#include "internal/cryptlib.h"
#include "bn_local.h"
#include "internal/constant_time.h"
static ossl_inline BIGNUM *bn_mod_inverse_no_branch(BIGNUM *in,
const BIGNUM *a, const BIGNUM *n,
BN_CTX *ctx, int *pnoinv)
{
BIGNUM *A, *B, *X, *Y, *M, *D, *T, *R = NULL;
BIGNUM *ret = NULL;
int sign;
bn_check_top(a);
bn_check_top(n);
BN_CTX_start(ctx);
A = BN_CTX_get(ctx);
B = BN_CTX_get(ctx);
X = BN_CTX_get(ctx);
D = BN_CTX_get(ctx);
M = BN_CTX_get(ctx);
Y = BN_CTX_get(ctx);
T = BN_CTX_get(ctx);
if (T == NULL)
goto err;
if (in == NULL)
R = BN_new();
else
R = in;
if (R == NULL)
goto err;
if (!BN_one(X))
goto err;
BN_zero(Y);
if (BN_copy(B, a) == NULL)
goto err;
if (BN_copy(A, n) == NULL)
goto err;
A->neg = 0;
if (B->neg || (BN_ucmp(B, A) >= 0)) {
{
BIGNUM local_B;
bn_init(&local_B);
BN_with_flags(&local_B, B, BN_FLG_CONSTTIME);
if (!BN_nnmod(B, &local_B, A, ctx))
goto err;
}
}
sign = -1;
while (!BN_is_zero(B)) {
BIGNUM *tmp;
{
BIGNUM local_A;
bn_init(&local_A);
BN_with_flags(&local_A, A, BN_FLG_CONSTTIME);
if (!BN_div(D, M, &local_A, B, ctx))
goto err;
}
tmp = A;
A = B;
B = M;
if (!BN_mul(tmp, D, X, ctx))
goto err;
if (!BN_add(tmp, tmp, Y))
goto err;
M = Y;
Y = X;
X = tmp;
sign = -sign;
}
if (sign < 0) {
if (!BN_sub(Y, n, Y))
goto err;
}
if (BN_is_one(A)) {
if (!Y->neg && BN_ucmp(Y, n) < 0) {
if (!BN_copy(R, Y))
goto err;
} else {
if (!BN_nnmod(R, Y, n, ctx))
goto err;
}
} else {
*pnoinv = 1;
goto err;
}
ret = R;
*pnoinv = 0;
err:
if ((ret == NULL) && (in == NULL))
BN_free(R);
BN_CTX_end(ctx);
bn_check_top(ret);
return ret;
}
BIGNUM *int_bn_mod_inverse(BIGNUM *in,
const BIGNUM *a, const BIGNUM *n, BN_CTX *ctx,
int *pnoinv)
{
BIGNUM *A, *B, *X, *Y, *M, *D, *T, *R = NULL;
BIGNUM *ret = NULL;
int sign;
if (BN_abs_is_word(n, 1) || BN_is_zero(n)) {
*pnoinv = 1;
return NULL;
}
*pnoinv = 0;
if ((BN_get_flags(a, BN_FLG_CONSTTIME) != 0)
|| (BN_get_flags(n, BN_FLG_CONSTTIME) != 0)) {
return bn_mod_inverse_no_branch(in, a, n, ctx, pnoinv);
}
bn_check_top(a);
bn_check_top(n);
BN_CTX_start(ctx);
A = BN_CTX_get(ctx);
B = BN_CTX_get(ctx);
X = BN_CTX_get(ctx);
D = BN_CTX_get(ctx);
M = BN_CTX_get(ctx);
Y = BN_CTX_get(ctx);
T = BN_CTX_get(ctx);
if (T == NULL)
goto err;
if (in == NULL)
R = BN_new();
else
R = in;
if (R == NULL)
goto err;
if (!BN_one(X))
goto err;
BN_zero(Y);
if (BN_copy(B, a) == NULL)
goto err;
if (BN_copy(A, n) == NULL)
goto err;
A->neg = 0;
if (B->neg || (BN_ucmp(B, A) >= 0)) {
if (!BN_nnmod(B, B, A, ctx))
goto err;
}
sign = -1;
if (BN_is_odd(n) && (BN_num_bits(n) <= 2048)) {
int shift;
while (!BN_is_zero(B)) {
shift = 0;
while (!BN_is_bit_set(B, shift)) {
shift++;
if (BN_is_odd(X)) {
if (!BN_uadd(X, X, n))
goto err;
}
if (!BN_rshift1(X, X))
goto err;
}
if (shift > 0) {
if (!BN_rshift(B, B, shift))
goto err;
}
shift = 0;
while (!BN_is_bit_set(A, shift)) {
shift++;
if (BN_is_odd(Y)) {
if (!BN_uadd(Y, Y, n))
goto err;
}
if (!BN_rshift1(Y, Y))
goto err;
}
if (shift > 0) {
if (!BN_rshift(A, A, shift))
goto err;
}
if (BN_ucmp(B, A) >= 0) {
if (!BN_uadd(X, X, Y))
goto err;
if (!BN_usub(B, B, A))
goto err;
} else {
if (!BN_uadd(Y, Y, X))
goto err;
if (!BN_usub(A, A, B))
goto err;
}
}
} else {
while (!BN_is_zero(B)) {
BIGNUM *tmp;
if (BN_num_bits(A) == BN_num_bits(B)) {
if (!BN_one(D))
goto err;
if (!BN_sub(M, A, B))
goto err;
} else if (BN_num_bits(A) == BN_num_bits(B) + 1) {
if (!BN_lshift1(T, B))
goto err;
if (BN_ucmp(A, T) < 0) {
if (!BN_one(D))
goto err;
if (!BN_sub(M, A, B))
goto err;
} else {
if (!BN_sub(M, A, T))
goto err;
if (!BN_add(D, T, B))
goto err;
if (BN_ucmp(A, D) < 0) {
if (!BN_set_word(D, 2))
goto err;
} else {
if (!BN_set_word(D, 3))
goto err;
if (!BN_sub(M, M, B))
goto err;
}
}
} else {
if (!BN_div(D, M, A, B, ctx))
goto err;
}
tmp = A;
A = B;
B = M;
if (BN_is_one(D)) {
if (!BN_add(tmp, X, Y))
goto err;
} else {
if (BN_is_word(D, 2)) {
if (!BN_lshift1(tmp, X))
goto err;
} else if (BN_is_word(D, 4)) {
if (!BN_lshift(tmp, X, 2))
goto err;
} else if (D->top == 1) {
if (!BN_copy(tmp, X))
goto err;
if (!BN_mul_word(tmp, D->d[0]))
goto err;
} else {
if (!BN_mul(tmp, D, X, ctx))
goto err;
}
if (!BN_add(tmp, tmp, Y))
goto err;
}
M = Y;
Y = X;
X = tmp;
sign = -sign;
}
}
if (sign < 0) {
if (!BN_sub(Y, n, Y))
goto err;
}
if (BN_is_one(A)) {
if (!Y->neg && BN_ucmp(Y, n) < 0) {
if (!BN_copy(R, Y))
goto err;
} else {
if (!BN_nnmod(R, Y, n, ctx))
goto err;
}
} else {
*pnoinv = 1;
goto err;
}
ret = R;
err:
if ((ret == NULL) && (in == NULL))
BN_free(R);
BN_CTX_end(ctx);
bn_check_top(ret);
return ret;
}
BIGNUM *BN_mod_inverse(BIGNUM *in,
const BIGNUM *a, const BIGNUM *n, BN_CTX *ctx)
{
BN_CTX *new_ctx = NULL;
BIGNUM *rv;
int noinv = 0;
if (ctx == NULL) {
ctx = new_ctx = BN_CTX_new_ex(NULL);
if (ctx == NULL) {
ERR_raise(ERR_LIB_BN, ERR_R_BN_LIB);
return NULL;
}
}
rv = int_bn_mod_inverse(in, a, n, ctx, &noinv);
if (noinv)
ERR_raise(ERR_LIB_BN, BN_R_NO_INVERSE);
BN_CTX_free(new_ctx);
return rv;
}
int BN_are_coprime(BIGNUM *a, const BIGNUM *b, BN_CTX *ctx)
{
int ret = 0;
BIGNUM *tmp;
BN_CTX_start(ctx);
tmp = BN_CTX_get(ctx);
if (tmp == NULL)
goto end;
ERR_set_mark();
BN_set_flags(a, BN_FLG_CONSTTIME);
ret = (BN_mod_inverse(tmp, a, b, ctx) != NULL);
ERR_pop_to_mark();
end:
BN_CTX_end(ctx);
return ret;
}
int BN_gcd(BIGNUM *r, const BIGNUM *in_a, const BIGNUM *in_b, BN_CTX *ctx)
{
BIGNUM *g, *temp = NULL;
BN_ULONG pow2_numbits, pow2_numbits_temp, pow2_condition_mask, pow2_flag;
int i, j, top, rlen, glen, m, delta = 1, cond = 0, pow2_shifts, ret = 0;
if (BN_is_zero(in_b)) {
ret = BN_copy(r, in_a) != NULL;
r->neg = 0;
return ret;
}
if (BN_is_zero(in_a)) {
ret = BN_copy(r, in_b) != NULL;
r->neg = 0;
return ret;
}
bn_check_top(in_a);
bn_check_top(in_b);
BN_CTX_start(ctx);
temp = BN_CTX_get(ctx);
g = BN_CTX_get(ctx);
if (g == NULL
|| !BN_lshift1(g, in_b)
|| !BN_lshift1(r, in_a))
goto err;
pow2_flag = 1;
pow2_shifts = 0;
pow2_numbits = 0;
for (i = 0; i < r->dmax && i < g->dmax; i++) {
pow2_numbits_temp = r->d[i] | g->d[i];
pow2_condition_mask = constant_time_is_zero_bn(pow2_flag);
pow2_flag &= constant_time_is_zero_bn(pow2_numbits_temp);
pow2_shifts += pow2_flag;
pow2_numbits = constant_time_select_bn(pow2_condition_mask,
pow2_numbits, pow2_numbits_temp);
}
pow2_numbits = ~pow2_numbits;
pow2_shifts *= BN_BITS2;
pow2_flag = 1;
for (j = 0; j < BN_BITS2; j++) {
pow2_flag &= pow2_numbits;
pow2_shifts += pow2_flag;
pow2_numbits >>= 1;
}
if (!BN_rshift(r, r, pow2_shifts)
|| !BN_rshift(g, g, pow2_shifts))
goto err;
top = 1 + ((r->top >= g->top) ? r->top : g->top);
if (bn_wexpand(r, top) == NULL
|| bn_wexpand(g, top) == NULL
|| bn_wexpand(temp, top) == NULL)
goto err;
BN_consttime_swap((~r->d[0]) & 1, r, g, top);
rlen = BN_num_bits(r);
glen = BN_num_bits(g);
m = 4 + 3 * ((rlen >= glen) ? rlen : glen);
for (i = 0; i < m; i++) {
cond = ((unsigned int)-delta >> (8 * sizeof(delta) - 1)) & g->d[0] & 1
& (~((unsigned int)(g->top - 1) >> (sizeof(g->top) * 8 - 1)));
delta = (-cond & -delta) | ((cond - 1) & delta);
r->neg ^= cond;
BN_consttime_swap(cond, r, g, top);
delta++;
if (!BN_add(temp, g, r))
goto err;
BN_consttime_swap(g->d[0] & 1
& (~((unsigned int)(g->top - 1) >> (sizeof(g->top) * 8 - 1))),
g, temp, top);
if (!BN_rshift1(g, g))
goto err;
}
r->neg = 0;
if (!BN_lshift(r, r, pow2_shifts)
|| !BN_rshift1(r, r))
goto err;
ret = 1;
err:
BN_CTX_end(ctx);
bn_check_top(r);
return ret;
}