summaryrefslogtreecommitdiffhomepage
path: root/libtomcrypt/notes/tech0006.txt
diff options
context:
space:
mode:
authorMatt Johnston <matt@ucc.asn.au>2007-02-03 08:20:34 +0000
committerMatt Johnston <matt@ucc.asn.au>2007-02-03 08:20:34 +0000
commitd9aeb2773e236e662c8b493f4bcee978f9908d7c (patch)
treebac48e388bf3ac739ae14cdf98da0eb4bb9d17bf /libtomcrypt/notes/tech0006.txt
parent056b92bd4c8a42ce1843493310d382159166edb8 (diff)
parentc5fd7dd5548f28e32d846e39d17e5c4de4e769af (diff)
merge of '5fdf69ca60d1683cdd9f4c2595134bed26394834'
and '6b61c50f4cf888bea302ac8fcf5dbb573b443251' --HG-- extra : convert_revision : b1dd3b94e60a07a176dba2b035ac79968595990a
Diffstat (limited to 'libtomcrypt/notes/tech0006.txt')
-rw-r--r--libtomcrypt/notes/tech0006.txt91
1 files changed, 91 insertions, 0 deletions
diff --git a/libtomcrypt/notes/tech0006.txt b/libtomcrypt/notes/tech0006.txt
new file mode 100644
index 0000000..ecbe8b0
--- /dev/null
+++ b/libtomcrypt/notes/tech0006.txt
@@ -0,0 +1,91 @@
+Tech Note 0006
+PK Standards Compliance
+Tom St Denis
+
+RSA
+----
+
+PKCS #1 compliance.
+
+Key Format: RSAPublicKey and RSAPrivateKey as per PKCS #1 v2.1
+Encryption: OAEP as per PKCS #1
+Signature : PSS as per PKCS #1
+
+DSA
+----
+
+The NIST DSA algorithm
+
+Key Format: HomeBrew [see below]
+Signature : ANSI X9.62 format [see below].
+
+Keys are stored as
+
+DSAPublicKey ::= SEQUENCE {
+ publicFlags BIT STRING(1), -- must be 0
+ g INTEGER , -- base generator, check that g^q mod p == 1
+ -- and that 1 < g < p - 1
+ p INTEGER , -- prime modulus
+ q INTEGER , -- order of sub-group (must be prime)
+ y INTEGER , -- public key, specifically, g^x mod p,
+ -- check that y^q mod p == 1
+ -- and that 1 < y < p - 1
+}
+
+DSAPrivateKey ::= SEQUENCE {
+ publicFlags BIT STRING(1), -- must be 1
+ g INTEGER , -- base generator, check that g^q mod p == 1
+ -- and that 1 < g < p - 1
+ p INTEGER , -- prime modulus
+ q INTEGER , -- order of sub-group (must be prime)
+ y INTEGER , -- public key, specifically, g^x mod p,
+ -- check that y^q mod p == 1
+ -- and that 1 < y < p - 1
+ x INTEGER -- private key
+}
+
+Signatures are stored as
+
+DSASignature ::= SEQUENCE {
+ r, s INTEGER -- signature parameters
+}
+
+ECC
+----
+
+The ANSI X9.62 and X9.63 algorithms [partial]. Supports all NIST GF(p) curves.
+
+Key Format : Homebrew [see below, only GF(p) NIST curves supported]
+Signature : X9.62 compliant
+Encryption : Homebrew [based on X9.63, differs in that the public point is stored as an ECCPublicKey]
+Shared Secret: X9.63 compliant
+
+ECCPublicKey ::= SEQUENCE {
+ flags BIT STRING(1), -- public/private flag (always zero),
+ keySize INTEGER, -- Curve size (in bits) divided by eight
+ -- and rounded down, e.g. 521 => 65
+ pubkey.x INTEGER, -- The X co-ordinate of the public key point
+ pubkey.y INTEGER, -- The Y co-ordinate of the public key point
+}
+
+ECCPrivateKey ::= SEQUENCE {
+ flags BIT STRING(1), -- public/private flag (always one),
+ keySize INTEGER, -- Curve size (in bits) divided by eight
+ -- and rounded down, e.g. 521 => 65
+ pubkey.x INTEGER, -- The X co-ordinate of the public key point
+ pubkey.y INTEGER, -- The Y co-ordinate of the public key point
+ secret.k INTEGER, -- The secret key scalar
+}
+
+The encryption works by finding the X9.63 shared secret and hashing it. The hash is then simply XOR'ed against the message [which must be at most the size
+of the hash digest]. The format of the encrypted text is as follows
+
+ECCEncrypted ::= SEQUENCE {
+ hashOID OBJECT IDENTIFIER, -- The OID of the hash used
+ pubkey OCTET STRING , -- Encapsulation of a random ECCPublicKey
+ skey OCTET STRING -- The encrypted text (which the hash was XOR'ed against)
+}
+
+% $Source: /cvs/libtom/libtomcrypt/notes/tech0006.txt,v $
+% $Revision: 1.2 $
+% $Date: 2005/06/18 02:26:27 $