ed448.h
Go to the documentation of this file.
1 /**
2  * @file ed448.h
3  * @brief Ed448 elliptic curve (constant-time implementation)
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2025 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneCRYPTO Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.5.0
29  **/
30 
31 #ifndef _ED448_H
32 #define _ED448_H
33 
34 //Dependencies
35 #include "core/crypto.h"
36 #include "ecc/eddsa.h"
37 #include "xof/shake.h"
38 
39 //Length of Ed448 private keys
40 #define ED448_PRIVATE_KEY_LEN 57
41 //Length of Ed448 public keys
42 #define ED448_PUBLIC_KEY_LEN 57
43 //Length of Ed448 signatures
44 #define ED448_SIGNATURE_LEN 114
45 
46 //Ed448ph flag
47 #define ED448_PH_FLAG 1
48 //Prehash function output size
49 #define ED448_PH_SIZE 64
50 
51 //C++ guard
52 #ifdef __cplusplus
53 extern "C" {
54 #endif
55 
56 
57 /**
58  * @brief Projective point representation
59  **/
60 
61 typedef struct
62 {
63  int32_t x[16];
64  int32_t y[16];
65  int32_t z[16];
66 } Ed448Point;
67 
68 
69 /**
70  * @brief Working state (scalar multiplication)
71  **/
72 
73 typedef struct
74 {
77  int32_t a[16];
78  int32_t b[16];
79  int32_t c[16];
80  int32_t d[16];
81  int32_t e[16];
82  int32_t f[16];
83  int32_t g[16];
85 
86 
87 /**
88  * @brief Working state (public key generation)
89  **/
90 
91 typedef struct
92 {
97 
98 
99 /**
100  * @brief Working state (signature generation)
101  **/
102 
103 typedef struct
104 {
106  uint8_t k[114];
107  uint8_t p[57];
108  uint8_t r[57];
109  uint8_t s[57];
110  uint8_t t[57];
114 
115 
116 /**
117  * @brief Working state (signature verification)
118  **/
119 
120 typedef struct
121 {
123  uint8_t k[114];
124  uint8_t p[57];
125  uint8_t r[57];
126  uint8_t s[57];
130 
131 
132 //Ed448 related functions
133 error_t ed448GenerateKeyPair(const PrngAlgo *prngAlgo, void *prngContext,
134  uint8_t *privateKey, uint8_t *publicKey);
135 
136 error_t ed448GeneratePrivateKey(const PrngAlgo *prngAlgo, void *prngContext,
137  uint8_t *privateKey);
138 
139 error_t ed448GeneratePublicKey(const uint8_t *privateKey, uint8_t *publicKey);
140 
141 error_t ed448GenerateSignature(const uint8_t *privateKey,
142  const uint8_t *publicKey, const void *message, size_t messageLen,
143  const void *context, uint8_t contextLen, uint8_t flag, uint8_t *signature);
144 
145 error_t ed448GenerateSignatureEx(const uint8_t *privateKey,
146  const uint8_t *publicKey, const DataChunk *message, uint_t messageLen,
147  const void *context, uint8_t contextLen, uint8_t flag, uint8_t *signature);
148 
149 error_t ed448VerifySignature(const uint8_t *publicKey, const void *message,
150  size_t messageLen, const void *context, uint8_t contextLen, uint8_t flag,
151  const uint8_t *signature);
152 
153 error_t ed448VerifySignatureEx(const uint8_t *publicKey,
154  const DataChunk *message, uint_t messageLen, const void *context,
155  uint8_t contextLen, uint8_t flag, const uint8_t *signature);
156 
157 void ed448Mul(Ed448SubState *state, Ed448Point *r, const uint8_t *k,
158  const Ed448Point *p);
159 
160 void ed448TwinMul(Ed448SubState *state, Ed448Point *r, const uint8_t *k1,
161  const Ed448Point *p, const uint8_t *k2, const Ed448Point *q);
162 
163 void ed448Add(Ed448SubState *state, Ed448Point *r, const Ed448Point *p,
164  const Ed448Point *q);
165 
166 void ed448Double(Ed448SubState *state, Ed448Point *r, const Ed448Point *p);
167 
168 void ed448Encode(Ed448Point *p, uint8_t *data);
169 uint32_t ed448Decode(Ed448Point *p, const uint8_t *data);
170 
171 void ed448RedInt(uint8_t *r, const uint8_t *a);
172 
173 void ed448AddInt(uint8_t *r, const uint8_t *a, const uint8_t *b, uint_t n);
174 uint8_t ed448SubInt(uint8_t *r, const uint8_t *a, const uint8_t *b, uint_t n);
175 
176 void ed448MulInt(uint8_t *rl, uint8_t *rh, const uint8_t *a,
177  const uint8_t *b, uint_t n);
178 
179 void ed448CopyInt(uint8_t *a, const uint8_t *b, uint_t n);
180 
181 void ed448SelectInt(uint8_t *r, const uint8_t *a, const uint8_t *b,
182  uint8_t c, uint_t n);
183 
184 uint8_t ed448CompInt(const uint8_t *a, const uint8_t *b, uint_t n);
185 
186 //C++ guard
187 #ifdef __cplusplus
188 }
189 #endif
190 
191 #endif
void ed448SelectInt(uint8_t *r, const uint8_t *a, const uint8_t *b, uint8_t c, uint_t n)
Select an integer.
Definition: ed448.c:1012
void ed448Double(Ed448SubState *state, Ed448Point *r, const Ed448Point *p)
Point doubling.
Definition: ed448.c:698
Ed448SubState subState
Definition: ed448.h:112
uint8_t b
Definition: nbns_common.h:104
SHAKE128 and SHAKE256 extendable-output functions.
uint8_t a
Definition: ndp.h:411
Working state (public key generation)
Definition: ed448.h:92
#define PrngAlgo
Definition: crypto.h:973
void ed448AddInt(uint8_t *r, const uint8_t *a, const uint8_t *b, uint_t n)
Addition of two integers.
Definition: ed448.c:874
uint8_t p
Definition: ndp.h:300
uint8_t x
Definition: lldp_ext_med.h:211
uint8_t message[]
Definition: chap.h:154
uint8_t t
Definition: lldp_ext_med.h:212
uint8_t data[]
Definition: ethernet.h:222
void ed448Add(Ed448SubState *state, Ed448Point *r, const Ed448Point *p, const Ed448Point *q)
Point addition.
Definition: ed448.c:649
Working state (signature generation)
Definition: ed448.h:104
Working state (scalar multiplication)
Definition: ed448.h:74
void ed448TwinMul(Ed448SubState *state, Ed448Point *r, const uint8_t *k1, const Ed448Point *p, const uint8_t *k2, const Ed448Point *q)
Twin multiplication.
Definition: ed448.c:588
uint8_t r
Definition: ndp.h:346
Ed448SubState subState
Definition: ed448.h:95
ShakeContext shakeContext
Definition: ed448.h:122
error_t
Error codes.
Definition: error.h:43
error_t ed448VerifySignature(const uint8_t *publicKey, const void *message, size_t messageLen, const void *context, uint8_t contextLen, uint8_t flag, const uint8_t *signature)
EdDSA signature verification.
Definition: ed448.c:404
void ed448MulInt(uint8_t *rl, uint8_t *rh, const uint8_t *a, const uint8_t *b, uint_t n)
Multiplication of two integers.
Definition: ed448.c:927
void ed448Encode(Ed448Point *p, uint8_t *data)
Point encoding.
Definition: ed448.c:736
EdDSA (Edwards-Curve Digital Signature Algorithm)
General definitions for cryptographic algorithms.
SHAKE algorithm context.
Definition: shake.h:49
Ed448Point u
Definition: ed448.h:75
error_t ed448GeneratePublicKey(const uint8_t *privateKey, uint8_t *publicKey)
Derive the public key from an EdDSA private key.
Definition: ed448.c:155
uint8_t z
Definition: dns_common.h:191
ShakeContext shakeContext
Definition: ed448.h:105
Data chunk descriptor.
Definition: crypto.h:1017
uint32_t ed448Decode(Ed448Point *p, const uint8_t *data)
Point decoding.
Definition: ed448.c:765
uint8_t ed448SubInt(uint8_t *r, const uint8_t *a, const uint8_t *b, uint_t n)
Subtraction of two integers.
Definition: ed448.c:899
Ed448SubState subState
Definition: ed448.h:128
Ed448Point v
Definition: ed448.h:76
error_t ed448VerifySignatureEx(const uint8_t *publicKey, const DataChunk *message, uint_t messageLen, const void *context, uint8_t contextLen, uint8_t flag, const uint8_t *signature)
EdDSA signature verification.
Definition: ed448.c:437
error_t ed448GenerateKeyPair(const PrngAlgo *prngAlgo, void *prngContext, uint8_t *privateKey, uint8_t *publicKey)
EdDSA key pair generation.
Definition: ed448.c:103
Projective point representation.
Definition: ed448.h:62
uint8_t n
Working state (signature verification)
Definition: ed448.h:121
void ed448RedInt(uint8_t *r, const uint8_t *a)
Reduce an integer modulo L.
Definition: ed448.c:839
error_t ed448GenerateSignature(const uint8_t *privateKey, const uint8_t *publicKey, const void *message, size_t messageLen, const void *context, uint8_t contextLen, uint8_t flag, uint8_t *signature)
EdDSA signature generation.
Definition: ed448.c:223
void ed448CopyInt(uint8_t *a, const uint8_t *b, uint_t n)
Copy an integer.
Definition: ed448.c:991
uint8_t s
Definition: igmp_common.h:234
error_t ed448GenerateSignatureEx(const uint8_t *privateKey, const uint8_t *publicKey, const DataChunk *message, uint_t messageLen, const void *context, uint8_t contextLen, uint8_t flag, uint8_t *signature)
EdDSA signature generation.
Definition: ed448.c:257
unsigned int uint_t
Definition: compiler_port.h:57
void ed448Mul(Ed448SubState *state, Ed448Point *r, const uint8_t *k, const Ed448Point *p)
Scalar multiplication (regular calculation)
Definition: ed448.c:543
error_t ed448GeneratePrivateKey(const PrngAlgo *prngAlgo, void *prngContext, uint8_t *privateKey)
EdDSA private key generation.
Definition: ed448.c:131
ShakeContext shakeContext
Definition: ed448.h:93
uint8_t c
Definition: ndp.h:514
uint8_t ed448CompInt(const uint8_t *a, const uint8_t *b, uint_t n)
Compare integers.
Definition: ed448.c:1038