8#include <botan/elgamal.h>
10#include <botan/internal/blinding.h>
11#include <botan/internal/buffer_stuffer.h>
12#include <botan/internal/dl_scheme.h>
13#include <botan/internal/keypair.h>
14#include <botan/internal/monty_exp.h>
15#include <botan/internal/pk_ops_impl.h>
20 m_public_key = std::make_shared<DL_PublicKey>(group, y);
28 return m_public_key->estimated_strength();
32 return m_public_key->p_bits();
40 return m_public_key->public_key_as_bytes();
44 return m_public_key->DER_encode();
48 return m_public_key->get_int_field(
algo_name(), field);
52 return std::make_unique<ElGamal_PrivateKey>(rng, m_public_key->group());
56 return m_public_key->check_key(rng, strong);
60 m_private_key = std::make_shared<DL_PrivateKey>(group, rng);
61 m_public_key = m_private_key->public_key();
65 m_private_key = std::make_shared<DL_PrivateKey>(group, x);
66 m_public_key = m_private_key->public_key();
71 m_public_key = m_private_key->public_key();
79 return m_private_key->get_int_field(
algo_name(), field);
83 return m_private_key->DER_encode();
87 return m_private_key->raw_private_key_bits();
91 if(!m_private_key->check_key(rng, strong)) {
95#if defined(BOTAN_HAS_OAEP) && defined(BOTAN_HAS_SHA_256)
96 const std::string padding =
"OAEP(SHA-256)";
98 const std::string padding =
"Raw";
111 ElGamal_Encryption_Operation(
const std::shared_ptr<const DL_PublicKey>& key, std::string_view padding) :
112 PK_Ops::Encryption_with_Padding(padding), m_key(key) {
113 const size_t powm_window = 4;
114 m_monty_y_p =
monty_precompute(m_key->group()._monty_params_p(), m_key->public_key(), powm_window);
117 size_t ciphertext_length(
size_t )
const override {
return 2 * m_key->group().p_bytes(); }
119 size_t max_ptext_input_bits()
const override {
return m_key->group().p_bits() - 1; }
121 std::vector<uint8_t> raw_encrypt(std::span<const uint8_t> ptext, RandomNumberGenerator& rng)
override;
124 std::shared_ptr<const DL_PublicKey> m_key;
125 std::shared_ptr<const Montgomery_Exponentiation_State> m_monty_y_p;
128std::vector<uint8_t> ElGamal_Encryption_Operation::raw_encrypt(std::span<const uint8_t> ptext,
130 const BigInt m(ptext);
132 const auto& group = m_key->group();
134 if(m >= group.get_p()) {
135 throw Invalid_Argument(
"ElGamal encryption: Input is too large");
146 const size_t k_bits = group.p_bits() - 1;
147 const BigInt k(rng, k_bits,
false);
149 const BigInt a = group.power_g_p(k, k_bits);
150 const BigInt b = group.multiply_mod_p(m,
monty_execute(*m_monty_y_p, k, k_bits).value());
152 const size_t p_bytes = group.p_bytes();
153 std::vector<uint8_t> ctext(2 * p_bytes);
154 BufferStuffer stuffer(ctext);
155 a.serialize_to(stuffer.next(p_bytes));
156 b.serialize_to(stuffer.next(p_bytes));
163class ElGamal_Decryption_Operation final :
public PK_Ops::Decryption_with_Padding {
165 ElGamal_Decryption_Operation(
const std::shared_ptr<const DL_PrivateKey>& key,
166 std::string_view padding,
167 RandomNumberGenerator& rng) :
168 PK_Ops::Decryption_with_Padding(padding),
171 m_key->group()._reducer_mod_p(),
173 [](const BigInt& k) {
return k; },
174 [
this](
const BigInt& k) {
return powermod_x_p(k); }) {}
176 size_t plaintext_length(
size_t )
const override {
return m_key->group().p_bytes(); }
178 secure_vector<uint8_t> raw_decrypt(std::span<const uint8_t> ctext)
override;
181 BigInt powermod_x_p(
const BigInt& v)
const {
return m_key->group().power_b_p(v, m_key->private_key()); }
183 std::shared_ptr<const DL_PrivateKey> m_key;
188 const auto& group = m_key->group();
190 const size_t p_bytes = group.p_bytes();
192 if(ctext.size() != 2 * p_bytes) {
193 throw Invalid_Argument(
"ElGamal decryption: Invalid message");
196 BigInt a(ctext.first(p_bytes));
197 const BigInt b(ctext.last(p_bytes));
199 if(a >= group.get_p() || b >= group.get_p()) {
200 throw Invalid_Argument(
"ElGamal decryption: Invalid message");
203 a = m_blinder.
blind(a);
205 const BigInt r = group.multiply_mod_p(group.inverse_mod_p(powermod_x_p(a)), b);
213 std::string_view params,
214 std::string_view provider)
const {
215 if(provider ==
"base" || provider.empty()) {
216 return std::make_unique<ElGamal_Encryption_Operation>(this->m_public_key, params);
222 std::string_view params,
223 std::string_view provider)
const {
224 if(provider ==
"base" || provider.empty()) {
225 return std::make_unique<ElGamal_Decryption_Operation>(this->m_private_key, params, rng);
virtual OID object_identifier() const
T serialize(size_t len) const
BigInt blind(const BigInt &x) const
BigInt unblind(const BigInt &x) const
std::unique_ptr< PK_Ops::Decryption > create_decryption_op(RandomNumberGenerator &rng, std::string_view params, std::string_view provider) const override
secure_vector< uint8_t > private_key_bits() const override
const BigInt & get_int_field(std::string_view field) const override
bool check_key(RandomNumberGenerator &rng, bool strong) const override
std::unique_ptr< Public_Key > public_key() const override
secure_vector< uint8_t > raw_private_key_bits() const override
std::unique_ptr< PK_Ops::Encryption > create_encryption_op(RandomNumberGenerator &rng, std::string_view params, std::string_view provider) const override
const BigInt & get_int_field(std::string_view field) const override
std::vector< uint8_t > public_key_bits() const override
friend class ElGamal_PrivateKey
size_t estimated_strength() const override
bool check_key(RandomNumberGenerator &rng, bool strong) const override
AlgorithmIdentifier algorithm_identifier() const override
std::vector< uint8_t > raw_public_key_bits() const override
size_t key_length() const override
std::unique_ptr< Private_Key > generate_another(RandomNumberGenerator &rng) const final
std::string algo_name() const override
ElGamal_PublicKey(const AlgorithmIdentifier &alg_id, std::span< const uint8_t > key_bits)
bool encryption_consistency_check(RandomNumberGenerator &rng, const Private_Key &private_key, const Public_Key &public_key, std::string_view padding)
std::shared_ptr< const Montgomery_Exponentiation_State > monty_precompute(const Montgomery_Int &g, size_t window_bits, bool const_time)
Montgomery_Int monty_execute(const Montgomery_Exponentiation_State &precomputed_state, const BigInt &k, size_t max_k_bits)
std::vector< T, secure_allocator< T > > secure_vector