1 // GoGOST -- Pure Go GOST cryptographic functions library
2 // Copyright (C) 2015-2021 Sergey Matveev <stargrave@stargrave.org>
4 // This program is free software: you can redistribute it and/or modify
5 // it under the terms of the GNU General Public License as published by
6 // the Free Software Foundation, version 3 of the License.
8 // This program is distributed in the hope that it will be useful,
9 // but WITHOUT ANY WARRANTY; without even the implied warranty of
10 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
11 // GNU General Public License for more details.
13 // You should have received a copy of the GNU General Public License
14 // along with this program. If not, see <http://www.gnu.org/licenses/>.
26 type PrivateKey struct {
31 func NewPrivateKey(curve *Curve, raw []byte) (*PrivateKey, error) {
32 pointSize := curve.PointSize()
33 if len(raw) != pointSize {
34 return nil, fmt.Errorf("gogost/gost3410: len(key) != %d", pointSize)
36 key := make([]byte, pointSize)
37 for i := 0; i < len(key); i++ {
38 key[i] = raw[len(raw)-i-1]
42 return nil, errors.New("gogost/gost3410: zero private key")
44 return &PrivateKey{curve, k}, nil
47 func GenPrivateKey(curve *Curve, rand io.Reader) (*PrivateKey, error) {
48 raw := make([]byte, curve.PointSize())
49 if _, err := io.ReadFull(rand, raw); err != nil {
52 return NewPrivateKey(curve, raw)
55 func (prv *PrivateKey) Raw() []byte {
56 raw := pad(prv.Key.Bytes(), prv.C.PointSize())
61 func (prv *PrivateKey) PublicKey() (*PublicKey, error) {
62 x, y, err := prv.C.Exp(prv.Key, prv.C.X, prv.C.Y)
66 return &PublicKey{prv.C, x, y}, nil
69 func (prv *PrivateKey) SignDigest(digest []byte, rand io.Reader) ([]byte, error) {
70 e := bytes2big(digest)
75 kRaw := make([]byte, prv.C.PointSize())
82 if _, err = io.ReadFull(rand, kRaw); err != nil {
90 r, _, err = prv.C.Exp(k, prv.C.X, prv.C.Y)
102 if s.Cmp(zero) == 0 {
105 pointSize := prv.C.PointSize()
107 pad(s.Bytes(), pointSize),
108 pad(r.Bytes(), pointSize)...,
112 func (prv *PrivateKey) Sign(rand io.Reader, digest []byte, opts crypto.SignerOpts) ([]byte, error) {
113 return prv.SignDigest(digest, rand)
116 func (prv *PrivateKey) Public() crypto.PublicKey {
117 pub, err := prv.PublicKey()
124 type PrivateKeyReverseDigest struct {
128 func (prv *PrivateKeyReverseDigest) Public() crypto.PublicKey {
129 return prv.Prv.Public()
132 func (prv *PrivateKeyReverseDigest) Sign(rand io.Reader, digest []byte, opts crypto.SignerOpts) ([]byte, error) {
133 d := make([]byte, len(digest))
136 return prv.Prv.Sign(rand, d, opts)
139 type PrivateKeyReverseDigestAndSignature struct {
143 func (prv *PrivateKeyReverseDigestAndSignature) Public() crypto.PublicKey {
144 return prv.Prv.Public()
147 func (prv *PrivateKeyReverseDigestAndSignature) Sign(rand io.Reader, digest []byte, opts crypto.SignerOpts) ([]byte, error) {
148 d := make([]byte, len(digest))
151 sign, err := prv.Prv.Sign(rand, d, opts)