Wire Sysio Wire Sysion 1.0.0
Loading...
Searching...
No Matches
elliptic_em_common.cpp
Go to the documentation of this file.
4#include <fc/io/raw.hpp>
5#include <fc/crypto/hmac.hpp>
8
9#ifdef _WIN32
10# include <malloc.h>
11#elif defined(__FreeBSD__)
12# include <stdlib.h>
13#else
14# include <alloca.h>
15#endif
16
17/* stuff common to all ecc implementations */
18
19#define BTC_EXT_PUB_MAGIC (0x0488B21E)
20#define BTC_EXT_PRIV_MAGIC (0x0488ADE4)
21
22namespace fc { namespace em {
23
24 namespace detail {
26
28 {
29 fc::sha256 result;
30 memcpy( result.data(), v.data(), 32 );
31 return result;
32 }
33
35 {
36 fc::sha256 result;
37 memcpy( result.data(), v.data() + 32, 32 );
38 return result;
39 }
40
41 static void _put( unsigned char** dest, unsigned int i)
42 {
43 *(*dest)++ = (i >> 24) & 0xff;
44 *(*dest)++ = (i >> 16) & 0xff;
45 *(*dest)++ = (i >> 8) & 0xff;
46 *(*dest)++ = i & 0xff;
47 }
48
49
50 static chr37 _derive_message( char first, const char* key32, int i )
51 {
52 chr37 result;
53 unsigned char* dest = (unsigned char*) result.begin();
54 *dest++ = first;
55 memcpy( dest, key32, 32 ); dest += 32;
56 _put( &dest, i );
57 return result;
58 }
59
61 {
62 return _derive_message( *key.begin(), key.begin() + 1, i );
63 }
64
65
66 const ec_group& get_curve()
67 {
68 static const ec_group secp256k1( EC_GROUP_new_by_curve_name( NID_secp256k1 ) );
69 return secp256k1;
70 }
71
72 static private_key_secret _get_curve_order()
73 {
74 const ec_group& group = get_curve();
75 bn_ctx ctx(BN_CTX_new());
76 ssl_bignum order;
77 FC_ASSERT( EC_GROUP_get_order( group, order, ctx ) );
78 private_key_secret bin;
79 FC_ASSERT( BN_num_bytes( order ) == static_cast<int>(bin.data_size()) );
80 FC_ASSERT( BN_bn2bin( order, (unsigned char*) bin.data() ) == static_cast<int>(bin.data_size()) );
81 return bin;
82 }
83
84 const private_key_secret& get_curve_order()
85 {
86 static private_key_secret order = _get_curve_order();
87 return order;
88 }
89
90 static private_key_secret _get_half_curve_order()
91 {
92 const ec_group& group = get_curve();
93 bn_ctx ctx(BN_CTX_new());
94 ssl_bignum order;
95 FC_ASSERT( EC_GROUP_get_order( group, order, ctx ) );
96 BN_rshift1( order, order );
97 private_key_secret bin;
98 FC_ASSERT( BN_num_bytes( order ) == static_cast<int>(bin.data_size()) );
99 FC_ASSERT( BN_bn2bin( order, (unsigned char*) bin.data() ) == static_cast<int>(bin.data_size()) );
100 return bin;
101 }
102
103 const private_key_secret& get_half_curve_order()
104 {
105 static private_key_secret half_order = _get_half_curve_order();
106 return half_order;
107 }
108 }
109
110 public_key public_key::from_key_data( const public_key_data &data ) {
111 return public_key(data);
112 }
113
115 {
118 fc::raw::pack( enc, offset );
119 return generate_from_seed( get_secret(), enc.result() );
120 }
121
122 std::string public_key::to_base58( const public_key_data &key )
123 {
124 uint32_t check = (uint32_t)sha256::hash(key.data, sizeof(key))._hash[0];
125 static_assert(sizeof(key) + sizeof(check) == 37, ""); // hack around gcc bug: key.size() should be constexpr, but isn't
126 array<char, 37> data;
127 memcpy(data.data, key.begin(), key.size());
128 memcpy(data.begin() + key.size(), (const char*)&check, sizeof(check));
129 return fc::to_base58(data.begin(), data.size(), fc::yield_function_t());
130 }
131
132 public_key public_key::from_base58( const std::string& b58 )
133 {
134 array<char, 37> data;
135 size_t s = fc::from_base58(b58, (char*)&data, sizeof(data) );
136 FC_ASSERT( s == sizeof(data) );
137
139 uint32_t check = (uint32_t)sha256::hash(data.data, sizeof(key))._hash[0];
140 FC_ASSERT( memcmp( (char*)&check, data.data + sizeof(key), sizeof(check) ) == 0 );
141 memcpy( (char*)key.data, data.data, sizeof(key) );
142 return from_key_data(key);
143 }
144
145 unsigned int public_key::fingerprint() const
146 {
148 ripemd160 hash = ripemd160::hash( sha256::hash( key.begin(), key.size() ) );
149 unsigned char* fp = (unsigned char*) hash._hash;
150 return (fp[0] << 24) | (fp[1] << 16) | (fp[2] << 8) | fp[3];
151 }
152
153 bool public_key::is_canonical( const compact_signature& c ) {
154 return !(c.data[1] & 0x80)
155 && !(c.data[1] == 0 && !(c.data[2] & 0x80))
156 && !(c.data[33] & 0x80)
157 && !(c.data[33] == 0 && !(c.data[34] & 0x80));
158 }
159
161 {
162 ssl_bignum z;
163 BN_bin2bn((unsigned char*)&offset, sizeof(offset), z);
164
165 ec_group group(EC_GROUP_new_by_curve_name(NID_secp256k1));
166 bn_ctx ctx(BN_CTX_new());
167 ssl_bignum order;
168 EC_GROUP_get_order(group, order, ctx);
169
170 // secexp = (seed + z) % order
171 ssl_bignum secexp;
172 BN_bin2bn((unsigned char*)&seed, sizeof(seed), secexp);
173 BN_add(secexp, secexp, z);
174 BN_mod(secexp, secexp, order, ctx);
175
176 fc::sha256 secret;
177 FC_ASSERT(BN_num_bytes(secexp) <= int64_t(sizeof(secret)));
178 auto shift = sizeof(secret) - BN_num_bytes(secexp);
179 BN_bn2bin(secexp, ((unsigned char*)&secret)+shift);
180 return regenerate( secret );
181 }
182
183 fc::sha256 private_key::get_secret( const EC_KEY * const k )
184 {
185 if( !k )
186 {
187 return fc::sha256();
188 }
189
190 fc::sha256 sec;
191 const BIGNUM* bn = EC_KEY_get0_private_key(k);
192 if( bn == NULL )
193 {
194 FC_THROW_EXCEPTION( exception, "get private key failed" );
195 }
196 int nbytes = BN_num_bytes(bn);
197 BN_bn2bin(bn, &((unsigned char*)&sec)[32-nbytes] );
198 return sec;
199 }
200
202 {
203 EC_KEY* k = EC_KEY_new_by_curve_name( NID_secp256k1 );
204 if( !k ) FC_THROW_EXCEPTION( exception, "Unable to generate EC key" );
205 if( !EC_KEY_generate_key( k ) )
206 {
207 FC_THROW_EXCEPTION( exception, "ecc key generation error" );
208
209 }
210
211 return private_key( k );
212 }
213
214
215}
216
217void to_variant( const em::private_key& var, variant& vo )
218{
219 vo = var.get_secret();
220}
221
222void from_variant( const variant& var, em::private_key& vo )
223{
224 fc::sha256 sec;
225 from_variant( var, sec );
227}
228
229void to_variant( const em::public_key& var, variant& vo )
230{
231 vo = var.serialize();
232}
233
234void from_variant( const variant& var, em::public_key& vo )
235{
237 from_variant( var, dat );
238 vo = em::public_key(dat);
239}
240
241}
T data[N]
Definition array.hpp:37
an elliptic curve private key.
static private_key generate_from_seed(const fc::sha256 &seed, const fc::sha256 &offset=fc::sha256())
public_key get_public_key() const
private_key_secret get_secret() const
static private_key regenerate(const fc::sha256 &secret)
static private_key generate()
private_key child(const fc::sha256 &offset) const
contains only the public point of an elliptic curve key.
unsigned int fingerprint() const
std::string to_base58() const
Allows to convert current public key object into base58 number.
static public_key from_base58(const std::string &b58)
public_key_data serialize() const
Used to generate a useful error report when an exception is thrown.
Definition exception.hpp:58
static ripemd160 hash(const fc::sha512 &h)
Definition ripemd160.cpp:44
static sha256 hash(const char *d, uint32_t dlen)
Definition sha256.cpp:44
uint64_t _hash[4]
Definition sha256.hpp:100
char * data()
Definition sha512.cpp:24
stores null, int64, uint64, double, bool, string, std::vector<variant>, and variant_object's.
Definition variant.hpp:191
#define FC_THROW_EXCEPTION(EXCEPTION, FORMAT,...)
#define FC_ASSERT(TEST,...)
Checks a condition and throws an assert_exception if the test is FALSE.
bignum_st BIGNUM
Definition bigint.hpp:7
Definition bn.h:56
const private_key_secret & get_curve_order()
const ec_group & get_curve()
chr37 _derive_message(const public_key_data &key, int i)
fc::sha256 _left(const fc::sha512 &v)
fc::array< char, 37 > chr37
fc::sha256 _right(const fc::sha512 &v)
const private_key_secret & get_half_curve_order()
fc::array< char, 33 > public_key_data
void pack(Stream &s, const std::deque< T > &value)
Definition raw.hpp:531
namespace sysio::chain
Definition authority.cpp:3
std::string to_base58(const char *d, size_t s, const fc::yield_function_t &yield)
Definition base58.cpp:618
std::vector< char > from_base58(const std::string &base58_str)
Definition base58.cpp:628
void from_variant(const fc::variant &v, sysio::chain::chain_id_type &cid)
void to_variant(const sysio::chain::shared_public_key &var, fc::variant &vo)
Definition authority.cpp:4
signed __int64 int64_t
Definition stdint.h:135
unsigned int uint32_t
Definition stdint.h:126
uint8_t key[16]
Definition yubico_otp.c:41
char * s
memcpy((char *) pInfo->slotDescription, s, l)