psa_crypto.c 203 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892
  1. /*
  2. * PSA crypto layer on top of Mbed TLS crypto
  3. */
  4. /*
  5. * Copyright The Mbed TLS Contributors
  6. * SPDX-License-Identifier: Apache-2.0
  7. *
  8. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  9. * not use this file except in compliance with the License.
  10. * You may obtain a copy of the License at
  11. *
  12. * http://www.apache.org/licenses/LICENSE-2.0
  13. *
  14. * Unless required by applicable law or agreed to in writing, software
  15. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  16. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  17. * See the License for the specific language governing permissions and
  18. * limitations under the License.
  19. */
  20. #include "common.h"
  21. #if defined(MBEDTLS_PSA_CRYPTO_C)
  22. #if defined(MBEDTLS_PSA_CRYPTO_CONFIG)
  23. #include "check_crypto_config.h"
  24. #endif
  25. #include "psa/crypto.h"
  26. #include "psa_crypto_cipher.h"
  27. #include "psa_crypto_core.h"
  28. #include "psa_crypto_invasive.h"
  29. #include "psa_crypto_driver_wrappers.h"
  30. #include "psa_crypto_ecp.h"
  31. #include "psa_crypto_hash.h"
  32. #include "psa_crypto_mac.h"
  33. #include "psa_crypto_rsa.h"
  34. #include "psa_crypto_ecp.h"
  35. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  36. #include "psa_crypto_se.h"
  37. #endif
  38. #include "psa_crypto_slot_management.h"
  39. /* Include internal declarations that are useful for implementing persistently
  40. * stored keys. */
  41. #include "psa_crypto_storage.h"
  42. #include "psa_crypto_random_impl.h"
  43. #include <assert.h>
  44. #include <stdlib.h>
  45. #include <string.h>
  46. #include "mbedtls/platform.h"
  47. #if !defined(MBEDTLS_PLATFORM_C)
  48. #define mbedtls_calloc calloc
  49. #define mbedtls_free free
  50. #endif
  51. #include "mbedtls/aes.h"
  52. #include "mbedtls/asn1.h"
  53. #include "mbedtls/asn1write.h"
  54. #include "mbedtls/bignum.h"
  55. #include "mbedtls/camellia.h"
  56. #include "mbedtls/chacha20.h"
  57. #include "mbedtls/chachapoly.h"
  58. #include "mbedtls/cipher.h"
  59. #include "mbedtls/ccm.h"
  60. #include "mbedtls/cmac.h"
  61. #include "mbedtls/des.h"
  62. #include "mbedtls/ecdh.h"
  63. #include "mbedtls/ecp.h"
  64. #include "mbedtls/entropy.h"
  65. #include "mbedtls/error.h"
  66. #include "mbedtls/gcm.h"
  67. #include "mbedtls/md5.h"
  68. #include "mbedtls/md.h"
  69. #include "md_wrap.h"
  70. #include "mbedtls/pk.h"
  71. #include "pk_wrap.h"
  72. #include "mbedtls/platform_util.h"
  73. #include "mbedtls/error.h"
  74. #include "mbedtls/ripemd160.h"
  75. #include "mbedtls/rsa.h"
  76. #include "mbedtls/sha1.h"
  77. #include "mbedtls/sha256.h"
  78. #include "mbedtls/sha512.h"
  79. #define ARRAY_LENGTH( array ) ( sizeof( array ) / sizeof( *( array ) ) )
  80. /****************************************************************/
  81. /* Global data, support functions and library management */
  82. /****************************************************************/
  83. static int key_type_is_raw_bytes( psa_key_type_t type )
  84. {
  85. return( PSA_KEY_TYPE_IS_UNSTRUCTURED( type ) );
  86. }
  87. /* Values for psa_global_data_t::rng_state */
  88. #define RNG_NOT_INITIALIZED 0
  89. #define RNG_INITIALIZED 1
  90. #define RNG_SEEDED 2
  91. typedef struct
  92. {
  93. mbedtls_psa_random_context_t rng;
  94. unsigned initialized : 1;
  95. unsigned rng_state : 2;
  96. } psa_global_data_t;
  97. static psa_global_data_t global_data;
  98. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  99. mbedtls_psa_drbg_context_t *const mbedtls_psa_random_state =
  100. &global_data.rng.drbg;
  101. #endif
  102. #define GUARD_MODULE_INITIALIZED \
  103. if( global_data.initialized == 0 ) \
  104. return( PSA_ERROR_BAD_STATE );
  105. psa_status_t mbedtls_to_psa_error( int ret )
  106. {
  107. /* Mbed TLS error codes can combine a high-level error code and a
  108. * low-level error code. The low-level error usually reflects the
  109. * root cause better, so dispatch on that preferably. */
  110. int low_level_ret = - ( -ret & 0x007f );
  111. switch( low_level_ret != 0 ? low_level_ret : ret )
  112. {
  113. case 0:
  114. return( PSA_SUCCESS );
  115. case MBEDTLS_ERR_AES_INVALID_KEY_LENGTH:
  116. case MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH:
  117. return( PSA_ERROR_NOT_SUPPORTED );
  118. case MBEDTLS_ERR_ASN1_OUT_OF_DATA:
  119. case MBEDTLS_ERR_ASN1_UNEXPECTED_TAG:
  120. case MBEDTLS_ERR_ASN1_INVALID_LENGTH:
  121. case MBEDTLS_ERR_ASN1_LENGTH_MISMATCH:
  122. case MBEDTLS_ERR_ASN1_INVALID_DATA:
  123. return( PSA_ERROR_INVALID_ARGUMENT );
  124. case MBEDTLS_ERR_ASN1_ALLOC_FAILED:
  125. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  126. case MBEDTLS_ERR_ASN1_BUF_TOO_SMALL:
  127. return( PSA_ERROR_BUFFER_TOO_SMALL );
  128. #if defined(MBEDTLS_ERR_CAMELLIA_BAD_INPUT_DATA)
  129. case MBEDTLS_ERR_CAMELLIA_BAD_INPUT_DATA:
  130. #endif
  131. case MBEDTLS_ERR_CAMELLIA_INVALID_INPUT_LENGTH:
  132. return( PSA_ERROR_NOT_SUPPORTED );
  133. case MBEDTLS_ERR_CCM_BAD_INPUT:
  134. return( PSA_ERROR_INVALID_ARGUMENT );
  135. case MBEDTLS_ERR_CCM_AUTH_FAILED:
  136. return( PSA_ERROR_INVALID_SIGNATURE );
  137. case MBEDTLS_ERR_CHACHA20_BAD_INPUT_DATA:
  138. return( PSA_ERROR_INVALID_ARGUMENT );
  139. case MBEDTLS_ERR_CHACHAPOLY_BAD_STATE:
  140. return( PSA_ERROR_BAD_STATE );
  141. case MBEDTLS_ERR_CHACHAPOLY_AUTH_FAILED:
  142. return( PSA_ERROR_INVALID_SIGNATURE );
  143. case MBEDTLS_ERR_CIPHER_FEATURE_UNAVAILABLE:
  144. return( PSA_ERROR_NOT_SUPPORTED );
  145. case MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA:
  146. return( PSA_ERROR_INVALID_ARGUMENT );
  147. case MBEDTLS_ERR_CIPHER_ALLOC_FAILED:
  148. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  149. case MBEDTLS_ERR_CIPHER_INVALID_PADDING:
  150. return( PSA_ERROR_INVALID_PADDING );
  151. case MBEDTLS_ERR_CIPHER_FULL_BLOCK_EXPECTED:
  152. return( PSA_ERROR_INVALID_ARGUMENT );
  153. case MBEDTLS_ERR_CIPHER_AUTH_FAILED:
  154. return( PSA_ERROR_INVALID_SIGNATURE );
  155. case MBEDTLS_ERR_CIPHER_INVALID_CONTEXT:
  156. return( PSA_ERROR_CORRUPTION_DETECTED );
  157. #if !( defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) || \
  158. defined(MBEDTLS_PSA_HMAC_DRBG_MD_TYPE) )
  159. /* Only check CTR_DRBG error codes if underlying mbedtls_xxx
  160. * functions are passed a CTR_DRBG instance. */
  161. case MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED:
  162. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  163. case MBEDTLS_ERR_CTR_DRBG_REQUEST_TOO_BIG:
  164. case MBEDTLS_ERR_CTR_DRBG_INPUT_TOO_BIG:
  165. return( PSA_ERROR_NOT_SUPPORTED );
  166. case MBEDTLS_ERR_CTR_DRBG_FILE_IO_ERROR:
  167. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  168. #endif
  169. case MBEDTLS_ERR_DES_INVALID_INPUT_LENGTH:
  170. return( PSA_ERROR_NOT_SUPPORTED );
  171. case MBEDTLS_ERR_ENTROPY_NO_SOURCES_DEFINED:
  172. case MBEDTLS_ERR_ENTROPY_NO_STRONG_SOURCE:
  173. case MBEDTLS_ERR_ENTROPY_SOURCE_FAILED:
  174. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  175. case MBEDTLS_ERR_GCM_AUTH_FAILED:
  176. return( PSA_ERROR_INVALID_SIGNATURE );
  177. case MBEDTLS_ERR_GCM_BUFFER_TOO_SMALL:
  178. return( PSA_ERROR_BUFFER_TOO_SMALL );
  179. case MBEDTLS_ERR_GCM_BAD_INPUT:
  180. return( PSA_ERROR_INVALID_ARGUMENT );
  181. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) && \
  182. defined(MBEDTLS_PSA_HMAC_DRBG_MD_TYPE)
  183. /* Only check HMAC_DRBG error codes if underlying mbedtls_xxx
  184. * functions are passed a HMAC_DRBG instance. */
  185. case MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED:
  186. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  187. case MBEDTLS_ERR_HMAC_DRBG_REQUEST_TOO_BIG:
  188. case MBEDTLS_ERR_HMAC_DRBG_INPUT_TOO_BIG:
  189. return( PSA_ERROR_NOT_SUPPORTED );
  190. case MBEDTLS_ERR_HMAC_DRBG_FILE_IO_ERROR:
  191. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  192. #endif
  193. case MBEDTLS_ERR_MD_FEATURE_UNAVAILABLE:
  194. return( PSA_ERROR_NOT_SUPPORTED );
  195. case MBEDTLS_ERR_MD_BAD_INPUT_DATA:
  196. return( PSA_ERROR_INVALID_ARGUMENT );
  197. case MBEDTLS_ERR_MD_ALLOC_FAILED:
  198. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  199. case MBEDTLS_ERR_MD_FILE_IO_ERROR:
  200. return( PSA_ERROR_STORAGE_FAILURE );
  201. case MBEDTLS_ERR_MPI_FILE_IO_ERROR:
  202. return( PSA_ERROR_STORAGE_FAILURE );
  203. case MBEDTLS_ERR_MPI_BAD_INPUT_DATA:
  204. return( PSA_ERROR_INVALID_ARGUMENT );
  205. case MBEDTLS_ERR_MPI_INVALID_CHARACTER:
  206. return( PSA_ERROR_INVALID_ARGUMENT );
  207. case MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL:
  208. return( PSA_ERROR_BUFFER_TOO_SMALL );
  209. case MBEDTLS_ERR_MPI_NEGATIVE_VALUE:
  210. return( PSA_ERROR_INVALID_ARGUMENT );
  211. case MBEDTLS_ERR_MPI_DIVISION_BY_ZERO:
  212. return( PSA_ERROR_INVALID_ARGUMENT );
  213. case MBEDTLS_ERR_MPI_NOT_ACCEPTABLE:
  214. return( PSA_ERROR_INVALID_ARGUMENT );
  215. case MBEDTLS_ERR_MPI_ALLOC_FAILED:
  216. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  217. case MBEDTLS_ERR_PK_ALLOC_FAILED:
  218. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  219. case MBEDTLS_ERR_PK_TYPE_MISMATCH:
  220. case MBEDTLS_ERR_PK_BAD_INPUT_DATA:
  221. return( PSA_ERROR_INVALID_ARGUMENT );
  222. case MBEDTLS_ERR_PK_FILE_IO_ERROR:
  223. return( PSA_ERROR_STORAGE_FAILURE );
  224. case MBEDTLS_ERR_PK_KEY_INVALID_VERSION:
  225. case MBEDTLS_ERR_PK_KEY_INVALID_FORMAT:
  226. return( PSA_ERROR_INVALID_ARGUMENT );
  227. case MBEDTLS_ERR_PK_UNKNOWN_PK_ALG:
  228. return( PSA_ERROR_NOT_SUPPORTED );
  229. case MBEDTLS_ERR_PK_PASSWORD_REQUIRED:
  230. case MBEDTLS_ERR_PK_PASSWORD_MISMATCH:
  231. return( PSA_ERROR_NOT_PERMITTED );
  232. case MBEDTLS_ERR_PK_INVALID_PUBKEY:
  233. return( PSA_ERROR_INVALID_ARGUMENT );
  234. case MBEDTLS_ERR_PK_INVALID_ALG:
  235. case MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE:
  236. case MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE:
  237. return( PSA_ERROR_NOT_SUPPORTED );
  238. case MBEDTLS_ERR_PK_SIG_LEN_MISMATCH:
  239. return( PSA_ERROR_INVALID_SIGNATURE );
  240. case MBEDTLS_ERR_PK_BUFFER_TOO_SMALL:
  241. return( PSA_ERROR_BUFFER_TOO_SMALL );
  242. case MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED:
  243. return( PSA_ERROR_HARDWARE_FAILURE );
  244. case MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED:
  245. return( PSA_ERROR_NOT_SUPPORTED );
  246. case MBEDTLS_ERR_RSA_BAD_INPUT_DATA:
  247. return( PSA_ERROR_INVALID_ARGUMENT );
  248. case MBEDTLS_ERR_RSA_INVALID_PADDING:
  249. return( PSA_ERROR_INVALID_PADDING );
  250. case MBEDTLS_ERR_RSA_KEY_GEN_FAILED:
  251. return( PSA_ERROR_HARDWARE_FAILURE );
  252. case MBEDTLS_ERR_RSA_KEY_CHECK_FAILED:
  253. return( PSA_ERROR_INVALID_ARGUMENT );
  254. case MBEDTLS_ERR_RSA_PUBLIC_FAILED:
  255. case MBEDTLS_ERR_RSA_PRIVATE_FAILED:
  256. return( PSA_ERROR_CORRUPTION_DETECTED );
  257. case MBEDTLS_ERR_RSA_VERIFY_FAILED:
  258. return( PSA_ERROR_INVALID_SIGNATURE );
  259. case MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE:
  260. return( PSA_ERROR_BUFFER_TOO_SMALL );
  261. case MBEDTLS_ERR_RSA_RNG_FAILED:
  262. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  263. case MBEDTLS_ERR_ECP_BAD_INPUT_DATA:
  264. case MBEDTLS_ERR_ECP_INVALID_KEY:
  265. return( PSA_ERROR_INVALID_ARGUMENT );
  266. case MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL:
  267. return( PSA_ERROR_BUFFER_TOO_SMALL );
  268. case MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE:
  269. return( PSA_ERROR_NOT_SUPPORTED );
  270. case MBEDTLS_ERR_ECP_SIG_LEN_MISMATCH:
  271. case MBEDTLS_ERR_ECP_VERIFY_FAILED:
  272. return( PSA_ERROR_INVALID_SIGNATURE );
  273. case MBEDTLS_ERR_ECP_ALLOC_FAILED:
  274. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  275. case MBEDTLS_ERR_ECP_RANDOM_FAILED:
  276. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  277. case MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED:
  278. return( PSA_ERROR_CORRUPTION_DETECTED );
  279. default:
  280. return( PSA_ERROR_GENERIC_ERROR );
  281. }
  282. }
  283. /****************************************************************/
  284. /* Key management */
  285. /****************************************************************/
  286. /* For now the MBEDTLS_PSA_ACCEL_ guards are also used here since the
  287. * current test driver in key_management.c is using this function
  288. * when accelerators are used for ECC key pair and public key.
  289. * Once that dependency is resolved these guards can be removed.
  290. */
  291. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  292. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) || \
  293. defined(MBEDTLS_PSA_ACCEL_KEY_TYPE_ECC_KEY_PAIR) || \
  294. defined(MBEDTLS_PSA_ACCEL_KEY_TYPE_ECC_PUBLIC_KEY)
  295. mbedtls_ecp_group_id mbedtls_ecc_group_of_psa( psa_ecc_family_t curve,
  296. size_t bits,
  297. int bits_is_sloppy )
  298. {
  299. switch( curve )
  300. {
  301. case PSA_ECC_FAMILY_SECP_R1:
  302. switch( bits )
  303. {
  304. #if defined(PSA_WANT_ECC_SECP_R1_192)
  305. case 192:
  306. return( MBEDTLS_ECP_DP_SECP192R1 );
  307. #endif
  308. #if defined(PSA_WANT_ECC_SECP_R1_224)
  309. case 224:
  310. return( MBEDTLS_ECP_DP_SECP224R1 );
  311. #endif
  312. #if defined(PSA_WANT_ECC_SECP_R1_256)
  313. case 256:
  314. return( MBEDTLS_ECP_DP_SECP256R1 );
  315. #endif
  316. #if defined(PSA_WANT_ECC_SECP_R1_384)
  317. case 384:
  318. return( MBEDTLS_ECP_DP_SECP384R1 );
  319. #endif
  320. #if defined(PSA_WANT_ECC_SECP_R1_521)
  321. case 521:
  322. return( MBEDTLS_ECP_DP_SECP521R1 );
  323. case 528:
  324. if( bits_is_sloppy )
  325. return( MBEDTLS_ECP_DP_SECP521R1 );
  326. break;
  327. #endif
  328. }
  329. break;
  330. case PSA_ECC_FAMILY_BRAINPOOL_P_R1:
  331. switch( bits )
  332. {
  333. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_256)
  334. case 256:
  335. return( MBEDTLS_ECP_DP_BP256R1 );
  336. #endif
  337. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_384)
  338. case 384:
  339. return( MBEDTLS_ECP_DP_BP384R1 );
  340. #endif
  341. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_512)
  342. case 512:
  343. return( MBEDTLS_ECP_DP_BP512R1 );
  344. #endif
  345. }
  346. break;
  347. case PSA_ECC_FAMILY_MONTGOMERY:
  348. switch( bits )
  349. {
  350. #if defined(PSA_WANT_ECC_MONTGOMERY_255)
  351. case 255:
  352. return( MBEDTLS_ECP_DP_CURVE25519 );
  353. case 256:
  354. if( bits_is_sloppy )
  355. return( MBEDTLS_ECP_DP_CURVE25519 );
  356. break;
  357. #endif
  358. #if defined(PSA_WANT_ECC_MONTGOMERY_448)
  359. case 448:
  360. return( MBEDTLS_ECP_DP_CURVE448 );
  361. #endif
  362. }
  363. break;
  364. case PSA_ECC_FAMILY_SECP_K1:
  365. switch( bits )
  366. {
  367. #if defined(PSA_WANT_ECC_SECP_K1_192)
  368. case 192:
  369. return( MBEDTLS_ECP_DP_SECP192K1 );
  370. #endif
  371. #if defined(PSA_WANT_ECC_SECP_K1_224)
  372. case 224:
  373. return( MBEDTLS_ECP_DP_SECP224K1 );
  374. #endif
  375. #if defined(PSA_WANT_ECC_SECP_K1_256)
  376. case 256:
  377. return( MBEDTLS_ECP_DP_SECP256K1 );
  378. #endif
  379. }
  380. break;
  381. }
  382. (void) bits_is_sloppy;
  383. return( MBEDTLS_ECP_DP_NONE );
  384. }
  385. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  386. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) ||
  387. * defined(MBEDTLS_PSA_ACCEL_KEY_TYPE_ECC_KEY_PAIR) ||
  388. * defined(MBEDTLS_PSA_ACCEL_KEY_TYPE_ECC_PUBLIC_KEY) */
  389. psa_status_t psa_validate_unstructured_key_bit_size( psa_key_type_t type,
  390. size_t bits )
  391. {
  392. /* Check that the bit size is acceptable for the key type */
  393. switch( type )
  394. {
  395. case PSA_KEY_TYPE_RAW_DATA:
  396. case PSA_KEY_TYPE_HMAC:
  397. case PSA_KEY_TYPE_DERIVE:
  398. break;
  399. #if defined(PSA_WANT_KEY_TYPE_AES)
  400. case PSA_KEY_TYPE_AES:
  401. if( bits != 128 && bits != 192 && bits != 256 )
  402. return( PSA_ERROR_INVALID_ARGUMENT );
  403. break;
  404. #endif
  405. #if defined(PSA_WANT_KEY_TYPE_ARIA)
  406. case PSA_KEY_TYPE_ARIA:
  407. if( bits != 128 && bits != 192 && bits != 256 )
  408. return( PSA_ERROR_INVALID_ARGUMENT );
  409. break;
  410. #endif
  411. #if defined(PSA_WANT_KEY_TYPE_CAMELLIA)
  412. case PSA_KEY_TYPE_CAMELLIA:
  413. if( bits != 128 && bits != 192 && bits != 256 )
  414. return( PSA_ERROR_INVALID_ARGUMENT );
  415. break;
  416. #endif
  417. #if defined(PSA_WANT_KEY_TYPE_DES)
  418. case PSA_KEY_TYPE_DES:
  419. if( bits != 64 && bits != 128 && bits != 192 )
  420. return( PSA_ERROR_INVALID_ARGUMENT );
  421. break;
  422. #endif
  423. #if defined(PSA_WANT_KEY_TYPE_CHACHA20)
  424. case PSA_KEY_TYPE_CHACHA20:
  425. if( bits != 256 )
  426. return( PSA_ERROR_INVALID_ARGUMENT );
  427. break;
  428. #endif
  429. default:
  430. return( PSA_ERROR_NOT_SUPPORTED );
  431. }
  432. if( bits % 8 != 0 )
  433. return( PSA_ERROR_INVALID_ARGUMENT );
  434. return( PSA_SUCCESS );
  435. }
  436. /** Check whether a given key type is valid for use with a given MAC algorithm
  437. *
  438. * Upon successful return of this function, the behavior of #PSA_MAC_LENGTH
  439. * when called with the validated \p algorithm and \p key_type is well-defined.
  440. *
  441. * \param[in] algorithm The specific MAC algorithm (can be wildcard).
  442. * \param[in] key_type The key type of the key to be used with the
  443. * \p algorithm.
  444. *
  445. * \retval #PSA_SUCCESS
  446. * The \p key_type is valid for use with the \p algorithm
  447. * \retval #PSA_ERROR_INVALID_ARGUMENT
  448. * The \p key_type is not valid for use with the \p algorithm
  449. */
  450. MBEDTLS_STATIC_TESTABLE psa_status_t psa_mac_key_can_do(
  451. psa_algorithm_t algorithm,
  452. psa_key_type_t key_type )
  453. {
  454. if( PSA_ALG_IS_HMAC( algorithm ) )
  455. {
  456. if( key_type == PSA_KEY_TYPE_HMAC )
  457. return( PSA_SUCCESS );
  458. }
  459. if( PSA_ALG_IS_BLOCK_CIPHER_MAC( algorithm ) )
  460. {
  461. /* Check that we're calling PSA_BLOCK_CIPHER_BLOCK_LENGTH with a cipher
  462. * key. */
  463. if( ( key_type & PSA_KEY_TYPE_CATEGORY_MASK ) ==
  464. PSA_KEY_TYPE_CATEGORY_SYMMETRIC )
  465. {
  466. /* PSA_BLOCK_CIPHER_BLOCK_LENGTH returns 1 for stream ciphers and
  467. * the block length (larger than 1) for block ciphers. */
  468. if( PSA_BLOCK_CIPHER_BLOCK_LENGTH( key_type ) > 1 )
  469. return( PSA_SUCCESS );
  470. }
  471. }
  472. return( PSA_ERROR_INVALID_ARGUMENT );
  473. }
  474. psa_status_t psa_allocate_buffer_to_slot( psa_key_slot_t *slot,
  475. size_t buffer_length )
  476. {
  477. if( slot->key.data != NULL )
  478. return( PSA_ERROR_ALREADY_EXISTS );
  479. slot->key.data = mbedtls_calloc( 1, buffer_length );
  480. if( slot->key.data == NULL )
  481. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  482. slot->key.bytes = buffer_length;
  483. return( PSA_SUCCESS );
  484. }
  485. psa_status_t psa_copy_key_material_into_slot( psa_key_slot_t *slot,
  486. const uint8_t* data,
  487. size_t data_length )
  488. {
  489. psa_status_t status = psa_allocate_buffer_to_slot( slot,
  490. data_length );
  491. if( status != PSA_SUCCESS )
  492. return( status );
  493. memcpy( slot->key.data, data, data_length );
  494. return( PSA_SUCCESS );
  495. }
  496. psa_status_t psa_import_key_into_slot(
  497. const psa_key_attributes_t *attributes,
  498. const uint8_t *data, size_t data_length,
  499. uint8_t *key_buffer, size_t key_buffer_size,
  500. size_t *key_buffer_length, size_t *bits )
  501. {
  502. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  503. psa_key_type_t type = attributes->core.type;
  504. /* zero-length keys are never supported. */
  505. if( data_length == 0 )
  506. return( PSA_ERROR_NOT_SUPPORTED );
  507. if( key_type_is_raw_bytes( type ) )
  508. {
  509. *bits = PSA_BYTES_TO_BITS( data_length );
  510. status = psa_validate_unstructured_key_bit_size( attributes->core.type,
  511. *bits );
  512. if( status != PSA_SUCCESS )
  513. return( status );
  514. /* Copy the key material. */
  515. memcpy( key_buffer, data, data_length );
  516. *key_buffer_length = data_length;
  517. (void)key_buffer_size;
  518. return( PSA_SUCCESS );
  519. }
  520. else if( PSA_KEY_TYPE_IS_ASYMMETRIC( type ) )
  521. {
  522. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  523. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY)
  524. if( PSA_KEY_TYPE_IS_ECC( type ) )
  525. {
  526. return( mbedtls_psa_ecp_import_key( attributes,
  527. data, data_length,
  528. key_buffer, key_buffer_size,
  529. key_buffer_length,
  530. bits ) );
  531. }
  532. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  533. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) */
  534. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  535. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  536. if( PSA_KEY_TYPE_IS_RSA( type ) )
  537. {
  538. return( mbedtls_psa_rsa_import_key( attributes,
  539. data, data_length,
  540. key_buffer, key_buffer_size,
  541. key_buffer_length,
  542. bits ) );
  543. }
  544. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  545. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  546. }
  547. return( PSA_ERROR_NOT_SUPPORTED );
  548. }
  549. /** Calculate the intersection of two algorithm usage policies.
  550. *
  551. * Return 0 (which allows no operation) on incompatibility.
  552. */
  553. static psa_algorithm_t psa_key_policy_algorithm_intersection(
  554. psa_key_type_t key_type,
  555. psa_algorithm_t alg1,
  556. psa_algorithm_t alg2 )
  557. {
  558. /* Common case: both sides actually specify the same policy. */
  559. if( alg1 == alg2 )
  560. return( alg1 );
  561. /* If the policies are from the same hash-and-sign family, check
  562. * if one is a wildcard. If so the other has the specific algorithm. */
  563. if( PSA_ALG_IS_SIGN_HASH( alg1 ) &&
  564. PSA_ALG_IS_SIGN_HASH( alg2 ) &&
  565. ( alg1 & ~PSA_ALG_HASH_MASK ) == ( alg2 & ~PSA_ALG_HASH_MASK ) )
  566. {
  567. if( PSA_ALG_SIGN_GET_HASH( alg1 ) == PSA_ALG_ANY_HASH )
  568. return( alg2 );
  569. if( PSA_ALG_SIGN_GET_HASH( alg2 ) == PSA_ALG_ANY_HASH )
  570. return( alg1 );
  571. }
  572. /* If the policies are from the same AEAD family, check whether
  573. * one of them is a minimum-tag-length wildcard. Calculate the most
  574. * restrictive tag length. */
  575. if( PSA_ALG_IS_AEAD( alg1 ) && PSA_ALG_IS_AEAD( alg2 ) &&
  576. ( PSA_ALG_AEAD_WITH_SHORTENED_TAG( alg1, 0 ) ==
  577. PSA_ALG_AEAD_WITH_SHORTENED_TAG( alg2, 0 ) ) )
  578. {
  579. size_t alg1_len = PSA_ALG_AEAD_GET_TAG_LENGTH( alg1 );
  580. size_t alg2_len = PSA_ALG_AEAD_GET_TAG_LENGTH( alg2 );
  581. size_t restricted_len = alg1_len > alg2_len ? alg1_len : alg2_len;
  582. /* If both are wildcards, return most restrictive wildcard */
  583. if( ( ( alg1 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  584. ( ( alg2 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) )
  585. {
  586. return( PSA_ALG_AEAD_WITH_AT_LEAST_THIS_LENGTH_TAG(
  587. alg1, restricted_len ) );
  588. }
  589. /* If only one is a wildcard, return specific algorithm if compatible. */
  590. if( ( ( alg1 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  591. ( alg1_len <= alg2_len ) )
  592. {
  593. return( alg2 );
  594. }
  595. if( ( ( alg2 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  596. ( alg2_len <= alg1_len ) )
  597. {
  598. return( alg1 );
  599. }
  600. }
  601. /* If the policies are from the same MAC family, check whether one
  602. * of them is a minimum-MAC-length policy. Calculate the most
  603. * restrictive tag length. */
  604. if( PSA_ALG_IS_MAC( alg1 ) && PSA_ALG_IS_MAC( alg2 ) &&
  605. ( PSA_ALG_FULL_LENGTH_MAC( alg1 ) ==
  606. PSA_ALG_FULL_LENGTH_MAC( alg2 ) ) )
  607. {
  608. /* Validate the combination of key type and algorithm. Since the base
  609. * algorithm of alg1 and alg2 are the same, we only need this once. */
  610. if( PSA_SUCCESS != psa_mac_key_can_do( alg1, key_type ) )
  611. return( 0 );
  612. /* Get the (exact or at-least) output lengths for both sides of the
  613. * requested intersection. None of the currently supported algorithms
  614. * have an output length dependent on the actual key size, so setting it
  615. * to a bogus value of 0 is currently OK.
  616. *
  617. * Note that for at-least-this-length wildcard algorithms, the output
  618. * length is set to the shortest allowed length, which allows us to
  619. * calculate the most restrictive tag length for the intersection. */
  620. size_t alg1_len = PSA_MAC_LENGTH( key_type, 0, alg1 );
  621. size_t alg2_len = PSA_MAC_LENGTH( key_type, 0, alg2 );
  622. size_t restricted_len = alg1_len > alg2_len ? alg1_len : alg2_len;
  623. /* If both are wildcards, return most restrictive wildcard */
  624. if( ( ( alg1 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  625. ( ( alg2 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) )
  626. {
  627. return( PSA_ALG_AT_LEAST_THIS_LENGTH_MAC( alg1, restricted_len ) );
  628. }
  629. /* If only one is an at-least-this-length policy, the intersection would
  630. * be the other (fixed-length) policy as long as said fixed length is
  631. * equal to or larger than the shortest allowed length. */
  632. if( ( alg1 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 )
  633. {
  634. return( ( alg1_len <= alg2_len ) ? alg2 : 0 );
  635. }
  636. if( ( alg2 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 )
  637. {
  638. return( ( alg2_len <= alg1_len ) ? alg1 : 0 );
  639. }
  640. /* If none of them are wildcards, check whether they define the same tag
  641. * length. This is still possible here when one is default-length and
  642. * the other specific-length. Ensure to always return the
  643. * specific-length version for the intersection. */
  644. if( alg1_len == alg2_len )
  645. return( PSA_ALG_TRUNCATED_MAC( alg1, alg1_len ) );
  646. }
  647. /* If the policies are incompatible, allow nothing. */
  648. return( 0 );
  649. }
  650. static int psa_key_algorithm_permits( psa_key_type_t key_type,
  651. psa_algorithm_t policy_alg,
  652. psa_algorithm_t requested_alg )
  653. {
  654. /* Common case: the policy only allows requested_alg. */
  655. if( requested_alg == policy_alg )
  656. return( 1 );
  657. /* If policy_alg is a hash-and-sign with a wildcard for the hash,
  658. * and requested_alg is the same hash-and-sign family with any hash,
  659. * then requested_alg is compliant with policy_alg. */
  660. if( PSA_ALG_IS_SIGN_HASH( requested_alg ) &&
  661. PSA_ALG_SIGN_GET_HASH( policy_alg ) == PSA_ALG_ANY_HASH )
  662. {
  663. return( ( policy_alg & ~PSA_ALG_HASH_MASK ) ==
  664. ( requested_alg & ~PSA_ALG_HASH_MASK ) );
  665. }
  666. /* If policy_alg is a wildcard AEAD algorithm of the same base as
  667. * the requested algorithm, check the requested tag length to be
  668. * equal-length or longer than the wildcard-specified length. */
  669. if( PSA_ALG_IS_AEAD( policy_alg ) &&
  670. PSA_ALG_IS_AEAD( requested_alg ) &&
  671. ( PSA_ALG_AEAD_WITH_SHORTENED_TAG( policy_alg, 0 ) ==
  672. PSA_ALG_AEAD_WITH_SHORTENED_TAG( requested_alg, 0 ) ) &&
  673. ( ( policy_alg & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) )
  674. {
  675. return( PSA_ALG_AEAD_GET_TAG_LENGTH( policy_alg ) <=
  676. PSA_ALG_AEAD_GET_TAG_LENGTH( requested_alg ) );
  677. }
  678. /* If policy_alg is a MAC algorithm of the same base as the requested
  679. * algorithm, check whether their MAC lengths are compatible. */
  680. if( PSA_ALG_IS_MAC( policy_alg ) &&
  681. PSA_ALG_IS_MAC( requested_alg ) &&
  682. ( PSA_ALG_FULL_LENGTH_MAC( policy_alg ) ==
  683. PSA_ALG_FULL_LENGTH_MAC( requested_alg ) ) )
  684. {
  685. /* Validate the combination of key type and algorithm. Since the policy
  686. * and requested algorithms are the same, we only need this once. */
  687. if( PSA_SUCCESS != psa_mac_key_can_do( policy_alg, key_type ) )
  688. return( 0 );
  689. /* Get both the requested output length for the algorithm which is to be
  690. * verified, and the default output length for the base algorithm.
  691. * Note that none of the currently supported algorithms have an output
  692. * length dependent on actual key size, so setting it to a bogus value
  693. * of 0 is currently OK. */
  694. size_t requested_output_length = PSA_MAC_LENGTH(
  695. key_type, 0, requested_alg );
  696. size_t default_output_length = PSA_MAC_LENGTH(
  697. key_type, 0,
  698. PSA_ALG_FULL_LENGTH_MAC( requested_alg ) );
  699. /* If the policy is default-length, only allow an algorithm with
  700. * a declared exact-length matching the default. */
  701. if( PSA_MAC_TRUNCATED_LENGTH( policy_alg ) == 0 )
  702. return( requested_output_length == default_output_length );
  703. /* If the requested algorithm is default-length, allow it if the policy
  704. * length exactly matches the default length. */
  705. if( PSA_MAC_TRUNCATED_LENGTH( requested_alg ) == 0 &&
  706. PSA_MAC_TRUNCATED_LENGTH( policy_alg ) == default_output_length )
  707. {
  708. return( 1 );
  709. }
  710. /* If policy_alg is an at-least-this-length wildcard MAC algorithm,
  711. * check for the requested MAC length to be equal to or longer than the
  712. * minimum allowed length. */
  713. if( ( policy_alg & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 )
  714. {
  715. return( PSA_MAC_TRUNCATED_LENGTH( policy_alg ) <=
  716. requested_output_length );
  717. }
  718. }
  719. /* If policy_alg is a generic key agreement operation, then using it for
  720. * a key derivation with that key agreement should also be allowed. This
  721. * behaviour is expected to be defined in a future specification version. */
  722. if( PSA_ALG_IS_RAW_KEY_AGREEMENT( policy_alg ) &&
  723. PSA_ALG_IS_KEY_AGREEMENT( requested_alg ) )
  724. {
  725. return( PSA_ALG_KEY_AGREEMENT_GET_BASE( requested_alg ) ==
  726. policy_alg );
  727. }
  728. /* If it isn't explicitly permitted, it's forbidden. */
  729. return( 0 );
  730. }
  731. /** Test whether a policy permits an algorithm.
  732. *
  733. * The caller must test usage flags separately.
  734. *
  735. * \note This function requires providing the key type for which the policy is
  736. * being validated, since some algorithm policy definitions (e.g. MAC)
  737. * have different properties depending on what kind of cipher it is
  738. * combined with.
  739. *
  740. * \retval PSA_SUCCESS When \p alg is a specific algorithm
  741. * allowed by the \p policy.
  742. * \retval PSA_ERROR_INVALID_ARGUMENT When \p alg is not a specific algorithm
  743. * \retval PSA_ERROR_NOT_PERMITTED When \p alg is a specific algorithm, but
  744. * the \p policy does not allow it.
  745. */
  746. static psa_status_t psa_key_policy_permits( const psa_key_policy_t *policy,
  747. psa_key_type_t key_type,
  748. psa_algorithm_t alg )
  749. {
  750. /* '0' is not a valid algorithm */
  751. if( alg == 0 )
  752. return( PSA_ERROR_INVALID_ARGUMENT );
  753. /* A requested algorithm cannot be a wildcard. */
  754. if( PSA_ALG_IS_WILDCARD( alg ) )
  755. return( PSA_ERROR_INVALID_ARGUMENT );
  756. if( psa_key_algorithm_permits( key_type, policy->alg, alg ) ||
  757. psa_key_algorithm_permits( key_type, policy->alg2, alg ) )
  758. return( PSA_SUCCESS );
  759. else
  760. return( PSA_ERROR_NOT_PERMITTED );
  761. }
  762. /** Restrict a key policy based on a constraint.
  763. *
  764. * \note This function requires providing the key type for which the policy is
  765. * being restricted, since some algorithm policy definitions (e.g. MAC)
  766. * have different properties depending on what kind of cipher it is
  767. * combined with.
  768. *
  769. * \param[in] key_type The key type for which to restrict the policy
  770. * \param[in,out] policy The policy to restrict.
  771. * \param[in] constraint The policy constraint to apply.
  772. *
  773. * \retval #PSA_SUCCESS
  774. * \c *policy contains the intersection of the original value of
  775. * \c *policy and \c *constraint.
  776. * \retval #PSA_ERROR_INVALID_ARGUMENT
  777. * \c key_type, \c *policy and \c *constraint are incompatible.
  778. * \c *policy is unchanged.
  779. */
  780. static psa_status_t psa_restrict_key_policy(
  781. psa_key_type_t key_type,
  782. psa_key_policy_t *policy,
  783. const psa_key_policy_t *constraint )
  784. {
  785. psa_algorithm_t intersection_alg =
  786. psa_key_policy_algorithm_intersection( key_type, policy->alg,
  787. constraint->alg );
  788. psa_algorithm_t intersection_alg2 =
  789. psa_key_policy_algorithm_intersection( key_type, policy->alg2,
  790. constraint->alg2 );
  791. if( intersection_alg == 0 && policy->alg != 0 && constraint->alg != 0 )
  792. return( PSA_ERROR_INVALID_ARGUMENT );
  793. if( intersection_alg2 == 0 && policy->alg2 != 0 && constraint->alg2 != 0 )
  794. return( PSA_ERROR_INVALID_ARGUMENT );
  795. policy->usage &= constraint->usage;
  796. policy->alg = intersection_alg;
  797. policy->alg2 = intersection_alg2;
  798. return( PSA_SUCCESS );
  799. }
  800. /** Get the description of a key given its identifier and policy constraints
  801. * and lock it.
  802. *
  803. * The key must have allow all the usage flags set in \p usage. If \p alg is
  804. * nonzero, the key must allow operations with this algorithm. If \p alg is
  805. * zero, the algorithm is not checked.
  806. *
  807. * In case of a persistent key, the function loads the description of the key
  808. * into a key slot if not already done.
  809. *
  810. * On success, the returned key slot is locked. It is the responsibility of
  811. * the caller to unlock the key slot when it does not access it anymore.
  812. */
  813. static psa_status_t psa_get_and_lock_key_slot_with_policy(
  814. mbedtls_svc_key_id_t key,
  815. psa_key_slot_t **p_slot,
  816. psa_key_usage_t usage,
  817. psa_algorithm_t alg )
  818. {
  819. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  820. psa_key_slot_t *slot;
  821. status = psa_get_and_lock_key_slot( key, p_slot );
  822. if( status != PSA_SUCCESS )
  823. return( status );
  824. slot = *p_slot;
  825. /* Enforce that usage policy for the key slot contains all the flags
  826. * required by the usage parameter. There is one exception: public
  827. * keys can always be exported, so we treat public key objects as
  828. * if they had the export flag. */
  829. if( PSA_KEY_TYPE_IS_PUBLIC_KEY( slot->attr.type ) )
  830. usage &= ~PSA_KEY_USAGE_EXPORT;
  831. if( ( slot->attr.policy.usage & usage ) != usage )
  832. {
  833. status = PSA_ERROR_NOT_PERMITTED;
  834. goto error;
  835. }
  836. /* Enforce that the usage policy permits the requested algortihm. */
  837. if( alg != 0 )
  838. {
  839. status = psa_key_policy_permits( &slot->attr.policy,
  840. slot->attr.type,
  841. alg );
  842. if( status != PSA_SUCCESS )
  843. goto error;
  844. }
  845. return( PSA_SUCCESS );
  846. error:
  847. *p_slot = NULL;
  848. psa_unlock_key_slot( slot );
  849. return( status );
  850. }
  851. /** Get a key slot containing a transparent key and lock it.
  852. *
  853. * A transparent key is a key for which the key material is directly
  854. * available, as opposed to a key in a secure element and/or to be used
  855. * by a secure element.
  856. *
  857. * This is a temporary function that may be used instead of
  858. * psa_get_and_lock_key_slot_with_policy() when there is no opaque key support
  859. * for a cryptographic operation.
  860. *
  861. * On success, the returned key slot is locked. It is the responsibility of the
  862. * caller to unlock the key slot when it does not access it anymore.
  863. */
  864. static psa_status_t psa_get_and_lock_transparent_key_slot_with_policy(
  865. mbedtls_svc_key_id_t key,
  866. psa_key_slot_t **p_slot,
  867. psa_key_usage_t usage,
  868. psa_algorithm_t alg )
  869. {
  870. psa_status_t status = psa_get_and_lock_key_slot_with_policy( key, p_slot,
  871. usage, alg );
  872. if( status != PSA_SUCCESS )
  873. return( status );
  874. if( psa_key_lifetime_is_external( (*p_slot)->attr.lifetime ) )
  875. {
  876. psa_unlock_key_slot( *p_slot );
  877. *p_slot = NULL;
  878. return( PSA_ERROR_NOT_SUPPORTED );
  879. }
  880. return( PSA_SUCCESS );
  881. }
  882. psa_status_t psa_remove_key_data_from_memory( psa_key_slot_t *slot )
  883. {
  884. /* Data pointer will always be either a valid pointer or NULL in an
  885. * initialized slot, so we can just free it. */
  886. if( slot->key.data != NULL )
  887. mbedtls_platform_zeroize( slot->key.data, slot->key.bytes);
  888. mbedtls_free( slot->key.data );
  889. slot->key.data = NULL;
  890. slot->key.bytes = 0;
  891. return( PSA_SUCCESS );
  892. }
  893. /** Completely wipe a slot in memory, including its policy.
  894. * Persistent storage is not affected. */
  895. psa_status_t psa_wipe_key_slot( psa_key_slot_t *slot )
  896. {
  897. psa_status_t status = psa_remove_key_data_from_memory( slot );
  898. /*
  899. * As the return error code may not be handled in case of multiple errors,
  900. * do our best to report an unexpected lock counter. Assert with
  901. * MBEDTLS_TEST_HOOK_TEST_ASSERT that the lock counter is equal to one:
  902. * if the MBEDTLS_TEST_HOOKS configuration option is enabled and the
  903. * function is called as part of the execution of a test suite, the
  904. * execution of the test suite is stopped in error if the assertion fails.
  905. */
  906. if( slot->lock_count != 1 )
  907. {
  908. MBEDTLS_TEST_HOOK_TEST_ASSERT( slot->lock_count == 1 );
  909. status = PSA_ERROR_CORRUPTION_DETECTED;
  910. }
  911. /* Multipart operations may still be using the key. This is safe
  912. * because all multipart operation objects are independent from
  913. * the key slot: if they need to access the key after the setup
  914. * phase, they have a copy of the key. Note that this means that
  915. * key material can linger until all operations are completed. */
  916. /* At this point, key material and other type-specific content has
  917. * been wiped. Clear remaining metadata. We can call memset and not
  918. * zeroize because the metadata is not particularly sensitive. */
  919. memset( slot, 0, sizeof( *slot ) );
  920. return( status );
  921. }
  922. psa_status_t psa_destroy_key( mbedtls_svc_key_id_t key )
  923. {
  924. psa_key_slot_t *slot;
  925. psa_status_t status; /* status of the last operation */
  926. psa_status_t overall_status = PSA_SUCCESS;
  927. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  928. psa_se_drv_table_entry_t *driver;
  929. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  930. if( mbedtls_svc_key_id_is_null( key ) )
  931. return( PSA_SUCCESS );
  932. /*
  933. * Get the description of the key in a key slot. In case of a persistent
  934. * key, this will load the key description from persistent memory if not
  935. * done yet. We cannot avoid this loading as without it we don't know if
  936. * the key is operated by an SE or not and this information is needed by
  937. * the current implementation.
  938. */
  939. status = psa_get_and_lock_key_slot( key, &slot );
  940. if( status != PSA_SUCCESS )
  941. return( status );
  942. /*
  943. * If the key slot containing the key description is under access by the
  944. * library (apart from the present access), the key cannot be destroyed
  945. * yet. For the time being, just return in error. Eventually (to be
  946. * implemented), the key should be destroyed when all accesses have
  947. * stopped.
  948. */
  949. if( slot->lock_count > 1 )
  950. {
  951. psa_unlock_key_slot( slot );
  952. return( PSA_ERROR_GENERIC_ERROR );
  953. }
  954. if( PSA_KEY_LIFETIME_IS_READ_ONLY( slot->attr.lifetime ) )
  955. {
  956. /* Refuse the destruction of a read-only key (which may or may not work
  957. * if we attempt it, depending on whether the key is merely read-only
  958. * by policy or actually physically read-only).
  959. * Just do the best we can, which is to wipe the copy in memory
  960. * (done in this function's cleanup code). */
  961. overall_status = PSA_ERROR_NOT_PERMITTED;
  962. goto exit;
  963. }
  964. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  965. driver = psa_get_se_driver_entry( slot->attr.lifetime );
  966. if( driver != NULL )
  967. {
  968. /* For a key in a secure element, we need to do three things:
  969. * remove the key file in internal storage, destroy the
  970. * key inside the secure element, and update the driver's
  971. * persistent data. Start a transaction that will encompass these
  972. * three actions. */
  973. psa_crypto_prepare_transaction( PSA_CRYPTO_TRANSACTION_DESTROY_KEY );
  974. psa_crypto_transaction.key.lifetime = slot->attr.lifetime;
  975. psa_crypto_transaction.key.slot = psa_key_slot_get_slot_number( slot );
  976. psa_crypto_transaction.key.id = slot->attr.id;
  977. status = psa_crypto_save_transaction( );
  978. if( status != PSA_SUCCESS )
  979. {
  980. (void) psa_crypto_stop_transaction( );
  981. /* We should still try to destroy the key in the secure
  982. * element and the key metadata in storage. This is especially
  983. * important if the error is that the storage is full.
  984. * But how to do it exactly without risking an inconsistent
  985. * state after a reset?
  986. * https://github.com/ARMmbed/mbed-crypto/issues/215
  987. */
  988. overall_status = status;
  989. goto exit;
  990. }
  991. status = psa_destroy_se_key( driver,
  992. psa_key_slot_get_slot_number( slot ) );
  993. if( overall_status == PSA_SUCCESS )
  994. overall_status = status;
  995. }
  996. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  997. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C)
  998. if( ! PSA_KEY_LIFETIME_IS_VOLATILE( slot->attr.lifetime ) )
  999. {
  1000. status = psa_destroy_persistent_key( slot->attr.id );
  1001. if( overall_status == PSA_SUCCESS )
  1002. overall_status = status;
  1003. /* TODO: other slots may have a copy of the same key. We should
  1004. * invalidate them.
  1005. * https://github.com/ARMmbed/mbed-crypto/issues/214
  1006. */
  1007. }
  1008. #endif /* defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) */
  1009. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1010. if( driver != NULL )
  1011. {
  1012. status = psa_save_se_persistent_data( driver );
  1013. if( overall_status == PSA_SUCCESS )
  1014. overall_status = status;
  1015. status = psa_crypto_stop_transaction( );
  1016. if( overall_status == PSA_SUCCESS )
  1017. overall_status = status;
  1018. }
  1019. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1020. exit:
  1021. status = psa_wipe_key_slot( slot );
  1022. /* Prioritize CORRUPTION_DETECTED from wiping over a storage error */
  1023. if( status != PSA_SUCCESS )
  1024. overall_status = status;
  1025. return( overall_status );
  1026. }
  1027. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1028. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1029. static psa_status_t psa_get_rsa_public_exponent(
  1030. const mbedtls_rsa_context *rsa,
  1031. psa_key_attributes_t *attributes )
  1032. {
  1033. mbedtls_mpi mpi;
  1034. int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
  1035. uint8_t *buffer = NULL;
  1036. size_t buflen;
  1037. mbedtls_mpi_init( &mpi );
  1038. ret = mbedtls_rsa_export( rsa, NULL, NULL, NULL, NULL, &mpi );
  1039. if( ret != 0 )
  1040. goto exit;
  1041. if( mbedtls_mpi_cmp_int( &mpi, 65537 ) == 0 )
  1042. {
  1043. /* It's the default value, which is reported as an empty string,
  1044. * so there's nothing to do. */
  1045. goto exit;
  1046. }
  1047. buflen = mbedtls_mpi_size( &mpi );
  1048. buffer = mbedtls_calloc( 1, buflen );
  1049. if( buffer == NULL )
  1050. {
  1051. ret = MBEDTLS_ERR_MPI_ALLOC_FAILED;
  1052. goto exit;
  1053. }
  1054. ret = mbedtls_mpi_write_binary( &mpi, buffer, buflen );
  1055. if( ret != 0 )
  1056. goto exit;
  1057. attributes->domain_parameters = buffer;
  1058. attributes->domain_parameters_size = buflen;
  1059. exit:
  1060. mbedtls_mpi_free( &mpi );
  1061. if( ret != 0 )
  1062. mbedtls_free( buffer );
  1063. return( mbedtls_to_psa_error( ret ) );
  1064. }
  1065. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1066. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1067. /** Retrieve all the publicly-accessible attributes of a key.
  1068. */
  1069. psa_status_t psa_get_key_attributes( mbedtls_svc_key_id_t key,
  1070. psa_key_attributes_t *attributes )
  1071. {
  1072. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1073. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1074. psa_key_slot_t *slot;
  1075. psa_reset_key_attributes( attributes );
  1076. status = psa_get_and_lock_key_slot_with_policy( key, &slot, 0, 0 );
  1077. if( status != PSA_SUCCESS )
  1078. return( status );
  1079. attributes->core = slot->attr;
  1080. attributes->core.flags &= ( MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY |
  1081. MBEDTLS_PSA_KA_MASK_DUAL_USE );
  1082. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1083. if( psa_get_se_driver_entry( slot->attr.lifetime ) != NULL )
  1084. psa_set_key_slot_number( attributes,
  1085. psa_key_slot_get_slot_number( slot ) );
  1086. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1087. switch( slot->attr.type )
  1088. {
  1089. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1090. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1091. case PSA_KEY_TYPE_RSA_KEY_PAIR:
  1092. case PSA_KEY_TYPE_RSA_PUBLIC_KEY:
  1093. /* TODO: reporting the public exponent for opaque keys
  1094. * is not yet implemented.
  1095. * https://github.com/ARMmbed/mbed-crypto/issues/216
  1096. */
  1097. if( ! psa_key_lifetime_is_external( slot->attr.lifetime ) )
  1098. {
  1099. mbedtls_rsa_context *rsa = NULL;
  1100. status = mbedtls_psa_rsa_load_representation(
  1101. slot->attr.type,
  1102. slot->key.data,
  1103. slot->key.bytes,
  1104. &rsa );
  1105. if( status != PSA_SUCCESS )
  1106. break;
  1107. status = psa_get_rsa_public_exponent( rsa,
  1108. attributes );
  1109. mbedtls_rsa_free( rsa );
  1110. mbedtls_free( rsa );
  1111. }
  1112. break;
  1113. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1114. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1115. default:
  1116. /* Nothing else to do. */
  1117. break;
  1118. }
  1119. if( status != PSA_SUCCESS )
  1120. psa_reset_key_attributes( attributes );
  1121. unlock_status = psa_unlock_key_slot( slot );
  1122. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1123. }
  1124. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1125. psa_status_t psa_get_key_slot_number(
  1126. const psa_key_attributes_t *attributes,
  1127. psa_key_slot_number_t *slot_number )
  1128. {
  1129. if( attributes->core.flags & MBEDTLS_PSA_KA_FLAG_HAS_SLOT_NUMBER )
  1130. {
  1131. *slot_number = attributes->slot_number;
  1132. return( PSA_SUCCESS );
  1133. }
  1134. else
  1135. return( PSA_ERROR_INVALID_ARGUMENT );
  1136. }
  1137. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1138. static psa_status_t psa_export_key_buffer_internal( const uint8_t *key_buffer,
  1139. size_t key_buffer_size,
  1140. uint8_t *data,
  1141. size_t data_size,
  1142. size_t *data_length )
  1143. {
  1144. if( key_buffer_size > data_size )
  1145. return( PSA_ERROR_BUFFER_TOO_SMALL );
  1146. memcpy( data, key_buffer, key_buffer_size );
  1147. memset( data + key_buffer_size, 0,
  1148. data_size - key_buffer_size );
  1149. *data_length = key_buffer_size;
  1150. return( PSA_SUCCESS );
  1151. }
  1152. psa_status_t psa_export_key_internal(
  1153. const psa_key_attributes_t *attributes,
  1154. const uint8_t *key_buffer, size_t key_buffer_size,
  1155. uint8_t *data, size_t data_size, size_t *data_length )
  1156. {
  1157. psa_key_type_t type = attributes->core.type;
  1158. if( key_type_is_raw_bytes( type ) ||
  1159. PSA_KEY_TYPE_IS_RSA( type ) ||
  1160. PSA_KEY_TYPE_IS_ECC( type ) )
  1161. {
  1162. return( psa_export_key_buffer_internal(
  1163. key_buffer, key_buffer_size,
  1164. data, data_size, data_length ) );
  1165. }
  1166. else
  1167. {
  1168. /* This shouldn't happen in the reference implementation, but
  1169. it is valid for a special-purpose implementation to omit
  1170. support for exporting certain key types. */
  1171. return( PSA_ERROR_NOT_SUPPORTED );
  1172. }
  1173. }
  1174. psa_status_t psa_export_key( mbedtls_svc_key_id_t key,
  1175. uint8_t *data,
  1176. size_t data_size,
  1177. size_t *data_length )
  1178. {
  1179. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1180. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1181. psa_key_slot_t *slot;
  1182. /* Reject a zero-length output buffer now, since this can never be a
  1183. * valid key representation. This way we know that data must be a valid
  1184. * pointer and we can do things like memset(data, ..., data_size). */
  1185. if( data_size == 0 )
  1186. return( PSA_ERROR_BUFFER_TOO_SMALL );
  1187. /* Set the key to empty now, so that even when there are errors, we always
  1188. * set data_length to a value between 0 and data_size. On error, setting
  1189. * the key to empty is a good choice because an empty key representation is
  1190. * unlikely to be accepted anywhere. */
  1191. *data_length = 0;
  1192. /* Export requires the EXPORT flag. There is an exception for public keys,
  1193. * which don't require any flag, but
  1194. * psa_get_and_lock_key_slot_with_policy() takes care of this.
  1195. */
  1196. status = psa_get_and_lock_key_slot_with_policy( key, &slot,
  1197. PSA_KEY_USAGE_EXPORT, 0 );
  1198. if( status != PSA_SUCCESS )
  1199. return( status );
  1200. psa_key_attributes_t attributes = {
  1201. .core = slot->attr
  1202. };
  1203. status = psa_driver_wrapper_export_key( &attributes,
  1204. slot->key.data, slot->key.bytes,
  1205. data, data_size, data_length );
  1206. unlock_status = psa_unlock_key_slot( slot );
  1207. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1208. }
  1209. psa_status_t psa_export_public_key_internal(
  1210. const psa_key_attributes_t *attributes,
  1211. const uint8_t *key_buffer,
  1212. size_t key_buffer_size,
  1213. uint8_t *data,
  1214. size_t data_size,
  1215. size_t *data_length )
  1216. {
  1217. psa_key_type_t type = attributes->core.type;
  1218. if( PSA_KEY_TYPE_IS_RSA( type ) || PSA_KEY_TYPE_IS_ECC( type ) )
  1219. {
  1220. if( PSA_KEY_TYPE_IS_PUBLIC_KEY( type ) )
  1221. {
  1222. /* Exporting public -> public */
  1223. return( psa_export_key_buffer_internal(
  1224. key_buffer, key_buffer_size,
  1225. data, data_size, data_length ) );
  1226. }
  1227. if( PSA_KEY_TYPE_IS_RSA( type ) )
  1228. {
  1229. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1230. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1231. return( mbedtls_psa_rsa_export_public_key( attributes,
  1232. key_buffer,
  1233. key_buffer_size,
  1234. data,
  1235. data_size,
  1236. data_length ) );
  1237. #else
  1238. /* We don't know how to convert a private RSA key to public. */
  1239. return( PSA_ERROR_NOT_SUPPORTED );
  1240. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1241. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1242. }
  1243. else
  1244. {
  1245. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  1246. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY)
  1247. return( mbedtls_psa_ecp_export_public_key( attributes,
  1248. key_buffer,
  1249. key_buffer_size,
  1250. data,
  1251. data_size,
  1252. data_length ) );
  1253. #else
  1254. /* We don't know how to convert a private ECC key to public */
  1255. return( PSA_ERROR_NOT_SUPPORTED );
  1256. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  1257. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) */
  1258. }
  1259. }
  1260. else
  1261. {
  1262. /* This shouldn't happen in the reference implementation, but
  1263. it is valid for a special-purpose implementation to omit
  1264. support for exporting certain key types. */
  1265. return( PSA_ERROR_NOT_SUPPORTED );
  1266. }
  1267. }
  1268. psa_status_t psa_export_public_key( mbedtls_svc_key_id_t key,
  1269. uint8_t *data,
  1270. size_t data_size,
  1271. size_t *data_length )
  1272. {
  1273. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1274. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1275. psa_key_slot_t *slot;
  1276. /* Reject a zero-length output buffer now, since this can never be a
  1277. * valid key representation. This way we know that data must be a valid
  1278. * pointer and we can do things like memset(data, ..., data_size). */
  1279. if( data_size == 0 )
  1280. return( PSA_ERROR_BUFFER_TOO_SMALL );
  1281. /* Set the key to empty now, so that even when there are errors, we always
  1282. * set data_length to a value between 0 and data_size. On error, setting
  1283. * the key to empty is a good choice because an empty key representation is
  1284. * unlikely to be accepted anywhere. */
  1285. *data_length = 0;
  1286. /* Exporting a public key doesn't require a usage flag. */
  1287. status = psa_get_and_lock_key_slot_with_policy( key, &slot, 0, 0 );
  1288. if( status != PSA_SUCCESS )
  1289. return( status );
  1290. if( ! PSA_KEY_TYPE_IS_ASYMMETRIC( slot->attr.type ) )
  1291. {
  1292. status = PSA_ERROR_INVALID_ARGUMENT;
  1293. goto exit;
  1294. }
  1295. psa_key_attributes_t attributes = {
  1296. .core = slot->attr
  1297. };
  1298. status = psa_driver_wrapper_export_public_key(
  1299. &attributes, slot->key.data, slot->key.bytes,
  1300. data, data_size, data_length );
  1301. exit:
  1302. unlock_status = psa_unlock_key_slot( slot );
  1303. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1304. }
  1305. #if defined(static_assert)
  1306. static_assert( ( MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_DUAL_USE ) == 0,
  1307. "One or more key attribute flag is listed as both external-only and dual-use" );
  1308. static_assert( ( PSA_KA_MASK_INTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_DUAL_USE ) == 0,
  1309. "One or more key attribute flag is listed as both internal-only and dual-use" );
  1310. static_assert( ( PSA_KA_MASK_INTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY ) == 0,
  1311. "One or more key attribute flag is listed as both internal-only and external-only" );
  1312. #endif
  1313. /** Validate that a key policy is internally well-formed.
  1314. *
  1315. * This function only rejects invalid policies. It does not validate the
  1316. * consistency of the policy with respect to other attributes of the key
  1317. * such as the key type.
  1318. */
  1319. static psa_status_t psa_validate_key_policy( const psa_key_policy_t *policy )
  1320. {
  1321. if( ( policy->usage & ~( PSA_KEY_USAGE_EXPORT |
  1322. PSA_KEY_USAGE_COPY |
  1323. PSA_KEY_USAGE_ENCRYPT |
  1324. PSA_KEY_USAGE_DECRYPT |
  1325. PSA_KEY_USAGE_SIGN_MESSAGE |
  1326. PSA_KEY_USAGE_VERIFY_MESSAGE |
  1327. PSA_KEY_USAGE_SIGN_HASH |
  1328. PSA_KEY_USAGE_VERIFY_HASH |
  1329. PSA_KEY_USAGE_VERIFY_DERIVATION |
  1330. PSA_KEY_USAGE_DERIVE ) ) != 0 )
  1331. return( PSA_ERROR_INVALID_ARGUMENT );
  1332. return( PSA_SUCCESS );
  1333. }
  1334. /** Validate the internal consistency of key attributes.
  1335. *
  1336. * This function only rejects invalid attribute values. If does not
  1337. * validate the consistency of the attributes with any key data that may
  1338. * be involved in the creation of the key.
  1339. *
  1340. * Call this function early in the key creation process.
  1341. *
  1342. * \param[in] attributes Key attributes for the new key.
  1343. * \param[out] p_drv On any return, the driver for the key, if any.
  1344. * NULL for a transparent key.
  1345. *
  1346. */
  1347. static psa_status_t psa_validate_key_attributes(
  1348. const psa_key_attributes_t *attributes,
  1349. psa_se_drv_table_entry_t **p_drv )
  1350. {
  1351. psa_status_t status = PSA_ERROR_INVALID_ARGUMENT;
  1352. psa_key_lifetime_t lifetime = psa_get_key_lifetime( attributes );
  1353. mbedtls_svc_key_id_t key = psa_get_key_id( attributes );
  1354. status = psa_validate_key_location( lifetime, p_drv );
  1355. if( status != PSA_SUCCESS )
  1356. return( status );
  1357. status = psa_validate_key_persistence( lifetime );
  1358. if( status != PSA_SUCCESS )
  1359. return( status );
  1360. if ( PSA_KEY_LIFETIME_IS_VOLATILE( lifetime ) )
  1361. {
  1362. if( MBEDTLS_SVC_KEY_ID_GET_KEY_ID( key ) != 0 )
  1363. return( PSA_ERROR_INVALID_ARGUMENT );
  1364. }
  1365. else
  1366. {
  1367. if( !psa_is_valid_key_id( psa_get_key_id( attributes ), 0 ) )
  1368. return( PSA_ERROR_INVALID_ARGUMENT );
  1369. }
  1370. status = psa_validate_key_policy( &attributes->core.policy );
  1371. if( status != PSA_SUCCESS )
  1372. return( status );
  1373. /* Refuse to create overly large keys.
  1374. * Note that this doesn't trigger on import if the attributes don't
  1375. * explicitly specify a size (so psa_get_key_bits returns 0), so
  1376. * psa_import_key() needs its own checks. */
  1377. if( psa_get_key_bits( attributes ) > PSA_MAX_KEY_BITS )
  1378. return( PSA_ERROR_NOT_SUPPORTED );
  1379. /* Reject invalid flags. These should not be reachable through the API. */
  1380. if( attributes->core.flags & ~ ( MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY |
  1381. MBEDTLS_PSA_KA_MASK_DUAL_USE ) )
  1382. return( PSA_ERROR_INVALID_ARGUMENT );
  1383. return( PSA_SUCCESS );
  1384. }
  1385. /** Prepare a key slot to receive key material.
  1386. *
  1387. * This function allocates a key slot and sets its metadata.
  1388. *
  1389. * If this function fails, call psa_fail_key_creation().
  1390. *
  1391. * This function is intended to be used as follows:
  1392. * -# Call psa_start_key_creation() to allocate a key slot, prepare
  1393. * it with the specified attributes, and in case of a volatile key assign it
  1394. * a volatile key identifier.
  1395. * -# Populate the slot with the key material.
  1396. * -# Call psa_finish_key_creation() to finalize the creation of the slot.
  1397. * In case of failure at any step, stop the sequence and call
  1398. * psa_fail_key_creation().
  1399. *
  1400. * On success, the key slot is locked. It is the responsibility of the caller
  1401. * to unlock the key slot when it does not access it anymore.
  1402. *
  1403. * \param method An identification of the calling function.
  1404. * \param[in] attributes Key attributes for the new key.
  1405. * \param[out] p_slot On success, a pointer to the prepared slot.
  1406. * \param[out] p_drv On any return, the driver for the key, if any.
  1407. * NULL for a transparent key.
  1408. *
  1409. * \retval #PSA_SUCCESS
  1410. * The key slot is ready to receive key material.
  1411. * \return If this function fails, the key slot is an invalid state.
  1412. * You must call psa_fail_key_creation() to wipe and free the slot.
  1413. */
  1414. static psa_status_t psa_start_key_creation(
  1415. psa_key_creation_method_t method,
  1416. const psa_key_attributes_t *attributes,
  1417. psa_key_slot_t **p_slot,
  1418. psa_se_drv_table_entry_t **p_drv )
  1419. {
  1420. psa_status_t status;
  1421. psa_key_id_t volatile_key_id;
  1422. psa_key_slot_t *slot;
  1423. (void) method;
  1424. *p_drv = NULL;
  1425. status = psa_validate_key_attributes( attributes, p_drv );
  1426. if( status != PSA_SUCCESS )
  1427. return( status );
  1428. status = psa_get_empty_key_slot( &volatile_key_id, p_slot );
  1429. if( status != PSA_SUCCESS )
  1430. return( status );
  1431. slot = *p_slot;
  1432. /* We're storing the declared bit-size of the key. It's up to each
  1433. * creation mechanism to verify that this information is correct.
  1434. * It's automatically correct for mechanisms that use the bit-size as
  1435. * an input (generate, device) but not for those where the bit-size
  1436. * is optional (import, copy). In case of a volatile key, assign it the
  1437. * volatile key identifier associated to the slot returned to contain its
  1438. * definition. */
  1439. slot->attr = attributes->core;
  1440. if( PSA_KEY_LIFETIME_IS_VOLATILE( slot->attr.lifetime ) )
  1441. {
  1442. #if !defined(MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER)
  1443. slot->attr.id = volatile_key_id;
  1444. #else
  1445. slot->attr.id.key_id = volatile_key_id;
  1446. #endif
  1447. }
  1448. /* Erase external-only flags from the internal copy. To access
  1449. * external-only flags, query `attributes`. Thanks to the check
  1450. * in psa_validate_key_attributes(), this leaves the dual-use
  1451. * flags and any internal flag that psa_get_empty_key_slot()
  1452. * may have set. */
  1453. slot->attr.flags &= ~MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY;
  1454. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1455. /* For a key in a secure element, we need to do three things
  1456. * when creating or registering a persistent key:
  1457. * create the key file in internal storage, create the
  1458. * key inside the secure element, and update the driver's
  1459. * persistent data. This is done by starting a transaction that will
  1460. * encompass these three actions.
  1461. * For registering a volatile key, we just need to find an appropriate
  1462. * slot number inside the SE. Since the key is designated volatile, creating
  1463. * a transaction is not required. */
  1464. /* The first thing to do is to find a slot number for the new key.
  1465. * We save the slot number in persistent storage as part of the
  1466. * transaction data. It will be needed to recover if the power
  1467. * fails during the key creation process, to clean up on the secure
  1468. * element side after restarting. Obtaining a slot number from the
  1469. * secure element driver updates its persistent state, but we do not yet
  1470. * save the driver's persistent state, so that if the power fails,
  1471. * we can roll back to a state where the key doesn't exist. */
  1472. if( *p_drv != NULL )
  1473. {
  1474. psa_key_slot_number_t slot_number;
  1475. status = psa_find_se_slot_for_key( attributes, method, *p_drv,
  1476. &slot_number );
  1477. if( status != PSA_SUCCESS )
  1478. return( status );
  1479. if( ! PSA_KEY_LIFETIME_IS_VOLATILE( attributes->core.lifetime ) )
  1480. {
  1481. psa_crypto_prepare_transaction( PSA_CRYPTO_TRANSACTION_CREATE_KEY );
  1482. psa_crypto_transaction.key.lifetime = slot->attr.lifetime;
  1483. psa_crypto_transaction.key.slot = slot_number;
  1484. psa_crypto_transaction.key.id = slot->attr.id;
  1485. status = psa_crypto_save_transaction( );
  1486. if( status != PSA_SUCCESS )
  1487. {
  1488. (void) psa_crypto_stop_transaction( );
  1489. return( status );
  1490. }
  1491. }
  1492. status = psa_copy_key_material_into_slot(
  1493. slot, (uint8_t *)( &slot_number ), sizeof( slot_number ) );
  1494. }
  1495. if( *p_drv == NULL && method == PSA_KEY_CREATION_REGISTER )
  1496. {
  1497. /* Key registration only makes sense with a secure element. */
  1498. return( PSA_ERROR_INVALID_ARGUMENT );
  1499. }
  1500. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1501. return( PSA_SUCCESS );
  1502. }
  1503. /** Finalize the creation of a key once its key material has been set.
  1504. *
  1505. * This entails writing the key to persistent storage.
  1506. *
  1507. * If this function fails, call psa_fail_key_creation().
  1508. * See the documentation of psa_start_key_creation() for the intended use
  1509. * of this function.
  1510. *
  1511. * If the finalization succeeds, the function unlocks the key slot (it was
  1512. * locked by psa_start_key_creation()) and the key slot cannot be accessed
  1513. * anymore as part of the key creation process.
  1514. *
  1515. * \param[in,out] slot Pointer to the slot with key material.
  1516. * \param[in] driver The secure element driver for the key,
  1517. * or NULL for a transparent key.
  1518. * \param[out] key On success, identifier of the key. Note that the
  1519. * key identifier is also stored in the key slot.
  1520. *
  1521. * \retval #PSA_SUCCESS
  1522. * The key was successfully created.
  1523. * \retval #PSA_ERROR_INSUFFICIENT_MEMORY
  1524. * \retval #PSA_ERROR_INSUFFICIENT_STORAGE
  1525. * \retval #PSA_ERROR_ALREADY_EXISTS
  1526. * \retval #PSA_ERROR_DATA_INVALID
  1527. * \retval #PSA_ERROR_DATA_CORRUPT
  1528. * \retval #PSA_ERROR_STORAGE_FAILURE
  1529. *
  1530. * \return If this function fails, the key slot is an invalid state.
  1531. * You must call psa_fail_key_creation() to wipe and free the slot.
  1532. */
  1533. static psa_status_t psa_finish_key_creation(
  1534. psa_key_slot_t *slot,
  1535. psa_se_drv_table_entry_t *driver,
  1536. mbedtls_svc_key_id_t *key)
  1537. {
  1538. psa_status_t status = PSA_SUCCESS;
  1539. (void) slot;
  1540. (void) driver;
  1541. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C)
  1542. if( ! PSA_KEY_LIFETIME_IS_VOLATILE( slot->attr.lifetime ) )
  1543. {
  1544. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1545. if( driver != NULL )
  1546. {
  1547. psa_se_key_data_storage_t data;
  1548. psa_key_slot_number_t slot_number =
  1549. psa_key_slot_get_slot_number( slot ) ;
  1550. #if defined(static_assert)
  1551. static_assert( sizeof( slot_number ) ==
  1552. sizeof( data.slot_number ),
  1553. "Slot number size does not match psa_se_key_data_storage_t" );
  1554. #endif
  1555. memcpy( &data.slot_number, &slot_number, sizeof( slot_number ) );
  1556. status = psa_save_persistent_key( &slot->attr,
  1557. (uint8_t*) &data,
  1558. sizeof( data ) );
  1559. }
  1560. else
  1561. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1562. {
  1563. /* Key material is saved in export representation in the slot, so
  1564. * just pass the slot buffer for storage. */
  1565. status = psa_save_persistent_key( &slot->attr,
  1566. slot->key.data,
  1567. slot->key.bytes );
  1568. }
  1569. }
  1570. #endif /* defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) */
  1571. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1572. /* Finish the transaction for a key creation. This does not
  1573. * happen when registering an existing key. Detect this case
  1574. * by checking whether a transaction is in progress (actual
  1575. * creation of a persistent key in a secure element requires a transaction,
  1576. * but registration or volatile key creation doesn't use one). */
  1577. if( driver != NULL &&
  1578. psa_crypto_transaction.unknown.type == PSA_CRYPTO_TRANSACTION_CREATE_KEY )
  1579. {
  1580. status = psa_save_se_persistent_data( driver );
  1581. if( status != PSA_SUCCESS )
  1582. {
  1583. psa_destroy_persistent_key( slot->attr.id );
  1584. return( status );
  1585. }
  1586. status = psa_crypto_stop_transaction( );
  1587. }
  1588. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1589. if( status == PSA_SUCCESS )
  1590. {
  1591. *key = slot->attr.id;
  1592. status = psa_unlock_key_slot( slot );
  1593. if( status != PSA_SUCCESS )
  1594. *key = MBEDTLS_SVC_KEY_ID_INIT;
  1595. }
  1596. return( status );
  1597. }
  1598. /** Abort the creation of a key.
  1599. *
  1600. * You may call this function after calling psa_start_key_creation(),
  1601. * or after psa_finish_key_creation() fails. In other circumstances, this
  1602. * function may not clean up persistent storage.
  1603. * See the documentation of psa_start_key_creation() for the intended use
  1604. * of this function.
  1605. *
  1606. * \param[in,out] slot Pointer to the slot with key material.
  1607. * \param[in] driver The secure element driver for the key,
  1608. * or NULL for a transparent key.
  1609. */
  1610. static void psa_fail_key_creation( psa_key_slot_t *slot,
  1611. psa_se_drv_table_entry_t *driver )
  1612. {
  1613. (void) driver;
  1614. if( slot == NULL )
  1615. return;
  1616. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1617. /* TODO: If the key has already been created in the secure
  1618. * element, and the failure happened later (when saving metadata
  1619. * to internal storage), we need to destroy the key in the secure
  1620. * element.
  1621. * https://github.com/ARMmbed/mbed-crypto/issues/217
  1622. */
  1623. /* Abort the ongoing transaction if any (there may not be one if
  1624. * the creation process failed before starting one, or if the
  1625. * key creation is a registration of a key in a secure element).
  1626. * Earlier functions must already have done what it takes to undo any
  1627. * partial creation. All that's left is to update the transaction data
  1628. * itself. */
  1629. (void) psa_crypto_stop_transaction( );
  1630. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1631. psa_wipe_key_slot( slot );
  1632. }
  1633. /** Validate optional attributes during key creation.
  1634. *
  1635. * Some key attributes are optional during key creation. If they are
  1636. * specified in the attributes structure, check that they are consistent
  1637. * with the data in the slot.
  1638. *
  1639. * This function should be called near the end of key creation, after
  1640. * the slot in memory is fully populated but before saving persistent data.
  1641. */
  1642. static psa_status_t psa_validate_optional_attributes(
  1643. const psa_key_slot_t *slot,
  1644. const psa_key_attributes_t *attributes )
  1645. {
  1646. if( attributes->core.type != 0 )
  1647. {
  1648. if( attributes->core.type != slot->attr.type )
  1649. return( PSA_ERROR_INVALID_ARGUMENT );
  1650. }
  1651. if( attributes->domain_parameters_size != 0 )
  1652. {
  1653. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1654. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1655. if( PSA_KEY_TYPE_IS_RSA( slot->attr.type ) )
  1656. {
  1657. mbedtls_rsa_context *rsa = NULL;
  1658. mbedtls_mpi actual, required;
  1659. int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
  1660. psa_status_t status = mbedtls_psa_rsa_load_representation(
  1661. slot->attr.type,
  1662. slot->key.data,
  1663. slot->key.bytes,
  1664. &rsa );
  1665. if( status != PSA_SUCCESS )
  1666. return( status );
  1667. mbedtls_mpi_init( &actual );
  1668. mbedtls_mpi_init( &required );
  1669. ret = mbedtls_rsa_export( rsa,
  1670. NULL, NULL, NULL, NULL, &actual );
  1671. mbedtls_rsa_free( rsa );
  1672. mbedtls_free( rsa );
  1673. if( ret != 0 )
  1674. goto rsa_exit;
  1675. ret = mbedtls_mpi_read_binary( &required,
  1676. attributes->domain_parameters,
  1677. attributes->domain_parameters_size );
  1678. if( ret != 0 )
  1679. goto rsa_exit;
  1680. if( mbedtls_mpi_cmp_mpi( &actual, &required ) != 0 )
  1681. ret = MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
  1682. rsa_exit:
  1683. mbedtls_mpi_free( &actual );
  1684. mbedtls_mpi_free( &required );
  1685. if( ret != 0)
  1686. return( mbedtls_to_psa_error( ret ) );
  1687. }
  1688. else
  1689. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1690. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1691. {
  1692. return( PSA_ERROR_INVALID_ARGUMENT );
  1693. }
  1694. }
  1695. if( attributes->core.bits != 0 )
  1696. {
  1697. if( attributes->core.bits != slot->attr.bits )
  1698. return( PSA_ERROR_INVALID_ARGUMENT );
  1699. }
  1700. return( PSA_SUCCESS );
  1701. }
  1702. psa_status_t psa_import_key( const psa_key_attributes_t *attributes,
  1703. const uint8_t *data,
  1704. size_t data_length,
  1705. mbedtls_svc_key_id_t *key )
  1706. {
  1707. psa_status_t status;
  1708. psa_key_slot_t *slot = NULL;
  1709. psa_se_drv_table_entry_t *driver = NULL;
  1710. size_t bits;
  1711. size_t storage_size = data_length;
  1712. *key = MBEDTLS_SVC_KEY_ID_INIT;
  1713. /* Reject zero-length symmetric keys (including raw data key objects).
  1714. * This also rejects any key which might be encoded as an empty string,
  1715. * which is never valid. */
  1716. if( data_length == 0 )
  1717. return( PSA_ERROR_INVALID_ARGUMENT );
  1718. /* Ensure that the bytes-to-bits conversion cannot overflow. */
  1719. if( data_length > SIZE_MAX / 8 )
  1720. return( PSA_ERROR_NOT_SUPPORTED );
  1721. status = psa_start_key_creation( PSA_KEY_CREATION_IMPORT, attributes,
  1722. &slot, &driver );
  1723. if( status != PSA_SUCCESS )
  1724. goto exit;
  1725. /* In the case of a transparent key or an opaque key stored in local
  1726. * storage ( thus not in the case of importing a key in a secure element
  1727. * with storage ( MBEDTLS_PSA_CRYPTO_SE_C ) ),we have to allocate a
  1728. * buffer to hold the imported key material. */
  1729. if( slot->key.data == NULL )
  1730. {
  1731. if( psa_key_lifetime_is_external( attributes->core.lifetime ) )
  1732. {
  1733. status = psa_driver_wrapper_get_key_buffer_size_from_key_data(
  1734. attributes, data, data_length, &storage_size );
  1735. if( status != PSA_SUCCESS )
  1736. goto exit;
  1737. }
  1738. status = psa_allocate_buffer_to_slot( slot, storage_size );
  1739. if( status != PSA_SUCCESS )
  1740. goto exit;
  1741. }
  1742. bits = slot->attr.bits;
  1743. status = psa_driver_wrapper_import_key( attributes,
  1744. data, data_length,
  1745. slot->key.data,
  1746. slot->key.bytes,
  1747. &slot->key.bytes, &bits );
  1748. if( status != PSA_SUCCESS )
  1749. goto exit;
  1750. if( slot->attr.bits == 0 )
  1751. slot->attr.bits = (psa_key_bits_t) bits;
  1752. else if( bits != slot->attr.bits )
  1753. {
  1754. status = PSA_ERROR_INVALID_ARGUMENT;
  1755. goto exit;
  1756. }
  1757. /* Enforce a size limit, and in particular ensure that the bit
  1758. * size fits in its representation type.*/
  1759. if( bits > PSA_MAX_KEY_BITS )
  1760. {
  1761. status = PSA_ERROR_NOT_SUPPORTED;
  1762. goto exit;
  1763. }
  1764. status = psa_validate_optional_attributes( slot, attributes );
  1765. if( status != PSA_SUCCESS )
  1766. goto exit;
  1767. status = psa_finish_key_creation( slot, driver, key );
  1768. exit:
  1769. if( status != PSA_SUCCESS )
  1770. psa_fail_key_creation( slot, driver );
  1771. return( status );
  1772. }
  1773. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1774. psa_status_t mbedtls_psa_register_se_key(
  1775. const psa_key_attributes_t *attributes )
  1776. {
  1777. psa_status_t status;
  1778. psa_key_slot_t *slot = NULL;
  1779. psa_se_drv_table_entry_t *driver = NULL;
  1780. mbedtls_svc_key_id_t key = MBEDTLS_SVC_KEY_ID_INIT;
  1781. /* Leaving attributes unspecified is not currently supported.
  1782. * It could make sense to query the key type and size from the
  1783. * secure element, but not all secure elements support this
  1784. * and the driver HAL doesn't currently support it. */
  1785. if( psa_get_key_type( attributes ) == PSA_KEY_TYPE_NONE )
  1786. return( PSA_ERROR_NOT_SUPPORTED );
  1787. if( psa_get_key_bits( attributes ) == 0 )
  1788. return( PSA_ERROR_NOT_SUPPORTED );
  1789. status = psa_start_key_creation( PSA_KEY_CREATION_REGISTER, attributes,
  1790. &slot, &driver );
  1791. if( status != PSA_SUCCESS )
  1792. goto exit;
  1793. status = psa_finish_key_creation( slot, driver, &key );
  1794. exit:
  1795. if( status != PSA_SUCCESS )
  1796. psa_fail_key_creation( slot, driver );
  1797. /* Registration doesn't keep the key in RAM. */
  1798. psa_close_key( key );
  1799. return( status );
  1800. }
  1801. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1802. psa_status_t psa_copy_key( mbedtls_svc_key_id_t source_key,
  1803. const psa_key_attributes_t *specified_attributes,
  1804. mbedtls_svc_key_id_t *target_key )
  1805. {
  1806. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1807. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1808. psa_key_slot_t *source_slot = NULL;
  1809. psa_key_slot_t *target_slot = NULL;
  1810. psa_key_attributes_t actual_attributes = *specified_attributes;
  1811. psa_se_drv_table_entry_t *driver = NULL;
  1812. size_t storage_size = 0;
  1813. *target_key = MBEDTLS_SVC_KEY_ID_INIT;
  1814. status = psa_get_and_lock_key_slot_with_policy(
  1815. source_key, &source_slot, PSA_KEY_USAGE_COPY, 0 );
  1816. if( status != PSA_SUCCESS )
  1817. goto exit;
  1818. status = psa_validate_optional_attributes( source_slot,
  1819. specified_attributes );
  1820. if( status != PSA_SUCCESS )
  1821. goto exit;
  1822. /* The target key type and number of bits have been validated by
  1823. * psa_validate_optional_attributes() to be either equal to zero or
  1824. * equal to the ones of the source key. So it is safe to inherit
  1825. * them from the source key now."
  1826. * */
  1827. actual_attributes.core.bits = source_slot->attr.bits;
  1828. actual_attributes.core.type = source_slot->attr.type;
  1829. status = psa_restrict_key_policy( source_slot->attr.type,
  1830. &actual_attributes.core.policy,
  1831. &source_slot->attr.policy );
  1832. if( status != PSA_SUCCESS )
  1833. goto exit;
  1834. status = psa_start_key_creation( PSA_KEY_CREATION_COPY, &actual_attributes,
  1835. &target_slot, &driver );
  1836. if( status != PSA_SUCCESS )
  1837. goto exit;
  1838. if( PSA_KEY_LIFETIME_GET_LOCATION( target_slot->attr.lifetime ) !=
  1839. PSA_KEY_LIFETIME_GET_LOCATION( source_slot->attr.lifetime ) )
  1840. {
  1841. /*
  1842. * If the source and target keys are stored in different locations,
  1843. * the source key would need to be exported as plaintext and re-imported
  1844. * in the other location. This has security implications which have not
  1845. * been fully mapped. For now, this can be achieved through
  1846. * appropriate API invocations from the application, if needed.
  1847. * */
  1848. status = PSA_ERROR_NOT_SUPPORTED;
  1849. goto exit;
  1850. }
  1851. /*
  1852. * When the source and target keys are within the same location,
  1853. * - For transparent keys it is a blind copy without any driver invocation,
  1854. * - For opaque keys this translates to an invocation of the drivers'
  1855. * copy_key entry point through the dispatch layer.
  1856. * */
  1857. if( psa_key_lifetime_is_external( actual_attributes.core.lifetime ) )
  1858. {
  1859. status = psa_driver_wrapper_get_key_buffer_size( &actual_attributes,
  1860. &storage_size );
  1861. if( status != PSA_SUCCESS )
  1862. goto exit;
  1863. status = psa_allocate_buffer_to_slot( target_slot, storage_size );
  1864. if( status != PSA_SUCCESS )
  1865. goto exit;
  1866. status = psa_driver_wrapper_copy_key( &actual_attributes,
  1867. source_slot->key.data,
  1868. source_slot->key.bytes,
  1869. target_slot->key.data,
  1870. target_slot->key.bytes,
  1871. &target_slot->key.bytes );
  1872. if( status != PSA_SUCCESS )
  1873. goto exit;
  1874. }
  1875. else
  1876. {
  1877. status = psa_copy_key_material_into_slot( target_slot,
  1878. source_slot->key.data,
  1879. source_slot->key.bytes );
  1880. if( status != PSA_SUCCESS )
  1881. goto exit;
  1882. }
  1883. status = psa_finish_key_creation( target_slot, driver, target_key );
  1884. exit:
  1885. if( status != PSA_SUCCESS )
  1886. psa_fail_key_creation( target_slot, driver );
  1887. unlock_status = psa_unlock_key_slot( source_slot );
  1888. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1889. }
  1890. /****************************************************************/
  1891. /* Message digests */
  1892. /****************************************************************/
  1893. psa_status_t psa_hash_abort( psa_hash_operation_t *operation )
  1894. {
  1895. /* Aborting a non-active operation is allowed */
  1896. if( operation->id == 0 )
  1897. return( PSA_SUCCESS );
  1898. psa_status_t status = psa_driver_wrapper_hash_abort( operation );
  1899. operation->id = 0;
  1900. return( status );
  1901. }
  1902. psa_status_t psa_hash_setup( psa_hash_operation_t *operation,
  1903. psa_algorithm_t alg )
  1904. {
  1905. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1906. /* A context must be freshly initialized before it can be set up. */
  1907. if( operation->id != 0 )
  1908. {
  1909. status = PSA_ERROR_BAD_STATE;
  1910. goto exit;
  1911. }
  1912. if( !PSA_ALG_IS_HASH( alg ) )
  1913. {
  1914. status = PSA_ERROR_INVALID_ARGUMENT;
  1915. goto exit;
  1916. }
  1917. /* Ensure all of the context is zeroized, since PSA_HASH_OPERATION_INIT only
  1918. * directly zeroes the int-sized dummy member of the context union. */
  1919. memset( &operation->ctx, 0, sizeof( operation->ctx ) );
  1920. status = psa_driver_wrapper_hash_setup( operation, alg );
  1921. exit:
  1922. if( status != PSA_SUCCESS )
  1923. psa_hash_abort( operation );
  1924. return status;
  1925. }
  1926. psa_status_t psa_hash_update( psa_hash_operation_t *operation,
  1927. const uint8_t *input,
  1928. size_t input_length )
  1929. {
  1930. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1931. if( operation->id == 0 )
  1932. {
  1933. status = PSA_ERROR_BAD_STATE;
  1934. goto exit;
  1935. }
  1936. /* Don't require hash implementations to behave correctly on a
  1937. * zero-length input, which may have an invalid pointer. */
  1938. if( input_length == 0 )
  1939. return( PSA_SUCCESS );
  1940. status = psa_driver_wrapper_hash_update( operation, input, input_length );
  1941. exit:
  1942. if( status != PSA_SUCCESS )
  1943. psa_hash_abort( operation );
  1944. return( status );
  1945. }
  1946. psa_status_t psa_hash_finish( psa_hash_operation_t *operation,
  1947. uint8_t *hash,
  1948. size_t hash_size,
  1949. size_t *hash_length )
  1950. {
  1951. *hash_length = 0;
  1952. if( operation->id == 0 )
  1953. return( PSA_ERROR_BAD_STATE );
  1954. psa_status_t status = psa_driver_wrapper_hash_finish(
  1955. operation, hash, hash_size, hash_length );
  1956. psa_hash_abort( operation );
  1957. return( status );
  1958. }
  1959. psa_status_t psa_hash_verify( psa_hash_operation_t *operation,
  1960. const uint8_t *hash,
  1961. size_t hash_length )
  1962. {
  1963. uint8_t actual_hash[MBEDTLS_MD_MAX_SIZE];
  1964. size_t actual_hash_length;
  1965. psa_status_t status = psa_hash_finish(
  1966. operation,
  1967. actual_hash, sizeof( actual_hash ),
  1968. &actual_hash_length );
  1969. if( status != PSA_SUCCESS )
  1970. goto exit;
  1971. if( actual_hash_length != hash_length )
  1972. {
  1973. status = PSA_ERROR_INVALID_SIGNATURE;
  1974. goto exit;
  1975. }
  1976. if( mbedtls_psa_safer_memcmp( hash, actual_hash, actual_hash_length ) != 0 )
  1977. status = PSA_ERROR_INVALID_SIGNATURE;
  1978. exit:
  1979. if( status != PSA_SUCCESS )
  1980. psa_hash_abort(operation);
  1981. return( status );
  1982. }
  1983. psa_status_t psa_hash_compute( psa_algorithm_t alg,
  1984. const uint8_t *input, size_t input_length,
  1985. uint8_t *hash, size_t hash_size,
  1986. size_t *hash_length )
  1987. {
  1988. *hash_length = 0;
  1989. if( !PSA_ALG_IS_HASH( alg ) )
  1990. return( PSA_ERROR_INVALID_ARGUMENT );
  1991. return( psa_driver_wrapper_hash_compute( alg, input, input_length,
  1992. hash, hash_size, hash_length ) );
  1993. }
  1994. psa_status_t psa_hash_compare( psa_algorithm_t alg,
  1995. const uint8_t *input, size_t input_length,
  1996. const uint8_t *hash, size_t hash_length )
  1997. {
  1998. uint8_t actual_hash[MBEDTLS_MD_MAX_SIZE];
  1999. size_t actual_hash_length;
  2000. if( !PSA_ALG_IS_HASH( alg ) )
  2001. return( PSA_ERROR_INVALID_ARGUMENT );
  2002. psa_status_t status = psa_driver_wrapper_hash_compute(
  2003. alg, input, input_length,
  2004. actual_hash, sizeof(actual_hash),
  2005. &actual_hash_length );
  2006. if( status != PSA_SUCCESS )
  2007. return( status );
  2008. if( actual_hash_length != hash_length )
  2009. return( PSA_ERROR_INVALID_SIGNATURE );
  2010. if( mbedtls_psa_safer_memcmp( hash, actual_hash, actual_hash_length ) != 0 )
  2011. return( PSA_ERROR_INVALID_SIGNATURE );
  2012. return( PSA_SUCCESS );
  2013. }
  2014. psa_status_t psa_hash_clone( const psa_hash_operation_t *source_operation,
  2015. psa_hash_operation_t *target_operation )
  2016. {
  2017. if( source_operation->id == 0 ||
  2018. target_operation->id != 0 )
  2019. {
  2020. return( PSA_ERROR_BAD_STATE );
  2021. }
  2022. psa_status_t status = psa_driver_wrapper_hash_clone( source_operation,
  2023. target_operation );
  2024. if( status != PSA_SUCCESS )
  2025. psa_hash_abort( target_operation );
  2026. return( status );
  2027. }
  2028. /****************************************************************/
  2029. /* MAC */
  2030. /****************************************************************/
  2031. psa_status_t psa_mac_abort( psa_mac_operation_t *operation )
  2032. {
  2033. /* Aborting a non-active operation is allowed */
  2034. if( operation->id == 0 )
  2035. return( PSA_SUCCESS );
  2036. psa_status_t status = psa_driver_wrapper_mac_abort( operation );
  2037. operation->mac_size = 0;
  2038. operation->is_sign = 0;
  2039. operation->id = 0;
  2040. return( status );
  2041. }
  2042. static psa_status_t psa_mac_finalize_alg_and_key_validation(
  2043. psa_algorithm_t alg,
  2044. const psa_key_attributes_t *attributes,
  2045. uint8_t *mac_size )
  2046. {
  2047. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2048. psa_key_type_t key_type = psa_get_key_type( attributes );
  2049. size_t key_bits = psa_get_key_bits( attributes );
  2050. if( ! PSA_ALG_IS_MAC( alg ) )
  2051. return( PSA_ERROR_INVALID_ARGUMENT );
  2052. /* Validate the combination of key type and algorithm */
  2053. status = psa_mac_key_can_do( alg, key_type );
  2054. if( status != PSA_SUCCESS )
  2055. return( status );
  2056. /* Get the output length for the algorithm and key combination */
  2057. *mac_size = PSA_MAC_LENGTH( key_type, key_bits, alg );
  2058. if( *mac_size < 4 )
  2059. {
  2060. /* A very short MAC is too short for security since it can be
  2061. * brute-forced. Ancient protocols with 32-bit MACs do exist,
  2062. * so we make this our minimum, even though 32 bits is still
  2063. * too small for security. */
  2064. return( PSA_ERROR_NOT_SUPPORTED );
  2065. }
  2066. if( *mac_size > PSA_MAC_LENGTH( key_type, key_bits,
  2067. PSA_ALG_FULL_LENGTH_MAC( alg ) ) )
  2068. {
  2069. /* It's impossible to "truncate" to a larger length than the full length
  2070. * of the algorithm. */
  2071. return( PSA_ERROR_INVALID_ARGUMENT );
  2072. }
  2073. return( PSA_SUCCESS );
  2074. }
  2075. static psa_status_t psa_mac_setup( psa_mac_operation_t *operation,
  2076. mbedtls_svc_key_id_t key,
  2077. psa_algorithm_t alg,
  2078. int is_sign )
  2079. {
  2080. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2081. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2082. psa_key_slot_t *slot = NULL;
  2083. /* A context must be freshly initialized before it can be set up. */
  2084. if( operation->id != 0 )
  2085. {
  2086. status = PSA_ERROR_BAD_STATE;
  2087. goto exit;
  2088. }
  2089. status = psa_get_and_lock_key_slot_with_policy(
  2090. key,
  2091. &slot,
  2092. is_sign ? PSA_KEY_USAGE_SIGN_MESSAGE : PSA_KEY_USAGE_VERIFY_MESSAGE,
  2093. alg );
  2094. if( status != PSA_SUCCESS )
  2095. goto exit;
  2096. psa_key_attributes_t attributes = {
  2097. .core = slot->attr
  2098. };
  2099. status = psa_mac_finalize_alg_and_key_validation( alg, &attributes,
  2100. &operation->mac_size );
  2101. if( status != PSA_SUCCESS )
  2102. goto exit;
  2103. operation->is_sign = is_sign;
  2104. /* Dispatch the MAC setup call with validated input */
  2105. if( is_sign )
  2106. {
  2107. status = psa_driver_wrapper_mac_sign_setup( operation,
  2108. &attributes,
  2109. slot->key.data,
  2110. slot->key.bytes,
  2111. alg );
  2112. }
  2113. else
  2114. {
  2115. status = psa_driver_wrapper_mac_verify_setup( operation,
  2116. &attributes,
  2117. slot->key.data,
  2118. slot->key.bytes,
  2119. alg );
  2120. }
  2121. exit:
  2122. if( status != PSA_SUCCESS )
  2123. psa_mac_abort( operation );
  2124. unlock_status = psa_unlock_key_slot( slot );
  2125. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2126. }
  2127. psa_status_t psa_mac_sign_setup( psa_mac_operation_t *operation,
  2128. mbedtls_svc_key_id_t key,
  2129. psa_algorithm_t alg )
  2130. {
  2131. return( psa_mac_setup( operation, key, alg, 1 ) );
  2132. }
  2133. psa_status_t psa_mac_verify_setup( psa_mac_operation_t *operation,
  2134. mbedtls_svc_key_id_t key,
  2135. psa_algorithm_t alg )
  2136. {
  2137. return( psa_mac_setup( operation, key, alg, 0 ) );
  2138. }
  2139. psa_status_t psa_mac_update( psa_mac_operation_t *operation,
  2140. const uint8_t *input,
  2141. size_t input_length )
  2142. {
  2143. if( operation->id == 0 )
  2144. return( PSA_ERROR_BAD_STATE );
  2145. /* Don't require hash implementations to behave correctly on a
  2146. * zero-length input, which may have an invalid pointer. */
  2147. if( input_length == 0 )
  2148. return( PSA_SUCCESS );
  2149. psa_status_t status = psa_driver_wrapper_mac_update( operation,
  2150. input, input_length );
  2151. if( status != PSA_SUCCESS )
  2152. psa_mac_abort( operation );
  2153. return( status );
  2154. }
  2155. psa_status_t psa_mac_sign_finish( psa_mac_operation_t *operation,
  2156. uint8_t *mac,
  2157. size_t mac_size,
  2158. size_t *mac_length )
  2159. {
  2160. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2161. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  2162. if( operation->id == 0 )
  2163. {
  2164. status = PSA_ERROR_BAD_STATE;
  2165. goto exit;
  2166. }
  2167. if( ! operation->is_sign )
  2168. {
  2169. status = PSA_ERROR_BAD_STATE;
  2170. goto exit;
  2171. }
  2172. /* Sanity check. This will guarantee that mac_size != 0 (and so mac != NULL)
  2173. * once all the error checks are done. */
  2174. if( operation->mac_size == 0 )
  2175. {
  2176. status = PSA_ERROR_BAD_STATE;
  2177. goto exit;
  2178. }
  2179. if( mac_size < operation->mac_size )
  2180. {
  2181. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2182. goto exit;
  2183. }
  2184. status = psa_driver_wrapper_mac_sign_finish( operation,
  2185. mac, operation->mac_size,
  2186. mac_length );
  2187. exit:
  2188. /* In case of success, set the potential excess room in the output buffer
  2189. * to an invalid value, to avoid potentially leaking a longer MAC.
  2190. * In case of error, set the output length and content to a safe default,
  2191. * such that in case the caller misses an error check, the output would be
  2192. * an unachievable MAC.
  2193. */
  2194. if( status != PSA_SUCCESS )
  2195. {
  2196. *mac_length = mac_size;
  2197. operation->mac_size = 0;
  2198. }
  2199. if( mac_size > operation->mac_size )
  2200. memset( &mac[operation->mac_size], '!',
  2201. mac_size - operation->mac_size );
  2202. abort_status = psa_mac_abort( operation );
  2203. return( status == PSA_SUCCESS ? abort_status : status );
  2204. }
  2205. psa_status_t psa_mac_verify_finish( psa_mac_operation_t *operation,
  2206. const uint8_t *mac,
  2207. size_t mac_length )
  2208. {
  2209. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2210. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  2211. if( operation->id == 0 )
  2212. {
  2213. status = PSA_ERROR_BAD_STATE;
  2214. goto exit;
  2215. }
  2216. if( operation->is_sign )
  2217. {
  2218. status = PSA_ERROR_BAD_STATE;
  2219. goto exit;
  2220. }
  2221. if( operation->mac_size != mac_length )
  2222. {
  2223. status = PSA_ERROR_INVALID_SIGNATURE;
  2224. goto exit;
  2225. }
  2226. status = psa_driver_wrapper_mac_verify_finish( operation,
  2227. mac, mac_length );
  2228. exit:
  2229. abort_status = psa_mac_abort( operation );
  2230. return( status == PSA_SUCCESS ? abort_status : status );
  2231. }
  2232. static psa_status_t psa_mac_compute_internal( mbedtls_svc_key_id_t key,
  2233. psa_algorithm_t alg,
  2234. const uint8_t *input,
  2235. size_t input_length,
  2236. uint8_t *mac,
  2237. size_t mac_size,
  2238. size_t *mac_length,
  2239. int is_sign )
  2240. {
  2241. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2242. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2243. psa_key_slot_t *slot;
  2244. uint8_t operation_mac_size = 0;
  2245. status = psa_get_and_lock_key_slot_with_policy(
  2246. key,
  2247. &slot,
  2248. is_sign ? PSA_KEY_USAGE_SIGN_MESSAGE : PSA_KEY_USAGE_VERIFY_MESSAGE,
  2249. alg );
  2250. if( status != PSA_SUCCESS )
  2251. goto exit;
  2252. psa_key_attributes_t attributes = {
  2253. .core = slot->attr
  2254. };
  2255. status = psa_mac_finalize_alg_and_key_validation( alg, &attributes,
  2256. &operation_mac_size );
  2257. if( status != PSA_SUCCESS )
  2258. goto exit;
  2259. if( mac_size < operation_mac_size )
  2260. {
  2261. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2262. goto exit;
  2263. }
  2264. status = psa_driver_wrapper_mac_compute(
  2265. &attributes,
  2266. slot->key.data, slot->key.bytes,
  2267. alg,
  2268. input, input_length,
  2269. mac, operation_mac_size, mac_length );
  2270. exit:
  2271. /* In case of success, set the potential excess room in the output buffer
  2272. * to an invalid value, to avoid potentially leaking a longer MAC.
  2273. * In case of error, set the output length and content to a safe default,
  2274. * such that in case the caller misses an error check, the output would be
  2275. * an unachievable MAC.
  2276. */
  2277. if( status != PSA_SUCCESS )
  2278. {
  2279. *mac_length = mac_size;
  2280. operation_mac_size = 0;
  2281. }
  2282. if( mac_size > operation_mac_size )
  2283. memset( &mac[operation_mac_size], '!', mac_size - operation_mac_size );
  2284. unlock_status = psa_unlock_key_slot( slot );
  2285. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2286. }
  2287. psa_status_t psa_mac_compute( mbedtls_svc_key_id_t key,
  2288. psa_algorithm_t alg,
  2289. const uint8_t *input,
  2290. size_t input_length,
  2291. uint8_t *mac,
  2292. size_t mac_size,
  2293. size_t *mac_length)
  2294. {
  2295. return( psa_mac_compute_internal( key, alg,
  2296. input, input_length,
  2297. mac, mac_size, mac_length, 1 ) );
  2298. }
  2299. psa_status_t psa_mac_verify( mbedtls_svc_key_id_t key,
  2300. psa_algorithm_t alg,
  2301. const uint8_t *input,
  2302. size_t input_length,
  2303. const uint8_t *mac,
  2304. size_t mac_length)
  2305. {
  2306. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2307. uint8_t actual_mac[PSA_MAC_MAX_SIZE];
  2308. size_t actual_mac_length;
  2309. status = psa_mac_compute_internal( key, alg,
  2310. input, input_length,
  2311. actual_mac, sizeof( actual_mac ),
  2312. &actual_mac_length, 0 );
  2313. if( status != PSA_SUCCESS )
  2314. goto exit;
  2315. if( mac_length != actual_mac_length )
  2316. {
  2317. status = PSA_ERROR_INVALID_SIGNATURE;
  2318. goto exit;
  2319. }
  2320. if( mbedtls_psa_safer_memcmp( mac, actual_mac, actual_mac_length ) != 0 )
  2321. {
  2322. status = PSA_ERROR_INVALID_SIGNATURE;
  2323. goto exit;
  2324. }
  2325. exit:
  2326. mbedtls_platform_zeroize( actual_mac, sizeof( actual_mac ) );
  2327. return ( status );
  2328. }
  2329. /****************************************************************/
  2330. /* Asymmetric cryptography */
  2331. /****************************************************************/
  2332. static psa_status_t psa_sign_verify_check_alg( int input_is_message,
  2333. psa_algorithm_t alg )
  2334. {
  2335. if( input_is_message )
  2336. {
  2337. if( ! PSA_ALG_IS_SIGN_MESSAGE( alg ) )
  2338. return( PSA_ERROR_INVALID_ARGUMENT );
  2339. if ( PSA_ALG_IS_SIGN_HASH( alg ) )
  2340. {
  2341. if( ! PSA_ALG_IS_HASH( PSA_ALG_SIGN_GET_HASH( alg ) ) )
  2342. return( PSA_ERROR_INVALID_ARGUMENT );
  2343. }
  2344. }
  2345. else
  2346. {
  2347. if( ! PSA_ALG_IS_SIGN_HASH( alg ) )
  2348. return( PSA_ERROR_INVALID_ARGUMENT );
  2349. }
  2350. return( PSA_SUCCESS );
  2351. }
  2352. static psa_status_t psa_sign_internal( mbedtls_svc_key_id_t key,
  2353. int input_is_message,
  2354. psa_algorithm_t alg,
  2355. const uint8_t * input,
  2356. size_t input_length,
  2357. uint8_t * signature,
  2358. size_t signature_size,
  2359. size_t * signature_length )
  2360. {
  2361. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2362. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2363. psa_key_slot_t *slot;
  2364. *signature_length = 0;
  2365. status = psa_sign_verify_check_alg( input_is_message, alg );
  2366. if( status != PSA_SUCCESS )
  2367. return status;
  2368. /* Immediately reject a zero-length signature buffer. This guarantees
  2369. * that signature must be a valid pointer. (On the other hand, the input
  2370. * buffer can in principle be empty since it doesn't actually have
  2371. * to be a hash.) */
  2372. if( signature_size == 0 )
  2373. return( PSA_ERROR_BUFFER_TOO_SMALL );
  2374. status = psa_get_and_lock_key_slot_with_policy(
  2375. key, &slot,
  2376. input_is_message ? PSA_KEY_USAGE_SIGN_MESSAGE :
  2377. PSA_KEY_USAGE_SIGN_HASH,
  2378. alg );
  2379. if( status != PSA_SUCCESS )
  2380. goto exit;
  2381. if( ! PSA_KEY_TYPE_IS_KEY_PAIR( slot->attr.type ) )
  2382. {
  2383. status = PSA_ERROR_INVALID_ARGUMENT;
  2384. goto exit;
  2385. }
  2386. psa_key_attributes_t attributes = {
  2387. .core = slot->attr
  2388. };
  2389. if( input_is_message )
  2390. {
  2391. status = psa_driver_wrapper_sign_message(
  2392. &attributes, slot->key.data, slot->key.bytes,
  2393. alg, input, input_length,
  2394. signature, signature_size, signature_length );
  2395. }
  2396. else
  2397. {
  2398. status = psa_driver_wrapper_sign_hash(
  2399. &attributes, slot->key.data, slot->key.bytes,
  2400. alg, input, input_length,
  2401. signature, signature_size, signature_length );
  2402. }
  2403. exit:
  2404. /* Fill the unused part of the output buffer (the whole buffer on error,
  2405. * the trailing part on success) with something that isn't a valid signature
  2406. * (barring an attack on the signature and deliberately-crafted input),
  2407. * in case the caller doesn't check the return status properly. */
  2408. if( status == PSA_SUCCESS )
  2409. memset( signature + *signature_length, '!',
  2410. signature_size - *signature_length );
  2411. else
  2412. memset( signature, '!', signature_size );
  2413. /* If signature_size is 0 then we have nothing to do. We must not call
  2414. * memset because signature may be NULL in this case. */
  2415. unlock_status = psa_unlock_key_slot( slot );
  2416. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2417. }
  2418. static psa_status_t psa_verify_internal( mbedtls_svc_key_id_t key,
  2419. int input_is_message,
  2420. psa_algorithm_t alg,
  2421. const uint8_t * input,
  2422. size_t input_length,
  2423. const uint8_t * signature,
  2424. size_t signature_length )
  2425. {
  2426. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2427. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2428. psa_key_slot_t *slot;
  2429. status = psa_sign_verify_check_alg( input_is_message, alg );
  2430. if( status != PSA_SUCCESS )
  2431. return status;
  2432. status = psa_get_and_lock_key_slot_with_policy(
  2433. key, &slot,
  2434. input_is_message ? PSA_KEY_USAGE_VERIFY_MESSAGE :
  2435. PSA_KEY_USAGE_VERIFY_HASH,
  2436. alg );
  2437. if( status != PSA_SUCCESS )
  2438. return( status );
  2439. psa_key_attributes_t attributes = {
  2440. .core = slot->attr
  2441. };
  2442. if( input_is_message )
  2443. {
  2444. status = psa_driver_wrapper_verify_message(
  2445. &attributes, slot->key.data, slot->key.bytes,
  2446. alg, input, input_length,
  2447. signature, signature_length );
  2448. }
  2449. else
  2450. {
  2451. status = psa_driver_wrapper_verify_hash(
  2452. &attributes, slot->key.data, slot->key.bytes,
  2453. alg, input, input_length,
  2454. signature, signature_length );
  2455. }
  2456. unlock_status = psa_unlock_key_slot( slot );
  2457. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2458. }
  2459. psa_status_t psa_sign_message_builtin(
  2460. const psa_key_attributes_t *attributes,
  2461. const uint8_t *key_buffer,
  2462. size_t key_buffer_size,
  2463. psa_algorithm_t alg,
  2464. const uint8_t *input,
  2465. size_t input_length,
  2466. uint8_t *signature,
  2467. size_t signature_size,
  2468. size_t *signature_length )
  2469. {
  2470. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2471. if ( PSA_ALG_IS_SIGN_HASH( alg ) )
  2472. {
  2473. size_t hash_length;
  2474. uint8_t hash[PSA_HASH_MAX_SIZE];
  2475. status = psa_driver_wrapper_hash_compute(
  2476. PSA_ALG_SIGN_GET_HASH( alg ),
  2477. input, input_length,
  2478. hash, sizeof( hash ), &hash_length );
  2479. if( status != PSA_SUCCESS )
  2480. return status;
  2481. return psa_driver_wrapper_sign_hash(
  2482. attributes, key_buffer, key_buffer_size,
  2483. alg, hash, hash_length,
  2484. signature, signature_size, signature_length );
  2485. }
  2486. return( PSA_ERROR_NOT_SUPPORTED );
  2487. }
  2488. psa_status_t psa_sign_message( mbedtls_svc_key_id_t key,
  2489. psa_algorithm_t alg,
  2490. const uint8_t * input,
  2491. size_t input_length,
  2492. uint8_t * signature,
  2493. size_t signature_size,
  2494. size_t * signature_length )
  2495. {
  2496. return psa_sign_internal(
  2497. key, 1, alg, input, input_length,
  2498. signature, signature_size, signature_length );
  2499. }
  2500. psa_status_t psa_verify_message_builtin(
  2501. const psa_key_attributes_t *attributes,
  2502. const uint8_t *key_buffer,
  2503. size_t key_buffer_size,
  2504. psa_algorithm_t alg,
  2505. const uint8_t *input,
  2506. size_t input_length,
  2507. const uint8_t *signature,
  2508. size_t signature_length )
  2509. {
  2510. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2511. if ( PSA_ALG_IS_SIGN_HASH( alg ) )
  2512. {
  2513. size_t hash_length;
  2514. uint8_t hash[PSA_HASH_MAX_SIZE];
  2515. status = psa_driver_wrapper_hash_compute(
  2516. PSA_ALG_SIGN_GET_HASH( alg ),
  2517. input, input_length,
  2518. hash, sizeof( hash ), &hash_length );
  2519. if( status != PSA_SUCCESS )
  2520. return status;
  2521. return psa_driver_wrapper_verify_hash(
  2522. attributes, key_buffer, key_buffer_size,
  2523. alg, hash, hash_length,
  2524. signature, signature_length );
  2525. }
  2526. return( PSA_ERROR_NOT_SUPPORTED );
  2527. }
  2528. psa_status_t psa_verify_message( mbedtls_svc_key_id_t key,
  2529. psa_algorithm_t alg,
  2530. const uint8_t * input,
  2531. size_t input_length,
  2532. const uint8_t * signature,
  2533. size_t signature_length )
  2534. {
  2535. return psa_verify_internal(
  2536. key, 1, alg, input, input_length,
  2537. signature, signature_length );
  2538. }
  2539. psa_status_t psa_sign_hash_builtin(
  2540. const psa_key_attributes_t *attributes,
  2541. const uint8_t *key_buffer, size_t key_buffer_size,
  2542. psa_algorithm_t alg, const uint8_t *hash, size_t hash_length,
  2543. uint8_t *signature, size_t signature_size, size_t *signature_length )
  2544. {
  2545. if( attributes->core.type == PSA_KEY_TYPE_RSA_KEY_PAIR )
  2546. {
  2547. if( PSA_ALG_IS_RSA_PKCS1V15_SIGN( alg ) ||
  2548. PSA_ALG_IS_RSA_PSS( alg) )
  2549. {
  2550. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) || \
  2551. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS)
  2552. return( mbedtls_psa_rsa_sign_hash(
  2553. attributes,
  2554. key_buffer, key_buffer_size,
  2555. alg, hash, hash_length,
  2556. signature, signature_size, signature_length ) );
  2557. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) ||
  2558. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS) */
  2559. }
  2560. else
  2561. {
  2562. return( PSA_ERROR_INVALID_ARGUMENT );
  2563. }
  2564. }
  2565. else
  2566. if( PSA_KEY_TYPE_IS_ECC( attributes->core.type ) )
  2567. {
  2568. if( PSA_ALG_IS_ECDSA( alg ) )
  2569. {
  2570. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  2571. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  2572. return( mbedtls_psa_ecdsa_sign_hash(
  2573. attributes,
  2574. key_buffer, key_buffer_size,
  2575. alg, hash, hash_length,
  2576. signature, signature_size, signature_length ) );
  2577. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  2578. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  2579. }
  2580. else
  2581. {
  2582. return( PSA_ERROR_INVALID_ARGUMENT );
  2583. }
  2584. }
  2585. (void)key_buffer;
  2586. (void)key_buffer_size;
  2587. (void)hash;
  2588. (void)hash_length;
  2589. (void)signature;
  2590. (void)signature_size;
  2591. (void)signature_length;
  2592. return( PSA_ERROR_NOT_SUPPORTED );
  2593. }
  2594. psa_status_t psa_sign_hash( mbedtls_svc_key_id_t key,
  2595. psa_algorithm_t alg,
  2596. const uint8_t *hash,
  2597. size_t hash_length,
  2598. uint8_t *signature,
  2599. size_t signature_size,
  2600. size_t *signature_length )
  2601. {
  2602. return psa_sign_internal(
  2603. key, 0, alg, hash, hash_length,
  2604. signature, signature_size, signature_length );
  2605. }
  2606. psa_status_t psa_verify_hash_builtin(
  2607. const psa_key_attributes_t *attributes,
  2608. const uint8_t *key_buffer, size_t key_buffer_size,
  2609. psa_algorithm_t alg, const uint8_t *hash, size_t hash_length,
  2610. const uint8_t *signature, size_t signature_length )
  2611. {
  2612. if( PSA_KEY_TYPE_IS_RSA( attributes->core.type ) )
  2613. {
  2614. if( PSA_ALG_IS_RSA_PKCS1V15_SIGN( alg ) ||
  2615. PSA_ALG_IS_RSA_PSS( alg) )
  2616. {
  2617. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) || \
  2618. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS)
  2619. return( mbedtls_psa_rsa_verify_hash(
  2620. attributes,
  2621. key_buffer, key_buffer_size,
  2622. alg, hash, hash_length,
  2623. signature, signature_length ) );
  2624. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) ||
  2625. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS) */
  2626. }
  2627. else
  2628. {
  2629. return( PSA_ERROR_INVALID_ARGUMENT );
  2630. }
  2631. }
  2632. else
  2633. if( PSA_KEY_TYPE_IS_ECC( attributes->core.type ) )
  2634. {
  2635. if( PSA_ALG_IS_ECDSA( alg ) )
  2636. {
  2637. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  2638. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  2639. return( mbedtls_psa_ecdsa_verify_hash(
  2640. attributes,
  2641. key_buffer, key_buffer_size,
  2642. alg, hash, hash_length,
  2643. signature, signature_length ) );
  2644. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  2645. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  2646. }
  2647. else
  2648. {
  2649. return( PSA_ERROR_INVALID_ARGUMENT );
  2650. }
  2651. }
  2652. (void)key_buffer;
  2653. (void)key_buffer_size;
  2654. (void)hash;
  2655. (void)hash_length;
  2656. (void)signature;
  2657. (void)signature_length;
  2658. return( PSA_ERROR_NOT_SUPPORTED );
  2659. }
  2660. psa_status_t psa_verify_hash( mbedtls_svc_key_id_t key,
  2661. psa_algorithm_t alg,
  2662. const uint8_t *hash,
  2663. size_t hash_length,
  2664. const uint8_t *signature,
  2665. size_t signature_length )
  2666. {
  2667. return psa_verify_internal(
  2668. key, 0, alg, hash, hash_length,
  2669. signature, signature_length );
  2670. }
  2671. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2672. static int psa_rsa_oaep_set_padding_mode( psa_algorithm_t alg,
  2673. mbedtls_rsa_context *rsa )
  2674. {
  2675. psa_algorithm_t hash_alg = PSA_ALG_RSA_OAEP_GET_HASH( alg );
  2676. const mbedtls_md_info_t *md_info = mbedtls_md_info_from_psa( hash_alg );
  2677. mbedtls_md_type_t md_alg = mbedtls_md_get_type( md_info );
  2678. return( mbedtls_rsa_set_padding( rsa, MBEDTLS_RSA_PKCS_V21, md_alg ) );
  2679. }
  2680. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2681. psa_status_t psa_asymmetric_encrypt( mbedtls_svc_key_id_t key,
  2682. psa_algorithm_t alg,
  2683. const uint8_t *input,
  2684. size_t input_length,
  2685. const uint8_t *salt,
  2686. size_t salt_length,
  2687. uint8_t *output,
  2688. size_t output_size,
  2689. size_t *output_length )
  2690. {
  2691. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2692. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2693. psa_key_slot_t *slot;
  2694. (void) input;
  2695. (void) input_length;
  2696. (void) salt;
  2697. (void) output;
  2698. (void) output_size;
  2699. *output_length = 0;
  2700. if( ! PSA_ALG_IS_RSA_OAEP( alg ) && salt_length != 0 )
  2701. return( PSA_ERROR_INVALID_ARGUMENT );
  2702. status = psa_get_and_lock_transparent_key_slot_with_policy(
  2703. key, &slot, PSA_KEY_USAGE_ENCRYPT, alg );
  2704. if( status != PSA_SUCCESS )
  2705. return( status );
  2706. if( ! ( PSA_KEY_TYPE_IS_PUBLIC_KEY( slot->attr.type ) ||
  2707. PSA_KEY_TYPE_IS_KEY_PAIR( slot->attr.type ) ) )
  2708. {
  2709. status = PSA_ERROR_INVALID_ARGUMENT;
  2710. goto exit;
  2711. }
  2712. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) || \
  2713. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2714. if( PSA_KEY_TYPE_IS_RSA( slot->attr.type ) )
  2715. {
  2716. mbedtls_rsa_context *rsa = NULL;
  2717. status = mbedtls_psa_rsa_load_representation( slot->attr.type,
  2718. slot->key.data,
  2719. slot->key.bytes,
  2720. &rsa );
  2721. if( status != PSA_SUCCESS )
  2722. goto rsa_exit;
  2723. if( output_size < mbedtls_rsa_get_len( rsa ) )
  2724. {
  2725. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2726. goto rsa_exit;
  2727. }
  2728. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT)
  2729. if( alg == PSA_ALG_RSA_PKCS1V15_CRYPT )
  2730. {
  2731. status = mbedtls_to_psa_error(
  2732. mbedtls_rsa_pkcs1_encrypt( rsa,
  2733. mbedtls_psa_get_random,
  2734. MBEDTLS_PSA_RANDOM_STATE,
  2735. input_length,
  2736. input,
  2737. output ) );
  2738. }
  2739. else
  2740. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT */
  2741. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2742. if( PSA_ALG_IS_RSA_OAEP( alg ) )
  2743. {
  2744. status = mbedtls_to_psa_error(
  2745. psa_rsa_oaep_set_padding_mode( alg, rsa ) );
  2746. if( status != PSA_SUCCESS )
  2747. goto rsa_exit;
  2748. status = mbedtls_to_psa_error(
  2749. mbedtls_rsa_rsaes_oaep_encrypt( rsa,
  2750. mbedtls_psa_get_random,
  2751. MBEDTLS_PSA_RANDOM_STATE,
  2752. salt, salt_length,
  2753. input_length,
  2754. input,
  2755. output ) );
  2756. }
  2757. else
  2758. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP */
  2759. {
  2760. status = PSA_ERROR_INVALID_ARGUMENT;
  2761. goto rsa_exit;
  2762. }
  2763. rsa_exit:
  2764. if( status == PSA_SUCCESS )
  2765. *output_length = mbedtls_rsa_get_len( rsa );
  2766. mbedtls_rsa_free( rsa );
  2767. mbedtls_free( rsa );
  2768. }
  2769. else
  2770. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) ||
  2771. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2772. {
  2773. status = PSA_ERROR_NOT_SUPPORTED;
  2774. }
  2775. exit:
  2776. unlock_status = psa_unlock_key_slot( slot );
  2777. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2778. }
  2779. psa_status_t psa_asymmetric_decrypt( mbedtls_svc_key_id_t key,
  2780. psa_algorithm_t alg,
  2781. const uint8_t *input,
  2782. size_t input_length,
  2783. const uint8_t *salt,
  2784. size_t salt_length,
  2785. uint8_t *output,
  2786. size_t output_size,
  2787. size_t *output_length )
  2788. {
  2789. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2790. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2791. psa_key_slot_t *slot;
  2792. (void) input;
  2793. (void) input_length;
  2794. (void) salt;
  2795. (void) output;
  2796. (void) output_size;
  2797. *output_length = 0;
  2798. if( ! PSA_ALG_IS_RSA_OAEP( alg ) && salt_length != 0 )
  2799. return( PSA_ERROR_INVALID_ARGUMENT );
  2800. status = psa_get_and_lock_transparent_key_slot_with_policy(
  2801. key, &slot, PSA_KEY_USAGE_DECRYPT, alg );
  2802. if( status != PSA_SUCCESS )
  2803. return( status );
  2804. if( ! PSA_KEY_TYPE_IS_KEY_PAIR( slot->attr.type ) )
  2805. {
  2806. status = PSA_ERROR_INVALID_ARGUMENT;
  2807. goto exit;
  2808. }
  2809. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) || \
  2810. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2811. if( slot->attr.type == PSA_KEY_TYPE_RSA_KEY_PAIR )
  2812. {
  2813. mbedtls_rsa_context *rsa = NULL;
  2814. status = mbedtls_psa_rsa_load_representation( slot->attr.type,
  2815. slot->key.data,
  2816. slot->key.bytes,
  2817. &rsa );
  2818. if( status != PSA_SUCCESS )
  2819. goto exit;
  2820. if( input_length != mbedtls_rsa_get_len( rsa ) )
  2821. {
  2822. status = PSA_ERROR_INVALID_ARGUMENT;
  2823. goto rsa_exit;
  2824. }
  2825. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT)
  2826. if( alg == PSA_ALG_RSA_PKCS1V15_CRYPT )
  2827. {
  2828. status = mbedtls_to_psa_error(
  2829. mbedtls_rsa_pkcs1_decrypt( rsa,
  2830. mbedtls_psa_get_random,
  2831. MBEDTLS_PSA_RANDOM_STATE,
  2832. output_length,
  2833. input,
  2834. output,
  2835. output_size ) );
  2836. }
  2837. else
  2838. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT */
  2839. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2840. if( PSA_ALG_IS_RSA_OAEP( alg ) )
  2841. {
  2842. status = mbedtls_to_psa_error(
  2843. psa_rsa_oaep_set_padding_mode( alg, rsa ) );
  2844. if( status != PSA_SUCCESS )
  2845. goto rsa_exit;
  2846. status = mbedtls_to_psa_error(
  2847. mbedtls_rsa_rsaes_oaep_decrypt( rsa,
  2848. mbedtls_psa_get_random,
  2849. MBEDTLS_PSA_RANDOM_STATE,
  2850. salt, salt_length,
  2851. output_length,
  2852. input,
  2853. output,
  2854. output_size ) );
  2855. }
  2856. else
  2857. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP */
  2858. {
  2859. status = PSA_ERROR_INVALID_ARGUMENT;
  2860. }
  2861. rsa_exit:
  2862. mbedtls_rsa_free( rsa );
  2863. mbedtls_free( rsa );
  2864. }
  2865. else
  2866. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) ||
  2867. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2868. {
  2869. status = PSA_ERROR_NOT_SUPPORTED;
  2870. }
  2871. exit:
  2872. unlock_status = psa_unlock_key_slot( slot );
  2873. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2874. }
  2875. /****************************************************************/
  2876. /* Symmetric cryptography */
  2877. /****************************************************************/
  2878. static psa_status_t psa_cipher_setup( psa_cipher_operation_t *operation,
  2879. mbedtls_svc_key_id_t key,
  2880. psa_algorithm_t alg,
  2881. mbedtls_operation_t cipher_operation )
  2882. {
  2883. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2884. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2885. psa_key_slot_t *slot = NULL;
  2886. psa_key_usage_t usage = ( cipher_operation == MBEDTLS_ENCRYPT ?
  2887. PSA_KEY_USAGE_ENCRYPT :
  2888. PSA_KEY_USAGE_DECRYPT );
  2889. /* A context must be freshly initialized before it can be set up. */
  2890. if( operation->id != 0 )
  2891. {
  2892. status = PSA_ERROR_BAD_STATE;
  2893. goto exit;
  2894. }
  2895. if( ! PSA_ALG_IS_CIPHER( alg ) )
  2896. {
  2897. status = PSA_ERROR_INVALID_ARGUMENT;
  2898. goto exit;
  2899. }
  2900. status = psa_get_and_lock_key_slot_with_policy( key, &slot, usage, alg );
  2901. if( status != PSA_SUCCESS )
  2902. goto exit;
  2903. /* Initialize the operation struct members, except for id. The id member
  2904. * is used to indicate to psa_cipher_abort that there are resources to free,
  2905. * so we only set it (in the driver wrapper) after resources have been
  2906. * allocated/initialized. */
  2907. operation->iv_set = 0;
  2908. if( alg == PSA_ALG_ECB_NO_PADDING )
  2909. operation->iv_required = 0;
  2910. else
  2911. operation->iv_required = 1;
  2912. operation->default_iv_length = PSA_CIPHER_IV_LENGTH( slot->attr.type, alg );
  2913. psa_key_attributes_t attributes = {
  2914. .core = slot->attr
  2915. };
  2916. /* Try doing the operation through a driver before using software fallback. */
  2917. if( cipher_operation == MBEDTLS_ENCRYPT )
  2918. status = psa_driver_wrapper_cipher_encrypt_setup( operation,
  2919. &attributes,
  2920. slot->key.data,
  2921. slot->key.bytes,
  2922. alg );
  2923. else
  2924. status = psa_driver_wrapper_cipher_decrypt_setup( operation,
  2925. &attributes,
  2926. slot->key.data,
  2927. slot->key.bytes,
  2928. alg );
  2929. exit:
  2930. if( status != PSA_SUCCESS )
  2931. psa_cipher_abort( operation );
  2932. unlock_status = psa_unlock_key_slot( slot );
  2933. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2934. }
  2935. psa_status_t psa_cipher_encrypt_setup( psa_cipher_operation_t *operation,
  2936. mbedtls_svc_key_id_t key,
  2937. psa_algorithm_t alg )
  2938. {
  2939. return( psa_cipher_setup( operation, key, alg, MBEDTLS_ENCRYPT ) );
  2940. }
  2941. psa_status_t psa_cipher_decrypt_setup( psa_cipher_operation_t *operation,
  2942. mbedtls_svc_key_id_t key,
  2943. psa_algorithm_t alg )
  2944. {
  2945. return( psa_cipher_setup( operation, key, alg, MBEDTLS_DECRYPT ) );
  2946. }
  2947. psa_status_t psa_cipher_generate_iv( psa_cipher_operation_t *operation,
  2948. uint8_t *iv,
  2949. size_t iv_size,
  2950. size_t *iv_length )
  2951. {
  2952. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2953. *iv_length = 0;
  2954. if( operation->id == 0 )
  2955. {
  2956. status = PSA_ERROR_BAD_STATE;
  2957. goto exit;
  2958. }
  2959. if( operation->iv_set || ! operation->iv_required )
  2960. {
  2961. status = PSA_ERROR_BAD_STATE;
  2962. goto exit;
  2963. }
  2964. if( iv_size < operation->default_iv_length )
  2965. {
  2966. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2967. goto exit;
  2968. }
  2969. status = psa_generate_random( iv, operation->default_iv_length );
  2970. if( status != PSA_SUCCESS )
  2971. goto exit;
  2972. status = psa_driver_wrapper_cipher_set_iv( operation,
  2973. iv,
  2974. operation->default_iv_length );
  2975. exit:
  2976. if( status == PSA_SUCCESS )
  2977. {
  2978. operation->iv_set = 1;
  2979. *iv_length = operation->default_iv_length;
  2980. }
  2981. else
  2982. psa_cipher_abort( operation );
  2983. return( status );
  2984. }
  2985. psa_status_t psa_cipher_set_iv( psa_cipher_operation_t *operation,
  2986. const uint8_t *iv,
  2987. size_t iv_length )
  2988. {
  2989. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2990. if( operation->id == 0 )
  2991. {
  2992. status = PSA_ERROR_BAD_STATE;
  2993. goto exit;
  2994. }
  2995. if( operation->iv_set || ! operation->iv_required )
  2996. {
  2997. status = PSA_ERROR_BAD_STATE;
  2998. goto exit;
  2999. }
  3000. if( iv_length > PSA_CIPHER_IV_MAX_SIZE )
  3001. {
  3002. status = PSA_ERROR_INVALID_ARGUMENT;
  3003. goto exit;
  3004. }
  3005. status = psa_driver_wrapper_cipher_set_iv( operation,
  3006. iv,
  3007. iv_length );
  3008. exit:
  3009. if( status == PSA_SUCCESS )
  3010. operation->iv_set = 1;
  3011. else
  3012. psa_cipher_abort( operation );
  3013. return( status );
  3014. }
  3015. psa_status_t psa_cipher_update( psa_cipher_operation_t *operation,
  3016. const uint8_t *input,
  3017. size_t input_length,
  3018. uint8_t *output,
  3019. size_t output_size,
  3020. size_t *output_length )
  3021. {
  3022. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3023. if( operation->id == 0 )
  3024. {
  3025. status = PSA_ERROR_BAD_STATE;
  3026. goto exit;
  3027. }
  3028. if( operation->iv_required && ! operation->iv_set )
  3029. {
  3030. status = PSA_ERROR_BAD_STATE;
  3031. goto exit;
  3032. }
  3033. status = psa_driver_wrapper_cipher_update( operation,
  3034. input,
  3035. input_length,
  3036. output,
  3037. output_size,
  3038. output_length );
  3039. exit:
  3040. if( status != PSA_SUCCESS )
  3041. psa_cipher_abort( operation );
  3042. return( status );
  3043. }
  3044. psa_status_t psa_cipher_finish( psa_cipher_operation_t *operation,
  3045. uint8_t *output,
  3046. size_t output_size,
  3047. size_t *output_length )
  3048. {
  3049. psa_status_t status = PSA_ERROR_GENERIC_ERROR;
  3050. if( operation->id == 0 )
  3051. {
  3052. status = PSA_ERROR_BAD_STATE;
  3053. goto exit;
  3054. }
  3055. if( operation->iv_required && ! operation->iv_set )
  3056. {
  3057. status = PSA_ERROR_BAD_STATE;
  3058. goto exit;
  3059. }
  3060. status = psa_driver_wrapper_cipher_finish( operation,
  3061. output,
  3062. output_size,
  3063. output_length );
  3064. exit:
  3065. if( status == PSA_SUCCESS )
  3066. return( psa_cipher_abort( operation ) );
  3067. else
  3068. {
  3069. *output_length = 0;
  3070. (void) psa_cipher_abort( operation );
  3071. return( status );
  3072. }
  3073. }
  3074. psa_status_t psa_cipher_abort( psa_cipher_operation_t *operation )
  3075. {
  3076. if( operation->id == 0 )
  3077. {
  3078. /* The object has (apparently) been initialized but it is not (yet)
  3079. * in use. It's ok to call abort on such an object, and there's
  3080. * nothing to do. */
  3081. return( PSA_SUCCESS );
  3082. }
  3083. psa_driver_wrapper_cipher_abort( operation );
  3084. operation->id = 0;
  3085. operation->iv_set = 0;
  3086. operation->iv_required = 0;
  3087. return( PSA_SUCCESS );
  3088. }
  3089. psa_status_t psa_cipher_encrypt( mbedtls_svc_key_id_t key,
  3090. psa_algorithm_t alg,
  3091. const uint8_t *input,
  3092. size_t input_length,
  3093. uint8_t *output,
  3094. size_t output_size,
  3095. size_t *output_length )
  3096. {
  3097. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3098. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3099. psa_key_slot_t *slot;
  3100. psa_key_type_t key_type;
  3101. size_t iv_length;
  3102. *output_length = 0;
  3103. if( ! PSA_ALG_IS_CIPHER( alg ) )
  3104. return( PSA_ERROR_INVALID_ARGUMENT );
  3105. status = psa_get_and_lock_key_slot_with_policy( key, &slot,
  3106. PSA_KEY_USAGE_ENCRYPT,
  3107. alg );
  3108. if( status != PSA_SUCCESS )
  3109. return( status );
  3110. psa_key_attributes_t attributes = {
  3111. .core = slot->attr
  3112. };
  3113. key_type = slot->attr.type;
  3114. iv_length = PSA_CIPHER_IV_LENGTH( key_type, alg );
  3115. if( iv_length > 0 )
  3116. {
  3117. if( output_size < iv_length )
  3118. {
  3119. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3120. goto exit;
  3121. }
  3122. status = psa_generate_random( output, iv_length );
  3123. if( status != PSA_SUCCESS )
  3124. goto exit;
  3125. }
  3126. status = psa_driver_wrapper_cipher_encrypt(
  3127. &attributes, slot->key.data, slot->key.bytes,
  3128. alg, input, input_length,
  3129. output, output_size, output_length );
  3130. exit:
  3131. unlock_status = psa_unlock_key_slot( slot );
  3132. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  3133. }
  3134. psa_status_t psa_cipher_decrypt( mbedtls_svc_key_id_t key,
  3135. psa_algorithm_t alg,
  3136. const uint8_t *input,
  3137. size_t input_length,
  3138. uint8_t *output,
  3139. size_t output_size,
  3140. size_t *output_length )
  3141. {
  3142. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3143. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3144. psa_key_slot_t *slot;
  3145. *output_length = 0;
  3146. if( ! PSA_ALG_IS_CIPHER( alg ) )
  3147. return( PSA_ERROR_INVALID_ARGUMENT );
  3148. status = psa_get_and_lock_key_slot_with_policy( key, &slot,
  3149. PSA_KEY_USAGE_DECRYPT,
  3150. alg );
  3151. if( status != PSA_SUCCESS )
  3152. return( status );
  3153. psa_key_attributes_t attributes = {
  3154. .core = slot->attr
  3155. };
  3156. if( alg == PSA_ALG_CCM_STAR_NO_TAG && input_length < PSA_BLOCK_CIPHER_BLOCK_LENGTH( slot->attr.type ) )
  3157. {
  3158. status = PSA_ERROR_INVALID_ARGUMENT;
  3159. goto exit;
  3160. }
  3161. else if ( input_length < PSA_CIPHER_IV_LENGTH( slot->attr.type, alg ) )
  3162. {
  3163. status = PSA_ERROR_INVALID_ARGUMENT;
  3164. goto exit;
  3165. }
  3166. status = psa_driver_wrapper_cipher_decrypt(
  3167. &attributes, slot->key.data, slot->key.bytes,
  3168. alg, input, input_length,
  3169. output, output_size, output_length );
  3170. exit:
  3171. unlock_status = psa_unlock_key_slot( slot );
  3172. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  3173. }
  3174. /****************************************************************/
  3175. /* AEAD */
  3176. /****************************************************************/
  3177. /* Helper function to get the base algorithm from its variants. */
  3178. static psa_algorithm_t psa_aead_get_base_algorithm( psa_algorithm_t alg )
  3179. {
  3180. return PSA_ALG_AEAD_WITH_DEFAULT_LENGTH_TAG( alg );
  3181. }
  3182. /* Helper function to perform common nonce length checks. */
  3183. static psa_status_t psa_aead_check_nonce_length( psa_algorithm_t alg,
  3184. size_t nonce_length )
  3185. {
  3186. psa_algorithm_t base_alg = psa_aead_get_base_algorithm( alg );
  3187. switch(base_alg)
  3188. {
  3189. #if defined(PSA_WANT_ALG_GCM)
  3190. case PSA_ALG_GCM:
  3191. /* Not checking max nonce size here as GCM spec allows almost
  3192. * arbitrarily large nonces. Please note that we do not generally
  3193. * recommend the usage of nonces of greater length than
  3194. * PSA_AEAD_NONCE_MAX_SIZE, as large nonces are hashed to a shorter
  3195. * size, which can then lead to collisions if you encrypt a very
  3196. * large number of messages.*/
  3197. if( nonce_length != 0 )
  3198. return( PSA_SUCCESS );
  3199. break;
  3200. #endif /* PSA_WANT_ALG_GCM */
  3201. #if defined(PSA_WANT_ALG_CCM)
  3202. case PSA_ALG_CCM:
  3203. if( nonce_length >= 7 && nonce_length <= 13 )
  3204. return( PSA_SUCCESS );
  3205. break;
  3206. #endif /* PSA_WANT_ALG_CCM */
  3207. #if defined(PSA_WANT_ALG_CHACHA20_POLY1305)
  3208. case PSA_ALG_CHACHA20_POLY1305:
  3209. if( nonce_length == 12 )
  3210. return( PSA_SUCCESS );
  3211. else if( nonce_length == 8 )
  3212. return( PSA_ERROR_NOT_SUPPORTED );
  3213. break;
  3214. #endif /* PSA_WANT_ALG_CHACHA20_POLY1305 */
  3215. default:
  3216. return( PSA_ERROR_NOT_SUPPORTED );
  3217. }
  3218. return( PSA_ERROR_INVALID_ARGUMENT );
  3219. }
  3220. psa_status_t psa_aead_encrypt( mbedtls_svc_key_id_t key,
  3221. psa_algorithm_t alg,
  3222. const uint8_t *nonce,
  3223. size_t nonce_length,
  3224. const uint8_t *additional_data,
  3225. size_t additional_data_length,
  3226. const uint8_t *plaintext,
  3227. size_t plaintext_length,
  3228. uint8_t *ciphertext,
  3229. size_t ciphertext_size,
  3230. size_t *ciphertext_length )
  3231. {
  3232. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3233. psa_key_slot_t *slot;
  3234. *ciphertext_length = 0;
  3235. if( !PSA_ALG_IS_AEAD( alg ) || PSA_ALG_IS_WILDCARD( alg ) )
  3236. return( PSA_ERROR_NOT_SUPPORTED );
  3237. status = psa_get_and_lock_key_slot_with_policy(
  3238. key, &slot, PSA_KEY_USAGE_ENCRYPT, alg );
  3239. if( status != PSA_SUCCESS )
  3240. return( status );
  3241. psa_key_attributes_t attributes = {
  3242. .core = slot->attr
  3243. };
  3244. status = psa_aead_check_nonce_length( alg, nonce_length );
  3245. if( status != PSA_SUCCESS )
  3246. goto exit;
  3247. status = psa_driver_wrapper_aead_encrypt(
  3248. &attributes, slot->key.data, slot->key.bytes,
  3249. alg,
  3250. nonce, nonce_length,
  3251. additional_data, additional_data_length,
  3252. plaintext, plaintext_length,
  3253. ciphertext, ciphertext_size, ciphertext_length );
  3254. if( status != PSA_SUCCESS && ciphertext_size != 0 )
  3255. memset( ciphertext, 0, ciphertext_size );
  3256. exit:
  3257. psa_unlock_key_slot( slot );
  3258. return( status );
  3259. }
  3260. psa_status_t psa_aead_decrypt( mbedtls_svc_key_id_t key,
  3261. psa_algorithm_t alg,
  3262. const uint8_t *nonce,
  3263. size_t nonce_length,
  3264. const uint8_t *additional_data,
  3265. size_t additional_data_length,
  3266. const uint8_t *ciphertext,
  3267. size_t ciphertext_length,
  3268. uint8_t *plaintext,
  3269. size_t plaintext_size,
  3270. size_t *plaintext_length )
  3271. {
  3272. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3273. psa_key_slot_t *slot;
  3274. *plaintext_length = 0;
  3275. if( !PSA_ALG_IS_AEAD( alg ) || PSA_ALG_IS_WILDCARD( alg ) )
  3276. return( PSA_ERROR_NOT_SUPPORTED );
  3277. status = psa_get_and_lock_key_slot_with_policy(
  3278. key, &slot, PSA_KEY_USAGE_DECRYPT, alg );
  3279. if( status != PSA_SUCCESS )
  3280. return( status );
  3281. psa_key_attributes_t attributes = {
  3282. .core = slot->attr
  3283. };
  3284. status = psa_aead_check_nonce_length( alg, nonce_length );
  3285. if( status != PSA_SUCCESS )
  3286. goto exit;
  3287. status = psa_driver_wrapper_aead_decrypt(
  3288. &attributes, slot->key.data, slot->key.bytes,
  3289. alg,
  3290. nonce, nonce_length,
  3291. additional_data, additional_data_length,
  3292. ciphertext, ciphertext_length,
  3293. plaintext, plaintext_size, plaintext_length );
  3294. if( status != PSA_SUCCESS && plaintext_size != 0 )
  3295. memset( plaintext, 0, plaintext_size );
  3296. exit:
  3297. psa_unlock_key_slot( slot );
  3298. return( status );
  3299. }
  3300. /* Set the key for a multipart authenticated operation. */
  3301. static psa_status_t psa_aead_setup( psa_aead_operation_t *operation,
  3302. int is_encrypt,
  3303. mbedtls_svc_key_id_t key,
  3304. psa_algorithm_t alg )
  3305. {
  3306. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3307. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3308. psa_key_slot_t *slot = NULL;
  3309. psa_key_usage_t key_usage = 0;
  3310. if( !PSA_ALG_IS_AEAD( alg ) || PSA_ALG_IS_WILDCARD( alg ) )
  3311. {
  3312. status = PSA_ERROR_INVALID_ARGUMENT;
  3313. goto exit;
  3314. }
  3315. if( operation->id != 0 )
  3316. {
  3317. status = PSA_ERROR_BAD_STATE;
  3318. goto exit;
  3319. }
  3320. if( operation->nonce_set || operation->lengths_set ||
  3321. operation->ad_started || operation->body_started )
  3322. {
  3323. status = PSA_ERROR_BAD_STATE;
  3324. goto exit;
  3325. }
  3326. if( is_encrypt )
  3327. key_usage = PSA_KEY_USAGE_ENCRYPT;
  3328. else
  3329. key_usage = PSA_KEY_USAGE_DECRYPT;
  3330. status = psa_get_and_lock_key_slot_with_policy( key, &slot, key_usage,
  3331. alg );
  3332. if( status != PSA_SUCCESS )
  3333. goto exit;
  3334. psa_key_attributes_t attributes = {
  3335. .core = slot->attr
  3336. };
  3337. if( is_encrypt )
  3338. status = psa_driver_wrapper_aead_encrypt_setup( operation,
  3339. &attributes,
  3340. slot->key.data,
  3341. slot->key.bytes,
  3342. alg );
  3343. else
  3344. status = psa_driver_wrapper_aead_decrypt_setup( operation,
  3345. &attributes,
  3346. slot->key.data,
  3347. slot->key.bytes,
  3348. alg );
  3349. if( status != PSA_SUCCESS )
  3350. goto exit;
  3351. operation->key_type = psa_get_key_type( &attributes );
  3352. exit:
  3353. unlock_status = psa_unlock_key_slot( slot );
  3354. if( status == PSA_SUCCESS )
  3355. {
  3356. status = unlock_status;
  3357. operation->alg = psa_aead_get_base_algorithm( alg );
  3358. operation->is_encrypt = is_encrypt;
  3359. }
  3360. else
  3361. psa_aead_abort( operation );
  3362. return( status );
  3363. }
  3364. /* Set the key for a multipart authenticated encryption operation. */
  3365. psa_status_t psa_aead_encrypt_setup( psa_aead_operation_t *operation,
  3366. mbedtls_svc_key_id_t key,
  3367. psa_algorithm_t alg )
  3368. {
  3369. return( psa_aead_setup( operation, 1, key, alg ) );
  3370. }
  3371. /* Set the key for a multipart authenticated decryption operation. */
  3372. psa_status_t psa_aead_decrypt_setup( psa_aead_operation_t *operation,
  3373. mbedtls_svc_key_id_t key,
  3374. psa_algorithm_t alg )
  3375. {
  3376. return( psa_aead_setup( operation, 0, key, alg ) );
  3377. }
  3378. /* Generate a random nonce / IV for multipart AEAD operation */
  3379. psa_status_t psa_aead_generate_nonce( psa_aead_operation_t *operation,
  3380. uint8_t *nonce,
  3381. size_t nonce_size,
  3382. size_t *nonce_length )
  3383. {
  3384. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3385. size_t required_nonce_size;
  3386. *nonce_length = 0;
  3387. if( operation->id == 0 )
  3388. {
  3389. status = PSA_ERROR_BAD_STATE;
  3390. goto exit;
  3391. }
  3392. if( operation->nonce_set || !operation->is_encrypt )
  3393. {
  3394. status = PSA_ERROR_BAD_STATE;
  3395. goto exit;
  3396. }
  3397. required_nonce_size = PSA_AEAD_NONCE_LENGTH( operation->key_type,
  3398. operation->alg );
  3399. if( nonce_size < required_nonce_size )
  3400. {
  3401. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3402. goto exit;
  3403. }
  3404. status = psa_generate_random( nonce, required_nonce_size );
  3405. if( status != PSA_SUCCESS )
  3406. goto exit;
  3407. status = psa_aead_set_nonce( operation, nonce, required_nonce_size );
  3408. exit:
  3409. if( status == PSA_SUCCESS )
  3410. *nonce_length = required_nonce_size;
  3411. else
  3412. psa_aead_abort( operation );
  3413. return( status );
  3414. }
  3415. /* Set the nonce for a multipart authenticated encryption or decryption
  3416. operation.*/
  3417. psa_status_t psa_aead_set_nonce( psa_aead_operation_t *operation,
  3418. const uint8_t *nonce,
  3419. size_t nonce_length )
  3420. {
  3421. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3422. if( operation->id == 0 )
  3423. {
  3424. status = PSA_ERROR_BAD_STATE;
  3425. goto exit;
  3426. }
  3427. if( operation->nonce_set )
  3428. {
  3429. status = PSA_ERROR_BAD_STATE;
  3430. goto exit;
  3431. }
  3432. status = psa_aead_check_nonce_length( operation->alg, nonce_length );
  3433. if( status != PSA_SUCCESS )
  3434. {
  3435. status = PSA_ERROR_INVALID_ARGUMENT;
  3436. goto exit;
  3437. }
  3438. status = psa_driver_wrapper_aead_set_nonce( operation, nonce,
  3439. nonce_length );
  3440. exit:
  3441. if( status == PSA_SUCCESS )
  3442. operation->nonce_set = 1;
  3443. else
  3444. psa_aead_abort( operation );
  3445. return( status );
  3446. }
  3447. /* Declare the lengths of the message and additional data for multipart AEAD. */
  3448. psa_status_t psa_aead_set_lengths( psa_aead_operation_t *operation,
  3449. size_t ad_length,
  3450. size_t plaintext_length )
  3451. {
  3452. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3453. if( operation->id == 0 )
  3454. {
  3455. status = PSA_ERROR_BAD_STATE;
  3456. goto exit;
  3457. }
  3458. if( operation->lengths_set || operation->ad_started ||
  3459. operation->body_started )
  3460. {
  3461. status = PSA_ERROR_BAD_STATE;
  3462. goto exit;
  3463. }
  3464. switch(operation->alg)
  3465. {
  3466. #if defined(PSA_WANT_ALG_GCM)
  3467. case PSA_ALG_GCM:
  3468. /* Lengths can only be too large for GCM if size_t is bigger than 32
  3469. * bits. Without the guard this code will generate warnings on 32bit
  3470. * builds. */
  3471. #if SIZE_MAX > UINT32_MAX
  3472. if( (( uint64_t ) ad_length ) >> 61 != 0 ||
  3473. (( uint64_t ) plaintext_length ) > 0xFFFFFFFE0ull )
  3474. {
  3475. status = PSA_ERROR_INVALID_ARGUMENT;
  3476. goto exit;
  3477. }
  3478. #endif
  3479. break;
  3480. #endif /* PSA_WANT_ALG_GCM */
  3481. #if defined(PSA_WANT_ALG_CCM)
  3482. case PSA_ALG_CCM:
  3483. if( ad_length > 0xFF00 )
  3484. {
  3485. status = PSA_ERROR_INVALID_ARGUMENT;
  3486. goto exit;
  3487. }
  3488. break;
  3489. #endif /* PSA_WANT_ALG_CCM */
  3490. #if defined(PSA_WANT_ALG_CHACHA20_POLY1305)
  3491. case PSA_ALG_CHACHA20_POLY1305:
  3492. /* No length restrictions for ChaChaPoly. */
  3493. break;
  3494. #endif /* PSA_WANT_ALG_CHACHA20_POLY1305 */
  3495. default:
  3496. break;
  3497. }
  3498. status = psa_driver_wrapper_aead_set_lengths( operation, ad_length,
  3499. plaintext_length );
  3500. exit:
  3501. if( status == PSA_SUCCESS )
  3502. {
  3503. operation->ad_remaining = ad_length;
  3504. operation->body_remaining = plaintext_length;
  3505. operation->lengths_set = 1;
  3506. }
  3507. else
  3508. psa_aead_abort( operation );
  3509. return( status );
  3510. }
  3511. /* Pass additional data to an active multipart AEAD operation. */
  3512. psa_status_t psa_aead_update_ad( psa_aead_operation_t *operation,
  3513. const uint8_t *input,
  3514. size_t input_length )
  3515. {
  3516. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3517. if( operation->id == 0 )
  3518. {
  3519. status = PSA_ERROR_BAD_STATE;
  3520. goto exit;
  3521. }
  3522. if( !operation->nonce_set || operation->body_started )
  3523. {
  3524. status = PSA_ERROR_BAD_STATE;
  3525. goto exit;
  3526. }
  3527. if( operation->lengths_set )
  3528. {
  3529. if( operation->ad_remaining < input_length )
  3530. {
  3531. status = PSA_ERROR_INVALID_ARGUMENT;
  3532. goto exit;
  3533. }
  3534. operation->ad_remaining -= input_length;
  3535. }
  3536. status = psa_driver_wrapper_aead_update_ad( operation, input,
  3537. input_length );
  3538. exit:
  3539. if( status == PSA_SUCCESS )
  3540. operation->ad_started = 1;
  3541. else
  3542. psa_aead_abort( operation );
  3543. return( status );
  3544. }
  3545. /* Encrypt or decrypt a message fragment in an active multipart AEAD
  3546. operation.*/
  3547. psa_status_t psa_aead_update( psa_aead_operation_t *operation,
  3548. const uint8_t *input,
  3549. size_t input_length,
  3550. uint8_t *output,
  3551. size_t output_size,
  3552. size_t *output_length )
  3553. {
  3554. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3555. *output_length = 0;
  3556. if( operation->id == 0 )
  3557. {
  3558. status = PSA_ERROR_BAD_STATE;
  3559. goto exit;
  3560. }
  3561. if( !operation->nonce_set )
  3562. {
  3563. status = PSA_ERROR_BAD_STATE;
  3564. goto exit;
  3565. }
  3566. if( operation->lengths_set )
  3567. {
  3568. /* Additional data length was supplied, but not all the additional
  3569. data was supplied.*/
  3570. if( operation->ad_remaining != 0 )
  3571. {
  3572. status = PSA_ERROR_INVALID_ARGUMENT;
  3573. goto exit;
  3574. }
  3575. /* Too much data provided. */
  3576. if( operation->body_remaining < input_length )
  3577. {
  3578. status = PSA_ERROR_INVALID_ARGUMENT;
  3579. goto exit;
  3580. }
  3581. operation->body_remaining -= input_length;
  3582. }
  3583. status = psa_driver_wrapper_aead_update( operation, input, input_length,
  3584. output, output_size,
  3585. output_length );
  3586. exit:
  3587. if( status == PSA_SUCCESS )
  3588. operation->body_started = 1;
  3589. else
  3590. psa_aead_abort( operation );
  3591. return( status );
  3592. }
  3593. static psa_status_t psa_aead_final_checks( const psa_aead_operation_t *operation )
  3594. {
  3595. if( operation->id == 0 || !operation->nonce_set )
  3596. return( PSA_ERROR_BAD_STATE );
  3597. if( operation->lengths_set && ( operation->ad_remaining != 0 ||
  3598. operation->body_remaining != 0 ) )
  3599. return( PSA_ERROR_INVALID_ARGUMENT );
  3600. return( PSA_SUCCESS );
  3601. }
  3602. /* Finish encrypting a message in a multipart AEAD operation. */
  3603. psa_status_t psa_aead_finish( psa_aead_operation_t *operation,
  3604. uint8_t *ciphertext,
  3605. size_t ciphertext_size,
  3606. size_t *ciphertext_length,
  3607. uint8_t *tag,
  3608. size_t tag_size,
  3609. size_t *tag_length )
  3610. {
  3611. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3612. *ciphertext_length = 0;
  3613. *tag_length = tag_size;
  3614. status = psa_aead_final_checks( operation );
  3615. if( status != PSA_SUCCESS )
  3616. goto exit;
  3617. if( !operation->is_encrypt )
  3618. {
  3619. status = PSA_ERROR_BAD_STATE;
  3620. goto exit;
  3621. }
  3622. status = psa_driver_wrapper_aead_finish( operation, ciphertext,
  3623. ciphertext_size,
  3624. ciphertext_length,
  3625. tag, tag_size, tag_length );
  3626. exit:
  3627. /* In case the operation fails and the user fails to check for failure or
  3628. * the zero tag size, make sure the tag is set to something implausible.
  3629. * Even if the operation succeeds, make sure we clear the rest of the
  3630. * buffer to prevent potential leakage of anything previously placed in
  3631. * the same buffer.*/
  3632. if( tag != NULL )
  3633. {
  3634. if( status != PSA_SUCCESS )
  3635. memset( tag, '!', tag_size );
  3636. else if( *tag_length < tag_size )
  3637. memset( tag + *tag_length, '!', ( tag_size - *tag_length ) );
  3638. }
  3639. psa_aead_abort( operation );
  3640. return( status );
  3641. }
  3642. /* Finish authenticating and decrypting a message in a multipart AEAD
  3643. operation.*/
  3644. psa_status_t psa_aead_verify( psa_aead_operation_t *operation,
  3645. uint8_t *plaintext,
  3646. size_t plaintext_size,
  3647. size_t *plaintext_length,
  3648. const uint8_t *tag,
  3649. size_t tag_length )
  3650. {
  3651. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3652. *plaintext_length = 0;
  3653. status = psa_aead_final_checks( operation );
  3654. if( status != PSA_SUCCESS )
  3655. goto exit;
  3656. if( operation->is_encrypt )
  3657. {
  3658. status = PSA_ERROR_BAD_STATE;
  3659. goto exit;
  3660. }
  3661. status = psa_driver_wrapper_aead_verify( operation, plaintext,
  3662. plaintext_size,
  3663. plaintext_length,
  3664. tag, tag_length );
  3665. exit:
  3666. psa_aead_abort( operation );
  3667. return( status );
  3668. }
  3669. /* Abort an AEAD operation. */
  3670. psa_status_t psa_aead_abort( psa_aead_operation_t *operation )
  3671. {
  3672. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3673. if( operation->id == 0 )
  3674. {
  3675. /* The object has (apparently) been initialized but it is not (yet)
  3676. * in use. It's ok to call abort on such an object, and there's
  3677. * nothing to do. */
  3678. return( PSA_SUCCESS );
  3679. }
  3680. status = psa_driver_wrapper_aead_abort( operation );
  3681. memset( operation, 0, sizeof( *operation ) );
  3682. return( status );
  3683. }
  3684. /****************************************************************/
  3685. /* Generators */
  3686. /****************************************************************/
  3687. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF) || \
  3688. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3689. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3690. #define AT_LEAST_ONE_BUILTIN_KDF
  3691. #endif /* At least one builtin KDF */
  3692. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF) || \
  3693. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3694. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3695. static psa_status_t psa_key_derivation_start_hmac(
  3696. psa_mac_operation_t *operation,
  3697. psa_algorithm_t hash_alg,
  3698. const uint8_t *hmac_key,
  3699. size_t hmac_key_length )
  3700. {
  3701. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3702. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  3703. psa_set_key_type( &attributes, PSA_KEY_TYPE_HMAC );
  3704. psa_set_key_bits( &attributes, PSA_BYTES_TO_BITS( hmac_key_length ) );
  3705. psa_set_key_usage_flags( &attributes, PSA_KEY_USAGE_SIGN_HASH );
  3706. operation->is_sign = 1;
  3707. operation->mac_size = PSA_HASH_LENGTH( hash_alg );
  3708. status = psa_driver_wrapper_mac_sign_setup( operation,
  3709. &attributes,
  3710. hmac_key, hmac_key_length,
  3711. PSA_ALG_HMAC( hash_alg ) );
  3712. psa_reset_key_attributes( &attributes );
  3713. return( status );
  3714. }
  3715. #endif /* KDF algorithms reliant on HMAC */
  3716. #define HKDF_STATE_INIT 0 /* no input yet */
  3717. #define HKDF_STATE_STARTED 1 /* got salt */
  3718. #define HKDF_STATE_KEYED 2 /* got key */
  3719. #define HKDF_STATE_OUTPUT 3 /* output started */
  3720. static psa_algorithm_t psa_key_derivation_get_kdf_alg(
  3721. const psa_key_derivation_operation_t *operation )
  3722. {
  3723. if ( PSA_ALG_IS_KEY_AGREEMENT( operation->alg ) )
  3724. return( PSA_ALG_KEY_AGREEMENT_GET_KDF( operation->alg ) );
  3725. else
  3726. return( operation->alg );
  3727. }
  3728. psa_status_t psa_key_derivation_abort( psa_key_derivation_operation_t *operation )
  3729. {
  3730. psa_status_t status = PSA_SUCCESS;
  3731. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg( operation );
  3732. if( kdf_alg == 0 )
  3733. {
  3734. /* The object has (apparently) been initialized but it is not
  3735. * in use. It's ok to call abort on such an object, and there's
  3736. * nothing to do. */
  3737. }
  3738. else
  3739. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3740. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  3741. {
  3742. mbedtls_free( operation->ctx.hkdf.info );
  3743. status = psa_mac_abort( &operation->ctx.hkdf.hmac );
  3744. }
  3745. else
  3746. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  3747. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3748. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3749. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) ||
  3750. /* TLS-1.2 PSK-to-MS KDF uses the same core as TLS-1.2 PRF */
  3751. PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  3752. {
  3753. if( operation->ctx.tls12_prf.secret != NULL )
  3754. {
  3755. mbedtls_platform_zeroize( operation->ctx.tls12_prf.secret,
  3756. operation->ctx.tls12_prf.secret_length );
  3757. mbedtls_free( operation->ctx.tls12_prf.secret );
  3758. }
  3759. if( operation->ctx.tls12_prf.seed != NULL )
  3760. {
  3761. mbedtls_platform_zeroize( operation->ctx.tls12_prf.seed,
  3762. operation->ctx.tls12_prf.seed_length );
  3763. mbedtls_free( operation->ctx.tls12_prf.seed );
  3764. }
  3765. if( operation->ctx.tls12_prf.label != NULL )
  3766. {
  3767. mbedtls_platform_zeroize( operation->ctx.tls12_prf.label,
  3768. operation->ctx.tls12_prf.label_length );
  3769. mbedtls_free( operation->ctx.tls12_prf.label );
  3770. }
  3771. status = PSA_SUCCESS;
  3772. /* We leave the fields Ai and output_block to be erased safely by the
  3773. * mbedtls_platform_zeroize() in the end of this function. */
  3774. }
  3775. else
  3776. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) ||
  3777. * defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS) */
  3778. {
  3779. status = PSA_ERROR_BAD_STATE;
  3780. }
  3781. mbedtls_platform_zeroize( operation, sizeof( *operation ) );
  3782. return( status );
  3783. }
  3784. psa_status_t psa_key_derivation_get_capacity(const psa_key_derivation_operation_t *operation,
  3785. size_t *capacity)
  3786. {
  3787. if( operation->alg == 0 )
  3788. {
  3789. /* This is a blank key derivation operation. */
  3790. return( PSA_ERROR_BAD_STATE );
  3791. }
  3792. *capacity = operation->capacity;
  3793. return( PSA_SUCCESS );
  3794. }
  3795. psa_status_t psa_key_derivation_set_capacity( psa_key_derivation_operation_t *operation,
  3796. size_t capacity )
  3797. {
  3798. if( operation->alg == 0 )
  3799. return( PSA_ERROR_BAD_STATE );
  3800. if( capacity > operation->capacity )
  3801. return( PSA_ERROR_INVALID_ARGUMENT );
  3802. operation->capacity = capacity;
  3803. return( PSA_SUCCESS );
  3804. }
  3805. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3806. /* Read some bytes from an HKDF-based operation. This performs a chunk
  3807. * of the expand phase of the HKDF algorithm. */
  3808. static psa_status_t psa_key_derivation_hkdf_read( psa_hkdf_key_derivation_t *hkdf,
  3809. psa_algorithm_t hash_alg,
  3810. uint8_t *output,
  3811. size_t output_length )
  3812. {
  3813. uint8_t hash_length = PSA_HASH_LENGTH( hash_alg );
  3814. size_t hmac_output_length;
  3815. psa_status_t status;
  3816. if( hkdf->state < HKDF_STATE_KEYED || ! hkdf->info_set )
  3817. return( PSA_ERROR_BAD_STATE );
  3818. hkdf->state = HKDF_STATE_OUTPUT;
  3819. while( output_length != 0 )
  3820. {
  3821. /* Copy what remains of the current block */
  3822. uint8_t n = hash_length - hkdf->offset_in_block;
  3823. if( n > output_length )
  3824. n = (uint8_t) output_length;
  3825. memcpy( output, hkdf->output_block + hkdf->offset_in_block, n );
  3826. output += n;
  3827. output_length -= n;
  3828. hkdf->offset_in_block += n;
  3829. if( output_length == 0 )
  3830. break;
  3831. /* We can't be wanting more output after block 0xff, otherwise
  3832. * the capacity check in psa_key_derivation_output_bytes() would have
  3833. * prevented this call. It could happen only if the operation
  3834. * object was corrupted or if this function is called directly
  3835. * inside the library. */
  3836. if( hkdf->block_number == 0xff )
  3837. return( PSA_ERROR_BAD_STATE );
  3838. /* We need a new block */
  3839. ++hkdf->block_number;
  3840. hkdf->offset_in_block = 0;
  3841. status = psa_key_derivation_start_hmac( &hkdf->hmac,
  3842. hash_alg,
  3843. hkdf->prk,
  3844. hash_length );
  3845. if( status != PSA_SUCCESS )
  3846. return( status );
  3847. if( hkdf->block_number != 1 )
  3848. {
  3849. status = psa_mac_update( &hkdf->hmac,
  3850. hkdf->output_block,
  3851. hash_length );
  3852. if( status != PSA_SUCCESS )
  3853. return( status );
  3854. }
  3855. status = psa_mac_update( &hkdf->hmac,
  3856. hkdf->info,
  3857. hkdf->info_length );
  3858. if( status != PSA_SUCCESS )
  3859. return( status );
  3860. status = psa_mac_update( &hkdf->hmac,
  3861. &hkdf->block_number, 1 );
  3862. if( status != PSA_SUCCESS )
  3863. return( status );
  3864. status = psa_mac_sign_finish( &hkdf->hmac,
  3865. hkdf->output_block,
  3866. sizeof( hkdf->output_block ),
  3867. &hmac_output_length );
  3868. if( status != PSA_SUCCESS )
  3869. return( status );
  3870. }
  3871. return( PSA_SUCCESS );
  3872. }
  3873. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  3874. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3875. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3876. static psa_status_t psa_key_derivation_tls12_prf_generate_next_block(
  3877. psa_tls12_prf_key_derivation_t *tls12_prf,
  3878. psa_algorithm_t alg )
  3879. {
  3880. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH( alg );
  3881. uint8_t hash_length = PSA_HASH_LENGTH( hash_alg );
  3882. psa_mac_operation_t hmac = PSA_MAC_OPERATION_INIT;
  3883. size_t hmac_output_length;
  3884. psa_status_t status, cleanup_status;
  3885. /* We can't be wanting more output after block 0xff, otherwise
  3886. * the capacity check in psa_key_derivation_output_bytes() would have
  3887. * prevented this call. It could happen only if the operation
  3888. * object was corrupted or if this function is called directly
  3889. * inside the library. */
  3890. if( tls12_prf->block_number == 0xff )
  3891. return( PSA_ERROR_CORRUPTION_DETECTED );
  3892. /* We need a new block */
  3893. ++tls12_prf->block_number;
  3894. tls12_prf->left_in_block = hash_length;
  3895. /* Recall the definition of the TLS-1.2-PRF from RFC 5246:
  3896. *
  3897. * PRF(secret, label, seed) = P_<hash>(secret, label + seed)
  3898. *
  3899. * P_hash(secret, seed) = HMAC_hash(secret, A(1) + seed) +
  3900. * HMAC_hash(secret, A(2) + seed) +
  3901. * HMAC_hash(secret, A(3) + seed) + ...
  3902. *
  3903. * A(0) = seed
  3904. * A(i) = HMAC_hash(secret, A(i-1))
  3905. *
  3906. * The `psa_tls12_prf_key_derivation` structure saves the block
  3907. * `HMAC_hash(secret, A(i) + seed)` from which the output
  3908. * is currently extracted as `output_block` and where i is
  3909. * `block_number`.
  3910. */
  3911. status = psa_key_derivation_start_hmac( &hmac,
  3912. hash_alg,
  3913. tls12_prf->secret,
  3914. tls12_prf->secret_length );
  3915. if( status != PSA_SUCCESS )
  3916. goto cleanup;
  3917. /* Calculate A(i) where i = tls12_prf->block_number. */
  3918. if( tls12_prf->block_number == 1 )
  3919. {
  3920. /* A(1) = HMAC_hash(secret, A(0)), where A(0) = seed. (The RFC overloads
  3921. * the variable seed and in this instance means it in the context of the
  3922. * P_hash function, where seed = label + seed.) */
  3923. status = psa_mac_update( &hmac,
  3924. tls12_prf->label,
  3925. tls12_prf->label_length );
  3926. if( status != PSA_SUCCESS )
  3927. goto cleanup;
  3928. status = psa_mac_update( &hmac,
  3929. tls12_prf->seed,
  3930. tls12_prf->seed_length );
  3931. if( status != PSA_SUCCESS )
  3932. goto cleanup;
  3933. }
  3934. else
  3935. {
  3936. /* A(i) = HMAC_hash(secret, A(i-1)) */
  3937. status = psa_mac_update( &hmac, tls12_prf->Ai, hash_length );
  3938. if( status != PSA_SUCCESS )
  3939. goto cleanup;
  3940. }
  3941. status = psa_mac_sign_finish( &hmac,
  3942. tls12_prf->Ai, hash_length,
  3943. &hmac_output_length );
  3944. if( hmac_output_length != hash_length )
  3945. status = PSA_ERROR_CORRUPTION_DETECTED;
  3946. if( status != PSA_SUCCESS )
  3947. goto cleanup;
  3948. /* Calculate HMAC_hash(secret, A(i) + label + seed). */
  3949. status = psa_key_derivation_start_hmac( &hmac,
  3950. hash_alg,
  3951. tls12_prf->secret,
  3952. tls12_prf->secret_length );
  3953. if( status != PSA_SUCCESS )
  3954. goto cleanup;
  3955. status = psa_mac_update( &hmac, tls12_prf->Ai, hash_length );
  3956. if( status != PSA_SUCCESS )
  3957. goto cleanup;
  3958. status = psa_mac_update( &hmac, tls12_prf->label, tls12_prf->label_length );
  3959. if( status != PSA_SUCCESS )
  3960. goto cleanup;
  3961. status = psa_mac_update( &hmac, tls12_prf->seed, tls12_prf->seed_length );
  3962. if( status != PSA_SUCCESS )
  3963. goto cleanup;
  3964. status = psa_mac_sign_finish( &hmac,
  3965. tls12_prf->output_block, hash_length,
  3966. &hmac_output_length );
  3967. if( status != PSA_SUCCESS )
  3968. goto cleanup;
  3969. cleanup:
  3970. cleanup_status = psa_mac_abort( &hmac );
  3971. if( status == PSA_SUCCESS && cleanup_status != PSA_SUCCESS )
  3972. status = cleanup_status;
  3973. return( status );
  3974. }
  3975. static psa_status_t psa_key_derivation_tls12_prf_read(
  3976. psa_tls12_prf_key_derivation_t *tls12_prf,
  3977. psa_algorithm_t alg,
  3978. uint8_t *output,
  3979. size_t output_length )
  3980. {
  3981. psa_algorithm_t hash_alg = PSA_ALG_TLS12_PRF_GET_HASH( alg );
  3982. uint8_t hash_length = PSA_HASH_LENGTH( hash_alg );
  3983. psa_status_t status;
  3984. uint8_t offset, length;
  3985. switch( tls12_prf->state )
  3986. {
  3987. case PSA_TLS12_PRF_STATE_LABEL_SET:
  3988. tls12_prf->state = PSA_TLS12_PRF_STATE_OUTPUT;
  3989. break;
  3990. case PSA_TLS12_PRF_STATE_OUTPUT:
  3991. break;
  3992. default:
  3993. return( PSA_ERROR_BAD_STATE );
  3994. }
  3995. while( output_length != 0 )
  3996. {
  3997. /* Check if we have fully processed the current block. */
  3998. if( tls12_prf->left_in_block == 0 )
  3999. {
  4000. status = psa_key_derivation_tls12_prf_generate_next_block( tls12_prf,
  4001. alg );
  4002. if( status != PSA_SUCCESS )
  4003. return( status );
  4004. continue;
  4005. }
  4006. if( tls12_prf->left_in_block > output_length )
  4007. length = (uint8_t) output_length;
  4008. else
  4009. length = tls12_prf->left_in_block;
  4010. offset = hash_length - tls12_prf->left_in_block;
  4011. memcpy( output, tls12_prf->output_block + offset, length );
  4012. output += length;
  4013. output_length -= length;
  4014. tls12_prf->left_in_block -= length;
  4015. }
  4016. return( PSA_SUCCESS );
  4017. }
  4018. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF ||
  4019. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4020. psa_status_t psa_key_derivation_output_bytes(
  4021. psa_key_derivation_operation_t *operation,
  4022. uint8_t *output,
  4023. size_t output_length )
  4024. {
  4025. psa_status_t status;
  4026. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg( operation );
  4027. if( operation->alg == 0 )
  4028. {
  4029. /* This is a blank operation. */
  4030. return( PSA_ERROR_BAD_STATE );
  4031. }
  4032. if( output_length > operation->capacity )
  4033. {
  4034. operation->capacity = 0;
  4035. /* Go through the error path to wipe all confidential data now
  4036. * that the operation object is useless. */
  4037. status = PSA_ERROR_INSUFFICIENT_DATA;
  4038. goto exit;
  4039. }
  4040. if( output_length == 0 && operation->capacity == 0 )
  4041. {
  4042. /* Edge case: this is a finished operation, and 0 bytes
  4043. * were requested. The right error in this case could
  4044. * be either INSUFFICIENT_CAPACITY or BAD_STATE. Return
  4045. * INSUFFICIENT_CAPACITY, which is right for a finished
  4046. * operation, for consistency with the case when
  4047. * output_length > 0. */
  4048. return( PSA_ERROR_INSUFFICIENT_DATA );
  4049. }
  4050. operation->capacity -= output_length;
  4051. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  4052. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  4053. {
  4054. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH( kdf_alg );
  4055. status = psa_key_derivation_hkdf_read( &operation->ctx.hkdf, hash_alg,
  4056. output, output_length );
  4057. }
  4058. else
  4059. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  4060. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4061. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4062. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) ||
  4063. PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  4064. {
  4065. status = psa_key_derivation_tls12_prf_read( &operation->ctx.tls12_prf,
  4066. kdf_alg, output,
  4067. output_length );
  4068. }
  4069. else
  4070. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF ||
  4071. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4072. {
  4073. (void) kdf_alg;
  4074. return( PSA_ERROR_BAD_STATE );
  4075. }
  4076. exit:
  4077. if( status != PSA_SUCCESS )
  4078. {
  4079. /* Preserve the algorithm upon errors, but clear all sensitive state.
  4080. * This allows us to differentiate between exhausted operations and
  4081. * blank operations, so we can return PSA_ERROR_BAD_STATE on blank
  4082. * operations. */
  4083. psa_algorithm_t alg = operation->alg;
  4084. psa_key_derivation_abort( operation );
  4085. operation->alg = alg;
  4086. memset( output, '!', output_length );
  4087. }
  4088. return( status );
  4089. }
  4090. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  4091. static void psa_des_set_key_parity( uint8_t *data, size_t data_size )
  4092. {
  4093. if( data_size >= 8 )
  4094. mbedtls_des_key_set_parity( data );
  4095. if( data_size >= 16 )
  4096. mbedtls_des_key_set_parity( data + 8 );
  4097. if( data_size >= 24 )
  4098. mbedtls_des_key_set_parity( data + 16 );
  4099. }
  4100. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  4101. static psa_status_t psa_generate_derived_key_internal(
  4102. psa_key_slot_t *slot,
  4103. size_t bits,
  4104. psa_key_derivation_operation_t *operation )
  4105. {
  4106. uint8_t *data = NULL;
  4107. size_t bytes = PSA_BITS_TO_BYTES( bits );
  4108. size_t storage_size = bytes;
  4109. psa_status_t status;
  4110. if( ! key_type_is_raw_bytes( slot->attr.type ) )
  4111. return( PSA_ERROR_INVALID_ARGUMENT );
  4112. if( bits % 8 != 0 )
  4113. return( PSA_ERROR_INVALID_ARGUMENT );
  4114. data = mbedtls_calloc( 1, bytes );
  4115. if( data == NULL )
  4116. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  4117. status = psa_key_derivation_output_bytes( operation, data, bytes );
  4118. if( status != PSA_SUCCESS )
  4119. goto exit;
  4120. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  4121. if( slot->attr.type == PSA_KEY_TYPE_DES )
  4122. psa_des_set_key_parity( data, bytes );
  4123. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  4124. slot->attr.bits = (psa_key_bits_t) bits;
  4125. psa_key_attributes_t attributes = {
  4126. .core = slot->attr
  4127. };
  4128. if( psa_key_lifetime_is_external( attributes.core.lifetime ) )
  4129. {
  4130. status = psa_driver_wrapper_get_key_buffer_size( &attributes,
  4131. &storage_size );
  4132. if( status != PSA_SUCCESS )
  4133. goto exit;
  4134. }
  4135. status = psa_allocate_buffer_to_slot( slot, storage_size );
  4136. if( status != PSA_SUCCESS )
  4137. goto exit;
  4138. status = psa_driver_wrapper_import_key( &attributes,
  4139. data, bytes,
  4140. slot->key.data,
  4141. slot->key.bytes,
  4142. &slot->key.bytes, &bits );
  4143. if( bits != slot->attr.bits )
  4144. status = PSA_ERROR_INVALID_ARGUMENT;
  4145. exit:
  4146. mbedtls_free( data );
  4147. return( status );
  4148. }
  4149. psa_status_t psa_key_derivation_output_key( const psa_key_attributes_t *attributes,
  4150. psa_key_derivation_operation_t *operation,
  4151. mbedtls_svc_key_id_t *key )
  4152. {
  4153. psa_status_t status;
  4154. psa_key_slot_t *slot = NULL;
  4155. psa_se_drv_table_entry_t *driver = NULL;
  4156. *key = MBEDTLS_SVC_KEY_ID_INIT;
  4157. /* Reject any attempt to create a zero-length key so that we don't
  4158. * risk tripping up later, e.g. on a malloc(0) that returns NULL. */
  4159. if( psa_get_key_bits( attributes ) == 0 )
  4160. return( PSA_ERROR_INVALID_ARGUMENT );
  4161. if( operation->alg == PSA_ALG_NONE )
  4162. return( PSA_ERROR_BAD_STATE );
  4163. if( ! operation->can_output_key )
  4164. return( PSA_ERROR_NOT_PERMITTED );
  4165. status = psa_start_key_creation( PSA_KEY_CREATION_DERIVE, attributes,
  4166. &slot, &driver );
  4167. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  4168. if( driver != NULL )
  4169. {
  4170. /* Deriving a key in a secure element is not implemented yet. */
  4171. status = PSA_ERROR_NOT_SUPPORTED;
  4172. }
  4173. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  4174. if( status == PSA_SUCCESS )
  4175. {
  4176. status = psa_generate_derived_key_internal( slot,
  4177. attributes->core.bits,
  4178. operation );
  4179. }
  4180. if( status == PSA_SUCCESS )
  4181. status = psa_finish_key_creation( slot, driver, key );
  4182. if( status != PSA_SUCCESS )
  4183. psa_fail_key_creation( slot, driver );
  4184. return( status );
  4185. }
  4186. /****************************************************************/
  4187. /* Key derivation */
  4188. /****************************************************************/
  4189. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  4190. static psa_status_t psa_key_derivation_setup_kdf(
  4191. psa_key_derivation_operation_t *operation,
  4192. psa_algorithm_t kdf_alg )
  4193. {
  4194. int is_kdf_alg_supported;
  4195. /* Make sure that operation->ctx is properly zero-initialised. (Macro
  4196. * initialisers for this union leave some bytes unspecified.) */
  4197. memset( &operation->ctx, 0, sizeof( operation->ctx ) );
  4198. /* Make sure that kdf_alg is a supported key derivation algorithm. */
  4199. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  4200. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  4201. is_kdf_alg_supported = 1;
  4202. else
  4203. #endif
  4204. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF)
  4205. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) )
  4206. is_kdf_alg_supported = 1;
  4207. else
  4208. #endif
  4209. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4210. if( PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  4211. is_kdf_alg_supported = 1;
  4212. else
  4213. #endif
  4214. is_kdf_alg_supported = 0;
  4215. if( is_kdf_alg_supported )
  4216. {
  4217. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH( kdf_alg );
  4218. size_t hash_size = PSA_HASH_LENGTH( hash_alg );
  4219. if( hash_size == 0 )
  4220. return( PSA_ERROR_NOT_SUPPORTED );
  4221. if( ( PSA_ALG_IS_TLS12_PRF( kdf_alg ) ||
  4222. PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) ) &&
  4223. ! ( hash_alg == PSA_ALG_SHA_256 || hash_alg == PSA_ALG_SHA_384 ) )
  4224. {
  4225. return( PSA_ERROR_NOT_SUPPORTED );
  4226. }
  4227. operation->capacity = 255 * hash_size;
  4228. return( PSA_SUCCESS );
  4229. }
  4230. return( PSA_ERROR_NOT_SUPPORTED );
  4231. }
  4232. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  4233. psa_status_t psa_key_derivation_setup( psa_key_derivation_operation_t *operation,
  4234. psa_algorithm_t alg )
  4235. {
  4236. psa_status_t status;
  4237. if( operation->alg != 0 )
  4238. return( PSA_ERROR_BAD_STATE );
  4239. if( PSA_ALG_IS_RAW_KEY_AGREEMENT( alg ) )
  4240. return( PSA_ERROR_INVALID_ARGUMENT );
  4241. else if( PSA_ALG_IS_KEY_AGREEMENT( alg ) )
  4242. {
  4243. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  4244. psa_algorithm_t kdf_alg = PSA_ALG_KEY_AGREEMENT_GET_KDF( alg );
  4245. status = psa_key_derivation_setup_kdf( operation, kdf_alg );
  4246. #else
  4247. return( PSA_ERROR_NOT_SUPPORTED );
  4248. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  4249. }
  4250. else if( PSA_ALG_IS_KEY_DERIVATION( alg ) )
  4251. {
  4252. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  4253. status = psa_key_derivation_setup_kdf( operation, alg );
  4254. #else
  4255. return( PSA_ERROR_NOT_SUPPORTED );
  4256. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  4257. }
  4258. else
  4259. return( PSA_ERROR_INVALID_ARGUMENT );
  4260. if( status == PSA_SUCCESS )
  4261. operation->alg = alg;
  4262. return( status );
  4263. }
  4264. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  4265. static psa_status_t psa_hkdf_input( psa_hkdf_key_derivation_t *hkdf,
  4266. psa_algorithm_t hash_alg,
  4267. psa_key_derivation_step_t step,
  4268. const uint8_t *data,
  4269. size_t data_length )
  4270. {
  4271. psa_status_t status;
  4272. switch( step )
  4273. {
  4274. case PSA_KEY_DERIVATION_INPUT_SALT:
  4275. if( hkdf->state != HKDF_STATE_INIT )
  4276. return( PSA_ERROR_BAD_STATE );
  4277. else
  4278. {
  4279. status = psa_key_derivation_start_hmac( &hkdf->hmac,
  4280. hash_alg,
  4281. data, data_length );
  4282. if( status != PSA_SUCCESS )
  4283. return( status );
  4284. hkdf->state = HKDF_STATE_STARTED;
  4285. return( PSA_SUCCESS );
  4286. }
  4287. case PSA_KEY_DERIVATION_INPUT_SECRET:
  4288. /* If no salt was provided, use an empty salt. */
  4289. if( hkdf->state == HKDF_STATE_INIT )
  4290. {
  4291. status = psa_key_derivation_start_hmac( &hkdf->hmac,
  4292. hash_alg,
  4293. NULL, 0 );
  4294. if( status != PSA_SUCCESS )
  4295. return( status );
  4296. hkdf->state = HKDF_STATE_STARTED;
  4297. }
  4298. if( hkdf->state != HKDF_STATE_STARTED )
  4299. return( PSA_ERROR_BAD_STATE );
  4300. status = psa_mac_update( &hkdf->hmac,
  4301. data, data_length );
  4302. if( status != PSA_SUCCESS )
  4303. return( status );
  4304. status = psa_mac_sign_finish( &hkdf->hmac,
  4305. hkdf->prk,
  4306. sizeof( hkdf->prk ),
  4307. &data_length );
  4308. if( status != PSA_SUCCESS )
  4309. return( status );
  4310. hkdf->offset_in_block = PSA_HASH_LENGTH( hash_alg );
  4311. hkdf->block_number = 0;
  4312. hkdf->state = HKDF_STATE_KEYED;
  4313. return( PSA_SUCCESS );
  4314. case PSA_KEY_DERIVATION_INPUT_INFO:
  4315. if( hkdf->state == HKDF_STATE_OUTPUT )
  4316. return( PSA_ERROR_BAD_STATE );
  4317. if( hkdf->info_set )
  4318. return( PSA_ERROR_BAD_STATE );
  4319. hkdf->info_length = data_length;
  4320. if( data_length != 0 )
  4321. {
  4322. hkdf->info = mbedtls_calloc( 1, data_length );
  4323. if( hkdf->info == NULL )
  4324. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  4325. memcpy( hkdf->info, data, data_length );
  4326. }
  4327. hkdf->info_set = 1;
  4328. return( PSA_SUCCESS );
  4329. default:
  4330. return( PSA_ERROR_INVALID_ARGUMENT );
  4331. }
  4332. }
  4333. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  4334. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4335. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4336. static psa_status_t psa_tls12_prf_set_seed( psa_tls12_prf_key_derivation_t *prf,
  4337. const uint8_t *data,
  4338. size_t data_length )
  4339. {
  4340. if( prf->state != PSA_TLS12_PRF_STATE_INIT )
  4341. return( PSA_ERROR_BAD_STATE );
  4342. if( data_length != 0 )
  4343. {
  4344. prf->seed = mbedtls_calloc( 1, data_length );
  4345. if( prf->seed == NULL )
  4346. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  4347. memcpy( prf->seed, data, data_length );
  4348. prf->seed_length = data_length;
  4349. }
  4350. prf->state = PSA_TLS12_PRF_STATE_SEED_SET;
  4351. return( PSA_SUCCESS );
  4352. }
  4353. static psa_status_t psa_tls12_prf_set_key( psa_tls12_prf_key_derivation_t *prf,
  4354. const uint8_t *data,
  4355. size_t data_length )
  4356. {
  4357. if( prf->state != PSA_TLS12_PRF_STATE_SEED_SET )
  4358. return( PSA_ERROR_BAD_STATE );
  4359. if( data_length != 0 )
  4360. {
  4361. prf->secret = mbedtls_calloc( 1, data_length );
  4362. if( prf->secret == NULL )
  4363. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  4364. memcpy( prf->secret, data, data_length );
  4365. prf->secret_length = data_length;
  4366. }
  4367. prf->state = PSA_TLS12_PRF_STATE_KEY_SET;
  4368. return( PSA_SUCCESS );
  4369. }
  4370. static psa_status_t psa_tls12_prf_set_label( psa_tls12_prf_key_derivation_t *prf,
  4371. const uint8_t *data,
  4372. size_t data_length )
  4373. {
  4374. if( prf->state != PSA_TLS12_PRF_STATE_KEY_SET )
  4375. return( PSA_ERROR_BAD_STATE );
  4376. if( data_length != 0 )
  4377. {
  4378. prf->label = mbedtls_calloc( 1, data_length );
  4379. if( prf->label == NULL )
  4380. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  4381. memcpy( prf->label, data, data_length );
  4382. prf->label_length = data_length;
  4383. }
  4384. prf->state = PSA_TLS12_PRF_STATE_LABEL_SET;
  4385. return( PSA_SUCCESS );
  4386. }
  4387. static psa_status_t psa_tls12_prf_input( psa_tls12_prf_key_derivation_t *prf,
  4388. psa_key_derivation_step_t step,
  4389. const uint8_t *data,
  4390. size_t data_length )
  4391. {
  4392. switch( step )
  4393. {
  4394. case PSA_KEY_DERIVATION_INPUT_SEED:
  4395. return( psa_tls12_prf_set_seed( prf, data, data_length ) );
  4396. case PSA_KEY_DERIVATION_INPUT_SECRET:
  4397. return( psa_tls12_prf_set_key( prf, data, data_length ) );
  4398. case PSA_KEY_DERIVATION_INPUT_LABEL:
  4399. return( psa_tls12_prf_set_label( prf, data, data_length ) );
  4400. default:
  4401. return( PSA_ERROR_INVALID_ARGUMENT );
  4402. }
  4403. }
  4404. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) ||
  4405. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4406. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4407. static psa_status_t psa_tls12_prf_psk_to_ms_set_key(
  4408. psa_tls12_prf_key_derivation_t *prf,
  4409. const uint8_t *data,
  4410. size_t data_length )
  4411. {
  4412. psa_status_t status;
  4413. uint8_t pms[ 4 + 2 * PSA_TLS12_PSK_TO_MS_PSK_MAX_SIZE ];
  4414. uint8_t *cur = pms;
  4415. if( data_length > PSA_TLS12_PSK_TO_MS_PSK_MAX_SIZE )
  4416. return( PSA_ERROR_INVALID_ARGUMENT );
  4417. /* Quoting RFC 4279, Section 2:
  4418. *
  4419. * The premaster secret is formed as follows: if the PSK is N octets
  4420. * long, concatenate a uint16 with the value N, N zero octets, a second
  4421. * uint16 with the value N, and the PSK itself.
  4422. */
  4423. *cur++ = MBEDTLS_BYTE_1( data_length );
  4424. *cur++ = MBEDTLS_BYTE_0( data_length );
  4425. memset( cur, 0, data_length );
  4426. cur += data_length;
  4427. *cur++ = pms[0];
  4428. *cur++ = pms[1];
  4429. memcpy( cur, data, data_length );
  4430. cur += data_length;
  4431. status = psa_tls12_prf_set_key( prf, pms, cur - pms );
  4432. mbedtls_platform_zeroize( pms, sizeof( pms ) );
  4433. return( status );
  4434. }
  4435. static psa_status_t psa_tls12_prf_psk_to_ms_input(
  4436. psa_tls12_prf_key_derivation_t *prf,
  4437. psa_key_derivation_step_t step,
  4438. const uint8_t *data,
  4439. size_t data_length )
  4440. {
  4441. if( step == PSA_KEY_DERIVATION_INPUT_SECRET )
  4442. {
  4443. return( psa_tls12_prf_psk_to_ms_set_key( prf,
  4444. data, data_length ) );
  4445. }
  4446. return( psa_tls12_prf_input( prf, step, data, data_length ) );
  4447. }
  4448. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4449. /** Check whether the given key type is acceptable for the given
  4450. * input step of a key derivation.
  4451. *
  4452. * Secret inputs must have the type #PSA_KEY_TYPE_DERIVE.
  4453. * Non-secret inputs must have the type #PSA_KEY_TYPE_RAW_DATA.
  4454. * Both secret and non-secret inputs can alternatively have the type
  4455. * #PSA_KEY_TYPE_NONE, which is never the type of a key object, meaning
  4456. * that the input was passed as a buffer rather than via a key object.
  4457. */
  4458. static int psa_key_derivation_check_input_type(
  4459. psa_key_derivation_step_t step,
  4460. psa_key_type_t key_type )
  4461. {
  4462. switch( step )
  4463. {
  4464. case PSA_KEY_DERIVATION_INPUT_SECRET:
  4465. if( key_type == PSA_KEY_TYPE_DERIVE )
  4466. return( PSA_SUCCESS );
  4467. if( key_type == PSA_KEY_TYPE_NONE )
  4468. return( PSA_SUCCESS );
  4469. break;
  4470. case PSA_KEY_DERIVATION_INPUT_LABEL:
  4471. case PSA_KEY_DERIVATION_INPUT_SALT:
  4472. case PSA_KEY_DERIVATION_INPUT_INFO:
  4473. case PSA_KEY_DERIVATION_INPUT_SEED:
  4474. if( key_type == PSA_KEY_TYPE_RAW_DATA )
  4475. return( PSA_SUCCESS );
  4476. if( key_type == PSA_KEY_TYPE_NONE )
  4477. return( PSA_SUCCESS );
  4478. break;
  4479. }
  4480. return( PSA_ERROR_INVALID_ARGUMENT );
  4481. }
  4482. static psa_status_t psa_key_derivation_input_internal(
  4483. psa_key_derivation_operation_t *operation,
  4484. psa_key_derivation_step_t step,
  4485. psa_key_type_t key_type,
  4486. const uint8_t *data,
  4487. size_t data_length )
  4488. {
  4489. psa_status_t status;
  4490. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg( operation );
  4491. status = psa_key_derivation_check_input_type( step, key_type );
  4492. if( status != PSA_SUCCESS )
  4493. goto exit;
  4494. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  4495. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  4496. {
  4497. status = psa_hkdf_input( &operation->ctx.hkdf,
  4498. PSA_ALG_HKDF_GET_HASH( kdf_alg ),
  4499. step, data, data_length );
  4500. }
  4501. else
  4502. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  4503. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF)
  4504. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) )
  4505. {
  4506. status = psa_tls12_prf_input( &operation->ctx.tls12_prf,
  4507. step, data, data_length );
  4508. }
  4509. else
  4510. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF */
  4511. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4512. if( PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  4513. {
  4514. status = psa_tls12_prf_psk_to_ms_input( &operation->ctx.tls12_prf,
  4515. step, data, data_length );
  4516. }
  4517. else
  4518. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4519. {
  4520. /* This can't happen unless the operation object was not initialized */
  4521. (void) data;
  4522. (void) data_length;
  4523. (void) kdf_alg;
  4524. return( PSA_ERROR_BAD_STATE );
  4525. }
  4526. exit:
  4527. if( status != PSA_SUCCESS )
  4528. psa_key_derivation_abort( operation );
  4529. return( status );
  4530. }
  4531. psa_status_t psa_key_derivation_input_bytes(
  4532. psa_key_derivation_operation_t *operation,
  4533. psa_key_derivation_step_t step,
  4534. const uint8_t *data,
  4535. size_t data_length )
  4536. {
  4537. return( psa_key_derivation_input_internal( operation, step,
  4538. PSA_KEY_TYPE_NONE,
  4539. data, data_length ) );
  4540. }
  4541. psa_status_t psa_key_derivation_input_key(
  4542. psa_key_derivation_operation_t *operation,
  4543. psa_key_derivation_step_t step,
  4544. mbedtls_svc_key_id_t key )
  4545. {
  4546. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4547. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  4548. psa_key_slot_t *slot;
  4549. status = psa_get_and_lock_transparent_key_slot_with_policy(
  4550. key, &slot, PSA_KEY_USAGE_DERIVE, operation->alg );
  4551. if( status != PSA_SUCCESS )
  4552. {
  4553. psa_key_derivation_abort( operation );
  4554. return( status );
  4555. }
  4556. /* Passing a key object as a SECRET input unlocks the permission
  4557. * to output to a key object. */
  4558. if( step == PSA_KEY_DERIVATION_INPUT_SECRET )
  4559. operation->can_output_key = 1;
  4560. status = psa_key_derivation_input_internal( operation,
  4561. step, slot->attr.type,
  4562. slot->key.data,
  4563. slot->key.bytes );
  4564. unlock_status = psa_unlock_key_slot( slot );
  4565. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  4566. }
  4567. /****************************************************************/
  4568. /* Key agreement */
  4569. /****************************************************************/
  4570. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  4571. static psa_status_t psa_key_agreement_ecdh( const uint8_t *peer_key,
  4572. size_t peer_key_length,
  4573. const mbedtls_ecp_keypair *our_key,
  4574. uint8_t *shared_secret,
  4575. size_t shared_secret_size,
  4576. size_t *shared_secret_length )
  4577. {
  4578. mbedtls_ecp_keypair *their_key = NULL;
  4579. mbedtls_ecdh_context ecdh;
  4580. psa_status_t status;
  4581. size_t bits = 0;
  4582. psa_ecc_family_t curve = mbedtls_ecc_group_to_psa( our_key->grp.id, &bits );
  4583. mbedtls_ecdh_init( &ecdh );
  4584. status = mbedtls_psa_ecp_load_representation(
  4585. PSA_KEY_TYPE_ECC_PUBLIC_KEY(curve),
  4586. bits,
  4587. peer_key,
  4588. peer_key_length,
  4589. &their_key );
  4590. if( status != PSA_SUCCESS )
  4591. goto exit;
  4592. status = mbedtls_to_psa_error(
  4593. mbedtls_ecdh_get_params( &ecdh, their_key, MBEDTLS_ECDH_THEIRS ) );
  4594. if( status != PSA_SUCCESS )
  4595. goto exit;
  4596. status = mbedtls_to_psa_error(
  4597. mbedtls_ecdh_get_params( &ecdh, our_key, MBEDTLS_ECDH_OURS ) );
  4598. if( status != PSA_SUCCESS )
  4599. goto exit;
  4600. status = mbedtls_to_psa_error(
  4601. mbedtls_ecdh_calc_secret( &ecdh,
  4602. shared_secret_length,
  4603. shared_secret, shared_secret_size,
  4604. mbedtls_psa_get_random,
  4605. MBEDTLS_PSA_RANDOM_STATE ) );
  4606. if( status != PSA_SUCCESS )
  4607. goto exit;
  4608. if( PSA_BITS_TO_BYTES( bits ) != *shared_secret_length )
  4609. status = PSA_ERROR_CORRUPTION_DETECTED;
  4610. exit:
  4611. if( status != PSA_SUCCESS )
  4612. mbedtls_platform_zeroize( shared_secret, shared_secret_size );
  4613. mbedtls_ecdh_free( &ecdh );
  4614. mbedtls_ecp_keypair_free( their_key );
  4615. mbedtls_free( their_key );
  4616. return( status );
  4617. }
  4618. #endif /* MBEDTLS_PSA_BUILTIN_ALG_ECDH */
  4619. #define PSA_KEY_AGREEMENT_MAX_SHARED_SECRET_SIZE MBEDTLS_ECP_MAX_BYTES
  4620. static psa_status_t psa_key_agreement_raw_internal( psa_algorithm_t alg,
  4621. psa_key_slot_t *private_key,
  4622. const uint8_t *peer_key,
  4623. size_t peer_key_length,
  4624. uint8_t *shared_secret,
  4625. size_t shared_secret_size,
  4626. size_t *shared_secret_length )
  4627. {
  4628. switch( alg )
  4629. {
  4630. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  4631. case PSA_ALG_ECDH:
  4632. if( ! PSA_KEY_TYPE_IS_ECC_KEY_PAIR( private_key->attr.type ) )
  4633. return( PSA_ERROR_INVALID_ARGUMENT );
  4634. mbedtls_ecp_keypair *ecp = NULL;
  4635. psa_status_t status = mbedtls_psa_ecp_load_representation(
  4636. private_key->attr.type,
  4637. private_key->attr.bits,
  4638. private_key->key.data,
  4639. private_key->key.bytes,
  4640. &ecp );
  4641. if( status != PSA_SUCCESS )
  4642. return( status );
  4643. status = psa_key_agreement_ecdh( peer_key, peer_key_length,
  4644. ecp,
  4645. shared_secret, shared_secret_size,
  4646. shared_secret_length );
  4647. mbedtls_ecp_keypair_free( ecp );
  4648. mbedtls_free( ecp );
  4649. return( status );
  4650. #endif /* MBEDTLS_PSA_BUILTIN_ALG_ECDH */
  4651. default:
  4652. (void) private_key;
  4653. (void) peer_key;
  4654. (void) peer_key_length;
  4655. (void) shared_secret;
  4656. (void) shared_secret_size;
  4657. (void) shared_secret_length;
  4658. return( PSA_ERROR_NOT_SUPPORTED );
  4659. }
  4660. }
  4661. /* Note that if this function fails, you must call psa_key_derivation_abort()
  4662. * to potentially free embedded data structures and wipe confidential data.
  4663. */
  4664. static psa_status_t psa_key_agreement_internal( psa_key_derivation_operation_t *operation,
  4665. psa_key_derivation_step_t step,
  4666. psa_key_slot_t *private_key,
  4667. const uint8_t *peer_key,
  4668. size_t peer_key_length )
  4669. {
  4670. psa_status_t status;
  4671. uint8_t shared_secret[PSA_KEY_AGREEMENT_MAX_SHARED_SECRET_SIZE];
  4672. size_t shared_secret_length = 0;
  4673. psa_algorithm_t ka_alg = PSA_ALG_KEY_AGREEMENT_GET_BASE( operation->alg );
  4674. /* Step 1: run the secret agreement algorithm to generate the shared
  4675. * secret. */
  4676. status = psa_key_agreement_raw_internal( ka_alg,
  4677. private_key,
  4678. peer_key, peer_key_length,
  4679. shared_secret,
  4680. sizeof( shared_secret ),
  4681. &shared_secret_length );
  4682. if( status != PSA_SUCCESS )
  4683. goto exit;
  4684. /* Step 2: set up the key derivation to generate key material from
  4685. * the shared secret. A shared secret is permitted wherever a key
  4686. * of type DERIVE is permitted. */
  4687. status = psa_key_derivation_input_internal( operation, step,
  4688. PSA_KEY_TYPE_DERIVE,
  4689. shared_secret,
  4690. shared_secret_length );
  4691. exit:
  4692. mbedtls_platform_zeroize( shared_secret, shared_secret_length );
  4693. return( status );
  4694. }
  4695. psa_status_t psa_key_derivation_key_agreement( psa_key_derivation_operation_t *operation,
  4696. psa_key_derivation_step_t step,
  4697. mbedtls_svc_key_id_t private_key,
  4698. const uint8_t *peer_key,
  4699. size_t peer_key_length )
  4700. {
  4701. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4702. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  4703. psa_key_slot_t *slot;
  4704. if( ! PSA_ALG_IS_KEY_AGREEMENT( operation->alg ) )
  4705. return( PSA_ERROR_INVALID_ARGUMENT );
  4706. status = psa_get_and_lock_transparent_key_slot_with_policy(
  4707. private_key, &slot, PSA_KEY_USAGE_DERIVE, operation->alg );
  4708. if( status != PSA_SUCCESS )
  4709. return( status );
  4710. status = psa_key_agreement_internal( operation, step,
  4711. slot,
  4712. peer_key, peer_key_length );
  4713. if( status != PSA_SUCCESS )
  4714. psa_key_derivation_abort( operation );
  4715. else
  4716. {
  4717. /* If a private key has been added as SECRET, we allow the derived
  4718. * key material to be used as a key in PSA Crypto. */
  4719. if( step == PSA_KEY_DERIVATION_INPUT_SECRET )
  4720. operation->can_output_key = 1;
  4721. }
  4722. unlock_status = psa_unlock_key_slot( slot );
  4723. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  4724. }
  4725. psa_status_t psa_raw_key_agreement( psa_algorithm_t alg,
  4726. mbedtls_svc_key_id_t private_key,
  4727. const uint8_t *peer_key,
  4728. size_t peer_key_length,
  4729. uint8_t *output,
  4730. size_t output_size,
  4731. size_t *output_length )
  4732. {
  4733. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4734. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  4735. psa_key_slot_t *slot = NULL;
  4736. if( ! PSA_ALG_IS_KEY_AGREEMENT( alg ) )
  4737. {
  4738. status = PSA_ERROR_INVALID_ARGUMENT;
  4739. goto exit;
  4740. }
  4741. status = psa_get_and_lock_transparent_key_slot_with_policy(
  4742. private_key, &slot, PSA_KEY_USAGE_DERIVE, alg );
  4743. if( status != PSA_SUCCESS )
  4744. goto exit;
  4745. status = psa_key_agreement_raw_internal( alg, slot,
  4746. peer_key, peer_key_length,
  4747. output, output_size,
  4748. output_length );
  4749. exit:
  4750. if( status != PSA_SUCCESS )
  4751. {
  4752. /* If an error happens and is not handled properly, the output
  4753. * may be used as a key to protect sensitive data. Arrange for such
  4754. * a key to be random, which is likely to result in decryption or
  4755. * verification errors. This is better than filling the buffer with
  4756. * some constant data such as zeros, which would result in the data
  4757. * being protected with a reproducible, easily knowable key.
  4758. */
  4759. psa_generate_random( output, output_size );
  4760. *output_length = output_size;
  4761. }
  4762. unlock_status = psa_unlock_key_slot( slot );
  4763. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  4764. }
  4765. /****************************************************************/
  4766. /* Random generation */
  4767. /****************************************************************/
  4768. /** Initialize the PSA random generator.
  4769. */
  4770. static void mbedtls_psa_random_init( mbedtls_psa_random_context_t *rng )
  4771. {
  4772. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4773. memset( rng, 0, sizeof( *rng ) );
  4774. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4775. /* Set default configuration if
  4776. * mbedtls_psa_crypto_configure_entropy_sources() hasn't been called. */
  4777. if( rng->entropy_init == NULL )
  4778. rng->entropy_init = mbedtls_entropy_init;
  4779. if( rng->entropy_free == NULL )
  4780. rng->entropy_free = mbedtls_entropy_free;
  4781. rng->entropy_init( &rng->entropy );
  4782. #if defined(MBEDTLS_PSA_INJECT_ENTROPY) && \
  4783. defined(MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES)
  4784. /* The PSA entropy injection feature depends on using NV seed as an entropy
  4785. * source. Add NV seed as an entropy source for PSA entropy injection. */
  4786. mbedtls_entropy_add_source( &rng->entropy,
  4787. mbedtls_nv_seed_poll, NULL,
  4788. MBEDTLS_ENTROPY_BLOCK_SIZE,
  4789. MBEDTLS_ENTROPY_SOURCE_STRONG );
  4790. #endif
  4791. mbedtls_psa_drbg_init( MBEDTLS_PSA_RANDOM_STATE );
  4792. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4793. }
  4794. /** Deinitialize the PSA random generator.
  4795. */
  4796. static void mbedtls_psa_random_free( mbedtls_psa_random_context_t *rng )
  4797. {
  4798. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4799. memset( rng, 0, sizeof( *rng ) );
  4800. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4801. mbedtls_psa_drbg_free( MBEDTLS_PSA_RANDOM_STATE );
  4802. rng->entropy_free( &rng->entropy );
  4803. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4804. }
  4805. /** Seed the PSA random generator.
  4806. */
  4807. static psa_status_t mbedtls_psa_random_seed( mbedtls_psa_random_context_t *rng )
  4808. {
  4809. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4810. /* Do nothing: the external RNG seeds itself. */
  4811. (void) rng;
  4812. return( PSA_SUCCESS );
  4813. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4814. const unsigned char drbg_seed[] = "PSA";
  4815. int ret = mbedtls_psa_drbg_seed( &rng->entropy,
  4816. drbg_seed, sizeof( drbg_seed ) - 1 );
  4817. return mbedtls_to_psa_error( ret );
  4818. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4819. }
  4820. psa_status_t psa_generate_random( uint8_t *output,
  4821. size_t output_size )
  4822. {
  4823. GUARD_MODULE_INITIALIZED;
  4824. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4825. size_t output_length = 0;
  4826. psa_status_t status = mbedtls_psa_external_get_random( &global_data.rng,
  4827. output, output_size,
  4828. &output_length );
  4829. if( status != PSA_SUCCESS )
  4830. return( status );
  4831. /* Breaking up a request into smaller chunks is currently not supported
  4832. * for the extrernal RNG interface. */
  4833. if( output_length != output_size )
  4834. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  4835. return( PSA_SUCCESS );
  4836. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4837. while( output_size > 0 )
  4838. {
  4839. size_t request_size =
  4840. ( output_size > MBEDTLS_PSA_RANDOM_MAX_REQUEST ?
  4841. MBEDTLS_PSA_RANDOM_MAX_REQUEST :
  4842. output_size );
  4843. int ret = mbedtls_psa_get_random( MBEDTLS_PSA_RANDOM_STATE,
  4844. output, request_size );
  4845. if( ret != 0 )
  4846. return( mbedtls_to_psa_error( ret ) );
  4847. output_size -= request_size;
  4848. output += request_size;
  4849. }
  4850. return( PSA_SUCCESS );
  4851. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4852. }
  4853. /* Wrapper function allowing the classic API to use the PSA RNG.
  4854. *
  4855. * `mbedtls_psa_get_random(MBEDTLS_PSA_RANDOM_STATE, ...)` calls
  4856. * `psa_generate_random(...)`. The state parameter is ignored since the
  4857. * PSA API doesn't support passing an explicit state.
  4858. *
  4859. * In the non-external case, psa_generate_random() calls an
  4860. * `mbedtls_xxx_drbg_random` function which has exactly the same signature
  4861. * and semantics as mbedtls_psa_get_random(). As an optimization,
  4862. * instead of doing this back-and-forth between the PSA API and the
  4863. * classic API, psa_crypto_random_impl.h defines `mbedtls_psa_get_random`
  4864. * as a constant function pointer to `mbedtls_xxx_drbg_random`.
  4865. */
  4866. #if defined (MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4867. int mbedtls_psa_get_random( void *p_rng,
  4868. unsigned char *output,
  4869. size_t output_size )
  4870. {
  4871. /* This function takes a pointer to the RNG state because that's what
  4872. * classic mbedtls functions using an RNG expect. The PSA RNG manages
  4873. * its own state internally and doesn't let the caller access that state.
  4874. * So we just ignore the state parameter, and in practice we'll pass
  4875. * NULL. */
  4876. (void) p_rng;
  4877. psa_status_t status = psa_generate_random( output, output_size );
  4878. if( status == PSA_SUCCESS )
  4879. return( 0 );
  4880. else
  4881. return( MBEDTLS_ERR_ENTROPY_SOURCE_FAILED );
  4882. }
  4883. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4884. #if defined(MBEDTLS_PSA_INJECT_ENTROPY)
  4885. #include "entropy_poll.h"
  4886. psa_status_t mbedtls_psa_inject_entropy( const uint8_t *seed,
  4887. size_t seed_size )
  4888. {
  4889. if( global_data.initialized )
  4890. return( PSA_ERROR_NOT_PERMITTED );
  4891. if( ( ( seed_size < MBEDTLS_ENTROPY_MIN_PLATFORM ) ||
  4892. ( seed_size < MBEDTLS_ENTROPY_BLOCK_SIZE ) ) ||
  4893. ( seed_size > MBEDTLS_ENTROPY_MAX_SEED_SIZE ) )
  4894. return( PSA_ERROR_INVALID_ARGUMENT );
  4895. return( mbedtls_psa_storage_inject_entropy( seed, seed_size ) );
  4896. }
  4897. #endif /* MBEDTLS_PSA_INJECT_ENTROPY */
  4898. /** Validate the key type and size for key generation
  4899. *
  4900. * \param type The key type
  4901. * \param bits The number of bits of the key
  4902. *
  4903. * \retval #PSA_SUCCESS
  4904. * The key type and size are valid.
  4905. * \retval #PSA_ERROR_INVALID_ARGUMENT
  4906. * The size in bits of the key is not valid.
  4907. * \retval #PSA_ERROR_NOT_SUPPORTED
  4908. * The type and/or the size in bits of the key or the combination of
  4909. * the two is not supported.
  4910. */
  4911. static psa_status_t psa_validate_key_type_and_size_for_key_generation(
  4912. psa_key_type_t type, size_t bits )
  4913. {
  4914. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4915. if( key_type_is_raw_bytes( type ) )
  4916. {
  4917. status = psa_validate_unstructured_key_bit_size( type, bits );
  4918. if( status != PSA_SUCCESS )
  4919. return( status );
  4920. }
  4921. else
  4922. #if defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR)
  4923. if( PSA_KEY_TYPE_IS_RSA( type ) && PSA_KEY_TYPE_IS_KEY_PAIR( type ) )
  4924. {
  4925. if( bits > PSA_VENDOR_RSA_MAX_KEY_BITS )
  4926. return( PSA_ERROR_NOT_SUPPORTED );
  4927. /* Accept only byte-aligned keys, for the same reasons as
  4928. * in psa_import_rsa_key(). */
  4929. if( bits % 8 != 0 )
  4930. return( PSA_ERROR_NOT_SUPPORTED );
  4931. }
  4932. else
  4933. #endif /* defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR) */
  4934. #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR)
  4935. if( PSA_KEY_TYPE_IS_ECC( type ) && PSA_KEY_TYPE_IS_KEY_PAIR( type ) )
  4936. {
  4937. /* To avoid empty block, return successfully here. */
  4938. return( PSA_SUCCESS );
  4939. }
  4940. else
  4941. #endif /* defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR) */
  4942. {
  4943. return( PSA_ERROR_NOT_SUPPORTED );
  4944. }
  4945. return( PSA_SUCCESS );
  4946. }
  4947. psa_status_t psa_generate_key_internal(
  4948. const psa_key_attributes_t *attributes,
  4949. uint8_t *key_buffer, size_t key_buffer_size, size_t *key_buffer_length )
  4950. {
  4951. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4952. psa_key_type_t type = attributes->core.type;
  4953. if( ( attributes->domain_parameters == NULL ) &&
  4954. ( attributes->domain_parameters_size != 0 ) )
  4955. return( PSA_ERROR_INVALID_ARGUMENT );
  4956. if( key_type_is_raw_bytes( type ) )
  4957. {
  4958. status = psa_generate_random( key_buffer, key_buffer_size );
  4959. if( status != PSA_SUCCESS )
  4960. return( status );
  4961. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  4962. if( type == PSA_KEY_TYPE_DES )
  4963. psa_des_set_key_parity( key_buffer, key_buffer_size );
  4964. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  4965. }
  4966. else
  4967. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) && \
  4968. defined(MBEDTLS_GENPRIME)
  4969. if ( type == PSA_KEY_TYPE_RSA_KEY_PAIR )
  4970. {
  4971. return( mbedtls_psa_rsa_generate_key( attributes,
  4972. key_buffer,
  4973. key_buffer_size,
  4974. key_buffer_length ) );
  4975. }
  4976. else
  4977. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR)
  4978. * defined(MBEDTLS_GENPRIME) */
  4979. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR)
  4980. if ( PSA_KEY_TYPE_IS_ECC( type ) && PSA_KEY_TYPE_IS_KEY_PAIR( type ) )
  4981. {
  4982. return( mbedtls_psa_ecp_generate_key( attributes,
  4983. key_buffer,
  4984. key_buffer_size,
  4985. key_buffer_length ) );
  4986. }
  4987. else
  4988. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) */
  4989. {
  4990. (void)key_buffer_length;
  4991. return( PSA_ERROR_NOT_SUPPORTED );
  4992. }
  4993. return( PSA_SUCCESS );
  4994. }
  4995. psa_status_t psa_generate_key( const psa_key_attributes_t *attributes,
  4996. mbedtls_svc_key_id_t *key )
  4997. {
  4998. psa_status_t status;
  4999. psa_key_slot_t *slot = NULL;
  5000. psa_se_drv_table_entry_t *driver = NULL;
  5001. size_t key_buffer_size;
  5002. *key = MBEDTLS_SVC_KEY_ID_INIT;
  5003. /* Reject any attempt to create a zero-length key so that we don't
  5004. * risk tripping up later, e.g. on a malloc(0) that returns NULL. */
  5005. if( psa_get_key_bits( attributes ) == 0 )
  5006. return( PSA_ERROR_INVALID_ARGUMENT );
  5007. /* Reject any attempt to create a public key. */
  5008. if( PSA_KEY_TYPE_IS_PUBLIC_KEY(attributes->core.type) )
  5009. return( PSA_ERROR_INVALID_ARGUMENT );
  5010. status = psa_start_key_creation( PSA_KEY_CREATION_GENERATE, attributes,
  5011. &slot, &driver );
  5012. if( status != PSA_SUCCESS )
  5013. goto exit;
  5014. /* In the case of a transparent key or an opaque key stored in local
  5015. * storage ( thus not in the case of generating a key in a secure element
  5016. * with storage ( MBEDTLS_PSA_CRYPTO_SE_C ) ),we have to allocate a
  5017. * buffer to hold the generated key material. */
  5018. if( slot->key.data == NULL )
  5019. {
  5020. if ( PSA_KEY_LIFETIME_GET_LOCATION( attributes->core.lifetime ) ==
  5021. PSA_KEY_LOCATION_LOCAL_STORAGE )
  5022. {
  5023. status = psa_validate_key_type_and_size_for_key_generation(
  5024. attributes->core.type, attributes->core.bits );
  5025. if( status != PSA_SUCCESS )
  5026. goto exit;
  5027. key_buffer_size = PSA_EXPORT_KEY_OUTPUT_SIZE(
  5028. attributes->core.type,
  5029. attributes->core.bits );
  5030. }
  5031. else
  5032. {
  5033. status = psa_driver_wrapper_get_key_buffer_size(
  5034. attributes, &key_buffer_size );
  5035. if( status != PSA_SUCCESS )
  5036. goto exit;
  5037. }
  5038. status = psa_allocate_buffer_to_slot( slot, key_buffer_size );
  5039. if( status != PSA_SUCCESS )
  5040. goto exit;
  5041. }
  5042. status = psa_driver_wrapper_generate_key( attributes,
  5043. slot->key.data, slot->key.bytes, &slot->key.bytes );
  5044. if( status != PSA_SUCCESS )
  5045. psa_remove_key_data_from_memory( slot );
  5046. exit:
  5047. if( status == PSA_SUCCESS )
  5048. status = psa_finish_key_creation( slot, driver, key );
  5049. if( status != PSA_SUCCESS )
  5050. psa_fail_key_creation( slot, driver );
  5051. return( status );
  5052. }
  5053. /****************************************************************/
  5054. /* Module setup */
  5055. /****************************************************************/
  5056. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  5057. psa_status_t mbedtls_psa_crypto_configure_entropy_sources(
  5058. void (* entropy_init )( mbedtls_entropy_context *ctx ),
  5059. void (* entropy_free )( mbedtls_entropy_context *ctx ) )
  5060. {
  5061. if( global_data.rng_state != RNG_NOT_INITIALIZED )
  5062. return( PSA_ERROR_BAD_STATE );
  5063. global_data.rng.entropy_init = entropy_init;
  5064. global_data.rng.entropy_free = entropy_free;
  5065. return( PSA_SUCCESS );
  5066. }
  5067. #endif /* !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) */
  5068. void mbedtls_psa_crypto_free( void )
  5069. {
  5070. psa_wipe_all_key_slots( );
  5071. if( global_data.rng_state != RNG_NOT_INITIALIZED )
  5072. {
  5073. mbedtls_psa_random_free( &global_data.rng );
  5074. }
  5075. /* Wipe all remaining data, including configuration.
  5076. * In particular, this sets all state indicator to the value
  5077. * indicating "uninitialized". */
  5078. mbedtls_platform_zeroize( &global_data, sizeof( global_data ) );
  5079. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  5080. /* Unregister all secure element drivers, so that we restart from
  5081. * a pristine state. */
  5082. psa_unregister_all_se_drivers( );
  5083. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  5084. }
  5085. #if defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS)
  5086. /** Recover a transaction that was interrupted by a power failure.
  5087. *
  5088. * This function is called during initialization, before psa_crypto_init()
  5089. * returns. If this function returns a failure status, the initialization
  5090. * fails.
  5091. */
  5092. static psa_status_t psa_crypto_recover_transaction(
  5093. const psa_crypto_transaction_t *transaction )
  5094. {
  5095. switch( transaction->unknown.type )
  5096. {
  5097. case PSA_CRYPTO_TRANSACTION_CREATE_KEY:
  5098. case PSA_CRYPTO_TRANSACTION_DESTROY_KEY:
  5099. /* TODO - fall through to the failure case until this
  5100. * is implemented.
  5101. * https://github.com/ARMmbed/mbed-crypto/issues/218
  5102. */
  5103. default:
  5104. /* We found an unsupported transaction in the storage.
  5105. * We don't know what state the storage is in. Give up. */
  5106. return( PSA_ERROR_DATA_INVALID );
  5107. }
  5108. }
  5109. #endif /* PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS */
  5110. psa_status_t psa_crypto_init( void )
  5111. {
  5112. psa_status_t status;
  5113. /* Double initialization is explicitly allowed. */
  5114. if( global_data.initialized != 0 )
  5115. return( PSA_SUCCESS );
  5116. /* Initialize and seed the random generator. */
  5117. mbedtls_psa_random_init( &global_data.rng );
  5118. global_data.rng_state = RNG_INITIALIZED;
  5119. status = mbedtls_psa_random_seed( &global_data.rng );
  5120. if( status != PSA_SUCCESS )
  5121. goto exit;
  5122. global_data.rng_state = RNG_SEEDED;
  5123. status = psa_initialize_key_slots( );
  5124. if( status != PSA_SUCCESS )
  5125. goto exit;
  5126. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  5127. status = psa_init_all_se_drivers( );
  5128. if( status != PSA_SUCCESS )
  5129. goto exit;
  5130. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  5131. #if defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS)
  5132. status = psa_crypto_load_transaction( );
  5133. if( status == PSA_SUCCESS )
  5134. {
  5135. status = psa_crypto_recover_transaction( &psa_crypto_transaction );
  5136. if( status != PSA_SUCCESS )
  5137. goto exit;
  5138. status = psa_crypto_stop_transaction( );
  5139. }
  5140. else if( status == PSA_ERROR_DOES_NOT_EXIST )
  5141. {
  5142. /* There's no transaction to complete. It's all good. */
  5143. status = PSA_SUCCESS;
  5144. }
  5145. #endif /* PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS */
  5146. /* All done. */
  5147. global_data.initialized = 1;
  5148. exit:
  5149. if( status != PSA_SUCCESS )
  5150. mbedtls_psa_crypto_free( );
  5151. return( status );
  5152. }
  5153. #endif /* MBEDTLS_PSA_CRYPTO_C */