1/* mpz_powm_sec(res,base,exp,mod) -- Set R to (U^E) mod M.
2
3   Contributed to the GNU project by Torbjorn Granlund.
4
5Copyright 1991, 1993, 1994, 1996, 1997, 2000-2002, 2005, 2008, 2009,
62012, 2015 Free Software Foundation, Inc.
7
8This file is part of the GNU MP Library.
9
10The GNU MP Library is free software; you can redistribute it and/or modify
11it under the terms of either:
12
13  * the GNU Lesser General Public License as published by the Free
14    Software Foundation; either version 3 of the License, or (at your
15    option) any later version.
16
17or
18
19  * the GNU General Public License as published by the Free Software
20    Foundation; either version 2 of the License, or (at your option) any
21    later version.
22
23or both in parallel, as here.
24
25The GNU MP Library is distributed in the hope that it will be useful, but
26WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
27or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
28for more details.
29
30You should have received copies of the GNU General Public License and the
31GNU Lesser General Public License along with the GNU MP Library.  If not,
32see https://www.gnu.org/licenses/.  */
33
34
35#include "gmp-impl.h"
36
37
38void
39mpz_powm_sec (mpz_ptr r, mpz_srcptr b, mpz_srcptr e, mpz_srcptr m)
40{
41  mp_size_t n;
42  mp_ptr rp, tp;
43  mp_srcptr bp, ep, mp;
44  mp_size_t rn, bn, es, en;
45  TMP_DECL;
46
47  n = ABSIZ(m);
48
49  mp = PTR(m);
50
51  if (UNLIKELY ((n == 0) || (mp[0] % 2 == 0)))
52    DIVIDE_BY_ZERO;
53
54  es = SIZ(e);
55  if (UNLIKELY (es <= 0))
56    {
57      if (es == 0)
58	{
59	  /* b^0 mod m,  b is anything and m is non-zero.
60	     Result is 1 mod m, i.e., 1 or 0 depending on if m = 1.  */
61	  SIZ(r) = n != 1 || mp[0] != 1;
62	  MPZ_NEWALLOC (r, 1)[0] = 1;
63	  return;
64	}
65      DIVIDE_BY_ZERO;
66    }
67  en = es;
68
69  bn = ABSIZ(b);
70
71  if (UNLIKELY (bn == 0))
72    {
73      SIZ(r) = 0;
74      return;
75    }
76
77  TMP_MARK;
78  TMP_ALLOC_LIMBS_2 (rp, n,
79		     tp, mpn_sec_powm_itch (bn, en * GMP_NUMB_BITS, n));
80
81  bp = PTR(b);
82  ep = PTR(e);
83
84  mpn_sec_powm (rp, bp, bn, ep, en * GMP_NUMB_BITS, mp, n, tp);
85
86  rn = n;
87
88  MPN_NORMALIZE (rp, rn);
89
90  if ((ep[0] & 1) && SIZ(b) < 0 && rn != 0)
91    {
92      mpn_sub (rp, PTR(m), n, rp, rn);
93      rn = n;
94      MPN_NORMALIZE (rp, rn);
95    }
96
97  MPZ_NEWALLOC (r, rn);
98  SIZ(r) = rn;
99  MPN_COPY (PTR(r), rp, rn);
100
101  TMP_FREE;
102}
103