| package org.bouncycastle.math.ec.custom.djb; |
| |
| import java.math.BigInteger; |
| |
| import org.bouncycastle.math.ec.ECCurve; |
| import org.bouncycastle.math.ec.ECFieldElement; |
| import org.bouncycastle.math.ec.ECLookupTable; |
| import org.bouncycastle.math.ec.ECPoint; |
| import org.bouncycastle.math.raw.Nat256; |
| import org.bouncycastle.util.encoders.Hex; |
| |
| public class Curve25519 extends ECCurve.AbstractFp |
| { |
| public static final BigInteger q = Nat256.toBigInteger(Curve25519Field.P); |
| |
| private static final int Curve25519_DEFAULT_COORDS = COORD_JACOBIAN_MODIFIED; |
| |
| protected Curve25519Point infinity; |
| |
| public Curve25519() |
| { |
| super(q); |
| |
| this.infinity = new Curve25519Point(this, null, null); |
| |
| this.a = fromBigInteger(new BigInteger(1, |
| Hex.decode("2AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA984914A144"))); |
| this.b = fromBigInteger(new BigInteger(1, |
| Hex.decode("7B425ED097B425ED097B425ED097B425ED097B425ED097B4260B5E9C7710C864"))); |
| this.order = new BigInteger(1, Hex.decode("1000000000000000000000000000000014DEF9DEA2F79CD65812631A5CF5D3ED")); |
| this.cofactor = BigInteger.valueOf(8); |
| |
| this.coord = Curve25519_DEFAULT_COORDS; |
| } |
| |
| protected ECCurve cloneCurve() |
| { |
| return new Curve25519(); |
| } |
| |
| public boolean supportsCoordinateSystem(int coord) |
| { |
| switch (coord) |
| { |
| case COORD_JACOBIAN_MODIFIED: |
| return true; |
| default: |
| return false; |
| } |
| } |
| |
| public BigInteger getQ() |
| { |
| return q; |
| } |
| |
| public int getFieldSize() |
| { |
| return q.bitLength(); |
| } |
| |
| public ECFieldElement fromBigInteger(BigInteger x) |
| { |
| return new Curve25519FieldElement(x); |
| } |
| |
| protected ECPoint createRawPoint(ECFieldElement x, ECFieldElement y, boolean withCompression) |
| { |
| return new Curve25519Point(this, x, y, withCompression); |
| } |
| |
| protected ECPoint createRawPoint(ECFieldElement x, ECFieldElement y, ECFieldElement[] zs, boolean withCompression) |
| { |
| return new Curve25519Point(this, x, y, zs, withCompression); |
| } |
| |
| public ECPoint getInfinity() |
| { |
| return infinity; |
| } |
| |
| public ECLookupTable createCacheSafeLookupTable(ECPoint[] points, int off, final int len) |
| { |
| final int FE_INTS = 8; |
| |
| final int[] table = new int[len * FE_INTS * 2]; |
| { |
| int pos = 0; |
| for (int i = 0; i < len; ++i) |
| { |
| ECPoint p = points[off + i]; |
| Nat256.copy(((Curve25519FieldElement)p.getRawXCoord()).x, 0, table, pos); pos += FE_INTS; |
| Nat256.copy(((Curve25519FieldElement)p.getRawYCoord()).x, 0, table, pos); pos += FE_INTS; |
| } |
| } |
| |
| return new ECLookupTable() |
| { |
| public int getSize() |
| { |
| return len; |
| } |
| |
| public ECPoint lookup(int index) |
| { |
| int[] x = Nat256.create(), y = Nat256.create(); |
| int pos = 0; |
| |
| for (int i = 0; i < len; ++i) |
| { |
| int MASK = ((i ^ index) - 1) >> 31; |
| |
| for (int j = 0; j < FE_INTS; ++j) |
| { |
| x[j] ^= table[pos + j] & MASK; |
| y[j] ^= table[pos + FE_INTS + j] & MASK; |
| } |
| |
| pos += (FE_INTS * 2); |
| } |
| |
| return createRawPoint(new Curve25519FieldElement(x), new Curve25519FieldElement(y), false); |
| } |
| }; |
| } |
| } |