From 88bbab22e96a5872c73337819290ff51424cdec7 Mon Sep 17 00:00:00 2001 From: Hanno Becker Date: Thu, 11 May 2017 15:57:15 +0100 Subject: [PATCH 1/3] Correct sign in modular exponentiation algorithm. The modular exponentiation function handled the sign incorrectly. This commit fixes this and a test case which should have caught it. --- library/bignum.c | 2 +- tests/suites/test_suite_mpi.data | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/library/bignum.c b/library/bignum.c index afde19bd5..211cb2af5 100644 --- a/library/bignum.c +++ b/library/bignum.c @@ -1788,7 +1788,7 @@ int mpi_exp_mod( mpi *X, const mpi *A, const mpi *E, const mpi *N, mpi *_RR ) */ mpi_montred( X, N, mm, &T ); - if( neg ) + if( neg && E->n != 0 && ( E->p[0] & 1 ) != 0 ) { X->s = -1; MPI_CHK( mpi_add_mpi( X, N, X ) ); diff --git a/tests/suites/test_suite_mpi.data b/tests/suites/test_suite_mpi.data index 81fc73f32..cff62b4d9 100644 --- a/tests/suites/test_suite_mpi.data +++ b/tests/suites/test_suite_mpi.data @@ -521,7 +521,7 @@ Test mpi_exp_mod #1 mpi_exp_mod:10:"433019240910377478217373572959560109819648647016096560523769010881172869083338285573756574557395862965095016483867813043663981946477698466501451832407592327356331263124555137732393938242285782144928753919588632679050799198937132922145084847":10:"5781538327977828897150909166778407659250458379645823062042492461576758526757490910073628008613977550546382774775570888130029763571528699574717583228939535960234464230882573615930384979100379102915657483866755371559811718767760594919456971354184113721":10:"583137007797276923956891216216022144052044091311388601652961409557516421612874571554415606746479105795833145583959622117418531166391184939066520869800857530421873250114773204354963864729386957427276448683092491947566992077136553066273207777134303397724679138833126700957":10:"":10:"114597449276684355144920670007147953232659436380163461553186940113929777196018164149703566472936578890991049344459204199888254907113495794730452699842273939581048142004834330369483813876618772578869083248061616444392091693787039636316845512292127097865026290173004860736":0 Test mpi_exp_mod (Negative base) -mpi_exp_mod:10:"-10000000000":10:"10000000000":10:"99999":10:"":10:"99998":0 +mpi_exp_mod:10:"-10000000000":10:"10000000000":10:"99999":10:"":10:"1":0 Test mpi_exp_mod (Negative base) mpi_exp_mod:16:"-9f13012cd92aa72fb86ac8879d2fde4f7fd661aaae43a00971f081cc60ca277059d5c37e89652e2af2585d281d66ef6a9d38a117e9608e9e7574cd142dc55278838a2161dd56db9470d4c1da2d5df15a908ee2eb886aaa890f23be16de59386663a12f1afbb325431a3e835e3fd89b98b96a6f77382f458ef9a37e1f84a03045c8676ab55291a94c2228ea15448ee96b626b998":16:"40a54d1b9e86789f06d9607fb158672d64867665c73ee9abb545fc7a785634b354c7bae5b962ce8040cf45f2c1f3d3659b2ee5ede17534c8fc2ec85c815e8df1fe7048d12c90ee31b88a68a081f17f0d8ce5f4030521e9400083bcea73a429031d4ca7949c2000d597088e0c39a6014d8bf962b73bb2e8083bd0390a4e00b9b3":16:"eeaf0ab9adb38dd69c33f80afa8fc5e86072618775ff3c0b9ea2314c9c256576d674df7496ea81d3383b4813d692c6e0e0d5d8e250b98be48e495c1d6089dad15dc7d7b46154d6b6ce8ef4ad69b15d4982559b297bcf1885c529f566660e57ec68edbc3c05726cc02fd4cbf4976eaa9afd5138fe8376435b9fc61d2fc0eb06e3":16:"":16:"21acc7199e1b90f9b4844ffe12c19f00ec548c5d32b21c647d48b6015d8eb9ec9db05b4f3d44db4227a2b5659c1a7cceb9d5fa8fa60376047953ce7397d90aaeb7465e14e820734f84aa52ad0fc66701bcbb991d57715806a11531268e1e83dd48288c72b424a6287e9ce4e5cc4db0dd67614aecc23b0124a5776d36e5c89483":0 From 1c6339f966b327c6994a86c553d73024586e413d Mon Sep 17 00:00:00 2001 From: Hanno Becker Date: Thu, 11 May 2017 15:59:11 +0100 Subject: [PATCH 2/3] Abort modular inversion when modulus is one. The modular inversion function hangs when provided with the modulus 1. This commit refuses this modulus with a BAD_INPUT error code. It also adds a test for this case. --- include/polarssl/bignum.h | 2 ++ library/bignum.c | 2 +- tests/suites/test_suite_mpi.data | 3 +++ 3 files changed, 6 insertions(+), 1 deletion(-) diff --git a/include/polarssl/bignum.h b/include/polarssl/bignum.h index 2db29d5ae..dc54af8cd 100644 --- a/include/polarssl/bignum.h +++ b/include/polarssl/bignum.h @@ -691,6 +691,8 @@ int mpi_fill_random( mpi *X, size_t size, * * \return 0 if successful, * POLARSSL_ERR_MPI_MALLOC_FAILED if memory allocation failed + * POLARSSL_ERR_MPI_BAD_INPUT_DATA if N is <= 1, + * POLARSSL_ERR_MPI_NOT_ACCEPTABLE if A has no inverse mod N. */ int mpi_gcd( mpi *G, const mpi *A, const mpi *B ); diff --git a/library/bignum.c b/library/bignum.c index 211cb2af5..9d12a86cc 100644 --- a/library/bignum.c +++ b/library/bignum.c @@ -1891,7 +1891,7 @@ int mpi_inv_mod( mpi *X, const mpi *A, const mpi *N ) int ret; mpi G, TA, TU, U1, U2, TB, TV, V1, V2; - if( mpi_cmp_int( N, 0 ) <= 0 ) + if( mpi_cmp_int( N, 1 ) <= 0 ) return( POLARSSL_ERR_MPI_BAD_INPUT_DATA ); mpi_init( &TA ); mpi_init( &TU ); mpi_init( &U1 ); mpi_init( &U2 ); diff --git a/tests/suites/test_suite_mpi.data b/tests/suites/test_suite_mpi.data index cff62b4d9..52cbd7e6a 100644 --- a/tests/suites/test_suite_mpi.data +++ b/tests/suites/test_suite_mpi.data @@ -550,6 +550,9 @@ mpi_inv_mod:10:"3":10:"-11":10:"4":POLARSSL_ERR_MPI_BAD_INPUT_DATA Base test mpi_inv_mod #4 mpi_inv_mod:10:"2":10:"4":10:"0":POLARSSL_ERR_MPI_NOT_ACCEPTABLE +Base test mbedtls_mpi_inv_mod #5 +mpi_inv_mod:10:"3":10:"1":10:"0":POLARSSL_ERR_MPI_BAD_INPUT_DATA + Test mpi_inv_mod #1 mpi_inv_mod:16:"aa4df5cb14b4c31237f98bd1faf527c283c2d0f3eec89718664ba33f9762907c":16:"fffbbd660b94412ae61ead9c2906a344116e316a256fd387874c6c675b1d587d":16:"8d6a5c1d7adeae3e94b9bcd2c47e0d46e778bc8804a2cc25c02d775dc3d05b0c":0 From a07a58357db64e94615cb6efbd618b6d20540bc9 Mon Sep 17 00:00:00 2001 From: Hanno Becker Date: Thu, 11 May 2017 15:59:52 +0100 Subject: [PATCH 3/3] Adapt ChangeLog --- ChangeLog | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/ChangeLog b/ChangeLog index b46c72879..38e85823f 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,5 +1,13 @@ mbed TLS ChangeLog (Sorted per branch, date) += mbed TLS x.x.x branch released xxxx-xx-xx + +Bugfix + * Fix modular inversion function on invalid modulus 1. + Found by blaufish. Fixes #641. + * Fix incorrect sign computation in modular exponentiation + when dealing with negative MPI. Found by Guido Vranken. + = mbed TLS 1.3.19 branch released 2017-03-08 Security