2013-03-20 21:14:06 +04:00
|
|
|
/* crypto.c
|
|
|
|
*
|
2016-03-18 01:02:13 +03:00
|
|
|
* Copyright (C) 2006-2016 wolfSSL Inc.
|
2013-03-20 21:14:06 +04:00
|
|
|
*
|
2016-03-18 01:02:13 +03:00
|
|
|
* This file is part of wolfSSL.
|
2013-03-20 21:14:06 +04:00
|
|
|
*
|
2015-01-06 22:14:15 +03:00
|
|
|
* wolfSSL is free software; you can redistribute it and/or modify
|
2013-03-20 21:14:06 +04:00
|
|
|
* it under the terms of the GNU General Public License as published by
|
|
|
|
* the Free Software Foundation; either version 2 of the License, or
|
|
|
|
* (at your option) any later version.
|
|
|
|
*
|
2015-01-06 22:14:15 +03:00
|
|
|
* wolfSSL is distributed in the hope that it will be useful,
|
2013-03-20 21:14:06 +04:00
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* along with this program; if not, write to the Free Software
|
2016-03-18 01:02:13 +03:00
|
|
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA
|
2013-03-20 21:14:06 +04:00
|
|
|
*/
|
|
|
|
|
|
|
|
|
2016-03-18 01:02:13 +03:00
|
|
|
|
2013-03-20 21:14:06 +04:00
|
|
|
/* Implements Microchip CRYPTO API layer */
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#include "crypto.h"
|
|
|
|
|
2013-04-10 23:17:23 +04:00
|
|
|
#include <cyassl/ctaocrypt/settings.h>
|
|
|
|
|
2013-03-20 21:14:06 +04:00
|
|
|
#include <cyassl/ctaocrypt/md5.h>
|
|
|
|
#include <cyassl/ctaocrypt/sha.h>
|
|
|
|
#include <cyassl/ctaocrypt/sha256.h>
|
|
|
|
#include <cyassl/ctaocrypt/sha512.h>
|
2013-03-20 22:59:27 +04:00
|
|
|
#include <cyassl/ctaocrypt/hmac.h>
|
2013-03-21 01:37:05 +04:00
|
|
|
#include <cyassl/ctaocrypt/compress.h>
|
2013-03-21 02:02:03 +04:00
|
|
|
#include <cyassl/ctaocrypt/random.h>
|
2013-03-21 05:35:26 +04:00
|
|
|
#include <cyassl/ctaocrypt/des3.h>
|
2013-03-21 06:21:04 +04:00
|
|
|
#include <cyassl/ctaocrypt/aes.h>
|
2013-03-21 21:28:55 +04:00
|
|
|
#include <cyassl/ctaocrypt/rsa.h>
|
2013-03-22 00:20:23 +04:00
|
|
|
#include <cyassl/ctaocrypt/ecc.h>
|
2014-03-25 22:39:07 +04:00
|
|
|
#include <cyassl/ctaocrypt/error-crypt.h>
|
2013-03-20 21:14:06 +04:00
|
|
|
|
|
|
|
|
|
|
|
/* Initialize MD5 */
|
|
|
|
int CRYPT_MD5_Initialize(CRYPT_MD5_CTX* md5)
|
|
|
|
{
|
|
|
|
typedef char md5_test[sizeof(CRYPT_MD5_CTX) >= sizeof(Md5) ? 1 : -1];
|
|
|
|
(void)sizeof(md5_test);
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (md5 == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
wc_InitMd5((Md5*)md5);
|
2013-03-20 21:14:06 +04:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Add data to MD5 */
|
|
|
|
int CRYPT_MD5_DataAdd(CRYPT_MD5_CTX* md5, const unsigned char* input,
|
|
|
|
unsigned int sz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (md5 == NULL || input == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
wc_Md5Update((Md5*)md5, input, sz);
|
2013-03-20 21:14:06 +04:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Get MD5 Final into digest */
|
|
|
|
int CRYPT_MD5_Finalize(CRYPT_MD5_CTX* md5, unsigned char* digest)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (md5 == NULL || digest == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
wc_Md5Final((Md5*)md5, digest);
|
2013-03-20 21:14:06 +04:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Initialize SHA */
|
|
|
|
int CRYPT_SHA_Initialize(CRYPT_SHA_CTX* sha)
|
|
|
|
{
|
|
|
|
typedef char sha_test[sizeof(CRYPT_SHA_CTX) >= sizeof(Sha) ? 1 : -1];
|
|
|
|
(void)sizeof(sha_test);
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_InitSha((Sha*)sha);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Add data to SHA */
|
|
|
|
int CRYPT_SHA_DataAdd(CRYPT_SHA_CTX* sha, const unsigned char* input,
|
|
|
|
unsigned int sz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha == NULL || input == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_ShaUpdate((Sha*)sha, input, sz);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Get SHA Final into digest */
|
|
|
|
int CRYPT_SHA_Finalize(CRYPT_SHA_CTX* sha, unsigned char* digest)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha == NULL || digest == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_ShaFinal((Sha*)sha, digest);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Initialize SHA-256 */
|
|
|
|
int CRYPT_SHA256_Initialize(CRYPT_SHA256_CTX* sha256)
|
|
|
|
{
|
|
|
|
typedef char sha_test[sizeof(CRYPT_SHA256_CTX) >= sizeof(Sha256) ? 1 : -1];
|
|
|
|
(void)sizeof(sha_test);
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha256 == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_InitSha256((Sha256*)sha256);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Add data to SHA-256 */
|
|
|
|
int CRYPT_SHA256_DataAdd(CRYPT_SHA256_CTX* sha256, const unsigned char* input,
|
|
|
|
unsigned int sz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha256 == NULL || input == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_Sha256Update((Sha256*)sha256, input, sz);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Get SHA-256 Final into digest */
|
|
|
|
int CRYPT_SHA256_Finalize(CRYPT_SHA256_CTX* sha256, unsigned char* digest)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha256 == NULL || digest == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_Sha256Final((Sha256*)sha256, digest);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Initialize SHA-384 */
|
|
|
|
int CRYPT_SHA384_Initialize(CRYPT_SHA384_CTX* sha384)
|
|
|
|
{
|
|
|
|
typedef char sha_test[sizeof(CRYPT_SHA384_CTX) >= sizeof(Sha384) ? 1 : -1];
|
|
|
|
(void)sizeof(sha_test);
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha384 == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_InitSha384((Sha384*)sha384);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Add data to SHA-384 */
|
|
|
|
int CRYPT_SHA384_DataAdd(CRYPT_SHA384_CTX* sha384, const unsigned char* input,
|
|
|
|
unsigned int sz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha384 == NULL || input == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_Sha384Update((Sha384*)sha384, input, sz);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Get SHA-384 Final into digest */
|
|
|
|
int CRYPT_SHA384_Finalize(CRYPT_SHA384_CTX* sha384, unsigned char* digest)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha384 == NULL || digest == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_Sha384Final((Sha384*)sha384, digest);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Initialize SHA-512 */
|
|
|
|
int CRYPT_SHA512_Initialize(CRYPT_SHA512_CTX* sha512)
|
|
|
|
{
|
|
|
|
typedef char sha_test[sizeof(CRYPT_SHA512_CTX) >= sizeof(Sha512) ? 1 : -1];
|
|
|
|
(void)sizeof(sha_test);
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha512 == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_InitSha512((Sha512*)sha512);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Add data to SHA-512 */
|
|
|
|
int CRYPT_SHA512_DataAdd(CRYPT_SHA512_CTX* sha512, const unsigned char* input,
|
|
|
|
unsigned int sz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha512 == NULL || input == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_Sha512Update((Sha512*)sha512, input, sz);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Get SHA-512 Final into digest */
|
|
|
|
int CRYPT_SHA512_Finalize(CRYPT_SHA512_CTX* sha512, unsigned char* digest)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (sha512 == NULL || digest == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_Sha512Final((Sha512*)sha512, digest);
|
2013-03-20 21:14:06 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2013-03-20 22:59:27 +04:00
|
|
|
/* Set HMAC key with type */
|
|
|
|
int CRYPT_HMAC_SetKey(CRYPT_HMAC_CTX* hmac, int type, const unsigned char* key,
|
|
|
|
unsigned int sz)
|
|
|
|
{
|
2016-08-15 22:59:41 +03:00
|
|
|
/* compile-time check to verify CRYPT_HMAC_CTX is large enough to hold Hmac */
|
2013-03-20 22:59:27 +04:00
|
|
|
typedef char hmac_test[sizeof(CRYPT_HMAC_CTX) >= sizeof(Hmac) ? 1 : -1];
|
|
|
|
(void)sizeof(hmac_test);
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (hmac == NULL || key == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-20 22:59:27 +04:00
|
|
|
if (type != CRYPT_HMAC_SHA && type != CRYPT_HMAC_SHA256 &&
|
|
|
|
type != CRYPT_HMAC_SHA384 && type != CRYPT_HMAC_SHA512) {
|
2013-03-22 00:39:13 +04:00
|
|
|
return BAD_FUNC_ARG; /* bad hmac type */
|
2013-03-20 22:59:27 +04:00
|
|
|
}
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_HmacSetKey((Hmac*)hmac, type, key, sz);
|
2013-03-20 22:59:27 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int CRYPT_HMAC_DataAdd(CRYPT_HMAC_CTX* hmac, const unsigned char* input,
|
|
|
|
unsigned int sz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (hmac == NULL || input == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_HmacUpdate((Hmac*)hmac, input, sz);
|
2013-03-20 22:59:27 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Get HMAC Final into digest */
|
|
|
|
int CRYPT_HMAC_Finalize(CRYPT_HMAC_CTX* hmac, unsigned char* digest)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (hmac == NULL || digest == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_HmacFinal((Hmac*)hmac, digest);
|
2013-03-20 22:59:27 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2013-03-21 01:37:05 +04:00
|
|
|
/* Huffman Compression, set flag to do static, otherwise dynamic */
|
|
|
|
/* return compressed size, otherwise < 0 for error */
|
|
|
|
int CRYPT_HUFFMAN_Compress(unsigned char* out, unsigned int outSz,
|
|
|
|
const unsigned char* in, unsigned int inSz,
|
|
|
|
unsigned int flags)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (out == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-21 01:37:05 +04:00
|
|
|
return Compress(out, outSz, in, inSz, flags);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Huffman DeCompression, self determines type */
|
|
|
|
/* return decompressed size, otherwise < 0 for error */
|
|
|
|
int CRYPT_HUFFMAN_DeCompress(unsigned char* out, unsigned int outSz,
|
|
|
|
const unsigned char* in, unsigned int inSz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (out == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-21 01:37:05 +04:00
|
|
|
return DeCompress(out, outSz, in, inSz);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2013-03-21 02:02:03 +04:00
|
|
|
/* RNG Initialize, < 0 on error */
|
|
|
|
int CRYPT_RNG_Initialize(CRYPT_RNG_CTX* rng)
|
|
|
|
{
|
2015-08-07 20:53:19 +03:00
|
|
|
typedef char rng_test[sizeof(CRYPT_RNG_CTX) >= sizeof(WC_RNG) ? 1 : -1];
|
2013-03-21 02:02:03 +04:00
|
|
|
(void)sizeof(rng_test);
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (rng == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-08-07 20:53:19 +03:00
|
|
|
return InitRng((WC_RNG*)rng);
|
2013-03-21 02:02:03 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* RNG Get single bytes, < 0 on error */
|
|
|
|
int CRYPT_RNG_Get(CRYPT_RNG_CTX* rng, unsigned char* b)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (rng == NULL || b == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-08-07 20:53:19 +03:00
|
|
|
return RNG_GenerateByte((WC_RNG*)rng, (byte*)b);
|
2013-03-21 02:02:03 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* RNG Block Generation of sz bytes, < 0 on error */
|
|
|
|
int CRYPT_RNG_BlockGenerate(CRYPT_RNG_CTX* rng, unsigned char* b,
|
|
|
|
unsigned int sz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (rng == NULL || b == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-08-07 20:53:19 +03:00
|
|
|
return RNG_GenerateBlock((WC_RNG*)rng, b, sz);
|
2013-03-21 02:02:03 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2013-03-21 05:35:26 +04:00
|
|
|
/* Triple DES Key Set, may have iv, will have direction */
|
|
|
|
int CRYPT_TDES_KeySet(CRYPT_TDES_CTX* tdes, const unsigned char* key,
|
|
|
|
const unsigned char* iv, int dir)
|
|
|
|
{
|
|
|
|
typedef char tdes_test[sizeof(CRYPT_TDES_CTX) >= sizeof(Des3) ? 1 : -1];
|
|
|
|
(void)sizeof(tdes_test);
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (tdes == NULL || key == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2014-03-25 00:37:52 +04:00
|
|
|
return Des3_SetKey((Des3*)tdes, key, iv, dir);
|
2013-03-21 05:35:26 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Triple DES Iv Set, sometimes added later */
|
|
|
|
int CRYPT_TDES_IvSet(CRYPT_TDES_CTX* tdes, const unsigned char* iv)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (tdes == NULL || iv == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_Des3_SetIV((Des3*)tdes, iv);
|
2013-03-21 05:35:26 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Triple DES CBC Encrypt */
|
|
|
|
int CRYPT_TDES_CBC_Encrypt(CRYPT_TDES_CTX* tdes, unsigned char* out,
|
|
|
|
const unsigned char* in, unsigned int inSz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (tdes == NULL || out == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_Des3_CbcEncrypt((Des3*)tdes, out, in, inSz);
|
2013-03-21 05:35:26 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* Triple DES CBC Decrypt */
|
|
|
|
int CRYPT_TDES_CBC_Decrypt(CRYPT_TDES_CTX* tdes, unsigned char* out,
|
|
|
|
const unsigned char* in, unsigned int inSz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (tdes == NULL || out == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2014-03-25 00:37:52 +04:00
|
|
|
return Des3_CbcDecrypt((Des3*)tdes, out, in, inSz);
|
2013-03-21 05:35:26 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2013-03-21 06:21:04 +04:00
|
|
|
/* AES Key Set, may have iv, will have direction */
|
|
|
|
int CRYPT_AES_KeySet(CRYPT_AES_CTX* aes, const unsigned char* key,
|
|
|
|
unsigned int keyLen, const unsigned char* iv, int dir)
|
|
|
|
{
|
|
|
|
typedef char aes_test[sizeof(CRYPT_AES_CTX) >= sizeof(Aes) ? 1 : -1];
|
|
|
|
(void)sizeof(aes_test);
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (aes == NULL || key == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_AesSetKey((Aes*)aes, key, keyLen, iv, dir);
|
2013-03-21 06:21:04 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* AES Iv Set, sometimes added later */
|
|
|
|
int CRYPT_AES_IvSet(CRYPT_AES_CTX* aes, const unsigned char* iv)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (aes == NULL || iv == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_AesSetIV((Aes*)aes, iv);
|
2013-03-21 06:21:04 +04:00
|
|
|
}
|
|
|
|
|
2013-03-21 05:35:26 +04:00
|
|
|
|
2013-03-21 06:21:04 +04:00
|
|
|
/* AES CBC Encrypt */
|
|
|
|
int CRYPT_AES_CBC_Encrypt(CRYPT_AES_CTX* aes, unsigned char* out,
|
|
|
|
const unsigned char* in, unsigned int inSz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (aes == NULL || out == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_AesCbcEncrypt((Aes*)aes, out, in, inSz);
|
2013-03-21 06:21:04 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* AES CBC Decrypt */
|
|
|
|
int CRYPT_AES_CBC_Decrypt(CRYPT_AES_CTX* aes, unsigned char* out,
|
|
|
|
const unsigned char* in, unsigned int inSz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (aes == NULL || out == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-26 23:36:39 +04:00
|
|
|
return AesCbcDecrypt((Aes*)aes, out, in, inSz);
|
2013-03-21 06:21:04 +04:00
|
|
|
}
|
2013-03-21 05:35:26 +04:00
|
|
|
|
2013-03-21 02:02:03 +04:00
|
|
|
|
2013-03-21 19:33:02 +04:00
|
|
|
/* AES CTR Encrypt (used for decrypt too, with ENCRYPT key setup) */
|
|
|
|
int CRYPT_AES_CTR_Encrypt(CRYPT_AES_CTX* aes, unsigned char* out,
|
|
|
|
const unsigned char* in, unsigned int inSz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (aes == NULL || out == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
wc_AesCtrEncrypt((Aes*)aes, out, in, inSz);
|
2013-03-21 19:33:02 +04:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2013-03-21 19:49:12 +04:00
|
|
|
/* AES Direct mode encrypt, one block at a time */
|
|
|
|
int CRYPT_AES_DIRECT_Encrypt(CRYPT_AES_CTX* aes, unsigned char* out,
|
|
|
|
const unsigned char* in)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (aes == NULL || out == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
wc_AesEncryptDirect((Aes*)aes, out, in);
|
2013-03-21 19:49:12 +04:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* AES Direct mode decrypt, one block at a time */
|
|
|
|
int CRYPT_AES_DIRECT_Decrypt(CRYPT_AES_CTX* aes, unsigned char* out,
|
|
|
|
const unsigned char* in)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (aes == NULL || out == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
wc_AesDecryptDirect((Aes*)aes, out, in);
|
2013-03-21 19:49:12 +04:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2013-03-21 19:33:02 +04:00
|
|
|
|
2013-03-21 21:28:55 +04:00
|
|
|
/* RSA Initialize */
|
|
|
|
int CRYPT_RSA_Initialize(CRYPT_RSA_CTX* rsa)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (rsa == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-21 21:28:55 +04:00
|
|
|
rsa->holder = (RsaKey*)XMALLOC(sizeof(RsaKey), NULL, DYNAMIC_TYPE_RSA);
|
|
|
|
if (rsa->holder == NULL)
|
|
|
|
return -1;
|
|
|
|
|
2014-04-02 00:08:48 +04:00
|
|
|
return InitRsaKey((RsaKey*)rsa->holder, NULL);
|
2013-03-21 21:28:55 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* RSA Free resources */
|
|
|
|
int CRYPT_RSA_Free(CRYPT_RSA_CTX* rsa)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (rsa == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-21 21:28:55 +04:00
|
|
|
FreeRsaKey((RsaKey*)rsa->holder);
|
|
|
|
XFREE(rsa->holder, NULL, DYNAMIC_TYPE_RSA);
|
|
|
|
rsa->holder = NULL;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* RSA Public key decode ASN.1 */
|
|
|
|
int CRYPT_RSA_PublicKeyDecode(CRYPT_RSA_CTX* rsa, const unsigned char* in,
|
|
|
|
unsigned int inSz)
|
|
|
|
{
|
|
|
|
unsigned int idx = 0;
|
|
|
|
(void)idx;
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (rsa == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-21 21:28:55 +04:00
|
|
|
return RsaPublicKeyDecode(in, &idx, (RsaKey*)rsa->holder, inSz);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* RSA Private key decode ASN.1 */
|
|
|
|
int CRYPT_RSA_PrivateKeyDecode(CRYPT_RSA_CTX* rsa, const unsigned char* in,
|
|
|
|
unsigned int inSz)
|
|
|
|
{
|
|
|
|
unsigned int idx = 0;
|
|
|
|
(void)idx;
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (rsa == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-21 21:28:55 +04:00
|
|
|
return RsaPrivateKeyDecode(in, &idx, (RsaKey*)rsa->holder, inSz);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* RSA Public Encrypt */
|
|
|
|
int CRYPT_RSA_PublicEncrypt(CRYPT_RSA_CTX* rsa, unsigned char* out,
|
|
|
|
unsigned int outSz, const unsigned char* in,
|
|
|
|
unsigned int inSz, CRYPT_RNG_CTX* rng)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (rsa == NULL || in == NULL || out == NULL || rng == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-21 21:28:55 +04:00
|
|
|
return RsaPublicEncrypt(in, inSz, out, outSz, (RsaKey*)rsa->holder,
|
2015-08-07 20:53:19 +03:00
|
|
|
(WC_RNG*)rng);
|
2013-03-21 21:28:55 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* RSA Private Decrypt */
|
|
|
|
int CRYPT_RSA_PrivateDecrypt(CRYPT_RSA_CTX* rsa, unsigned char* out,
|
|
|
|
unsigned int outSz, const unsigned char* in,
|
|
|
|
unsigned int inSz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (rsa == NULL || in == NULL || out == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-21 21:28:55 +04:00
|
|
|
return RsaPrivateDecrypt(in, inSz, out, outSz, (RsaKey*)rsa->holder);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* RSA Get Encrypt size helper */
|
|
|
|
int CRYPT_RSA_EncryptSizeGet(CRYPT_RSA_CTX* rsa)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (rsa == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-21 21:28:55 +04:00
|
|
|
return RsaEncryptSize((RsaKey*)rsa->holder);
|
2016-07-26 01:57:38 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int CRYPT_RSA_SetRng(CRYPT_RSA_CTX* rsa, CRYPT_RNG_CTX* rng)
|
|
|
|
{
|
|
|
|
if (rsa == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2016-07-26 19:06:46 +03:00
|
|
|
#ifdef WC_RSA_BLINDING
|
2016-07-26 01:57:38 +03:00
|
|
|
return wc_RsaSetRNG((RsaKey*)rsa->holder, (WC_RNG*)rng);
|
2016-07-26 19:06:46 +03:00
|
|
|
#else
|
|
|
|
(void)rng;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
#endif
|
2016-07-26 01:57:38 +03:00
|
|
|
}
|
2013-03-21 21:28:55 +04:00
|
|
|
|
|
|
|
|
2013-03-22 00:20:23 +04:00
|
|
|
/* ECC init */
|
|
|
|
int CRYPT_ECC_Initialize(CRYPT_ECC_CTX* ecc)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (ecc == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2013-03-22 00:20:23 +04:00
|
|
|
ecc->holder = (ecc_key*)XMALLOC(sizeof(ecc_key), NULL, DYNAMIC_TYPE_ECC);
|
|
|
|
if (ecc->holder == NULL)
|
|
|
|
return -1;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
wc_ecc_init((ecc_key*)ecc->holder);
|
2013-03-22 00:20:23 +04:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* ECC free resources */
|
|
|
|
int CRYPT_ECC_Free(CRYPT_ECC_CTX* ecc)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (ecc == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
wc_ecc_free((ecc_key*)ecc->holder);
|
2013-03-22 00:20:23 +04:00
|
|
|
XFREE(ecc->holder, NULL, DYNAMIC_TYPE_ECC);
|
|
|
|
ecc->holder = NULL;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* ECC Public x963 Export */
|
|
|
|
int CRYPT_ECC_PublicExport(CRYPT_ECC_CTX* ecc, unsigned char* out,
|
|
|
|
unsigned int outSz, unsigned int* usedSz)
|
|
|
|
{
|
|
|
|
int ret;
|
|
|
|
unsigned int inOut = outSz;
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (ecc == NULL || out == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
ret = wc_ecc_export_x963((ecc_key*)ecc->holder, out, &inOut);
|
2013-03-22 00:20:23 +04:00
|
|
|
*usedSz = inOut;
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* ECC Public x963 Import */
|
|
|
|
int CRYPT_ECC_PublicImport(CRYPT_ECC_CTX* ecc, const unsigned char* in,
|
|
|
|
unsigned int inSz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (ecc == NULL || in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_ecc_import_x963(in, inSz, (ecc_key*)ecc->holder);
|
2013-03-22 00:20:23 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* ECC Private x963 Import */
|
|
|
|
int CRYPT_ECC_PrivateImport(CRYPT_ECC_CTX* ecc, const unsigned char* priv,
|
|
|
|
unsigned int privSz, const unsigned char* pub, unsigned int pubSz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (ecc == NULL || priv == NULL || pub == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_ecc_import_private_key(priv, privSz, pub, pubSz,
|
2013-03-22 00:20:23 +04:00
|
|
|
(ecc_key*)ecc->holder);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* ECC DHE Make key */
|
|
|
|
int CRYPT_ECC_DHE_KeyMake(CRYPT_ECC_CTX* ecc, CRYPT_RNG_CTX* rng, int keySz)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (ecc == NULL || rng == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-08-07 20:53:19 +03:00
|
|
|
return wc_ecc_make_key((WC_RNG*)rng, keySz, (ecc_key*)ecc->holder);
|
2013-03-22 00:20:23 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* ECC DHE Make shared secret with our private and peer public */
|
|
|
|
int CRYPT_ECC_DHE_SharedSecretMake(CRYPT_ECC_CTX* priv, CRYPT_ECC_CTX* pub,
|
|
|
|
unsigned char* out, unsigned int outSz, unsigned int* usedSz)
|
|
|
|
{
|
|
|
|
int ret;
|
|
|
|
unsigned int inOut = outSz;
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (priv == NULL || pub == NULL || out == NULL || usedSz == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
ret = wc_ecc_shared_secret((ecc_key*)priv->holder, (ecc_key*)pub->holder,
|
2013-03-22 00:20:23 +04:00
|
|
|
out, &inOut);
|
|
|
|
*usedSz = inOut;
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* ECC DSA Hash Sign */
|
|
|
|
int CRYPT_ECC_DSA_HashSign(CRYPT_ECC_CTX* ecc, CRYPT_RNG_CTX* rng,
|
|
|
|
unsigned char* sig, unsigned int sigSz,
|
|
|
|
unsigned int* usedSz, const unsigned char* in,
|
|
|
|
unsigned int inSz)
|
|
|
|
{
|
|
|
|
int ret;
|
|
|
|
unsigned int inOut = sigSz;
|
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
if (ecc == NULL || rng == NULL || sig == NULL || usedSz == NULL ||
|
|
|
|
in == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-08-07 20:53:19 +03:00
|
|
|
ret = wc_ecc_sign_hash(in, inSz, sig, &inOut, (WC_RNG*)rng,
|
2013-03-22 00:20:23 +04:00
|
|
|
(ecc_key*)ecc->holder);
|
|
|
|
*usedSz = inOut;
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* ECC DSA Hash Verify */
|
|
|
|
int CRYPT_ECC_DSA_HashVerify(CRYPT_ECC_CTX* ecc, const unsigned char* sig,
|
|
|
|
unsigned int sigSz, unsigned char* hash,
|
|
|
|
unsigned int hashSz, int* status)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (ecc == NULL || sig == NULL || hash == NULL || status == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_ecc_verify_hash(sig, sigSz, hash, hashSz, status,
|
2013-03-22 00:20:23 +04:00
|
|
|
(ecc_key*)ecc->holder);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* ECC get key size helper */
|
|
|
|
int CRYPT_ECC_KeySizeGet(CRYPT_ECC_CTX* ecc)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (ecc == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_ecc_size((ecc_key*)ecc->holder);
|
2013-03-22 00:20:23 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/* ECC get signature size helper */
|
|
|
|
int CRYPT_ECC_SignatureSizeGet(CRYPT_ECC_CTX* ecc)
|
|
|
|
{
|
2013-03-22 00:39:13 +04:00
|
|
|
if (ecc == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
2015-02-19 15:00:54 +03:00
|
|
|
return wc_ecc_sig_size((ecc_key*)ecc->holder);
|
2013-03-22 00:20:23 +04:00
|
|
|
}
|
|
|
|
|
2013-03-21 02:02:03 +04:00
|
|
|
|
2013-03-22 00:39:13 +04:00
|
|
|
/* Save error string from err to str which needs to be >= 80 chars */
|
|
|
|
int CRYPT_ERROR_StringGet(int err, char* str)
|
|
|
|
{
|
|
|
|
if (str == NULL)
|
|
|
|
return BAD_FUNC_ARG;
|
|
|
|
|
|
|
|
CTaoCryptErrorString(err, str);
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
2013-03-21 02:02:03 +04:00
|
|
|
|