1*2139Sjp161948 /* crypto/ec/ec_curve.c */
2*2139Sjp161948 /*
3*2139Sjp161948 * Written by Nils Larsch for the OpenSSL project.
4*2139Sjp161948 */
5*2139Sjp161948 /* ====================================================================
6*2139Sjp161948 * Copyright (c) 1998-2004 The OpenSSL Project. All rights reserved.
7*2139Sjp161948 *
8*2139Sjp161948 * Redistribution and use in source and binary forms, with or without
9*2139Sjp161948 * modification, are permitted provided that the following conditions
10*2139Sjp161948 * are met:
11*2139Sjp161948 *
12*2139Sjp161948 * 1. Redistributions of source code must retain the above copyright
13*2139Sjp161948 * notice, this list of conditions and the following disclaimer.
14*2139Sjp161948 *
15*2139Sjp161948 * 2. Redistributions in binary form must reproduce the above copyright
16*2139Sjp161948 * notice, this list of conditions and the following disclaimer in
17*2139Sjp161948 * the documentation and/or other materials provided with the
18*2139Sjp161948 * distribution.
19*2139Sjp161948 *
20*2139Sjp161948 * 3. All advertising materials mentioning features or use of this
21*2139Sjp161948 * software must display the following acknowledgment:
22*2139Sjp161948 * "This product includes software developed by the OpenSSL Project
23*2139Sjp161948 * for use in the OpenSSL Toolkit. (http://www.openssl.org/)"
24*2139Sjp161948 *
25*2139Sjp161948 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
26*2139Sjp161948 * endorse or promote products derived from this software without
27*2139Sjp161948 * prior written permission. For written permission, please contact
28*2139Sjp161948 * openssl-core@openssl.org.
29*2139Sjp161948 *
30*2139Sjp161948 * 5. Products derived from this software may not be called "OpenSSL"
31*2139Sjp161948 * nor may "OpenSSL" appear in their names without prior written
32*2139Sjp161948 * permission of the OpenSSL Project.
33*2139Sjp161948 *
34*2139Sjp161948 * 6. Redistributions of any form whatsoever must retain the following
35*2139Sjp161948 * acknowledgment:
36*2139Sjp161948 * "This product includes software developed by the OpenSSL Project
37*2139Sjp161948 * for use in the OpenSSL Toolkit (http://www.openssl.org/)"
38*2139Sjp161948 *
39*2139Sjp161948 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
40*2139Sjp161948 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
41*2139Sjp161948 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
42*2139Sjp161948 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
43*2139Sjp161948 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
44*2139Sjp161948 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
45*2139Sjp161948 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
46*2139Sjp161948 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
47*2139Sjp161948 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
48*2139Sjp161948 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
49*2139Sjp161948 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
50*2139Sjp161948 * OF THE POSSIBILITY OF SUCH DAMAGE.
51*2139Sjp161948 * ====================================================================
52*2139Sjp161948 *
53*2139Sjp161948 * This product includes cryptographic software written by Eric Young
54*2139Sjp161948 * (eay@cryptsoft.com). This product includes software written by Tim
55*2139Sjp161948 * Hudson (tjh@cryptsoft.com).
56*2139Sjp161948 *
57*2139Sjp161948 */
58*2139Sjp161948 /* ====================================================================
59*2139Sjp161948 * Copyright 2002 Sun Microsystems, Inc. ALL RIGHTS RESERVED.
60*2139Sjp161948 *
61*2139Sjp161948 * Portions of the attached software ("Contribution") are developed by
62*2139Sjp161948 * SUN MICROSYSTEMS, INC., and are contributed to the OpenSSL project.
63*2139Sjp161948 *
64*2139Sjp161948 * The Contribution is licensed pursuant to the OpenSSL open source
65*2139Sjp161948 * license provided above.
66*2139Sjp161948 *
67*2139Sjp161948 * The elliptic curve binary polynomial software is originally written by
68*2139Sjp161948 * Sheueling Chang Shantz and Douglas Stebila of Sun Microsystems Laboratories.
69*2139Sjp161948 *
70*2139Sjp161948 */
71*2139Sjp161948
72*2139Sjp161948 #include "ec_lcl.h"
73*2139Sjp161948 #include <openssl/err.h>
74*2139Sjp161948 #include <openssl/obj_mac.h>
75*2139Sjp161948
76*2139Sjp161948 typedef struct ec_curve_data_st {
77*2139Sjp161948 int field_type; /* either NID_X9_62_prime_field or
78*2139Sjp161948 * NID_X9_62_characteristic_two_field */
79*2139Sjp161948 const char *p; /* either a prime number or a polynomial */
80*2139Sjp161948 const char *a;
81*2139Sjp161948 const char *b;
82*2139Sjp161948 const char *x; /* the x coordinate of the generator */
83*2139Sjp161948 const char *y; /* the y coordinate of the generator */
84*2139Sjp161948 const char *order; /* the order of the group generated by the
85*2139Sjp161948 * generator */
86*2139Sjp161948 const BN_ULONG cofactor;/* the cofactor */
87*2139Sjp161948 const unsigned char *seed;/* the seed (optional) */
88*2139Sjp161948 size_t seed_len;
89*2139Sjp161948 const char *comment; /* a short description of the curve */
90*2139Sjp161948 } EC_CURVE_DATA;
91*2139Sjp161948
92*2139Sjp161948 /* the nist prime curves */
93*2139Sjp161948 static const unsigned char _EC_NIST_PRIME_192_SEED[] = {
94*2139Sjp161948 0x30,0x45,0xAE,0x6F,0xC8,0x42,0x2F,0x64,0xED,0x57,
95*2139Sjp161948 0x95,0x28,0xD3,0x81,0x20,0xEA,0xE1,0x21,0x96,0xD5};
96*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_PRIME_192 = {
97*2139Sjp161948 NID_X9_62_prime_field,
98*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",
99*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",
100*2139Sjp161948 "64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1",
101*2139Sjp161948 "188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012",
102*2139Sjp161948 "07192b95ffc8da78631011ed6b24cdd573f977a11e794811",
103*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831",1,
104*2139Sjp161948 _EC_NIST_PRIME_192_SEED, 20,
105*2139Sjp161948 "NIST/X9.62/SECG curve over a 192 bit prime field"
106*2139Sjp161948 };
107*2139Sjp161948
108*2139Sjp161948 static const unsigned char _EC_NIST_PRIME_224_SEED[] = {
109*2139Sjp161948 0xBD,0x71,0x34,0x47,0x99,0xD5,0xC7,0xFC,0xDC,0x45,
110*2139Sjp161948 0xB5,0x9F,0xA3,0xB9,0xAB,0x8F,0x6A,0x94,0x8B,0xC5};
111*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_PRIME_224 = {
112*2139Sjp161948 NID_X9_62_prime_field,
113*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001",
114*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE",
115*2139Sjp161948 "B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4",
116*2139Sjp161948 "B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21",
117*2139Sjp161948 "bd376388b5f723fb4c22dfe6cd4375a05a07476444d5819985007e34",
118*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D",1,
119*2139Sjp161948 _EC_NIST_PRIME_224_SEED, 20,
120*2139Sjp161948 "NIST/SECG curve over a 224 bit prime field"
121*2139Sjp161948 };
122*2139Sjp161948
123*2139Sjp161948 static const unsigned char _EC_NIST_PRIME_384_SEED[] = {
124*2139Sjp161948 0xA3,0x35,0x92,0x6A,0xA3,0x19,0xA2,0x7A,0x1D,0x00,
125*2139Sjp161948 0x89,0x6A,0x67,0x73,0xA4,0x82,0x7A,0xCD,0xAC,0x73};
126*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_PRIME_384 = {
127*2139Sjp161948 NID_X9_62_prime_field,
128*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFF"
129*2139Sjp161948 "FFF0000000000000000FFFFFFFF",
130*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFF"
131*2139Sjp161948 "FFF0000000000000000FFFFFFFC",
132*2139Sjp161948 "B3312FA7E23EE7E4988E056BE3F82D19181D9C6EFE8141120314088F5013875AC6563"
133*2139Sjp161948 "98D8A2ED19D2A85C8EDD3EC2AEF",
134*2139Sjp161948 "AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F"
135*2139Sjp161948 "25DBF55296C3A545E3872760AB7",
136*2139Sjp161948 "3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b"
137*2139Sjp161948 "1ce1d7e819d7a431d7c90ea0e5f",
138*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0"
139*2139Sjp161948 "DB248B0A77AECEC196ACCC52973",1,
140*2139Sjp161948 _EC_NIST_PRIME_384_SEED, 20,
141*2139Sjp161948 "NIST/SECG curve over a 384 bit prime field"
142*2139Sjp161948 };
143*2139Sjp161948
144*2139Sjp161948 static const unsigned char _EC_NIST_PRIME_521_SEED[] = {
145*2139Sjp161948 0xD0,0x9E,0x88,0x00,0x29,0x1C,0xB8,0x53,0x96,0xCC,
146*2139Sjp161948 0x67,0x17,0x39,0x32,0x84,0xAA,0xA0,0xDA,0x64,0xBA};
147*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_PRIME_521 = {
148*2139Sjp161948 NID_X9_62_prime_field,
149*2139Sjp161948 "1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF"
150*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF",
151*2139Sjp161948 "1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF"
152*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC",
153*2139Sjp161948 "051953EB9618E1C9A1F929A21A0B68540EEA2DA725B99B315F3B8B489918EF109E156"
154*2139Sjp161948 "193951EC7E937B1652C0BD3BB1BF073573DF883D2C34F1EF451FD46B503F00",
155*2139Sjp161948 "C6858E06B70404E9CD9E3ECB662395B4429C648139053FB521F828AF606B4D3DBAA14"
156*2139Sjp161948 "B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66",
157*2139Sjp161948 "011839296a789a3bc0045c8a5fb42c7d1bd998f54449579b446817afbd17273e662c9"
158*2139Sjp161948 "7ee72995ef42640c550b9013fad0761353c7086a272c24088be94769fd16650",
159*2139Sjp161948 "1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA51"
160*2139Sjp161948 "868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409",1,
161*2139Sjp161948 _EC_NIST_PRIME_521_SEED, 20,
162*2139Sjp161948 "NIST/SECG curve over a 521 bit prime field"
163*2139Sjp161948 };
164*2139Sjp161948 /* the x9.62 prime curves (minus the nist prime curves) */
165*2139Sjp161948 static const unsigned char _EC_X9_62_PRIME_192V2_SEED[] = {
166*2139Sjp161948 0x31,0xA9,0x2E,0xE2,0x02,0x9F,0xD1,0x0D,0x90,0x1B,
167*2139Sjp161948 0x11,0x3E,0x99,0x07,0x10,0xF0,0xD2,0x1A,0xC6,0xB6};
168*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_PRIME_192V2 = {
169*2139Sjp161948 NID_X9_62_prime_field,
170*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",
171*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",
172*2139Sjp161948 "CC22D6DFB95C6B25E49C0D6364A4E5980C393AA21668D953",
173*2139Sjp161948 "EEA2BAE7E1497842F2DE7769CFE9C989C072AD696F48034A",
174*2139Sjp161948 "6574d11d69b6ec7a672bb82a083df2f2b0847de970b2de15",
175*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFE5FB1A724DC80418648D8DD31",1,
176*2139Sjp161948 _EC_X9_62_PRIME_192V2_SEED, 20,
177*2139Sjp161948 "X9.62 curve over a 192 bit prime field"
178*2139Sjp161948 };
179*2139Sjp161948
180*2139Sjp161948 static const unsigned char _EC_X9_62_PRIME_192V3_SEED[] = {
181*2139Sjp161948 0xC4,0x69,0x68,0x44,0x35,0xDE,0xB3,0x78,0xC4,0xB6,
182*2139Sjp161948 0x5C,0xA9,0x59,0x1E,0x2A,0x57,0x63,0x05,0x9A,0x2E};
183*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_PRIME_192V3 = {
184*2139Sjp161948 NID_X9_62_prime_field,
185*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",
186*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",
187*2139Sjp161948 "22123DC2395A05CAA7423DAECCC94760A7D462256BD56916",
188*2139Sjp161948 "7D29778100C65A1DA1783716588DCE2B8B4AEE8E228F1896",
189*2139Sjp161948 "38a90f22637337334b49dcb66a6dc8f9978aca7648a943b0",
190*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFF7A62D031C83F4294F640EC13",1,
191*2139Sjp161948 _EC_X9_62_PRIME_192V3_SEED, 20,
192*2139Sjp161948 "X9.62 curve over a 192 bit prime field"
193*2139Sjp161948 };
194*2139Sjp161948
195*2139Sjp161948 static const unsigned char _EC_X9_62_PRIME_239V1_SEED[] = {
196*2139Sjp161948 0xE4,0x3B,0xB4,0x60,0xF0,0xB8,0x0C,0xC0,0xC0,0xB0,
197*2139Sjp161948 0x75,0x79,0x8E,0x94,0x80,0x60,0xF8,0x32,0x1B,0x7D};
198*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_PRIME_239V1 = {
199*2139Sjp161948 NID_X9_62_prime_field,
200*2139Sjp161948 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",
201*2139Sjp161948 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",
202*2139Sjp161948 "6B016C3BDCF18941D0D654921475CA71A9DB2FB27D1D37796185C2942C0A",
203*2139Sjp161948 "0FFA963CDCA8816CCC33B8642BEDF905C3D358573D3F27FBBD3B3CB9AAAF",
204*2139Sjp161948 "7debe8e4e90a5dae6e4054ca530ba04654b36818ce226b39fccb7b02f1ae",
205*2139Sjp161948 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFF9E5E9A9F5D9071FBD1522688909D0B",1,
206*2139Sjp161948 _EC_X9_62_PRIME_239V1_SEED, 20,
207*2139Sjp161948 "X9.62 curve over a 239 bit prime field"
208*2139Sjp161948 };
209*2139Sjp161948
210*2139Sjp161948 static const unsigned char _EC_X9_62_PRIME_239V2_SEED[] = {
211*2139Sjp161948 0xE8,0xB4,0x01,0x16,0x04,0x09,0x53,0x03,0xCA,0x3B,
212*2139Sjp161948 0x80,0x99,0x98,0x2B,0xE0,0x9F,0xCB,0x9A,0xE6,0x16};
213*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_PRIME_239V2 = {
214*2139Sjp161948 NID_X9_62_prime_field,
215*2139Sjp161948 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",
216*2139Sjp161948 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",
217*2139Sjp161948 "617FAB6832576CBBFED50D99F0249C3FEE58B94BA0038C7AE84C8C832F2C",
218*2139Sjp161948 "38AF09D98727705120C921BB5E9E26296A3CDCF2F35757A0EAFD87B830E7",
219*2139Sjp161948 "5b0125e4dbea0ec7206da0fc01d9b081329fb555de6ef460237dff8be4ba",
220*2139Sjp161948 "7FFFFFFFFFFFFFFFFFFFFFFF800000CFA7E8594377D414C03821BC582063",1,
221*2139Sjp161948 _EC_X9_62_PRIME_239V2_SEED, 20,
222*2139Sjp161948 "X9.62 curve over a 239 bit prime field"
223*2139Sjp161948 };
224*2139Sjp161948
225*2139Sjp161948 static const unsigned char _EC_X9_62_PRIME_239V3_SEED[] = {
226*2139Sjp161948 0x7D,0x73,0x74,0x16,0x8F,0xFE,0x34,0x71,0xB6,0x0A,
227*2139Sjp161948 0x85,0x76,0x86,0xA1,0x94,0x75,0xD3,0xBF,0xA2,0xFF};
228*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_PRIME_239V3 = {
229*2139Sjp161948 NID_X9_62_prime_field,
230*2139Sjp161948 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",
231*2139Sjp161948 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",
232*2139Sjp161948 "255705FA2A306654B1F4CB03D6A750A30C250102D4988717D9BA15AB6D3E",
233*2139Sjp161948 "6768AE8E18BB92CFCF005C949AA2C6D94853D0E660BBF854B1C9505FE95A",
234*2139Sjp161948 "1607e6898f390c06bc1d552bad226f3b6fcfe48b6e818499af18e3ed6cf3",
235*2139Sjp161948 "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFF975DEB41B3A6057C3C432146526551",1,
236*2139Sjp161948 _EC_X9_62_PRIME_239V3_SEED, 20,
237*2139Sjp161948 "X9.62 curve over a 239 bit prime field"
238*2139Sjp161948 };
239*2139Sjp161948
240*2139Sjp161948 static const unsigned char _EC_X9_62_PRIME_256V1_SEED[] = {
241*2139Sjp161948 0xC4,0x9D,0x36,0x08,0x86,0xE7,0x04,0x93,0x6A,0x66,
242*2139Sjp161948 0x78,0xE1,0x13,0x9D,0x26,0xB7,0x81,0x9F,0x7E,0x90};
243*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_PRIME_256V1 = {
244*2139Sjp161948 NID_X9_62_prime_field,
245*2139Sjp161948 "FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF",
246*2139Sjp161948 "FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFC",
247*2139Sjp161948 "5AC635D8AA3A93E7B3EBBD55769886BC651D06B0CC53B0F63BCE3C3E27D2604B",
248*2139Sjp161948 "6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296",
249*2139Sjp161948 "4fe342e2fe1a7f9b8ee7eb4a7c0f9e162bce33576b315ececbb6406837bf51f5",
250*2139Sjp161948 "FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551",1,
251*2139Sjp161948 _EC_X9_62_PRIME_256V1_SEED, 20,
252*2139Sjp161948 "X9.62/SECG curve over a 256 bit prime field"
253*2139Sjp161948 };
254*2139Sjp161948 /* the secg prime curves (minus the nist and x9.62 prime curves) */
255*2139Sjp161948 static const unsigned char _EC_SECG_PRIME_112R1_SEED[] = {
256*2139Sjp161948 0x00,0xF5,0x0B,0x02,0x8E,0x4D,0x69,0x6E,0x67,0x68,
257*2139Sjp161948 0x75,0x61,0x51,0x75,0x29,0x04,0x72,0x78,0x3F,0xB1};
258*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_PRIME_112R1 = {
259*2139Sjp161948 NID_X9_62_prime_field,
260*2139Sjp161948 "DB7C2ABF62E35E668076BEAD208B",
261*2139Sjp161948 "DB7C2ABF62E35E668076BEAD2088",
262*2139Sjp161948 "659EF8BA043916EEDE8911702B22",
263*2139Sjp161948 "09487239995A5EE76B55F9C2F098",
264*2139Sjp161948 "a89ce5af8724c0a23e0e0ff77500",
265*2139Sjp161948 "DB7C2ABF62E35E7628DFAC6561C5",1,
266*2139Sjp161948 _EC_SECG_PRIME_112R1_SEED, 20,
267*2139Sjp161948 "SECG/WTLS curve over a 112 bit prime field"
268*2139Sjp161948 };
269*2139Sjp161948
270*2139Sjp161948 static const unsigned char _EC_SECG_PRIME_112R2_SEED[] = {
271*2139Sjp161948 0x00,0x27,0x57,0xA1,0x11,0x4D,0x69,0x6E,0x67,0x68,
272*2139Sjp161948 0x75,0x61,0x51,0x75,0x53,0x16,0xC0,0x5E,0x0B,0xD4};
273*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_PRIME_112R2 = {
274*2139Sjp161948 NID_X9_62_prime_field,
275*2139Sjp161948 "DB7C2ABF62E35E668076BEAD208B",
276*2139Sjp161948 "6127C24C05F38A0AAAF65C0EF02C",
277*2139Sjp161948 "51DEF1815DB5ED74FCC34C85D709",
278*2139Sjp161948 "4BA30AB5E892B4E1649DD0928643",
279*2139Sjp161948 "adcd46f5882e3747def36e956e97",
280*2139Sjp161948 "36DF0AAFD8B8D7597CA10520D04B",4,
281*2139Sjp161948 _EC_SECG_PRIME_112R2_SEED, 20,
282*2139Sjp161948 "SECG curve over a 112 bit prime field"
283*2139Sjp161948 };
284*2139Sjp161948
285*2139Sjp161948 static const unsigned char _EC_SECG_PRIME_128R1_SEED[] = {
286*2139Sjp161948 0x00,0x0E,0x0D,0x4D,0x69,0x6E,0x67,0x68,0x75,0x61,
287*2139Sjp161948 0x51,0x75,0x0C,0xC0,0x3A,0x44,0x73,0xD0,0x36,0x79};
288*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_PRIME_128R1 = {
289*2139Sjp161948 NID_X9_62_prime_field,
290*2139Sjp161948 "FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF",
291*2139Sjp161948 "FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFC",
292*2139Sjp161948 "E87579C11079F43DD824993C2CEE5ED3",
293*2139Sjp161948 "161FF7528B899B2D0C28607CA52C5B86",
294*2139Sjp161948 "cf5ac8395bafeb13c02da292dded7a83",
295*2139Sjp161948 "FFFFFFFE0000000075A30D1B9038A115",1,
296*2139Sjp161948 _EC_SECG_PRIME_128R1_SEED, 20,
297*2139Sjp161948 "SECG curve over a 128 bit prime field"
298*2139Sjp161948 };
299*2139Sjp161948
300*2139Sjp161948 static const unsigned char _EC_SECG_PRIME_128R2_SEED[] = {
301*2139Sjp161948 0x00,0x4D,0x69,0x6E,0x67,0x68,0x75,0x61,0x51,0x75,
302*2139Sjp161948 0x12,0xD8,0xF0,0x34,0x31,0xFC,0xE6,0x3B,0x88,0xF4};
303*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_PRIME_128R2 = {
304*2139Sjp161948 NID_X9_62_prime_field,
305*2139Sjp161948 "FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF",
306*2139Sjp161948 "D6031998D1B3BBFEBF59CC9BBFF9AEE1",
307*2139Sjp161948 "5EEEFCA380D02919DC2C6558BB6D8A5D",
308*2139Sjp161948 "7B6AA5D85E572983E6FB32A7CDEBC140",
309*2139Sjp161948 "27b6916a894d3aee7106fe805fc34b44",
310*2139Sjp161948 "3FFFFFFF7FFFFFFFBE0024720613B5A3",4,
311*2139Sjp161948 _EC_SECG_PRIME_128R2_SEED, 20,
312*2139Sjp161948 "SECG curve over a 128 bit prime field"
313*2139Sjp161948 };
314*2139Sjp161948
315*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_PRIME_160K1 = {
316*2139Sjp161948 NID_X9_62_prime_field,
317*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73",
318*2139Sjp161948 "0",
319*2139Sjp161948 "7",
320*2139Sjp161948 "3B4C382CE37AA192A4019E763036F4F5DD4D7EBB",
321*2139Sjp161948 "938cf935318fdced6bc28286531733c3f03c4fee",
322*2139Sjp161948 "0100000000000000000001B8FA16DFAB9ACA16B6B3",1,
323*2139Sjp161948 NULL, 0,
324*2139Sjp161948 "SECG curve over a 160 bit prime field"
325*2139Sjp161948 };
326*2139Sjp161948
327*2139Sjp161948 static const unsigned char _EC_SECG_PRIME_160R1_SEED[] = {
328*2139Sjp161948 0x10,0x53,0xCD,0xE4,0x2C,0x14,0xD6,0x96,0xE6,0x76,
329*2139Sjp161948 0x87,0x56,0x15,0x17,0x53,0x3B,0xF3,0xF8,0x33,0x45};
330*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_PRIME_160R1 = {
331*2139Sjp161948 NID_X9_62_prime_field,
332*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFF",
333*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFC",
334*2139Sjp161948 "1C97BEFC54BD7A8B65ACF89F81D4D4ADC565FA45",
335*2139Sjp161948 "4A96B5688EF573284664698968C38BB913CBFC82",
336*2139Sjp161948 "23a628553168947d59dcc912042351377ac5fb32",
337*2139Sjp161948 "0100000000000000000001F4C8F927AED3CA752257",1,
338*2139Sjp161948 _EC_SECG_PRIME_160R1_SEED, 20,
339*2139Sjp161948 "SECG curve over a 160 bit prime field"
340*2139Sjp161948 };
341*2139Sjp161948
342*2139Sjp161948 static const unsigned char _EC_SECG_PRIME_160R2_SEED[] = {
343*2139Sjp161948 0xB9,0x9B,0x99,0xB0,0x99,0xB3,0x23,0xE0,0x27,0x09,
344*2139Sjp161948 0xA4,0xD6,0x96,0xE6,0x76,0x87,0x56,0x15,0x17,0x51};
345*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_PRIME_160R2 = {
346*2139Sjp161948 NID_X9_62_prime_field,
347*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73",
348*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC70",
349*2139Sjp161948 "B4E134D3FB59EB8BAB57274904664D5AF50388BA",
350*2139Sjp161948 "52DCB034293A117E1F4FF11B30F7199D3144CE6D",
351*2139Sjp161948 "feaffef2e331f296e071fa0df9982cfea7d43f2e",
352*2139Sjp161948 "0100000000000000000000351EE786A818F3A1A16B",1,
353*2139Sjp161948 _EC_SECG_PRIME_160R2_SEED, 20,
354*2139Sjp161948 "SECG/WTLS curve over a 160 bit prime field"
355*2139Sjp161948 };
356*2139Sjp161948
357*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_PRIME_192K1 = {
358*2139Sjp161948 NID_X9_62_prime_field,
359*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFEE37",
360*2139Sjp161948 "0",
361*2139Sjp161948 "3",
362*2139Sjp161948 "DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D",
363*2139Sjp161948 "9b2f2f6d9c5628a7844163d015be86344082aa88d95e2f9d",
364*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D",1,
365*2139Sjp161948 NULL, 20,
366*2139Sjp161948 "SECG curve over a 192 bit prime field"
367*2139Sjp161948 };
368*2139Sjp161948
369*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_PRIME_224K1 = {
370*2139Sjp161948 NID_X9_62_prime_field,
371*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFE56D",
372*2139Sjp161948 "0",
373*2139Sjp161948 "5",
374*2139Sjp161948 "A1455B334DF099DF30FC28A169A467E9E47075A90F7E650EB6B7A45C",
375*2139Sjp161948 "7e089fed7fba344282cafbd6f7e319f7c0b0bd59e2ca4bdb556d61a5",
376*2139Sjp161948 "010000000000000000000000000001DCE8D2EC6184CAF0A971769FB1F7",1,
377*2139Sjp161948 NULL, 20,
378*2139Sjp161948 "SECG curve over a 224 bit prime field"
379*2139Sjp161948 };
380*2139Sjp161948
381*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_PRIME_256K1 = {
382*2139Sjp161948 NID_X9_62_prime_field,
383*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F",
384*2139Sjp161948 "0",
385*2139Sjp161948 "7",
386*2139Sjp161948 "79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798",
387*2139Sjp161948 "483ada7726a3c4655da4fbfc0e1108a8fd17b448a68554199c47d08ffb10d4b8",
388*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141",1,
389*2139Sjp161948 NULL, 20,
390*2139Sjp161948 "SECG curve over a 256 bit prime field"
391*2139Sjp161948 };
392*2139Sjp161948
393*2139Sjp161948 /* some wap/wtls curves */
394*2139Sjp161948 static const EC_CURVE_DATA _EC_WTLS_8 = {
395*2139Sjp161948 NID_X9_62_prime_field,
396*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFDE7",
397*2139Sjp161948 "0",
398*2139Sjp161948 "3",
399*2139Sjp161948 "1",
400*2139Sjp161948 "2",
401*2139Sjp161948 "0100000000000001ECEA551AD837E9",1,
402*2139Sjp161948 NULL, 20,
403*2139Sjp161948 "WTLS curve over a 112 bit prime field"
404*2139Sjp161948 };
405*2139Sjp161948
406*2139Sjp161948 static const EC_CURVE_DATA _EC_WTLS_9 = {
407*2139Sjp161948 NID_X9_62_prime_field,
408*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC808F",
409*2139Sjp161948 "0",
410*2139Sjp161948 "3",
411*2139Sjp161948 "1",
412*2139Sjp161948 "2",
413*2139Sjp161948 "0100000000000000000001CDC98AE0E2DE574ABF33",1,
414*2139Sjp161948 NULL, 20,
415*2139Sjp161948 "WTLS curve over a 160 bit prime field"
416*2139Sjp161948 };
417*2139Sjp161948
418*2139Sjp161948 static const EC_CURVE_DATA _EC_WTLS_12 = {
419*2139Sjp161948 NID_X9_62_prime_field,
420*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001",
421*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE",
422*2139Sjp161948 "B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4",
423*2139Sjp161948 "B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21",
424*2139Sjp161948 "bd376388b5f723fb4c22dfe6cd4375a05a07476444d5819985007e34",
425*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D", 1,
426*2139Sjp161948 NULL, 0,
427*2139Sjp161948 "WTLS curvs over a 224 bit prime field"
428*2139Sjp161948 };
429*2139Sjp161948
430*2139Sjp161948 /* characteristic two curves */
431*2139Sjp161948 static const unsigned char _EC_SECG_CHAR2_113R1_SEED[] = {
432*2139Sjp161948 0x10,0xE7,0x23,0xAB,0x14,0xD6,0x96,0xE6,0x76,0x87,
433*2139Sjp161948 0x56,0x15,0x17,0x56,0xFE,0xBF,0x8F,0xCB,0x49,0xA9};
434*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_CHAR2_113R1 = {
435*2139Sjp161948 NID_X9_62_characteristic_two_field,
436*2139Sjp161948 "020000000000000000000000000201",
437*2139Sjp161948 "003088250CA6E7C7FE649CE85820F7",
438*2139Sjp161948 "00E8BEE4D3E2260744188BE0E9C723",
439*2139Sjp161948 "009D73616F35F4AB1407D73562C10F",
440*2139Sjp161948 "00A52830277958EE84D1315ED31886",
441*2139Sjp161948 "0100000000000000D9CCEC8A39E56F", 2,
442*2139Sjp161948 _EC_SECG_CHAR2_113R1_SEED, 20,
443*2139Sjp161948 "SECG curve over a 113 bit binary field"
444*2139Sjp161948 };
445*2139Sjp161948
446*2139Sjp161948 static const unsigned char _EC_SECG_CHAR2_113R2_SEED[] = {
447*2139Sjp161948 0x10,0xC0,0xFB,0x15,0x76,0x08,0x60,0xDE,0xF1,0xEE,
448*2139Sjp161948 0xF4,0xD6,0x96,0xE6,0x76,0x87,0x56,0x15,0x17,0x5D};
449*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_CHAR2_113R2 = {
450*2139Sjp161948 NID_X9_62_characteristic_two_field,
451*2139Sjp161948 "020000000000000000000000000201",
452*2139Sjp161948 "00689918DBEC7E5A0DD6DFC0AA55C7",
453*2139Sjp161948 "0095E9A9EC9B297BD4BF36E059184F",
454*2139Sjp161948 "01A57A6A7B26CA5EF52FCDB8164797",
455*2139Sjp161948 "00B3ADC94ED1FE674C06E695BABA1D",
456*2139Sjp161948 "010000000000000108789B2496AF93", 2,
457*2139Sjp161948 _EC_SECG_CHAR2_113R2_SEED, 20,
458*2139Sjp161948 "SECG curve over a 113 bit binary field"
459*2139Sjp161948 };
460*2139Sjp161948
461*2139Sjp161948 static const unsigned char _EC_SECG_CHAR2_131R1_SEED[] = {
462*2139Sjp161948 0x4D,0x69,0x6E,0x67,0x68,0x75,0x61,0x51,0x75,0x98,
463*2139Sjp161948 0x5B,0xD3,0xAD,0xBA,0xDA,0x21,0xB4,0x3A,0x97,0xE2};
464*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_CHAR2_131R1 = {
465*2139Sjp161948 NID_X9_62_characteristic_two_field,
466*2139Sjp161948 "080000000000000000000000000000010D",
467*2139Sjp161948 "07A11B09A76B562144418FF3FF8C2570B8",
468*2139Sjp161948 "0217C05610884B63B9C6C7291678F9D341",
469*2139Sjp161948 "0081BAF91FDF9833C40F9C181343638399",
470*2139Sjp161948 "078C6E7EA38C001F73C8134B1B4EF9E150",
471*2139Sjp161948 "0400000000000000023123953A9464B54D", 2,
472*2139Sjp161948 _EC_SECG_CHAR2_131R1_SEED, 20,
473*2139Sjp161948 "SECG/WTLS curve over a 131 bit binary field"
474*2139Sjp161948 };
475*2139Sjp161948
476*2139Sjp161948 static const unsigned char _EC_SECG_CHAR2_131R2_SEED[] = {
477*2139Sjp161948 0x98,0x5B,0xD3,0xAD,0xBA,0xD4,0xD6,0x96,0xE6,0x76,
478*2139Sjp161948 0x87,0x56,0x15,0x17,0x5A,0x21,0xB4,0x3A,0x97,0xE3};
479*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_CHAR2_131R2 = {
480*2139Sjp161948 NID_X9_62_characteristic_two_field,
481*2139Sjp161948 "080000000000000000000000000000010D",
482*2139Sjp161948 "03E5A88919D7CAFCBF415F07C2176573B2",
483*2139Sjp161948 "04B8266A46C55657AC734CE38F018F2192",
484*2139Sjp161948 "0356DCD8F2F95031AD652D23951BB366A8",
485*2139Sjp161948 "0648F06D867940A5366D9E265DE9EB240F",
486*2139Sjp161948 "0400000000000000016954A233049BA98F", 2,
487*2139Sjp161948 _EC_SECG_CHAR2_131R2_SEED, 20,
488*2139Sjp161948 "SECG curve over a 131 bit binary field"
489*2139Sjp161948 };
490*2139Sjp161948
491*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_CHAR2_163K = {
492*2139Sjp161948 NID_X9_62_characteristic_two_field,
493*2139Sjp161948 "0800000000000000000000000000000000000000C9",
494*2139Sjp161948 "1",
495*2139Sjp161948 "1",
496*2139Sjp161948 "02FE13C0537BBC11ACAA07D793DE4E6D5E5C94EEE8",
497*2139Sjp161948 "0289070FB05D38FF58321F2E800536D538CCDAA3D9",
498*2139Sjp161948 "04000000000000000000020108A2E0CC0D99F8A5EF", 2,
499*2139Sjp161948 NULL, 0,
500*2139Sjp161948 "NIST/SECG/WTLS curve over a 163 bit binary field"
501*2139Sjp161948 };
502*2139Sjp161948
503*2139Sjp161948 static const unsigned char _EC_SECG_CHAR2_163R1_SEED[] = {
504*2139Sjp161948 0x24,0xB7,0xB1,0x37,0xC8,0xA1,0x4D,0x69,0x6E,0x67,
505*2139Sjp161948 0x68,0x75,0x61,0x51,0x75,0x6F,0xD0,0xDA,0x2E,0x5C};
506*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_CHAR2_163R1 = {
507*2139Sjp161948 NID_X9_62_characteristic_two_field,
508*2139Sjp161948 "0800000000000000000000000000000000000000C9",
509*2139Sjp161948 "07B6882CAAEFA84F9554FF8428BD88E246D2782AE2",
510*2139Sjp161948 "0713612DCDDCB40AAB946BDA29CA91F73AF958AFD9",
511*2139Sjp161948 "0369979697AB43897789566789567F787A7876A654",
512*2139Sjp161948 "00435EDB42EFAFB2989D51FEFCE3C80988F41FF883",
513*2139Sjp161948 "03FFFFFFFFFFFFFFFFFFFF48AAB689C29CA710279B", 2,
514*2139Sjp161948 /* The algorithm used to derive the curve parameters from
515*2139Sjp161948 * the seed used here is slightly different than the
516*2139Sjp161948 * algorithm described in X9.62 .
517*2139Sjp161948 */
518*2139Sjp161948 #if 0
519*2139Sjp161948 _EC_SECG_CHAR2_163R1_SEED, 20,
520*2139Sjp161948 #else
521*2139Sjp161948 NULL, 0,
522*2139Sjp161948 #endif
523*2139Sjp161948 "SECG curve over a 163 bit binary field"
524*2139Sjp161948 };
525*2139Sjp161948
526*2139Sjp161948 static const unsigned char _EC_NIST_CHAR2_163B_SEED[] = {
527*2139Sjp161948 0x85,0xE2,0x5B,0xFE,0x5C,0x86,0x22,0x6C,0xDB,0x12,
528*2139Sjp161948 0x01,0x6F,0x75,0x53,0xF9,0xD0,0xE6,0x93,0xA2,0x68};
529*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_CHAR2_163B ={
530*2139Sjp161948 NID_X9_62_characteristic_two_field,
531*2139Sjp161948 "0800000000000000000000000000000000000000C9",
532*2139Sjp161948 "1",
533*2139Sjp161948 "020A601907B8C953CA1481EB10512F78744A3205FD",
534*2139Sjp161948 "03F0EBA16286A2D57EA0991168D4994637E8343E36",
535*2139Sjp161948 "00D51FBC6C71A0094FA2CDD545B11C5C0C797324F1",
536*2139Sjp161948 "040000000000000000000292FE77E70C12A4234C33", 2,
537*2139Sjp161948 /* The seed here was used to created the curve parameters in normal
538*2139Sjp161948 * basis representation (and not the polynomial representation used here)
539*2139Sjp161948 */
540*2139Sjp161948 #if 0
541*2139Sjp161948 _EC_NIST_CHAR2_163B_SEED, 20,
542*2139Sjp161948 #else
543*2139Sjp161948 NULL, 0,
544*2139Sjp161948 #endif
545*2139Sjp161948 "NIST/SECG curve over a 163 bit binary field"
546*2139Sjp161948 };
547*2139Sjp161948
548*2139Sjp161948 static const unsigned char _EC_SECG_CHAR2_193R1_SEED[] = {
549*2139Sjp161948 0x10,0x3F,0xAE,0xC7,0x4D,0x69,0x6E,0x67,0x68,0x75,
550*2139Sjp161948 0x61,0x51,0x75,0x77,0x7F,0xC5,0xB1,0x91,0xEF,0x30};
551*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_CHAR2_193R1 = {
552*2139Sjp161948 NID_X9_62_characteristic_two_field,
553*2139Sjp161948 "02000000000000000000000000000000000000000000008001",
554*2139Sjp161948 "0017858FEB7A98975169E171F77B4087DE098AC8A911DF7B01",
555*2139Sjp161948 "00FDFB49BFE6C3A89FACADAA7A1E5BBC7CC1C2E5D831478814",
556*2139Sjp161948 "01F481BC5F0FF84A74AD6CDF6FDEF4BF6179625372D8C0C5E1",
557*2139Sjp161948 "0025E399F2903712CCF3EA9E3A1AD17FB0B3201B6AF7CE1B05",
558*2139Sjp161948 "01000000000000000000000000C7F34A778F443ACC920EBA49", 2,
559*2139Sjp161948 _EC_SECG_CHAR2_193R1_SEED, 20,
560*2139Sjp161948 "SECG curve over a 193 bit binary field"
561*2139Sjp161948 };
562*2139Sjp161948
563*2139Sjp161948 static const unsigned char _EC_SECG_CHAR2_193R2_SEED[] = {
564*2139Sjp161948 0x10,0xB7,0xB4,0xD6,0x96,0xE6,0x76,0x87,0x56,0x15,
565*2139Sjp161948 0x17,0x51,0x37,0xC8,0xA1,0x6F,0xD0,0xDA,0x22,0x11};
566*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_CHAR2_193R2 = {
567*2139Sjp161948 NID_X9_62_characteristic_two_field,
568*2139Sjp161948 "02000000000000000000000000000000000000000000008001",
569*2139Sjp161948 "0163F35A5137C2CE3EA6ED8667190B0BC43ECD69977702709B",
570*2139Sjp161948 "00C9BB9E8927D4D64C377E2AB2856A5B16E3EFB7F61D4316AE",
571*2139Sjp161948 "00D9B67D192E0367C803F39E1A7E82CA14A651350AAE617E8F",
572*2139Sjp161948 "01CE94335607C304AC29E7DEFBD9CA01F596F927224CDECF6C",
573*2139Sjp161948 "010000000000000000000000015AAB561B005413CCD4EE99D5", 2,
574*2139Sjp161948 _EC_SECG_CHAR2_193R2_SEED, 20,
575*2139Sjp161948 "SECG curve over a 193 bit binary field"
576*2139Sjp161948 };
577*2139Sjp161948
578*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_CHAR2_233K = {
579*2139Sjp161948 NID_X9_62_characteristic_two_field,
580*2139Sjp161948 "020000000000000000000000000000000000000004000000000000000001",
581*2139Sjp161948 "0",
582*2139Sjp161948 "1",
583*2139Sjp161948 "017232BA853A7E731AF129F22FF4149563A419C26BF50A4C9D6EEFAD6126",
584*2139Sjp161948 "01DB537DECE819B7F70F555A67C427A8CD9BF18AEB9B56E0C11056FAE6A3",
585*2139Sjp161948 "008000000000000000000000000000069D5BB915BCD46EFB1AD5F173ABDF", 4,
586*2139Sjp161948 NULL, 0,
587*2139Sjp161948 "NIST/SECG/WTLS curve over a 233 bit binary field"
588*2139Sjp161948 };
589*2139Sjp161948
590*2139Sjp161948 static const unsigned char _EC_NIST_CHAR2_233B_SEED[] = {
591*2139Sjp161948 0x74,0xD5,0x9F,0xF0,0x7F,0x6B,0x41,0x3D,0x0E,0xA1,
592*2139Sjp161948 0x4B,0x34,0x4B,0x20,0xA2,0xDB,0x04,0x9B,0x50,0xC3};
593*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_CHAR2_233B = {
594*2139Sjp161948 NID_X9_62_characteristic_two_field,
595*2139Sjp161948 "020000000000000000000000000000000000000004000000000000000001",
596*2139Sjp161948 "000000000000000000000000000000000000000000000000000000000001",
597*2139Sjp161948 "0066647EDE6C332C7F8C0923BB58213B333B20E9CE4281FE115F7D8F90AD",
598*2139Sjp161948 "00FAC9DFCBAC8313BB2139F1BB755FEF65BC391F8B36F8F8EB7371FD558B",
599*2139Sjp161948 "01006A08A41903350678E58528BEBF8A0BEFF867A7CA36716F7E01F81052",
600*2139Sjp161948 "01000000000000000000000000000013E974E72F8A6922031D2603CFE0D7", 2,
601*2139Sjp161948 _EC_NIST_CHAR2_233B_SEED, 20,
602*2139Sjp161948 "NIST/SECG/WTLS curve over a 233 bit binary field"
603*2139Sjp161948 };
604*2139Sjp161948
605*2139Sjp161948 static const EC_CURVE_DATA _EC_SECG_CHAR2_239K1 = {
606*2139Sjp161948 NID_X9_62_characteristic_two_field,
607*2139Sjp161948 "800000000000000000004000000000000000000000000000000000000001",
608*2139Sjp161948 "0",
609*2139Sjp161948 "1",
610*2139Sjp161948 "29A0B6A887A983E9730988A68727A8B2D126C44CC2CC7B2A6555193035DC",
611*2139Sjp161948 "76310804F12E549BDB011C103089E73510ACB275FC312A5DC6B76553F0CA",
612*2139Sjp161948 "2000000000000000000000000000005A79FEC67CB6E91F1C1DA800E478A5", 4,
613*2139Sjp161948 NULL, 0,
614*2139Sjp161948 "SECG curve over a 239 bit binary field"
615*2139Sjp161948 };
616*2139Sjp161948
617*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_CHAR2_283K = {
618*2139Sjp161948 NID_X9_62_characteristic_two_field,
619*2139Sjp161948 "080000000000000000000000000000000000000000000000000000000000000000001"
620*2139Sjp161948 "0A1",
621*2139Sjp161948 "0",
622*2139Sjp161948 "1",
623*2139Sjp161948 "0503213F78CA44883F1A3B8162F188E553CD265F23C1567A16876913B0C2AC2458492"
624*2139Sjp161948 "836",
625*2139Sjp161948 "01CCDA380F1C9E318D90F95D07E5426FE87E45C0E8184698E45962364E34116177DD2"
626*2139Sjp161948 "259",
627*2139Sjp161948 "01FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFE9AE2ED07577265DFF7F94451E061E163"
628*2139Sjp161948 "C61", 4,
629*2139Sjp161948 NULL, 20,
630*2139Sjp161948 "NIST/SECG curve over a 283 bit binary field"
631*2139Sjp161948 };
632*2139Sjp161948
633*2139Sjp161948 static const unsigned char _EC_NIST_CHAR2_283B_SEED[] = {
634*2139Sjp161948 0x77,0xE2,0xB0,0x73,0x70,0xEB,0x0F,0x83,0x2A,0x6D,
635*2139Sjp161948 0xD5,0xB6,0x2D,0xFC,0x88,0xCD,0x06,0xBB,0x84,0xBE};
636*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_CHAR2_283B = {
637*2139Sjp161948 NID_X9_62_characteristic_two_field,
638*2139Sjp161948 "080000000000000000000000000000000000000000000000000000000000000000001"
639*2139Sjp161948 "0A1",
640*2139Sjp161948 "000000000000000000000000000000000000000000000000000000000000000000000"
641*2139Sjp161948 "001",
642*2139Sjp161948 "027B680AC8B8596DA5A4AF8A19A0303FCA97FD7645309FA2A581485AF6263E313B79A"
643*2139Sjp161948 "2F5",
644*2139Sjp161948 "05F939258DB7DD90E1934F8C70B0DFEC2EED25B8557EAC9C80E2E198F8CDBECD86B12"
645*2139Sjp161948 "053",
646*2139Sjp161948 "03676854FE24141CB98FE6D4B20D02B4516FF702350EDDB0826779C813F0DF45BE811"
647*2139Sjp161948 "2F4",
648*2139Sjp161948 "03FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEF90399660FC938A90165B042A7CEFADB"
649*2139Sjp161948 "307", 2,
650*2139Sjp161948 _EC_NIST_CHAR2_283B_SEED, 20,
651*2139Sjp161948 "NIST/SECG curve over a 283 bit binary field"
652*2139Sjp161948 };
653*2139Sjp161948
654*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_CHAR2_409K = {
655*2139Sjp161948 NID_X9_62_characteristic_two_field,
656*2139Sjp161948 "020000000000000000000000000000000000000000000000000000000000000000000"
657*2139Sjp161948 "00000000000008000000000000000000001",
658*2139Sjp161948 "0",
659*2139Sjp161948 "1",
660*2139Sjp161948 "0060F05F658F49C1AD3AB1890F7184210EFD0987E307C84C27ACCFB8F9F67CC2C4601"
661*2139Sjp161948 "89EB5AAAA62EE222EB1B35540CFE9023746",
662*2139Sjp161948 "01E369050B7C4E42ACBA1DACBF04299C3460782F918EA427E6325165E9EA10E3DA5F6"
663*2139Sjp161948 "C42E9C55215AA9CA27A5863EC48D8E0286B",
664*2139Sjp161948 "007FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFE5F83B2D4EA20400"
665*2139Sjp161948 "EC4557D5ED3E3E7CA5B4B5C83B8E01E5FCF", 4,
666*2139Sjp161948 NULL, 0,
667*2139Sjp161948 "NIST/SECG curve over a 409 bit binary field"
668*2139Sjp161948 };
669*2139Sjp161948
670*2139Sjp161948 static const unsigned char _EC_NIST_CHAR2_409B_SEED[] = {
671*2139Sjp161948 0x40,0x99,0xB5,0xA4,0x57,0xF9,0xD6,0x9F,0x79,0x21,
672*2139Sjp161948 0x3D,0x09,0x4C,0x4B,0xCD,0x4D,0x42,0x62,0x21,0x0B};
673*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_CHAR2_409B = {
674*2139Sjp161948 NID_X9_62_characteristic_two_field,
675*2139Sjp161948 "020000000000000000000000000000000000000000000000000000000000000000000"
676*2139Sjp161948 "00000000000008000000000000000000001",
677*2139Sjp161948 "000000000000000000000000000000000000000000000000000000000000000000000"
678*2139Sjp161948 "00000000000000000000000000000000001",
679*2139Sjp161948 "0021A5C2C8EE9FEB5C4B9A753B7B476B7FD6422EF1F3DD674761FA99D6AC27C8A9A19"
680*2139Sjp161948 "7B272822F6CD57A55AA4F50AE317B13545F",
681*2139Sjp161948 "015D4860D088DDB3496B0C6064756260441CDE4AF1771D4DB01FFE5B34E59703DC255"
682*2139Sjp161948 "A868A1180515603AEAB60794E54BB7996A7",
683*2139Sjp161948 "0061B1CFAB6BE5F32BBFA78324ED106A7636B9C5A7BD198D0158AA4F5488D08F38514"
684*2139Sjp161948 "F1FDF4B4F40D2181B3681C364BA0273C706",
685*2139Sjp161948 "010000000000000000000000000000000000000000000000000001E2AAD6A612F3330"
686*2139Sjp161948 "7BE5FA47C3C9E052F838164CD37D9A21173", 2,
687*2139Sjp161948 _EC_NIST_CHAR2_409B_SEED, 20,
688*2139Sjp161948 "NIST/SECG curve over a 409 bit binary field"
689*2139Sjp161948 };
690*2139Sjp161948
691*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_CHAR2_571K = {
692*2139Sjp161948 NID_X9_62_characteristic_two_field,
693*2139Sjp161948 "800000000000000000000000000000000000000000000000000000000000000000000"
694*2139Sjp161948 "000000000000000000000000000000000000000000000000000000000000000000000"
695*2139Sjp161948 "00425",
696*2139Sjp161948 "0",
697*2139Sjp161948 "1",
698*2139Sjp161948 "026EB7A859923FBC82189631F8103FE4AC9CA2970012D5D46024804801841CA443709"
699*2139Sjp161948 "58493B205E647DA304DB4CEB08CBBD1BA39494776FB988B47174DCA88C7E2945283A0"
700*2139Sjp161948 "1C8972",
701*2139Sjp161948 "0349DC807F4FBF374F4AEADE3BCA95314DD58CEC9F307A54FFC61EFC006D8A2C9D497"
702*2139Sjp161948 "9C0AC44AEA74FBEBBB9F772AEDCB620B01A7BA7AF1B320430C8591984F601CD4C143E"
703*2139Sjp161948 "F1C7A3",
704*2139Sjp161948 "020000000000000000000000000000000000000000000000000000000000000000000"
705*2139Sjp161948 "000131850E1F19A63E4B391A8DB917F4138B630D84BE5D639381E91DEB45CFE778F63"
706*2139Sjp161948 "7C1001", 4,
707*2139Sjp161948 NULL, 0,
708*2139Sjp161948 "NIST/SECG curve over a 571 bit binary field"
709*2139Sjp161948 };
710*2139Sjp161948
711*2139Sjp161948 static const unsigned char _EC_NIST_CHAR2_571B_SEED[] = {
712*2139Sjp161948 0x2A,0xA0,0x58,0xF7,0x3A,0x0E,0x33,0xAB,0x48,0x6B,
713*2139Sjp161948 0x0F,0x61,0x04,0x10,0xC5,0x3A,0x7F,0x13,0x23,0x10};
714*2139Sjp161948 static const EC_CURVE_DATA _EC_NIST_CHAR2_571B = {
715*2139Sjp161948 NID_X9_62_characteristic_two_field,
716*2139Sjp161948 "800000000000000000000000000000000000000000000000000000000000000000000"
717*2139Sjp161948 "000000000000000000000000000000000000000000000000000000000000000000000"
718*2139Sjp161948 "00425",
719*2139Sjp161948 "000000000000000000000000000000000000000000000000000000000000000000000"
720*2139Sjp161948 "000000000000000000000000000000000000000000000000000000000000000000000"
721*2139Sjp161948 "000001",
722*2139Sjp161948 "02F40E7E2221F295DE297117B7F3D62F5C6A97FFCB8CEFF1CD6BA8CE4A9A18AD84FFA"
723*2139Sjp161948 "BBD8EFA59332BE7AD6756A66E294AFD185A78FF12AA520E4DE739BACA0C7FFEFF7F29"
724*2139Sjp161948 "55727A",
725*2139Sjp161948 "0303001D34B856296C16C0D40D3CD7750A93D1D2955FA80AA5F40FC8DB7B2ABDBDE53"
726*2139Sjp161948 "950F4C0D293CDD711A35B67FB1499AE60038614F1394ABFA3B4C850D927E1E7769C8E"
727*2139Sjp161948 "EC2D19",
728*2139Sjp161948 "037BF27342DA639B6DCCFFFEB73D69D78C6C27A6009CBBCA1980F8533921E8A684423"
729*2139Sjp161948 "E43BAB08A576291AF8F461BB2A8B3531D2F0485C19B16E2F1516E23DD3C1A4827AF1B"
730*2139Sjp161948 "8AC15B",
731*2139Sjp161948 "03FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF"
732*2139Sjp161948 "FFFE661CE18FF55987308059B186823851EC7DD9CA1161DE93D5174D66E8382E9BB2F"
733*2139Sjp161948 "E84E47", 2,
734*2139Sjp161948 _EC_NIST_CHAR2_571B_SEED, 20,
735*2139Sjp161948 "NIST/SECG curve over a 571 bit binary field"
736*2139Sjp161948 };
737*2139Sjp161948
738*2139Sjp161948 static const unsigned char _EC_X9_62_CHAR2_163V1_SEED[] = {
739*2139Sjp161948 0xD2,0xC0,0xFB,0x15,0x76,0x08,0x60,0xDE,0xF1,0xEE,
740*2139Sjp161948 0xF4,0xD6,0x96,0xE6,0x76,0x87,0x56,0x15,0x17,0x54};
741*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_163V1 = {
742*2139Sjp161948 NID_X9_62_characteristic_two_field,
743*2139Sjp161948 "080000000000000000000000000000000000000107",
744*2139Sjp161948 "072546B5435234A422E0789675F432C89435DE5242",
745*2139Sjp161948 "00C9517D06D5240D3CFF38C74B20B6CD4D6F9DD4D9",
746*2139Sjp161948 "07AF69989546103D79329FCC3D74880F33BBE803CB",
747*2139Sjp161948 "01EC23211B5966ADEA1D3F87F7EA5848AEF0B7CA9F",
748*2139Sjp161948 "0400000000000000000001E60FC8821CC74DAEAFC1", 2,
749*2139Sjp161948 _EC_X9_62_CHAR2_163V1_SEED, 20,
750*2139Sjp161948 "X9.62 curve over a 163 bit binary field"
751*2139Sjp161948 };
752*2139Sjp161948
753*2139Sjp161948 static const unsigned char _EC_X9_62_CHAR2_163V2_SEED[] = {
754*2139Sjp161948 0x53,0x81,0x4C,0x05,0x0D,0x44,0xD6,0x96,0xE6,0x76,
755*2139Sjp161948 0x87,0x56,0x15,0x17,0x58,0x0C,0xA4,0xE2,0x9F,0xFD};
756*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_163V2 = {
757*2139Sjp161948 NID_X9_62_characteristic_two_field,
758*2139Sjp161948 "080000000000000000000000000000000000000107",
759*2139Sjp161948 "0108B39E77C4B108BED981ED0E890E117C511CF072",
760*2139Sjp161948 "0667ACEB38AF4E488C407433FFAE4F1C811638DF20",
761*2139Sjp161948 "0024266E4EB5106D0A964D92C4860E2671DB9B6CC5",
762*2139Sjp161948 "079F684DDF6684C5CD258B3890021B2386DFD19FC5",
763*2139Sjp161948 "03FFFFFFFFFFFFFFFFFFFDF64DE1151ADBB78F10A7", 2,
764*2139Sjp161948 _EC_X9_62_CHAR2_163V2_SEED, 20,
765*2139Sjp161948 "X9.62 curve over a 163 bit binary field"
766*2139Sjp161948 };
767*2139Sjp161948
768*2139Sjp161948 static const unsigned char _EC_X9_62_CHAR2_163V3_SEED[] = {
769*2139Sjp161948 0x50,0xCB,0xF1,0xD9,0x5C,0xA9,0x4D,0x69,0x6E,0x67,
770*2139Sjp161948 0x68,0x75,0x61,0x51,0x75,0xF1,0x6A,0x36,0xA3,0xB8};
771*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_163V3 = {
772*2139Sjp161948 NID_X9_62_characteristic_two_field,
773*2139Sjp161948 "080000000000000000000000000000000000000107",
774*2139Sjp161948 "07A526C63D3E25A256A007699F5447E32AE456B50E",
775*2139Sjp161948 "03F7061798EB99E238FD6F1BF95B48FEEB4854252B",
776*2139Sjp161948 "02F9F87B7C574D0BDECF8A22E6524775F98CDEBDCB",
777*2139Sjp161948 "05B935590C155E17EA48EB3FF3718B893DF59A05D0",
778*2139Sjp161948 "03FFFFFFFFFFFFFFFFFFFE1AEE140F110AFF961309", 2,
779*2139Sjp161948 _EC_X9_62_CHAR2_163V3_SEED, 20,
780*2139Sjp161948 "X9.62 curve over a 163 bit binary field"
781*2139Sjp161948 };
782*2139Sjp161948
783*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_176V1 = {
784*2139Sjp161948 NID_X9_62_characteristic_two_field,
785*2139Sjp161948 "0100000000000000000000000000000000080000000007",
786*2139Sjp161948 "E4E6DB2995065C407D9D39B8D0967B96704BA8E9C90B",
787*2139Sjp161948 "5DDA470ABE6414DE8EC133AE28E9BBD7FCEC0AE0FFF2",
788*2139Sjp161948 "8D16C2866798B600F9F08BB4A8E860F3298CE04A5798",
789*2139Sjp161948 "6FA4539C2DADDDD6BAB5167D61B436E1D92BB16A562C",
790*2139Sjp161948 "00010092537397ECA4F6145799D62B0A19CE06FE26AD", 0xFF6E,
791*2139Sjp161948 NULL, 0,
792*2139Sjp161948 "X9.62 curve over a 176 bit binary field"
793*2139Sjp161948 };
794*2139Sjp161948
795*2139Sjp161948 static const unsigned char _EC_X9_62_CHAR2_191V1_SEED[] = {
796*2139Sjp161948 0x4E,0x13,0xCA,0x54,0x27,0x44,0xD6,0x96,0xE6,0x76,
797*2139Sjp161948 0x87,0x56,0x15,0x17,0x55,0x2F,0x27,0x9A,0x8C,0x84};
798*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_191V1 = {
799*2139Sjp161948 NID_X9_62_characteristic_two_field,
800*2139Sjp161948 "800000000000000000000000000000000000000000000201",
801*2139Sjp161948 "2866537B676752636A68F56554E12640276B649EF7526267",
802*2139Sjp161948 "2E45EF571F00786F67B0081B9495A3D95462F5DE0AA185EC",
803*2139Sjp161948 "36B3DAF8A23206F9C4F299D7B21A9C369137F2C84AE1AA0D",
804*2139Sjp161948 "765BE73433B3F95E332932E70EA245CA2418EA0EF98018FB",
805*2139Sjp161948 "40000000000000000000000004A20E90C39067C893BBB9A5", 2,
806*2139Sjp161948 _EC_X9_62_CHAR2_191V1_SEED, 20,
807*2139Sjp161948 "X9.62 curve over a 191 bit binary field"
808*2139Sjp161948 };
809*2139Sjp161948
810*2139Sjp161948 static const unsigned char _EC_X9_62_CHAR2_191V2_SEED[] = {
811*2139Sjp161948 0x08,0x71,0xEF,0x2F,0xEF,0x24,0xD6,0x96,0xE6,0x76,
812*2139Sjp161948 0x87,0x56,0x15,0x17,0x58,0xBE,0xE0,0xD9,0x5C,0x15};
813*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_191V2 = {
814*2139Sjp161948 NID_X9_62_characteristic_two_field,
815*2139Sjp161948 "800000000000000000000000000000000000000000000201",
816*2139Sjp161948 "401028774D7777C7B7666D1366EA432071274F89FF01E718",
817*2139Sjp161948 "0620048D28BCBD03B6249C99182B7C8CD19700C362C46A01",
818*2139Sjp161948 "3809B2B7CC1B28CC5A87926AAD83FD28789E81E2C9E3BF10",
819*2139Sjp161948 "17434386626D14F3DBF01760D9213A3E1CF37AEC437D668A",
820*2139Sjp161948 "20000000000000000000000050508CB89F652824E06B8173", 4,
821*2139Sjp161948 _EC_X9_62_CHAR2_191V2_SEED, 20,
822*2139Sjp161948 "X9.62 curve over a 191 bit binary field"
823*2139Sjp161948 };
824*2139Sjp161948
825*2139Sjp161948 static const unsigned char _EC_X9_62_CHAR2_191V3_SEED[] = {
826*2139Sjp161948 0xE0,0x53,0x51,0x2D,0xC6,0x84,0xD6,0x96,0xE6,0x76,
827*2139Sjp161948 0x87,0x56,0x15,0x17,0x50,0x67,0xAE,0x78,0x6D,0x1F};
828*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_191V3 = {
829*2139Sjp161948 NID_X9_62_characteristic_two_field,
830*2139Sjp161948 "800000000000000000000000000000000000000000000201",
831*2139Sjp161948 "6C01074756099122221056911C77D77E77A777E7E7E77FCB",
832*2139Sjp161948 "71FE1AF926CF847989EFEF8DB459F66394D90F32AD3F15E8",
833*2139Sjp161948 "375D4CE24FDE434489DE8746E71786015009E66E38A926DD",
834*2139Sjp161948 "545A39176196575D985999366E6AD34CE0A77CD7127B06BE",
835*2139Sjp161948 "155555555555555555555555610C0B196812BFB6288A3EA3", 6,
836*2139Sjp161948 _EC_X9_62_CHAR2_191V3_SEED, 20,
837*2139Sjp161948 "X9.62 curve over a 191 bit binary field"
838*2139Sjp161948 };
839*2139Sjp161948
840*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_208W1 = {
841*2139Sjp161948 NID_X9_62_characteristic_two_field,
842*2139Sjp161948 "010000000000000000000000000000000800000000000000000007",
843*2139Sjp161948 "0000000000000000000000000000000000000000000000000000",
844*2139Sjp161948 "C8619ED45A62E6212E1160349E2BFA844439FAFC2A3FD1638F9E",
845*2139Sjp161948 "89FDFBE4ABE193DF9559ECF07AC0CE78554E2784EB8C1ED1A57A",
846*2139Sjp161948 "0F55B51A06E78E9AC38A035FF520D8B01781BEB1A6BB08617DE3",
847*2139Sjp161948 "000101BAF95C9723C57B6C21DA2EFF2D5ED588BDD5717E212F9D", 0xFE48,
848*2139Sjp161948 NULL, 0,
849*2139Sjp161948 "X9.62 curve over a 208 bit binary field"
850*2139Sjp161948 };
851*2139Sjp161948
852*2139Sjp161948 static const unsigned char _EC_X9_62_CHAR2_239V1_SEED[] = {
853*2139Sjp161948 0xD3,0x4B,0x9A,0x4D,0x69,0x6E,0x67,0x68,0x75,0x61,
854*2139Sjp161948 0x51,0x75,0xCA,0x71,0xB9,0x20,0xBF,0xEF,0xB0,0x5D};
855*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_239V1 = {
856*2139Sjp161948 NID_X9_62_characteristic_two_field,
857*2139Sjp161948 "800000000000000000000000000000000000000000000000001000000001",
858*2139Sjp161948 "32010857077C5431123A46B808906756F543423E8D27877578125778AC76",
859*2139Sjp161948 "790408F2EEDAF392B012EDEFB3392F30F4327C0CA3F31FC383C422AA8C16",
860*2139Sjp161948 "57927098FA932E7C0A96D3FD5B706EF7E5F5C156E16B7E7C86038552E91D",
861*2139Sjp161948 "61D8EE5077C33FECF6F1A16B268DE469C3C7744EA9A971649FC7A9616305",
862*2139Sjp161948 "2000000000000000000000000000000F4D42FFE1492A4993F1CAD666E447", 4,
863*2139Sjp161948 _EC_X9_62_CHAR2_239V1_SEED, 20,
864*2139Sjp161948 "X9.62 curve over a 239 bit binary field"
865*2139Sjp161948 };
866*2139Sjp161948
867*2139Sjp161948 static const unsigned char _EC_X9_62_CHAR2_239V2_SEED[] = {
868*2139Sjp161948 0x2A,0xA6,0x98,0x2F,0xDF,0xA4,0xD6,0x96,0xE6,0x76,
869*2139Sjp161948 0x87,0x56,0x15,0x17,0x5D,0x26,0x67,0x27,0x27,0x7D};
870*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_239V2 = {
871*2139Sjp161948 NID_X9_62_characteristic_two_field,
872*2139Sjp161948 "800000000000000000000000000000000000000000000000001000000001",
873*2139Sjp161948 "4230017757A767FAE42398569B746325D45313AF0766266479B75654E65F",
874*2139Sjp161948 "5037EA654196CFF0CD82B2C14A2FCF2E3FF8775285B545722F03EACDB74B",
875*2139Sjp161948 "28F9D04E900069C8DC47A08534FE76D2B900B7D7EF31F5709F200C4CA205",
876*2139Sjp161948 "5667334C45AFF3B5A03BAD9DD75E2C71A99362567D5453F7FA6E227EC833",
877*2139Sjp161948 "1555555555555555555555555555553C6F2885259C31E3FCDF154624522D", 6,
878*2139Sjp161948 _EC_X9_62_CHAR2_239V2_SEED, 20,
879*2139Sjp161948 "X9.62 curve over a 239 bit binary field"
880*2139Sjp161948 };
881*2139Sjp161948
882*2139Sjp161948 static const unsigned char _EC_X9_62_CHAR2_239V3_SEED[] = {
883*2139Sjp161948 0x9E,0x07,0x6F,0x4D,0x69,0x6E,0x67,0x68,0x75,0x61,
884*2139Sjp161948 0x51,0x75,0xE1,0x1E,0x9F,0xDD,0x77,0xF9,0x20,0x41};
885*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_239V3 = {
886*2139Sjp161948 NID_X9_62_characteristic_two_field,
887*2139Sjp161948 "800000000000000000000000000000000000000000000000001000000001",
888*2139Sjp161948 "01238774666A67766D6676F778E676B66999176666E687666D8766C66A9F",
889*2139Sjp161948 "6A941977BA9F6A435199ACFC51067ED587F519C5ECB541B8E44111DE1D40",
890*2139Sjp161948 "70F6E9D04D289C4E89913CE3530BFDE903977D42B146D539BF1BDE4E9C92",
891*2139Sjp161948 "2E5A0EAF6E5E1305B9004DCE5C0ED7FE59A35608F33837C816D80B79F461",
892*2139Sjp161948 "0CCCCCCCCCCCCCCCCCCCCCCCCCCCCCAC4912D2D9DF903EF9888B8A0E4CFF", 0xA,
893*2139Sjp161948 _EC_X9_62_CHAR2_239V3_SEED, 20,
894*2139Sjp161948 "X9.62 curve over a 239 bit binary field"
895*2139Sjp161948 };
896*2139Sjp161948
897*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_272W1 = {
898*2139Sjp161948 NID_X9_62_characteristic_two_field,
899*2139Sjp161948 "010000000000000000000000000000000000000000000000000000010000000000000"
900*2139Sjp161948 "B",
901*2139Sjp161948 "91A091F03B5FBA4AB2CCF49C4EDD220FB028712D42BE752B2C40094DBACDB586FB20",
902*2139Sjp161948 "7167EFC92BB2E3CE7C8AAAFF34E12A9C557003D7C73A6FAF003F99F6CC8482E540F7",
903*2139Sjp161948 "6108BABB2CEEBCF787058A056CBE0CFE622D7723A289E08A07AE13EF0D10D171DD8D",
904*2139Sjp161948 "10C7695716851EEF6BA7F6872E6142FBD241B830FF5EFCACECCAB05E02005DDE9D23",
905*2139Sjp161948 "000100FAF51354E0E39E4892DF6E319C72C8161603FA45AA7B998A167B8F1E629521",
906*2139Sjp161948 0xFF06,
907*2139Sjp161948 NULL, 0,
908*2139Sjp161948 "X9.62 curve over a 272 bit binary field"
909*2139Sjp161948 };
910*2139Sjp161948
911*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_304W1 = {
912*2139Sjp161948 NID_X9_62_characteristic_two_field,
913*2139Sjp161948 "010000000000000000000000000000000000000000000000000000000000000000000"
914*2139Sjp161948 "000000807",
915*2139Sjp161948 "FD0D693149A118F651E6DCE6802085377E5F882D1B510B44160074C1288078365A039"
916*2139Sjp161948 "6C8E681",
917*2139Sjp161948 "BDDB97E555A50A908E43B01C798EA5DAA6788F1EA2794EFCF57166B8C14039601E558"
918*2139Sjp161948 "27340BE",
919*2139Sjp161948 "197B07845E9BE2D96ADB0F5F3C7F2CFFBD7A3EB8B6FEC35C7FD67F26DDF6285A644F7"
920*2139Sjp161948 "40A2614",
921*2139Sjp161948 "E19FBEB76E0DA171517ECF401B50289BF014103288527A9B416A105E80260B549FDC1"
922*2139Sjp161948 "B92C03B",
923*2139Sjp161948 "000101D556572AABAC800101D556572AABAC8001022D5C91DD173F8FB561DA6899164"
924*2139Sjp161948 "443051D", 0xFE2E,
925*2139Sjp161948 NULL, 0,
926*2139Sjp161948 "X9.62 curve over a 304 bit binary field"
927*2139Sjp161948 };
928*2139Sjp161948
929*2139Sjp161948 static const unsigned char _EC_X9_62_CHAR2_359V1_SEED[] = {
930*2139Sjp161948 0x2B,0x35,0x49,0x20,0xB7,0x24,0xD6,0x96,0xE6,0x76,
931*2139Sjp161948 0x87,0x56,0x15,0x17,0x58,0x5B,0xA1,0x33,0x2D,0xC6};
932*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_359V1 = {
933*2139Sjp161948 NID_X9_62_characteristic_two_field,
934*2139Sjp161948 "800000000000000000000000000000000000000000000000000000000000000000000"
935*2139Sjp161948 "000100000000000000001",
936*2139Sjp161948 "5667676A654B20754F356EA92017D946567C46675556F19556A04616B567D223A5E05"
937*2139Sjp161948 "656FB549016A96656A557",
938*2139Sjp161948 "2472E2D0197C49363F1FE7F5B6DB075D52B6947D135D8CA445805D39BC34562608968"
939*2139Sjp161948 "7742B6329E70680231988",
940*2139Sjp161948 "3C258EF3047767E7EDE0F1FDAA79DAEE3841366A132E163ACED4ED2401DF9C6BDCDE9"
941*2139Sjp161948 "8E8E707C07A2239B1B097",
942*2139Sjp161948 "53D7E08529547048121E9C95F3791DD804963948F34FAE7BF44EA82365DC7868FE57E"
943*2139Sjp161948 "4AE2DE211305A407104BD",
944*2139Sjp161948 "01AF286BCA1AF286BCA1AF286BCA1AF286BCA1AF286BC9FB8F6B85C556892C20A7EB9"
945*2139Sjp161948 "64FE7719E74F490758D3B", 0x4C,
946*2139Sjp161948 _EC_X9_62_CHAR2_359V1_SEED, 20,
947*2139Sjp161948 "X9.62 curve over a 359 bit binary field"
948*2139Sjp161948 };
949*2139Sjp161948
950*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_368W1 = {
951*2139Sjp161948 NID_X9_62_characteristic_two_field,
952*2139Sjp161948 "010000000000000000000000000000000000000000000000000000000000000000000"
953*2139Sjp161948 "0002000000000000000000007",
954*2139Sjp161948 "E0D2EE25095206F5E2A4F9ED229F1F256E79A0E2B455970D8D0D865BD94778C576D62"
955*2139Sjp161948 "F0AB7519CCD2A1A906AE30D",
956*2139Sjp161948 "FC1217D4320A90452C760A58EDCD30C8DD069B3C34453837A34ED50CB54917E1C2112"
957*2139Sjp161948 "D84D164F444F8F74786046A",
958*2139Sjp161948 "1085E2755381DCCCE3C1557AFA10C2F0C0C2825646C5B34A394CBCFA8BC16B22E7E78"
959*2139Sjp161948 "9E927BE216F02E1FB136A5F",
960*2139Sjp161948 "7B3EB1BDDCBA62D5D8B2059B525797FC73822C59059C623A45FF3843CEE8F87CD1855"
961*2139Sjp161948 "ADAA81E2A0750B80FDA2310",
962*2139Sjp161948 "00010090512DA9AF72B08349D98A5DD4C7B0532ECA51CE03E2D10F3B7AC579BD87E90"
963*2139Sjp161948 "9AE40A6F131E9CFCE5BD967", 0xFF70,
964*2139Sjp161948 NULL, 0,
965*2139Sjp161948 "X9.62 curve over a 368 bit binary field"
966*2139Sjp161948 };
967*2139Sjp161948
968*2139Sjp161948 static const EC_CURVE_DATA _EC_X9_62_CHAR2_431R1 = {
969*2139Sjp161948 NID_X9_62_characteristic_two_field,
970*2139Sjp161948 "800000000000000000000000000000000000000000000000000000000000000000000"
971*2139Sjp161948 "000000001000000000000000000000000000001",
972*2139Sjp161948 "1A827EF00DD6FC0E234CAF046C6A5D8A85395B236CC4AD2CF32A0CADBDC9DDF620B0E"
973*2139Sjp161948 "B9906D0957F6C6FEACD615468DF104DE296CD8F",
974*2139Sjp161948 "10D9B4A3D9047D8B154359ABFB1B7F5485B04CEB868237DDC9DEDA982A679A5A919B6"
975*2139Sjp161948 "26D4E50A8DD731B107A9962381FB5D807BF2618",
976*2139Sjp161948 "120FC05D3C67A99DE161D2F4092622FECA701BE4F50F4758714E8A87BBF2A658EF8C2"
977*2139Sjp161948 "1E7C5EFE965361F6C2999C0C247B0DBD70CE6B7",
978*2139Sjp161948 "20D0AF8903A96F8D5FA2C255745D3C451B302C9346D9B7E485E7BCE41F6B591F3E8F6"
979*2139Sjp161948 "ADDCBB0BC4C2F947A7DE1A89B625D6A598B3760",
980*2139Sjp161948 "0340340340340340340340340340340340340340340340340340340323C313FAB5058"
981*2139Sjp161948 "9703B5EC68D3587FEC60D161CC149C1AD4A91", 0x2760,
982*2139Sjp161948 NULL, 0,
983*2139Sjp161948 "X9.62 curve over a 431 bit binary field"
984*2139Sjp161948 };
985*2139Sjp161948
986*2139Sjp161948 static const EC_CURVE_DATA _EC_WTLS_1 = {
987*2139Sjp161948 NID_X9_62_characteristic_two_field,
988*2139Sjp161948 "020000000000000000000000000201",
989*2139Sjp161948 "1",
990*2139Sjp161948 "1",
991*2139Sjp161948 "01667979A40BA497E5D5C270780617",
992*2139Sjp161948 "00F44B4AF1ECC2630E08785CEBCC15",
993*2139Sjp161948 "00FFFFFFFFFFFFFFFDBF91AF6DEA73", 2,
994*2139Sjp161948 NULL, 0,
995*2139Sjp161948 "WTLS curve over a 113 bit binary field"
996*2139Sjp161948 };
997*2139Sjp161948
998*2139Sjp161948 /* IPSec curves */
999*2139Sjp161948 /* NOTE: The of curves over a extension field of non prime degree
1000*2139Sjp161948 * is not recommended (Weil-descent).
1001*2139Sjp161948 * As the group order is not a prime this curve is not suitable
1002*2139Sjp161948 * for ECDSA.
1003*2139Sjp161948 */
1004*2139Sjp161948 static const EC_CURVE_DATA _EC_IPSEC_155_ID3 = {
1005*2139Sjp161948 NID_X9_62_characteristic_two_field,
1006*2139Sjp161948 "0800000000000000000000004000000000000001",
1007*2139Sjp161948 "0",
1008*2139Sjp161948 "07338f",
1009*2139Sjp161948 "7b",
1010*2139Sjp161948 "1c8",
1011*2139Sjp161948 "2AAAAAAAAAAAAAAAAAAC7F3C7881BD0868FA86C",3,
1012*2139Sjp161948 NULL, 0,
1013*2139Sjp161948 "\n\tIPSec/IKE/Oakley curve #3 over a 155 bit binary field.\n"
1014*2139Sjp161948 "\tNot suitable for ECDSA.\n\tQuestionable extension field!"
1015*2139Sjp161948 };
1016*2139Sjp161948
1017*2139Sjp161948 /* NOTE: The of curves over a extension field of non prime degree
1018*2139Sjp161948 * is not recommended (Weil-descent).
1019*2139Sjp161948 * As the group order is not a prime this curve is not suitable
1020*2139Sjp161948 * for ECDSA.
1021*2139Sjp161948 */
1022*2139Sjp161948 static const EC_CURVE_DATA _EC_IPSEC_185_ID4 = {
1023*2139Sjp161948 NID_X9_62_characteristic_two_field,
1024*2139Sjp161948 "020000000000000000000000000000200000000000000001",
1025*2139Sjp161948 "0",
1026*2139Sjp161948 "1ee9",
1027*2139Sjp161948 "18",
1028*2139Sjp161948 "0d",
1029*2139Sjp161948 "FFFFFFFFFFFFFFFFFFFFFFEDF97C44DB9F2420BAFCA75E",2,
1030*2139Sjp161948 NULL, 0,
1031*2139Sjp161948 "\n\tIPSec/IKE/Oakley curve #4 over a 185 bit binary field.\n"
1032*2139Sjp161948 "\tNot suitable for ECDSA.\n\tQuestionable extension field!"
1033*2139Sjp161948 };
1034*2139Sjp161948
1035*2139Sjp161948 typedef struct _ec_list_element_st {
1036*2139Sjp161948 int nid;
1037*2139Sjp161948 const EC_CURVE_DATA *data;
1038*2139Sjp161948 } ec_list_element;
1039*2139Sjp161948
1040*2139Sjp161948 static const ec_list_element curve_list[] = {
1041*2139Sjp161948 /* prime field curves */
1042*2139Sjp161948 /* secg curves */
1043*2139Sjp161948 { NID_secp112r1, &_EC_SECG_PRIME_112R1},
1044*2139Sjp161948 { NID_secp112r2, &_EC_SECG_PRIME_112R2},
1045*2139Sjp161948 { NID_secp128r1, &_EC_SECG_PRIME_128R1},
1046*2139Sjp161948 { NID_secp128r2, &_EC_SECG_PRIME_128R2},
1047*2139Sjp161948 { NID_secp160k1, &_EC_SECG_PRIME_160K1},
1048*2139Sjp161948 { NID_secp160r1, &_EC_SECG_PRIME_160R1},
1049*2139Sjp161948 { NID_secp160r2, &_EC_SECG_PRIME_160R2},
1050*2139Sjp161948 /* SECG secp192r1 is the same as X9.62 prime192v1 and hence omitted */
1051*2139Sjp161948 { NID_secp192k1, &_EC_SECG_PRIME_192K1},
1052*2139Sjp161948 { NID_secp224k1, &_EC_SECG_PRIME_224K1},
1053*2139Sjp161948 { NID_secp224r1, &_EC_NIST_PRIME_224},
1054*2139Sjp161948 { NID_secp256k1, &_EC_SECG_PRIME_256K1},
1055*2139Sjp161948 /* SECG secp256r1 is the same as X9.62 prime256v1 and hence omitted */
1056*2139Sjp161948 { NID_secp384r1, &_EC_NIST_PRIME_384},
1057*2139Sjp161948 { NID_secp521r1, &_EC_NIST_PRIME_521},
1058*2139Sjp161948 /* X9.62 curves */
1059*2139Sjp161948 { NID_X9_62_prime192v1, &_EC_NIST_PRIME_192},
1060*2139Sjp161948 { NID_X9_62_prime192v2, &_EC_X9_62_PRIME_192V2},
1061*2139Sjp161948 { NID_X9_62_prime192v3, &_EC_X9_62_PRIME_192V3},
1062*2139Sjp161948 { NID_X9_62_prime239v1, &_EC_X9_62_PRIME_239V1},
1063*2139Sjp161948 { NID_X9_62_prime239v2, &_EC_X9_62_PRIME_239V2},
1064*2139Sjp161948 { NID_X9_62_prime239v3, &_EC_X9_62_PRIME_239V3},
1065*2139Sjp161948 { NID_X9_62_prime256v1, &_EC_X9_62_PRIME_256V1},
1066*2139Sjp161948 /* characteristic two field curves */
1067*2139Sjp161948 /* NIST/SECG curves */
1068*2139Sjp161948 { NID_sect113r1, &_EC_SECG_CHAR2_113R1},
1069*2139Sjp161948 { NID_sect113r2, &_EC_SECG_CHAR2_113R2},
1070*2139Sjp161948 { NID_sect131r1, &_EC_SECG_CHAR2_131R1},
1071*2139Sjp161948 { NID_sect131r2, &_EC_SECG_CHAR2_131R2},
1072*2139Sjp161948 { NID_sect163k1, &_EC_NIST_CHAR2_163K },
1073*2139Sjp161948 { NID_sect163r1, &_EC_SECG_CHAR2_163R1},
1074*2139Sjp161948 { NID_sect163r2, &_EC_NIST_CHAR2_163B },
1075*2139Sjp161948 { NID_sect193r1, &_EC_SECG_CHAR2_193R1},
1076*2139Sjp161948 { NID_sect193r2, &_EC_SECG_CHAR2_193R2},
1077*2139Sjp161948 { NID_sect233k1, &_EC_NIST_CHAR2_233K },
1078*2139Sjp161948 { NID_sect233r1, &_EC_NIST_CHAR2_233B },
1079*2139Sjp161948 { NID_sect239k1, &_EC_SECG_CHAR2_239K1},
1080*2139Sjp161948 { NID_sect283k1, &_EC_NIST_CHAR2_283K },
1081*2139Sjp161948 { NID_sect283r1, &_EC_NIST_CHAR2_283B },
1082*2139Sjp161948 { NID_sect409k1, &_EC_NIST_CHAR2_409K },
1083*2139Sjp161948 { NID_sect409r1, &_EC_NIST_CHAR2_409B },
1084*2139Sjp161948 { NID_sect571k1, &_EC_NIST_CHAR2_571K },
1085*2139Sjp161948 { NID_sect571r1, &_EC_NIST_CHAR2_571B },
1086*2139Sjp161948 /* X9.62 curves */
1087*2139Sjp161948 { NID_X9_62_c2pnb163v1, &_EC_X9_62_CHAR2_163V1},
1088*2139Sjp161948 { NID_X9_62_c2pnb163v2, &_EC_X9_62_CHAR2_163V2},
1089*2139Sjp161948 { NID_X9_62_c2pnb163v3, &_EC_X9_62_CHAR2_163V3},
1090*2139Sjp161948 { NID_X9_62_c2pnb176v1, &_EC_X9_62_CHAR2_176V1},
1091*2139Sjp161948 { NID_X9_62_c2tnb191v1, &_EC_X9_62_CHAR2_191V1},
1092*2139Sjp161948 { NID_X9_62_c2tnb191v2, &_EC_X9_62_CHAR2_191V2},
1093*2139Sjp161948 { NID_X9_62_c2tnb191v3, &_EC_X9_62_CHAR2_191V3},
1094*2139Sjp161948 { NID_X9_62_c2pnb208w1, &_EC_X9_62_CHAR2_208W1},
1095*2139Sjp161948 { NID_X9_62_c2tnb239v1, &_EC_X9_62_CHAR2_239V1},
1096*2139Sjp161948 { NID_X9_62_c2tnb239v2, &_EC_X9_62_CHAR2_239V2},
1097*2139Sjp161948 { NID_X9_62_c2tnb239v3, &_EC_X9_62_CHAR2_239V3},
1098*2139Sjp161948 { NID_X9_62_c2pnb272w1, &_EC_X9_62_CHAR2_272W1},
1099*2139Sjp161948 { NID_X9_62_c2pnb304w1, &_EC_X9_62_CHAR2_304W1},
1100*2139Sjp161948 { NID_X9_62_c2tnb359v1, &_EC_X9_62_CHAR2_359V1},
1101*2139Sjp161948 { NID_X9_62_c2pnb368w1, &_EC_X9_62_CHAR2_368W1},
1102*2139Sjp161948 { NID_X9_62_c2tnb431r1, &_EC_X9_62_CHAR2_431R1},
1103*2139Sjp161948 /* the WAP/WTLS curves */
1104*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls1, &_EC_WTLS_1},
1105*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls3, &_EC_NIST_CHAR2_163K},
1106*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls4, &_EC_SECG_CHAR2_113R1},
1107*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls5, &_EC_X9_62_CHAR2_163V1},
1108*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls6, &_EC_SECG_PRIME_112R1},
1109*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls7, &_EC_SECG_PRIME_160R2},
1110*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls8, &_EC_WTLS_8},
1111*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls9, &_EC_WTLS_9 },
1112*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls10, &_EC_NIST_CHAR2_233K},
1113*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls11, &_EC_NIST_CHAR2_233B},
1114*2139Sjp161948 { NID_wap_wsg_idm_ecid_wtls12, &_EC_WTLS_12},
1115*2139Sjp161948 /* IPSec curves */
1116*2139Sjp161948 { NID_ipsec3, &_EC_IPSEC_155_ID3},
1117*2139Sjp161948 { NID_ipsec4, &_EC_IPSEC_185_ID4},
1118*2139Sjp161948 };
1119*2139Sjp161948
1120*2139Sjp161948 static size_t curve_list_length = sizeof(curve_list)/sizeof(ec_list_element);
1121*2139Sjp161948
ec_group_new_from_data(const EC_CURVE_DATA * data)1122*2139Sjp161948 static EC_GROUP *ec_group_new_from_data(const EC_CURVE_DATA *data)
1123*2139Sjp161948 {
1124*2139Sjp161948 EC_GROUP *group=NULL;
1125*2139Sjp161948 EC_POINT *P=NULL;
1126*2139Sjp161948 BN_CTX *ctx=NULL;
1127*2139Sjp161948 BIGNUM *p=NULL, *a=NULL, *b=NULL, *x=NULL, *y=NULL, *order=NULL;
1128*2139Sjp161948 int ok=0;
1129*2139Sjp161948
1130*2139Sjp161948 if ((ctx = BN_CTX_new()) == NULL)
1131*2139Sjp161948 {
1132*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_MALLOC_FAILURE);
1133*2139Sjp161948 goto err;
1134*2139Sjp161948 }
1135*2139Sjp161948 if ((p = BN_new()) == NULL || (a = BN_new()) == NULL ||
1136*2139Sjp161948 (b = BN_new()) == NULL || (x = BN_new()) == NULL ||
1137*2139Sjp161948 (y = BN_new()) == NULL || (order = BN_new()) == NULL)
1138*2139Sjp161948 {
1139*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_MALLOC_FAILURE);
1140*2139Sjp161948 goto err;
1141*2139Sjp161948 }
1142*2139Sjp161948
1143*2139Sjp161948 if (!BN_hex2bn(&p, data->p) || !BN_hex2bn(&a, data->a)
1144*2139Sjp161948 || !BN_hex2bn(&b, data->b))
1145*2139Sjp161948 {
1146*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_BN_LIB);
1147*2139Sjp161948 goto err;
1148*2139Sjp161948 }
1149*2139Sjp161948
1150*2139Sjp161948 if (data->field_type == NID_X9_62_prime_field)
1151*2139Sjp161948 {
1152*2139Sjp161948 if ((group = EC_GROUP_new_curve_GFp(p, a, b, ctx)) == NULL)
1153*2139Sjp161948 {
1154*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
1155*2139Sjp161948 goto err;
1156*2139Sjp161948 }
1157*2139Sjp161948 }
1158*2139Sjp161948 else
1159*2139Sjp161948 { /* field_type == NID_X9_62_characteristic_two_field */
1160*2139Sjp161948 if ((group = EC_GROUP_new_curve_GF2m(p, a, b, ctx)) == NULL)
1161*2139Sjp161948 {
1162*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
1163*2139Sjp161948 goto err;
1164*2139Sjp161948 }
1165*2139Sjp161948 }
1166*2139Sjp161948
1167*2139Sjp161948 if ((P = EC_POINT_new(group)) == NULL)
1168*2139Sjp161948 {
1169*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
1170*2139Sjp161948 goto err;
1171*2139Sjp161948 }
1172*2139Sjp161948
1173*2139Sjp161948 if (!BN_hex2bn(&x, data->x) || !BN_hex2bn(&y, data->y))
1174*2139Sjp161948 {
1175*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_BN_LIB);
1176*2139Sjp161948 goto err;
1177*2139Sjp161948 }
1178*2139Sjp161948 if (!EC_POINT_set_affine_coordinates_GF2m(group, P, x, y, ctx))
1179*2139Sjp161948 {
1180*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
1181*2139Sjp161948 goto err;
1182*2139Sjp161948 }
1183*2139Sjp161948 if (!BN_hex2bn(&order, data->order) || !BN_set_word(x, data->cofactor))
1184*2139Sjp161948 {
1185*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_BN_LIB);
1186*2139Sjp161948 goto err;
1187*2139Sjp161948 }
1188*2139Sjp161948 if (!EC_GROUP_set_generator(group, P, order, x))
1189*2139Sjp161948 {
1190*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
1191*2139Sjp161948 goto err;
1192*2139Sjp161948 }
1193*2139Sjp161948 if (data->seed)
1194*2139Sjp161948 {
1195*2139Sjp161948 if (!EC_GROUP_set_seed(group, data->seed, data->seed_len))
1196*2139Sjp161948 {
1197*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
1198*2139Sjp161948 goto err;
1199*2139Sjp161948 }
1200*2139Sjp161948 }
1201*2139Sjp161948 ok=1;
1202*2139Sjp161948 err:
1203*2139Sjp161948 if (!ok)
1204*2139Sjp161948 {
1205*2139Sjp161948 EC_GROUP_free(group);
1206*2139Sjp161948 group = NULL;
1207*2139Sjp161948 }
1208*2139Sjp161948 if (P)
1209*2139Sjp161948 EC_POINT_free(P);
1210*2139Sjp161948 if (ctx)
1211*2139Sjp161948 BN_CTX_free(ctx);
1212*2139Sjp161948 if (p)
1213*2139Sjp161948 BN_free(p);
1214*2139Sjp161948 if (a)
1215*2139Sjp161948 BN_free(a);
1216*2139Sjp161948 if (b)
1217*2139Sjp161948 BN_free(b);
1218*2139Sjp161948 if (order)
1219*2139Sjp161948 BN_free(order);
1220*2139Sjp161948 if (x)
1221*2139Sjp161948 BN_free(x);
1222*2139Sjp161948 if (y)
1223*2139Sjp161948 BN_free(y);
1224*2139Sjp161948 return group;
1225*2139Sjp161948 }
1226*2139Sjp161948
EC_GROUP_new_by_curve_name(int nid)1227*2139Sjp161948 EC_GROUP *EC_GROUP_new_by_curve_name(int nid)
1228*2139Sjp161948 {
1229*2139Sjp161948 size_t i;
1230*2139Sjp161948 EC_GROUP *ret = NULL;
1231*2139Sjp161948
1232*2139Sjp161948 if (nid <= 0)
1233*2139Sjp161948 return NULL;
1234*2139Sjp161948
1235*2139Sjp161948 for (i=0; i<curve_list_length; i++)
1236*2139Sjp161948 if (curve_list[i].nid == nid)
1237*2139Sjp161948 {
1238*2139Sjp161948 ret = ec_group_new_from_data(curve_list[i].data);
1239*2139Sjp161948 break;
1240*2139Sjp161948 }
1241*2139Sjp161948
1242*2139Sjp161948 if (ret == NULL)
1243*2139Sjp161948 {
1244*2139Sjp161948 ECerr(EC_F_EC_GROUP_NEW_BY_CURVE_NAME, EC_R_UNKNOWN_GROUP);
1245*2139Sjp161948 return NULL;
1246*2139Sjp161948 }
1247*2139Sjp161948
1248*2139Sjp161948 EC_GROUP_set_curve_name(ret, nid);
1249*2139Sjp161948
1250*2139Sjp161948 return ret;
1251*2139Sjp161948 }
1252*2139Sjp161948
EC_get_builtin_curves(EC_builtin_curve * r,size_t nitems)1253*2139Sjp161948 size_t EC_get_builtin_curves(EC_builtin_curve *r, size_t nitems)
1254*2139Sjp161948 {
1255*2139Sjp161948 size_t i, min;
1256*2139Sjp161948
1257*2139Sjp161948 if (r == NULL || nitems == 0)
1258*2139Sjp161948 return curve_list_length;
1259*2139Sjp161948
1260*2139Sjp161948 min = nitems < curve_list_length ? nitems : curve_list_length;
1261*2139Sjp161948
1262*2139Sjp161948 for (i = 0; i < min; i++)
1263*2139Sjp161948 {
1264*2139Sjp161948 r[i].nid = curve_list[i].nid;
1265*2139Sjp161948 r[i].comment = curve_list[i].data->comment;
1266*2139Sjp161948 }
1267*2139Sjp161948
1268*2139Sjp161948 return curve_list_length;
1269*2139Sjp161948 }
1270