/*
* Copyright 2002-2021 The OpenSSL Project Authors. All Rights Reserved.
*
* Licensed under the Apache License 2.0 (the "License"). You may not use
* this file except in compliance with the License. You can obtain a copy
* in the file LICENSE in the source distribution or at
* https://www.openssl.org/source/license.html
*/
#include "bn_local.h"
#include "internal/cryptlib.h"
#define BN_NIST_192_TOP (192+BN_BITS2-1)/BN_BITS2
#define BN_NIST_224_TOP (224+BN_BITS2-1)/BN_BITS2
#define BN_NIST_256_TOP (256+BN_BITS2-1)/BN_BITS2
#define BN_NIST_384_TOP (384+BN_BITS2-1)/BN_BITS2
#define BN_NIST_521_TOP (521+BN_BITS2-1)/BN_BITS2
/* pre-computed tables are "carry-less" values of modulus*(i+1) */
#if BN_BITS2 == 64
static const BN_ULONG _nist_p_192[][BN_NIST_192_TOP] = {
{0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFEULL, 0xFFFFFFFFFFFFFFFFULL},
{0xFFFFFFFFFFFFFFFEULL, 0xFFFFFFFFFFFFFFFDULL, 0xFFFFFFFFFFFFFFFFULL},
{0xFFFFFFFFFFFFFFFDULL, 0xFFFFFFFFFFFFFFFCULL, 0xFFFFFFFFFFFFFFFFULL}
};
static const BN_ULONG _nist_p_192_sqr[] = {
0x0000000000000001ULL, 0x0000000000000002ULL, 0x0000000000000001ULL,
0xFFFFFFFFFFFFFFFEULL, 0xFFFFFFFFFFFFFFFDULL, 0xFFFFFFFFFFFFFFFFULL
};
static const BN_ULONG _nist_p_224[][BN_NIST_224_TOP] = {
{0x0000000000000001ULL, 0xFFFFFFFF00000000ULL,
0xFFFFFFFFFFFFFFFFULL, 0x00000000FFFFFFFFULL},
{0x0000000000000002ULL, 0xFFFFFFFE00000000ULL,
0xFFFFFFFFFFFFFFFFULL, 0x00000001FFFFFFFFULL} /* this one is
* "carry-full" */
};
static const BN_ULONG _nist_p_224_sqr[] = {
0x0000000000000001ULL, 0xFFFFFFFE00000000ULL,
0xFFFFFFFFFFFFFFFFULL, 0x0000000200000000ULL,
0x0000000000000000ULL, 0xFFFFFFFFFFFFFFFEULL,
0xFFFFFFFFFFFFFFFFULL
};
static const BN_ULONG _nist_p_256[][BN_NIST_256_TOP] = {
{0xFFFFFFFFFFFFFFFFULL, 0x00000000FFFFFFFFULL,
0x0000000000000000ULL, 0xFFFFFFFF00000001ULL},
{0xFFFFFFFFFFFFFFFEULL, 0x00000001FFFFFFFFULL,
0x0000000000000000ULL, 0xFFFFFFFE00000002ULL},
{0xFFFFFFFFFFFFFFFDULL, 0x00000002FFFFFFFFULL,
0x0000000000000000ULL, 0xFFFFFFFD00000003ULL},
{0xFFFFFFFFFFFFFFFCULL, 0x00000003FFFFFFFFULL,
0x0000000000000000ULL, 0xFFFFFFFC00000004ULL},
{0xFFFFFFFFFFFFFFFBULL, 0x00000004FFFFFFFFULL,
0x0000000000000000ULL, 0xFFFFFFFB00000005ULL},
};
static const BN_ULONG _nist_p_256_sqr[] = {
0x0000000000000001ULL, 0xFFFFFFFE00000000ULL,
0xFFFFFFFFFFFFFFFFULL, 0x00000001FFFFFFFEULL,
0x00000001FFFFFFFEULL, 0x00000001FFFFFFFEULL,
0xFFFFFFFE00000001ULL, 0xFFFFFFFE00000002ULL
};
static const BN_ULONG _nist_p_384[][BN_NIST_384_TOP] = {
{0x00000000FFFFFFFFULL, 0xFFFFFFFF00000000ULL, 0xFFFFFFFFFFFFFFFEULL,
0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFFULL},
{0x00000001FFFFFFFEULL, 0xFFFFFFFE00000000ULL, 0xFFFFFFFFFFFFFFFDULL,
0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFFULL},
{0x00000002FFFFFFFDULL, 0xFFFFFFFD00000000ULL, 0xFFFFFFFFFFFFFFFCULL,
0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFFULL},
{0x00000003FFFFFFFCULL, 0xFFFFFFFC00000000ULL, 0xFFFFFFFFFFFFFFFBULL,
0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFFULL},
{0x00000004FFFFFFFBULL, 0xFFFFFFFB00000000ULL, 0xFFFFFFFFFFFFFFFAULL,
0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFFULL, 0xFFFFFFFFFFFFFFFFULL},
};
static const BN_ULONG _nist_p_384_sqr[] = {
0xFFFFFFFE00000001ULL