Diffstat (limited to 'frontend/gamma/js/Clipperz/Crypto/ECC/StandardCurves.js') (more/less context) (ignore whitespace changes)
-rw-r--r-- | frontend/gamma/js/Clipperz/Crypto/ECC/StandardCurves.js | 239 |
1 files changed, 239 insertions, 0 deletions
diff --git a/frontend/gamma/js/Clipperz/Crypto/ECC/StandardCurves.js b/frontend/gamma/js/Clipperz/Crypto/ECC/StandardCurves.js new file mode 100644 index 0000000..ae2b8fb --- a/dev/null +++ b/frontend/gamma/js/Clipperz/Crypto/ECC/StandardCurves.js | |||
@@ -0,0 +1,239 @@ | |||
1 | /* | ||
2 | |||
3 | Copyright 2008-2011 Clipperz Srl | ||
4 | |||
5 | This file is part of Clipperz's Javascript Crypto Library. | ||
6 | Javascript Crypto Library provides web developers with an extensive | ||
7 | and efficient set of cryptographic functions. The library aims to | ||
8 | obtain maximum execution speed while preserving modularity and | ||
9 | reusability. | ||
10 | For further information about its features and functionalities please | ||
11 | refer to http://www.clipperz.com | ||
12 | |||
13 | * Javascript Crypto Library is free software: you can redistribute | ||
14 | it and/or modify it under the terms of the GNU Affero General Public | ||
15 | License as published by the Free Software Foundation, either version | ||
16 | 3 of the License, or (at your option) any later version. | ||
17 | |||
18 | * Javascript Crypto Library is distributed in the hope that it will | ||
19 | be useful, but WITHOUT ANY WARRANTY; without even the implied | ||
20 | warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. | ||
21 | See the GNU Affero General Public License for more details. | ||
22 | |||
23 | * You should have received a copy of the GNU Affero General Public | ||
24 | License along with Javascript Crypto Library. If not, see | ||
25 | <http://www.gnu.org/licenses/>. | ||
26 | |||
27 | */ | ||
28 | |||
29 | //try { if (typeof(Clipperz.Crypto.ECC.BinaryField.Curve) == 'undefined') { throw ""; }} catch (e) { | ||
30 | //throw "Clipperz.Crypto.ECC depends on Clipperz.Crypto.ECC.BinaryField.Curve!"; | ||
31 | //} | ||
32 | //try { if (typeof(Clipperz.Crypto.ECC.Koblitz.Curve) == 'undefined') { throw ""; }} catch (e) { | ||
33 | //throw "Clipperz.Crypto.ECC depends on Clipperz.Crypto.ECC.Koblitz.Curve!"; | ||
34 | //} | ||
35 | |||
36 | Clipperz.Crypto.ECC.StandardCurves = {}; | ||
37 | |||
38 | MochiKit.Base.update(Clipperz.Crypto.ECC.StandardCurves, { | ||
39 | |||
40 | //============================================================================== | ||
41 | |||
42 | '_K571': null, | ||
43 | 'K571': function() { //f(z) = z^571 + z^10 + z^5 + z^2 + 1 | ||
44 | if ((Clipperz.Crypto.ECC.StandardCurves._K571 == null) && (typeof(Clipperz.Crypto.ECC.Koblitz.Curve) != 'undefined')) { | ||
45 | Clipperz.Crypto.ECC.StandardCurves._K571 = new Clipperz.Crypto.ECC.Koblitz.Curve({ | ||
46 | modulus: new Clipperz.Crypto.ECC.Koblitz.Value('08000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000425', 16), | ||
47 | a: new Clipperz.Crypto.ECC.Koblitz.Value('0', 16), | ||
48 | b: new Clipperz.Crypto.ECC.Koblitz.Value('1', 16), | ||
49 | G: new Clipperz.Crypto.ECC.Koblitz.Point({ | ||
50 | x: new Clipperz.Crypto.ECC.Koblitz.Value('026eb7a8 59923fbc 82189631 f8103fe4 ac9ca297 0012d5d4 60248048 01841ca4 43709584 93b205e6 47da304d b4ceb08c bbd1ba39 494776fb 988b4717 4dca88c7 e2945283 a01c8972', 16), | ||
51 | y: new Clipperz.Crypto.ECC.Koblitz.Value('0349dc80 7f4fbf37 4f4aeade 3bca9531 4dd58cec 9f307a54 ffc61efc 006d8a2c 9d4979c0 ac44aea7 4fbebbb9 f772aedc b620b01a 7ba7af1b 320430c8 591984f6 01cd4c14 3ef1c7a3', 16) | ||
52 | }), | ||
53 | r: new Clipperz.Crypto.ECC.Koblitz.Value('02000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 131850e1 f19a63e4 b391a8db 917f4138 b630d84b e5d63938 1e91deb4 5cfe778f 637c1001', 16), | ||
54 | h: new Clipperz.Crypto.ECC.Koblitz.Value('4', 16), | ||
55 | primeFactor: new Clipperz.Crypto.ECC.Koblitz.Value('02000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 131850e1 f19a63e4 b391a8db 917f4138 b630d84b e5d63938 1e91deb4 5cfe778f 637c1001', 16) | ||
56 | }); | ||
57 | } | ||
58 | |||
59 | return Clipperz.Crypto.ECC.StandardCurves._K571; | ||
60 | }, | ||
61 | |||
62 | //----------------------------------------------------------------------------- | ||
63 | |||
64 | '_K283': null, | ||
65 | 'K283': function() { //f(z) = z^283 + z^12 + z^7 + z^5 + 1 | ||
66 | if ((Clipperz.Crypto.ECC.StandardCurves._K283 == null) && (typeof(Clipperz.Crypto.ECC.Koblitz.Curve) != 'undefined')) { | ||
67 | Clipperz.Crypto.ECC.StandardCurves._K283 = new Clipperz.Crypto.ECC.Koblitz.Curve({ | ||
68 | modulus: new Clipperz.Crypto.ECC.Koblitz.Value('08000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 000010a1', 16), | ||
69 | a: new Clipperz.Crypto.ECC.Koblitz.Value('0', 16), | ||
70 | b: new Clipperz.Crypto.ECC.Koblitz.Value('1', 16), | ||
71 | G: new Clipperz.Crypto.ECC.Koblitz.Point({ | ||
72 | x: new Clipperz.Crypto.ECC.Koblitz.Value('0503213f 78ca4488 3f1a3b81 62f188e5 53cd265f 23c1567a 16876913 b0c2ac24 58492836', 16), | ||
73 | y: new Clipperz.Crypto.ECC.Koblitz.Value('01ccda38 0f1c9e31 8d90f95d 07e5426f e87e45c0 e8184698 e4596236 4e341161 77dd2259', 16) | ||
74 | }), | ||
75 | r: new Clipperz.Crypto.ECC.Koblitz.Value('01ffffff ffffffff ffffffff ffffffff ffffe9ae 2ed07577 265dff7f 94451e06 1e163c61', 16), | ||
76 | h: new Clipperz.Crypto.ECC.Koblitz.Value('4', 16), | ||
77 | primeFactor: new Clipperz.Crypto.ECC.Koblitz.Value('01ffffff ffffffff ffffffff ffffffff ffffe9ae 2ed07577 265dff7f 94451e06 1e163c61', 16) | ||
78 | }); | ||
79 | } | ||
80 | |||
81 | return Clipperz.Crypto.ECC.StandardCurves._K283; | ||
82 | }, | ||
83 | |||
84 | //============================================================================== | ||
85 | |||
86 | '_B571': null, | ||
87 | 'B571': function() { //f(z) = z^571 + z^10 + z^5 + z^2 + 1 | ||
88 | if ((Clipperz.Crypto.ECC.StandardCurves._B571 == null) && (typeof(Clipperz.Crypto.ECC.BinaryField.Curve) != 'undefined')) { | ||
89 | Clipperz.Crypto.ECC.StandardCurves._B571 = new Clipperz.Crypto.ECC.BinaryField.Curve({ | ||
90 | modulus: new Clipperz.Crypto.ECC.BinaryField.Value('08000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000425', 16), | ||
91 | a: new Clipperz.Crypto.ECC.BinaryField.Value('1', 16), | ||
92 | b: new Clipperz.Crypto.ECC.BinaryField.Value('02f40e7e 2221f295 de297117 b7f3d62f 5c6a97ff cb8ceff1 cd6ba8ce 4a9a18ad 84ffabbd 8efa5933 2be7ad67 56a66e29 4afd185a 78ff12aa 520e4de7 39baca0c 7ffeff7f 2955727a', 16), | ||
93 | G: new Clipperz.Crypto.ECC.BinaryField.Point({ | ||
94 | x: new Clipperz.Crypto.ECC.BinaryField.Value('0303001d 34b85629 6c16c0d4 0d3cd775 0a93d1d2 955fa80a a5f40fc8 db7b2abd bde53950 f4c0d293 cdd711a3 5b67fb14 99ae6003 8614f139 4abfa3b4 c850d927 e1e7769c 8eec2d19', 16), | ||
95 | y: new Clipperz.Crypto.ECC.BinaryField.Value('037bf273 42da639b 6dccfffe b73d69d7 8c6c27a6 009cbbca 1980f853 3921e8a6 84423e43 bab08a57 6291af8f 461bb2a8 b3531d2f 0485c19b 16e2f151 6e23dd3c 1a4827af 1b8ac15b', 16) | ||
96 | }), | ||
97 | r: new Clipperz.Crypto.ECC.BinaryField.Value('03ffffff ffffffff ffffffff ffffffff ffffffff ffffffff ffffffff ffffffff ffffffff e661ce18 ff559873 08059b18 6823851e c7dd9ca1 161de93d 5174d66e 8382e9bb 2fe84e47', 16), | ||
98 | h: new Clipperz.Crypto.ECC.BinaryField.Value('2', 16) | ||
99 | |||
100 | // S: new Clipperz.Crypto.ECC.BinaryField.Value('2aa058f73a0e33ab486b0f610410c53a7f132310', 10), | ||
101 | // n: new Clipperz.Crypto.ECC.BinaryField.Value('03ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffe661ce18ff55987308059b186823851ec7dd9ca1161de93d5174d66e8382e9bb2fe84e47', 16) | ||
102 | }); | ||
103 | |||
104 | //----------------------------------------------------------------------------- | ||
105 | // | ||
106 | //Guide to Elliptic Curve Cryptography | ||
107 | //Darrel Hankerson, Alfred Menezes, Scott Vanstone | ||
108 | //- Pag: 56, Alorithm 2.45 (with a typo!!!) | ||
109 | // | ||
110 | //----------------------------------------------------------------------------- | ||
111 | // | ||
112 | // http://www.milw0rm.com/papers/136 | ||
113 | // | ||
114 | // ------------------------------------------------------------------------- | ||
115 | // Polynomial Reduction Algorithm Modulo f571 | ||
116 | // ------------------------------------------------------------------------- | ||
117 | // | ||
118 | // Input: Polynomial p(x) of degree 1140 or less, stored as | ||
119 | // an array of 2T machinewords. | ||
120 | // Output: p(x) mod f571(x) | ||
121 | // | ||
122 | // FOR i = T-1, ..., 0 DO | ||
123 | // SET X := P[i+T] | ||
124 | // P[i] := P[i] ^ (X<<5) ^ (X<<7) ^ (X<<10) ^ (X<<15) | ||
125 | // P[i+1] := P[i+1] ^ (X>>17) ^ (X>>22) ^ (X>>25) ^ (X>>27) | ||
126 | // | ||
127 | // SET X := P[T-1] >> 27 | ||
128 | // P[0] := P[0] ^ X ^ (X<<2) ^ (X<<5) ^ (X<<10) | ||
129 | // P[T-1] := P[T-1] & 0x07ffffff | ||
130 | // | ||
131 | // RETURN P[T-1],...,P[0] | ||
132 | // | ||
133 | // ------------------------------------------------------------------------- | ||
134 | // | ||
135 | Clipperz.Crypto.ECC.StandardCurves._B571.finiteField().slowModule = Clipperz.Crypto.ECC.StandardCurves._B571.finiteField().module; | ||
136 | Clipperz.Crypto.ECC.StandardCurves._B571.finiteField().module = function(aValue) { | ||
137 | varresult; | ||
138 | |||
139 | if (aValue.bitSize() > 1140) { | ||
140 | MochiKit.Logging.logWarning("ECC.StandarCurves.B571.finiteField().module: falling back to default implementation"); | ||
141 | result = Clipperz.Crypto.ECC.StandardCurves._B571.finiteField().slowModule(aValue); | ||
142 | } else { | ||
143 | varC, T; | ||
144 | var i; | ||
145 | |||
146 | //console.log(">>> binaryField.finiteField.(improved)module"); | ||
147 | // C = aValue.value().slice(0); | ||
148 | C = aValue._value.slice(0); | ||
149 | for (i=35; i>=18; i--) { | ||
150 | T = C[i]; | ||
151 | C[i-18] = (((C[i-18] ^ (T<<5) ^ (T<<7) ^ (T<<10) ^ (T<<15)) & 0xffffffff) >>> 0); | ||
152 | C[i-17] = ((C[i-17] ^ (T>>>27) ^ (T>>>25) ^ (T>>>22) ^ (T>>>17)) >>> 0); | ||
153 | } | ||
154 | T = (C[17] >>> 27); | ||
155 | C[0] = ((C[0] ^ T ^ ((T<<2) ^ (T<<5) ^ (T<<10)) & 0xffffffff) >>> 0); | ||
156 | C[17] = (C[17] & 0x07ffffff); | ||
157 | |||
158 | for(i=18; i<=35; i++) { | ||
159 | C[i] = 0; | ||
160 | } | ||
161 | |||
162 | result = new Clipperz.Crypto.ECC.BinaryField.Value(C); | ||
163 | //console.log("<<< binaryField.finiteField.(improved)module"); | ||
164 | } | ||
165 | |||
166 | return result; | ||
167 | }; | ||
168 | } | ||
169 | |||
170 | return Clipperz.Crypto.ECC.StandardCurves._B571; | ||
171 | }, | ||
172 | |||
173 | //----------------------------------------------------------------------------- | ||
174 | |||
175 | '_B283': null, | ||
176 | 'B283': function() { //f(z) = z^283 + z^12 + z^7 + z^5 + 1 | ||
177 | if ((Clipperz.Crypto.ECC.StandardCurves._B283 == null) && (typeof(Clipperz.Crypto.ECC.BinaryField.Curve) != 'undefined')) { | ||
178 | Clipperz.Crypto.ECC.StandardCurves._B283 = new Clipperz.Crypto.ECC.BinaryField.Curve({ | ||
179 | modulus: new Clipperz.Crypto.ECC.BinaryField.Value('08000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 000010a1', 16), | ||
180 | a: new Clipperz.Crypto.ECC.BinaryField.Value('1', 16), | ||
181 | b: new Clipperz.Crypto.ECC.BinaryField.Value('027b680a c8b8596d a5a4af8a 19a0303f ca97fd76 45309fa2 a581485a f6263e31 3b79a2f5', 16), | ||
182 | G: new Clipperz.Crypto.ECC.BinaryField.Point({ | ||
183 | x: new Clipperz.Crypto.ECC.BinaryField.Value('05f93925 8db7dd90 e1934f8c 70b0dfec 2eed25b8 557eac9c 80e2e198 f8cdbecd 86b12053', 16), | ||
184 | y: new Clipperz.Crypto.ECC.BinaryField.Value('03676854 fe24141c b98fe6d4 b20d02b4 516ff702 350eddb0 826779c8 13f0df45 be8112f4', 16) | ||
185 | }), | ||
186 | r: new Clipperz.Crypto.ECC.BinaryField.Value('03ffffff ffffffff ffffffff ffffffff ffffef90 399660fc 938a9016 5b042a7c efadb307', 16), | ||
187 | h: new Clipperz.Crypto.ECC.BinaryField.Value('2', 16) | ||
188 | }); | ||
189 | |||
190 | //----------------------------------------------------------------------------- | ||
191 | // | ||
192 | //Guide to Elliptic Curve Cryptography | ||
193 | //Darrel Hankerson, Alfred Menezes, Scott Vanstone | ||
194 | //- Pag: 56, Alorithm 2.43 | ||
195 | // | ||
196 | //----------------------------------------------------------------------------- | ||
197 | Clipperz.Crypto.ECC.StandardCurves._B283.finiteField().slowModule = Clipperz.Crypto.ECC.StandardCurves._B283.finiteField().module; | ||
198 | Clipperz.Crypto.ECC.StandardCurves._B283.finiteField().module = function(aValue) { | ||
199 | varresult; | ||
200 | |||
201 | if (aValue.bitSize() > 564) { | ||
202 | MochiKit.Logging.logWarning("ECC.StandarCurves.B283.finiteField().module: falling back to default implementation"); | ||
203 | result = Clipperz.Crypto.ECC.StandardCurves._B283.finiteField().slowModule(aValue); | ||
204 | } else { | ||
205 | varC, T; | ||
206 | var i; | ||
207 | |||
208 | //console.log(">>> binaryField.finiteField.(improved)module"); | ||
209 | C = aValue._value.slice(0); | ||
210 | for (i=17; i>=9; i--) { | ||
211 | T = C[i]; | ||
212 | C[i-9] = (((C[i-9] ^ (T<<5) ^ (T<<10) ^ (T<<12) ^ (T<<17)) & 0xffffffff) >>> 0); | ||
213 | C[i-8] = ((C[i-8] ^ (T>>>27) ^ (T>>>22) ^ (T>>>20) ^ (T>>>15)) >>> 0); | ||
214 | } | ||
215 | T = (C[8] >>> 27); | ||
216 | C[0] = ((C[0] ^ T ^ ((T<<5) ^ (T<<7) ^ (T<<12)) & 0xffffffff) >>> 0); | ||
217 | C[8] = (C[8] & 0x07ffffff); | ||
218 | |||
219 | for(i=9; i<=17; i++) { | ||
220 | C[i] = 0; | ||
221 | } | ||
222 | |||
223 | result = new Clipperz.Crypto.ECC.BinaryField.Value(C); | ||
224 | //console.log("<<< binaryField.finiteField.(improved)module"); | ||
225 | } | ||
226 | |||
227 | return result; | ||
228 | }; | ||
229 | } | ||
230 | |||
231 | return Clipperz.Crypto.ECC.StandardCurves._B283; | ||
232 | }, | ||
233 | |||
234 | //============================================================================== | ||
235 | __syntaxFix__: "syntax fix" | ||
236 | }); | ||
237 | |||
238 | |||
239 | |||