CustomNamedCurves.cs 39 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900
  1. #if !BESTHTTP_DISABLE_ALTERNATE_SSL && (!UNITY_WEBGL || UNITY_EDITOR)
  2. #pragma warning disable
  3. using System;
  4. using System.Collections;
  5. using BestHTTP.SecureProtocol.Org.BouncyCastle.Asn1;
  6. using BestHTTP.SecureProtocol.Org.BouncyCastle.Asn1.GM;
  7. using BestHTTP.SecureProtocol.Org.BouncyCastle.Asn1.Sec;
  8. using BestHTTP.SecureProtocol.Org.BouncyCastle.Asn1.X9;
  9. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math;
  10. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math.EC;
  11. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math.EC.Custom.Djb;
  12. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math.EC.Custom.GM;
  13. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math.EC.Custom.Sec;
  14. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math.EC.Endo;
  15. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math.EC.Multiplier;
  16. using BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities;
  17. using BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Collections;
  18. using BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Encoders;
  19. namespace BestHTTP.SecureProtocol.Org.BouncyCastle.Crypto.EC
  20. {
  21. public sealed class CustomNamedCurves
  22. {
  23. private CustomNamedCurves()
  24. {
  25. }
  26. private static X9ECPoint ConfigureBasepoint(ECCurve curve, string encoding)
  27. {
  28. X9ECPoint G = new X9ECPoint(curve, Hex.DecodeStrict(encoding));
  29. WNafUtilities.ConfigureBasepoint(G.Point);
  30. return G;
  31. }
  32. private static ECCurve ConfigureCurve(ECCurve curve)
  33. {
  34. return curve;
  35. }
  36. private static ECCurve ConfigureCurveGlv(ECCurve c, GlvTypeBParameters p)
  37. {
  38. return c.Configure().SetEndomorphism(new GlvTypeBEndomorphism(c, p)).Create();
  39. }
  40. /*
  41. * curve25519
  42. */
  43. internal class Curve25519Holder
  44. : X9ECParametersHolder
  45. {
  46. private Curve25519Holder() { }
  47. internal static readonly X9ECParametersHolder Instance = new Curve25519Holder();
  48. protected override X9ECParameters CreateParameters()
  49. {
  50. byte[] S = null;
  51. ECCurve curve = ConfigureCurve(new Curve25519());
  52. /*
  53. * NOTE: Curve25519 was specified in Montgomery form. Rewriting in Weierstrass form
  54. * involves substitution of variables, so the base-point x coordinate is 9 + (486662 / 3).
  55. *
  56. * The Curve25519 paper doesn't say which of the two possible y values the base
  57. * point has. The choice here is guided by language in the Ed25519 paper.
  58. *
  59. * (The other possible y value is 5F51E65E475F794B1FE122D388B72EB36DC2B28192839E4DD6163A5D81312C14)
  60. */
  61. X9ECPoint G = ConfigureBasepoint(curve,
  62. "042AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD245A20AE19A1B8A086B4E01EDD2C7748D14C923D4D7E6D7C61B229E9C5A27ECED3D9");
  63. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  64. }
  65. }
  66. /*
  67. * secp128r1
  68. */
  69. internal class SecP128R1Holder
  70. : X9ECParametersHolder
  71. {
  72. private SecP128R1Holder() { }
  73. internal static readonly X9ECParametersHolder Instance = new SecP128R1Holder();
  74. protected override X9ECParameters CreateParameters()
  75. {
  76. byte[] S = Hex.DecodeStrict("000E0D4D696E6768756151750CC03A4473D03679");
  77. ECCurve curve = ConfigureCurve(new SecP128R1Curve());
  78. X9ECPoint G = ConfigureBasepoint(curve,
  79. "04161FF7528B899B2D0C28607CA52C5B86CF5AC8395BAFEB13C02DA292DDED7A83");
  80. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  81. }
  82. };
  83. /*
  84. * secp160k1
  85. */
  86. internal class SecP160K1Holder
  87. : X9ECParametersHolder
  88. {
  89. private SecP160K1Holder() { }
  90. internal static readonly X9ECParametersHolder Instance = new SecP160K1Holder();
  91. protected override X9ECParameters CreateParameters()
  92. {
  93. byte[] S = null;
  94. GlvTypeBParameters glv = new GlvTypeBParameters(
  95. new BigInteger("9ba48cba5ebcb9b6bd33b92830b2a2e0e192f10a", 16),
  96. new BigInteger("c39c6c3b3a36d7701b9c71a1f5804ae5d0003f4", 16),
  97. new ScalarSplitParameters(
  98. new BigInteger[]{
  99. new BigInteger("9162fbe73984472a0a9e", 16),
  100. new BigInteger("-96341f1138933bc2f505", 16) },
  101. new BigInteger[]{
  102. new BigInteger("127971af8721782ecffa3", 16),
  103. new BigInteger("9162fbe73984472a0a9e", 16) },
  104. new BigInteger("9162fbe73984472a0a9d0590", 16),
  105. new BigInteger("96341f1138933bc2f503fd44", 16),
  106. 176));
  107. ECCurve curve = ConfigureCurveGlv(new SecP160K1Curve(), glv);
  108. X9ECPoint G = ConfigureBasepoint(curve,
  109. "043B4C382CE37AA192A4019E763036F4F5DD4D7EBB938CF935318FDCED6BC28286531733C3F03C4FEE");
  110. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  111. }
  112. };
  113. /*
  114. * secp160r1
  115. */
  116. internal class SecP160R1Holder
  117. : X9ECParametersHolder
  118. {
  119. private SecP160R1Holder() { }
  120. internal static readonly X9ECParametersHolder Instance = new SecP160R1Holder();
  121. protected override X9ECParameters CreateParameters()
  122. {
  123. byte[] S = Hex.DecodeStrict("1053CDE42C14D696E67687561517533BF3F83345");
  124. ECCurve curve = ConfigureCurve(new SecP160R1Curve());
  125. X9ECPoint G = ConfigureBasepoint(curve,
  126. "044A96B5688EF573284664698968C38BB913CBFC8223A628553168947D59DCC912042351377AC5FB32");
  127. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  128. }
  129. };
  130. /*
  131. * secp160r2
  132. */
  133. internal class SecP160R2Holder
  134. : X9ECParametersHolder
  135. {
  136. private SecP160R2Holder() { }
  137. internal static readonly X9ECParametersHolder Instance = new SecP160R2Holder();
  138. protected override X9ECParameters CreateParameters()
  139. {
  140. byte[] S = Hex.DecodeStrict("B99B99B099B323E02709A4D696E6768756151751");
  141. ECCurve curve = ConfigureCurve(new SecP160R2Curve());
  142. X9ECPoint G = ConfigureBasepoint(curve,
  143. "0452DCB034293A117E1F4FF11B30F7199D3144CE6DFEAFFEF2E331F296E071FA0DF9982CFEA7D43F2E");
  144. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  145. }
  146. };
  147. /*
  148. * secp192k1
  149. */
  150. internal class SecP192K1Holder
  151. : X9ECParametersHolder
  152. {
  153. private SecP192K1Holder() { }
  154. internal static readonly X9ECParametersHolder Instance = new SecP192K1Holder();
  155. protected override X9ECParameters CreateParameters()
  156. {
  157. byte[] S = null;
  158. GlvTypeBParameters glv = new GlvTypeBParameters(
  159. new BigInteger("bb85691939b869c1d087f601554b96b80cb4f55b35f433c2", 16),
  160. new BigInteger("3d84f26c12238d7b4f3d516613c1759033b1a5800175d0b1", 16),
  161. new ScalarSplitParameters(
  162. new BigInteger[]{
  163. new BigInteger("71169be7330b3038edb025f1", 16),
  164. new BigInteger("-b3fb3400dec5c4adceb8655c", 16) },
  165. new BigInteger[]{
  166. new BigInteger("12511cfe811d0f4e6bc688b4d", 16),
  167. new BigInteger("71169be7330b3038edb025f1", 16) },
  168. new BigInteger("71169be7330b3038edb025f1d0f9", 16),
  169. new BigInteger("b3fb3400dec5c4adceb8655d4c94", 16),
  170. 208));
  171. ECCurve curve = ConfigureCurveGlv(new SecP192K1Curve(), glv);
  172. X9ECPoint G = ConfigureBasepoint(curve,
  173. "04DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D9B2F2F6D9C5628A7844163D015BE86344082AA88D95E2F9D");
  174. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  175. }
  176. }
  177. /*
  178. * secp192r1
  179. */
  180. internal class SecP192R1Holder
  181. : X9ECParametersHolder
  182. {
  183. private SecP192R1Holder() { }
  184. internal static readonly X9ECParametersHolder Instance = new SecP192R1Holder();
  185. protected override X9ECParameters CreateParameters()
  186. {
  187. byte[] S = Hex.DecodeStrict("3045AE6FC8422F64ED579528D38120EAE12196D5");
  188. ECCurve curve = ConfigureCurve(new SecP192R1Curve());
  189. X9ECPoint G = ConfigureBasepoint(curve,
  190. "04188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF101207192B95FFC8DA78631011ED6B24CDD573F977A11E794811");
  191. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  192. }
  193. }
  194. /*
  195. * secp224k1
  196. */
  197. internal class SecP224K1Holder
  198. : X9ECParametersHolder
  199. {
  200. private SecP224K1Holder() { }
  201. internal static readonly X9ECParametersHolder Instance = new SecP224K1Holder();
  202. protected override X9ECParameters CreateParameters()
  203. {
  204. byte[] S = null;
  205. GlvTypeBParameters glv = new GlvTypeBParameters(
  206. new BigInteger("fe0e87005b4e83761908c5131d552a850b3f58b749c37cf5b84d6768", 16),
  207. new BigInteger("60dcd2104c4cbc0be6eeefc2bdd610739ec34e317f9b33046c9e4788", 16),
  208. new ScalarSplitParameters(
  209. new BigInteger[]{
  210. new BigInteger("6b8cf07d4ca75c88957d9d670591", 16),
  211. new BigInteger("-b8adf1378a6eb73409fa6c9c637d", 16) },
  212. new BigInteger[]{
  213. new BigInteger("1243ae1b4d71613bc9f780a03690e", 16),
  214. new BigInteger("6b8cf07d4ca75c88957d9d670591", 16) },
  215. new BigInteger("6b8cf07d4ca75c88957d9d67059037a4", 16),
  216. new BigInteger("b8adf1378a6eb73409fa6c9c637ba7f5", 16),
  217. 240));
  218. ECCurve curve = ConfigureCurveGlv(new SecP224K1Curve(), glv);
  219. X9ECPoint G = ConfigureBasepoint(curve,
  220. "04A1455B334DF099DF30FC28A169A467E9E47075A90F7E650EB6B7A45C7E089FED7FBA344282CAFBD6F7E319F7C0B0BD59E2CA4BDB556D61A5");
  221. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  222. }
  223. }
  224. /*
  225. * secp224r1
  226. */
  227. internal class SecP224R1Holder
  228. : X9ECParametersHolder
  229. {
  230. private SecP224R1Holder() { }
  231. internal static readonly X9ECParametersHolder Instance = new SecP224R1Holder();
  232. protected override X9ECParameters CreateParameters()
  233. {
  234. byte[] S = Hex.DecodeStrict("BD71344799D5C7FCDC45B59FA3B9AB8F6A948BC5");
  235. ECCurve curve = ConfigureCurve(new SecP224R1Curve());
  236. X9ECPoint G = ConfigureBasepoint(curve,
  237. "04B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21BD376388B5F723FB4C22DFE6CD4375A05A07476444D5819985007E34");
  238. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  239. }
  240. }
  241. /*
  242. * secp256k1
  243. */
  244. internal class SecP256K1Holder
  245. : X9ECParametersHolder
  246. {
  247. private SecP256K1Holder() {}
  248. internal static readonly X9ECParametersHolder Instance = new SecP256K1Holder();
  249. protected override X9ECParameters CreateParameters()
  250. {
  251. byte[] S = null;
  252. GlvTypeBParameters glv = new GlvTypeBParameters(
  253. new BigInteger("7ae96a2b657c07106e64479eac3434e99cf0497512f58995c1396c28719501ee", 16),
  254. new BigInteger("5363ad4cc05c30e0a5261c028812645a122e22ea20816678df02967c1b23bd72", 16),
  255. new ScalarSplitParameters(
  256. new BigInteger[]{
  257. new BigInteger("3086d221a7d46bcde86c90e49284eb15", 16),
  258. new BigInteger("-e4437ed6010e88286f547fa90abfe4c3", 16) },
  259. new BigInteger[]{
  260. new BigInteger("114ca50f7a8e2f3f657c1108d9d44cfd8", 16),
  261. new BigInteger("3086d221a7d46bcde86c90e49284eb15", 16) },
  262. new BigInteger("3086d221a7d46bcde86c90e49284eb153dab", 16),
  263. new BigInteger("e4437ed6010e88286f547fa90abfe4c42212", 16),
  264. 272));
  265. ECCurve curve = ConfigureCurveGlv(new SecP256K1Curve(), glv);
  266. X9ECPoint G = ConfigureBasepoint(curve,
  267. "0479BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8");
  268. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  269. }
  270. }
  271. /*
  272. * secp256r1
  273. */
  274. internal class SecP256R1Holder
  275. : X9ECParametersHolder
  276. {
  277. private SecP256R1Holder() {}
  278. internal static readonly X9ECParametersHolder Instance = new SecP256R1Holder();
  279. protected override X9ECParameters CreateParameters()
  280. {
  281. byte[] S = Hex.DecodeStrict("C49D360886E704936A6678E1139D26B7819F7E90");
  282. ECCurve curve = ConfigureCurve(new SecP256R1Curve());
  283. X9ECPoint G = ConfigureBasepoint(curve,
  284. "046B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C2964FE342E2FE1A7F9B8EE7EB4A7C0F9E162BCE33576B315ECECBB6406837BF51F5");
  285. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  286. }
  287. }
  288. /*
  289. * secp384r1
  290. */
  291. internal class SecP384R1Holder
  292. : X9ECParametersHolder
  293. {
  294. private SecP384R1Holder() { }
  295. internal static readonly X9ECParametersHolder Instance = new SecP384R1Holder();
  296. protected override X9ECParameters CreateParameters()
  297. {
  298. byte[] S = Hex.DecodeStrict("A335926AA319A27A1D00896A6773A4827ACDAC73");
  299. ECCurve curve = ConfigureCurve(new SecP384R1Curve());
  300. X9ECPoint G = ConfigureBasepoint(curve, "04"
  301. + "AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7"
  302. + "3617DE4A96262C6F5D9E98BF9292DC29F8F41DBD289A147CE9DA3113B5F0B8C00A60B1CE1D7E819D7A431D7C90EA0E5F");
  303. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  304. }
  305. }
  306. /*
  307. * secp521r1
  308. */
  309. internal class SecP521R1Holder
  310. : X9ECParametersHolder
  311. {
  312. private SecP521R1Holder() { }
  313. internal static readonly X9ECParametersHolder Instance = new SecP521R1Holder();
  314. protected override X9ECParameters CreateParameters()
  315. {
  316. byte[] S = Hex.DecodeStrict("D09E8800291CB85396CC6717393284AAA0DA64BA");
  317. ECCurve curve = ConfigureCurve(new SecP521R1Curve());
  318. X9ECPoint G = ConfigureBasepoint(curve, "04"
  319. + "00C6858E06B70404E9CD9E3ECB662395B4429C648139053FB521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66"
  320. + "011839296A789A3BC0045C8A5FB42C7D1BD998F54449579B446817AFBD17273E662C97EE72995EF42640C550B9013FAD0761353C7086A272C24088BE94769FD16650");
  321. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  322. }
  323. }
  324. /*
  325. * sect113r1
  326. */
  327. internal class SecT113R1Holder
  328. : X9ECParametersHolder
  329. {
  330. private SecT113R1Holder() { }
  331. internal static readonly X9ECParametersHolder Instance = new SecT113R1Holder();
  332. protected override X9ECParameters CreateParameters()
  333. {
  334. byte[] S = Hex.DecodeStrict("10E723AB14D696E6768756151756FEBF8FCB49A9");
  335. ECCurve curve = ConfigureCurve(new SecT113R1Curve());
  336. X9ECPoint G = ConfigureBasepoint(curve,
  337. "04009D73616F35F4AB1407D73562C10F00A52830277958EE84D1315ED31886");
  338. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  339. }
  340. };
  341. /*
  342. * sect113r2
  343. */
  344. internal class SecT113R2Holder
  345. : X9ECParametersHolder
  346. {
  347. private SecT113R2Holder() { }
  348. internal static readonly X9ECParametersHolder Instance = new SecT113R2Holder();
  349. protected override X9ECParameters CreateParameters()
  350. {
  351. byte[] S = Hex.DecodeStrict("10C0FB15760860DEF1EEF4D696E676875615175D");
  352. ECCurve curve = ConfigureCurve(new SecT113R2Curve());
  353. X9ECPoint G = ConfigureBasepoint(curve,
  354. "0401A57A6A7B26CA5EF52FCDB816479700B3ADC94ED1FE674C06E695BABA1D");
  355. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  356. }
  357. };
  358. /*
  359. * sect131r1
  360. */
  361. internal class SecT131R1Holder
  362. : X9ECParametersHolder
  363. {
  364. private SecT131R1Holder() { }
  365. internal static readonly X9ECParametersHolder Instance = new SecT131R1Holder();
  366. protected override X9ECParameters CreateParameters()
  367. {
  368. byte[] S = Hex.DecodeStrict("4D696E676875615175985BD3ADBADA21B43A97E2");
  369. ECCurve curve = ConfigureCurve(new SecT131R1Curve());
  370. X9ECPoint G = ConfigureBasepoint(curve,
  371. "040081BAF91FDF9833C40F9C181343638399078C6E7EA38C001F73C8134B1B4EF9E150");
  372. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  373. }
  374. };
  375. /*
  376. * sect131r2
  377. */
  378. internal class SecT131R2Holder
  379. : X9ECParametersHolder
  380. {
  381. private SecT131R2Holder() { }
  382. internal static readonly X9ECParametersHolder Instance = new SecT131R2Holder();
  383. protected override X9ECParameters CreateParameters()
  384. {
  385. byte[] S = Hex.DecodeStrict("985BD3ADBAD4D696E676875615175A21B43A97E3");
  386. ECCurve curve = ConfigureCurve(new SecT131R2Curve());
  387. X9ECPoint G = ConfigureBasepoint(curve,
  388. "040356DCD8F2F95031AD652D23951BB366A80648F06D867940A5366D9E265DE9EB240F");
  389. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  390. }
  391. };
  392. /*
  393. * sect163k1
  394. */
  395. internal class SecT163K1Holder
  396. : X9ECParametersHolder
  397. {
  398. private SecT163K1Holder() { }
  399. internal static readonly X9ECParametersHolder Instance = new SecT163K1Holder();
  400. protected override X9ECParameters CreateParameters()
  401. {
  402. byte[] S = null;
  403. ECCurve curve = ConfigureCurve(new SecT163K1Curve());
  404. X9ECPoint G = ConfigureBasepoint(curve,
  405. "0402FE13C0537BBC11ACAA07D793DE4E6D5E5C94EEE80289070FB05D38FF58321F2E800536D538CCDAA3D9");
  406. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  407. }
  408. };
  409. /*
  410. * sect163r1
  411. */
  412. internal class SecT163R1Holder
  413. : X9ECParametersHolder
  414. {
  415. private SecT163R1Holder() { }
  416. internal static readonly X9ECParametersHolder Instance = new SecT163R1Holder();
  417. protected override X9ECParameters CreateParameters()
  418. {
  419. byte[] S = Hex.DecodeStrict("24B7B137C8A14D696E6768756151756FD0DA2E5C");
  420. ECCurve curve = ConfigureCurve(new SecT163R1Curve());
  421. X9ECPoint G = ConfigureBasepoint(curve,
  422. "040369979697AB43897789566789567F787A7876A65400435EDB42EFAFB2989D51FEFCE3C80988F41FF883");
  423. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  424. }
  425. };
  426. /*
  427. * sect163r2
  428. */
  429. internal class SecT163R2Holder
  430. : X9ECParametersHolder
  431. {
  432. private SecT163R2Holder() { }
  433. internal static readonly X9ECParametersHolder Instance = new SecT163R2Holder();
  434. protected override X9ECParameters CreateParameters()
  435. {
  436. byte[] S = Hex.DecodeStrict("85E25BFE5C86226CDB12016F7553F9D0E693A268");
  437. ECCurve curve = ConfigureCurve(new SecT163R2Curve());
  438. X9ECPoint G = ConfigureBasepoint(curve,
  439. "0403F0EBA16286A2D57EA0991168D4994637E8343E3600D51FBC6C71A0094FA2CDD545B11C5C0C797324F1");
  440. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  441. }
  442. };
  443. /*
  444. * sect193r1
  445. */
  446. internal class SecT193R1Holder
  447. : X9ECParametersHolder
  448. {
  449. private SecT193R1Holder() { }
  450. internal static readonly X9ECParametersHolder Instance = new SecT193R1Holder();
  451. protected override X9ECParameters CreateParameters()
  452. {
  453. byte[] S = Hex.DecodeStrict("103FAEC74D696E676875615175777FC5B191EF30");
  454. ECCurve curve = ConfigureCurve(new SecT193R1Curve());
  455. X9ECPoint G = ConfigureBasepoint(curve,
  456. "0401F481BC5F0FF84A74AD6CDF6FDEF4BF6179625372D8C0C5E10025E399F2903712CCF3EA9E3A1AD17FB0B3201B6AF7CE1B05");
  457. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  458. }
  459. };
  460. /*
  461. * sect193r2
  462. */
  463. internal class SecT193R2Holder
  464. : X9ECParametersHolder
  465. {
  466. private SecT193R2Holder() { }
  467. internal static readonly X9ECParametersHolder Instance = new SecT193R2Holder();
  468. protected override X9ECParameters CreateParameters()
  469. {
  470. byte[] S = Hex.DecodeStrict("10B7B4D696E676875615175137C8A16FD0DA2211");
  471. ECCurve curve = ConfigureCurve(new SecT193R2Curve());
  472. X9ECPoint G = ConfigureBasepoint(curve,
  473. "0400D9B67D192E0367C803F39E1A7E82CA14A651350AAE617E8F01CE94335607C304AC29E7DEFBD9CA01F596F927224CDECF6C");
  474. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  475. }
  476. };
  477. /*
  478. * sect233k1
  479. */
  480. internal class SecT233K1Holder
  481. : X9ECParametersHolder
  482. {
  483. private SecT233K1Holder() { }
  484. internal static readonly X9ECParametersHolder Instance = new SecT233K1Holder();
  485. protected override X9ECParameters CreateParameters()
  486. {
  487. byte[] S = null;
  488. ECCurve curve = ConfigureCurve(new SecT233K1Curve());
  489. X9ECPoint G = ConfigureBasepoint(curve,
  490. "04017232BA853A7E731AF129F22FF4149563A419C26BF50A4C9D6EEFAD612601DB537DECE819B7F70F555A67C427A8CD9BF18AEB9B56E0C11056FAE6A3");
  491. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  492. }
  493. };
  494. /*
  495. * sect233r1
  496. */
  497. internal class SecT233R1Holder
  498. : X9ECParametersHolder
  499. {
  500. private SecT233R1Holder() { }
  501. internal static readonly X9ECParametersHolder Instance = new SecT233R1Holder();
  502. protected override X9ECParameters CreateParameters()
  503. {
  504. byte[] S = Hex.DecodeStrict("74D59FF07F6B413D0EA14B344B20A2DB049B50C3");
  505. ECCurve curve = ConfigureCurve(new SecT233R1Curve());
  506. X9ECPoint G = ConfigureBasepoint(curve,
  507. "0400FAC9DFCBAC8313BB2139F1BB755FEF65BC391F8B36F8F8EB7371FD558B01006A08A41903350678E58528BEBF8A0BEFF867A7CA36716F7E01F81052");
  508. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  509. }
  510. };
  511. /*
  512. * sect239k1
  513. */
  514. internal class SecT239K1Holder
  515. : X9ECParametersHolder
  516. {
  517. private SecT239K1Holder() { }
  518. internal static readonly X9ECParametersHolder Instance = new SecT239K1Holder();
  519. protected override X9ECParameters CreateParameters()
  520. {
  521. byte[] S = null;
  522. ECCurve curve = ConfigureCurve(new SecT239K1Curve());
  523. X9ECPoint G = ConfigureBasepoint(curve,
  524. "0429A0B6A887A983E9730988A68727A8B2D126C44CC2CC7B2A6555193035DC76310804F12E549BDB011C103089E73510ACB275FC312A5DC6B76553F0CA");
  525. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  526. }
  527. };
  528. /*
  529. * sect283k1
  530. */
  531. internal class SecT283K1Holder
  532. : X9ECParametersHolder
  533. {
  534. private SecT283K1Holder() { }
  535. internal static readonly X9ECParametersHolder Instance = new SecT283K1Holder();
  536. protected override X9ECParameters CreateParameters()
  537. {
  538. byte[] S = null;
  539. ECCurve curve = ConfigureCurve(new SecT283K1Curve());
  540. X9ECPoint G = ConfigureBasepoint(curve, "04"
  541. + "0503213F78CA44883F1A3B8162F188E553CD265F23C1567A16876913B0C2AC2458492836"
  542. + "01CCDA380F1C9E318D90F95D07E5426FE87E45C0E8184698E45962364E34116177DD2259");
  543. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  544. }
  545. };
  546. /*
  547. * sect283r1
  548. */
  549. internal class SecT283R1Holder
  550. : X9ECParametersHolder
  551. {
  552. private SecT283R1Holder() { }
  553. internal static readonly X9ECParametersHolder Instance = new SecT283R1Holder();
  554. protected override X9ECParameters CreateParameters()
  555. {
  556. byte[] S = Hex.DecodeStrict("77E2B07370EB0F832A6DD5B62DFC88CD06BB84BE");
  557. ECCurve curve = ConfigureCurve(new SecT283R1Curve());
  558. X9ECPoint G = ConfigureBasepoint(curve, "04"
  559. + "05F939258DB7DD90E1934F8C70B0DFEC2EED25B8557EAC9C80E2E198F8CDBECD86B12053"
  560. + "03676854FE24141CB98FE6D4B20D02B4516FF702350EDDB0826779C813F0DF45BE8112F4");
  561. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  562. }
  563. };
  564. /*
  565. * sect409k1
  566. */
  567. internal class SecT409K1Holder
  568. : X9ECParametersHolder
  569. {
  570. private SecT409K1Holder() { }
  571. internal static readonly X9ECParametersHolder Instance = new SecT409K1Holder();
  572. protected override X9ECParameters CreateParameters()
  573. {
  574. byte[] S = null;
  575. ECCurve curve = ConfigureCurve(new SecT409K1Curve());
  576. X9ECPoint G = ConfigureBasepoint(curve, "04"
  577. + "0060F05F658F49C1AD3AB1890F7184210EFD0987E307C84C27ACCFB8F9F67CC2C460189EB5AAAA62EE222EB1B35540CFE9023746"
  578. + "01E369050B7C4E42ACBA1DACBF04299C3460782F918EA427E6325165E9EA10E3DA5F6C42E9C55215AA9CA27A5863EC48D8E0286B");
  579. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  580. }
  581. };
  582. /*
  583. * sect409r1
  584. */
  585. internal class SecT409R1Holder
  586. : X9ECParametersHolder
  587. {
  588. private SecT409R1Holder() { }
  589. internal static readonly X9ECParametersHolder Instance = new SecT409R1Holder();
  590. protected override X9ECParameters CreateParameters()
  591. {
  592. byte[] S = Hex.DecodeStrict("4099B5A457F9D69F79213D094C4BCD4D4262210B");
  593. ECCurve curve = ConfigureCurve(new SecT409R1Curve());
  594. X9ECPoint G = ConfigureBasepoint(curve, "04"
  595. + "015D4860D088DDB3496B0C6064756260441CDE4AF1771D4DB01FFE5B34E59703DC255A868A1180515603AEAB60794E54BB7996A7"
  596. + "0061B1CFAB6BE5F32BBFA78324ED106A7636B9C5A7BD198D0158AA4F5488D08F38514F1FDF4B4F40D2181B3681C364BA0273C706");
  597. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  598. }
  599. };
  600. /*
  601. * sect571k1
  602. */
  603. internal class SecT571K1Holder
  604. : X9ECParametersHolder
  605. {
  606. private SecT571K1Holder() { }
  607. internal static readonly X9ECParametersHolder Instance = new SecT571K1Holder();
  608. protected override X9ECParameters CreateParameters()
  609. {
  610. byte[] S = null;
  611. ECCurve curve = ConfigureCurve(new SecT571K1Curve());
  612. X9ECPoint G = ConfigureBasepoint(curve, "04"
  613. + "026EB7A859923FBC82189631F8103FE4AC9CA2970012D5D46024804801841CA44370958493B205E647DA304DB4CEB08CBBD1BA39494776FB988B47174DCA88C7E2945283A01C8972"
  614. + "0349DC807F4FBF374F4AEADE3BCA95314DD58CEC9F307A54FFC61EFC006D8A2C9D4979C0AC44AEA74FBEBBB9F772AEDCB620B01A7BA7AF1B320430C8591984F601CD4C143EF1C7A3");
  615. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  616. }
  617. };
  618. /*
  619. * sect571r1
  620. */
  621. internal class SecT571R1Holder
  622. : X9ECParametersHolder
  623. {
  624. private SecT571R1Holder() { }
  625. internal static readonly X9ECParametersHolder Instance = new SecT571R1Holder();
  626. protected override X9ECParameters CreateParameters()
  627. {
  628. byte[] S = Hex.DecodeStrict("2AA058F73A0E33AB486B0F610410C53A7F132310");
  629. ECCurve curve = ConfigureCurve(new SecT571R1Curve());
  630. X9ECPoint G = ConfigureBasepoint(curve, "04"
  631. + "0303001D34B856296C16C0D40D3CD7750A93D1D2955FA80AA5F40FC8DB7B2ABDBDE53950F4C0D293CDD711A35B67FB1499AE60038614F1394ABFA3B4C850D927E1E7769C8EEC2D19"
  632. + "037BF27342DA639B6DCCFFFEB73D69D78C6C27A6009CBBCA1980F8533921E8A684423E43BAB08A576291AF8F461BB2A8B3531D2F0485C19B16E2F1516E23DD3C1A4827AF1B8AC15B");
  633. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  634. }
  635. };
  636. /*
  637. * sm2p256v1
  638. */
  639. internal class SM2P256V1Holder
  640. : X9ECParametersHolder
  641. {
  642. private SM2P256V1Holder() { }
  643. internal static readonly X9ECParametersHolder Instance = new SM2P256V1Holder();
  644. protected override X9ECParameters CreateParameters()
  645. {
  646. byte[] S = null;
  647. ECCurve curve = ConfigureCurve(new SM2P256V1Curve());
  648. X9ECPoint G = ConfigureBasepoint(curve,
  649. "0432C4AE2C1F1981195F9904466A39C9948FE30BBFF2660BE1715A4589334C74C7BC3736A2F4F6779C59BDCEE36B692153D0A9877CC62A474002DF32E52139F0A0");
  650. return new X9ECParameters(curve, G, curve.Order, curve.Cofactor, S);
  651. }
  652. }
  653. private static readonly IDictionary nameToCurve = BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.CreateHashtable();
  654. private static readonly IDictionary nameToOid = BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.CreateHashtable();
  655. private static readonly IDictionary oidToCurve = BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.CreateHashtable();
  656. private static readonly IDictionary oidToName = BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.CreateHashtable();
  657. private static readonly IList names = BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.CreateArrayList();
  658. private static void DefineCurve(string name, X9ECParametersHolder holder)
  659. {
  660. names.Add(name);
  661. name = BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.ToUpperInvariant(name);
  662. nameToCurve.Add(name, holder);
  663. }
  664. private static void DefineCurveWithOid(string name, DerObjectIdentifier oid, X9ECParametersHolder holder)
  665. {
  666. names.Add(name);
  667. oidToName.Add(oid, name);
  668. oidToCurve.Add(oid, holder);
  669. name = BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.ToUpperInvariant(name);
  670. nameToOid.Add(name, oid);
  671. nameToCurve.Add(name, holder);
  672. }
  673. private static void DefineCurveAlias(string name, DerObjectIdentifier oid)
  674. {
  675. object curve = oidToCurve[oid];
  676. if (curve == null)
  677. throw new InvalidOperationException();
  678. name = BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.ToUpperInvariant(name);
  679. nameToOid.Add(name, oid);
  680. nameToCurve.Add(name, curve);
  681. }
  682. static CustomNamedCurves()
  683. {
  684. DefineCurve("curve25519", Curve25519Holder.Instance);
  685. //DefineCurveWithOid("secp112r1", SecObjectIdentifiers.SecP112r1, SecP112R1Holder.Instance);
  686. //DefineCurveWithOid("secp112r2", SecObjectIdentifiers.SecP112r2, SecP112R2Holder.Instance);
  687. DefineCurveWithOid("secp128r1", SecObjectIdentifiers.SecP128r1, SecP128R1Holder.Instance);
  688. //DefineCurveWithOid("secp128r2", SecObjectIdentifiers.SecP128r2, SecP128R2Holder.Instance);
  689. DefineCurveWithOid("secp160k1", SecObjectIdentifiers.SecP160k1, SecP160K1Holder.Instance);
  690. DefineCurveWithOid("secp160r1", SecObjectIdentifiers.SecP160r1, SecP160R1Holder.Instance);
  691. DefineCurveWithOid("secp160r2", SecObjectIdentifiers.SecP160r2, SecP160R2Holder.Instance);
  692. DefineCurveWithOid("secp192k1", SecObjectIdentifiers.SecP192k1, SecP192K1Holder.Instance);
  693. DefineCurveWithOid("secp192r1", SecObjectIdentifiers.SecP192r1, SecP192R1Holder.Instance);
  694. DefineCurveWithOid("secp224k1", SecObjectIdentifiers.SecP224k1, SecP224K1Holder.Instance);
  695. DefineCurveWithOid("secp224r1", SecObjectIdentifiers.SecP224r1, SecP224R1Holder.Instance);
  696. DefineCurveWithOid("secp256k1", SecObjectIdentifiers.SecP256k1, SecP256K1Holder.Instance);
  697. DefineCurveWithOid("secp256r1", SecObjectIdentifiers.SecP256r1, SecP256R1Holder.Instance);
  698. DefineCurveWithOid("secp384r1", SecObjectIdentifiers.SecP384r1, SecP384R1Holder.Instance);
  699. DefineCurveWithOid("secp521r1", SecObjectIdentifiers.SecP521r1, SecP521R1Holder.Instance);
  700. DefineCurveWithOid("sect113r1", SecObjectIdentifiers.SecT113r1, SecT113R1Holder.Instance);
  701. DefineCurveWithOid("sect113r2", SecObjectIdentifiers.SecT113r2, SecT113R2Holder.Instance);
  702. DefineCurveWithOid("sect131r1", SecObjectIdentifiers.SecT131r1, SecT131R1Holder.Instance);
  703. DefineCurveWithOid("sect131r2", SecObjectIdentifiers.SecT131r2, SecT131R2Holder.Instance);
  704. DefineCurveWithOid("sect163k1", SecObjectIdentifiers.SecT163k1, SecT163K1Holder.Instance);
  705. DefineCurveWithOid("sect163r1", SecObjectIdentifiers.SecT163r1, SecT163R1Holder.Instance);
  706. DefineCurveWithOid("sect163r2", SecObjectIdentifiers.SecT163r2, SecT163R2Holder.Instance);
  707. DefineCurveWithOid("sect193r1", SecObjectIdentifiers.SecT193r1, SecT193R1Holder.Instance);
  708. DefineCurveWithOid("sect193r2", SecObjectIdentifiers.SecT193r2, SecT193R2Holder.Instance);
  709. DefineCurveWithOid("sect233k1", SecObjectIdentifiers.SecT233k1, SecT233K1Holder.Instance);
  710. DefineCurveWithOid("sect233r1", SecObjectIdentifiers.SecT233r1, SecT233R1Holder.Instance);
  711. DefineCurveWithOid("sect239k1", SecObjectIdentifiers.SecT239k1, SecT239K1Holder.Instance);
  712. DefineCurveWithOid("sect283k1", SecObjectIdentifiers.SecT283k1, SecT283K1Holder.Instance);
  713. DefineCurveWithOid("sect283r1", SecObjectIdentifiers.SecT283r1, SecT283R1Holder.Instance);
  714. DefineCurveWithOid("sect409k1", SecObjectIdentifiers.SecT409k1, SecT409K1Holder.Instance);
  715. DefineCurveWithOid("sect409r1", SecObjectIdentifiers.SecT409r1, SecT409R1Holder.Instance);
  716. DefineCurveWithOid("sect571k1", SecObjectIdentifiers.SecT571k1, SecT571K1Holder.Instance);
  717. DefineCurveWithOid("sect571r1", SecObjectIdentifiers.SecT571r1, SecT571R1Holder.Instance);
  718. DefineCurveWithOid("sm2p256v1", GMObjectIdentifiers.sm2p256v1, SM2P256V1Holder.Instance);
  719. DefineCurveAlias("B-163", SecObjectIdentifiers.SecT163r2);
  720. DefineCurveAlias("B-233", SecObjectIdentifiers.SecT233r1);
  721. DefineCurveAlias("B-283", SecObjectIdentifiers.SecT283r1);
  722. DefineCurveAlias("B-409", SecObjectIdentifiers.SecT409r1);
  723. DefineCurveAlias("B-571", SecObjectIdentifiers.SecT571r1);
  724. DefineCurveAlias("K-163", SecObjectIdentifiers.SecT163k1);
  725. DefineCurveAlias("K-233", SecObjectIdentifiers.SecT233k1);
  726. DefineCurveAlias("K-283", SecObjectIdentifiers.SecT283k1);
  727. DefineCurveAlias("K-409", SecObjectIdentifiers.SecT409k1);
  728. DefineCurveAlias("K-571", SecObjectIdentifiers.SecT571k1);
  729. DefineCurveAlias("P-192", SecObjectIdentifiers.SecP192r1);
  730. DefineCurveAlias("P-224", SecObjectIdentifiers.SecP224r1);
  731. DefineCurveAlias("P-256", SecObjectIdentifiers.SecP256r1);
  732. DefineCurveAlias("P-384", SecObjectIdentifiers.SecP384r1);
  733. DefineCurveAlias("P-521", SecObjectIdentifiers.SecP521r1);
  734. }
  735. public static X9ECParameters GetByName(string name)
  736. {
  737. X9ECParametersHolder holder = (X9ECParametersHolder)nameToCurve[BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.ToUpperInvariant(name)];
  738. return holder == null ? null : holder.Parameters;
  739. }
  740. /**
  741. * return the X9ECParameters object for the named curve represented by
  742. * the passed in object identifier. Null if the curve isn't present.
  743. *
  744. * @param oid an object identifier representing a named curve, if present.
  745. */
  746. public static X9ECParameters GetByOid(DerObjectIdentifier oid)
  747. {
  748. X9ECParametersHolder holder = (X9ECParametersHolder)oidToCurve[oid];
  749. return holder == null ? null : holder.Parameters;
  750. }
  751. /**
  752. * return the object identifier signified by the passed in name. Null
  753. * if there is no object identifier associated with name.
  754. *
  755. * @return the object identifier associated with name, if present.
  756. */
  757. public static DerObjectIdentifier GetOid(string name)
  758. {
  759. return (DerObjectIdentifier)nameToOid[BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.ToUpperInvariant(name)];
  760. }
  761. /**
  762. * return the named curve name represented by the given object identifier.
  763. */
  764. public static string GetName(DerObjectIdentifier oid)
  765. {
  766. return (string)oidToName[oid];
  767. }
  768. /**
  769. * returns an enumeration containing the name strings for curves
  770. * contained in this structure.
  771. */
  772. public static IEnumerable Names
  773. {
  774. get { return new EnumerableProxy(names); }
  775. }
  776. }
  777. }
  778. #pragma warning restore
  779. #endif