X-Git-Url: http://www.git.cypherpunks.ru/?p=pygost.git;a=blobdiff_plain;f=pygost%2Fgost3410_vko.py;h=7bc71113b69e99bcf10dbe2d819d2d8b96361a47;hp=719c4f40f4d17b5ee9ec311354430ba59d0c31b6;hb=2bb1a163d32e4167e6904ff3c6b4cf64ea7287bb;hpb=d9b48dd1937f5acd55c0eb6d92e1b5b98e6d302e diff --git a/pygost/gost3410_vko.py b/pygost/gost3410_vko.py index 719c4f4..7bc7111 100644 --- a/pygost/gost3410_vko.py +++ b/pygost/gost3410_vko.py @@ -1,11 +1,10 @@ # coding: utf-8 # PyGOST -- Pure Python GOST cryptographic functions library -# Copyright (C) 2015-2016 Sergey Matveev +# Copyright (C) 2015-2020 Sergey Matveev # # This program is free software: you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by -# the Free Software Foundation, either version 3 of the License, or -# (at your option) any later version. +# the Free Software Foundation, version 3 of the License. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of @@ -14,7 +13,7 @@ # # You should have received a copy of the GNU General Public License # along with this program. If not, see . -"""Diffie-Hellman functions, VKO GOST R 34.10-2001/2012 +"""Key agreement functions, VKO GOST R 34.10-2001/2012 """ from pygost.gost3410 import pub_marshal @@ -27,19 +26,25 @@ from pygost.utils import bytes2long def ukm_unmarshal(ukm): """Unmarshal UKM value - :type ukm: bytes + :type ukm: little-endian bytes :rtype: long """ return bytes2long(ukm[::-1]) -def vko_34102001(curve, prv, pubkey, ukm): - """ Make Diffie-Hellman computation (34.10-2001, 34.11-94) +def kek(curve, prv, pub, ukm, mode): + key = curve.exp(prv, pub[0], pub[1]) + key = curve.exp(curve.cofactor * ukm, key[0], key[1]) + return pub_marshal(key, mode) + + +def kek_34102001(curve, prv, pub, ukm): + """ Key agreement (34.10-2001, 34.11-94) :param GOST3410Curve curve: curve to use :param long prv: private key - :param pubkey: public key - :type pubkey: (long, long) + :param pub: public key + :type pub: (long, long) :param long ukm: user keying material, VKO-factor :returns: Key Encryption Key (shared key) :rtype: bytes, 32 bytes @@ -48,38 +53,41 @@ def vko_34102001(curve, prv, pubkey, ukm): :rfc:`4357` VKO GOST R 34.10-2001 with little-endian hash output. """ - key = curve.exp(prv, pubkey[0], pubkey[1]) - key = curve.exp(ukm, key[0], key[1]) - return GOST341194(pub_marshal(key), "GostR3411_94_CryptoProParamSet").digest() + return GOST341194( + kek(curve, prv, pub, ukm, mode=2001), + sbox="id-GostR3411-94-CryptoProParamSet", + ).digest() -def vko_34102012256(curve, prv, pubkey, ukm=1): - """ Make Diffie-Hellman computation (34.10-2012, 34.11-2012 256 bit) +def kek_34102012256(curve, prv, pub, ukm=1, mode=2012): + """ Key agreement (34.10-2012, 34.11-2012 256 bit) :param GOST3410Curve curve: curve to use :param long prv: private key - :param pubkey: public key - :type pubkey: (long, long) + :param pub: public key + :type pub: (long, long) :param long ukm: user keying material, VKO-factor :returns: Key Encryption Key (shared key) :rtype: bytes, 32 bytes + + Shared Key Encryption Key computation is based on + :rfc:`7836` VKO GOST R 34.10-2012. """ - key = curve.exp(prv, pubkey[0], pubkey[1]) - key = curve.exp(ukm, key[0], key[1]) - return GOST34112012256(pub_marshal(key, mode=2012)).digest() + return GOST34112012256(kek(curve, prv, pub, ukm, mode=mode)).digest() -def vko_34102012512(curve, prv, pubkey, ukm=1): - """ Make Diffie-Hellman computation (34.10-2012, 34.11-2012 512 bit) +def kek_34102012512(curve, prv, pub, ukm=1): + """ Key agreement (34.10-2012, 34.11-2012 512 bit) :param GOST3410Curve curve: curve to use :param long prv: private key - :param pubkey: public key - :type pubkey: (long, long) + :param pub: public key + :type pub: (long, long) :param long ukm: user keying material, VKO-factor :returns: Key Encryption Key (shared key) :rtype: bytes, 32 bytes + + Shared Key Encryption Key computation is based on + :rfc:`7836` VKO GOST R 34.10-2012. """ - key = curve.exp(prv, pubkey[0], pubkey[1]) - key = curve.exp(ukm, key[0], key[1]) - return GOST34112012512(pub_marshal(key, mode=2012)).digest() + return GOST34112012512(kek(curve, prv, pub, ukm, mode=2012)).digest()