1 // GoGOST -- Pure Go GOST cryptographic functions library
2 // Copyright (C) 2015-2024 Sergey Matveev <stargrave@stargrave.org>
4 // This program is free software: you can redistribute it and/or modify
5 // it under the terms of the GNU General Public License as published by
6 // the Free Software Foundation, version 3 of the License.
8 // This program is distributed in the hope that it will be useful,
9 // but WITHOUT ANY WARRANTY; without even the implied warranty of
10 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
11 // GNU General Public License for more details.
13 // You should have received a copy of the GNU General Public License
14 // along with this program. If not, see <http://www.gnu.org/licenses/>.
26 type PrivateKey struct {
31 // Unmarshal little-endian private key. "raw" must be c.PointSize() length.
32 func NewPrivateKeyLE(c *Curve, raw []byte) (*PrivateKey, error) {
33 pointSize := c.PointSize()
34 if len(raw) != pointSize {
35 return nil, fmt.Errorf("gogost/gost3410: len(key)=%d != %d", len(raw), pointSize)
37 key := make([]byte, pointSize)
38 for i := 0; i < len(key); i++ {
39 key[i] = raw[len(raw)-i-1]
43 return nil, errors.New("gogost/gost3410: zero private key")
45 return &PrivateKey{c, k.Mod(k, c.Q)}, nil
48 // Unmarshal big-endian private key. "raw" must be c.PointSize() length.
49 func NewPrivateKeyBE(c *Curve, raw []byte) (*PrivateKey, error) {
50 pointSize := c.PointSize()
51 if len(raw) != pointSize {
52 return nil, fmt.Errorf("gogost/gost3410: len(key)=%d != %d", len(raw), pointSize)
56 return nil, errors.New("gogost/gost3410: zero private key")
58 return &PrivateKey{c, k.Mod(k, c.Q)}, nil
61 // This is an alias for NewPrivateKeyLE().
62 func NewPrivateKey(c *Curve, raw []byte) (*PrivateKey, error) {
63 return NewPrivateKeyLE(c, raw)
66 func GenPrivateKey(c *Curve, rand io.Reader) (*PrivateKey, error) {
67 raw := make([]byte, c.PointSize())
68 if _, err := io.ReadFull(rand, raw); err != nil {
69 return nil, fmt.Errorf("gogost/gost3410.GenPrivateKey: %w", err)
71 return NewPrivateKey(c, raw)
74 // Marshal little-endian private key. raw will be prv.C.PointSize() length.
75 func (prv *PrivateKey) RawLE() (raw []byte) {
76 raw = pad(prv.Key.Bytes(), prv.C.PointSize())
81 // Marshal big-endian private key. raw will be prv.C.PointSize() length.
82 func (prv *PrivateKey) RawBE() (raw []byte) {
83 return pad(prv.Key.Bytes(), prv.C.PointSize())
86 // This is an alias for RawLE().
87 func (prv *PrivateKey) Raw() []byte {
91 func (prv *PrivateKey) PublicKey() (*PublicKey, error) {
92 x, y, err := prv.C.Exp(prv.Key, prv.C.X, prv.C.Y)
94 return nil, fmt.Errorf("gogost/gost3410.PrivateKey.PublicKey: %w", err)
96 return &PublicKey{prv.C, x, y}, nil
99 func (prv *PrivateKey) SignDigest(digest []byte, rand io.Reader) ([]byte, error) {
100 e := bytes2big(digest)
102 if e.Cmp(zero) == 0 {
105 kRaw := make([]byte, prv.C.PointSize())
112 if _, err = io.ReadFull(rand, kRaw); err != nil {
113 return nil, fmt.Errorf("gogost/gost3410.PrivateKey.SignDigest: %w", err)
117 if k.Cmp(zero) == 0 {
120 r, _, err = prv.C.Exp(k, prv.C.X, prv.C.Y)
122 return nil, fmt.Errorf("gogost/gost3410.PrivateKey.SignDigest: %w", err)
125 if r.Cmp(zero) == 0 {
132 if s.Cmp(zero) == 0 {
135 pointSize := prv.C.PointSize()
137 pad(s.Bytes(), pointSize),
138 pad(r.Bytes(), pointSize)...,
142 // Sign the digest. opts argument is unused. That is identical to SignDigest,
143 // but kept to be friendly to crypto.Signer.
144 func (prv *PrivateKey) Sign(
145 rand io.Reader, digest []byte, opts crypto.SignerOpts,
147 return prv.SignDigest(digest, rand)
150 func (prv *PrivateKey) Public() crypto.PublicKey {
151 pub, err := prv.PublicKey()
158 type PrivateKeyReverseDigest struct {
162 func (prv *PrivateKeyReverseDigest) Public() crypto.PublicKey {
163 return prv.Prv.Public()
166 func (prv *PrivateKeyReverseDigest) Sign(
167 rand io.Reader, digest []byte, opts crypto.SignerOpts,
169 dgst := make([]byte, len(digest))
170 for i := 0; i < len(digest); i++ {
171 dgst[i] = digest[len(digest)-i-1]
173 return prv.Prv.Sign(rand, dgst, opts)
176 type PrivateKeyReverseDigestAndSignature struct {
180 func (prv *PrivateKeyReverseDigestAndSignature) Public() crypto.PublicKey {
181 return prv.Prv.Public()
184 func (prv *PrivateKeyReverseDigestAndSignature) Sign(
185 rand io.Reader, digest []byte, opts crypto.SignerOpts,
187 dgst := make([]byte, len(digest))
188 for i := 0; i < len(digest); i++ {
189 dgst[i] = digest[len(digest)-i-1]
191 sign, err := prv.Prv.Sign(rand, dgst, opts)