pkwrite.h 4.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121
  1. /**
  2. * \file pkwrite.h
  3. *
  4. * \brief Internal defines shared by the PK write module
  5. */
  6. /*
  7. * Copyright The Mbed TLS Contributors
  8. * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
  9. */
  10. #ifndef MBEDTLS_PK_WRITE_H
  11. #define MBEDTLS_PK_WRITE_H
  12. #include "mbedtls/build_info.h"
  13. #include "mbedtls/pk.h"
  14. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  15. #include "psa/crypto.h"
  16. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  17. /*
  18. * Max sizes of key per types. Shown as tag + len (+ content).
  19. */
  20. #if defined(MBEDTLS_RSA_C)
  21. /*
  22. * RSA public keys:
  23. * SubjectPublicKeyInfo ::= SEQUENCE { 1 + 3
  24. * algorithm AlgorithmIdentifier, 1 + 1 (sequence)
  25. * + 1 + 1 + 9 (rsa oid)
  26. * + 1 + 1 (params null)
  27. * subjectPublicKey BIT STRING } 1 + 3 + (1 + below)
  28. * RSAPublicKey ::= SEQUENCE { 1 + 3
  29. * modulus INTEGER, -- n 1 + 3 + MPI_MAX + 1
  30. * publicExponent INTEGER -- e 1 + 3 + MPI_MAX + 1
  31. * }
  32. */
  33. #define MBEDTLS_PK_RSA_PUB_DER_MAX_BYTES (38 + 2 * MBEDTLS_MPI_MAX_SIZE)
  34. /*
  35. * RSA private keys:
  36. * RSAPrivateKey ::= SEQUENCE { 1 + 3
  37. * version Version, 1 + 1 + 1
  38. * modulus INTEGER, 1 + 3 + MPI_MAX + 1
  39. * publicExponent INTEGER, 1 + 3 + MPI_MAX + 1
  40. * privateExponent INTEGER, 1 + 3 + MPI_MAX + 1
  41. * prime1 INTEGER, 1 + 3 + MPI_MAX / 2 + 1
  42. * prime2 INTEGER, 1 + 3 + MPI_MAX / 2 + 1
  43. * exponent1 INTEGER, 1 + 3 + MPI_MAX / 2 + 1
  44. * exponent2 INTEGER, 1 + 3 + MPI_MAX / 2 + 1
  45. * coefficient INTEGER, 1 + 3 + MPI_MAX / 2 + 1
  46. * otherPrimeInfos OtherPrimeInfos OPTIONAL 0 (not supported)
  47. * }
  48. */
  49. #define MBEDTLS_MPI_MAX_SIZE_2 (MBEDTLS_MPI_MAX_SIZE / 2 + \
  50. MBEDTLS_MPI_MAX_SIZE % 2)
  51. #define MBEDTLS_PK_RSA_PRV_DER_MAX_BYTES (47 + 3 * MBEDTLS_MPI_MAX_SIZE \
  52. + 5 * MBEDTLS_MPI_MAX_SIZE_2)
  53. #else /* MBEDTLS_RSA_C */
  54. #define MBEDTLS_PK_RSA_PUB_DER_MAX_BYTES 0
  55. #define MBEDTLS_PK_RSA_PRV_DER_MAX_BYTES 0
  56. #endif /* MBEDTLS_RSA_C */
  57. #if defined(MBEDTLS_PK_HAVE_ECC_KEYS)
  58. /* Find the maximum number of bytes necessary to store an EC point. When USE_PSA
  59. * is defined this means looking for the maximum between PSA and built-in
  60. * supported curves. */
  61. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  62. #define MBEDTLS_PK_MAX_ECC_BYTES (PSA_BITS_TO_BYTES(PSA_VENDOR_ECC_MAX_CURVE_BITS) > \
  63. MBEDTLS_ECP_MAX_BYTES ? \
  64. PSA_BITS_TO_BYTES(PSA_VENDOR_ECC_MAX_CURVE_BITS) : \
  65. MBEDTLS_ECP_MAX_BYTES)
  66. #else /* MBEDTLS_USE_PSA_CRYPTO */
  67. #define MBEDTLS_PK_MAX_ECC_BYTES MBEDTLS_ECP_MAX_BYTES
  68. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  69. /*
  70. * EC public keys:
  71. * SubjectPublicKeyInfo ::= SEQUENCE { 1 + 2
  72. * algorithm AlgorithmIdentifier, 1 + 1 (sequence)
  73. * + 1 + 1 + 7 (ec oid)
  74. * + 1 + 1 + 9 (namedCurve oid)
  75. * subjectPublicKey BIT STRING 1 + 2 + 1 [1]
  76. * + 1 (point format) [1]
  77. * + 2 * ECP_MAX (coords) [1]
  78. * }
  79. */
  80. #define MBEDTLS_PK_ECP_PUB_DER_MAX_BYTES (30 + 2 * MBEDTLS_PK_MAX_ECC_BYTES)
  81. /*
  82. * EC private keys:
  83. * ECPrivateKey ::= SEQUENCE { 1 + 2
  84. * version INTEGER , 1 + 1 + 1
  85. * privateKey OCTET STRING, 1 + 1 + ECP_MAX
  86. * parameters [0] ECParameters OPTIONAL, 1 + 1 + (1 + 1 + 9)
  87. * publicKey [1] BIT STRING OPTIONAL 1 + 2 + [1] above
  88. * }
  89. */
  90. #define MBEDTLS_PK_ECP_PRV_DER_MAX_BYTES (29 + 3 * MBEDTLS_PK_MAX_ECC_BYTES)
  91. #else /* MBEDTLS_PK_HAVE_ECC_KEYS */
  92. #define MBEDTLS_PK_ECP_PUB_DER_MAX_BYTES 0
  93. #define MBEDTLS_PK_ECP_PRV_DER_MAX_BYTES 0
  94. #endif /* MBEDTLS_PK_HAVE_ECC_KEYS */
  95. /* Define the maximum available public key DER length based on the supported
  96. * key types (EC and/or RSA). */
  97. #if (MBEDTLS_PK_RSA_PUB_DER_MAX_BYTES > MBEDTLS_PK_ECP_PUB_DER_MAX_BYTES)
  98. #define MBEDTLS_PK_WRITE_PUBKEY_MAX_SIZE MBEDTLS_PK_RSA_PUB_DER_MAX_BYTES
  99. #else
  100. #define MBEDTLS_PK_WRITE_PUBKEY_MAX_SIZE MBEDTLS_PK_ECP_PUB_DER_MAX_BYTES
  101. #endif
  102. #endif /* MBEDTLS_PK_WRITE_H */