psa_crypto.c 267 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049
  1. /*
  2. * PSA crypto layer on top of Mbed TLS crypto
  3. */
  4. /*
  5. * Copyright The Mbed TLS Contributors
  6. * SPDX-License-Identifier: Apache-2.0
  7. *
  8. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  9. * not use this file except in compliance with the License.
  10. * You may obtain a copy of the License at
  11. *
  12. * http://www.apache.org/licenses/LICENSE-2.0
  13. *
  14. * Unless required by applicable law or agreed to in writing, software
  15. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  16. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  17. * See the License for the specific language governing permissions and
  18. * limitations under the License.
  19. */
  20. #include "common.h"
  21. #if defined(MBEDTLS_PSA_CRYPTO_C)
  22. #if defined(MBEDTLS_PSA_CRYPTO_CONFIG)
  23. #include "check_crypto_config.h"
  24. #endif
  25. #include "psa/crypto.h"
  26. #include "psa/crypto_values.h"
  27. #include "psa_crypto_cipher.h"
  28. #include "psa_crypto_core.h"
  29. #include "psa_crypto_invasive.h"
  30. #include "psa_crypto_driver_wrappers.h"
  31. #include "psa_crypto_ecp.h"
  32. #include "psa_crypto_hash.h"
  33. #include "psa_crypto_mac.h"
  34. #include "psa_crypto_rsa.h"
  35. #include "psa_crypto_ecp.h"
  36. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  37. #include "psa_crypto_se.h"
  38. #endif
  39. #include "psa_crypto_slot_management.h"
  40. /* Include internal declarations that are useful for implementing persistently
  41. * stored keys. */
  42. #include "psa_crypto_storage.h"
  43. #include "psa_crypto_random_impl.h"
  44. #include <stdlib.h>
  45. #include <string.h>
  46. #include "mbedtls/platform.h"
  47. #include "mbedtls/aes.h"
  48. #include "mbedtls/asn1.h"
  49. #include "mbedtls/asn1write.h"
  50. #include "mbedtls/bignum.h"
  51. #include "mbedtls/camellia.h"
  52. #include "mbedtls/chacha20.h"
  53. #include "mbedtls/chachapoly.h"
  54. #include "mbedtls/cipher.h"
  55. #include "mbedtls/ccm.h"
  56. #include "mbedtls/cmac.h"
  57. #include "mbedtls/des.h"
  58. #include "mbedtls/ecdh.h"
  59. #include "mbedtls/ecp.h"
  60. #include "mbedtls/entropy.h"
  61. #include "mbedtls/error.h"
  62. #include "mbedtls/gcm.h"
  63. #include "mbedtls/md5.h"
  64. #include "mbedtls/md.h"
  65. #include "md_wrap.h"
  66. #include "mbedtls/pk.h"
  67. #include "pk_wrap.h"
  68. #include "mbedtls/platform_util.h"
  69. #include "mbedtls/error.h"
  70. #include "mbedtls/ripemd160.h"
  71. #include "mbedtls/rsa.h"
  72. #include "mbedtls/sha1.h"
  73. #include "mbedtls/sha256.h"
  74. #include "mbedtls/sha512.h"
  75. #include "hash_info.h"
  76. #define ARRAY_LENGTH(array) (sizeof(array) / sizeof(*(array)))
  77. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF) || \
  78. defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT) || \
  79. defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND)
  80. #define BUILTIN_ALG_ANY_HKDF 1
  81. #endif
  82. /* The only two JPAKE user/peer identifiers supported for the time being. */
  83. static const uint8_t jpake_server_id[] = { 's', 'e', 'r', 'v', 'e', 'r' };
  84. static const uint8_t jpake_client_id[] = { 'c', 'l', 'i', 'e', 'n', 't' };
  85. /****************************************************************/
  86. /* Global data, support functions and library management */
  87. /****************************************************************/
  88. static int key_type_is_raw_bytes(psa_key_type_t type)
  89. {
  90. return PSA_KEY_TYPE_IS_UNSTRUCTURED(type);
  91. }
  92. /* Values for psa_global_data_t::rng_state */
  93. #define RNG_NOT_INITIALIZED 0
  94. #define RNG_INITIALIZED 1
  95. #define RNG_SEEDED 2
  96. typedef struct {
  97. unsigned initialized : 1;
  98. unsigned rng_state : 2;
  99. unsigned drivers_initialized : 1;
  100. mbedtls_psa_random_context_t rng;
  101. } psa_global_data_t;
  102. static psa_global_data_t global_data;
  103. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  104. mbedtls_psa_drbg_context_t *const mbedtls_psa_random_state =
  105. &global_data.rng.drbg;
  106. #endif
  107. #define GUARD_MODULE_INITIALIZED \
  108. if (global_data.initialized == 0) \
  109. return PSA_ERROR_BAD_STATE;
  110. int psa_can_do_hash(psa_algorithm_t hash_alg)
  111. {
  112. (void) hash_alg;
  113. return global_data.drivers_initialized;
  114. }
  115. psa_status_t mbedtls_to_psa_error(int ret)
  116. {
  117. /* Mbed TLS error codes can combine a high-level error code and a
  118. * low-level error code. The low-level error usually reflects the
  119. * root cause better, so dispatch on that preferably. */
  120. int low_level_ret = -(-ret & 0x007f);
  121. switch (low_level_ret != 0 ? low_level_ret : ret) {
  122. case 0:
  123. return PSA_SUCCESS;
  124. case MBEDTLS_ERR_AES_INVALID_KEY_LENGTH:
  125. case MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH:
  126. return PSA_ERROR_NOT_SUPPORTED;
  127. case MBEDTLS_ERR_ASN1_OUT_OF_DATA:
  128. case MBEDTLS_ERR_ASN1_UNEXPECTED_TAG:
  129. case MBEDTLS_ERR_ASN1_INVALID_LENGTH:
  130. case MBEDTLS_ERR_ASN1_LENGTH_MISMATCH:
  131. case MBEDTLS_ERR_ASN1_INVALID_DATA:
  132. return PSA_ERROR_INVALID_ARGUMENT;
  133. case MBEDTLS_ERR_ASN1_ALLOC_FAILED:
  134. return PSA_ERROR_INSUFFICIENT_MEMORY;
  135. case MBEDTLS_ERR_ASN1_BUF_TOO_SMALL:
  136. return PSA_ERROR_BUFFER_TOO_SMALL;
  137. #if defined(MBEDTLS_ERR_CAMELLIA_BAD_INPUT_DATA)
  138. case MBEDTLS_ERR_CAMELLIA_BAD_INPUT_DATA:
  139. #endif
  140. case MBEDTLS_ERR_CAMELLIA_INVALID_INPUT_LENGTH:
  141. return PSA_ERROR_NOT_SUPPORTED;
  142. case MBEDTLS_ERR_CCM_BAD_INPUT:
  143. return PSA_ERROR_INVALID_ARGUMENT;
  144. case MBEDTLS_ERR_CCM_AUTH_FAILED:
  145. return PSA_ERROR_INVALID_SIGNATURE;
  146. case MBEDTLS_ERR_CHACHA20_BAD_INPUT_DATA:
  147. return PSA_ERROR_INVALID_ARGUMENT;
  148. case MBEDTLS_ERR_CHACHAPOLY_BAD_STATE:
  149. return PSA_ERROR_BAD_STATE;
  150. case MBEDTLS_ERR_CHACHAPOLY_AUTH_FAILED:
  151. return PSA_ERROR_INVALID_SIGNATURE;
  152. case MBEDTLS_ERR_CIPHER_FEATURE_UNAVAILABLE:
  153. return PSA_ERROR_NOT_SUPPORTED;
  154. case MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA:
  155. return PSA_ERROR_INVALID_ARGUMENT;
  156. case MBEDTLS_ERR_CIPHER_ALLOC_FAILED:
  157. return PSA_ERROR_INSUFFICIENT_MEMORY;
  158. case MBEDTLS_ERR_CIPHER_INVALID_PADDING:
  159. return PSA_ERROR_INVALID_PADDING;
  160. case MBEDTLS_ERR_CIPHER_FULL_BLOCK_EXPECTED:
  161. return PSA_ERROR_INVALID_ARGUMENT;
  162. case MBEDTLS_ERR_CIPHER_AUTH_FAILED:
  163. return PSA_ERROR_INVALID_SIGNATURE;
  164. case MBEDTLS_ERR_CIPHER_INVALID_CONTEXT:
  165. return PSA_ERROR_CORRUPTION_DETECTED;
  166. #if !(defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) || \
  167. defined(MBEDTLS_PSA_HMAC_DRBG_MD_TYPE))
  168. /* Only check CTR_DRBG error codes if underlying mbedtls_xxx
  169. * functions are passed a CTR_DRBG instance. */
  170. case MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED:
  171. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  172. case MBEDTLS_ERR_CTR_DRBG_REQUEST_TOO_BIG:
  173. case MBEDTLS_ERR_CTR_DRBG_INPUT_TOO_BIG:
  174. return PSA_ERROR_NOT_SUPPORTED;
  175. case MBEDTLS_ERR_CTR_DRBG_FILE_IO_ERROR:
  176. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  177. #endif
  178. case MBEDTLS_ERR_DES_INVALID_INPUT_LENGTH:
  179. return PSA_ERROR_NOT_SUPPORTED;
  180. case MBEDTLS_ERR_ENTROPY_NO_SOURCES_DEFINED:
  181. case MBEDTLS_ERR_ENTROPY_NO_STRONG_SOURCE:
  182. case MBEDTLS_ERR_ENTROPY_SOURCE_FAILED:
  183. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  184. case MBEDTLS_ERR_GCM_AUTH_FAILED:
  185. return PSA_ERROR_INVALID_SIGNATURE;
  186. case MBEDTLS_ERR_GCM_BUFFER_TOO_SMALL:
  187. return PSA_ERROR_BUFFER_TOO_SMALL;
  188. case MBEDTLS_ERR_GCM_BAD_INPUT:
  189. return PSA_ERROR_INVALID_ARGUMENT;
  190. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) && \
  191. defined(MBEDTLS_PSA_HMAC_DRBG_MD_TYPE)
  192. /* Only check HMAC_DRBG error codes if underlying mbedtls_xxx
  193. * functions are passed a HMAC_DRBG instance. */
  194. case MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED:
  195. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  196. case MBEDTLS_ERR_HMAC_DRBG_REQUEST_TOO_BIG:
  197. case MBEDTLS_ERR_HMAC_DRBG_INPUT_TOO_BIG:
  198. return PSA_ERROR_NOT_SUPPORTED;
  199. case MBEDTLS_ERR_HMAC_DRBG_FILE_IO_ERROR:
  200. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  201. #endif
  202. case MBEDTLS_ERR_MD_FEATURE_UNAVAILABLE:
  203. return PSA_ERROR_NOT_SUPPORTED;
  204. case MBEDTLS_ERR_MD_BAD_INPUT_DATA:
  205. return PSA_ERROR_INVALID_ARGUMENT;
  206. case MBEDTLS_ERR_MD_ALLOC_FAILED:
  207. return PSA_ERROR_INSUFFICIENT_MEMORY;
  208. case MBEDTLS_ERR_MD_FILE_IO_ERROR:
  209. return PSA_ERROR_STORAGE_FAILURE;
  210. case MBEDTLS_ERR_MPI_FILE_IO_ERROR:
  211. return PSA_ERROR_STORAGE_FAILURE;
  212. case MBEDTLS_ERR_MPI_BAD_INPUT_DATA:
  213. return PSA_ERROR_INVALID_ARGUMENT;
  214. case MBEDTLS_ERR_MPI_INVALID_CHARACTER:
  215. return PSA_ERROR_INVALID_ARGUMENT;
  216. case MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL:
  217. return PSA_ERROR_BUFFER_TOO_SMALL;
  218. case MBEDTLS_ERR_MPI_NEGATIVE_VALUE:
  219. return PSA_ERROR_INVALID_ARGUMENT;
  220. case MBEDTLS_ERR_MPI_DIVISION_BY_ZERO:
  221. return PSA_ERROR_INVALID_ARGUMENT;
  222. case MBEDTLS_ERR_MPI_NOT_ACCEPTABLE:
  223. return PSA_ERROR_INVALID_ARGUMENT;
  224. case MBEDTLS_ERR_MPI_ALLOC_FAILED:
  225. return PSA_ERROR_INSUFFICIENT_MEMORY;
  226. case MBEDTLS_ERR_PK_ALLOC_FAILED:
  227. return PSA_ERROR_INSUFFICIENT_MEMORY;
  228. case MBEDTLS_ERR_PK_TYPE_MISMATCH:
  229. case MBEDTLS_ERR_PK_BAD_INPUT_DATA:
  230. return PSA_ERROR_INVALID_ARGUMENT;
  231. case MBEDTLS_ERR_PK_FILE_IO_ERROR:
  232. return PSA_ERROR_STORAGE_FAILURE;
  233. case MBEDTLS_ERR_PK_KEY_INVALID_VERSION:
  234. case MBEDTLS_ERR_PK_KEY_INVALID_FORMAT:
  235. return PSA_ERROR_INVALID_ARGUMENT;
  236. case MBEDTLS_ERR_PK_UNKNOWN_PK_ALG:
  237. return PSA_ERROR_NOT_SUPPORTED;
  238. case MBEDTLS_ERR_PK_PASSWORD_REQUIRED:
  239. case MBEDTLS_ERR_PK_PASSWORD_MISMATCH:
  240. return PSA_ERROR_NOT_PERMITTED;
  241. case MBEDTLS_ERR_PK_INVALID_PUBKEY:
  242. return PSA_ERROR_INVALID_ARGUMENT;
  243. case MBEDTLS_ERR_PK_INVALID_ALG:
  244. case MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE:
  245. case MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE:
  246. return PSA_ERROR_NOT_SUPPORTED;
  247. case MBEDTLS_ERR_PK_SIG_LEN_MISMATCH:
  248. return PSA_ERROR_INVALID_SIGNATURE;
  249. case MBEDTLS_ERR_PK_BUFFER_TOO_SMALL:
  250. return PSA_ERROR_BUFFER_TOO_SMALL;
  251. case MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED:
  252. return PSA_ERROR_HARDWARE_FAILURE;
  253. case MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED:
  254. return PSA_ERROR_NOT_SUPPORTED;
  255. case MBEDTLS_ERR_RSA_BAD_INPUT_DATA:
  256. return PSA_ERROR_INVALID_ARGUMENT;
  257. case MBEDTLS_ERR_RSA_INVALID_PADDING:
  258. return PSA_ERROR_INVALID_PADDING;
  259. case MBEDTLS_ERR_RSA_KEY_GEN_FAILED:
  260. return PSA_ERROR_HARDWARE_FAILURE;
  261. case MBEDTLS_ERR_RSA_KEY_CHECK_FAILED:
  262. return PSA_ERROR_INVALID_ARGUMENT;
  263. case MBEDTLS_ERR_RSA_PUBLIC_FAILED:
  264. case MBEDTLS_ERR_RSA_PRIVATE_FAILED:
  265. return PSA_ERROR_CORRUPTION_DETECTED;
  266. case MBEDTLS_ERR_RSA_VERIFY_FAILED:
  267. return PSA_ERROR_INVALID_SIGNATURE;
  268. case MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE:
  269. return PSA_ERROR_BUFFER_TOO_SMALL;
  270. case MBEDTLS_ERR_RSA_RNG_FAILED:
  271. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  272. case MBEDTLS_ERR_ECP_BAD_INPUT_DATA:
  273. case MBEDTLS_ERR_ECP_INVALID_KEY:
  274. return PSA_ERROR_INVALID_ARGUMENT;
  275. case MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL:
  276. return PSA_ERROR_BUFFER_TOO_SMALL;
  277. case MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE:
  278. return PSA_ERROR_NOT_SUPPORTED;
  279. case MBEDTLS_ERR_ECP_SIG_LEN_MISMATCH:
  280. case MBEDTLS_ERR_ECP_VERIFY_FAILED:
  281. return PSA_ERROR_INVALID_SIGNATURE;
  282. case MBEDTLS_ERR_ECP_ALLOC_FAILED:
  283. return PSA_ERROR_INSUFFICIENT_MEMORY;
  284. case MBEDTLS_ERR_ECP_RANDOM_FAILED:
  285. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  286. case MBEDTLS_ERR_ECP_IN_PROGRESS:
  287. return PSA_OPERATION_INCOMPLETE;
  288. case MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED:
  289. return PSA_ERROR_CORRUPTION_DETECTED;
  290. default:
  291. return PSA_ERROR_GENERIC_ERROR;
  292. }
  293. }
  294. /**
  295. * \brief For output buffers which contain "tags"
  296. * (outputs that may be checked for validity like
  297. * hashes, MACs and signatures), fill the unused
  298. * part of the output buffer (the whole buffer on
  299. * error, the trailing part on success) with
  300. * something that isn't a valid tag (barring an
  301. * attack on the tag and deliberately-crafted
  302. * input), in case the caller doesn't check the
  303. * return status properly.
  304. *
  305. * \param output_buffer Pointer to buffer to wipe. May not be NULL
  306. * unless \p output_buffer_size is zero.
  307. * \param status Status of function called to generate
  308. * output_buffer originally
  309. * \param output_buffer_size Size of output buffer. If zero, \p output_buffer
  310. * could be NULL.
  311. * \param output_buffer_length Length of data written to output_buffer, must be
  312. * less than \p output_buffer_size
  313. */
  314. static void psa_wipe_tag_output_buffer(uint8_t *output_buffer, psa_status_t status,
  315. size_t output_buffer_size, size_t output_buffer_length)
  316. {
  317. size_t offset = 0;
  318. if (output_buffer_size == 0) {
  319. /* If output_buffer_size is 0 then we have nothing to do. We must not
  320. call memset because output_buffer may be NULL in this case */
  321. return;
  322. }
  323. if (status == PSA_SUCCESS) {
  324. offset = output_buffer_length;
  325. }
  326. memset(output_buffer + offset, '!', output_buffer_size - offset);
  327. }
  328. /****************************************************************/
  329. /* Key management */
  330. /****************************************************************/
  331. #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR) || \
  332. defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY) || \
  333. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  334. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) || \
  335. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  336. mbedtls_ecp_group_id mbedtls_ecc_group_of_psa(psa_ecc_family_t curve,
  337. size_t bits,
  338. int bits_is_sloppy)
  339. {
  340. switch (curve) {
  341. case PSA_ECC_FAMILY_SECP_R1:
  342. switch (bits) {
  343. #if defined(PSA_WANT_ECC_SECP_R1_192)
  344. case 192:
  345. return MBEDTLS_ECP_DP_SECP192R1;
  346. #endif
  347. #if defined(PSA_WANT_ECC_SECP_R1_224)
  348. case 224:
  349. return MBEDTLS_ECP_DP_SECP224R1;
  350. #endif
  351. #if defined(PSA_WANT_ECC_SECP_R1_256)
  352. case 256:
  353. return MBEDTLS_ECP_DP_SECP256R1;
  354. #endif
  355. #if defined(PSA_WANT_ECC_SECP_R1_384)
  356. case 384:
  357. return MBEDTLS_ECP_DP_SECP384R1;
  358. #endif
  359. #if defined(PSA_WANT_ECC_SECP_R1_521)
  360. case 521:
  361. return MBEDTLS_ECP_DP_SECP521R1;
  362. case 528:
  363. if (bits_is_sloppy) {
  364. return MBEDTLS_ECP_DP_SECP521R1;
  365. }
  366. break;
  367. #endif
  368. }
  369. break;
  370. case PSA_ECC_FAMILY_BRAINPOOL_P_R1:
  371. switch (bits) {
  372. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_256)
  373. case 256:
  374. return MBEDTLS_ECP_DP_BP256R1;
  375. #endif
  376. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_384)
  377. case 384:
  378. return MBEDTLS_ECP_DP_BP384R1;
  379. #endif
  380. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_512)
  381. case 512:
  382. return MBEDTLS_ECP_DP_BP512R1;
  383. #endif
  384. }
  385. break;
  386. case PSA_ECC_FAMILY_MONTGOMERY:
  387. switch (bits) {
  388. #if defined(PSA_WANT_ECC_MONTGOMERY_255)
  389. case 255:
  390. return MBEDTLS_ECP_DP_CURVE25519;
  391. case 256:
  392. if (bits_is_sloppy) {
  393. return MBEDTLS_ECP_DP_CURVE25519;
  394. }
  395. break;
  396. #endif
  397. #if defined(PSA_WANT_ECC_MONTGOMERY_448)
  398. case 448:
  399. return MBEDTLS_ECP_DP_CURVE448;
  400. #endif
  401. }
  402. break;
  403. case PSA_ECC_FAMILY_SECP_K1:
  404. switch (bits) {
  405. #if defined(PSA_WANT_ECC_SECP_K1_192)
  406. case 192:
  407. return MBEDTLS_ECP_DP_SECP192K1;
  408. #endif
  409. #if defined(PSA_WANT_ECC_SECP_K1_224)
  410. case 224:
  411. return MBEDTLS_ECP_DP_SECP224K1;
  412. #endif
  413. #if defined(PSA_WANT_ECC_SECP_K1_256)
  414. case 256:
  415. return MBEDTLS_ECP_DP_SECP256K1;
  416. #endif
  417. }
  418. break;
  419. }
  420. (void) bits_is_sloppy;
  421. return MBEDTLS_ECP_DP_NONE;
  422. }
  423. #endif /* defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR) ||
  424. defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY) ||
  425. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  426. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) ||
  427. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH) */
  428. psa_status_t psa_validate_unstructured_key_bit_size(psa_key_type_t type,
  429. size_t bits)
  430. {
  431. /* Check that the bit size is acceptable for the key type */
  432. switch (type) {
  433. case PSA_KEY_TYPE_RAW_DATA:
  434. case PSA_KEY_TYPE_HMAC:
  435. case PSA_KEY_TYPE_DERIVE:
  436. case PSA_KEY_TYPE_PASSWORD:
  437. case PSA_KEY_TYPE_PASSWORD_HASH:
  438. break;
  439. #if defined(PSA_WANT_KEY_TYPE_AES)
  440. case PSA_KEY_TYPE_AES:
  441. if (bits != 128 && bits != 192 && bits != 256) {
  442. return PSA_ERROR_INVALID_ARGUMENT;
  443. }
  444. break;
  445. #endif
  446. #if defined(PSA_WANT_KEY_TYPE_ARIA)
  447. case PSA_KEY_TYPE_ARIA:
  448. if (bits != 128 && bits != 192 && bits != 256) {
  449. return PSA_ERROR_INVALID_ARGUMENT;
  450. }
  451. break;
  452. #endif
  453. #if defined(PSA_WANT_KEY_TYPE_CAMELLIA)
  454. case PSA_KEY_TYPE_CAMELLIA:
  455. if (bits != 128 && bits != 192 && bits != 256) {
  456. return PSA_ERROR_INVALID_ARGUMENT;
  457. }
  458. break;
  459. #endif
  460. #if defined(PSA_WANT_KEY_TYPE_DES)
  461. case PSA_KEY_TYPE_DES:
  462. if (bits != 64 && bits != 128 && bits != 192) {
  463. return PSA_ERROR_INVALID_ARGUMENT;
  464. }
  465. break;
  466. #endif
  467. #if defined(PSA_WANT_KEY_TYPE_CHACHA20)
  468. case PSA_KEY_TYPE_CHACHA20:
  469. if (bits != 256) {
  470. return PSA_ERROR_INVALID_ARGUMENT;
  471. }
  472. break;
  473. #endif
  474. default:
  475. return PSA_ERROR_NOT_SUPPORTED;
  476. }
  477. if (bits % 8 != 0) {
  478. return PSA_ERROR_INVALID_ARGUMENT;
  479. }
  480. return PSA_SUCCESS;
  481. }
  482. /** Check whether a given key type is valid for use with a given MAC algorithm
  483. *
  484. * Upon successful return of this function, the behavior of #PSA_MAC_LENGTH
  485. * when called with the validated \p algorithm and \p key_type is well-defined.
  486. *
  487. * \param[in] algorithm The specific MAC algorithm (can be wildcard).
  488. * \param[in] key_type The key type of the key to be used with the
  489. * \p algorithm.
  490. *
  491. * \retval #PSA_SUCCESS
  492. * The \p key_type is valid for use with the \p algorithm
  493. * \retval #PSA_ERROR_INVALID_ARGUMENT
  494. * The \p key_type is not valid for use with the \p algorithm
  495. */
  496. MBEDTLS_STATIC_TESTABLE psa_status_t psa_mac_key_can_do(
  497. psa_algorithm_t algorithm,
  498. psa_key_type_t key_type)
  499. {
  500. if (PSA_ALG_IS_HMAC(algorithm)) {
  501. if (key_type == PSA_KEY_TYPE_HMAC) {
  502. return PSA_SUCCESS;
  503. }
  504. }
  505. if (PSA_ALG_IS_BLOCK_CIPHER_MAC(algorithm)) {
  506. /* Check that we're calling PSA_BLOCK_CIPHER_BLOCK_LENGTH with a cipher
  507. * key. */
  508. if ((key_type & PSA_KEY_TYPE_CATEGORY_MASK) ==
  509. PSA_KEY_TYPE_CATEGORY_SYMMETRIC) {
  510. /* PSA_BLOCK_CIPHER_BLOCK_LENGTH returns 1 for stream ciphers and
  511. * the block length (larger than 1) for block ciphers. */
  512. if (PSA_BLOCK_CIPHER_BLOCK_LENGTH(key_type) > 1) {
  513. return PSA_SUCCESS;
  514. }
  515. }
  516. }
  517. return PSA_ERROR_INVALID_ARGUMENT;
  518. }
  519. psa_status_t psa_allocate_buffer_to_slot(psa_key_slot_t *slot,
  520. size_t buffer_length)
  521. {
  522. if (slot->key.data != NULL) {
  523. return PSA_ERROR_ALREADY_EXISTS;
  524. }
  525. slot->key.data = mbedtls_calloc(1, buffer_length);
  526. if (slot->key.data == NULL) {
  527. return PSA_ERROR_INSUFFICIENT_MEMORY;
  528. }
  529. slot->key.bytes = buffer_length;
  530. return PSA_SUCCESS;
  531. }
  532. psa_status_t psa_copy_key_material_into_slot(psa_key_slot_t *slot,
  533. const uint8_t *data,
  534. size_t data_length)
  535. {
  536. psa_status_t status = psa_allocate_buffer_to_slot(slot,
  537. data_length);
  538. if (status != PSA_SUCCESS) {
  539. return status;
  540. }
  541. memcpy(slot->key.data, data, data_length);
  542. return PSA_SUCCESS;
  543. }
  544. psa_status_t psa_import_key_into_slot(
  545. const psa_key_attributes_t *attributes,
  546. const uint8_t *data, size_t data_length,
  547. uint8_t *key_buffer, size_t key_buffer_size,
  548. size_t *key_buffer_length, size_t *bits)
  549. {
  550. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  551. psa_key_type_t type = attributes->core.type;
  552. /* zero-length keys are never supported. */
  553. if (data_length == 0) {
  554. return PSA_ERROR_NOT_SUPPORTED;
  555. }
  556. if (key_type_is_raw_bytes(type)) {
  557. *bits = PSA_BYTES_TO_BITS(data_length);
  558. status = psa_validate_unstructured_key_bit_size(attributes->core.type,
  559. *bits);
  560. if (status != PSA_SUCCESS) {
  561. return status;
  562. }
  563. /* Copy the key material. */
  564. memcpy(key_buffer, data, data_length);
  565. *key_buffer_length = data_length;
  566. (void) key_buffer_size;
  567. return PSA_SUCCESS;
  568. } else if (PSA_KEY_TYPE_IS_ASYMMETRIC(type)) {
  569. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  570. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY)
  571. if (PSA_KEY_TYPE_IS_ECC(type)) {
  572. return mbedtls_psa_ecp_import_key(attributes,
  573. data, data_length,
  574. key_buffer, key_buffer_size,
  575. key_buffer_length,
  576. bits);
  577. }
  578. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  579. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) */
  580. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  581. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  582. if (PSA_KEY_TYPE_IS_RSA(type)) {
  583. return mbedtls_psa_rsa_import_key(attributes,
  584. data, data_length,
  585. key_buffer, key_buffer_size,
  586. key_buffer_length,
  587. bits);
  588. }
  589. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  590. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  591. }
  592. return PSA_ERROR_NOT_SUPPORTED;
  593. }
  594. /** Calculate the intersection of two algorithm usage policies.
  595. *
  596. * Return 0 (which allows no operation) on incompatibility.
  597. */
  598. static psa_algorithm_t psa_key_policy_algorithm_intersection(
  599. psa_key_type_t key_type,
  600. psa_algorithm_t alg1,
  601. psa_algorithm_t alg2)
  602. {
  603. /* Common case: both sides actually specify the same policy. */
  604. if (alg1 == alg2) {
  605. return alg1;
  606. }
  607. /* If the policies are from the same hash-and-sign family, check
  608. * if one is a wildcard. If so the other has the specific algorithm. */
  609. if (PSA_ALG_IS_SIGN_HASH(alg1) &&
  610. PSA_ALG_IS_SIGN_HASH(alg2) &&
  611. (alg1 & ~PSA_ALG_HASH_MASK) == (alg2 & ~PSA_ALG_HASH_MASK)) {
  612. if (PSA_ALG_SIGN_GET_HASH(alg1) == PSA_ALG_ANY_HASH) {
  613. return alg2;
  614. }
  615. if (PSA_ALG_SIGN_GET_HASH(alg2) == PSA_ALG_ANY_HASH) {
  616. return alg1;
  617. }
  618. }
  619. /* If the policies are from the same AEAD family, check whether
  620. * one of them is a minimum-tag-length wildcard. Calculate the most
  621. * restrictive tag length. */
  622. if (PSA_ALG_IS_AEAD(alg1) && PSA_ALG_IS_AEAD(alg2) &&
  623. (PSA_ALG_AEAD_WITH_SHORTENED_TAG(alg1, 0) ==
  624. PSA_ALG_AEAD_WITH_SHORTENED_TAG(alg2, 0))) {
  625. size_t alg1_len = PSA_ALG_AEAD_GET_TAG_LENGTH(alg1);
  626. size_t alg2_len = PSA_ALG_AEAD_GET_TAG_LENGTH(alg2);
  627. size_t restricted_len = alg1_len > alg2_len ? alg1_len : alg2_len;
  628. /* If both are wildcards, return most restrictive wildcard */
  629. if (((alg1 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG) != 0) &&
  630. ((alg2 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG) != 0)) {
  631. return PSA_ALG_AEAD_WITH_AT_LEAST_THIS_LENGTH_TAG(
  632. alg1, restricted_len);
  633. }
  634. /* If only one is a wildcard, return specific algorithm if compatible. */
  635. if (((alg1 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG) != 0) &&
  636. (alg1_len <= alg2_len)) {
  637. return alg2;
  638. }
  639. if (((alg2 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG) != 0) &&
  640. (alg2_len <= alg1_len)) {
  641. return alg1;
  642. }
  643. }
  644. /* If the policies are from the same MAC family, check whether one
  645. * of them is a minimum-MAC-length policy. Calculate the most
  646. * restrictive tag length. */
  647. if (PSA_ALG_IS_MAC(alg1) && PSA_ALG_IS_MAC(alg2) &&
  648. (PSA_ALG_FULL_LENGTH_MAC(alg1) ==
  649. PSA_ALG_FULL_LENGTH_MAC(alg2))) {
  650. /* Validate the combination of key type and algorithm. Since the base
  651. * algorithm of alg1 and alg2 are the same, we only need this once. */
  652. if (PSA_SUCCESS != psa_mac_key_can_do(alg1, key_type)) {
  653. return 0;
  654. }
  655. /* Get the (exact or at-least) output lengths for both sides of the
  656. * requested intersection. None of the currently supported algorithms
  657. * have an output length dependent on the actual key size, so setting it
  658. * to a bogus value of 0 is currently OK.
  659. *
  660. * Note that for at-least-this-length wildcard algorithms, the output
  661. * length is set to the shortest allowed length, which allows us to
  662. * calculate the most restrictive tag length for the intersection. */
  663. size_t alg1_len = PSA_MAC_LENGTH(key_type, 0, alg1);
  664. size_t alg2_len = PSA_MAC_LENGTH(key_type, 0, alg2);
  665. size_t restricted_len = alg1_len > alg2_len ? alg1_len : alg2_len;
  666. /* If both are wildcards, return most restrictive wildcard */
  667. if (((alg1 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG) != 0) &&
  668. ((alg2 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG) != 0)) {
  669. return PSA_ALG_AT_LEAST_THIS_LENGTH_MAC(alg1, restricted_len);
  670. }
  671. /* If only one is an at-least-this-length policy, the intersection would
  672. * be the other (fixed-length) policy as long as said fixed length is
  673. * equal to or larger than the shortest allowed length. */
  674. if ((alg1 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG) != 0) {
  675. return (alg1_len <= alg2_len) ? alg2 : 0;
  676. }
  677. if ((alg2 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG) != 0) {
  678. return (alg2_len <= alg1_len) ? alg1 : 0;
  679. }
  680. /* If none of them are wildcards, check whether they define the same tag
  681. * length. This is still possible here when one is default-length and
  682. * the other specific-length. Ensure to always return the
  683. * specific-length version for the intersection. */
  684. if (alg1_len == alg2_len) {
  685. return PSA_ALG_TRUNCATED_MAC(alg1, alg1_len);
  686. }
  687. }
  688. /* If the policies are incompatible, allow nothing. */
  689. return 0;
  690. }
  691. static int psa_key_algorithm_permits(psa_key_type_t key_type,
  692. psa_algorithm_t policy_alg,
  693. psa_algorithm_t requested_alg)
  694. {
  695. /* Common case: the policy only allows requested_alg. */
  696. if (requested_alg == policy_alg) {
  697. return 1;
  698. }
  699. /* If policy_alg is a hash-and-sign with a wildcard for the hash,
  700. * and requested_alg is the same hash-and-sign family with any hash,
  701. * then requested_alg is compliant with policy_alg. */
  702. if (PSA_ALG_IS_SIGN_HASH(requested_alg) &&
  703. PSA_ALG_SIGN_GET_HASH(policy_alg) == PSA_ALG_ANY_HASH) {
  704. return (policy_alg & ~PSA_ALG_HASH_MASK) ==
  705. (requested_alg & ~PSA_ALG_HASH_MASK);
  706. }
  707. /* If policy_alg is a wildcard AEAD algorithm of the same base as
  708. * the requested algorithm, check the requested tag length to be
  709. * equal-length or longer than the wildcard-specified length. */
  710. if (PSA_ALG_IS_AEAD(policy_alg) &&
  711. PSA_ALG_IS_AEAD(requested_alg) &&
  712. (PSA_ALG_AEAD_WITH_SHORTENED_TAG(policy_alg, 0) ==
  713. PSA_ALG_AEAD_WITH_SHORTENED_TAG(requested_alg, 0)) &&
  714. ((policy_alg & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG) != 0)) {
  715. return PSA_ALG_AEAD_GET_TAG_LENGTH(policy_alg) <=
  716. PSA_ALG_AEAD_GET_TAG_LENGTH(requested_alg);
  717. }
  718. /* If policy_alg is a MAC algorithm of the same base as the requested
  719. * algorithm, check whether their MAC lengths are compatible. */
  720. if (PSA_ALG_IS_MAC(policy_alg) &&
  721. PSA_ALG_IS_MAC(requested_alg) &&
  722. (PSA_ALG_FULL_LENGTH_MAC(policy_alg) ==
  723. PSA_ALG_FULL_LENGTH_MAC(requested_alg))) {
  724. /* Validate the combination of key type and algorithm. Since the policy
  725. * and requested algorithms are the same, we only need this once. */
  726. if (PSA_SUCCESS != psa_mac_key_can_do(policy_alg, key_type)) {
  727. return 0;
  728. }
  729. /* Get both the requested output length for the algorithm which is to be
  730. * verified, and the default output length for the base algorithm.
  731. * Note that none of the currently supported algorithms have an output
  732. * length dependent on actual key size, so setting it to a bogus value
  733. * of 0 is currently OK. */
  734. size_t requested_output_length = PSA_MAC_LENGTH(
  735. key_type, 0, requested_alg);
  736. size_t default_output_length = PSA_MAC_LENGTH(
  737. key_type, 0,
  738. PSA_ALG_FULL_LENGTH_MAC(requested_alg));
  739. /* If the policy is default-length, only allow an algorithm with
  740. * a declared exact-length matching the default. */
  741. if (PSA_MAC_TRUNCATED_LENGTH(policy_alg) == 0) {
  742. return requested_output_length == default_output_length;
  743. }
  744. /* If the requested algorithm is default-length, allow it if the policy
  745. * length exactly matches the default length. */
  746. if (PSA_MAC_TRUNCATED_LENGTH(requested_alg) == 0 &&
  747. PSA_MAC_TRUNCATED_LENGTH(policy_alg) == default_output_length) {
  748. return 1;
  749. }
  750. /* If policy_alg is an at-least-this-length wildcard MAC algorithm,
  751. * check for the requested MAC length to be equal to or longer than the
  752. * minimum allowed length. */
  753. if ((policy_alg & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG) != 0) {
  754. return PSA_MAC_TRUNCATED_LENGTH(policy_alg) <=
  755. requested_output_length;
  756. }
  757. }
  758. /* If policy_alg is a generic key agreement operation, then using it for
  759. * a key derivation with that key agreement should also be allowed. This
  760. * behaviour is expected to be defined in a future specification version. */
  761. if (PSA_ALG_IS_RAW_KEY_AGREEMENT(policy_alg) &&
  762. PSA_ALG_IS_KEY_AGREEMENT(requested_alg)) {
  763. return PSA_ALG_KEY_AGREEMENT_GET_BASE(requested_alg) ==
  764. policy_alg;
  765. }
  766. /* If it isn't explicitly permitted, it's forbidden. */
  767. return 0;
  768. }
  769. /** Test whether a policy permits an algorithm.
  770. *
  771. * The caller must test usage flags separately.
  772. *
  773. * \note This function requires providing the key type for which the policy is
  774. * being validated, since some algorithm policy definitions (e.g. MAC)
  775. * have different properties depending on what kind of cipher it is
  776. * combined with.
  777. *
  778. * \retval PSA_SUCCESS When \p alg is a specific algorithm
  779. * allowed by the \p policy.
  780. * \retval PSA_ERROR_INVALID_ARGUMENT When \p alg is not a specific algorithm
  781. * \retval PSA_ERROR_NOT_PERMITTED When \p alg is a specific algorithm, but
  782. * the \p policy does not allow it.
  783. */
  784. static psa_status_t psa_key_policy_permits(const psa_key_policy_t *policy,
  785. psa_key_type_t key_type,
  786. psa_algorithm_t alg)
  787. {
  788. /* '0' is not a valid algorithm */
  789. if (alg == 0) {
  790. return PSA_ERROR_INVALID_ARGUMENT;
  791. }
  792. /* A requested algorithm cannot be a wildcard. */
  793. if (PSA_ALG_IS_WILDCARD(alg)) {
  794. return PSA_ERROR_INVALID_ARGUMENT;
  795. }
  796. if (psa_key_algorithm_permits(key_type, policy->alg, alg) ||
  797. psa_key_algorithm_permits(key_type, policy->alg2, alg)) {
  798. return PSA_SUCCESS;
  799. } else {
  800. return PSA_ERROR_NOT_PERMITTED;
  801. }
  802. }
  803. /** Restrict a key policy based on a constraint.
  804. *
  805. * \note This function requires providing the key type for which the policy is
  806. * being restricted, since some algorithm policy definitions (e.g. MAC)
  807. * have different properties depending on what kind of cipher it is
  808. * combined with.
  809. *
  810. * \param[in] key_type The key type for which to restrict the policy
  811. * \param[in,out] policy The policy to restrict.
  812. * \param[in] constraint The policy constraint to apply.
  813. *
  814. * \retval #PSA_SUCCESS
  815. * \c *policy contains the intersection of the original value of
  816. * \c *policy and \c *constraint.
  817. * \retval #PSA_ERROR_INVALID_ARGUMENT
  818. * \c key_type, \c *policy and \c *constraint are incompatible.
  819. * \c *policy is unchanged.
  820. */
  821. static psa_status_t psa_restrict_key_policy(
  822. psa_key_type_t key_type,
  823. psa_key_policy_t *policy,
  824. const psa_key_policy_t *constraint)
  825. {
  826. psa_algorithm_t intersection_alg =
  827. psa_key_policy_algorithm_intersection(key_type, policy->alg,
  828. constraint->alg);
  829. psa_algorithm_t intersection_alg2 =
  830. psa_key_policy_algorithm_intersection(key_type, policy->alg2,
  831. constraint->alg2);
  832. if (intersection_alg == 0 && policy->alg != 0 && constraint->alg != 0) {
  833. return PSA_ERROR_INVALID_ARGUMENT;
  834. }
  835. if (intersection_alg2 == 0 && policy->alg2 != 0 && constraint->alg2 != 0) {
  836. return PSA_ERROR_INVALID_ARGUMENT;
  837. }
  838. policy->usage &= constraint->usage;
  839. policy->alg = intersection_alg;
  840. policy->alg2 = intersection_alg2;
  841. return PSA_SUCCESS;
  842. }
  843. /** Get the description of a key given its identifier and policy constraints
  844. * and lock it.
  845. *
  846. * The key must have allow all the usage flags set in \p usage. If \p alg is
  847. * nonzero, the key must allow operations with this algorithm. If \p alg is
  848. * zero, the algorithm is not checked.
  849. *
  850. * In case of a persistent key, the function loads the description of the key
  851. * into a key slot if not already done.
  852. *
  853. * On success, the returned key slot is locked. It is the responsibility of
  854. * the caller to unlock the key slot when it does not access it anymore.
  855. */
  856. static psa_status_t psa_get_and_lock_key_slot_with_policy(
  857. mbedtls_svc_key_id_t key,
  858. psa_key_slot_t **p_slot,
  859. psa_key_usage_t usage,
  860. psa_algorithm_t alg)
  861. {
  862. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  863. psa_key_slot_t *slot = NULL;
  864. status = psa_get_and_lock_key_slot(key, p_slot);
  865. if (status != PSA_SUCCESS) {
  866. return status;
  867. }
  868. slot = *p_slot;
  869. /* Enforce that usage policy for the key slot contains all the flags
  870. * required by the usage parameter. There is one exception: public
  871. * keys can always be exported, so we treat public key objects as
  872. * if they had the export flag. */
  873. if (PSA_KEY_TYPE_IS_PUBLIC_KEY(slot->attr.type)) {
  874. usage &= ~PSA_KEY_USAGE_EXPORT;
  875. }
  876. if ((slot->attr.policy.usage & usage) != usage) {
  877. status = PSA_ERROR_NOT_PERMITTED;
  878. goto error;
  879. }
  880. /* Enforce that the usage policy permits the requested algorithm. */
  881. if (alg != 0) {
  882. status = psa_key_policy_permits(&slot->attr.policy,
  883. slot->attr.type,
  884. alg);
  885. if (status != PSA_SUCCESS) {
  886. goto error;
  887. }
  888. }
  889. return PSA_SUCCESS;
  890. error:
  891. *p_slot = NULL;
  892. psa_unlock_key_slot(slot);
  893. return status;
  894. }
  895. /** Get a key slot containing a transparent key and lock it.
  896. *
  897. * A transparent key is a key for which the key material is directly
  898. * available, as opposed to a key in a secure element and/or to be used
  899. * by a secure element.
  900. *
  901. * This is a temporary function that may be used instead of
  902. * psa_get_and_lock_key_slot_with_policy() when there is no opaque key support
  903. * for a cryptographic operation.
  904. *
  905. * On success, the returned key slot is locked. It is the responsibility of the
  906. * caller to unlock the key slot when it does not access it anymore.
  907. */
  908. static psa_status_t psa_get_and_lock_transparent_key_slot_with_policy(
  909. mbedtls_svc_key_id_t key,
  910. psa_key_slot_t **p_slot,
  911. psa_key_usage_t usage,
  912. psa_algorithm_t alg)
  913. {
  914. psa_status_t status = psa_get_and_lock_key_slot_with_policy(key, p_slot,
  915. usage, alg);
  916. if (status != PSA_SUCCESS) {
  917. return status;
  918. }
  919. if (psa_key_lifetime_is_external((*p_slot)->attr.lifetime)) {
  920. psa_unlock_key_slot(*p_slot);
  921. *p_slot = NULL;
  922. return PSA_ERROR_NOT_SUPPORTED;
  923. }
  924. return PSA_SUCCESS;
  925. }
  926. psa_status_t psa_remove_key_data_from_memory(psa_key_slot_t *slot)
  927. {
  928. /* Data pointer will always be either a valid pointer or NULL in an
  929. * initialized slot, so we can just free it. */
  930. if (slot->key.data != NULL) {
  931. mbedtls_platform_zeroize(slot->key.data, slot->key.bytes);
  932. }
  933. mbedtls_free(slot->key.data);
  934. slot->key.data = NULL;
  935. slot->key.bytes = 0;
  936. return PSA_SUCCESS;
  937. }
  938. /** Completely wipe a slot in memory, including its policy.
  939. * Persistent storage is not affected. */
  940. psa_status_t psa_wipe_key_slot(psa_key_slot_t *slot)
  941. {
  942. psa_status_t status = psa_remove_key_data_from_memory(slot);
  943. /*
  944. * As the return error code may not be handled in case of multiple errors,
  945. * do our best to report an unexpected lock counter. Assert with
  946. * MBEDTLS_TEST_HOOK_TEST_ASSERT that the lock counter is equal to one:
  947. * if the MBEDTLS_TEST_HOOKS configuration option is enabled and the
  948. * function is called as part of the execution of a test suite, the
  949. * execution of the test suite is stopped in error if the assertion fails.
  950. */
  951. if (slot->lock_count != 1) {
  952. MBEDTLS_TEST_HOOK_TEST_ASSERT(slot->lock_count == 1);
  953. status = PSA_ERROR_CORRUPTION_DETECTED;
  954. }
  955. /* Multipart operations may still be using the key. This is safe
  956. * because all multipart operation objects are independent from
  957. * the key slot: if they need to access the key after the setup
  958. * phase, they have a copy of the key. Note that this means that
  959. * key material can linger until all operations are completed. */
  960. /* At this point, key material and other type-specific content has
  961. * been wiped. Clear remaining metadata. We can call memset and not
  962. * zeroize because the metadata is not particularly sensitive. */
  963. memset(slot, 0, sizeof(*slot));
  964. return status;
  965. }
  966. psa_status_t psa_destroy_key(mbedtls_svc_key_id_t key)
  967. {
  968. psa_key_slot_t *slot;
  969. psa_status_t status; /* status of the last operation */
  970. psa_status_t overall_status = PSA_SUCCESS;
  971. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  972. psa_se_drv_table_entry_t *driver;
  973. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  974. if (mbedtls_svc_key_id_is_null(key)) {
  975. return PSA_SUCCESS;
  976. }
  977. /*
  978. * Get the description of the key in a key slot. In case of a persistent
  979. * key, this will load the key description from persistent memory if not
  980. * done yet. We cannot avoid this loading as without it we don't know if
  981. * the key is operated by an SE or not and this information is needed by
  982. * the current implementation.
  983. */
  984. status = psa_get_and_lock_key_slot(key, &slot);
  985. if (status != PSA_SUCCESS) {
  986. return status;
  987. }
  988. /*
  989. * If the key slot containing the key description is under access by the
  990. * library (apart from the present access), the key cannot be destroyed
  991. * yet. For the time being, just return in error. Eventually (to be
  992. * implemented), the key should be destroyed when all accesses have
  993. * stopped.
  994. */
  995. if (slot->lock_count > 1) {
  996. psa_unlock_key_slot(slot);
  997. return PSA_ERROR_GENERIC_ERROR;
  998. }
  999. if (PSA_KEY_LIFETIME_IS_READ_ONLY(slot->attr.lifetime)) {
  1000. /* Refuse the destruction of a read-only key (which may or may not work
  1001. * if we attempt it, depending on whether the key is merely read-only
  1002. * by policy or actually physically read-only).
  1003. * Just do the best we can, which is to wipe the copy in memory
  1004. * (done in this function's cleanup code). */
  1005. overall_status = PSA_ERROR_NOT_PERMITTED;
  1006. goto exit;
  1007. }
  1008. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1009. driver = psa_get_se_driver_entry(slot->attr.lifetime);
  1010. if (driver != NULL) {
  1011. /* For a key in a secure element, we need to do three things:
  1012. * remove the key file in internal storage, destroy the
  1013. * key inside the secure element, and update the driver's
  1014. * persistent data. Start a transaction that will encompass these
  1015. * three actions. */
  1016. psa_crypto_prepare_transaction(PSA_CRYPTO_TRANSACTION_DESTROY_KEY);
  1017. psa_crypto_transaction.key.lifetime = slot->attr.lifetime;
  1018. psa_crypto_transaction.key.slot = psa_key_slot_get_slot_number(slot);
  1019. psa_crypto_transaction.key.id = slot->attr.id;
  1020. status = psa_crypto_save_transaction();
  1021. if (status != PSA_SUCCESS) {
  1022. (void) psa_crypto_stop_transaction();
  1023. /* We should still try to destroy the key in the secure
  1024. * element and the key metadata in storage. This is especially
  1025. * important if the error is that the storage is full.
  1026. * But how to do it exactly without risking an inconsistent
  1027. * state after a reset?
  1028. * https://github.com/ARMmbed/mbed-crypto/issues/215
  1029. */
  1030. overall_status = status;
  1031. goto exit;
  1032. }
  1033. status = psa_destroy_se_key(driver,
  1034. psa_key_slot_get_slot_number(slot));
  1035. if (overall_status == PSA_SUCCESS) {
  1036. overall_status = status;
  1037. }
  1038. }
  1039. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1040. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C)
  1041. if (!PSA_KEY_LIFETIME_IS_VOLATILE(slot->attr.lifetime)) {
  1042. status = psa_destroy_persistent_key(slot->attr.id);
  1043. if (overall_status == PSA_SUCCESS) {
  1044. overall_status = status;
  1045. }
  1046. /* TODO: other slots may have a copy of the same key. We should
  1047. * invalidate them.
  1048. * https://github.com/ARMmbed/mbed-crypto/issues/214
  1049. */
  1050. }
  1051. #endif /* defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) */
  1052. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1053. if (driver != NULL) {
  1054. status = psa_save_se_persistent_data(driver);
  1055. if (overall_status == PSA_SUCCESS) {
  1056. overall_status = status;
  1057. }
  1058. status = psa_crypto_stop_transaction();
  1059. if (overall_status == PSA_SUCCESS) {
  1060. overall_status = status;
  1061. }
  1062. }
  1063. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1064. exit:
  1065. status = psa_wipe_key_slot(slot);
  1066. /* Prioritize CORRUPTION_DETECTED from wiping over a storage error */
  1067. if (status != PSA_SUCCESS) {
  1068. overall_status = status;
  1069. }
  1070. return overall_status;
  1071. }
  1072. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1073. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1074. static psa_status_t psa_get_rsa_public_exponent(
  1075. const mbedtls_rsa_context *rsa,
  1076. psa_key_attributes_t *attributes)
  1077. {
  1078. mbedtls_mpi mpi;
  1079. int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
  1080. uint8_t *buffer = NULL;
  1081. size_t buflen;
  1082. mbedtls_mpi_init(&mpi);
  1083. ret = mbedtls_rsa_export(rsa, NULL, NULL, NULL, NULL, &mpi);
  1084. if (ret != 0) {
  1085. goto exit;
  1086. }
  1087. if (mbedtls_mpi_cmp_int(&mpi, 65537) == 0) {
  1088. /* It's the default value, which is reported as an empty string,
  1089. * so there's nothing to do. */
  1090. goto exit;
  1091. }
  1092. buflen = mbedtls_mpi_size(&mpi);
  1093. buffer = mbedtls_calloc(1, buflen);
  1094. if (buffer == NULL) {
  1095. ret = MBEDTLS_ERR_MPI_ALLOC_FAILED;
  1096. goto exit;
  1097. }
  1098. ret = mbedtls_mpi_write_binary(&mpi, buffer, buflen);
  1099. if (ret != 0) {
  1100. goto exit;
  1101. }
  1102. attributes->domain_parameters = buffer;
  1103. attributes->domain_parameters_size = buflen;
  1104. exit:
  1105. mbedtls_mpi_free(&mpi);
  1106. if (ret != 0) {
  1107. mbedtls_free(buffer);
  1108. }
  1109. return mbedtls_to_psa_error(ret);
  1110. }
  1111. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1112. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1113. /** Retrieve all the publicly-accessible attributes of a key.
  1114. */
  1115. psa_status_t psa_get_key_attributes(mbedtls_svc_key_id_t key,
  1116. psa_key_attributes_t *attributes)
  1117. {
  1118. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1119. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1120. psa_key_slot_t *slot;
  1121. psa_reset_key_attributes(attributes);
  1122. status = psa_get_and_lock_key_slot_with_policy(key, &slot, 0, 0);
  1123. if (status != PSA_SUCCESS) {
  1124. return status;
  1125. }
  1126. attributes->core = slot->attr;
  1127. attributes->core.flags &= (MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY |
  1128. MBEDTLS_PSA_KA_MASK_DUAL_USE);
  1129. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1130. if (psa_get_se_driver_entry(slot->attr.lifetime) != NULL) {
  1131. psa_set_key_slot_number(attributes,
  1132. psa_key_slot_get_slot_number(slot));
  1133. }
  1134. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1135. switch (slot->attr.type) {
  1136. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1137. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1138. case PSA_KEY_TYPE_RSA_KEY_PAIR:
  1139. case PSA_KEY_TYPE_RSA_PUBLIC_KEY:
  1140. /* TODO: reporting the public exponent for opaque keys
  1141. * is not yet implemented.
  1142. * https://github.com/ARMmbed/mbed-crypto/issues/216
  1143. */
  1144. if (!psa_key_lifetime_is_external(slot->attr.lifetime)) {
  1145. mbedtls_rsa_context *rsa = NULL;
  1146. status = mbedtls_psa_rsa_load_representation(
  1147. slot->attr.type,
  1148. slot->key.data,
  1149. slot->key.bytes,
  1150. &rsa);
  1151. if (status != PSA_SUCCESS) {
  1152. break;
  1153. }
  1154. status = psa_get_rsa_public_exponent(rsa,
  1155. attributes);
  1156. mbedtls_rsa_free(rsa);
  1157. mbedtls_free(rsa);
  1158. }
  1159. break;
  1160. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1161. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1162. default:
  1163. /* Nothing else to do. */
  1164. break;
  1165. }
  1166. if (status != PSA_SUCCESS) {
  1167. psa_reset_key_attributes(attributes);
  1168. }
  1169. unlock_status = psa_unlock_key_slot(slot);
  1170. return (status == PSA_SUCCESS) ? unlock_status : status;
  1171. }
  1172. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1173. psa_status_t psa_get_key_slot_number(
  1174. const psa_key_attributes_t *attributes,
  1175. psa_key_slot_number_t *slot_number)
  1176. {
  1177. if (attributes->core.flags & MBEDTLS_PSA_KA_FLAG_HAS_SLOT_NUMBER) {
  1178. *slot_number = attributes->slot_number;
  1179. return PSA_SUCCESS;
  1180. } else {
  1181. return PSA_ERROR_INVALID_ARGUMENT;
  1182. }
  1183. }
  1184. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1185. static psa_status_t psa_export_key_buffer_internal(const uint8_t *key_buffer,
  1186. size_t key_buffer_size,
  1187. uint8_t *data,
  1188. size_t data_size,
  1189. size_t *data_length)
  1190. {
  1191. if (key_buffer_size > data_size) {
  1192. return PSA_ERROR_BUFFER_TOO_SMALL;
  1193. }
  1194. memcpy(data, key_buffer, key_buffer_size);
  1195. memset(data + key_buffer_size, 0,
  1196. data_size - key_buffer_size);
  1197. *data_length = key_buffer_size;
  1198. return PSA_SUCCESS;
  1199. }
  1200. psa_status_t psa_export_key_internal(
  1201. const psa_key_attributes_t *attributes,
  1202. const uint8_t *key_buffer, size_t key_buffer_size,
  1203. uint8_t *data, size_t data_size, size_t *data_length)
  1204. {
  1205. psa_key_type_t type = attributes->core.type;
  1206. if (key_type_is_raw_bytes(type) ||
  1207. PSA_KEY_TYPE_IS_RSA(type) ||
  1208. PSA_KEY_TYPE_IS_ECC(type)) {
  1209. return psa_export_key_buffer_internal(
  1210. key_buffer, key_buffer_size,
  1211. data, data_size, data_length);
  1212. } else {
  1213. /* This shouldn't happen in the reference implementation, but
  1214. it is valid for a special-purpose implementation to omit
  1215. support for exporting certain key types. */
  1216. return PSA_ERROR_NOT_SUPPORTED;
  1217. }
  1218. }
  1219. psa_status_t psa_export_key(mbedtls_svc_key_id_t key,
  1220. uint8_t *data,
  1221. size_t data_size,
  1222. size_t *data_length)
  1223. {
  1224. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1225. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1226. psa_key_slot_t *slot;
  1227. /* Reject a zero-length output buffer now, since this can never be a
  1228. * valid key representation. This way we know that data must be a valid
  1229. * pointer and we can do things like memset(data, ..., data_size). */
  1230. if (data_size == 0) {
  1231. return PSA_ERROR_BUFFER_TOO_SMALL;
  1232. }
  1233. /* Set the key to empty now, so that even when there are errors, we always
  1234. * set data_length to a value between 0 and data_size. On error, setting
  1235. * the key to empty is a good choice because an empty key representation is
  1236. * unlikely to be accepted anywhere. */
  1237. *data_length = 0;
  1238. /* Export requires the EXPORT flag. There is an exception for public keys,
  1239. * which don't require any flag, but
  1240. * psa_get_and_lock_key_slot_with_policy() takes care of this.
  1241. */
  1242. status = psa_get_and_lock_key_slot_with_policy(key, &slot,
  1243. PSA_KEY_USAGE_EXPORT, 0);
  1244. if (status != PSA_SUCCESS) {
  1245. return status;
  1246. }
  1247. psa_key_attributes_t attributes = {
  1248. .core = slot->attr
  1249. };
  1250. status = psa_driver_wrapper_export_key(&attributes,
  1251. slot->key.data, slot->key.bytes,
  1252. data, data_size, data_length);
  1253. unlock_status = psa_unlock_key_slot(slot);
  1254. return (status == PSA_SUCCESS) ? unlock_status : status;
  1255. }
  1256. psa_status_t psa_export_public_key_internal(
  1257. const psa_key_attributes_t *attributes,
  1258. const uint8_t *key_buffer,
  1259. size_t key_buffer_size,
  1260. uint8_t *data,
  1261. size_t data_size,
  1262. size_t *data_length)
  1263. {
  1264. psa_key_type_t type = attributes->core.type;
  1265. if (PSA_KEY_TYPE_IS_RSA(type) || PSA_KEY_TYPE_IS_ECC(type)) {
  1266. if (PSA_KEY_TYPE_IS_PUBLIC_KEY(type)) {
  1267. /* Exporting public -> public */
  1268. return psa_export_key_buffer_internal(
  1269. key_buffer, key_buffer_size,
  1270. data, data_size, data_length);
  1271. }
  1272. if (PSA_KEY_TYPE_IS_RSA(type)) {
  1273. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1274. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1275. return mbedtls_psa_rsa_export_public_key(attributes,
  1276. key_buffer,
  1277. key_buffer_size,
  1278. data,
  1279. data_size,
  1280. data_length);
  1281. #else
  1282. /* We don't know how to convert a private RSA key to public. */
  1283. return PSA_ERROR_NOT_SUPPORTED;
  1284. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1285. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1286. } else {
  1287. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  1288. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY)
  1289. return mbedtls_psa_ecp_export_public_key(attributes,
  1290. key_buffer,
  1291. key_buffer_size,
  1292. data,
  1293. data_size,
  1294. data_length);
  1295. #else
  1296. /* We don't know how to convert a private ECC key to public */
  1297. return PSA_ERROR_NOT_SUPPORTED;
  1298. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  1299. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) */
  1300. }
  1301. } else {
  1302. /* This shouldn't happen in the reference implementation, but
  1303. it is valid for a special-purpose implementation to omit
  1304. support for exporting certain key types. */
  1305. return PSA_ERROR_NOT_SUPPORTED;
  1306. }
  1307. }
  1308. psa_status_t psa_export_public_key(mbedtls_svc_key_id_t key,
  1309. uint8_t *data,
  1310. size_t data_size,
  1311. size_t *data_length)
  1312. {
  1313. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1314. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1315. psa_key_slot_t *slot;
  1316. /* Reject a zero-length output buffer now, since this can never be a
  1317. * valid key representation. This way we know that data must be a valid
  1318. * pointer and we can do things like memset(data, ..., data_size). */
  1319. if (data_size == 0) {
  1320. return PSA_ERROR_BUFFER_TOO_SMALL;
  1321. }
  1322. /* Set the key to empty now, so that even when there are errors, we always
  1323. * set data_length to a value between 0 and data_size. On error, setting
  1324. * the key to empty is a good choice because an empty key representation is
  1325. * unlikely to be accepted anywhere. */
  1326. *data_length = 0;
  1327. /* Exporting a public key doesn't require a usage flag. */
  1328. status = psa_get_and_lock_key_slot_with_policy(key, &slot, 0, 0);
  1329. if (status != PSA_SUCCESS) {
  1330. return status;
  1331. }
  1332. if (!PSA_KEY_TYPE_IS_ASYMMETRIC(slot->attr.type)) {
  1333. status = PSA_ERROR_INVALID_ARGUMENT;
  1334. goto exit;
  1335. }
  1336. psa_key_attributes_t attributes = {
  1337. .core = slot->attr
  1338. };
  1339. status = psa_driver_wrapper_export_public_key(
  1340. &attributes, slot->key.data, slot->key.bytes,
  1341. data, data_size, data_length);
  1342. exit:
  1343. unlock_status = psa_unlock_key_slot(slot);
  1344. return (status == PSA_SUCCESS) ? unlock_status : status;
  1345. }
  1346. MBEDTLS_STATIC_ASSERT(
  1347. (MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_DUAL_USE) == 0,
  1348. "One or more key attribute flag is listed as both external-only and dual-use")
  1349. MBEDTLS_STATIC_ASSERT(
  1350. (PSA_KA_MASK_INTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_DUAL_USE) == 0,
  1351. "One or more key attribute flag is listed as both internal-only and dual-use")
  1352. MBEDTLS_STATIC_ASSERT(
  1353. (PSA_KA_MASK_INTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY) == 0,
  1354. "One or more key attribute flag is listed as both internal-only and external-only")
  1355. /** Validate that a key policy is internally well-formed.
  1356. *
  1357. * This function only rejects invalid policies. It does not validate the
  1358. * consistency of the policy with respect to other attributes of the key
  1359. * such as the key type.
  1360. */
  1361. static psa_status_t psa_validate_key_policy(const psa_key_policy_t *policy)
  1362. {
  1363. if ((policy->usage & ~(PSA_KEY_USAGE_EXPORT |
  1364. PSA_KEY_USAGE_COPY |
  1365. PSA_KEY_USAGE_ENCRYPT |
  1366. PSA_KEY_USAGE_DECRYPT |
  1367. PSA_KEY_USAGE_SIGN_MESSAGE |
  1368. PSA_KEY_USAGE_VERIFY_MESSAGE |
  1369. PSA_KEY_USAGE_SIGN_HASH |
  1370. PSA_KEY_USAGE_VERIFY_HASH |
  1371. PSA_KEY_USAGE_VERIFY_DERIVATION |
  1372. PSA_KEY_USAGE_DERIVE)) != 0) {
  1373. return PSA_ERROR_INVALID_ARGUMENT;
  1374. }
  1375. return PSA_SUCCESS;
  1376. }
  1377. /** Validate the internal consistency of key attributes.
  1378. *
  1379. * This function only rejects invalid attribute values. If does not
  1380. * validate the consistency of the attributes with any key data that may
  1381. * be involved in the creation of the key.
  1382. *
  1383. * Call this function early in the key creation process.
  1384. *
  1385. * \param[in] attributes Key attributes for the new key.
  1386. * \param[out] p_drv On any return, the driver for the key, if any.
  1387. * NULL for a transparent key.
  1388. *
  1389. */
  1390. static psa_status_t psa_validate_key_attributes(
  1391. const psa_key_attributes_t *attributes,
  1392. psa_se_drv_table_entry_t **p_drv)
  1393. {
  1394. psa_status_t status = PSA_ERROR_INVALID_ARGUMENT;
  1395. psa_key_lifetime_t lifetime = psa_get_key_lifetime(attributes);
  1396. mbedtls_svc_key_id_t key = psa_get_key_id(attributes);
  1397. status = psa_validate_key_location(lifetime, p_drv);
  1398. if (status != PSA_SUCCESS) {
  1399. return status;
  1400. }
  1401. status = psa_validate_key_persistence(lifetime);
  1402. if (status != PSA_SUCCESS) {
  1403. return status;
  1404. }
  1405. if (PSA_KEY_LIFETIME_IS_VOLATILE(lifetime)) {
  1406. if (MBEDTLS_SVC_KEY_ID_GET_KEY_ID(key) != 0) {
  1407. return PSA_ERROR_INVALID_ARGUMENT;
  1408. }
  1409. } else {
  1410. if (!psa_is_valid_key_id(psa_get_key_id(attributes), 0)) {
  1411. return PSA_ERROR_INVALID_ARGUMENT;
  1412. }
  1413. }
  1414. status = psa_validate_key_policy(&attributes->core.policy);
  1415. if (status != PSA_SUCCESS) {
  1416. return status;
  1417. }
  1418. /* Refuse to create overly large keys.
  1419. * Note that this doesn't trigger on import if the attributes don't
  1420. * explicitly specify a size (so psa_get_key_bits returns 0), so
  1421. * psa_import_key() needs its own checks. */
  1422. if (psa_get_key_bits(attributes) > PSA_MAX_KEY_BITS) {
  1423. return PSA_ERROR_NOT_SUPPORTED;
  1424. }
  1425. /* Reject invalid flags. These should not be reachable through the API. */
  1426. if (attributes->core.flags & ~(MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY |
  1427. MBEDTLS_PSA_KA_MASK_DUAL_USE)) {
  1428. return PSA_ERROR_INVALID_ARGUMENT;
  1429. }
  1430. return PSA_SUCCESS;
  1431. }
  1432. /** Prepare a key slot to receive key material.
  1433. *
  1434. * This function allocates a key slot and sets its metadata.
  1435. *
  1436. * If this function fails, call psa_fail_key_creation().
  1437. *
  1438. * This function is intended to be used as follows:
  1439. * -# Call psa_start_key_creation() to allocate a key slot, prepare
  1440. * it with the specified attributes, and in case of a volatile key assign it
  1441. * a volatile key identifier.
  1442. * -# Populate the slot with the key material.
  1443. * -# Call psa_finish_key_creation() to finalize the creation of the slot.
  1444. * In case of failure at any step, stop the sequence and call
  1445. * psa_fail_key_creation().
  1446. *
  1447. * On success, the key slot is locked. It is the responsibility of the caller
  1448. * to unlock the key slot when it does not access it anymore.
  1449. *
  1450. * \param method An identification of the calling function.
  1451. * \param[in] attributes Key attributes for the new key.
  1452. * \param[out] p_slot On success, a pointer to the prepared slot.
  1453. * \param[out] p_drv On any return, the driver for the key, if any.
  1454. * NULL for a transparent key.
  1455. *
  1456. * \retval #PSA_SUCCESS
  1457. * The key slot is ready to receive key material.
  1458. * \return If this function fails, the key slot is an invalid state.
  1459. * You must call psa_fail_key_creation() to wipe and free the slot.
  1460. */
  1461. static psa_status_t psa_start_key_creation(
  1462. psa_key_creation_method_t method,
  1463. const psa_key_attributes_t *attributes,
  1464. psa_key_slot_t **p_slot,
  1465. psa_se_drv_table_entry_t **p_drv)
  1466. {
  1467. psa_status_t status;
  1468. psa_key_id_t volatile_key_id;
  1469. psa_key_slot_t *slot;
  1470. (void) method;
  1471. *p_drv = NULL;
  1472. status = psa_validate_key_attributes(attributes, p_drv);
  1473. if (status != PSA_SUCCESS) {
  1474. return status;
  1475. }
  1476. status = psa_get_empty_key_slot(&volatile_key_id, p_slot);
  1477. if (status != PSA_SUCCESS) {
  1478. return status;
  1479. }
  1480. slot = *p_slot;
  1481. /* We're storing the declared bit-size of the key. It's up to each
  1482. * creation mechanism to verify that this information is correct.
  1483. * It's automatically correct for mechanisms that use the bit-size as
  1484. * an input (generate, device) but not for those where the bit-size
  1485. * is optional (import, copy). In case of a volatile key, assign it the
  1486. * volatile key identifier associated to the slot returned to contain its
  1487. * definition. */
  1488. slot->attr = attributes->core;
  1489. if (PSA_KEY_LIFETIME_IS_VOLATILE(slot->attr.lifetime)) {
  1490. #if !defined(MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER)
  1491. slot->attr.id = volatile_key_id;
  1492. #else
  1493. slot->attr.id.key_id = volatile_key_id;
  1494. #endif
  1495. }
  1496. /* Erase external-only flags from the internal copy. To access
  1497. * external-only flags, query `attributes`. Thanks to the check
  1498. * in psa_validate_key_attributes(), this leaves the dual-use
  1499. * flags and any internal flag that psa_get_empty_key_slot()
  1500. * may have set. */
  1501. slot->attr.flags &= ~MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY;
  1502. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1503. /* For a key in a secure element, we need to do three things
  1504. * when creating or registering a persistent key:
  1505. * create the key file in internal storage, create the
  1506. * key inside the secure element, and update the driver's
  1507. * persistent data. This is done by starting a transaction that will
  1508. * encompass these three actions.
  1509. * For registering a volatile key, we just need to find an appropriate
  1510. * slot number inside the SE. Since the key is designated volatile, creating
  1511. * a transaction is not required. */
  1512. /* The first thing to do is to find a slot number for the new key.
  1513. * We save the slot number in persistent storage as part of the
  1514. * transaction data. It will be needed to recover if the power
  1515. * fails during the key creation process, to clean up on the secure
  1516. * element side after restarting. Obtaining a slot number from the
  1517. * secure element driver updates its persistent state, but we do not yet
  1518. * save the driver's persistent state, so that if the power fails,
  1519. * we can roll back to a state where the key doesn't exist. */
  1520. if (*p_drv != NULL) {
  1521. psa_key_slot_number_t slot_number;
  1522. status = psa_find_se_slot_for_key(attributes, method, *p_drv,
  1523. &slot_number);
  1524. if (status != PSA_SUCCESS) {
  1525. return status;
  1526. }
  1527. if (!PSA_KEY_LIFETIME_IS_VOLATILE(attributes->core.lifetime)) {
  1528. psa_crypto_prepare_transaction(PSA_CRYPTO_TRANSACTION_CREATE_KEY);
  1529. psa_crypto_transaction.key.lifetime = slot->attr.lifetime;
  1530. psa_crypto_transaction.key.slot = slot_number;
  1531. psa_crypto_transaction.key.id = slot->attr.id;
  1532. status = psa_crypto_save_transaction();
  1533. if (status != PSA_SUCCESS) {
  1534. (void) psa_crypto_stop_transaction();
  1535. return status;
  1536. }
  1537. }
  1538. status = psa_copy_key_material_into_slot(
  1539. slot, (uint8_t *) (&slot_number), sizeof(slot_number));
  1540. }
  1541. if (*p_drv == NULL && method == PSA_KEY_CREATION_REGISTER) {
  1542. /* Key registration only makes sense with a secure element. */
  1543. return PSA_ERROR_INVALID_ARGUMENT;
  1544. }
  1545. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1546. return PSA_SUCCESS;
  1547. }
  1548. /** Finalize the creation of a key once its key material has been set.
  1549. *
  1550. * This entails writing the key to persistent storage.
  1551. *
  1552. * If this function fails, call psa_fail_key_creation().
  1553. * See the documentation of psa_start_key_creation() for the intended use
  1554. * of this function.
  1555. *
  1556. * If the finalization succeeds, the function unlocks the key slot (it was
  1557. * locked by psa_start_key_creation()) and the key slot cannot be accessed
  1558. * anymore as part of the key creation process.
  1559. *
  1560. * \param[in,out] slot Pointer to the slot with key material.
  1561. * \param[in] driver The secure element driver for the key,
  1562. * or NULL for a transparent key.
  1563. * \param[out] key On success, identifier of the key. Note that the
  1564. * key identifier is also stored in the key slot.
  1565. *
  1566. * \retval #PSA_SUCCESS
  1567. * The key was successfully created.
  1568. * \retval #PSA_ERROR_INSUFFICIENT_MEMORY \emptydescription
  1569. * \retval #PSA_ERROR_INSUFFICIENT_STORAGE \emptydescription
  1570. * \retval #PSA_ERROR_ALREADY_EXISTS \emptydescription
  1571. * \retval #PSA_ERROR_DATA_INVALID \emptydescription
  1572. * \retval #PSA_ERROR_DATA_CORRUPT \emptydescription
  1573. * \retval #PSA_ERROR_STORAGE_FAILURE \emptydescription
  1574. *
  1575. * \return If this function fails, the key slot is an invalid state.
  1576. * You must call psa_fail_key_creation() to wipe and free the slot.
  1577. */
  1578. static psa_status_t psa_finish_key_creation(
  1579. psa_key_slot_t *slot,
  1580. psa_se_drv_table_entry_t *driver,
  1581. mbedtls_svc_key_id_t *key)
  1582. {
  1583. psa_status_t status = PSA_SUCCESS;
  1584. (void) slot;
  1585. (void) driver;
  1586. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C)
  1587. if (!PSA_KEY_LIFETIME_IS_VOLATILE(slot->attr.lifetime)) {
  1588. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1589. if (driver != NULL) {
  1590. psa_se_key_data_storage_t data;
  1591. psa_key_slot_number_t slot_number =
  1592. psa_key_slot_get_slot_number(slot);
  1593. MBEDTLS_STATIC_ASSERT(sizeof(slot_number) ==
  1594. sizeof(data.slot_number),
  1595. "Slot number size does not match psa_se_key_data_storage_t");
  1596. memcpy(&data.slot_number, &slot_number, sizeof(slot_number));
  1597. status = psa_save_persistent_key(&slot->attr,
  1598. (uint8_t *) &data,
  1599. sizeof(data));
  1600. } else
  1601. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1602. {
  1603. /* Key material is saved in export representation in the slot, so
  1604. * just pass the slot buffer for storage. */
  1605. status = psa_save_persistent_key(&slot->attr,
  1606. slot->key.data,
  1607. slot->key.bytes);
  1608. }
  1609. }
  1610. #endif /* defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) */
  1611. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1612. /* Finish the transaction for a key creation. This does not
  1613. * happen when registering an existing key. Detect this case
  1614. * by checking whether a transaction is in progress (actual
  1615. * creation of a persistent key in a secure element requires a transaction,
  1616. * but registration or volatile key creation doesn't use one). */
  1617. if (driver != NULL &&
  1618. psa_crypto_transaction.unknown.type == PSA_CRYPTO_TRANSACTION_CREATE_KEY) {
  1619. status = psa_save_se_persistent_data(driver);
  1620. if (status != PSA_SUCCESS) {
  1621. psa_destroy_persistent_key(slot->attr.id);
  1622. return status;
  1623. }
  1624. status = psa_crypto_stop_transaction();
  1625. }
  1626. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1627. if (status == PSA_SUCCESS) {
  1628. *key = slot->attr.id;
  1629. status = psa_unlock_key_slot(slot);
  1630. if (status != PSA_SUCCESS) {
  1631. *key = MBEDTLS_SVC_KEY_ID_INIT;
  1632. }
  1633. }
  1634. return status;
  1635. }
  1636. /** Abort the creation of a key.
  1637. *
  1638. * You may call this function after calling psa_start_key_creation(),
  1639. * or after psa_finish_key_creation() fails. In other circumstances, this
  1640. * function may not clean up persistent storage.
  1641. * See the documentation of psa_start_key_creation() for the intended use
  1642. * of this function.
  1643. *
  1644. * \param[in,out] slot Pointer to the slot with key material.
  1645. * \param[in] driver The secure element driver for the key,
  1646. * or NULL for a transparent key.
  1647. */
  1648. static void psa_fail_key_creation(psa_key_slot_t *slot,
  1649. psa_se_drv_table_entry_t *driver)
  1650. {
  1651. (void) driver;
  1652. if (slot == NULL) {
  1653. return;
  1654. }
  1655. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1656. /* TODO: If the key has already been created in the secure
  1657. * element, and the failure happened later (when saving metadata
  1658. * to internal storage), we need to destroy the key in the secure
  1659. * element.
  1660. * https://github.com/ARMmbed/mbed-crypto/issues/217
  1661. */
  1662. /* Abort the ongoing transaction if any (there may not be one if
  1663. * the creation process failed before starting one, or if the
  1664. * key creation is a registration of a key in a secure element).
  1665. * Earlier functions must already have done what it takes to undo any
  1666. * partial creation. All that's left is to update the transaction data
  1667. * itself. */
  1668. (void) psa_crypto_stop_transaction();
  1669. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1670. psa_wipe_key_slot(slot);
  1671. }
  1672. /** Validate optional attributes during key creation.
  1673. *
  1674. * Some key attributes are optional during key creation. If they are
  1675. * specified in the attributes structure, check that they are consistent
  1676. * with the data in the slot.
  1677. *
  1678. * This function should be called near the end of key creation, after
  1679. * the slot in memory is fully populated but before saving persistent data.
  1680. */
  1681. static psa_status_t psa_validate_optional_attributes(
  1682. const psa_key_slot_t *slot,
  1683. const psa_key_attributes_t *attributes)
  1684. {
  1685. if (attributes->core.type != 0) {
  1686. if (attributes->core.type != slot->attr.type) {
  1687. return PSA_ERROR_INVALID_ARGUMENT;
  1688. }
  1689. }
  1690. if (attributes->domain_parameters_size != 0) {
  1691. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1692. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1693. if (PSA_KEY_TYPE_IS_RSA(slot->attr.type)) {
  1694. mbedtls_rsa_context *rsa = NULL;
  1695. mbedtls_mpi actual, required;
  1696. int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
  1697. psa_status_t status = mbedtls_psa_rsa_load_representation(
  1698. slot->attr.type,
  1699. slot->key.data,
  1700. slot->key.bytes,
  1701. &rsa);
  1702. if (status != PSA_SUCCESS) {
  1703. return status;
  1704. }
  1705. mbedtls_mpi_init(&actual);
  1706. mbedtls_mpi_init(&required);
  1707. ret = mbedtls_rsa_export(rsa,
  1708. NULL, NULL, NULL, NULL, &actual);
  1709. mbedtls_rsa_free(rsa);
  1710. mbedtls_free(rsa);
  1711. if (ret != 0) {
  1712. goto rsa_exit;
  1713. }
  1714. ret = mbedtls_mpi_read_binary(&required,
  1715. attributes->domain_parameters,
  1716. attributes->domain_parameters_size);
  1717. if (ret != 0) {
  1718. goto rsa_exit;
  1719. }
  1720. if (mbedtls_mpi_cmp_mpi(&actual, &required) != 0) {
  1721. ret = MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
  1722. }
  1723. rsa_exit:
  1724. mbedtls_mpi_free(&actual);
  1725. mbedtls_mpi_free(&required);
  1726. if (ret != 0) {
  1727. return mbedtls_to_psa_error(ret);
  1728. }
  1729. } else
  1730. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1731. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1732. {
  1733. return PSA_ERROR_INVALID_ARGUMENT;
  1734. }
  1735. }
  1736. if (attributes->core.bits != 0) {
  1737. if (attributes->core.bits != slot->attr.bits) {
  1738. return PSA_ERROR_INVALID_ARGUMENT;
  1739. }
  1740. }
  1741. return PSA_SUCCESS;
  1742. }
  1743. psa_status_t psa_import_key(const psa_key_attributes_t *attributes,
  1744. const uint8_t *data,
  1745. size_t data_length,
  1746. mbedtls_svc_key_id_t *key)
  1747. {
  1748. psa_status_t status;
  1749. psa_key_slot_t *slot = NULL;
  1750. psa_se_drv_table_entry_t *driver = NULL;
  1751. size_t bits;
  1752. size_t storage_size = data_length;
  1753. *key = MBEDTLS_SVC_KEY_ID_INIT;
  1754. /* Reject zero-length symmetric keys (including raw data key objects).
  1755. * This also rejects any key which might be encoded as an empty string,
  1756. * which is never valid. */
  1757. if (data_length == 0) {
  1758. return PSA_ERROR_INVALID_ARGUMENT;
  1759. }
  1760. /* Ensure that the bytes-to-bits conversion cannot overflow. */
  1761. if (data_length > SIZE_MAX / 8) {
  1762. return PSA_ERROR_NOT_SUPPORTED;
  1763. }
  1764. status = psa_start_key_creation(PSA_KEY_CREATION_IMPORT, attributes,
  1765. &slot, &driver);
  1766. if (status != PSA_SUCCESS) {
  1767. goto exit;
  1768. }
  1769. /* In the case of a transparent key or an opaque key stored in local
  1770. * storage ( thus not in the case of importing a key in a secure element
  1771. * with storage ( MBEDTLS_PSA_CRYPTO_SE_C ) ),we have to allocate a
  1772. * buffer to hold the imported key material. */
  1773. if (slot->key.data == NULL) {
  1774. if (psa_key_lifetime_is_external(attributes->core.lifetime)) {
  1775. status = psa_driver_wrapper_get_key_buffer_size_from_key_data(
  1776. attributes, data, data_length, &storage_size);
  1777. if (status != PSA_SUCCESS) {
  1778. goto exit;
  1779. }
  1780. }
  1781. status = psa_allocate_buffer_to_slot(slot, storage_size);
  1782. if (status != PSA_SUCCESS) {
  1783. goto exit;
  1784. }
  1785. }
  1786. bits = slot->attr.bits;
  1787. status = psa_driver_wrapper_import_key(attributes,
  1788. data, data_length,
  1789. slot->key.data,
  1790. slot->key.bytes,
  1791. &slot->key.bytes, &bits);
  1792. if (status != PSA_SUCCESS) {
  1793. goto exit;
  1794. }
  1795. if (slot->attr.bits == 0) {
  1796. slot->attr.bits = (psa_key_bits_t) bits;
  1797. } else if (bits != slot->attr.bits) {
  1798. status = PSA_ERROR_INVALID_ARGUMENT;
  1799. goto exit;
  1800. }
  1801. /* Enforce a size limit, and in particular ensure that the bit
  1802. * size fits in its representation type.*/
  1803. if (bits > PSA_MAX_KEY_BITS) {
  1804. status = PSA_ERROR_NOT_SUPPORTED;
  1805. goto exit;
  1806. }
  1807. status = psa_validate_optional_attributes(slot, attributes);
  1808. if (status != PSA_SUCCESS) {
  1809. goto exit;
  1810. }
  1811. status = psa_finish_key_creation(slot, driver, key);
  1812. exit:
  1813. if (status != PSA_SUCCESS) {
  1814. psa_fail_key_creation(slot, driver);
  1815. }
  1816. return status;
  1817. }
  1818. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1819. psa_status_t mbedtls_psa_register_se_key(
  1820. const psa_key_attributes_t *attributes)
  1821. {
  1822. psa_status_t status;
  1823. psa_key_slot_t *slot = NULL;
  1824. psa_se_drv_table_entry_t *driver = NULL;
  1825. mbedtls_svc_key_id_t key = MBEDTLS_SVC_KEY_ID_INIT;
  1826. /* Leaving attributes unspecified is not currently supported.
  1827. * It could make sense to query the key type and size from the
  1828. * secure element, but not all secure elements support this
  1829. * and the driver HAL doesn't currently support it. */
  1830. if (psa_get_key_type(attributes) == PSA_KEY_TYPE_NONE) {
  1831. return PSA_ERROR_NOT_SUPPORTED;
  1832. }
  1833. if (psa_get_key_bits(attributes) == 0) {
  1834. return PSA_ERROR_NOT_SUPPORTED;
  1835. }
  1836. status = psa_start_key_creation(PSA_KEY_CREATION_REGISTER, attributes,
  1837. &slot, &driver);
  1838. if (status != PSA_SUCCESS) {
  1839. goto exit;
  1840. }
  1841. status = psa_finish_key_creation(slot, driver, &key);
  1842. exit:
  1843. if (status != PSA_SUCCESS) {
  1844. psa_fail_key_creation(slot, driver);
  1845. }
  1846. /* Registration doesn't keep the key in RAM. */
  1847. psa_close_key(key);
  1848. return status;
  1849. }
  1850. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1851. psa_status_t psa_copy_key(mbedtls_svc_key_id_t source_key,
  1852. const psa_key_attributes_t *specified_attributes,
  1853. mbedtls_svc_key_id_t *target_key)
  1854. {
  1855. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1856. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1857. psa_key_slot_t *source_slot = NULL;
  1858. psa_key_slot_t *target_slot = NULL;
  1859. psa_key_attributes_t actual_attributes = *specified_attributes;
  1860. psa_se_drv_table_entry_t *driver = NULL;
  1861. size_t storage_size = 0;
  1862. *target_key = MBEDTLS_SVC_KEY_ID_INIT;
  1863. status = psa_get_and_lock_key_slot_with_policy(
  1864. source_key, &source_slot, PSA_KEY_USAGE_COPY, 0);
  1865. if (status != PSA_SUCCESS) {
  1866. goto exit;
  1867. }
  1868. status = psa_validate_optional_attributes(source_slot,
  1869. specified_attributes);
  1870. if (status != PSA_SUCCESS) {
  1871. goto exit;
  1872. }
  1873. /* The target key type and number of bits have been validated by
  1874. * psa_validate_optional_attributes() to be either equal to zero or
  1875. * equal to the ones of the source key. So it is safe to inherit
  1876. * them from the source key now."
  1877. * */
  1878. actual_attributes.core.bits = source_slot->attr.bits;
  1879. actual_attributes.core.type = source_slot->attr.type;
  1880. status = psa_restrict_key_policy(source_slot->attr.type,
  1881. &actual_attributes.core.policy,
  1882. &source_slot->attr.policy);
  1883. if (status != PSA_SUCCESS) {
  1884. goto exit;
  1885. }
  1886. status = psa_start_key_creation(PSA_KEY_CREATION_COPY, &actual_attributes,
  1887. &target_slot, &driver);
  1888. if (status != PSA_SUCCESS) {
  1889. goto exit;
  1890. }
  1891. if (PSA_KEY_LIFETIME_GET_LOCATION(target_slot->attr.lifetime) !=
  1892. PSA_KEY_LIFETIME_GET_LOCATION(source_slot->attr.lifetime)) {
  1893. /*
  1894. * If the source and target keys are stored in different locations,
  1895. * the source key would need to be exported as plaintext and re-imported
  1896. * in the other location. This has security implications which have not
  1897. * been fully mapped. For now, this can be achieved through
  1898. * appropriate API invocations from the application, if needed.
  1899. * */
  1900. status = PSA_ERROR_NOT_SUPPORTED;
  1901. goto exit;
  1902. }
  1903. /*
  1904. * When the source and target keys are within the same location,
  1905. * - For transparent keys it is a blind copy without any driver invocation,
  1906. * - For opaque keys this translates to an invocation of the drivers'
  1907. * copy_key entry point through the dispatch layer.
  1908. * */
  1909. if (psa_key_lifetime_is_external(actual_attributes.core.lifetime)) {
  1910. status = psa_driver_wrapper_get_key_buffer_size(&actual_attributes,
  1911. &storage_size);
  1912. if (status != PSA_SUCCESS) {
  1913. goto exit;
  1914. }
  1915. status = psa_allocate_buffer_to_slot(target_slot, storage_size);
  1916. if (status != PSA_SUCCESS) {
  1917. goto exit;
  1918. }
  1919. status = psa_driver_wrapper_copy_key(&actual_attributes,
  1920. source_slot->key.data,
  1921. source_slot->key.bytes,
  1922. target_slot->key.data,
  1923. target_slot->key.bytes,
  1924. &target_slot->key.bytes);
  1925. if (status != PSA_SUCCESS) {
  1926. goto exit;
  1927. }
  1928. } else {
  1929. status = psa_copy_key_material_into_slot(target_slot,
  1930. source_slot->key.data,
  1931. source_slot->key.bytes);
  1932. if (status != PSA_SUCCESS) {
  1933. goto exit;
  1934. }
  1935. }
  1936. status = psa_finish_key_creation(target_slot, driver, target_key);
  1937. exit:
  1938. if (status != PSA_SUCCESS) {
  1939. psa_fail_key_creation(target_slot, driver);
  1940. }
  1941. unlock_status = psa_unlock_key_slot(source_slot);
  1942. return (status == PSA_SUCCESS) ? unlock_status : status;
  1943. }
  1944. /****************************************************************/
  1945. /* Message digests */
  1946. /****************************************************************/
  1947. psa_status_t psa_hash_abort(psa_hash_operation_t *operation)
  1948. {
  1949. /* Aborting a non-active operation is allowed */
  1950. if (operation->id == 0) {
  1951. return PSA_SUCCESS;
  1952. }
  1953. psa_status_t status = psa_driver_wrapper_hash_abort(operation);
  1954. operation->id = 0;
  1955. return status;
  1956. }
  1957. psa_status_t psa_hash_setup(psa_hash_operation_t *operation,
  1958. psa_algorithm_t alg)
  1959. {
  1960. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1961. /* A context must be freshly initialized before it can be set up. */
  1962. if (operation->id != 0) {
  1963. status = PSA_ERROR_BAD_STATE;
  1964. goto exit;
  1965. }
  1966. if (!PSA_ALG_IS_HASH(alg)) {
  1967. status = PSA_ERROR_INVALID_ARGUMENT;
  1968. goto exit;
  1969. }
  1970. /* Ensure all of the context is zeroized, since PSA_HASH_OPERATION_INIT only
  1971. * directly zeroes the int-sized dummy member of the context union. */
  1972. memset(&operation->ctx, 0, sizeof(operation->ctx));
  1973. status = psa_driver_wrapper_hash_setup(operation, alg);
  1974. exit:
  1975. if (status != PSA_SUCCESS) {
  1976. psa_hash_abort(operation);
  1977. }
  1978. return status;
  1979. }
  1980. psa_status_t psa_hash_update(psa_hash_operation_t *operation,
  1981. const uint8_t *input,
  1982. size_t input_length)
  1983. {
  1984. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1985. if (operation->id == 0) {
  1986. status = PSA_ERROR_BAD_STATE;
  1987. goto exit;
  1988. }
  1989. /* Don't require hash implementations to behave correctly on a
  1990. * zero-length input, which may have an invalid pointer. */
  1991. if (input_length == 0) {
  1992. return PSA_SUCCESS;
  1993. }
  1994. status = psa_driver_wrapper_hash_update(operation, input, input_length);
  1995. exit:
  1996. if (status != PSA_SUCCESS) {
  1997. psa_hash_abort(operation);
  1998. }
  1999. return status;
  2000. }
  2001. psa_status_t psa_hash_finish(psa_hash_operation_t *operation,
  2002. uint8_t *hash,
  2003. size_t hash_size,
  2004. size_t *hash_length)
  2005. {
  2006. *hash_length = 0;
  2007. if (operation->id == 0) {
  2008. return PSA_ERROR_BAD_STATE;
  2009. }
  2010. psa_status_t status = psa_driver_wrapper_hash_finish(
  2011. operation, hash, hash_size, hash_length);
  2012. psa_hash_abort(operation);
  2013. return status;
  2014. }
  2015. psa_status_t psa_hash_verify(psa_hash_operation_t *operation,
  2016. const uint8_t *hash,
  2017. size_t hash_length)
  2018. {
  2019. uint8_t actual_hash[PSA_HASH_MAX_SIZE];
  2020. size_t actual_hash_length;
  2021. psa_status_t status = psa_hash_finish(
  2022. operation,
  2023. actual_hash, sizeof(actual_hash),
  2024. &actual_hash_length);
  2025. if (status != PSA_SUCCESS) {
  2026. goto exit;
  2027. }
  2028. if (actual_hash_length != hash_length) {
  2029. status = PSA_ERROR_INVALID_SIGNATURE;
  2030. goto exit;
  2031. }
  2032. if (mbedtls_psa_safer_memcmp(hash, actual_hash, actual_hash_length) != 0) {
  2033. status = PSA_ERROR_INVALID_SIGNATURE;
  2034. }
  2035. exit:
  2036. mbedtls_platform_zeroize(actual_hash, sizeof(actual_hash));
  2037. if (status != PSA_SUCCESS) {
  2038. psa_hash_abort(operation);
  2039. }
  2040. return status;
  2041. }
  2042. psa_status_t psa_hash_compute(psa_algorithm_t alg,
  2043. const uint8_t *input, size_t input_length,
  2044. uint8_t *hash, size_t hash_size,
  2045. size_t *hash_length)
  2046. {
  2047. *hash_length = 0;
  2048. if (!PSA_ALG_IS_HASH(alg)) {
  2049. return PSA_ERROR_INVALID_ARGUMENT;
  2050. }
  2051. return psa_driver_wrapper_hash_compute(alg, input, input_length,
  2052. hash, hash_size, hash_length);
  2053. }
  2054. psa_status_t psa_hash_compare(psa_algorithm_t alg,
  2055. const uint8_t *input, size_t input_length,
  2056. const uint8_t *hash, size_t hash_length)
  2057. {
  2058. uint8_t actual_hash[PSA_HASH_MAX_SIZE];
  2059. size_t actual_hash_length;
  2060. if (!PSA_ALG_IS_HASH(alg)) {
  2061. return PSA_ERROR_INVALID_ARGUMENT;
  2062. }
  2063. psa_status_t status = psa_driver_wrapper_hash_compute(
  2064. alg, input, input_length,
  2065. actual_hash, sizeof(actual_hash),
  2066. &actual_hash_length);
  2067. if (status != PSA_SUCCESS) {
  2068. goto exit;
  2069. }
  2070. if (actual_hash_length != hash_length) {
  2071. status = PSA_ERROR_INVALID_SIGNATURE;
  2072. goto exit;
  2073. }
  2074. if (mbedtls_psa_safer_memcmp(hash, actual_hash, actual_hash_length) != 0) {
  2075. status = PSA_ERROR_INVALID_SIGNATURE;
  2076. }
  2077. exit:
  2078. mbedtls_platform_zeroize(actual_hash, sizeof(actual_hash));
  2079. return status;
  2080. }
  2081. psa_status_t psa_hash_clone(const psa_hash_operation_t *source_operation,
  2082. psa_hash_operation_t *target_operation)
  2083. {
  2084. if (source_operation->id == 0 ||
  2085. target_operation->id != 0) {
  2086. return PSA_ERROR_BAD_STATE;
  2087. }
  2088. psa_status_t status = psa_driver_wrapper_hash_clone(source_operation,
  2089. target_operation);
  2090. if (status != PSA_SUCCESS) {
  2091. psa_hash_abort(target_operation);
  2092. }
  2093. return status;
  2094. }
  2095. /****************************************************************/
  2096. /* MAC */
  2097. /****************************************************************/
  2098. psa_status_t psa_mac_abort(psa_mac_operation_t *operation)
  2099. {
  2100. /* Aborting a non-active operation is allowed */
  2101. if (operation->id == 0) {
  2102. return PSA_SUCCESS;
  2103. }
  2104. psa_status_t status = psa_driver_wrapper_mac_abort(operation);
  2105. operation->mac_size = 0;
  2106. operation->is_sign = 0;
  2107. operation->id = 0;
  2108. return status;
  2109. }
  2110. static psa_status_t psa_mac_finalize_alg_and_key_validation(
  2111. psa_algorithm_t alg,
  2112. const psa_key_attributes_t *attributes,
  2113. uint8_t *mac_size)
  2114. {
  2115. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2116. psa_key_type_t key_type = psa_get_key_type(attributes);
  2117. size_t key_bits = psa_get_key_bits(attributes);
  2118. if (!PSA_ALG_IS_MAC(alg)) {
  2119. return PSA_ERROR_INVALID_ARGUMENT;
  2120. }
  2121. /* Validate the combination of key type and algorithm */
  2122. status = psa_mac_key_can_do(alg, key_type);
  2123. if (status != PSA_SUCCESS) {
  2124. return status;
  2125. }
  2126. /* Get the output length for the algorithm and key combination */
  2127. *mac_size = PSA_MAC_LENGTH(key_type, key_bits, alg);
  2128. if (*mac_size < 4) {
  2129. /* A very short MAC is too short for security since it can be
  2130. * brute-forced. Ancient protocols with 32-bit MACs do exist,
  2131. * so we make this our minimum, even though 32 bits is still
  2132. * too small for security. */
  2133. return PSA_ERROR_NOT_SUPPORTED;
  2134. }
  2135. if (*mac_size > PSA_MAC_LENGTH(key_type, key_bits,
  2136. PSA_ALG_FULL_LENGTH_MAC(alg))) {
  2137. /* It's impossible to "truncate" to a larger length than the full length
  2138. * of the algorithm. */
  2139. return PSA_ERROR_INVALID_ARGUMENT;
  2140. }
  2141. if (*mac_size > PSA_MAC_MAX_SIZE) {
  2142. /* PSA_MAC_LENGTH returns the correct length even for a MAC algorithm
  2143. * that is disabled in the compile-time configuration. The result can
  2144. * therefore be larger than PSA_MAC_MAX_SIZE, which does take the
  2145. * configuration into account. In this case, force a return of
  2146. * PSA_ERROR_NOT_SUPPORTED here. Otherwise psa_mac_verify(), or
  2147. * psa_mac_compute(mac_size=PSA_MAC_MAX_SIZE), would return
  2148. * PSA_ERROR_BUFFER_TOO_SMALL for an unsupported algorithm whose MAC size
  2149. * is larger than PSA_MAC_MAX_SIZE, which is misleading and which breaks
  2150. * systematically generated tests. */
  2151. return PSA_ERROR_NOT_SUPPORTED;
  2152. }
  2153. return PSA_SUCCESS;
  2154. }
  2155. static psa_status_t psa_mac_setup(psa_mac_operation_t *operation,
  2156. mbedtls_svc_key_id_t key,
  2157. psa_algorithm_t alg,
  2158. int is_sign)
  2159. {
  2160. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2161. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2162. psa_key_slot_t *slot = NULL;
  2163. /* A context must be freshly initialized before it can be set up. */
  2164. if (operation->id != 0) {
  2165. status = PSA_ERROR_BAD_STATE;
  2166. goto exit;
  2167. }
  2168. status = psa_get_and_lock_key_slot_with_policy(
  2169. key,
  2170. &slot,
  2171. is_sign ? PSA_KEY_USAGE_SIGN_MESSAGE : PSA_KEY_USAGE_VERIFY_MESSAGE,
  2172. alg);
  2173. if (status != PSA_SUCCESS) {
  2174. goto exit;
  2175. }
  2176. psa_key_attributes_t attributes = {
  2177. .core = slot->attr
  2178. };
  2179. status = psa_mac_finalize_alg_and_key_validation(alg, &attributes,
  2180. &operation->mac_size);
  2181. if (status != PSA_SUCCESS) {
  2182. goto exit;
  2183. }
  2184. operation->is_sign = is_sign;
  2185. /* Dispatch the MAC setup call with validated input */
  2186. if (is_sign) {
  2187. status = psa_driver_wrapper_mac_sign_setup(operation,
  2188. &attributes,
  2189. slot->key.data,
  2190. slot->key.bytes,
  2191. alg);
  2192. } else {
  2193. status = psa_driver_wrapper_mac_verify_setup(operation,
  2194. &attributes,
  2195. slot->key.data,
  2196. slot->key.bytes,
  2197. alg);
  2198. }
  2199. exit:
  2200. if (status != PSA_SUCCESS) {
  2201. psa_mac_abort(operation);
  2202. }
  2203. unlock_status = psa_unlock_key_slot(slot);
  2204. return (status == PSA_SUCCESS) ? unlock_status : status;
  2205. }
  2206. psa_status_t psa_mac_sign_setup(psa_mac_operation_t *operation,
  2207. mbedtls_svc_key_id_t key,
  2208. psa_algorithm_t alg)
  2209. {
  2210. return psa_mac_setup(operation, key, alg, 1);
  2211. }
  2212. psa_status_t psa_mac_verify_setup(psa_mac_operation_t *operation,
  2213. mbedtls_svc_key_id_t key,
  2214. psa_algorithm_t alg)
  2215. {
  2216. return psa_mac_setup(operation, key, alg, 0);
  2217. }
  2218. psa_status_t psa_mac_update(psa_mac_operation_t *operation,
  2219. const uint8_t *input,
  2220. size_t input_length)
  2221. {
  2222. if (operation->id == 0) {
  2223. return PSA_ERROR_BAD_STATE;
  2224. }
  2225. /* Don't require hash implementations to behave correctly on a
  2226. * zero-length input, which may have an invalid pointer. */
  2227. if (input_length == 0) {
  2228. return PSA_SUCCESS;
  2229. }
  2230. psa_status_t status = psa_driver_wrapper_mac_update(operation,
  2231. input, input_length);
  2232. if (status != PSA_SUCCESS) {
  2233. psa_mac_abort(operation);
  2234. }
  2235. return status;
  2236. }
  2237. psa_status_t psa_mac_sign_finish(psa_mac_operation_t *operation,
  2238. uint8_t *mac,
  2239. size_t mac_size,
  2240. size_t *mac_length)
  2241. {
  2242. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2243. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  2244. if (operation->id == 0) {
  2245. status = PSA_ERROR_BAD_STATE;
  2246. goto exit;
  2247. }
  2248. if (!operation->is_sign) {
  2249. status = PSA_ERROR_BAD_STATE;
  2250. goto exit;
  2251. }
  2252. /* Sanity check. This will guarantee that mac_size != 0 (and so mac != NULL)
  2253. * once all the error checks are done. */
  2254. if (operation->mac_size == 0) {
  2255. status = PSA_ERROR_BAD_STATE;
  2256. goto exit;
  2257. }
  2258. if (mac_size < operation->mac_size) {
  2259. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2260. goto exit;
  2261. }
  2262. status = psa_driver_wrapper_mac_sign_finish(operation,
  2263. mac, operation->mac_size,
  2264. mac_length);
  2265. exit:
  2266. /* In case of success, set the potential excess room in the output buffer
  2267. * to an invalid value, to avoid potentially leaking a longer MAC.
  2268. * In case of error, set the output length and content to a safe default,
  2269. * such that in case the caller misses an error check, the output would be
  2270. * an unachievable MAC.
  2271. */
  2272. if (status != PSA_SUCCESS) {
  2273. *mac_length = mac_size;
  2274. operation->mac_size = 0;
  2275. }
  2276. psa_wipe_tag_output_buffer(mac, status, mac_size, *mac_length);
  2277. abort_status = psa_mac_abort(operation);
  2278. return status == PSA_SUCCESS ? abort_status : status;
  2279. }
  2280. psa_status_t psa_mac_verify_finish(psa_mac_operation_t *operation,
  2281. const uint8_t *mac,
  2282. size_t mac_length)
  2283. {
  2284. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2285. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  2286. if (operation->id == 0) {
  2287. status = PSA_ERROR_BAD_STATE;
  2288. goto exit;
  2289. }
  2290. if (operation->is_sign) {
  2291. status = PSA_ERROR_BAD_STATE;
  2292. goto exit;
  2293. }
  2294. if (operation->mac_size != mac_length) {
  2295. status = PSA_ERROR_INVALID_SIGNATURE;
  2296. goto exit;
  2297. }
  2298. status = psa_driver_wrapper_mac_verify_finish(operation,
  2299. mac, mac_length);
  2300. exit:
  2301. abort_status = psa_mac_abort(operation);
  2302. return status == PSA_SUCCESS ? abort_status : status;
  2303. }
  2304. static psa_status_t psa_mac_compute_internal(mbedtls_svc_key_id_t key,
  2305. psa_algorithm_t alg,
  2306. const uint8_t *input,
  2307. size_t input_length,
  2308. uint8_t *mac,
  2309. size_t mac_size,
  2310. size_t *mac_length,
  2311. int is_sign)
  2312. {
  2313. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2314. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2315. psa_key_slot_t *slot;
  2316. uint8_t operation_mac_size = 0;
  2317. status = psa_get_and_lock_key_slot_with_policy(
  2318. key,
  2319. &slot,
  2320. is_sign ? PSA_KEY_USAGE_SIGN_MESSAGE : PSA_KEY_USAGE_VERIFY_MESSAGE,
  2321. alg);
  2322. if (status != PSA_SUCCESS) {
  2323. goto exit;
  2324. }
  2325. psa_key_attributes_t attributes = {
  2326. .core = slot->attr
  2327. };
  2328. status = psa_mac_finalize_alg_and_key_validation(alg, &attributes,
  2329. &operation_mac_size);
  2330. if (status != PSA_SUCCESS) {
  2331. goto exit;
  2332. }
  2333. if (mac_size < operation_mac_size) {
  2334. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2335. goto exit;
  2336. }
  2337. status = psa_driver_wrapper_mac_compute(
  2338. &attributes,
  2339. slot->key.data, slot->key.bytes,
  2340. alg,
  2341. input, input_length,
  2342. mac, operation_mac_size, mac_length);
  2343. exit:
  2344. /* In case of success, set the potential excess room in the output buffer
  2345. * to an invalid value, to avoid potentially leaking a longer MAC.
  2346. * In case of error, set the output length and content to a safe default,
  2347. * such that in case the caller misses an error check, the output would be
  2348. * an unachievable MAC.
  2349. */
  2350. if (status != PSA_SUCCESS) {
  2351. *mac_length = mac_size;
  2352. operation_mac_size = 0;
  2353. }
  2354. psa_wipe_tag_output_buffer(mac, status, mac_size, *mac_length);
  2355. unlock_status = psa_unlock_key_slot(slot);
  2356. return (status == PSA_SUCCESS) ? unlock_status : status;
  2357. }
  2358. psa_status_t psa_mac_compute(mbedtls_svc_key_id_t key,
  2359. psa_algorithm_t alg,
  2360. const uint8_t *input,
  2361. size_t input_length,
  2362. uint8_t *mac,
  2363. size_t mac_size,
  2364. size_t *mac_length)
  2365. {
  2366. return psa_mac_compute_internal(key, alg,
  2367. input, input_length,
  2368. mac, mac_size, mac_length, 1);
  2369. }
  2370. psa_status_t psa_mac_verify(mbedtls_svc_key_id_t key,
  2371. psa_algorithm_t alg,
  2372. const uint8_t *input,
  2373. size_t input_length,
  2374. const uint8_t *mac,
  2375. size_t mac_length)
  2376. {
  2377. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2378. uint8_t actual_mac[PSA_MAC_MAX_SIZE];
  2379. size_t actual_mac_length;
  2380. status = psa_mac_compute_internal(key, alg,
  2381. input, input_length,
  2382. actual_mac, sizeof(actual_mac),
  2383. &actual_mac_length, 0);
  2384. if (status != PSA_SUCCESS) {
  2385. goto exit;
  2386. }
  2387. if (mac_length != actual_mac_length) {
  2388. status = PSA_ERROR_INVALID_SIGNATURE;
  2389. goto exit;
  2390. }
  2391. if (mbedtls_psa_safer_memcmp(mac, actual_mac, actual_mac_length) != 0) {
  2392. status = PSA_ERROR_INVALID_SIGNATURE;
  2393. goto exit;
  2394. }
  2395. exit:
  2396. mbedtls_platform_zeroize(actual_mac, sizeof(actual_mac));
  2397. return status;
  2398. }
  2399. /****************************************************************/
  2400. /* Asymmetric cryptography */
  2401. /****************************************************************/
  2402. static psa_status_t psa_sign_verify_check_alg(int input_is_message,
  2403. psa_algorithm_t alg)
  2404. {
  2405. if (input_is_message) {
  2406. if (!PSA_ALG_IS_SIGN_MESSAGE(alg)) {
  2407. return PSA_ERROR_INVALID_ARGUMENT;
  2408. }
  2409. if (PSA_ALG_IS_SIGN_HASH(alg)) {
  2410. if (!PSA_ALG_IS_HASH(PSA_ALG_SIGN_GET_HASH(alg))) {
  2411. return PSA_ERROR_INVALID_ARGUMENT;
  2412. }
  2413. }
  2414. } else {
  2415. if (!PSA_ALG_IS_SIGN_HASH(alg)) {
  2416. return PSA_ERROR_INVALID_ARGUMENT;
  2417. }
  2418. }
  2419. return PSA_SUCCESS;
  2420. }
  2421. static psa_status_t psa_sign_internal(mbedtls_svc_key_id_t key,
  2422. int input_is_message,
  2423. psa_algorithm_t alg,
  2424. const uint8_t *input,
  2425. size_t input_length,
  2426. uint8_t *signature,
  2427. size_t signature_size,
  2428. size_t *signature_length)
  2429. {
  2430. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2431. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2432. psa_key_slot_t *slot;
  2433. *signature_length = 0;
  2434. status = psa_sign_verify_check_alg(input_is_message, alg);
  2435. if (status != PSA_SUCCESS) {
  2436. return status;
  2437. }
  2438. /* Immediately reject a zero-length signature buffer. This guarantees
  2439. * that signature must be a valid pointer. (On the other hand, the input
  2440. * buffer can in principle be empty since it doesn't actually have
  2441. * to be a hash.) */
  2442. if (signature_size == 0) {
  2443. return PSA_ERROR_BUFFER_TOO_SMALL;
  2444. }
  2445. status = psa_get_and_lock_key_slot_with_policy(
  2446. key, &slot,
  2447. input_is_message ? PSA_KEY_USAGE_SIGN_MESSAGE :
  2448. PSA_KEY_USAGE_SIGN_HASH,
  2449. alg);
  2450. if (status != PSA_SUCCESS) {
  2451. goto exit;
  2452. }
  2453. if (!PSA_KEY_TYPE_IS_KEY_PAIR(slot->attr.type)) {
  2454. status = PSA_ERROR_INVALID_ARGUMENT;
  2455. goto exit;
  2456. }
  2457. psa_key_attributes_t attributes = {
  2458. .core = slot->attr
  2459. };
  2460. if (input_is_message) {
  2461. status = psa_driver_wrapper_sign_message(
  2462. &attributes, slot->key.data, slot->key.bytes,
  2463. alg, input, input_length,
  2464. signature, signature_size, signature_length);
  2465. } else {
  2466. status = psa_driver_wrapper_sign_hash(
  2467. &attributes, slot->key.data, slot->key.bytes,
  2468. alg, input, input_length,
  2469. signature, signature_size, signature_length);
  2470. }
  2471. exit:
  2472. psa_wipe_tag_output_buffer(signature, status, signature_size,
  2473. *signature_length);
  2474. unlock_status = psa_unlock_key_slot(slot);
  2475. return (status == PSA_SUCCESS) ? unlock_status : status;
  2476. }
  2477. static psa_status_t psa_verify_internal(mbedtls_svc_key_id_t key,
  2478. int input_is_message,
  2479. psa_algorithm_t alg,
  2480. const uint8_t *input,
  2481. size_t input_length,
  2482. const uint8_t *signature,
  2483. size_t signature_length)
  2484. {
  2485. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2486. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2487. psa_key_slot_t *slot;
  2488. status = psa_sign_verify_check_alg(input_is_message, alg);
  2489. if (status != PSA_SUCCESS) {
  2490. return status;
  2491. }
  2492. status = psa_get_and_lock_key_slot_with_policy(
  2493. key, &slot,
  2494. input_is_message ? PSA_KEY_USAGE_VERIFY_MESSAGE :
  2495. PSA_KEY_USAGE_VERIFY_HASH,
  2496. alg);
  2497. if (status != PSA_SUCCESS) {
  2498. return status;
  2499. }
  2500. psa_key_attributes_t attributes = {
  2501. .core = slot->attr
  2502. };
  2503. if (input_is_message) {
  2504. status = psa_driver_wrapper_verify_message(
  2505. &attributes, slot->key.data, slot->key.bytes,
  2506. alg, input, input_length,
  2507. signature, signature_length);
  2508. } else {
  2509. status = psa_driver_wrapper_verify_hash(
  2510. &attributes, slot->key.data, slot->key.bytes,
  2511. alg, input, input_length,
  2512. signature, signature_length);
  2513. }
  2514. unlock_status = psa_unlock_key_slot(slot);
  2515. return (status == PSA_SUCCESS) ? unlock_status : status;
  2516. }
  2517. psa_status_t psa_sign_message_builtin(
  2518. const psa_key_attributes_t *attributes,
  2519. const uint8_t *key_buffer,
  2520. size_t key_buffer_size,
  2521. psa_algorithm_t alg,
  2522. const uint8_t *input,
  2523. size_t input_length,
  2524. uint8_t *signature,
  2525. size_t signature_size,
  2526. size_t *signature_length)
  2527. {
  2528. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2529. if (PSA_ALG_IS_SIGN_HASH(alg)) {
  2530. size_t hash_length;
  2531. uint8_t hash[PSA_HASH_MAX_SIZE];
  2532. status = psa_driver_wrapper_hash_compute(
  2533. PSA_ALG_SIGN_GET_HASH(alg),
  2534. input, input_length,
  2535. hash, sizeof(hash), &hash_length);
  2536. if (status != PSA_SUCCESS) {
  2537. return status;
  2538. }
  2539. return psa_driver_wrapper_sign_hash(
  2540. attributes, key_buffer, key_buffer_size,
  2541. alg, hash, hash_length,
  2542. signature, signature_size, signature_length);
  2543. }
  2544. return PSA_ERROR_NOT_SUPPORTED;
  2545. }
  2546. psa_status_t psa_sign_message(mbedtls_svc_key_id_t key,
  2547. psa_algorithm_t alg,
  2548. const uint8_t *input,
  2549. size_t input_length,
  2550. uint8_t *signature,
  2551. size_t signature_size,
  2552. size_t *signature_length)
  2553. {
  2554. return psa_sign_internal(
  2555. key, 1, alg, input, input_length,
  2556. signature, signature_size, signature_length);
  2557. }
  2558. psa_status_t psa_verify_message_builtin(
  2559. const psa_key_attributes_t *attributes,
  2560. const uint8_t *key_buffer,
  2561. size_t key_buffer_size,
  2562. psa_algorithm_t alg,
  2563. const uint8_t *input,
  2564. size_t input_length,
  2565. const uint8_t *signature,
  2566. size_t signature_length)
  2567. {
  2568. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2569. if (PSA_ALG_IS_SIGN_HASH(alg)) {
  2570. size_t hash_length;
  2571. uint8_t hash[PSA_HASH_MAX_SIZE];
  2572. status = psa_driver_wrapper_hash_compute(
  2573. PSA_ALG_SIGN_GET_HASH(alg),
  2574. input, input_length,
  2575. hash, sizeof(hash), &hash_length);
  2576. if (status != PSA_SUCCESS) {
  2577. return status;
  2578. }
  2579. return psa_driver_wrapper_verify_hash(
  2580. attributes, key_buffer, key_buffer_size,
  2581. alg, hash, hash_length,
  2582. signature, signature_length);
  2583. }
  2584. return PSA_ERROR_NOT_SUPPORTED;
  2585. }
  2586. psa_status_t psa_verify_message(mbedtls_svc_key_id_t key,
  2587. psa_algorithm_t alg,
  2588. const uint8_t *input,
  2589. size_t input_length,
  2590. const uint8_t *signature,
  2591. size_t signature_length)
  2592. {
  2593. return psa_verify_internal(
  2594. key, 1, alg, input, input_length,
  2595. signature, signature_length);
  2596. }
  2597. psa_status_t psa_sign_hash_builtin(
  2598. const psa_key_attributes_t *attributes,
  2599. const uint8_t *key_buffer, size_t key_buffer_size,
  2600. psa_algorithm_t alg, const uint8_t *hash, size_t hash_length,
  2601. uint8_t *signature, size_t signature_size, size_t *signature_length)
  2602. {
  2603. if (attributes->core.type == PSA_KEY_TYPE_RSA_KEY_PAIR) {
  2604. if (PSA_ALG_IS_RSA_PKCS1V15_SIGN(alg) ||
  2605. PSA_ALG_IS_RSA_PSS(alg)) {
  2606. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) || \
  2607. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS)
  2608. return mbedtls_psa_rsa_sign_hash(
  2609. attributes,
  2610. key_buffer, key_buffer_size,
  2611. alg, hash, hash_length,
  2612. signature, signature_size, signature_length);
  2613. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) ||
  2614. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS) */
  2615. } else {
  2616. return PSA_ERROR_INVALID_ARGUMENT;
  2617. }
  2618. } else if (PSA_KEY_TYPE_IS_ECC(attributes->core.type)) {
  2619. if (PSA_ALG_IS_ECDSA(alg)) {
  2620. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  2621. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  2622. return mbedtls_psa_ecdsa_sign_hash(
  2623. attributes,
  2624. key_buffer, key_buffer_size,
  2625. alg, hash, hash_length,
  2626. signature, signature_size, signature_length);
  2627. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  2628. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  2629. } else {
  2630. return PSA_ERROR_INVALID_ARGUMENT;
  2631. }
  2632. }
  2633. (void) key_buffer;
  2634. (void) key_buffer_size;
  2635. (void) hash;
  2636. (void) hash_length;
  2637. (void) signature;
  2638. (void) signature_size;
  2639. (void) signature_length;
  2640. return PSA_ERROR_NOT_SUPPORTED;
  2641. }
  2642. psa_status_t psa_sign_hash(mbedtls_svc_key_id_t key,
  2643. psa_algorithm_t alg,
  2644. const uint8_t *hash,
  2645. size_t hash_length,
  2646. uint8_t *signature,
  2647. size_t signature_size,
  2648. size_t *signature_length)
  2649. {
  2650. return psa_sign_internal(
  2651. key, 0, alg, hash, hash_length,
  2652. signature, signature_size, signature_length);
  2653. }
  2654. psa_status_t psa_verify_hash_builtin(
  2655. const psa_key_attributes_t *attributes,
  2656. const uint8_t *key_buffer, size_t key_buffer_size,
  2657. psa_algorithm_t alg, const uint8_t *hash, size_t hash_length,
  2658. const uint8_t *signature, size_t signature_length)
  2659. {
  2660. if (PSA_KEY_TYPE_IS_RSA(attributes->core.type)) {
  2661. if (PSA_ALG_IS_RSA_PKCS1V15_SIGN(alg) ||
  2662. PSA_ALG_IS_RSA_PSS(alg)) {
  2663. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) || \
  2664. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS)
  2665. return mbedtls_psa_rsa_verify_hash(
  2666. attributes,
  2667. key_buffer, key_buffer_size,
  2668. alg, hash, hash_length,
  2669. signature, signature_length);
  2670. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) ||
  2671. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS) */
  2672. } else {
  2673. return PSA_ERROR_INVALID_ARGUMENT;
  2674. }
  2675. } else if (PSA_KEY_TYPE_IS_ECC(attributes->core.type)) {
  2676. if (PSA_ALG_IS_ECDSA(alg)) {
  2677. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  2678. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  2679. return mbedtls_psa_ecdsa_verify_hash(
  2680. attributes,
  2681. key_buffer, key_buffer_size,
  2682. alg, hash, hash_length,
  2683. signature, signature_length);
  2684. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  2685. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  2686. } else {
  2687. return PSA_ERROR_INVALID_ARGUMENT;
  2688. }
  2689. }
  2690. (void) key_buffer;
  2691. (void) key_buffer_size;
  2692. (void) hash;
  2693. (void) hash_length;
  2694. (void) signature;
  2695. (void) signature_length;
  2696. return PSA_ERROR_NOT_SUPPORTED;
  2697. }
  2698. psa_status_t psa_verify_hash(mbedtls_svc_key_id_t key,
  2699. psa_algorithm_t alg,
  2700. const uint8_t *hash,
  2701. size_t hash_length,
  2702. const uint8_t *signature,
  2703. size_t signature_length)
  2704. {
  2705. return psa_verify_internal(
  2706. key, 0, alg, hash, hash_length,
  2707. signature, signature_length);
  2708. }
  2709. psa_status_t psa_asymmetric_encrypt(mbedtls_svc_key_id_t key,
  2710. psa_algorithm_t alg,
  2711. const uint8_t *input,
  2712. size_t input_length,
  2713. const uint8_t *salt,
  2714. size_t salt_length,
  2715. uint8_t *output,
  2716. size_t output_size,
  2717. size_t *output_length)
  2718. {
  2719. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2720. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2721. psa_key_slot_t *slot;
  2722. (void) input;
  2723. (void) input_length;
  2724. (void) salt;
  2725. (void) output;
  2726. (void) output_size;
  2727. *output_length = 0;
  2728. if (!PSA_ALG_IS_RSA_OAEP(alg) && salt_length != 0) {
  2729. return PSA_ERROR_INVALID_ARGUMENT;
  2730. }
  2731. status = psa_get_and_lock_transparent_key_slot_with_policy(
  2732. key, &slot, PSA_KEY_USAGE_ENCRYPT, alg);
  2733. if (status != PSA_SUCCESS) {
  2734. return status;
  2735. }
  2736. if (!(PSA_KEY_TYPE_IS_PUBLIC_KEY(slot->attr.type) ||
  2737. PSA_KEY_TYPE_IS_KEY_PAIR(slot->attr.type))) {
  2738. status = PSA_ERROR_INVALID_ARGUMENT;
  2739. goto exit;
  2740. }
  2741. psa_key_attributes_t attributes = {
  2742. .core = slot->attr
  2743. };
  2744. status = psa_driver_wrapper_asymmetric_encrypt(
  2745. &attributes, slot->key.data, slot->key.bytes,
  2746. alg, input, input_length, salt, salt_length,
  2747. output, output_size, output_length);
  2748. exit:
  2749. unlock_status = psa_unlock_key_slot(slot);
  2750. return (status == PSA_SUCCESS) ? unlock_status : status;
  2751. }
  2752. psa_status_t psa_asymmetric_decrypt(mbedtls_svc_key_id_t key,
  2753. psa_algorithm_t alg,
  2754. const uint8_t *input,
  2755. size_t input_length,
  2756. const uint8_t *salt,
  2757. size_t salt_length,
  2758. uint8_t *output,
  2759. size_t output_size,
  2760. size_t *output_length)
  2761. {
  2762. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2763. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2764. psa_key_slot_t *slot;
  2765. (void) input;
  2766. (void) input_length;
  2767. (void) salt;
  2768. (void) output;
  2769. (void) output_size;
  2770. *output_length = 0;
  2771. if (!PSA_ALG_IS_RSA_OAEP(alg) && salt_length != 0) {
  2772. return PSA_ERROR_INVALID_ARGUMENT;
  2773. }
  2774. status = psa_get_and_lock_transparent_key_slot_with_policy(
  2775. key, &slot, PSA_KEY_USAGE_DECRYPT, alg);
  2776. if (status != PSA_SUCCESS) {
  2777. return status;
  2778. }
  2779. if (!PSA_KEY_TYPE_IS_KEY_PAIR(slot->attr.type)) {
  2780. status = PSA_ERROR_INVALID_ARGUMENT;
  2781. goto exit;
  2782. }
  2783. psa_key_attributes_t attributes = {
  2784. .core = slot->attr
  2785. };
  2786. status = psa_driver_wrapper_asymmetric_decrypt(
  2787. &attributes, slot->key.data, slot->key.bytes,
  2788. alg, input, input_length, salt, salt_length,
  2789. output, output_size, output_length);
  2790. exit:
  2791. unlock_status = psa_unlock_key_slot(slot);
  2792. return (status == PSA_SUCCESS) ? unlock_status : status;
  2793. }
  2794. /****************************************************************/
  2795. /* Asymmetric interruptible cryptography */
  2796. /****************************************************************/
  2797. static uint32_t psa_interruptible_max_ops = PSA_INTERRUPTIBLE_MAX_OPS_UNLIMITED;
  2798. void psa_interruptible_set_max_ops(uint32_t max_ops)
  2799. {
  2800. psa_interruptible_max_ops = max_ops;
  2801. }
  2802. uint32_t psa_interruptible_get_max_ops(void)
  2803. {
  2804. return psa_interruptible_max_ops;
  2805. }
  2806. uint32_t psa_sign_hash_get_num_ops(
  2807. const psa_sign_hash_interruptible_operation_t *operation)
  2808. {
  2809. return operation->num_ops;
  2810. }
  2811. uint32_t psa_verify_hash_get_num_ops(
  2812. const psa_verify_hash_interruptible_operation_t *operation)
  2813. {
  2814. return operation->num_ops;
  2815. }
  2816. static psa_status_t psa_sign_hash_abort_internal(
  2817. psa_sign_hash_interruptible_operation_t *operation)
  2818. {
  2819. if (operation->id == 0) {
  2820. /* The object has (apparently) been initialized but it is not (yet)
  2821. * in use. It's ok to call abort on such an object, and there's
  2822. * nothing to do. */
  2823. return PSA_SUCCESS;
  2824. }
  2825. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2826. status = psa_driver_wrapper_sign_hash_abort(operation);
  2827. operation->id = 0;
  2828. /* Do not clear either the error_occurred or num_ops elements here as they
  2829. * only want to be cleared by the application calling abort, not by abort
  2830. * being called at completion of an operation. */
  2831. return status;
  2832. }
  2833. psa_status_t psa_sign_hash_start(
  2834. psa_sign_hash_interruptible_operation_t *operation,
  2835. mbedtls_svc_key_id_t key, psa_algorithm_t alg,
  2836. const uint8_t *hash, size_t hash_length)
  2837. {
  2838. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2839. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2840. psa_key_slot_t *slot;
  2841. /* Check that start has not been previously called, or operation has not
  2842. * previously errored. */
  2843. if (operation->id != 0 || operation->error_occurred) {
  2844. return PSA_ERROR_BAD_STATE;
  2845. }
  2846. status = psa_sign_verify_check_alg(0, alg);
  2847. if (status != PSA_SUCCESS) {
  2848. operation->error_occurred = 1;
  2849. return status;
  2850. }
  2851. status = psa_get_and_lock_key_slot_with_policy(key, &slot,
  2852. PSA_KEY_USAGE_SIGN_HASH,
  2853. alg);
  2854. if (status != PSA_SUCCESS) {
  2855. goto exit;
  2856. }
  2857. if (!PSA_KEY_TYPE_IS_KEY_PAIR(slot->attr.type)) {
  2858. status = PSA_ERROR_INVALID_ARGUMENT;
  2859. goto exit;
  2860. }
  2861. psa_key_attributes_t attributes = {
  2862. .core = slot->attr
  2863. };
  2864. /* Ensure ops count gets reset, in case of operation re-use. */
  2865. operation->num_ops = 0;
  2866. status = psa_driver_wrapper_sign_hash_start(operation, &attributes,
  2867. slot->key.data,
  2868. slot->key.bytes, alg,
  2869. hash, hash_length);
  2870. exit:
  2871. if (status != PSA_SUCCESS) {
  2872. operation->error_occurred = 1;
  2873. psa_sign_hash_abort_internal(operation);
  2874. }
  2875. unlock_status = psa_unlock_key_slot(slot);
  2876. if (unlock_status != PSA_SUCCESS) {
  2877. operation->error_occurred = 1;
  2878. }
  2879. return (status == PSA_SUCCESS) ? unlock_status : status;
  2880. }
  2881. psa_status_t psa_sign_hash_complete(
  2882. psa_sign_hash_interruptible_operation_t *operation,
  2883. uint8_t *signature, size_t signature_size,
  2884. size_t *signature_length)
  2885. {
  2886. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2887. *signature_length = 0;
  2888. /* Check that start has been called first, and that operation has not
  2889. * previously errored. */
  2890. if (operation->id == 0 || operation->error_occurred) {
  2891. status = PSA_ERROR_BAD_STATE;
  2892. goto exit;
  2893. }
  2894. /* Immediately reject a zero-length signature buffer. This guarantees that
  2895. * signature must be a valid pointer. */
  2896. if (signature_size == 0) {
  2897. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2898. goto exit;
  2899. }
  2900. status = psa_driver_wrapper_sign_hash_complete(operation, signature,
  2901. signature_size,
  2902. signature_length);
  2903. /* Update ops count with work done. */
  2904. operation->num_ops = psa_driver_wrapper_sign_hash_get_num_ops(operation);
  2905. exit:
  2906. psa_wipe_tag_output_buffer(signature, status, signature_size,
  2907. *signature_length);
  2908. if (status != PSA_OPERATION_INCOMPLETE) {
  2909. if (status != PSA_SUCCESS) {
  2910. operation->error_occurred = 1;
  2911. }
  2912. psa_sign_hash_abort_internal(operation);
  2913. }
  2914. return status;
  2915. }
  2916. psa_status_t psa_sign_hash_abort(
  2917. psa_sign_hash_interruptible_operation_t *operation)
  2918. {
  2919. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2920. status = psa_sign_hash_abort_internal(operation);
  2921. /* We clear the number of ops done here, so that it is not cleared when
  2922. * the operation fails or succeeds, only on manual abort. */
  2923. operation->num_ops = 0;
  2924. /* Likewise, failure state. */
  2925. operation->error_occurred = 0;
  2926. return status;
  2927. }
  2928. static psa_status_t psa_verify_hash_abort_internal(
  2929. psa_verify_hash_interruptible_operation_t *operation)
  2930. {
  2931. if (operation->id == 0) {
  2932. /* The object has (apparently) been initialized but it is not (yet)
  2933. * in use. It's ok to call abort on such an object, and there's
  2934. * nothing to do. */
  2935. return PSA_SUCCESS;
  2936. }
  2937. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2938. status = psa_driver_wrapper_verify_hash_abort(operation);
  2939. operation->id = 0;
  2940. /* Do not clear either the error_occurred or num_ops elements here as they
  2941. * only want to be cleared by the application calling abort, not by abort
  2942. * being called at completion of an operation. */
  2943. return status;
  2944. }
  2945. psa_status_t psa_verify_hash_start(
  2946. psa_verify_hash_interruptible_operation_t *operation,
  2947. mbedtls_svc_key_id_t key, psa_algorithm_t alg,
  2948. const uint8_t *hash, size_t hash_length,
  2949. const uint8_t *signature, size_t signature_length)
  2950. {
  2951. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2952. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2953. psa_key_slot_t *slot;
  2954. /* Check that start has not been previously called, or operation has not
  2955. * previously errored. */
  2956. if (operation->id != 0 || operation->error_occurred) {
  2957. return PSA_ERROR_BAD_STATE;
  2958. }
  2959. status = psa_sign_verify_check_alg(0, alg);
  2960. if (status != PSA_SUCCESS) {
  2961. operation->error_occurred = 1;
  2962. return status;
  2963. }
  2964. status = psa_get_and_lock_key_slot_with_policy(key, &slot,
  2965. PSA_KEY_USAGE_VERIFY_HASH,
  2966. alg);
  2967. if (status != PSA_SUCCESS) {
  2968. operation->error_occurred = 1;
  2969. return status;
  2970. }
  2971. psa_key_attributes_t attributes = {
  2972. .core = slot->attr
  2973. };
  2974. /* Ensure ops count gets reset, in case of operation re-use. */
  2975. operation->num_ops = 0;
  2976. status = psa_driver_wrapper_verify_hash_start(operation, &attributes,
  2977. slot->key.data,
  2978. slot->key.bytes,
  2979. alg, hash, hash_length,
  2980. signature, signature_length);
  2981. if (status != PSA_SUCCESS) {
  2982. operation->error_occurred = 1;
  2983. psa_verify_hash_abort_internal(operation);
  2984. }
  2985. unlock_status = psa_unlock_key_slot(slot);
  2986. if (unlock_status != PSA_SUCCESS) {
  2987. operation->error_occurred = 1;
  2988. }
  2989. return (status == PSA_SUCCESS) ? unlock_status : status;
  2990. }
  2991. psa_status_t psa_verify_hash_complete(
  2992. psa_verify_hash_interruptible_operation_t *operation)
  2993. {
  2994. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2995. /* Check that start has been called first, and that operation has not
  2996. * previously errored. */
  2997. if (operation->id == 0 || operation->error_occurred) {
  2998. status = PSA_ERROR_BAD_STATE;
  2999. goto exit;
  3000. }
  3001. status = psa_driver_wrapper_verify_hash_complete(operation);
  3002. /* Update ops count with work done. */
  3003. operation->num_ops = psa_driver_wrapper_verify_hash_get_num_ops(
  3004. operation);
  3005. exit:
  3006. if (status != PSA_OPERATION_INCOMPLETE) {
  3007. if (status != PSA_SUCCESS) {
  3008. operation->error_occurred = 1;
  3009. }
  3010. psa_verify_hash_abort_internal(operation);
  3011. }
  3012. return status;
  3013. }
  3014. psa_status_t psa_verify_hash_abort(
  3015. psa_verify_hash_interruptible_operation_t *operation)
  3016. {
  3017. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3018. status = psa_verify_hash_abort_internal(operation);
  3019. /* We clear the number of ops done here, so that it is not cleared when
  3020. * the operation fails or succeeds, only on manual abort. */
  3021. operation->num_ops = 0;
  3022. /* Likewise, failure state. */
  3023. operation->error_occurred = 0;
  3024. return status;
  3025. }
  3026. /****************************************************************/
  3027. /* Asymmetric interruptible cryptography internal */
  3028. /* implementations */
  3029. /****************************************************************/
  3030. void mbedtls_psa_interruptible_set_max_ops(uint32_t max_ops)
  3031. {
  3032. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3033. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3034. defined(MBEDTLS_ECP_RESTARTABLE)
  3035. /* Internal implementation uses zero to indicate infinite number max ops,
  3036. * therefore avoid this value, and set to minimum possible. */
  3037. if (max_ops == 0) {
  3038. max_ops = 1;
  3039. }
  3040. mbedtls_ecp_set_max_ops(max_ops);
  3041. #else
  3042. (void) max_ops;
  3043. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3044. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3045. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3046. }
  3047. uint32_t mbedtls_psa_sign_hash_get_num_ops(
  3048. const mbedtls_psa_sign_hash_interruptible_operation_t *operation)
  3049. {
  3050. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3051. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3052. defined(MBEDTLS_ECP_RESTARTABLE)
  3053. return operation->num_ops;
  3054. #else
  3055. (void) operation;
  3056. return 0;
  3057. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3058. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3059. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3060. }
  3061. uint32_t mbedtls_psa_verify_hash_get_num_ops(
  3062. const mbedtls_psa_verify_hash_interruptible_operation_t *operation)
  3063. {
  3064. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3065. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3066. defined(MBEDTLS_ECP_RESTARTABLE)
  3067. return operation->num_ops;
  3068. #else
  3069. (void) operation;
  3070. return 0;
  3071. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3072. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3073. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3074. }
  3075. psa_status_t mbedtls_psa_sign_hash_start(
  3076. mbedtls_psa_sign_hash_interruptible_operation_t *operation,
  3077. const psa_key_attributes_t *attributes, const uint8_t *key_buffer,
  3078. size_t key_buffer_size, psa_algorithm_t alg,
  3079. const uint8_t *hash, size_t hash_length)
  3080. {
  3081. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3082. size_t required_hash_length;
  3083. if (!PSA_KEY_TYPE_IS_ECC(attributes->core.type)) {
  3084. return PSA_ERROR_NOT_SUPPORTED;
  3085. }
  3086. if (!PSA_ALG_IS_ECDSA(alg)) {
  3087. return PSA_ERROR_NOT_SUPPORTED;
  3088. }
  3089. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3090. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3091. defined(MBEDTLS_ECP_RESTARTABLE)
  3092. mbedtls_ecdsa_restart_init(&operation->restart_ctx);
  3093. /* Ensure num_ops is zero'ed in case of context re-use. */
  3094. operation->num_ops = 0;
  3095. status = mbedtls_psa_ecp_load_representation(attributes->core.type,
  3096. attributes->core.bits,
  3097. key_buffer,
  3098. key_buffer_size,
  3099. &operation->ctx);
  3100. if (status != PSA_SUCCESS) {
  3101. return status;
  3102. }
  3103. operation->coordinate_bytes = PSA_BITS_TO_BYTES(
  3104. operation->ctx->grp.nbits);
  3105. psa_algorithm_t hash_alg = PSA_ALG_SIGN_GET_HASH(alg);
  3106. operation->md_alg = mbedtls_hash_info_md_from_psa(hash_alg);
  3107. operation->alg = alg;
  3108. /* We only need to store the same length of hash as the private key size
  3109. * here, it would be truncated by the internal implementation anyway. */
  3110. required_hash_length = (hash_length < operation->coordinate_bytes ?
  3111. hash_length : operation->coordinate_bytes);
  3112. if (required_hash_length > sizeof(operation->hash)) {
  3113. /* Shouldn't happen, but better safe than sorry. */
  3114. return PSA_ERROR_CORRUPTION_DETECTED;
  3115. }
  3116. memcpy(operation->hash, hash, required_hash_length);
  3117. operation->hash_length = required_hash_length;
  3118. return PSA_SUCCESS;
  3119. #else
  3120. (void) operation;
  3121. (void) key_buffer;
  3122. (void) key_buffer_size;
  3123. (void) alg;
  3124. (void) hash;
  3125. (void) hash_length;
  3126. (void) status;
  3127. (void) required_hash_length;
  3128. return PSA_ERROR_NOT_SUPPORTED;
  3129. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3130. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3131. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3132. }
  3133. psa_status_t mbedtls_psa_sign_hash_complete(
  3134. mbedtls_psa_sign_hash_interruptible_operation_t *operation,
  3135. uint8_t *signature, size_t signature_size,
  3136. size_t *signature_length)
  3137. {
  3138. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3139. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3140. defined(MBEDTLS_ECP_RESTARTABLE)
  3141. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3142. mbedtls_mpi r;
  3143. mbedtls_mpi s;
  3144. mbedtls_mpi_init(&r);
  3145. mbedtls_mpi_init(&s);
  3146. /* Ensure max_ops is set to the current value (or default). */
  3147. mbedtls_psa_interruptible_set_max_ops(psa_interruptible_get_max_ops());
  3148. if (signature_size < 2 * operation->coordinate_bytes) {
  3149. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3150. goto exit;
  3151. }
  3152. if (PSA_ALG_ECDSA_IS_DETERMINISTIC(operation->alg)) {
  3153. #if defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  3154. status = mbedtls_to_psa_error(
  3155. mbedtls_ecdsa_sign_det_restartable(&operation->ctx->grp,
  3156. &r,
  3157. &s,
  3158. &operation->ctx->d,
  3159. operation->hash,
  3160. operation->hash_length,
  3161. operation->md_alg,
  3162. mbedtls_psa_get_random,
  3163. MBEDTLS_PSA_RANDOM_STATE,
  3164. &operation->restart_ctx));
  3165. #else /* defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  3166. status = PSA_ERROR_NOT_SUPPORTED;
  3167. goto exit;
  3168. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  3169. } else {
  3170. status = mbedtls_to_psa_error(
  3171. mbedtls_ecdsa_sign_restartable(&operation->ctx->grp,
  3172. &r,
  3173. &s,
  3174. &operation->ctx->d,
  3175. operation->hash,
  3176. operation->hash_length,
  3177. mbedtls_psa_get_random,
  3178. MBEDTLS_PSA_RANDOM_STATE,
  3179. mbedtls_psa_get_random,
  3180. MBEDTLS_PSA_RANDOM_STATE,
  3181. &operation->restart_ctx));
  3182. }
  3183. /* Hide the fact that the restart context only holds a delta of number of
  3184. * ops done during the last operation, not an absolute value. */
  3185. operation->num_ops += operation->restart_ctx.ecp.ops_done;
  3186. if (status == PSA_SUCCESS) {
  3187. status = mbedtls_to_psa_error(
  3188. mbedtls_mpi_write_binary(&r,
  3189. signature,
  3190. operation->coordinate_bytes)
  3191. );
  3192. if (status != PSA_SUCCESS) {
  3193. goto exit;
  3194. }
  3195. status = mbedtls_to_psa_error(
  3196. mbedtls_mpi_write_binary(&s,
  3197. signature +
  3198. operation->coordinate_bytes,
  3199. operation->coordinate_bytes)
  3200. );
  3201. if (status != PSA_SUCCESS) {
  3202. goto exit;
  3203. }
  3204. *signature_length = operation->coordinate_bytes * 2;
  3205. status = PSA_SUCCESS;
  3206. }
  3207. exit:
  3208. mbedtls_mpi_free(&r);
  3209. mbedtls_mpi_free(&s);
  3210. return status;
  3211. #else
  3212. (void) operation;
  3213. (void) signature;
  3214. (void) signature_size;
  3215. (void) signature_length;
  3216. return PSA_ERROR_NOT_SUPPORTED;
  3217. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3218. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3219. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3220. }
  3221. psa_status_t mbedtls_psa_sign_hash_abort(
  3222. mbedtls_psa_sign_hash_interruptible_operation_t *operation)
  3223. {
  3224. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3225. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3226. defined(MBEDTLS_ECP_RESTARTABLE)
  3227. if (operation->ctx) {
  3228. mbedtls_ecdsa_free(operation->ctx);
  3229. mbedtls_free(operation->ctx);
  3230. operation->ctx = NULL;
  3231. }
  3232. mbedtls_ecdsa_restart_free(&operation->restart_ctx);
  3233. operation->num_ops = 0;
  3234. return PSA_SUCCESS;
  3235. #else
  3236. (void) operation;
  3237. return PSA_ERROR_NOT_SUPPORTED;
  3238. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3239. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3240. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3241. }
  3242. psa_status_t mbedtls_psa_verify_hash_start(
  3243. mbedtls_psa_verify_hash_interruptible_operation_t *operation,
  3244. const psa_key_attributes_t *attributes,
  3245. const uint8_t *key_buffer, size_t key_buffer_size,
  3246. psa_algorithm_t alg,
  3247. const uint8_t *hash, size_t hash_length,
  3248. const uint8_t *signature, size_t signature_length)
  3249. {
  3250. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3251. size_t coordinate_bytes = 0;
  3252. size_t required_hash_length = 0;
  3253. if (!PSA_KEY_TYPE_IS_ECC(attributes->core.type)) {
  3254. return PSA_ERROR_NOT_SUPPORTED;
  3255. }
  3256. if (!PSA_ALG_IS_ECDSA(alg)) {
  3257. return PSA_ERROR_NOT_SUPPORTED;
  3258. }
  3259. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3260. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3261. defined(MBEDTLS_ECP_RESTARTABLE)
  3262. mbedtls_ecdsa_restart_init(&operation->restart_ctx);
  3263. mbedtls_mpi_init(&operation->r);
  3264. mbedtls_mpi_init(&operation->s);
  3265. /* Ensure num_ops is zero'ed in case of context re-use. */
  3266. operation->num_ops = 0;
  3267. status = mbedtls_psa_ecp_load_representation(attributes->core.type,
  3268. attributes->core.bits,
  3269. key_buffer,
  3270. key_buffer_size,
  3271. &operation->ctx);
  3272. if (status != PSA_SUCCESS) {
  3273. return status;
  3274. }
  3275. coordinate_bytes = PSA_BITS_TO_BYTES(operation->ctx->grp.nbits);
  3276. if (signature_length != 2 * coordinate_bytes) {
  3277. return PSA_ERROR_INVALID_SIGNATURE;
  3278. }
  3279. status = mbedtls_to_psa_error(
  3280. mbedtls_mpi_read_binary(&operation->r,
  3281. signature,
  3282. coordinate_bytes));
  3283. if (status != PSA_SUCCESS) {
  3284. return status;
  3285. }
  3286. status = mbedtls_to_psa_error(
  3287. mbedtls_mpi_read_binary(&operation->s,
  3288. signature +
  3289. coordinate_bytes,
  3290. coordinate_bytes));
  3291. if (status != PSA_SUCCESS) {
  3292. return status;
  3293. }
  3294. status = mbedtls_psa_ecp_load_public_part(operation->ctx);
  3295. if (status != PSA_SUCCESS) {
  3296. return status;
  3297. }
  3298. /* We only need to store the same length of hash as the private key size
  3299. * here, it would be truncated by the internal implementation anyway. */
  3300. required_hash_length = (hash_length < coordinate_bytes ? hash_length :
  3301. coordinate_bytes);
  3302. if (required_hash_length > sizeof(operation->hash)) {
  3303. /* Shouldn't happen, but better safe than sorry. */
  3304. return PSA_ERROR_CORRUPTION_DETECTED;
  3305. }
  3306. memcpy(operation->hash, hash, required_hash_length);
  3307. operation->hash_length = required_hash_length;
  3308. return PSA_SUCCESS;
  3309. #else
  3310. (void) operation;
  3311. (void) key_buffer;
  3312. (void) key_buffer_size;
  3313. (void) alg;
  3314. (void) hash;
  3315. (void) hash_length;
  3316. (void) signature;
  3317. (void) signature_length;
  3318. (void) status;
  3319. (void) coordinate_bytes;
  3320. (void) required_hash_length;
  3321. return PSA_ERROR_NOT_SUPPORTED;
  3322. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3323. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3324. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3325. }
  3326. psa_status_t mbedtls_psa_verify_hash_complete(
  3327. mbedtls_psa_verify_hash_interruptible_operation_t *operation)
  3328. {
  3329. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3330. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3331. defined(MBEDTLS_ECP_RESTARTABLE)
  3332. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3333. /* Ensure max_ops is set to the current value (or default). */
  3334. mbedtls_psa_interruptible_set_max_ops(psa_interruptible_get_max_ops());
  3335. status = mbedtls_to_psa_error(
  3336. mbedtls_ecdsa_verify_restartable(&operation->ctx->grp,
  3337. operation->hash,
  3338. operation->hash_length,
  3339. &operation->ctx->Q,
  3340. &operation->r,
  3341. &operation->s,
  3342. &operation->restart_ctx));
  3343. /* Hide the fact that the restart context only holds a delta of number of
  3344. * ops done during the last operation, not an absolute value. */
  3345. operation->num_ops += operation->restart_ctx.ecp.ops_done;
  3346. return status;
  3347. #else
  3348. (void) operation;
  3349. return PSA_ERROR_NOT_SUPPORTED;
  3350. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3351. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3352. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3353. }
  3354. psa_status_t mbedtls_psa_verify_hash_abort(
  3355. mbedtls_psa_verify_hash_interruptible_operation_t *operation)
  3356. {
  3357. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3358. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3359. defined(MBEDTLS_ECP_RESTARTABLE)
  3360. if (operation->ctx) {
  3361. mbedtls_ecdsa_free(operation->ctx);
  3362. mbedtls_free(operation->ctx);
  3363. operation->ctx = NULL;
  3364. }
  3365. mbedtls_ecdsa_restart_free(&operation->restart_ctx);
  3366. operation->num_ops = 0;
  3367. mbedtls_mpi_free(&operation->r);
  3368. mbedtls_mpi_free(&operation->s);
  3369. return PSA_SUCCESS;
  3370. #else
  3371. (void) operation;
  3372. return PSA_ERROR_NOT_SUPPORTED;
  3373. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3374. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3375. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3376. }
  3377. /****************************************************************/
  3378. /* Symmetric cryptography */
  3379. /****************************************************************/
  3380. static psa_status_t psa_cipher_setup(psa_cipher_operation_t *operation,
  3381. mbedtls_svc_key_id_t key,
  3382. psa_algorithm_t alg,
  3383. mbedtls_operation_t cipher_operation)
  3384. {
  3385. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3386. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3387. psa_key_slot_t *slot = NULL;
  3388. psa_key_usage_t usage = (cipher_operation == MBEDTLS_ENCRYPT ?
  3389. PSA_KEY_USAGE_ENCRYPT :
  3390. PSA_KEY_USAGE_DECRYPT);
  3391. /* A context must be freshly initialized before it can be set up. */
  3392. if (operation->id != 0) {
  3393. status = PSA_ERROR_BAD_STATE;
  3394. goto exit;
  3395. }
  3396. if (!PSA_ALG_IS_CIPHER(alg)) {
  3397. status = PSA_ERROR_INVALID_ARGUMENT;
  3398. goto exit;
  3399. }
  3400. status = psa_get_and_lock_key_slot_with_policy(key, &slot, usage, alg);
  3401. if (status != PSA_SUCCESS) {
  3402. goto exit;
  3403. }
  3404. /* Initialize the operation struct members, except for id. The id member
  3405. * is used to indicate to psa_cipher_abort that there are resources to free,
  3406. * so we only set it (in the driver wrapper) after resources have been
  3407. * allocated/initialized. */
  3408. operation->iv_set = 0;
  3409. if (alg == PSA_ALG_ECB_NO_PADDING) {
  3410. operation->iv_required = 0;
  3411. } else {
  3412. operation->iv_required = 1;
  3413. }
  3414. operation->default_iv_length = PSA_CIPHER_IV_LENGTH(slot->attr.type, alg);
  3415. psa_key_attributes_t attributes = {
  3416. .core = slot->attr
  3417. };
  3418. /* Try doing the operation through a driver before using software fallback. */
  3419. if (cipher_operation == MBEDTLS_ENCRYPT) {
  3420. status = psa_driver_wrapper_cipher_encrypt_setup(operation,
  3421. &attributes,
  3422. slot->key.data,
  3423. slot->key.bytes,
  3424. alg);
  3425. } else {
  3426. status = psa_driver_wrapper_cipher_decrypt_setup(operation,
  3427. &attributes,
  3428. slot->key.data,
  3429. slot->key.bytes,
  3430. alg);
  3431. }
  3432. exit:
  3433. if (status != PSA_SUCCESS) {
  3434. psa_cipher_abort(operation);
  3435. }
  3436. unlock_status = psa_unlock_key_slot(slot);
  3437. return (status == PSA_SUCCESS) ? unlock_status : status;
  3438. }
  3439. psa_status_t psa_cipher_encrypt_setup(psa_cipher_operation_t *operation,
  3440. mbedtls_svc_key_id_t key,
  3441. psa_algorithm_t alg)
  3442. {
  3443. return psa_cipher_setup(operation, key, alg, MBEDTLS_ENCRYPT);
  3444. }
  3445. psa_status_t psa_cipher_decrypt_setup(psa_cipher_operation_t *operation,
  3446. mbedtls_svc_key_id_t key,
  3447. psa_algorithm_t alg)
  3448. {
  3449. return psa_cipher_setup(operation, key, alg, MBEDTLS_DECRYPT);
  3450. }
  3451. psa_status_t psa_cipher_generate_iv(psa_cipher_operation_t *operation,
  3452. uint8_t *iv,
  3453. size_t iv_size,
  3454. size_t *iv_length)
  3455. {
  3456. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3457. uint8_t local_iv[PSA_CIPHER_IV_MAX_SIZE];
  3458. size_t default_iv_length;
  3459. if (operation->id == 0) {
  3460. status = PSA_ERROR_BAD_STATE;
  3461. goto exit;
  3462. }
  3463. if (operation->iv_set || !operation->iv_required) {
  3464. status = PSA_ERROR_BAD_STATE;
  3465. goto exit;
  3466. }
  3467. default_iv_length = operation->default_iv_length;
  3468. if (iv_size < default_iv_length) {
  3469. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3470. goto exit;
  3471. }
  3472. if (default_iv_length > PSA_CIPHER_IV_MAX_SIZE) {
  3473. status = PSA_ERROR_GENERIC_ERROR;
  3474. goto exit;
  3475. }
  3476. status = psa_generate_random(local_iv, default_iv_length);
  3477. if (status != PSA_SUCCESS) {
  3478. goto exit;
  3479. }
  3480. status = psa_driver_wrapper_cipher_set_iv(operation,
  3481. local_iv, default_iv_length);
  3482. exit:
  3483. if (status == PSA_SUCCESS) {
  3484. memcpy(iv, local_iv, default_iv_length);
  3485. *iv_length = default_iv_length;
  3486. operation->iv_set = 1;
  3487. } else {
  3488. *iv_length = 0;
  3489. psa_cipher_abort(operation);
  3490. }
  3491. return status;
  3492. }
  3493. psa_status_t psa_cipher_set_iv(psa_cipher_operation_t *operation,
  3494. const uint8_t *iv,
  3495. size_t iv_length)
  3496. {
  3497. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3498. if (operation->id == 0) {
  3499. status = PSA_ERROR_BAD_STATE;
  3500. goto exit;
  3501. }
  3502. if (operation->iv_set || !operation->iv_required) {
  3503. status = PSA_ERROR_BAD_STATE;
  3504. goto exit;
  3505. }
  3506. if (iv_length > PSA_CIPHER_IV_MAX_SIZE) {
  3507. status = PSA_ERROR_INVALID_ARGUMENT;
  3508. goto exit;
  3509. }
  3510. status = psa_driver_wrapper_cipher_set_iv(operation,
  3511. iv,
  3512. iv_length);
  3513. exit:
  3514. if (status == PSA_SUCCESS) {
  3515. operation->iv_set = 1;
  3516. } else {
  3517. psa_cipher_abort(operation);
  3518. }
  3519. return status;
  3520. }
  3521. psa_status_t psa_cipher_update(psa_cipher_operation_t *operation,
  3522. const uint8_t *input,
  3523. size_t input_length,
  3524. uint8_t *output,
  3525. size_t output_size,
  3526. size_t *output_length)
  3527. {
  3528. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3529. if (operation->id == 0) {
  3530. status = PSA_ERROR_BAD_STATE;
  3531. goto exit;
  3532. }
  3533. if (operation->iv_required && !operation->iv_set) {
  3534. status = PSA_ERROR_BAD_STATE;
  3535. goto exit;
  3536. }
  3537. status = psa_driver_wrapper_cipher_update(operation,
  3538. input,
  3539. input_length,
  3540. output,
  3541. output_size,
  3542. output_length);
  3543. exit:
  3544. if (status != PSA_SUCCESS) {
  3545. psa_cipher_abort(operation);
  3546. }
  3547. return status;
  3548. }
  3549. psa_status_t psa_cipher_finish(psa_cipher_operation_t *operation,
  3550. uint8_t *output,
  3551. size_t output_size,
  3552. size_t *output_length)
  3553. {
  3554. psa_status_t status = PSA_ERROR_GENERIC_ERROR;
  3555. if (operation->id == 0) {
  3556. status = PSA_ERROR_BAD_STATE;
  3557. goto exit;
  3558. }
  3559. if (operation->iv_required && !operation->iv_set) {
  3560. status = PSA_ERROR_BAD_STATE;
  3561. goto exit;
  3562. }
  3563. status = psa_driver_wrapper_cipher_finish(operation,
  3564. output,
  3565. output_size,
  3566. output_length);
  3567. exit:
  3568. if (status == PSA_SUCCESS) {
  3569. return psa_cipher_abort(operation);
  3570. } else {
  3571. *output_length = 0;
  3572. (void) psa_cipher_abort(operation);
  3573. return status;
  3574. }
  3575. }
  3576. psa_status_t psa_cipher_abort(psa_cipher_operation_t *operation)
  3577. {
  3578. if (operation->id == 0) {
  3579. /* The object has (apparently) been initialized but it is not (yet)
  3580. * in use. It's ok to call abort on such an object, and there's
  3581. * nothing to do. */
  3582. return PSA_SUCCESS;
  3583. }
  3584. psa_driver_wrapper_cipher_abort(operation);
  3585. operation->id = 0;
  3586. operation->iv_set = 0;
  3587. operation->iv_required = 0;
  3588. return PSA_SUCCESS;
  3589. }
  3590. psa_status_t psa_cipher_encrypt(mbedtls_svc_key_id_t key,
  3591. psa_algorithm_t alg,
  3592. const uint8_t *input,
  3593. size_t input_length,
  3594. uint8_t *output,
  3595. size_t output_size,
  3596. size_t *output_length)
  3597. {
  3598. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3599. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3600. psa_key_slot_t *slot = NULL;
  3601. uint8_t local_iv[PSA_CIPHER_IV_MAX_SIZE];
  3602. size_t default_iv_length = 0;
  3603. if (!PSA_ALG_IS_CIPHER(alg)) {
  3604. status = PSA_ERROR_INVALID_ARGUMENT;
  3605. goto exit;
  3606. }
  3607. status = psa_get_and_lock_key_slot_with_policy(key, &slot,
  3608. PSA_KEY_USAGE_ENCRYPT,
  3609. alg);
  3610. if (status != PSA_SUCCESS) {
  3611. goto exit;
  3612. }
  3613. psa_key_attributes_t attributes = {
  3614. .core = slot->attr
  3615. };
  3616. default_iv_length = PSA_CIPHER_IV_LENGTH(slot->attr.type, alg);
  3617. if (default_iv_length > PSA_CIPHER_IV_MAX_SIZE) {
  3618. status = PSA_ERROR_GENERIC_ERROR;
  3619. goto exit;
  3620. }
  3621. if (default_iv_length > 0) {
  3622. if (output_size < default_iv_length) {
  3623. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3624. goto exit;
  3625. }
  3626. status = psa_generate_random(local_iv, default_iv_length);
  3627. if (status != PSA_SUCCESS) {
  3628. goto exit;
  3629. }
  3630. }
  3631. status = psa_driver_wrapper_cipher_encrypt(
  3632. &attributes, slot->key.data, slot->key.bytes,
  3633. alg, local_iv, default_iv_length, input, input_length,
  3634. mbedtls_buffer_offset(output, default_iv_length),
  3635. output_size - default_iv_length, output_length);
  3636. exit:
  3637. unlock_status = psa_unlock_key_slot(slot);
  3638. if (status == PSA_SUCCESS) {
  3639. status = unlock_status;
  3640. }
  3641. if (status == PSA_SUCCESS) {
  3642. if (default_iv_length > 0) {
  3643. memcpy(output, local_iv, default_iv_length);
  3644. }
  3645. *output_length += default_iv_length;
  3646. } else {
  3647. *output_length = 0;
  3648. }
  3649. return status;
  3650. }
  3651. psa_status_t psa_cipher_decrypt(mbedtls_svc_key_id_t key,
  3652. psa_algorithm_t alg,
  3653. const uint8_t *input,
  3654. size_t input_length,
  3655. uint8_t *output,
  3656. size_t output_size,
  3657. size_t *output_length)
  3658. {
  3659. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3660. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3661. psa_key_slot_t *slot = NULL;
  3662. if (!PSA_ALG_IS_CIPHER(alg)) {
  3663. status = PSA_ERROR_INVALID_ARGUMENT;
  3664. goto exit;
  3665. }
  3666. status = psa_get_and_lock_key_slot_with_policy(key, &slot,
  3667. PSA_KEY_USAGE_DECRYPT,
  3668. alg);
  3669. if (status != PSA_SUCCESS) {
  3670. goto exit;
  3671. }
  3672. psa_key_attributes_t attributes = {
  3673. .core = slot->attr
  3674. };
  3675. if (alg == PSA_ALG_CCM_STAR_NO_TAG &&
  3676. input_length < PSA_BLOCK_CIPHER_BLOCK_LENGTH(slot->attr.type)) {
  3677. status = PSA_ERROR_INVALID_ARGUMENT;
  3678. goto exit;
  3679. } else if (input_length < PSA_CIPHER_IV_LENGTH(slot->attr.type, alg)) {
  3680. status = PSA_ERROR_INVALID_ARGUMENT;
  3681. goto exit;
  3682. }
  3683. status = psa_driver_wrapper_cipher_decrypt(
  3684. &attributes, slot->key.data, slot->key.bytes,
  3685. alg, input, input_length,
  3686. output, output_size, output_length);
  3687. exit:
  3688. unlock_status = psa_unlock_key_slot(slot);
  3689. if (status == PSA_SUCCESS) {
  3690. status = unlock_status;
  3691. }
  3692. if (status != PSA_SUCCESS) {
  3693. *output_length = 0;
  3694. }
  3695. return status;
  3696. }
  3697. /****************************************************************/
  3698. /* AEAD */
  3699. /****************************************************************/
  3700. /* Helper function to get the base algorithm from its variants. */
  3701. static psa_algorithm_t psa_aead_get_base_algorithm(psa_algorithm_t alg)
  3702. {
  3703. return PSA_ALG_AEAD_WITH_DEFAULT_LENGTH_TAG(alg);
  3704. }
  3705. /* Helper function to perform common nonce length checks. */
  3706. static psa_status_t psa_aead_check_nonce_length(psa_algorithm_t alg,
  3707. size_t nonce_length)
  3708. {
  3709. psa_algorithm_t base_alg = psa_aead_get_base_algorithm(alg);
  3710. switch (base_alg) {
  3711. #if defined(PSA_WANT_ALG_GCM)
  3712. case PSA_ALG_GCM:
  3713. /* Not checking max nonce size here as GCM spec allows almost
  3714. * arbitrarily large nonces. Please note that we do not generally
  3715. * recommend the usage of nonces of greater length than
  3716. * PSA_AEAD_NONCE_MAX_SIZE, as large nonces are hashed to a shorter
  3717. * size, which can then lead to collisions if you encrypt a very
  3718. * large number of messages.*/
  3719. if (nonce_length != 0) {
  3720. return PSA_SUCCESS;
  3721. }
  3722. break;
  3723. #endif /* PSA_WANT_ALG_GCM */
  3724. #if defined(PSA_WANT_ALG_CCM)
  3725. case PSA_ALG_CCM:
  3726. if (nonce_length >= 7 && nonce_length <= 13) {
  3727. return PSA_SUCCESS;
  3728. }
  3729. break;
  3730. #endif /* PSA_WANT_ALG_CCM */
  3731. #if defined(PSA_WANT_ALG_CHACHA20_POLY1305)
  3732. case PSA_ALG_CHACHA20_POLY1305:
  3733. if (nonce_length == 12) {
  3734. return PSA_SUCCESS;
  3735. } else if (nonce_length == 8) {
  3736. return PSA_ERROR_NOT_SUPPORTED;
  3737. }
  3738. break;
  3739. #endif /* PSA_WANT_ALG_CHACHA20_POLY1305 */
  3740. default:
  3741. (void) nonce_length;
  3742. return PSA_ERROR_NOT_SUPPORTED;
  3743. }
  3744. return PSA_ERROR_INVALID_ARGUMENT;
  3745. }
  3746. static psa_status_t psa_aead_check_algorithm(psa_algorithm_t alg)
  3747. {
  3748. if (!PSA_ALG_IS_AEAD(alg) || PSA_ALG_IS_WILDCARD(alg)) {
  3749. return PSA_ERROR_INVALID_ARGUMENT;
  3750. }
  3751. return PSA_SUCCESS;
  3752. }
  3753. psa_status_t psa_aead_encrypt(mbedtls_svc_key_id_t key,
  3754. psa_algorithm_t alg,
  3755. const uint8_t *nonce,
  3756. size_t nonce_length,
  3757. const uint8_t *additional_data,
  3758. size_t additional_data_length,
  3759. const uint8_t *plaintext,
  3760. size_t plaintext_length,
  3761. uint8_t *ciphertext,
  3762. size_t ciphertext_size,
  3763. size_t *ciphertext_length)
  3764. {
  3765. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3766. psa_key_slot_t *slot;
  3767. *ciphertext_length = 0;
  3768. status = psa_aead_check_algorithm(alg);
  3769. if (status != PSA_SUCCESS) {
  3770. return status;
  3771. }
  3772. status = psa_get_and_lock_key_slot_with_policy(
  3773. key, &slot, PSA_KEY_USAGE_ENCRYPT, alg);
  3774. if (status != PSA_SUCCESS) {
  3775. return status;
  3776. }
  3777. psa_key_attributes_t attributes = {
  3778. .core = slot->attr
  3779. };
  3780. status = psa_aead_check_nonce_length(alg, nonce_length);
  3781. if (status != PSA_SUCCESS) {
  3782. goto exit;
  3783. }
  3784. status = psa_driver_wrapper_aead_encrypt(
  3785. &attributes, slot->key.data, slot->key.bytes,
  3786. alg,
  3787. nonce, nonce_length,
  3788. additional_data, additional_data_length,
  3789. plaintext, plaintext_length,
  3790. ciphertext, ciphertext_size, ciphertext_length);
  3791. if (status != PSA_SUCCESS && ciphertext_size != 0) {
  3792. memset(ciphertext, 0, ciphertext_size);
  3793. }
  3794. exit:
  3795. psa_unlock_key_slot(slot);
  3796. return status;
  3797. }
  3798. psa_status_t psa_aead_decrypt(mbedtls_svc_key_id_t key,
  3799. psa_algorithm_t alg,
  3800. const uint8_t *nonce,
  3801. size_t nonce_length,
  3802. const uint8_t *additional_data,
  3803. size_t additional_data_length,
  3804. const uint8_t *ciphertext,
  3805. size_t ciphertext_length,
  3806. uint8_t *plaintext,
  3807. size_t plaintext_size,
  3808. size_t *plaintext_length)
  3809. {
  3810. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3811. psa_key_slot_t *slot;
  3812. *plaintext_length = 0;
  3813. status = psa_aead_check_algorithm(alg);
  3814. if (status != PSA_SUCCESS) {
  3815. return status;
  3816. }
  3817. status = psa_get_and_lock_key_slot_with_policy(
  3818. key, &slot, PSA_KEY_USAGE_DECRYPT, alg);
  3819. if (status != PSA_SUCCESS) {
  3820. return status;
  3821. }
  3822. psa_key_attributes_t attributes = {
  3823. .core = slot->attr
  3824. };
  3825. status = psa_aead_check_nonce_length(alg, nonce_length);
  3826. if (status != PSA_SUCCESS) {
  3827. goto exit;
  3828. }
  3829. status = psa_driver_wrapper_aead_decrypt(
  3830. &attributes, slot->key.data, slot->key.bytes,
  3831. alg,
  3832. nonce, nonce_length,
  3833. additional_data, additional_data_length,
  3834. ciphertext, ciphertext_length,
  3835. plaintext, plaintext_size, plaintext_length);
  3836. if (status != PSA_SUCCESS && plaintext_size != 0) {
  3837. memset(plaintext, 0, plaintext_size);
  3838. }
  3839. exit:
  3840. psa_unlock_key_slot(slot);
  3841. return status;
  3842. }
  3843. static psa_status_t psa_validate_tag_length(psa_algorithm_t alg)
  3844. {
  3845. const uint8_t tag_len = PSA_ALG_AEAD_GET_TAG_LENGTH(alg);
  3846. switch (PSA_ALG_AEAD_WITH_SHORTENED_TAG(alg, 0)) {
  3847. #if defined(PSA_WANT_ALG_CCM)
  3848. case PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_CCM, 0):
  3849. /* CCM allows the following tag lengths: 4, 6, 8, 10, 12, 14, 16.*/
  3850. if (tag_len < 4 || tag_len > 16 || tag_len % 2) {
  3851. return PSA_ERROR_INVALID_ARGUMENT;
  3852. }
  3853. break;
  3854. #endif /* PSA_WANT_ALG_CCM */
  3855. #if defined(PSA_WANT_ALG_GCM)
  3856. case PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_GCM, 0):
  3857. /* GCM allows the following tag lengths: 4, 8, 12, 13, 14, 15, 16. */
  3858. if (tag_len != 4 && tag_len != 8 && (tag_len < 12 || tag_len > 16)) {
  3859. return PSA_ERROR_INVALID_ARGUMENT;
  3860. }
  3861. break;
  3862. #endif /* PSA_WANT_ALG_GCM */
  3863. #if defined(PSA_WANT_ALG_CHACHA20_POLY1305)
  3864. case PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_CHACHA20_POLY1305, 0):
  3865. /* We only support the default tag length. */
  3866. if (tag_len != 16) {
  3867. return PSA_ERROR_INVALID_ARGUMENT;
  3868. }
  3869. break;
  3870. #endif /* PSA_WANT_ALG_CHACHA20_POLY1305 */
  3871. default:
  3872. (void) tag_len;
  3873. return PSA_ERROR_NOT_SUPPORTED;
  3874. }
  3875. return PSA_SUCCESS;
  3876. }
  3877. /* Set the key for a multipart authenticated operation. */
  3878. static psa_status_t psa_aead_setup(psa_aead_operation_t *operation,
  3879. int is_encrypt,
  3880. mbedtls_svc_key_id_t key,
  3881. psa_algorithm_t alg)
  3882. {
  3883. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3884. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3885. psa_key_slot_t *slot = NULL;
  3886. psa_key_usage_t key_usage = 0;
  3887. status = psa_aead_check_algorithm(alg);
  3888. if (status != PSA_SUCCESS) {
  3889. goto exit;
  3890. }
  3891. if (operation->id != 0) {
  3892. status = PSA_ERROR_BAD_STATE;
  3893. goto exit;
  3894. }
  3895. if (operation->nonce_set || operation->lengths_set ||
  3896. operation->ad_started || operation->body_started) {
  3897. status = PSA_ERROR_BAD_STATE;
  3898. goto exit;
  3899. }
  3900. if (is_encrypt) {
  3901. key_usage = PSA_KEY_USAGE_ENCRYPT;
  3902. } else {
  3903. key_usage = PSA_KEY_USAGE_DECRYPT;
  3904. }
  3905. status = psa_get_and_lock_key_slot_with_policy(key, &slot, key_usage,
  3906. alg);
  3907. if (status != PSA_SUCCESS) {
  3908. goto exit;
  3909. }
  3910. psa_key_attributes_t attributes = {
  3911. .core = slot->attr
  3912. };
  3913. if ((status = psa_validate_tag_length(alg)) != PSA_SUCCESS) {
  3914. goto exit;
  3915. }
  3916. if (is_encrypt) {
  3917. status = psa_driver_wrapper_aead_encrypt_setup(operation,
  3918. &attributes,
  3919. slot->key.data,
  3920. slot->key.bytes,
  3921. alg);
  3922. } else {
  3923. status = psa_driver_wrapper_aead_decrypt_setup(operation,
  3924. &attributes,
  3925. slot->key.data,
  3926. slot->key.bytes,
  3927. alg);
  3928. }
  3929. if (status != PSA_SUCCESS) {
  3930. goto exit;
  3931. }
  3932. operation->key_type = psa_get_key_type(&attributes);
  3933. exit:
  3934. unlock_status = psa_unlock_key_slot(slot);
  3935. if (status == PSA_SUCCESS) {
  3936. status = unlock_status;
  3937. operation->alg = psa_aead_get_base_algorithm(alg);
  3938. operation->is_encrypt = is_encrypt;
  3939. } else {
  3940. psa_aead_abort(operation);
  3941. }
  3942. return status;
  3943. }
  3944. /* Set the key for a multipart authenticated encryption operation. */
  3945. psa_status_t psa_aead_encrypt_setup(psa_aead_operation_t *operation,
  3946. mbedtls_svc_key_id_t key,
  3947. psa_algorithm_t alg)
  3948. {
  3949. return psa_aead_setup(operation, 1, key, alg);
  3950. }
  3951. /* Set the key for a multipart authenticated decryption operation. */
  3952. psa_status_t psa_aead_decrypt_setup(psa_aead_operation_t *operation,
  3953. mbedtls_svc_key_id_t key,
  3954. psa_algorithm_t alg)
  3955. {
  3956. return psa_aead_setup(operation, 0, key, alg);
  3957. }
  3958. /* Generate a random nonce / IV for multipart AEAD operation */
  3959. psa_status_t psa_aead_generate_nonce(psa_aead_operation_t *operation,
  3960. uint8_t *nonce,
  3961. size_t nonce_size,
  3962. size_t *nonce_length)
  3963. {
  3964. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3965. uint8_t local_nonce[PSA_AEAD_NONCE_MAX_SIZE];
  3966. size_t required_nonce_size;
  3967. *nonce_length = 0;
  3968. if (operation->id == 0) {
  3969. status = PSA_ERROR_BAD_STATE;
  3970. goto exit;
  3971. }
  3972. if (operation->nonce_set || !operation->is_encrypt) {
  3973. status = PSA_ERROR_BAD_STATE;
  3974. goto exit;
  3975. }
  3976. /* For CCM, this size may not be correct according to the PSA
  3977. * specification. The PSA Crypto 1.0.1 specification states:
  3978. *
  3979. * CCM encodes the plaintext length pLen in L octets, with L the smallest
  3980. * integer >= 2 where pLen < 2^(8L). The nonce length is then 15 - L bytes.
  3981. *
  3982. * However this restriction that L has to be the smallest integer is not
  3983. * applied in practice, and it is not implementable here since the
  3984. * plaintext length may or may not be known at this time. */
  3985. required_nonce_size = PSA_AEAD_NONCE_LENGTH(operation->key_type,
  3986. operation->alg);
  3987. if (nonce_size < required_nonce_size) {
  3988. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3989. goto exit;
  3990. }
  3991. status = psa_generate_random(local_nonce, required_nonce_size);
  3992. if (status != PSA_SUCCESS) {
  3993. goto exit;
  3994. }
  3995. status = psa_aead_set_nonce(operation, local_nonce, required_nonce_size);
  3996. exit:
  3997. if (status == PSA_SUCCESS) {
  3998. memcpy(nonce, local_nonce, required_nonce_size);
  3999. *nonce_length = required_nonce_size;
  4000. } else {
  4001. psa_aead_abort(operation);
  4002. }
  4003. return status;
  4004. }
  4005. /* Set the nonce for a multipart authenticated encryption or decryption
  4006. operation.*/
  4007. psa_status_t psa_aead_set_nonce(psa_aead_operation_t *operation,
  4008. const uint8_t *nonce,
  4009. size_t nonce_length)
  4010. {
  4011. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4012. if (operation->id == 0) {
  4013. status = PSA_ERROR_BAD_STATE;
  4014. goto exit;
  4015. }
  4016. if (operation->nonce_set) {
  4017. status = PSA_ERROR_BAD_STATE;
  4018. goto exit;
  4019. }
  4020. status = psa_aead_check_nonce_length(operation->alg, nonce_length);
  4021. if (status != PSA_SUCCESS) {
  4022. status = PSA_ERROR_INVALID_ARGUMENT;
  4023. goto exit;
  4024. }
  4025. status = psa_driver_wrapper_aead_set_nonce(operation, nonce,
  4026. nonce_length);
  4027. exit:
  4028. if (status == PSA_SUCCESS) {
  4029. operation->nonce_set = 1;
  4030. } else {
  4031. psa_aead_abort(operation);
  4032. }
  4033. return status;
  4034. }
  4035. /* Declare the lengths of the message and additional data for multipart AEAD. */
  4036. psa_status_t psa_aead_set_lengths(psa_aead_operation_t *operation,
  4037. size_t ad_length,
  4038. size_t plaintext_length)
  4039. {
  4040. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4041. if (operation->id == 0) {
  4042. status = PSA_ERROR_BAD_STATE;
  4043. goto exit;
  4044. }
  4045. if (operation->lengths_set || operation->ad_started ||
  4046. operation->body_started) {
  4047. status = PSA_ERROR_BAD_STATE;
  4048. goto exit;
  4049. }
  4050. switch (operation->alg) {
  4051. #if defined(PSA_WANT_ALG_GCM)
  4052. case PSA_ALG_GCM:
  4053. /* Lengths can only be too large for GCM if size_t is bigger than 32
  4054. * bits. Without the guard this code will generate warnings on 32bit
  4055. * builds. */
  4056. #if SIZE_MAX > UINT32_MAX
  4057. if (((uint64_t) ad_length) >> 61 != 0 ||
  4058. ((uint64_t) plaintext_length) > 0xFFFFFFFE0ull) {
  4059. status = PSA_ERROR_INVALID_ARGUMENT;
  4060. goto exit;
  4061. }
  4062. #endif
  4063. break;
  4064. #endif /* PSA_WANT_ALG_GCM */
  4065. #if defined(PSA_WANT_ALG_CCM)
  4066. case PSA_ALG_CCM:
  4067. if (ad_length > 0xFF00) {
  4068. status = PSA_ERROR_INVALID_ARGUMENT;
  4069. goto exit;
  4070. }
  4071. break;
  4072. #endif /* PSA_WANT_ALG_CCM */
  4073. #if defined(PSA_WANT_ALG_CHACHA20_POLY1305)
  4074. case PSA_ALG_CHACHA20_POLY1305:
  4075. /* No length restrictions for ChaChaPoly. */
  4076. break;
  4077. #endif /* PSA_WANT_ALG_CHACHA20_POLY1305 */
  4078. default:
  4079. break;
  4080. }
  4081. status = psa_driver_wrapper_aead_set_lengths(operation, ad_length,
  4082. plaintext_length);
  4083. exit:
  4084. if (status == PSA_SUCCESS) {
  4085. operation->ad_remaining = ad_length;
  4086. operation->body_remaining = plaintext_length;
  4087. operation->lengths_set = 1;
  4088. } else {
  4089. psa_aead_abort(operation);
  4090. }
  4091. return status;
  4092. }
  4093. /* Pass additional data to an active multipart AEAD operation. */
  4094. psa_status_t psa_aead_update_ad(psa_aead_operation_t *operation,
  4095. const uint8_t *input,
  4096. size_t input_length)
  4097. {
  4098. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4099. if (operation->id == 0) {
  4100. status = PSA_ERROR_BAD_STATE;
  4101. goto exit;
  4102. }
  4103. if (!operation->nonce_set || operation->body_started) {
  4104. status = PSA_ERROR_BAD_STATE;
  4105. goto exit;
  4106. }
  4107. if (operation->lengths_set) {
  4108. if (operation->ad_remaining < input_length) {
  4109. status = PSA_ERROR_INVALID_ARGUMENT;
  4110. goto exit;
  4111. }
  4112. operation->ad_remaining -= input_length;
  4113. }
  4114. #if defined(PSA_WANT_ALG_CCM)
  4115. else if (operation->alg == PSA_ALG_CCM) {
  4116. status = PSA_ERROR_BAD_STATE;
  4117. goto exit;
  4118. }
  4119. #endif /* PSA_WANT_ALG_CCM */
  4120. status = psa_driver_wrapper_aead_update_ad(operation, input,
  4121. input_length);
  4122. exit:
  4123. if (status == PSA_SUCCESS) {
  4124. operation->ad_started = 1;
  4125. } else {
  4126. psa_aead_abort(operation);
  4127. }
  4128. return status;
  4129. }
  4130. /* Encrypt or decrypt a message fragment in an active multipart AEAD
  4131. operation.*/
  4132. psa_status_t psa_aead_update(psa_aead_operation_t *operation,
  4133. const uint8_t *input,
  4134. size_t input_length,
  4135. uint8_t *output,
  4136. size_t output_size,
  4137. size_t *output_length)
  4138. {
  4139. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4140. *output_length = 0;
  4141. if (operation->id == 0) {
  4142. status = PSA_ERROR_BAD_STATE;
  4143. goto exit;
  4144. }
  4145. if (!operation->nonce_set) {
  4146. status = PSA_ERROR_BAD_STATE;
  4147. goto exit;
  4148. }
  4149. if (operation->lengths_set) {
  4150. /* Additional data length was supplied, but not all the additional
  4151. data was supplied.*/
  4152. if (operation->ad_remaining != 0) {
  4153. status = PSA_ERROR_INVALID_ARGUMENT;
  4154. goto exit;
  4155. }
  4156. /* Too much data provided. */
  4157. if (operation->body_remaining < input_length) {
  4158. status = PSA_ERROR_INVALID_ARGUMENT;
  4159. goto exit;
  4160. }
  4161. operation->body_remaining -= input_length;
  4162. }
  4163. #if defined(PSA_WANT_ALG_CCM)
  4164. else if (operation->alg == PSA_ALG_CCM) {
  4165. status = PSA_ERROR_BAD_STATE;
  4166. goto exit;
  4167. }
  4168. #endif /* PSA_WANT_ALG_CCM */
  4169. status = psa_driver_wrapper_aead_update(operation, input, input_length,
  4170. output, output_size,
  4171. output_length);
  4172. exit:
  4173. if (status == PSA_SUCCESS) {
  4174. operation->body_started = 1;
  4175. } else {
  4176. psa_aead_abort(operation);
  4177. }
  4178. return status;
  4179. }
  4180. static psa_status_t psa_aead_final_checks(const psa_aead_operation_t *operation)
  4181. {
  4182. if (operation->id == 0 || !operation->nonce_set) {
  4183. return PSA_ERROR_BAD_STATE;
  4184. }
  4185. if (operation->lengths_set && (operation->ad_remaining != 0 ||
  4186. operation->body_remaining != 0)) {
  4187. return PSA_ERROR_INVALID_ARGUMENT;
  4188. }
  4189. return PSA_SUCCESS;
  4190. }
  4191. /* Finish encrypting a message in a multipart AEAD operation. */
  4192. psa_status_t psa_aead_finish(psa_aead_operation_t *operation,
  4193. uint8_t *ciphertext,
  4194. size_t ciphertext_size,
  4195. size_t *ciphertext_length,
  4196. uint8_t *tag,
  4197. size_t tag_size,
  4198. size_t *tag_length)
  4199. {
  4200. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4201. *ciphertext_length = 0;
  4202. *tag_length = tag_size;
  4203. status = psa_aead_final_checks(operation);
  4204. if (status != PSA_SUCCESS) {
  4205. goto exit;
  4206. }
  4207. if (!operation->is_encrypt) {
  4208. status = PSA_ERROR_BAD_STATE;
  4209. goto exit;
  4210. }
  4211. status = psa_driver_wrapper_aead_finish(operation, ciphertext,
  4212. ciphertext_size,
  4213. ciphertext_length,
  4214. tag, tag_size, tag_length);
  4215. exit:
  4216. /* In case the operation fails and the user fails to check for failure or
  4217. * the zero tag size, make sure the tag is set to something implausible.
  4218. * Even if the operation succeeds, make sure we clear the rest of the
  4219. * buffer to prevent potential leakage of anything previously placed in
  4220. * the same buffer.*/
  4221. psa_wipe_tag_output_buffer(tag, status, tag_size, *tag_length);
  4222. psa_aead_abort(operation);
  4223. return status;
  4224. }
  4225. /* Finish authenticating and decrypting a message in a multipart AEAD
  4226. operation.*/
  4227. psa_status_t psa_aead_verify(psa_aead_operation_t *operation,
  4228. uint8_t *plaintext,
  4229. size_t plaintext_size,
  4230. size_t *plaintext_length,
  4231. const uint8_t *tag,
  4232. size_t tag_length)
  4233. {
  4234. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4235. *plaintext_length = 0;
  4236. status = psa_aead_final_checks(operation);
  4237. if (status != PSA_SUCCESS) {
  4238. goto exit;
  4239. }
  4240. if (operation->is_encrypt) {
  4241. status = PSA_ERROR_BAD_STATE;
  4242. goto exit;
  4243. }
  4244. status = psa_driver_wrapper_aead_verify(operation, plaintext,
  4245. plaintext_size,
  4246. plaintext_length,
  4247. tag, tag_length);
  4248. exit:
  4249. psa_aead_abort(operation);
  4250. return status;
  4251. }
  4252. /* Abort an AEAD operation. */
  4253. psa_status_t psa_aead_abort(psa_aead_operation_t *operation)
  4254. {
  4255. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4256. if (operation->id == 0) {
  4257. /* The object has (apparently) been initialized but it is not (yet)
  4258. * in use. It's ok to call abort on such an object, and there's
  4259. * nothing to do. */
  4260. return PSA_SUCCESS;
  4261. }
  4262. status = psa_driver_wrapper_aead_abort(operation);
  4263. memset(operation, 0, sizeof(*operation));
  4264. return status;
  4265. }
  4266. /****************************************************************/
  4267. /* Generators */
  4268. /****************************************************************/
  4269. #if defined(BUILTIN_ALG_ANY_HKDF) || \
  4270. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4271. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS) || \
  4272. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  4273. #define AT_LEAST_ONE_BUILTIN_KDF
  4274. #endif /* At least one builtin KDF */
  4275. #if defined(BUILTIN_ALG_ANY_HKDF) || \
  4276. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4277. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4278. static psa_status_t psa_key_derivation_start_hmac(
  4279. psa_mac_operation_t *operation,
  4280. psa_algorithm_t hash_alg,
  4281. const uint8_t *hmac_key,
  4282. size_t hmac_key_length)
  4283. {
  4284. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4285. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  4286. psa_set_key_type(&attributes, PSA_KEY_TYPE_HMAC);
  4287. psa_set_key_bits(&attributes, PSA_BYTES_TO_BITS(hmac_key_length));
  4288. psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH);
  4289. operation->is_sign = 1;
  4290. operation->mac_size = PSA_HASH_LENGTH(hash_alg);
  4291. status = psa_driver_wrapper_mac_sign_setup(operation,
  4292. &attributes,
  4293. hmac_key, hmac_key_length,
  4294. PSA_ALG_HMAC(hash_alg));
  4295. psa_reset_key_attributes(&attributes);
  4296. return status;
  4297. }
  4298. #endif /* KDF algorithms reliant on HMAC */
  4299. #define HKDF_STATE_INIT 0 /* no input yet */
  4300. #define HKDF_STATE_STARTED 1 /* got salt */
  4301. #define HKDF_STATE_KEYED 2 /* got key */
  4302. #define HKDF_STATE_OUTPUT 3 /* output started */
  4303. static psa_algorithm_t psa_key_derivation_get_kdf_alg(
  4304. const psa_key_derivation_operation_t *operation)
  4305. {
  4306. if (PSA_ALG_IS_KEY_AGREEMENT(operation->alg)) {
  4307. return PSA_ALG_KEY_AGREEMENT_GET_KDF(operation->alg);
  4308. } else {
  4309. return operation->alg;
  4310. }
  4311. }
  4312. psa_status_t psa_key_derivation_abort(psa_key_derivation_operation_t *operation)
  4313. {
  4314. psa_status_t status = PSA_SUCCESS;
  4315. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg(operation);
  4316. if (kdf_alg == 0) {
  4317. /* The object has (apparently) been initialized but it is not
  4318. * in use. It's ok to call abort on such an object, and there's
  4319. * nothing to do. */
  4320. } else
  4321. #if defined(BUILTIN_ALG_ANY_HKDF)
  4322. if (PSA_ALG_IS_ANY_HKDF(kdf_alg)) {
  4323. mbedtls_free(operation->ctx.hkdf.info);
  4324. status = psa_mac_abort(&operation->ctx.hkdf.hmac);
  4325. } else
  4326. #endif /* BUILTIN_ALG_ANY_HKDF */
  4327. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4328. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4329. if (PSA_ALG_IS_TLS12_PRF(kdf_alg) ||
  4330. /* TLS-1.2 PSK-to-MS KDF uses the same core as TLS-1.2 PRF */
  4331. PSA_ALG_IS_TLS12_PSK_TO_MS(kdf_alg)) {
  4332. if (operation->ctx.tls12_prf.secret != NULL) {
  4333. mbedtls_platform_zeroize(operation->ctx.tls12_prf.secret,
  4334. operation->ctx.tls12_prf.secret_length);
  4335. mbedtls_free(operation->ctx.tls12_prf.secret);
  4336. }
  4337. if (operation->ctx.tls12_prf.seed != NULL) {
  4338. mbedtls_platform_zeroize(operation->ctx.tls12_prf.seed,
  4339. operation->ctx.tls12_prf.seed_length);
  4340. mbedtls_free(operation->ctx.tls12_prf.seed);
  4341. }
  4342. if (operation->ctx.tls12_prf.label != NULL) {
  4343. mbedtls_platform_zeroize(operation->ctx.tls12_prf.label,
  4344. operation->ctx.tls12_prf.label_length);
  4345. mbedtls_free(operation->ctx.tls12_prf.label);
  4346. }
  4347. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4348. if (operation->ctx.tls12_prf.other_secret != NULL) {
  4349. mbedtls_platform_zeroize(operation->ctx.tls12_prf.other_secret,
  4350. operation->ctx.tls12_prf.other_secret_length);
  4351. mbedtls_free(operation->ctx.tls12_prf.other_secret);
  4352. }
  4353. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4354. status = PSA_SUCCESS;
  4355. /* We leave the fields Ai and output_block to be erased safely by the
  4356. * mbedtls_platform_zeroize() in the end of this function. */
  4357. } else
  4358. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) ||
  4359. * defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS) */
  4360. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  4361. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  4362. mbedtls_platform_zeroize(operation->ctx.tls12_ecjpake_to_pms.data,
  4363. sizeof(operation->ctx.tls12_ecjpake_to_pms.data));
  4364. } else
  4365. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS) */
  4366. {
  4367. status = PSA_ERROR_BAD_STATE;
  4368. }
  4369. mbedtls_platform_zeroize(operation, sizeof(*operation));
  4370. return status;
  4371. }
  4372. psa_status_t psa_key_derivation_get_capacity(const psa_key_derivation_operation_t *operation,
  4373. size_t *capacity)
  4374. {
  4375. if (operation->alg == 0) {
  4376. /* This is a blank key derivation operation. */
  4377. return PSA_ERROR_BAD_STATE;
  4378. }
  4379. *capacity = operation->capacity;
  4380. return PSA_SUCCESS;
  4381. }
  4382. psa_status_t psa_key_derivation_set_capacity(psa_key_derivation_operation_t *operation,
  4383. size_t capacity)
  4384. {
  4385. if (operation->alg == 0) {
  4386. return PSA_ERROR_BAD_STATE;
  4387. }
  4388. if (capacity > operation->capacity) {
  4389. return PSA_ERROR_INVALID_ARGUMENT;
  4390. }
  4391. operation->capacity = capacity;
  4392. return PSA_SUCCESS;
  4393. }
  4394. #if defined(BUILTIN_ALG_ANY_HKDF)
  4395. /* Read some bytes from an HKDF-based operation. */
  4396. static psa_status_t psa_key_derivation_hkdf_read(psa_hkdf_key_derivation_t *hkdf,
  4397. psa_algorithm_t kdf_alg,
  4398. uint8_t *output,
  4399. size_t output_length)
  4400. {
  4401. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH(kdf_alg);
  4402. uint8_t hash_length = PSA_HASH_LENGTH(hash_alg);
  4403. size_t hmac_output_length;
  4404. psa_status_t status;
  4405. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  4406. const uint8_t last_block = PSA_ALG_IS_HKDF_EXTRACT(kdf_alg) ? 0 : 0xff;
  4407. #else
  4408. const uint8_t last_block = 0xff;
  4409. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  4410. if (hkdf->state < HKDF_STATE_KEYED ||
  4411. (!hkdf->info_set
  4412. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  4413. && !PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)
  4414. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  4415. )) {
  4416. return PSA_ERROR_BAD_STATE;
  4417. }
  4418. hkdf->state = HKDF_STATE_OUTPUT;
  4419. while (output_length != 0) {
  4420. /* Copy what remains of the current block */
  4421. uint8_t n = hash_length - hkdf->offset_in_block;
  4422. if (n > output_length) {
  4423. n = (uint8_t) output_length;
  4424. }
  4425. memcpy(output, hkdf->output_block + hkdf->offset_in_block, n);
  4426. output += n;
  4427. output_length -= n;
  4428. hkdf->offset_in_block += n;
  4429. if (output_length == 0) {
  4430. break;
  4431. }
  4432. /* We can't be wanting more output after the last block, otherwise
  4433. * the capacity check in psa_key_derivation_output_bytes() would have
  4434. * prevented this call. It could happen only if the operation
  4435. * object was corrupted or if this function is called directly
  4436. * inside the library. */
  4437. if (hkdf->block_number == last_block) {
  4438. return PSA_ERROR_BAD_STATE;
  4439. }
  4440. /* We need a new block */
  4441. ++hkdf->block_number;
  4442. hkdf->offset_in_block = 0;
  4443. status = psa_key_derivation_start_hmac(&hkdf->hmac,
  4444. hash_alg,
  4445. hkdf->prk,
  4446. hash_length);
  4447. if (status != PSA_SUCCESS) {
  4448. return status;
  4449. }
  4450. if (hkdf->block_number != 1) {
  4451. status = psa_mac_update(&hkdf->hmac,
  4452. hkdf->output_block,
  4453. hash_length);
  4454. if (status != PSA_SUCCESS) {
  4455. return status;
  4456. }
  4457. }
  4458. status = psa_mac_update(&hkdf->hmac,
  4459. hkdf->info,
  4460. hkdf->info_length);
  4461. if (status != PSA_SUCCESS) {
  4462. return status;
  4463. }
  4464. status = psa_mac_update(&hkdf->hmac,
  4465. &hkdf->block_number, 1);
  4466. if (status != PSA_SUCCESS) {
  4467. return status;
  4468. }
  4469. status = psa_mac_sign_finish(&hkdf->hmac,
  4470. hkdf->output_block,
  4471. sizeof(hkdf->output_block),
  4472. &hmac_output_length);
  4473. if (status != PSA_SUCCESS) {
  4474. return status;
  4475. }
  4476. }
  4477. return PSA_SUCCESS;
  4478. }
  4479. #endif /* BUILTIN_ALG_ANY_HKDF */
  4480. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4481. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4482. static psa_status_t psa_key_derivation_tls12_prf_generate_next_block(
  4483. psa_tls12_prf_key_derivation_t *tls12_prf,
  4484. psa_algorithm_t alg)
  4485. {
  4486. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH(alg);
  4487. uint8_t hash_length = PSA_HASH_LENGTH(hash_alg);
  4488. psa_mac_operation_t hmac = PSA_MAC_OPERATION_INIT;
  4489. size_t hmac_output_length;
  4490. psa_status_t status, cleanup_status;
  4491. /* We can't be wanting more output after block 0xff, otherwise
  4492. * the capacity check in psa_key_derivation_output_bytes() would have
  4493. * prevented this call. It could happen only if the operation
  4494. * object was corrupted or if this function is called directly
  4495. * inside the library. */
  4496. if (tls12_prf->block_number == 0xff) {
  4497. return PSA_ERROR_CORRUPTION_DETECTED;
  4498. }
  4499. /* We need a new block */
  4500. ++tls12_prf->block_number;
  4501. tls12_prf->left_in_block = hash_length;
  4502. /* Recall the definition of the TLS-1.2-PRF from RFC 5246:
  4503. *
  4504. * PRF(secret, label, seed) = P_<hash>(secret, label + seed)
  4505. *
  4506. * P_hash(secret, seed) = HMAC_hash(secret, A(1) + seed) +
  4507. * HMAC_hash(secret, A(2) + seed) +
  4508. * HMAC_hash(secret, A(3) + seed) + ...
  4509. *
  4510. * A(0) = seed
  4511. * A(i) = HMAC_hash(secret, A(i-1))
  4512. *
  4513. * The `psa_tls12_prf_key_derivation` structure saves the block
  4514. * `HMAC_hash(secret, A(i) + seed)` from which the output
  4515. * is currently extracted as `output_block` and where i is
  4516. * `block_number`.
  4517. */
  4518. status = psa_key_derivation_start_hmac(&hmac,
  4519. hash_alg,
  4520. tls12_prf->secret,
  4521. tls12_prf->secret_length);
  4522. if (status != PSA_SUCCESS) {
  4523. goto cleanup;
  4524. }
  4525. /* Calculate A(i) where i = tls12_prf->block_number. */
  4526. if (tls12_prf->block_number == 1) {
  4527. /* A(1) = HMAC_hash(secret, A(0)), where A(0) = seed. (The RFC overloads
  4528. * the variable seed and in this instance means it in the context of the
  4529. * P_hash function, where seed = label + seed.) */
  4530. status = psa_mac_update(&hmac,
  4531. tls12_prf->label,
  4532. tls12_prf->label_length);
  4533. if (status != PSA_SUCCESS) {
  4534. goto cleanup;
  4535. }
  4536. status = psa_mac_update(&hmac,
  4537. tls12_prf->seed,
  4538. tls12_prf->seed_length);
  4539. if (status != PSA_SUCCESS) {
  4540. goto cleanup;
  4541. }
  4542. } else {
  4543. /* A(i) = HMAC_hash(secret, A(i-1)) */
  4544. status = psa_mac_update(&hmac, tls12_prf->Ai, hash_length);
  4545. if (status != PSA_SUCCESS) {
  4546. goto cleanup;
  4547. }
  4548. }
  4549. status = psa_mac_sign_finish(&hmac,
  4550. tls12_prf->Ai, hash_length,
  4551. &hmac_output_length);
  4552. if (hmac_output_length != hash_length) {
  4553. status = PSA_ERROR_CORRUPTION_DETECTED;
  4554. }
  4555. if (status != PSA_SUCCESS) {
  4556. goto cleanup;
  4557. }
  4558. /* Calculate HMAC_hash(secret, A(i) + label + seed). */
  4559. status = psa_key_derivation_start_hmac(&hmac,
  4560. hash_alg,
  4561. tls12_prf->secret,
  4562. tls12_prf->secret_length);
  4563. if (status != PSA_SUCCESS) {
  4564. goto cleanup;
  4565. }
  4566. status = psa_mac_update(&hmac, tls12_prf->Ai, hash_length);
  4567. if (status != PSA_SUCCESS) {
  4568. goto cleanup;
  4569. }
  4570. status = psa_mac_update(&hmac, tls12_prf->label, tls12_prf->label_length);
  4571. if (status != PSA_SUCCESS) {
  4572. goto cleanup;
  4573. }
  4574. status = psa_mac_update(&hmac, tls12_prf->seed, tls12_prf->seed_length);
  4575. if (status != PSA_SUCCESS) {
  4576. goto cleanup;
  4577. }
  4578. status = psa_mac_sign_finish(&hmac,
  4579. tls12_prf->output_block, hash_length,
  4580. &hmac_output_length);
  4581. if (status != PSA_SUCCESS) {
  4582. goto cleanup;
  4583. }
  4584. cleanup:
  4585. cleanup_status = psa_mac_abort(&hmac);
  4586. if (status == PSA_SUCCESS && cleanup_status != PSA_SUCCESS) {
  4587. status = cleanup_status;
  4588. }
  4589. return status;
  4590. }
  4591. static psa_status_t psa_key_derivation_tls12_prf_read(
  4592. psa_tls12_prf_key_derivation_t *tls12_prf,
  4593. psa_algorithm_t alg,
  4594. uint8_t *output,
  4595. size_t output_length)
  4596. {
  4597. psa_algorithm_t hash_alg = PSA_ALG_TLS12_PRF_GET_HASH(alg);
  4598. uint8_t hash_length = PSA_HASH_LENGTH(hash_alg);
  4599. psa_status_t status;
  4600. uint8_t offset, length;
  4601. switch (tls12_prf->state) {
  4602. case PSA_TLS12_PRF_STATE_LABEL_SET:
  4603. tls12_prf->state = PSA_TLS12_PRF_STATE_OUTPUT;
  4604. break;
  4605. case PSA_TLS12_PRF_STATE_OUTPUT:
  4606. break;
  4607. default:
  4608. return PSA_ERROR_BAD_STATE;
  4609. }
  4610. while (output_length != 0) {
  4611. /* Check if we have fully processed the current block. */
  4612. if (tls12_prf->left_in_block == 0) {
  4613. status = psa_key_derivation_tls12_prf_generate_next_block(tls12_prf,
  4614. alg);
  4615. if (status != PSA_SUCCESS) {
  4616. return status;
  4617. }
  4618. continue;
  4619. }
  4620. if (tls12_prf->left_in_block > output_length) {
  4621. length = (uint8_t) output_length;
  4622. } else {
  4623. length = tls12_prf->left_in_block;
  4624. }
  4625. offset = hash_length - tls12_prf->left_in_block;
  4626. memcpy(output, tls12_prf->output_block + offset, length);
  4627. output += length;
  4628. output_length -= length;
  4629. tls12_prf->left_in_block -= length;
  4630. }
  4631. return PSA_SUCCESS;
  4632. }
  4633. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF ||
  4634. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4635. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  4636. static psa_status_t psa_key_derivation_tls12_ecjpake_to_pms_read(
  4637. psa_tls12_ecjpake_to_pms_t *ecjpake,
  4638. uint8_t *output,
  4639. size_t output_length)
  4640. {
  4641. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4642. size_t output_size = 0;
  4643. if (output_length != 32) {
  4644. return PSA_ERROR_INVALID_ARGUMENT;
  4645. }
  4646. status = psa_hash_compute(PSA_ALG_SHA_256, ecjpake->data,
  4647. PSA_TLS12_ECJPAKE_TO_PMS_DATA_SIZE, output, output_length,
  4648. &output_size);
  4649. if (status != PSA_SUCCESS) {
  4650. return status;
  4651. }
  4652. if (output_size != output_length) {
  4653. return PSA_ERROR_GENERIC_ERROR;
  4654. }
  4655. return PSA_SUCCESS;
  4656. }
  4657. #endif
  4658. psa_status_t psa_key_derivation_output_bytes(
  4659. psa_key_derivation_operation_t *operation,
  4660. uint8_t *output,
  4661. size_t output_length)
  4662. {
  4663. psa_status_t status;
  4664. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg(operation);
  4665. if (operation->alg == 0) {
  4666. /* This is a blank operation. */
  4667. return PSA_ERROR_BAD_STATE;
  4668. }
  4669. if (output_length > operation->capacity) {
  4670. operation->capacity = 0;
  4671. /* Go through the error path to wipe all confidential data now
  4672. * that the operation object is useless. */
  4673. status = PSA_ERROR_INSUFFICIENT_DATA;
  4674. goto exit;
  4675. }
  4676. if (output_length == 0 && operation->capacity == 0) {
  4677. /* Edge case: this is a finished operation, and 0 bytes
  4678. * were requested. The right error in this case could
  4679. * be either INSUFFICIENT_CAPACITY or BAD_STATE. Return
  4680. * INSUFFICIENT_CAPACITY, which is right for a finished
  4681. * operation, for consistency with the case when
  4682. * output_length > 0. */
  4683. return PSA_ERROR_INSUFFICIENT_DATA;
  4684. }
  4685. operation->capacity -= output_length;
  4686. #if defined(BUILTIN_ALG_ANY_HKDF)
  4687. if (PSA_ALG_IS_ANY_HKDF(kdf_alg)) {
  4688. status = psa_key_derivation_hkdf_read(&operation->ctx.hkdf, kdf_alg,
  4689. output, output_length);
  4690. } else
  4691. #endif /* BUILTIN_ALG_ANY_HKDF */
  4692. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4693. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4694. if (PSA_ALG_IS_TLS12_PRF(kdf_alg) ||
  4695. PSA_ALG_IS_TLS12_PSK_TO_MS(kdf_alg)) {
  4696. status = psa_key_derivation_tls12_prf_read(&operation->ctx.tls12_prf,
  4697. kdf_alg, output,
  4698. output_length);
  4699. } else
  4700. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF ||
  4701. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4702. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  4703. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  4704. status = psa_key_derivation_tls12_ecjpake_to_pms_read(
  4705. &operation->ctx.tls12_ecjpake_to_pms, output, output_length);
  4706. } else
  4707. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS */
  4708. {
  4709. (void) kdf_alg;
  4710. return PSA_ERROR_BAD_STATE;
  4711. }
  4712. exit:
  4713. if (status != PSA_SUCCESS) {
  4714. /* Preserve the algorithm upon errors, but clear all sensitive state.
  4715. * This allows us to differentiate between exhausted operations and
  4716. * blank operations, so we can return PSA_ERROR_BAD_STATE on blank
  4717. * operations. */
  4718. psa_algorithm_t alg = operation->alg;
  4719. psa_key_derivation_abort(operation);
  4720. operation->alg = alg;
  4721. memset(output, '!', output_length);
  4722. }
  4723. return status;
  4724. }
  4725. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  4726. static void psa_des_set_key_parity(uint8_t *data, size_t data_size)
  4727. {
  4728. if (data_size >= 8) {
  4729. mbedtls_des_key_set_parity(data);
  4730. }
  4731. if (data_size >= 16) {
  4732. mbedtls_des_key_set_parity(data + 8);
  4733. }
  4734. if (data_size >= 24) {
  4735. mbedtls_des_key_set_parity(data + 16);
  4736. }
  4737. }
  4738. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  4739. /*
  4740. * ECC keys on a Weierstrass elliptic curve require the generation
  4741. * of a private key which is an integer
  4742. * in the range [1, N - 1], where N is the boundary of the private key domain:
  4743. * N is the prime p for Diffie-Hellman, or the order of the
  4744. * curve’s base point for ECC.
  4745. *
  4746. * Let m be the bit size of N, such that 2^m > N >= 2^(m-1).
  4747. * This function generates the private key using the following process:
  4748. *
  4749. * 1. Draw a byte string of length ceiling(m/8) bytes.
  4750. * 2. If m is not a multiple of 8, set the most significant
  4751. * (8 * ceiling(m/8) - m) bits of the first byte in the string to zero.
  4752. * 3. Convert the string to integer k by decoding it as a big-endian byte string.
  4753. * 4. If k > N - 2, discard the result and return to step 1.
  4754. * 5. Output k + 1 as the private key.
  4755. *
  4756. * This method allows compliance to NIST standards, specifically the methods titled
  4757. * Key-Pair Generation by Testing Candidates in the following publications:
  4758. * - NIST Special Publication 800-56A: Recommendation for Pair-Wise Key-Establishment
  4759. * Schemes Using Discrete Logarithm Cryptography [SP800-56A] §5.6.1.1.4 for
  4760. * Diffie-Hellman keys.
  4761. *
  4762. * - [SP800-56A] §5.6.1.2.2 or FIPS Publication 186-4: Digital Signature
  4763. * Standard (DSS) [FIPS186-4] §B.4.2 for elliptic curve keys.
  4764. *
  4765. * Note: Function allocates memory for *data buffer, so given *data should be
  4766. * always NULL.
  4767. */
  4768. #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR) || \
  4769. defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY) || \
  4770. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  4771. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) || \
  4772. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  4773. static psa_status_t psa_generate_derived_ecc_key_weierstrass_helper(
  4774. psa_key_slot_t *slot,
  4775. size_t bits,
  4776. psa_key_derivation_operation_t *operation,
  4777. uint8_t **data
  4778. )
  4779. {
  4780. #if defined(MBEDTLS_ECP_C)
  4781. unsigned key_out_of_range = 1;
  4782. mbedtls_mpi k;
  4783. mbedtls_mpi diff_N_2;
  4784. int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
  4785. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4786. mbedtls_mpi_init(&k);
  4787. mbedtls_mpi_init(&diff_N_2);
  4788. psa_ecc_family_t curve = PSA_KEY_TYPE_ECC_GET_FAMILY(
  4789. slot->attr.type);
  4790. mbedtls_ecp_group_id grp_id =
  4791. mbedtls_ecc_group_of_psa(curve, bits, 0);
  4792. if (grp_id == MBEDTLS_ECP_DP_NONE) {
  4793. ret = MBEDTLS_ERR_ASN1_INVALID_DATA;
  4794. goto cleanup;
  4795. }
  4796. mbedtls_ecp_group ecp_group;
  4797. mbedtls_ecp_group_init(&ecp_group);
  4798. MBEDTLS_MPI_CHK(mbedtls_ecp_group_load(&ecp_group, grp_id));
  4799. /* N is the boundary of the private key domain (ecp_group.N). */
  4800. /* Let m be the bit size of N. */
  4801. size_t m = ecp_group.nbits;
  4802. size_t m_bytes = PSA_BITS_TO_BYTES(m);
  4803. /* Calculate N - 2 - it will be needed later. */
  4804. MBEDTLS_MPI_CHK(mbedtls_mpi_sub_int(&diff_N_2, &ecp_group.N, 2));
  4805. /* Note: This function is always called with *data == NULL and it
  4806. * allocates memory for the data buffer. */
  4807. *data = mbedtls_calloc(1, m_bytes);
  4808. if (*data == NULL) {
  4809. ret = MBEDTLS_ERR_ASN1_ALLOC_FAILED;
  4810. goto cleanup;
  4811. }
  4812. while (key_out_of_range) {
  4813. /* 1. Draw a byte string of length ceiling(m/8) bytes. */
  4814. if ((status = psa_key_derivation_output_bytes(operation, *data, m_bytes)) != 0) {
  4815. goto cleanup;
  4816. }
  4817. /* 2. If m is not a multiple of 8 */
  4818. if (m % 8 != 0) {
  4819. /* Set the most significant
  4820. * (8 * ceiling(m/8) - m) bits of the first byte in
  4821. * the string to zero.
  4822. */
  4823. uint8_t clear_bit_mask = (1 << (m % 8)) - 1;
  4824. (*data)[0] &= clear_bit_mask;
  4825. }
  4826. /* 3. Convert the string to integer k by decoding it as a
  4827. * big-endian byte string.
  4828. */
  4829. MBEDTLS_MPI_CHK(mbedtls_mpi_read_binary(&k, *data, m_bytes));
  4830. /* 4. If k > N - 2, discard the result and return to step 1.
  4831. * Result of comparison is returned. When it indicates error
  4832. * then this function is called again.
  4833. */
  4834. MBEDTLS_MPI_CHK(mbedtls_mpi_lt_mpi_ct(&diff_N_2, &k, &key_out_of_range));
  4835. }
  4836. /* 5. Output k + 1 as the private key. */
  4837. MBEDTLS_MPI_CHK(mbedtls_mpi_add_int(&k, &k, 1));
  4838. MBEDTLS_MPI_CHK(mbedtls_mpi_write_binary(&k, *data, m_bytes));
  4839. cleanup:
  4840. if (ret != 0) {
  4841. status = mbedtls_to_psa_error(ret);
  4842. }
  4843. if (status != PSA_SUCCESS) {
  4844. mbedtls_free(*data);
  4845. *data = NULL;
  4846. }
  4847. mbedtls_mpi_free(&k);
  4848. mbedtls_mpi_free(&diff_N_2);
  4849. return status;
  4850. #else /* MBEDTLS_ECP_C */
  4851. (void) slot;
  4852. (void) bits;
  4853. (void) operation;
  4854. (void) data;
  4855. return PSA_ERROR_NOT_SUPPORTED;
  4856. #endif /* MBEDTLS_ECP_C */
  4857. }
  4858. /* ECC keys on a Montgomery elliptic curve draws a byte string whose length
  4859. * is determined by the curve, and sets the mandatory bits accordingly. That is:
  4860. *
  4861. * - Curve25519 (PSA_ECC_FAMILY_MONTGOMERY, 255 bits):
  4862. * draw a 32-byte string and process it as specified in
  4863. * Elliptic Curves for Security [RFC7748] §5.
  4864. *
  4865. * - Curve448 (PSA_ECC_FAMILY_MONTGOMERY, 448 bits):
  4866. * draw a 56-byte string and process it as specified in [RFC7748] §5.
  4867. *
  4868. * Note: Function allocates memory for *data buffer, so given *data should be
  4869. * always NULL.
  4870. */
  4871. static psa_status_t psa_generate_derived_ecc_key_montgomery_helper(
  4872. size_t bits,
  4873. psa_key_derivation_operation_t *operation,
  4874. uint8_t **data
  4875. )
  4876. {
  4877. size_t output_length;
  4878. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4879. switch (bits) {
  4880. case 255:
  4881. output_length = 32;
  4882. break;
  4883. case 448:
  4884. output_length = 56;
  4885. break;
  4886. default:
  4887. return PSA_ERROR_INVALID_ARGUMENT;
  4888. break;
  4889. }
  4890. *data = mbedtls_calloc(1, output_length);
  4891. if (*data == NULL) {
  4892. return PSA_ERROR_INSUFFICIENT_MEMORY;
  4893. }
  4894. status = psa_key_derivation_output_bytes(operation, *data, output_length);
  4895. if (status != PSA_SUCCESS) {
  4896. return status;
  4897. }
  4898. switch (bits) {
  4899. case 255:
  4900. (*data)[0] &= 248;
  4901. (*data)[31] &= 127;
  4902. (*data)[31] |= 64;
  4903. break;
  4904. case 448:
  4905. (*data)[0] &= 252;
  4906. (*data)[55] |= 128;
  4907. break;
  4908. default:
  4909. return PSA_ERROR_CORRUPTION_DETECTED;
  4910. break;
  4911. }
  4912. return status;
  4913. }
  4914. #endif /* defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR) ||
  4915. defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY) ||
  4916. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  4917. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) ||
  4918. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH) */
  4919. static psa_status_t psa_generate_derived_key_internal(
  4920. psa_key_slot_t *slot,
  4921. size_t bits,
  4922. psa_key_derivation_operation_t *operation)
  4923. {
  4924. uint8_t *data = NULL;
  4925. size_t bytes = PSA_BITS_TO_BYTES(bits);
  4926. size_t storage_size = bytes;
  4927. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4928. if (PSA_KEY_TYPE_IS_PUBLIC_KEY(slot->attr.type)) {
  4929. return PSA_ERROR_INVALID_ARGUMENT;
  4930. }
  4931. #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR) || \
  4932. defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY) || \
  4933. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  4934. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) || \
  4935. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  4936. if (PSA_KEY_TYPE_IS_ECC(slot->attr.type)) {
  4937. psa_ecc_family_t curve = PSA_KEY_TYPE_ECC_GET_FAMILY(slot->attr.type);
  4938. if (PSA_ECC_FAMILY_IS_WEIERSTRASS(curve)) {
  4939. /* Weierstrass elliptic curve */
  4940. status = psa_generate_derived_ecc_key_weierstrass_helper(slot, bits, operation, &data);
  4941. if (status != PSA_SUCCESS) {
  4942. goto exit;
  4943. }
  4944. } else {
  4945. /* Montgomery elliptic curve */
  4946. status = psa_generate_derived_ecc_key_montgomery_helper(bits, operation, &data);
  4947. if (status != PSA_SUCCESS) {
  4948. goto exit;
  4949. }
  4950. }
  4951. } else
  4952. #endif /* defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR) ||
  4953. defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY) ||
  4954. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  4955. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) ||
  4956. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH) */
  4957. if (key_type_is_raw_bytes(slot->attr.type)) {
  4958. if (bits % 8 != 0) {
  4959. return PSA_ERROR_INVALID_ARGUMENT;
  4960. }
  4961. data = mbedtls_calloc(1, bytes);
  4962. if (data == NULL) {
  4963. return PSA_ERROR_INSUFFICIENT_MEMORY;
  4964. }
  4965. status = psa_key_derivation_output_bytes(operation, data, bytes);
  4966. if (status != PSA_SUCCESS) {
  4967. goto exit;
  4968. }
  4969. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  4970. if (slot->attr.type == PSA_KEY_TYPE_DES) {
  4971. psa_des_set_key_parity(data, bytes);
  4972. }
  4973. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES) */
  4974. } else {
  4975. return PSA_ERROR_NOT_SUPPORTED;
  4976. }
  4977. slot->attr.bits = (psa_key_bits_t) bits;
  4978. psa_key_attributes_t attributes = {
  4979. .core = slot->attr
  4980. };
  4981. if (psa_key_lifetime_is_external(attributes.core.lifetime)) {
  4982. status = psa_driver_wrapper_get_key_buffer_size(&attributes,
  4983. &storage_size);
  4984. if (status != PSA_SUCCESS) {
  4985. goto exit;
  4986. }
  4987. }
  4988. status = psa_allocate_buffer_to_slot(slot, storage_size);
  4989. if (status != PSA_SUCCESS) {
  4990. goto exit;
  4991. }
  4992. status = psa_driver_wrapper_import_key(&attributes,
  4993. data, bytes,
  4994. slot->key.data,
  4995. slot->key.bytes,
  4996. &slot->key.bytes, &bits);
  4997. if (bits != slot->attr.bits) {
  4998. status = PSA_ERROR_INVALID_ARGUMENT;
  4999. }
  5000. exit:
  5001. mbedtls_free(data);
  5002. return status;
  5003. }
  5004. psa_status_t psa_key_derivation_output_key(const psa_key_attributes_t *attributes,
  5005. psa_key_derivation_operation_t *operation,
  5006. mbedtls_svc_key_id_t *key)
  5007. {
  5008. psa_status_t status;
  5009. psa_key_slot_t *slot = NULL;
  5010. psa_se_drv_table_entry_t *driver = NULL;
  5011. *key = MBEDTLS_SVC_KEY_ID_INIT;
  5012. /* Reject any attempt to create a zero-length key so that we don't
  5013. * risk tripping up later, e.g. on a malloc(0) that returns NULL. */
  5014. if (psa_get_key_bits(attributes) == 0) {
  5015. return PSA_ERROR_INVALID_ARGUMENT;
  5016. }
  5017. if (operation->alg == PSA_ALG_NONE) {
  5018. return PSA_ERROR_BAD_STATE;
  5019. }
  5020. if (!operation->can_output_key) {
  5021. return PSA_ERROR_NOT_PERMITTED;
  5022. }
  5023. status = psa_start_key_creation(PSA_KEY_CREATION_DERIVE, attributes,
  5024. &slot, &driver);
  5025. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  5026. if (driver != NULL) {
  5027. /* Deriving a key in a secure element is not implemented yet. */
  5028. status = PSA_ERROR_NOT_SUPPORTED;
  5029. }
  5030. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  5031. if (status == PSA_SUCCESS) {
  5032. status = psa_generate_derived_key_internal(slot,
  5033. attributes->core.bits,
  5034. operation);
  5035. }
  5036. if (status == PSA_SUCCESS) {
  5037. status = psa_finish_key_creation(slot, driver, key);
  5038. }
  5039. if (status != PSA_SUCCESS) {
  5040. psa_fail_key_creation(slot, driver);
  5041. }
  5042. return status;
  5043. }
  5044. /****************************************************************/
  5045. /* Key derivation */
  5046. /****************************************************************/
  5047. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  5048. static int is_kdf_alg_supported(psa_algorithm_t kdf_alg)
  5049. {
  5050. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  5051. if (PSA_ALG_IS_HKDF(kdf_alg)) {
  5052. return 1;
  5053. }
  5054. #endif
  5055. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  5056. if (PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)) {
  5057. return 1;
  5058. }
  5059. #endif
  5060. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND)
  5061. if (PSA_ALG_IS_HKDF_EXPAND(kdf_alg)) {
  5062. return 1;
  5063. }
  5064. #endif
  5065. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF)
  5066. if (PSA_ALG_IS_TLS12_PRF(kdf_alg)) {
  5067. return 1;
  5068. }
  5069. #endif
  5070. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  5071. if (PSA_ALG_IS_TLS12_PSK_TO_MS(kdf_alg)) {
  5072. return 1;
  5073. }
  5074. #endif
  5075. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  5076. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  5077. return 1;
  5078. }
  5079. #endif
  5080. return 0;
  5081. }
  5082. static psa_status_t psa_hash_try_support(psa_algorithm_t alg)
  5083. {
  5084. psa_hash_operation_t operation = PSA_HASH_OPERATION_INIT;
  5085. psa_status_t status = psa_hash_setup(&operation, alg);
  5086. psa_hash_abort(&operation);
  5087. return status;
  5088. }
  5089. static psa_status_t psa_key_derivation_setup_kdf(
  5090. psa_key_derivation_operation_t *operation,
  5091. psa_algorithm_t kdf_alg)
  5092. {
  5093. /* Make sure that operation->ctx is properly zero-initialised. (Macro
  5094. * initialisers for this union leave some bytes unspecified.) */
  5095. memset(&operation->ctx, 0, sizeof(operation->ctx));
  5096. /* Make sure that kdf_alg is a supported key derivation algorithm. */
  5097. if (!is_kdf_alg_supported(kdf_alg)) {
  5098. return PSA_ERROR_NOT_SUPPORTED;
  5099. }
  5100. /* All currently supported key derivation algorithms (apart from
  5101. * ecjpake to pms) are based on a hash algorithm. */
  5102. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH(kdf_alg);
  5103. size_t hash_size = PSA_HASH_LENGTH(hash_alg);
  5104. if (kdf_alg != PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  5105. if (hash_size == 0) {
  5106. return PSA_ERROR_NOT_SUPPORTED;
  5107. }
  5108. /* Make sure that hash_alg is a supported hash algorithm. Otherwise
  5109. * we might fail later, which is somewhat unfriendly and potentially
  5110. * risk-prone. */
  5111. psa_status_t status = psa_hash_try_support(hash_alg);
  5112. if (status != PSA_SUCCESS) {
  5113. return status;
  5114. }
  5115. } else {
  5116. hash_size = PSA_HASH_LENGTH(PSA_ALG_SHA_256);
  5117. }
  5118. if ((PSA_ALG_IS_TLS12_PRF(kdf_alg) ||
  5119. PSA_ALG_IS_TLS12_PSK_TO_MS(kdf_alg)) &&
  5120. !(hash_alg == PSA_ALG_SHA_256 || hash_alg == PSA_ALG_SHA_384)) {
  5121. return PSA_ERROR_NOT_SUPPORTED;
  5122. }
  5123. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT) || \
  5124. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  5125. if (PSA_ALG_IS_HKDF_EXTRACT(kdf_alg) ||
  5126. (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS)) {
  5127. operation->capacity = hash_size;
  5128. } else
  5129. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT ||
  5130. MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS */
  5131. operation->capacity = 255 * hash_size;
  5132. return PSA_SUCCESS;
  5133. }
  5134. static psa_status_t psa_key_agreement_try_support(psa_algorithm_t alg)
  5135. {
  5136. #if defined(PSA_WANT_ALG_ECDH)
  5137. if (alg == PSA_ALG_ECDH) {
  5138. return PSA_SUCCESS;
  5139. }
  5140. #endif
  5141. (void) alg;
  5142. return PSA_ERROR_NOT_SUPPORTED;
  5143. }
  5144. static int psa_key_derivation_allows_free_form_secret_input(
  5145. psa_algorithm_t kdf_alg)
  5146. {
  5147. #if defined(PSA_WANT_ALG_TLS12_ECJPAKE_TO_PMS)
  5148. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  5149. return 0;
  5150. }
  5151. #endif
  5152. (void) kdf_alg;
  5153. return 1;
  5154. }
  5155. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  5156. psa_status_t psa_key_derivation_setup(psa_key_derivation_operation_t *operation,
  5157. psa_algorithm_t alg)
  5158. {
  5159. psa_status_t status;
  5160. if (operation->alg != 0) {
  5161. return PSA_ERROR_BAD_STATE;
  5162. }
  5163. if (PSA_ALG_IS_RAW_KEY_AGREEMENT(alg)) {
  5164. return PSA_ERROR_INVALID_ARGUMENT;
  5165. } else if (PSA_ALG_IS_KEY_AGREEMENT(alg)) {
  5166. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  5167. psa_algorithm_t kdf_alg = PSA_ALG_KEY_AGREEMENT_GET_KDF(alg);
  5168. psa_algorithm_t ka_alg = PSA_ALG_KEY_AGREEMENT_GET_BASE(alg);
  5169. status = psa_key_agreement_try_support(ka_alg);
  5170. if (status != PSA_SUCCESS) {
  5171. return status;
  5172. }
  5173. if (!psa_key_derivation_allows_free_form_secret_input(kdf_alg)) {
  5174. return PSA_ERROR_INVALID_ARGUMENT;
  5175. }
  5176. status = psa_key_derivation_setup_kdf(operation, kdf_alg);
  5177. #else
  5178. return PSA_ERROR_NOT_SUPPORTED;
  5179. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  5180. } else if (PSA_ALG_IS_KEY_DERIVATION(alg)) {
  5181. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  5182. status = psa_key_derivation_setup_kdf(operation, alg);
  5183. #else
  5184. return PSA_ERROR_NOT_SUPPORTED;
  5185. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  5186. } else {
  5187. return PSA_ERROR_INVALID_ARGUMENT;
  5188. }
  5189. if (status == PSA_SUCCESS) {
  5190. operation->alg = alg;
  5191. }
  5192. return status;
  5193. }
  5194. #if defined(BUILTIN_ALG_ANY_HKDF)
  5195. static psa_status_t psa_hkdf_input(psa_hkdf_key_derivation_t *hkdf,
  5196. psa_algorithm_t kdf_alg,
  5197. psa_key_derivation_step_t step,
  5198. const uint8_t *data,
  5199. size_t data_length)
  5200. {
  5201. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH(kdf_alg);
  5202. psa_status_t status;
  5203. switch (step) {
  5204. case PSA_KEY_DERIVATION_INPUT_SALT:
  5205. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND)
  5206. if (PSA_ALG_IS_HKDF_EXPAND(kdf_alg)) {
  5207. return PSA_ERROR_INVALID_ARGUMENT;
  5208. }
  5209. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND */
  5210. if (hkdf->state != HKDF_STATE_INIT) {
  5211. return PSA_ERROR_BAD_STATE;
  5212. } else {
  5213. status = psa_key_derivation_start_hmac(&hkdf->hmac,
  5214. hash_alg,
  5215. data, data_length);
  5216. if (status != PSA_SUCCESS) {
  5217. return status;
  5218. }
  5219. hkdf->state = HKDF_STATE_STARTED;
  5220. return PSA_SUCCESS;
  5221. }
  5222. case PSA_KEY_DERIVATION_INPUT_SECRET:
  5223. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND)
  5224. if (PSA_ALG_IS_HKDF_EXPAND(kdf_alg)) {
  5225. /* We shouldn't be in different state as HKDF_EXPAND only allows
  5226. * two inputs: SECRET (this case) and INFO which does not modify
  5227. * the state. It could happen only if the hkdf
  5228. * object was corrupted. */
  5229. if (hkdf->state != HKDF_STATE_INIT) {
  5230. return PSA_ERROR_BAD_STATE;
  5231. }
  5232. /* Allow only input that fits expected prk size */
  5233. if (data_length != PSA_HASH_LENGTH(hash_alg)) {
  5234. return PSA_ERROR_INVALID_ARGUMENT;
  5235. }
  5236. memcpy(hkdf->prk, data, data_length);
  5237. } else
  5238. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND */
  5239. {
  5240. /* HKDF: If no salt was provided, use an empty salt.
  5241. * HKDF-EXTRACT: salt is mandatory. */
  5242. if (hkdf->state == HKDF_STATE_INIT) {
  5243. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  5244. if (PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)) {
  5245. return PSA_ERROR_BAD_STATE;
  5246. }
  5247. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  5248. status = psa_key_derivation_start_hmac(&hkdf->hmac,
  5249. hash_alg,
  5250. NULL, 0);
  5251. if (status != PSA_SUCCESS) {
  5252. return status;
  5253. }
  5254. hkdf->state = HKDF_STATE_STARTED;
  5255. }
  5256. if (hkdf->state != HKDF_STATE_STARTED) {
  5257. return PSA_ERROR_BAD_STATE;
  5258. }
  5259. status = psa_mac_update(&hkdf->hmac,
  5260. data, data_length);
  5261. if (status != PSA_SUCCESS) {
  5262. return status;
  5263. }
  5264. status = psa_mac_sign_finish(&hkdf->hmac,
  5265. hkdf->prk,
  5266. sizeof(hkdf->prk),
  5267. &data_length);
  5268. if (status != PSA_SUCCESS) {
  5269. return status;
  5270. }
  5271. }
  5272. hkdf->state = HKDF_STATE_KEYED;
  5273. hkdf->block_number = 0;
  5274. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  5275. if (PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)) {
  5276. /* The only block of output is the PRK. */
  5277. memcpy(hkdf->output_block, hkdf->prk, PSA_HASH_LENGTH(hash_alg));
  5278. hkdf->offset_in_block = 0;
  5279. } else
  5280. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  5281. {
  5282. /* Block 0 is empty, and the next block will be
  5283. * generated by psa_key_derivation_hkdf_read(). */
  5284. hkdf->offset_in_block = PSA_HASH_LENGTH(hash_alg);
  5285. }
  5286. return PSA_SUCCESS;
  5287. case PSA_KEY_DERIVATION_INPUT_INFO:
  5288. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  5289. if (PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)) {
  5290. return PSA_ERROR_INVALID_ARGUMENT;
  5291. }
  5292. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  5293. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND)
  5294. if (PSA_ALG_IS_HKDF_EXPAND(kdf_alg) &&
  5295. hkdf->state == HKDF_STATE_INIT) {
  5296. return PSA_ERROR_BAD_STATE;
  5297. }
  5298. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  5299. if (hkdf->state == HKDF_STATE_OUTPUT) {
  5300. return PSA_ERROR_BAD_STATE;
  5301. }
  5302. if (hkdf->info_set) {
  5303. return PSA_ERROR_BAD_STATE;
  5304. }
  5305. hkdf->info_length = data_length;
  5306. if (data_length != 0) {
  5307. hkdf->info = mbedtls_calloc(1, data_length);
  5308. if (hkdf->info == NULL) {
  5309. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5310. }
  5311. memcpy(hkdf->info, data, data_length);
  5312. }
  5313. hkdf->info_set = 1;
  5314. return PSA_SUCCESS;
  5315. default:
  5316. return PSA_ERROR_INVALID_ARGUMENT;
  5317. }
  5318. }
  5319. #endif /* BUILTIN_ALG_ANY_HKDF */
  5320. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  5321. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  5322. static psa_status_t psa_tls12_prf_set_seed(psa_tls12_prf_key_derivation_t *prf,
  5323. const uint8_t *data,
  5324. size_t data_length)
  5325. {
  5326. if (prf->state != PSA_TLS12_PRF_STATE_INIT) {
  5327. return PSA_ERROR_BAD_STATE;
  5328. }
  5329. if (data_length != 0) {
  5330. prf->seed = mbedtls_calloc(1, data_length);
  5331. if (prf->seed == NULL) {
  5332. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5333. }
  5334. memcpy(prf->seed, data, data_length);
  5335. prf->seed_length = data_length;
  5336. }
  5337. prf->state = PSA_TLS12_PRF_STATE_SEED_SET;
  5338. return PSA_SUCCESS;
  5339. }
  5340. static psa_status_t psa_tls12_prf_set_key(psa_tls12_prf_key_derivation_t *prf,
  5341. const uint8_t *data,
  5342. size_t data_length)
  5343. {
  5344. if (prf->state != PSA_TLS12_PRF_STATE_SEED_SET &&
  5345. prf->state != PSA_TLS12_PRF_STATE_OTHER_KEY_SET) {
  5346. return PSA_ERROR_BAD_STATE;
  5347. }
  5348. if (data_length != 0) {
  5349. prf->secret = mbedtls_calloc(1, data_length);
  5350. if (prf->secret == NULL) {
  5351. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5352. }
  5353. memcpy(prf->secret, data, data_length);
  5354. prf->secret_length = data_length;
  5355. }
  5356. prf->state = PSA_TLS12_PRF_STATE_KEY_SET;
  5357. return PSA_SUCCESS;
  5358. }
  5359. static psa_status_t psa_tls12_prf_set_label(psa_tls12_prf_key_derivation_t *prf,
  5360. const uint8_t *data,
  5361. size_t data_length)
  5362. {
  5363. if (prf->state != PSA_TLS12_PRF_STATE_KEY_SET) {
  5364. return PSA_ERROR_BAD_STATE;
  5365. }
  5366. if (data_length != 0) {
  5367. prf->label = mbedtls_calloc(1, data_length);
  5368. if (prf->label == NULL) {
  5369. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5370. }
  5371. memcpy(prf->label, data, data_length);
  5372. prf->label_length = data_length;
  5373. }
  5374. prf->state = PSA_TLS12_PRF_STATE_LABEL_SET;
  5375. return PSA_SUCCESS;
  5376. }
  5377. static psa_status_t psa_tls12_prf_input(psa_tls12_prf_key_derivation_t *prf,
  5378. psa_key_derivation_step_t step,
  5379. const uint8_t *data,
  5380. size_t data_length)
  5381. {
  5382. switch (step) {
  5383. case PSA_KEY_DERIVATION_INPUT_SEED:
  5384. return psa_tls12_prf_set_seed(prf, data, data_length);
  5385. case PSA_KEY_DERIVATION_INPUT_SECRET:
  5386. return psa_tls12_prf_set_key(prf, data, data_length);
  5387. case PSA_KEY_DERIVATION_INPUT_LABEL:
  5388. return psa_tls12_prf_set_label(prf, data, data_length);
  5389. default:
  5390. return PSA_ERROR_INVALID_ARGUMENT;
  5391. }
  5392. }
  5393. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) ||
  5394. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  5395. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  5396. static psa_status_t psa_tls12_prf_psk_to_ms_set_key(
  5397. psa_tls12_prf_key_derivation_t *prf,
  5398. const uint8_t *data,
  5399. size_t data_length)
  5400. {
  5401. psa_status_t status;
  5402. const size_t pms_len = (prf->state == PSA_TLS12_PRF_STATE_OTHER_KEY_SET ?
  5403. 4 + data_length + prf->other_secret_length :
  5404. 4 + 2 * data_length);
  5405. if (data_length > PSA_TLS12_PSK_TO_MS_PSK_MAX_SIZE) {
  5406. return PSA_ERROR_INVALID_ARGUMENT;
  5407. }
  5408. uint8_t *pms = mbedtls_calloc(1, pms_len);
  5409. if (pms == NULL) {
  5410. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5411. }
  5412. uint8_t *cur = pms;
  5413. /* pure-PSK:
  5414. * Quoting RFC 4279, Section 2:
  5415. *
  5416. * The premaster secret is formed as follows: if the PSK is N octets
  5417. * long, concatenate a uint16 with the value N, N zero octets, a second
  5418. * uint16 with the value N, and the PSK itself.
  5419. *
  5420. * mixed-PSK:
  5421. * In a DHE-PSK, RSA-PSK, ECDHE-PSK the premaster secret is formed as
  5422. * follows: concatenate a uint16 with the length of the other secret,
  5423. * the other secret itself, uint16 with the length of PSK, and the
  5424. * PSK itself.
  5425. * For details please check:
  5426. * - RFC 4279, Section 4 for the definition of RSA-PSK,
  5427. * - RFC 4279, Section 3 for the definition of DHE-PSK,
  5428. * - RFC 5489 for the definition of ECDHE-PSK.
  5429. */
  5430. if (prf->state == PSA_TLS12_PRF_STATE_OTHER_KEY_SET) {
  5431. *cur++ = MBEDTLS_BYTE_1(prf->other_secret_length);
  5432. *cur++ = MBEDTLS_BYTE_0(prf->other_secret_length);
  5433. if (prf->other_secret_length != 0) {
  5434. memcpy(cur, prf->other_secret, prf->other_secret_length);
  5435. mbedtls_platform_zeroize(prf->other_secret, prf->other_secret_length);
  5436. cur += prf->other_secret_length;
  5437. }
  5438. } else {
  5439. *cur++ = MBEDTLS_BYTE_1(data_length);
  5440. *cur++ = MBEDTLS_BYTE_0(data_length);
  5441. memset(cur, 0, data_length);
  5442. cur += data_length;
  5443. }
  5444. *cur++ = MBEDTLS_BYTE_1(data_length);
  5445. *cur++ = MBEDTLS_BYTE_0(data_length);
  5446. memcpy(cur, data, data_length);
  5447. cur += data_length;
  5448. status = psa_tls12_prf_set_key(prf, pms, cur - pms);
  5449. mbedtls_platform_zeroize(pms, pms_len);
  5450. mbedtls_free(pms);
  5451. return status;
  5452. }
  5453. static psa_status_t psa_tls12_prf_psk_to_ms_set_other_key(
  5454. psa_tls12_prf_key_derivation_t *prf,
  5455. const uint8_t *data,
  5456. size_t data_length)
  5457. {
  5458. if (prf->state != PSA_TLS12_PRF_STATE_SEED_SET) {
  5459. return PSA_ERROR_BAD_STATE;
  5460. }
  5461. if (data_length != 0) {
  5462. prf->other_secret = mbedtls_calloc(1, data_length);
  5463. if (prf->other_secret == NULL) {
  5464. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5465. }
  5466. memcpy(prf->other_secret, data, data_length);
  5467. prf->other_secret_length = data_length;
  5468. } else {
  5469. prf->other_secret_length = 0;
  5470. }
  5471. prf->state = PSA_TLS12_PRF_STATE_OTHER_KEY_SET;
  5472. return PSA_SUCCESS;
  5473. }
  5474. static psa_status_t psa_tls12_prf_psk_to_ms_input(
  5475. psa_tls12_prf_key_derivation_t *prf,
  5476. psa_key_derivation_step_t step,
  5477. const uint8_t *data,
  5478. size_t data_length)
  5479. {
  5480. switch (step) {
  5481. case PSA_KEY_DERIVATION_INPUT_SECRET:
  5482. return psa_tls12_prf_psk_to_ms_set_key(prf,
  5483. data, data_length);
  5484. break;
  5485. case PSA_KEY_DERIVATION_INPUT_OTHER_SECRET:
  5486. return psa_tls12_prf_psk_to_ms_set_other_key(prf,
  5487. data,
  5488. data_length);
  5489. break;
  5490. default:
  5491. return psa_tls12_prf_input(prf, step, data, data_length);
  5492. break;
  5493. }
  5494. }
  5495. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  5496. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  5497. static psa_status_t psa_tls12_ecjpake_to_pms_input(
  5498. psa_tls12_ecjpake_to_pms_t *ecjpake,
  5499. psa_key_derivation_step_t step,
  5500. const uint8_t *data,
  5501. size_t data_length)
  5502. {
  5503. if (data_length != PSA_TLS12_ECJPAKE_TO_PMS_INPUT_SIZE ||
  5504. step != PSA_KEY_DERIVATION_INPUT_SECRET) {
  5505. return PSA_ERROR_INVALID_ARGUMENT;
  5506. }
  5507. /* Check if the passed point is in an uncompressed form */
  5508. if (data[0] != 0x04) {
  5509. return PSA_ERROR_INVALID_ARGUMENT;
  5510. }
  5511. /* Only K.X has to be extracted - bytes 1 to 32 inclusive. */
  5512. memcpy(ecjpake->data, data + 1, PSA_TLS12_ECJPAKE_TO_PMS_DATA_SIZE);
  5513. return PSA_SUCCESS;
  5514. }
  5515. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS */
  5516. /** Check whether the given key type is acceptable for the given
  5517. * input step of a key derivation.
  5518. *
  5519. * Secret inputs must have the type #PSA_KEY_TYPE_DERIVE.
  5520. * Non-secret inputs must have the type #PSA_KEY_TYPE_RAW_DATA.
  5521. * Both secret and non-secret inputs can alternatively have the type
  5522. * #PSA_KEY_TYPE_NONE, which is never the type of a key object, meaning
  5523. * that the input was passed as a buffer rather than via a key object.
  5524. */
  5525. static int psa_key_derivation_check_input_type(
  5526. psa_key_derivation_step_t step,
  5527. psa_key_type_t key_type)
  5528. {
  5529. switch (step) {
  5530. case PSA_KEY_DERIVATION_INPUT_SECRET:
  5531. if (key_type == PSA_KEY_TYPE_DERIVE) {
  5532. return PSA_SUCCESS;
  5533. }
  5534. if (key_type == PSA_KEY_TYPE_NONE) {
  5535. return PSA_SUCCESS;
  5536. }
  5537. break;
  5538. case PSA_KEY_DERIVATION_INPUT_OTHER_SECRET:
  5539. if (key_type == PSA_KEY_TYPE_DERIVE) {
  5540. return PSA_SUCCESS;
  5541. }
  5542. if (key_type == PSA_KEY_TYPE_NONE) {
  5543. return PSA_SUCCESS;
  5544. }
  5545. break;
  5546. case PSA_KEY_DERIVATION_INPUT_LABEL:
  5547. case PSA_KEY_DERIVATION_INPUT_SALT:
  5548. case PSA_KEY_DERIVATION_INPUT_INFO:
  5549. case PSA_KEY_DERIVATION_INPUT_SEED:
  5550. if (key_type == PSA_KEY_TYPE_RAW_DATA) {
  5551. return PSA_SUCCESS;
  5552. }
  5553. if (key_type == PSA_KEY_TYPE_NONE) {
  5554. return PSA_SUCCESS;
  5555. }
  5556. break;
  5557. }
  5558. return PSA_ERROR_INVALID_ARGUMENT;
  5559. }
  5560. static psa_status_t psa_key_derivation_input_internal(
  5561. psa_key_derivation_operation_t *operation,
  5562. psa_key_derivation_step_t step,
  5563. psa_key_type_t key_type,
  5564. const uint8_t *data,
  5565. size_t data_length)
  5566. {
  5567. psa_status_t status;
  5568. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg(operation);
  5569. status = psa_key_derivation_check_input_type(step, key_type);
  5570. if (status != PSA_SUCCESS) {
  5571. goto exit;
  5572. }
  5573. #if defined(BUILTIN_ALG_ANY_HKDF)
  5574. if (PSA_ALG_IS_ANY_HKDF(kdf_alg)) {
  5575. status = psa_hkdf_input(&operation->ctx.hkdf, kdf_alg,
  5576. step, data, data_length);
  5577. } else
  5578. #endif /* BUILTIN_ALG_ANY_HKDF */
  5579. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF)
  5580. if (PSA_ALG_IS_TLS12_PRF(kdf_alg)) {
  5581. status = psa_tls12_prf_input(&operation->ctx.tls12_prf,
  5582. step, data, data_length);
  5583. } else
  5584. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF */
  5585. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  5586. if (PSA_ALG_IS_TLS12_PSK_TO_MS(kdf_alg)) {
  5587. status = psa_tls12_prf_psk_to_ms_input(&operation->ctx.tls12_prf,
  5588. step, data, data_length);
  5589. } else
  5590. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  5591. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  5592. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  5593. status = psa_tls12_ecjpake_to_pms_input(
  5594. &operation->ctx.tls12_ecjpake_to_pms, step, data, data_length);
  5595. } else
  5596. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS */
  5597. {
  5598. /* This can't happen unless the operation object was not initialized */
  5599. (void) data;
  5600. (void) data_length;
  5601. (void) kdf_alg;
  5602. return PSA_ERROR_BAD_STATE;
  5603. }
  5604. exit:
  5605. if (status != PSA_SUCCESS) {
  5606. psa_key_derivation_abort(operation);
  5607. }
  5608. return status;
  5609. }
  5610. psa_status_t psa_key_derivation_input_bytes(
  5611. psa_key_derivation_operation_t *operation,
  5612. psa_key_derivation_step_t step,
  5613. const uint8_t *data,
  5614. size_t data_length)
  5615. {
  5616. return psa_key_derivation_input_internal(operation, step,
  5617. PSA_KEY_TYPE_NONE,
  5618. data, data_length);
  5619. }
  5620. psa_status_t psa_key_derivation_input_key(
  5621. psa_key_derivation_operation_t *operation,
  5622. psa_key_derivation_step_t step,
  5623. mbedtls_svc_key_id_t key)
  5624. {
  5625. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  5626. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  5627. psa_key_slot_t *slot;
  5628. status = psa_get_and_lock_transparent_key_slot_with_policy(
  5629. key, &slot, PSA_KEY_USAGE_DERIVE, operation->alg);
  5630. if (status != PSA_SUCCESS) {
  5631. psa_key_derivation_abort(operation);
  5632. return status;
  5633. }
  5634. /* Passing a key object as a SECRET input unlocks the permission
  5635. * to output to a key object. */
  5636. if (step == PSA_KEY_DERIVATION_INPUT_SECRET) {
  5637. operation->can_output_key = 1;
  5638. }
  5639. status = psa_key_derivation_input_internal(operation,
  5640. step, slot->attr.type,
  5641. slot->key.data,
  5642. slot->key.bytes);
  5643. unlock_status = psa_unlock_key_slot(slot);
  5644. return (status == PSA_SUCCESS) ? unlock_status : status;
  5645. }
  5646. /****************************************************************/
  5647. /* Key agreement */
  5648. /****************************************************************/
  5649. psa_status_t psa_key_agreement_raw_builtin(const psa_key_attributes_t *attributes,
  5650. const uint8_t *key_buffer,
  5651. size_t key_buffer_size,
  5652. psa_algorithm_t alg,
  5653. const uint8_t *peer_key,
  5654. size_t peer_key_length,
  5655. uint8_t *shared_secret,
  5656. size_t shared_secret_size,
  5657. size_t *shared_secret_length)
  5658. {
  5659. switch (alg) {
  5660. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  5661. case PSA_ALG_ECDH:
  5662. return mbedtls_psa_key_agreement_ecdh(attributes, key_buffer,
  5663. key_buffer_size, alg,
  5664. peer_key, peer_key_length,
  5665. shared_secret,
  5666. shared_secret_size,
  5667. shared_secret_length);
  5668. #endif /* MBEDTLS_PSA_BUILTIN_ALG_ECDH */
  5669. default:
  5670. (void) attributes;
  5671. (void) key_buffer;
  5672. (void) key_buffer_size;
  5673. (void) peer_key;
  5674. (void) peer_key_length;
  5675. (void) shared_secret;
  5676. (void) shared_secret_size;
  5677. (void) shared_secret_length;
  5678. return PSA_ERROR_NOT_SUPPORTED;
  5679. }
  5680. }
  5681. /** Internal function for raw key agreement
  5682. * Calls the driver wrapper which will hand off key agreement task
  5683. * to the driver's implementation if a driver is present.
  5684. * Fallback specified in the driver wrapper is built-in raw key agreement
  5685. * (psa_key_agreement_raw_builtin).
  5686. */
  5687. static psa_status_t psa_key_agreement_raw_internal(psa_algorithm_t alg,
  5688. psa_key_slot_t *private_key,
  5689. const uint8_t *peer_key,
  5690. size_t peer_key_length,
  5691. uint8_t *shared_secret,
  5692. size_t shared_secret_size,
  5693. size_t *shared_secret_length)
  5694. {
  5695. if (!PSA_ALG_IS_RAW_KEY_AGREEMENT(alg)) {
  5696. return PSA_ERROR_NOT_SUPPORTED;
  5697. }
  5698. psa_key_attributes_t attributes = {
  5699. .core = private_key->attr
  5700. };
  5701. return psa_driver_wrapper_key_agreement(&attributes,
  5702. private_key->key.data,
  5703. private_key->key.bytes, alg,
  5704. peer_key, peer_key_length,
  5705. shared_secret,
  5706. shared_secret_size,
  5707. shared_secret_length);
  5708. }
  5709. /* Note that if this function fails, you must call psa_key_derivation_abort()
  5710. * to potentially free embedded data structures and wipe confidential data.
  5711. */
  5712. static psa_status_t psa_key_agreement_internal(psa_key_derivation_operation_t *operation,
  5713. psa_key_derivation_step_t step,
  5714. psa_key_slot_t *private_key,
  5715. const uint8_t *peer_key,
  5716. size_t peer_key_length)
  5717. {
  5718. psa_status_t status;
  5719. uint8_t shared_secret[PSA_RAW_KEY_AGREEMENT_OUTPUT_MAX_SIZE];
  5720. size_t shared_secret_length = 0;
  5721. psa_algorithm_t ka_alg = PSA_ALG_KEY_AGREEMENT_GET_BASE(operation->alg);
  5722. /* Step 1: run the secret agreement algorithm to generate the shared
  5723. * secret. */
  5724. status = psa_key_agreement_raw_internal(ka_alg,
  5725. private_key,
  5726. peer_key, peer_key_length,
  5727. shared_secret,
  5728. sizeof(shared_secret),
  5729. &shared_secret_length);
  5730. if (status != PSA_SUCCESS) {
  5731. goto exit;
  5732. }
  5733. /* Step 2: set up the key derivation to generate key material from
  5734. * the shared secret. A shared secret is permitted wherever a key
  5735. * of type DERIVE is permitted. */
  5736. status = psa_key_derivation_input_internal(operation, step,
  5737. PSA_KEY_TYPE_DERIVE,
  5738. shared_secret,
  5739. shared_secret_length);
  5740. exit:
  5741. mbedtls_platform_zeroize(shared_secret, shared_secret_length);
  5742. return status;
  5743. }
  5744. psa_status_t psa_key_derivation_key_agreement(psa_key_derivation_operation_t *operation,
  5745. psa_key_derivation_step_t step,
  5746. mbedtls_svc_key_id_t private_key,
  5747. const uint8_t *peer_key,
  5748. size_t peer_key_length)
  5749. {
  5750. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  5751. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  5752. psa_key_slot_t *slot;
  5753. if (!PSA_ALG_IS_KEY_AGREEMENT(operation->alg)) {
  5754. return PSA_ERROR_INVALID_ARGUMENT;
  5755. }
  5756. status = psa_get_and_lock_transparent_key_slot_with_policy(
  5757. private_key, &slot, PSA_KEY_USAGE_DERIVE, operation->alg);
  5758. if (status != PSA_SUCCESS) {
  5759. return status;
  5760. }
  5761. status = psa_key_agreement_internal(operation, step,
  5762. slot,
  5763. peer_key, peer_key_length);
  5764. if (status != PSA_SUCCESS) {
  5765. psa_key_derivation_abort(operation);
  5766. } else {
  5767. /* If a private key has been added as SECRET, we allow the derived
  5768. * key material to be used as a key in PSA Crypto. */
  5769. if (step == PSA_KEY_DERIVATION_INPUT_SECRET) {
  5770. operation->can_output_key = 1;
  5771. }
  5772. }
  5773. unlock_status = psa_unlock_key_slot(slot);
  5774. return (status == PSA_SUCCESS) ? unlock_status : status;
  5775. }
  5776. psa_status_t psa_raw_key_agreement(psa_algorithm_t alg,
  5777. mbedtls_svc_key_id_t private_key,
  5778. const uint8_t *peer_key,
  5779. size_t peer_key_length,
  5780. uint8_t *output,
  5781. size_t output_size,
  5782. size_t *output_length)
  5783. {
  5784. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  5785. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  5786. psa_key_slot_t *slot = NULL;
  5787. if (!PSA_ALG_IS_KEY_AGREEMENT(alg)) {
  5788. status = PSA_ERROR_INVALID_ARGUMENT;
  5789. goto exit;
  5790. }
  5791. status = psa_get_and_lock_transparent_key_slot_with_policy(
  5792. private_key, &slot, PSA_KEY_USAGE_DERIVE, alg);
  5793. if (status != PSA_SUCCESS) {
  5794. goto exit;
  5795. }
  5796. /* PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE() is in general an upper bound
  5797. * for the output size. The PSA specification only guarantees that this
  5798. * function works if output_size >= PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE(...),
  5799. * but it might be nice to allow smaller buffers if the output fits.
  5800. * At the time of writing this comment, with only ECDH implemented,
  5801. * PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE() is exact so the point is moot.
  5802. * If FFDH is implemented, PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE() can easily
  5803. * be exact for it as well. */
  5804. size_t expected_length =
  5805. PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE(slot->attr.type, slot->attr.bits);
  5806. if (output_size < expected_length) {
  5807. status = PSA_ERROR_BUFFER_TOO_SMALL;
  5808. goto exit;
  5809. }
  5810. status = psa_key_agreement_raw_internal(alg, slot,
  5811. peer_key, peer_key_length,
  5812. output, output_size,
  5813. output_length);
  5814. exit:
  5815. if (status != PSA_SUCCESS) {
  5816. /* If an error happens and is not handled properly, the output
  5817. * may be used as a key to protect sensitive data. Arrange for such
  5818. * a key to be random, which is likely to result in decryption or
  5819. * verification errors. This is better than filling the buffer with
  5820. * some constant data such as zeros, which would result in the data
  5821. * being protected with a reproducible, easily knowable key.
  5822. */
  5823. psa_generate_random(output, output_size);
  5824. *output_length = output_size;
  5825. }
  5826. unlock_status = psa_unlock_key_slot(slot);
  5827. return (status == PSA_SUCCESS) ? unlock_status : status;
  5828. }
  5829. /****************************************************************/
  5830. /* Random generation */
  5831. /****************************************************************/
  5832. /** Initialize the PSA random generator.
  5833. */
  5834. static void mbedtls_psa_random_init(mbedtls_psa_random_context_t *rng)
  5835. {
  5836. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  5837. memset(rng, 0, sizeof(*rng));
  5838. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  5839. /* Set default configuration if
  5840. * mbedtls_psa_crypto_configure_entropy_sources() hasn't been called. */
  5841. if (rng->entropy_init == NULL) {
  5842. rng->entropy_init = mbedtls_entropy_init;
  5843. }
  5844. if (rng->entropy_free == NULL) {
  5845. rng->entropy_free = mbedtls_entropy_free;
  5846. }
  5847. rng->entropy_init(&rng->entropy);
  5848. #if defined(MBEDTLS_PSA_INJECT_ENTROPY) && \
  5849. defined(MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES)
  5850. /* The PSA entropy injection feature depends on using NV seed as an entropy
  5851. * source. Add NV seed as an entropy source for PSA entropy injection. */
  5852. mbedtls_entropy_add_source(&rng->entropy,
  5853. mbedtls_nv_seed_poll, NULL,
  5854. MBEDTLS_ENTROPY_BLOCK_SIZE,
  5855. MBEDTLS_ENTROPY_SOURCE_STRONG);
  5856. #endif
  5857. mbedtls_psa_drbg_init(MBEDTLS_PSA_RANDOM_STATE);
  5858. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  5859. }
  5860. /** Deinitialize the PSA random generator.
  5861. */
  5862. static void mbedtls_psa_random_free(mbedtls_psa_random_context_t *rng)
  5863. {
  5864. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  5865. memset(rng, 0, sizeof(*rng));
  5866. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  5867. mbedtls_psa_drbg_free(MBEDTLS_PSA_RANDOM_STATE);
  5868. rng->entropy_free(&rng->entropy);
  5869. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  5870. }
  5871. /** Seed the PSA random generator.
  5872. */
  5873. static psa_status_t mbedtls_psa_random_seed(mbedtls_psa_random_context_t *rng)
  5874. {
  5875. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  5876. /* Do nothing: the external RNG seeds itself. */
  5877. (void) rng;
  5878. return PSA_SUCCESS;
  5879. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  5880. const unsigned char drbg_seed[] = "PSA";
  5881. int ret = mbedtls_psa_drbg_seed(&rng->entropy,
  5882. drbg_seed, sizeof(drbg_seed) - 1);
  5883. return mbedtls_to_psa_error(ret);
  5884. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  5885. }
  5886. psa_status_t psa_generate_random(uint8_t *output,
  5887. size_t output_size)
  5888. {
  5889. GUARD_MODULE_INITIALIZED;
  5890. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  5891. size_t output_length = 0;
  5892. psa_status_t status = mbedtls_psa_external_get_random(&global_data.rng,
  5893. output, output_size,
  5894. &output_length);
  5895. if (status != PSA_SUCCESS) {
  5896. return status;
  5897. }
  5898. /* Breaking up a request into smaller chunks is currently not supported
  5899. * for the external RNG interface. */
  5900. if (output_length != output_size) {
  5901. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  5902. }
  5903. return PSA_SUCCESS;
  5904. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  5905. while (output_size > 0) {
  5906. size_t request_size =
  5907. (output_size > MBEDTLS_PSA_RANDOM_MAX_REQUEST ?
  5908. MBEDTLS_PSA_RANDOM_MAX_REQUEST :
  5909. output_size);
  5910. int ret = mbedtls_psa_get_random(MBEDTLS_PSA_RANDOM_STATE,
  5911. output, request_size);
  5912. if (ret != 0) {
  5913. return mbedtls_to_psa_error(ret);
  5914. }
  5915. output_size -= request_size;
  5916. output += request_size;
  5917. }
  5918. return PSA_SUCCESS;
  5919. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  5920. }
  5921. /* Wrapper function allowing the classic API to use the PSA RNG.
  5922. *
  5923. * `mbedtls_psa_get_random(MBEDTLS_PSA_RANDOM_STATE, ...)` calls
  5924. * `psa_generate_random(...)`. The state parameter is ignored since the
  5925. * PSA API doesn't support passing an explicit state.
  5926. *
  5927. * In the non-external case, psa_generate_random() calls an
  5928. * `mbedtls_xxx_drbg_random` function which has exactly the same signature
  5929. * and semantics as mbedtls_psa_get_random(). As an optimization,
  5930. * instead of doing this back-and-forth between the PSA API and the
  5931. * classic API, psa_crypto_random_impl.h defines `mbedtls_psa_get_random`
  5932. * as a constant function pointer to `mbedtls_xxx_drbg_random`.
  5933. */
  5934. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  5935. int mbedtls_psa_get_random(void *p_rng,
  5936. unsigned char *output,
  5937. size_t output_size)
  5938. {
  5939. /* This function takes a pointer to the RNG state because that's what
  5940. * classic mbedtls functions using an RNG expect. The PSA RNG manages
  5941. * its own state internally and doesn't let the caller access that state.
  5942. * So we just ignore the state parameter, and in practice we'll pass
  5943. * NULL. */
  5944. (void) p_rng;
  5945. psa_status_t status = psa_generate_random(output, output_size);
  5946. if (status == PSA_SUCCESS) {
  5947. return 0;
  5948. } else {
  5949. return MBEDTLS_ERR_ENTROPY_SOURCE_FAILED;
  5950. }
  5951. }
  5952. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  5953. #if defined(MBEDTLS_PSA_INJECT_ENTROPY)
  5954. #include "entropy_poll.h"
  5955. psa_status_t mbedtls_psa_inject_entropy(const uint8_t *seed,
  5956. size_t seed_size)
  5957. {
  5958. if (global_data.initialized) {
  5959. return PSA_ERROR_NOT_PERMITTED;
  5960. }
  5961. if (((seed_size < MBEDTLS_ENTROPY_MIN_PLATFORM) ||
  5962. (seed_size < MBEDTLS_ENTROPY_BLOCK_SIZE)) ||
  5963. (seed_size > MBEDTLS_ENTROPY_MAX_SEED_SIZE)) {
  5964. return PSA_ERROR_INVALID_ARGUMENT;
  5965. }
  5966. return mbedtls_psa_storage_inject_entropy(seed, seed_size);
  5967. }
  5968. #endif /* MBEDTLS_PSA_INJECT_ENTROPY */
  5969. /** Validate the key type and size for key generation
  5970. *
  5971. * \param type The key type
  5972. * \param bits The number of bits of the key
  5973. *
  5974. * \retval #PSA_SUCCESS
  5975. * The key type and size are valid.
  5976. * \retval #PSA_ERROR_INVALID_ARGUMENT
  5977. * The size in bits of the key is not valid.
  5978. * \retval #PSA_ERROR_NOT_SUPPORTED
  5979. * The type and/or the size in bits of the key or the combination of
  5980. * the two is not supported.
  5981. */
  5982. static psa_status_t psa_validate_key_type_and_size_for_key_generation(
  5983. psa_key_type_t type, size_t bits)
  5984. {
  5985. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  5986. if (key_type_is_raw_bytes(type)) {
  5987. status = psa_validate_unstructured_key_bit_size(type, bits);
  5988. if (status != PSA_SUCCESS) {
  5989. return status;
  5990. }
  5991. } else
  5992. #if defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR)
  5993. if (PSA_KEY_TYPE_IS_RSA(type) && PSA_KEY_TYPE_IS_KEY_PAIR(type)) {
  5994. if (bits > PSA_VENDOR_RSA_MAX_KEY_BITS) {
  5995. return PSA_ERROR_NOT_SUPPORTED;
  5996. }
  5997. /* Accept only byte-aligned keys, for the same reasons as
  5998. * in psa_import_rsa_key(). */
  5999. if (bits % 8 != 0) {
  6000. return PSA_ERROR_NOT_SUPPORTED;
  6001. }
  6002. } else
  6003. #endif /* defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR) */
  6004. #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR)
  6005. if (PSA_KEY_TYPE_IS_ECC(type) && PSA_KEY_TYPE_IS_KEY_PAIR(type)) {
  6006. /* To avoid empty block, return successfully here. */
  6007. return PSA_SUCCESS;
  6008. } else
  6009. #endif /* defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR) */
  6010. {
  6011. return PSA_ERROR_NOT_SUPPORTED;
  6012. }
  6013. return PSA_SUCCESS;
  6014. }
  6015. psa_status_t psa_generate_key_internal(
  6016. const psa_key_attributes_t *attributes,
  6017. uint8_t *key_buffer, size_t key_buffer_size, size_t *key_buffer_length)
  6018. {
  6019. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6020. psa_key_type_t type = attributes->core.type;
  6021. if ((attributes->domain_parameters == NULL) &&
  6022. (attributes->domain_parameters_size != 0)) {
  6023. return PSA_ERROR_INVALID_ARGUMENT;
  6024. }
  6025. if (key_type_is_raw_bytes(type)) {
  6026. status = psa_generate_random(key_buffer, key_buffer_size);
  6027. if (status != PSA_SUCCESS) {
  6028. return status;
  6029. }
  6030. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  6031. if (type == PSA_KEY_TYPE_DES) {
  6032. psa_des_set_key_parity(key_buffer, key_buffer_size);
  6033. }
  6034. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  6035. } else
  6036. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) && \
  6037. defined(MBEDTLS_GENPRIME)
  6038. if (type == PSA_KEY_TYPE_RSA_KEY_PAIR) {
  6039. return mbedtls_psa_rsa_generate_key(attributes,
  6040. key_buffer,
  6041. key_buffer_size,
  6042. key_buffer_length);
  6043. } else
  6044. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR)
  6045. * defined(MBEDTLS_GENPRIME) */
  6046. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR)
  6047. if (PSA_KEY_TYPE_IS_ECC(type) && PSA_KEY_TYPE_IS_KEY_PAIR(type)) {
  6048. return mbedtls_psa_ecp_generate_key(attributes,
  6049. key_buffer,
  6050. key_buffer_size,
  6051. key_buffer_length);
  6052. } else
  6053. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) */
  6054. {
  6055. (void) key_buffer_length;
  6056. return PSA_ERROR_NOT_SUPPORTED;
  6057. }
  6058. return PSA_SUCCESS;
  6059. }
  6060. psa_status_t psa_generate_key(const psa_key_attributes_t *attributes,
  6061. mbedtls_svc_key_id_t *key)
  6062. {
  6063. psa_status_t status;
  6064. psa_key_slot_t *slot = NULL;
  6065. psa_se_drv_table_entry_t *driver = NULL;
  6066. size_t key_buffer_size;
  6067. *key = MBEDTLS_SVC_KEY_ID_INIT;
  6068. /* Reject any attempt to create a zero-length key so that we don't
  6069. * risk tripping up later, e.g. on a malloc(0) that returns NULL. */
  6070. if (psa_get_key_bits(attributes) == 0) {
  6071. return PSA_ERROR_INVALID_ARGUMENT;
  6072. }
  6073. /* Reject any attempt to create a public key. */
  6074. if (PSA_KEY_TYPE_IS_PUBLIC_KEY(attributes->core.type)) {
  6075. return PSA_ERROR_INVALID_ARGUMENT;
  6076. }
  6077. status = psa_start_key_creation(PSA_KEY_CREATION_GENERATE, attributes,
  6078. &slot, &driver);
  6079. if (status != PSA_SUCCESS) {
  6080. goto exit;
  6081. }
  6082. /* In the case of a transparent key or an opaque key stored in local
  6083. * storage ( thus not in the case of generating a key in a secure element
  6084. * with storage ( MBEDTLS_PSA_CRYPTO_SE_C ) ),we have to allocate a
  6085. * buffer to hold the generated key material. */
  6086. if (slot->key.data == NULL) {
  6087. if (PSA_KEY_LIFETIME_GET_LOCATION(attributes->core.lifetime) ==
  6088. PSA_KEY_LOCATION_LOCAL_STORAGE) {
  6089. status = psa_validate_key_type_and_size_for_key_generation(
  6090. attributes->core.type, attributes->core.bits);
  6091. if (status != PSA_SUCCESS) {
  6092. goto exit;
  6093. }
  6094. key_buffer_size = PSA_EXPORT_KEY_OUTPUT_SIZE(
  6095. attributes->core.type,
  6096. attributes->core.bits);
  6097. } else {
  6098. status = psa_driver_wrapper_get_key_buffer_size(
  6099. attributes, &key_buffer_size);
  6100. if (status != PSA_SUCCESS) {
  6101. goto exit;
  6102. }
  6103. }
  6104. status = psa_allocate_buffer_to_slot(slot, key_buffer_size);
  6105. if (status != PSA_SUCCESS) {
  6106. goto exit;
  6107. }
  6108. }
  6109. status = psa_driver_wrapper_generate_key(attributes,
  6110. slot->key.data, slot->key.bytes, &slot->key.bytes);
  6111. if (status != PSA_SUCCESS) {
  6112. psa_remove_key_data_from_memory(slot);
  6113. }
  6114. exit:
  6115. if (status == PSA_SUCCESS) {
  6116. status = psa_finish_key_creation(slot, driver, key);
  6117. }
  6118. if (status != PSA_SUCCESS) {
  6119. psa_fail_key_creation(slot, driver);
  6120. }
  6121. return status;
  6122. }
  6123. /****************************************************************/
  6124. /* Module setup */
  6125. /****************************************************************/
  6126. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  6127. psa_status_t mbedtls_psa_crypto_configure_entropy_sources(
  6128. void (* entropy_init)(mbedtls_entropy_context *ctx),
  6129. void (* entropy_free)(mbedtls_entropy_context *ctx))
  6130. {
  6131. if (global_data.rng_state != RNG_NOT_INITIALIZED) {
  6132. return PSA_ERROR_BAD_STATE;
  6133. }
  6134. global_data.rng.entropy_init = entropy_init;
  6135. global_data.rng.entropy_free = entropy_free;
  6136. return PSA_SUCCESS;
  6137. }
  6138. #endif /* !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) */
  6139. void mbedtls_psa_crypto_free(void)
  6140. {
  6141. psa_wipe_all_key_slots();
  6142. if (global_data.rng_state != RNG_NOT_INITIALIZED) {
  6143. mbedtls_psa_random_free(&global_data.rng);
  6144. }
  6145. /* Wipe all remaining data, including configuration.
  6146. * In particular, this sets all state indicator to the value
  6147. * indicating "uninitialized". */
  6148. mbedtls_platform_zeroize(&global_data, sizeof(global_data));
  6149. /* Terminate drivers */
  6150. psa_driver_wrapper_free();
  6151. }
  6152. #if defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS)
  6153. /** Recover a transaction that was interrupted by a power failure.
  6154. *
  6155. * This function is called during initialization, before psa_crypto_init()
  6156. * returns. If this function returns a failure status, the initialization
  6157. * fails.
  6158. */
  6159. static psa_status_t psa_crypto_recover_transaction(
  6160. const psa_crypto_transaction_t *transaction)
  6161. {
  6162. switch (transaction->unknown.type) {
  6163. case PSA_CRYPTO_TRANSACTION_CREATE_KEY:
  6164. case PSA_CRYPTO_TRANSACTION_DESTROY_KEY:
  6165. /* TODO - fall through to the failure case until this
  6166. * is implemented.
  6167. * https://github.com/ARMmbed/mbed-crypto/issues/218
  6168. */
  6169. default:
  6170. /* We found an unsupported transaction in the storage.
  6171. * We don't know what state the storage is in. Give up. */
  6172. return PSA_ERROR_DATA_INVALID;
  6173. }
  6174. }
  6175. #endif /* PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS */
  6176. psa_status_t psa_crypto_init(void)
  6177. {
  6178. psa_status_t status;
  6179. /* Double initialization is explicitly allowed. */
  6180. if (global_data.initialized != 0) {
  6181. return PSA_SUCCESS;
  6182. }
  6183. /* Init drivers */
  6184. status = psa_driver_wrapper_init();
  6185. if (status != PSA_SUCCESS) {
  6186. goto exit;
  6187. }
  6188. global_data.drivers_initialized = 1;
  6189. /* Initialize and seed the random generator. */
  6190. mbedtls_psa_random_init(&global_data.rng);
  6191. global_data.rng_state = RNG_INITIALIZED;
  6192. status = mbedtls_psa_random_seed(&global_data.rng);
  6193. if (status != PSA_SUCCESS) {
  6194. goto exit;
  6195. }
  6196. global_data.rng_state = RNG_SEEDED;
  6197. status = psa_initialize_key_slots();
  6198. if (status != PSA_SUCCESS) {
  6199. goto exit;
  6200. }
  6201. #if defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS)
  6202. status = psa_crypto_load_transaction();
  6203. if (status == PSA_SUCCESS) {
  6204. status = psa_crypto_recover_transaction(&psa_crypto_transaction);
  6205. if (status != PSA_SUCCESS) {
  6206. goto exit;
  6207. }
  6208. status = psa_crypto_stop_transaction();
  6209. } else if (status == PSA_ERROR_DOES_NOT_EXIST) {
  6210. /* There's no transaction to complete. It's all good. */
  6211. status = PSA_SUCCESS;
  6212. }
  6213. #endif /* PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS */
  6214. /* All done. */
  6215. global_data.initialized = 1;
  6216. exit:
  6217. if (status != PSA_SUCCESS) {
  6218. mbedtls_psa_crypto_free();
  6219. }
  6220. return status;
  6221. }
  6222. psa_status_t psa_crypto_driver_pake_get_password_len(
  6223. const psa_crypto_driver_pake_inputs_t *inputs,
  6224. size_t *password_len)
  6225. {
  6226. if (inputs->password_len == 0) {
  6227. return PSA_ERROR_BAD_STATE;
  6228. }
  6229. *password_len = inputs->password_len;
  6230. return PSA_SUCCESS;
  6231. }
  6232. psa_status_t psa_crypto_driver_pake_get_password(
  6233. const psa_crypto_driver_pake_inputs_t *inputs,
  6234. uint8_t *buffer, size_t buffer_size, size_t *buffer_length)
  6235. {
  6236. if (inputs->password_len == 0) {
  6237. return PSA_ERROR_BAD_STATE;
  6238. }
  6239. if (buffer_size < inputs->password_len) {
  6240. return PSA_ERROR_BUFFER_TOO_SMALL;
  6241. }
  6242. memcpy(buffer, inputs->password, inputs->password_len);
  6243. *buffer_length = inputs->password_len;
  6244. return PSA_SUCCESS;
  6245. }
  6246. psa_status_t psa_crypto_driver_pake_get_role(
  6247. const psa_crypto_driver_pake_inputs_t *inputs,
  6248. psa_pake_role_t *role)
  6249. {
  6250. if (inputs->role == PSA_PAKE_ROLE_NONE) {
  6251. return PSA_ERROR_BAD_STATE;
  6252. }
  6253. *role = inputs->role;
  6254. return PSA_SUCCESS;
  6255. }
  6256. psa_status_t psa_crypto_driver_pake_get_user_len(
  6257. const psa_crypto_driver_pake_inputs_t *inputs,
  6258. size_t *user_len)
  6259. {
  6260. if (inputs->user_len == 0) {
  6261. return PSA_ERROR_BAD_STATE;
  6262. }
  6263. *user_len = inputs->user_len;
  6264. return PSA_SUCCESS;
  6265. }
  6266. psa_status_t psa_crypto_driver_pake_get_user(
  6267. const psa_crypto_driver_pake_inputs_t *inputs,
  6268. uint8_t *user_id, size_t user_id_size, size_t *user_id_len)
  6269. {
  6270. if (inputs->user_len == 0) {
  6271. return PSA_ERROR_BAD_STATE;
  6272. }
  6273. if (user_id_size < inputs->user_len) {
  6274. return PSA_ERROR_BUFFER_TOO_SMALL;
  6275. }
  6276. memcpy(user_id, inputs->user, inputs->user_len);
  6277. *user_id_len = inputs->user_len;
  6278. return PSA_SUCCESS;
  6279. }
  6280. psa_status_t psa_crypto_driver_pake_get_peer_len(
  6281. const psa_crypto_driver_pake_inputs_t *inputs,
  6282. size_t *peer_len)
  6283. {
  6284. if (inputs->peer_len == 0) {
  6285. return PSA_ERROR_BAD_STATE;
  6286. }
  6287. *peer_len = inputs->peer_len;
  6288. return PSA_SUCCESS;
  6289. }
  6290. psa_status_t psa_crypto_driver_pake_get_peer(
  6291. const psa_crypto_driver_pake_inputs_t *inputs,
  6292. uint8_t *peer_id, size_t peer_id_size, size_t *peer_id_length)
  6293. {
  6294. if (inputs->peer_len == 0) {
  6295. return PSA_ERROR_BAD_STATE;
  6296. }
  6297. if (peer_id_size < inputs->peer_len) {
  6298. return PSA_ERROR_BUFFER_TOO_SMALL;
  6299. }
  6300. memcpy(peer_id, inputs->peer, inputs->peer_len);
  6301. *peer_id_length = inputs->peer_len;
  6302. return PSA_SUCCESS;
  6303. }
  6304. psa_status_t psa_crypto_driver_pake_get_cipher_suite(
  6305. const psa_crypto_driver_pake_inputs_t *inputs,
  6306. psa_pake_cipher_suite_t *cipher_suite)
  6307. {
  6308. if (inputs->cipher_suite.algorithm == PSA_ALG_NONE) {
  6309. return PSA_ERROR_BAD_STATE;
  6310. }
  6311. *cipher_suite = inputs->cipher_suite;
  6312. return PSA_SUCCESS;
  6313. }
  6314. psa_status_t psa_pake_setup(
  6315. psa_pake_operation_t *operation,
  6316. const psa_pake_cipher_suite_t *cipher_suite)
  6317. {
  6318. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6319. if (operation->stage != PSA_PAKE_OPERATION_STAGE_SETUP) {
  6320. status = PSA_ERROR_BAD_STATE;
  6321. goto exit;
  6322. }
  6323. if (PSA_ALG_IS_PAKE(cipher_suite->algorithm) == 0 ||
  6324. PSA_ALG_IS_HASH(cipher_suite->hash) == 0) {
  6325. status = PSA_ERROR_INVALID_ARGUMENT;
  6326. goto exit;
  6327. }
  6328. memset(&operation->data.inputs, 0, sizeof(operation->data.inputs));
  6329. operation->alg = cipher_suite->algorithm;
  6330. operation->data.inputs.cipher_suite = *cipher_suite;
  6331. #if defined(PSA_WANT_ALG_JPAKE)
  6332. if (operation->alg == PSA_ALG_JPAKE) {
  6333. psa_jpake_computation_stage_t *computation_stage =
  6334. &operation->computation_stage.jpake;
  6335. computation_stage->state = PSA_PAKE_STATE_SETUP;
  6336. computation_stage->sequence = PSA_PAKE_SEQ_INVALID;
  6337. computation_stage->input_step = PSA_PAKE_STEP_X1_X2;
  6338. computation_stage->output_step = PSA_PAKE_STEP_X1_X2;
  6339. } else
  6340. #endif /* PSA_WANT_ALG_JPAKE */
  6341. {
  6342. status = PSA_ERROR_NOT_SUPPORTED;
  6343. goto exit;
  6344. }
  6345. operation->stage = PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS;
  6346. return PSA_SUCCESS;
  6347. exit:
  6348. psa_pake_abort(operation);
  6349. return status;
  6350. }
  6351. psa_status_t psa_pake_set_password_key(
  6352. psa_pake_operation_t *operation,
  6353. mbedtls_svc_key_id_t password)
  6354. {
  6355. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6356. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  6357. psa_key_slot_t *slot = NULL;
  6358. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  6359. status = PSA_ERROR_BAD_STATE;
  6360. goto exit;
  6361. }
  6362. status = psa_get_and_lock_key_slot_with_policy(password, &slot,
  6363. PSA_KEY_USAGE_DERIVE,
  6364. operation->alg);
  6365. if (status != PSA_SUCCESS) {
  6366. goto exit;
  6367. }
  6368. psa_key_attributes_t attributes = {
  6369. .core = slot->attr
  6370. };
  6371. psa_key_type_t type = psa_get_key_type(&attributes);
  6372. if (type != PSA_KEY_TYPE_PASSWORD &&
  6373. type != PSA_KEY_TYPE_PASSWORD_HASH) {
  6374. status = PSA_ERROR_INVALID_ARGUMENT;
  6375. goto exit;
  6376. }
  6377. operation->data.inputs.password = mbedtls_calloc(1, slot->key.bytes);
  6378. if (operation->data.inputs.password == NULL) {
  6379. status = PSA_ERROR_INSUFFICIENT_MEMORY;
  6380. goto exit;
  6381. }
  6382. memcpy(operation->data.inputs.password, slot->key.data, slot->key.bytes);
  6383. operation->data.inputs.password_len = slot->key.bytes;
  6384. operation->data.inputs.attributes = attributes;
  6385. exit:
  6386. if (status != PSA_SUCCESS) {
  6387. psa_pake_abort(operation);
  6388. }
  6389. unlock_status = psa_unlock_key_slot(slot);
  6390. return (status == PSA_SUCCESS) ? unlock_status : status;
  6391. }
  6392. psa_status_t psa_pake_set_user(
  6393. psa_pake_operation_t *operation,
  6394. const uint8_t *user_id,
  6395. size_t user_id_len)
  6396. {
  6397. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6398. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  6399. status = PSA_ERROR_BAD_STATE;
  6400. goto exit;
  6401. }
  6402. if (user_id_len == 0) {
  6403. status = PSA_ERROR_INVALID_ARGUMENT;
  6404. goto exit;
  6405. }
  6406. if (operation->data.inputs.user_len != 0) {
  6407. status = PSA_ERROR_BAD_STATE;
  6408. goto exit;
  6409. }
  6410. /* Allow only "client" or "server" values (temporary restriction). */
  6411. if ((user_id_len != sizeof(jpake_server_id) ||
  6412. memcmp(user_id, jpake_server_id, user_id_len) != 0) &&
  6413. (user_id_len != sizeof(jpake_client_id) ||
  6414. memcmp(user_id, jpake_client_id, user_id_len) != 0)) {
  6415. status = PSA_ERROR_NOT_SUPPORTED;
  6416. goto exit;
  6417. }
  6418. operation->data.inputs.user = mbedtls_calloc(1, user_id_len);
  6419. if (operation->data.inputs.user == NULL) {
  6420. status = PSA_ERROR_INSUFFICIENT_MEMORY;
  6421. goto exit;
  6422. }
  6423. memcpy(operation->data.inputs.user, user_id, user_id_len);
  6424. operation->data.inputs.user_len = user_id_len;
  6425. return PSA_SUCCESS;
  6426. exit:
  6427. psa_pake_abort(operation);
  6428. return status;
  6429. }
  6430. psa_status_t psa_pake_set_peer(
  6431. psa_pake_operation_t *operation,
  6432. const uint8_t *peer_id,
  6433. size_t peer_id_len)
  6434. {
  6435. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6436. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  6437. status = PSA_ERROR_BAD_STATE;
  6438. goto exit;
  6439. }
  6440. if (peer_id_len == 0) {
  6441. status = PSA_ERROR_INVALID_ARGUMENT;
  6442. goto exit;
  6443. }
  6444. if (operation->data.inputs.peer_len != 0) {
  6445. status = PSA_ERROR_BAD_STATE;
  6446. goto exit;
  6447. }
  6448. /* Allow only "client" or "server" values (temporary restriction). */
  6449. if ((peer_id_len != sizeof(jpake_server_id) ||
  6450. memcmp(peer_id, jpake_server_id, peer_id_len) != 0) &&
  6451. (peer_id_len != sizeof(jpake_client_id) ||
  6452. memcmp(peer_id, jpake_client_id, peer_id_len) != 0)) {
  6453. status = PSA_ERROR_NOT_SUPPORTED;
  6454. goto exit;
  6455. }
  6456. operation->data.inputs.peer = mbedtls_calloc(1, peer_id_len);
  6457. if (operation->data.inputs.peer == NULL) {
  6458. status = PSA_ERROR_INSUFFICIENT_MEMORY;
  6459. goto exit;
  6460. }
  6461. memcpy(operation->data.inputs.peer, peer_id, peer_id_len);
  6462. operation->data.inputs.peer_len = peer_id_len;
  6463. return PSA_SUCCESS;
  6464. exit:
  6465. psa_pake_abort(operation);
  6466. return status;
  6467. }
  6468. psa_status_t psa_pake_set_role(
  6469. psa_pake_operation_t *operation,
  6470. psa_pake_role_t role)
  6471. {
  6472. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6473. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  6474. status = PSA_ERROR_BAD_STATE;
  6475. goto exit;
  6476. }
  6477. switch (operation->alg) {
  6478. #if defined(PSA_WANT_ALG_JPAKE)
  6479. case PSA_ALG_JPAKE:
  6480. if (role == PSA_PAKE_ROLE_NONE) {
  6481. return PSA_SUCCESS;
  6482. }
  6483. status = PSA_ERROR_INVALID_ARGUMENT;
  6484. break;
  6485. #endif
  6486. default:
  6487. (void) role;
  6488. status = PSA_ERROR_NOT_SUPPORTED;
  6489. goto exit;
  6490. }
  6491. exit:
  6492. psa_pake_abort(operation);
  6493. return status;
  6494. }
  6495. /* Auxiliary function to convert core computation stage(step, sequence, state) to single driver step. */
  6496. #if defined(PSA_WANT_ALG_JPAKE)
  6497. static psa_crypto_driver_pake_step_t convert_jpake_computation_stage_to_driver_step(
  6498. psa_jpake_computation_stage_t *stage)
  6499. {
  6500. switch (stage->state) {
  6501. case PSA_PAKE_OUTPUT_X1_X2:
  6502. case PSA_PAKE_INPUT_X1_X2:
  6503. switch (stage->sequence) {
  6504. case PSA_PAKE_X1_STEP_KEY_SHARE:
  6505. return PSA_JPAKE_X1_STEP_KEY_SHARE;
  6506. case PSA_PAKE_X1_STEP_ZK_PUBLIC:
  6507. return PSA_JPAKE_X1_STEP_ZK_PUBLIC;
  6508. case PSA_PAKE_X1_STEP_ZK_PROOF:
  6509. return PSA_JPAKE_X1_STEP_ZK_PROOF;
  6510. case PSA_PAKE_X2_STEP_KEY_SHARE:
  6511. return PSA_JPAKE_X2_STEP_KEY_SHARE;
  6512. case PSA_PAKE_X2_STEP_ZK_PUBLIC:
  6513. return PSA_JPAKE_X2_STEP_ZK_PUBLIC;
  6514. case PSA_PAKE_X2_STEP_ZK_PROOF:
  6515. return PSA_JPAKE_X2_STEP_ZK_PROOF;
  6516. default:
  6517. return PSA_JPAKE_STEP_INVALID;
  6518. }
  6519. break;
  6520. case PSA_PAKE_OUTPUT_X2S:
  6521. switch (stage->sequence) {
  6522. case PSA_PAKE_X1_STEP_KEY_SHARE:
  6523. return PSA_JPAKE_X2S_STEP_KEY_SHARE;
  6524. case PSA_PAKE_X1_STEP_ZK_PUBLIC:
  6525. return PSA_JPAKE_X2S_STEP_ZK_PUBLIC;
  6526. case PSA_PAKE_X1_STEP_ZK_PROOF:
  6527. return PSA_JPAKE_X2S_STEP_ZK_PROOF;
  6528. default:
  6529. return PSA_JPAKE_STEP_INVALID;
  6530. }
  6531. break;
  6532. case PSA_PAKE_INPUT_X4S:
  6533. switch (stage->sequence) {
  6534. case PSA_PAKE_X1_STEP_KEY_SHARE:
  6535. return PSA_JPAKE_X4S_STEP_KEY_SHARE;
  6536. case PSA_PAKE_X1_STEP_ZK_PUBLIC:
  6537. return PSA_JPAKE_X4S_STEP_ZK_PUBLIC;
  6538. case PSA_PAKE_X1_STEP_ZK_PROOF:
  6539. return PSA_JPAKE_X4S_STEP_ZK_PROOF;
  6540. default:
  6541. return PSA_JPAKE_STEP_INVALID;
  6542. }
  6543. break;
  6544. default:
  6545. return PSA_JPAKE_STEP_INVALID;
  6546. }
  6547. return PSA_JPAKE_STEP_INVALID;
  6548. }
  6549. #endif /* PSA_WANT_ALG_JPAKE */
  6550. static psa_status_t psa_pake_complete_inputs(
  6551. psa_pake_operation_t *operation)
  6552. {
  6553. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6554. /* Create copy of the inputs on stack as inputs share memory
  6555. with the driver context which will be setup by the driver. */
  6556. psa_crypto_driver_pake_inputs_t inputs = operation->data.inputs;
  6557. if (inputs.password_len == 0) {
  6558. return PSA_ERROR_BAD_STATE;
  6559. }
  6560. if (operation->alg == PSA_ALG_JPAKE) {
  6561. if (inputs.user_len == 0 || inputs.peer_len == 0) {
  6562. return PSA_ERROR_BAD_STATE;
  6563. }
  6564. if (memcmp(inputs.user, jpake_client_id, inputs.user_len) == 0 &&
  6565. memcmp(inputs.peer, jpake_server_id, inputs.peer_len) == 0) {
  6566. inputs.role = PSA_PAKE_ROLE_CLIENT;
  6567. } else
  6568. if (memcmp(inputs.user, jpake_server_id, inputs.user_len) == 0 &&
  6569. memcmp(inputs.peer, jpake_client_id, inputs.peer_len) == 0) {
  6570. inputs.role = PSA_PAKE_ROLE_SERVER;
  6571. }
  6572. if (inputs.role != PSA_PAKE_ROLE_CLIENT &&
  6573. inputs.role != PSA_PAKE_ROLE_SERVER) {
  6574. return PSA_ERROR_NOT_SUPPORTED;
  6575. }
  6576. }
  6577. /* Clear driver context */
  6578. mbedtls_platform_zeroize(&operation->data, sizeof(operation->data));
  6579. status = psa_driver_wrapper_pake_setup(operation, &inputs);
  6580. /* Driver is responsible for creating its own copy of the password. */
  6581. mbedtls_platform_zeroize(inputs.password, inputs.password_len);
  6582. mbedtls_free(inputs.password);
  6583. /* User and peer are translated to role. */
  6584. mbedtls_free(inputs.user);
  6585. mbedtls_free(inputs.peer);
  6586. if (status == PSA_SUCCESS) {
  6587. #if defined(PSA_WANT_ALG_JPAKE)
  6588. if (operation->alg == PSA_ALG_JPAKE) {
  6589. operation->stage = PSA_PAKE_OPERATION_STAGE_COMPUTATION;
  6590. psa_jpake_computation_stage_t *computation_stage =
  6591. &operation->computation_stage.jpake;
  6592. computation_stage->state = PSA_PAKE_STATE_READY;
  6593. computation_stage->sequence = PSA_PAKE_SEQ_INVALID;
  6594. computation_stage->input_step = PSA_PAKE_STEP_X1_X2;
  6595. computation_stage->output_step = PSA_PAKE_STEP_X1_X2;
  6596. } else
  6597. #endif /* PSA_WANT_ALG_JPAKE */
  6598. {
  6599. status = PSA_ERROR_NOT_SUPPORTED;
  6600. }
  6601. }
  6602. return status;
  6603. }
  6604. #if defined(PSA_WANT_ALG_JPAKE)
  6605. static psa_status_t psa_jpake_output_prologue(
  6606. psa_pake_operation_t *operation,
  6607. psa_pake_step_t step)
  6608. {
  6609. if (step != PSA_PAKE_STEP_KEY_SHARE &&
  6610. step != PSA_PAKE_STEP_ZK_PUBLIC &&
  6611. step != PSA_PAKE_STEP_ZK_PROOF) {
  6612. return PSA_ERROR_INVALID_ARGUMENT;
  6613. }
  6614. psa_jpake_computation_stage_t *computation_stage =
  6615. &operation->computation_stage.jpake;
  6616. if (computation_stage->state == PSA_PAKE_STATE_INVALID) {
  6617. return PSA_ERROR_BAD_STATE;
  6618. }
  6619. if (computation_stage->state != PSA_PAKE_STATE_READY &&
  6620. computation_stage->state != PSA_PAKE_OUTPUT_X1_X2 &&
  6621. computation_stage->state != PSA_PAKE_OUTPUT_X2S) {
  6622. return PSA_ERROR_BAD_STATE;
  6623. }
  6624. if (computation_stage->state == PSA_PAKE_STATE_READY) {
  6625. if (step != PSA_PAKE_STEP_KEY_SHARE) {
  6626. return PSA_ERROR_BAD_STATE;
  6627. }
  6628. switch (computation_stage->output_step) {
  6629. case PSA_PAKE_STEP_X1_X2:
  6630. computation_stage->state = PSA_PAKE_OUTPUT_X1_X2;
  6631. break;
  6632. case PSA_PAKE_STEP_X2S:
  6633. computation_stage->state = PSA_PAKE_OUTPUT_X2S;
  6634. break;
  6635. default:
  6636. return PSA_ERROR_BAD_STATE;
  6637. }
  6638. computation_stage->sequence = PSA_PAKE_X1_STEP_KEY_SHARE;
  6639. }
  6640. /* Check if step matches current sequence */
  6641. switch (computation_stage->sequence) {
  6642. case PSA_PAKE_X1_STEP_KEY_SHARE:
  6643. case PSA_PAKE_X2_STEP_KEY_SHARE:
  6644. if (step != PSA_PAKE_STEP_KEY_SHARE) {
  6645. return PSA_ERROR_BAD_STATE;
  6646. }
  6647. break;
  6648. case PSA_PAKE_X1_STEP_ZK_PUBLIC:
  6649. case PSA_PAKE_X2_STEP_ZK_PUBLIC:
  6650. if (step != PSA_PAKE_STEP_ZK_PUBLIC) {
  6651. return PSA_ERROR_BAD_STATE;
  6652. }
  6653. break;
  6654. case PSA_PAKE_X1_STEP_ZK_PROOF:
  6655. case PSA_PAKE_X2_STEP_ZK_PROOF:
  6656. if (step != PSA_PAKE_STEP_ZK_PROOF) {
  6657. return PSA_ERROR_BAD_STATE;
  6658. }
  6659. break;
  6660. default:
  6661. return PSA_ERROR_BAD_STATE;
  6662. }
  6663. return PSA_SUCCESS;
  6664. }
  6665. static psa_status_t psa_jpake_output_epilogue(
  6666. psa_pake_operation_t *operation)
  6667. {
  6668. psa_jpake_computation_stage_t *computation_stage =
  6669. &operation->computation_stage.jpake;
  6670. if ((computation_stage->state == PSA_PAKE_OUTPUT_X1_X2 &&
  6671. computation_stage->sequence == PSA_PAKE_X2_STEP_ZK_PROOF) ||
  6672. (computation_stage->state == PSA_PAKE_OUTPUT_X2S &&
  6673. computation_stage->sequence == PSA_PAKE_X1_STEP_ZK_PROOF)) {
  6674. computation_stage->state = PSA_PAKE_STATE_READY;
  6675. computation_stage->output_step++;
  6676. computation_stage->sequence = PSA_PAKE_SEQ_INVALID;
  6677. } else {
  6678. computation_stage->sequence++;
  6679. }
  6680. return PSA_SUCCESS;
  6681. }
  6682. #endif /* PSA_WANT_ALG_JPAKE */
  6683. psa_status_t psa_pake_output(
  6684. psa_pake_operation_t *operation,
  6685. psa_pake_step_t step,
  6686. uint8_t *output,
  6687. size_t output_size,
  6688. size_t *output_length)
  6689. {
  6690. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6691. psa_crypto_driver_pake_step_t driver_step = PSA_JPAKE_STEP_INVALID;
  6692. *output_length = 0;
  6693. if (operation->stage == PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  6694. status = psa_pake_complete_inputs(operation);
  6695. if (status != PSA_SUCCESS) {
  6696. goto exit;
  6697. }
  6698. }
  6699. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COMPUTATION) {
  6700. status = PSA_ERROR_BAD_STATE;
  6701. goto exit;
  6702. }
  6703. if (output_size == 0) {
  6704. status = PSA_ERROR_INVALID_ARGUMENT;
  6705. goto exit;
  6706. }
  6707. switch (operation->alg) {
  6708. #if defined(PSA_WANT_ALG_JPAKE)
  6709. case PSA_ALG_JPAKE:
  6710. status = psa_jpake_output_prologue(operation, step);
  6711. if (status != PSA_SUCCESS) {
  6712. goto exit;
  6713. }
  6714. driver_step = convert_jpake_computation_stage_to_driver_step(
  6715. &operation->computation_stage.jpake);
  6716. break;
  6717. #endif /* PSA_WANT_ALG_JPAKE */
  6718. default:
  6719. (void) step;
  6720. status = PSA_ERROR_NOT_SUPPORTED;
  6721. goto exit;
  6722. }
  6723. status = psa_driver_wrapper_pake_output(operation, driver_step,
  6724. output, output_size, output_length);
  6725. if (status != PSA_SUCCESS) {
  6726. goto exit;
  6727. }
  6728. switch (operation->alg) {
  6729. #if defined(PSA_WANT_ALG_JPAKE)
  6730. case PSA_ALG_JPAKE:
  6731. status = psa_jpake_output_epilogue(operation);
  6732. if (status != PSA_SUCCESS) {
  6733. goto exit;
  6734. }
  6735. break;
  6736. #endif /* PSA_WANT_ALG_JPAKE */
  6737. default:
  6738. status = PSA_ERROR_NOT_SUPPORTED;
  6739. goto exit;
  6740. }
  6741. return PSA_SUCCESS;
  6742. exit:
  6743. psa_pake_abort(operation);
  6744. return status;
  6745. }
  6746. #if defined(PSA_WANT_ALG_JPAKE)
  6747. static psa_status_t psa_jpake_input_prologue(
  6748. psa_pake_operation_t *operation,
  6749. psa_pake_step_t step)
  6750. {
  6751. if (step != PSA_PAKE_STEP_KEY_SHARE &&
  6752. step != PSA_PAKE_STEP_ZK_PUBLIC &&
  6753. step != PSA_PAKE_STEP_ZK_PROOF) {
  6754. return PSA_ERROR_INVALID_ARGUMENT;
  6755. }
  6756. psa_jpake_computation_stage_t *computation_stage =
  6757. &operation->computation_stage.jpake;
  6758. if (computation_stage->state == PSA_PAKE_STATE_INVALID) {
  6759. return PSA_ERROR_BAD_STATE;
  6760. }
  6761. if (computation_stage->state != PSA_PAKE_STATE_READY &&
  6762. computation_stage->state != PSA_PAKE_INPUT_X1_X2 &&
  6763. computation_stage->state != PSA_PAKE_INPUT_X4S) {
  6764. return PSA_ERROR_BAD_STATE;
  6765. }
  6766. if (computation_stage->state == PSA_PAKE_STATE_READY) {
  6767. if (step != PSA_PAKE_STEP_KEY_SHARE) {
  6768. return PSA_ERROR_BAD_STATE;
  6769. }
  6770. switch (computation_stage->input_step) {
  6771. case PSA_PAKE_STEP_X1_X2:
  6772. computation_stage->state = PSA_PAKE_INPUT_X1_X2;
  6773. break;
  6774. case PSA_PAKE_STEP_X2S:
  6775. computation_stage->state = PSA_PAKE_INPUT_X4S;
  6776. break;
  6777. default:
  6778. return PSA_ERROR_BAD_STATE;
  6779. }
  6780. computation_stage->sequence = PSA_PAKE_X1_STEP_KEY_SHARE;
  6781. }
  6782. /* Check if step matches current sequence */
  6783. switch (computation_stage->sequence) {
  6784. case PSA_PAKE_X1_STEP_KEY_SHARE:
  6785. case PSA_PAKE_X2_STEP_KEY_SHARE:
  6786. if (step != PSA_PAKE_STEP_KEY_SHARE) {
  6787. return PSA_ERROR_BAD_STATE;
  6788. }
  6789. break;
  6790. case PSA_PAKE_X1_STEP_ZK_PUBLIC:
  6791. case PSA_PAKE_X2_STEP_ZK_PUBLIC:
  6792. if (step != PSA_PAKE_STEP_ZK_PUBLIC) {
  6793. return PSA_ERROR_BAD_STATE;
  6794. }
  6795. break;
  6796. case PSA_PAKE_X1_STEP_ZK_PROOF:
  6797. case PSA_PAKE_X2_STEP_ZK_PROOF:
  6798. if (step != PSA_PAKE_STEP_ZK_PROOF) {
  6799. return PSA_ERROR_BAD_STATE;
  6800. }
  6801. break;
  6802. default:
  6803. return PSA_ERROR_BAD_STATE;
  6804. }
  6805. return PSA_SUCCESS;
  6806. }
  6807. static psa_status_t psa_jpake_input_epilogue(
  6808. psa_pake_operation_t *operation)
  6809. {
  6810. psa_jpake_computation_stage_t *computation_stage =
  6811. &operation->computation_stage.jpake;
  6812. if ((computation_stage->state == PSA_PAKE_INPUT_X1_X2 &&
  6813. computation_stage->sequence == PSA_PAKE_X2_STEP_ZK_PROOF) ||
  6814. (computation_stage->state == PSA_PAKE_INPUT_X4S &&
  6815. computation_stage->sequence == PSA_PAKE_X1_STEP_ZK_PROOF)) {
  6816. computation_stage->state = PSA_PAKE_STATE_READY;
  6817. computation_stage->input_step++;
  6818. computation_stage->sequence = PSA_PAKE_SEQ_INVALID;
  6819. } else {
  6820. computation_stage->sequence++;
  6821. }
  6822. return PSA_SUCCESS;
  6823. }
  6824. #endif /* PSA_WANT_ALG_JPAKE */
  6825. psa_status_t psa_pake_input(
  6826. psa_pake_operation_t *operation,
  6827. psa_pake_step_t step,
  6828. const uint8_t *input,
  6829. size_t input_length)
  6830. {
  6831. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6832. psa_crypto_driver_pake_step_t driver_step = PSA_JPAKE_STEP_INVALID;
  6833. if (operation->stage == PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  6834. status = psa_pake_complete_inputs(operation);
  6835. if (status != PSA_SUCCESS) {
  6836. goto exit;
  6837. }
  6838. }
  6839. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COMPUTATION) {
  6840. status = PSA_ERROR_BAD_STATE;
  6841. goto exit;
  6842. }
  6843. if (input_length == 0 || input_length > PSA_PAKE_INPUT_MAX_SIZE) {
  6844. status = PSA_ERROR_INVALID_ARGUMENT;
  6845. goto exit;
  6846. }
  6847. switch (operation->alg) {
  6848. #if defined(PSA_WANT_ALG_JPAKE)
  6849. case PSA_ALG_JPAKE:
  6850. status = psa_jpake_input_prologue(operation, step);
  6851. if (status != PSA_SUCCESS) {
  6852. goto exit;
  6853. }
  6854. driver_step = convert_jpake_computation_stage_to_driver_step(
  6855. &operation->computation_stage.jpake);
  6856. break;
  6857. #endif /* PSA_WANT_ALG_JPAKE */
  6858. default:
  6859. (void) step;
  6860. status = PSA_ERROR_NOT_SUPPORTED;
  6861. goto exit;
  6862. }
  6863. status = psa_driver_wrapper_pake_input(operation, driver_step,
  6864. input, input_length);
  6865. if (status != PSA_SUCCESS) {
  6866. goto exit;
  6867. }
  6868. switch (operation->alg) {
  6869. #if defined(PSA_WANT_ALG_JPAKE)
  6870. case PSA_ALG_JPAKE:
  6871. status = psa_jpake_input_epilogue(operation);
  6872. if (status != PSA_SUCCESS) {
  6873. goto exit;
  6874. }
  6875. break;
  6876. #endif /* PSA_WANT_ALG_JPAKE */
  6877. default:
  6878. status = PSA_ERROR_NOT_SUPPORTED;
  6879. goto exit;
  6880. }
  6881. return PSA_SUCCESS;
  6882. exit:
  6883. psa_pake_abort(operation);
  6884. return status;
  6885. }
  6886. psa_status_t psa_pake_get_implicit_key(
  6887. psa_pake_operation_t *operation,
  6888. psa_key_derivation_operation_t *output)
  6889. {
  6890. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6891. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  6892. uint8_t shared_key[MBEDTLS_PSA_JPAKE_BUFFER_SIZE];
  6893. size_t shared_key_len = 0;
  6894. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COMPUTATION) {
  6895. status = PSA_ERROR_BAD_STATE;
  6896. goto exit;
  6897. }
  6898. #if defined(PSA_WANT_ALG_JPAKE)
  6899. if (operation->alg == PSA_ALG_JPAKE) {
  6900. psa_jpake_computation_stage_t *computation_stage =
  6901. &operation->computation_stage.jpake;
  6902. if (computation_stage->input_step != PSA_PAKE_STEP_DERIVE ||
  6903. computation_stage->output_step != PSA_PAKE_STEP_DERIVE) {
  6904. status = PSA_ERROR_BAD_STATE;
  6905. goto exit;
  6906. }
  6907. } else
  6908. #endif /* PSA_WANT_ALG_JPAKE */
  6909. {
  6910. status = PSA_ERROR_NOT_SUPPORTED;
  6911. goto exit;
  6912. }
  6913. status = psa_driver_wrapper_pake_get_implicit_key(operation,
  6914. shared_key,
  6915. sizeof(shared_key),
  6916. &shared_key_len);
  6917. if (status != PSA_SUCCESS) {
  6918. goto exit;
  6919. }
  6920. status = psa_key_derivation_input_bytes(output,
  6921. PSA_KEY_DERIVATION_INPUT_SECRET,
  6922. shared_key,
  6923. shared_key_len);
  6924. mbedtls_platform_zeroize(shared_key, sizeof(shared_key));
  6925. exit:
  6926. abort_status = psa_pake_abort(operation);
  6927. return status == PSA_SUCCESS ? abort_status : status;
  6928. }
  6929. psa_status_t psa_pake_abort(
  6930. psa_pake_operation_t *operation)
  6931. {
  6932. psa_status_t status = PSA_SUCCESS;
  6933. if (operation->stage == PSA_PAKE_OPERATION_STAGE_COMPUTATION) {
  6934. status = psa_driver_wrapper_pake_abort(operation);
  6935. }
  6936. if (operation->stage == PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  6937. if (operation->data.inputs.password != NULL) {
  6938. mbedtls_platform_zeroize(operation->data.inputs.password,
  6939. operation->data.inputs.password_len);
  6940. mbedtls_free(operation->data.inputs.password);
  6941. }
  6942. if (operation->data.inputs.user != NULL) {
  6943. mbedtls_free(operation->data.inputs.user);
  6944. }
  6945. if (operation->data.inputs.peer != NULL) {
  6946. mbedtls_free(operation->data.inputs.peer);
  6947. }
  6948. }
  6949. memset(operation, 0, sizeof(psa_pake_operation_t));
  6950. return status;
  6951. }
  6952. #endif /* MBEDTLS_PSA_CRYPTO_C */