2018-05-02 19:43:17 +00:00
|
|
|
#include "tommath_private.h"
|
2004-10-29 22:07:18 +00:00
|
|
|
#ifdef BN_MP_REDUCE_C
|
2019-04-07 13:29:11 +00:00
|
|
|
/* LibTomMath, multiple-precision integer library -- Tom St Denis */
|
|
|
|
/* SPDX-License-Identifier: Unlicense */
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2014-09-02 00:14:38 +00:00
|
|
|
/* reduces x mod m, assumes 0 < x < m**2, mu is
|
2003-05-29 13:35:26 +00:00
|
|
|
* precomputed via mp_reduce_setup.
|
2003-05-17 12:33:54 +00:00
|
|
|
* From HAC pp.604 Algorithm 14.42
|
2003-02-28 16:08:34 +00:00
|
|
|
*/
|
2019-05-12 22:22:18 +00:00
|
|
|
mp_err mp_reduce(mp_int *x, const mp_int *m, const mp_int *mu)
|
2003-02-28 16:08:34 +00:00
|
|
|
{
|
2017-08-30 18:23:46 +00:00
|
|
|
mp_int q;
|
2019-05-19 15:16:13 +00:00
|
|
|
mp_err err;
|
2019-05-12 22:22:18 +00:00
|
|
|
int um = m->used;
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2017-08-30 18:23:46 +00:00
|
|
|
/* q = x */
|
2019-05-19 15:16:13 +00:00
|
|
|
if ((err = mp_init_copy(&q, x)) != MP_OKAY) {
|
|
|
|
return err;
|
2017-08-30 18:23:46 +00:00
|
|
|
}
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2017-08-30 18:23:46 +00:00
|
|
|
/* q1 = x / b**(k-1) */
|
|
|
|
mp_rshd(&q, um - 1);
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2017-08-30 18:23:46 +00:00
|
|
|
/* according to HAC this optimization is ok */
|
2019-04-13 06:46:57 +00:00
|
|
|
if ((mp_digit)um > ((mp_digit)1 << (MP_DIGIT_BIT - 1))) {
|
2019-05-19 15:16:13 +00:00
|
|
|
if ((err = mp_mul(&q, mu, &q)) != MP_OKAY) {
|
2017-08-30 18:23:46 +00:00
|
|
|
goto CLEANUP;
|
|
|
|
}
|
2019-04-08 21:48:39 +00:00
|
|
|
} else if (MP_HAS(S_MP_MUL_HIGH_DIGS)) {
|
2019-05-19 15:16:13 +00:00
|
|
|
if ((err = s_mp_mul_high_digs(&q, mu, &q, um)) != MP_OKAY) {
|
2017-08-30 18:23:46 +00:00
|
|
|
goto CLEANUP;
|
|
|
|
}
|
2019-04-08 21:48:39 +00:00
|
|
|
} else if (MP_HAS(S_MP_MUL_HIGH_DIGS_FAST)) {
|
2019-05-19 15:16:13 +00:00
|
|
|
if ((err = s_mp_mul_high_digs_fast(&q, mu, &q, um)) != MP_OKAY) {
|
2017-08-30 18:23:46 +00:00
|
|
|
goto CLEANUP;
|
|
|
|
}
|
2019-04-08 21:48:39 +00:00
|
|
|
} else {
|
|
|
|
err = MP_VAL;
|
|
|
|
goto CLEANUP;
|
2017-08-30 18:23:46 +00:00
|
|
|
}
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2017-08-30 18:23:46 +00:00
|
|
|
/* q3 = q2 / b**(k+1) */
|
|
|
|
mp_rshd(&q, um + 1);
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2017-08-30 18:23:46 +00:00
|
|
|
/* x = x mod b**(k+1), quick (no division) */
|
2019-05-19 15:16:13 +00:00
|
|
|
if ((err = mp_mod_2d(x, MP_DIGIT_BIT * (um + 1), x)) != MP_OKAY) {
|
2003-02-28 16:08:34 +00:00
|
|
|
goto CLEANUP;
|
2017-08-30 18:23:46 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/* q = q * m mod b**(k+1), quick (no division) */
|
2019-05-19 15:16:13 +00:00
|
|
|
if ((err = s_mp_mul_digs(&q, m, &q, um + 1)) != MP_OKAY) {
|
2003-02-28 16:08:34 +00:00
|
|
|
goto CLEANUP;
|
2017-08-30 18:23:46 +00:00
|
|
|
}
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2017-08-30 18:23:46 +00:00
|
|
|
/* x = x - q */
|
2019-05-19 15:16:13 +00:00
|
|
|
if ((err = mp_sub(x, &q, x)) != MP_OKAY) {
|
2003-06-19 10:04:50 +00:00
|
|
|
goto CLEANUP;
|
2017-08-30 18:23:46 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/* If x < 0, add b**(k+1) to it */
|
2017-10-15 14:11:09 +00:00
|
|
|
if (mp_cmp_d(x, 0uL) == MP_LT) {
|
|
|
|
mp_set(&q, 1uL);
|
2019-06-12 05:51:04 +00:00
|
|
|
if ((err = mp_lshd(&q, um + 1)) != MP_OKAY) {
|
2017-08-30 18:23:46 +00:00
|
|
|
goto CLEANUP;
|
2019-06-12 05:51:04 +00:00
|
|
|
}
|
|
|
|
if ((err = mp_add(x, &q, x)) != MP_OKAY) {
|
2017-08-30 18:23:46 +00:00
|
|
|
goto CLEANUP;
|
2019-06-12 05:51:04 +00:00
|
|
|
}
|
2017-08-30 18:23:46 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/* Back off if it's too big */
|
|
|
|
while (mp_cmp(x, m) != MP_LT) {
|
2019-05-19 15:16:13 +00:00
|
|
|
if ((err = s_mp_sub(x, m, x)) != MP_OKAY) {
|
2017-08-30 18:23:46 +00:00
|
|
|
goto CLEANUP;
|
|
|
|
}
|
|
|
|
}
|
2014-09-02 00:14:38 +00:00
|
|
|
|
2003-02-28 16:08:34 +00:00
|
|
|
CLEANUP:
|
2017-08-30 18:23:46 +00:00
|
|
|
mp_clear(&q);
|
2003-02-28 16:08:34 +00:00
|
|
|
|
2019-05-19 15:16:13 +00:00
|
|
|
return err;
|
2003-02-28 16:08:34 +00:00
|
|
|
}
|
2004-10-29 22:07:18 +00:00
|
|
|
#endif
|