ed25519.h
Go to the documentation of this file.
1 /**
2  * @file ed25519.h
3  * @brief Ed25519 elliptic curve (constant-time implementation)
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2025 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneCRYPTO Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.5.0
29  **/
30 
31 #ifndef _ED25519_H
32 #define _ED25519_H
33 
34 //Dependencies
35 #include "core/crypto.h"
36 #include "ecc/eddsa.h"
37 #include "hash/sha512.h"
38 
39 //Length of Ed25519 private keys
40 #define ED25519_PRIVATE_KEY_LEN 32
41 //Length of Ed25519 public keys
42 #define ED25519_PUBLIC_KEY_LEN 32
43 //Length of Ed25519 signatures
44 #define ED25519_SIGNATURE_LEN 64
45 
46 //Ed25519ph flag
47 #define ED25519_PH_FLAG 1
48 //Prehash function output size
49 #define ED25519_PH_SIZE 64
50 
51 //C++ guard
52 #ifdef __cplusplus
53 extern "C" {
54 #endif
55 
56 
57 /**
58  * @brief Extended point representation
59  **/
60 
61 typedef struct
62 {
63  int32_t x[9];
64  int32_t y[9];
65  int32_t z[9];
66  int32_t t[9];
67 } Ed25519Point;
68 
69 
70 /**
71  * @brief Working state (scalar multiplication)
72  **/
73 
74 typedef struct
75 {
78  int32_t a[9];
79  int32_t b[9];
80  int32_t c[9];
81  int32_t d[9];
82  int32_t e[9];
83  int32_t f[9];
84  int32_t g[9];
85  int32_t h[9];
87 
88 
89 /**
90  * @brief Working state (public key generation)
91  **/
92 
93 typedef struct
94 {
96  uint8_t s[64];
100 
101 
102 /**
103  * @brief Working state (signature generation)
104  **/
105 
106 typedef struct
107 {
109  uint8_t h[64];
110  uint8_t k[64];
111  uint8_t p[32];
112  uint8_t r[32];
113  uint8_t s[32];
117 
118 
119 /**
120  * @brief Working state (signature verification)
121  **/
122 
123 typedef struct
124 {
126  uint8_t k[64];
127  uint8_t p[32];
128  uint8_t r[32];
129  uint8_t s[32];
133 
134 
135 //Ed25519 related functions
136 error_t ed25519GenerateKeyPair(const PrngAlgo *prngAlgo, void *prngContext,
137  uint8_t *privateKey, uint8_t *publicKey);
138 
139 error_t ed25519GeneratePrivateKey(const PrngAlgo *prngAlgo, void *prngContext,
140  uint8_t *privateKey);
141 
142 error_t ed25519GeneratePublicKey(const uint8_t *privateKey, uint8_t *publicKey);
143 
144 error_t ed25519GenerateSignature(const uint8_t *privateKey,
145  const uint8_t *publicKey, const void *message, size_t messageLen,
146  const void *context, uint8_t contextLen, uint8_t flag, uint8_t *signature);
147 
148 error_t ed25519GenerateSignatureEx(const uint8_t *privateKey,
149  const uint8_t *publicKey, const DataChunk *message, uint_t messageLen,
150  const void *context, uint8_t contextLen, uint8_t flag, uint8_t *signature);
151 
152 error_t ed25519VerifySignature(const uint8_t *publicKey, const void *message,
153  size_t messageLen, const void *context, uint8_t contextLen, uint8_t flag,
154  const uint8_t *signature);
155 
156 error_t ed25519VerifySignatureEx(const uint8_t *publicKey,
157  const DataChunk *message, uint_t messageLen, const void *context,
158  uint8_t contextLen, uint8_t flag, const uint8_t *signature);
159 
160 void ed25519Mul(Ed25519SubState *state, Ed25519Point *r, const uint8_t *k,
161  const Ed25519Point *p);
162 
163 void ed25519TwinMul(Ed25519SubState *state, Ed25519Point *r, const uint8_t *k1,
164  const Ed25519Point *p, const uint8_t *k2, const Ed25519Point *q);
165 
166 void ed25519Add(Ed25519SubState *state, Ed25519Point *r, const Ed25519Point *p,
167  const Ed25519Point *q);
168 
170  const Ed25519Point *p);
171 
172 void ed25519Encode(Ed25519Point *p, uint8_t *data);
173 uint32_t ed25519Decode(Ed25519Point *p, const uint8_t *data);
174 
175 void ed25519RedInt(uint8_t *r, const uint8_t *a);
176 
177 void ed25519AddInt(uint8_t *r, const uint8_t *a, const uint8_t *b, uint_t n);
178 uint8_t ed25519SubInt(uint8_t *r, const uint8_t *a, const uint8_t *b, uint_t n);
179 
180 void ed25519MulInt(uint8_t *rl, uint8_t *rh, const uint8_t *a,
181  const uint8_t *b, uint_t n);
182 
183 void ed25519CopyInt(uint8_t *a, const uint8_t *b, uint_t n);
184 
185 void ed25519SelectInt(uint8_t *r, const uint8_t *a, const uint8_t *b,
186  uint8_t c, uint_t n);
187 
188 uint8_t ed25519CompInt(const uint8_t *a, const uint8_t *b, uint_t n);
189 
190 //C++ guard
191 #ifdef __cplusplus
192 }
193 #endif
194 
195 #endif
void ed25519TwinMul(Ed25519SubState *state, Ed25519Point *r, const uint8_t *k1, const Ed25519Point *p, const uint8_t *k2, const Ed25519Point *q)
Twin multiplication.
Definition: ed25519.c:621
uint8_t b
Definition: nbns_common.h:104
Extended point representation.
Definition: ed25519.h:62
uint8_t a
Definition: ndp.h:411
error_t ed25519GenerateKeyPair(const PrngAlgo *prngAlgo, void *prngContext, uint8_t *privateKey, uint8_t *publicKey)
EdDSA key pair generation.
Definition: ed25519.c:116
uint8_t ed25519SubInt(uint8_t *r, const uint8_t *a, const uint8_t *b, uint_t n)
Subtraction of two integers.
Definition: ed25519.c:934
void ed25519CopyInt(uint8_t *a, const uint8_t *b, uint_t n)
Copy an integer.
Definition: ed25519.c:1017
#define PrngAlgo
Definition: crypto.h:973
uint8_t p
Definition: ndp.h:300
uint8_t x
Definition: lldp_ext_med.h:211
uint8_t message[]
Definition: chap.h:154
uint8_t t
Definition: lldp_ext_med.h:212
uint8_t data[]
Definition: ethernet.h:222
SHA-512 (Secure Hash Algorithm 512)
Working state (signature generation)
Definition: ed25519.h:107
error_t ed25519GeneratePublicKey(const uint8_t *privateKey, uint8_t *publicKey)
Derive the public key from an EdDSA private key.
Definition: ed25519.c:168
error_t ed25519GenerateSignatureEx(const uint8_t *privateKey, const uint8_t *publicKey, const DataChunk *message, uint_t messageLen, const void *context, uint8_t contextLen, uint8_t flag, uint8_t *signature)
EdDSA signature generation.
Definition: ed25519.c:268
uint8_t r
Definition: ndp.h:346
Ed25519SubState subState
Definition: ed25519.h:98
void ed25519RedInt(uint8_t *r, const uint8_t *a)
Reduce an integer modulo L.
Definition: ed25519.c:874
uint8_t h
Definition: ndp.h:302
uint32_t ed25519Decode(Ed25519Point *p, const uint8_t *data)
Point decoding.
Definition: ed25519.c:803
void ed25519SelectInt(uint8_t *r, const uint8_t *a, const uint8_t *b, uint8_t c, uint_t n)
Select an integer.
Definition: ed25519.c:1038
error_t
Error codes.
Definition: error.h:43
void ed25519Add(Ed25519SubState *state, Ed25519Point *r, const Ed25519Point *p, const Ed25519Point *q)
Point addition.
Definition: ed25519.c:685
Working state (scalar multiplication)
Definition: ed25519.h:75
void ed25519Encode(Ed25519Point *p, uint8_t *data)
Point encoding.
Definition: ed25519.c:773
Sha512Context sha512Context
Definition: ed25519.h:95
EdDSA (Edwards-Curve Digital Signature Algorithm)
SHA-512 algorithm context.
Definition: sha512.h:62
error_t ed25519GenerateSignature(const uint8_t *privateKey, const uint8_t *publicKey, const void *message, size_t messageLen, const void *context, uint8_t contextLen, uint8_t flag, uint8_t *signature)
EdDSA signature generation.
Definition: ed25519.c:234
General definitions for cryptographic algorithms.
void ed25519Mul(Ed25519SubState *state, Ed25519Point *r, const uint8_t *k, const Ed25519Point *p)
Scalar multiplication (regular calculation)
Definition: ed25519.c:573
Ed25519Point v
Definition: ed25519.h:77
error_t ed25519GeneratePrivateKey(const PrngAlgo *prngAlgo, void *prngContext, uint8_t *privateKey)
EdDSA private key generation.
Definition: ed25519.c:144
error_t ed25519VerifySignatureEx(const uint8_t *publicKey, const DataChunk *message, uint_t messageLen, const void *context, uint8_t contextLen, uint8_t flag, const uint8_t *signature)
EdDSA signature verification.
Definition: ed25519.c:459
Ed25519SubState subState
Definition: ed25519.h:115
uint8_t z
Definition: dns_common.h:191
Data chunk descriptor.
Definition: crypto.h:1017
Sha512Context sha512Context
Definition: ed25519.h:125
uint8_t n
void ed25519MulInt(uint8_t *rl, uint8_t *rh, const uint8_t *a, const uint8_t *b, uint_t n)
Multiplication of two integers.
Definition: ed25519.c:962
Ed25519SubState subState
Definition: ed25519.h:131
Sha512Context sha512Context
Definition: ed25519.h:108
uint8_t s
Definition: igmp_common.h:234
void ed25519AddInt(uint8_t *r, const uint8_t *a, const uint8_t *b, uint_t n)
Addition of two integers.
Definition: ed25519.c:909
void ed25519Double(Ed25519SubState *state, Ed25519Point *r, const Ed25519Point *p)
Point doubling.
Definition: ed25519.c:732
Working state (signature verification)
Definition: ed25519.h:124
unsigned int uint_t
Definition: compiler_port.h:57
Ed25519Point u
Definition: ed25519.h:76
uint8_t ed25519CompInt(const uint8_t *a, const uint8_t *b, uint_t n)
Compare integers.
Definition: ed25519.c:1064
uint8_t c
Definition: ndp.h:514
error_t ed25519VerifySignature(const uint8_t *publicKey, const void *message, size_t messageLen, const void *context, uint8_t contextLen, uint8_t flag, const uint8_t *signature)
EdDSA signature verification.
Definition: ed25519.c:427
Working state (public key generation)
Definition: ed25519.h:94