1 C nettle, low-level cryptographics library
3 C Copyright (C) 2013, Niels Möller
5 C The nettle library is free software; you can redistribute it and/or modify
6 C it under the terms of the GNU Lesser General Public License as published by
7 C the Free Software Foundation; either version 2.1 of the License, or (at your
8 C option) any later version.
10 C The nettle library is distributed in the hope that it will be useful, but
11 C WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 C or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public
13 C License for more details.
15 C You should have received a copy of the GNU Lesser General Public License
16 C along with the nettle library; see the file COPYING.LIB. If not, write to
17 C the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston,
20 .file "ecc-384-modp.asm"
36 C ecc_384_modp (const struct ecc_curve *ecc, mp_limb_t *rp)
40 PROLOGUE(nettle_ecc_384_modp)
41 push {r4,r5,r6,r7,r8,r10,lr}
44 ldm RP, {T0, T1, T2, T3} C 20-23
46 C First get top 4 limbs, which need folding twice, as
60 C F2 F1 F0 Always fits
82 ldm RP, {T0, T1, T2, T3} C 12-15
88 adcs F4, F4, #0 C Do F4 later
90 C Add to low part, keeping carry (positive or negative) in H
92 ldm RP, {T0, T1, T2, T3} C 0-3
106 stm RP!, {T0,T1,T2,T3} C 0-3
109 ldm RP, {T0,T1,T2,T3} C 4-7
111 C First, propagate carry
113 asr H, #31 C Sign extend
127 ldr F0, [RP, #+48] C 16
135 ldr F1, [RP, #+52] C 17-18
144 ldr F3, [RP, #+60] C 19
151 stm RP!, {T0,T1,T2,T3}
154 C Fold high limbs, we need to add in
156 C F4 F4 0 -F4 F4 H H 0 -H H
158 C We always have F4 >= 0, but we can have H < 0.
159 C Sign extension gets tricky when F4 = 0 and H < 0.
162 ldm RP, {T0,T1,T2,T3} C 0-3
168 C Define S = H >> 31 (asr), we then have
176 C And we get underflow in S - H iff H > 0
181 subs F1, H, F0 C 0,C=1 -H,C=0 0,C=1
182 sbc F2, F2, F2 C 0 -1 0
183 sbc F3, F0, #0 C 0 H-1 -1
189 adc H, H, F0 C 0+cy H+cy -2+cy
191 stm RP!, {T0,T1,T2,T3} C 0-3
192 ldm RP, {T0,T1,T2,T3} C 4-7
216 stm RP!, {T0,T1,T2,T3} C 4-7
217 ldm RP, {T0,T1,T2,T3} C 8-11
225 stm RP, {T0,T1,T2,T3} C 8-11
227 C Final (unlikely) carry
229 ldm RP, {T0,T1,T2,T3} C 0-3
243 stm RP!, {T0,T1,T2,T3} C 0-3
244 ldm RP, {T0,T1,T2,T3} C 4-7
249 stm RP!, {T0,T1,T2,T3} C 4-7
250 ldm RP, {T0,T1,T2,T3} C 8-11
255 stm RP!, {T0,T1,T2,T3} C 8-11
256 pop {r4,r5,r6,r7,r8,r10,pc}
257 EPILOGUE(nettle_ecc_384_modp)