diff --git a/src/build-data/ec_groups.txt b/src/build-data/ec_groups.txt index e83276a19c2..a4600bf4955 100644 --- a/src/build-data/ec_groups.txt +++ b/src/build-data/ec_groups.txt @@ -68,6 +68,16 @@ X = 0x8BD2AEB9CB7E57CB2C4B482FFC81B7AFB9DE27E1E3BD23C23A4453BD9ACE3262 Y = 0x547EF835C3DAC4FD97F8461A14611DC9C27745132DED8E545C1D54C72F046997 N = 0xA9FB57DBA1EEA9BC3E660A909D838D718C397AA3B561A6F7901E0E82974856A7 +Name = brainpool256t1 +OID = 1.3.36.3.3.2.8.1.1.8 +Impl = pcurve generic legacy +P = 0xA9FB57DBA1EEA9BC3E660A909D838D726E3BF623D52620282013481D1F6E5377 +A = 0xA9FB57DBA1EEA9BC3E660A909D838D726E3BF623D52620282013481D1F6E5374 +B = 0x662C61C430D84EA4FE66A7733D0B76B7BF93EBC4AF2F49256AE58101FEE92B04 +X = 0xA3E8EB3CC1CFE7B7732213B23A656149AFA142C47AAFBC2B79A191562E1305F4 +Y = 0x2D996C823439C56D7F7B22E14644417E69BCB6DE39D027001DABE8F35B25C9BE +N = 0xA9FB57DBA1EEA9BC3E660A909D838D718C397AA3B561A6F7901E0E82974856A7 + Name = brainpool320r1 OID = 1.3.36.3.3.2.8.1.1.9 Impl = generic legacy @@ -88,6 +98,16 @@ X = 0x1D1C64F068CF45FFA2A63A81B7C13F6B8847A3E77EF14FE3DB7FCAFE0CBD10E8E826E03436 Y = 0x8ABE1D7520F9C2A45CB1EB8E95CFD55262B70B29FEEC5864E19C054FF99129280E4646217791811142820341263C5315 N = 0x8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B31F166E6CAC0425A7CF3AB6AF6B7FC3103B883202E9046565 +Name = brainpool384t1 +OID = 1.3.36.3.3.2.8.1.1.12 +Impl = pcurve generic legacy +P = 0x8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B412B1DA197FB71123ACD3A729901D1A71874700133107EC53 +A = 0x8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B412B1DA197FB71123ACD3A729901D1A71874700133107EC50 +B = 0x7F519EADA7BDA81BD826DBA647910F8C4B9346ED8CCDC64E4B1ABD11756DCE1D2074AA263B88805CED70355A33B471EE +X = 0x18DE98B02DB9A306F2AFCD7235F72A819B80AB12EBD653172476FECD462AABFFC4FF191B946A5F54D8D0AA2F418808CC +Y = 0x25AB056962D30651A114AFD2755AD336747F93475B7A1FCA3B88F2B6A208CCFE469408584DC2B2912675BF5B9E582928 +N = 0x8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B31F166E6CAC0425A7CF3AB6AF6B7FC3103B883202E9046565 + Name = brainpool512r1 OID = 1.3.36.3.3.2.8.1.1.13 Impl = pcurve generic legacy @@ -98,6 +118,16 @@ X = 0x81AEE4BDD82ED9645A21322E9C4C6A9385ED9F70B5D916C1B43B62EEF4D0098EFF3B1F78E2 Y = 0x7DDE385D566332ECC0EABFA9CF7822FDF209F70024A57B1AA000C55B881F8111B2DCDE494A5F485E5BCA4BD88A2763AED1CA2B2FA8F0540678CD1E0F3AD80892 N = 0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069 +Name = brainpool512t1 +OID = 1.3.36.3.3.2.8.1.1.14 +Impl = pcurve generic legacy +P = 0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA703308717D4D9B009BC66842AECDA12AE6A380E62881FF2F2D82C68528AA6056583A48F3 +A = 0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA703308717D4D9B009BC66842AECDA12AE6A380E62881FF2F2D82C68528AA6056583A48F0 +B = 0x7CBBBCF9441CFAB76E1890E46884EAE321F70C0BCB4981527897504BEC3E36A62BCDFA2304976540F6450085F2DAE145C22553B465763689180EA2571867423E +X = 0x640ECE5C12788717B9C1BA06CBC2A6FEBA85842458C56DDE9DB1758D39C0313D82BA51735CDB3EA499AA77A7D6943A64F7A3F25FE26F06B51BAA2696FA9035DA +Y = 0x5B534BD595F5AF0FA2C892376C84ACE1BB4E3019B71634C01131159CAE03CEE9D9932184BEEF216BD71DF2DADF86A627306ECFF96DBB8BACE198B61E00F8B332 +N = 0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069 + Name = frp256v1 OID = 1.2.250.1.223.101.256.1 Impl = pcurve generic legacy diff --git a/src/build-data/oids.txt b/src/build-data/oids.txt index 62bd6fc3a83..9bdbbc4f0b1 100644 --- a/src/build-data/oids.txt +++ b/src/build-data/oids.txt @@ -475,9 +475,12 @@ 1.3.36.3.3.2.8.1.1.3 = brainpool192r1 1.3.36.3.3.2.8.1.1.5 = brainpool224r1 1.3.36.3.3.2.8.1.1.7 = brainpool256r1 +1.3.36.3.3.2.8.1.1.8 = brainpool256t1 1.3.36.3.3.2.8.1.1.9 = brainpool320r1 1.3.36.3.3.2.8.1.1.11 = brainpool384r1 +1.3.36.3.3.2.8.1.1.12 = brainpool384t1 1.3.36.3.3.2.8.1.1.13 = brainpool512r1 +1.3.36.3.3.2.8.1.1.14 = brainpool512t1 1.2.250.1.223.101.256.1 = frp256v1 diff --git a/src/lib/asn1/static_oids.cpp b/src/lib/asn1/static_oids.cpp index a8b933ad06f..2b656b64d35 100644 --- a/src/lib/asn1/static_oids.cpp +++ b/src/lib/asn1/static_oids.cpp @@ -1,5 +1,5 @@ /* -* This file was automatically generated by ./src/scripts/dev_tools/gen_oids.py on 2026-04-24 +* This file was automatically generated by ./src/scripts/dev_tools/gen_oids.py on 2026-05-08 * All manual changes will be lost. Edit the script instead. * * Botan is released under the Simplified BSD License (see license.txt) @@ -603,12 +603,18 @@ std::optional OID_Map::lookup_static_oid(const OID& oid) { return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 5}, "brainpool224r1"); case 0x9A00E: return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 7}, "brainpool256r1"); + case 0x9A00F: + return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 8}, "brainpool256t1"); case 0x9A010: return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 9}, "brainpool320r1"); case 0x9A012: return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 11}, "brainpool384r1"); + case 0x9A013: + return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 12}, "brainpool384t1"); case 0x9A014: return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 13}, "brainpool512r1"); + case 0x9A015: + return if_match(oid, {1, 3, 36, 3, 3, 2, 8, 1, 1, 14}, "brainpool512t1"); case 0xA0D61: return if_match(oid, {1, 3, 6, 1, 4, 1, 25258, 1, 3}, "McEliece"); case 0xA0D63: @@ -1117,6 +1123,8 @@ std::optional OID_Map::lookup_static_oid_name(std::string_view req) { return if_match(req, "PKIX.AuthorityInformationAccess", {1, 3, 6, 1, 5, 5, 7, 1, 1}); case 0x70BB6: return if_match(req, "brainpool384r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 11}); + case 0x70DAC: + return if_match(req, "brainpool384t1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 12}); case 0x70EA6: return if_match(req, "PKCS12.PKCS8ShroudedKeyBag", {1, 2, 840, 113549, 1, 12, 10, 1, 2}); case 0x71EB3: @@ -1143,6 +1151,8 @@ std::optional OID_Map::lookup_static_oid_name(std::string_view req) { return if_match(req, "PKCS9.LocalKeyId", {1, 2, 840, 113549, 1, 9, 21}); case 0x76A19: return if_match(req, "brainpool512r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 13}); + case 0x76C0F: + return if_match(req, "brainpool512t1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 14}); case 0x77254: return if_match(req, "SphincsPlus-haraka-256s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 5}); case 0x77ADC: @@ -1419,6 +1429,8 @@ std::optional OID_Map::lookup_static_oid_name(std::string_view req) { return if_match(req, "PKIX.OCSPSigning", {1, 3, 6, 1, 5, 5, 7, 3, 9}); case 0xC42CA: return if_match(req, "brainpool256r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 7}); + case 0xC44C0: + return if_match(req, "brainpool256t1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 8}); default: return {}; } diff --git a/src/lib/math/pcurves/pcurves.cpp b/src/lib/math/pcurves/pcurves.cpp index 8d0aa5d2e75..7bc9a8dc0d1 100644 --- a/src/lib/math/pcurves/pcurves.cpp +++ b/src/lib/math/pcurves/pcurves.cpp @@ -1,5 +1,5 @@ /* -* This file was automatically generated by ./src/scripts/dev_tools/gen_ec_groups.py on 2026-04-24 +* This file was automatically generated by ./src/scripts/dev_tools/gen_ec_groups.py on 2026-05-08 * All manual changes will be lost. Edit the script instead. * * Botan is released under the Simplified BSD License (see license.txt) @@ -54,18 +54,36 @@ std::shared_ptr PrimeOrderCurve::for_named_curve(std::str } #endif +#if defined(BOTAN_HAS_PCURVES_BRAINPOOL256T1) + if(name == "brainpool256t1") { + return PCurveInstance::brainpool256t1(); + } +#endif + #if defined(BOTAN_HAS_PCURVES_BRAINPOOL384R1) if(name == "brainpool384r1") { return PCurveInstance::brainpool384r1(); } #endif +#if defined(BOTAN_HAS_PCURVES_BRAINPOOL384T1) + if(name == "brainpool384t1") { + return PCurveInstance::brainpool384t1(); + } +#endif + #if defined(BOTAN_HAS_PCURVES_BRAINPOOL512R1) if(name == "brainpool512r1") { return PCurveInstance::brainpool512r1(); } #endif +#if defined(BOTAN_HAS_PCURVES_BRAINPOOL512T1) + if(name == "brainpool512t1") { + return PCurveInstance::brainpool512t1(); + } +#endif + #if defined(BOTAN_HAS_PCURVES_FRP256V1) if(name == "frp256v1") { return PCurveInstance::frp256v1(); diff --git a/src/lib/math/pcurves/pcurves_brainpool256t1/info.txt b/src/lib/math/pcurves/pcurves_brainpool256t1/info.txt new file mode 100644 index 00000000000..fbae05a9802 --- /dev/null +++ b/src/lib/math/pcurves/pcurves_brainpool256t1/info.txt @@ -0,0 +1,11 @@ + +PCURVES_BRAINPOOL256T1 -> 20260430 + + + +name -> "PCurve brainpool256t1" + + + +pcurves_impl + diff --git a/src/lib/math/pcurves/pcurves_brainpool256t1/pcurves_brainpool256t1.cpp b/src/lib/math/pcurves/pcurves_brainpool256t1/pcurves_brainpool256t1.cpp new file mode 100644 index 00000000000..fbdee6394ae --- /dev/null +++ b/src/lib/math/pcurves/pcurves_brainpool256t1/pcurves_brainpool256t1.cpp @@ -0,0 +1,342 @@ +/* +* Botan is released under the Simplified BSD License (see license.txt) +*/ + +#include + +#include + +namespace Botan::PCurve { + +namespace { + +namespace brainpool256t1 { + + +// clang-format off +class Params final : public EllipticCurveParameters< + "A9FB57DBA1EEA9BC3E660A909D838D726E3BF623D52620282013481D1F6E5377", + "A9FB57DBA1EEA9BC3E660A909D838D726E3BF623D52620282013481D1F6E5374", + "662C61C430D84EA4FE66A7733D0B76B7BF93EBC4AF2F49256AE58101FEE92B04", + "A9FB57DBA1EEA9BC3E660A909D838D718C397AA3B561A6F7901E0E82974856A7", + "A3E8EB3CC1CFE7B7732213B23A656149AFA142C47AAFBC2B79A191562E1305F4", + "2D996C823439C56D7F7B22E14644417E69BCB6DE39D027001DABE8F35B25C9BE"> { +}; +// clang-format on + +class Curve final : public EllipticCurve { + public: + // Return the square of the inverse of x + static constexpr FieldElement fe_invert2(const FieldElement& x) { + // Generated using https://github.com/mmcloughlin/addchain + auto t18 = x.square(); + auto t8 = t18.square(); + auto t6 = t8 * x; + auto t13 = t18 * t6; + auto t1 = t13 * x; + auto t4 = t1 * x; + auto t17 = t1 * t13; + auto t9 = t17 * t18; + auto t5 = t18 * t9; + auto t15 = t18 * t5; + auto z = t15 * t18; + auto t11 = t18 * z; + auto t3 = t11 * t8; + auto t2 = t18 * t3; + auto t14 = t18 * t2; + auto t0 = t1 * t14; + auto t7 = t0 * t1; + auto t16 = t18 * t7; + auto t12 = t16 * t18; + t1 = t12 * t18; + auto t10 = t1 * t8; + t8 = t10 * t18; + auto t19 = t8 * z; + t19.square_n(6); + t19 *= t8; + t18 *= t19; + t18.square_n(7); + t18 *= t12; + t18.square_n(6); + t18 *= t2; + t18.square_n(7); + t18 *= t1; + t18.square_n(7); + t18 *= t14; + t18.square_n(6); + t18 *= t10; + t18.square_n(5); + t18 *= t15; + t18.square_n(6); + t18 *= t5; + t18.square_n(5); + t17 *= t18; + t17.square_n(9); + t17 *= t2; + t17.square_n(8); + t16 *= t17; + t16.square_n(10); + t15 *= t16; + t15.square_n(8); + t14 *= t15; + t14.square_n(8); + t14 *= t10; + t14.square_n(8); + t13 *= t14; + t13.square_n(9); + t12 *= t13; + t12.square_n(5); + t11 *= t12; + t11.square_n(8); + t11 *= t1; + t11.square_n(9); + t10 *= t11; + t10.square_n(6); + t10 *= t8; + t10.square_n(5); + t9 *= t10; + t9.square_n(9); + t8 *= t9; + t8.square_n(7); + t8 *= t0; + t8.square_n(8); + t7 *= t8; + t7.square_n(10); + t6 *= t7; + t6.square_n(6); + t6 *= x; + t6.square_n(13); + t5 *= t6; + t5.square_n(5); + t4 *= t5; + t4.square_n(11); + t3 *= t4; + t3.square_n(8); + t2 *= t3; + t2.square_n(7); + t1 *= t2; + t1.square_n(8); + t0 *= t1; + t0.square_n(5); + z *= t0; + z.square_n(2); + z *= x; + z.square_n(2); + return z; + } + + // Return the square root of this field element (if it is a quadratic residue) + static constexpr FieldElement fe_sqrt(const FieldElement& x) { + // Generated using https://github.com/mmcloughlin/addchain + auto t18 = x.square(); + auto t8 = t18.square(); + auto t6 = t8 * x; + auto t13 = t18 * t6; + auto z = t13 * x; + auto t4 = x * z; + auto t17 = t13 * z; + auto t9 = t17 * t18; + auto t5 = t18 * t9; + auto t15 = t18 * t5; + auto t11 = t15 * t8; + auto t3 = t11 * t8; + auto t2 = t18 * t3; + auto t14 = t18 * t2; + auto t0 = t14 * z; + z = t0 * x; + z *= t6; + auto t7 = t18 * z; + auto t16 = t18 * t7; + auto t12 = t16 * t18; + auto t1 = t12 * t18; + auto t10 = t1 * t8; + t8 = t10 * t18; + auto t19 = t10 * t11; + t19.square_n(6); + t19 *= t8; + t18 *= t19; + t18.square_n(7); + t18 *= t12; + t18.square_n(6); + t18 *= t2; + t18.square_n(7); + t18 *= t1; + t18.square_n(7); + t18 *= t14; + t18.square_n(6); + t18 *= t10; + t18.square_n(5); + t18 *= t15; + t18.square_n(6); + t18 *= t5; + t18.square_n(5); + t17 *= t18; + t17.square_n(9); + t17 *= t2; + t17.square_n(8); + t16 *= t17; + t16.square_n(10); + t15 *= t16; + t15.square_n(8); + t14 *= t15; + t14.square_n(8); + t14 *= t10; + t14.square_n(8); + t13 *= t14; + t13.square_n(9); + t12 *= t13; + t12.square_n(5); + t11 *= t12; + t11.square_n(8); + t11 *= t1; + t11.square_n(9); + t10 *= t11; + t10.square_n(6); + t10 *= t8; + t10.square_n(5); + t9 *= t10; + t9.square_n(9); + t8 *= t9; + t8.square_n(7); + t8 *= t0; + t8.square_n(8); + t7 *= t8; + t7.square_n(10); + t6 *= t7; + t6.square_n(6); + t6 *= x; + t6.square_n(13); + t5 *= t6; + t5.square_n(5); + t4 *= t5; + t4.square_n(11); + t3 *= t4; + t3.square_n(8); + t2 *= t3; + t2.square_n(7); + t1 *= t2; + t1.square_n(8); + t0 *= t1; + t0.square_n(6); + z *= t0; + z = z.square(); + return z; + } + + // Return the inverse of an integer modulo the order + static constexpr Scalar scalar_invert(const Scalar& x) { + // Generated using https://github.com/mmcloughlin/addchain + auto t13 = x.square(); + auto t10 = t13 * x; + auto z = t10 * t13; + auto t9 = t13 * z; + auto t1 = t13 * t9; + auto t11 = t1 * t13; + auto t7 = t11 * t13; + auto t4 = t13 * t7; + auto t8 = t13 * t4; + auto t12 = t13 * t8; + auto t0 = t12 * t13; + auto t2 = t0 * t13; + auto t5 = t13 * t2; + auto t6 = t13 * t5; + auto t3 = t13 * t6; + t13 *= t3; + auto t14 = t11 * t13; + t14.square_n(6); + t14 *= t13; + t14 = t14.square(); + t14 *= x; + t14.square_n(5); + t14 *= t7; + t14.square_n(6); + t14 *= t2; + t14.square_n(5); + t14 *= t6; + t14.square_n(6); + t14 *= t3; + t14.square_n(8); + t14 *= t4; + t14.square_n(6); + t14 *= t3; + t14.square_n(4); + t14 *= z; + t14.square_n(7); + t14 *= t6; + t14.square_n(2); + t14 *= t10; + t14.square_n(9); + t13 *= t14; + t13.square_n(7); + t13 *= t5; + t13 = t13.square(); + t13 *= x; + t13.square_n(10); + t13 *= t0; + t13.square_n(3); + t13 *= x; + t13.square_n(9); + t12 *= t13; + t12.square_n(4); + t11 *= t12; + t11.square_n(8); + t11 *= t9; + t11.square_n(7); + t11 *= t7; + t11.square_n(4); + t11 *= t9; + t11.square_n(5); + t11 *= t10; + t11.square_n(5); + t10 *= t11; + t10.square_n(7); + t9 *= t10; + t9.square_n(7); + t9 *= t2; + t9.square_n(5); + t9 *= t0; + t9.square_n(6); + t8 *= t9; + t8.square_n(5); + t8 *= t6; + t8.square_n(6); + t8 *= t0; + t8 = t8.square(); + t8 *= x; + t8.square_n(8); + t7 *= t8; + t7.square_n(7); + t7 *= t6; + t7.square_n(5); + t6 *= t7; + t6.square_n(5); + t5 *= t6; + t5.square_n(11); + t4 *= t5; + t4.square_n(10); + t3 *= t4; + t3.square_n(8); + t3 *= z; + t3.square_n(7); + t2 *= t3; + t2.square_n(5); + t1 *= t2; + t1.square_n(9); + t1 *= t0; + t1.square_n(5); + t0 *= t1; + t0.square_n(5); + z *= t0; + return z; + } +}; + +} // namespace brainpool256t1 + +} // namespace + +std::shared_ptr PCurveInstance::brainpool256t1() { + return PrimeOrderCurveImpl::instance(); +} + +} // namespace Botan::PCurve diff --git a/src/lib/math/pcurves/pcurves_brainpool384t1/info.txt b/src/lib/math/pcurves/pcurves_brainpool384t1/info.txt new file mode 100644 index 00000000000..6a5b56cfa15 --- /dev/null +++ b/src/lib/math/pcurves/pcurves_brainpool384t1/info.txt @@ -0,0 +1,11 @@ + +PCURVES_BRAINPOOL384T1 -> 20260430 + + + +name -> "PCurve brainpool384t1" + + + +pcurves_impl + diff --git a/src/lib/math/pcurves/pcurves_brainpool384t1/pcurves_brainpool384t1.cpp b/src/lib/math/pcurves/pcurves_brainpool384t1/pcurves_brainpool384t1.cpp new file mode 100644 index 00000000000..3c50bd30841 --- /dev/null +++ b/src/lib/math/pcurves/pcurves_brainpool384t1/pcurves_brainpool384t1.cpp @@ -0,0 +1,466 @@ +/* +* Botan is released under the Simplified BSD License (see license.txt) +*/ + +#include + +#include + +namespace Botan::PCurve { + +namespace { + +namespace brainpool384t1 { + + +// clang-format off +class Params final : public EllipticCurveParameters< + "8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B412B1DA197FB71123ACD3A729901D1A71874700133107EC53", + "8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B412B1DA197FB71123ACD3A729901D1A71874700133107EC50", + "7F519EADA7BDA81BD826DBA647910F8C4B9346ED8CCDC64E4B1ABD11756DCE1D2074AA263B88805CED70355A33B471EE", + "8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B31F166E6CAC0425A7CF3AB6AF6B7FC3103B883202E9046565", + "18DE98B02DB9A306F2AFCD7235F72A819B80AB12EBD653172476FECD462AABFFC4FF191B946A5F54D8D0AA2F418808CC", + "25AB056962D30651A114AFD2755AD336747F93475B7A1FCA3B88F2B6A208CCFE469408584DC2B2912675BF5B9E582928"> { +}; +// clang-format on + +class Curve final : public EllipticCurve { + public: + // Return the square of the inverse of x + static constexpr FieldElement fe_invert2(const FieldElement& x) { + // Generated using https://github.com/mmcloughlin/addchain + auto t1 = x.square(); + auto t0 = t1 * x; + auto z = t0 * t1; + auto t3 = t1 * z; + auto t7 = t1 * t3; + auto t10 = t1 * t7; + auto t5 = t1 * t10; + auto t13 = t1 * t5; + auto t8 = t1 * t13; + auto t2 = t1 * t8; + auto t11 = t1 * t2; + auto t12 = t1 * t11; + auto t6 = t1 * t12; + auto t9 = t1 * t6; + auto t4 = t1 * t9; + t1 = t4.square(); + t1 *= z; + auto t14 = t1 * z; + t14.square_n(2); + t14 *= t7; + t14.square_n(4); + t14 *= t3; + t14.square_n(7); + t14 *= t8; + t14.square_n(5); + t14 *= t4; + t14.square_n(10); + t14 *= t11; + t14.square_n(8); + t14 *= t6; + t14.square_n(2); + t14 *= t0; + t14.square_n(9); + t14 *= t9; + t14.square_n(5); + t14 *= t7; + t14.square_n(2); + t14 *= x; + t14.square_n(11); + t14 *= t13; + t14.square_n(6); + t14 *= t12; + t14.square_n(5); + t14 *= t10; + t14.square_n(5); + t14 *= t13; + t14.square_n(7); + t14 *= t1; + t14.square_n(5); + t14 *= z; + t14.square_n(7); + t14 *= t3; + t14.square_n(7); + t14 *= t6; + t14.square_n(10); + t14 *= t4; + t14.square_n(4); + t13 *= t14; + t13.square_n(8); + t13 *= t11; + t13.square_n(7); + t13 *= t12; + t13.square_n(5); + t12 *= t13; + t12.square_n(4); + t12 *= x; + t12.square_n(9); + t12 *= t2; + t12.square_n(5); + t12 *= t9; + t12.square_n(6); + t11 *= t12; + t11.square_n(6); + t11 *= t8; + t11.square_n(5); + t11 *= t10; + t11.square_n(5); + t11 *= t10; + t11.square_n(2); + t11 *= x; + t11.square_n(9); + t11 *= t7; + t11.square_n(5); + t10 *= t11; + t10.square_n(8); + t10 *= t4; + t10.square_n(3); + t10 *= z; + t10.square_n(9); + t10 *= t6; + t10.square_n(7); + t10 *= t1; + t10.square_n(2); + t10 *= t0; + t10.square_n(6); + t9 *= t10; + t9.square_n(5); + t8 *= t9; + t8.square_n(7); + t7 *= t8; + t7.square_n(8); + t7 *= t4; + t7.square_n(6); + t7 *= t6; + t7.square_n(3); + t7 *= z; + t7.square_n(7); + t7 *= t4; + t7.square_n(5); + t7 *= t3; + t7.square_n(5); + t7 *= z; + t7.square_n(7); + t6 *= t7; + t6.square_n(12); + t6 *= t4; + t6.square_n(7); + t5 *= t6; + t5.square_n(5); + t5 *= t3; + t5.square_n(5); + t5 *= t0; + t5.square_n(9); + t4 *= t5; + t4.square_n(6); + t3 *= t4; + t3.square_n(16); + t2 *= t3; + t2.square_n(4); + t2 *= t0; + t2.square_n(4); + t2 *= x; + t2.square_n(11); + t1 *= t2; + t1.square_n(3); + t0 *= t1; + t0.square_n(6); + z *= t0; + z.square_n(4); + return z; + } + + // Return the square root of this field element (if it is a quadratic residue) + static constexpr FieldElement fe_sqrt(const FieldElement& x) { + // Generated using https://github.com/mmcloughlin/addchain + auto t1 = x.square(); + auto t0 = t1 * x; + auto t7 = t0 * t1; + auto t3 = t1 * t7; + auto t8 = t1 * t3; + auto t11 = t1 * t8; + auto t5 = t1 * t11; + auto t13 = t1 * t5; + auto t9 = t1 * t13; + auto t2 = t1 * t9; + auto z = t1 * t2; + auto t12 = t1 * z; + auto t6 = t1 * t12; + auto t10 = t1 * t6; + auto t4 = t1 * t10; + t1 = t4.square(); + t1 *= t7; + auto t14 = t1 * t7; + t14.square_n(2); + t14 *= t8; + t14.square_n(4); + t14 *= t3; + t14.square_n(7); + t14 *= t9; + t14.square_n(5); + t14 *= t4; + t14.square_n(10); + t14 *= z; + t14.square_n(8); + t14 *= t6; + t14.square_n(2); + t14 *= t0; + t14.square_n(9); + t14 *= t10; + t14.square_n(5); + t14 *= t8; + t14.square_n(2); + t14 *= x; + t14.square_n(11); + t14 *= t13; + t14.square_n(6); + t14 *= t12; + t14.square_n(5); + t14 *= t11; + t14.square_n(5); + t14 *= t13; + t14.square_n(7); + t14 *= t1; + t14.square_n(5); + t14 *= t7; + t14.square_n(7); + t14 *= t3; + t14.square_n(7); + t14 *= t6; + t14.square_n(10); + t14 *= t4; + t14.square_n(4); + t13 *= t14; + t13.square_n(8); + t13 *= z; + t13.square_n(7); + t13 *= t12; + t13.square_n(5); + t12 *= t13; + t12.square_n(4); + t12 *= x; + t12.square_n(9); + t12 *= t2; + t12.square_n(5); + t12 *= t10; + t12.square_n(6); + t12 *= z; + t12.square_n(6); + t12 *= t9; + t12.square_n(5); + t12 *= t11; + t12.square_n(5); + t12 *= t11; + t12.square_n(2); + t12 *= x; + t12.square_n(9); + t12 *= t8; + t12.square_n(5); + t11 *= t12; + t11.square_n(8); + t11 *= t4; + t11.square_n(3); + t11 *= t7; + t11.square_n(9); + t11 *= t6; + t11.square_n(7); + t11 *= t1; + t11.square_n(2); + t11 *= t0; + t11.square_n(6); + t10 *= t11; + t10.square_n(5); + t9 *= t10; + t9.square_n(7); + t8 *= t9; + t8.square_n(8); + t8 *= t4; + t8.square_n(6); + t8 *= t6; + t8.square_n(3); + t8 *= t7; + t8.square_n(7); + t8 *= t4; + t8.square_n(5); + t8 *= t3; + t8.square_n(5); + t7 *= t8; + t7.square_n(7); + t6 *= t7; + t6.square_n(12); + t6 *= t4; + t6.square_n(7); + t5 *= t6; + t5.square_n(5); + t5 *= t3; + t5.square_n(5); + t5 *= t0; + t5.square_n(9); + t4 *= t5; + t4.square_n(6); + t3 *= t4; + t3.square_n(16); + t2 *= t3; + t2.square_n(4); + t2 *= t0; + t2.square_n(4); + t2 *= x; + t2.square_n(11); + t1 *= t2; + t1.square_n(3); + t0 *= t1; + t0.square_n(8); + z *= t0; + return z; + } + + // Return the inverse of an integer modulo the order + static constexpr Scalar scalar_invert(const Scalar& x) { + // Generated using https://github.com/mmcloughlin/addchain + auto t8 = x.square(); + auto z = t8 * x; + auto t18 = t8 * z; + auto t19 = t18 * t8; + auto t6 = t19 * x; + auto t2 = t6 * x; + auto t17 = t2 * t8; + auto t22 = t17 * t8; + auto t12 = t22 * t8; + auto t5 = t12 * t8; + auto t9 = t22 * t6; + auto t3 = t8 * t9; + auto t4 = t3 * t8; + auto t15 = t4 * t8; + auto t11 = t15 * t8; + auto t13 = t11 * t8; + auto t14 = t13 * t8; + auto t1 = t14 * t8; + auto t0 = t1 * t6; + auto t10 = t0 * t8; + auto t20 = t10 * t8; + auto t7 = t20 * t8; + auto t21 = t7 * t8; + auto t16 = t20 * t6; + t6 *= t21; + t8 *= t6; + auto t23 = t2 * t8; + t23.square_n(6); + t23 *= t3; + t23.square_n(8); + t23 *= t1; + t23.square_n(4); + t22 *= t23; + t22.square_n(10); + t22 *= t9; + t22.square_n(9); + t22 *= t21; + t22.square_n(6); + t22 *= t14; + t22.square_n(6); + t22 *= t10; + t22.square_n(5); + t22 *= t18; + t22.square_n(13); + t22 *= t8; + t22.square_n(6); + t22 *= t11; + t22.square_n(7); + t22 *= t16; + t22.square_n(6); + t22 *= t20; + t22.square_n(5); + t22 *= t4; + t22.square_n(7); + t22 *= t14; + t22.square_n(6); + t21 *= t22; + t21.square_n(3); + t21 *= x; + t21.square_n(11); + t21 *= t6; + t21.square_n(3); + t21 *= t19; + t21.square_n(8); + t21 *= t9; + t21.square_n(8); + t20 *= t21; + t20.square_n(4); + t19 *= t20; + t19.square_n(9); + t19 *= t14; + t19.square_n(8); + t19 *= t8; + t19.square_n(5); + t19 *= t9; + t19.square_n(4); + t18 *= t19; + t18.square_n(9); + t18 *= t0; + t18.square_n(5); + t18 *= t17; + t18.square_n(8); + t18 *= t7; + t18.square_n(4); + t18 *= t12; + t18.square_n(7); + t17 *= t18; + t17.square_n(8); + t16 *= t17; + t16.square_n(7); + t15 *= t16; + t15.square_n(8); + t15 *= t0; + t15.square_n(13); + t14 *= t15; + t14.square_n(8); + t14 *= t10; + t14.square_n(7); + t13 *= t14; + t13.square_n(6); + t12 *= t13; + t12.square_n(7); + t11 *= t12; + t11.square_n(7); + t10 *= t11; + t10.square_n(5); + t9 *= t10; + t9.square_n(7); + t9 *= t8; + t9.square_n(6); + t9 *= t0; + t9.square_n(7); + t8 *= t9; + t8.square_n(3); + t8 *= t3; + t8.square_n(10); + t7 *= t8; + t7.square_n(12); + t6 *= t7; + t6.square_n(5); + t5 *= t6; + t5.square_n(10); + t4 *= t5; + t4.square_n(12); + t3 *= t4; + t3.square_n(5); + t2 *= t3; + t2.square_n(11); + t1 *= t2; + t1.square_n(8); + t0 *= t1; + t0.square_n(5); + z *= t0; + return z; + } +}; + +} // namespace brainpool384t1 + +} // namespace + +std::shared_ptr PCurveInstance::brainpool384t1() { + return PrimeOrderCurveImpl::instance(); +} + +} // namespace Botan::PCurve diff --git a/src/lib/math/pcurves/pcurves_brainpool512t1/info.txt b/src/lib/math/pcurves/pcurves_brainpool512t1/info.txt new file mode 100644 index 00000000000..bc8c51880ed --- /dev/null +++ b/src/lib/math/pcurves/pcurves_brainpool512t1/info.txt @@ -0,0 +1,11 @@ + +PCURVES_BRAINPOOL512T1 -> 20260430 + + + +name -> "PCurve brainpool512t1" + + + +pcurves_impl + diff --git a/src/lib/math/pcurves/pcurves_brainpool512t1/pcurves_brainpool512t1.cpp b/src/lib/math/pcurves/pcurves_brainpool512t1/pcurves_brainpool512t1.cpp new file mode 100644 index 00000000000..8189ba54d14 --- /dev/null +++ b/src/lib/math/pcurves/pcurves_brainpool512t1/pcurves_brainpool512t1.cpp @@ -0,0 +1,559 @@ +/* +* Botan is released under the Simplified BSD License (see license.txt) +*/ + +#include + +#include + +namespace Botan::PCurve { + +namespace { + +namespace brainpool512t1 { + + +// clang-format off +class Params final : public EllipticCurveParameters< + "AADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA703308717D4D9B009BC66842AECDA12AE6A380E62881FF2F2D82C68528AA6056583A48F3", + "AADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA703308717D4D9B009BC66842AECDA12AE6A380E62881FF2F2D82C68528AA6056583A48F0", + "7CBBBCF9441CFAB76E1890E46884EAE321F70C0BCB4981527897504BEC3E36A62BCDFA2304976540F6450085F2DAE145C22553B465763689180EA2571867423E", + "AADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069", + "640ECE5C12788717B9C1BA06CBC2A6FEBA85842458C56DDE9DB1758D39C0313D82BA51735CDB3EA499AA77A7D6943A64F7A3F25FE26F06B51BAA2696FA9035DA", + "5B534BD595F5AF0FA2C892376C84ACE1BB4E3019B71634C01131159CAE03CEE9D9932184BEEF216BD71DF2DADF86A627306ECFF96DBB8BACE198B61E00F8B332"> { +}; +// clang-format on + +class Curve final : public EllipticCurve { + public: + // Return the square of the inverse of x + static constexpr FieldElement fe_invert2(const FieldElement& x) { + // Generated using https://github.com/mmcloughlin/addchain + auto t11 = x.square(); + auto t4 = t11 * x; + auto t12 = t4.square(); + auto t13 = t12 * x; + auto t0 = t11 * t13; + auto t2 = t0 * t11; + auto t8 = t11 * t2; + auto z = t11 * t8; + auto t6 = t11 * z; + auto t18 = t11 * t6; + auto t5 = t11 * t18; + auto t15 = t12 * t5; + auto t1 = t11 * t15; + auto t19 = t1 * t11; + auto t14 = t11 * t19; + auto t22 = t11 * t14; + auto t21 = t12 * t14; + auto t7 = t11 * t21; + auto t3 = t11 * t7; + auto t9 = t11 * t3; + auto t10 = t11 * t9; + auto t20 = t10 * t11; + auto t17 = t11 * t20; + t12 *= t17; + auto t16 = t11 * t12; + t11 = t16.square(); + auto t23 = t0 * t11; + auto t24 = t23 * t7; + t11 = t23.square(); + t11 *= x; + t24.square_n(4); + t24 *= t9; + t24.square_n(5); + t24 *= t15; + t24.square_n(8); + t24 *= t16; + t24.square_n(4); + t24 *= t13; + t24.square_n(8); + t24 *= t15; + t24.square_n(6); + t24 *= t19; + t24.square_n(7); + t24 *= t21; + t24.square_n(7); + t24 *= t0; + t24.square_n(7); + t24 *= t2; + t24.square_n(10); + t24 *= t11; + t24.square_n(7); + t24 *= t7; + t24.square_n(6); + t24 *= t17; + t24.square_n(7); + t24 *= t3; + t24.square_n(6); + t24 *= t22; + t24.square_n(6); + t24 *= z; + t24.square_n(3); + t24 *= x; + t24.square_n(9); + t23 *= t24; + t23.square_n(12); + t23 *= t19; + t23.square_n(6); + t23 *= t2; + t23.square_n(4); + t23 *= t4; + t23.square_n(10); + t22 *= t23; + t22.square_n(6); + t22 *= t15; + t22.square_n(8); + t22 *= t16; + t22.square_n(6); + t22 *= z; + t22.square_n(8); + t21 *= t22; + t21.square_n(5); + t21 *= t0; + t21.square_n(11); + t21 *= t16; + t21.square_n(5); + t21 *= t2; + t21.square_n(8); + t21 *= t20; + t21.square_n(6); + t21 *= t17; + t21.square_n(5); + t21 *= t18; + t21.square_n(8); + t21 *= t7; + t21.square_n(2); + t21 *= t4; + t21.square_n(12); + t21 *= t17; + t21.square_n(10); + t21 *= t14; + t21.square_n(6); + t20 *= t21; + t20.square_n(6); + t19 *= t20; + t19.square_n(7); + t19 *= t7; + t19.square_n(4); + t19 *= t2; + t19.square_n(7); + t19 *= t15; + t19.square_n(13); + t18 *= t19; + t18.square_n(5); + t18 *= z; + t18.square_n(9); + t17 *= t18; + t17.square_n(7); + t17 *= t14; + t17.square_n(9); + t17 *= t5; + t17.square_n(7); + t16 *= t17; + t16.square_n(7); + t15 *= t16; + t15.square_n(7); + t14 *= t15; + t14.square_n(7); + t14 *= t5; + t14.square_n(7); + t14 *= t12; + t14.square_n(5); + t14 *= t5; + t14.square_n(6); + t13 *= t14; + t13.square_n(13); + t12 *= t13; + t12.square_n(5); + t12 *= t6; + t12.square_n(6); + t12 *= t6; + t12.square_n(14); + t11 *= t12; + t11 = t11.square(); + t11 *= x; + t11.square_n(8); + t10 *= t11; + t10.square_n(8); + t9 *= t10; + t9 = t9.square(); + t9 *= x; + t9.square_n(9); + t9 *= t2; + t9.square_n(7); + t8 *= t9; + t8.square_n(10); + t7 *= t8; + t7.square_n(6); + t6 *= t7; + t6.square_n(6); + t5 *= t6; + t5.square_n(4); + t4 *= t5; + t4.square_n(12); + t3 *= t4; + t3.square_n(6); + t2 *= t3; + t2.square_n(10); + t1 *= t2; + t1.square_n(6); + t0 *= t1; + t0.square_n(7); + z *= t0; + z.square_n(4); + return z; + } + + // Return the square root of this field element (if it is a quadratic residue) + static constexpr FieldElement fe_sqrt(const FieldElement& x) { + // Generated using https://github.com/mmcloughlin/addchain + auto z = x.square(); + auto t4 = x * z; + auto t11 = t4.square(); + auto t13 = t11 * x; + auto t0 = t13 * z; + auto t2 = t0 * z; + auto t8 = t2 * z; + auto t18 = t8 * z; + auto t6 = t18 * z; + auto t19 = t6 * z; + auto t5 = t19 * z; + auto t15 = t11 * t5; + auto t1 = t15 * z; + auto t20 = t1 * z; + auto t14 = t20 * z; + auto t23 = t14 * z; + auto t22 = t11 * t14; + auto t7 = t22 * z; + auto t3 = t7 * z; + auto t9 = t3 * z; + auto t10 = t9 * z; + auto t21 = t10 * z; + auto t17 = t21 * z; + auto t12 = t11 * t17; + auto t16 = t12 * z; + z *= t16; + t11 = t12 * t15; + auto t24 = t11 * t3; + auto t25 = t24 * t7; + t11 = t24.square(); + t11 *= x; + t25.square_n(4); + t25 *= t9; + t25.square_n(5); + t25 *= t15; + t25.square_n(8); + t25 *= t16; + t25.square_n(4); + t25 *= t13; + t25.square_n(8); + t25 *= t15; + t25.square_n(6); + t25 *= t20; + t25.square_n(7); + t25 *= t22; + t25.square_n(7); + t25 *= t0; + t25.square_n(7); + t25 *= t2; + t25.square_n(10); + t25 *= t11; + t25.square_n(7); + t25 *= t7; + t25.square_n(6); + t25 *= t17; + t25.square_n(7); + t25 *= t3; + t25.square_n(6); + t25 *= t23; + t25.square_n(6); + t25 *= t18; + t25.square_n(3); + t25 *= x; + t25.square_n(9); + t24 *= t25; + t24.square_n(12); + t24 *= t20; + t24.square_n(6); + t24 *= t2; + t24.square_n(4); + t24 *= t4; + t24.square_n(10); + t23 *= t24; + t23.square_n(6); + t23 *= t15; + t23.square_n(8); + t23 *= t16; + t23.square_n(6); + t23 *= t18; + t23.square_n(8); + t22 *= t23; + t22.square_n(5); + t22 *= t0; + t22.square_n(11); + t22 *= t16; + t22.square_n(5); + t22 *= t2; + t22.square_n(8); + t22 *= t21; + t22.square_n(6); + t22 *= t17; + t22.square_n(5); + t22 *= t19; + t22.square_n(8); + t22 *= t7; + t22.square_n(2); + t22 *= t4; + t22.square_n(12); + t22 *= t17; + t22.square_n(10); + t22 *= t14; + t22.square_n(6); + t21 *= t22; + t21.square_n(6); + t20 *= t21; + t20.square_n(7); + t20 *= t7; + t20.square_n(4); + t20 *= t2; + t20.square_n(7); + t20 *= t15; + t20.square_n(13); + t19 *= t20; + t19.square_n(5); + t18 *= t19; + t18.square_n(9); + t17 *= t18; + t17.square_n(7); + t17 *= t14; + t17.square_n(9); + t17 *= t5; + t17.square_n(7); + t16 *= t17; + t16.square_n(7); + t15 *= t16; + t15.square_n(7); + t14 *= t15; + t14.square_n(7); + t14 *= t5; + t14.square_n(7); + t14 *= t12; + t14.square_n(5); + t14 *= t5; + t14.square_n(6); + t13 *= t14; + t13.square_n(13); + t12 *= t13; + t12.square_n(5); + t12 *= t6; + t12.square_n(6); + t12 *= t6; + t12.square_n(14); + t11 *= t12; + t11 = t11.square(); + t11 *= x; + t11.square_n(8); + t10 *= t11; + t10.square_n(8); + t9 *= t10; + t9 = t9.square(); + t9 *= x; + t9.square_n(9); + t9 *= t2; + t9.square_n(7); + t8 *= t9; + t8.square_n(10); + t7 *= t8; + t7.square_n(6); + t6 *= t7; + t6.square_n(6); + t5 *= t6; + t5.square_n(4); + t4 *= t5; + t4.square_n(12); + t3 *= t4; + t3.square_n(6); + t2 *= t3; + t2.square_n(10); + t1 *= t2; + t1.square_n(6); + t0 *= t1; + t0.square_n(9); + z *= t0; + return z; + } + + // Return the inverse of an integer modulo the order + static constexpr Scalar scalar_invert(const Scalar& x) { + // Generated using https://github.com/mmcloughlin/addchain + auto t33 = x.square(); + auto t12 = t33.square(); + auto t25 = t12 * t33; + auto t24 = t25 * x; + auto t1 = t24 * x; + auto t10 = t1 * t33; + auto t20 = t10 * t33; + auto t2 = t20 * x; + auto t0 = t12 * t20; + auto t17 = t2 * t25; + auto z = t17 * x; + auto t38 = t12 * t17; + auto t7 = t10 * t38; + auto t8 = t25 * t7; + auto t35 = t10 * t8; + auto t23 = t33 * t35; + auto t9 = t23 * z; + auto t18 = t20 * t9; + auto t21 = t18 * t33; + auto t14 = t20 * t21; + auto t31 = t14 * t33; + auto t16 = t31 * t33; + z = t16 * t33; + auto t26 = t33 * z; + auto t4 = t26 * t33; + auto t19 = t25 * t4; + auto t3 = t1 * t19; + auto t30 = t25 * t3; + auto t22 = t1 * t30; + auto t34 = t12 * t22; + auto t29 = t33 * t34; + auto t39 = t0 * t29; + t1 = t10 * t39; + t0 = t1 * t33; + auto t28 = t0 * t10; + auto t6 = t28 * t33; + auto t5 = t25 * t6; + auto t11 = t25 * t5; + auto t15 = t11 * t33; + auto t27 = t15 * t25; + auto t13 = t27 * t33; + auto t32 = t10 * t13; + auto t37 = t25 * t32; + auto t40 = t33 * t37; + t25 = t10 * t40; + auto t36 = t25 * t33; + t10 = t12 * t36; + t20 *= t10; + t12 *= t20; + auto t41 = t10 * z; + t41.square_n(7); + t40 *= t41; + t40.square_n(8); + t39 *= t40; + t39.square_n(5); + t38 *= t39; + t38.square_n(11); + t37 *= t38; + t37.square_n(8); + t36 *= t37; + t36.square_n(6); + t35 *= t36; + t35.square_n(10); + t34 *= t35; + t34.square_n(10); + t34 *= t12; + t33 *= t34; + t33.square_n(9); + t33 *= t1; + t33.square_n(10); + t32 *= t33; + t32.square_n(7); + t31 *= t32; + t31.square_n(9); + t31 *= t3; + t31.square_n(9); + t30 *= t31; + t30.square_n(15); + t30 *= t20; + t30.square_n(7); + t30 *= t23; + t30.square_n(12); + t29 *= t30; + t29.square_n(8); + t29 *= t28; + t29.square_n(8); + t28 *= t29; + t28.square_n(8); + t27 *= t28; + t27.square_n(7); + t26 *= t27; + t26.square_n(13); + t26 *= t10; + t26.square_n(7); + t26 *= t23; + t26.square_n(11); + t25 *= t26; + t25.square_n(9); + t25 *= t16; + t25.square_n(5); + t24 *= t25; + t24.square_n(12); + t23 *= t24; + t23.square_n(12); + t22 *= t23; + t22.square_n(12); + t21 *= t22; + t21.square_n(10); + t20 *= t21; + t20.square_n(8); + t19 *= t20; + t19.square_n(12); + t18 *= t19; + t18.square_n(10); + t18 *= t0; + t18.square_n(7); + t17 *= t18; + t17.square_n(11); + t16 *= t17; + t16.square_n(13); + t15 *= t16; + t15.square_n(9); + t14 *= t15; + t14.square_n(11); + t13 *= t14; + t13.square_n(8); + t12 *= t13; + t12.square_n(9); + t11 *= t12; + t11.square_n(12); + t11 *= t9; + t11.square_n(11); + t10 *= t11; + t10.square_n(7); + t9 *= t10; + t9.square_n(7); + t8 *= t9; + t8.square_n(12); + t7 *= t8; + t7.square_n(12); + t7 *= t5; + t7.square_n(8); + t6 *= t7; + t6.square_n(8); + t5 *= t6; + t5.square_n(8); + t4 *= t5; + t4.square_n(11); + t3 *= t4; + t3.square_n(5); + t2 *= t3; + t2.square_n(13); + t1 *= t2; + t1.square_n(10); + t0 *= t1; + t0.square_n(16); + z *= t0; + return z; + } +}; + +} // namespace brainpool512t1 + +} // namespace + +std::shared_ptr PCurveInstance::brainpool512t1() { + return PrimeOrderCurveImpl::instance(); +} + +} // namespace Botan::PCurve diff --git a/src/lib/math/pcurves/pcurves_instance.h b/src/lib/math/pcurves/pcurves_instance.h index 32f7f07ce3f..d81fbbe20fa 100644 --- a/src/lib/math/pcurves/pcurves_instance.h +++ b/src/lib/math/pcurves/pcurves_instance.h @@ -1,5 +1,5 @@ /* -* This file was automatically generated by ./src/scripts/dev_tools/gen_ec_groups.py on 2026-04-24 +* This file was automatically generated by ./src/scripts/dev_tools/gen_ec_groups.py on 2026-05-08 * All manual changes will be lost. Edit the script instead. * * Botan is released under the Simplified BSD License (see license.txt) @@ -39,14 +39,26 @@ class PCurveInstance final { static std::shared_ptr brainpool256r1(); #endif +#if defined(BOTAN_HAS_PCURVES_BRAINPOOL256T1) + static std::shared_ptr brainpool256t1(); +#endif + #if defined(BOTAN_HAS_PCURVES_BRAINPOOL384R1) static std::shared_ptr brainpool384r1(); #endif +#if defined(BOTAN_HAS_PCURVES_BRAINPOOL384T1) + static std::shared_ptr brainpool384t1(); +#endif + #if defined(BOTAN_HAS_PCURVES_BRAINPOOL512R1) static std::shared_ptr brainpool512r1(); #endif +#if defined(BOTAN_HAS_PCURVES_BRAINPOOL512T1) + static std::shared_ptr brainpool512t1(); +#endif + #if defined(BOTAN_HAS_PCURVES_FRP256V1) static std::shared_ptr frp256v1(); #endif diff --git a/src/lib/pubkey/ec_group/ec_named.cpp b/src/lib/pubkey/ec_group/ec_named.cpp index a70070261ba..412e0157a8e 100644 --- a/src/lib/pubkey/ec_group/ec_named.cpp +++ b/src/lib/pubkey/ec_group/ec_named.cpp @@ -1,6 +1,6 @@ /* * ECC Group Info -* This file was automatically generated by ./src/scripts/dev_tools/gen_ec_groups.py on 2026-04-24 +* This file was automatically generated by ./src/scripts/dev_tools/gen_ec_groups.py on 2026-05-08 * All manual changes will be lost. Edit the script instead. * * Botan is released under the Simplified BSD License (see license.txt) @@ -98,6 +98,18 @@ std::shared_ptr EC_Group::EC_group_info(const OID& oid) { oid); } + // brainpool256t1 + if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 8}) { + return load_EC_group_info( + "0xA9FB57DBA1EEA9BC3E660A909D838D726E3BF623D52620282013481D1F6E5377", + "0xA9FB57DBA1EEA9BC3E660A909D838D726E3BF623D52620282013481D1F6E5374", + "0x662C61C430D84EA4FE66A7733D0B76B7BF93EBC4AF2F49256AE58101FEE92B04", + "0xA3E8EB3CC1CFE7B7732213B23A656149AFA142C47AAFBC2B79A191562E1305F4", + "0x2D996C823439C56D7F7B22E14644417E69BCB6DE39D027001DABE8F35B25C9BE", + "0xA9FB57DBA1EEA9BC3E660A909D838D718C397AA3B561A6F7901E0E82974856A7", + oid); + } + // brainpool320r1 if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 9}) { return load_EC_group_info( @@ -122,6 +134,18 @@ std::shared_ptr EC_Group::EC_group_info(const OID& oid) { oid); } + // brainpool384t1 + if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 12}) { + return load_EC_group_info( + "0x8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B412B1DA197FB71123ACD3A729901D1A71874700133107EC53", + "0x8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B412B1DA197FB71123ACD3A729901D1A71874700133107EC50", + "0x7F519EADA7BDA81BD826DBA647910F8C4B9346ED8CCDC64E4B1ABD11756DCE1D2074AA263B88805CED70355A33B471EE", + "0x18DE98B02DB9A306F2AFCD7235F72A819B80AB12EBD653172476FECD462AABFFC4FF191B946A5F54D8D0AA2F418808CC", + "0x25AB056962D30651A114AFD2755AD336747F93475B7A1FCA3B88F2B6A208CCFE469408584DC2B2912675BF5B9E582928", + "0x8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B31F166E6CAC0425A7CF3AB6AF6B7FC3103B883202E9046565", + oid); + } + // brainpool512r1 if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 13}) { return load_EC_group_info( @@ -134,6 +158,18 @@ std::shared_ptr EC_Group::EC_group_info(const OID& oid) { oid); } + // brainpool512t1 + if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 14}) { + return load_EC_group_info( + "0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA703308717D4D9B009BC66842AECDA12AE6A380E62881FF2F2D82C68528AA6056583A48F3", + "0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA703308717D4D9B009BC66842AECDA12AE6A380E62881FF2F2D82C68528AA6056583A48F0", + "0x7CBBBCF9441CFAB76E1890E46884EAE321F70C0BCB4981527897504BEC3E36A62BCDFA2304976540F6450085F2DAE145C22553B465763689180EA2571867423E", + "0x640ECE5C12788717B9C1BA06CBC2A6FEBA85842458C56DDE9DB1758D39C0313D82BA51735CDB3EA499AA77A7D6943A64F7A3F25FE26F06B51BAA2696FA9035DA", + "0x5B534BD595F5AF0FA2C892376C84ACE1BB4E3019B71634C01131159CAE03CEE9D9932184BEEF216BD71DF2DADF86A627306ECFF96DBB8BACE198B61E00F8B332", + "0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069", + oid); + } + // frp256v1 if(oid == OID{1, 2, 250, 1, 223, 101, 256, 1}) { return load_EC_group_info( @@ -386,6 +422,10 @@ OID EC_Group::EC_group_identity_from_order(const BigInt& order) return OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 7}; } + if(low_bits == 0x974856A7 && order == BigInt("0xA9FB57DBA1EEA9BC3E660A909D838D718C397AA3B561A6F7901E0E82974856A7")) { + return OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 8}; + } + if(low_bits == 0x44C59311 && order == BigInt("0xD35E472036BC4FB7E13C785ED201E065F98FCFA5B68F12A32D482EC7EE8658E98691555B44C59311")) { return OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 9}; } @@ -394,10 +434,18 @@ OID EC_Group::EC_group_identity_from_order(const BigInt& order) return OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 11}; } + if(low_bits == 0xE9046565 && order == BigInt("0x8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B31F166E6CAC0425A7CF3AB6AF6B7FC3103B883202E9046565")) { + return OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 12}; + } + if(low_bits == 0x9CA90069 && order == BigInt("0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069")) { return OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 13}; } + if(low_bits == 0x9CA90069 && order == BigInt("0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069")) { + return OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 14}; + } + if(low_bits == 0xC6D655E1 && order == BigInt("0xF1FD178C0B3AD58F10126DE8CE42435B53DC67E140D2BF941FFDD459C6D655E1")) { return OID{1, 2, 250, 1, 223, 101, 256, 1}; } @@ -480,14 +528,26 @@ const std::set& EC_Group::known_named_groups() { "brainpool256r1", #endif +#if defined(BOTAN_HAS_PCURVES_BRAINPOOL256T1) || defined(BOTAN_HAS_LEGACY_EC_POINT) || defined(BOTAN_HAS_PCURVES_GENERIC) + "brainpool256t1", +#endif + #if defined(BOTAN_HAS_PCURVES_BRAINPOOL384R1) || defined(BOTAN_HAS_LEGACY_EC_POINT) || defined(BOTAN_HAS_PCURVES_GENERIC) "brainpool384r1", #endif +#if defined(BOTAN_HAS_PCURVES_BRAINPOOL384T1) || defined(BOTAN_HAS_LEGACY_EC_POINT) || defined(BOTAN_HAS_PCURVES_GENERIC) + "brainpool384t1", +#endif + #if defined(BOTAN_HAS_PCURVES_BRAINPOOL512R1) || defined(BOTAN_HAS_LEGACY_EC_POINT) || defined(BOTAN_HAS_PCURVES_GENERIC) "brainpool512r1", #endif +#if defined(BOTAN_HAS_PCURVES_BRAINPOOL512T1) || defined(BOTAN_HAS_LEGACY_EC_POINT) || defined(BOTAN_HAS_PCURVES_GENERIC) + "brainpool512t1", +#endif + #if defined(BOTAN_HAS_PCURVES_FRP256V1) || defined(BOTAN_HAS_LEGACY_EC_POINT) || defined(BOTAN_HAS_PCURVES_GENERIC) "frp256v1", #endif