8#include <botan/elgamal.h>
9#include <botan/internal/dl_scheme.h>
10#include <botan/internal/pk_ops_impl.h>
11#include <botan/internal/monty_exp.h>
12#include <botan/internal/keypair.h>
13#include <botan/internal/blinding.h>
19 m_public_key = std::make_shared<DL_PublicKey>(group,
y);
23 std::span<const uint8_t> key_bits)
30 return m_public_key->estimated_strength();
35 return m_public_key->p_bits();
47 return m_public_key->DER_encode();
52 return m_public_key->get_int_field(
algo_name(), field);
57 return m_public_key->check_key(rng, strong);
63 m_private_key = std::make_shared<DL_PrivateKey>(group, rng);
64 m_public_key = m_private_key->public_key();
70 m_private_key = std::make_shared<DL_PrivateKey>(group, x);
71 m_public_key = m_private_key->public_key();
75 std::span<const uint8_t> key_bits)
78 m_public_key = m_private_key->public_key();
88 return m_private_key->get_int_field(
algo_name(), field);
93 return m_private_key->DER_encode();
98 return m_private_key->raw_private_key_bits();
104 if(!m_private_key->check_key(rng, strong))
119 ElGamal_Encryption_Operation(
const std::shared_ptr<const DL_PublicKey>& key,
120 std::string_view eme) :
121 PK_Ops::Encryption_with_EME(eme),
124 const size_t powm_window = 4;
130 size_t ciphertext_length(
size_t )
const override
132 return 2*m_key->group().p_bytes();
135 size_t max_ptext_input_bits()
const override
137 return m_key->group().p_bits() - 1;
140 secure_vector<uint8_t> raw_encrypt(
const uint8_t msg[],
size_t msg_len,
141 RandomNumberGenerator& rng)
override;
144 std::shared_ptr<const DL_PublicKey> m_key;
145 std::shared_ptr<const Montgomery_Exponentation_State> m_monty_y_p;
148secure_vector<uint8_t>
149ElGamal_Encryption_Operation::raw_encrypt(
const uint8_t msg[],
size_t msg_len,
150 RandomNumberGenerator& rng)
152 BigInt m(msg, msg_len);
154 const auto& group = m_key->group();
156 if(m >= group.get_p())
157 throw Invalid_Argument(
"ElGamal encryption: Input is too large");
167 const size_t k_bits = group.p_bits() - 1;
168 const BigInt k(rng, k_bits,
false);
170 const BigInt a = group.power_g_p(k, k_bits);
171 const BigInt b = group.multiply_mod_p(m,
monty_execute(*m_monty_y_p, k, k_bits));
179class ElGamal_Decryption_Operation
final :
public PK_Ops::Decryption_with_EME
183 ElGamal_Decryption_Operation(
const std::shared_ptr<const DL_PrivateKey>& key,
184 std::string_view eme,
185 RandomNumberGenerator& rng) :
186 PK_Ops::Decryption_with_EME(eme),
188 m_blinder(m_key->group().get_p(),
190 [](const BigInt& k) {
return k; },
191 [
this](
const BigInt& k) {
return powermod_x_p(k); })
194 size_t plaintext_length(
size_t )
const override
196 return m_key->group().p_bytes();
199 secure_vector<uint8_t> raw_decrypt(
const uint8_t msg[],
size_t msg_len)
override;
201 BigInt powermod_x_p(
const BigInt& v)
const
203 return m_key->group().power_b_p(v, m_key->private_key());
206 std::shared_ptr<const DL_PrivateKey> m_key;
210secure_vector<uint8_t>
211ElGamal_Decryption_Operation::raw_decrypt(
const uint8_t msg[],
size_t msg_len)
213 const auto& group = m_key->group();
215 const size_t p_bytes = group.p_bytes();
217 if(msg_len != 2 * p_bytes)
218 throw Invalid_Argument(
"ElGamal decryption: Invalid message");
220 BigInt a(msg, p_bytes);
221 const BigInt b(msg + p_bytes, p_bytes);
223 if(a >= group.get_p() || b >= group.get_p())
224 throw Invalid_Argument(
"ElGamal decryption: Invalid message");
226 a = m_blinder.
blind(a);
228 const BigInt r = group.multiply_mod_p(group.inverse_mod_p(powermod_x_p(a)), b);
235std::unique_ptr<PK_Ops::Encryption>
237 std::string_view params,
238 std::string_view provider)
const
240 if(provider ==
"base" || provider.empty())
241 return std::make_unique<ElGamal_Encryption_Operation>(this->m_public_key, params);
245std::unique_ptr<PK_Ops::Decryption>
247 std::string_view params,
248 std::string_view provider)
const
250 if(provider ==
"base" || provider.empty())
251 return std::make_unique<ElGamal_Decryption_Operation>(this->m_private_key, params, rng);
virtual OID object_identifier() const
static secure_vector< uint8_t > encode_fixed_length_int_pair(const BigInt &n1, const BigInt &n2, size_t bytes)
static secure_vector< uint8_t > encode_1363(const BigInt &n, size_t bytes)
BigInt blind(const BigInt &x) const
BigInt unblind(const BigInt &x) const
std::unique_ptr< PK_Ops::Decryption > create_decryption_op(RandomNumberGenerator &rng, std::string_view params, std::string_view provider) const override
secure_vector< uint8_t > private_key_bits() const override
const BigInt & get_int_field(std::string_view field) const override
std::unique_ptr< Public_Key > public_key() const override
secure_vector< uint8_t > raw_private_key_bits() const override
bool check_key(RandomNumberGenerator &rng, bool) const override
std::unique_ptr< PK_Ops::Encryption > create_encryption_op(RandomNumberGenerator &rng, std::string_view params, std::string_view provider) const override
const BigInt & get_int_field(std::string_view field) const override
std::vector< uint8_t > public_key_bits() const override
friend class ElGamal_PrivateKey
size_t estimated_strength() const override
bool check_key(RandomNumberGenerator &rng, bool strong) const override
AlgorithmIdentifier algorithm_identifier() const override
size_t key_length() const override
std::string algo_name() const override
int(* final)(unsigned char *, CTX *)
bool encryption_consistency_check(RandomNumberGenerator &rng, const Private_Key &private_key, const Public_Key &public_key, std::string_view padding)
BigInt monty_execute(const Montgomery_Exponentation_State &precomputed_state, const BigInt &k, size_t max_k_bits)
std::vector< T, secure_allocator< T > > secure_vector
std::shared_ptr< const Montgomery_Exponentation_State > monty_precompute(const std::shared_ptr< const Montgomery_Params > ¶ms, const BigInt &g, size_t window_bits, bool const_time)