1656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* crypto/rsa/rsa_gen.c */ 2656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) 3656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * All rights reserved. 4656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 5656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * This package is an SSL implementation written 6656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * by Eric Young (eay@cryptsoft.com). 7656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * The implementation was written so as to conform with Netscapes SSL. 8656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 9656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * This library is free for commercial and non-commercial use as long as 10656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * the following conditions are aheared to. The following conditions 11656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * apply to all code found in this distribution, be it the RC4, RSA, 12656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * lhash, DES, etc., code; not just the SSL code. The SSL documentation 13656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * included with this distribution is covered by the same copyright terms 14656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * except that the holder is Tim Hudson (tjh@cryptsoft.com). 15656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 16656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * Copyright remains Eric Young's, and as such any Copyright notices in 17656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * the code are not to be removed. 18656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * If this package is used in a product, Eric Young should be given attribution 19656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * as the author of the parts of the library used. 20656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * This can be in the form of a textual message at program startup or 21656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * in documentation (online or textual) provided with the package. 22656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 23656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * Redistribution and use in source and binary forms, with or without 24656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * modification, are permitted provided that the following conditions 25656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * are met: 26656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 1. Redistributions of source code must retain the copyright 27656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * notice, this list of conditions and the following disclaimer. 28656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 2. Redistributions in binary form must reproduce the above copyright 29656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * notice, this list of conditions and the following disclaimer in the 30656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * documentation and/or other materials provided with the distribution. 31656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 3. All advertising materials mentioning features or use of this software 32656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * must display the following acknowledgement: 33656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * "This product includes cryptographic software written by 34656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * Eric Young (eay@cryptsoft.com)" 35656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * The word 'cryptographic' can be left out if the rouines from the library 36656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * being used are not cryptographic related :-). 37656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 4. If you include any Windows specific code (or a derivative thereof) from 38656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * the apps directory (application code) you must include an acknowledgement: 39656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" 40656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 41656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND 42656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 43656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 44656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 45656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 46656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 47656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 48656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 49656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 50656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 51656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * SUCH DAMAGE. 52656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 53656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * The licence and distribution terms for any publically available version or 54656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * derivative of this code cannot be changed. i.e. this code cannot simply be 55656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * copied and put under another distribution licence 56656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * [including the GNU Public Licence.] 57656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project */ 58656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 59656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 60656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* NB: these functions have been "upgraded", the deprecated versions (which are 61656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * compatibility wrappers using these functions) are in rsa_depr.c. 62656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * - Geoff 63656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project */ 64656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 65656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <stdio.h> 66656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <time.h> 67656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include "cryptlib.h" 68656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/bn.h> 69656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/rsa.h> 70392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom#ifdef OPENSSL_FIPS 71392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom#include <openssl/fips.h> 72392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom#endif 73656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 74656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectstatic int rsa_builtin_keygen(RSA *rsa, int bits, BIGNUM *e_value, BN_GENCB *cb); 75656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 76656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* NB: this wrapper would normally be placed in rsa_lib.c and the static 77656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * implementation would probably be in rsa_eay.c. Nonetheless, is kept here so 78656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * that we don't introduce a new linker dependency. Eg. any application that 79656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * wasn't previously linking object code related to key-generation won't have to 80656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * now just because key-generation is part of RSA_METHOD. */ 81656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint RSA_generate_key_ex(RSA *rsa, int bits, BIGNUM *e_value, BN_GENCB *cb) 82656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 83392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom#ifdef OPENSSL_FIPS 84392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom if (FIPS_mode() && !(rsa->meth->flags & RSA_FLAG_FIPS_METHOD) 85392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom && !(rsa->flags & RSA_FLAG_NON_FIPS_ALLOW)) 86392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom { 87392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom RSAerr(RSA_F_RSA_GENERATE_KEY_EX, RSA_R_NON_FIPS_RSA_METHOD); 88392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom return 0; 89392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom } 90392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom#endif 91656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(rsa->meth->rsa_keygen) 92656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return rsa->meth->rsa_keygen(rsa, bits, e_value, cb); 93392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom#ifdef OPENSSL_FIPS 94392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom if (FIPS_mode()) 95392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom return FIPS_rsa_generate_key_ex(rsa, bits, e_value, cb); 96392aa7cc7d2b122614c5393c3e357da07fd07af3Brian Carlstrom#endif 97656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return rsa_builtin_keygen(rsa, bits, e_value, cb); 98656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 99656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 100656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectstatic int rsa_builtin_keygen(RSA *rsa, int bits, BIGNUM *e_value, BN_GENCB *cb) 101656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 102656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIGNUM *r0=NULL,*r1=NULL,*r2=NULL,*r3=NULL,*tmp; 103656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIGNUM local_r0,local_d,local_p; 104656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIGNUM *pr0,*d,*p; 105656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int bitsp,bitsq,ok= -1,n=0; 106656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BN_CTX *ctx=NULL; 107656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 108656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ctx=BN_CTX_new(); 109656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (ctx == NULL) goto err; 110656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BN_CTX_start(ctx); 111656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project r0 = BN_CTX_get(ctx); 112656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project r1 = BN_CTX_get(ctx); 113656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project r2 = BN_CTX_get(ctx); 114656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project r3 = BN_CTX_get(ctx); 115656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (r3 == NULL) goto err; 116656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 117656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project bitsp=(bits+1)/2; 118656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project bitsq=bits-bitsp; 119656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 120656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* We need the RSA components non-NULL */ 121656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!rsa->n && ((rsa->n=BN_new()) == NULL)) goto err; 122656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!rsa->d && ((rsa->d=BN_new()) == NULL)) goto err; 123656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!rsa->e && ((rsa->e=BN_new()) == NULL)) goto err; 124656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!rsa->p && ((rsa->p=BN_new()) == NULL)) goto err; 125656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!rsa->q && ((rsa->q=BN_new()) == NULL)) goto err; 126656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!rsa->dmp1 && ((rsa->dmp1=BN_new()) == NULL)) goto err; 127656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!rsa->dmq1 && ((rsa->dmq1=BN_new()) == NULL)) goto err; 128656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!rsa->iqmp && ((rsa->iqmp=BN_new()) == NULL)) goto err; 129656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 130656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BN_copy(rsa->e, e_value); 131656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 132656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* generate p and q */ 133656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project for (;;) 134656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 135656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!BN_generate_prime_ex(rsa->p, bitsp, 0, NULL, NULL, cb)) 136656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 137656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_sub(r2,rsa->p,BN_value_one())) goto err; 138656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_gcd(r1,r2,rsa->e,ctx)) goto err; 139656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (BN_is_one(r1)) break; 140656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!BN_GENCB_call(cb, 2, n++)) 141656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 142656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 143656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!BN_GENCB_call(cb, 3, 0)) 144656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 145656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project for (;;) 146656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 147656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* When generating ridiculously small keys, we can get stuck 148656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * continually regenerating the same prime values. Check for 149656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * this and bail if it happens 3 times. */ 150656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project unsigned int degenerate = 0; 151656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project do 152656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 153656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!BN_generate_prime_ex(rsa->q, bitsq, 0, NULL, NULL, cb)) 154656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 155656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } while((BN_cmp(rsa->p, rsa->q) == 0) && (++degenerate < 3)); 156656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(degenerate == 3) 157656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 158656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ok = 0; /* we set our own err */ 159656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project RSAerr(RSA_F_RSA_BUILTIN_KEYGEN,RSA_R_KEY_SIZE_TOO_SMALL); 160656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 161656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 162656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_sub(r2,rsa->q,BN_value_one())) goto err; 163656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_gcd(r1,r2,rsa->e,ctx)) goto err; 164656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (BN_is_one(r1)) 165656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project break; 166656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!BN_GENCB_call(cb, 2, n++)) 167656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 168656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 169656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!BN_GENCB_call(cb, 3, 1)) 170656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 171656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (BN_cmp(rsa->p,rsa->q) < 0) 172656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 173656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project tmp=rsa->p; 174656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project rsa->p=rsa->q; 175656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project rsa->q=tmp; 176656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 177656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 178656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* calculate n */ 179656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_mul(rsa->n,rsa->p,rsa->q,ctx)) goto err; 180656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 181656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* calculate d */ 182656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_sub(r1,rsa->p,BN_value_one())) goto err; /* p-1 */ 183656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_sub(r2,rsa->q,BN_value_one())) goto err; /* q-1 */ 184656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_mul(r0,r1,r2,ctx)) goto err; /* (p-1)(q-1) */ 185656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!(rsa->flags & RSA_FLAG_NO_CONSTTIME)) 186656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 187656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project pr0 = &local_r0; 188656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BN_with_flags(pr0, r0, BN_FLG_CONSTTIME); 189656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 190656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project else 191656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project pr0 = r0; 192656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_mod_inverse(rsa->d,rsa->e,pr0,ctx)) goto err; /* d */ 193656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 194656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* set up d for correct BN_FLG_CONSTTIME flag */ 195656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!(rsa->flags & RSA_FLAG_NO_CONSTTIME)) 196656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 197656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project d = &local_d; 198656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BN_with_flags(d, rsa->d, BN_FLG_CONSTTIME); 199656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 200656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project else 201656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project d = rsa->d; 202656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 203656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* calculate d mod (p-1) */ 204656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_mod(rsa->dmp1,d,r1,ctx)) goto err; 205656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 206656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* calculate d mod (q-1) */ 207656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_mod(rsa->dmq1,d,r2,ctx)) goto err; 208656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 209656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* calculate inverse of q mod p */ 210656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!(rsa->flags & RSA_FLAG_NO_CONSTTIME)) 211656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 212656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project p = &local_p; 213656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BN_with_flags(p, rsa->p, BN_FLG_CONSTTIME); 214656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 215656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project else 216656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project p = rsa->p; 217656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BN_mod_inverse(rsa->iqmp,rsa->q,p,ctx)) goto err; 218656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 219656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ok=1; 220656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projecterr: 221656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (ok == -1) 222656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 223656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project RSAerr(RSA_F_RSA_BUILTIN_KEYGEN,ERR_LIB_BN); 224656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ok=0; 225656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 226656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (ctx != NULL) 227656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 228656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BN_CTX_end(ctx); 229656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BN_CTX_free(ctx); 230656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 231656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 232656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return ok; 233656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 234656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 235