1 | /*
|
---|
2 | * Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved.
|
---|
3 | * Copyright 2014 Cryptography Research, Inc.
|
---|
4 | *
|
---|
5 | * Licensed under the Apache License 2.0 (the "License"). You may not use
|
---|
6 | * this file except in compliance with the License. You can obtain a copy
|
---|
7 | * in the file LICENSE in the source distribution or at
|
---|
8 | * https://www.openssl.org/source/license.html
|
---|
9 | *
|
---|
10 | * Originally written by Mike Hamburg
|
---|
11 | */
|
---|
12 |
|
---|
13 | #ifndef OSSL_CRYPTO_EC_CURVE448_WORD_H
|
---|
14 | # define OSSL_CRYPTO_EC_CURVE448_WORD_H
|
---|
15 |
|
---|
16 | # include <string.h>
|
---|
17 | # include <assert.h>
|
---|
18 | # include <stdlib.h>
|
---|
19 | # include <openssl/e_os2.h>
|
---|
20 | # include "curve448utils.h"
|
---|
21 |
|
---|
22 | # ifdef INT128_MAX
|
---|
23 | # include "arch_64/arch_intrinsics.h"
|
---|
24 | # else
|
---|
25 | # include "arch_32/arch_intrinsics.h"
|
---|
26 | # endif
|
---|
27 |
|
---|
28 | # if (ARCH_WORD_BITS == 64)
|
---|
29 | typedef uint64_t word_t, mask_t;
|
---|
30 | typedef uint128_t dword_t;
|
---|
31 | typedef int32_t hsword_t;
|
---|
32 | typedef int64_t sword_t;
|
---|
33 | typedef int128_t dsword_t;
|
---|
34 | # elif (ARCH_WORD_BITS == 32)
|
---|
35 | typedef uint32_t word_t, mask_t;
|
---|
36 | typedef uint64_t dword_t;
|
---|
37 | typedef int16_t hsword_t;
|
---|
38 | typedef int32_t sword_t;
|
---|
39 | typedef int64_t dsword_t;
|
---|
40 | # else
|
---|
41 | # error "For now, we only support 32- and 64-bit architectures."
|
---|
42 | # endif
|
---|
43 |
|
---|
44 | /*
|
---|
45 | * Scalar limbs are keyed off of the API word size instead of the arch word
|
---|
46 | * size.
|
---|
47 | */
|
---|
48 | # if C448_WORD_BITS == 64
|
---|
49 | # define SC_LIMB(x) (x)
|
---|
50 | # elif C448_WORD_BITS == 32
|
---|
51 | # define SC_LIMB(x) ((uint32_t)(x)),((x) >> 32)
|
---|
52 | # else
|
---|
53 | # error "For now we only support 32- and 64-bit architectures."
|
---|
54 | # endif
|
---|
55 |
|
---|
56 | /*
|
---|
57 | * The plan on booleans: The external interface uses c448_bool_t, but this
|
---|
58 | * might be a different size than our particular arch's word_t (and thus
|
---|
59 | * mask_t). Also, the caller isn't guaranteed to pass it as nonzero. So
|
---|
60 | * bool_to_mask converts word sizes and checks nonzero. On the flip side,
|
---|
61 | * mask_t is always -1 or 0, but it might be a different size than
|
---|
62 | * c448_bool_t. On the third hand, we have success vs boolean types, but
|
---|
63 | * that's handled in common.h: it converts between c448_bool_t and
|
---|
64 | * c448_error_t.
|
---|
65 | */
|
---|
66 | static ossl_inline c448_bool_t mask_to_bool(mask_t m)
|
---|
67 | {
|
---|
68 | return (c448_sword_t)(sword_t)m;
|
---|
69 | }
|
---|
70 |
|
---|
71 | static ossl_inline mask_t bool_to_mask(c448_bool_t m)
|
---|
72 | {
|
---|
73 | /* On most arches this will be optimized to a simple cast. */
|
---|
74 | mask_t ret = 0;
|
---|
75 | unsigned int i;
|
---|
76 | unsigned int limit = sizeof(c448_bool_t) / sizeof(mask_t);
|
---|
77 |
|
---|
78 | if (limit < 1)
|
---|
79 | limit = 1;
|
---|
80 | for (i = 0; i < limit; i++)
|
---|
81 | ret |= ~word_is_zero(m >> (i * 8 * sizeof(word_t)));
|
---|
82 |
|
---|
83 | return ret;
|
---|
84 | }
|
---|
85 |
|
---|
86 | #endif /* OSSL_CRYPTO_EC_CURVE448_WORD_H */
|
---|