1/* 2 * Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved. 3 * Copyright 2014 Cryptography Research, Inc. 4 * 5 * Licensed under the Apache License 2.0 (the "License"). You may not use 6 * this file except in compliance with the License. You can obtain a copy 7 * in the file LICENSE in the source distribution or at 8 * https://www.openssl.org/source/license.html 9 * 10 * Originally written by Mike Hamburg 11 */ 12 13#ifndef OSSL_CRYPTO_EC_CURVE448_WORD_H 14# define OSSL_CRYPTO_EC_CURVE448_WORD_H 15 16# include <string.h> 17# include <assert.h> 18# include <stdlib.h> 19# include <openssl/e_os2.h> 20# include "curve448utils.h" 21 22# ifdef INT128_MAX 23# include "arch_64/arch_intrinsics.h" 24# else 25# include "arch_32/arch_intrinsics.h" 26# endif 27 28# if (ARCH_WORD_BITS == 64) 29typedef uint64_t word_t, mask_t; 30typedef uint128_t dword_t; 31typedef int32_t hsword_t; 32typedef int64_t sword_t; 33typedef int128_t dsword_t; 34# elif (ARCH_WORD_BITS == 32) 35typedef uint32_t word_t, mask_t; 36typedef uint64_t dword_t; 37typedef int16_t hsword_t; 38typedef int32_t sword_t; 39typedef int64_t dsword_t; 40# else 41# error "For now, we only support 32- and 64-bit architectures." 42# endif 43 44/* 45 * Scalar limbs are keyed off of the API word size instead of the arch word 46 * size. 47 */ 48# if C448_WORD_BITS == 64 49# define SC_LIMB(x) (x) 50# elif C448_WORD_BITS == 32 51# define SC_LIMB(x) ((uint32_t)(x)),((x) >> 32) 52# else 53# error "For now we only support 32- and 64-bit architectures." 54# endif 55 56/* 57 * The plan on booleans: The external interface uses c448_bool_t, but this 58 * might be a different size than our particular arch's word_t (and thus 59 * mask_t). Also, the caller isn't guaranteed to pass it as nonzero. So 60 * bool_to_mask converts word sizes and checks nonzero. On the flip side, 61 * mask_t is always -1 or 0, but it might be a different size than 62 * c448_bool_t. On the third hand, we have success vs boolean types, but 63 * that's handled in common.h: it converts between c448_bool_t and 64 * c448_error_t. 65 */ 66static ossl_inline c448_bool_t mask_to_bool(mask_t m) 67{ 68 return (c448_sword_t)(sword_t)m; 69} 70 71static ossl_inline mask_t bool_to_mask(c448_bool_t m) 72{ 73 /* On most arches this will be optimized to a simple cast. */ 74 mask_t ret = 0; 75 unsigned int i; 76 unsigned int limit = sizeof(c448_bool_t) / sizeof(mask_t); 77 78 if (limit < 1) 79 limit = 1; 80 for (i = 0; i < limit; i++) 81 ret |= ~word_is_zero(m >> (i * 8 * sizeof(word_t))); 82 83 return ret; 84} 85 86#endif /* OSSL_CRYPTO_EC_CURVE448_WORD_H */ 87