ec_curve.c 89 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154
  1. /* crypto/ec/ec_curve.c */
  2. /*
  3. * Written by Nils Larsch for the OpenSSL project.
  4. */
  5. /* ====================================================================
  6. * Copyright (c) 1998-2010 The OpenSSL Project. All rights reserved.
  7. *
  8. * Redistribution and use in source and binary forms, with or without
  9. * modification, are permitted provided that the following conditions
  10. * are met:
  11. *
  12. * 1. Redistributions of source code must retain the above copyright
  13. * notice, this list of conditions and the following disclaimer.
  14. *
  15. * 2. Redistributions in binary form must reproduce the above copyright
  16. * notice, this list of conditions and the following disclaimer in
  17. * the documentation and/or other materials provided with the
  18. * distribution.
  19. *
  20. * 3. All advertising materials mentioning features or use of this
  21. * software must display the following acknowledgment:
  22. * "This product includes software developed by the OpenSSL Project
  23. * for use in the OpenSSL Toolkit. (http://www.openssl.org/)"
  24. *
  25. * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
  26. * endorse or promote products derived from this software without
  27. * prior written permission. For written permission, please contact
  28. * openssl-core@openssl.org.
  29. *
  30. * 5. Products derived from this software may not be called "OpenSSL"
  31. * nor may "OpenSSL" appear in their names without prior written
  32. * permission of the OpenSSL Project.
  33. *
  34. * 6. Redistributions of any form whatsoever must retain the following
  35. * acknowledgment:
  36. * "This product includes software developed by the OpenSSL Project
  37. * for use in the OpenSSL Toolkit (http://www.openssl.org/)"
  38. *
  39. * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
  40. * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
  41. * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
  42. * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
  43. * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  44. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  45. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  46. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
  47. * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  48. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  49. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
  50. * OF THE POSSIBILITY OF SUCH DAMAGE.
  51. * ====================================================================
  52. *
  53. * This product includes cryptographic software written by Eric Young
  54. * (eay@cryptsoft.com). This product includes software written by Tim
  55. * Hudson (tjh@cryptsoft.com).
  56. *
  57. */
  58. /* ====================================================================
  59. * Copyright 2002 Sun Microsystems, Inc. ALL RIGHTS RESERVED.
  60. *
  61. * Portions of the attached software ("Contribution") are developed by
  62. * SUN MICROSYSTEMS, INC., and are contributed to the OpenSSL project.
  63. *
  64. * The Contribution is licensed pursuant to the OpenSSL open source
  65. * license provided above.
  66. *
  67. * The elliptic curve binary polynomial software is originally written by
  68. * Sheueling Chang Shantz and Douglas Stebila of Sun Microsystems Laboratories.
  69. *
  70. */
  71. #define OPENSSL_FIPSAPI
  72. #include "ec_lcl.h"
  73. #include <openssl/err.h>
  74. #include <openssl/obj_mac.h>
  75. typedef struct {
  76. int field_type, /* either NID_X9_62_prime_field or
  77. * NID_X9_62_characteristic_two_field */
  78. seed_len,
  79. param_len;
  80. unsigned int cofactor; /* promoted to BN_ULONG */
  81. } EC_CURVE_DATA;
  82. /* the nist prime curves */
  83. __fips_constseg
  84. static const struct { EC_CURVE_DATA h; unsigned char data[20+24*6]; }
  85. _EC_NIST_PRIME_192 = {
  86. { NID_X9_62_prime_field,20,24,1 },
  87. { 0x30,0x45,0xAE,0x6F,0xC8,0x42,0x2F,0x64,0xED,0x57, /* seed */
  88. 0x95,0x28,0xD3,0x81,0x20,0xEA,0xE1,0x21,0x96,0xD5,
  89. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  90. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xFF,0xFF,
  91. 0xFF,0xFF,0xFF,0xFF,
  92. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  93. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xFF,0xFF,
  94. 0xFF,0xFF,0xFF,0xFC,
  95. 0x64,0x21,0x05,0x19,0xE5,0x9C,0x80,0xE7,0x0F,0xA7, /* b */
  96. 0xE9,0xAB,0x72,0x24,0x30,0x49,0xFE,0xB8,0xDE,0xEC,
  97. 0xC1,0x46,0xB9,0xB1,
  98. 0x18,0x8D,0xA8,0x0E,0xB0,0x30,0x90,0xF6,0x7C,0xBF, /* x */
  99. 0x20,0xEB,0x43,0xA1,0x88,0x00,0xF4,0xFF,0x0A,0xFD,
  100. 0x82,0xFF,0x10,0x12,
  101. 0x07,0x19,0x2b,0x95,0xff,0xc8,0xda,0x78,0x63,0x10, /* y */
  102. 0x11,0xed,0x6b,0x24,0xcd,0xd5,0x73,0xf9,0x77,0xa1,
  103. 0x1e,0x79,0x48,0x11,
  104. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  105. 0xFF,0xFF,0x99,0xDE,0xF8,0x36,0x14,0x6B,0xC9,0xB1,
  106. 0xB4,0xD2,0x28,0x31 }
  107. };
  108. __fips_constseg
  109. static const struct { EC_CURVE_DATA h; unsigned char data[20+28*6]; }
  110. _EC_NIST_PRIME_224 = {
  111. { NID_X9_62_prime_field,20,28,1 },
  112. { 0xBD,0x71,0x34,0x47,0x99,0xD5,0xC7,0xFC,0xDC,0x45, /* seed */
  113. 0xB5,0x9F,0xA3,0xB9,0xAB,0x8F,0x6A,0x94,0x8B,0xC5,
  114. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  115. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0x00,0x00,0x00,0x00,
  116. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  117. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  118. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xFF,0xFF,
  119. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,
  120. 0xB4,0x05,0x0A,0x85,0x0C,0x04,0xB3,0xAB,0xF5,0x41, /* b */
  121. 0x32,0x56,0x50,0x44,0xB0,0xB7,0xD7,0xBF,0xD8,0xBA,
  122. 0x27,0x0B,0x39,0x43,0x23,0x55,0xFF,0xB4,
  123. 0xB7,0x0E,0x0C,0xBD,0x6B,0xB4,0xBF,0x7F,0x32,0x13, /* x */
  124. 0x90,0xB9,0x4A,0x03,0xC1,0xD3,0x56,0xC2,0x11,0x22,
  125. 0x34,0x32,0x80,0xD6,0x11,0x5C,0x1D,0x21,
  126. 0xbd,0x37,0x63,0x88,0xb5,0xf7,0x23,0xfb,0x4c,0x22, /* y */
  127. 0xdf,0xe6,0xcd,0x43,0x75,0xa0,0x5a,0x07,0x47,0x64,
  128. 0x44,0xd5,0x81,0x99,0x85,0x00,0x7e,0x34,
  129. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  130. 0xFF,0xFF,0xFF,0xFF,0x16,0xA2,0xE0,0xB8,0xF0,0x3E,
  131. 0x13,0xDD,0x29,0x45,0x5C,0x5C,0x2A,0x3D }
  132. };
  133. __fips_constseg
  134. static const struct { EC_CURVE_DATA h; unsigned char data[20+48*6]; }
  135. _EC_NIST_PRIME_384 = {
  136. { NID_X9_62_prime_field,20,48,1 },
  137. { 0xA3,0x35,0x92,0x6A,0xA3,0x19,0xA2,0x7A,0x1D,0x00, /* seed */
  138. 0x89,0x6A,0x67,0x73,0xA4,0x82,0x7A,0xCD,0xAC,0x73,
  139. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  140. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  141. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  142. 0xFF,0xFE,0xFF,0xFF,0xFF,0xFF,0x00,0x00,0x00,0x00,
  143. 0x00,0x00,0x00,0x00,0xFF,0xFF,0xFF,0xFF,
  144. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  145. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  146. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  147. 0xFF,0xFE,0xFF,0xFF,0xFF,0xFF,0x00,0x00,0x00,0x00,
  148. 0x00,0x00,0x00,0x00,0xFF,0xFF,0xFF,0xFC,
  149. 0xB3,0x31,0x2F,0xA7,0xE2,0x3E,0xE7,0xE4,0x98,0x8E, /* b */
  150. 0x05,0x6B,0xE3,0xF8,0x2D,0x19,0x18,0x1D,0x9C,0x6E,
  151. 0xFE,0x81,0x41,0x12,0x03,0x14,0x08,0x8F,0x50,0x13,
  152. 0x87,0x5A,0xC6,0x56,0x39,0x8D,0x8A,0x2E,0xD1,0x9D,
  153. 0x2A,0x85,0xC8,0xED,0xD3,0xEC,0x2A,0xEF,
  154. 0xAA,0x87,0xCA,0x22,0xBE,0x8B,0x05,0x37,0x8E,0xB1, /* x */
  155. 0xC7,0x1E,0xF3,0x20,0xAD,0x74,0x6E,0x1D,0x3B,0x62,
  156. 0x8B,0xA7,0x9B,0x98,0x59,0xF7,0x41,0xE0,0x82,0x54,
  157. 0x2A,0x38,0x55,0x02,0xF2,0x5D,0xBF,0x55,0x29,0x6C,
  158. 0x3A,0x54,0x5E,0x38,0x72,0x76,0x0A,0xB7,
  159. 0x36,0x17,0xde,0x4a,0x96,0x26,0x2c,0x6f,0x5d,0x9e, /* y */
  160. 0x98,0xbf,0x92,0x92,0xdc,0x29,0xf8,0xf4,0x1d,0xbd,
  161. 0x28,0x9a,0x14,0x7c,0xe9,0xda,0x31,0x13,0xb5,0xf0,
  162. 0xb8,0xc0,0x0a,0x60,0xb1,0xce,0x1d,0x7e,0x81,0x9d,
  163. 0x7a,0x43,0x1d,0x7c,0x90,0xea,0x0e,0x5f,
  164. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  165. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  166. 0xFF,0xFF,0xFF,0xFF,0xC7,0x63,0x4D,0x81,0xF4,0x37,
  167. 0x2D,0xDF,0x58,0x1A,0x0D,0xB2,0x48,0xB0,0xA7,0x7A,
  168. 0xEC,0xEC,0x19,0x6A,0xCC,0xC5,0x29,0x73 }
  169. };
  170. __fips_constseg
  171. static const struct { EC_CURVE_DATA h; unsigned char data[20+66*6]; }
  172. _EC_NIST_PRIME_521 = {
  173. { NID_X9_62_prime_field,20,66,1 },
  174. { 0xD0,0x9E,0x88,0x00,0x29,0x1C,0xB8,0x53,0x96,0xCC, /* seed */
  175. 0x67,0x17,0x39,0x32,0x84,0xAA,0xA0,0xDA,0x64,0xBA,
  176. 0x01,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  177. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  178. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  179. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  180. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  181. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  182. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  183. 0x01,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  184. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  185. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  186. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  187. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  188. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  189. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFC,
  190. 0x00,0x51,0x95,0x3E,0xB9,0x61,0x8E,0x1C,0x9A,0x1F, /* b */
  191. 0x92,0x9A,0x21,0xA0,0xB6,0x85,0x40,0xEE,0xA2,0xDA,
  192. 0x72,0x5B,0x99,0xB3,0x15,0xF3,0xB8,0xB4,0x89,0x91,
  193. 0x8E,0xF1,0x09,0xE1,0x56,0x19,0x39,0x51,0xEC,0x7E,
  194. 0x93,0x7B,0x16,0x52,0xC0,0xBD,0x3B,0xB1,0xBF,0x07,
  195. 0x35,0x73,0xDF,0x88,0x3D,0x2C,0x34,0xF1,0xEF,0x45,
  196. 0x1F,0xD4,0x6B,0x50,0x3F,0x00,
  197. 0x00,0xC6,0x85,0x8E,0x06,0xB7,0x04,0x04,0xE9,0xCD, /* x */
  198. 0x9E,0x3E,0xCB,0x66,0x23,0x95,0xB4,0x42,0x9C,0x64,
  199. 0x81,0x39,0x05,0x3F,0xB5,0x21,0xF8,0x28,0xAF,0x60,
  200. 0x6B,0x4D,0x3D,0xBA,0xA1,0x4B,0x5E,0x77,0xEF,0xE7,
  201. 0x59,0x28,0xFE,0x1D,0xC1,0x27,0xA2,0xFF,0xA8,0xDE,
  202. 0x33,0x48,0xB3,0xC1,0x85,0x6A,0x42,0x9B,0xF9,0x7E,
  203. 0x7E,0x31,0xC2,0xE5,0xBD,0x66,
  204. 0x01,0x18,0x39,0x29,0x6a,0x78,0x9a,0x3b,0xc0,0x04, /* y */
  205. 0x5c,0x8a,0x5f,0xb4,0x2c,0x7d,0x1b,0xd9,0x98,0xf5,
  206. 0x44,0x49,0x57,0x9b,0x44,0x68,0x17,0xaf,0xbd,0x17,
  207. 0x27,0x3e,0x66,0x2c,0x97,0xee,0x72,0x99,0x5e,0xf4,
  208. 0x26,0x40,0xc5,0x50,0xb9,0x01,0x3f,0xad,0x07,0x61,
  209. 0x35,0x3c,0x70,0x86,0xa2,0x72,0xc2,0x40,0x88,0xbe,
  210. 0x94,0x76,0x9f,0xd1,0x66,0x50,
  211. 0x01,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  212. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  213. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  214. 0xFF,0xFF,0xFF,0xFA,0x51,0x86,0x87,0x83,0xBF,0x2F,
  215. 0x96,0x6B,0x7F,0xCC,0x01,0x48,0xF7,0x09,0xA5,0xD0,
  216. 0x3B,0xB5,0xC9,0xB8,0x89,0x9C,0x47,0xAE,0xBB,0x6F,
  217. 0xB7,0x1E,0x91,0x38,0x64,0x09 }
  218. };
  219. /* the x9.62 prime curves (minus the nist prime curves) */
  220. __fips_constseg
  221. static const struct { EC_CURVE_DATA h; unsigned char data[20+24*6]; }
  222. _EC_X9_62_PRIME_192V2 = {
  223. { NID_X9_62_prime_field,20,24,1 },
  224. { 0x31,0xA9,0x2E,0xE2,0x02,0x9F,0xD1,0x0D,0x90,0x1B, /* seed */
  225. 0x11,0x3E,0x99,0x07,0x10,0xF0,0xD2,0x1A,0xC6,0xB6,
  226. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  227. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xFF,0xFF,
  228. 0xFF,0xFF,0xFF,0xFF,
  229. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  230. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xFF,0xFF,
  231. 0xFF,0xFF,0xFF,0xFC,
  232. 0xCC,0x22,0xD6,0xDF,0xB9,0x5C,0x6B,0x25,0xE4,0x9C, /* b */
  233. 0x0D,0x63,0x64,0xA4,0xE5,0x98,0x0C,0x39,0x3A,0xA2,
  234. 0x16,0x68,0xD9,0x53,
  235. 0xEE,0xA2,0xBA,0xE7,0xE1,0x49,0x78,0x42,0xF2,0xDE, /* x */
  236. 0x77,0x69,0xCF,0xE9,0xC9,0x89,0xC0,0x72,0xAD,0x69,
  237. 0x6F,0x48,0x03,0x4A,
  238. 0x65,0x74,0xd1,0x1d,0x69,0xb6,0xec,0x7a,0x67,0x2b, /* y */
  239. 0xb8,0x2a,0x08,0x3d,0xf2,0xf2,0xb0,0x84,0x7d,0xe9,
  240. 0x70,0xb2,0xde,0x15,
  241. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  242. 0xFF,0xFE,0x5F,0xB1,0xA7,0x24,0xDC,0x80,0x41,0x86,
  243. 0x48,0xD8,0xDD,0x31 }
  244. };
  245. __fips_constseg
  246. static const struct { EC_CURVE_DATA h; unsigned char data[20+24*6]; }
  247. _EC_X9_62_PRIME_192V3 = {
  248. { NID_X9_62_prime_field,20,24,1 },
  249. { 0xC4,0x69,0x68,0x44,0x35,0xDE,0xB3,0x78,0xC4,0xB6, /* seed */
  250. 0x5C,0xA9,0x59,0x1E,0x2A,0x57,0x63,0x05,0x9A,0x2E,
  251. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  252. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xFF,0xFF,
  253. 0xFF,0xFF,0xFF,0xFF,
  254. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  255. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xFF,0xFF,
  256. 0xFF,0xFF,0xFF,0xFC,
  257. 0x22,0x12,0x3D,0xC2,0x39,0x5A,0x05,0xCA,0xA7,0x42, /* b */
  258. 0x3D,0xAE,0xCC,0xC9,0x47,0x60,0xA7,0xD4,0x62,0x25,
  259. 0x6B,0xD5,0x69,0x16,
  260. 0x7D,0x29,0x77,0x81,0x00,0xC6,0x5A,0x1D,0xA1,0x78, /* x */
  261. 0x37,0x16,0x58,0x8D,0xCE,0x2B,0x8B,0x4A,0xEE,0x8E,
  262. 0x22,0x8F,0x18,0x96,
  263. 0x38,0xa9,0x0f,0x22,0x63,0x73,0x37,0x33,0x4b,0x49, /* y */
  264. 0xdc,0xb6,0x6a,0x6d,0xc8,0xf9,0x97,0x8a,0xca,0x76,
  265. 0x48,0xa9,0x43,0xb0,
  266. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  267. 0xFF,0xFF,0x7A,0x62,0xD0,0x31,0xC8,0x3F,0x42,0x94,
  268. 0xF6,0x40,0xEC,0x13 }
  269. };
  270. __fips_constseg
  271. static const struct { EC_CURVE_DATA h; unsigned char data[20+30*6]; }
  272. _EC_X9_62_PRIME_239V1 = {
  273. { NID_X9_62_prime_field,20,30,1 },
  274. { 0xE4,0x3B,0xB4,0x60,0xF0,0xB8,0x0C,0xC0,0xC0,0xB0, /* seed */
  275. 0x75,0x79,0x8E,0x94,0x80,0x60,0xF8,0x32,0x1B,0x7D,
  276. 0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  277. 0xFF,0xFF,0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0x80,0x00,
  278. 0x00,0x00,0x00,0x00,0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,
  279. 0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  280. 0xFF,0xFF,0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0x80,0x00,
  281. 0x00,0x00,0x00,0x00,0x7F,0xFF,0xFF,0xFF,0xFF,0xFC,
  282. 0x6B,0x01,0x6C,0x3B,0xDC,0xF1,0x89,0x41,0xD0,0xD6, /* b */
  283. 0x54,0x92,0x14,0x75,0xCA,0x71,0xA9,0xDB,0x2F,0xB2,
  284. 0x7D,0x1D,0x37,0x79,0x61,0x85,0xC2,0x94,0x2C,0x0A,
  285. 0x0F,0xFA,0x96,0x3C,0xDC,0xA8,0x81,0x6C,0xCC,0x33, /* x */
  286. 0xB8,0x64,0x2B,0xED,0xF9,0x05,0xC3,0xD3,0x58,0x57,
  287. 0x3D,0x3F,0x27,0xFB,0xBD,0x3B,0x3C,0xB9,0xAA,0xAF,
  288. 0x7d,0xeb,0xe8,0xe4,0xe9,0x0a,0x5d,0xae,0x6e,0x40, /* y */
  289. 0x54,0xca,0x53,0x0b,0xa0,0x46,0x54,0xb3,0x68,0x18,
  290. 0xce,0x22,0x6b,0x39,0xfc,0xcb,0x7b,0x02,0xf1,0xae,
  291. 0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  292. 0xFF,0xFF,0x7F,0xFF,0xFF,0x9E,0x5E,0x9A,0x9F,0x5D,
  293. 0x90,0x71,0xFB,0xD1,0x52,0x26,0x88,0x90,0x9D,0x0B }
  294. };
  295. __fips_constseg
  296. static const struct { EC_CURVE_DATA h; unsigned char data[20+30*6]; }
  297. _EC_X9_62_PRIME_239V2 = {
  298. { NID_X9_62_prime_field,20,30,1 },
  299. { 0xE8,0xB4,0x01,0x16,0x04,0x09,0x53,0x03,0xCA,0x3B, /* seed */
  300. 0x80,0x99,0x98,0x2B,0xE0,0x9F,0xCB,0x9A,0xE6,0x16,
  301. 0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  302. 0xFF,0xFF,0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0x80,0x00,
  303. 0x00,0x00,0x00,0x00,0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,
  304. 0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  305. 0xFF,0xFF,0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0x80,0x00,
  306. 0x00,0x00,0x00,0x00,0x7F,0xFF,0xFF,0xFF,0xFF,0xFC,
  307. 0x61,0x7F,0xAB,0x68,0x32,0x57,0x6C,0xBB,0xFE,0xD5, /* b */
  308. 0x0D,0x99,0xF0,0x24,0x9C,0x3F,0xEE,0x58,0xB9,0x4B,
  309. 0xA0,0x03,0x8C,0x7A,0xE8,0x4C,0x8C,0x83,0x2F,0x2C,
  310. 0x38,0xAF,0x09,0xD9,0x87,0x27,0x70,0x51,0x20,0xC9, /* x */
  311. 0x21,0xBB,0x5E,0x9E,0x26,0x29,0x6A,0x3C,0xDC,0xF2,
  312. 0xF3,0x57,0x57,0xA0,0xEA,0xFD,0x87,0xB8,0x30,0xE7,
  313. 0x5b,0x01,0x25,0xe4,0xdb,0xea,0x0e,0xc7,0x20,0x6d, /* y */
  314. 0xa0,0xfc,0x01,0xd9,0xb0,0x81,0x32,0x9f,0xb5,0x55,
  315. 0xde,0x6e,0xf4,0x60,0x23,0x7d,0xff,0x8b,0xe4,0xba,
  316. 0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  317. 0xFF,0xFF,0x80,0x00,0x00,0xCF,0xA7,0xE8,0x59,0x43,
  318. 0x77,0xD4,0x14,0xC0,0x38,0x21,0xBC,0x58,0x20,0x63 }
  319. };
  320. __fips_constseg
  321. static const struct { EC_CURVE_DATA h; unsigned char data[20+30*6]; }
  322. _EC_X9_62_PRIME_239V3 = {
  323. { NID_X9_62_prime_field,20,30,1 },
  324. { 0x7D,0x73,0x74,0x16,0x8F,0xFE,0x34,0x71,0xB6,0x0A, /* seed */
  325. 0x85,0x76,0x86,0xA1,0x94,0x75,0xD3,0xBF,0xA2,0xFF,
  326. 0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  327. 0xFF,0xFF,0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0x80,0x00,
  328. 0x00,0x00,0x00,0x00,0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,
  329. 0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  330. 0xFF,0xFF,0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0x80,0x00,
  331. 0x00,0x00,0x00,0x00,0x7F,0xFF,0xFF,0xFF,0xFF,0xFC,
  332. 0x25,0x57,0x05,0xFA,0x2A,0x30,0x66,0x54,0xB1,0xF4, /* b */
  333. 0xCB,0x03,0xD6,0xA7,0x50,0xA3,0x0C,0x25,0x01,0x02,
  334. 0xD4,0x98,0x87,0x17,0xD9,0xBA,0x15,0xAB,0x6D,0x3E,
  335. 0x67,0x68,0xAE,0x8E,0x18,0xBB,0x92,0xCF,0xCF,0x00, /* x */
  336. 0x5C,0x94,0x9A,0xA2,0xC6,0xD9,0x48,0x53,0xD0,0xE6,
  337. 0x60,0xBB,0xF8,0x54,0xB1,0xC9,0x50,0x5F,0xE9,0x5A,
  338. 0x16,0x07,0xe6,0x89,0x8f,0x39,0x0c,0x06,0xbc,0x1d, /* y */
  339. 0x55,0x2b,0xad,0x22,0x6f,0x3b,0x6f,0xcf,0xe4,0x8b,
  340. 0x6e,0x81,0x84,0x99,0xaf,0x18,0xe3,0xed,0x6c,0xf3,
  341. 0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  342. 0xFF,0xFF,0x7F,0xFF,0xFF,0x97,0x5D,0xEB,0x41,0xB3,
  343. 0xA6,0x05,0x7C,0x3C,0x43,0x21,0x46,0x52,0x65,0x51 }
  344. };
  345. __fips_constseg
  346. static const struct { EC_CURVE_DATA h; unsigned char data[20+32*6]; }
  347. _EC_X9_62_PRIME_256V1 = {
  348. { NID_X9_62_prime_field,20,32,1 },
  349. { 0xC4,0x9D,0x36,0x08,0x86,0xE7,0x04,0x93,0x6A,0x66, /* seed */
  350. 0x78,0xE1,0x13,0x9D,0x26,0xB7,0x81,0x9F,0x7E,0x90,
  351. 0xFF,0xFF,0xFF,0xFF,0x00,0x00,0x00,0x01,0x00,0x00, /* p */
  352. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  353. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  354. 0xFF,0xFF,
  355. 0xFF,0xFF,0xFF,0xFF,0x00,0x00,0x00,0x01,0x00,0x00, /* a */
  356. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  357. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  358. 0xFF,0xFC,
  359. 0x5A,0xC6,0x35,0xD8,0xAA,0x3A,0x93,0xE7,0xB3,0xEB, /* b */
  360. 0xBD,0x55,0x76,0x98,0x86,0xBC,0x65,0x1D,0x06,0xB0,
  361. 0xCC,0x53,0xB0,0xF6,0x3B,0xCE,0x3C,0x3E,0x27,0xD2,
  362. 0x60,0x4B,
  363. 0x6B,0x17,0xD1,0xF2,0xE1,0x2C,0x42,0x47,0xF8,0xBC, /* x */
  364. 0xE6,0xE5,0x63,0xA4,0x40,0xF2,0x77,0x03,0x7D,0x81,
  365. 0x2D,0xEB,0x33,0xA0,0xF4,0xA1,0x39,0x45,0xD8,0x98,
  366. 0xC2,0x96,
  367. 0x4f,0xe3,0x42,0xe2,0xfe,0x1a,0x7f,0x9b,0x8e,0xe7, /* y */
  368. 0xeb,0x4a,0x7c,0x0f,0x9e,0x16,0x2b,0xce,0x33,0x57,
  369. 0x6b,0x31,0x5e,0xce,0xcb,0xb6,0x40,0x68,0x37,0xbf,
  370. 0x51,0xf5,
  371. 0xFF,0xFF,0xFF,0xFF,0x00,0x00,0x00,0x00,0xFF,0xFF, /* order */
  372. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xBC,0xE6,0xFA,0xAD,
  373. 0xA7,0x17,0x9E,0x84,0xF3,0xB9,0xCA,0xC2,0xFC,0x63,
  374. 0x25,0x51 }
  375. };
  376. /* the secg prime curves (minus the nist and x9.62 prime curves) */
  377. __fips_constseg
  378. static const struct { EC_CURVE_DATA h; unsigned char data[20+14*6]; }
  379. _EC_SECG_PRIME_112R1 = {
  380. { NID_X9_62_prime_field,20,14,1 },
  381. { 0x00,0xF5,0x0B,0x02,0x8E,0x4D,0x69,0x6E,0x67,0x68, /* seed */
  382. 0x75,0x61,0x51,0x75,0x29,0x04,0x72,0x78,0x3F,0xB1,
  383. 0xDB,0x7C,0x2A,0xBF,0x62,0xE3,0x5E,0x66,0x80,0x76, /* p */
  384. 0xBE,0xAD,0x20,0x8B,
  385. 0xDB,0x7C,0x2A,0xBF,0x62,0xE3,0x5E,0x66,0x80,0x76, /* a */
  386. 0xBE,0xAD,0x20,0x88,
  387. 0x65,0x9E,0xF8,0xBA,0x04,0x39,0x16,0xEE,0xDE,0x89, /* b */
  388. 0x11,0x70,0x2B,0x22,
  389. 0x09,0x48,0x72,0x39,0x99,0x5A,0x5E,0xE7,0x6B,0x55, /* x */
  390. 0xF9,0xC2,0xF0,0x98,
  391. 0xa8,0x9c,0xe5,0xaf,0x87,0x24,0xc0,0xa2,0x3e,0x0e, /* y */
  392. 0x0f,0xf7,0x75,0x00,
  393. 0xDB,0x7C,0x2A,0xBF,0x62,0xE3,0x5E,0x76,0x28,0xDF, /* order */
  394. 0xAC,0x65,0x61,0xC5 }
  395. };
  396. __fips_constseg
  397. static const struct { EC_CURVE_DATA h; unsigned char data[20+14*6]; }
  398. _EC_SECG_PRIME_112R2 = {
  399. { NID_X9_62_prime_field,20,14,4 },
  400. { 0x00,0x27,0x57,0xA1,0x11,0x4D,0x69,0x6E,0x67,0x68, /* seed */
  401. 0x75,0x61,0x51,0x75,0x53,0x16,0xC0,0x5E,0x0B,0xD4,
  402. 0xDB,0x7C,0x2A,0xBF,0x62,0xE3,0x5E,0x66,0x80,0x76, /* p */
  403. 0xBE,0xAD,0x20,0x8B,
  404. 0x61,0x27,0xC2,0x4C,0x05,0xF3,0x8A,0x0A,0xAA,0xF6, /* a */
  405. 0x5C,0x0E,0xF0,0x2C,
  406. 0x51,0xDE,0xF1,0x81,0x5D,0xB5,0xED,0x74,0xFC,0xC3, /* b */
  407. 0x4C,0x85,0xD7,0x09,
  408. 0x4B,0xA3,0x0A,0xB5,0xE8,0x92,0xB4,0xE1,0x64,0x9D, /* x */
  409. 0xD0,0x92,0x86,0x43,
  410. 0xad,0xcd,0x46,0xf5,0x88,0x2e,0x37,0x47,0xde,0xf3, /* y */
  411. 0x6e,0x95,0x6e,0x97,
  412. 0x36,0xDF,0x0A,0xAF,0xD8,0xB8,0xD7,0x59,0x7C,0xA1, /* order */
  413. 0x05,0x20,0xD0,0x4B }
  414. };
  415. __fips_constseg
  416. static const struct { EC_CURVE_DATA h; unsigned char data[20+16*6]; }
  417. _EC_SECG_PRIME_128R1 = {
  418. { NID_X9_62_prime_field,20,16,1 },
  419. { 0x00,0x0E,0x0D,0x4D,0x69,0x6E,0x67,0x68,0x75,0x61, /* seed */
  420. 0x51,0x75,0x0C,0xC0,0x3A,0x44,0x73,0xD0,0x36,0x79,
  421. 0xFF,0xFF,0xFF,0xFD,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  422. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  423. 0xFF,0xFF,0xFF,0xFD,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  424. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFC,
  425. 0xE8,0x75,0x79,0xC1,0x10,0x79,0xF4,0x3D,0xD8,0x24, /* b */
  426. 0x99,0x3C,0x2C,0xEE,0x5E,0xD3,
  427. 0x16,0x1F,0xF7,0x52,0x8B,0x89,0x9B,0x2D,0x0C,0x28, /* x */
  428. 0x60,0x7C,0xA5,0x2C,0x5B,0x86,
  429. 0xcf,0x5a,0xc8,0x39,0x5b,0xaf,0xeb,0x13,0xc0,0x2d, /* y */
  430. 0xa2,0x92,0xdd,0xed,0x7a,0x83,
  431. 0xFF,0xFF,0xFF,0xFE,0x00,0x00,0x00,0x00,0x75,0xA3, /* order */
  432. 0x0D,0x1B,0x90,0x38,0xA1,0x15 }
  433. };
  434. __fips_constseg
  435. static const struct { EC_CURVE_DATA h; unsigned char data[20+16*6]; }
  436. _EC_SECG_PRIME_128R2 = {
  437. { NID_X9_62_prime_field,20,16,4 },
  438. { 0x00,0x4D,0x69,0x6E,0x67,0x68,0x75,0x61,0x51,0x75, /* seed */
  439. 0x12,0xD8,0xF0,0x34,0x31,0xFC,0xE6,0x3B,0x88,0xF4,
  440. 0xFF,0xFF,0xFF,0xFD,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  441. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  442. 0xD6,0x03,0x19,0x98,0xD1,0xB3,0xBB,0xFE,0xBF,0x59, /* a */
  443. 0xCC,0x9B,0xBF,0xF9,0xAE,0xE1,
  444. 0x5E,0xEE,0xFC,0xA3,0x80,0xD0,0x29,0x19,0xDC,0x2C, /* b */
  445. 0x65,0x58,0xBB,0x6D,0x8A,0x5D,
  446. 0x7B,0x6A,0xA5,0xD8,0x5E,0x57,0x29,0x83,0xE6,0xFB, /* x */
  447. 0x32,0xA7,0xCD,0xEB,0xC1,0x40,
  448. 0x27,0xb6,0x91,0x6a,0x89,0x4d,0x3a,0xee,0x71,0x06, /* y */
  449. 0xfe,0x80,0x5f,0xc3,0x4b,0x44,
  450. 0x3F,0xFF,0xFF,0xFF,0x7F,0xFF,0xFF,0xFF,0xBE,0x00, /* order */
  451. 0x24,0x72,0x06,0x13,0xB5,0xA3 }
  452. };
  453. __fips_constseg
  454. static const struct { EC_CURVE_DATA h; unsigned char data[0+21*6]; }
  455. _EC_SECG_PRIME_160K1 = {
  456. { NID_X9_62_prime_field,0,21,1 },
  457. { /* no seed */
  458. 0x00,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  459. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xAC,
  460. 0x73,
  461. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  462. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  463. 0x00,
  464. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  465. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  466. 0x07,
  467. 0x00,0x3B,0x4C,0x38,0x2C,0xE3,0x7A,0xA1,0x92,0xA4, /* x */
  468. 0x01,0x9E,0x76,0x30,0x36,0xF4,0xF5,0xDD,0x4D,0x7E,
  469. 0xBB,
  470. 0x00,0x93,0x8c,0xf9,0x35,0x31,0x8f,0xdc,0xed,0x6b, /* y */
  471. 0xc2,0x82,0x86,0x53,0x17,0x33,0xc3,0xf0,0x3c,0x4f,
  472. 0xee,
  473. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  474. 0x01,0xB8,0xFA,0x16,0xDF,0xAB,0x9A,0xCA,0x16,0xB6,
  475. 0xB3 }
  476. };
  477. __fips_constseg
  478. static const struct { EC_CURVE_DATA h; unsigned char data[20+21*6]; }
  479. _EC_SECG_PRIME_160R1 = {
  480. { NID_X9_62_prime_field,20,21,1 },
  481. { 0x10,0x53,0xCD,0xE4,0x2C,0x14,0xD6,0x96,0xE6,0x76, /* seed */
  482. 0x87,0x56,0x15,0x17,0x53,0x3B,0xF3,0xF8,0x33,0x45,
  483. 0x00,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  484. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0x7F,0xFF,0xFF,
  485. 0xFF,
  486. 0x00,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  487. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0x7F,0xFF,0xFF,
  488. 0xFC,
  489. 0x00,0x1C,0x97,0xBE,0xFC,0x54,0xBD,0x7A,0x8B,0x65, /* b */
  490. 0xAC,0xF8,0x9F,0x81,0xD4,0xD4,0xAD,0xC5,0x65,0xFA,
  491. 0x45,
  492. 0x00,0x4A,0x96,0xB5,0x68,0x8E,0xF5,0x73,0x28,0x46, /* x */
  493. 0x64,0x69,0x89,0x68,0xC3,0x8B,0xB9,0x13,0xCB,0xFC,
  494. 0x82,
  495. 0x00,0x23,0xa6,0x28,0x55,0x31,0x68,0x94,0x7d,0x59, /* y */
  496. 0xdc,0xc9,0x12,0x04,0x23,0x51,0x37,0x7a,0xc5,0xfb,
  497. 0x32,
  498. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  499. 0x01,0xF4,0xC8,0xF9,0x27,0xAE,0xD3,0xCA,0x75,0x22,
  500. 0x57 }
  501. };
  502. __fips_constseg
  503. static const struct { EC_CURVE_DATA h; unsigned char data[20+21*6]; }
  504. _EC_SECG_PRIME_160R2 = {
  505. { NID_X9_62_prime_field,20,21,1 },
  506. { 0xB9,0x9B,0x99,0xB0,0x99,0xB3,0x23,0xE0,0x27,0x09, /* seed */
  507. 0xA4,0xD6,0x96,0xE6,0x76,0x87,0x56,0x15,0x17,0x51,
  508. 0x00,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  509. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xAC,
  510. 0x73,
  511. 0x00,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  512. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xAC,
  513. 0x70,
  514. 0x00,0xB4,0xE1,0x34,0xD3,0xFB,0x59,0xEB,0x8B,0xAB, /* b */
  515. 0x57,0x27,0x49,0x04,0x66,0x4D,0x5A,0xF5,0x03,0x88,
  516. 0xBA,
  517. 0x00,0x52,0xDC,0xB0,0x34,0x29,0x3A,0x11,0x7E,0x1F, /* x */
  518. 0x4F,0xF1,0x1B,0x30,0xF7,0x19,0x9D,0x31,0x44,0xCE,
  519. 0x6D,
  520. 0x00,0xfe,0xaf,0xfe,0xf2,0xe3,0x31,0xf2,0x96,0xe0, /* y */
  521. 0x71,0xfa,0x0d,0xf9,0x98,0x2c,0xfe,0xa7,0xd4,0x3f,
  522. 0x2e,
  523. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  524. 0x00,0x35,0x1E,0xE7,0x86,0xA8,0x18,0xF3,0xA1,0xA1,
  525. 0x6B }
  526. };
  527. __fips_constseg
  528. static const struct { EC_CURVE_DATA h; unsigned char data[0+24*6]; }
  529. _EC_SECG_PRIME_192K1 = {
  530. { NID_X9_62_prime_field,0,24,1 },
  531. { /* no seed */
  532. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  533. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,
  534. 0xFF,0xFF,0xEE,0x37,
  535. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  536. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  537. 0x00,0x00,0x00,0x00,
  538. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  539. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  540. 0x00,0x00,0x00,0x03,
  541. 0xDB,0x4F,0xF1,0x0E,0xC0,0x57,0xE9,0xAE,0x26,0xB0, /* x */
  542. 0x7D,0x02,0x80,0xB7,0xF4,0x34,0x1D,0xA5,0xD1,0xB1,
  543. 0xEA,0xE0,0x6C,0x7D,
  544. 0x9b,0x2f,0x2f,0x6d,0x9c,0x56,0x28,0xa7,0x84,0x41, /* y */
  545. 0x63,0xd0,0x15,0xbe,0x86,0x34,0x40,0x82,0xaa,0x88,
  546. 0xd9,0x5e,0x2f,0x9d,
  547. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  548. 0xFF,0xFE,0x26,0xF2,0xFC,0x17,0x0F,0x69,0x46,0x6A,
  549. 0x74,0xDE,0xFD,0x8D }
  550. };
  551. __fips_constseg
  552. static const struct { EC_CURVE_DATA h; unsigned char data[0+29*6]; }
  553. _EC_SECG_PRIME_224K1 = {
  554. { NID_X9_62_prime_field,0,29,1 },
  555. { /* no seed */
  556. 0x00,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  557. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  558. 0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xE5,0x6D,
  559. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  560. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  561. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  562. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  563. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  564. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x05,
  565. 0x00,0xA1,0x45,0x5B,0x33,0x4D,0xF0,0x99,0xDF,0x30, /* x */
  566. 0xFC,0x28,0xA1,0x69,0xA4,0x67,0xE9,0xE4,0x70,0x75,
  567. 0xA9,0x0F,0x7E,0x65,0x0E,0xB6,0xB7,0xA4,0x5C,
  568. 0x00,0x7e,0x08,0x9f,0xed,0x7f,0xba,0x34,0x42,0x82, /* y */
  569. 0xca,0xfb,0xd6,0xf7,0xe3,0x19,0xf7,0xc0,0xb0,0xbd,
  570. 0x59,0xe2,0xca,0x4b,0xdb,0x55,0x6d,0x61,0xa5,
  571. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  572. 0x00,0x00,0x00,0x00,0x01,0xDC,0xE8,0xD2,0xEC,0x61,
  573. 0x84,0xCA,0xF0,0xA9,0x71,0x76,0x9F,0xB1,0xF7 }
  574. };
  575. __fips_constseg
  576. static const struct { EC_CURVE_DATA h; unsigned char data[0+32*6]; }
  577. _EC_SECG_PRIME_256K1 = {
  578. { NID_X9_62_prime_field,0,32,1 },
  579. { /* no seed */
  580. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  581. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  582. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,
  583. 0xFC,0x2F,
  584. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  585. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  586. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  587. 0x00,0x00,
  588. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  589. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  590. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  591. 0x00,0x07,
  592. 0x79,0xBE,0x66,0x7E,0xF9,0xDC,0xBB,0xAC,0x55,0xA0, /* x */
  593. 0x62,0x95,0xCE,0x87,0x0B,0x07,0x02,0x9B,0xFC,0xDB,
  594. 0x2D,0xCE,0x28,0xD9,0x59,0xF2,0x81,0x5B,0x16,0xF8,
  595. 0x17,0x98,
  596. 0x48,0x3a,0xda,0x77,0x26,0xa3,0xc4,0x65,0x5d,0xa4, /* y */
  597. 0xfb,0xfc,0x0e,0x11,0x08,0xa8,0xfd,0x17,0xb4,0x48,
  598. 0xa6,0x85,0x54,0x19,0x9c,0x47,0xd0,0x8f,0xfb,0x10,
  599. 0xd4,0xb8,
  600. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  601. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xBA,0xAE,0xDC,0xE6,
  602. 0xAF,0x48,0xA0,0x3B,0xBF,0xD2,0x5E,0x8C,0xD0,0x36,
  603. 0x41,0x41 }
  604. };
  605. /* some wap/wtls curves */
  606. __fips_constseg
  607. static const struct { EC_CURVE_DATA h; unsigned char data[0+15*6]; }
  608. _EC_WTLS_8 = {
  609. { NID_X9_62_prime_field,0,15,1 },
  610. { /* no seed */
  611. 0x00,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  612. 0xFF,0xFF,0xFF,0xFD,0xE7,
  613. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  614. 0x00,0x00,0x00,0x00,0x00,
  615. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  616. 0x00,0x00,0x00,0x00,0x03,
  617. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* x */
  618. 0x00,0x00,0x00,0x00,0x01,
  619. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* y */
  620. 0x00,0x00,0x00,0x00,0x02,
  621. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0xEC,0xEA, /* order */
  622. 0x55,0x1A,0xD8,0x37,0xE9 }
  623. };
  624. __fips_constseg
  625. static const struct { EC_CURVE_DATA h; unsigned char data[0+21*6]; }
  626. _EC_WTLS_9 = {
  627. { NID_X9_62_prime_field,0,21,1 },
  628. { /* no seed */
  629. 0x00,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  630. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFC,0x80,
  631. 0x8F,
  632. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  633. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  634. 0x00,
  635. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  636. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  637. 0x03,
  638. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* x */
  639. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  640. 0x01,
  641. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* y */
  642. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  643. 0x02,
  644. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  645. 0x01,0xCD,0xC9,0x8A,0xE0,0xE2,0xDE,0x57,0x4A,0xBF,
  646. 0x33 }
  647. };
  648. __fips_constseg
  649. static const struct { EC_CURVE_DATA h; unsigned char data[0+28*6]; }
  650. _EC_WTLS_12 = {
  651. { NID_X9_62_prime_field,0,28,1 },
  652. { /* no seed */
  653. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* p */
  654. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0x00,0x00,0x00,0x00,
  655. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  656. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* a */
  657. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0xFF,0xFF,0xFF,0xFF,
  658. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,
  659. 0xB4,0x05,0x0A,0x85,0x0C,0x04,0xB3,0xAB,0xF5,0x41, /* b */
  660. 0x32,0x56,0x50,0x44,0xB0,0xB7,0xD7,0xBF,0xD8,0xBA,
  661. 0x27,0x0B,0x39,0x43,0x23,0x55,0xFF,0xB4,
  662. 0xB7,0x0E,0x0C,0xBD,0x6B,0xB4,0xBF,0x7F,0x32,0x13, /* x */
  663. 0x90,0xB9,0x4A,0x03,0xC1,0xD3,0x56,0xC2,0x11,0x22,
  664. 0x34,0x32,0x80,0xD6,0x11,0x5C,0x1D,0x21,
  665. 0xbd,0x37,0x63,0x88,0xb5,0xf7,0x23,0xfb,0x4c,0x22, /* y */
  666. 0xdf,0xe6,0xcd,0x43,0x75,0xa0,0x5a,0x07,0x47,0x64,
  667. 0x44,0xd5,0x81,0x99,0x85,0x00,0x7e,0x34,
  668. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  669. 0xFF,0xFF,0xFF,0xFF,0x16,0xA2,0xE0,0xB8,0xF0,0x3E,
  670. 0x13,0xDD,0x29,0x45,0x5C,0x5C,0x2A,0x3D }
  671. };
  672. #ifndef OPENSSL_NO_EC2M
  673. /* characteristic two curves */
  674. __fips_constseg
  675. static const struct { EC_CURVE_DATA h; unsigned char data[20+15*6]; }
  676. _EC_SECG_CHAR2_113R1 = {
  677. { NID_X9_62_characteristic_two_field,20,15,2 },
  678. { 0x10,0xE7,0x23,0xAB,0x14,0xD6,0x96,0xE6,0x76,0x87, /* seed */
  679. 0x56,0x15,0x17,0x56,0xFE,0xBF,0x8F,0xCB,0x49,0xA9,
  680. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  681. 0x00,0x00,0x00,0x02,0x01,
  682. 0x00,0x30,0x88,0x25,0x0C,0xA6,0xE7,0xC7,0xFE,0x64, /* a */
  683. 0x9C,0xE8,0x58,0x20,0xF7,
  684. 0x00,0xE8,0xBE,0xE4,0xD3,0xE2,0x26,0x07,0x44,0x18, /* b */
  685. 0x8B,0xE0,0xE9,0xC7,0x23,
  686. 0x00,0x9D,0x73,0x61,0x6F,0x35,0xF4,0xAB,0x14,0x07, /* x */
  687. 0xD7,0x35,0x62,0xC1,0x0F,
  688. 0x00,0xA5,0x28,0x30,0x27,0x79,0x58,0xEE,0x84,0xD1, /* y */
  689. 0x31,0x5E,0xD3,0x18,0x86,
  690. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0xD9,0xCC, /* order */
  691. 0xEC,0x8A,0x39,0xE5,0x6F }
  692. };
  693. __fips_constseg
  694. static const struct { EC_CURVE_DATA h; unsigned char data[20+15*6]; }
  695. _EC_SECG_CHAR2_113R2 = {
  696. { NID_X9_62_characteristic_two_field,20,15,2 },
  697. { 0x10,0xC0,0xFB,0x15,0x76,0x08,0x60,0xDE,0xF1,0xEE, /* seed */
  698. 0xF4,0xD6,0x96,0xE6,0x76,0x87,0x56,0x15,0x17,0x5D,
  699. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  700. 0x00,0x00,0x00,0x02,0x01,
  701. 0x00,0x68,0x99,0x18,0xDB,0xEC,0x7E,0x5A,0x0D,0xD6, /* a */
  702. 0xDF,0xC0,0xAA,0x55,0xC7,
  703. 0x00,0x95,0xE9,0xA9,0xEC,0x9B,0x29,0x7B,0xD4,0xBF, /* b */
  704. 0x36,0xE0,0x59,0x18,0x4F,
  705. 0x01,0xA5,0x7A,0x6A,0x7B,0x26,0xCA,0x5E,0xF5,0x2F, /* x */
  706. 0xCD,0xB8,0x16,0x47,0x97,
  707. 0x00,0xB3,0xAD,0xC9,0x4E,0xD1,0xFE,0x67,0x4C,0x06, /* y */
  708. 0xE6,0x95,0xBA,0xBA,0x1D,
  709. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x08,0x78, /* order */
  710. 0x9B,0x24,0x96,0xAF,0x93 }
  711. };
  712. __fips_constseg
  713. static const struct { EC_CURVE_DATA h; unsigned char data[20+17*6]; }
  714. _EC_SECG_CHAR2_131R1 = {
  715. { NID_X9_62_characteristic_two_field,20,17,2 },
  716. { 0x4D,0x69,0x6E,0x67,0x68,0x75,0x61,0x51,0x75,0x98, /* seed */
  717. 0x5B,0xD3,0xAD,0xBA,0xDA,0x21,0xB4,0x3A,0x97,0xE2,
  718. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  719. 0x00,0x00,0x00,0x00,0x00,0x01,0x0D,
  720. 0x07,0xA1,0x1B,0x09,0xA7,0x6B,0x56,0x21,0x44,0x41, /* a */
  721. 0x8F,0xF3,0xFF,0x8C,0x25,0x70,0xB8,
  722. 0x02,0x17,0xC0,0x56,0x10,0x88,0x4B,0x63,0xB9,0xC6, /* b */
  723. 0xC7,0x29,0x16,0x78,0xF9,0xD3,0x41,
  724. 0x00,0x81,0xBA,0xF9,0x1F,0xDF,0x98,0x33,0xC4,0x0F, /* x */
  725. 0x9C,0x18,0x13,0x43,0x63,0x83,0x99,
  726. 0x07,0x8C,0x6E,0x7E,0xA3,0x8C,0x00,0x1F,0x73,0xC8, /* y */
  727. 0x13,0x4B,0x1B,0x4E,0xF9,0xE1,0x50,
  728. 0x04,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x02,0x31, /* order */
  729. 0x23,0x95,0x3A,0x94,0x64,0xB5,0x4D }
  730. };
  731. __fips_constseg
  732. static const struct { EC_CURVE_DATA h; unsigned char data[20+17*6]; }
  733. _EC_SECG_CHAR2_131R2 = {
  734. { NID_X9_62_characteristic_two_field,20,17,2 },
  735. { 0x98,0x5B,0xD3,0xAD,0xBA,0xD4,0xD6,0x96,0xE6,0x76, /* seed */
  736. 0x87,0x56,0x15,0x17,0x5A,0x21,0xB4,0x3A,0x97,0xE3,
  737. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  738. 0x00,0x00,0x00,0x00,0x00,0x01,0x0D,
  739. 0x03,0xE5,0xA8,0x89,0x19,0xD7,0xCA,0xFC,0xBF,0x41, /* a */
  740. 0x5F,0x07,0xC2,0x17,0x65,0x73,0xB2,
  741. 0x04,0xB8,0x26,0x6A,0x46,0xC5,0x56,0x57,0xAC,0x73, /* b */
  742. 0x4C,0xE3,0x8F,0x01,0x8F,0x21,0x92,
  743. 0x03,0x56,0xDC,0xD8,0xF2,0xF9,0x50,0x31,0xAD,0x65, /* x */
  744. 0x2D,0x23,0x95,0x1B,0xB3,0x66,0xA8,
  745. 0x06,0x48,0xF0,0x6D,0x86,0x79,0x40,0xA5,0x36,0x6D, /* y */
  746. 0x9E,0x26,0x5D,0xE9,0xEB,0x24,0x0F,
  747. 0x04,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x69, /* order */
  748. 0x54,0xA2,0x33,0x04,0x9B,0xA9,0x8F }
  749. };
  750. __fips_constseg
  751. static const struct { EC_CURVE_DATA h; unsigned char data[0+21*6]; }
  752. _EC_NIST_CHAR2_163K = {
  753. { NID_X9_62_characteristic_two_field,0,21,2 },
  754. { /* no seed */
  755. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  756. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  757. 0xC9,
  758. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  759. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  760. 0x01,
  761. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  762. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  763. 0x01,
  764. 0x02,0xFE,0x13,0xC0,0x53,0x7B,0xBC,0x11,0xAC,0xAA, /* x */
  765. 0x07,0xD7,0x93,0xDE,0x4E,0x6D,0x5E,0x5C,0x94,0xEE,
  766. 0xE8,
  767. 0x02,0x89,0x07,0x0F,0xB0,0x5D,0x38,0xFF,0x58,0x32, /* y */
  768. 0x1F,0x2E,0x80,0x05,0x36,0xD5,0x38,0xCC,0xDA,0xA3,
  769. 0xD9,
  770. 0x04,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  771. 0x02,0x01,0x08,0xA2,0xE0,0xCC,0x0D,0x99,0xF8,0xA5,
  772. 0xEF }
  773. };
  774. __fips_constseg
  775. static const struct { EC_CURVE_DATA h; unsigned char data[0+21*6]; }
  776. _EC_SECG_CHAR2_163R1 = {
  777. { NID_X9_62_characteristic_two_field,0,21,2 },
  778. { /* no seed */
  779. #if 0
  780. /* The algorithm used to derive the curve parameters from
  781. * the seed used here is slightly different than the
  782. * algorithm described in X9.62 . */
  783. 0x24,0xB7,0xB1,0x37,0xC8,0xA1,0x4D,0x69,0x6E,0x67,
  784. 0x68,0x75,0x61,0x51,0x75,0x6F,0xD0,0xDA,0x2E,0x5C,
  785. #endif
  786. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  787. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  788. 0xC9,
  789. 0x07,0xB6,0x88,0x2C,0xAA,0xEF,0xA8,0x4F,0x95,0x54, /* a */
  790. 0xFF,0x84,0x28,0xBD,0x88,0xE2,0x46,0xD2,0x78,0x2A,
  791. 0xE2,
  792. 0x07,0x13,0x61,0x2D,0xCD,0xDC,0xB4,0x0A,0xAB,0x94, /* b */
  793. 0x6B,0xDA,0x29,0xCA,0x91,0xF7,0x3A,0xF9,0x58,0xAF,
  794. 0xD9,
  795. 0x03,0x69,0x97,0x96,0x97,0xAB,0x43,0x89,0x77,0x89, /* x */
  796. 0x56,0x67,0x89,0x56,0x7F,0x78,0x7A,0x78,0x76,0xA6,
  797. 0x54,
  798. 0x00,0x43,0x5E,0xDB,0x42,0xEF,0xAF,0xB2,0x98,0x9D, /* y */
  799. 0x51,0xFE,0xFC,0xE3,0xC8,0x09,0x88,0xF4,0x1F,0xF8,
  800. 0x83,
  801. 0x03,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  802. 0xFF,0x48,0xAA,0xB6,0x89,0xC2,0x9C,0xA7,0x10,0x27,
  803. 0x9B }
  804. };
  805. __fips_constseg
  806. static const struct { EC_CURVE_DATA h; unsigned char data[0+21*6]; }
  807. _EC_NIST_CHAR2_163B = {
  808. { NID_X9_62_characteristic_two_field,0,21,2 },
  809. { /* no seed */
  810. #if 0
  811. /* The seed here was used to created the curve parameters in normal
  812. * basis representation (and not the polynomial representation used here) */
  813. 0x85,0xE2,0x5B,0xFE,0x5C,0x86,0x22,0x6C,0xDB,0x12,
  814. 0x01,0x6F,0x75,0x53,0xF9,0xD0,0xE6,0x93,0xA2,0x68,
  815. #endif
  816. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  817. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  818. 0xC9,
  819. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  820. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  821. 0x01,
  822. 0x02,0x0A,0x60,0x19,0x07,0xB8,0xC9,0x53,0xCA,0x14, /* b */
  823. 0x81,0xEB,0x10,0x51,0x2F,0x78,0x74,0x4A,0x32,0x05,
  824. 0xFD,
  825. 0x03,0xF0,0xEB,0xA1,0x62,0x86,0xA2,0xD5,0x7E,0xA0, /* x */
  826. 0x99,0x11,0x68,0xD4,0x99,0x46,0x37,0xE8,0x34,0x3E,
  827. 0x36,
  828. 0x00,0xD5,0x1F,0xBC,0x6C,0x71,0xA0,0x09,0x4F,0xA2, /* y */
  829. 0xCD,0xD5,0x45,0xB1,0x1C,0x5C,0x0C,0x79,0x73,0x24,
  830. 0xF1,
  831. 0x04,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  832. 0x02,0x92,0xFE,0x77,0xE7,0x0C,0x12,0xA4,0x23,0x4C,
  833. 0x33 }
  834. };
  835. __fips_constseg
  836. static const struct { EC_CURVE_DATA h; unsigned char data[20+25*6]; }
  837. _EC_SECG_CHAR2_193R1 = {
  838. { NID_X9_62_characteristic_two_field,20,25,2 },
  839. { 0x10,0x3F,0xAE,0xC7,0x4D,0x69,0x6E,0x67,0x68,0x75, /* seed */
  840. 0x61,0x51,0x75,0x77,0x7F,0xC5,0xB1,0x91,0xEF,0x30,
  841. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  842. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  843. 0x00,0x00,0x00,0x80,0x01,
  844. 0x00,0x17,0x85,0x8F,0xEB,0x7A,0x98,0x97,0x51,0x69, /* a */
  845. 0xE1,0x71,0xF7,0x7B,0x40,0x87,0xDE,0x09,0x8A,0xC8,
  846. 0xA9,0x11,0xDF,0x7B,0x01,
  847. 0x00,0xFD,0xFB,0x49,0xBF,0xE6,0xC3,0xA8,0x9F,0xAC, /* b */
  848. 0xAD,0xAA,0x7A,0x1E,0x5B,0xBC,0x7C,0xC1,0xC2,0xE5,
  849. 0xD8,0x31,0x47,0x88,0x14,
  850. 0x01,0xF4,0x81,0xBC,0x5F,0x0F,0xF8,0x4A,0x74,0xAD, /* x */
  851. 0x6C,0xDF,0x6F,0xDE,0xF4,0xBF,0x61,0x79,0x62,0x53,
  852. 0x72,0xD8,0xC0,0xC5,0xE1,
  853. 0x00,0x25,0xE3,0x99,0xF2,0x90,0x37,0x12,0xCC,0xF3, /* y */
  854. 0xEA,0x9E,0x3A,0x1A,0xD1,0x7F,0xB0,0xB3,0x20,0x1B,
  855. 0x6A,0xF7,0xCE,0x1B,0x05,
  856. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  857. 0x00,0x00,0x00,0xC7,0xF3,0x4A,0x77,0x8F,0x44,0x3A,
  858. 0xCC,0x92,0x0E,0xBA,0x49 }
  859. };
  860. __fips_constseg
  861. static const struct { EC_CURVE_DATA h; unsigned char data[20+25*6]; }
  862. _EC_SECG_CHAR2_193R2 = {
  863. { NID_X9_62_characteristic_two_field,20,25,2 },
  864. { 0x10,0xB7,0xB4,0xD6,0x96,0xE6,0x76,0x87,0x56,0x15, /* seed */
  865. 0x17,0x51,0x37,0xC8,0xA1,0x6F,0xD0,0xDA,0x22,0x11,
  866. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  867. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  868. 0x00,0x00,0x00,0x80,0x01,
  869. 0x01,0x63,0xF3,0x5A,0x51,0x37,0xC2,0xCE,0x3E,0xA6, /* a */
  870. 0xED,0x86,0x67,0x19,0x0B,0x0B,0xC4,0x3E,0xCD,0x69,
  871. 0x97,0x77,0x02,0x70,0x9B,
  872. 0x00,0xC9,0xBB,0x9E,0x89,0x27,0xD4,0xD6,0x4C,0x37, /* b */
  873. 0x7E,0x2A,0xB2,0x85,0x6A,0x5B,0x16,0xE3,0xEF,0xB7,
  874. 0xF6,0x1D,0x43,0x16,0xAE,
  875. 0x00,0xD9,0xB6,0x7D,0x19,0x2E,0x03,0x67,0xC8,0x03, /* x */
  876. 0xF3,0x9E,0x1A,0x7E,0x82,0xCA,0x14,0xA6,0x51,0x35,
  877. 0x0A,0xAE,0x61,0x7E,0x8F,
  878. 0x01,0xCE,0x94,0x33,0x56,0x07,0xC3,0x04,0xAC,0x29, /* y */
  879. 0xE7,0xDE,0xFB,0xD9,0xCA,0x01,0xF5,0x96,0xF9,0x27,
  880. 0x22,0x4C,0xDE,0xCF,0x6C,
  881. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  882. 0x00,0x00,0x01,0x5A,0xAB,0x56,0x1B,0x00,0x54,0x13,
  883. 0xCC,0xD4,0xEE,0x99,0xD5 }
  884. };
  885. __fips_constseg
  886. static const struct { EC_CURVE_DATA h; unsigned char data[0+30*6]; }
  887. _EC_NIST_CHAR2_233K = {
  888. { NID_X9_62_characteristic_two_field,0,30,4 },
  889. { /* no seed */
  890. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  891. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  892. 0x04,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  893. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  894. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  895. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  896. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  897. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  898. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  899. 0x01,0x72,0x32,0xBA,0x85,0x3A,0x7E,0x73,0x1A,0xF1, /* x */
  900. 0x29,0xF2,0x2F,0xF4,0x14,0x95,0x63,0xA4,0x19,0xC2,
  901. 0x6B,0xF5,0x0A,0x4C,0x9D,0x6E,0xEF,0xAD,0x61,0x26,
  902. 0x01,0xDB,0x53,0x7D,0xEC,0xE8,0x19,0xB7,0xF7,0x0F, /* y */
  903. 0x55,0x5A,0x67,0xC4,0x27,0xA8,0xCD,0x9B,0xF1,0x8A,
  904. 0xEB,0x9B,0x56,0xE0,0xC1,0x10,0x56,0xFA,0xE6,0xA3,
  905. 0x00,0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  906. 0x00,0x00,0x00,0x00,0x00,0x06,0x9D,0x5B,0xB9,0x15,
  907. 0xBC,0xD4,0x6E,0xFB,0x1A,0xD5,0xF1,0x73,0xAB,0xDF }
  908. };
  909. __fips_constseg
  910. static const struct { EC_CURVE_DATA h; unsigned char data[20+30*6]; }
  911. _EC_NIST_CHAR2_233B = {
  912. { NID_X9_62_characteristic_two_field,20,30,2 },
  913. { 0x74,0xD5,0x9F,0xF0,0x7F,0x6B,0x41,0x3D,0x0E,0xA1, /* seed */
  914. 0x4B,0x34,0x4B,0x20,0xA2,0xDB,0x04,0x9B,0x50,0xC3,
  915. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  916. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  917. 0x04,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  918. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  919. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  920. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  921. 0x00,0x66,0x64,0x7E,0xDE,0x6C,0x33,0x2C,0x7F,0x8C, /* b */
  922. 0x09,0x23,0xBB,0x58,0x21,0x3B,0x33,0x3B,0x20,0xE9,
  923. 0xCE,0x42,0x81,0xFE,0x11,0x5F,0x7D,0x8F,0x90,0xAD,
  924. 0x00,0xFA,0xC9,0xDF,0xCB,0xAC,0x83,0x13,0xBB,0x21, /* x */
  925. 0x39,0xF1,0xBB,0x75,0x5F,0xEF,0x65,0xBC,0x39,0x1F,
  926. 0x8B,0x36,0xF8,0xF8,0xEB,0x73,0x71,0xFD,0x55,0x8B,
  927. 0x01,0x00,0x6A,0x08,0xA4,0x19,0x03,0x35,0x06,0x78, /* y */
  928. 0xE5,0x85,0x28,0xBE,0xBF,0x8A,0x0B,0xEF,0xF8,0x67,
  929. 0xA7,0xCA,0x36,0x71,0x6F,0x7E,0x01,0xF8,0x10,0x52,
  930. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  931. 0x00,0x00,0x00,0x00,0x00,0x13,0xE9,0x74,0xE7,0x2F,
  932. 0x8A,0x69,0x22,0x03,0x1D,0x26,0x03,0xCF,0xE0,0xD7 }
  933. };
  934. __fips_constseg
  935. static const struct { EC_CURVE_DATA h; unsigned char data[0+30*6]; }
  936. _EC_SECG_CHAR2_239K1 = {
  937. { NID_X9_62_characteristic_two_field,0,30,4 },
  938. { /* no seed */
  939. 0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  940. 0x40,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  941. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  942. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  943. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  944. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  945. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  946. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  947. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  948. 0x29,0xA0,0xB6,0xA8,0x87,0xA9,0x83,0xE9,0x73,0x09, /* x */
  949. 0x88,0xA6,0x87,0x27,0xA8,0xB2,0xD1,0x26,0xC4,0x4C,
  950. 0xC2,0xCC,0x7B,0x2A,0x65,0x55,0x19,0x30,0x35,0xDC,
  951. 0x76,0x31,0x08,0x04,0xF1,0x2E,0x54,0x9B,0xDB,0x01, /* y */
  952. 0x1C,0x10,0x30,0x89,0xE7,0x35,0x10,0xAC,0xB2,0x75,
  953. 0xFC,0x31,0x2A,0x5D,0xC6,0xB7,0x65,0x53,0xF0,0xCA,
  954. 0x20,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  955. 0x00,0x00,0x00,0x00,0x00,0x5A,0x79,0xFE,0xC6,0x7C,
  956. 0xB6,0xE9,0x1F,0x1C,0x1D,0xA8,0x00,0xE4,0x78,0xA5 }
  957. };
  958. __fips_constseg
  959. static const struct { EC_CURVE_DATA h; unsigned char data[0+36*6]; }
  960. _EC_NIST_CHAR2_283K = {
  961. { NID_X9_62_characteristic_two_field,0,36,4 },
  962. { /* no seed */
  963. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  964. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  965. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  966. 0x00,0x00,0x00,0x00,0x10,0xA1,
  967. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  968. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  969. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  970. 0x00,0x00,0x00,0x00,0x00,0x00,
  971. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  972. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  973. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  974. 0x00,0x00,0x00,0x00,0x00,0x01,
  975. 0x05,0x03,0x21,0x3F,0x78,0xCA,0x44,0x88,0x3F,0x1A, /* x */
  976. 0x3B,0x81,0x62,0xF1,0x88,0xE5,0x53,0xCD,0x26,0x5F,
  977. 0x23,0xC1,0x56,0x7A,0x16,0x87,0x69,0x13,0xB0,0xC2,
  978. 0xAC,0x24,0x58,0x49,0x28,0x36,
  979. 0x01,0xCC,0xDA,0x38,0x0F,0x1C,0x9E,0x31,0x8D,0x90, /* y */
  980. 0xF9,0x5D,0x07,0xE5,0x42,0x6F,0xE8,0x7E,0x45,0xC0,
  981. 0xE8,0x18,0x46,0x98,0xE4,0x59,0x62,0x36,0x4E,0x34,
  982. 0x11,0x61,0x77,0xDD,0x22,0x59,
  983. 0x01,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  984. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xE9,0xAE,
  985. 0x2E,0xD0,0x75,0x77,0x26,0x5D,0xFF,0x7F,0x94,0x45,
  986. 0x1E,0x06,0x1E,0x16,0x3C,0x61 }
  987. };
  988. __fips_constseg
  989. static const struct { EC_CURVE_DATA h; unsigned char data[20+36*6]; }
  990. _EC_NIST_CHAR2_283B = {
  991. { NID_X9_62_characteristic_two_field,20,36,2 },
  992. { 0x77,0xE2,0xB0,0x73,0x70,0xEB,0x0F,0x83,0x2A,0x6D, /* no seed */
  993. 0xD5,0xB6,0x2D,0xFC,0x88,0xCD,0x06,0xBB,0x84,0xBE,
  994. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  995. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  996. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  997. 0x00,0x00,0x00,0x00,0x10,0xA1,
  998. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  999. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1000. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1001. 0x00,0x00,0x00,0x00,0x00,0x01,
  1002. 0x02,0x7B,0x68,0x0A,0xC8,0xB8,0x59,0x6D,0xA5,0xA4, /* b */
  1003. 0xAF,0x8A,0x19,0xA0,0x30,0x3F,0xCA,0x97,0xFD,0x76,
  1004. 0x45,0x30,0x9F,0xA2,0xA5,0x81,0x48,0x5A,0xF6,0x26,
  1005. 0x3E,0x31,0x3B,0x79,0xA2,0xF5,
  1006. 0x05,0xF9,0x39,0x25,0x8D,0xB7,0xDD,0x90,0xE1,0x93, /* x */
  1007. 0x4F,0x8C,0x70,0xB0,0xDF,0xEC,0x2E,0xED,0x25,0xB8,
  1008. 0x55,0x7E,0xAC,0x9C,0x80,0xE2,0xE1,0x98,0xF8,0xCD,
  1009. 0xBE,0xCD,0x86,0xB1,0x20,0x53,
  1010. 0x03,0x67,0x68,0x54,0xFE,0x24,0x14,0x1C,0xB9,0x8F, /* y */
  1011. 0xE6,0xD4,0xB2,0x0D,0x02,0xB4,0x51,0x6F,0xF7,0x02,
  1012. 0x35,0x0E,0xDD,0xB0,0x82,0x67,0x79,0xC8,0x13,0xF0,
  1013. 0xDF,0x45,0xBE,0x81,0x12,0xF4,
  1014. 0x03,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  1015. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xEF,0x90,
  1016. 0x39,0x96,0x60,0xFC,0x93,0x8A,0x90,0x16,0x5B,0x04,
  1017. 0x2A,0x7C,0xEF,0xAD,0xB3,0x07 }
  1018. };
  1019. __fips_constseg
  1020. static const struct { EC_CURVE_DATA h; unsigned char data[0+52*6]; }
  1021. _EC_NIST_CHAR2_409K = {
  1022. { NID_X9_62_characteristic_two_field,0,52,4 },
  1023. { /* no seed */
  1024. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1025. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1026. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1027. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1028. 0x00,0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1029. 0x00,0x01,
  1030. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  1031. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1032. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1033. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1034. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1035. 0x00,0x00,
  1036. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  1037. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1038. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1039. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1040. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1041. 0x00,0x01,
  1042. 0x00,0x60,0xF0,0x5F,0x65,0x8F,0x49,0xC1,0xAD,0x3A, /* x */
  1043. 0xB1,0x89,0x0F,0x71,0x84,0x21,0x0E,0xFD,0x09,0x87,
  1044. 0xE3,0x07,0xC8,0x4C,0x27,0xAC,0xCF,0xB8,0xF9,0xF6,
  1045. 0x7C,0xC2,0xC4,0x60,0x18,0x9E,0xB5,0xAA,0xAA,0x62,
  1046. 0xEE,0x22,0x2E,0xB1,0xB3,0x55,0x40,0xCF,0xE9,0x02,
  1047. 0x37,0x46,
  1048. 0x01,0xE3,0x69,0x05,0x0B,0x7C,0x4E,0x42,0xAC,0xBA, /* y */
  1049. 0x1D,0xAC,0xBF,0x04,0x29,0x9C,0x34,0x60,0x78,0x2F,
  1050. 0x91,0x8E,0xA4,0x27,0xE6,0x32,0x51,0x65,0xE9,0xEA,
  1051. 0x10,0xE3,0xDA,0x5F,0x6C,0x42,0xE9,0xC5,0x52,0x15,
  1052. 0xAA,0x9C,0xA2,0x7A,0x58,0x63,0xEC,0x48,0xD8,0xE0,
  1053. 0x28,0x6B,
  1054. 0x00,0x7F,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  1055. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  1056. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,0x5F,0x83,0xB2,
  1057. 0xD4,0xEA,0x20,0x40,0x0E,0xC4,0x55,0x7D,0x5E,0xD3,
  1058. 0xE3,0xE7,0xCA,0x5B,0x4B,0x5C,0x83,0xB8,0xE0,0x1E,
  1059. 0x5F,0xCF }
  1060. };
  1061. __fips_constseg
  1062. static const struct { EC_CURVE_DATA h; unsigned char data[20+52*6]; }
  1063. _EC_NIST_CHAR2_409B = {
  1064. { NID_X9_62_characteristic_two_field,20,52,2 },
  1065. { 0x40,0x99,0xB5,0xA4,0x57,0xF9,0xD6,0x9F,0x79,0x21, /* seed */
  1066. 0x3D,0x09,0x4C,0x4B,0xCD,0x4D,0x42,0x62,0x21,0x0B,
  1067. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1068. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1069. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1070. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1071. 0x00,0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1072. 0x00,0x01,
  1073. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  1074. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1075. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1076. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1077. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1078. 0x00,0x01,
  1079. 0x00,0x21,0xA5,0xC2,0xC8,0xEE,0x9F,0xEB,0x5C,0x4B, /* b */
  1080. 0x9A,0x75,0x3B,0x7B,0x47,0x6B,0x7F,0xD6,0x42,0x2E,
  1081. 0xF1,0xF3,0xDD,0x67,0x47,0x61,0xFA,0x99,0xD6,0xAC,
  1082. 0x27,0xC8,0xA9,0xA1,0x97,0xB2,0x72,0x82,0x2F,0x6C,
  1083. 0xD5,0x7A,0x55,0xAA,0x4F,0x50,0xAE,0x31,0x7B,0x13,
  1084. 0x54,0x5F,
  1085. 0x01,0x5D,0x48,0x60,0xD0,0x88,0xDD,0xB3,0x49,0x6B, /* x */
  1086. 0x0C,0x60,0x64,0x75,0x62,0x60,0x44,0x1C,0xDE,0x4A,
  1087. 0xF1,0x77,0x1D,0x4D,0xB0,0x1F,0xFE,0x5B,0x34,0xE5,
  1088. 0x97,0x03,0xDC,0x25,0x5A,0x86,0x8A,0x11,0x80,0x51,
  1089. 0x56,0x03,0xAE,0xAB,0x60,0x79,0x4E,0x54,0xBB,0x79,
  1090. 0x96,0xA7,
  1091. 0x00,0x61,0xB1,0xCF,0xAB,0x6B,0xE5,0xF3,0x2B,0xBF, /* y */
  1092. 0xA7,0x83,0x24,0xED,0x10,0x6A,0x76,0x36,0xB9,0xC5,
  1093. 0xA7,0xBD,0x19,0x8D,0x01,0x58,0xAA,0x4F,0x54,0x88,
  1094. 0xD0,0x8F,0x38,0x51,0x4F,0x1F,0xDF,0x4B,0x4F,0x40,
  1095. 0xD2,0x18,0x1B,0x36,0x81,0xC3,0x64,0xBA,0x02,0x73,
  1096. 0xC7,0x06,
  1097. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  1098. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1099. 0x00,0x00,0x00,0x00,0x00,0x00,0x01,0xE2,0xAA,0xD6,
  1100. 0xA6,0x12,0xF3,0x33,0x07,0xBE,0x5F,0xA4,0x7C,0x3C,
  1101. 0x9E,0x05,0x2F,0x83,0x81,0x64,0xCD,0x37,0xD9,0xA2,
  1102. 0x11,0x73 }
  1103. };
  1104. __fips_constseg
  1105. static const struct { EC_CURVE_DATA h; unsigned char data[0+72*6]; }
  1106. _EC_NIST_CHAR2_571K = {
  1107. { NID_X9_62_characteristic_two_field,0,72,4 },
  1108. { /* no seed */
  1109. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1110. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1111. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1112. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1113. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1114. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1115. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1116. 0x04,0x25,
  1117. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  1118. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1119. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1120. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1121. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1122. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1123. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1124. 0x00,0x00,
  1125. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  1126. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1127. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1128. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1129. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1130. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1131. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1132. 0x00,0x01,
  1133. 0x02,0x6E,0xB7,0xA8,0x59,0x92,0x3F,0xBC,0x82,0x18, /* x */
  1134. 0x96,0x31,0xF8,0x10,0x3F,0xE4,0xAC,0x9C,0xA2,0x97,
  1135. 0x00,0x12,0xD5,0xD4,0x60,0x24,0x80,0x48,0x01,0x84,
  1136. 0x1C,0xA4,0x43,0x70,0x95,0x84,0x93,0xB2,0x05,0xE6,
  1137. 0x47,0xDA,0x30,0x4D,0xB4,0xCE,0xB0,0x8C,0xBB,0xD1,
  1138. 0xBA,0x39,0x49,0x47,0x76,0xFB,0x98,0x8B,0x47,0x17,
  1139. 0x4D,0xCA,0x88,0xC7,0xE2,0x94,0x52,0x83,0xA0,0x1C,
  1140. 0x89,0x72,
  1141. 0x03,0x49,0xDC,0x80,0x7F,0x4F,0xBF,0x37,0x4F,0x4A, /* y */
  1142. 0xEA,0xDE,0x3B,0xCA,0x95,0x31,0x4D,0xD5,0x8C,0xEC,
  1143. 0x9F,0x30,0x7A,0x54,0xFF,0xC6,0x1E,0xFC,0x00,0x6D,
  1144. 0x8A,0x2C,0x9D,0x49,0x79,0xC0,0xAC,0x44,0xAE,0xA7,
  1145. 0x4F,0xBE,0xBB,0xB9,0xF7,0x72,0xAE,0xDC,0xB6,0x20,
  1146. 0xB0,0x1A,0x7B,0xA7,0xAF,0x1B,0x32,0x04,0x30,0xC8,
  1147. 0x59,0x19,0x84,0xF6,0x01,0xCD,0x4C,0x14,0x3E,0xF1,
  1148. 0xC7,0xA3,
  1149. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  1150. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1151. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1152. 0x00,0x00,0x00,0x00,0x00,0x00,0x13,0x18,0x50,0xE1,
  1153. 0xF1,0x9A,0x63,0xE4,0xB3,0x91,0xA8,0xDB,0x91,0x7F,
  1154. 0x41,0x38,0xB6,0x30,0xD8,0x4B,0xE5,0xD6,0x39,0x38,
  1155. 0x1E,0x91,0xDE,0xB4,0x5C,0xFE,0x77,0x8F,0x63,0x7C,
  1156. 0x10,0x01 }
  1157. };
  1158. __fips_constseg
  1159. static const struct { EC_CURVE_DATA h; unsigned char data[20+72*6]; }
  1160. _EC_NIST_CHAR2_571B = {
  1161. { NID_X9_62_characteristic_two_field,20,72,2 },
  1162. { 0x2A,0xA0,0x58,0xF7,0x3A,0x0E,0x33,0xAB,0x48,0x6B, /* seed */
  1163. 0x0F,0x61,0x04,0x10,0xC5,0x3A,0x7F,0x13,0x23,0x10,
  1164. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1165. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1166. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1167. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1168. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1169. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1170. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1171. 0x04,0x25,
  1172. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  1173. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1174. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1175. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1176. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1177. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1178. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1179. 0x00,0x01,
  1180. 0x02,0xF4,0x0E,0x7E,0x22,0x21,0xF2,0x95,0xDE,0x29, /* b */
  1181. 0x71,0x17,0xB7,0xF3,0xD6,0x2F,0x5C,0x6A,0x97,0xFF,
  1182. 0xCB,0x8C,0xEF,0xF1,0xCD,0x6B,0xA8,0xCE,0x4A,0x9A,
  1183. 0x18,0xAD,0x84,0xFF,0xAB,0xBD,0x8E,0xFA,0x59,0x33,
  1184. 0x2B,0xE7,0xAD,0x67,0x56,0xA6,0x6E,0x29,0x4A,0xFD,
  1185. 0x18,0x5A,0x78,0xFF,0x12,0xAA,0x52,0x0E,0x4D,0xE7,
  1186. 0x39,0xBA,0xCA,0x0C,0x7F,0xFE,0xFF,0x7F,0x29,0x55,
  1187. 0x72,0x7A,
  1188. 0x03,0x03,0x00,0x1D,0x34,0xB8,0x56,0x29,0x6C,0x16, /* x */
  1189. 0xC0,0xD4,0x0D,0x3C,0xD7,0x75,0x0A,0x93,0xD1,0xD2,
  1190. 0x95,0x5F,0xA8,0x0A,0xA5,0xF4,0x0F,0xC8,0xDB,0x7B,
  1191. 0x2A,0xBD,0xBD,0xE5,0x39,0x50,0xF4,0xC0,0xD2,0x93,
  1192. 0xCD,0xD7,0x11,0xA3,0x5B,0x67,0xFB,0x14,0x99,0xAE,
  1193. 0x60,0x03,0x86,0x14,0xF1,0x39,0x4A,0xBF,0xA3,0xB4,
  1194. 0xC8,0x50,0xD9,0x27,0xE1,0xE7,0x76,0x9C,0x8E,0xEC,
  1195. 0x2D,0x19,
  1196. 0x03,0x7B,0xF2,0x73,0x42,0xDA,0x63,0x9B,0x6D,0xCC, /* y */
  1197. 0xFF,0xFE,0xB7,0x3D,0x69,0xD7,0x8C,0x6C,0x27,0xA6,
  1198. 0x00,0x9C,0xBB,0xCA,0x19,0x80,0xF8,0x53,0x39,0x21,
  1199. 0xE8,0xA6,0x84,0x42,0x3E,0x43,0xBA,0xB0,0x8A,0x57,
  1200. 0x62,0x91,0xAF,0x8F,0x46,0x1B,0xB2,0xA8,0xB3,0x53,
  1201. 0x1D,0x2F,0x04,0x85,0xC1,0x9B,0x16,0xE2,0xF1,0x51,
  1202. 0x6E,0x23,0xDD,0x3C,0x1A,0x48,0x27,0xAF,0x1B,0x8A,
  1203. 0xC1,0x5B,
  1204. 0x03,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  1205. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  1206. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
  1207. 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xE6,0x61,0xCE,0x18,
  1208. 0xFF,0x55,0x98,0x73,0x08,0x05,0x9B,0x18,0x68,0x23,
  1209. 0x85,0x1E,0xC7,0xDD,0x9C,0xA1,0x16,0x1D,0xE9,0x3D,
  1210. 0x51,0x74,0xD6,0x6E,0x83,0x82,0xE9,0xBB,0x2F,0xE8,
  1211. 0x4E,0x47 }
  1212. };
  1213. __fips_constseg
  1214. static const struct { EC_CURVE_DATA h; unsigned char data[20+21*6]; }
  1215. _EC_X9_62_CHAR2_163V1 = {
  1216. { NID_X9_62_characteristic_two_field,20,21,2 },
  1217. { 0xD2,0xC0,0xFB,0x15,0x76,0x08,0x60,0xDE,0xF1,0xEE,
  1218. 0xF4,0xD6,0x96,0xE6,0x76,0x87,0x56,0x15,0x17,0x54, /* seed */
  1219. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1220. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  1221. 0x07,
  1222. 0x07,0x25,0x46,0xB5,0x43,0x52,0x34,0xA4,0x22,0xE0, /* a */
  1223. 0x78,0x96,0x75,0xF4,0x32,0xC8,0x94,0x35,0xDE,0x52,
  1224. 0x42,
  1225. 0x00,0xC9,0x51,0x7D,0x06,0xD5,0x24,0x0D,0x3C,0xFF, /* b */
  1226. 0x38,0xC7,0x4B,0x20,0xB6,0xCD,0x4D,0x6F,0x9D,0xD4,
  1227. 0xD9,
  1228. 0x07,0xAF,0x69,0x98,0x95,0x46,0x10,0x3D,0x79,0x32, /* x */
  1229. 0x9F,0xCC,0x3D,0x74,0x88,0x0F,0x33,0xBB,0xE8,0x03,
  1230. 0xCB,
  1231. 0x01,0xEC,0x23,0x21,0x1B,0x59,0x66,0xAD,0xEA,0x1D, /* y */
  1232. 0x3F,0x87,0xF7,0xEA,0x58,0x48,0xAE,0xF0,0xB7,0xCA,
  1233. 0x9F,
  1234. 0x04,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  1235. 0x01,0xE6,0x0F,0xC8,0x82,0x1C,0xC7,0x4D,0xAE,0xAF,
  1236. 0xC1 }
  1237. };
  1238. __fips_constseg
  1239. static const struct { EC_CURVE_DATA h; unsigned char data[20+21*6]; }
  1240. _EC_X9_62_CHAR2_163V2 = {
  1241. { NID_X9_62_characteristic_two_field,20,21,2 },
  1242. { 0x53,0x81,0x4C,0x05,0x0D,0x44,0xD6,0x96,0xE6,0x76, /* seed */
  1243. 0x87,0x56,0x15,0x17,0x58,0x0C,0xA4,0xE2,0x9F,0xFD,
  1244. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1245. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  1246. 0x07,
  1247. 0x01,0x08,0xB3,0x9E,0x77,0xC4,0xB1,0x08,0xBE,0xD9, /* a */
  1248. 0x81,0xED,0x0E,0x89,0x0E,0x11,0x7C,0x51,0x1C,0xF0,
  1249. 0x72,
  1250. 0x06,0x67,0xAC,0xEB,0x38,0xAF,0x4E,0x48,0x8C,0x40, /* b */
  1251. 0x74,0x33,0xFF,0xAE,0x4F,0x1C,0x81,0x16,0x38,0xDF,
  1252. 0x20,
  1253. 0x00,0x24,0x26,0x6E,0x4E,0xB5,0x10,0x6D,0x0A,0x96, /* x */
  1254. 0x4D,0x92,0xC4,0x86,0x0E,0x26,0x71,0xDB,0x9B,0x6C,
  1255. 0xC5,
  1256. 0x07,0x9F,0x68,0x4D,0xDF,0x66,0x84,0xC5,0xCD,0x25, /* y */
  1257. 0x8B,0x38,0x90,0x02,0x1B,0x23,0x86,0xDF,0xD1,0x9F,
  1258. 0xC5,
  1259. 0x03,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  1260. 0xFD,0xF6,0x4D,0xE1,0x15,0x1A,0xDB,0xB7,0x8F,0x10,
  1261. 0xA7 }
  1262. };
  1263. __fips_constseg
  1264. static const struct { EC_CURVE_DATA h; unsigned char data[20+21*6]; }
  1265. _EC_X9_62_CHAR2_163V3 = {
  1266. { NID_X9_62_characteristic_two_field,20,21,2 },
  1267. { 0x50,0xCB,0xF1,0xD9,0x5C,0xA9,0x4D,0x69,0x6E,0x67, /* seed */
  1268. 0x68,0x75,0x61,0x51,0x75,0xF1,0x6A,0x36,0xA3,0xB8,
  1269. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1270. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  1271. 0x07,
  1272. 0x07,0xA5,0x26,0xC6,0x3D,0x3E,0x25,0xA2,0x56,0xA0, /* a */
  1273. 0x07,0x69,0x9F,0x54,0x47,0xE3,0x2A,0xE4,0x56,0xB5,
  1274. 0x0E,
  1275. 0x03,0xF7,0x06,0x17,0x98,0xEB,0x99,0xE2,0x38,0xFD, /* b */
  1276. 0x6F,0x1B,0xF9,0x5B,0x48,0xFE,0xEB,0x48,0x54,0x25,
  1277. 0x2B,
  1278. 0x02,0xF9,0xF8,0x7B,0x7C,0x57,0x4D,0x0B,0xDE,0xCF, /* x */
  1279. 0x8A,0x22,0xE6,0x52,0x47,0x75,0xF9,0x8C,0xDE,0xBD,
  1280. 0xCB,
  1281. 0x05,0xB9,0x35,0x59,0x0C,0x15,0x5E,0x17,0xEA,0x48, /* y */
  1282. 0xEB,0x3F,0xF3,0x71,0x8B,0x89,0x3D,0xF5,0x9A,0x05,
  1283. 0xD0,
  1284. 0x03,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  1285. 0xFE,0x1A,0xEE,0x14,0x0F,0x11,0x0A,0xFF,0x96,0x13,
  1286. 0x09 }
  1287. };
  1288. __fips_constseg
  1289. static const struct { EC_CURVE_DATA h; unsigned char data[0+23*6]; }
  1290. _EC_X9_62_CHAR2_176V1 = {
  1291. { NID_X9_62_characteristic_two_field,0,23,0xFF6E },
  1292. { /* no seed */
  1293. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1294. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x08,0x00,0x00,
  1295. 0x00,0x00,0x07,
  1296. 0x00,0xE4,0xE6,0xDB,0x29,0x95,0x06,0x5C,0x40,0x7D, /* a */
  1297. 0x9D,0x39,0xB8,0xD0,0x96,0x7B,0x96,0x70,0x4B,0xA8,
  1298. 0xE9,0xC9,0x0B,
  1299. 0x00,0x5D,0xDA,0x47,0x0A,0xBE,0x64,0x14,0xDE,0x8E, /* b */
  1300. 0xC1,0x33,0xAE,0x28,0xE9,0xBB,0xD7,0xFC,0xEC,0x0A,
  1301. 0xE0,0xFF,0xF2,
  1302. 0x00,0x8D,0x16,0xC2,0x86,0x67,0x98,0xB6,0x00,0xF9, /* x */
  1303. 0xF0,0x8B,0xB4,0xA8,0xE8,0x60,0xF3,0x29,0x8C,0xE0,
  1304. 0x4A,0x57,0x98,
  1305. 0x00,0x6F,0xA4,0x53,0x9C,0x2D,0xAD,0xDD,0xD6,0xBA, /* y */
  1306. 0xB5,0x16,0x7D,0x61,0xB4,0x36,0xE1,0xD9,0x2B,0xB1,
  1307. 0x6A,0x56,0x2C,
  1308. 0x00,0x00,0x01,0x00,0x92,0x53,0x73,0x97,0xEC,0xA4, /* order */
  1309. 0xF6,0x14,0x57,0x99,0xD6,0x2B,0x0A,0x19,0xCE,0x06,
  1310. 0xFE,0x26,0xAD }
  1311. };
  1312. __fips_constseg
  1313. static const struct { EC_CURVE_DATA h; unsigned char data[20+24*6]; }
  1314. _EC_X9_62_CHAR2_191V1 = {
  1315. { NID_X9_62_characteristic_two_field,20,24,2 },
  1316. { 0x4E,0x13,0xCA,0x54,0x27,0x44,0xD6,0x96,0xE6,0x76, /* seed */
  1317. 0x87,0x56,0x15,0x17,0x55,0x2F,0x27,0x9A,0x8C,0x84,
  1318. 0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1319. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1320. 0x00,0x00,0x02,0x01,
  1321. 0x28,0x66,0x53,0x7B,0x67,0x67,0x52,0x63,0x6A,0x68, /* a */
  1322. 0xF5,0x65,0x54,0xE1,0x26,0x40,0x27,0x6B,0x64,0x9E,
  1323. 0xF7,0x52,0x62,0x67,
  1324. 0x2E,0x45,0xEF,0x57,0x1F,0x00,0x78,0x6F,0x67,0xB0, /* b */
  1325. 0x08,0x1B,0x94,0x95,0xA3,0xD9,0x54,0x62,0xF5,0xDE,
  1326. 0x0A,0xA1,0x85,0xEC,
  1327. 0x36,0xB3,0xDA,0xF8,0xA2,0x32,0x06,0xF9,0xC4,0xF2, /* x */
  1328. 0x99,0xD7,0xB2,0x1A,0x9C,0x36,0x91,0x37,0xF2,0xC8,
  1329. 0x4A,0xE1,0xAA,0x0D,
  1330. 0x76,0x5B,0xE7,0x34,0x33,0xB3,0xF9,0x5E,0x33,0x29, /* y */
  1331. 0x32,0xE7,0x0E,0xA2,0x45,0xCA,0x24,0x18,0xEA,0x0E,
  1332. 0xF9,0x80,0x18,0xFB,
  1333. 0x40,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  1334. 0x00,0x00,0x04,0xA2,0x0E,0x90,0xC3,0x90,0x67,0xC8,
  1335. 0x93,0xBB,0xB9,0xA5 }
  1336. };
  1337. __fips_constseg
  1338. static const struct { EC_CURVE_DATA h; unsigned char data[20+24*6]; }
  1339. _EC_X9_62_CHAR2_191V2 = {
  1340. { NID_X9_62_characteristic_two_field,20,24,4 },
  1341. { 0x08,0x71,0xEF,0x2F,0xEF,0x24,0xD6,0x96,0xE6,0x76, /* seed */
  1342. 0x87,0x56,0x15,0x17,0x58,0xBE,0xE0,0xD9,0x5C,0x15,
  1343. 0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1344. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1345. 0x00,0x00,0x02,0x01,
  1346. 0x40,0x10,0x28,0x77,0x4D,0x77,0x77,0xC7,0xB7,0x66, /* a */
  1347. 0x6D,0x13,0x66,0xEA,0x43,0x20,0x71,0x27,0x4F,0x89,
  1348. 0xFF,0x01,0xE7,0x18,
  1349. 0x06,0x20,0x04,0x8D,0x28,0xBC,0xBD,0x03,0xB6,0x24, /* b */
  1350. 0x9C,0x99,0x18,0x2B,0x7C,0x8C,0xD1,0x97,0x00,0xC3,
  1351. 0x62,0xC4,0x6A,0x01,
  1352. 0x38,0x09,0xB2,0xB7,0xCC,0x1B,0x28,0xCC,0x5A,0x87, /* x */
  1353. 0x92,0x6A,0xAD,0x83,0xFD,0x28,0x78,0x9E,0x81,0xE2,
  1354. 0xC9,0xE3,0xBF,0x10,
  1355. 0x17,0x43,0x43,0x86,0x62,0x6D,0x14,0xF3,0xDB,0xF0, /* y */
  1356. 0x17,0x60,0xD9,0x21,0x3A,0x3E,0x1C,0xF3,0x7A,0xEC,
  1357. 0x43,0x7D,0x66,0x8A,
  1358. 0x20,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  1359. 0x00,0x00,0x50,0x50,0x8C,0xB8,0x9F,0x65,0x28,0x24,
  1360. 0xE0,0x6B,0x81,0x73 }
  1361. };
  1362. __fips_constseg
  1363. static const struct { EC_CURVE_DATA h; unsigned char data[20+24*6]; }
  1364. _EC_X9_62_CHAR2_191V3 = {
  1365. { NID_X9_62_characteristic_two_field,20,24,6 },
  1366. { 0xE0,0x53,0x51,0x2D,0xC6,0x84,0xD6,0x96,0xE6,0x76, /* seed */
  1367. 0x87,0x56,0x15,0x17,0x50,0x67,0xAE,0x78,0x6D,0x1F,
  1368. 0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1369. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1370. 0x00,0x00,0x02,0x01,
  1371. 0x6C,0x01,0x07,0x47,0x56,0x09,0x91,0x22,0x22,0x10, /* a */
  1372. 0x56,0x91,0x1C,0x77,0xD7,0x7E,0x77,0xA7,0x77,0xE7,
  1373. 0xE7,0xE7,0x7F,0xCB,
  1374. 0x71,0xFE,0x1A,0xF9,0x26,0xCF,0x84,0x79,0x89,0xEF, /* b */
  1375. 0xEF,0x8D,0xB4,0x59,0xF6,0x63,0x94,0xD9,0x0F,0x32,
  1376. 0xAD,0x3F,0x15,0xE8,
  1377. 0x37,0x5D,0x4C,0xE2,0x4F,0xDE,0x43,0x44,0x89,0xDE, /* x */
  1378. 0x87,0x46,0xE7,0x17,0x86,0x01,0x50,0x09,0xE6,0x6E,
  1379. 0x38,0xA9,0x26,0xDD,
  1380. 0x54,0x5A,0x39,0x17,0x61,0x96,0x57,0x5D,0x98,0x59, /* y */
  1381. 0x99,0x36,0x6E,0x6A,0xD3,0x4C,0xE0,0xA7,0x7C,0xD7,
  1382. 0x12,0x7B,0x06,0xBE,
  1383. 0x15,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55, /* order */
  1384. 0x55,0x55,0x61,0x0C,0x0B,0x19,0x68,0x12,0xBF,0xB6,
  1385. 0x28,0x8A,0x3E,0xA3 }
  1386. };
  1387. __fips_constseg
  1388. static const struct { EC_CURVE_DATA h; unsigned char data[0+27*6]; }
  1389. _EC_X9_62_CHAR2_208W1 = {
  1390. { NID_X9_62_characteristic_two_field,0,27,0xFE48 },
  1391. { /* no seed */
  1392. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1393. 0x00,0x00,0x00,0x00,0x00,0x00,0x08,0x00,0x00,0x00,
  1394. 0x00,0x00,0x00,0x00,0x00,0x00,0x07,
  1395. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  1396. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1397. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1398. 0x00,0xC8,0x61,0x9E,0xD4,0x5A,0x62,0xE6,0x21,0x2E, /* b */
  1399. 0x11,0x60,0x34,0x9E,0x2B,0xFA,0x84,0x44,0x39,0xFA,
  1400. 0xFC,0x2A,0x3F,0xD1,0x63,0x8F,0x9E,
  1401. 0x00,0x89,0xFD,0xFB,0xE4,0xAB,0xE1,0x93,0xDF,0x95, /* x */
  1402. 0x59,0xEC,0xF0,0x7A,0xC0,0xCE,0x78,0x55,0x4E,0x27,
  1403. 0x84,0xEB,0x8C,0x1E,0xD1,0xA5,0x7A,
  1404. 0x00,0x0F,0x55,0xB5,0x1A,0x06,0xE7,0x8E,0x9A,0xC3, /* y */
  1405. 0x8A,0x03,0x5F,0xF5,0x20,0xD8,0xB0,0x17,0x81,0xBE,
  1406. 0xB1,0xA6,0xBB,0x08,0x61,0x7D,0xE3,
  1407. 0x00,0x00,0x01,0x01,0xBA,0xF9,0x5C,0x97,0x23,0xC5, /* order */
  1408. 0x7B,0x6C,0x21,0xDA,0x2E,0xFF,0x2D,0x5E,0xD5,0x88,
  1409. 0xBD,0xD5,0x71,0x7E,0x21,0x2F,0x9D }
  1410. };
  1411. __fips_constseg
  1412. static const struct { EC_CURVE_DATA h; unsigned char data[20+30*6]; }
  1413. _EC_X9_62_CHAR2_239V1 = {
  1414. { NID_X9_62_characteristic_two_field,20,30,4 },
  1415. { 0xD3,0x4B,0x9A,0x4D,0x69,0x6E,0x67,0x68,0x75,0x61, /* seed */
  1416. 0x51,0x75,0xCA,0x71,0xB9,0x20,0xBF,0xEF,0xB0,0x5D,
  1417. 0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1418. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1419. 0x00,0x00,0x00,0x00,0x00,0x10,0x00,0x00,0x00,0x01,
  1420. 0x32,0x01,0x08,0x57,0x07,0x7C,0x54,0x31,0x12,0x3A, /* a */
  1421. 0x46,0xB8,0x08,0x90,0x67,0x56,0xF5,0x43,0x42,0x3E,
  1422. 0x8D,0x27,0x87,0x75,0x78,0x12,0x57,0x78,0xAC,0x76,
  1423. 0x79,0x04,0x08,0xF2,0xEE,0xDA,0xF3,0x92,0xB0,0x12, /* b */
  1424. 0xED,0xEF,0xB3,0x39,0x2F,0x30,0xF4,0x32,0x7C,0x0C,
  1425. 0xA3,0xF3,0x1F,0xC3,0x83,0xC4,0x22,0xAA,0x8C,0x16,
  1426. 0x57,0x92,0x70,0x98,0xFA,0x93,0x2E,0x7C,0x0A,0x96, /* x */
  1427. 0xD3,0xFD,0x5B,0x70,0x6E,0xF7,0xE5,0xF5,0xC1,0x56,
  1428. 0xE1,0x6B,0x7E,0x7C,0x86,0x03,0x85,0x52,0xE9,0x1D,
  1429. 0x61,0xD8,0xEE,0x50,0x77,0xC3,0x3F,0xEC,0xF6,0xF1, /* y */
  1430. 0xA1,0x6B,0x26,0x8D,0xE4,0x69,0xC3,0xC7,0x74,0x4E,
  1431. 0xA9,0xA9,0x71,0x64,0x9F,0xC7,0xA9,0x61,0x63,0x05,
  1432. 0x20,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* order */
  1433. 0x00,0x00,0x00,0x00,0x00,0x0F,0x4D,0x42,0xFF,0xE1,
  1434. 0x49,0x2A,0x49,0x93,0xF1,0xCA,0xD6,0x66,0xE4,0x47 }
  1435. };
  1436. __fips_constseg
  1437. static const struct { EC_CURVE_DATA h; unsigned char data[20+30*6]; }
  1438. _EC_X9_62_CHAR2_239V2 = {
  1439. { NID_X9_62_characteristic_two_field,20,30,6 },
  1440. { 0x2A,0xA6,0x98,0x2F,0xDF,0xA4,0xD6,0x96,0xE6,0x76, /* seed */
  1441. 0x87,0x56,0x15,0x17,0x5D,0x26,0x67,0x27,0x27,0x7D,
  1442. 0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1443. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1444. 0x00,0x00,0x00,0x00,0x00,0x10,0x00,0x00,0x00,0x01,
  1445. 0x42,0x30,0x01,0x77,0x57,0xA7,0x67,0xFA,0xE4,0x23, /* a */
  1446. 0x98,0x56,0x9B,0x74,0x63,0x25,0xD4,0x53,0x13,0xAF,
  1447. 0x07,0x66,0x26,0x64,0x79,0xB7,0x56,0x54,0xE6,0x5F,
  1448. 0x50,0x37,0xEA,0x65,0x41,0x96,0xCF,0xF0,0xCD,0x82, /* b */
  1449. 0xB2,0xC1,0x4A,0x2F,0xCF,0x2E,0x3F,0xF8,0x77,0x52,
  1450. 0x85,0xB5,0x45,0x72,0x2F,0x03,0xEA,0xCD,0xB7,0x4B,
  1451. 0x28,0xF9,0xD0,0x4E,0x90,0x00,0x69,0xC8,0xDC,0x47, /* x */
  1452. 0xA0,0x85,0x34,0xFE,0x76,0xD2,0xB9,0x00,0xB7,0xD7,
  1453. 0xEF,0x31,0xF5,0x70,0x9F,0x20,0x0C,0x4C,0xA2,0x05,
  1454. 0x56,0x67,0x33,0x4C,0x45,0xAF,0xF3,0xB5,0xA0,0x3B, /* y */
  1455. 0xAD,0x9D,0xD7,0x5E,0x2C,0x71,0xA9,0x93,0x62,0x56,
  1456. 0x7D,0x54,0x53,0xF7,0xFA,0x6E,0x22,0x7E,0xC8,0x33,
  1457. 0x15,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55,0x55, /* order */
  1458. 0x55,0x55,0x55,0x55,0x55,0x3C,0x6F,0x28,0x85,0x25,
  1459. 0x9C,0x31,0xE3,0xFC,0xDF,0x15,0x46,0x24,0x52,0x2D }
  1460. };
  1461. __fips_constseg
  1462. static const struct { EC_CURVE_DATA h; unsigned char data[20+30*6]; }
  1463. _EC_X9_62_CHAR2_239V3 = {
  1464. { NID_X9_62_characteristic_two_field,20,30,0xA },
  1465. { 0x9E,0x07,0x6F,0x4D,0x69,0x6E,0x67,0x68,0x75,0x61, /* seed */
  1466. 0x51,0x75,0xE1,0x1E,0x9F,0xDD,0x77,0xF9,0x20,0x41,
  1467. 0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1468. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1469. 0x00,0x00,0x00,0x00,0x00,0x10,0x00,0x00,0x00,0x01,
  1470. 0x01,0x23,0x87,0x74,0x66,0x6A,0x67,0x76,0x6D,0x66, /* a */
  1471. 0x76,0xF7,0x78,0xE6,0x76,0xB6,0x69,0x99,0x17,0x66,
  1472. 0x66,0xE6,0x87,0x66,0x6D,0x87,0x66,0xC6,0x6A,0x9F,
  1473. 0x6A,0x94,0x19,0x77,0xBA,0x9F,0x6A,0x43,0x51,0x99, /* b */
  1474. 0xAC,0xFC,0x51,0x06,0x7E,0xD5,0x87,0xF5,0x19,0xC5,
  1475. 0xEC,0xB5,0x41,0xB8,0xE4,0x41,0x11,0xDE,0x1D,0x40,
  1476. 0x70,0xF6,0xE9,0xD0,0x4D,0x28,0x9C,0x4E,0x89,0x91, /* x */
  1477. 0x3C,0xE3,0x53,0x0B,0xFD,0xE9,0x03,0x97,0x7D,0x42,
  1478. 0xB1,0x46,0xD5,0x39,0xBF,0x1B,0xDE,0x4E,0x9C,0x92,
  1479. 0x2E,0x5A,0x0E,0xAF,0x6E,0x5E,0x13,0x05,0xB9,0x00, /* y */
  1480. 0x4D,0xCE,0x5C,0x0E,0xD7,0xFE,0x59,0xA3,0x56,0x08,
  1481. 0xF3,0x38,0x37,0xC8,0x16,0xD8,0x0B,0x79,0xF4,0x61,
  1482. 0x0C,0xCC,0xCC,0xCC,0xCC,0xCC,0xCC,0xCC,0xCC,0xCC, /* order */
  1483. 0xCC,0xCC,0xCC,0xCC,0xCC,0xAC,0x49,0x12,0xD2,0xD9,
  1484. 0xDF,0x90,0x3E,0xF9,0x88,0x8B,0x8A,0x0E,0x4C,0xFF }
  1485. };
  1486. __fips_constseg
  1487. static const struct { EC_CURVE_DATA h; unsigned char data[0+35*6]; }
  1488. _EC_X9_62_CHAR2_272W1 = {
  1489. { NID_X9_62_characteristic_two_field,0,35,0xFF06 },
  1490. { /* no seed */
  1491. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1492. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1493. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x00,0x00,
  1494. 0x00,0x00,0x00,0x00,0x0B,
  1495. 0x00,0x91,0xA0,0x91,0xF0,0x3B,0x5F,0xBA,0x4A,0xB2, /* a */
  1496. 0xCC,0xF4,0x9C,0x4E,0xDD,0x22,0x0F,0xB0,0x28,0x71,
  1497. 0x2D,0x42,0xBE,0x75,0x2B,0x2C,0x40,0x09,0x4D,0xBA,
  1498. 0xCD,0xB5,0x86,0xFB,0x20,
  1499. 0x00,0x71,0x67,0xEF,0xC9,0x2B,0xB2,0xE3,0xCE,0x7C, /* b */
  1500. 0x8A,0xAA,0xFF,0x34,0xE1,0x2A,0x9C,0x55,0x70,0x03,
  1501. 0xD7,0xC7,0x3A,0x6F,0xAF,0x00,0x3F,0x99,0xF6,0xCC,
  1502. 0x84,0x82,0xE5,0x40,0xF7,
  1503. 0x00,0x61,0x08,0xBA,0xBB,0x2C,0xEE,0xBC,0xF7,0x87, /* x */
  1504. 0x05,0x8A,0x05,0x6C,0xBE,0x0C,0xFE,0x62,0x2D,0x77,
  1505. 0x23,0xA2,0x89,0xE0,0x8A,0x07,0xAE,0x13,0xEF,0x0D,
  1506. 0x10,0xD1,0x71,0xDD,0x8D,
  1507. 0x00,0x10,0xC7,0x69,0x57,0x16,0x85,0x1E,0xEF,0x6B, /* y */
  1508. 0xA7,0xF6,0x87,0x2E,0x61,0x42,0xFB,0xD2,0x41,0xB8,
  1509. 0x30,0xFF,0x5E,0xFC,0xAC,0xEC,0xCA,0xB0,0x5E,0x02,
  1510. 0x00,0x5D,0xDE,0x9D,0x23,
  1511. 0x00,0x00,0x01,0x00,0xFA,0xF5,0x13,0x54,0xE0,0xE3, /* order */
  1512. 0x9E,0x48,0x92,0xDF,0x6E,0x31,0x9C,0x72,0xC8,0x16,
  1513. 0x16,0x03,0xFA,0x45,0xAA,0x7B,0x99,0x8A,0x16,0x7B,
  1514. 0x8F,0x1E,0x62,0x95,0x21 }
  1515. };
  1516. __fips_constseg
  1517. static const struct { EC_CURVE_DATA h; unsigned char data[0+39*6]; }
  1518. _EC_X9_62_CHAR2_304W1 = {
  1519. { NID_X9_62_characteristic_two_field,0,39,0xFE2E },
  1520. { /* no seed */
  1521. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1522. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1523. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1524. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x08,0x07,
  1525. 0x00,0xFD,0x0D,0x69,0x31,0x49,0xA1,0x18,0xF6,0x51, /* a */
  1526. 0xE6,0xDC,0xE6,0x80,0x20,0x85,0x37,0x7E,0x5F,0x88,
  1527. 0x2D,0x1B,0x51,0x0B,0x44,0x16,0x00,0x74,0xC1,0x28,
  1528. 0x80,0x78,0x36,0x5A,0x03,0x96,0xC8,0xE6,0x81,
  1529. 0x00,0xBD,0xDB,0x97,0xE5,0x55,0xA5,0x0A,0x90,0x8E, /* b */
  1530. 0x43,0xB0,0x1C,0x79,0x8E,0xA5,0xDA,0xA6,0x78,0x8F,
  1531. 0x1E,0xA2,0x79,0x4E,0xFC,0xF5,0x71,0x66,0xB8,0xC1,
  1532. 0x40,0x39,0x60,0x1E,0x55,0x82,0x73,0x40,0xBE,
  1533. 0x00,0x19,0x7B,0x07,0x84,0x5E,0x9B,0xE2,0xD9,0x6A, /* x */
  1534. 0xDB,0x0F,0x5F,0x3C,0x7F,0x2C,0xFF,0xBD,0x7A,0x3E,
  1535. 0xB8,0xB6,0xFE,0xC3,0x5C,0x7F,0xD6,0x7F,0x26,0xDD,
  1536. 0xF6,0x28,0x5A,0x64,0x4F,0x74,0x0A,0x26,0x14,
  1537. 0x00,0xE1,0x9F,0xBE,0xB7,0x6E,0x0D,0xA1,0x71,0x51, /* y */
  1538. 0x7E,0xCF,0x40,0x1B,0x50,0x28,0x9B,0xF0,0x14,0x10,
  1539. 0x32,0x88,0x52,0x7A,0x9B,0x41,0x6A,0x10,0x5E,0x80,
  1540. 0x26,0x0B,0x54,0x9F,0xDC,0x1B,0x92,0xC0,0x3B,
  1541. 0x00,0x00,0x01,0x01,0xD5,0x56,0x57,0x2A,0xAB,0xAC, /* order */
  1542. 0x80,0x01,0x01,0xD5,0x56,0x57,0x2A,0xAB,0xAC,0x80,
  1543. 0x01,0x02,0x2D,0x5C,0x91,0xDD,0x17,0x3F,0x8F,0xB5,
  1544. 0x61,0xDA,0x68,0x99,0x16,0x44,0x43,0x05,0x1D }
  1545. };
  1546. __fips_constseg
  1547. static const struct { EC_CURVE_DATA h; unsigned char data[20+45*6]; }
  1548. _EC_X9_62_CHAR2_359V1 = {
  1549. { NID_X9_62_characteristic_two_field,20,45,0x4C },
  1550. { 0x2B,0x35,0x49,0x20,0xB7,0x24,0xD6,0x96,0xE6,0x76, /* seed */
  1551. 0x87,0x56,0x15,0x17,0x58,0x5B,0xA1,0x33,0x2D,0xC6,
  1552. 0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1553. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1554. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1555. 0x00,0x00,0x00,0x00,0x00,0x00,0x10,0x00,0x00,0x00,
  1556. 0x00,0x00,0x00,0x00,0x01,
  1557. 0x56,0x67,0x67,0x6A,0x65,0x4B,0x20,0x75,0x4F,0x35, /* a */
  1558. 0x6E,0xA9,0x20,0x17,0xD9,0x46,0x56,0x7C,0x46,0x67,
  1559. 0x55,0x56,0xF1,0x95,0x56,0xA0,0x46,0x16,0xB5,0x67,
  1560. 0xD2,0x23,0xA5,0xE0,0x56,0x56,0xFB,0x54,0x90,0x16,
  1561. 0xA9,0x66,0x56,0xA5,0x57,
  1562. 0x24,0x72,0xE2,0xD0,0x19,0x7C,0x49,0x36,0x3F,0x1F, /* b */
  1563. 0xE7,0xF5,0xB6,0xDB,0x07,0x5D,0x52,0xB6,0x94,0x7D,
  1564. 0x13,0x5D,0x8C,0xA4,0x45,0x80,0x5D,0x39,0xBC,0x34,
  1565. 0x56,0x26,0x08,0x96,0x87,0x74,0x2B,0x63,0x29,0xE7,
  1566. 0x06,0x80,0x23,0x19,0x88,
  1567. 0x3C,0x25,0x8E,0xF3,0x04,0x77,0x67,0xE7,0xED,0xE0, /* x */
  1568. 0xF1,0xFD,0xAA,0x79,0xDA,0xEE,0x38,0x41,0x36,0x6A,
  1569. 0x13,0x2E,0x16,0x3A,0xCE,0xD4,0xED,0x24,0x01,0xDF,
  1570. 0x9C,0x6B,0xDC,0xDE,0x98,0xE8,0xE7,0x07,0xC0,0x7A,
  1571. 0x22,0x39,0xB1,0xB0,0x97,
  1572. 0x53,0xD7,0xE0,0x85,0x29,0x54,0x70,0x48,0x12,0x1E, /* y */
  1573. 0x9C,0x95,0xF3,0x79,0x1D,0xD8,0x04,0x96,0x39,0x48,
  1574. 0xF3,0x4F,0xAE,0x7B,0xF4,0x4E,0xA8,0x23,0x65,0xDC,
  1575. 0x78,0x68,0xFE,0x57,0xE4,0xAE,0x2D,0xE2,0x11,0x30,
  1576. 0x5A,0x40,0x71,0x04,0xBD,
  1577. 0x01,0xAF,0x28,0x6B,0xCA,0x1A,0xF2,0x86,0xBC,0xA1, /* order */
  1578. 0xAF,0x28,0x6B,0xCA,0x1A,0xF2,0x86,0xBC,0xA1,0xAF,
  1579. 0x28,0x6B,0xC9,0xFB,0x8F,0x6B,0x85,0xC5,0x56,0x89,
  1580. 0x2C,0x20,0xA7,0xEB,0x96,0x4F,0xE7,0x71,0x9E,0x74,
  1581. 0xF4,0x90,0x75,0x8D,0x3B }
  1582. };
  1583. __fips_constseg
  1584. static const struct { EC_CURVE_DATA h; unsigned char data[0+47*6]; }
  1585. _EC_X9_62_CHAR2_368W1 = {
  1586. { NID_X9_62_characteristic_two_field,0,47,0xFF70 },
  1587. { /* no seed */
  1588. 0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1589. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1590. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1591. 0x00,0x00,0x00,0x00,0x00,0x00,0x20,0x00,0x00,0x00,
  1592. 0x00,0x00,0x00,0x00,0x00,0x00,0x07,
  1593. 0x00,0xE0,0xD2,0xEE,0x25,0x09,0x52,0x06,0xF5,0xE2, /* a */
  1594. 0xA4,0xF9,0xED,0x22,0x9F,0x1F,0x25,0x6E,0x79,0xA0,
  1595. 0xE2,0xB4,0x55,0x97,0x0D,0x8D,0x0D,0x86,0x5B,0xD9,
  1596. 0x47,0x78,0xC5,0x76,0xD6,0x2F,0x0A,0xB7,0x51,0x9C,
  1597. 0xCD,0x2A,0x1A,0x90,0x6A,0xE3,0x0D,
  1598. 0x00,0xFC,0x12,0x17,0xD4,0x32,0x0A,0x90,0x45,0x2C, /* b */
  1599. 0x76,0x0A,0x58,0xED,0xCD,0x30,0xC8,0xDD,0x06,0x9B,
  1600. 0x3C,0x34,0x45,0x38,0x37,0xA3,0x4E,0xD5,0x0C,0xB5,
  1601. 0x49,0x17,0xE1,0xC2,0x11,0x2D,0x84,0xD1,0x64,0xF4,
  1602. 0x44,0xF8,0xF7,0x47,0x86,0x04,0x6A,
  1603. 0x00,0x10,0x85,0xE2,0x75,0x53,0x81,0xDC,0xCC,0xE3, /* x */
  1604. 0xC1,0x55,0x7A,0xFA,0x10,0xC2,0xF0,0xC0,0xC2,0x82,
  1605. 0x56,0x46,0xC5,0xB3,0x4A,0x39,0x4C,0xBC,0xFA,0x8B,
  1606. 0xC1,0x6B,0x22,0xE7,0xE7,0x89,0xE9,0x27,0xBE,0x21,
  1607. 0x6F,0x02,0xE1,0xFB,0x13,0x6A,0x5F,
  1608. 0x00,0x7B,0x3E,0xB1,0xBD,0xDC,0xBA,0x62,0xD5,0xD8, /* y */
  1609. 0xB2,0x05,0x9B,0x52,0x57,0x97,0xFC,0x73,0x82,0x2C,
  1610. 0x59,0x05,0x9C,0x62,0x3A,0x45,0xFF,0x38,0x43,0xCE,
  1611. 0xE8,0xF8,0x7C,0xD1,0x85,0x5A,0xDA,0xA8,0x1E,0x2A,
  1612. 0x07,0x50,0xB8,0x0F,0xDA,0x23,0x10,
  1613. 0x00,0x00,0x01,0x00,0x90,0x51,0x2D,0xA9,0xAF,0x72, /* order */
  1614. 0xB0,0x83,0x49,0xD9,0x8A,0x5D,0xD4,0xC7,0xB0,0x53,
  1615. 0x2E,0xCA,0x51,0xCE,0x03,0xE2,0xD1,0x0F,0x3B,0x7A,
  1616. 0xC5,0x79,0xBD,0x87,0xE9,0x09,0xAE,0x40,0xA6,0xF1,
  1617. 0x31,0xE9,0xCF,0xCE,0x5B,0xD9,0x67 }
  1618. };
  1619. __fips_constseg
  1620. static const struct { EC_CURVE_DATA h; unsigned char data[0+54*6]; }
  1621. _EC_X9_62_CHAR2_431R1 = {
  1622. { NID_X9_62_characteristic_two_field,0,54,0x2760 },
  1623. { /* no seed */
  1624. 0x80,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1625. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1626. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1627. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0x00,
  1628. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1629. 0x00,0x00,0x00,0x01,
  1630. 0x1A,0x82,0x7E,0xF0,0x0D,0xD6,0xFC,0x0E,0x23,0x4C, /* a */
  1631. 0xAF,0x04,0x6C,0x6A,0x5D,0x8A,0x85,0x39,0x5B,0x23,
  1632. 0x6C,0xC4,0xAD,0x2C,0xF3,0x2A,0x0C,0xAD,0xBD,0xC9,
  1633. 0xDD,0xF6,0x20,0xB0,0xEB,0x99,0x06,0xD0,0x95,0x7F,
  1634. 0x6C,0x6F,0xEA,0xCD,0x61,0x54,0x68,0xDF,0x10,0x4D,
  1635. 0xE2,0x96,0xCD,0x8F,
  1636. 0x10,0xD9,0xB4,0xA3,0xD9,0x04,0x7D,0x8B,0x15,0x43, /* b */
  1637. 0x59,0xAB,0xFB,0x1B,0x7F,0x54,0x85,0xB0,0x4C,0xEB,
  1638. 0x86,0x82,0x37,0xDD,0xC9,0xDE,0xDA,0x98,0x2A,0x67,
  1639. 0x9A,0x5A,0x91,0x9B,0x62,0x6D,0x4E,0x50,0xA8,0xDD,
  1640. 0x73,0x1B,0x10,0x7A,0x99,0x62,0x38,0x1F,0xB5,0xD8,
  1641. 0x07,0xBF,0x26,0x18,
  1642. 0x12,0x0F,0xC0,0x5D,0x3C,0x67,0xA9,0x9D,0xE1,0x61, /* x */
  1643. 0xD2,0xF4,0x09,0x26,0x22,0xFE,0xCA,0x70,0x1B,0xE4,
  1644. 0xF5,0x0F,0x47,0x58,0x71,0x4E,0x8A,0x87,0xBB,0xF2,
  1645. 0xA6,0x58,0xEF,0x8C,0x21,0xE7,0xC5,0xEF,0xE9,0x65,
  1646. 0x36,0x1F,0x6C,0x29,0x99,0xC0,0xC2,0x47,0xB0,0xDB,
  1647. 0xD7,0x0C,0xE6,0xB7,
  1648. 0x20,0xD0,0xAF,0x89,0x03,0xA9,0x6F,0x8D,0x5F,0xA2, /* y */
  1649. 0xC2,0x55,0x74,0x5D,0x3C,0x45,0x1B,0x30,0x2C,0x93,
  1650. 0x46,0xD9,0xB7,0xE4,0x85,0xE7,0xBC,0xE4,0x1F,0x6B,
  1651. 0x59,0x1F,0x3E,0x8F,0x6A,0xDD,0xCB,0xB0,0xBC,0x4C,
  1652. 0x2F,0x94,0x7A,0x7D,0xE1,0xA8,0x9B,0x62,0x5D,0x6A,
  1653. 0x59,0x8B,0x37,0x60,
  1654. 0x00,0x03,0x40,0x34,0x03,0x40,0x34,0x03,0x40,0x34, /* order */
  1655. 0x03,0x40,0x34,0x03,0x40,0x34,0x03,0x40,0x34,0x03,
  1656. 0x40,0x34,0x03,0x40,0x34,0x03,0x40,0x34,0x03,0x23,
  1657. 0xC3,0x13,0xFA,0xB5,0x05,0x89,0x70,0x3B,0x5E,0xC6,
  1658. 0x8D,0x35,0x87,0xFE,0xC6,0x0D,0x16,0x1C,0xC1,0x49,
  1659. 0xC1,0xAD,0x4A,0x91 }
  1660. };
  1661. __fips_constseg
  1662. static const struct { EC_CURVE_DATA h; unsigned char data[0+15*6]; }
  1663. _EC_WTLS_1 = {
  1664. { NID_X9_62_characteristic_two_field,0,15,2 },
  1665. { /* no seed */
  1666. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1667. 0x00,0x00,0x00,0x02,0x01,
  1668. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  1669. 0x00,0x00,0x00,0x00,0x01,
  1670. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  1671. 0x00,0x00,0x00,0x00,0x01,
  1672. 0x01,0x66,0x79,0x79,0xA4,0x0B,0xA4,0x97,0xE5,0xD5, /* x */
  1673. 0xC2,0x70,0x78,0x06,0x17,
  1674. 0x00,0xF4,0x4B,0x4A,0xF1,0xEC,0xC2,0x63,0x0E,0x08, /* y */
  1675. 0x78,0x5C,0xEB,0xCC,0x15,
  1676. 0x00,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFD,0xBF, /* order */
  1677. 0x91,0xAF,0x6D,0xEA,0x73 }
  1678. };
  1679. /* IPSec curves */
  1680. /* NOTE: The of curves over a extension field of non prime degree
  1681. * is not recommended (Weil-descent).
  1682. * As the group order is not a prime this curve is not suitable
  1683. * for ECDSA.
  1684. */
  1685. __fips_constseg
  1686. static const struct { EC_CURVE_DATA h; unsigned char data[0+20*6]; }
  1687. _EC_IPSEC_155_ID3 = {
  1688. { NID_X9_62_characteristic_two_field,0,20,3 },
  1689. { /* no seed */
  1690. 0x08,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1691. 0x00,0x00,0x40,0x00,0x00,0x00,0x00,0x00,0x00,0x01,
  1692. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  1693. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1694. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  1695. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x07,0x33,0x8f,
  1696. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* x */
  1697. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x7b,
  1698. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* y */
  1699. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x01,0xc8,
  1700. 0x02,0xAA,0xAA,0xAA,0xAA,0xAA,0xAA,0xAA,0xAA,0xAA, /* order */
  1701. 0xC7,0xF3,0xC7,0x88,0x1B,0xD0,0x86,0x8F,0xA8,0x6C }
  1702. };
  1703. /* NOTE: The of curves over a extension field of non prime degree
  1704. * is not recommended (Weil-descent).
  1705. * As the group order is not a prime this curve is not suitable
  1706. * for ECDSA.
  1707. */
  1708. __fips_constseg
  1709. static const struct { EC_CURVE_DATA h; unsigned char data[0+24*6]; }
  1710. _EC_IPSEC_185_ID4 = {
  1711. { NID_X9_62_characteristic_two_field,0,24,2 },
  1712. { /* no seed */
  1713. 0x02,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* p */
  1714. 0x00,0x00,0x00,0x00,0x00,0x20,0x00,0x00,0x00,0x00,
  1715. 0x00,0x00,0x00,0x01,
  1716. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* a */
  1717. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1718. 0x00,0x00,0x00,0x00,
  1719. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* b */
  1720. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1721. 0x00,0x00,0x1e,0xe9,
  1722. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* x */
  1723. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1724. 0x00,0x00,0x00,0x18,
  1725. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00, /* y */
  1726. 0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
  1727. 0x00,0x00,0x00,0x0d,
  1728. 0x00,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF, /* order */
  1729. 0xFF,0xFF,0xED,0xF9,0x7C,0x44,0xDB,0x9F,0x24,0x20,
  1730. 0xBA,0xFC,0xA7,0x5E }
  1731. };
  1732. #endif
  1733. typedef struct _ec_list_element_st {
  1734. int nid;
  1735. const EC_CURVE_DATA *data;
  1736. const EC_METHOD *(*meth)(void);
  1737. const char *comment;
  1738. } ec_list_element;
  1739. static const ec_list_element curve_list[] = {
  1740. /* prime field curves */
  1741. /* secg curves */
  1742. { NID_secp112r1, &_EC_SECG_PRIME_112R1.h, 0, "SECG/WTLS curve over a 112 bit prime field" },
  1743. { NID_secp112r2, &_EC_SECG_PRIME_112R2.h, 0, "SECG curve over a 112 bit prime field" },
  1744. { NID_secp128r1, &_EC_SECG_PRIME_128R1.h, 0, "SECG curve over a 128 bit prime field" },
  1745. { NID_secp128r2, &_EC_SECG_PRIME_128R2.h, 0, "SECG curve over a 128 bit prime field" },
  1746. { NID_secp160k1, &_EC_SECG_PRIME_160K1.h, 0, "SECG curve over a 160 bit prime field" },
  1747. { NID_secp160r1, &_EC_SECG_PRIME_160R1.h, 0, "SECG curve over a 160 bit prime field" },
  1748. { NID_secp160r2, &_EC_SECG_PRIME_160R2.h, 0, "SECG/WTLS curve over a 160 bit prime field" },
  1749. /* SECG secp192r1 is the same as X9.62 prime192v1 and hence omitted */
  1750. { NID_secp192k1, &_EC_SECG_PRIME_192K1.h, 0, "SECG curve over a 192 bit prime field" },
  1751. { NID_secp224k1, &_EC_SECG_PRIME_224K1.h, 0, "SECG curve over a 224 bit prime field" },
  1752. #ifdef EC_NISTP224_64_GCC_128
  1753. { NID_secp224r1, &_EC_NIST_PRIME_224.h, EC_GFp_nistp224_method, "NIST/SECG curve over a 224 bit prime field,\n"
  1754. "\t\t64-bit optimized implementation." },
  1755. #else
  1756. { NID_secp224r1, &_EC_NIST_PRIME_224.h, 0, "NIST/SECG curve over a 224 bit prime field" },
  1757. #endif
  1758. { NID_secp256k1, &_EC_SECG_PRIME_256K1.h, 0, "SECG curve over a 256 bit prime field" },
  1759. /* SECG secp256r1 is the same as X9.62 prime256v1 and hence omitted */
  1760. { NID_secp384r1, &_EC_NIST_PRIME_384.h, 0, "NIST/SECG curve over a 384 bit prime field" },
  1761. { NID_secp521r1, &_EC_NIST_PRIME_521.h, 0, "NIST/SECG curve over a 521 bit prime field" },
  1762. /* X9.62 curves */
  1763. { NID_X9_62_prime192v1, &_EC_NIST_PRIME_192.h, 0, "NIST/X9.62/SECG curve over a 192 bit prime field" },
  1764. { NID_X9_62_prime192v2, &_EC_X9_62_PRIME_192V2.h, 0, "X9.62 curve over a 192 bit prime field" },
  1765. { NID_X9_62_prime192v3, &_EC_X9_62_PRIME_192V3.h, 0, "X9.62 curve over a 192 bit prime field" },
  1766. { NID_X9_62_prime239v1, &_EC_X9_62_PRIME_239V1.h, 0, "X9.62 curve over a 239 bit prime field" },
  1767. { NID_X9_62_prime239v2, &_EC_X9_62_PRIME_239V2.h, 0, "X9.62 curve over a 239 bit prime field" },
  1768. { NID_X9_62_prime239v3, &_EC_X9_62_PRIME_239V3.h, 0, "X9.62 curve over a 239 bit prime field" },
  1769. { NID_X9_62_prime256v1, &_EC_X9_62_PRIME_256V1.h, 0, "X9.62/SECG curve over a 256 bit prime field" },
  1770. #ifndef OPENSSL_NO_EC2M
  1771. /* characteristic two field curves */
  1772. /* NIST/SECG curves */
  1773. { NID_sect113r1, &_EC_SECG_CHAR2_113R1.h, 0, "SECG curve over a 113 bit binary field" },
  1774. { NID_sect113r2, &_EC_SECG_CHAR2_113R2.h, 0, "SECG curve over a 113 bit binary field" },
  1775. { NID_sect131r1, &_EC_SECG_CHAR2_131R1.h, 0, "SECG/WTLS curve over a 131 bit binary field" },
  1776. { NID_sect131r2, &_EC_SECG_CHAR2_131R2.h, 0, "SECG curve over a 131 bit binary field" },
  1777. { NID_sect163k1, &_EC_NIST_CHAR2_163K.h, 0, "NIST/SECG/WTLS curve over a 163 bit binary field" },
  1778. { NID_sect163r1, &_EC_SECG_CHAR2_163R1.h, 0, "SECG curve over a 163 bit binary field" },
  1779. { NID_sect163r2, &_EC_NIST_CHAR2_163B.h, 0, "NIST/SECG curve over a 163 bit binary field" },
  1780. { NID_sect193r1, &_EC_SECG_CHAR2_193R1.h, 0, "SECG curve over a 193 bit binary field" },
  1781. { NID_sect193r2, &_EC_SECG_CHAR2_193R2.h, 0, "SECG curve over a 193 bit binary field" },
  1782. { NID_sect233k1, &_EC_NIST_CHAR2_233K.h, 0, "NIST/SECG/WTLS curve over a 233 bit binary field" },
  1783. { NID_sect233r1, &_EC_NIST_CHAR2_233B.h, 0, "NIST/SECG/WTLS curve over a 233 bit binary field" },
  1784. { NID_sect239k1, &_EC_SECG_CHAR2_239K1.h, 0, "SECG curve over a 239 bit binary field" },
  1785. { NID_sect283k1, &_EC_NIST_CHAR2_283K.h, 0, "NIST/SECG curve over a 283 bit binary field" },
  1786. { NID_sect283r1, &_EC_NIST_CHAR2_283B.h, 0, "NIST/SECG curve over a 283 bit binary field" },
  1787. { NID_sect409k1, &_EC_NIST_CHAR2_409K.h, 0, "NIST/SECG curve over a 409 bit binary field" },
  1788. { NID_sect409r1, &_EC_NIST_CHAR2_409B.h, 0, "NIST/SECG curve over a 409 bit binary field" },
  1789. { NID_sect571k1, &_EC_NIST_CHAR2_571K.h, 0, "NIST/SECG curve over a 571 bit binary field" },
  1790. { NID_sect571r1, &_EC_NIST_CHAR2_571B.h, 0, "NIST/SECG curve over a 571 bit binary field" },
  1791. /* X9.62 curves */
  1792. { NID_X9_62_c2pnb163v1, &_EC_X9_62_CHAR2_163V1.h, 0, "X9.62 curve over a 163 bit binary field" },
  1793. { NID_X9_62_c2pnb163v2, &_EC_X9_62_CHAR2_163V2.h, 0, "X9.62 curve over a 163 bit binary field" },
  1794. { NID_X9_62_c2pnb163v3, &_EC_X9_62_CHAR2_163V3.h, 0, "X9.62 curve over a 163 bit binary field" },
  1795. { NID_X9_62_c2pnb176v1, &_EC_X9_62_CHAR2_176V1.h, 0, "X9.62 curve over a 176 bit binary field" },
  1796. { NID_X9_62_c2tnb191v1, &_EC_X9_62_CHAR2_191V1.h, 0, "X9.62 curve over a 191 bit binary field" },
  1797. { NID_X9_62_c2tnb191v2, &_EC_X9_62_CHAR2_191V2.h, 0, "X9.62 curve over a 191 bit binary field" },
  1798. { NID_X9_62_c2tnb191v3, &_EC_X9_62_CHAR2_191V3.h, 0, "X9.62 curve over a 191 bit binary field" },
  1799. { NID_X9_62_c2pnb208w1, &_EC_X9_62_CHAR2_208W1.h, 0, "X9.62 curve over a 208 bit binary field" },
  1800. { NID_X9_62_c2tnb239v1, &_EC_X9_62_CHAR2_239V1.h, 0, "X9.62 curve over a 239 bit binary field" },
  1801. { NID_X9_62_c2tnb239v2, &_EC_X9_62_CHAR2_239V2.h, 0, "X9.62 curve over a 239 bit binary field" },
  1802. { NID_X9_62_c2tnb239v3, &_EC_X9_62_CHAR2_239V3.h, 0, "X9.62 curve over a 239 bit binary field" },
  1803. { NID_X9_62_c2pnb272w1, &_EC_X9_62_CHAR2_272W1.h, 0, "X9.62 curve over a 272 bit binary field" },
  1804. { NID_X9_62_c2pnb304w1, &_EC_X9_62_CHAR2_304W1.h, 0, "X9.62 curve over a 304 bit binary field" },
  1805. { NID_X9_62_c2tnb359v1, &_EC_X9_62_CHAR2_359V1.h, 0, "X9.62 curve over a 359 bit binary field" },
  1806. { NID_X9_62_c2pnb368w1, &_EC_X9_62_CHAR2_368W1.h, 0, "X9.62 curve over a 368 bit binary field" },
  1807. { NID_X9_62_c2tnb431r1, &_EC_X9_62_CHAR2_431R1.h, 0, "X9.62 curve over a 431 bit binary field" },
  1808. /* the WAP/WTLS curves
  1809. * [unlike SECG, spec has its own OIDs for curves from X9.62] */
  1810. { NID_wap_wsg_idm_ecid_wtls1, &_EC_WTLS_1.h, 0, "WTLS curve over a 113 bit binary field" },
  1811. { NID_wap_wsg_idm_ecid_wtls3, &_EC_NIST_CHAR2_163K.h, 0, "NIST/SECG/WTLS curve over a 163 bit binary field" },
  1812. { NID_wap_wsg_idm_ecid_wtls4, &_EC_SECG_CHAR2_113R1.h, 0, "SECG curve over a 113 bit binary field" },
  1813. { NID_wap_wsg_idm_ecid_wtls5, &_EC_X9_62_CHAR2_163V1.h, 0, "X9.62 curve over a 163 bit binary field" },
  1814. #endif
  1815. { NID_wap_wsg_idm_ecid_wtls6, &_EC_SECG_PRIME_112R1.h, 0, "SECG/WTLS curve over a 112 bit prime field" },
  1816. { NID_wap_wsg_idm_ecid_wtls7, &_EC_SECG_PRIME_160R2.h, 0, "SECG/WTLS curve over a 160 bit prime field" },
  1817. { NID_wap_wsg_idm_ecid_wtls8, &_EC_WTLS_8.h, 0, "WTLS curve over a 112 bit prime field" },
  1818. { NID_wap_wsg_idm_ecid_wtls9, &_EC_WTLS_9.h, 0, "WTLS curve over a 160 bit prime field" },
  1819. #ifndef OPENSSL_NO_EC2M
  1820. { NID_wap_wsg_idm_ecid_wtls10, &_EC_NIST_CHAR2_233K.h, 0, "NIST/SECG/WTLS curve over a 233 bit binary field" },
  1821. { NID_wap_wsg_idm_ecid_wtls11, &_EC_NIST_CHAR2_233B.h, 0, "NIST/SECG/WTLS curve over a 233 bit binary field" },
  1822. #endif
  1823. { NID_wap_wsg_idm_ecid_wtls12, &_EC_WTLS_12.h, 0, "WTLS curvs over a 224 bit prime field" },
  1824. #ifndef OPENSSL_NO_EC2M
  1825. /* IPSec curves */
  1826. { NID_ipsec3, &_EC_IPSEC_155_ID3.h, 0, "\n\tIPSec/IKE/Oakley curve #3 over a 155 bit binary field.\n"
  1827. "\tNot suitable for ECDSA.\n\tQuestionable extension field!" },
  1828. { NID_ipsec4, &_EC_IPSEC_185_ID4.h, 0, "\n\tIPSec/IKE/Oakley curve #4 over a 185 bit binary field.\n"
  1829. "\tNot suitable for ECDSA.\n\tQuestionable extension field!" },
  1830. #endif
  1831. };
  1832. #define curve_list_length (sizeof(curve_list)/sizeof(ec_list_element))
  1833. static EC_GROUP *ec_group_new_from_data(const ec_list_element curve)
  1834. {
  1835. EC_GROUP *group=NULL;
  1836. EC_POINT *P=NULL;
  1837. BN_CTX *ctx=NULL;
  1838. BIGNUM *p=NULL, *a=NULL, *b=NULL, *x=NULL, *y=NULL, *order=NULL;
  1839. int ok=0;
  1840. int seed_len,param_len;
  1841. const EC_METHOD *meth;
  1842. const EC_CURVE_DATA *data;
  1843. const unsigned char *params;
  1844. if ((ctx = BN_CTX_new()) == NULL)
  1845. {
  1846. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_MALLOC_FAILURE);
  1847. goto err;
  1848. }
  1849. data = curve.data;
  1850. seed_len = data->seed_len;
  1851. param_len = data->param_len;
  1852. params = (const unsigned char *)(data+1); /* skip header */
  1853. params += seed_len; /* skip seed */
  1854. if (!(p = BN_bin2bn(params+0*param_len, param_len, NULL))
  1855. || !(a = BN_bin2bn(params+1*param_len, param_len, NULL))
  1856. || !(b = BN_bin2bn(params+2*param_len, param_len, NULL)))
  1857. {
  1858. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_BN_LIB);
  1859. goto err;
  1860. }
  1861. if (curve.meth != 0)
  1862. {
  1863. meth = curve.meth();
  1864. if (((group = EC_GROUP_new(meth)) == NULL) ||
  1865. (!(group->meth->group_set_curve(group, p, a, b, ctx))))
  1866. {
  1867. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
  1868. goto err;
  1869. }
  1870. }
  1871. else if (data->field_type == NID_X9_62_prime_field)
  1872. {
  1873. if ((group = EC_GROUP_new_curve_GFp(p, a, b, ctx)) == NULL)
  1874. {
  1875. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
  1876. goto err;
  1877. }
  1878. }
  1879. #ifndef OPENSSL_NO_EC2M
  1880. else /* field_type == NID_X9_62_characteristic_two_field */
  1881. {
  1882. if ((group = EC_GROUP_new_curve_GF2m(p, a, b, ctx)) == NULL)
  1883. {
  1884. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
  1885. goto err;
  1886. }
  1887. }
  1888. #endif
  1889. if ((P = EC_POINT_new(group)) == NULL)
  1890. {
  1891. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
  1892. goto err;
  1893. }
  1894. if (!(x = BN_bin2bn(params+3*param_len, param_len, NULL))
  1895. || !(y = BN_bin2bn(params+4*param_len, param_len, NULL)))
  1896. {
  1897. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_BN_LIB);
  1898. goto err;
  1899. }
  1900. if (!EC_POINT_set_affine_coordinates_GFp(group, P, x, y, ctx))
  1901. {
  1902. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
  1903. goto err;
  1904. }
  1905. if (!(order = BN_bin2bn(params+5*param_len, param_len, NULL))
  1906. || !BN_set_word(x, (BN_ULONG)data->cofactor))
  1907. {
  1908. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_BN_LIB);
  1909. goto err;
  1910. }
  1911. if (!EC_GROUP_set_generator(group, P, order, x))
  1912. {
  1913. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
  1914. goto err;
  1915. }
  1916. if (seed_len)
  1917. {
  1918. if (!EC_GROUP_set_seed(group, params-seed_len, seed_len))
  1919. {
  1920. ECerr(EC_F_EC_GROUP_NEW_FROM_DATA, ERR_R_EC_LIB);
  1921. goto err;
  1922. }
  1923. }
  1924. ok=1;
  1925. err:
  1926. if (!ok)
  1927. {
  1928. EC_GROUP_free(group);
  1929. group = NULL;
  1930. }
  1931. if (P)
  1932. EC_POINT_free(P);
  1933. if (ctx)
  1934. BN_CTX_free(ctx);
  1935. if (p)
  1936. BN_free(p);
  1937. if (a)
  1938. BN_free(a);
  1939. if (b)
  1940. BN_free(b);
  1941. if (order)
  1942. BN_free(order);
  1943. if (x)
  1944. BN_free(x);
  1945. if (y)
  1946. BN_free(y);
  1947. return group;
  1948. }
  1949. EC_GROUP *EC_GROUP_new_by_curve_name(int nid)
  1950. {
  1951. size_t i;
  1952. EC_GROUP *ret = NULL;
  1953. if (nid <= 0)
  1954. return NULL;
  1955. for (i=0; i<curve_list_length; i++)
  1956. if (curve_list[i].nid == nid)
  1957. {
  1958. ret = ec_group_new_from_data(curve_list[i]);
  1959. break;
  1960. }
  1961. if (ret == NULL)
  1962. {
  1963. ECerr(EC_F_EC_GROUP_NEW_BY_CURVE_NAME, EC_R_UNKNOWN_GROUP);
  1964. return NULL;
  1965. }
  1966. EC_GROUP_set_curve_name(ret, nid);
  1967. return ret;
  1968. }
  1969. size_t EC_get_builtin_curves(EC_builtin_curve *r, size_t nitems)
  1970. {
  1971. size_t i, min;
  1972. if (r == NULL || nitems == 0)
  1973. return curve_list_length;
  1974. min = nitems < curve_list_length ? nitems : curve_list_length;
  1975. for (i = 0; i < min; i++)
  1976. {
  1977. r[i].nid = curve_list[i].nid;
  1978. r[i].comment = curve_list[i].comment;
  1979. }
  1980. return curve_list_length;
  1981. }