/opt/alt/python27/lib64/python2.7/site-packages/Crypto/PublicKey
Edit: /opt/alt/python27/lib64/python2.7/site-packages/Crypto/PublicKey/ElGamal.pyc (13343B)
Ñò
Bd\Rc @ sƒ d Z d Z d d d d g Z d d k Td d k l Z d e f d „ ƒ YZ d
d
„ Z d „ Z
d e f d „ ƒ YZ e Z
d
S( sP ElGamal public-key algorithm (randomized encryption and signature).
Signature algorithm
-------------------
The security of the ElGamal signature scheme is based (like DSA) on the discrete
logarithm problem (DLP_). Given a cyclic group, a generator *g*,
and an element *h*, it is hard to find an integer *x* such that *g^x = h*.
The group is the largest multiplicative sub-group of the integers modulo *p*,
with *p* prime.
The signer holds a value *x* (*0
>> from Crypto import Random
>>> from Crypto.Random import random
>>> from Crypto.PublicKey import ElGamal
>>> from Crypto.Util.number import GCD
>>> from Crypto.Hash import SHA
>>>
>>> message = "Hello"
>>> key = ElGamal.generate(1024, Random.new().read)
>>> h = SHA.new(message).digest()
>>> while 1:
>>> k = random.StrongRandom().randint(1,key.p-1)
>>> if GCD(k,key.p-1)==1: break
>>> sig = key.sign(h,k)
>>> ...
>>> if key.verify(h,sig):
>>> print "OK"
>>> else:
>>> print "Incorrect signature"
.. _DLP: http://www.cosic.esat.kuleuven.be/publications/talk-78.pdf
.. _CDH: http://en.wikipedia.org/wiki/Computational_Diffie%E2%80%93Hellman_assumption
.. _ECRYPT: http://www.ecrypt.eu.org/documents/D.SPA.17.pdf
s $Id$t generatet constructt errort
ElGamalobjiÿÿÿÿ( t *( t numberc B s e Z RS( ( t __name__t
__module__( ( ( sK /opt/alt/python27/lib64/python2.7/site-packages/Crypto/PublicKey/ElGamal.pyR s s c C s÷ t ƒ } | o | d ƒ n xK t t | d | ƒ ƒ } d | d | _ t i | i d | ƒo Pq! q! | o | d ƒ n xt i d | i | ƒ | _ d } t | i d | i ƒ d j o
d } n | o) t | i | | i ƒ d j o
d } n | o. t | i d | i ƒ d d j o
d } n t i
| i | i ƒ } | o+ t | i d | ƒ d d j o
d } n | o Pq„ q„ | o | d ƒ n t i d | i d | ƒ | _ | o | d ƒ n t | i | i | i ƒ | _ | S(
s' Randomly generate a fresh, new ElGamal key.
The key will be safe for use for both encryption and signature
(although it should be used for **only one** purpose).
:Parameters:
bits : int
Key length, or size (in bits) of the modulus *p*.
Recommended value is 2048.
randfunc : callable
Random number generation function; it should accept
a single integer N and return a string of random data
N bytes long.
progress_func : callable
Optional function that will be called with a short string
containing the key parameter currently being generated;
it's useful for interactive applications where a user is
waiting for a key to be generated.
:attention: You should always use a cryptographically secure random number generator,
such as the one defined in the ``Crypto.Random`` module; **don't** just use the
current time and the ``random`` module.
:Return: An ElGamal key object (`ElGamalobj`).
s p
i i t randfuncs g
i i s x
s y
(
R t bignumt getPrimet pR t isPrimet getRandomRanget gt powt divmodt inverset xt y( t bitsR t
progress_funct objt qt safet ginv( ( sK /opt/alt/python27/lib64/python2.7/site-packages/Crypto/PublicKey/ElGamal.pyR w s>
&
+
(
c C sn t ƒ } t | ƒ d j o t d ƒ ‚ n x; t t | ƒ ƒ D]' } | i | } t | | | | ƒ q? W| S( s* Construct an ElGamal key from a tuple of valid ElGamal components.
The modulus *p* must be a prime.
The following conditions must apply:
- 1 < g < p-1
- g^{p-1} = 1 mod p
- 1 < x < p-1
- g^x = y mod p
:Parameters:
tup : tuple
A tuple of long integers, with 3 or 4 items
in the following order:
1. Modulus (*p*).
2. Generator (*g*).
3. Public key (*y*).
4. Private key (*x*). Optional.
:Return: An ElGamal key object (`ElGamalobj`).
i i s% argument for construct() wrong length( i i ( R t lent
ValueErrort ranget keydatat setattr( t tupR t it field( ( sK /opt/alt/python27/lib64/python2.7/site-packages/Crypto/PublicKey/ElGamal.pyR Á s
c B sƒ e Z d Z d d d d g Z d „ Z d „ Z d „ Z d „ Z d „ Z d
„ Z d „ Z
d „ Z d
„ Z d „ Z
d „ Z RS( si Class defining an ElGamal key.
:undocumented: __getstate__, __setstate__, __repr__, __getattr__
R R R R c C s t i | | | ƒ S( sR Encrypt a piece of data with ElGamal.
:Parameter plaintext: The piece of data to encrypt with ElGamal.
It must be numerically smaller than the module (*p*).
:Type plaintext: byte string or long
:Parameter K: A secret number, chosen randomly in the closed
range *[1,p-2]*.
:Type K: long (recommended) or byte string (not recommended)
:Return: A tuple with two items. Each item is of the same type as the
plaintext (string or long).
:attention: selection of *K* is crucial for security. Generating a
random number larger than *p-1* and taking the modulus by *p-1* is
**not** secure, since smaller values will occur more frequently.
Generating a random number systematically smaller than *p-1*
(e.g. *floor((p-1)/8)* random bytes) is also **not** secure.
In general, it shall not be possible for an attacker to know
the value of any bit of K.
:attention: The number *K* shall not be reused for any other
operation and shall be discarded immediately.
( t pubkeyt encrypt( t selft plaintextt K( ( sK /opt/alt/python27/lib64/python2.7/site-packages/Crypto/PublicKey/ElGamal.pyR# õ s c C s t i | | ƒ S( sP Decrypt a piece of data with ElGamal.
:Parameter ciphertext: The piece of data to decrypt with ElGamal.
:Type ciphertext: byte string, long or a 2-item tuple as returned
by `encrypt`
:Return: A byte string if ciphertext was a byte string or a tuple
of byte strings. A long otherwise.
( R" t decrypt( R$ t
ciphertext( ( sK /opt/alt/python27/lib64/python2.7/site-packages/Crypto/PublicKey/ElGamal.pyR' s
c C s t i | | | ƒ S( s„ Sign a piece of data with ElGamal.
:Parameter M: The piece of data to sign with ElGamal. It may
not be longer in bit size than *p-1*.
:Type M: byte string or long
:Parameter K: A secret number, chosen randomly in the closed
range *[1,p-2]* and such that *gcd(k,p-1)=1*.
:Type K: long (recommended) or byte string (not recommended)
:attention: selection of *K* is crucial for security. Generating a
random number larger than *p-1* and taking the modulus by *p-1* is
**not** secure, since smaller values will occur more frequently.
Generating a random number systematically smaller than *p-1*
(e.g. *floor((p-1)/8)* random bytes) is also **not** secure.
In general, it shall not be possible for an attacker to know
the value of any bit of K.
:attention: The number *K* shall not be reused for any other
operation and shall be discarded immediately.
:attention: M must be be a cryptographic hash, otherwise an
attacker may mount an existential forgery attack.
:Return: A tuple with 2 longs.
( R" t sign( R$ t MR&