1 // GoGOST -- Pure Go GOST cryptographic functions library
2 // Copyright (C) 2015-2020 Sergey Matveev <stargrave@stargrave.org>
4 // This program is free software: you can redistribute it and/or modify
5 // it under the terms of the GNU General Public License as published by
6 // the Free Software Foundation, version 3 of the License.
8 // This program is distributed in the hope that it will be useful,
9 // but WITHOUT ANY WARRANTY; without even the implied warranty of
10 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
11 // GNU General Public License for more details.
13 // You should have received a copy of the GNU General Public License
14 // along with this program. If not, see <http://www.gnu.org/licenses/>.
23 type PublicKey struct {
29 func NewPublicKey(curve *Curve, raw []byte) (*PublicKey, error) {
30 pointSize := curve.PointSize()
31 key := make([]byte, 2*pointSize)
32 if len(raw) != len(key) {
33 return nil, fmt.Errorf("gogost/gost3410: len(key) != %d", len(key))
35 for i := 0; i < len(key); i++ {
36 key[i] = raw[len(raw)-i-1]
40 bytes2big(key[pointSize : 2*pointSize]),
41 bytes2big(key[:pointSize]),
45 func (pub *PublicKey) Raw() []byte {
46 pointSize := pub.C.PointSize()
48 pad(pub.Y.Bytes(), pointSize),
49 pad(pub.X.Bytes(), pointSize)...,
55 func (pub *PublicKey) VerifyDigest(digest, signature []byte) (bool, error) {
56 pointSize := pub.C.PointSize()
57 if len(signature) != 2*pointSize {
58 return false, fmt.Errorf("gogost/gost3410: len(signature) != %d", 2*pointSize)
60 s := bytes2big(signature[:pointSize])
61 r := bytes2big(signature[pointSize:])
62 if r.Cmp(zero) <= 0 ||
63 r.Cmp(pub.C.Q) >= 0 ||
68 e := bytes2big(digest)
74 v.ModInverse(e, pub.C.Q)
82 p1x, p1y, err := pub.C.Exp(z1, pub.C.X, pub.C.Y)
86 q1x, q1y, err := pub.C.Exp(z2, pub.X, pub.Y)
95 lm.ModInverse(lm, pub.C.P)
104 if lm.Cmp(zero) < 0 {
108 return lm.Cmp(r) == 0, nil