diff options
author | ShenNoether <Shen.Noether@gmx.com> | 2015-08-23 14:48:50 -0600 |
---|---|---|
committer | ShenNoether <Shen.Noether@gmx.com> | 2015-08-23 14:48:50 -0600 |
commit | 0a4bc84b2f681dfd89b501648f65a951d876e2d8 (patch) | |
tree | 9f37622b56f26724b4c057dd28f4c9a0ee7ecd74 /src/crypto/shen_ed25519_ref/ref10/open.c | |
parent | revert to 776b4fc91a821be152f0f23e6873aabb78a72029 (diff) | |
download | monero-0a4bc84b2f681dfd89b501648f65a951d876e2d8.tar.xz |
Added ref10 shen_ed25519_ref code, which includes code that can replace crypto-ops with a version straight from Bernstein's ref 10
Diffstat (limited to 'src/crypto/shen_ed25519_ref/ref10/open.c')
-rw-r--r-- | src/crypto/shen_ed25519_ref/ref10/open.c | 48 |
1 files changed, 48 insertions, 0 deletions
diff --git a/src/crypto/shen_ed25519_ref/ref10/open.c b/src/crypto/shen_ed25519_ref/ref10/open.c new file mode 100644 index 000000000..1ec4cd2bf --- /dev/null +++ b/src/crypto/shen_ed25519_ref/ref10/open.c @@ -0,0 +1,48 @@ +#include <string.h> +#include "crypto_sign.h" +#include "crypto_hash_sha512.h" +#include "crypto_verify_32.h" +#include "ge.h" +#include "sc.h" + +int crypto_sign_open( + unsigned char *m,unsigned long long *mlen, + const unsigned char *sm,unsigned long long smlen, + const unsigned char *pk +) +{ + unsigned char pkcopy[32]; + unsigned char rcopy[32]; + unsigned char scopy[32]; + unsigned char h[64]; + unsigned char rcheck[32]; + ge_p3 A; + ge_p2 R; + + if (smlen < 64) goto badsig; + if (sm[63] & 224) goto badsig; + if (ge_frombytes_negate_vartime(&A,pk) != 0) goto badsig; + + memmove(pkcopy,pk,32); + memmove(rcopy,sm,32); + memmove(scopy,sm + 32,32); + + memmove(m,sm,smlen); + memmove(m + 32,pkcopy,32); + crypto_hash_sha512(h,m,smlen); + sc_reduce(h); + + ge_double_scalarmult_vartime(&R,h,&A,scopy); + ge_tobytes(rcheck,&R); + if (crypto_verify_32(rcheck,rcopy) == 0) { + memmove(m,m + 64,smlen - 64); + memset(m + smlen - 64,0,64); + *mlen = smlen - 64; + return 0; + } + +badsig: + *mlen = -1; + memset(m,0,smlen); + return -1; +} |