SecP128R1Field.cs 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222
  1. #if !BESTHTTP_DISABLE_ALTERNATE_SSL && (!UNITY_WEBGL || UNITY_EDITOR)
  2. #pragma warning disable
  3. using System;
  4. using System.Diagnostics;
  5. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math.Raw;
  6. namespace BestHTTP.SecureProtocol.Org.BouncyCastle.Math.EC.Custom.Sec
  7. {
  8. internal class SecP128R1Field
  9. {
  10. // 2^128 - 2^97 - 1
  11. internal static readonly uint[] P = new uint[] { 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFD };
  12. internal static readonly uint[] PExt = new uint[] { 0x00000001, 0x00000000, 0x00000000, 0x00000004, 0xFFFFFFFE,
  13. 0xFFFFFFFF, 0x00000003, 0xFFFFFFFC };
  14. private static readonly uint[] PExtInv = new uint[]{ 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFB,
  15. 0x00000001, 0x00000000, 0xFFFFFFFC, 0x00000003 };
  16. private const uint P3 = 0xFFFFFFFD;
  17. private const uint PExt7 = 0xFFFFFFFC;
  18. public static void Add(uint[] x, uint[] y, uint[] z)
  19. {
  20. uint c = Nat128.Add(x, y, z);
  21. if (c != 0 || (z[3] >= P3 && Nat128.Gte(z, P)))
  22. {
  23. AddPInvTo(z);
  24. }
  25. }
  26. public static void AddExt(uint[] xx, uint[] yy, uint[] zz)
  27. {
  28. uint c = Nat256.Add(xx, yy, zz);
  29. if (c != 0 || (zz[7] >= PExt7 && Nat256.Gte(zz, PExt)))
  30. {
  31. Nat.AddTo(PExtInv.Length, PExtInv, zz);
  32. }
  33. }
  34. public static void AddOne(uint[] x, uint[] z)
  35. {
  36. uint c = Nat.Inc(4, x, z);
  37. if (c != 0 || (z[3] >= P3 && Nat128.Gte(z, P)))
  38. {
  39. AddPInvTo(z);
  40. }
  41. }
  42. public static uint[] FromBigInteger(BigInteger x)
  43. {
  44. uint[] z = Nat128.FromBigInteger(x);
  45. if (z[3] >= P3 && Nat128.Gte(z, P))
  46. {
  47. Nat128.SubFrom(P, z);
  48. }
  49. return z;
  50. }
  51. public static void Half(uint[] x, uint[] z)
  52. {
  53. if ((x[0] & 1) == 0)
  54. {
  55. Nat.ShiftDownBit(4, x, 0, z);
  56. }
  57. else
  58. {
  59. uint c = Nat128.Add(x, P, z);
  60. Nat.ShiftDownBit(4, z, c);
  61. }
  62. }
  63. public static void Multiply(uint[] x, uint[] y, uint[] z)
  64. {
  65. uint[] tt = Nat128.CreateExt();
  66. Nat128.Mul(x, y, tt);
  67. Reduce(tt, z);
  68. }
  69. public static void MultiplyAddToExt(uint[] x, uint[] y, uint[] zz)
  70. {
  71. uint c = Nat128.MulAddTo(x, y, zz);
  72. if (c != 0 || (zz[7] >= PExt7 && Nat256.Gte(zz, PExt)))
  73. {
  74. Nat.AddTo(PExtInv.Length, PExtInv, zz);
  75. }
  76. }
  77. public static void Negate(uint[] x, uint[] z)
  78. {
  79. if (Nat128.IsZero(x))
  80. {
  81. Nat128.Zero(z);
  82. }
  83. else
  84. {
  85. Nat128.Sub(P, x, z);
  86. }
  87. }
  88. public static void Reduce(uint[] xx, uint[] z)
  89. {
  90. ulong x0 = xx[0], x1 = xx[1], x2 = xx[2], x3 = xx[3];
  91. ulong x4 = xx[4], x5 = xx[5], x6 = xx[6], x7 = xx[7];
  92. x3 += x7; x6 += (x7 << 1);
  93. x2 += x6; x5 += (x6 << 1);
  94. x1 += x5; x4 += (x5 << 1);
  95. x0 += x4; x3 += (x4 << 1);
  96. z[0] = (uint)x0; x1 += (x0 >> 32);
  97. z[1] = (uint)x1; x2 += (x1 >> 32);
  98. z[2] = (uint)x2; x3 += (x2 >> 32);
  99. z[3] = (uint)x3;
  100. Reduce32((uint)(x3 >> 32), z);
  101. }
  102. public static void Reduce32(uint x, uint[] z)
  103. {
  104. while (x != 0)
  105. {
  106. ulong c, x4 = x;
  107. c = (ulong)z[0] + x4;
  108. z[0] = (uint)c; c >>= 32;
  109. if (c != 0)
  110. {
  111. c += (ulong)z[1];
  112. z[1] = (uint)c; c >>= 32;
  113. c += (ulong)z[2];
  114. z[2] = (uint)c; c >>= 32;
  115. }
  116. c += (ulong)z[3] + (x4 << 1);
  117. z[3] = (uint)c; c >>= 32;
  118. Debug.Assert(c >= 0 && c <= 2);
  119. x = (uint)c;
  120. }
  121. }
  122. public static void Square(uint[] x, uint[] z)
  123. {
  124. uint[] tt = Nat128.CreateExt();
  125. Nat128.Square(x, tt);
  126. Reduce(tt, z);
  127. }
  128. public static void SquareN(uint[] x, int n, uint[] z)
  129. {
  130. Debug.Assert(n > 0);
  131. uint[] tt = Nat128.CreateExt();
  132. Nat128.Square(x, tt);
  133. Reduce(tt, z);
  134. while (--n > 0)
  135. {
  136. Nat128.Square(z, tt);
  137. Reduce(tt, z);
  138. }
  139. }
  140. public static void Subtract(uint[] x, uint[] y, uint[] z)
  141. {
  142. int c = Nat128.Sub(x, y, z);
  143. if (c != 0)
  144. {
  145. SubPInvFrom(z);
  146. }
  147. }
  148. public static void SubtractExt(uint[] xx, uint[] yy, uint[] zz)
  149. {
  150. int c = Nat.Sub(10, xx, yy, zz);
  151. if (c != 0)
  152. {
  153. Nat.SubFrom(PExtInv.Length, PExtInv, zz);
  154. }
  155. }
  156. public static void Twice(uint[] x, uint[] z)
  157. {
  158. uint c = Nat.ShiftUpBit(4, x, 0, z);
  159. if (c != 0 || (z[3] >= P3 && Nat128.Gte(z, P)))
  160. {
  161. AddPInvTo(z);
  162. }
  163. }
  164. private static void AddPInvTo(uint[] z)
  165. {
  166. long c = (long)z[0] + 1;
  167. z[0] = (uint)c; c >>= 32;
  168. if (c != 0)
  169. {
  170. c += (long)z[1];
  171. z[1] = (uint)c; c >>= 32;
  172. c += (long)z[2];
  173. z[2] = (uint)c; c >>= 32;
  174. }
  175. c += (long)z[3] + 2;
  176. z[3] = (uint)c;
  177. }
  178. private static void SubPInvFrom(uint[] z)
  179. {
  180. long c = (long)z[0] - 1;
  181. z[0] = (uint)c; c >>= 32;
  182. if (c != 0)
  183. {
  184. c += (long)z[1];
  185. z[1] = (uint)c; c >>= 32;
  186. c += (long)z[2];
  187. z[2] = (uint)c; c >>= 32;
  188. }
  189. c += (long)z[3] - 2;
  190. z[3] = (uint)c;
  191. }
  192. }
  193. }
  194. #pragma warning restore
  195. #endif