntAddSameSize (_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
 
UINT32 SYMCRYPT_CALL SymCryptIntAddMixedSize (_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
 
UINT32 SYMCRYPT_CALL SymCryptIntSubUint32 (_In_ PCSYMCRYPT_INT piSrc1, UINT32 Src2, _Out_ PSYMCRYPT_INT piDst)
 
UINT32 SYMCRYPT_CALL SymCryptIntSubSameSize (_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
 
UINT32 SYMCRYPT_CALL SymCryptIntSubMixedSize (_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
 
VOID SYMCRYPT_CALL SymCryptIntNeg (_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst)
 
VOID SYMCRYPT_CALL SymCryptIntMulPow2 (_In_ PCSYMCRYPT_INT piSrc, SIZE_T exp, _Out_ PSYMCRYPT_INT piDst)
 
VOID SYMCRYPT_CALL SymCryptIntDivPow2 (_In_ PCSYMCRYPT_INT piSrc, SIZE_T exp, _Out_ PSYMCRYPT_INT piDst)
 
VOID SYMCRYPT_CALL SymCryptIntShr1 (UINT32 highestBit, _In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst)
 
VOID SYMCRYPT_CALL SymCryptIntModPow2 (_In_ PCSYMCRYPT_INT piSrc, SIZE_T exp, _Out_ PSYMCRYPT_INT piDst)
 
UINT32 SYMCRYPT_CALL SymCryptIntGetBit (_In_ PCSYMCRYPT_INT piSrc, UINT32 iBit)
 
UINT32 SYMCRYPT_CALL SymCryptIntGetBits (_In_ PCSYMCRYPT_INT piSrc, UINT32 iBit, UINT32 nBits)
 
VOID SYMCRYPT_CALL SymCryptIntSetBits (_In_ PSYMCRYPT_INT piDst, UINT32 value, UINT32 iBit, UINT32 nBits)
 
UINT32 SYMCRYPT_CALL SymCryptIntMulUint32 (_In_ PCSYMCRYPT_INT piSrc1, UINT32 Src2, _Out_ PSYMCRYPT_INT piDst)
 
VOID SYMCRYPT_CALL SymCryptIntMulSameSize (_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptIntSquare (_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptIntMulMixedSize (_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
PSYMCRYPT_INT SYMCRYPT_CALL SymCryptIntFromDivisor (_In_ PSYMCRYPT_DIVISOR pdSrc)
 
VOID SYMCRYPT_CALL SymCryptIntToDivisor (_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_DIVISOR pdDst, UINT32 totalOperations, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptIntDivMod (_In_ PCSYMCRYPT_INT piSrc, _In_ PCSYMCRYPT_DIVISOR pdDivisor, _Out_opt_ PSYMCRYPT_INT piQuotient, _Out_opt_ PSYMCRYPT_INT piRemainder, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptIntExtendedGcd (_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, UINT32 flags, _Out_opt_ PSYMCRYPT_INT piGcd, _Out_opt_ PSYMCRYPT_INT piLcm, _Out_opt_ PSYMCRYPT_INT piInvSrc1ModSrc2, _Out_opt_ PSYMCRYPT_INT piInvSrc2ModSrc1, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
UINT64 SYMCRYPT_CALL SymCryptUint64Gcd (UINT64 a, UINT64 b, UINT32 flags)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptCrtGenerateInverses (UINT32 nCoprimes, _In_reads_(nCoprimes) PCSYMCRYPT_MODULUS *ppmCoprimes, UINT32 flags, _Out_writes_(nCoprimes) PSYMCRYPT_MODELEMENT *ppeCrtInverses, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptCrtSolve (UINT32 nCoprimes, _In_reads_(nCoprimes) PCSYMCRYPT_MODULUS *ppmCoprimes, _In_reads_(nCoprimes) PCSYMCRYPT_MODELEMENT *ppeCrtInverses, _In_reads_(nCoprimes) PCSYMCRYPT_MODELEMENT *ppeCrtRemainders, UINT32 flags, _Out_ PSYMCRYPT_INT piSolution, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
PCSYMCRYPT_TRIALDIVISION_CONTEXT SYMCRYPT_CALL SymCryptCreateTrialDivisionContext (UINT32 nDigits)
 
VOID SYMCRYPT_CALL SymCryptFreeTrialDivisionContext (PCSYMCRYPT_TRIALDIVISION_CONTEXT pContext)
 
UINT32 SYMCRYPT_CALL SymCryptIntFindSmallDivisor (_In_ PCSYMCRYPT_TRIALDIVISION_CONTEXT pContext, _In_ PCSYMCRYPT_INT piSrc, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
UINT32 SYMCRYPT_CALL SymCryptIntMillerRabinPrimalityTest (_In_ PCSYMCRYPT_INT piSrc, UINT32 nBitsSrc, UINT32 nIterations, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptIntGenerateRandomPrime (_In_ PCSYMCRYPT_INT piLow, _In_ PCSYMCRYPT_INT piHigh, _In_reads_opt_(nPubExp) PCUINT64 pu64PubExp, UINT32 nPubExp, UINT32 nTries, UINT32 flags, _Inout_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
PSYMCRYPT_DIVISOR SYMCRYPT_CALL SymCryptDivisorFromModulus (_In_ PSYMCRYPT_MODULUS pmSrc)
 
PSYMCRYPT_INT SYMCRYPT_CALL SymCryptIntFromModulus (_In_ PSYMCRYPT_MODULUS pmSrc)
 
VOID SYMCRYPT_CALL SymCryptIntToModulus (_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_MODULUS pmDst, UINT32 averageOperations, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptIntToModElement (_In_ PCSYMCRYPT_INT piSrc, _In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptModElementToInt (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModElementSetValue (_In_reads_bytes_(cbSrc) PCBYTE pbSrc, SIZE_T cbSrc, SYMCRYPT_NUMBER_FORMAT format, PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptModElementSetValueUint32 (UINT32 value, _In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptModElementSetValueNegUint32 (UINT32 value, _In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModElementGetValue (PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_writes_bytes_(cbDst) PBYTE pbDst, SIZE_T cbDst, SYMCRYPT_NUMBER_FORMAT format, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
UINT32 SYMCRYPT_CALL SymCryptModElementIsEqual (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc1, _In_ PCSYMCRYPT_MODELEMENT peSrc2)
 
UINT32 SYMCRYPT_CALL SymCryptModElementIsZero (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc)
 
VOID SYMCRYPT_CALL SymCryptModSetRandom (_In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptModNeg (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptModAdd (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc1, _In_ PCSYMCRYPT_MODELEMENT peSrc2, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptModSub (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc1, _In_ PCSYMCRYPT_MODELEMENT peSrc2, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptModMul (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc1, _In_ PCSYMCRYPT_MODELEMENT peSrc2, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptModSquare (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptModDivPow2 (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, UINT32 exp, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModInv (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_MODELEMENT peDst, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptModExp (_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peBase, _In_ PCSYMCRYPT_INT piExp, UINT32 nBitsExp, UINT32 flags, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModMultiExp (_In_ PCSYMCRYPT_MODULUS pmMod, _In_reads_(nBases) PCSYMCRYPT_MODELEMENT *peBaseArray, _In_reads_(nBases) PCSYMCRYPT_INT *piExpArray, UINT32 nBases, UINT32 nBitsExp, UINT32 flags, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
UINT32 SYMCRYPT_CALL SymCryptScsTableInit (_Out_ PSYMCRYPT_SCSTABLE pScsTable, UINT32 nElements, UINT32 elementSize)
 
VOID SYMCRYPT_CALL SymCryptScsTableSetBuffer (_Inout_ PSYMCRYPT_SCSTABLE pScsTable, _Inout_updates_bytes_(cbBuffer) PBYTE pbBuffer, UINT32 cbBuffer)
 
VOID SYMCRYPT_CALL SymCryptScsTableStore (_Inout_ PSYMCRYPT_SCSTABLE pScsTable, UINT32 iIndex, _In_reads_bytes_(cbData) PCBYTE pbData, UINT32 cbData)
 
VOID SYMCRYPT_CALL SymCryptScsTableLoad (_In_ PSYMCRYPT_SCSTABLE pScsTable, UINT32 iIndex, _Out_writes_bytes_(cbData) PBYTE pbData, UINT32 cbData)
 
VOID SYMCRYPT_CALL SymCryptScsTableWipe (_Inout_ PSYMCRYPT_SCSTABLE pScsTable)
 
VOID SYMCRYPT_CALL SymCryptScsRotateBuffer (_Inout_updates_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, SIZE_T lshift)
 
VOID SYMCRYPT_CALL SymCryptScsCopy (_In_reads_(cbDst) PCBYTE pbSrc, SIZE_T cbSrc, _Out_writes_(cbDst) PBYTE pbDst, SIZE_T cbDst)
 
UINT32 SYMCRYPT_CALL SymCryptMask32IsZeroU31 (UINT32 v)
 
UINT32 SYMCRYPT_CALL SymCryptMask32IsNonzeroU31 (UINT32 v)
 
UINT32 SYMCRYPT_CALL SymCryptMask32EqU32 (UINT32 a, UINT32 b)
 
UINT32 SYMCRYPT_CALL SymCryptMask32NeqU31 (UINT32 a, UINT32 b)
 
UINT32 SYMCRYPT_CALL SymCryptMask32LtU31 (UINT32 a, UINT32 b)
 
SIZE_T SYMCRYPT_CALL SymCryptRoundUpPow2Sizet (SIZE_T v)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPkcs1ApplyEncryptionPadding (_In_reads_bytes_(cbPlaintext) PCBYTE pbPlaintext, SIZE_T cbPlaintext, _Out_writes_bytes_(cbPkcs1Format) PBYTE pbPkcs1Format, SIZE_T cbPkcs1Format)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPkcs1RemoveEncryptionPadding (_Inout_updates_bytes_(cbPkcs1Buffer) PBYTE pbPkcs1Format, SIZE_T cbPkcs1Format, SIZE_T cbPkcs1Buffer, _Out_writes_bytes_opt_(cbPlaintext) PBYTE pbPlaintext, SIZE_T cbPlaintext, _Out_ SIZE_T *pcbPlaintext)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaOaepApplyEncryptionPadding (_In_reads_bytes_(cbPlaintext) PCBYTE pbPlaintext, SIZE_T cbPlaintext, _In_ PCSYMCRYPT_HASH hashAlgorithm, _In_reads_bytes_(cbLabel) PCBYTE pbLabel, SIZE_T cbLabel, _In_reads_bytes_opt_(cbSeed) PCBYTE pbSeed, SIZE_T cbSeed, _Out_writes_bytes_(cbOaepFormat) PBYTE pbOaepFormat, SIZE_T cbOaepFormat, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaOaepRemoveEncryptionPadding (_In_reads_bytes_(cbOAEPFormat) PCBYTE pbOAEPFormat, SIZE_T cbOAEPFormat, _In_ PCSYMCRYPT_HASH hashAlgorithm, _In_reads_bytes_(cbLabel) PCBYTE pbLabel, SIZE_T cbLabel, UINT32 flags, _Out_writes_bytes_(cbPlaintext) PBYTE pbPlaintext, SIZE_T cbPlaintext, _Out_ SIZE_T *pcbPlaintext, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPkcs1ApplySignaturePadding (_In_reads_bytes_(cbHash) PCBYTE pbHash, SIZE_T cbHash, _In_reads_bytes_(cbHashOid) PCBYTE pbHashOid, SIZE_T cbHashOid, UINT32 flags, _Out_writes_bytes_(cbPKCS1Format) PBYTE pbPKCS1Format, SIZE_T cbPKCS1Format)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPkcs1VerifySignaturePadding (_In_reads_bytes_(cbHash) PCBYTE pbHash, SIZE_T cbHash, _In_reads_(nOIDCount) PCSYMCRYPT_OID pHashOIDs, _In_ SIZE_T nOIDCount, _In_reads_bytes_(cbPKCS1Format) PCBYTE pbPKCS1Format, SIZE_T cbPKCS1Format, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPssApplySignaturePadding (_In_reads_bytes_(cbHash) PCBYTE pbHash, SIZE_T cbHash, _In_ PCSYMCRYPT_HASH hashAlgorithm, _In_reads_bytes_opt_(cbSalt) PCBYTE pbSalt, _In_range_(0, cbPSSFormat) SIZE_T cbSalt, UINT32 nBitsOfModulus, UINT32 flags, _Out_writes_bytes_(cbPSSFormat) PBYTE pbPSSFormat, SIZE_T cbPSSFormat, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPssVerifySignaturePadding (_In_reads_bytes_(cbHash) PCBYTE pbHash, SIZE_T cbHash, _In_ PCSYMCRYPT_HASH hashAlgorithm, _In_range_(0, cbPSSFormat) SIZE_T cbSalt, _In_reads_bytes_(cbPSSFormat) PCBYTE pbPSSFormat, SIZE_T cbPSSFormat, UINT32 nBitsOfModulus, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
PCSYMCRYPT_MODULUS SYMCRYPT_CALL SymCryptEcurveGroupOrder (_In_ PCSYMCRYPT_ECURVE pCurve)
 
UINT32 SYMCRYPT_CALL SymCryptEcurveDigitsofScalarMultiplier (_In_ PCSYMCRYPT_ECURVE pCurve)
 
UINT32 SYMCRYPT_CALL SymCryptEcurveDigitsofFieldElement (_In_ PCSYMCRYPT_ECURVE pCurve)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointSetValue (_In_ PCSYMCRYPT_ECURVE pCurve, _In_reads_bytes_(cbSrc) PCBYTE pbSrc, SIZE_T cbSrc, SYMCRYPT_NUMBER_FORMAT nformat, SYMCRYPT_ECPOINT_FORMAT eformat, _Out_ PSYMCRYPT_ECPOINT poDst, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointGetValue (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, SYMCRYPT_NUMBER_FORMAT nformat, SYMCRYPT_ECPOINT_FORMAT eformat, _Out_writes_bytes_(cbDst) PBYTE pbDst, SIZE_T cbDst, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptEcpointSetZero (_In_ PCSYMCRYPT_ECURVE pCurve, _Out_ PSYMCRYPT_ECPOINT poDst, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptEcpointSetDistinguishedPoint (_In_ PCSYMCRYPT_ECURVE pCurve, _Out_ PSYMCRYPT_ECPOINT poDst, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
UINT32 SYMCRYPT_CALL SymCryptEcpointIsEqual (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc1, _In_ PCSYMCRYPT_ECPOINT poSrc2, UINT32 flags, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
UINT32 SYMCRYPT_CALL SymCryptEcpointIsZero (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
UINT32 SYMCRYPT_CALL SymCryptEcpointOnCurve (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptEcpointAdd (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc1, _In_ PCSYMCRYPT_ECPOINT poSrc2, _Out_ PSYMCRYPT_ECPOINT poDst, UINT32 flags, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptEcpointAddDiffNonZero (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc1, _In_ PCSYMCRYPT_ECPOINT poSrc2, _Out_ PSYMCRYPT_ECPOINT poDst, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptEcpointDouble (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, _Out_ PSYMCRYPT_ECPOINT poDst, UINT32 flags, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptEcpointNegate (_In_ PCSYMCRYPT_ECURVE pCurve, _Inout_ PSYMCRYPT_ECPOINT poSrc, UINT32 mask, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
VOID SYMCRYPT_CALL SymCryptEcpointSetRandom (_In_ PCSYMCRYPT_ECURVE pCurve, _Out_ PSYMCRYPT_INT piScalar, _Out_ PSYMCRYPT_ECPOINT poDst, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointScalarMul (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_INT piScalar, _In_opt_ PCSYMCRYPT_ECPOINT poSrc, UINT32 flags, _Out_ PSYMCRYPT_ECPOINT poDst, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointMultiScalarMul (_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_INT *piSrcScalarArray, _In_ PCSYMCRYPT_ECPOINT *poSrcEcpointArray, UINT32 nPoints, UINT32 flags, _Out_ PSYMCRYPT_ECPOINT poDst, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRngAesGenerateSmall (_Inout_ PSYMCRYPT_RNG_AES_STATE pRngState, _Out_writes_(cbRandom) PBYTE pbRandom, SIZE_T cbRandom, _In_reads_opt_(cbAdditionalInput) PCBYTE pbAdditionalInput, SIZE_T cbAdditionalInput)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcDsaSignEx (_In_ PCSYMCRYPT_ECKEY pKey, _In_reads_bytes_(cbHashValue) PCBYTE pbHashValue, SIZE_T cbHashValue, _In_opt_ PCSYMCRYPT_INT piK, SYMCRYPT_NUMBER_FORMAT format, UINT32 flags, _Out_writes_bytes_(cbSignature) PBYTE pbSignature, SIZE_T cbSignature)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlKemEncapsulateEx (_In_ PCSYMCRYPT_MLKEMKEY pkMlKemkey, _In_reads_bytes_(cbRandom) PCBYTE pbRandom, SIZE_T cbRandom, _Out_writes_bytes_(cbAgreedSecret) PBYTE pbAgreedSecret, SIZE_T cbAgreedSecret, _Out_writes_bytes_(cbCiphertext) PBYTE pbCiphertext, SIZE_T cbCiphertext)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptCompositeMlKemEncapsulateEx (_In_ PCSYMCRYPT_COMPOSITE_MLKEMKEY pkCompositeMlKemkey, _In_reads_bytes_opt_(cbMlKemRandom) PCBYTE pbMlKemRandom, SIZE_T cbMlKemRandom, _In_reads_bytes_opt_(cbTradRandom) PCBYTE pbTradRandom, SIZE_T cbTradRandom, _Out_writes_bytes_(cbAgreedSecret) PBYTE pbAgreedSecret, SIZE_T cbAgreedSecret, _Out_writes_bytes_(cbCiphertext) PBYTE pbCiphertext, SIZE_T cbCiphertext)
 
VOID SymCrypt802_11SaeGetGroupSizes (SYMCRYPT_802_11_SAE_GROUP group, _Out_opt_ SIZE_T *pcbScalar, _Out_opt_ SIZE_T *pcbPoint)
 
SYMCRYPT_ERROR SymCrypt802_11SaeCustomInit (_Out_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, _In_reads_(6) PCBYTE pbMacA, _In_reads_(6) PCBYTE pbMacB, _In_reads_(cbPassword) PCBYTE pbPassword, SIZE_T cbPassword, _Out_opt_ PBYTE pbCounter, _Inout_updates_opt_(32) PBYTE pbRand, _Inout_updates_opt_(32) PBYTE pbMask)
 
SYMCRYPT_ERROR SymCrypt802_11SaeCustomCreatePT (_In_reads_(cbSsid) PCBYTE pbSsid, SIZE_T cbSsid, _In_reads_(cbPassword) PCBYTE pbPassword, SIZE_T cbPassword, _In_reads_opt_(cbPasswordIdentifier) PCBYTE pbPasswordIdentifier, SIZE_T cbPasswordIdentifier, _Out_writes_(64) PBYTE pbPT)
 
SYMCRYPT_ERROR SymCrypt802_11SaeCustomCreatePTGeneric (SYMCRYPT_802_11_SAE_GROUP group, _In_reads_(cbSsid) PCBYTE pbSsid, SIZE_T cbSsid, _In_reads_(cbPassword) PCBYTE pbPassword, SIZE_T cbPassword, _In_reads_opt_(cbPasswordIdentifier) PCBYTE pbPasswordIdentifier, SIZE_T cbPasswordIdentifier, _Out_writes_(cbPT) PBYTE pbPT, SIZE_T cbPT)
 
SYMCRYPT_ERROR SymCrypt802_11SaeCustomInitH2E (_Out_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, _In_reads_(64) PCBYTE pbPT, _In_reads_(6) PCBYTE pbMacA, _In_reads_(6) PCBYTE pbMacB, _Inout_updates_opt_(32) PBYTE pbRand, _Inout_updates_opt_(32) PBYTE pbMask)
 
SYMCRYPT_ERROR SymCrypt802_11SaeCustomInitH2EGeneric (_Out_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, SYMCRYPT_802_11_SAE_GROUP group, _In_reads_(cbPT) PCBYTE pbPT, SIZE_T cbPT, _In_reads_(6) PCBYTE pbMacA, _In_reads_(6) PCBYTE pbMacB, _Inout_updates_opt_(cbRand) PBYTE pbRand, SIZE_T cbRand, _Inout_updates_opt_(cbMask) PBYTE pbMask, SIZE_T cbMask)
 
SYMCRYPT_ERROR SymCrypt802_11SaeCustomCommitCreate (_In_ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, _Out_writes_(32) PBYTE pbCommitScalar, _Out_writes_(64) PBYTE pbCommitElement)
 
SYMCRYPT_ERROR SymCrypt802_11SaeCustomCommitCreateGeneric (_In_ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, _Out_writes_(cbCommitScalar) PBYTE pbCommitScalar, SIZE_T cbCommitScalar, _Out_writes_(cbCommitElement) PBYTE pbCommitElement, SIZE_T cbCommitElement)
 
SYMCRYPT_ERROR SymCrypt802_11SaeCustomCommitProcess (_In_ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, _In_reads_(32) PCBYTE pbPeerCommitScalar, _In_reads_(64) PCBYTE pbPeerCommitElement, _Out_writes_(32) PBYTE pbSharedSecret, _Out_writes_(32) PBYTE pbScalarSum)
 
SYMCRYPT_ERROR SymCrypt802_11SaeCustomCommitProcessGeneric (_In_ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, _In_reads_(cbPeerCommitScalar) PCBYTE pbPeerCommitScalar, SIZE_T cbPeerCommitScalar, _In_reads_(cbPeerCommitElement) PCBYTE pbPeerCommitElement, SIZE_T cbPeerCommitElement, _Out_writes_(cbSharedSecret) PBYTE pbSharedSecret, SIZE_T cbSharedSecret, _Out_writes_(cbScalarSum) PBYTE pbScalarSum, SIZE_T cbScalarSum)
 
VOID SymCrypt802_11SaeCustomDestroy (_Inout_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE pState)
 

Macro Definition Documentation

◆ SYMCRYPT_ECURVE_MULTI_SCALAR_MUL_MAX_NPOINTS

#define SYMCRYPT_ECURVE_MULTI_SCALAR_MUL_MAX_NPOINTS   (2)

Definition at line 2678 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_DATA_PUBLIC

#define SYMCRYPT_FLAG_DATA_PUBLIC   (0x01)

Definition at line 100 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_ECC_LL_COFACTOR_MUL

#define SYMCRYPT_FLAG_ECC_LL_COFACTOR_MUL   (0x20)

Definition at line 2422 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_ECPOINT_EQUAL

#define SYMCRYPT_FLAG_ECPOINT_EQUAL   (0x01)

Definition at line 2463 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_ECPOINT_NEG_EQUAL

#define SYMCRYPT_FLAG_ECPOINT_NEG_EQUAL   (0x02)

Definition at line 2464 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_GCD_INPUTS_NOT_BOTH_EVEN

#define SYMCRYPT_FLAG_GCD_INPUTS_NOT_BOTH_EVEN   (0x02)

Definition at line 1204 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_GCD_PUBLIC

#define SYMCRYPT_FLAG_GCD_PUBLIC   (0x04)

Definition at line 1205 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_MODRANDOM_ALLOW_MINUSONE

#define SYMCRYPT_FLAG_MODRANDOM_ALLOW_MINUSONE   (0x04)

Definition at line 1693 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_MODRANDOM_ALLOW_ONE

#define SYMCRYPT_FLAG_MODRANDOM_ALLOW_ONE   (0x02)

Definition at line 1692 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_MODRANDOM_ALLOW_ZERO

#define SYMCRYPT_FLAG_MODRANDOM_ALLOW_ZERO   (0x01)

Definition at line 1691 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_MODULUS_ADDITIVE_ONLY

#define SYMCRYPT_FLAG_MODULUS_ADDITIVE_ONLY   (0x04)

Definition at line 1502 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_MODULUS_PARITY_PUBLIC

#define SYMCRYPT_FLAG_MODULUS_PARITY_PUBLIC   (0x02)

Definition at line 1501 of file symcrypt_low_level.h.

◆ SYMCRYPT_FLAG_MODULUS_PRIME

#define SYMCRYPT_FLAG_MODULUS_PRIME   (0x08)

Definition at line 1503 of file symcrypt_low_level.h.

◆ SYMCRYPT_MODMULTIEXP_MAX_NBASES

#define SYMCRYPT_MODMULTIEXP_MAX_NBASES   (8)

Definition at line 1879 of file symcrypt_low_level.h.

◆ SYMCRYPT_MODMULTIEXP_MAX_NBITSEXP

#define SYMCRYPT_MODMULTIEXP_MAX_NBITSEXP   (SYMCRYPT_INT_MAX_BITS)

Definition at line 1880 of file symcrypt_low_level.h.

◆ SYMCRYPT_RNG_AES_INTERNAL_SEED_SIZE

#define SYMCRYPT_RNG_AES_INTERNAL_SEED_SIZE   (32 + 16)

Definition at line 2721 of file symcrypt_low_level.h.

◆ SYMCRYPT_SAE_MAX_EC_POINT_SIZE_BYTES

#define SYMCRYPT_SAE_MAX_EC_POINT_SIZE_BYTES   ( 2 * SYMCRYPT_SAE_MAX_MOD_SIZE_BYTES )

Definition at line 2881 of file symcrypt_low_level.h.

◆ SYMCRYPT_SAE_MAX_HMAC_OUTPUT_SIZE_BYTES

#define SYMCRYPT_SAE_MAX_HMAC_OUTPUT_SIZE_BYTES   SYMCRYPT_BYTES_FROM_BITS( 384 )

Definition at line 2882 of file symcrypt_low_level.h.

◆ SYMCRYPT_SAE_MAX_MOD_SIZE_BITS

#define SYMCRYPT_SAE_MAX_MOD_SIZE_BITS   384

Definition at line 2879 of file symcrypt_low_level.h.

◆ SYMCRYPT_SAE_MAX_MOD_SIZE_BYTES

#define SYMCRYPT_SAE_MAX_MOD_SIZE_BYTES   SYMCRYPT_BYTES_FROM_BITS( SYMCRYPT_SAE_MAX_MOD_SIZE_BITS )

Definition at line 2880 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_COMMON_ECURVE_OPERATIONS

#define SYMCRYPT_SCRATCH_BYTES_FOR_COMMON_ECURVE_OPERATIONS (   _pCurve)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_COMMON_ECURVE_OPERATIONS( _pCurve )

Definition at line 2428 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_COMMON_MOD_OPERATIONS

#define SYMCRYPT_SCRATCH_BYTES_FOR_COMMON_MOD_OPERATIONS (   _nDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_COMMON_MOD_OPERATIONS( _nDigits )

Definition at line 1505 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_CRT_GENERATION

#define SYMCRYPT_SCRATCH_BYTES_FOR_CRT_GENERATION (   _nDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_CRT_GENERATION( _nDigits )

Definition at line 1226 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_CRT_SOLUTION

#define SYMCRYPT_SCRATCH_BYTES_FOR_CRT_SOLUTION (   _nDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_CRT_SOLUTION( _nDigits )

Definition at line 1266 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_EXTENDED_GCD

#define SYMCRYPT_SCRATCH_BYTES_FOR_EXTENDED_GCD (   _nDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_EXTENDED_GCD( _nDigits )

Definition at line 1154 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_GETSET_VALUE_ECURVE_OPERATIONS

#define SYMCRYPT_SCRATCH_BYTES_FOR_GETSET_VALUE_ECURVE_OPERATIONS (   _pCurve)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_GETSET_VALUE_ECURVE_OPERATIONS( _pCurve )

Definition at line 2335 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_INT_DIVMOD

#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_DIVMOD (   _nSrcDigits,
  _nDivisorDigits 
)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_DIVMOD( _nSrcDigits, _nDivisorDigits )

Definition at line 1131 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_INT_IS_PRIME

#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_IS_PRIME (   _nDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_IS_PRIME( _nDigits )

Definition at line 1343 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_INT_MUL

#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_MUL (   _nResultDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_MUL( _nResultDigits )

Definition at line 1020 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_INT_PRIME_GEN

#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_PRIME_GEN (   _nDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_PRIME_GEN( _nDigits )

Definition at line 1383 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_INT_TO_DIVISOR

#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_TO_DIVISOR (   _nDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_TO_DIVISOR( _nDigits )

Definition at line 1100 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_INT_TO_MODULUS

#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_TO_MODULUS (   _nDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_INT_TO_MODULUS( _nDigits )

Definition at line 1461 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_MODEXP

#define SYMCRYPT_SCRATCH_BYTES_FOR_MODEXP (   _nDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_MODEXP( _nDigits )

Definition at line 1835 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_MODINV

#define SYMCRYPT_SCRATCH_BYTES_FOR_MODINV (   _nDigits)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_MODINV( _nDigits )

Definition at line 1804 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_MODMULTIEXP

#define SYMCRYPT_SCRATCH_BYTES_FOR_MODMULTIEXP (   _nDigits,
  _nBases,
  _nBitsExp 
)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_MODMULTIEXP( _nDigits, _nBases, _nBitsExp )

Definition at line 1882 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_MULTI_SCALAR_ECURVE_OPERATIONS

#define SYMCRYPT_SCRATCH_BYTES_FOR_MULTI_SCALAR_ECURVE_OPERATIONS (   _pCurve,
  _nPoints 
)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_SCALAR_ECURVE_OPERATIONS( (_pCurve), (_nPoints) )

Definition at line 2618 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_RSA_OAEP

#define SYMCRYPT_SCRATCH_BYTES_FOR_RSA_OAEP (   _hashAlgorithm,
  _nBytesOAEP 
)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_RSA_OAEP( _hashAlgorithm, _nBytesOAEP )

Definition at line 2122 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_RSA_PKCS1

#define SYMCRYPT_SCRATCH_BYTES_FOR_RSA_PKCS1 (   _nBytesPKCS1)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_RSA_PKCS1( _nBytesPKCS1 )

Definition at line 2185 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_RSA_PSS

#define SYMCRYPT_SCRATCH_BYTES_FOR_RSA_PSS (   _hashAlgorithm,
  _nBytesMessage,
  _nBytesPSS 
)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_RSA_PSS( _hashAlgorithm, _nBytesMessage, _nBytesPSS )

Definition at line 2234 of file symcrypt_low_level.h.

◆ SYMCRYPT_SCRATCH_BYTES_FOR_SCALAR_ECURVE_OPERATIONS

#define SYMCRYPT_SCRATCH_BYTES_FOR_SCALAR_ECURVE_OPERATIONS (   _pCurve)    SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_SCALAR_ECURVE_OPERATIONS( (_pCurve), 1 )

Definition at line 2617 of file symcrypt_low_level.h.

◆ SYMCRYPT_SIZEOF_DIVISOR_FROM_BITS

#define SYMCRYPT_SIZEOF_DIVISOR_FROM_BITS (   _bitsize)    SYMCRYPT_INTERNAL_SIZEOF_DIVISOR_FROM_BITS( _bitsize )

Definition at line 370 of file symcrypt_low_level.h.

◆ SYMCRYPT_SIZEOF_INT_FROM_BITS

#define SYMCRYPT_SIZEOF_INT_FROM_BITS (   _bitsize)    SYMCRYPT_INTERNAL_SIZEOF_INT_FROM_BITS( _bitsize )

Definition at line 306 of file symcrypt_low_level.h.

◆ SYMCRYPT_SIZEOF_MODELEMENT_FROM_BITS

#define SYMCRYPT_SIZEOF_MODELEMENT_FROM_BITS (   _bitsize)    SYMCRYPT_INTERNAL_SIZEOF_MODELEMENT_FROM_BITS( _bitsize )

Definition at line 451 of file symcrypt_low_level.h.

◆ SYMCRYPT_SIZEOF_MODULUS_FROM_BITS

#define SYMCRYPT_SIZEOF_MODULUS_FROM_BITS (   _bitsize)    SYMCRYPT_INTERNAL_SIZEOF_MODULUS_FROM_BITS( _bitsize )

Definition at line 408 of file symcrypt_low_level.h.

Typedef Documentation

◆ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE

◆ PCSYMCRYPT_TRIALDIVISION_CONTEXT

◆ PSYMCRYPT_802_11_SAE_CUSTOM_STATE

◆ PSYMCRYPT_SCSTABLE

◆ SYMCRYPT_802_11_SAE_CUSTOM_STATE

◆ SYMCRYPT_802_11_SAE_GROUP

◆ SYMCRYPT_SCSTABLE

Enumeration Type Documentation

◆ _SYMCRYPT_802_11_SAE_GROUP

Enumerator
SYMCRYPT_SAE_GROUP_19 
SYMCRYPT_SAE_GROUP_20 

Definition at line 2872 of file symcrypt_low_level.h.

2872 {
2873 SYMCRYPT_SAE_GROUP_19 = 19, // NIST P256
2874 SYMCRYPT_SAE_GROUP_20, // NIST P384
@ SYMCRYPT_SAE_GROUP_20
@ SYMCRYPT_SAE_GROUP_19
enum _SYMCRYPT_802_11_SAE_GROUP SYMCRYPT_802_11_SAE_GROUP

Function Documentation

◆ SymCrypt802_11SaeCustomCommitCreate()

SYMCRYPT_ERROR SymCrypt802_11SaeCustomCommitCreate ( _In_ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE  pState,
_Out_writes_(32) PBYTE  pbCommitScalar,
_Out_writes_(64) PBYTE  pbCommitElement 
)

Definition at line 1384 of file IEEE802_11SaeCustom.c.

1388{
1390 pbCommitScalar,
1391 32,
1392 pbCommitElement,
1393 64 );
1394}
SYMCRYPT_ERROR SymCrypt802_11SaeCustomCommitCreateGeneric(_In_ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, _Out_writes_(cbCommitScalar) PBYTE pbCommitScalar, SIZE_T cbCommitScalar, _Out_writes_(cbCommitElement) PBYTE pbCommitElement, SIZE_T cbCommitElement)
PSYMCRYPT_COMMON_HASH_STATE pState

◆ SymCrypt802_11SaeCustomCommitCreateGeneric()

SYMCRYPT_ERROR SymCrypt802_11SaeCustomCommitCreateGeneric ( _In_ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE  pState,
_Out_writes_(cbCommitScalar) PBYTE  pbCommitScalar,
SIZE_T  cbCommitScalar,
_Out_writes_(cbCommitElement) PBYTE  pbCommitElement,
SIZE_T  cbCommitElement 
)

Definition at line 1282 of file IEEE802_11SaeCustom.c.

1288{
1289 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
1290 PSYMCRYPT_MODELEMENT peTmp = NULL;
1291 PSYMCRYPT_INT piTmp = NULL;
1292 PSYMCRYPT_ECPOINT poPoint = NULL;
1293 PBYTE pbScratch = NULL;
1295 SIZE_T nDigits;
1296
1298
1299 nDigits = SymCryptDigitsFromBits( pCurve->FModBitsize );
1303
1304 pbScratch = SymCryptCallbackAlloc( cbScratch );
1305
1306 peTmp = SymCryptModElementAllocate( pCurve->GOrd );
1308 poPoint = SymCryptEcpointAllocate( pCurve );
1309
1310 if( peTmp == NULL || piTmp == NULL || poPoint == NULL || pbScratch == NULL )
1311 {
1312 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
1313 goto cleanup;
1314 }
1315
1316 SymCryptModAdd( pCurve->GOrd, pState->peRand, pState->peMask, peTmp, pbScratch, cbScratch );
1317 scError = SymCryptModElementGetValue( pCurve->GOrd, peTmp, pbCommitScalar, cbCommitScalar, SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, pbScratch, cbScratch );
1318 if( scError != SYMCRYPT_NO_ERROR )
1319 {
1320 goto cleanup;
1321 }
1322
1323 SymCryptModElementToInt( pCurve->GOrd, pState->peMask, piTmp, pbScratch, cbScratch );
1325 piTmp,
1326 pState->poPWE,
1327 0,
1328 poPoint,
1329 pbScratch,
1330 cbScratch );
1331 if( scError != SYMCRYPT_NO_ERROR )
1332 {
1333 goto cleanup;
1334 }
1335
1336 // Now we have mask * PWE, but we need the negative...
1337 SymCryptEcpointNegate( pCurve, poPoint, (UINT32)-1, pbScratch, cbScratch );
1338
1340 poPoint,
1343 pbCommitElement,
1344 cbCommitElement,
1345 0,
1346 pbScratch,
1347 cbScratch );
1348 if( scError != SYMCRYPT_NO_ERROR )
1349 {
1350 goto cleanup;
1351 }
1352
1353cleanup:
1354
1355 if( piTmp != NULL )
1356 {
1357 SymCryptIntFree( piTmp );
1358 piTmp = NULL;
1359 }
1360
1361 if( peTmp != NULL )
1362 {
1363 SymCryptModElementFree( pCurve->GOrd, peTmp );
1364 peTmp = NULL;
1365 }
1366
1367 if( poPoint != NULL )
1368 {
1369 SymCryptEcpointFree( pCurve, poPoint );
1370 poPoint = NULL;
1371 }
1372
1373 if( pbScratch != NULL )
1374 {
1375 SymCryptWipe( pbScratch, cbScratch );
1376 SymCryptCallbackFree( pbScratch );
1377 pbScratch = NULL;
1378 }
1379
1380 return scError;
1381}
#define NULL
Definition: types.h:112
static void cleanup(void)
Definition: main.c:1335
void SYMCRYPT_CALL SymCryptCallbackFree(void *ptr)
Definition: implglue.c:42
void *SYMCRYPT_CALL SymCryptCallbackAlloc(SIZE_T size)
Definition: implglue.c:37
BYTE * PBYTE
Definition: pedump.c:66
UINT32 UINT32 UINT32 UINT32 cbScratch
VOID SYMCRYPT_CALL SymCryptWipe(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)
Definition: libmain.c:137
@ SYMCRYPT_ECPOINT_FORMAT_XY
Definition: symcrypt.h:7195
@ SYMCRYPT_NUMBER_FORMAT_MSB_FIRST
Definition: symcrypt.h:7017
SYMCRYPT_ERROR
Definition: symcrypt.h:227
SYMCRYPT_MODELEMENT * PSYMCRYPT_MODELEMENT
PCSYMCRYPT_ECURVE pCurve
#define SYMCRYPT_MAX(_a, _b)
SYMCRYPT_ECPOINT * PSYMCRYPT_ECPOINT
SYMCRYPT_INT * PSYMCRYPT_INT
const SYMCRYPT_ECURVE * PCSYMCRYPT_ECURVE
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointScalarMul(_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_INT piScalar, _In_opt_ PCSYMCRYPT_ECPOINT poSrc, UINT32 flags, _Out_ PSYMCRYPT_ECPOINT poDst, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: ec_dispatch.c:262
UINT32 SymCryptDigitsFromBits(UINT32 nBits)
Definition: a_dispatch.c:111
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModElementGetValue(PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_writes_bytes_(cbDst) PBYTE pbDst, SIZE_T cbDst, SYMCRYPT_NUMBER_FORMAT format, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:804
#define SYMCRYPT_SCRATCH_BYTES_FOR_SCALAR_ECURVE_OPERATIONS(_pCurve)
PSYMCRYPT_ECPOINT SYMCRYPT_CALL SymCryptEcpointAllocate(_In_ PCSYMCRYPT_ECURVE pCurve)
Definition: ecpoint.c:49
#define SYMCRYPT_SCRATCH_BYTES_FOR_COMMON_MOD_OPERATIONS(_nDigits)
VOID SYMCRYPT_CALL SymCryptModAdd(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc1, _In_ PCSYMCRYPT_MODELEMENT peSrc2, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:838
VOID SYMCRYPT_CALL SymCryptModElementToInt(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:762
PSYMCRYPT_INT SYMCRYPT_CALL SymCryptIntAllocate(UINT32 nDigits)
Definition: a_dispatch.c:119
VOID SYMCRYPT_CALL SymCryptEcpointFree(_In_ PCSYMCRYPT_ECURVE pCurve, _Out_ PSYMCRYPT_ECPOINT poDst)
Definition: ecpoint.c:75
VOID SYMCRYPT_CALL SymCryptEcpointNegate(_In_ PCSYMCRYPT_ECURVE pCurve, _Inout_ PSYMCRYPT_ECPOINT poSrc, UINT32 mask, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: ec_dispatch.c:248
VOID SYMCRYPT_CALL SymCryptIntFree(_Out_ PSYMCRYPT_INT piObj)
Definition: a_dispatch.c:126
UINT32 SYMCRYPT_CALL SymCryptEcurveDigitsofScalarMultiplier(_In_ PCSYMCRYPT_ECURVE pCurve)
Definition: ecurve.c:710
#define SYMCRYPT_SCRATCH_BYTES_FOR_GETSET_VALUE_ECURVE_OPERATIONS(_pCurve)
VOID SYMCRYPT_CALL SymCryptModElementFree(_In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peObj)
Definition: a_dispatch.c:649
PSYMCRYPT_MODELEMENT SYMCRYPT_CALL SymCryptModElementAllocate(_In_ PCSYMCRYPT_MODULUS pmMod)
Definition: a_dispatch.c:642
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointGetValue(_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, SYMCRYPT_NUMBER_FORMAT nformat, SYMCRYPT_ECPOINT_FORMAT eformat, _Out_writes_bytes_(cbDst) PBYTE pbDst, SIZE_T cbDst, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: ecpoint.c:705
ULONG_PTR SIZE_T
Definition: typedefs.h:80
uint32_t UINT32
Definition: typedefs.h:59

Referenced by SymCrypt802_11SaeCustomCommitCreate().

◆ SymCrypt802_11SaeCustomCommitProcess()

SYMCRYPT_ERROR SymCrypt802_11SaeCustomCommitProcess ( _In_ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE  pState,
_In_reads_(32) PCBYTE  pbPeerCommitScalar,
_In_reads_(64) PCBYTE  pbPeerCommitElement,
_Out_writes_(32) PBYTE  pbSharedSecret,
_Out_writes_(32) PBYTE  pbScalarSum 
)

Definition at line 1569 of file IEEE802_11SaeCustom.c.

1575{
1577 pbPeerCommitScalar,
1578 32,
1579 pbPeerCommitElement,
1580 64,
1581 pbSharedSecret,
1582 32,
1583 pbScalarSum,
1584 32 );
1585}
SYMCRYPT_ERROR SymCrypt802_11SaeCustomCommitProcessGeneric(_In_ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, _In_reads_(cbPeerCommitScalar) PCBYTE pbPeerCommitScalar, SIZE_T cbPeerCommitScalar, _In_reads_(cbPeerCommitElement) PCBYTE pbPeerCommitElement, SIZE_T cbPeerCommitElement, _Out_writes_(cbSharedSecret) PBYTE pbSharedSecret, SIZE_T cbSharedSecret, _Out_writes_(cbScalarSum) PBYTE pbScalarSum, SIZE_T cbScalarSum)

◆ SymCrypt802_11SaeCustomCommitProcessGeneric()

SYMCRYPT_ERROR SymCrypt802_11SaeCustomCommitProcessGeneric ( _In_ PCSYMCRYPT_802_11_SAE_CUSTOM_STATE  pState,
_In_reads_(cbPeerCommitScalar) PCBYTE  pbPeerCommitScalar,
SIZE_T  cbPeerCommitScalar,
_In_reads_(cbPeerCommitElement) PCBYTE  pbPeerCommitElement,
SIZE_T  cbPeerCommitElement,
_Out_writes_(cbSharedSecret) PBYTE  pbSharedSecret,
SIZE_T  cbSharedSecret,
_Out_writes_(cbScalarSum) PBYTE  pbScalarSum,
SIZE_T  cbScalarSum 
)

Definition at line 1397 of file IEEE802_11SaeCustom.c.

1407{
1408 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
1409
1410 PSYMCRYPT_ECURVE pCurve = pState->pCurve;
1411 PSYMCRYPT_MODELEMENT peCommitScalarSum = NULL;
1412 PSYMCRYPT_ECPOINT poPeerCommitElement = NULL;
1413 PSYMCRYPT_ECPOINT poTmp = NULL;
1414 PSYMCRYPT_INT piTmp = NULL;
1415 UINT32 nDigits;
1416
1417 PBYTE pbScratch = NULL;
1419
1420 nDigits = SymCryptDigitsFromBits( pCurve->FModBitsize );
1425 pbScratch = SymCryptCallbackAlloc( cbScratch );
1426
1427 peCommitScalarSum = SymCryptModElementAllocate( pCurve->GOrd );
1428 poPeerCommitElement = SymCryptEcpointAllocate( pCurve );
1431
1432 if( pbScratch == NULL || peCommitScalarSum == NULL || poPeerCommitElement == NULL || poTmp == NULL || piTmp == NULL )
1433 {
1434 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
1435 goto cleanup;
1436 }
1437
1438 // piTmp = peer commit value
1439 scError = SymCryptIntSetValue( pbPeerCommitScalar, cbPeerCommitScalar, SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, piTmp );
1440 if( scError != SYMCRYPT_NO_ERROR )
1441 {
1442 goto cleanup;
1443 }
1444
1445 // The Standard requires a check that the Peer commit value must be 1 < peer-commit < r where r is the group order.
1446 if( !SymCryptIntIsLessThan( piTmp, SymCryptIntFromModulus( pCurve->GOrd ) ) ||
1447 SymCryptIntIsEqualUint32( piTmp, 0 ) ||
1448 SymCryptIntIsEqualUint32( piTmp, 1 ) )
1449 {
1450 scError = SYMCRYPT_INVALID_ARGUMENT;
1451 goto cleanup;
1452 }
1453
1454 SymCryptIntToModElement( piTmp, pCurve->GOrd, peCommitScalarSum, pbScratch, cbScratch );
1455
1456 // Now compute the sum of the scalar commit values
1457 SymCryptModAdd( pCurve->GOrd, peCommitScalarSum, pState->peRand, peCommitScalarSum, pbScratch, cbScratch );
1458 SymCryptModAdd( pCurve->GOrd, peCommitScalarSum, pState->peMask, peCommitScalarSum, pbScratch, cbScratch );
1459
1461 pbPeerCommitElement,
1462 cbPeerCommitElement,
1465 poPeerCommitElement,
1466 0,
1467 pbScratch,
1468 cbScratch );
1469 if( scError != SYMCRYPT_NO_ERROR )
1470 {
1471 goto cleanup;
1472 }
1473
1474 // The EcPointSetValue routine returns an error if either coordinate is >= P.
1475 // We need to check that the point is on the curve and not the zero point of the curve
1476 // (The zero point is sometimes called the 'point at infinity'.)
1477 if( !SymCryptEcpointOnCurve( pCurve, poPeerCommitElement, pbScratch, cbScratch ) ||
1478 SymCryptEcpointIsZero( pCurve, poPeerCommitElement, pbScratch, cbScratch ) )
1479 {
1480 scError = SYMCRYPT_INVALID_ARGUMENT;
1481 goto cleanup;
1482 }
1483
1484
1486 piTmp,
1487 pState->poPWE,
1488 0,
1489 poTmp,
1490 pbScratch,
1491 cbScratch );
1492 if( scError != SYMCRYPT_NO_ERROR )
1493 {
1494 goto cleanup;
1495 }
1496
1497 SymCryptEcpointAdd( pCurve, poTmp, poPeerCommitElement, poTmp, 0, pbScratch, cbScratch );
1498
1499 SymCryptModElementToInt( pCurve->GOrd, pState->peRand, piTmp, pbScratch, cbScratch );
1501 piTmp,
1502 poTmp,
1503 0,
1504 poTmp,
1505 pbScratch,
1506 cbScratch );
1507 if( scError != SYMCRYPT_NO_ERROR )
1508 {
1509 goto cleanup;
1510 }
1511
1513 poTmp,
1516 pbSharedSecret,
1517 cbSharedSecret,
1518 0,
1519 pbScratch,
1520 cbScratch );
1521 if( scError != SYMCRYPT_NO_ERROR )
1522 {
1523 goto cleanup;
1524 }
1525
1526 scError = SymCryptModElementGetValue( pCurve->GOrd, peCommitScalarSum, pbScalarSum, cbScalarSum, SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, pbScratch, cbScratch );
1527 if( scError != SYMCRYPT_NO_ERROR )
1528 {
1529 goto cleanup;
1530 }
1531
1532cleanup:
1533
1534 if( peCommitScalarSum != NULL )
1535 {
1536 SymCryptModElementFree( pCurve->GOrd, peCommitScalarSum );
1537 peCommitScalarSum = NULL;
1538 }
1539
1540 if( poPeerCommitElement != NULL )
1541 {
1542 SymCryptEcpointFree( pCurve, poPeerCommitElement );
1543 poPeerCommitElement = NULL;
1544 }
1545
1546 if( poTmp != NULL )
1547 {
1548 SymCryptEcpointFree( pCurve, poTmp );
1549 poTmp = NULL;
1550 }
1551
1552 if( piTmp != NULL )
1553 {
1554 SymCryptIntFree( piTmp );
1555 piTmp = NULL;
1556 }
1557
1558 if( pbScratch != NULL )
1559 {
1560 SymCryptWipe( pbScratch, cbScratch );
1561 SymCryptCallbackFree( pbScratch );
1562 pbScratch = NULL;
1563 }
1564
1565 return scError;
1566}
@ SYMCRYPT_ECPOINT_FORMAT_X
Definition: symcrypt.h:7194
SYMCRYPT_ECURVE * PSYMCRYPT_ECURVE
VOID SYMCRYPT_CALL SymCryptEcpointAdd(_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc1, _In_ PCSYMCRYPT_ECPOINT poSrc2, _Out_ PSYMCRYPT_ECPOINT poDst, UINT32 flags, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: ec_dispatch.c:202
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointSetValue(_In_ PCSYMCRYPT_ECURVE pCurve, _In_reads_bytes_(cbSrc) PCBYTE pbSrc, SIZE_T cbSrc, SYMCRYPT_NUMBER_FORMAT nformat, SYMCRYPT_ECPOINT_FORMAT eformat, _Out_ PSYMCRYPT_ECPOINT poDst, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: ecpoint.c:605
UINT32 SYMCRYPT_CALL SymCryptIntIsLessThan(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2)
Definition: a_dispatch.c:442
VOID SYMCRYPT_CALL SymCryptIntToModElement(_In_ PCSYMCRYPT_INT piSrc, _In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:749
UINT32 SYMCRYPT_CALL SymCryptEcpointIsZero(_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: ec_dispatch.c:176
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptIntSetValue(_In_reads_bytes_(cbSrc) PCBYTE pbSrc, SIZE_T cbSrc, SYMCRYPT_NUMBER_FORMAT format, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:248
UINT32 SYMCRYPT_CALL SymCryptEcpointOnCurve(_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: ec_dispatch.c:189
PSYMCRYPT_INT SYMCRYPT_CALL SymCryptIntFromModulus(_In_ PSYMCRYPT_MODULUS pmSrc)
Definition: a_dispatch.c:720
#define SYMCRYPT_SCRATCH_BYTES_FOR_COMMON_ECURVE_OPERATIONS(_pCurve)
UINT32 SYMCRYPT_CALL SymCryptIntIsEqualUint32(_In_ PCSYMCRYPT_INT piSrc1, _In_ UINT32 u32Src2)
Definition: a_dispatch.c:424

Referenced by SymCrypt802_11SaeCustomCommitProcess().

◆ SymCrypt802_11SaeCustomCreatePT()

SYMCRYPT_ERROR SymCrypt802_11SaeCustomCreatePT ( _In_reads_(cbSsid) PCBYTE  pbSsid,
SIZE_T  cbSsid,
_In_reads_(cbPassword) PCBYTE  pbPassword,
SIZE_T  cbPassword,
_In_reads_opt_(cbPasswordIdentifier) PCBYTE  pbPasswordIdentifier,
SIZE_T  cbPasswordIdentifier,
_Out_writes_(64) PBYTE  pbPT 
)

Definition at line 981 of file IEEE802_11SaeCustom.c.

989{
991 pbSsid,
992 cbSsid,
993 pbPassword,
994 cbPassword,
995 pbPasswordIdentifier,
996 cbPasswordIdentifier,
997 pbPT,
998 64 );
999}
SYMCRYPT_ERROR SymCrypt802_11SaeCustomCreatePTGeneric(SYMCRYPT_802_11_SAE_GROUP group, _In_reads_(cbSsid) PCBYTE pbSsid, SIZE_T cbSsid, _In_reads_(cbPassword) PCBYTE pbPassword, SIZE_T cbPassword, _In_reads_opt_(cbPasswordIdentifier) PCBYTE pbPasswordIdentifier, SIZE_T cbPasswordIdentifier, _Out_writes_(cbPT) PBYTE pbPT, SIZE_T cbPT)

◆ SymCrypt802_11SaeCustomCreatePTGeneric()

SYMCRYPT_ERROR SymCrypt802_11SaeCustomCreatePTGeneric ( SYMCRYPT_802_11_SAE_GROUP  group,
_In_reads_(cbSsid) PCBYTE  pbSsid,
SIZE_T  cbSsid,
_In_reads_(cbPassword) PCBYTE  pbPassword,
SIZE_T  cbPassword,
_In_reads_opt_(cbPasswordIdentifier) PCBYTE  pbPasswordIdentifier,
SIZE_T  cbPasswordIdentifier,
_Out_writes_(cbPT) PBYTE  pbPT,
SIZE_T  cbPT 
)

Definition at line 755 of file IEEE802_11SaeCustom.c.

765{
766 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
767
768 SIZE_T cbIkm = 0;
769 SIZE_T cbScratch = 0;
770
771 PBYTE pbPwdValue = NULL;
772 UINT32 cbPwdValue = 0;
773 PBYTE pbScratch = NULL;
775
777 PCSYMCRYPT_MAC pMacAlgorithm = NULL;
778 PSYMCRYPT_INT piU1 = NULL;
779 PSYMCRYPT_INT piU2 = NULL;
782
783 PSYMCRYPT_ECPOINT poP1 = NULL;
784 PSYMCRYPT_ECPOINT poP2 = NULL;
785 PSYMCRYPT_ECPOINT poPT = NULL;
786
787 PCSYMCRYPT_SAE_GROUP_DATA pGroupData = NULL;
788
789
790 pGroupData = SymCryptSaeFindGroupData( group );
791
792 // Provided IANA group number must match one of the supported groups
793 if ( pGroupData == NULL)
794 {
795 scError = SYMCRYPT_INVALID_ARGUMENT;
796 goto cleanup;
797 }
798
799 // Construct the objects associated with the IANA group number
800 pCurve = SymCryptEcurveAllocate( *( pGroupData->pCurveParams), 0 );
801 if( pCurve == NULL )
802 {
803 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
804 goto cleanup;
805 }
806
807 pMacAlgorithm = *( pGroupData->macAlgorithm );
808
810
811 cbIkm = cbPassword + cbPasswordIdentifier;
812 cbScratch = SYMCRYPT_MAX( cbIkm,
817 pbScratch = SymCryptCallbackAlloc( cbScratch );
818
819 // len = olen( p ) + floor( olen( p ) / 2 )
820 cbPwdValue = SYMCRYPT_BYTES_FROM_BITS(pCurve->FModBitsize) + SYMCRYPT_BYTES_FROM_BITS(pCurve->FModBitsize) / 2;
821
822 pbPwdValue = SymCryptCallbackAlloc( cbPwdValue );
823
824 piU1 = SymCryptIntAllocate( SymCryptDigitsFromBits( cbPwdValue * 8 ) );
825 piU2 = SymCryptIntAllocate( SymCryptDigitsFromBits( cbPwdValue * 8 ) );
826 peU1 = SymCryptModElementAllocate( pCurve->FMod );
827 peU2 = SymCryptModElementAllocate( pCurve->FMod );
828
832
833 if( pbScratch == NULL || pbPwdValue == NULL || piU1 == NULL || piU2 == NULL ||
834 peU1 == NULL || peU2 == NULL || poP1 == NULL || poP2 == NULL || poPT == NULL)
835 {
836 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
837 goto cleanup;
838 }
839
840 // pwd-seed = HKDF-Extract( ssid, password [|| identifier] )
841 // Note that SymCryptHkdfExpandKey corresponds to HKDF-Extract
842 memcpy( pbScratch, pbPassword, cbPassword );
843 if( pbPasswordIdentifier )
844 {
845 memcpy( pbScratch + cbPassword, pbPasswordIdentifier, cbPasswordIdentifier );
846 }
847
848 scError = SymCryptHkdfExpandKey( &hkdfKey, pMacAlgorithm, pbScratch, cbIkm, pbSsid, cbSsid );
849 if( scError != SYMCRYPT_NO_ERROR )
850 {
851 goto cleanup;
852 }
853
854 // pwd-value = HKDF-Expand( pwd-seed, "SAE Hash to Element u1 P1", len )
855 // Note that SymCryptHkdf derive corresponds to HKDF-Expand
856 // Salt does not include a null terminator, so the length is 25 chars
857 scError = SymCryptHkdfDerive( &hkdfKey, (PCBYTE) "SAE Hash to Element u1 P1", 25, pbPwdValue, cbPwdValue );
858 if( scError != SYMCRYPT_NO_ERROR )
859 {
860 goto cleanup;
861 }
862
863 // u1 = pwd-value modulo p
864 scError = SymCryptIntSetValue( pbPwdValue, cbPwdValue, SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, piU1 );
865 if( scError != SYMCRYPT_NO_ERROR )
866 {
867 goto cleanup;
868 }
869
870 SymCryptIntToModElement( piU1, pCurve->FMod, peU1, pbScratch, cbScratch );
871
872 // P1 = SSWU( u1 )
873 SymCryptSswu( pCurve, pGroupData->z, peU1, poP1, pbScratch, cbScratch );
874
875 // pwd-value = HKDF-Expand( pwd-seed, "SAE Hash to Element u2 P2", len )
876 scError = SymCryptHkdfDerive( &hkdfKey, (PCBYTE) "SAE Hash to Element u2 P2", 25, pbPwdValue, cbPwdValue );
877 if( scError != SYMCRYPT_NO_ERROR )
878 {
879 goto cleanup;
880 }
881
882 // u2 = pwd-value modulo p
883 scError = SymCryptIntSetValue( pbPwdValue, cbPwdValue, SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, piU2 );
884 if( scError != SYMCRYPT_NO_ERROR )
885 {
886 goto cleanup;
887 }
888
889 SymCryptIntToModElement( piU2, pCurve->FMod, peU2, pbScratch, cbScratch );
890
891 // P2 = SSWU( u2 )
892 scError = SymCryptSswu( pCurve, pGroupData->z, peU2, poP2, pbScratch, cbScratch );
893 if( scError != SYMCRYPT_NO_ERROR )
894 {
895 goto cleanup;
896 }
897
898 // PT = P1 + P2
899 SymCryptEcpointAdd( pCurve, poP1, poP2, poPT, 0, pbScratch, cbScratch );
900
902 poPT,
905 pbPT,
906 cbPT,
907 0,
908 pbScratch,
909 cbScratch );
910 SYMCRYPT_ASSERT( scError == SYMCRYPT_NO_ERROR );
911
912cleanup:
913
914 if( poP2 != NULL )
915 {
917 poP2 = NULL;
918 }
919
920 if( poP1 != NULL )
921 {
923 poP1 = NULL;
924 }
925
926 if( poPT != NULL )
927 {
929 poPT = NULL;
930 }
931
932 if( peU2 != NULL )
933 {
934 SymCryptModElementFree( pCurve->FMod, peU2 );
935 peU2 = NULL;
936 }
937
938 if( peU1 != NULL )
939 {
940 SymCryptModElementFree( pCurve->FMod, peU1 );
941 peU1 = NULL;
942 }
943
944 if( piU2 != NULL )
945 {
946 SymCryptIntFree( piU2 );
947 piU2 = NULL;
948 }
949
950 if( piU1 != NULL )
951 {
952 SymCryptIntFree( piU1 );
953 piU1 = NULL;
954 }
955
956 if( pbPwdValue != NULL )
957 {
958 SymCryptWipe( pbPwdValue, cbPwdValue );
959 SymCryptCallbackFree( pbPwdValue );
960 pbPwdValue = NULL;
961 }
962
963 if( pbScratch != NULL )
964 {
965 SymCryptWipe( pbScratch, cbScratch );
966 SymCryptCallbackFree( pbScratch );
967 pbScratch = NULL;
968 }
969
970 if ( pCurve != NULL )
971 {
973 pCurve = NULL;
974 }
975
976 return scError;
977}
PCSYMCRYPT_SAE_GROUP_DATA SymCryptSaeFindGroupData(SYMCRYPT_802_11_SAE_GROUP ianaGroup)
SYMCRYPT_ERROR SymCryptSswu(_In_ PSYMCRYPT_ECURVE pCurve, _In_ INT32 z, _In_ PSYMCRYPT_MODELEMENT peU, _Out_ PSYMCRYPT_ECPOINT poP, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
GLboolean GLuint group
Definition: glext.h:11120
#define memcpy(s1, s2, n)
Definition: mkisofs.h:878
const PCSYMCRYPT_ECURVE_PARAMS * pCurveParams
const PCSYMCRYPT_MAC * macAlgorithm
VOID SYMCRYPT_CALL SymCryptEcurveFree(_Out_ PSYMCRYPT_ECURVE pCurve)
Definition: ecurve.c:657
#define SYMCRYPT_ASSERT(_x)
Definition: symcrypt.h:10807
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptHkdfExpandKey(_Out_ PSYMCRYPT_HKDF_EXPANDED_KEY pExpandedKey, _In_ PCSYMCRYPT_MAC macAlgorithm, _In_reads_(cbIkm) PCBYTE pbIkm, SIZE_T cbIkm, _In_reads_opt_(cbSalt) PCBYTE pbSalt, SIZE_T cbSalt)
Definition: hkdf.c:18
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptHkdfDerive(_In_ PCSYMCRYPT_HKDF_EXPANDED_KEY pExpandedKey, _In_reads_opt_(cbInfo) PCBYTE pbInfo, SIZE_T cbInfo, _Out_writes_(cbResult) PBYTE pbResult, SIZE_T cbResult)
Definition: hkdf.c:106
PSYMCRYPT_ECURVE SYMCRYPT_CALL SymCryptEcurveAllocate(_In_ PCSYMCRYPT_ECURVE_PARAMS pParams, _In_ UINT32 flags)
Definition: ecurve.c:606
#define SYMCRYPT_BYTES_FROM_BITS(bits)
const BYTE * PCBYTE
UINT32 SYMCRYPT_CALL SymCryptEcurveDigitsofFieldElement(_In_ PCSYMCRYPT_ECURVE pCurve)
Definition: ecurve.c:682
#define SYMCRYPT_SCRATCH_BYTES_FOR_MODEXP(_nDigits)

Referenced by SymCrypt802_11SaeCustomCreatePT().

◆ SymCrypt802_11SaeCustomDestroy()

VOID SymCrypt802_11SaeCustomDestroy ( _Inout_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE  pState)

Definition at line 1253 of file IEEE802_11SaeCustom.c.

1255{
1256 PSYMCRYPT_ECURVE pCurve = pState->pCurve;
1257
1258 if( pState->poPWE != NULL )
1259 {
1261 }
1262
1263 if( pState->peMask != NULL )
1264 {
1265 SymCryptModElementFree( pCurve->GOrd, pState->peMask );
1266 }
1267
1268 if( pState->peRand != NULL )
1269 {
1270 SymCryptModElementFree( pCurve->GOrd, pState->peRand );
1271 }
1272
1273 if( pCurve != NULL )
1274 {
1276 }
1277
1278 SymCryptWipeKnownSize( pState, sizeof( *pState ) );
1279}
FORCEINLINE VOID SYMCRYPT_CALL SymCryptWipeKnownSize(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)

Referenced by SymCrypt802_11SaeCustomInit(), and SymCrypt802_11SaeCustomInitH2EGeneric().

◆ SymCrypt802_11SaeCustomInit()

SYMCRYPT_ERROR SymCrypt802_11SaeCustomInit ( _Out_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE  pState,
_In_reads_(6) PCBYTE  pbMacA,
_In_reads_(6) PCBYTE  pbMacB,
_In_reads_(cbPassword) PCBYTE  pbPassword,
SIZE_T  cbPassword,
_Out_opt_ PBYTE  pbCounter,
_Inout_updates_opt_(32) PBYTE  pbRand,
_Inout_updates_opt_(32) PBYTE  pbMask 
)

Definition at line 467 of file IEEE802_11SaeCustom.c.

476{
477 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
478
480 UINT32 notFoundMask;
481 UINT32 solutionMask;
482 UINT32 negMask;
485 BYTE abSeedKey[16]; // Need only 12, but the extra bytes make the code easier.
489 BYTE abTmp[2];
490 BYTE pointBuf[ 64 ];
491 PBYTE pbScratch = NULL;
492 SIZE_T cbScratch = 0;
493 UINT64 minMac;
494 UINT64 maxMac;
495
496 UINT32 nDigits;
497 PSYMCRYPT_ECURVE pCurve; // Only a cache, pState->pCurve owns the allocation
498 PSYMCRYPT_INT piTmp = NULL;
501 PSYMCRYPT_MODELEMENT peCubic = NULL;
503 PSYMCRYPT_ECPOINT poPWECandidate = NULL;
504
505 // Set state to 0 so that our pointers have valid values.
506 SymCryptWipe( pState, sizeof( *pState ) );
507
508 // Per IEEE 802.11-2016 section 12.4.4.1 the mandatory-to-implement curve is
509 // number 19 from the IANA Group description for RFC 2409 (IKE)
510 // The IANA website maps this to a 256-bit Random ECP group in RFC 5903.
511 // RFC 5903 specifies this group to be identical to the NIST P256 curve.
513 pState->pCurve = pCurve;
514 if( pCurve == NULL )
515 {
516 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
517 goto cleanup;
518 }
519
520 pState->macAlgorithm = SymCryptHmacSha256Algorithm;
521
522 pState->peRand = SymCryptModElementAllocate( pCurve->GOrd );
523 if( pState->peRand == NULL )
524 {
525 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
526 goto cleanup;
527 }
528
529 pState->peMask = SymCryptModElementAllocate( pCurve->GOrd );
530 if( pState->peMask == NULL )
531 {
532 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
533 goto cleanup;
534 }
535
537 if( pState->poPWE == NULL )
538 {
539 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
540 goto cleanup;
541 }
542
544
548 pbScratch = SymCryptCallbackAlloc( cbScratch );
549
550 piTmp = SymCryptIntAllocate( nDigits );
551 peX = SymCryptModElementAllocate( pCurve->FMod );
552 peY = SymCryptModElementAllocate( pCurve->FMod );
553 peCubic = SymCryptModElementAllocate( pCurve->FMod );
554 peTmp = SymCryptModElementAllocate( pCurve->FMod );
555 poPWECandidate = SymCryptEcpointAllocate( pCurve );
556
557 if( pbScratch == NULL || piTmp == NULL || peX == NULL || peY == NULL || peCubic == NULL || peTmp == NULL || poPWECandidate == NULL )
558 {
559 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
560 goto cleanup;
561 }
562
563 SymCryptWipeKnownSize( abSeedKey, sizeof( abSeedKey ) );
564 memcpy( &abSeedKey[0], pbMac1, 6 );
565 minMac = SYMCRYPT_LOAD_MSBFIRST64( abSeedKey );
566 memcpy( &abSeedKey[0], pbMac2, 6 );
567 maxMac = SYMCRYPT_LOAD_MSBFIRST64( abSeedKey );
568
569 if( minMac > maxMac )
570 {
571 // MAC values are public, no side-channel issues with this if()
572 // Swap the two values
573 minMac ^= maxMac;
574 maxMac ^= minMac;
575 minMac ^= maxMac;
576 }
577
578 // Now we write the two MACs into the buffer.
579 // Note the slight overlap, and the use of 14 bytes rather than 12
580 SYMCRYPT_STORE_MSBFIRST64( &abSeedKey[0], maxMac );
581 SYMCRYPT_STORE_MSBFIRST64( &abSeedKey[6], minMac ); // This writes up to abSeedKey[14]
582
583 SymCryptHmacSha256ExpandKey( &hmacSeedKey, abSeedKey, 12 );
584 SymCryptWipeKnownSize( abSeedKey, sizeof( abSeedKey ) ); // Not strictly speaking a secret, but good general hygiene
585
586 notFoundMask = (UINT32)-1;
587 counter = 0;
588
589 // We exit the loop only after 40 or more iterations
590 // This greatly reduces the side-channel of how often we run this loop.
591 while( notFoundMask != 0 || counter < 40 )
592 {
593 counter += 1;
594 if( counter == 0 )
595 {
596 scError = SYMCRYPT_INVALID_ARGUMENT;
597 goto cleanup;
598 }
599
600 // pwd-seed = Hmac-sha256( MacA || MacB , Password || counter )
601 SymCryptHmacSha256Init( &hmacState, &hmacSeedKey );
602 SymCryptHmacSha256Append( &hmacState, pbPassword, cbPassword );
603 SymCryptHmacSha256Append( &hmacState, &counter, 1 );
604 SymCryptHmacSha256Result( &hmacState, abSeed );
605
606 // pwd-value
607 SymCryptHmacSha256ExpandKey( &hmacValueKey, abSeed, sizeof( abSeed ) );
608 SymCryptHmacSha256Init( &hmacState, &hmacValueKey );
609
610 SYMCRYPT_STORE_LSBFIRST16( abTmp, 1 );
611 SymCryptHmacSha256Append( &hmacState, abTmp, 2 ); // i value = 1
612 // Spec is unclear on whether there should be a terminating 0 on the context
613 // There are 23 characters in the string, so using len=24 gives us a zero
614 SymCryptHmacSha256Append( &hmacState, (PCBYTE) "SAE Hunting and Pecking", 23 );
615
616 // Pick up the byte representation of p from the parameters
618
619 SYMCRYPT_STORE_LSBFIRST16( abTmp, 256 );
620 SymCryptHmacSha256Append( &hmacState, abTmp, 2 ); // Length value = 256
621 SymCryptHmacSha256Result( &hmacState, abValue );
622
623 // Get the pwd-value into an integer
624 scError = SymCryptIntSetValue( abValue, sizeof( abValue ), SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, piTmp );
625 if( scError != SYMCRYPT_NO_ERROR )
626 {
627 goto cleanup;
628 }
629
630 // Check that it is less than P
631 if( !SymCryptIntIsLessThan( piTmp, SymCryptIntFromModulus( pCurve->FMod ) ) )
632 {
633 // This is a slight side-channel, but our prime P starts with FFFFFFFF so the probability of
634 // hitting this case is < 2^-32.
635 continue;
636 }
637
638 // Compute x^3 + A*x + B
639 SymCryptIntToModElement( piTmp, pCurve->FMod, peX, pbScratch, cbScratch );
640 SymCryptModSquare( pCurve->FMod, peX, peCubic, pbScratch, cbScratch );
641 SymCryptModAdd( pCurve->FMod, peCubic, pCurve->A, peCubic, pbScratch, cbScratch );
642 SymCryptModMul( pCurve->FMod, peCubic, peX, peCubic, pbScratch, cbScratch );
643 SymCryptModAdd( pCurve->FMod, peCubic, pCurve->B, peCubic, pbScratch, cbScratch );
644
645 // Get the quadratic residue of (x^3 + A*x + B) modulo P if it exists
646 scError = SymCryptModSqrt( pCurve->FMod, peCubic, &solutionMask, peY, pbScratch, cbScratch );
647 if( scError != SYMCRYPT_NO_ERROR )
648 {
649 goto cleanup;
650 }
651
652 solutionMask &= notFoundMask;
653
654 // Pick Y or -Y according to the LSbits
655 SymCryptModElementToInt( pCurve->FMod, peY, piTmp, pbScratch, cbScratch );
656 SymCryptModNeg( pCurve->FMod, peY, peTmp, pbScratch, cbScratch );
657
658 negMask = 0 - ((abSeed[ sizeof( abSeed ) - 1 ] ^ SymCryptIntGetValueLsbits32( piTmp ) ) & 1);
659 SymCryptModElementMaskedCopy( pCurve->FMod, peTmp, peY, negMask );
660
661 SymCryptModElementGetValue( pCurve->FMod, peX, &pointBuf[ 0], 32, SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, pbScratch, cbScratch );
662 SymCryptModElementGetValue( pCurve->FMod, peY, &pointBuf[32], 32, SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, pbScratch, cbScratch );
664 pointBuf,
665 sizeof( pointBuf ),
668 poPWECandidate,
669 0,
670 pbScratch,
671 cbScratch );
672 if( scError != SYMCRYPT_NO_ERROR )
673 {
674 goto cleanup;
675 }
676
677 SymCryptEcpointMaskedCopy( pCurve, poPWECandidate, pState->poPWE, solutionMask );
678 pState->counter |= (BYTE)(counter & solutionMask);
679
680 notFoundMask &= ~solutionMask;
681 }
682
683 scError = SymCrypt802_11SaeCustomSetRandMask( pState, pbRand, 32, pbMask, 32, pbScratch, cbScratch );
684 if( scError != SYMCRYPT_NO_ERROR)
685 {
686 goto cleanup;
687 }
688
689 if( pbCounter != NULL )
690 {
691 *pbCounter = pState->counter;
692 }
693
694cleanup:
695
696 SymCryptWipe( &hmacSeedKey, sizeof( hmacSeedKey ) );
697 SymCryptWipe( &hmacValueKey, sizeof( hmacValueKey ) );
698 SymCryptWipe( abSeed, sizeof( abSeed ) );
699 SymCryptWipe( abValue, sizeof( abValue ) );
700 SymCryptWipe( pointBuf, sizeof( pointBuf ) );
701
702 if( piTmp != NULL )
703 {
704 SymCryptIntFree( piTmp );
705 piTmp = NULL;
706 }
707
708 if( peX != NULL )
709 {
710 SymCryptModElementFree( pCurve->FMod, peX );
711 peX = NULL;
712 }
713
714 if( peY != NULL )
715 {
716 SymCryptModElementFree( pCurve->FMod, peY );
717 peY = NULL;
718 }
719
720 if( peCubic != NULL )
721 {
722 SymCryptModElementFree( pCurve->FMod, peCubic );
723 peCubic = NULL;
724 }
725
726 if( peTmp != NULL )
727 {
728 SymCryptModElementFree( pCurve->FMod, peTmp );
729 peTmp = NULL;
730 }
731
732 if( poPWECandidate != NULL )
733 {
734 SymCryptEcpointFree( pCurve, poPWECandidate );
735 poPWECandidate = NULL;
736 }
737
738 if( scError != SYMCRYPT_NO_ERROR )
739 {
741 }
742
743 if( pbScratch != NULL )
744 {
745 SymCryptWipe( pbScratch, cbScratch );
746 SymCryptCallbackFree( pbScratch );
747 pbScratch = NULL;
748 }
749
750 return scError;
751}
#define PRIME_LENGTH_BITS
SYMCRYPT_ERROR SymCryptModSqrt(_In_ PSYMCRYPT_MODULUS pmMod, _In_ PSYMCRYPT_MODELEMENT peVal, _Out_ PUINT32 puIsQuadraticResidue, _Out_opt_ PSYMCRYPT_MODELEMENT peSqrtArg, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
SYMCRYPT_ERROR SymCrypt802_11SaeCustomSetRandMask(_Inout_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, _Inout_updates_opt_(cbRand) PBYTE pbRand, SIZE_T cbRand, _Inout_updates_opt_(cbMask) PBYTE pbMask, SIZE_T cbMask, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
VOID SymCrypt802_11SaeCustomDestroy(_Inout_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE pState)
COMPILER_DEPENDENT_UINT64 UINT64
Definition: actypes.h:131
BYTE abSeed[SYMCRYPT_LMS_MAX_N]
Definition: sc_lib.h:4735
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptHmacSha256ExpandKey(_Out_ PSYMCRYPT_HMAC_SHA256_EXPANDED_KEY pExpandedKey, _In_reads_opt_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
const PCSYMCRYPT_MAC SymCryptHmacSha256Algorithm
Definition: hmacsha256.c:29
#define SYMCRYPT_STORE_LSBFIRST16(p, v)
Definition: symcrypt.h:306
#define SYMCRYPT_LOAD_MSBFIRST64(p)
Definition: symcrypt.h:304
#define SYMCRYPT_HMAC_SHA256_RESULT_SIZE
Definition: symcrypt.h:2856
const PCSYMCRYPT_ECURVE_PARAMS SymCryptEcurveParamsNistP256
VOID SYMCRYPT_CALL SymCryptHmacSha256Result(_Inout_ PSYMCRYPT_HMAC_SHA256_STATE pState, _Out_writes_(SYMCRYPT_HMAC_SHA256_RESULT_SIZE) PBYTE pbResult)
#define SYMCRYPT_STORE_MSBFIRST64(p, v)
Definition: symcrypt.h:312
VOID SYMCRYPT_CALL SymCryptHmacSha256Init(_Out_ PSYMCRYPT_HMAC_SHA256_STATE pState, _In_ PCSYMCRYPT_HMAC_SHA256_EXPANDED_KEY pExpandedKey)
VOID SYMCRYPT_CALL SymCryptHmacSha256Append(_Inout_ PSYMCRYPT_HMAC_SHA256_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
SYMCRYPT_MAGIC_FIELD SYMCRYPT_HMAC_SHA256_STATE
SYMCRYPT_MAGIC_FIELD SYMCRYPT_HMAC_SHA256_EXPANDED_KEY
UINT32 SYMCRYPT_CALL SymCryptIntGetValueLsbits32(_In_ PCSYMCRYPT_INT piSrc)
Definition: a_dispatch.c:270
VOID SymCryptModElementMaskedCopy(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_MODELEMENT peDst, UINT32 mask)
Definition: a_dispatch.c:692
VOID SymCryptEcpointMaskedCopy(_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, _Out_ PSYMCRYPT_ECPOINT poDst, UINT32 mask)
Definition: ecpoint.c:190
VOID SYMCRYPT_CALL SymCryptModNeg(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:895
VOID SYMCRYPT_CALL SymCryptModMul(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc1, _In_ PCSYMCRYPT_MODELEMENT peSrc2, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:867
VOID SYMCRYPT_CALL SymCryptModSquare(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:881
unsigned char BYTE
Definition: xxhash.c:193

◆ SymCrypt802_11SaeCustomInitH2E()

SYMCRYPT_ERROR SymCrypt802_11SaeCustomInitH2E ( _Out_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE  pState,
_In_reads_(64) PCBYTE  pbPT,
_In_reads_(6) PCBYTE  pbMacA,
_In_reads_(6) PCBYTE  pbMacB,
_Inout_updates_opt_(32) PBYTE  pbRand,
_Inout_updates_opt_(32) PBYTE  pbMask 
)

Definition at line 1231 of file IEEE802_11SaeCustom.c.

1238{
1241 pbPT,
1242 64,
1243 pbMacA,
1244 pbMacB,
1245 pbRand,
1246 32,
1247 pbMask,
1248 32 );
1249}
SYMCRYPT_ERROR SymCrypt802_11SaeCustomInitH2EGeneric(_Out_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE pState, SYMCRYPT_802_11_SAE_GROUP group, _In_reads_(cbPT) PCBYTE pbPT, SIZE_T cbPT, _In_reads_(6) PCBYTE pbMacA, _In_reads_(6) PCBYTE pbMacB, _Inout_updates_opt_(cbRand) PBYTE pbRand, SIZE_T cbRand, _Inout_updates_opt_(cbMask) PBYTE pbMask, SIZE_T cbMask)

◆ SymCrypt802_11SaeCustomInitH2EGeneric()

SYMCRYPT_ERROR SymCrypt802_11SaeCustomInitH2EGeneric ( _Out_ PSYMCRYPT_802_11_SAE_CUSTOM_STATE  pState,
SYMCRYPT_802_11_SAE_GROUP  group,
_In_reads_(cbPT) PCBYTE  pbPT,
SIZE_T  cbPT,
_In_reads_(6) PCBYTE  pbMacA,
_In_reads_(6) PCBYTE  pbMacB,
_Inout_updates_opt_(cbRand) PBYTE  pbRand,
SIZE_T  cbRand,
_Inout_updates_opt_(cbMask) PBYTE  pbMask,
SIZE_T  cbMask 
)

Definition at line 1003 of file IEEE802_11SaeCustom.c.

1014{
1015 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
1016
1017 BYTE hmacKeyBytes[SYMCRYPT_SAE_MAX_HMAC_OUTPUT_SIZE_BYTES] = { 0 };
1019 BYTE macBuffer[16] = { 0 }; // Need only 12, but the extra bytes make the code easier.
1020 SYMCRYPT_MAC_EXPANDED_KEY hmacKey = { 0 };
1021 SYMCRYPT_MAC_STATE hmacState = { 0 };
1022
1023 SIZE_T cbScratch = 0;
1024 PBYTE pbScratch = NULL;
1025
1026 UINT64 minMac = 0;
1027 UINT64 maxMac = 0;
1028
1029 UINT32 nDigits = 0;
1030
1031 PSYMCRYPT_INT piTmp = NULL;
1032 PSYMCRYPT_MODULUS pmMod = NULL;
1033 PSYMCRYPT_MODELEMENT peVal = NULL;
1034 PSYMCRYPT_MODELEMENT peTmp = NULL;
1035 PSYMCRYPT_ECPOINT poPT = NULL;
1036 PCSYMCRYPT_SAE_GROUP_DATA pGroupData = NULL;
1037 PCSYMCRYPT_MAC pMacAlgorithm = NULL;
1038
1039 // Set state to 0 so that our pointers have valid values.
1040 SymCryptWipeKnownSize( pState, sizeof( *pState ) );
1041
1042 PSYMCRYPT_ECURVE pCurve = NULL; // Weak reference; curve is owned by pState
1043
1044 pGroupData = SymCryptSaeFindGroupData( group );
1045
1046 // Provided IANA group number must match one of the supported groups
1047 if ( pGroupData == NULL )
1048 {
1049 scError = SYMCRYPT_INVALID_ARGUMENT;
1050 goto cleanup;
1051 }
1052
1053 // Construct the objects associated with the IANA group number
1054 pCurve = SymCryptEcurveAllocate( *( pGroupData->pCurveParams ), 0 );
1055 if ( pCurve == NULL )
1056 {
1057 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
1058 goto cleanup;
1059 }
1060
1061 pState->pCurve = pCurve;
1062
1063 pMacAlgorithm = *( pGroupData->macAlgorithm );
1064
1065 SIZE_T cbHMACOutputSize = pMacAlgorithm->resultSize;
1066
1067 pState->peRand = SymCryptModElementAllocate( pCurve->GOrd );
1068 if( pState->peRand == NULL )
1069 {
1070 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
1071 goto cleanup;
1072 }
1073
1074 pState->peMask = SymCryptModElementAllocate( pCurve->GOrd );
1075 if( pState->peMask == NULL )
1076 {
1077 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
1078 goto cleanup;
1079 }
1080
1082 if( pState->poPWE == NULL )
1083 {
1084 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
1085 goto cleanup;
1086 }
1087
1088 nDigits = SymCryptDigitsFromBits( pCurve->GOrdBitsize );
1089
1090 piTmp = SymCryptIntAllocate( nDigits );
1091 pmMod = SymCryptModulusAllocate( nDigits );
1093
1098 pbScratch = SymCryptCallbackAlloc( cbScratch );
1099
1100 if( piTmp == NULL || pmMod == NULL || poPT == NULL || pbScratch == NULL )
1101 {
1102 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
1103 goto cleanup;
1104 }
1105
1106 memcpy( &macBuffer[0], pbMacA, 6 );
1107 minMac = SYMCRYPT_LOAD_MSBFIRST64( macBuffer );
1108 memcpy( &macBuffer[0], pbMacB, 6 );
1109 maxMac = SYMCRYPT_LOAD_MSBFIRST64( macBuffer );
1110
1111 if( minMac > maxMac )
1112 {
1113 // MAC values are public, no side-channel issues with this if()
1114 // Swap the two values
1115 minMac ^= maxMac;
1116 maxMac ^= minMac;
1117 minMac ^= maxMac;
1118 }
1119
1120 // Now we write the two MACs into the buffer.
1121 // Note the slight overlap, and the use of 14 bytes rather than 12
1122 SYMCRYPT_STORE_MSBFIRST64( &macBuffer[0], maxMac );
1123 SYMCRYPT_STORE_MSBFIRST64( &macBuffer[6], minMac ); // This writes up to macBuffer[14]
1124
1125 // val = hmac-sha256( 0^n, maxMac || minMac )
1126 // The HMAC key is is a buffer of all zeros whose length equals the length of the digest from the hash function
1127 pMacAlgorithm->expandKeyFunc(&hmacKey, hmacKeyBytes, cbHMACOutputSize);
1128
1129 pMacAlgorithm->initFunc( &hmacState, &hmacKey );
1130 pMacAlgorithm->appendFunc( &hmacState, macBuffer, 12 );
1131 pMacAlgorithm->resultFunc( &hmacState, valBytes );
1132
1133 // val = val (#4666)modulo (q - 1) + 1
1135 SymCryptIntToModulus( piTmp, pmMod, 1, SYMCRYPT_FLAG_DATA_PUBLIC, pbScratch, cbScratch );
1136
1137 peVal = SymCryptModElementAllocate( pmMod );
1138 peTmp = SymCryptModElementAllocate( pmMod );
1139
1140 if( peVal == NULL || peTmp == NULL )
1141 {
1142 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
1143 goto cleanup;
1144 }
1145
1146 scError = SymCryptModElementSetValue( valBytes, cbHMACOutputSize, SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, pmMod, peVal, pbScratch, cbScratch );
1147 if( scError != SYMCRYPT_NO_ERROR )
1148 {
1149 goto cleanup;
1150 }
1151
1152 SymCryptModElementSetValueUint32( 1, pmMod, peTmp, pbScratch, cbScratch );
1153 SymCryptModAdd( pmMod, peVal, peTmp, peVal, pbScratch, cbScratch );
1154
1155 SymCryptModElementToInt( pmMod, peVal, piTmp, pbScratch, cbScratch );
1156
1158 pbPT,
1159 cbPT,
1162 poPT,
1163 0,
1164 pbScratch,
1165 cbScratch );
1166 if( scError != SYMCRYPT_NO_ERROR )
1167 {
1168 goto cleanup;
1169 }
1170
1171 scError = SymCryptEcpointScalarMul( pCurve, piTmp, poPT, 0, pState->poPWE, pbScratch, cbScratch );
1172 if( scError != SYMCRYPT_NO_ERROR )
1173 {
1174 goto cleanup;
1175 }
1176
1177 scError = SymCrypt802_11SaeCustomSetRandMask( pState, pbRand, cbRand, pbMask, cbMask, pbScratch, cbScratch );
1178 if( scError != SYMCRYPT_NO_ERROR )
1179 {
1180 goto cleanup;
1181 }
1182
1183cleanup:
1184
1185 if( peTmp != NULL )
1186 {
1187 SymCryptModElementFree( pmMod, peTmp );
1188 peTmp = NULL;
1189 }
1190
1191 if( peVal != NULL )
1192 {
1193 SymCryptModElementFree( pmMod, peVal );
1194 peVal = NULL;
1195 }
1196
1197 if( poPT != NULL )
1198 {
1199 SymCryptEcpointFree( pCurve, poPT );
1200 poPT = NULL;
1201 }
1202
1203 if( pmMod != NULL )
1204 {
1205 SymCryptModulusFree( pmMod );
1206 pmMod = NULL;
1207 }
1208
1209 if( piTmp != NULL )
1210 {
1211 SymCryptIntFree( piTmp );
1212 piTmp = NULL;
1213 }
1214
1215 if( pbScratch != NULL )
1216 {
1217 SymCryptWipe( pbScratch, cbScratch );
1218 SymCryptCallbackFree( pbScratch );
1219 pbScratch = NULL;
1220 }
1221
1222 if( scError != SYMCRYPT_NO_ERROR )
1223 {
1225 }
1226
1227 return scError;
1228}
PSYMCRYPT_MAC_EXPAND_KEY expandKeyFunc
PSYMCRYPT_MAC_RESULT resultFunc
PSYMCRYPT_MAC_APPEND appendFunc
PSYMCRYPT_MAC_INIT initFunc
SYMCRYPT_MODULUS * PSYMCRYPT_MODULUS
#define SYMCRYPT_INTERNAL_SCRATCH_BYTES_FOR_SCALAR_ECURVE_OPERATIONS(_pCurve, _nPoints)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModElementSetValue(_In_reads_bytes_(cbSrc) PCBYTE pbSrc, SIZE_T cbSrc, SYMCRYPT_NUMBER_FORMAT format, PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:781
VOID SYMCRYPT_CALL SymCryptModElementSetValueUint32(UINT32 value, _In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:908
UINT32 SYMCRYPT_CALL SymCryptIntSubUint32(_In_ PCSYMCRYPT_INT piSrc1, UINT32 Src2, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:314
VOID SYMCRYPT_CALL SymCryptIntToModulus(_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_MODULUS pmDst, UINT32 averageOperations, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:727
PSYMCRYPT_MODULUS SYMCRYPT_CALL SymCryptModulusAllocate(UINT32 nDigits)
Definition: a_dispatch.c:587
VOID SYMCRYPT_CALL SymCryptModulusFree(_Out_ PSYMCRYPT_MODULUS pmObj)
Definition: a_dispatch.c:594
#define SYMCRYPT_SAE_MAX_HMAC_OUTPUT_SIZE_BYTES
#define SYMCRYPT_FLAG_DATA_PUBLIC

Referenced by SymCrypt802_11SaeCustomInitH2E().

◆ SymCrypt802_11SaeGetGroupSizes()

VOID SymCrypt802_11SaeGetGroupSizes ( SYMCRYPT_802_11_SAE_GROUP  group,
_Out_opt_ SIZE_T *  pcbScalar,
_Out_opt_ SIZE_T *  pcbPoint 
)

Definition at line 58 of file IEEE802_11SaeCustom.c.

62{
64 SIZE_T cbScalar = 0;
65 SIZE_T cbPoint = 0;
66
67 pGroupData = SymCryptSaeFindGroupData( group );
68
69 if ( pGroupData != NULL )
70 {
71 cbScalar = ( *( pGroupData->pCurveParams ) )->cbFieldLength;
72 cbPoint = 2 * cbScalar;
73 }
74
75 if ( pcbScalar != NULL )
76 {
77 *pcbScalar = cbScalar;
78 }
79
80 if ( pcbPoint != NULL )
81 {
82 *pcbPoint = cbPoint;
83 }
84}

◆ SymCryptCompositeMlKemEncapsulateEx()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptCompositeMlKemEncapsulateEx ( _In_ PCSYMCRYPT_COMPOSITE_MLKEMKEY  pkCompositeMlKemkey,
_In_reads_bytes_opt_(cbMlKemRandom) PCBYTE  pbMlKemRandom,
SIZE_T  cbMlKemRandom,
_In_reads_bytes_opt_(cbTradRandom) PCBYTE  pbTradRandom,
SIZE_T  cbTradRandom,
_Out_writes_bytes_(cbAgreedSecret) PBYTE  pbAgreedSecret,
SIZE_T  cbAgreedSecret,
_Out_writes_bytes_(cbCiphertext) PBYTE  pbCiphertext,
SIZE_T  cbCiphertext 
)

◆ SymCryptCreateTrialDivisionContext()

PCSYMCRYPT_TRIALDIVISION_CONTEXT SYMCRYPT_CALL SymCryptCreateTrialDivisionContext ( UINT32  nDigits)

Definition at line 1007 of file a_dispatch.c.

1008{
1010}
PCSYMCRYPT_TRIALDIVISION_CONTEXT SYMCRYPT_CALL SymCryptFdefCreateTrialDivisionContext(UINT32 nDigits)

Referenced by SymCryptDlgroupGenerate(), SymCryptDlgroupSetValue(), and SymCryptIntGenerateRandomPrime().

◆ SymCryptCrtGenerateInverses()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptCrtGenerateInverses ( UINT32  nCoprimes,
_In_reads_(nCoprimes) PCSYMCRYPT_MODULUS *  ppmCoprimes,
UINT32  flags,
_Out_writes_(nCoprimes) PSYMCRYPT_MODELEMENT *  ppeCrtInverses,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 90 of file crt.c.

97{
98 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
99
100 if (nCoprimes == 2)
101 {
103 ppmCoprimes[0],
104 ppmCoprimes[1],
105 flags,
106 ppeCrtInverses[0],
107 ppeCrtInverses[1],
108 pbScratch,
109 cbScratch );
110 }
111 else
112 {
113 scError = SYMCRYPT_INVALID_ARGUMENT;
114 goto cleanup;
115 }
116
117cleanup:
118 return scError;
119}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptCrtGenerateForTwoCoprimes(_In_ PCSYMCRYPT_MODULUS pmP, _In_ PCSYMCRYPT_MODULUS pmQ, UINT32 flags, _Out_ PSYMCRYPT_MODELEMENT peInvQModP, _Out_ PSYMCRYPT_MODELEMENT peInvPModQ, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: crt.c:11
GLbitfield flags
Definition: glext.h:7161

Referenced by SymCryptRsakeyCalculatePrivateFields().

◆ SymCryptCrtSolve()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptCrtSolve ( UINT32  nCoprimes,
_In_reads_(nCoprimes) PCSYMCRYPT_MODULUS *  ppmCoprimes,
_In_reads_(nCoprimes) PCSYMCRYPT_MODELEMENT *  ppeCrtInverses,
_In_reads_(nCoprimes) PCSYMCRYPT_MODELEMENT *  ppeCrtRemainders,
UINT32  flags,
_Out_ PSYMCRYPT_INT  piSolution,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 123 of file crt.c.

132{
133 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
134
135 SYMCRYPT_ASSERT( nCoprimes >= 2 );
136
137 PSYMCRYPT_INT piTmp = NULL;
139
140 PSYMCRYPT_INT piDouble = NULL;
141
142 UINT32 nDigitsMax = 0;
143
144 UINT32 cbInt = 0;
146 UINT32 cbDouble = 0;
147
148 UINT32 carry = 0;
149
151
152 nDigitsMax = SYMCRYPT_MAX( SymCryptModulusDigitsizeOfObject( ppmCoprimes[0] ), SymCryptModulusDigitsizeOfObject( ppmCoprimes[1] ) );
153
154 cbInt = SymCryptSizeofIntFromDigits( nDigitsMax );
156 cbDouble = SymCryptSizeofIntFromDigits( 2*nDigitsMax );
157
158 if( cbDouble == 0 )
159 {
160 // It is possible that cbDouble would not fit within the maximum integer
161 scError = SYMCRYPT_INVALID_ARGUMENT;
162 goto cleanup;
163 }
164
165 SYMCRYPT_ASSERT( cbScratch >= cbInt + cbModElement + cbDouble +
167 SYMCRYPT_SCRATCH_BYTES_FOR_INT_MUL( 2*nDigitsMax ) )
168 );
169
170 // Create temporaries
171 piTmp = SymCryptIntCreate( pbScratch, cbInt, nDigitsMax ); pbScratch += cbInt; cbScratch -= cbInt;
172
173 peTmp = SymCryptModElementCreate( pbScratch, cbModElement, ppmCoprimes[0] ); pbScratch += cbModElement; cbScratch -= cbModElement;
174
175 piDouble = SymCryptIntCreate( pbScratch, cbDouble, 2*nDigitsMax ); pbScratch += cbDouble; cbScratch -= cbDouble;
176
177 if (nCoprimes == 2)
178 {
179 //
180 // Let r0 and r1 be the two remainders modulo p and q respectively
181 // Then we calculate (q^{-1}(r0 - r1) mod p)*q + r1
182 //
183 SymCryptModElementToInt( ppmCoprimes[1], ppeCrtRemainders[1], piTmp, pbScratch, cbScratch ); // Convert r1 to Int
184 SymCryptIntToModElement( piTmp, ppmCoprimes[0], peTmp, pbScratch, cbScratch ); // Convert it to r1 mod p
185
186 SymCryptModSub( ppmCoprimes[0], ppeCrtRemainders[0], peTmp, peTmp, pbScratch, cbScratch ); // (r0 - r1) mod p
187 SymCryptModMul( ppmCoprimes[0], ppeCrtInverses[0], peTmp, peTmp, pbScratch, cbScratch ); // q^{-1}*(r0 - r1) mod p
188 SymCryptModElementToInt( ppmCoprimes[0], peTmp, piTmp, pbScratch, cbScratch ); // Convert it to integer
189
190 SymCryptIntMulMixedSize( piTmp, SymCryptIntFromModulus((PSYMCRYPT_MODULUS)ppmCoprimes[1]), piDouble, pbScratch, cbScratch ); // Multiply by q
191 scError = SymCryptIntCopyMixedSize( piDouble, piSolution ); // Copy it into the solution
192 if (scError != SYMCRYPT_NO_ERROR)
193 {
194 goto cleanup;
195 }
196
197 SymCryptModElementToInt( ppmCoprimes[1], ppeCrtRemainders[1], piTmp, pbScratch, cbScratch ); // Convert r1 to integer
198
199 carry = SymCryptIntAddMixedSize( piTmp, piSolution, piSolution ); // Add it to the solution
200
201 if (carry>0)
202 {
203 scError = SYMCRYPT_INVALID_ARGUMENT;
204 goto cleanup;
205 }
206 }
207 else
208 {
209 scError = SYMCRYPT_INVALID_ARGUMENT;
210 goto cleanup;
211 }
212
213cleanup:
214 return scError;
215}
#define UNREFERENCED_PARAMETER(P)
Definition: ntbasedef.h:329
UINT32 cbModElement
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_MUL(_nResultDigits)
UINT32 SYMCRYPT_CALL SymCryptSizeofModElementFromModulus(PCSYMCRYPT_MODULUS pmMod)
Definition: a_dispatch.c:658
VOID SYMCRYPT_CALL SymCryptModSub(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc1, _In_ PCSYMCRYPT_MODELEMENT peSrc2, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:852
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptIntCopyMixedSize(_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:214
PSYMCRYPT_MODELEMENT SYMCRYPT_CALL SymCryptModElementCreate(_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, _In_ PCSYMCRYPT_MODULUS pmMod)
Definition: a_dispatch.c:665
VOID SYMCRYPT_CALL SymCryptIntMulMixedSize(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:485
UINT32 SYMCRYPT_CALL SymCryptSizeofIntFromDigits(UINT32 nDigits)
Definition: a_dispatch.c:134
UINT32 SYMCRYPT_CALL SymCryptModulusDigitsizeOfObject(_In_ PCSYMCRYPT_MODULUS pmSrc)
Definition: a_dispatch.c:635
PSYMCRYPT_INT SYMCRYPT_CALL SymCryptIntCreate(_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, UINT32 nDigits)
Definition: a_dispatch.c:141
UINT32 SYMCRYPT_CALL SymCryptIntAddMixedSize(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:304

Referenced by rsa_decrypt(), and SymCryptRsaCoreDecCrt().

◆ SymCryptDigitsFromBits()

◆ SymCryptDivisorAllocate()

PSYMCRYPT_DIVISOR SYMCRYPT_CALL SymCryptDivisorAllocate ( UINT32  nDigits)

Definition at line 497 of file a_dispatch.c.

498{
499 return SymCryptFdefDivisorAllocate( nDigits );
500}
PSYMCRYPT_DIVISOR SYMCRYPT_CALL SymCryptFdefDivisorAllocate(UINT32 nDigits)
Definition: fdef_general.c:796

◆ SymCryptDivisorCopy()

VOID SymCryptDivisorCopy ( _In_ PCSYMCRYPT_DIVISOR  pdSrc,
_Out_ PSYMCRYPT_DIVISOR  pdDst 
)

Definition at line 537 of file a_dispatch.c.

540{
541 SymCryptFdefDivisorCopy( pdSrc, pdDst );
542}
VOID SymCryptFdefDivisorCopy(_In_ PCSYMCRYPT_DIVISOR pdSrc, _Out_ PSYMCRYPT_DIVISOR pdDst)
Definition: fdef_general.c:891

◆ SymCryptDivisorCreate()

PSYMCRYPT_DIVISOR SYMCRYPT_CALL SymCryptDivisorCreate ( _Out_writes_bytes_(cbBuffer) PBYTE  pbBuffer,
SIZE_T  cbBuffer,
UINT32  nDigits 
)

Definition at line 519 of file a_dispatch.c.

523{
524 return SymCryptFdefDivisorCreate( pbBuffer, cbBuffer, nDigits );
525}
PSYMCRYPT_DIVISOR SYMCRYPT_CALL SymCryptFdefDivisorCreate(_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, UINT32 nDigits)
Definition: fdef_general.c:842
SIZE_T cbBuffer
Definition: sc_lib_mldsa.h:405

Referenced by SymCryptDlgroupGenerate(), SymCryptDlgroupSetValue(), SymCryptIntExtendedGcd(), SymCryptIntGenerateRandomPrime(), SymCryptRsakeyGenerate(), and SymCryptRsakeySetValueInternal().

◆ SymCryptDivisorDigitsizeOfObject()

UINT32 SYMCRYPT_CALL SymCryptDivisorDigitsizeOfObject ( _In_ PCSYMCRYPT_DIVISOR  pdSrc)

Definition at line 546 of file a_dispatch.c.

547{
548 return pdSrc->nDigits;
549}

Referenced by SymCryptDlgroupGeneratePrimeP_FIPS().

◆ SymCryptDivisorFree()

VOID SYMCRYPT_CALL SymCryptDivisorFree ( _Out_ PSYMCRYPT_DIVISOR  pdObj)

Definition at line 504 of file a_dispatch.c.

505{
506 SymCryptDivisorWipe( pdObj );
507 SymCryptCallbackFree( pdObj );
508}
VOID SYMCRYPT_CALL SymCryptDivisorWipe(_Out_ PSYMCRYPT_DIVISOR pdObj)
Definition: a_dispatch.c:529

◆ SymCryptDivisorFromModulus()

PSYMCRYPT_DIVISOR SYMCRYPT_CALL SymCryptDivisorFromModulus ( _In_ PSYMCRYPT_MODULUS  pmSrc)

Definition at line 703 of file a_dispatch.c.

704{
705 return SymCryptFdefDivisorFromModulus( pmSrc );
706}
PSYMCRYPT_DIVISOR SYMCRYPT_CALL SymCryptFdefDivisorFromModulus(_In_ PSYMCRYPT_MODULUS pmSrc)
Definition: fdef_mod.c:265

Referenced by rsa_decrypt(), SymCryptDlgroupGenerateGenG_FIPS(), SymCryptDsaSignEx(), SymCryptDsaVerify(), SymCryptEckeyGetValue(), SymCryptEckeySetValue(), SymCryptRsaCoreDecCrt(), and SymCryptRsakeyCalculatePrimesFromPrivateExponent().

◆ SymCryptDivisorWipe()

VOID SYMCRYPT_CALL SymCryptDivisorWipe ( _Out_ PSYMCRYPT_DIVISOR  pdObj)

Definition at line 529 of file a_dispatch.c.

530{
531 SYMCRYPT_CHECK_MAGIC( pdObj );
532
533 SymCryptWipe( pdObj, pdObj->cbSize );
534}
#define SYMCRYPT_CHECK_MAGIC(p)

Referenced by SymCryptDivisorFree().

◆ SymCryptEcDsaSignEx()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcDsaSignEx ( _In_ PCSYMCRYPT_ECKEY  pKey,
_In_reads_bytes_(cbHashValue) PCBYTE  pbHashValue,
SIZE_T  cbHashValue,
_In_opt_ PCSYMCRYPT_INT  piK,
SYMCRYPT_NUMBER_FORMAT  format,
UINT32  flags,
_Out_writes_bytes_(cbSignature) PBYTE  pbSignature,
SIZE_T  cbSignature 
)

Definition at line 146 of file ec_dsa.c.

155{
156 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
157
158 PBYTE pbScratch = NULL;
159 SIZE_T cbScratch = 0;
160 SIZE_T cbScratchInternal = 0;
161 PBYTE pCurr = NULL;
162
163 PCSYMCRYPT_ECURVE pCurve = pKey->pCurve;
164
165 PSYMCRYPT_INT piTmp = NULL;
166 PSYMCRYPT_INT piMul = NULL;
167 PSYMCRYPT_ECPOINT poKG = NULL;
168
169 PSYMCRYPT_MODELEMENT peMsghash = NULL;
170 PSYMCRYPT_MODELEMENT peSigC = NULL;
171 PSYMCRYPT_MODELEMENT peSigD = NULL;
173
174 PBYTE pbX = NULL;
175
176 UINT32 nDigitsInt = 0;
177 UINT32 nDigitsMul = 0;
178
179 UINT32 cbInt = 0;
180 UINT32 cbMul = 0;
181 UINT32 cbKG = 0;
182 UINT32 cbRs = 0;
183 UINT32 cbX = 0;
184
185 UINT32 signatureCount = 0;
189
190 // Make sure that the key may be used in ECDSA
191 if ( ((pKey->fAlgorithmInfo & SYMCRYPT_FLAG_ECKEY_ECDSA) == 0) )
192 {
193 scError = SYMCRYPT_INVALID_ARGUMENT;
194 goto cleanup;
195 }
196
197 // Make sure only allowed flags are specified and
198 // there is a private key
199 if ( ((flags & ~(allowedFlags)) != 0) ||
200 (!pKey->hasPrivateKey) )
201 {
202 scError = SYMCRYPT_INVALID_ARGUMENT;
203 goto cleanup;
204 }
205
206 // Calculating the digits for the temporary integers
207 nDigitsInt = pCurve->GOrdDigits;
208
210
211 // Objects and scratch space size calculation
212 cbInt = SymCryptSizeofIntFromDigits( nDigitsInt );
213 cbMul = SymCryptSizeofIntFromDigits( nDigitsMul );
217
219 cbScratchInternal = SYMCRYPT_MAX( cbScratchInternal, SYMCRYPT_SCRATCH_BYTES_FOR_COMMON_MOD_OPERATIONS( pCurve->GOrdDigits ) );
220 cbScratchInternal = SYMCRYPT_MAX( cbScratchInternal, SYMCRYPT_SCRATCH_BYTES_FOR_COMMON_MOD_OPERATIONS( pCurve->FModDigits ) );
221 cbScratchInternal = SYMCRYPT_MAX( cbScratchInternal, SYMCRYPT_SCRATCH_BYTES_FOR_MODINV( pCurve->GOrdDigits ) );
222 cbScratchInternal = SYMCRYPT_MAX( cbScratchInternal, SYMCRYPT_SCRATCH_BYTES_FOR_GETSET_VALUE_ECURVE_OPERATIONS( pCurve ) );
223
224 //
225 // From symcrypt_internal.h we have:
226 // - sizeof results are upper bounded by 2^19
227 // - SYMCRYPT_SCRATCH_BYTES results are upper bounded by 2^27 (including RSA and ECURVE)
228 // Thus the following calculation does not overflow cbScratch.
229 //
230 cbScratch = cbScratchInternal + cbInt + cbMul + cbKG + 4*cbRs + cbX;
231
232 // Scratch space allocation
233 pbScratch = SymCryptCallbackAlloc( cbScratch );
234 if ( pbScratch == NULL )
235 {
236 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
237 goto cleanup;
238 }
239
240 // Creating temporaries
241 pCurr = pbScratch + cbScratchInternal;
242 piTmp = SymCryptIntCreate( pCurr, cbInt, nDigitsInt );
243 pCurr += cbInt;
244 piMul = SymCryptIntCreate( pCurr, cbMul, nDigitsMul );
245 pCurr += cbMul;
246 poKG = SymCryptEcpointCreate( pCurr, cbKG, pCurve );
247 pCurr += cbKG;
248 peMsghash = SymCryptModElementCreate( pCurr, cbRs, pCurve->GOrd );
249 pCurr += cbRs;
250 peSigC = SymCryptModElementCreate( pCurr, cbRs, pCurve->GOrd );
251 pCurr += cbRs;
252 peSigD = SymCryptModElementCreate( pCurr, cbRs, pCurve->GOrd );
253 pCurr += cbRs;
254 peTmp = SymCryptModElementCreate( pCurr, cbRs, pCurve->GOrd );
255 pCurr += cbRs;
256 pbX = pCurr;
257
258 SYMCRYPT_ASSERT( piTmp != NULL);
259 SYMCRYPT_ASSERT( piMul != NULL);
260 SYMCRYPT_ASSERT( poKG != NULL);
261 SYMCRYPT_ASSERT( peMsghash != NULL);
262 SYMCRYPT_ASSERT( peSigC != NULL);
263 SYMCRYPT_ASSERT( peSigD != NULL);
264 SYMCRYPT_ASSERT( peTmp != NULL);
265
266 // Truncate the message according to the flags
268 pCurve,
269 pbHashValue,
270 cbHashValue,
271 truncationFlag,
272 peMsghash,
273 piTmp,
274 pbScratch,
275 cbScratchInternal );
276 if ( scError != SYMCRYPT_NO_ERROR )
277 {
278 goto cleanup;
279 }
280
281 //
282 // Main loop: Stop when both c and d are not zero (unless a specific k is provided)
283 //
284 while( TRUE )
285 {
286 if ( piK == NULL )
287 {
288 SymCryptEcpointSetRandom( pCurve, piMul, poKG, pbScratch, cbScratchInternal ); // Generate k and k*G
289 SymCryptIntToModElement( piMul, pCurve->GOrd, peTmp, pbScratch, cbScratchInternal );
290 }
291 else
292 {
293 // Ensure that piK is in the range [1, GOrd-1]
294 if( SymCryptIntIsEqualUint32( piK, 0 ) ||
296 {
297 scError = SYMCRYPT_INVALID_ARGUMENT;
298 goto cleanup;
299 }
300
301 SymCryptIntCopy( piK, piMul );
302 SymCryptIntToModElement( piMul, pCurve->GOrd, peTmp, pbScratch, cbScratchInternal );
303
304 scError = SymCryptEcpointScalarMul( pCurve, piMul, NULL, 0, poKG, pbScratch, cbScratchInternal ); // Generate k*G
305 if ( scError != SYMCRYPT_NO_ERROR )
306 {
307 goto cleanup;
308 }
309 }
310
311 scError = SymCryptModInv( pCurve->GOrd, peTmp, peTmp, publicFlag, pbScratch, cbScratchInternal ); // Invert k
312 if ( scError != SYMCRYPT_NO_ERROR )
313 {
314 goto cleanup;
315 }
316
317 // Get the x coordinates from KG
318 scError = SymCryptEcpointGetValue(
319 pCurve,
320 poKG,
323 pbX,
324 cbX,
325 publicFlag,
326 pbScratch,
327 cbScratchInternal );
328 if ( scError != SYMCRYPT_NO_ERROR )
329 {
330 goto cleanup;
331 }
332
333 // Store c = x(KG) as an integer
334 scError = SymCryptModElementSetValue( pbX, cbX, SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, pCurve->GOrd, peSigC, pbScratch, cbScratch );
335 if ( scError != SYMCRYPT_NO_ERROR )
336 {
337 goto cleanup;
338 }
339
340 // Move the private key into peSigD
341 SymCryptIntToModElement( pKey->piPrivateKey, pCurve->GOrd, peSigD, pbScratch, cbScratchInternal );
342
343 // Multiply the private key by h since its internal format is "DivH"
344 for (UINT32 i=0; i<pCurve->coFactorPower; i++)
345 {
346 SymCryptModAdd( pCurve->GOrd, peSigD, peSigD, peSigD, pbScratch, cbScratchInternal );
347 }
348
349 SymCryptModMul( pCurve->GOrd, peSigC, peSigD, peSigD, pbScratch, cbScratchInternal ); // s * c
350 SymCryptModAdd( pCurve->GOrd, peMsghash, peSigD, peSigD, pbScratch, cbScratchInternal ); // msghash + s*c
351 SymCryptModMul( pCurve->GOrd, peSigD, peTmp, peSigD, pbScratch, cbScratchInternal ); // ( msghash + s*c ) / k
352
353 if ( !( SymCryptModElementIsZero( pCurve->GOrd, peSigC ) |
354 SymCryptModElementIsZero( pCurve->GOrd, peSigD ) ) )
355 {
356 break;
357 }
358
359 if (piK != NULL)
360 {
361 // piK resulted in 0 signature
362 scError = SYMCRYPT_INVALID_ARGUMENT;
363 goto cleanup;
364 }
365
366 signatureCount++;
367 if ( signatureCount >= SYMCRYPT_MAX_ECDSA_SIGNATURE_COUNT )
368 {
369 // We have not generated a non-zero signature after SYMCRYPT_MAX_ECDSA_SIGNATURE_COUNT attempts;
370 // Something is wrong with the group setup
371 scError = SYMCRYPT_INVALID_ARGUMENT;
372 goto cleanup;
373 }
374 }
375
376 // Output c
377 scError = SymCryptModElementGetValue( pCurve->GOrd, peSigC, pbSignature, cbSignature / 2, format, pbScratch, cbScratchInternal );
378 if ( scError != SYMCRYPT_NO_ERROR )
379 {
380 goto cleanup;
381 }
382
383 // Output d
384 scError = SymCryptModElementGetValue( pCurve->GOrd, peSigD, pbSignature + cbSignature / 2, cbSignature / 2, format, pbScratch, cbScratchInternal );
385 if ( scError != SYMCRYPT_NO_ERROR )
386 {
387 goto cleanup;
388 }
389
390cleanup:
391 if ( pbScratch != NULL )
392 {
393 SymCryptWipe( pbScratch, cbScratch );
394 SymCryptCallbackFree( pbScratch );
395 }
396
397 if (scError != SYMCRYPT_NO_ERROR)
398 {
399 SymCryptWipe( pbSignature, cbSignature );
400 }
401
402 return scError;
403}
#define TRUE
Definition: types.h:120
#define SYMCRYPT_MAX_ECDSA_SIGNATURE_COUNT
Definition: ec_dsa.c:142
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcDsaTruncateHash(_In_ PCSYMCRYPT_ECURVE pCurve, _In_reads_bytes_(cbHashValue) PCBYTE pbHashValue, SIZE_T cbHashValue, UINT32 flags, _Out_ PSYMCRYPT_MODELEMENT peMsghash, _Out_ PSYMCRYPT_INT piTmp, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: ec_dsa.c:84
GLsizei GLenum const GLvoid GLsizei GLenum GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLint GLint GLint GLshort GLshort GLshort GLubyte GLubyte GLubyte GLuint GLuint GLuint GLushort GLushort GLushort GLbyte GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLfloat GLint GLint GLint GLint GLshort GLshort GLshort GLshort GLubyte GLubyte GLubyte GLubyte GLuint GLuint GLuint GLuint GLushort GLushort GLushort GLushort GLboolean const GLdouble const GLfloat const GLint const GLshort const GLbyte const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLdouble const GLfloat const GLfloat const GLint const GLint const GLshort const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort GLenum GLenum GLenum GLfloat GLenum GLint GLenum GLenum GLenum GLfloat GLenum GLenum GLint GLenum GLfloat GLenum GLint GLint GLushort GLenum GLenum GLfloat GLenum GLenum GLint GLfloat const GLubyte GLenum GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLint GLint GLsizei GLsizei GLint GLenum GLenum const GLvoid GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLenum const GLdouble GLenum GLenum const GLfloat GLenum GLenum const GLint GLsizei GLuint GLfloat GLuint GLbitfield GLfloat GLint GLuint GLboolean GLenum GLfloat GLenum GLbitfield GLenum GLfloat GLfloat GLint GLint const GLfloat GLenum GLfloat GLfloat GLint GLint GLfloat GLfloat GLint GLint const GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat const GLdouble const GLfloat const GLdouble const GLfloat GLint i
Definition: glfuncs.h:248
#define SYMCRYPT_FLAG_ECKEY_ECDSA
Definition: symcrypt.h:7595
#define SYMCRYPT_FLAG_ECDSA_NO_TRUNCATION
Definition: symcrypt.h:8327
UINT32 SYMCRYPT_CALL SymCryptEcurveSizeofFieldElement(_In_ PCSYMCRYPT_ECURVE pCurve)
Definition: ecurve.c:689
PCSYMCRYPT_HMAC_MD5_EXPANDED_KEY pKey
VOID SYMCRYPT_CALL SymCryptEcpointSetRandom(_In_ PCSYMCRYPT_ECURVE pCurve, _Out_ PSYMCRYPT_INT piScalar, _Out_ PSYMCRYPT_ECPOINT poDst, _Out_writes_bytes_opt_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: ec_dispatch.c:147
VOID SYMCRYPT_CALL SymCryptIntCopy(_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:161
UINT32 SYMCRYPT_CALL SymCryptModElementIsZero(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc)
Definition: a_dispatch.c:828
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModInv(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_MODELEMENT peDst, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:948
PSYMCRYPT_ECPOINT SYMCRYPT_CALL SymCryptEcpointCreate(_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, _In_ PCSYMCRYPT_ECURVE pCurve)
Definition: ecpoint.c:142
UINT32 SYMCRYPT_CALL SymCryptSizeofEcpointFromCurve(PCSYMCRYPT_ECURVE pCurve)
Definition: ecpoint.c:41
#define SYMCRYPT_SCRATCH_BYTES_FOR_MODINV(_nDigits)

Referenced by SymCryptEcDsaSign().

◆ SymCryptEcpointAdd()

VOID SYMCRYPT_CALL SymCryptEcpointAdd ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_In_ PCSYMCRYPT_ECPOINT  poSrc1,
_In_ PCSYMCRYPT_ECPOINT  poSrc2,
_Out_ PSYMCRYPT_ECPOINT  poDst,
UINT32  flags,
_Out_writes_bytes_opt_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

◆ SymCryptEcpointAddDiffNonZero()

VOID SYMCRYPT_CALL SymCryptEcpointAddDiffNonZero ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_In_ PCSYMCRYPT_ECPOINT  poSrc1,
_In_ PCSYMCRYPT_ECPOINT  poSrc2,
_Out_ PSYMCRYPT_ECPOINT  poDst,
_Out_writes_bytes_opt_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 218 of file ec_dispatch.c.

226{
227 SYMCRYPT_ECURVE_CALL( pCurve ) addDiffFunc( pCurve, poSrc1, poSrc2, poDst, pbScratch, cbScratch );
228}

Referenced by SymCryptEcpointScalarMulFixedWindow(), and SymCryptPrecomputation().

◆ SymCryptEcpointAllocate()

PSYMCRYPT_ECPOINT SYMCRYPT_CALL SymCryptEcpointAllocate ( _In_ PCSYMCRYPT_ECURVE  pCurve)

Definition at line 49 of file ecpoint.c.

50{
51 PVOID p = NULL;
52 SIZE_T cb;
54
56
57 if ( cb != 0 )
58 {
60 }
61
62 if ( p==NULL )
63 {
64 goto cleanup;
65 }
66
68
70 return res;
71}
static MonoProfilerRuntimeShutdownBeginCallback cb
Definition: metahost.c:118
PSYMCRYPT_ECPOINT SYMCRYPT_CALL SymCryptEcpointCreate(_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, _In_ PCSYMCRYPT_ECURVE pCurve)
Definition: ecpoint.c:142
UINT32 SYMCRYPT_CALL SymCryptSizeofEcpointFromCurve(PCSYMCRYPT_ECURVE pCurve)
Definition: ecpoint.c:41
GLuint res
Definition: glext.h:9613
GLfloat GLfloat p
Definition: glext.h:8902

Referenced by SymCrypt802_11SaeCustomCommitCreateGeneric(), SymCrypt802_11SaeCustomCommitProcessGeneric(), SymCrypt802_11SaeCustomCreatePTGeneric(), SymCrypt802_11SaeCustomInit(), and SymCrypt802_11SaeCustomInitH2EGeneric().

◆ SymCryptEcpointCopy()

VOID SymCryptEcpointCopy ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_In_ PCSYMCRYPT_ECPOINT  poSrc,
_Out_ PSYMCRYPT_ECPOINT  poDst 
)

Definition at line 173 of file ecpoint.c.

177{
178 SYMCRYPT_ASSERT( SymCryptEcurveIsSame(pCurve, poSrc->pCurve) && SymCryptEcurveIsSame(pCurve, poDst->pCurve) );
179
180 if( poSrc != poDst )
181 {
182 // Unconditionally set the normalization state of destination to source
183 poDst->normalized = poSrc->normalized;
184
185 memcpy(poDst + 1, poSrc + 1, SYMCRYPT_INTERNAL_NUMOF_COORDINATES(pCurve->eCoordinates) * pCurve->FModDigits * SYMCRYPT_FDEF_DIGIT_SIZE);
186 }
187}
BOOLEAN SYMCRYPT_CALL SymCryptEcurveIsSame(_In_ PCSYMCRYPT_ECURVE pCurve1, _In_ PCSYMCRYPT_ECURVE pCurve2)
Definition: ecurve.c:745
#define SYMCRYPT_INTERNAL_NUMOF_COORDINATES(_eCoordinates)
#define SYMCRYPT_FDEF_DIGIT_SIZE

Referenced by SymCryptEckeyCopy(), SymCryptEcpointMultiScalarMulWnafWithInterleaving(), SymCryptEcpointScalarMulFixedWindow(), SymCryptEcpointTransform(), SymCryptMontgomerySetDistinguished(), SymCryptShortWeierstrassAdd(), SymCryptShortWeierstrassAddSideChannelUnsafe(), SymCryptShortWeierstrassSetDistinguished(), and SymCryptTwistedEdwardsSetDistinguished().

◆ SymCryptEcpointCreate()

PSYMCRYPT_ECPOINT SYMCRYPT_CALL SymCryptEcpointCreate ( _Out_writes_bytes_(cbBuffer) PBYTE  pbBuffer,
SIZE_T  cbBuffer,
_In_ PCSYMCRYPT_ECURVE  pCurve 
)

Definition at line 142 of file ecpoint.c.

146{
147
148 SYMCRYPT_ASSERT( pCurve->eCoordinates != 0 );
149
151}
PSYMCRYPT_ECPOINT SYMCRYPT_CALL SymCryptEcpointCreateEx(_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, PCSYMCRYPT_ECURVE pCurve, UINT32 numOfCoordinates)
Definition: ecpoint.c:86

Referenced by SymCryptEcDhSecretAgreement(), SymCryptEcDsaSignEx(), SymCryptEcDsaVerify(), SymCryptEckeyCreate(), SymCryptEckeyPerformPublicKeyValidation(), SymCryptEckeySetRandom(), SymCryptEckeySetValue(), SymCryptEcpointAllocate(), SymCryptEcpointMultiScalarMulWnafWithInterleaving(), SymCryptEcpointScalarMulFixedWindow(), SymCryptEcurveInitialize(), SymCryptOfflinePrecomputation(), and SymCryptShortWeierstrassAdd().

◆ SymCryptEcpointDouble()

VOID SYMCRYPT_CALL SymCryptEcpointDouble ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_In_ PCSYMCRYPT_ECPOINT  poSrc,
_Out_ PSYMCRYPT_ECPOINT  poDst,
UINT32  flags,
_Out_writes_bytes_opt_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

◆ SymCryptEcpointFree()

VOID SYMCRYPT_CALL SymCryptEcpointFree ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_Out_ PSYMCRYPT_ECPOINT  poDst 
)

Definition at line 75 of file ecpoint.c.

78{
79 SYMCRYPT_CHECK_MAGIC( poDst );
81 SymCryptCallbackFree( poDst );
82}
VOID SYMCRYPT_CALL SymCryptEcpointWipe(_In_ PCSYMCRYPT_ECURVE pCurve, _Out_ PSYMCRYPT_ECPOINT poDst)
Definition: ecpoint.c:164

Referenced by SymCrypt802_11SaeCustomCommitCreateGeneric(), SymCrypt802_11SaeCustomCommitProcessGeneric(), SymCrypt802_11SaeCustomCreatePTGeneric(), SymCrypt802_11SaeCustomDestroy(), SymCrypt802_11SaeCustomInit(), and SymCrypt802_11SaeCustomInitH2EGeneric().

◆ SymCryptEcpointGetValue()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointGetValue ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_In_ PCSYMCRYPT_ECPOINT  poSrc,
SYMCRYPT_NUMBER_FORMAT  nformat,
SYMCRYPT_ECPOINT_FORMAT  eformat,
_Out_writes_bytes_(cbDst) PBYTE  pbDst,
SIZE_T  cbDst,
UINT32  flags,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 705 of file ecpoint.c.

715{
716 SYMCRYPT_ERROR scError = SYMCRYPT_NOT_IMPLEMENTED;
717 PSYMCRYPT_MODELEMENT peTmp = NULL; // Temporary MODELEMENT handle
718 PSYMCRYPT_ECPOINT poLarge = NULL; // ECPOINT with the largest format available
719 UINT32 cbLarge = 0;
720 SIZE_T cbDstElem;
721
723 SYMCRYPT_ASSERT( pCurve->FMod != 0 );
724 SYMCRYPT_ASSERT( pCurve->eCoordinates != 0 );
725 SYMCRYPT_ASSERT( pCurve->cbModElement != 0 );
726
728
729 // Check that the buffer is of correct size
731 {
732 scError = SYMCRYPT_BUFFER_TOO_SMALL;
733 goto cleanup;
734 }
736 cbDstElem = cbDst / SymCryptEcpointFormatNumberofElements[ eformat ];
737
738 // Create the big point
740 SYMCRYPT_ASSERT( cbScratch > cbLarge );
741 poLarge = SymCryptEcpointCreateEx( pbScratch, cbLarge, pCurve, SYMCRYPT_ECPOINT_FORMAT_MAX_LENGTH );
742 if ( poLarge == NULL )
743 {
744 scError = SYMCRYPT_INVALID_BLOB;
745 goto cleanup;
746 }
747
748 // Transform the source point into the big point if needed
749 scError = SymCryptEcpointTransform( pCurve, poSrc, poLarge, eformat, FALSE, flags, pbScratch + cbLarge, cbScratch - cbLarge);
750 if (scError != SYMCRYPT_NO_ERROR)
751 {
752 goto cleanup;
753 }
754
755 // Getting the point coordinates into the destination buffer
757 {
758 SYMCRYPT_ASSERT( cbDst >= cbDstElem );
760 if ( peTmp == NULL )
761 {
762 scError = SYMCRYPT_INVALID_BLOB;
763 goto cleanup;
764 }
765
767 pCurve->FMod,
768 peTmp,
769 pbDst,
770 cbDstElem,
771 nformat,
772 pbScratch + cbLarge,
773 cbScratch - cbLarge );
774 if ( scError != SYMCRYPT_NO_ERROR )
775 {
776 goto cleanup;
777 }
778 pbDst += cbDstElem;
779 cbDst -= cbDstElem;
780 }
781
782cleanup:
783
784 return scError;
785}
#define FALSE
Definition: types.h:117
UINT32 SYMCRYPT_CALL SymCryptSizeofEcpointEx(UINT32 cbModElement, UINT32 numOfCoordinates)
Definition: ecpoint.c:19
const UINT32 SymCryptEcpointFormatNumberofElements[]
Definition: ecpoint.c:11
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointTransform(_In_ PCSYMCRYPT_ECURVE pCurve, _In_ PCSYMCRYPT_ECPOINT poSrc, _Out_ PSYMCRYPT_ECPOINT poDst, SYMCRYPT_ECPOINT_FORMAT eformat, BOOLEAN setValue, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: ecpoint.c:221
PCBYTE PBYTE pbDst
#define SYMCRYPT_ECPOINT_FORMAT_MAX_LENGTH
#define SYMCRYPT_INTERNAL_ECPOINT_COORDINATE_OFFSET(_pCurve, _ord)

Referenced by SymCrypt802_11SaeCustomCommitCreateGeneric(), SymCrypt802_11SaeCustomCommitProcessGeneric(), SymCrypt802_11SaeCustomCreatePTGeneric(), SymCryptEcDhSecretAgreement(), SymCryptEcDsaSignEx(), SymCryptEcDsaVerify(), and SymCryptEckeyGetValue().

◆ SymCryptEcpointIsEqual()

UINT32 SYMCRYPT_CALL SymCryptEcpointIsEqual ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_In_ PCSYMCRYPT_ECPOINT  poSrc1,
_In_ PCSYMCRYPT_ECPOINT  poSrc2,
UINT32  flags,
_Out_writes_bytes_opt_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 161 of file ec_dispatch.c.

169{
170 return SYMCRYPT_ECURVE_CALL( pCurve ) isEqualFunc( pCurve, poSrc1, poSrc2, flags, pbScratch, cbScratch );
171}

Referenced by SymCryptEckeySetRandom(), and SymCryptEckeySetValue().

◆ SymCryptEcpointIsZero()

◆ SymCryptEcpointMaskedCopy()

VOID SymCryptEcpointMaskedCopy ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_In_ PCSYMCRYPT_ECPOINT  poSrc,
_Out_ PSYMCRYPT_ECPOINT  poDst,
UINT32  mask 
)

Definition at line 190 of file ecpoint.c.

195{
196 SYMCRYPT_ASSERT( (mask == 0) || (mask == 0xffffffff) );
197 SYMCRYPT_ASSERT( SymCryptEcurveIsSame(pCurve, poSrc->pCurve) && SymCryptEcurveIsSame(pCurve, poDst->pCurve) );
198
199 // Unconditionally combine the normalization state of source and destination to avoid potential for
200 // leak of mask. Normalized is a non-secret value and is permitted to be leaked by side-channels
201 poDst->normalized &= poSrc->normalized;
202
203 // dcl - this looks like the equivalent of memcpy
204 // should be proven that arguments cannot be the result of an integer overflow
205 SymCryptFdefMaskedCopy((PCBYTE)poSrc + sizeof(SYMCRYPT_ECPOINT), (PBYTE)poDst + sizeof(SYMCRYPT_ECPOINT), SYMCRYPT_INTERNAL_NUMOF_COORDINATES(pCurve->eCoordinates) * pCurve->FModDigits, mask );
206}
VOID SYMCRYPT_CALL SymCryptFdefMaskedCopy(_In_reads_bytes_(nDigits *SYMCRYPT_FDEF_DIGIT_SIZE) PCBYTE pbSrc, _Inout_updates_bytes_(nDigits *SYMCRYPT_FDEF_DIGIT_SIZE) PBYTE pbDst, UINT32 nDigits, UINT32 mask)
Definition: fdef_general.c:74
GLenum GLint GLuint mask
Definition: glext.h:6028
struct _SYMCRYPT_ECPOINT SYMCRYPT_ECPOINT

Referenced by SymCrypt802_11SaeCustomInit(), SymCryptEcpointScalarMulFixedWindow(), and SymCryptShortWeierstrassAdd().

◆ SymCryptEcpointMultiScalarMul()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointMultiScalarMul ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_In_ PCSYMCRYPT_INT *  piSrcScalarArray,
_In_ PCSYMCRYPT_ECPOINT *  poSrcEcpointArray,
UINT32  nPoints,
UINT32  flags,
_Out_ PSYMCRYPT_ECPOINT  poDst,
_Out_writes_bytes_opt_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 279 of file ec_dispatch.c.

289{
290 return SYMCRYPT_ECURVE_CALL( pCurve ) multiScalarMulFunc( pCurve, piSrcScalarArray, poSrcEcpointArray, nPoints, flags, poDst, pbScratch, cbScratch );
291}

Referenced by SymCryptEcDsaVerify().

◆ SymCryptEcpointNegate()

VOID SYMCRYPT_CALL SymCryptEcpointNegate ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_Inout_ PSYMCRYPT_ECPOINT  poSrc,
UINT32  mask,
_Out_writes_bytes_opt_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

◆ SymCryptEcpointOnCurve()

UINT32 SYMCRYPT_CALL SymCryptEcpointOnCurve ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_In_ PCSYMCRYPT_ECPOINT  poSrc,
_Out_writes_bytes_opt_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 189 of file ec_dispatch.c.

195{
196 return SYMCRYPT_ECURVE_CALL( pCurve ) onCurveFunc( pCurve, poSrc, pbScratch, cbScratch );
197}

Referenced by SymCrypt802_11SaeCustomCommitProcessGeneric(), and SymCryptEckeyPerformPublicKeyValidation().

◆ SymCryptEcpointRetrieveHandle()

PSYMCRYPT_ECPOINT SYMCRYPT_CALL SymCryptEcpointRetrieveHandle ( _In_ PBYTE  pbBuffer)

Definition at line 155 of file ecpoint.c.

156{
158
159 return (PSYMCRYPT_ECPOINT) pbBuffer;
160}
#define SYMCRYPT_ASSERT_ASYM_ALIGNED(_p)
Definition: sc_lib.h:1912

◆ SymCryptEcpointScalarMul()

◆ SymCryptEcpointSetDistinguishedPoint()

VOID SYMCRYPT_CALL SymCryptEcpointSetDistinguishedPoint ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_Out_ PSYMCRYPT_ECPOINT  poDst,
_Out_writes_bytes_opt_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 134 of file ec_dispatch.c.

140{
141 SYMCRYPT_ECURVE_CALL( pCurve ) setDistinguishedFunc( pCurve, poDst, pbScratch, cbScratch );
142}

◆ SymCryptEcpointSetRandom()

VOID SYMCRYPT_CALL SymCryptEcpointSetRandom ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_Out_ PSYMCRYPT_INT  piScalar,
_Out_ PSYMCRYPT_ECPOINT  poDst,
_Out_writes_bytes_opt_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 147 of file ec_dispatch.c.

154{
155 SYMCRYPT_ECURVE_CALL( pCurve ) setRandomFunc( pCurve, piScalar, poDst, pbScratch, cbScratch );
156}

Referenced by SymCryptEcDsaSignEx().

◆ SymCryptEcpointSetValue()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptEcpointSetValue ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_In_reads_bytes_(cbSrc) PCBYTE  pbSrc,
SIZE_T  cbSrc,
SYMCRYPT_NUMBER_FORMAT  nformat,
SYMCRYPT_ECPOINT_FORMAT  eformat,
_Out_ PSYMCRYPT_ECPOINT  poDst,
UINT32  flags,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 605 of file ecpoint.c.

615{
616 SYMCRYPT_ERROR scError = SYMCRYPT_NOT_IMPLEMENTED;
617 PSYMCRYPT_MODELEMENT peTmp = NULL; // Temporary MODELEMENT handle
618 PSYMCRYPT_ECPOINT poLarge = NULL; // ECPOINT with the largest format available
619 UINT32 cbLarge = 0;
620 PSYMCRYPT_INT piTemp = NULL;
621 UINT32 cbTemp = 0;
623
625
626 SYMCRYPT_ASSERT( pCurve->FMod != 0 );
627 SYMCRYPT_ASSERT( pCurve->eCoordinates != 0 );
628 SYMCRYPT_ASSERT( pCurve->cbModElement != 0 );
629
631
632 // Check that the buffer is of correct size
634 {
635 scError = SYMCRYPT_BUFFER_TOO_SMALL;
636 goto cleanup;
637 }
638 cbSrc = cbSrc / SymCryptEcpointFormatNumberofElements[ eformat ];
639
640 cbTemp = SymCryptSizeofIntFromDigits( publicKeyDigits );
641 SYMCRYPT_ASSERT( cbScratch > cbTemp );
642
643 piTemp = SymCryptIntCreate( pbScratch, cbTemp, publicKeyDigits );
644
645 // Validate the coordinate of the input public key is less than the field modulus
646 for ( UINT32 i = 0; i < SymCryptEcpointFormatNumberofElements[eformat]; i++ )
647 {
648 scError = SymCryptIntSetValue( pbSrc + i * cbSrc, cbSrc, nformat, piTemp );
649 if (scError != SYMCRYPT_NO_ERROR)
650 {
651 goto cleanup;
652 }
653
654 if ( !SymCryptIntIsLessThan( piTemp, SymCryptIntFromModulus( pCurve->FMod ) ) )
655 {
656 scError = SYMCRYPT_INVALID_ARGUMENT;
657 goto cleanup;
658 }
659 }
660
661 // Create the large point
663 SYMCRYPT_ASSERT( cbScratch > cbLarge );
664 poLarge = SymCryptEcpointCreateEx( pbScratch, cbLarge, pCurve, SYMCRYPT_ECPOINT_FORMAT_MAX_LENGTH );
665 if ( poLarge == NULL )
666 {
667 scError = SYMCRYPT_INVALID_BLOB;
668 goto cleanup;
669 }
670
671 // Setting the point coordinates into the big point
673 {
675 if ( peTmp == NULL )
676 {
677 scError = SYMCRYPT_INVALID_BLOB;
678 goto cleanup;
679 }
680
682 pbSrc,
683 cbSrc,
684 nformat,
685 pCurve->FMod,
686 peTmp,
687 pbScratch + cbLarge,
688 cbScratch - cbLarge );
689 if ( scError != SYMCRYPT_NO_ERROR )
690 {
691 goto cleanup;
692 }
693 pbSrc += cbSrc;
694 }
695
696 // Transform the big point into the destination point
697 scError = SymCryptEcpointTransform( pCurve, poLarge, poDst, eformat, TRUE, flags, pbScratch + cbLarge, cbScratch - cbLarge);
698
699cleanup:
700 return scError;
701}
PCBYTE pbSrc

Referenced by SymCrypt802_11SaeCustomCommitProcessGeneric(), SymCrypt802_11SaeCustomInit(), SymCrypt802_11SaeCustomInitH2EGeneric(), SymCryptEckeySetValue(), SymCryptEcurveInitialize(), and SymCryptSswu().

◆ SymCryptEcpointSetZero()

VOID SYMCRYPT_CALL SymCryptEcpointSetZero ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_Out_ PSYMCRYPT_ECPOINT  poDst,
_Out_writes_bytes_opt_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 121 of file ec_dispatch.c.

127{
128 SYMCRYPT_ECURVE_CALL( pCurve ) setZeroFunc( pCurve, poDst, pbScratch, cbScratch );
129}

Referenced by SymCryptEcpointMultiScalarMulWnafWithInterleaving(), and SymCryptEcpointScalarMulFixedWindow().

◆ SymCryptEcpointWipe()

VOID SYMCRYPT_CALL SymCryptEcpointWipe ( _In_ PCSYMCRYPT_ECURVE  pCurve,
_Out_ PSYMCRYPT_ECPOINT  poDst 
)

Definition at line 164 of file ecpoint.c.

165{
167
168 // Wipe the whole structure in one go.
170}

Referenced by SymCryptEcpointFree().

◆ SymCryptEcurveBufferSizesFromParams()

BOOLEAN SYMCRYPT_CALL SymCryptEcurveBufferSizesFromParams ( _In_ PCSYMCRYPT_ECURVE_PARAMS  pParams,
_Out_ SIZE_T *  pcbCurve,
_Out_ SIZE_T *  pcbScratch 
)

Definition at line 160 of file ecurve.c.

164{
165 BOOLEAN fSuccess = FALSE;
167
168 if ( !SymCryptEcurveValidateAndComputeSizes( pParams, &sizes ))
169 {
170 goto cleanup;
171 }
172
173 *pcbCurve = sizes.cbAlloc;
174 *pcbScratch = sizes.cbScratch;
175
176 fSuccess = TRUE;
177
178cleanup:
179 return fSuccess;
180}
unsigned char BOOLEAN
Definition: actypes.h:127
static BOOLEAN SymCryptEcurveValidateAndComputeSizes(_In_ PCSYMCRYPT_ECURVE_PARAMS pParams, _Out_ PSYMCRYPT_ECURVE_SIZES pSizes)
Definition: ecurve.c:44

◆ SymCryptEcurveCreate()

PSYMCRYPT_ECURVE SYMCRYPT_CALL SymCryptEcurveCreate ( _In_ PSYMCRYPT_ECURVE_PARAMS  pParams,
_In_ UINT32  flags,
_Out_writes_bytes_(cbCurve) PBYTE  pbCurve,
SIZE_T  cbCurve,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 571 of file ecurve.c.

578{
580
582
583 if ( !SymCryptEcurveValidateAndComputeSizes(pParams, &sizes) )
584 {
585 goto cleanup;
586 }
587
588 if ( cbCurve < sizes.cbAlloc )
589 {
590 goto cleanup;
591 }
592
593 if ( cbScratch < sizes.cbScratch )
594 {
595 goto cleanup;
596 }
597
598 pCurve = SymCryptEcurveInitialize( pParams, flags, &sizes, pbCurve, pbScratch );
599
600cleanup:
601 return pCurve;
602}
static PSYMCRYPT_ECURVE SymCryptEcurveInitialize(_In_ PCSYMCRYPT_ECURVE_PARAMS pParams, _In_ UINT32 flags, _In_ PCSYMCRYPT_ECURVE_SIZES pSizes, _Out_writes_bytes_(pSizes->cbAlloc) PBYTE pbCurve, _Out_writes_bytes_(pSizes->cbScratch) PBYTE pbScratch)
Definition: ecurve.c:187

◆ SymCryptEcurveDigitsofFieldElement()

UINT32 SYMCRYPT_CALL SymCryptEcurveDigitsofFieldElement ( _In_ PCSYMCRYPT_ECURVE  pCurve)

Definition at line 682 of file ecurve.c.

683{
684 return pCurve->FModDigits;
685}

Referenced by SymCrypt802_11SaeCustomCreatePTGeneric(), and SymCryptEcpointSetValue().

◆ SymCryptEcurveDigitsofScalarMultiplier()

◆ SymCryptEcurveGroupOrder()

PCSYMCRYPT_MODULUS SYMCRYPT_CALL SymCryptEcurveGroupOrder ( _In_ PCSYMCRYPT_ECURVE  pCurve)

Definition at line 703 of file ecurve.c.

704{
705 return pCurve->GOrd;
706}

◆ SymCryptFreeTrialDivisionContext()

VOID SYMCRYPT_CALL SymCryptFreeTrialDivisionContext ( PCSYMCRYPT_TRIALDIVISION_CONTEXT  pContext)

Definition at line 1025 of file a_dispatch.c.

1026{
1028}
VOID SYMCRYPT_CALL SymCryptFdefFreeTrialDivisionContext(PCSYMCRYPT_TRIALDIVISION_CONTEXT pContext)

Referenced by SymCryptDlgroupGenerate(), SymCryptDlgroupSetValue(), and SymCryptIntGenerateRandomPrime().

◆ SymCryptIntAddMixedSize()

UINT32 SYMCRYPT_CALL SymCryptIntAddMixedSize ( _In_ PCSYMCRYPT_INT  piSrc1,
_In_ PCSYMCRYPT_INT  piSrc2,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 304 of file a_dispatch.c.

308{
309 return SymCryptFdefIntAddMixedSize( piSrc1, piSrc2, piDst );
310}
UINT32 SYMCRYPT_CALL SymCryptFdefIntAddMixedSize(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_int.c:113

Referenced by SymCryptCrtSolve(), and SymCryptIntExtendedGcd().

◆ SymCryptIntAddSameSize()

UINT32 SYMCRYPT_CALL SymCryptIntAddSameSize ( _In_ PCSYMCRYPT_INT  piSrc1,
_In_ PCSYMCRYPT_INT  piSrc2,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 294 of file a_dispatch.c.

298{
299 return SymCryptFdefIntAddSameSize( piSrc1, piSrc2, piDst );
300}
UINT32 SYMCRYPT_CALL SymCryptFdefIntAddSameSize(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_int.c:98

◆ SymCryptIntAddUint32()

UINT32 SYMCRYPT_CALL SymCryptIntAddUint32 ( _In_ PCSYMCRYPT_INT  piSrc1,
UINT32  u32Src2,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 284 of file a_dispatch.c.

288{
289 return SymCryptFdefIntAddUint32( piSrc1, u32Src2, piDst );
290}
UINT32 SYMCRYPT_CALL SymCryptFdefIntAddUint32(_In_ PCSYMCRYPT_INT piSrc1, UINT32 u32Src2, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_int.c:83

Referenced by SymCryptDlgroupGeneratePrimeP_FIPS(), SymCryptDlgroupGeneratePrimeQ_FIPS(), SymCryptFixedWindowRecoding(), SymCryptModSqrt(), and SymCryptWidthNafRecoding().

◆ SymCryptIntAllocate()

◆ SymCryptIntBitsizeOfObject()

UINT32 SYMCRYPT_CALL SymCryptIntBitsizeOfObject ( _In_ PCSYMCRYPT_INT  piSrc)

Definition at line 200 of file a_dispatch.c.

201{
202 return SymCryptFdefIntBitsizeOfObject( piSrc );
203}
UINT32 SYMCRYPT_CALL SymCryptFdefIntBitsizeOfObject(_In_ PCSYMCRYPT_INT piSrc)
Definition: fdef_general.c:328

Referenced by SymCryptIntExtendedGcd(), SymCryptIntGenerateRandomPrime(), SymCryptModExpWindowed(), and SymCryptPositiveWidthNafRecoding().

◆ SymCryptIntBitsizeOfValue()

◆ SymCryptIntConditionalCopy()

VOID SYMCRYPT_CALL SymCryptIntConditionalCopy ( _In_ PCSYMCRYPT_INT  piSrc,
_Inout_ PSYMCRYPT_INT  piDst,
UINT32  cond 
)

Definition at line 180 of file a_dispatch.c.

184{
185 SymCryptFdefIntConditionalCopy( piSrc, piDst, cond );
186}
VOID SYMCRYPT_CALL SymCryptFdefIntConditionalCopy(_In_ PCSYMCRYPT_INT piSrc, _Inout_ PSYMCRYPT_INT piDst, UINT32 cond)
Definition: fdef_general.c:298

Referenced by SymCryptIntExtendedGcd().

◆ SymCryptIntConditionalSwap()

VOID SYMCRYPT_CALL SymCryptIntConditionalSwap ( _Inout_ PSYMCRYPT_INT  piSrc1,
_Inout_ PSYMCRYPT_INT  piSrc2,
UINT32  cond 
)

Definition at line 190 of file a_dispatch.c.

194{
195 SymCryptFdefIntConditionalSwap( piSrc1, piSrc2, cond );
196}
VOID SYMCRYPT_CALL SymCryptFdefIntConditionalSwap(_Inout_ PSYMCRYPT_INT piSrc1, _Inout_ PSYMCRYPT_INT piSrc2, UINT32 cond)
Definition: fdef_general.c:313

Referenced by SymCryptIntExtendedGcd().

◆ SymCryptIntCopy()

◆ SymCryptIntCopyMixedSize()

◆ SymCryptIntCreate()

PSYMCRYPT_INT SYMCRYPT_CALL SymCryptIntCreate ( _Out_writes_bytes_(cbBuffer) PBYTE  pbBuffer,
SIZE_T  cbBuffer,
UINT32  nDigits 
)

◆ SymCryptIntDigitsizeOfObject()

UINT32 SYMCRYPT_CALL SymCryptIntDigitsizeOfObject ( _In_ PCSYMCRYPT_INT  piSrc)

Definition at line 207 of file a_dispatch.c.

208{
209 return piSrc->nDigits;
210}

Referenced by SymCryptDsaSignEx(), SymCryptIntExtendedGcd(), SymCryptIntGenerateRandomPrime(), and SymCryptIntMillerRabinPrimalityTest().

◆ SymCryptIntDivMod()

VOID SYMCRYPT_CALL SymCryptIntDivMod ( _In_ PCSYMCRYPT_INT  piSrc,
_In_ PCSYMCRYPT_DIVISOR  pdDivisor,
_Out_opt_ PSYMCRYPT_INT  piQuotient,
_Out_opt_ PSYMCRYPT_INT  piRemainder,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 573 of file a_dispatch.c.

580{
581 SymCryptFdefIntDivMod( piSrc, pdDivisor, piQuotient, piRemainder, pbScratch, cbScratch );
582}
VOID SYMCRYPT_CALL SymCryptFdefIntDivMod(_In_ PCSYMCRYPT_INT piSrc, _In_ PCSYMCRYPT_DIVISOR pdDivisor, _Out_opt_ PSYMCRYPT_INT piQuotient, _Out_opt_ PSYMCRYPT_INT piRemainder, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_int.c:1219

Referenced by rsa_decrypt(), SymCryptDlgroupGenerateGenG_FIPS(), SymCryptDlgroupGeneratePrimeP_FIPS(), SymCryptDsaSignEx(), SymCryptDsaVerify(), SymCryptEckeyGetValue(), SymCryptEckeySetValue(), SymCryptIntExtendedGcd(), SymCryptIntGenerateRandomPrime(), SymCryptRsaCoreDecCrt(), SymCryptRsakeyCalculatePrimesFromPrivateExponent(), and SymCryptRsakeyCalculatePrivateFields().

◆ SymCryptIntDivPow2()

VOID SYMCRYPT_CALL SymCryptIntDivPow2 ( _In_ PCSYMCRYPT_INT  piSrc,
SIZE_T  exp,
_Out_ PSYMCRYPT_INT  piDst 
)

◆ SymCryptIntExtendedGcd()

VOID SYMCRYPT_CALL SymCryptIntExtendedGcd ( _In_ PCSYMCRYPT_INT  piSrc1,
_In_ PCSYMCRYPT_INT  piSrc2,
UINT32  flags,
_Out_opt_ PSYMCRYPT_INT  piGcd,
_Out_opt_ PSYMCRYPT_INT  piLcm,
_Out_opt_ PSYMCRYPT_INT  piInvSrc1ModSrc2,
_Out_opt_ PSYMCRYPT_INT  piInvSrc2ModSrc1,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 176 of file gen_int.c.

186{
188 PSYMCRYPT_INT piA; // size nDigits
189 PSYMCRYPT_INT piB; // size nDigits, NOT ALLOCATED (part of the pdGcd divisor)
190 PSYMCRYPT_INT piTmp; // size nDigits
191 PSYMCRYPT_INT piA1; // size nDigits
192 PSYMCRYPT_INT piB1; // size nDigits
193 PSYMCRYPT_INT piTmpDbl; // size 2*nDigits
194 PSYMCRYPT_DIVISOR pdGcd; // size nDigits
195 PSYMCRYPT_DIVISOR pdTmp; // size nDigits
196 UINT32 cbInt;
197 UINT32 cbWideInt;
198 UINT32 cbDivisor;
199 SIZE_T cbFnScratch;
200 UINT32 t;
201 UINT32 c;
202 UINT32 d;
203
204 UNREFERENCED_PARAMETER( flags ); // Currently not used to improve performance.
205
206 // Compute how much scratch space we need for the functions we call
207 cbFnScratch = SYMCRYPT_SCRATCH_BYTES_FOR_INT_DIVMOD( 2 * nDigits, nDigits );
208 cbFnScratch = SYMCRYPT_MAX( cbFnScratch, SYMCRYPT_SCRATCH_BYTES_FOR_INT_MUL( 2*nDigits ) );
209 cbFnScratch = SYMCRYPT_MAX( cbFnScratch, SYMCRYPT_SCRATCH_BYTES_FOR_INT_TO_DIVISOR( nDigits ) );
210
211 cbInt = SymCryptSizeofIntFromDigits( nDigits );
212 cbWideInt = SymCryptSizeofIntFromDigits( 2*nDigits );
213 cbDivisor = SymCryptSizeofDivisorFromDigits( nDigits );
214
215 SYMCRYPT_ASSERT( cbWideInt != 0 );
216 SYMCRYPT_ASSERT( cbScratch >= 4 * cbInt +
217 1 * cbWideInt +
218 2 * cbDivisor +
219 cbFnScratch );
220
221 piA = SymCryptIntCreate( pbScratch, cbInt, nDigits );
222 pbScratch += cbInt; cbScratch -= cbInt;
223 // piB is stored inside the pdGcd object created later
224 piTmp = SymCryptIntCreate( pbScratch, cbInt, nDigits );
225 pbScratch += cbInt; cbScratch -= cbInt;
226 piA1 = SymCryptIntCreate( pbScratch, cbInt, nDigits );
227 pbScratch += cbInt; cbScratch -= cbInt;
228 piB1 = SymCryptIntCreate( pbScratch, cbInt, nDigits );
229 pbScratch += cbInt; cbScratch -= cbInt;
230
231 piTmpDbl = SymCryptIntCreate( pbScratch, cbWideInt, 2 * nDigits );
232 pbScratch += cbWideInt; cbScratch -= cbWideInt;
233
234 pdGcd = SymCryptDivisorCreate( pbScratch, cbDivisor, nDigits );
235 pbScratch += cbDivisor; cbScratch -= cbDivisor;
236 piB = SymCryptIntFromDivisor( pdGcd );
237
238 pdTmp = SymCryptDivisorCreate( pbScratch, cbDivisor, nDigits );
239 pbScratch += cbDivisor; cbScratch -= cbDivisor;
240
241 SymCryptIntCopyMixedSize( piSrc1, piA ); // Ignore the error return value here as we know
242 SymCryptIntCopyMixedSize( piSrc2, piB ); // that the destination integers are large enough.
243
244 SymCryptIntSetValueUint32( 1, piA1 );
245 SymCryptIntSetValueUint32( 0, piB1 );
246
247 // Currently not supported: Src1 to be 0 or Src2 to be even
249 SYMCRYPT_ASSERT( (SymCryptIntGetValueLsbits32( piB ) & 1) != 0 );
250 if ( SymCryptIntIsEqualUint32( piA, 0 ) ||
251 ((SymCryptIntGetValueLsbits32( piB ) & 1) == 0) )
252 {
253 goto cleanup;
254 }
255
256 // Currently not supported: piInvSrc2ModSrc1 != NULL and max( Src1.nDigits, Src2.nDigits ) * 2 > SymCryptDigitsFromBits(SYMCRYPT_INT_MAX_BITS)
257 if( (piInvSrc2ModSrc1 != NULL) && (piTmpDbl == NULL) )
258 {
259 goto cleanup;
260 }
261
262 t = SymCryptIntBitsizeOfObject( piSrc1 ) + SymCryptIntBitsizeOfObject( piSrc2 ) - 1;
263 while( t > 0 )
264 {
265 t--;
266
267 //if A odd and A < B:
268 // Swap (A, A1) with (B, B1)
269 c = 1 & (SymCryptIntGetValueLsbits32( piA ) & SymCryptIntSubSameSize( piA, piB, piTmp ) );
270 SymCryptIntConditionalSwap( piA, piB, c );
271 SymCryptIntConditionalSwap( piA1, piB1, c );
272
273 //if A odd:
274 // A -= B; A1 -= B1 (mod S2);
275 c = 1 & SymCryptIntGetValueLsbits32( piA );
276 SymCryptIntSubSameSize( piA, piB, piTmp ); // Never a carry due to the previous conditional swap
277 SymCryptIntConditionalCopy( piTmp, piA, c );
278
279 d = SymCryptIntSubSameSize( piA1, piB1, piTmp );
280 SymCryptIntConditionalCopy( piTmp, piA1, c );
281 SymCryptIntAddMixedSize( piA1, piSrc2, piTmp );
282 SymCryptIntConditionalCopy( piTmp, piA1, c & d );
283
284 // A /= 2; A1 /= 2 (mod S2);
285 SYMCRYPT_ASSERT( (SymCryptIntGetValueLsbits32( piA ) & 1) == 0 );
286 SymCryptIntShr1( 0, piA, piA );
287 c = SymCryptIntGetValueLsbits32( piA1 ) & 1;
288 d = SymCryptIntAddMixedSize( piA1, piSrc2, piTmp );
289 SymCryptIntConditionalCopy( piTmp, piA1, c );
290 SymCryptIntShr1( c & d, piA1, piA1 );
291
292 }
293
294 // B = GCD, B1 * S1 = GCD (mod S2)
295 // A = 0, A1 is scratch
296 //
297 // Algorithm from here:
298 // GCD as divisor
299 // LCM = S1 * S2 / GCD.
300 // P2 = S2 / GCD, as divisor (only for InvS1ModS2)
301 // InvS1ModS2 = B1 mod P2
302 // InvS2ModS1 = -((B1*S1 - GCD) div S2) mod S1
303
304 if( piGcd != NULL )
305 {
306 SymCryptIntCopyMixedSize( piB, piGcd );
307 }
308
309 if( piLcm == NULL && piInvSrc1ModSrc2 == NULL && piInvSrc2ModSrc1 == NULL )
310 {
311 // Only GCD needed; don't do the other work
312 goto cleanup;
313 }
314
315 SymCryptIntCopyMixedSize( piB, SymCryptIntFromDivisor( pdGcd ) ); // copy into INT of the right size
316
317 // IntToDivisor requirement:
318 // Gcd !=0
319 SymCryptIntToDivisor( SymCryptIntFromDivisor( pdGcd ), pdGcd, 3, 0, pbScratch, cbScratch );
320
321 if( piLcm != NULL )
322 {
323 // LCM = S1 * S2 / GCD
324 SymCryptIntMulMixedSize( piSrc1, piSrc2, piLcm, pbScratch, cbScratch );
325 SymCryptIntDivMod( piLcm, pdGcd, piLcm, NULL, pbScratch, cbScratch );
326 }
327
328 if( piInvSrc1ModSrc2 != NULL )
329 {
330 // Future optimization: if GCD == 1 then we can just copy B1.
331 SymCryptIntDivMod( piSrc2, pdGcd, SymCryptIntFromDivisor( pdTmp ), NULL, pbScratch, cbScratch );
332
333 // IntToDivisor requirement:
334 // Src2 / pdGcd > 0
335 SymCryptIntToDivisor( SymCryptIntFromDivisor( pdTmp ), pdTmp, 1, 0, pbScratch, cbScratch );
336 SymCryptIntDivMod( piB1, pdTmp, NULL, piInvSrc1ModSrc2, pbScratch, cbScratch );
337 }
338
339 if( piInvSrc2ModSrc1 != NULL )
340 {
341 // InvS2ModS1 = - ( (B1*S1 - GCD)/S2 ) mod S1
342
343 // S2 as divisor
345
346 // IntToDivisor requirement:
347 // Src2 is odd --> Src2 != 0
348 SymCryptIntToDivisor( SymCryptIntFromDivisor( pdTmp ), pdTmp, 1, 0, pbScratch, cbScratch );
349
350 SymCryptIntMulMixedSize( piB1, piSrc1, piTmpDbl, pbScratch, cbScratch );
351 SymCryptIntSubMixedSize( piTmpDbl, piB, piTmpDbl ); // Never a borrow if B1 >= 1
352 SymCryptIntDivMod( piTmpDbl, pdTmp, piTmpDbl, NULL, pbScratch, cbScratch );
353
354 // and reduce modulo S1
356
357 // IntToDivisor requirement:
358 // Src1 > 0
359 SymCryptIntToDivisor( SymCryptIntFromDivisor( pdTmp ), pdTmp, 1, 0, pbScratch, cbScratch );
360 SymCryptIntDivMod( piTmpDbl, pdTmp, NULL, piInvSrc2ModSrc1, pbScratch, cbScratch );
361
362 // Negative modulo S1
363 SymCryptIntSubMixedSize( SymCryptIntFromDivisor( pdTmp ), piInvSrc2ModSrc1, piInvSrc2ModSrc1 ); // Never a borrow as piInvSrc2ModSrc1 < S1
364 }
365
366cleanup:
367 return; // Need a statement after a label...
368}
GLdouble GLdouble t
Definition: gl.h:2047
const GLubyte * c
Definition: glext.h:8905
#define d
Definition: ke_i.h:81
#define c
Definition: ke_i.h:80
SYMCRYPT_DIVISOR * PSYMCRYPT_DIVISOR
UINT32 SYMCRYPT_CALL SymCryptSizeofDivisorFromDigits(UINT32 nDigits)
Definition: a_dispatch.c:512
UINT32 SYMCRYPT_CALL SymCryptIntBitsizeOfObject(_In_ PCSYMCRYPT_INT piSrc)
Definition: a_dispatch.c:200
VOID SYMCRYPT_CALL SymCryptIntShr1(UINT32 highestBit, _In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:374
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_DIVMOD(_nSrcDigits, _nDivisorDigits)
UINT32 SYMCRYPT_CALL SymCryptIntSubMixedSize(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:334
UINT32 SYMCRYPT_CALL SymCryptIntDigitsizeOfObject(_In_ PCSYMCRYPT_INT piSrc)
Definition: a_dispatch.c:207
VOID SYMCRYPT_CALL SymCryptIntConditionalCopy(_In_ PCSYMCRYPT_INT piSrc, _Inout_ PSYMCRYPT_INT piDst, UINT32 cond)
Definition: a_dispatch.c:180
VOID SYMCRYPT_CALL SymCryptIntConditionalSwap(_Inout_ PSYMCRYPT_INT piSrc1, _Inout_ PSYMCRYPT_INT piSrc2, UINT32 cond)
Definition: a_dispatch.c:190
VOID SYMCRYPT_CALL SymCryptIntToDivisor(_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_DIVISOR pdDst, UINT32 totalOperations, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:560
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_TO_DIVISOR(_nDigits)
PSYMCRYPT_INT SYMCRYPT_CALL SymCryptIntFromDivisor(_In_ PSYMCRYPT_DIVISOR pdSrc)
Definition: a_dispatch.c:553
PSYMCRYPT_DIVISOR SYMCRYPT_CALL SymCryptDivisorCreate(_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, UINT32 nDigits)
Definition: a_dispatch.c:519
VOID SYMCRYPT_CALL SymCryptIntSetValueUint32(UINT32 u32Src, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:230
UINT32 SYMCRYPT_CALL SymCryptIntSubSameSize(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:324
VOID SYMCRYPT_CALL SymCryptIntDivMod(_In_ PCSYMCRYPT_INT piSrc, _In_ PCSYMCRYPT_DIVISOR pdDivisor, _Out_opt_ PSYMCRYPT_INT piQuotient, _Out_opt_ PSYMCRYPT_INT piRemainder, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:573

Referenced by SymCryptCrtGenerateForTwoCoprimes(), SymCryptRsakeyCalculatePrimesFromPrivateExponent(), and SymCryptRsakeyCalculatePrivateFields().

◆ SymCryptIntFindSmallDivisor()

UINT32 SYMCRYPT_CALL SymCryptIntFindSmallDivisor ( _In_ PCSYMCRYPT_TRIALDIVISION_CONTEXT  pContext,
_In_ PCSYMCRYPT_INT  piSrc,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 1014 of file a_dispatch.c.

1019{
1020 return SymCryptFdefIntFindSmallDivisor( pContext, piSrc, pbScratch, cbScratch );
1021}
UINT32 SYMCRYPT_CALL SymCryptFdefIntFindSmallDivisor(_In_ PCSYMCRYPT_TRIALDIVISION_CONTEXT pContext, _In_ PCSYMCRYPT_INT piSrc, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)

Referenced by SymCryptDlgroupGeneratePrimeP_FIPS(), SymCryptDlgroupGeneratePrimeQ_FIPS(), and SymCryptIntGenerateRandomPrime().

◆ SymCryptIntFree()

◆ SymCryptIntFromDivisor()

PSYMCRYPT_INT SYMCRYPT_CALL SymCryptIntFromDivisor ( _In_ PSYMCRYPT_DIVISOR  pdSrc)

Definition at line 553 of file a_dispatch.c.

554{
555 return SymCryptFdefIntFromDivisor( pdSrc );
556}
PSYMCRYPT_INT SYMCRYPT_CALL SymCryptFdefIntFromDivisor(_In_ PSYMCRYPT_DIVISOR pdSrc)
Definition: fdef_int.c:915

Referenced by SymCryptDlgroupGeneratePrimeQ_FIPS(), SymCryptIntExtendedGcd(), SymCryptIntGenerateRandomPrime(), and SymCryptRsakeyCalculatePrivateFields().

◆ SymCryptIntFromModulus()

◆ SymCryptIntGenerateRandomPrime()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptIntGenerateRandomPrime ( _In_ PCSYMCRYPT_INT  piLow,
_In_ PCSYMCRYPT_INT  piHigh,
_In_reads_opt_(nPubExp) PCUINT64  pu64PubExp,
UINT32  nPubExp,
UINT32  nTries,
UINT32  flags,
_Inout_ PSYMCRYPT_INT  piDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 170 of file primes.c.

180{
181 SYMCRYPT_ERROR scError = SYMCRYPT_EXTERNAL_FAILURE;
183 PSYMCRYPT_INT piTmp;
184
185 UINT32 cnt = 0;
186 UINT32 e;
187 BOOLEAN reject;
188 SIZE_T cbObj;
189
191 UINT32 nBytes = (nBits + 7)/8;
192
193 UINT32 nBitsHigh = SymCryptIntBitsizeOfValue( piHigh );
194
196
200
202
203 // Allocate divisor objects for each public exponent & initialize them
205 for( e = 0; e < nPubExp; e++ )
206 {
207 SYMCRYPT_ASSERT( cbScratch >= cbObj );
208 if( pu64PubExp[e] == 0 )
209 {
210 scError = SYMCRYPT_INVALID_ARGUMENT;
211 goto exit;
212 }
213
214 pdPubExp[e] = SymCryptDivisorCreate( pbScratch, cbObj, 1 );
215 pbScratch += cbObj;
216 cbScratch -= cbObj;
217
218 SymCryptIntSetValueUint64( pu64PubExp[e], SymCryptIntFromDivisor( pdPubExp[e] ) );
219 SymCryptIntToDivisor( SymCryptIntFromDivisor( pdPubExp[e] ), pdPubExp[e], 1000, SYMCRYPT_FLAG_DATA_PUBLIC, pbScratch, cbScratch );
220 }
221
222 cbObj = SymCryptSizeofIntFromDigits( 1 );
223 SYMCRYPT_ASSERT( cbScratch >= cbObj + nBytes );
224 piTmp = SymCryptIntCreate( pbScratch, cbObj, 1 );
225 pbScratch += cbObj;
226 cbScratch -= cbObj;
227
228 do
229 {
230 cnt++;
231
232 scError = SymCryptCallbackRandom( pbScratch, nBytes );
233 if (scError != SYMCRYPT_NO_ERROR)
234 {
235 goto exit;
236 }
237
238 scError = SymCryptIntSetValue( pbScratch, nBytes, SYMCRYPT_NUMBER_FORMAT_MSB_FIRST, piDst );
239 if (scError != SYMCRYPT_NO_ERROR)
240 {
241 goto exit;
242 }
243
244 // Set the integer to 3 mod 4
245 SymCryptIntSetBits( piDst, 3, 0, 2 );
246
247 // Zero out the top bits above the upper limit
248 SymCryptIntModPow2( piDst, nBitsHigh, piDst );
249
250 // Check if it is in the correct range
251 if ( (SymCryptIntIsLessThan( piDst, piLow )) ||
252 (!SymCryptIntIsLessThan( piDst, piHigh )) )
253 {
254 continue;
255 }
256
257 // Fast compositeness check
258 if( SymCryptIntFindSmallDivisor( pTrialDivisionContext, piDst, NULL, 0 ) != 0 )
259 {
260 // We found a small divisor; it is not a prime
261 continue;
262 }
263
264 // Check for compatibility with public exponents (if provided)
265 reject = FALSE;
266 for( e = 0; e < nPubExp; e++ )
267 {
268 SymCryptIntDivMod( piDst, pdPubExp[e], NULL, piTmp, pbScratch, cbScratch );
269
270 // Check that e has a modular inverse mod P-1
271 // If e and P-1 are coprime, or GCD( P-1, e ) == 1, then e^-1 exists
272 // We have (P mod e) in piTmp.
273 // If piTmp == 0 then P is divisible by e, and will fail primality test - we don't care about the result of the GCD
274 // Otherwise, GCD( (P mod e)-1, e ) == GCD( P-1 mod e, e ) == GCD( P-1, e )
275 //
276 // Note that if P-1 is a multiple of e then (P mod e)-1 == 0, and GCD( 0, e ) == e
278 {
279 // We can't continue the big loop from here :-(
280 reject = TRUE;
281 break;
282 }
283 }
284 if( reject )
285 {
286 continue;
287 }
288
289 // Primality check
291 {
292 scError = SYMCRYPT_NO_ERROR;
293 break;
294 }
295 }
296 while (cnt<nTries);
297
298 if (cnt>=nTries)
299 {
300 scError = SYMCRYPT_INVALID_ARGUMENT;
301 }
302
303exit:
304 SymCryptFreeTrialDivisionContext( pTrialDivisionContext );
305 return scError;
306}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptCallbackRandom(BYTE *buf, SIZE_T size)
Definition: implglue.c:56
#define e
Definition: ke_i.h:82
UINT32 SYMCRYPT_CALL SymCryptIntMillerRabinPrimalityTest(_In_ PCSYMCRYPT_INT piSrc, UINT32 nBitsSrc, UINT32 nIterations, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: primes.c:12
#define SYMCRYPT_PRIME_GENERATION_MR_ITERATIONS
Definition: primes.c:166
#define exit(n)
Definition: config.h:202
UINT32 nPubExp
#define SYMCRYPT_RSAKEY_MAX_NUMOF_PUBEXPS
PCSYMCRYPT_TRIALDIVISION_CONTEXT SYMCRYPT_CALL SymCryptCreateTrialDivisionContext(UINT32 nDigits)
Definition: a_dispatch.c:1007
UINT64 SYMCRYPT_CALL SymCryptUint64Gcd(UINT64 a, UINT64 b, UINT32 flags)
Definition: gen_int.c:12
#define SYMCRYPT_FLAG_GCD_INPUTS_NOT_BOTH_EVEN
VOID SYMCRYPT_CALL SymCryptIntSetBits(_In_ PSYMCRYPT_INT piDst, UINT32 value, UINT32 iBit, UINT32 nBits)
Definition: a_dispatch.c:413
VOID SYMCRYPT_CALL SymCryptIntSetValueUint64(UINT64 u64Src, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:239
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_PRIME_GEN(_nDigits)
UINT64 SYMCRYPT_CALL SymCryptIntGetValueLsbits64(_In_ PCSYMCRYPT_INT piSrc)
Definition: a_dispatch.c:277
VOID SYMCRYPT_CALL SymCryptIntModPow2(_In_ PCSYMCRYPT_INT piSrc, SIZE_T exp, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:384
VOID SYMCRYPT_CALL SymCryptFreeTrialDivisionContext(PCSYMCRYPT_TRIALDIVISION_CONTEXT pContext)
Definition: a_dispatch.c:1025
UINT32 SYMCRYPT_CALL SymCryptIntBitsizeOfValue(_In_ PCSYMCRYPT_INT piSrc)
Definition: a_dispatch.c:223
UINT32 SYMCRYPT_CALL SymCryptIntFindSmallDivisor(_In_ PCSYMCRYPT_TRIALDIVISION_CONTEXT pContext, _In_ PCSYMCRYPT_INT piSrc, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:1014
_In_ size_t cnt
Definition: wcstombs.cpp:43

Referenced by SymCryptRsakeyGenerate().

◆ SymCryptIntGetBit()

UINT32 SYMCRYPT_CALL SymCryptIntGetBit ( _In_ PCSYMCRYPT_INT  piSrc,
UINT32  iBit 
)

Definition at line 394 of file a_dispatch.c.

397{
398 return SymCryptFdefIntGetBit( piSrc, iBit );
399}
UINT32 SYMCRYPT_CALL SymCryptFdefIntGetBit(_In_ PCSYMCRYPT_INT piSrc, UINT32 iBit)
Definition: fdef_int.c:580

Referenced by SymCryptDlgroupGeneratePrimeP_FIPS(), SymCryptEcpointScalarMulFixedWindow(), SymCryptIntMillerRabinPrimalityTest(), and SymCryptMontgomeryPointScalarMul().

◆ SymCryptIntGetBits()

UINT32 SYMCRYPT_CALL SymCryptIntGetBits ( _In_ PCSYMCRYPT_INT  piSrc,
UINT32  iBit,
UINT32  nBits 
)

Definition at line 403 of file a_dispatch.c.

407{
408 return SymCryptFdefIntGetBits( piSrc, iBit, nBits );
409}
UINT32 SYMCRYPT_CALL SymCryptFdefIntGetBits(_In_ PCSYMCRYPT_INT piSrc, UINT32 iBit, UINT32 nBits)
Definition: fdef_int.c:591

Referenced by SymCryptEckeySetValue(), SymCryptModExpWindowed(), and SymCryptPositiveWidthNafRecoding().

◆ SymCryptIntGetValue()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptIntGetValue ( _In_ PCSYMCRYPT_INT  piSrc,
_Out_writes_bytes_(cbDst) PBYTE  pbDst,
SIZE_T  cbDst,
SYMCRYPT_NUMBER_FORMAT  format 
)

Definition at line 259 of file a_dispatch.c.

264{
265 return SymCryptFdefIntGetValue( piSrc, pbDst, cbDst, format );
266}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptFdefIntGetValue(_In_ PCSYMCRYPT_INT piSrc, _Out_writes_bytes_(cbDst) PBYTE pbDst, SIZE_T cbDst, SYMCRYPT_NUMBER_FORMAT format)
Definition: fdef_general.c:695

Referenced by rsa_decrypt(), SymCryptDlgroupGeneratePrimeP_FIPS(), SymCryptDlgroupGeneratePrimeQ_FIPS(), SymCryptDlgroupGetValue(), SymCryptDlkeyGetValue(), SymCryptEckeyGetValue(), SymCryptRsaCoreDecCrt(), SymCryptRsakeyGetCrtValue(), and SymCryptRsakeyGetValue().

◆ SymCryptIntGetValueLsbits32()

◆ SymCryptIntGetValueLsbits64()

UINT64 SYMCRYPT_CALL SymCryptIntGetValueLsbits64 ( _In_ PCSYMCRYPT_INT  piSrc)

Definition at line 277 of file a_dispatch.c.

278{
279 return SymCryptFdefIntGetValueLsbits64( piSrc );
280}
UINT64 SYMCRYPT_CALL SymCryptFdefIntGetValueLsbits64(_In_ PCSYMCRYPT_INT piSrc)
Definition: fdef_general.c:721

Referenced by SymCryptDlgroupAutoCompleteNamedSafePrimeGroup(), SymCryptFdefIntToModulus(), SymCryptIntGenerateRandomPrime(), and SymCryptRsakeyCalculatePrimesFromPrivateExponent().

◆ SymCryptIntIsEqual()

UINT32 SYMCRYPT_CALL SymCryptIntIsEqual ( _In_ PCSYMCRYPT_INT  piSrc1,
_In_ PCSYMCRYPT_INT  piSrc2 
)

Definition at line 433 of file a_dispatch.c.

436{
437 return SymCryptFdefIntIsEqual( piSrc1, piSrc2 );
438}
UINT32 SYMCRYPT_CALL SymCryptFdefIntIsEqual(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2)
Definition: fdef_general.c:758

Referenced by SymCryptDlgroupAutoCompleteNamedSafePrimeGroup(), SymCryptDlgroupIsSame(), SymCryptDlgroupSetValue(), SymCryptEcurveIsSame(), SymCryptRsaCoreDecCrt(), and SymCryptRsakeyCalculatePrivateFields().

◆ SymCryptIntIsEqualUint32()

◆ SymCryptIntIsLessThan()

◆ SymCryptIntMaskedCopy()

VOID SYMCRYPT_CALL SymCryptIntMaskedCopy ( _In_ PCSYMCRYPT_INT  piSrc,
_Inout_ PSYMCRYPT_INT  piDst,
UINT32  mask 
)

Definition at line 170 of file a_dispatch.c.

174{
175 SymCryptFdefIntMaskedCopy( piSrc, piDst, mask );
176}
VOID SymCryptFdefIntMaskedCopy(_In_ PCSYMCRYPT_INT piSrc, _Inout_ PSYMCRYPT_INT piDst, UINT32 mask)
Definition: fdef_general.c:280

Referenced by SymCryptEcpointScalarMulFixedWindow(), and SymCryptFixedWindowRecoding().

◆ SymCryptIntMillerRabinPrimalityTest()

UINT32 SYMCRYPT_CALL SymCryptIntMillerRabinPrimalityTest ( _In_ PCSYMCRYPT_INT  piSrc,
UINT32  nBitsSrc,
UINT32  nIterations,
UINT32  flags,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 12 of file primes.c.

19{
20 BOOLEAN innerLoop = TRUE;
21 UINT32 borrow = 0;
22
23 UINT32 nDigitsSrc = 0;
24
25 UINT32 R = 1;
26 PSYMCRYPT_INT piD = NULL;
27 UINT32 cbD = 0;
29 UINT32 cbModulus = 0;
31 UINT32 cbX = 0;
32
34 PSYMCRYPT_MODELEMENT peMinOne = NULL;
35
36 nDigitsSrc = SymCryptIntDigitsizeOfObject( piSrc );
37 cbD = SymCryptSizeofIntFromDigits( nDigitsSrc );
38 cbModulus = SymCryptSizeofModulusFromDigits( nDigitsSrc );
39
40 SYMCRYPT_ASSERT( nBitsSrc >= SymCryptIntBitsizeOfValue( piSrc ) );
41
43
44 // Allocate the modulus
45 pmModulus = SymCryptModulusCreate( pbScratch, cbModulus, nDigitsSrc );
47 pbScratch += cbModulus;
48 cbScratch -= cbModulus;
49
50 // Set the modulus
52 piSrc,
54 nBitsSrc, // Average number of expected operations
56 pbScratch,
57 cbScratch );
58
59 // Modelement size
61
62 SYMCRYPT_ASSERT( cbScratch >= 3*cbX + cbD +
64
65 peX = SymCryptModElementCreate( pbScratch, cbX, pmModulus );
66 SYMCRYPT_ASSERT( peX != NULL );
67 pbScratch += cbX;
68 cbScratch -= cbX;
69
70 peOne = SymCryptModElementCreate( pbScratch, cbX, pmModulus );
71 SYMCRYPT_ASSERT( peOne != NULL );
72 pbScratch += cbX;
73 cbScratch -= cbX;
74
75 peMinOne = SymCryptModElementCreate( pbScratch, cbX, pmModulus );
76 SYMCRYPT_ASSERT( peMinOne != NULL );
77 pbScratch += cbX;
78 cbScratch -= cbX;
79
80 // Allocate D
81 piD = SymCryptIntCreate( pbScratch, cbD, nDigitsSrc );
82 SYMCRYPT_ASSERT( piD != NULL );
83 pbScratch += cbD;
84 cbScratch -= cbD;
85
86 // Calculate (piSrc - 1)
87 // Note: We should never get a borrow here because the requirement
88 // is that Src > 3.
89 SymCryptIntCopy( piSrc, piD );
90 borrow = SymCryptIntSubUint32( piD, 1, piD );
91 SYMCRYPT_ASSERT( borrow==0 );
92
93 SYMCRYPT_ASSERT( SymCryptIntGetBit( piD, 0 ) == 0 );
94
95 // Check the 3 mod 4 requirement when side-channel safe
98 (SymCryptIntGetBit( piD, 1 )!=0) );
100
101 // Calculate R and D such that Src - 1 = D*2^R
102 // Notice that the loop executes only if
103 // the SYMCRYPT_FLAG_DATA_PUBLIC is
104 // specified (and Src != 3 mod 4)
105 R = 1;
106 while( SymCryptIntGetBit( piD, R )==0 )
107 {
108 R++;
109 }
110 SymCryptIntDivPow2( piD, R, piD );
111
112 // Set peOne and peMinOne
114 SymCryptModElementSetValueNegUint32( 1, pmModulus, peMinOne, pbScratch, cbScratch );
115
116 for (UINT32 i=0; i<nIterations; i++)
117 {
118 // Pick a random X in [2, piSrc-2]
119 // Therefore the flags parameter is 0 (default: not allowed 0, 1, -1 when modulus > 3)
120 SymCryptModSetRandom( pmModulus, peX, 0, pbScratch, cbScratch );
121
122 // X^D mod piSrc
123 // Notice that nBitsSrc is public in the call of SymCryptModExp
124 SymCryptModExp( pmModulus, peX, piD, nBitsSrc, 0, peX, pbScratch, cbScratch );
125
126 // Check for 1 or -1
127 if ( SymCryptModElementIsEqual( pmModulus, peX, peOne ) |
128 SymCryptModElementIsEqual( pmModulus, peX, peMinOne ) )
129 {
130 continue;
131 }
132
133 // repeat R-1 times
134 // Notice that the inner loop executes only if
135 // the SYMCRYPT_FLAG_DATA_PUBLIC is
136 // specified (and Src != 3 mod 4)
137 innerLoop = TRUE;
138 for (UINT32 j=0; (j<R-1)&&(innerLoop); j++)
139 {
140 // Square X
141 SymCryptModSquare( pmModulus, peX, peX, pbScratch, cbScratch );
142
143 // Check if it is 1
144 if (SymCryptModElementIsEqual( pmModulus, peX, peOne ))
145 {
146 return 0x0;
147 }
148
149 // Check if it is -1
150 if (SymCryptModElementIsEqual( pmModulus, peX, peMinOne ))
151 {
152 innerLoop = FALSE;
153 break;
154 }
155 }
156
157 if (innerLoop)
158 {
159 return 0x0;
160 }
161 }
162
163 return 0xffffffff; // Prime
164}
@ R
Definition: bidi.c:79
GLsizei GLenum const GLvoid GLsizei GLenum GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLint GLint GLint GLshort GLshort GLshort GLubyte GLubyte GLubyte GLuint GLuint GLuint GLushort GLushort GLushort GLbyte GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLfloat GLint GLint GLint GLint GLshort GLshort GLshort GLshort GLubyte GLubyte GLubyte GLubyte GLuint GLuint GLuint GLuint GLushort GLushort GLushort GLushort GLboolean const GLdouble const GLfloat const GLint const GLshort const GLbyte const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLdouble const GLfloat const GLfloat const GLint const GLint const GLshort const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort GLenum GLenum GLenum GLfloat GLenum GLint GLenum GLenum GLenum GLfloat GLenum GLenum GLint GLenum GLfloat GLenum GLint GLint GLushort GLenum GLenum GLfloat GLenum GLenum GLint GLfloat const GLubyte GLenum GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLint GLint GLsizei GLsizei GLint GLenum GLenum const GLvoid GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLenum const GLdouble GLenum GLenum const GLfloat GLenum GLenum const GLint GLsizei GLuint GLfloat GLuint GLbitfield GLfloat GLint GLuint GLboolean GLenum GLfloat GLenum GLbitfield GLenum GLfloat GLfloat GLint GLint const GLfloat GLenum GLfloat GLfloat GLint GLint GLfloat GLfloat GLint GLint const GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat const GLdouble const GLfloat const GLdouble const GLfloat GLint GLint GLint j
Definition: glfuncs.h:250
PSYMCRYPT_MODULUS pmModulus
VOID SYMCRYPT_CALL SymCryptIntDivPow2(_In_ PCSYMCRYPT_INT piSrc, SIZE_T exp, _Out_ PSYMCRYPT_INT piDst)
Definition: a_dispatch.c:364
UINT32 SYMCRYPT_CALL SymCryptModElementIsEqual(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc1, _In_ PCSYMCRYPT_MODELEMENT peSrc2)
Definition: a_dispatch.c:818
#define SYMCRYPT_SCRATCH_BYTES_FOR_INT_TO_MODULUS(_nDigits)
VOID SYMCRYPT_CALL SymCryptModSetRandom(_In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:993
#define SYMCRYPT_FLAG_MODULUS_PARITY_PUBLIC
UINT32 SYMCRYPT_CALL SymCryptIntGetBit(_In_ PCSYMCRYPT_INT piSrc, UINT32 iBit)
Definition: a_dispatch.c:394
PSYMCRYPT_MODULUS SYMCRYPT_CALL SymCryptModulusCreate(_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, UINT32 nDigits)
Definition: a_dispatch.c:608
UINT32 SYMCRYPT_CALL SymCryptSizeofModulusFromDigits(UINT32 nDigits)
Definition: a_dispatch.c:601
VOID SYMCRYPT_CALL SymCryptModExp(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peBase, _In_ PCSYMCRYPT_INT piExp, UINT32 nBitsExp, UINT32 flags, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:961
VOID SYMCRYPT_CALL SymCryptModElementSetValueNegUint32(UINT32 value, _In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: a_dispatch.c:922

Referenced by SymCryptDlgroupGeneratePrimeP_FIPS(), SymCryptDlgroupGeneratePrimeQ_FIPS(), and SymCryptIntGenerateRandomPrime().

◆ SymCryptIntModPow2()

VOID SYMCRYPT_CALL SymCryptIntModPow2 ( _In_ PCSYMCRYPT_INT  piSrc,
SIZE_T  exp,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 384 of file a_dispatch.c.

388{
389 SymCryptFdefIntModPow2( piSrc, exp, piDst );
390}
VOID SYMCRYPT_CALL SymCryptFdefIntModPow2(_In_ PCSYMCRYPT_INT piSrc, SIZE_T exp, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_int.c:539

Referenced by SymCryptDlgroupGeneratePrimeP_FIPS(), SymCryptDlgroupGeneratePrimeQ_FIPS(), and SymCryptIntGenerateRandomPrime().

◆ SymCryptIntMulMixedSize()

VOID SYMCRYPT_CALL SymCryptIntMulMixedSize ( _In_ PCSYMCRYPT_INT  piSrc1,
_In_ PCSYMCRYPT_INT  piSrc2,
_Out_ PSYMCRYPT_INT  piDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 485 of file a_dispatch.c.

491{
492 SymCryptFdefIntMulMixedSize( piSrc1, piSrc2, piDst, pbScratch, cbScratch );
493}
VOID SYMCRYPT_CALL SymCryptFdefIntMulMixedSize(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_int.c:889

Referenced by SymCryptCrtSolve(), SymCryptIntExtendedGcd(), SymCryptRsakeyCalculatePrimesFromPrivateExponent(), SymCryptRsakeyCalculatePrivateFields(), and SymCryptRsakeyGenerate().

◆ SymCryptIntMulPow2()

VOID SYMCRYPT_CALL SymCryptIntMulPow2 ( _In_ PCSYMCRYPT_INT  piSrc,
SIZE_T  exp,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 354 of file a_dispatch.c.

358{
359 SymCryptFdefIntMulPow2( piSrc, exp, piDst );
360}
VOID SYMCRYPT_CALL SymCryptFdefIntMulPow2(_In_ PCSYMCRYPT_INT piSrc, SIZE_T Exp, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_int.c:407

Referenced by SymCryptDlgroupGeneratePrimeQ_FIPS(), SymCryptEckeyGetValue(), and SymCryptRsakeyGenerate().

◆ SymCryptIntMulSameSize()

VOID SYMCRYPT_CALL SymCryptIntMulSameSize ( _In_ PCSYMCRYPT_INT  piSrc1,
_In_ PCSYMCRYPT_INT  piSrc2,
_Out_ PSYMCRYPT_INT  piDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 461 of file a_dispatch.c.

467{
468 SymCryptFdefIntMulSameSize( piSrc1, piSrc2, piDst, pbScratch, cbScratch );
469}
VOID SYMCRYPT_CALL SymCryptFdefIntMulSameSize(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_int.c:704

◆ SymCryptIntMulUint32()

UINT32 SYMCRYPT_CALL SymCryptIntMulUint32 ( _In_ PCSYMCRYPT_INT  piSrc1,
UINT32  Src2,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 451 of file a_dispatch.c.

455{
456 return SymCryptFdefIntMulUint32( piSrc1, Src2, piDst );
457}
UINT32 SYMCRYPT_CALL SymCryptFdefIntMulUint32(_In_ PCSYMCRYPT_INT piSrc1, UINT32 Src2, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_int.c:681

◆ SymCryptIntNeg()

VOID SYMCRYPT_CALL SymCryptIntNeg ( _In_ PCSYMCRYPT_INT  piSrc,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 344 of file a_dispatch.c.

347{
348 SymCryptFdefIntNeg( piSrc, piDst );
349}
VOID SYMCRYPT_CALL SymCryptFdefIntNeg(_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_int.c:394

Referenced by SymCryptFdefModInvGeneric().

◆ SymCryptIntSetBits()

VOID SYMCRYPT_CALL SymCryptIntSetBits ( _In_ PSYMCRYPT_INT  piDst,
UINT32  value,
UINT32  iBit,
UINT32  nBits 
)

Definition at line 413 of file a_dispatch.c.

418{
419 SymCryptFdefIntSetBits( piDst, value, iBit, nBits );
420}
VOID SYMCRYPT_CALL SymCryptFdefIntSetBits(_In_ PSYMCRYPT_INT piDst, UINT32 value, UINT32 iBit, UINT32 nBits)
Definition: fdef_int.c:627
Definition: pdh_main.c:64

Referenced by SymCryptDlgroupGeneratePrimeP_FIPS(), SymCryptEckeySetRandom(), and SymCryptIntGenerateRandomPrime().

◆ SymCryptIntSetValue()

◆ SymCryptIntSetValueUint32()

VOID SYMCRYPT_CALL SymCryptIntSetValueUint32 ( UINT32  u32Src,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 230 of file a_dispatch.c.

233{
234 SymCryptFdefIntSetValueUint32( u32Src, piDst );
235}
VOID SYMCRYPT_CALL SymCryptFdefIntSetValueUint32(UINT32 u32Src, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_general.c:497

Referenced by SymCryptEckeyWipePrivateState(), SymCryptFdefIntToDivisor(), SymCryptIntExtendedGcd(), SymCryptRsakeyCalculatePrivateFields(), SymCryptRsakeyGenerate(), and SymCryptSswu().

◆ SymCryptIntSetValueUint64()

VOID SYMCRYPT_CALL SymCryptIntSetValueUint64 ( UINT64  u64Src,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 239 of file a_dispatch.c.

242{
243 SymCryptFdefIntSetValueUint64( u64Src, piDst );
244}
VOID SYMCRYPT_CALL SymCryptFdefIntSetValueUint64(UINT64 u64Src, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_general.c:511

Referenced by rsa_encrypt(), SymCryptIntGenerateRandomPrime(), SymCryptRsaCoreDecCrt(), SymCryptRsaCoreEnc(), SymCryptRsakeyCalculatePrimesFromPrivateExponent(), and SymCryptRsakeyCalculatePrivateFields().

◆ SymCryptIntShr1()

VOID SYMCRYPT_CALL SymCryptIntShr1 ( UINT32  highestBit,
_In_ PCSYMCRYPT_INT  piSrc,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 374 of file a_dispatch.c.

378{
379 SymCryptFdefIntShr1( highestBit, piSrc, piDst );
380}
VOID SYMCRYPT_CALL SymCryptFdefIntShr1(UINT32 highestBit, _In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_int.c:511

Referenced by SymCryptDlgroupAutoCompleteNamedSafePrimeGroup(), SymCryptDlgroupSetValueSafePrime(), and SymCryptIntExtendedGcd().

◆ SymCryptIntSquare()

VOID SYMCRYPT_CALL SymCryptIntSquare ( _In_ PCSYMCRYPT_INT  piSrc,
_Out_ PSYMCRYPT_INT  piDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 474 of file a_dispatch.c.

479{
480 SymCryptFdefIntSquare( piSrc, piDst, pbScratch, cbScratch );
481}
VOID SYMCRYPT_CALL SymCryptFdefIntSquare(_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_int.c:716

◆ SymCryptIntSubMixedSize()

UINT32 SYMCRYPT_CALL SymCryptIntSubMixedSize ( _In_ PCSYMCRYPT_INT  piSrc1,
_In_ PCSYMCRYPT_INT  piSrc2,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 334 of file a_dispatch.c.

338{
339 return SymCryptFdefIntSubMixedSize( piSrc1, piSrc2, piDst );
340}
UINT32 SYMCRYPT_CALL SymCryptFdefIntSubMixedSize(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_int.c:260

Referenced by SymCryptDlgroupGeneratePrimeP_FIPS(), and SymCryptIntExtendedGcd().

◆ SymCryptIntSubSameSize()

UINT32 SYMCRYPT_CALL SymCryptIntSubSameSize ( _In_ PCSYMCRYPT_INT  piSrc1,
_In_ PCSYMCRYPT_INT  piSrc2,
_Out_ PSYMCRYPT_INT  piDst 
)

Definition at line 324 of file a_dispatch.c.

328{
329 return SymCryptFdefIntSubSameSize( piSrc1, piSrc2, piDst );
330}
UINT32 SYMCRYPT_CALL SymCryptFdefIntSubSameSize(_In_ PCSYMCRYPT_INT piSrc1, _In_ PCSYMCRYPT_INT piSrc2, _Out_ PSYMCRYPT_INT piDst)
Definition: fdef_int.c:248

Referenced by SymCryptEcpointScalarMulFixedWindow(), SymCryptFdefModInvGeneric(), and SymCryptIntExtendedGcd().

◆ SymCryptIntSubUint32()

◆ SymCryptIntToDivisor()

VOID SYMCRYPT_CALL SymCryptIntToDivisor ( _In_ PCSYMCRYPT_INT  piSrc,
_Out_ PSYMCRYPT_DIVISOR  pdDst,
UINT32  totalOperations,
UINT32  flags,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 560 of file a_dispatch.c.

567{
568 SymCryptFdefIntToDivisor( piSrc, pdDst, totalOperations, flags, pbScratch, cbScratch );
569}
VOID SYMCRYPT_CALL SymCryptFdefIntToDivisor(_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_DIVISOR pdDst, UINT32 totalOperations, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_int.c:922

Referenced by SymCryptDlgroupGeneratePrimeQ_FIPS(), SymCryptFdefIntToModulus(), SymCryptIntExtendedGcd(), SymCryptIntGenerateRandomPrime(), and SymCryptRsakeyCalculatePrivateFields().

◆ SymCryptIntToModElement()

VOID SYMCRYPT_CALL SymCryptIntToModElement ( _In_ PCSYMCRYPT_INT  piSrc,
_In_ PCSYMCRYPT_MODULUS  pmMod,
_Out_ PSYMCRYPT_MODELEMENT  peDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 749 of file a_dispatch.c.

755{
756 SymCryptFdefIntToModElement( piSrc, pmMod, peDst, pbScratch, cbScratch );
757}
VOID SYMCRYPT_CALL SymCryptFdefIntToModElement(_In_ PCSYMCRYPT_INT piSrc, _In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_mod.c:407

Referenced by rsa_decrypt(), SymCrypt802_11SaeCustomCommitProcessGeneric(), SymCrypt802_11SaeCustomCreatePTGeneric(), SymCrypt802_11SaeCustomInit(), SymCryptCrtGenerateForTwoCoprimes(), SymCryptCrtSolve(), SymCryptDsaSignEx(), SymCryptDsaTruncateHash(), SymCryptDsaVerify(), SymCryptEcDsaSignEx(), SymCryptEcDsaTruncateHash(), SymCryptEcDsaVerify(), SymCryptEckeySetRandom(), SymCryptEckeySetValue(), SymCryptRsaCoreDecCrt(), and SymCryptSswu().

◆ SymCryptIntToModulus()

VOID SYMCRYPT_CALL SymCryptIntToModulus ( _In_ PCSYMCRYPT_INT  piSrc,
_Out_ PSYMCRYPT_MODULUS  pmDst,
UINT32  averageOperations,
UINT32  flags,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 727 of file a_dispatch.c.

734{
735 PSYMCRYPT_INT piSrcTweak = (PSYMCRYPT_INT) piSrc;
736
737 // In CHKed build, we'll verify that the modulus is not prime, or that it is 2 or odd
738 // (Some inversion algorithms fail hard when one input isn't 2 or odd.)
739 // We are constant-time w.r.t. piSrc being odd or =2. We don't hide the size of any input,
740 // but inputs 2 and 3 are handled with the same code path.
742 (((SymCryptIntGetValueLsbits32( piSrc ) & 1) | SymCryptIntIsEqualUint32( piSrc, 2 )) != 0) );
743
744 SymCryptFdefIntToModulus( piSrcTweak, pmDst, averageOperations, flags, pbScratch, cbScratch );
745}
UINT32 SYMCRYPT_CALL SymCryptIntGetValueLsbits32(_In_ PCSYMCRYPT_INT piSrc)
Definition: a_dispatch.c:270
UINT32 SYMCRYPT_CALL SymCryptIntIsEqualUint32(_In_ PCSYMCRYPT_INT piSrc1, _In_ UINT32 u32Src2)
Definition: a_dispatch.c:424
VOID SYMCRYPT_CALL SymCryptFdefIntToModulus(_In_ PCSYMCRYPT_INT piSrc, _Out_ PSYMCRYPT_MODULUS pmDst, UINT32 averageOperations, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_mod.c:385
#define SYMCRYPT_FLAG_MODULUS_PRIME

Referenced by SymCrypt802_11SaeCustomInitH2EGeneric(), SymCryptDlgroupAutoCompleteNamedSafePrimeGroup(), SymCryptDlgroupGenerate(), SymCryptDlgroupSetValue(), SymCryptDlgroupSetValueSafePrime(), SymCryptEcurveInitialize(), SymCryptIntMillerRabinPrimalityTest(), SymCryptRsakeyCalculatePrimesFromPrivateExponent(), SymCryptRsakeyGenerate(), and SymCryptRsakeySetValueInternal().

◆ SymCryptIntWipe()

VOID SYMCRYPT_CALL SymCryptIntWipe ( _Out_ PSYMCRYPT_INT  piObj)

Definition at line 151 of file a_dispatch.c.

152{
153 SYMCRYPT_CHECK_MAGIC( piDst );
154
155 // Wipe the whole structure in one go;
156 SymCryptWipe( piDst, piDst->cbSize );
157}

Referenced by SymCryptIntFree(), and SymCryptRsaCoreEnc().

◆ SymCryptMask32EqU32()

UINT32 SYMCRYPT_CALL SymCryptMask32EqU32 ( UINT32  a,
UINT32  b 
)

Definition at line 67 of file scsTools.c.

68{
69 return ~(UINT32) ( (-(INT64)(a^b)) >> 32);
70}
COMPILER_DEPENDENT_INT64 INT64
Definition: actypes.h:132
GLboolean GLboolean GLboolean b
Definition: glext.h:6204
GLboolean GLboolean GLboolean GLboolean a
Definition: glext.h:6204

Referenced by SymCryptMapUint32().

◆ SymCryptMask32IsNonzeroU31()

UINT32 SYMCRYPT_CALL SymCryptMask32IsNonzeroU31 ( UINT32  v)

Definition at line 28 of file scsTools.c.

29{
30 SYMCRYPT_ASSERT( v < (1UL<<31) );
31 return (-(INT32) v) >> 31;
32}
const GLdouble * v
Definition: gl.h:2040
int32_t INT32
Definition: typedefs.h:58

Referenced by SymCryptMask32NeqU31(), SymCryptPaddingPkcs7Remove(), SymCryptRsaOaepRemoveEncryptionPadding(), and SymCryptRsaPkcs1RemoveEncryptionPadding().

◆ SymCryptMask32IsZeroU31()

UINT32 SYMCRYPT_CALL SymCryptMask32IsZeroU31 ( UINT32  v)

Definition at line 36 of file scsTools.c.

37{
38 return ~SymCryptMask32IsNonzeroU31( v );
39}

Referenced by SymCryptPaddingPkcs7Remove(), SymCryptRsaOaepRemoveEncryptionPadding(), and SymCryptRsaPkcs1RemoveEncryptionPadding().

◆ SymCryptMask32LtU31()

UINT32 SYMCRYPT_CALL SymCryptMask32LtU31 ( UINT32  a,
UINT32  b 
)

Definition at line 53 of file scsTools.c.

54{
55 SYMCRYPT_ASSERT( a < (1UL<<31) );
56 SYMCRYPT_ASSERT( b < (1UL<<31) );
57
58 // Casting to INT32 is defined as a and b are < 2^31
59 return ((INT32) a - (INT32) b) >> 31;
60}

Referenced by SymCryptAesKwpDecrypt(), SymCryptPaddingPkcs7Remove(), SymCryptRsaPkcs1RemoveEncryptionPadding(), and SymCryptScsCopy().

◆ SymCryptMask32NeqU31()

UINT32 SYMCRYPT_CALL SymCryptMask32NeqU31 ( UINT32  a,
UINT32  b 
)

Definition at line 43 of file scsTools.c.

44{
45 SYMCRYPT_ASSERT( a < (1UL<<31) );
46 SYMCRYPT_ASSERT( b < (1UL<<31) );
47
48 return SymCryptMask32IsNonzeroU31( a ^ b );
49}
UINT32 SYMCRYPT_CALL SymCryptMask32IsNonzeroU31(UINT32 v)
Definition: scsTools.c:28

Referenced by SymCryptRsaPkcs1RemoveEncryptionPadding().

◆ SymCryptMlKemEncapsulateEx()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlKemEncapsulateEx ( _In_ PCSYMCRYPT_MLKEMKEY  pkMlKemkey,
_In_reads_bytes_(cbRandom) PCBYTE  pbRandom,
SIZE_T  cbRandom,
_Out_writes_bytes_(cbAgreedSecret) PBYTE  pbAgreedSecret,
SIZE_T  cbAgreedSecret,
_Out_writes_bytes_(cbCiphertext) PBYTE  pbCiphertext,
SIZE_T  cbCiphertext 
)

Definition at line 952 of file mlkem.c.

960{
961 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
963
965 {
966 scError = SYMCRYPT_INVALID_ARGUMENT;
967 goto cleanup;
968 }
969
971 if( pCompTemps == NULL )
972 {
973 scError = SYMCRYPT_MEMORY_ALLOCATION_FAILURE;
974 goto cleanup;
975 }
976
979 pbAgreedSecret, cbAgreedSecret,
980 pbCiphertext, cbCiphertext,
981 pbRandom,
982 pCompTemps );
983
984cleanup:
985 if( pCompTemps != NULL )
986 {
987 SymCryptWipe( pCompTemps, sizeof(*pCompTemps) );
988 SymCryptCallbackFree( pCompTemps );
989 }
990
991 return scError;
992}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptMlKemEncapsulateInternal(_In_ PCSYMCRYPT_MLKEMKEY pkMlKemkey, _Out_writes_bytes_(cbAgreedSecret) PBYTE pbAgreedSecret, SIZE_T cbAgreedSecret, _Out_writes_bytes_(cbCiphertext) PBYTE pbCiphertext, SIZE_T cbCiphertext, _In_reads_bytes_(SYMCRYPT_MLKEM_SIZEOF_ENCAPS_RANDOM) PCBYTE pbRandom, _Inout_ PSYMCRYPT_MLKEM_INTERNAL_COMPUTATION_TEMPORARIES pCompTemps)
Definition: mlkem.c:807
PSYMCRYPT_MLKEMKEY pkMlKemkey
Definition: sc_lib.h:4444
#define SYMCRYPT_MLKEM_SIZEOF_ENCAPS_RANDOM
Definition: sc_lib_mlkem.h:133
SYMCRYPT_MLKEM_INTERNAL_COMPUTATION_TEMPORARIES
Definition: sc_lib_mlkem.h:153
SYMCRYPT_MLKEM_INTERNAL_COMPUTATION_TEMPORARIES * PSYMCRYPT_MLKEM_INTERNAL_COMPUTATION_TEMPORARIES
Definition: sc_lib_mlkem.h:154

Referenced by SymCryptMlKemEncapsulate().

◆ SymCryptModAdd()

◆ SymCryptModDivPow2()

VOID SYMCRYPT_CALL SymCryptModDivPow2 ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_In_ PCSYMCRYPT_MODELEMENT  peSrc,
UINT32  exp,
_Out_ PSYMCRYPT_MODELEMENT  peDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 934 of file a_dispatch.c.

941{
942 SymCryptFdefModDivPow2( pmMod, peSrc, exp, peDst, pbScratch, cbScratch );
943}
VOID SYMCRYPT_CALL SymCryptFdefModDivPow2(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, UINT32 exp, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_mod.c:872

Referenced by SymCryptEckeySetRandom(), SymCryptEckeySetValue(), and SymCryptEcurveInitialize().

◆ SymCryptModElementAllocate()

◆ SymCryptModElementConditionalSwap()

VOID SymCryptModElementConditionalSwap ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_Inout_ PSYMCRYPT_MODELEMENT  peData1,
_Inout_ PSYMCRYPT_MODELEMENT  peData2,
_In_ UINT32  cond 
)

Definition at line 709 of file a_dispatch.c.

714{
715 SymCryptFdefModElementConditionalSwap( pmMod, peData1, peData2, cond );
716}
VOID SymCryptFdefModElementConditionalSwap(_In_ PCSYMCRYPT_MODULUS pmMod, _Inout_ PSYMCRYPT_MODELEMENT peData1, _Inout_ PSYMCRYPT_MODELEMENT peData2, _In_ UINT32 cond)
Definition: fdef_mod.c:271

Referenced by SymCryptMontgomeryPointScalarMul().

◆ SymCryptModElementCopy()

VOID SymCryptModElementCopy ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_In_ PCSYMCRYPT_MODELEMENT  peSrc,
_Out_ PSYMCRYPT_MODELEMENT  peDst 
)

◆ SymCryptModElementCreate()

PSYMCRYPT_MODELEMENT SYMCRYPT_CALL SymCryptModElementCreate ( _Out_writes_bytes_(cbBuffer) PBYTE  pbBuffer,
SIZE_T  cbBuffer,
_In_ PCSYMCRYPT_MODULUS  pmMod 
)

Definition at line 665 of file a_dispatch.c.

669{
670 return SymCryptFdefModElementCreate( pbBuffer, cbBuffer, pmMod );
671}
PSYMCRYPT_MODELEMENT SYMCRYPT_CALL SymCryptFdefModElementCreate(_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, PCSYMCRYPT_MODULUS pmMod)
Definition: fdef_mod.c:202

Referenced by rsa_decrypt(), rsa_encrypt(), SymCryptCrtSolve(), SymCryptDhSecretAgreement(), SymCryptDlgroupCreate(), SymCryptDlgroupGenerateGenG_FIPS(), SymCryptDlgroupSetValue(), SymCryptDlkeyCreate(), SymCryptDlkeyGenerate(), SymCryptDlkeyPerformPublicKeyValidation(), SymCryptDlkeySetValue(), SymCryptDsaSignEx(), SymCryptDsaVerify(), SymCryptEcDsaSignEx(), SymCryptEcDsaVerify(), SymCryptEckeyGetValue(), SymCryptEckeySetRandom(), SymCryptEckeySetValue(), SymCryptEcpointCreateEx(), SymCryptEcpointGenericSetRandom(), SymCryptEcpointScalarMulFixedWindow(), SymCryptEcpointTransform(), SymCryptEcurveInitialize(), SymCryptFdefModInvGeneric(), SymCryptIntMillerRabinPrimalityTest(), SymCryptModExpSquareAndMultiply32(), SymCryptModExpWindowed(), SymCryptModMultiExpGeneric(), SymCryptModMultiExpWnafWithInterleaving(), SymCryptMontgomeryIsEqual(), SymCryptMontgomeryPointScalarMul(), SymCryptRsaCoreDec(), SymCryptRsaCoreDecCrt(), SymCryptRsaCoreEnc(), SymCryptRsakeyCalculatePrimesFromPrivateExponent(), SymCryptRsakeyCreateAllObjects(), SymCryptShortWeierstrassAddDiffNonZero(), SymCryptShortWeierstrassAddSideChannelUnsafe(), SymCryptShortWeierstrassDouble(), SymCryptShortWeierstrassDoubleSpecializedAm3(), SymCryptShortWeierstrassIsEqual(), SymCryptShortWeierstrassNegate(), SymCryptShortWeierstrassOnCurve(), SymCryptTwistedEdwardsAdd(), SymCryptTwistedEdwardsDouble(), SymCryptTwistedEdwardsIsEqual(), SymCryptTwistedEdwardsNegate(), and SymCryptTwistedEdwardsOnCurve().

◆ SymCryptModElementFree()

VOID SYMCRYPT_CALL SymCryptModElementFree ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_Out_ PSYMCRYPT_MODELEMENT  peObj 
)

◆ SymCryptModElementGetValue()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModElementGetValue ( PCSYMCRYPT_MODULUS  pmMod,
_In_ PCSYMCRYPT_MODELEMENT  peSrc,
_Out_writes_bytes_(cbDst) PBYTE  pbDst,
SIZE_T  cbDst,
SYMCRYPT_NUMBER_FORMAT  format,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 804 of file a_dispatch.c.

812{
813 return SymCryptFdefModElementGetValue( pmMod, peSrc, pbDst, cbDst, format, pbScratch, cbScratch );
814}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptFdefModElementGetValue(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_writes_bytes_(cbDst) PBYTE pbDst, SIZE_T cbDst, SYMCRYPT_NUMBER_FORMAT format, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_mod.c:484

Referenced by rsa_encrypt(), SymCrypt802_11SaeCustomCommitCreateGeneric(), SymCrypt802_11SaeCustomCommitProcessGeneric(), SymCrypt802_11SaeCustomInit(), SymCrypt802_11SaeCustomSetRandMask(), SymCryptDhSecretAgreement(), SymCryptDlgroupGetValue(), SymCryptDlkeyGetValue(), SymCryptDsaSignEx(), SymCryptEcDsaSignEx(), SymCryptEcpointGetValue(), SymCryptRsaCoreDec(), SymCryptRsaCoreEnc(), SymCryptRsakeyGetCrtValue(), and SymCryptSswu().

◆ SymCryptModElementIsEqual()

◆ SymCryptModElementIsZero()

◆ SymCryptModElementMaskedCopy()

VOID SymCryptModElementMaskedCopy ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_In_ PCSYMCRYPT_MODELEMENT  peSrc,
_Out_ PSYMCRYPT_MODELEMENT  peDst,
UINT32  mask 
)

Definition at line 692 of file a_dispatch.c.

697{
698 SymCryptFdefModElementMaskedCopy( pmMod, peSrc, peDst, mask );
699}
VOID SymCryptFdefModElementMaskedCopy(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peSrc, _Out_ PSYMCRYPT_MODELEMENT peDst, UINT32 mask)
Definition: fdef_mod.c:253

Referenced by SymCrypt802_11SaeCustomInit(), SymCryptShortWeierstrassNegate(), SymCryptSswu(), and SymCryptTwistedEdwardsNegate().

◆ SymCryptModElementSetValue()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModElementSetValue ( _In_reads_bytes_(cbSrc) PCBYTE  pbSrc,
SIZE_T  cbSrc,
SYMCRYPT_NUMBER_FORMAT  format,
PCSYMCRYPT_MODULUS  pmMod,
_Out_ PSYMCRYPT_MODELEMENT  peDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 781 of file a_dispatch.c.

789{
790 SYMCRYPT_ERROR scError;
791
792 scError = SymCryptFdefModElementSetValueGeneric( pbSrc, cbSrc, format, pmMod, peDst, pbScratch, cbScratch );
793
794 if( scError == SYMCRYPT_NO_ERROR )
795 {
796 SYMCRYPT_MOD_CALL( pmMod ) modSetPost( pmMod, peDst, pbScratch, cbScratch );
797 }
798
799 return scError;
800}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptFdefModElementSetValueGeneric(_In_reads_bytes_(cbSrc) PCBYTE pbSrc, SIZE_T cbSrc, SYMCRYPT_NUMBER_FORMAT format, _In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_mod.c:445

Referenced by rsa_encrypt(), SymCrypt802_11SaeCustomInitH2EGeneric(), SymCrypt802_11SaeCustomSetRandMask(), SymCryptDlgroupGenerateGenG_FIPS(), SymCryptDlgroupSetValue(), SymCryptDlkeySetValue(), SymCryptEcDsaSignEx(), SymCryptEcpointSetValue(), SymCryptEcurveInitialize(), SymCryptRsaCoreDec(), and SymCryptRsaCoreEnc().

◆ SymCryptModElementSetValueNegUint32()

VOID SYMCRYPT_CALL SymCryptModElementSetValueNegUint32 ( UINT32  value,
_In_ PCSYMCRYPT_MODULUS  pmMod,
_Out_ PSYMCRYPT_MODELEMENT  peDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 922 of file a_dispatch.c.

928{
929 SymCryptFdefModElementSetValueNegUint32( value, pmMod, peDst, pbScratch, cbScratch );
930}
VOID SYMCRYPT_CALL SymCryptFdefModElementSetValueNegUint32(UINT32 value, _In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_mod.c:663

Referenced by SymCryptDlkeyPerformPublicKeyValidation(), SymCryptEcurveInitialize(), SymCryptIntMillerRabinPrimalityTest(), SymCryptRsakeyCalculatePrimesFromPrivateExponent(), and SymCryptSswu().

◆ SymCryptModElementSetValueUint32()

◆ SymCryptModElementToInt()

VOID SYMCRYPT_CALL SymCryptModElementToInt ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_In_ PCSYMCRYPT_MODELEMENT  peSrc,
_Out_ PSYMCRYPT_INT  piDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 762 of file a_dispatch.c.

768{
770
771 SYMCRYPT_ASSERT( piDst->nDigits >= pmMod->nDigits );
772
773 pData = SYMCRYPT_MOD_CALL( pmMod ) modPreGet( pmMod, peSrc, pbScratch, cbScratch );
774
775 SymCryptFdefModElementToIntGeneric( pmMod, pData, piDst, pbScratch, cbScratch );
776}
VOID SYMCRYPT_CALL SymCryptFdefModElementToIntGeneric(_In_ PCSYMCRYPT_MODULUS pmMod, _In_reads_bytes_(pmMod->nDigits *SYMCRYPT_FDEF_DIGIT_SIZE) PCUINT32 pSrc, _Out_ PSYMCRYPT_INT piDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_mod.c:428
const UINT32 * PCUINT32
TW_UINT32 TW_UINT16 TW_UINT16 TW_MEMREF pData
Definition: twain.h:1830

Referenced by SymCrypt802_11SaeCustomCommitCreateGeneric(), SymCrypt802_11SaeCustomCommitProcessGeneric(), SymCrypt802_11SaeCustomInit(), SymCrypt802_11SaeCustomInitH2EGeneric(), SymCryptCrtSolve(), SymCryptDlgroupAutoCompleteNamedSafePrimeGroup(), SymCryptDlkeyGenerate(), SymCryptDsaSignEx(), SymCryptDsaVerify(), SymCryptEcDsaVerify(), SymCryptEckeySetRandom(), SymCryptEckeySetValue(), SymCryptEcpointGenericSetRandom(), SymCryptRsaCoreDecCrt(), SymCryptRsakeyCalculatePrimesFromPrivateExponent(), and SymCryptSswu().

◆ SymCryptModElementWipe()

VOID SYMCRYPT_CALL SymCryptModElementWipe ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_Out_ PSYMCRYPT_MODELEMENT  peDst 
)

Definition at line 675 of file a_dispatch.c.

678{
679 SymCryptFdefModElementWipe( pmMod, peDst );
680}
VOID SYMCRYPT_CALL SymCryptFdefModElementWipe(_In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst)
Definition: fdef_mod.c:233

◆ SymCryptModExp()

VOID SYMCRYPT_CALL SymCryptModExp ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_In_ PCSYMCRYPT_MODELEMENT  peBase,
_In_ PCSYMCRYPT_INT  piExp,
UINT32  nBitsExp,
UINT32  flags,
_Out_ PSYMCRYPT_MODELEMENT  peDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 961 of file a_dispatch.c.

970{
971 SymCryptModExpGeneric( pmMod, peBase, piExp, nBitsExp, flags, peDst, pbScratch, cbScratch );
972}
VOID SYMCRYPT_CALL SymCryptModExpGeneric(_In_ PCSYMCRYPT_MODULUS pmMod, _In_ PCSYMCRYPT_MODELEMENT peBase, _In_ PCSYMCRYPT_INT piExp, UINT32 nBitsExp, UINT32 flags, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: modexp.c:217

Referenced by rsa_decrypt(), rsa_encrypt(), SymCryptDhSecretAgreement(), SymCryptDlgroupGenerateGenG_FIPS(), SymCryptDlgroupSetValue(), SymCryptDlkeyGenerate(), SymCryptDlkeyPerformPublicKeyValidation(), SymCryptDlkeySetValue(), SymCryptDsaSignEx(), SymCryptIntMillerRabinPrimalityTest(), SymCryptModSqrt(), SymCryptRsaCoreDec(), SymCryptRsaCoreDecCrt(), SymCryptRsaCoreEnc(), SymCryptRsakeyCalculatePrimesFromPrivateExponent(), and SymCryptSswu().

◆ SymCryptModInv()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModInv ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_In_ PCSYMCRYPT_MODELEMENT  peSrc,
_Out_ PSYMCRYPT_MODELEMENT  peDst,
UINT32  flags,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 948 of file a_dispatch.c.

955{
956 return SYMCRYPT_MOD_CALL( pmMod ) modInv( pmMod, peSrc, peDst, flags, pbScratch, cbScratch );
957}

Referenced by SymCryptDsaSignEx(), SymCryptDsaVerify(), SymCryptEcDsaSignEx(), SymCryptEcDsaVerify(), SymCryptEcpointTransform(), and SymCryptSswu().

◆ SymCryptModMul()

◆ SymCryptModMultiExp()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModMultiExp ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_In_reads_(nBases) PCSYMCRYPT_MODELEMENT *  peBaseArray,
_In_reads_(nBases) PCSYMCRYPT_INT *  piExpArray,
UINT32  nBases,
UINT32  nBitsExp,
UINT32  flags,
_Out_ PSYMCRYPT_MODELEMENT  peDst,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 976 of file a_dispatch.c.

986{
987 return SymCryptModMultiExpGeneric( pmMod, peBaseArray, piExpArray, nBases, nBitsExp, flags, peDst, pbScratch, cbScratch );
988}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptModMultiExpGeneric(_In_ PCSYMCRYPT_MODULUS pmMod, _In_reads_(nBases) PCSYMCRYPT_MODELEMENT *peBaseArray, _In_reads_(nBases) PCSYMCRYPT_INT *piExpArray, UINT32 nBases, UINT32 nBitsExp, UINT32 flags, _Out_ PSYMCRYPT_MODELEMENT peDst, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: modexp.c:449

Referenced by SymCryptDsaVerify().

◆ SymCryptModNeg()

◆ SymCryptModSetRandom()

VOID SYMCRYPT_CALL SymCryptModSetRandom ( _In_ PCSYMCRYPT_MODULUS  pmMod,
_Out_ PSYMCRYPT_MODELEMENT  peDst,
UINT32  flags,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 993 of file a_dispatch.c.

999{
1000 SymCryptFdefModSetRandomGeneric( pmMod, peDst, flags, pbScratch, cbScratch );
1001
1002 SYMCRYPT_MOD_CALL( pmMod ) modSetPost( pmMod, peDst, pbScratch, cbScratch );
1003}
VOID SYMCRYPT_CALL SymCryptFdefModSetRandomGeneric(_In_ PCSYMCRYPT_MODULUS pmMod, _Out_ PSYMCRYPT_MODELEMENT peDst, UINT32 flags, _Out_writes_bytes_(cbScratch) PBYTE pbScratch, SIZE_T cbScratch)
Definition: fdef_mod.c:703

Referenced by SymCrypt802_11SaeCustomSetRandMask(), SymCryptDlkeyGenerate(), SymCryptDsaSignEx(), SymCryptEckeySetRandom(), SymCryptEcpointGenericSetRandom(), SymCryptFdefModInvGeneric(), SymCryptIntMillerRabinPrimalityTest(), and SymCryptRsakeyCalculatePrimesFromPrivateExponent().

◆ SymCryptModSquare()

◆ SymCryptModSub()

◆ SymCryptModulusAllocate()

PSYMCRYPT_MODULUS SYMCRYPT_CALL SymCryptModulusAllocate ( UINT32  nDigits)

Definition at line 587 of file a_dispatch.c.

588{
589 return SymCryptFdefModulusAllocate( nDigits );
590}
PSYMCRYPT_MODULUS SYMCRYPT_CALL SymCryptFdefModulusAllocate(UINT32 nDigits)
Definition: fdef_mod.c:11

Referenced by SymCrypt802_11SaeCustomInitH2EGeneric().

◆ SymCryptModulusCopy()

VOID SymCryptModulusCopy ( _In_ PCSYMCRYPT_MODULUS  pmSrc,
_Out_ PSYMCRYPT_MODULUS  pmDst 
)

Definition at line 626 of file a_dispatch.c.

629{
630 SymCryptFdefModulusCopy( pmSrc, pmDst );
631}
VOID SymCryptFdefModulusCopy(_In_ PCSYMCRYPT_MODULUS pmSrc, _Out_ PSYMCRYPT_MODULUS pmDst)
Definition: fdef_mod.c:124

◆ SymCryptModulusCreate()

PSYMCRYPT_MODULUS SYMCRYPT_CALL SymCryptModulusCreate ( _Out_writes_bytes_(cbBuffer) PBYTE  pbBuffer,
SIZE_T  cbBuffer,
UINT32  nDigits 
)

Definition at line 608 of file a_dispatch.c.

612{
613 return SymCryptFdefModulusCreate( pbBuffer, cbBuffer, nDigits );
614}
PSYMCRYPT_MODULUS SYMCRYPT_CALL SymCryptFdefModulusCreate(_Out_writes_bytes_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, UINT32 nDigits)
Definition: fdef_mod.c:67

Referenced by SymCryptDlgroupAutoCompleteNamedSafePrimeGroup(), SymCryptDlgroupCreate(), SymCryptDlgroupGenerate(), SymCryptDlgroupSetValue(), SymCryptDlgroupSetValueSafePrime(), SymCryptEcurveInitialize(), SymCryptIntMillerRabinPrimalityTest(), SymCryptRsakeyCreate(), and SymCryptRsakeyCreateAllObjects().

◆ SymCryptModulusDigitsizeOfObject()

UINT32 SYMCRYPT_CALL SymCryptModulusDigitsizeOfObject ( _In_ PCSYMCRYPT_MODULUS  pmSrc)

◆ SymCryptModulusFree()

VOID SYMCRYPT_CALL SymCryptModulusFree ( _Out_ PSYMCRYPT_MODULUS  pmObj)

Definition at line 594 of file a_dispatch.c.

595{
597}
VOID SYMCRYPT_CALL SymCryptFdefModulusFree(_Out_ PSYMCRYPT_MODULUS pmObj)
Definition: fdef_mod.c:41

Referenced by SymCrypt802_11SaeCustomInitH2EGeneric().

◆ SymCryptModulusWipe()

VOID SYMCRYPT_CALL SymCryptModulusWipe ( _Out_ PSYMCRYPT_MODULUS  pmObj)

Definition at line 618 of file a_dispatch.c.

619{
620 SYMCRYPT_CHECK_MAGIC( pmObj );
621
622 SymCryptWipe( pmObj, pmObj->cbSize );
623}

Referenced by SymCryptDlgroupSetValue(), and SymCryptFdefModulusFree().

◆ SymCryptRngAesGenerateSmall()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRngAesGenerateSmall ( _Inout_ PSYMCRYPT_RNG_AES_STATE  pRngState,
_Out_writes_(cbRandom) PBYTE  pbRandom,
SIZE_T  cbRandom,
_In_reads_opt_(cbAdditionalInput) PCBYTE  pbAdditionalInput,
SIZE_T  cbAdditionalInput 
)

Definition at line 436 of file aesCtrDrbg.c.

446{
450
451 //
452 // SP 800-90 9.3.1 requires a check on the length of the request.
453 //
454 if( cbRandom > SYMCRYPT_RNG_AES_MAX_REQUEST_SIZE )
455 {
456 return SYMCRYPT_WRONG_DATA_SIZE;
457 }
458 //
459 // The requestCounter test is useless as it can never happen. (It would require
460 // 2^48 calls to this function to trigger this error.)
461 // Unfortunately, SP800-90 section 11 requires a test of this error, so we have
462 // to implement the error.
463 //
464 if( pRngState->requestCounter > SYMCRYPT_RNG_AES_MAX_REQUESTS_PER_RESEED )
465 {
466 return SYMCRYPT_FIPS_FAILURE;
467 }
468
469 if( pbAdditionalInput != NULL )
470 {
471 // Update additional input using Derivation function
472 SymCryptRngAesDf( pbAdditionalInput, cbAdditionalInput, abSeed );
473 pbAdditionalInput = &abSeed[0];
474
475 // Update state with modified additional input
476 SymCryptRngAesUpdate( pRngState, pbAdditionalInput, NULL );
477 }
478
479 SymCryptAesExpandKeyEncryptOnly( &aesKey, pRngState->keyAndV, SYMCRYPT_RNG_AES_KEY_SIZE );
480
481 if( cbRandom >= SYMCRYPT_AES_BLOCK_SIZE )
482 {
483 SIZE_T wholeBlocks = cbRandom & ~(SYMCRYPT_AES_BLOCK_SIZE - 1);
485 &pRngState->keyAndV[ SYMCRYPT_RNG_AES_KEY_SIZE],
486 pbRandom,
487 wholeBlocks );
488 if( pRngState->fips140_2Check )
489 {
490 SymCryptRngAesCheckBlocksNotIdentical( pRngState->previousBlock, pbRandom, wholeBlocks );
491 }
492 pbRandom += wholeBlocks;
493 cbRandom -= wholeBlocks;
494 }
495
496 if( cbRandom > 0 )
497 {
500 &pRngState->keyAndV[ SYMCRYPT_RNG_AES_KEY_SIZE],
501 buf,
502 sizeof( buf ) );
503 if( pRngState->fips140_2Check )
504 {
505 SymCryptRngAesCheckBlocksNotIdentical( pRngState->previousBlock, buf, sizeof( buf ) );
506 }
507
508 memcpy( pbRandom, buf, cbRandom );
509 SymCryptWipeKnownSize( buf, sizeof( buf ) );
510 }
511
512 SymCryptRngAesUpdate( pRngState, pbAdditionalInput, &aesKey );
513
514 ++pRngState->requestCounter;
515
516 SymCryptWipeKnownSize( &aesKey, sizeof( aesKey ) );
517 SymCryptWipeKnownSize( abSeed, sizeof( abSeed ) );
518
519 return SYMCRYPT_NO_ERROR;
520}
#define SYMCRYPT_RNG_AES_MAX_REQUESTS_PER_RESEED
Definition: aesCtrDrbg.c:16
#define SYMCRYPT_RNG_AES_KEY_SIZE
Definition: aesCtrDrbg.c:13
#define SYMCRYPT_RNG_AES_MAX_REQUEST_SIZE
Definition: aesCtrDrbg.c:15
VOID SYMCRYPT_CALL SymCryptRngAesUpdate(_Inout_ PSYMCRYPT_RNG_AES_STATE pState, _In_reads_opt_(SYMCRYPT_RNG_AES_INTERNAL_SEED_SIZE) PCBYTE pbProvidedData, _In_opt_ PSYMCRYPT_AES_EXPANDED_KEY pAesKey)
Definition: aesCtrDrbg.c:380
VOID SYMCRYPT_CALL SymCryptRngAesGenerateBlocks(_In_ PSYMCRYPT_AES_EXPANDED_KEY pAesKey, _Inout_updates_(SYMCRYPT_AES_BLOCK_SIZE) PBYTE pV, _Out_writes_(cbRandom) PBYTE pbRandom, _In_ SIZE_T cbRandom)
Definition: aesCtrDrbg.c:163
VOID SYMCRYPT_CALL SymCryptRngAesCheckBlocksNotIdentical(_Inout_updates_(SYMCRYPT_AES_BLOCK_SIZE) PBYTE pbPreviousBlock, _In_reads_(cbData) PCBYTE pcbData, SIZE_T cbData)
Definition: aesCtrDrbg.c:341
VOID SYMCRYPT_CALL SymCryptRngAesDf(_In_reads_(cbData) PCBYTE pcbData, _In_ SIZE_T cbData, _Out_writes_(SYMCRYPT_RNG_AES_INTERNAL_SEED_SIZE) PBYTE pbSeed)
Definition: aesCtrDrbg.c:39
GLenum GLuint GLenum GLsizei const GLchar * buf
Definition: glext.h:7751
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptAesExpandKeyEncryptOnly(_Out_ PSYMCRYPT_AES_EXPANDED_KEY pExpandedKey, _In_reads_(cbKey) PCBYTE pbKey, SIZE_T cbKey)
Definition: aes-key.c:230
#define SYMCRYPT_AES_BLOCK_SIZE
Definition: symcrypt.h:4255
#define SYMCRYPT_ALIGN
SYMCRYPT_MAGIC_FIELD SYMCRYPT_AES_EXPANDED_KEY
#define SYMCRYPT_RNG_AES_INTERNAL_SEED_SIZE

Referenced by SymCryptRngAesGenerate(), and SymCryptRngAesTestGenerate().

◆ SymCryptRoundUpPow2Sizet()

SIZE_T SYMCRYPT_CALL SymCryptRoundUpPow2Sizet ( SIZE_T  v)

Definition at line 76 of file scsTools.c.

77{
78 SIZE_T res;
79
80 SYMCRYPT_ASSERT( v <= (SIZE_T_MAX / 2) + 1);
81 // If v is very large, then the result res might overflow.
82 // As SIZE_T is an unsigned type, the overflow is defined to
83 // be modulo 2^n for some n, and therefore we'll get res==0
84 // which will terminate the loop.
85
86 res = 1;
87 while( res < v )
88 {
89 res += res;
90
91 // Catch any overflows; should never happen but break to avoid infinite loop
92 if( res == 0 )
93 {
94 break;
95 }
96 }
97
98 return res;
99}
#define SIZE_T_MAX
Definition: dhcpd.h:91

Referenced by SymCryptRsaPkcs1Decrypt(), and SymCryptTlsCbcHmacVerifyCore().

◆ SymCryptRsaOaepApplyEncryptionPadding()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaOaepApplyEncryptionPadding ( _In_reads_bytes_(cbPlaintext) PCBYTE  pbPlaintext,
SIZE_T  cbPlaintext,
_In_ PCSYMCRYPT_HASH  hashAlgorithm,
_In_reads_bytes_(cbLabel) PCBYTE  pbLabel,
SIZE_T  cbLabel,
_In_reads_bytes_opt_(cbSeed) PCBYTE  pbSeed,
SIZE_T  cbSeed,
_Out_writes_bytes_(cbOaepFormat) PBYTE  pbOaepFormat,
SIZE_T  cbOaepFormat,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 364 of file rsa_padding.c.

376{
377 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
378
379 PVOID pHashState;
380
381 PBYTE pbSeedInternal;
382 PBYTE pbSeedMask;
383 PBYTE pbDB;
384 PBYTE pbDBMask;
385
386 SIZE_T cbDB;
387 SIZE_T cbPS;
388
389 SIZE_T cbHash = SymCryptHashResultSize( hashAlgorithm );
390 SIZE_T cbHashState = SymCryptHashStateSize( hashAlgorithm );
391
393
394 // OAEP overhead is 2 + 2 * size of hash result
395 if( cbOaepFormat < (cbPlaintext + (cbHash * 2) + 2) ||
396 ((pbSeed!=NULL) && (cbSeed>cbHash)) ||
397 ((pbSeed==NULL) && (cbSeed!=0)) )
398 {
399 scError = SYMCRYPT_INVALID_ARGUMENT;
400 goto cleanup;
401 }
402
403 cbPS = cbOaepFormat - (cbPlaintext + (cbHash * 2) + 2);
404 cbDB = cbOaepFormat - (cbHash + 1);
405
406 SYMCRYPT_ASSERT( cbScratch >= cbHashState + (cbHash * 2) + (cbDB * 2) );
407
408 pHashState = (PVOID) pbScratch;
409 pbSeedInternal = pbScratch + cbHashState;
410 pbSeedMask = pbSeedInternal + cbHash;
411 pbDB = pbSeedMask + cbHash;
412 pbDBMask = pbDB + cbDB;
413
414 // hash the label
415 SymCryptHash( hashAlgorithm, pbLabel, cbLabel, pbDB, cbHash );
416
417 SymCryptWipe(pbDB + cbHash, cbPS);
418 pbDB[cbHash + cbPS] = 0x01;
419
420 // dcl - are we quite sure that none of these numbers are under attacker control?
421 memcpy(pbDB + cbHash + cbPS + 1, pbPlaintext, cbPlaintext);
422
423 if (NULL == pbSeed)
424 {
425 // generate the random seed (same length as the hash result)
426 scError = SymCryptCallbackRandom( pbSeedInternal, cbHash );
427 if (scError != SYMCRYPT_NO_ERROR)
428 {
429 goto cleanup;
430 }
431 }
432 else
433 {
434 SymCryptWipe( pbSeedInternal, cbHash );
435 memcpy(pbSeedInternal, pbSeed, cbSeed);
436 }
437
438 // MGF(seed)
440 hashAlgorithm,
441 pHashState,
442 pbSeedInternal,
443 cbHash,
444 pbDBMask,
445 cbDB);
446
447 // set the most significant byte to 0x00
448 pbOaepFormat[0] = 0x00;
449
450 // XOR the DB and the mask MGF(seed)
451 for (UINT32 i = 0; i < cbDB; i++)
452 {
453 pbOaepFormat[cbHash + 1 + i] = pbDB[i] ^ pbDBMask[i];
454 }
455
456 // MGF(masked DB)
458 hashAlgorithm,
459 pHashState,
460 pbOaepFormat + cbHash + 1,
461 cbDB,
462 pbSeedMask,
463 cbHash);
464
465 // XOR the seed and the seed mask MGF(masked DB)
466 for (UINT32 i = 0; i < cbHash; i++)
467 {
468 pbOaepFormat[1 + i] = pbSeedInternal[i] ^ pbSeedMask[i];
469 }
470
471 scError = SYMCRYPT_NO_ERROR;
472
473cleanup:
474
475 return scError;
476}
VOID SYMCRYPT_CALL SymCryptRsaPaddingMaskGeneration(_In_ PCSYMCRYPT_HASH hashAlgorithm, _In_ PVOID pHashState, _In_reads_bytes_(cbSrc) PCBYTE pbSrc, SIZE_T cbSrc, _Out_writes_bytes_(cbDst) PBYTE pbDst, SIZE_T cbDst)
Definition: rsa_padding.c:105
SIZE_T SYMCRYPT_CALL SymCryptHashResultSize(_In_ PCSYMCRYPT_HASH pHash)
Definition: hash.c:132
VOID SYMCRYPT_CALL SymCryptHash(_In_ PCSYMCRYPT_HASH pHash, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_MIN(cbResult, pHash->resultSize)) PBYTE pbResult, SIZE_T cbResult)
Definition: hash.c:155
SIZE_T SYMCRYPT_CALL SymCryptHashStateSize(_In_ PCSYMCRYPT_HASH pHash)
Definition: hash.c:147
UINT32 cbSeed
PBYTE pbSeed
void * PVOID
Definition: typedefs.h:50

Referenced by SymCryptRsaOaepEncrypt().

◆ SymCryptRsaOaepRemoveEncryptionPadding()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaOaepRemoveEncryptionPadding ( _In_reads_bytes_(cbOAEPFormat) PCBYTE  pbOAEPFormat,
SIZE_T  cbOAEPFormat,
_In_ PCSYMCRYPT_HASH  hashAlgorithm,
_In_reads_bytes_(cbLabel) PCBYTE  pbLabel,
SIZE_T  cbLabel,
UINT32  flags,
_Out_writes_bytes_(cbPlaintext) PBYTE  pbPlaintext,
SIZE_T  cbPlaintext,
_Out_ SIZE_T *  pcbPlaintext,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 480 of file rsa_padding.c.

495{
496 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
497
498 PVOID pHashState;
499
500 PBYTE pbSeedMask;
502 PBYTE pbDBMask;
503 PBYTE pbDB;
504 PBYTE pbLabelHash;
505 UINT32 mPaddingError;
506
507 SIZE_T cbDB;
508
509 SIZE_T cnt = 0;
510
511 SIZE_T cbHashAlg = SymCryptHashResultSize( hashAlgorithm );
512 SIZE_T cbHashState = SymCryptHashStateSize( hashAlgorithm );
513
515
516 if (flags != 0)
517 {
518 scError = SYMCRYPT_INVALID_ARGUMENT;
519 goto cleanup;
520 }
521
522 // check if the most significant byte is set to 0x00
523 mPaddingError = SymCryptMask32IsNonzeroU31( pbOAEPFormat[0] );
524
525 // Padding overhead is 2 hash values plus 2 bytes
526 if( cbOAEPFormat < (2*cbHashAlg + 2) )
527 {
528 scError = SYMCRYPT_INVALID_ARGUMENT;
529 goto cleanup;
530 }
531
532 cbDB = cbOAEPFormat - (cbHashAlg + 1);
533
534 SYMCRYPT_ASSERT( cbScratch >= cbHashState + (cbHashAlg * 3) + (cbDB * 2) );
535
536 pHashState = (PVOID) pbScratch;
537 pbSeedMask = pbScratch + cbHashState;
538 pbSeed = pbSeedMask + cbHashAlg;
539 pbDBMask = pbSeed + cbHashAlg;
540 pbDB = pbDBMask + cbDB;
541 pbLabelHash = pbDB + cbDB;
542
543 // MGF(masked DB)
545 hashAlgorithm,
546 pHashState,
547 pbOAEPFormat + cbHashAlg + 1,
548 cbDB,
549 pbSeedMask,
550 cbHashAlg);
551
552 // XOR the masked seed and the seed mask MGF(masked DB)
553 for (UINT32 i = 0; i < cbHashAlg; i++)
554 {
555 pbSeed[i] = pbOAEPFormat[1 + i] ^ pbSeedMask[i];
556 }
557
558 // MGF(seed)
560 hashAlgorithm,
561 pHashState,
562 pbSeed,
563 cbHashAlg,
564 pbDBMask,
565 cbDB);
566
567 // XOR the masked DB and the mask MGF(seed)
568 for (UINT32 i = 0; i < cbDB; i++)
569 {
570 pbDB[i] = pbOAEPFormat[cbHashAlg + 1 + i] ^ pbDBMask[i];
571 }
572
573 // hash the label
574 SymCryptHash( hashAlgorithm, pbLabel, cbLabel, pbLabelHash, cbHashAlg );
575
576 // check the label hash
577 mPaddingError |= SymCryptMask32IsZeroU31( SymCryptEqual( pbLabelHash, pbDB, cbHashAlg ) );
578
579 //
580 // At this point we have verified the leading 0 byte and the label hash, with any
581 // errors in mPaddingError. We could continue to make the entire padding removal
582 // side-channel safe like we do in the PKCS1 padding case, but that is not necessary.
583 // The side-channel only leaks data if the attacker can trigger two different behaviours
584 // and derive information from the difference.
585 // This is relatively easy to do with something like a match on 1 or 2 bytes because the
586 // chance of satisfying the check on a random input is still useful. But here we have
587 // matched 33 bytes (assuming a 32-byte hash) and the Bleichenbacher style attacks don't
588 // work beyond this point. Basically, these attacks produce ciphertexts without knowing
589 // the corresponding plaintext, and the chance of the label hash matching is something
590 // like 2^{-256}. So these ciphertexts will always fail right here, and there is no
591 // difference of behaviour that leaks data to the attacker.
592 // Thus, we can switch back to normal processing of the errors here.
593 //
594
595 if( mPaddingError != 0 )
596 {
597 scError = SYMCRYPT_INVALID_ARGUMENT;
598 goto cleanup;
599 }
600
601 // check the PS
602 for (cnt = cbHashAlg; cnt < cbDB; cnt++)
603 {
604 if (pbDB[cnt] == 0x01)
605 {
606 cnt++;
607 break;
608 }
609 else if (pbDB[cnt] != 0x00)
610 {
611 scError = SYMCRYPT_INVALID_ARGUMENT;
612 goto cleanup;
613 }
614 }
615
616 if (pbDB[cnt - 1] != 0x01)
617 {
618 scError = SYMCRYPT_INVALID_ARGUMENT;
619 goto cleanup;
620 }
621
622 // the rest is data
623 *pcbPlaintext = cbDB - cnt;
624
625 if(NULL == pbPlaintext)
626 {
627 scError = SYMCRYPT_NO_ERROR;
628 goto cleanup;
629 }
630
631 if (cbPlaintext < *pcbPlaintext)
632 {
633 scError = SYMCRYPT_BUFFER_TOO_SMALL;
634 goto cleanup;
635 }
636
637 memcpy(pbPlaintext, pbDB + cnt, *pcbPlaintext);
638
639 scError = SYMCRYPT_NO_ERROR;
640
641cleanup:
642
643 return scError;
644}
BOOLEAN SYMCRYPT_CALL SymCryptEqual(_In_reads_(cbBytes) PCBYTE pbSrc1, _In_reads_(cbBytes) PCBYTE pbSrc2, SIZE_T cbBytes)
Definition: equal.c:11
UINT32 SYMCRYPT_CALL SymCryptMask32IsNonzeroU31(UINT32 v)
Definition: scsTools.c:28
UINT32 SYMCRYPT_CALL SymCryptMask32IsZeroU31(UINT32 v)
Definition: scsTools.c:36

Referenced by SymCryptRsaOaepDecrypt().

◆ SymCryptRsaPkcs1ApplyEncryptionPadding()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPkcs1ApplyEncryptionPadding ( _In_reads_bytes_(cbPlaintext) PCBYTE  pbPlaintext,
SIZE_T  cbPlaintext,
_Out_writes_bytes_(cbPkcs1Format) PBYTE  pbPkcs1Format,
SIZE_T  cbPkcs1Format 
)

Definition at line 180 of file rsa_padding.c.

185{
186 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
187
188 // Format: 00 02 <PS> 00 <M>
189 // <PS> 8 or more padding bytes, random, all nonzero
190 // <M> message, length between 0 and cbPKCS1Format - 11.
191 // See RFC 3447 for more details.
192
193 SIZE_T cbPS;
194 SIZE_T i;
195
196 // ensure output buffer is big enough (padding has 11 bytes overhead)
197 if( cbPkcs1Format < (cbPlaintext + 11) )
198 {
199 scError = SYMCRYPT_INVALID_ARGUMENT;
200 goto cleanup;
201 }
202
203 cbPS = cbPkcs1Format - (cbPlaintext + 3);
204
205 pbPkcs1Format[0] = 0x00;
206 pbPkcs1Format[1] = PKCS_BLOCKTYPE_2;
207
208 scError = SymCryptCallbackRandom( &pbPkcs1Format[2], cbPS );
209 if( scError != SYMCRYPT_NO_ERROR )
210 {
211 goto cleanup;
212 }
213
214 // Make sure that none of the bytes in PS is zero (as per specs)
215 for( i = 0; i < cbPS; i++ )
216 {
217 while( pbPkcs1Format[2 + i] == 0x00 )
218 {
219 scError = SymCryptCallbackRandom( &pbPkcs1Format[2+i], 1 );
220 if( scError != SYMCRYPT_NO_ERROR )
221 {
222 goto cleanup;
223 }
224 }
225 }
226
227 pbPkcs1Format[2 + cbPS] = 0x00;
228
229 memcpy(pbPkcs1Format + 3 + cbPS, pbPlaintext, cbPlaintext);
230
231cleanup:
232 return scError;
233}
#define PKCS_BLOCKTYPE_2
Definition: rsa_padding.c:13

Referenced by SymCryptRsaPkcs1Encrypt().

◆ SymCryptRsaPkcs1ApplySignaturePadding()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPkcs1ApplySignaturePadding ( _In_reads_bytes_(cbHash) PCBYTE  pbHash,
SIZE_T  cbHash,
_In_reads_bytes_(cbHashOid) PCBYTE  pbHashOid,
SIZE_T  cbHashOid,
UINT32  flags,
_Out_writes_bytes_(cbPKCS1Format) PBYTE  pbPKCS1Format,
SIZE_T  cbPKCS1Format 
)

Definition at line 651 of file rsa_padding.c.

661{
662 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
663
664 SIZE_T cbEncoding;
665 SIZE_T cbPadding;
666 SIZE_T cbOidOffset;
667
668 BOOLEAN fInsertASN1 = TRUE;
669
671 {
672 scError = SYMCRYPT_INVALID_ARGUMENT;
673 goto cleanup;
674 }
675
676 // Simple check to avoid funky behavior if cbHash is close to SIZE_MAX
677 if (cbHash >= cbPKCS1Format)
678 {
679 scError = SYMCRYPT_INVALID_ARGUMENT;
680 goto cleanup;
681 }
682
683 fInsertASN1 = ((flags & SYMCRYPT_FLAG_RSA_PKCS1_NO_ASN1) == 0);
684
685 if (fInsertASN1)
686 {
687 if ( (pbHashOid!=NULL) && (cbHashOid>0) )
688 {
689 // determine the length of the ASN1 Encoding
690 // 2 sequence bytes, 1 id byte and 3 length bytes
691 cbEncoding = 6 + cbHashOid + cbHash;
692 }
693 else
694 {
695 if (cbHashOid > 0)
696 {
697 // The caller has passed a NULL hash and a non 0 size for it.
698 // We can't guess the intent, hence we fail
699 scError = SYMCRYPT_INVALID_ARGUMENT;
700 goto cleanup;
701 }
702
703 // special case for MD5 hash without OID
704 cbEncoding = 2 + cbHash;
705 }
706
707 // we don't support encodings longer than 128 bytes,
708 // with this check we know that the length of the OID as
709 // well as the length of the hash value will each fit in
710 // one byte
711 if (cbEncoding > 0x80)
712 {
713 scError = SYMCRYPT_INVALID_ARGUMENT;
714 goto cleanup;
715 }
716 }
717 else
718 {
719 cbEncoding = cbHash;
720 }
721
722 // In a few scenarios (involving small RSA keys), the new large SHA
723 // hashes are too big to be signed by the specified key.
724 // There must be at least 8 bytes of 0xff.
725 if (3 + 8 + cbEncoding > cbPKCS1Format)
726 {
727 scError = SYMCRYPT_INVALID_ARGUMENT;
728 goto cleanup;
729 }
730
731 cbPadding = cbPKCS1Format - 3 - cbEncoding;
732
733
734 // insert the block type and delimiters
735 pbPKCS1Format[0] = 0x00;
736 pbPKCS1Format[1] = 0x01;
737 pbPKCS1Format[2 + cbPadding] = 0x00;
738
739 // insert the type 1 padding
740 memset(pbPKCS1Format + 2, 0xff, cbPadding);
741
742 if (fInsertASN1)
743 {
744 cbOidOffset = 1;
745 if ( (pbHashOid!=NULL) && (cbHashOid>0) )
746 {
747 // insert the algorithm encoding
748 pbPKCS1Format[2 + cbPadding + 1] = ASN1_SEQUENCE_BYTE;
749 pbPKCS1Format[2 + cbPadding + 2] = (BYTE)cbEncoding - 2;
750
751 // insert the sequence string byte, length of the hash and the hash value
752 pbPKCS1Format[2 + cbPadding + 3] = ASN1_SEQUENCE_BYTE;
753 pbPKCS1Format[2 + cbPadding + 4] = (BYTE)cbHashOid;
754 cbOidOffset += 4;
755 memcpy(pbPKCS1Format + 2 + cbPadding + cbOidOffset, pbHashOid, cbHashOid);
756 }
757
758 // insert the octet string byte, length of the hash and the hash value
759 pbPKCS1Format[2 + cbPadding + cbOidOffset + cbHashOid] = ASN1_OCTET_STRING_BYTE;
760 pbPKCS1Format[2 + cbPadding + cbOidOffset + cbHashOid + 1] = (BYTE)cbHash;
761 memcpy(pbPKCS1Format + 2 + cbPadding + cbOidOffset + cbHashOid + 2, pbHash, cbHash);
762 }
763 else
764 {
765 memcpy(pbPKCS1Format + 3 + cbPadding, pbHash, cbHash);
766 }
767
768 scError = SYMCRYPT_NO_ERROR;
769
770cleanup:
771
772 return scError;
773}
#define ASN1_SEQUENCE_BYTE
Definition: rsa_padding.c:9
#define ASN1_OCTET_STRING_BYTE
Definition: rsa_padding.c:10
#define memset(x, y, z)
Definition: compat.h:39
static const BYTE pbHash[]
#define SYMCRYPT_FLAG_RSA_PKCS1_NO_ASN1
Definition: symcrypt.h:8671

Referenced by SymCryptRsaPkcs1CheckSignaturePadding(), and SymCryptRsaPkcs1Sign().

◆ SymCryptRsaPkcs1RemoveEncryptionPadding()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPkcs1RemoveEncryptionPadding ( _Inout_updates_bytes_(cbPkcs1Buffer) PBYTE  pbPkcs1Format,
SIZE_T  cbPkcs1Format,
SIZE_T  cbPkcs1Buffer,
_Out_writes_bytes_opt_(cbPlaintext) PBYTE  pbPlaintext,
SIZE_T  cbPlaintext,
_Out_ SIZE_T *  pcbPlaintext 
)

Definition at line 237 of file rsa_padding.c.

244{
245 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
246 UINT32 mPaddingError = 0;
247 UINT32 mBufferSizeError = 0;
248
249 UINT32 cbPlaintextResult = 0;
250 UINT32 i;
251 UINT32 mByteIsZero;
252 UINT32 mLengthFound;
253 UINT32 iFirstZero;
254 UINT32 cbPlaintextTruncated;
255
256 SYMCRYPT_ASSERT( cbPkcs1Buffer >= cbPkcs1Format );
257 SYMCRYPT_ASSERT( cbPkcs1Buffer >= 32 ); // Requirements for SymcryptScsRotateBuffer
258 SYMCRYPT_ASSERT( (cbPkcs1Buffer & (cbPkcs1Buffer - 1)) == 0 ); // must be a power of 2
259 SYMCRYPT_ASSERT( cbPkcs1Buffer <= (1 << 30 )); // Ensure we can use 31-bit masking operations
260
261 // Format: 00 02 <PS> 00 <M>
262 // <PS> 8 or more padding bytes, random, all nonzero
263 // <M> message, length between 0 and cbPKCS1Format - 11.
264 // See RFC 3447 for more details.
265 // We do not reveal the buffer contents through side-channels to avoid Bleichenbacher-style attacks
266 // This includes the plaintext length, which is determined by the location of the 00 byte
267
268 if ( cbPkcs1Format < 11 )
269 {
270 // cbPKCS1Format is public, so the if() is safe. 11 is the total overhead
271 scError = SYMCRYPT_INVALID_ARGUMENT;
272 goto cleanup;
273 }
274 // this also implies that cbPkcs1Buffer >= 16
275
276 // Check the leading bytes
277 mPaddingError |= SymCryptMask32IsNonzeroU31( pbPkcs1Format[0] ); // First byte must be = 0
278 mPaddingError |= SymCryptMask32NeqU31( pbPkcs1Format[1], PKCS_BLOCKTYPE_2 ); // Second byte must be = 2
279
280 iFirstZero = 0;
281 mLengthFound = 0;
282 for (i = 2; i < cbPkcs1Format; i++)
283 {
284 mByteIsZero = SymCryptMask32IsZeroU31( pbPkcs1Format[i] );
285
286 // remember the index of the first zero byte
287 iFirstZero |= i & mByteIsZero & ~mLengthFound;
288 mLengthFound |= mByteIsZero;
289 }
290 mPaddingError |= ~mLengthFound;
291
292 // At this point:
293 // - iFirstZero points to the first zero byte, or is 0 if there is no zero byte
294 // - mPaddingError is set if no zero byte was found
295
296 // It is an error if the first zero is at index < 10 as <PS> needs to be at least 8 bytes
297 mPaddingError |= SymCryptMask32LtU31( iFirstZero, 10 );
298
299 // Compute the # bytes of the message; 0 if there was a padding error
300 cbPlaintextResult = ~mPaddingError & ((UINT32)(cbPkcs1Format - iFirstZero - 1));
301
302 // We're done if the caller didn't want the actual message, but only the size.
303 // We do that before checking the size of the plaintext buffer so that callers who
304 // only want the size do not get an error.
305 if( pbPlaintext == NULL )
306 {
307 // Condition is public.
308 goto cleanup;
309 }
310
311 // Checking that the output buffer is large enough is a bit tricky as we have a SIZE_T as
312 // buffer size, but we like to work on 31-bit integers as they have better mask algorithm perf.
313 // We can truncate the SIZE_T and check for equality, which is side-channel safe.
314 cbPlaintextTruncated = ((UINT32) cbPlaintext) & 0x7fffffff; // Truncate to 31 bits
315 if( cbPlaintextTruncated == cbPlaintext )
316 {
317 // Condition is public as we write the whole plaintext buffer anyway.
318 mBufferSizeError = SymCryptMask32LtU31( cbPlaintextTruncated, cbPlaintextResult );
319 }
320
321 // The message starts at iFirstZero + 1, which is a variable location so we can't just memcpy it without
322 // revealing information through side channels.
323 // Instead we rotate the buffer left (side-channel safe) so that the message appears at the front.
324 // Rotation constant is such that the message appears at the start.
325 SymCryptScsRotateBuffer( pbPkcs1Format, cbPkcs1Buffer, (iFirstZero + 1) & (cbPkcs1Buffer - 1) );
326
327 // The ScsCopy function can copy the data to the destination buffer, but the input buffer must be
328 // as long as the output buffer. We can't just use cbPlaintext as the output buffer size, as it is
329 // unbounded. But we can limit it to cbPkcs1Format as that is the public key size and is public.
330 SymCryptScsCopy( pbPkcs1Format, cbPlaintextResult, pbPlaintext, SYMCRYPT_MIN( cbPlaintext, cbPkcs1Format ) );
331
332cleanup:
333 // Update scError with the two error masks. Padding error given highest priority.
334 scError ^= mBufferSizeError & (scError ^ SYMCRYPT_BUFFER_TOO_SMALL);
335 scError ^= mPaddingError & (scError ^ SYMCRYPT_INVALID_ARGUMENT);
336
337 *pcbPlaintext = cbPlaintextResult;
338 return scError;
339}
#define SYMCRYPT_MIN(_a, _b)
VOID SYMCRYPT_CALL SymCryptScsRotateBuffer(_Inout_updates_(cbBuffer) PBYTE pbBuffer, SIZE_T cbBuffer, SIZE_T lshift)
Definition: scsTools.c:179
UINT32 SYMCRYPT_CALL SymCryptMask32NeqU31(UINT32 a, UINT32 b)
Definition: scsTools.c:43
UINT32 SYMCRYPT_CALL SymCryptMask32LtU31(UINT32 a, UINT32 b)
Definition: scsTools.c:53
VOID SYMCRYPT_CALL SymCryptScsCopy(_In_reads_(cbDst) PCBYTE pbSrc, SIZE_T cbSrc, _Out_writes_(cbDst) PBYTE pbDst, SIZE_T cbDst)
Definition: scsTools.c:108

Referenced by SymCryptRsaPkcs1Decrypt().

◆ SymCryptRsaPkcs1VerifySignaturePadding()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPkcs1VerifySignaturePadding ( _In_reads_bytes_(cbHash) PCBYTE  pbHash,
SIZE_T  cbHash,
_In_reads_(nOIDCount) PCSYMCRYPT_OID  pHashOIDs,
_In_ SIZE_T  nOIDCount,
_In_reads_bytes_(cbPKCS1Format) PCBYTE  pbPKCS1Format,
SIZE_T  cbPKCS1Format,
UINT32  flags,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 827 of file rsa_padding.c.

839{
840 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
841 UINT32 i = 0;
842
844 SYMCRYPT_ASSERT( cbScratch >= cbPKCS1Format );
845
847 {
848 scError = SYMCRYPT_INVALID_ARGUMENT;
849 goto cleanup;
850 }
851
852 //
853 // Verify padding and the hash value
854 //
855 if (pHashOIDs)
856 {
857 for (i = 0; i < nOIDCount; i++)
858 {
860 pbHash,
861 cbHash,
862 pHashOIDs[i].pbOID,
863 pHashOIDs[i].cbOID,
864 pbPKCS1Format,
865 0,
866 pbScratch,
867 cbPKCS1Format );
868 if (scError == SYMCRYPT_NO_ERROR)
869 {
870 break;
871 }
872 }
873 }
874
875 if ((pHashOIDs == NULL ) ||
876 (scError != SYMCRYPT_NO_ERROR &&
878 {
879 // if no OID is passed in, or
880 // OID is passed in but failed verification, but OID is optional
882 pbHash,
883 cbHash,
884 NULL,
885 0,
886 pbPKCS1Format,
888 pbScratch,
889 cbPKCS1Format );
890 }
891
892cleanup:
893
894 return scError;
895}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPkcs1CheckSignaturePadding(_In_reads_bytes_(cbHash) PCBYTE pbHash, SIZE_T cbHash, _In_reads_bytes_(cbHashOid) PCBYTE pbHashOid, SIZE_T cbHashOid, _In_reads_bytes_(cbPKCS1Format) PCBYTE pbPKCS1Format, UINT32 flags, _Out_writes_bytes_(cbPKCS1Format) PBYTE pbScratch, SIZE_T cbPKCS1Format)
Definition: rsa_padding.c:780
#define SYMCRYPT_FLAG_RSA_PKCS1_OPTIONAL_HASH_OID
Definition: symcrypt.h:8672

Referenced by SymCryptRsaPkcs1Verify().

◆ SymCryptRsaPssApplySignaturePadding()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPssApplySignaturePadding ( _In_reads_bytes_(cbHash) PCBYTE  pbHash,
SIZE_T  cbHash,
_In_ PCSYMCRYPT_HASH  hashAlgorithm,
_In_reads_bytes_opt_(cbSalt) PCBYTE  pbSalt,
_In_range_(0, cbPSSFormat) SIZE_T  cbSalt,
UINT32  nBitsOfModulus,
UINT32  flags,
_Out_writes_bytes_(cbPSSFormat) PBYTE  pbPSSFormat,
SIZE_T  cbPSSFormat,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 918 of file rsa_padding.c.

933{
934 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
935
936 PVOID pHashState;
937
938 PBYTE pbMPrime;
939 PBYTE pbDB;
940 PBYTE pbDBMask;
941
942 SIZE_T cbDB;
943 SIZE_T cbMPrime;
944 SIZE_T cbPadding2;
945
946 SIZE_T dwZeroBits = 0; // Number of bits of the leftmost bit to be zeroed
947
948 SIZE_T cbHashAlg = SymCryptHashResultSize( hashAlgorithm );
949 SIZE_T cbHashState = SymCryptHashStateSize( hashAlgorithm );
950
952
953 if ((cbPSSFormat == 0) || (pbPSSFormat == NULL))
954 {
955 scError = SYMCRYPT_INVALID_ARGUMENT;
956 goto cleanup;
957 }
958
959 // Corner case of RFC 3447 for PSS:
960 // If nBitsOfModulus == 1 mod 8, then emBits = nBitsOfModulus - 1 == 0 mod 8
961 // Thus the size of the input buffer in bytes is emLen = ceil(emBits /8),
962 // one smaller than the size of the modulus. Fix this here by setting the
963 // leftmost byte of the output equal to 0.
964 if (nBitsOfModulus%8 == 1)
965 {
966 pbPSSFormat[0] = 0;
967 pbPSSFormat++;
968 cbPSSFormat--;
969 }
970
971 if ((flags!=0) ||
972 (cbPSSFormat < (cbHashAlg + cbSalt + 2)) )
973 {
974 scError = SYMCRYPT_INVALID_ARGUMENT;
975 goto cleanup;
976 }
977
978 cbDB = cbPSSFormat - (cbHashAlg + 1);
979 cbPadding2 = cbDB - cbSalt - 1;
980 cbMPrime = 8 + cbHash + cbSalt;
981
982 SYMCRYPT_ASSERT( cbScratch >= cbHashState + cbMPrime + (cbDB * 2) );
983
984 pHashState = (PVOID) pbScratch;
985 pbMPrime = pbScratch + cbHashState;
986 pbDB = pbMPrime + cbMPrime;
987 pbDBMask = pbDB + cbDB;
988
989 // set up the M Prime
990 SymCryptWipe(pbMPrime, 8);
991 memcpy(pbMPrime + 8, pbHash, cbHash);
992
993 if (NULL == pbSalt)
994 {
995 // generate the random salt
996 scError = SymCryptCallbackRandom(
997 pbMPrime + 8 + cbHash,
998 cbSalt);
999 if (scError != SYMCRYPT_NO_ERROR)
1000 {
1001 goto cleanup;
1002 }
1003 }
1004 else
1005 {
1006 // copy the salt passed
1007 memcpy(pbMPrime + 8 + cbHash, pbSalt, cbSalt);
1008 }
1009
1010 // hash the MPrime
1011 SymCryptHash( hashAlgorithm, pbMPrime, cbMPrime, pbPSSFormat + cbDB, cbHashAlg );
1012
1013 // copy the same salt into the DB
1014 SymCryptWipe(pbDB, cbPadding2);
1015 pbDB[cbPadding2] = 0x01;
1016 memcpy(pbDB + cbPadding2 + 1, pbMPrime + 8 + cbHash, cbSalt);
1017
1018 // MGF(Hash of MPrime)
1020 hashAlgorithm,
1021 pHashState,
1022 pbPSSFormat + cbDB,
1023 cbHashAlg,
1024 pbDBMask,
1025 cbDB);
1026
1027 // XOR the DB and the mask MGF(seed)
1028 for (UINT32 i = 0; i < cbDB; i++)
1029 {
1030 pbPSSFormat[i] = pbDB[i] ^ pbDBMask[i];
1031 }
1032
1033 // calculate the number of bits to be zeroed
1034 dwZeroBits = 8*cbPSSFormat + 1 - nBitsOfModulus;
1035
1036 // mask off dwZeroBits worth of the encoded message
1037 pbPSSFormat[0] &= (BYTE)(0xff >> dwZeroBits);
1038
1039 // set the least significant byte of pbPSSFormat to bc
1040 pbPSSFormat[cbPSSFormat - 1] = 0xbc;
1041
1042 scError = SYMCRYPT_NO_ERROR;
1043
1044cleanup:
1045
1046 return scError;
1047}
UINT32 nBitsOfModulus

Referenced by SymCryptRsaPssSign().

◆ SymCryptRsaPssVerifySignaturePadding()

SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptRsaPssVerifySignaturePadding ( _In_reads_bytes_(cbHash) PCBYTE  pbHash,
SIZE_T  cbHash,
_In_ PCSYMCRYPT_HASH  hashAlgorithm,
_In_range_(0, cbPSSFormat) SIZE_T  cbSalt,
_In_reads_bytes_(cbPSSFormat) PCBYTE  pbPSSFormat,
SIZE_T  cbPSSFormat,
UINT32  nBitsOfModulus,
UINT32  flags,
_Out_writes_bytes_(cbScratch) PBYTE  pbScratch,
SIZE_T  cbScratch 
)

Definition at line 1051 of file rsa_padding.c.

1064{
1065 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
1066
1067 PVOID pHashState;
1068
1069 PBYTE pbDBMask;
1070 PBYTE pbMPrime;
1071 PBYTE pbMPrimeHash;
1072 PCBYTE pbHashOfMPrimeIndex;
1073
1074 SIZE_T cbDB;
1075 SIZE_T cbMPrime;
1076 SIZE_T cbPadding2;
1077 SIZE_T cbSaltObserved;
1078
1079 SIZE_T dwZeroBits = 0; // Number of bits of the leftmost bit to be zeroed
1080
1081 SIZE_T cbHashAlg = SymCryptHashResultSize( hashAlgorithm );
1082 SIZE_T cbHashState = SymCryptHashStateSize( hashAlgorithm );
1083
1085
1087 (cbPSSFormat == 0) ||
1088 (pbPSSFormat == NULL))
1089 {
1090 scError = SYMCRYPT_INVALID_ARGUMENT;
1091 goto cleanup;
1092 }
1093
1094 // Corner case of RFC 3447 for PSS:
1095 // If nBitsOfModulus == 1 mod 8, then emBits = nBitsOfModulus - 1 == 0 mod 8
1096 // Thus the size of the input buffer in bytes is emLen = ceil(emBits /8),
1097 // one smaller than the size of the modulus. Fix this here by checking that the
1098 // leftmost byte of the input equals 0.
1099 if (nBitsOfModulus%8 == 1)
1100 {
1101 if (pbPSSFormat[0] != 0)
1102 {
1103 scError = SYMCRYPT_SIGNATURE_VERIFICATION_FAILURE;
1104 goto cleanup;
1105 }
1106 pbPSSFormat++;
1107 cbPSSFormat--;
1108 }
1109
1110 // calculate the number of bits to be zeroed
1111 dwZeroBits = 8*cbPSSFormat + 1 - nBitsOfModulus;
1112
1113 // check the most significant dwZeroBits bits to ensure they're zero and
1114 // check the least significant byte
1115 if( (cbPSSFormat < (cbHashAlg + cbSalt + 2)) ||
1116 (pbPSSFormat[0] & (BYTE)(0xff << (8 - dwZeroBits))) != 0 ||
1117 pbPSSFormat[cbPSSFormat - 1] != 0xbc
1118 )
1119 {
1120 scError = SYMCRYPT_SIGNATURE_VERIFICATION_FAILURE;
1121 goto cleanup;
1122 }
1123
1124 cbDB = cbPSSFormat - (cbHashAlg + 1);
1125
1126 pHashState = (PVOID) pbScratch;
1127 pbDBMask = pbScratch + cbHashState;
1128
1129 // index to hash of M Prime
1130 pbHashOfMPrimeIndex = pbPSSFormat + (cbPSSFormat - (cbHashAlg + 1));
1131
1132 // MGF(masked DB)
1134 hashAlgorithm,
1135 pHashState,
1136 pbHashOfMPrimeIndex,
1137 cbHashAlg,
1138 pbDBMask,
1139 cbDB);
1140
1141 // XOR the DB and the DB mask and store the result in pbDBMask (not needed after this)
1142 for (UINT32 i = 0; i < cbDB; i++)
1143 {
1144 pbDBMask[i] = pbPSSFormat[i] ^ pbDBMask[i];
1145 }
1146
1147 // mask off the first dwZeroBits
1148 pbDBMask[0] &= (BYTE)(0xff >> dwZeroBits);
1149
1150 // find the length of the all-zeroes padding2 in pbDBMask
1151 // padding2 must be terminated by a 0x01 byte
1152 for (cbPadding2 = 0; cbPadding2 < (cbDB - cbSalt); cbPadding2++)
1153 {
1154 if (pbDBMask[cbPadding2] == 0x01)
1155 {
1156 // we have reached the end of padding2
1157 break;
1158 }
1159
1160 if (pbDBMask[cbPadding2] != 0x00)
1161 {
1162 // non-zero byte in what should be padding2
1163 scError = SYMCRYPT_SIGNATURE_VERIFICATION_FAILURE;
1164 goto cleanup;
1165 }
1166 }
1167
1168 // Here we have either:
1169 // cbPadding2 == cbDB - cbSalt, which means the padding is too long
1170 // or
1171 // cbPadding2 <= cbDB - cbSalt - 1, and we have broken out of the loop when we found the 0x01 byte
1172 if( cbPadding2 == cbDB - cbSalt )
1173 {
1174 scError = SYMCRYPT_SIGNATURE_VERIFICATION_FAILURE;
1175 goto cleanup;
1176 }
1177
1178 cbSaltObserved = cbDB - cbPadding2 - 1;
1179 // cbSalt <= cbDB - cbPadding2 - 1 = cbSaltObserved
1180 // so cbSaltObserved is acceptable value for signature verification
1181 // with SYMCRYPT_FLAG_RSA_PSS_VERIFY_WITH_MINIMUM_SALT
1182
1184 cbSaltObserved != cbSalt )
1185 {
1186 // When SYMCRYPT_FLAG_RSA_PSS_VERIFY_WITH_MINIMUM_SALT not specified,
1187 // we require salt length observed to exactly match the caller provided salt length
1188 scError = SYMCRYPT_SIGNATURE_VERIFICATION_FAILURE;
1189 goto cleanup;
1190 }
1191
1192 pbMPrime = pbDBMask + cbDB;
1193 cbMPrime = 8 + cbHash + cbSaltObserved;
1194 pbMPrimeHash = pbMPrime + cbMPrime;
1195
1196 SYMCRYPT_ASSERT( cbScratch >= cbHashState + cbDB + cbMPrime + cbHashAlg );
1197
1198 // create the M Prime
1199 SymCryptWipe(pbMPrime, 8);
1200 memcpy(pbMPrime + 8, pbHash, cbHash);
1201 memcpy(pbMPrime + 8 + cbHash,
1202 pbDBMask + (cbDB - cbSaltObserved),
1203 cbSaltObserved);
1204
1205 // hash the M Prime
1206 SymCryptHash( hashAlgorithm, pbMPrime, cbMPrime, pbMPrimeHash, cbHashAlg );
1207
1208 if ( !SymCryptEqual(pbPSSFormat + cbDB, pbMPrimeHash, cbHashAlg) )
1209 {
1210 scError = SYMCRYPT_SIGNATURE_VERIFICATION_FAILURE;
1211 goto cleanup;
1212 }
1213
1214 scError = SYMCRYPT_NO_ERROR;
1215
1216cleanup:
1217 return scError;
1218}
#define SYMCRYPT_FLAG_RSA_PSS_VERIFY_WITH_MINIMUM_SALT
Definition: symcrypt.h:8674

Referenced by SymCryptRsaPssVerify().

◆ SymCryptScsCopy()

VOID SYMCRYPT_CALL SymCryptScsCopy ( _In_reads_(cbDst) PCBYTE  pbSrc,
SIZE_T  cbSrc,
_Out_writes_(cbDst) PBYTE  pbDst,
SIZE_T  cbDst 
)

Definition at line 108 of file scsTools.c.

122{
123 UINT32 i;
124
125 SYMCRYPT_ASSERT( cbSrc <= (1UL << 31) && cbDst <= (1UL << 31) );
126
127 // Loop over the destination buffer and update each byte with the source data (if appropriate)
128 // We round-robin loop over the source buffer
129 for( i = 0; i < cbDst; i++ )
130 {
131 pbDst[ i ] ^= (pbSrc[ i ] ^ pbDst[ i ]) & SymCryptMask32LtU31( i, (UINT32) cbSrc );
132 }
133}
UINT32 SYMCRYPT_CALL SymCryptMask32LtU31(UINT32 a, UINT32 b)
Definition: scsTools.c:53

Referenced by SymCryptMlKemDecapsulate(), and SymCryptRsaPkcs1RemoveEncryptionPadding().

◆ SymCryptScsRotateBuffer()

VOID SYMCRYPT_CALL SymCryptScsRotateBuffer ( _Inout_updates_(cbBuffer) PBYTE  pbBuffer,
SIZE_T  cbBuffer,
SIZE_T  lshift 
)

Definition at line 179 of file scsTools.c.

183{
184 NATIVE_UINT * pBuf;
185 UINT32 n;
186 UINT32 a;
187 UINT32 b;
188 UINT32 i;
189 UINT32 j;
190 UINT32 blockSize;
191 UINT32 blockSizeLog;
192 UINT32 blockSizeLimit;
193
201 NATIVE_UINT M0;
202 NATIVE_UINT M1;
203
204 NATIVE_UINT Mask[ 16 ]; // Size must be a power of 2
205
207 SYMCRYPT_ASSERT( lshift < cbBuffer );
208
209 pBuf = (NATIVE_UINT *) pbBuffer;
211
212 // First a rotate left by lshift % NATIVE_BYTES
213 // This is more complex because shifting by NATIVE_BITS is not a defined operation, and behavior is different
214 // on different CPUs.
215
216 // Compute the shift amounts & mask
217 // M = 0 if lshift % NATIVE_BYTES == 0, -1 otherwise
218 a = 8 * (lshift & (NATIVE_BYTES-1)); // Core shift
219 M = (-(NATIVE_INT)a) >> (NATIVE_BITS - 1); // mask
220 b = (NATIVE_BITS - a) & (UINT32) M; // complementary shift, or 0 if it would be equal to NATIVE_BITS
221
222 i = n;
223 V = pBuf[0];
224 do{
225 // Loop invariant: i > 0 && v = pBuf[i] from before any changes;
226 i--;
227 T = pBuf[i];
228 pBuf[i] = T >> a | ((V << b) & M);
229 V = T;
230 } while( i > 0 );
231
232 // Now that the rotation is word-aligned, we can start our word rotation
233 lshift >>= NATIVE_BYTES_LOG2; // convert to # words to rotate.
234
235 // We know we have at least 4 words, so we start with a pass do do 4-word rotations
236 SYMCRYPT_ASSERT( n >= 4 );
237
238 M = -(NATIVE_INT)(lshift & 1);
239 M0 = -(NATIVE_INT)( ((lshift + 0) >> 1) & 1 ); // s + 0 mod 4 >= 2
240 M1 = -(NATIVE_INT)( ((lshift + 1) >> 1) & 1 ); // s + 1 mod 4 >= 2
241
242 for( i=0; i<n; i+=4 )
243 {
244 A = pBuf[i];
245 B = pBuf[i+1];
246 C = pBuf[i+2];
247 D = pBuf[i+3];
248
249 T = (A ^ B) & M;
250 A ^= T;
251 B ^= T;
252
253 T = (C ^ D) & M;
254 C ^= T;
255 D ^= T;
256
257 T = (A ^ C) & M0;
258 A ^= T;
259 C ^= T;
260
261 T = (B ^ D) & M1;
262 B ^= T;
263 D ^= T;
264
265 pBuf[i ] = A;
266 pBuf[i+1] = B;
267 pBuf[i+2] = C;
268 pBuf[i+3] = D;
269 }
270
271 // Do the swaps using the mask array
272 blockSize = 4; // size of rotated blocks
273 blockSizeLog = 2;
274
275 //
276 // Using the mask array is beneficial as long as the array is used twice or more
277 // Each swap loop processes 2 * blockSize of data, so the block size should never
278 // be larger than n/4
279 blockSizeLimit = SYMCRYPT_MIN( SYMCRYPT_ARRAY_SIZE( Mask ), n/4 );
280 while( blockSize <= blockSizeLimit )
281 {
282 // Compute the masks for this level
283 for( i=0; i<blockSize; i++ )
284 {
285 Mask[i] =-(NATIVE_INT)( ((i + lshift) >> blockSizeLog) & 1);
286 }
287
288 // Now swap the elements of pairs of blocks according to the masks
289 for( i=0; i < n; i += 2 * blockSize )
290 {
291 for( j=0; j < blockSize; j++ )
292 {
293 A = pBuf[ i + j ];
294 B = pBuf[ i + j + blockSize ];
295 T = (A ^ B) & Mask[j];
296 A ^= T;
297 B ^= T;
298 pBuf[ i + j ] = A;
299 pBuf[ i + j + blockSize ] = B;
300 }
301 }
302 blockSize *= 2;
303 blockSizeLog += 1;
304 }
305
306 // Do the rest without using a mask array, either because we are only
307 // going to use each mask value once, or because we don't have a large-enough
308 // array
309 while( blockSize < n )
310 {
311 // Now swap the elements of pairs of blocks according to the masks
312 for( i=0; i < n; i += 2 * blockSize )
313 {
314 for( j=0; j < blockSize; j++ )
315 {
316 M = -(NATIVE_INT)( ((j + lshift) >> blockSizeLog) & 1);
317 A = pBuf[ i + j ];
318 B = pBuf[ i + j + blockSize ];
319 T = (A ^ B) & M;
320 A ^= T;
321 B ^= T;
322 pBuf[ i + j ] = A;
323 pBuf[ i + j + blockSize ] = B;
324 }
325 }
326 blockSize *= 2;
327 blockSizeLog += 1;
328 }
329
330}
#define D(d)
Definition: builtin.c:4557
#define C(c)
Definition: builtin.c:4556
Definition: ehthrow.cxx:93
Definition: ehthrow.cxx:54
Definition: terminate.cpp:24
#define A(row, col)
#define B(row, col)
#define M(row, col)
unsigned int Mask
Definition: fpcontrol.c:82
GLdouble n
Definition: glext.h:7729
#define V(i, a, b, c, d)
Definition: jaricom.c:29
#define a
Definition: ke_i.h:78
#define b
Definition: ke_i.h:79
#define T(num)
Definition: thunks.c:311
INT32 NATIVE_INT
Definition: sc_lib.h:76
UINT32 NATIVE_UINT
Definition: sc_lib.h:77
#define NATIVE_BYTES_LOG2
Definition: sc_lib.h:80
#define NATIVE_BYTES
Definition: sc_lib.h:79
#define NATIVE_BITS
Definition: sc_lib.h:78
#define SYMCRYPT_ARRAY_SIZE(_x)
Definition: sc_lib.h:342
#define MIN_BUFFER_SIZE
Definition: scsTools.c:15

Referenced by SymCryptRsaPkcs1RemoveEncryptionPadding(), and SymCryptTlsCbcHmacVerifyCore().

◆ SymCryptScsTableInit()

UINT32 SYMCRYPT_CALL SymCryptScsTableInit ( _Out_ PSYMCRYPT_SCSTABLE  pScsTable,
UINT32  nElements,
UINT32  elementSize 
)

Definition at line 56 of file ScsTable.c.

60{
61 UINT32 groupSize;
62 UINT32 interleaveSize;
64
65 SYMCRYPT_ASSERT( nElements > 0 );
66
67#pragma warning( suppress: 4127 ) // conditional expression is constant
68 if( SYMCRYPT_CPU_AMD64 && elementSize == 128 )
69 {
70 // Highly optimized assembler mode for 1024-bit entries for RSA-2048...
71 interleaveSize = 128;
72 groupSize = 1;
73 } else {
74 // Standard C implementation
75 interleaveSize = SYMCRYPT_SCSTABLE_INTERLEAVE_SIZE;
77 }
78
79 // Right now, we limit ourselves to element sizes that are a multiple of the interleaveSize and
80 // # elements that are a multiple of the group size.
81 // We also limit ourselves to sensible input sizes
82 SYMCRYPT_ASSERT( elementSize % interleaveSize == 0 && nElements % groupSize == 0 && (elementSize | nElements) < (1 << 16) && elementSize > 0 );
83
84 cbBuffer = elementSize * nElements; // Each factor is < 2^16, so there is no overflow in the mul
85
86 pScsTable->groupSize = groupSize;
87 pScsTable->interleaveSize = interleaveSize;
88 pScsTable->nElements = nElements;
89 pScsTable->elementSize = elementSize;
90 pScsTable->cbTableData = cbBuffer;
91 pScsTable->pbTableData = NULL;
92
93 return cbBuffer;
94}
#define SYMCRYPT_SCSTABLE_INTERLEAVE_SIZE
Definition: ScsTable.c:49
#define SYMCRYPT_SCSTABLE_GROUP_SIZE
Definition: ScsTable.c:50
#define SYMCRYPT_CPU_AMD64

Referenced by SymCryptModExpWindowed().

◆ SymCryptScsTableLoad()

VOID SYMCRYPT_CALL SymCryptScsTableLoad ( _In_ PSYMCRYPT_SCSTABLE  pScsTable,
UINT32  iIndex,
_Out_writes_bytes_(cbData) PBYTE  pbData,
UINT32  cbData 
)

Definition at line 358 of file ScsTable.c.

363{
364 // This is the side-channel safe routine
365
366#if SYMCRYPT_CPU_AMD64
367
368 if( pScsTable->elementSize == 128 )
369 {
370 SymCryptScsTableLoad128Xmm( pScsTable, iIndex, pbData, cbData );
371 } else {
372 SymCryptScsTableLoadC( pScsTable, iIndex, pbData, cbData );
373 }
374
375#else
376
377 SymCryptScsTableLoadC( pScsTable, iIndex, pbData, cbData );
378
379#endif
380}
VOID SYMCRYPT_CALL SymCryptScsTableLoadC(_In_ PSYMCRYPT_SCSTABLE pScsTable, UINT32 iIndex, _Out_writes_bytes_(cbData) PBYTE pbData, UINT32 cbData)
Definition: ScsTable.c:185
PCBYTE PBYTE SIZE_T cbData
PCBYTE pbData

Referenced by SymCryptModExpWindowed().

◆ SymCryptScsTableSetBuffer()

VOID SYMCRYPT_CALL SymCryptScsTableSetBuffer ( _Inout_ PSYMCRYPT_SCSTABLE  pScsTable,
_Inout_updates_bytes_(cbBuffer) PBYTE  pbBuffer,
UINT32  cbBuffer 
)

Definition at line 98 of file ScsTable.c.

102{
103 SYMCRYPT_ASSERT(cbBuffer >= pScsTable->cbTableData);
105
106 pScsTable->pbTableData = pbBuffer;
107}

Referenced by SymCryptModExpWindowed().

◆ SymCryptScsTableStore()

VOID SYMCRYPT_CALL SymCryptScsTableStore ( _Inout_ PSYMCRYPT_SCSTABLE  pScsTable,
UINT32  iIndex,
_In_reads_bytes_(cbData) PCBYTE  pbData,
UINT32  cbData 
)

Definition at line 334 of file ScsTable.c.

339{
340#if SYMCRYPT_CPU_AMD64
341
342 if( pScsTable->elementSize == 128 )
343 {
344 SymCryptScsTableStore128Xmm( pScsTable, iIndex, pbData, cbData );
345 } else {
346 SymCryptScsTableStoreC( pScsTable, iIndex, pbData, cbData );
347 }
348
349#else
350
351 SymCryptScsTableStoreC( pScsTable, iIndex, pbData, cbData );
352
353#endif
354}
VOID SYMCRYPT_CALL SymCryptScsTableStoreC(_Inout_ PSYMCRYPT_SCSTABLE pScsTable, UINT32 iIndex, _In_reads_bytes_(cbData) PCBYTE pbData, UINT32 cbData)
Definition: ScsTable.c:116

Referenced by SymCryptModExpWindowed().

◆ SymCryptScsTableWipe()

VOID SYMCRYPT_CALL SymCryptScsTableWipe ( _Inout_ PSYMCRYPT_SCSTABLE  pScsTable)

Definition at line 384 of file ScsTable.c.

386{
387 SymCryptWipe( pScsTable->pbTableData, pScsTable->cbTableData );
388}

◆ SymCryptSizeofDivisorFromDigits()

◆ SymCryptSizeofEcpointFromCurve()

◆ SymCryptSizeofIntFromDigits()

UINT32 SYMCRYPT_CALL SymCryptSizeofIntFromDigits ( UINT32  nDigits)

Definition at line 134 of file a_dispatch.c.

135{
136 return SymCryptFdefSizeofIntFromDigits( nDigits );
137}
UINT32 SYMCRYPT_CALL SymCryptFdefSizeofIntFromDigits(UINT32 nDigits)
Definition: fdef_general.c:196

Referenced by rsa_decrypt(), SymCryptCrtGenerateForTwoCoprimes(), SymCryptCrtSolve(), SymCryptDlgroupAutoCompleteNamedSafePrimeGroup(), SymCryptDlgroupGenerateGenG_FIPS(), SymCryptDlgroupGeneratePrimeP_FIPS(), SymCryptDlgroupScratchSpace_FIPS(), SymCryptDlgroupSetValue(), SymCryptDlkeyGenerate(), SymCryptDlkeySetValue(), SymCryptDsaSignEx(), SymCryptDsaVerify(), SymCryptEcDsaSignEx(), SymCryptEcDsaVerify(), SymCryptEckeyCreate(), SymCryptEckeyGetValue(), SymCryptEckeySetRandom(), SymCryptEckeySetValue(), SymCryptEcpointMultiScalarMulWnafWithInterleaving(), SymCryptEcpointScalarMulFixedWindow(), SymCryptEcpointSetValue(), SymCryptEcurveValidateAndComputeSizes(), SymCryptFdefModInvGeneric(), SymCryptIntExtendedGcd(), SymCryptIntGenerateRandomPrime(), SymCryptIntMillerRabinPrimalityTest(), SymCryptMontgomeryFillScratchSpaces(), SymCryptMontgomeryPointScalarMul(), SymCryptRsaCoreDecCrt(), SymCryptRsaCoreDecCrtScratchSpace(), SymCryptRsaCoreVerifyInput(), SymCryptRsakeyCalculatePrimesFromPrivateExponent(), SymCryptRsakeyCreate(), SymCryptRsakeyCreateAllObjects(), SymCryptRsakeyGenerate(), SymCryptRsakeySetValueInternal(), SymCryptShortWeierstrassFillScratchSpaces(), SymCryptSizeofDlkeyFromDlgroup(), SymCryptSizeofEckeyFromCurve(), SymCryptSizeofRsakeyFromParams(), SymCryptTwistedEdwardsFillScratchSpaces(), and verify_input().

◆ SymCryptSizeofModElementFromModulus()

◆ SymCryptSizeofModulusFromDigits()

◆ SymCryptUint64Gcd()

UINT64 SYMCRYPT_CALL SymCryptUint64Gcd ( UINT64  a,
UINT64  b,
UINT32  flags 
)

Definition at line 12 of file gen_int.c.

13{
15 UINT64 tmp;
16 UINT64 a2;
17 UINT64 b2;
18 UINT32 i;
19
20/*
21 Algorithm outline:
22
23 if( b even )
24 swap (a,b)
25
26 loop:
27 { invariant: b is odd }
28 if( a even )
29 a = a/2
30 else
31 if a < b
32 swap (a,b)
33 a = (a - b) / 2
34
35 We ignore the data_public flag as we currently always use a side-channel safe implementation
36
37 to compute (a < b) on 64-bit values is hard if we want to avoid
38*/
41
42 // First we make sure that b is odd
43 // If b even: swap (a,b)
44 swap = ~(0 - (b & 1));
45 tmp = (a ^ b) & swap;
46 a ^= tmp;
47 b ^= tmp;
48
49 // Each loop iteration reduces len(a) + len(b) by at least 1, so looping 127 times is enough.
50 // For inputs (2^63, 2^63 + 1) we get 63 iterations to reduce a to 1, and then another 63 to get
51 // the other value to 1, plus one more to make it 0.
52 for( i=0; i < 127; i++ )
53 {
54 // Compute the result of the 'else' part of the if( a even ) into (a2, b2)
55 // First we evaluate (a < b), which is a bit tricky without access to the carry flag.
56 // a < b = (b>>63) if ((a^b) >> 63) == 1
57 // (a - b) >> 63 otherwise
58 tmp = a ^ b;
59 tmp = (tmp & b) | (~tmp & (a-b));
60 swap = 0 - (tmp >> 63);
61
62 // Now swap if a < b into (a2, b2)
63 tmp = (a ^ b) & swap;
64 a2 = a ^ tmp;
65 b2 = b ^ tmp;
66
67 //
68 a2 = (a2 - b2) / 2;
69
70 // Compute the (a is odd) condition
71 tmp = 0 - (a & 1);
72
73 // Assemble the final result
74 a = (tmp & a2) | (~tmp & a/2);
75 b = (tmp & b2) | (~tmp & b);
76 }
77
78 SYMCRYPT_ASSERT( a == 0 );
79 return b;
80}
static const struct update_accum a2
Definition: msg.c:542
static CRYPT_DATA_BLOB b2[]
Definition: msg.c:538
#define swap(a, b)
Definition: qsort.c:63

Referenced by SymCryptIntGenerateRandomPrime().