1 // GoGOST -- Pure Go GOST cryptographic functions library
2 // Copyright (C) 2015-2024 Sergey Matveev <stargrave@stargrave.org>
4 // This program is free software: you can redistribute it and/or modify
5 // it under the terms of the GNU General Public License as published by
6 // the Free Software Foundation, version 3 of the License.
8 // This program is distributed in the hope that it will be useful,
9 // but WITHOUT ANY WARRANTY; without even the implied warranty of
10 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
11 // GNU General Public License for more details.
13 // You should have received a copy of the GNU General Public License
14 // along with this program. If not, see <http://www.gnu.org/licenses/>.
24 type PublicKey struct {
29 // Unmarshal LE(X)||LE(Y) public key. "raw" must be 2*c.PointSize() length.
30 func NewPublicKeyLE(c *Curve, raw []byte) (*PublicKey, error) {
31 pointSize := c.PointSize()
32 key := make([]byte, 2*pointSize)
33 if len(raw) != len(key) {
34 return nil, fmt.Errorf("gogost/gost3410: len(key) != %d", len(key))
36 for i := 0; i < len(key); i++ {
37 key[i] = raw[len(raw)-i-1]
41 bytes2big(key[pointSize : 2*pointSize]),
42 bytes2big(key[:pointSize]),
46 // Unmarshal BE(X)||BE(Y) public key. "raw" must be 2*c.PointSize() length.
47 func NewPublicKeyBE(c *Curve, raw []byte) (*PublicKey, error) {
48 pointSize := c.PointSize()
49 if len(raw) != 2*pointSize {
50 return nil, fmt.Errorf("gogost/gost3410: len(key) != %d", 2*pointSize)
54 bytes2big(raw[:pointSize]),
55 bytes2big(raw[pointSize:]),
59 // This is an alias for NewPublicKeyLE().
60 func NewPublicKey(c *Curve, raw []byte) (*PublicKey, error) {
61 return NewPublicKeyLE(c, raw)
64 // Marshal LE(X)||LE(Y) public key. raw will be 2*pub.C.PointSize() length.
65 func (pub *PublicKey) RawLE() []byte {
66 pointSize := pub.C.PointSize()
68 pad(pub.Y.Bytes(), pointSize),
69 pad(pub.X.Bytes(), pointSize)...,
75 // Marshal BE(X)||BE(Y) public key. raw will be 2*pub.C.PointSize() length.
76 func (pub *PublicKey) RawBE() []byte {
77 pointSize := pub.C.PointSize()
79 pad(pub.X.Bytes(), pointSize),
80 pad(pub.Y.Bytes(), pointSize)...,
84 // This is an alias for RawLE().
85 func (pub *PublicKey) Raw() []byte {
89 func (pub *PublicKey) VerifyDigest(digest, signature []byte) (bool, error) {
90 pointSize := pub.C.PointSize()
91 if len(signature) != 2*pointSize {
92 return false, fmt.Errorf("gogost/gost3410: len(signature)=%d != %d", len(signature), 2*pointSize)
94 s := bytes2big(signature[:pointSize])
95 r := bytes2big(signature[pointSize:])
96 if r.Cmp(zero) <= 0 ||
97 r.Cmp(pub.C.Q) >= 0 ||
102 e := bytes2big(digest)
104 if e.Cmp(zero) == 0 {
108 v.ModInverse(e, pub.C.Q)
116 p1x, p1y, err := pub.C.Exp(z1, pub.C.X, pub.C.Y)
120 q1x, q1y, err := pub.C.Exp(z2, pub.X, pub.Y)
126 if lm.Cmp(zero) < 0 {
129 lm.ModInverse(lm, pub.C.P)
138 if lm.Cmp(zero) < 0 {
142 return lm.Cmp(r) == 0, nil
145 func (our *PublicKey) Equal(theirKey crypto.PublicKey) bool {
146 their, ok := theirKey.(*PublicKey)
150 return our.X.Cmp(their.X) == 0 && our.Y.Cmp(their.Y) == 0 && our.C.Equal(their.C)
153 type PublicKeyReverseDigest struct {
157 func (pub PublicKeyReverseDigest) VerifyDigest(
158 digest, signature []byte,
160 dgst := make([]byte, len(digest))
161 for i := 0; i < len(digest); i++ {
162 dgst[i] = digest[len(digest)-i-1]
164 return pub.Pub.VerifyDigest(dgst, signature)
167 func (pub PublicKeyReverseDigest) Equal(theirKey crypto.PublicKey) bool {
168 return pub.Pub.Equal(theirKey)
171 type PublicKeyReverseDigestAndSignature struct {
175 func (pub PublicKeyReverseDigestAndSignature) VerifyDigest(
176 digest, signature []byte,
178 dgst := make([]byte, len(digest))
179 for i := 0; i < len(digest); i++ {
180 dgst[i] = digest[len(digest)-i-1]
182 sign := make([]byte, len(signature))
183 for i := 0; i < len(signature); i++ {
184 sign[i] = signature[len(signature)-i-1]
186 return pub.Pub.VerifyDigest(dgst, sign)
189 func (pub PublicKeyReverseDigestAndSignature) Equal(theirKey crypto.PublicKey) bool {
190 return pub.Pub.Equal(theirKey)