数据搜索系统,热门电子元器件搜索
  Chinese  ▼
ALLDATASHEETCN.COM

X  

5812-DS01-R 数据表(PDF) 40 Page - Broadcom Corporation.

部件名 5812-DS01-R
功能描述  Security Processor
PDF  84 Pages
Scroll/Zoom Zoom In 100%  Zoom Out
制造商  BOARDCOM [Broadcom Corporation.]
网页  http://www.broadcom.com
标志 BOARDCOM - Broadcom Corporation.

5812-DS01-R 数据表(HTML) 40 Page - Broadcom Corporation.

Back Button 5812-DS01-R Datasheet HTML 36Page - Broadcom Corporation. 5812-DS01-R Datasheet HTML 37Page - Broadcom Corporation. 5812-DS01-R Datasheet HTML 38Page - Broadcom Corporation. 5812-DS01-R Datasheet HTML 39Page - Broadcom Corporation. 5812-DS01-R Datasheet HTML 40Page - Broadcom Corporation. 5812-DS01-R Datasheet HTML 41Page - Broadcom Corporation. 5812-DS01-R Datasheet HTML 42Page - Broadcom Corporation. 5812-DS01-R Datasheet HTML 43Page - Broadcom Corporation. 5812-DS01-R Datasheet HTML 44Page - Broadcom Corporation. Next Button
Zoom Inzoom in Zoom Outzoom out
 40 / 84 page
background image
BCM5812
Advance Data Sheet
3/11/03
B roa dcom Co rpo rat ion
Page 32
Cryptographic Operations
Document
5812-DS01-405-R
DSA
DSA, also known as the Digital Signature Standard (DSS), is described in FIPS-180-2 [19] as follows.
1
p, which is an L-bit long prime modulus, 2L-1< p < 2L, where L is an integer multiple of 64 greater than or equal to 512
and less than or equal to 1024.
2
q is a 160-bit prime factor of (p - 1), in other words, 2159 < q < 2160.
3
g = h(p-1)/q mod p, where h is any integer with 1 < h < (p - 1) such that h(p-1)/q mod p is greater than 1 (g has order q mod p).
4
x is a randomly or pseudo randomly generated integer with 0 < x < q.
5
y = gx mod p
6
k, a... randomly or pseudo randomly generated integer with 0 < k < q.
The integers p, q, and g can be public and can be common to a group of users. A user's private and public keys are x and
y, respectively. They are normally fixed for a period of time. Parameters x and k are used for signature generation only, and
must be kept secret. Parameter k must be regenerated for each signature.
For Alice to sign a message m, and Bob to verify the message:
1
Alice generates a k as above, and uses it to compute r and s, according to the following formula:
r = (g
k mod p) mod q, and
s = (k
-1 (SHA-1(M) + xr)) mod q
Alice sends Bob the pair (r,s) as the signature on message M.
2
For Bob to verify the signature, he uses Alice’s public key, y, and message M, along with the public parameters p and q,
and performs the following computation:
w = s
-1 mod q
u1 = (SHA-1(M) * w) mod q
u2 = (r * w) mod q
v = ((g
u1 * yu2) mod p) mod q
If v equals r, Bob accepts the signature as valid.
Refer to FIPS-180-2 for details.
The BCM5812 provides separate operations for DSA sign and DSA verify. Figure 29 on page 33 shows the command
context, input, and output parameter buffers for the DSA sign operation. P, Q, and G, and X correspond to p, q, g, and X in
the above description, and are provided in the command context. The modulus P length is supplied in bits.
DSA sign uses MCR2@, and opcode 0x05.
The input message, M, can be supplied directly and hashed by the BCM5812, or it can be supplied as a pre-computed SHA-
1 hash value. If supplied as a hash value, it is provided at the first input fragment address, 20 bytes in length, and the hash
generated parameter is 0x0000. In this case, the Dlength parameter in the packet descriptor is zero.
If an explicit message is supplied for the BCM5812 to compute the SHA-1 hash, the hash generated parameter should be
set to 0x0001. If M is explicitly supplied, the total length in bytes must be supplied in the Dlength field of the packet descriptor
structure. M can be supplied in a single fragment of up to 65,535 bytes in length, or in multiple fragments, with the restriction
that intermediate fragments, other than the last, must be exactly 64 bytes (512 bits) in length. Hash generated should be one
of these two values.
The random number can be optionally generated by the BCM5812 or explicitly provided. If it is generated, generate random
number is set to 0x0001. If software provides the random number, generate random number should be 0x0000, and the
random number is taken from the 20 byte buffer address in the last input fragment chain entry descriptor. Figure 29 illustrates



Html Pages

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84


数据表 下载

Go To PDF Page


链接网址



ALLDATASHEET是否为您带来帮助?  [ DONATE ] 

关于 Alldatasheet   |   广告服务   |   联系我们   |   隐私政策   |   数据表链接    |   链接交换   |   制造商名单
All Rights Reserved©Alldatasheet.com


Mirror Sites
English : Alldatasheet.com  |   English : Alldatasheet.net  |   Chinese : Alldatasheetcn.com  |   German : Alldatasheetde.com  |   Japanese : Alldatasheet.jp
Russian : Alldatasheetru.com  |   Korean : Alldatasheet.co.kr  |   Spanish : Alldatasheet.es  |   French : Alldatasheet.fr  |   Italian : Alldatasheetit.com
Portuguese : Alldatasheetpt.com  |   Polish : Alldatasheet.pl  |   Vietnamese : Alldatasheet.vn
Indian : Alldatasheet.in  |   Mexican : Alldatasheet.com.mx  |   British : Alldatasheet.co.uk  |   New Zealand : Alldatasheet.co.nz
Family Site : ic2ic.com  |   icmetro.com