195c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley/* ====================================================================
295c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * Copyright (c) 1998-2005 The OpenSSL Project.  All rights reserved.
395c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *
495c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * Redistribution and use in source and binary forms, with or without
595c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * modification, are permitted provided that the following conditions
695c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * are met:
795c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *
895c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * 1. Redistributions of source code must retain the above copyright
995c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    notice, this list of conditions and the following disclaimer.
1095c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *
1195c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * 2. Redistributions in binary form must reproduce the above copyright
1295c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    notice, this list of conditions and the following disclaimer in
1395c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    the documentation and/or other materials provided with the
1495c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    distribution.
1595c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *
1695c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * 3. All advertising materials mentioning features or use of this
1795c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    software must display the following acknowledgment:
1895c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    "This product includes software developed by the OpenSSL Project
1995c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
2095c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *
2195c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
2295c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    endorse or promote products derived from this software without
2395c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    prior written permission. For written permission, please contact
2495c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    openssl-core@OpenSSL.org.
2595c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *
2695c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * 5. Products derived from this software may not be called "OpenSSL"
2795c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    nor may "OpenSSL" appear in their names without prior written
2895c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    permission of the OpenSSL Project.
2995c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *
3095c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * 6. Redistributions of any form whatsoever must retain the following
3195c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    acknowledgment:
3295c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    "This product includes software developed by the OpenSSL Project
3395c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
3495c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *
3595c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
3695c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
3795c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
3895c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
3995c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
4095c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
4195c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
4295c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
4395c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
4495c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
4595c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
4695c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * OF THE POSSIBILITY OF SUCH DAMAGE.
4795c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * ====================================================================
4895c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley *
4995c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * This product includes cryptographic software written by Eric Young
5095c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * (eay@cryptsoft.com).  This product includes software written by Tim
5195c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley * Hudson (tjh@cryptsoft.com). */
5295c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
5395c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley#include <openssl/ecdsa.h>
5495c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
5595c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley#include <openssl/asn1.h>
5695c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley#include <openssl/asn1t.h>
5795c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley#include <openssl/ec_key.h>
5895c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
5995c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley#include "../ec/internal.h"
6095c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
6195c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
6295c29f3cd1f6c08c6c0927868683392eea727ccAdam LangleyASN1_SEQUENCE(ECDSA_SIG) = {
6395c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley    ASN1_SIMPLE(ECDSA_SIG, r, CBIGNUM),
6495c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley    ASN1_SIMPLE(ECDSA_SIG, s, CBIGNUM),
6595c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley} ASN1_SEQUENCE_END(ECDSA_SIG);
6695c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
6795c29f3cd1f6c08c6c0927868683392eea727ccAdam LangleyDECLARE_ASN1_FUNCTIONS_const(ECDSA_SIG);
6895c29f3cd1f6c08c6c0927868683392eea727ccAdam LangleyDECLARE_ASN1_ENCODE_FUNCTIONS_const(ECDSA_SIG, ECDSA_SIG);
6995c29f3cd1f6c08c6c0927868683392eea727ccAdam LangleyIMPLEMENT_ASN1_FUNCTIONS_const(ECDSA_SIG);
7095c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
7195c29f3cd1f6c08c6c0927868683392eea727ccAdam Langleysize_t ECDSA_size(const EC_KEY *key) {
72449f16b947bf3df8a0151468d330918378ad8acbAdam Langley  size_t ret, i, group_order_size;
7395c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  ASN1_INTEGER bs;
7495c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  BIGNUM *order = NULL;
7595c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  unsigned char buf[4];
7695c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  const EC_GROUP *group;
7795c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
78449f16b947bf3df8a0151468d330918378ad8acbAdam Langley  if (key->ecdsa_meth && key->ecdsa_meth->group_order_size) {
79449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    group_order_size = key->ecdsa_meth->group_order_size(key);
80449f16b947bf3df8a0151468d330918378ad8acbAdam Langley  } else {
81449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    size_t num_bits;
8295c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
83449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    if (key == NULL) {
84449f16b947bf3df8a0151468d330918378ad8acbAdam Langley      return 0;
85449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    }
86449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    group = EC_KEY_get0_group(key);
87449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    if (group == NULL) {
88449f16b947bf3df8a0151468d330918378ad8acbAdam Langley      return 0;
89449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    }
9095c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
91449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    order = BN_new();
92449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    if (order == NULL) {
93449f16b947bf3df8a0151468d330918378ad8acbAdam Langley      return 0;
94449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    }
95449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    if (!EC_GROUP_get_order(group, order, NULL)) {
96449f16b947bf3df8a0151468d330918378ad8acbAdam Langley      BN_clear_free(order);
97449f16b947bf3df8a0151468d330918378ad8acbAdam Langley      return 0;
98449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    }
99449f16b947bf3df8a0151468d330918378ad8acbAdam Langley
100449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    num_bits = BN_num_bits(order);
101449f16b947bf3df8a0151468d330918378ad8acbAdam Langley    group_order_size = (num_bits + 7) / 8;
10295c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  }
10395c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
104449f16b947bf3df8a0151468d330918378ad8acbAdam Langley  bs.length = group_order_size;
10595c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  bs.data = buf;
10695c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  bs.type = V_ASN1_INTEGER;
10795c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  /* If the top bit is set the ASN.1 encoding is 1 larger. */
10895c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  buf[0] = 0xff;
10995c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley
11095c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  i = i2d_ASN1_INTEGER(&bs, NULL);
11195c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  i += i; /* r and s */
11295c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  ret = ASN1_object_size(1, i, V_ASN1_SEQUENCE);
11395c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  BN_clear_free(order);
11495c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley  return ret;
11595c29f3cd1f6c08c6c0927868683392eea727ccAdam Langley}
116