psa_crypto.c 311 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139414041414142414341444145414641474148414941504151415241534154415541564157415841594160416141624163416441654166416741684169417041714172417341744175417641774178417941804181418241834184418541864187418841894190419141924193419441954196419741984199420042014202420342044205420642074208420942104211421242134214421542164217421842194220422142224223422442254226422742284229423042314232423342344235423642374238423942404241424242434244424542464247424842494250425142524253425442554256425742584259426042614262426342644265426642674268426942704271427242734274427542764277427842794280428142824283428442854286428742884289429042914292429342944295429642974298429943004301430243034304430543064307430843094310431143124313431443154316431743184319432043214322432343244325432643274328432943304331433243334334433543364337433843394340434143424343434443454346434743484349435043514352435343544355435643574358435943604361436243634364436543664367436843694370437143724373437443754376437743784379438043814382438343844385438643874388438943904391439243934394439543964397439843994400440144024403440444054406440744084409441044114412441344144415441644174418441944204421442244234424442544264427442844294430443144324433443444354436443744384439444044414442444344444445444644474448444944504451445244534454445544564457445844594460446144624463446444654466446744684469447044714472447344744475447644774478447944804481448244834484448544864487448844894490449144924493449444954496449744984499450045014502450345044505450645074508450945104511451245134514451545164517451845194520452145224523452445254526452745284529453045314532453345344535453645374538453945404541454245434544454545464547454845494550455145524553455445554556455745584559456045614562456345644565456645674568456945704571457245734574457545764577457845794580458145824583458445854586458745884589459045914592459345944595459645974598459946004601460246034604460546064607460846094610461146124613461446154616461746184619462046214622462346244625462646274628462946304631463246334634463546364637463846394640464146424643464446454646464746484649465046514652465346544655465646574658465946604661466246634664466546664667466846694670467146724673467446754676467746784679468046814682468346844685468646874688468946904691469246934694469546964697469846994700470147024703470447054706470747084709471047114712471347144715471647174718471947204721472247234724472547264727472847294730473147324733473447354736473747384739474047414742474347444745474647474748474947504751475247534754475547564757475847594760476147624763476447654766476747684769477047714772477347744775477647774778477947804781478247834784478547864787478847894790479147924793479447954796479747984799480048014802480348044805480648074808480948104811481248134814481548164817481848194820482148224823482448254826482748284829483048314832483348344835483648374838483948404841484248434844484548464847484848494850485148524853485448554856485748584859486048614862486348644865486648674868486948704871487248734874487548764877487848794880488148824883488448854886488748884889489048914892489348944895489648974898489949004901490249034904490549064907490849094910491149124913491449154916491749184919492049214922492349244925492649274928492949304931493249334934493549364937493849394940494149424943494449454946494749484949495049514952495349544955495649574958495949604961496249634964496549664967496849694970497149724973497449754976497749784979498049814982498349844985498649874988498949904991499249934994499549964997499849995000500150025003500450055006500750085009501050115012501350145015501650175018501950205021502250235024502550265027502850295030503150325033503450355036503750385039504050415042504350445045504650475048504950505051505250535054505550565057505850595060506150625063506450655066506750685069507050715072507350745075507650775078507950805081508250835084508550865087508850895090509150925093509450955096509750985099510051015102510351045105510651075108510951105111511251135114511551165117511851195120512151225123512451255126512751285129513051315132513351345135513651375138513951405141514251435144514551465147514851495150515151525153515451555156515751585159516051615162516351645165516651675168516951705171517251735174517551765177517851795180518151825183518451855186518751885189519051915192519351945195519651975198519952005201520252035204520552065207520852095210521152125213521452155216521752185219522052215222522352245225522652275228522952305231523252335234523552365237523852395240524152425243524452455246524752485249525052515252525352545255525652575258525952605261526252635264526552665267526852695270527152725273527452755276527752785279528052815282528352845285528652875288528952905291529252935294529552965297529852995300530153025303530453055306530753085309531053115312531353145315531653175318531953205321532253235324532553265327532853295330533153325333533453355336533753385339534053415342534353445345534653475348534953505351535253535354535553565357535853595360536153625363536453655366536753685369537053715372537353745375537653775378537953805381538253835384538553865387538853895390539153925393539453955396539753985399540054015402540354045405540654075408540954105411541254135414541554165417541854195420542154225423542454255426542754285429543054315432543354345435543654375438543954405441544254435444544554465447544854495450545154525453545454555456545754585459546054615462546354645465546654675468546954705471547254735474547554765477547854795480548154825483548454855486548754885489549054915492549354945495549654975498549955005501550255035504550555065507550855095510551155125513551455155516551755185519552055215522552355245525552655275528552955305531553255335534553555365537553855395540554155425543554455455546554755485549555055515552555355545555555655575558555955605561556255635564556555665567556855695570557155725573557455755576557755785579558055815582558355845585558655875588558955905591559255935594559555965597559855995600560156025603560456055606560756085609561056115612561356145615561656175618561956205621562256235624562556265627562856295630563156325633563456355636563756385639564056415642564356445645564656475648564956505651565256535654565556565657565856595660566156625663566456655666566756685669567056715672567356745675567656775678567956805681568256835684568556865687568856895690569156925693569456955696569756985699570057015702570357045705570657075708570957105711571257135714571557165717571857195720572157225723572457255726572757285729573057315732573357345735573657375738573957405741574257435744574557465747574857495750575157525753575457555756575757585759576057615762576357645765576657675768576957705771577257735774577557765777577857795780578157825783578457855786578757885789579057915792579357945795579657975798579958005801580258035804580558065807580858095810581158125813581458155816581758185819582058215822582358245825582658275828582958305831583258335834583558365837583858395840584158425843584458455846584758485849585058515852585358545855585658575858585958605861586258635864586558665867586858695870587158725873587458755876587758785879588058815882588358845885588658875888588958905891589258935894589558965897589858995900590159025903590459055906590759085909591059115912591359145915591659175918591959205921592259235924592559265927592859295930593159325933593459355936593759385939594059415942594359445945594659475948594959505951595259535954595559565957595859595960596159625963596459655966596759685969597059715972597359745975597659775978597959805981598259835984598559865987598859895990599159925993599459955996599759985999600060016002600360046005600660076008600960106011601260136014601560166017601860196020602160226023602460256026602760286029603060316032603360346035603660376038603960406041604260436044604560466047604860496050605160526053605460556056605760586059606060616062606360646065606660676068606960706071607260736074607560766077607860796080608160826083608460856086608760886089609060916092609360946095609660976098609961006101610261036104610561066107610861096110611161126113611461156116611761186119612061216122612361246125612661276128612961306131613261336134613561366137613861396140614161426143614461456146614761486149615061516152615361546155615661576158615961606161616261636164616561666167616861696170617161726173617461756176617761786179618061816182618361846185618661876188618961906191619261936194619561966197619861996200620162026203620462056206620762086209621062116212621362146215621662176218621962206221622262236224622562266227622862296230623162326233623462356236623762386239624062416242624362446245624662476248624962506251625262536254625562566257625862596260626162626263626462656266626762686269627062716272627362746275627662776278627962806281628262836284628562866287628862896290629162926293629462956296629762986299630063016302630363046305630663076308630963106311631263136314631563166317631863196320632163226323632463256326632763286329633063316332633363346335633663376338633963406341634263436344634563466347634863496350635163526353635463556356635763586359636063616362636363646365636663676368636963706371637263736374637563766377637863796380638163826383638463856386638763886389639063916392639363946395639663976398639964006401640264036404640564066407640864096410641164126413641464156416641764186419642064216422642364246425642664276428642964306431643264336434643564366437643864396440644164426443644464456446644764486449645064516452645364546455645664576458645964606461646264636464646564666467646864696470647164726473647464756476647764786479648064816482648364846485648664876488648964906491649264936494649564966497649864996500650165026503650465056506650765086509651065116512651365146515651665176518651965206521652265236524652565266527652865296530653165326533653465356536653765386539654065416542654365446545654665476548654965506551655265536554655565566557655865596560656165626563656465656566656765686569657065716572657365746575657665776578657965806581658265836584658565866587658865896590659165926593659465956596659765986599660066016602660366046605660666076608660966106611661266136614661566166617661866196620662166226623662466256626662766286629663066316632663366346635663666376638663966406641664266436644664566466647664866496650665166526653665466556656665766586659666066616662666366646665666666676668666966706671667266736674667566766677667866796680668166826683668466856686668766886689669066916692669366946695669666976698669967006701670267036704670567066707670867096710671167126713671467156716671767186719672067216722672367246725672667276728672967306731673267336734673567366737673867396740674167426743674467456746674767486749675067516752675367546755675667576758675967606761676267636764676567666767676867696770677167726773677467756776677767786779678067816782678367846785678667876788678967906791679267936794679567966797679867996800680168026803680468056806680768086809681068116812681368146815681668176818681968206821682268236824682568266827682868296830683168326833683468356836683768386839684068416842684368446845684668476848684968506851685268536854685568566857685868596860686168626863686468656866686768686869687068716872687368746875687668776878687968806881688268836884688568866887688868896890689168926893689468956896689768986899690069016902690369046905690669076908690969106911691269136914691569166917691869196920692169226923692469256926692769286929693069316932693369346935693669376938693969406941694269436944694569466947694869496950695169526953695469556956695769586959696069616962696369646965696669676968696969706971697269736974697569766977697869796980698169826983698469856986698769886989699069916992699369946995699669976998699970007001700270037004700570067007700870097010701170127013701470157016701770187019702070217022702370247025702670277028702970307031703270337034703570367037703870397040704170427043704470457046704770487049705070517052705370547055705670577058705970607061706270637064706570667067706870697070707170727073707470757076707770787079708070817082708370847085708670877088708970907091709270937094709570967097709870997100710171027103710471057106710771087109711071117112711371147115711671177118711971207121712271237124712571267127712871297130713171327133713471357136713771387139714071417142714371447145714671477148714971507151715271537154715571567157715871597160716171627163716471657166716771687169717071717172717371747175717671777178717971807181718271837184718571867187718871897190719171927193719471957196719771987199720072017202720372047205720672077208720972107211721272137214721572167217721872197220722172227223722472257226722772287229723072317232723372347235723672377238723972407241724272437244724572467247724872497250725172527253725472557256725772587259726072617262726372647265726672677268726972707271727272737274727572767277727872797280728172827283728472857286728772887289729072917292729372947295729672977298729973007301730273037304730573067307730873097310731173127313731473157316731773187319732073217322732373247325732673277328732973307331733273337334733573367337733873397340734173427343734473457346734773487349735073517352735373547355735673577358735973607361736273637364736573667367736873697370737173727373737473757376737773787379738073817382738373847385738673877388738973907391739273937394739573967397739873997400740174027403740474057406740774087409741074117412741374147415741674177418741974207421742274237424742574267427742874297430743174327433743474357436743774387439744074417442744374447445744674477448744974507451745274537454745574567457745874597460746174627463746474657466746774687469747074717472747374747475747674777478747974807481748274837484748574867487748874897490749174927493749474957496749774987499750075017502750375047505750675077508750975107511751275137514751575167517751875197520752175227523752475257526752775287529753075317532753375347535753675377538753975407541754275437544754575467547754875497550755175527553755475557556755775587559756075617562756375647565756675677568756975707571757275737574757575767577757875797580758175827583758475857586758775887589759075917592759375947595759675977598759976007601760276037604760576067607760876097610761176127613761476157616761776187619762076217622762376247625762676277628762976307631763276337634763576367637763876397640764176427643764476457646764776487649765076517652765376547655765676577658765976607661766276637664766576667667766876697670767176727673767476757676767776787679768076817682768376847685768676877688768976907691769276937694769576967697769876997700770177027703770477057706770777087709771077117712771377147715771677177718771977207721772277237724772577267727772877297730773177327733773477357736773777387739774077417742774377447745774677477748774977507751775277537754775577567757775877597760776177627763776477657766776777687769777077717772777377747775777677777778777977807781778277837784778577867787778877897790779177927793779477957796779777987799780078017802780378047805780678077808780978107811781278137814781578167817781878197820782178227823782478257826782778287829783078317832783378347835783678377838783978407841784278437844784578467847784878497850785178527853785478557856785778587859786078617862786378647865786678677868786978707871787278737874787578767877787878797880788178827883788478857886788778887889789078917892789378947895789678977898789979007901790279037904790579067907790879097910791179127913791479157916791779187919792079217922792379247925792679277928792979307931793279337934793579367937793879397940794179427943794479457946794779487949795079517952795379547955795679577958795979607961796279637964796579667967796879697970797179727973797479757976797779787979798079817982798379847985798679877988798979907991799279937994799579967997799879998000800180028003800480058006800780088009801080118012801380148015801680178018801980208021802280238024802580268027802880298030803180328033803480358036803780388039804080418042804380448045804680478048804980508051805280538054805580568057805880598060806180628063806480658066806780688069807080718072807380748075807680778078807980808081808280838084808580868087808880898090809180928093809480958096809780988099810081018102810381048105810681078108810981108111811281138114811581168117811881198120812181228123812481258126812781288129813081318132813381348135813681378138813981408141814281438144814581468147814881498150815181528153815481558156815781588159816081618162816381648165816681678168816981708171817281738174817581768177817881798180818181828183818481858186818781888189819081918192819381948195819681978198819982008201820282038204820582068207820882098210821182128213821482158216821782188219822082218222822382248225822682278228822982308231823282338234823582368237823882398240824182428243824482458246824782488249825082518252825382548255825682578258825982608261826282638264826582668267826882698270827182728273827482758276827782788279828082818282828382848285828682878288828982908291829282938294829582968297829882998300830183028303830483058306830783088309831083118312831383148315831683178318831983208321832283238324832583268327832883298330833183328333833483358336833783388339834083418342834383448345834683478348834983508351835283538354835583568357835883598360836183628363836483658366836783688369837083718372837383748375837683778378837983808381838283838384838583868387838883898390839183928393839483958396839783988399840084018402840384048405840684078408840984108411841284138414841584168417841884198420842184228423842484258426842784288429843084318432843384348435843684378438843984408441844284438444844584468447844884498450845184528453845484558456845784588459846084618462846384648465846684678468846984708471847284738474847584768477847884798480848184828483848484858486848784888489849084918492849384948495849684978498849985008501850285038504850585068507850885098510851185128513851485158516851785188519852085218522852385248525852685278528852985308531853285338534853585368537853885398540854185428543854485458546854785488549855085518552855385548555855685578558855985608561856285638564856585668567856885698570857185728573857485758576857785788579858085818582858385848585858685878588858985908591859285938594859585968597859885998600860186028603860486058606860786088609861086118612861386148615861686178618861986208621862286238624862586268627862886298630863186328633863486358636863786388639864086418642864386448645864686478648864986508651865286538654865586568657865886598660866186628663866486658666866786688669867086718672867386748675867686778678867986808681868286838684868586868687868886898690869186928693869486958696869786988699870087018702870387048705870687078708870987108711871287138714871587168717871887198720872187228723872487258726872787288729873087318732873387348735873687378738873987408741874287438744874587468747874887498750875187528753875487558756875787588759876087618762876387648765876687678768876987708771877287738774877587768777877887798780878187828783878487858786878787888789879087918792879387948795879687978798879988008801880288038804880588068807880888098810881188128813881488158816881788188819882088218822882388248825882688278828882988308831883288338834883588368837883888398840884188428843884488458846884788488849885088518852885388548855885688578858885988608861886288638864886588668867886888698870887188728873887488758876887788788879888088818882888388848885888688878888888988908891889288938894889588968897889888998900890189028903890489058906890789088909891089118912891389148915891689178918891989208921892289238924892589268927892889298930893189328933893489358936893789388939894089418942894389448945894689478948894989508951895289538954895589568957895889598960896189628963896489658966896789688969897089718972897389748975897689778978897989808981898289838984898589868987898889898990899189928993899489958996899789988999900090019002900390049005900690079008900990109011901290139014901590169017901890199020902190229023902490259026902790289029903090319032903390349035903690379038903990409041904290439044904590469047904890499050905190529053905490559056905790589059906090619062906390649065906690679068906990709071907290739074907590769077907890799080908190829083908490859086908790889089909090919092909390949095909690979098909991009101910291039104910591069107910891099110911191129113911491159116911791189119912091219122912391249125912691279128912991309131913291339134913591369137913891399140914191429143914491459146914791489149915091519152915391549155915691579158915991609161916291639164916591669167916891699170917191729173917491759176917791789179918091819182918391849185918691879188918991909191919291939194919591969197919891999200920192029203920492059206920792089209921092119212921392149215921692179218921992209221922292239224922592269227922892299230923192329233
  1. /*
  2. * PSA crypto layer on top of Mbed TLS crypto
  3. */
  4. /*
  5. * Copyright The Mbed TLS Contributors
  6. * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
  7. */
  8. #include "common.h"
  9. #include "psa_crypto_core_common.h"
  10. #if defined(MBEDTLS_PSA_CRYPTO_C)
  11. #if defined(MBEDTLS_PSA_CRYPTO_CONFIG)
  12. #include "check_crypto_config.h"
  13. #endif
  14. #include "psa/crypto.h"
  15. #include "psa/crypto_values.h"
  16. #include "psa_crypto_cipher.h"
  17. #include "psa_crypto_core.h"
  18. #include "psa_crypto_invasive.h"
  19. #include "psa_crypto_driver_wrappers.h"
  20. #include "psa_crypto_driver_wrappers_no_static.h"
  21. #include "psa_crypto_ecp.h"
  22. #include "psa_crypto_ffdh.h"
  23. #include "psa_crypto_hash.h"
  24. #include "psa_crypto_mac.h"
  25. #include "psa_crypto_rsa.h"
  26. #include "psa_crypto_ecp.h"
  27. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  28. #include "psa_crypto_se.h"
  29. #endif
  30. #include "psa_crypto_slot_management.h"
  31. /* Include internal declarations that are useful for implementing persistently
  32. * stored keys. */
  33. #include "psa_crypto_storage.h"
  34. #include "psa_crypto_random_impl.h"
  35. #include <stdlib.h>
  36. #include <string.h>
  37. #include "mbedtls/platform.h"
  38. #include "mbedtls/aes.h"
  39. #include "mbedtls/asn1.h"
  40. #include "mbedtls/asn1write.h"
  41. #include "mbedtls/bignum.h"
  42. #include "mbedtls/camellia.h"
  43. #include "mbedtls/chacha20.h"
  44. #include "mbedtls/chachapoly.h"
  45. #include "mbedtls/cipher.h"
  46. #include "mbedtls/ccm.h"
  47. #include "mbedtls/cmac.h"
  48. #include "mbedtls/constant_time.h"
  49. #include "mbedtls/des.h"
  50. #include "mbedtls/ecdh.h"
  51. #include "mbedtls/ecp.h"
  52. #include "mbedtls/entropy.h"
  53. #include "mbedtls/error.h"
  54. #include "mbedtls/gcm.h"
  55. #include "mbedtls/md5.h"
  56. #include "mbedtls/pk.h"
  57. #include "pk_wrap.h"
  58. #include "mbedtls/platform_util.h"
  59. #include "mbedtls/error.h"
  60. #include "mbedtls/ripemd160.h"
  61. #include "mbedtls/rsa.h"
  62. #include "mbedtls/sha1.h"
  63. #include "mbedtls/sha256.h"
  64. #include "mbedtls/sha512.h"
  65. #include "mbedtls/psa_util.h"
  66. #include "mbedtls/threading.h"
  67. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF) || \
  68. defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT) || \
  69. defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND)
  70. #define BUILTIN_ALG_ANY_HKDF 1
  71. #endif
  72. /****************************************************************/
  73. /* Global data, support functions and library management */
  74. /****************************************************************/
  75. static int key_type_is_raw_bytes(psa_key_type_t type)
  76. {
  77. return PSA_KEY_TYPE_IS_UNSTRUCTURED(type);
  78. }
  79. /* Values for psa_global_data_t::rng_state */
  80. #define RNG_NOT_INITIALIZED 0
  81. #define RNG_INITIALIZED 1
  82. #define RNG_SEEDED 2
  83. /* IDs for PSA crypto subsystems. Starts at 1 to catch potential uninitialized
  84. * variables as arguments. */
  85. typedef enum {
  86. PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS = 1,
  87. PSA_CRYPTO_SUBSYSTEM_KEY_SLOTS,
  88. PSA_CRYPTO_SUBSYSTEM_RNG,
  89. PSA_CRYPTO_SUBSYSTEM_TRANSACTION,
  90. } mbedtls_psa_crypto_subsystem;
  91. /* Initialization flags for global_data::initialized */
  92. #define PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS_INITIALIZED 0x01
  93. #define PSA_CRYPTO_SUBSYSTEM_KEY_SLOTS_INITIALIZED 0x02
  94. #define PSA_CRYPTO_SUBSYSTEM_TRANSACTION_INITIALIZED 0x04
  95. #define PSA_CRYPTO_SUBSYSTEM_ALL_INITIALISED ( \
  96. PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS_INITIALIZED | \
  97. PSA_CRYPTO_SUBSYSTEM_KEY_SLOTS_INITIALIZED | \
  98. PSA_CRYPTO_SUBSYSTEM_TRANSACTION_INITIALIZED)
  99. typedef struct {
  100. uint8_t initialized;
  101. uint8_t rng_state;
  102. mbedtls_psa_random_context_t rng;
  103. } psa_global_data_t;
  104. static psa_global_data_t global_data;
  105. static uint8_t psa_get_initialized(void)
  106. {
  107. uint8_t initialized;
  108. #if defined(MBEDTLS_THREADING_C)
  109. mbedtls_mutex_lock(&mbedtls_threading_psa_rngdata_mutex);
  110. #endif /* defined(MBEDTLS_THREADING_C) */
  111. initialized = global_data.rng_state == RNG_SEEDED;
  112. #if defined(MBEDTLS_THREADING_C)
  113. mbedtls_mutex_unlock(&mbedtls_threading_psa_rngdata_mutex);
  114. #endif /* defined(MBEDTLS_THREADING_C) */
  115. #if defined(MBEDTLS_THREADING_C)
  116. mbedtls_mutex_lock(&mbedtls_threading_psa_globaldata_mutex);
  117. #endif /* defined(MBEDTLS_THREADING_C) */
  118. initialized =
  119. (initialized && (global_data.initialized == PSA_CRYPTO_SUBSYSTEM_ALL_INITIALISED));
  120. #if defined(MBEDTLS_THREADING_C)
  121. mbedtls_mutex_unlock(&mbedtls_threading_psa_globaldata_mutex);
  122. #endif /* defined(MBEDTLS_THREADING_C) */
  123. return initialized;
  124. }
  125. static uint8_t psa_get_drivers_initialized(void)
  126. {
  127. uint8_t initialized;
  128. #if defined(MBEDTLS_THREADING_C)
  129. mbedtls_mutex_lock(&mbedtls_threading_psa_globaldata_mutex);
  130. #endif /* defined(MBEDTLS_THREADING_C) */
  131. initialized = (global_data.initialized & PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS_INITIALIZED) != 0;
  132. #if defined(MBEDTLS_THREADING_C)
  133. mbedtls_mutex_unlock(&mbedtls_threading_psa_globaldata_mutex);
  134. #endif /* defined(MBEDTLS_THREADING_C) */
  135. return initialized;
  136. }
  137. #define GUARD_MODULE_INITIALIZED \
  138. if (psa_get_initialized() == 0) \
  139. return PSA_ERROR_BAD_STATE;
  140. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  141. /* Declare a local copy of an input buffer and a variable that will be used
  142. * to store a pointer to the start of the buffer.
  143. *
  144. * Note: This macro must be called before any operations which may jump to
  145. * the exit label, so that the local input copy object is safe to be freed.
  146. *
  147. * Assumptions:
  148. * - input is the name of a pointer to the buffer to be copied
  149. * - The name LOCAL_INPUT_COPY_OF_input is unused in the current scope
  150. * - input_copy_name is a name that is unused in the current scope
  151. */
  152. #define LOCAL_INPUT_DECLARE(input, input_copy_name) \
  153. psa_crypto_local_input_t LOCAL_INPUT_COPY_OF_##input = PSA_CRYPTO_LOCAL_INPUT_INIT; \
  154. const uint8_t *input_copy_name = NULL;
  155. /* Allocate a copy of the buffer input and set the pointer input_copy to
  156. * point to the start of the copy.
  157. *
  158. * Assumptions:
  159. * - psa_status_t status exists
  160. * - An exit label is declared
  161. * - input is the name of a pointer to the buffer to be copied
  162. * - LOCAL_INPUT_DECLARE(input, input_copy) has previously been called
  163. */
  164. #define LOCAL_INPUT_ALLOC(input, length, input_copy) \
  165. status = psa_crypto_local_input_alloc(input, length, \
  166. &LOCAL_INPUT_COPY_OF_##input); \
  167. if (status != PSA_SUCCESS) { \
  168. goto exit; \
  169. } \
  170. input_copy = LOCAL_INPUT_COPY_OF_##input.buffer;
  171. /* Free the local input copy allocated previously by LOCAL_INPUT_ALLOC()
  172. *
  173. * Assumptions:
  174. * - input_copy is the name of the input copy pointer set by LOCAL_INPUT_ALLOC()
  175. * - input is the name of the original buffer that was copied
  176. */
  177. #define LOCAL_INPUT_FREE(input, input_copy) \
  178. input_copy = NULL; \
  179. psa_crypto_local_input_free(&LOCAL_INPUT_COPY_OF_##input);
  180. /* Declare a local copy of an output buffer and a variable that will be used
  181. * to store a pointer to the start of the buffer.
  182. *
  183. * Note: This macro must be called before any operations which may jump to
  184. * the exit label, so that the local output copy object is safe to be freed.
  185. *
  186. * Assumptions:
  187. * - output is the name of a pointer to the buffer to be copied
  188. * - The name LOCAL_OUTPUT_COPY_OF_output is unused in the current scope
  189. * - output_copy_name is a name that is unused in the current scope
  190. */
  191. #define LOCAL_OUTPUT_DECLARE(output, output_copy_name) \
  192. psa_crypto_local_output_t LOCAL_OUTPUT_COPY_OF_##output = PSA_CRYPTO_LOCAL_OUTPUT_INIT; \
  193. uint8_t *output_copy_name = NULL;
  194. /* Allocate a copy of the buffer output and set the pointer output_copy to
  195. * point to the start of the copy.
  196. *
  197. * Assumptions:
  198. * - psa_status_t status exists
  199. * - An exit label is declared
  200. * - output is the name of a pointer to the buffer to be copied
  201. * - LOCAL_OUTPUT_DECLARE(output, output_copy) has previously been called
  202. */
  203. #define LOCAL_OUTPUT_ALLOC(output, length, output_copy) \
  204. status = psa_crypto_local_output_alloc(output, length, \
  205. &LOCAL_OUTPUT_COPY_OF_##output); \
  206. if (status != PSA_SUCCESS) { \
  207. goto exit; \
  208. } \
  209. output_copy = LOCAL_OUTPUT_COPY_OF_##output.buffer;
  210. /* Free the local output copy allocated previously by LOCAL_OUTPUT_ALLOC()
  211. * after first copying back its contents to the original buffer.
  212. *
  213. * Assumptions:
  214. * - psa_status_t status exists
  215. * - output_copy is the name of the output copy pointer set by LOCAL_OUTPUT_ALLOC()
  216. * - output is the name of the original buffer that was copied
  217. */
  218. #define LOCAL_OUTPUT_FREE(output, output_copy) \
  219. output_copy = NULL; \
  220. do { \
  221. psa_status_t local_output_status; \
  222. local_output_status = psa_crypto_local_output_free(&LOCAL_OUTPUT_COPY_OF_##output); \
  223. if (local_output_status != PSA_SUCCESS) { \
  224. /* Since this error case is an internal error, it's more serious than \
  225. * any existing error code and so it's fine to overwrite the existing \
  226. * status. */ \
  227. status = local_output_status; \
  228. } \
  229. } while (0)
  230. #else /* !MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS */
  231. #define LOCAL_INPUT_DECLARE(input, input_copy_name) \
  232. const uint8_t *input_copy_name = NULL;
  233. #define LOCAL_INPUT_ALLOC(input, length, input_copy) \
  234. input_copy = input;
  235. #define LOCAL_INPUT_FREE(input, input_copy) \
  236. input_copy = NULL;
  237. #define LOCAL_OUTPUT_DECLARE(output, output_copy_name) \
  238. uint8_t *output_copy_name = NULL;
  239. #define LOCAL_OUTPUT_ALLOC(output, length, output_copy) \
  240. output_copy = output;
  241. #define LOCAL_OUTPUT_FREE(output, output_copy) \
  242. output_copy = NULL;
  243. #endif /* !MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS */
  244. int psa_can_do_hash(psa_algorithm_t hash_alg)
  245. {
  246. (void) hash_alg;
  247. return psa_get_drivers_initialized();
  248. }
  249. int psa_can_do_cipher(psa_key_type_t key_type, psa_algorithm_t cipher_alg)
  250. {
  251. (void) key_type;
  252. (void) cipher_alg;
  253. return psa_get_drivers_initialized();
  254. }
  255. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_IMPORT) || \
  256. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_PUBLIC_KEY) || \
  257. defined(PSA_WANT_KEY_TYPE_DH_KEY_PAIR_GENERATE)
  258. static int psa_is_dh_key_size_valid(size_t bits)
  259. {
  260. switch (bits) {
  261. #if defined(PSA_WANT_DH_RFC7919_2048)
  262. case 2048:
  263. return 1;
  264. #endif /* PSA_WANT_DH_RFC7919_2048 */
  265. #if defined(PSA_WANT_DH_RFC7919_3072)
  266. case 3072:
  267. return 1;
  268. #endif /* PSA_WANT_DH_RFC7919_3072 */
  269. #if defined(PSA_WANT_DH_RFC7919_4096)
  270. case 4096:
  271. return 1;
  272. #endif /* PSA_WANT_DH_RFC7919_4096 */
  273. #if defined(PSA_WANT_DH_RFC7919_6144)
  274. case 6144:
  275. return 1;
  276. #endif /* PSA_WANT_DH_RFC7919_6144 */
  277. #if defined(PSA_WANT_DH_RFC7919_8192)
  278. case 8192:
  279. return 1;
  280. #endif /* PSA_WANT_DH_RFC7919_8192 */
  281. default:
  282. return 0;
  283. }
  284. }
  285. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_IMPORT ||
  286. MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_PUBLIC_KEY ||
  287. PSA_WANT_KEY_TYPE_DH_KEY_PAIR_GENERATE */
  288. psa_status_t mbedtls_to_psa_error(int ret)
  289. {
  290. /* Mbed TLS error codes can combine a high-level error code and a
  291. * low-level error code. The low-level error usually reflects the
  292. * root cause better, so dispatch on that preferably. */
  293. int low_level_ret = -(-ret & 0x007f);
  294. switch (low_level_ret != 0 ? low_level_ret : ret) {
  295. case 0:
  296. return PSA_SUCCESS;
  297. #if defined(MBEDTLS_AES_C)
  298. case MBEDTLS_ERR_AES_INVALID_KEY_LENGTH:
  299. case MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH:
  300. return PSA_ERROR_NOT_SUPPORTED;
  301. case MBEDTLS_ERR_AES_BAD_INPUT_DATA:
  302. return PSA_ERROR_INVALID_ARGUMENT;
  303. #endif
  304. #if defined(MBEDTLS_ASN1_PARSE_C) || defined(MBEDTLS_ASN1_WRITE_C)
  305. case MBEDTLS_ERR_ASN1_OUT_OF_DATA:
  306. case MBEDTLS_ERR_ASN1_UNEXPECTED_TAG:
  307. case MBEDTLS_ERR_ASN1_INVALID_LENGTH:
  308. case MBEDTLS_ERR_ASN1_LENGTH_MISMATCH:
  309. case MBEDTLS_ERR_ASN1_INVALID_DATA:
  310. return PSA_ERROR_INVALID_ARGUMENT;
  311. case MBEDTLS_ERR_ASN1_ALLOC_FAILED:
  312. return PSA_ERROR_INSUFFICIENT_MEMORY;
  313. case MBEDTLS_ERR_ASN1_BUF_TOO_SMALL:
  314. return PSA_ERROR_BUFFER_TOO_SMALL;
  315. #endif
  316. #if defined(MBEDTLS_CAMELLIA_C)
  317. case MBEDTLS_ERR_CAMELLIA_BAD_INPUT_DATA:
  318. case MBEDTLS_ERR_CAMELLIA_INVALID_INPUT_LENGTH:
  319. return PSA_ERROR_NOT_SUPPORTED;
  320. #endif
  321. #if defined(MBEDTLS_CCM_C)
  322. case MBEDTLS_ERR_CCM_BAD_INPUT:
  323. return PSA_ERROR_INVALID_ARGUMENT;
  324. case MBEDTLS_ERR_CCM_AUTH_FAILED:
  325. return PSA_ERROR_INVALID_SIGNATURE;
  326. #endif
  327. #if defined(MBEDTLS_CHACHA20_C)
  328. case MBEDTLS_ERR_CHACHA20_BAD_INPUT_DATA:
  329. return PSA_ERROR_INVALID_ARGUMENT;
  330. #endif
  331. #if defined(MBEDTLS_CHACHAPOLY_C)
  332. case MBEDTLS_ERR_CHACHAPOLY_BAD_STATE:
  333. return PSA_ERROR_BAD_STATE;
  334. case MBEDTLS_ERR_CHACHAPOLY_AUTH_FAILED:
  335. return PSA_ERROR_INVALID_SIGNATURE;
  336. #endif
  337. #if defined(MBEDTLS_CIPHER_C)
  338. case MBEDTLS_ERR_CIPHER_FEATURE_UNAVAILABLE:
  339. return PSA_ERROR_NOT_SUPPORTED;
  340. case MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA:
  341. return PSA_ERROR_INVALID_ARGUMENT;
  342. case MBEDTLS_ERR_CIPHER_ALLOC_FAILED:
  343. return PSA_ERROR_INSUFFICIENT_MEMORY;
  344. case MBEDTLS_ERR_CIPHER_INVALID_PADDING:
  345. return PSA_ERROR_INVALID_PADDING;
  346. case MBEDTLS_ERR_CIPHER_FULL_BLOCK_EXPECTED:
  347. return PSA_ERROR_INVALID_ARGUMENT;
  348. case MBEDTLS_ERR_CIPHER_AUTH_FAILED:
  349. return PSA_ERROR_INVALID_SIGNATURE;
  350. case MBEDTLS_ERR_CIPHER_INVALID_CONTEXT:
  351. return PSA_ERROR_CORRUPTION_DETECTED;
  352. #endif
  353. #if !(defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) || \
  354. defined(MBEDTLS_PSA_HMAC_DRBG_MD_TYPE))
  355. /* Only check CTR_DRBG error codes if underlying mbedtls_xxx
  356. * functions are passed a CTR_DRBG instance. */
  357. case MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED:
  358. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  359. case MBEDTLS_ERR_CTR_DRBG_REQUEST_TOO_BIG:
  360. case MBEDTLS_ERR_CTR_DRBG_INPUT_TOO_BIG:
  361. return PSA_ERROR_NOT_SUPPORTED;
  362. case MBEDTLS_ERR_CTR_DRBG_FILE_IO_ERROR:
  363. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  364. #endif
  365. #if defined(MBEDTLS_DES_C)
  366. case MBEDTLS_ERR_DES_INVALID_INPUT_LENGTH:
  367. return PSA_ERROR_NOT_SUPPORTED;
  368. #endif
  369. case MBEDTLS_ERR_ENTROPY_NO_SOURCES_DEFINED:
  370. case MBEDTLS_ERR_ENTROPY_NO_STRONG_SOURCE:
  371. case MBEDTLS_ERR_ENTROPY_SOURCE_FAILED:
  372. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  373. #if defined(MBEDTLS_GCM_C)
  374. case MBEDTLS_ERR_GCM_AUTH_FAILED:
  375. return PSA_ERROR_INVALID_SIGNATURE;
  376. case MBEDTLS_ERR_GCM_BUFFER_TOO_SMALL:
  377. return PSA_ERROR_BUFFER_TOO_SMALL;
  378. case MBEDTLS_ERR_GCM_BAD_INPUT:
  379. return PSA_ERROR_INVALID_ARGUMENT;
  380. #endif
  381. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) && \
  382. defined(MBEDTLS_PSA_HMAC_DRBG_MD_TYPE)
  383. /* Only check HMAC_DRBG error codes if underlying mbedtls_xxx
  384. * functions are passed a HMAC_DRBG instance. */
  385. case MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED:
  386. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  387. case MBEDTLS_ERR_HMAC_DRBG_REQUEST_TOO_BIG:
  388. case MBEDTLS_ERR_HMAC_DRBG_INPUT_TOO_BIG:
  389. return PSA_ERROR_NOT_SUPPORTED;
  390. case MBEDTLS_ERR_HMAC_DRBG_FILE_IO_ERROR:
  391. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  392. #endif
  393. #if defined(MBEDTLS_MD_LIGHT)
  394. case MBEDTLS_ERR_MD_FEATURE_UNAVAILABLE:
  395. return PSA_ERROR_NOT_SUPPORTED;
  396. case MBEDTLS_ERR_MD_BAD_INPUT_DATA:
  397. return PSA_ERROR_INVALID_ARGUMENT;
  398. case MBEDTLS_ERR_MD_ALLOC_FAILED:
  399. return PSA_ERROR_INSUFFICIENT_MEMORY;
  400. #if defined(MBEDTLS_FS_IO)
  401. case MBEDTLS_ERR_MD_FILE_IO_ERROR:
  402. return PSA_ERROR_STORAGE_FAILURE;
  403. #endif
  404. #endif
  405. #if defined(MBEDTLS_BIGNUM_C)
  406. #if defined(MBEDTLS_FS_IO)
  407. case MBEDTLS_ERR_MPI_FILE_IO_ERROR:
  408. return PSA_ERROR_STORAGE_FAILURE;
  409. #endif
  410. case MBEDTLS_ERR_MPI_BAD_INPUT_DATA:
  411. return PSA_ERROR_INVALID_ARGUMENT;
  412. case MBEDTLS_ERR_MPI_INVALID_CHARACTER:
  413. return PSA_ERROR_INVALID_ARGUMENT;
  414. case MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL:
  415. return PSA_ERROR_BUFFER_TOO_SMALL;
  416. case MBEDTLS_ERR_MPI_NEGATIVE_VALUE:
  417. return PSA_ERROR_INVALID_ARGUMENT;
  418. case MBEDTLS_ERR_MPI_DIVISION_BY_ZERO:
  419. return PSA_ERROR_INVALID_ARGUMENT;
  420. case MBEDTLS_ERR_MPI_NOT_ACCEPTABLE:
  421. return PSA_ERROR_INVALID_ARGUMENT;
  422. case MBEDTLS_ERR_MPI_ALLOC_FAILED:
  423. return PSA_ERROR_INSUFFICIENT_MEMORY;
  424. #endif
  425. #if defined(MBEDTLS_PK_C)
  426. case MBEDTLS_ERR_PK_ALLOC_FAILED:
  427. return PSA_ERROR_INSUFFICIENT_MEMORY;
  428. case MBEDTLS_ERR_PK_TYPE_MISMATCH:
  429. case MBEDTLS_ERR_PK_BAD_INPUT_DATA:
  430. return PSA_ERROR_INVALID_ARGUMENT;
  431. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) || defined(MBEDTLS_FS_IO) || \
  432. defined(MBEDTLS_PSA_ITS_FILE_C)
  433. case MBEDTLS_ERR_PK_FILE_IO_ERROR:
  434. return PSA_ERROR_STORAGE_FAILURE;
  435. #endif
  436. case MBEDTLS_ERR_PK_KEY_INVALID_VERSION:
  437. case MBEDTLS_ERR_PK_KEY_INVALID_FORMAT:
  438. return PSA_ERROR_INVALID_ARGUMENT;
  439. case MBEDTLS_ERR_PK_UNKNOWN_PK_ALG:
  440. return PSA_ERROR_NOT_SUPPORTED;
  441. case MBEDTLS_ERR_PK_PASSWORD_REQUIRED:
  442. case MBEDTLS_ERR_PK_PASSWORD_MISMATCH:
  443. return PSA_ERROR_NOT_PERMITTED;
  444. case MBEDTLS_ERR_PK_INVALID_PUBKEY:
  445. return PSA_ERROR_INVALID_ARGUMENT;
  446. case MBEDTLS_ERR_PK_INVALID_ALG:
  447. case MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE:
  448. case MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE:
  449. return PSA_ERROR_NOT_SUPPORTED;
  450. case MBEDTLS_ERR_PK_SIG_LEN_MISMATCH:
  451. return PSA_ERROR_INVALID_SIGNATURE;
  452. case MBEDTLS_ERR_PK_BUFFER_TOO_SMALL:
  453. return PSA_ERROR_BUFFER_TOO_SMALL;
  454. #endif
  455. case MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED:
  456. return PSA_ERROR_HARDWARE_FAILURE;
  457. case MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED:
  458. return PSA_ERROR_NOT_SUPPORTED;
  459. #if defined(MBEDTLS_RSA_C)
  460. case MBEDTLS_ERR_RSA_BAD_INPUT_DATA:
  461. return PSA_ERROR_INVALID_ARGUMENT;
  462. case MBEDTLS_ERR_RSA_INVALID_PADDING:
  463. return PSA_ERROR_INVALID_PADDING;
  464. case MBEDTLS_ERR_RSA_KEY_GEN_FAILED:
  465. return PSA_ERROR_HARDWARE_FAILURE;
  466. case MBEDTLS_ERR_RSA_KEY_CHECK_FAILED:
  467. return PSA_ERROR_INVALID_ARGUMENT;
  468. case MBEDTLS_ERR_RSA_PUBLIC_FAILED:
  469. case MBEDTLS_ERR_RSA_PRIVATE_FAILED:
  470. return PSA_ERROR_CORRUPTION_DETECTED;
  471. case MBEDTLS_ERR_RSA_VERIFY_FAILED:
  472. return PSA_ERROR_INVALID_SIGNATURE;
  473. case MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE:
  474. return PSA_ERROR_BUFFER_TOO_SMALL;
  475. case MBEDTLS_ERR_RSA_RNG_FAILED:
  476. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  477. #endif
  478. #if defined(MBEDTLS_ECP_LIGHT)
  479. case MBEDTLS_ERR_ECP_BAD_INPUT_DATA:
  480. case MBEDTLS_ERR_ECP_INVALID_KEY:
  481. return PSA_ERROR_INVALID_ARGUMENT;
  482. case MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL:
  483. return PSA_ERROR_BUFFER_TOO_SMALL;
  484. case MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE:
  485. return PSA_ERROR_NOT_SUPPORTED;
  486. case MBEDTLS_ERR_ECP_SIG_LEN_MISMATCH:
  487. case MBEDTLS_ERR_ECP_VERIFY_FAILED:
  488. return PSA_ERROR_INVALID_SIGNATURE;
  489. case MBEDTLS_ERR_ECP_ALLOC_FAILED:
  490. return PSA_ERROR_INSUFFICIENT_MEMORY;
  491. case MBEDTLS_ERR_ECP_RANDOM_FAILED:
  492. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  493. #if defined(MBEDTLS_ECP_RESTARTABLE)
  494. case MBEDTLS_ERR_ECP_IN_PROGRESS:
  495. return PSA_OPERATION_INCOMPLETE;
  496. #endif
  497. #endif
  498. case MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED:
  499. return PSA_ERROR_CORRUPTION_DETECTED;
  500. default:
  501. return PSA_ERROR_GENERIC_ERROR;
  502. }
  503. }
  504. /**
  505. * \brief For output buffers which contain "tags"
  506. * (outputs that may be checked for validity like
  507. * hashes, MACs and signatures), fill the unused
  508. * part of the output buffer (the whole buffer on
  509. * error, the trailing part on success) with
  510. * something that isn't a valid tag (barring an
  511. * attack on the tag and deliberately-crafted
  512. * input), in case the caller doesn't check the
  513. * return status properly.
  514. *
  515. * \param output_buffer Pointer to buffer to wipe. May not be NULL
  516. * unless \p output_buffer_size is zero.
  517. * \param status Status of function called to generate
  518. * output_buffer originally
  519. * \param output_buffer_size Size of output buffer. If zero, \p output_buffer
  520. * could be NULL.
  521. * \param output_buffer_length Length of data written to output_buffer, must be
  522. * less than \p output_buffer_size
  523. */
  524. static void psa_wipe_tag_output_buffer(uint8_t *output_buffer, psa_status_t status,
  525. size_t output_buffer_size, size_t output_buffer_length)
  526. {
  527. size_t offset = 0;
  528. if (output_buffer_size == 0) {
  529. /* If output_buffer_size is 0 then we have nothing to do. We must not
  530. call memset because output_buffer may be NULL in this case */
  531. return;
  532. }
  533. if (status == PSA_SUCCESS) {
  534. offset = output_buffer_length;
  535. }
  536. memset(output_buffer + offset, '!', output_buffer_size - offset);
  537. }
  538. psa_status_t psa_validate_unstructured_key_bit_size(psa_key_type_t type,
  539. size_t bits)
  540. {
  541. /* Check that the bit size is acceptable for the key type */
  542. switch (type) {
  543. case PSA_KEY_TYPE_RAW_DATA:
  544. case PSA_KEY_TYPE_HMAC:
  545. case PSA_KEY_TYPE_DERIVE:
  546. case PSA_KEY_TYPE_PASSWORD:
  547. case PSA_KEY_TYPE_PASSWORD_HASH:
  548. break;
  549. #if defined(PSA_WANT_KEY_TYPE_AES)
  550. case PSA_KEY_TYPE_AES:
  551. if (bits != 128 && bits != 192 && bits != 256) {
  552. return PSA_ERROR_INVALID_ARGUMENT;
  553. }
  554. break;
  555. #endif
  556. #if defined(PSA_WANT_KEY_TYPE_ARIA)
  557. case PSA_KEY_TYPE_ARIA:
  558. if (bits != 128 && bits != 192 && bits != 256) {
  559. return PSA_ERROR_INVALID_ARGUMENT;
  560. }
  561. break;
  562. #endif
  563. #if defined(PSA_WANT_KEY_TYPE_CAMELLIA)
  564. case PSA_KEY_TYPE_CAMELLIA:
  565. if (bits != 128 && bits != 192 && bits != 256) {
  566. return PSA_ERROR_INVALID_ARGUMENT;
  567. }
  568. break;
  569. #endif
  570. #if defined(PSA_WANT_KEY_TYPE_DES)
  571. case PSA_KEY_TYPE_DES:
  572. if (bits != 64 && bits != 128 && bits != 192) {
  573. return PSA_ERROR_INVALID_ARGUMENT;
  574. }
  575. break;
  576. #endif
  577. #if defined(PSA_WANT_KEY_TYPE_CHACHA20)
  578. case PSA_KEY_TYPE_CHACHA20:
  579. if (bits != 256) {
  580. return PSA_ERROR_INVALID_ARGUMENT;
  581. }
  582. break;
  583. #endif
  584. default:
  585. return PSA_ERROR_NOT_SUPPORTED;
  586. }
  587. if (bits % 8 != 0) {
  588. return PSA_ERROR_INVALID_ARGUMENT;
  589. }
  590. return PSA_SUCCESS;
  591. }
  592. /** Check whether a given key type is valid for use with a given MAC algorithm
  593. *
  594. * Upon successful return of this function, the behavior of #PSA_MAC_LENGTH
  595. * when called with the validated \p algorithm and \p key_type is well-defined.
  596. *
  597. * \param[in] algorithm The specific MAC algorithm (can be wildcard).
  598. * \param[in] key_type The key type of the key to be used with the
  599. * \p algorithm.
  600. *
  601. * \retval #PSA_SUCCESS
  602. * The \p key_type is valid for use with the \p algorithm
  603. * \retval #PSA_ERROR_INVALID_ARGUMENT
  604. * The \p key_type is not valid for use with the \p algorithm
  605. */
  606. MBEDTLS_STATIC_TESTABLE psa_status_t psa_mac_key_can_do(
  607. psa_algorithm_t algorithm,
  608. psa_key_type_t key_type)
  609. {
  610. if (PSA_ALG_IS_HMAC(algorithm)) {
  611. if (key_type == PSA_KEY_TYPE_HMAC) {
  612. return PSA_SUCCESS;
  613. }
  614. }
  615. if (PSA_ALG_IS_BLOCK_CIPHER_MAC(algorithm)) {
  616. /* Check that we're calling PSA_BLOCK_CIPHER_BLOCK_LENGTH with a cipher
  617. * key. */
  618. if ((key_type & PSA_KEY_TYPE_CATEGORY_MASK) ==
  619. PSA_KEY_TYPE_CATEGORY_SYMMETRIC) {
  620. /* PSA_BLOCK_CIPHER_BLOCK_LENGTH returns 1 for stream ciphers and
  621. * the block length (larger than 1) for block ciphers. */
  622. if (PSA_BLOCK_CIPHER_BLOCK_LENGTH(key_type) > 1) {
  623. return PSA_SUCCESS;
  624. }
  625. }
  626. }
  627. return PSA_ERROR_INVALID_ARGUMENT;
  628. }
  629. psa_status_t psa_allocate_buffer_to_slot(psa_key_slot_t *slot,
  630. size_t buffer_length)
  631. {
  632. if (slot->key.data != NULL) {
  633. return PSA_ERROR_ALREADY_EXISTS;
  634. }
  635. slot->key.data = mbedtls_calloc(1, buffer_length);
  636. if (slot->key.data == NULL) {
  637. return PSA_ERROR_INSUFFICIENT_MEMORY;
  638. }
  639. slot->key.bytes = buffer_length;
  640. return PSA_SUCCESS;
  641. }
  642. psa_status_t psa_copy_key_material_into_slot(psa_key_slot_t *slot,
  643. const uint8_t *data,
  644. size_t data_length)
  645. {
  646. psa_status_t status = psa_allocate_buffer_to_slot(slot,
  647. data_length);
  648. if (status != PSA_SUCCESS) {
  649. return status;
  650. }
  651. memcpy(slot->key.data, data, data_length);
  652. return PSA_SUCCESS;
  653. }
  654. psa_status_t psa_import_key_into_slot(
  655. const psa_key_attributes_t *attributes,
  656. const uint8_t *data, size_t data_length,
  657. uint8_t *key_buffer, size_t key_buffer_size,
  658. size_t *key_buffer_length, size_t *bits)
  659. {
  660. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  661. psa_key_type_t type = attributes->type;
  662. /* zero-length keys are never supported. */
  663. if (data_length == 0) {
  664. return PSA_ERROR_NOT_SUPPORTED;
  665. }
  666. if (key_type_is_raw_bytes(type)) {
  667. *bits = PSA_BYTES_TO_BITS(data_length);
  668. status = psa_validate_unstructured_key_bit_size(attributes->type,
  669. *bits);
  670. if (status != PSA_SUCCESS) {
  671. return status;
  672. }
  673. /* Copy the key material. */
  674. memcpy(key_buffer, data, data_length);
  675. *key_buffer_length = data_length;
  676. (void) key_buffer_size;
  677. return PSA_SUCCESS;
  678. } else if (PSA_KEY_TYPE_IS_ASYMMETRIC(type)) {
  679. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_IMPORT) || \
  680. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_PUBLIC_KEY)
  681. if (PSA_KEY_TYPE_IS_DH(type)) {
  682. if (psa_is_dh_key_size_valid(PSA_BYTES_TO_BITS(data_length)) == 0) {
  683. return PSA_ERROR_NOT_SUPPORTED;
  684. }
  685. return mbedtls_psa_ffdh_import_key(attributes,
  686. data, data_length,
  687. key_buffer, key_buffer_size,
  688. key_buffer_length,
  689. bits);
  690. }
  691. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_IMPORT) ||
  692. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_PUBLIC_KEY) */
  693. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_IMPORT) || \
  694. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY)
  695. if (PSA_KEY_TYPE_IS_ECC(type)) {
  696. return mbedtls_psa_ecp_import_key(attributes,
  697. data, data_length,
  698. key_buffer, key_buffer_size,
  699. key_buffer_length,
  700. bits);
  701. }
  702. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_IMPORT) ||
  703. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) */
  704. #if (defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_IMPORT) && \
  705. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_EXPORT)) || \
  706. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  707. if (PSA_KEY_TYPE_IS_RSA(type)) {
  708. return mbedtls_psa_rsa_import_key(attributes,
  709. data, data_length,
  710. key_buffer, key_buffer_size,
  711. key_buffer_length,
  712. bits);
  713. }
  714. #endif /* (defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_IMPORT) &&
  715. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_EXPORT)) ||
  716. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  717. }
  718. return PSA_ERROR_NOT_SUPPORTED;
  719. }
  720. /** Calculate the intersection of two algorithm usage policies.
  721. *
  722. * Return 0 (which allows no operation) on incompatibility.
  723. */
  724. static psa_algorithm_t psa_key_policy_algorithm_intersection(
  725. psa_key_type_t key_type,
  726. psa_algorithm_t alg1,
  727. psa_algorithm_t alg2)
  728. {
  729. /* Common case: both sides actually specify the same policy. */
  730. if (alg1 == alg2) {
  731. return alg1;
  732. }
  733. /* If the policies are from the same hash-and-sign family, check
  734. * if one is a wildcard. If so the other has the specific algorithm. */
  735. if (PSA_ALG_IS_SIGN_HASH(alg1) &&
  736. PSA_ALG_IS_SIGN_HASH(alg2) &&
  737. (alg1 & ~PSA_ALG_HASH_MASK) == (alg2 & ~PSA_ALG_HASH_MASK)) {
  738. if (PSA_ALG_SIGN_GET_HASH(alg1) == PSA_ALG_ANY_HASH) {
  739. return alg2;
  740. }
  741. if (PSA_ALG_SIGN_GET_HASH(alg2) == PSA_ALG_ANY_HASH) {
  742. return alg1;
  743. }
  744. }
  745. /* If the policies are from the same AEAD family, check whether
  746. * one of them is a minimum-tag-length wildcard. Calculate the most
  747. * restrictive tag length. */
  748. if (PSA_ALG_IS_AEAD(alg1) && PSA_ALG_IS_AEAD(alg2) &&
  749. (PSA_ALG_AEAD_WITH_SHORTENED_TAG(alg1, 0) ==
  750. PSA_ALG_AEAD_WITH_SHORTENED_TAG(alg2, 0))) {
  751. size_t alg1_len = PSA_ALG_AEAD_GET_TAG_LENGTH(alg1);
  752. size_t alg2_len = PSA_ALG_AEAD_GET_TAG_LENGTH(alg2);
  753. size_t restricted_len = alg1_len > alg2_len ? alg1_len : alg2_len;
  754. /* If both are wildcards, return most restrictive wildcard */
  755. if (((alg1 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG) != 0) &&
  756. ((alg2 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG) != 0)) {
  757. return PSA_ALG_AEAD_WITH_AT_LEAST_THIS_LENGTH_TAG(
  758. alg1, restricted_len);
  759. }
  760. /* If only one is a wildcard, return specific algorithm if compatible. */
  761. if (((alg1 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG) != 0) &&
  762. (alg1_len <= alg2_len)) {
  763. return alg2;
  764. }
  765. if (((alg2 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG) != 0) &&
  766. (alg2_len <= alg1_len)) {
  767. return alg1;
  768. }
  769. }
  770. /* If the policies are from the same MAC family, check whether one
  771. * of them is a minimum-MAC-length policy. Calculate the most
  772. * restrictive tag length. */
  773. if (PSA_ALG_IS_MAC(alg1) && PSA_ALG_IS_MAC(alg2) &&
  774. (PSA_ALG_FULL_LENGTH_MAC(alg1) ==
  775. PSA_ALG_FULL_LENGTH_MAC(alg2))) {
  776. /* Validate the combination of key type and algorithm. Since the base
  777. * algorithm of alg1 and alg2 are the same, we only need this once. */
  778. if (PSA_SUCCESS != psa_mac_key_can_do(alg1, key_type)) {
  779. return 0;
  780. }
  781. /* Get the (exact or at-least) output lengths for both sides of the
  782. * requested intersection. None of the currently supported algorithms
  783. * have an output length dependent on the actual key size, so setting it
  784. * to a bogus value of 0 is currently OK.
  785. *
  786. * Note that for at-least-this-length wildcard algorithms, the output
  787. * length is set to the shortest allowed length, which allows us to
  788. * calculate the most restrictive tag length for the intersection. */
  789. size_t alg1_len = PSA_MAC_LENGTH(key_type, 0, alg1);
  790. size_t alg2_len = PSA_MAC_LENGTH(key_type, 0, alg2);
  791. size_t restricted_len = alg1_len > alg2_len ? alg1_len : alg2_len;
  792. /* If both are wildcards, return most restrictive wildcard */
  793. if (((alg1 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG) != 0) &&
  794. ((alg2 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG) != 0)) {
  795. return PSA_ALG_AT_LEAST_THIS_LENGTH_MAC(alg1, restricted_len);
  796. }
  797. /* If only one is an at-least-this-length policy, the intersection would
  798. * be the other (fixed-length) policy as long as said fixed length is
  799. * equal to or larger than the shortest allowed length. */
  800. if ((alg1 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG) != 0) {
  801. return (alg1_len <= alg2_len) ? alg2 : 0;
  802. }
  803. if ((alg2 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG) != 0) {
  804. return (alg2_len <= alg1_len) ? alg1 : 0;
  805. }
  806. /* If none of them are wildcards, check whether they define the same tag
  807. * length. This is still possible here when one is default-length and
  808. * the other specific-length. Ensure to always return the
  809. * specific-length version for the intersection. */
  810. if (alg1_len == alg2_len) {
  811. return PSA_ALG_TRUNCATED_MAC(alg1, alg1_len);
  812. }
  813. }
  814. /* If the policies are incompatible, allow nothing. */
  815. return 0;
  816. }
  817. static int psa_key_algorithm_permits(psa_key_type_t key_type,
  818. psa_algorithm_t policy_alg,
  819. psa_algorithm_t requested_alg)
  820. {
  821. /* Common case: the policy only allows requested_alg. */
  822. if (requested_alg == policy_alg) {
  823. return 1;
  824. }
  825. /* If policy_alg is a hash-and-sign with a wildcard for the hash,
  826. * and requested_alg is the same hash-and-sign family with any hash,
  827. * then requested_alg is compliant with policy_alg. */
  828. if (PSA_ALG_IS_SIGN_HASH(requested_alg) &&
  829. PSA_ALG_SIGN_GET_HASH(policy_alg) == PSA_ALG_ANY_HASH) {
  830. return (policy_alg & ~PSA_ALG_HASH_MASK) ==
  831. (requested_alg & ~PSA_ALG_HASH_MASK);
  832. }
  833. /* If policy_alg is a wildcard AEAD algorithm of the same base as
  834. * the requested algorithm, check the requested tag length to be
  835. * equal-length or longer than the wildcard-specified length. */
  836. if (PSA_ALG_IS_AEAD(policy_alg) &&
  837. PSA_ALG_IS_AEAD(requested_alg) &&
  838. (PSA_ALG_AEAD_WITH_SHORTENED_TAG(policy_alg, 0) ==
  839. PSA_ALG_AEAD_WITH_SHORTENED_TAG(requested_alg, 0)) &&
  840. ((policy_alg & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG) != 0)) {
  841. return PSA_ALG_AEAD_GET_TAG_LENGTH(policy_alg) <=
  842. PSA_ALG_AEAD_GET_TAG_LENGTH(requested_alg);
  843. }
  844. /* If policy_alg is a MAC algorithm of the same base as the requested
  845. * algorithm, check whether their MAC lengths are compatible. */
  846. if (PSA_ALG_IS_MAC(policy_alg) &&
  847. PSA_ALG_IS_MAC(requested_alg) &&
  848. (PSA_ALG_FULL_LENGTH_MAC(policy_alg) ==
  849. PSA_ALG_FULL_LENGTH_MAC(requested_alg))) {
  850. /* Validate the combination of key type and algorithm. Since the policy
  851. * and requested algorithms are the same, we only need this once. */
  852. if (PSA_SUCCESS != psa_mac_key_can_do(policy_alg, key_type)) {
  853. return 0;
  854. }
  855. /* Get both the requested output length for the algorithm which is to be
  856. * verified, and the default output length for the base algorithm.
  857. * Note that none of the currently supported algorithms have an output
  858. * length dependent on actual key size, so setting it to a bogus value
  859. * of 0 is currently OK. */
  860. size_t requested_output_length = PSA_MAC_LENGTH(
  861. key_type, 0, requested_alg);
  862. size_t default_output_length = PSA_MAC_LENGTH(
  863. key_type, 0,
  864. PSA_ALG_FULL_LENGTH_MAC(requested_alg));
  865. /* If the policy is default-length, only allow an algorithm with
  866. * a declared exact-length matching the default. */
  867. if (PSA_MAC_TRUNCATED_LENGTH(policy_alg) == 0) {
  868. return requested_output_length == default_output_length;
  869. }
  870. /* If the requested algorithm is default-length, allow it if the policy
  871. * length exactly matches the default length. */
  872. if (PSA_MAC_TRUNCATED_LENGTH(requested_alg) == 0 &&
  873. PSA_MAC_TRUNCATED_LENGTH(policy_alg) == default_output_length) {
  874. return 1;
  875. }
  876. /* If policy_alg is an at-least-this-length wildcard MAC algorithm,
  877. * check for the requested MAC length to be equal to or longer than the
  878. * minimum allowed length. */
  879. if ((policy_alg & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG) != 0) {
  880. return PSA_MAC_TRUNCATED_LENGTH(policy_alg) <=
  881. requested_output_length;
  882. }
  883. }
  884. /* If policy_alg is a generic key agreement operation, then using it for
  885. * a key derivation with that key agreement should also be allowed. This
  886. * behaviour is expected to be defined in a future specification version. */
  887. if (PSA_ALG_IS_RAW_KEY_AGREEMENT(policy_alg) &&
  888. PSA_ALG_IS_KEY_AGREEMENT(requested_alg)) {
  889. return PSA_ALG_KEY_AGREEMENT_GET_BASE(requested_alg) ==
  890. policy_alg;
  891. }
  892. /* If it isn't explicitly permitted, it's forbidden. */
  893. return 0;
  894. }
  895. /** Test whether a policy permits an algorithm.
  896. *
  897. * The caller must test usage flags separately.
  898. *
  899. * \note This function requires providing the key type for which the policy is
  900. * being validated, since some algorithm policy definitions (e.g. MAC)
  901. * have different properties depending on what kind of cipher it is
  902. * combined with.
  903. *
  904. * \retval PSA_SUCCESS When \p alg is a specific algorithm
  905. * allowed by the \p policy.
  906. * \retval PSA_ERROR_INVALID_ARGUMENT When \p alg is not a specific algorithm
  907. * \retval PSA_ERROR_NOT_PERMITTED When \p alg is a specific algorithm, but
  908. * the \p policy does not allow it.
  909. */
  910. static psa_status_t psa_key_policy_permits(const psa_key_policy_t *policy,
  911. psa_key_type_t key_type,
  912. psa_algorithm_t alg)
  913. {
  914. /* '0' is not a valid algorithm */
  915. if (alg == 0) {
  916. return PSA_ERROR_INVALID_ARGUMENT;
  917. }
  918. /* A requested algorithm cannot be a wildcard. */
  919. if (PSA_ALG_IS_WILDCARD(alg)) {
  920. return PSA_ERROR_INVALID_ARGUMENT;
  921. }
  922. if (psa_key_algorithm_permits(key_type, policy->alg, alg) ||
  923. psa_key_algorithm_permits(key_type, policy->alg2, alg)) {
  924. return PSA_SUCCESS;
  925. } else {
  926. return PSA_ERROR_NOT_PERMITTED;
  927. }
  928. }
  929. /** Restrict a key policy based on a constraint.
  930. *
  931. * \note This function requires providing the key type for which the policy is
  932. * being restricted, since some algorithm policy definitions (e.g. MAC)
  933. * have different properties depending on what kind of cipher it is
  934. * combined with.
  935. *
  936. * \param[in] key_type The key type for which to restrict the policy
  937. * \param[in,out] policy The policy to restrict.
  938. * \param[in] constraint The policy constraint to apply.
  939. *
  940. * \retval #PSA_SUCCESS
  941. * \c *policy contains the intersection of the original value of
  942. * \c *policy and \c *constraint.
  943. * \retval #PSA_ERROR_INVALID_ARGUMENT
  944. * \c key_type, \c *policy and \c *constraint are incompatible.
  945. * \c *policy is unchanged.
  946. */
  947. static psa_status_t psa_restrict_key_policy(
  948. psa_key_type_t key_type,
  949. psa_key_policy_t *policy,
  950. const psa_key_policy_t *constraint)
  951. {
  952. psa_algorithm_t intersection_alg =
  953. psa_key_policy_algorithm_intersection(key_type, policy->alg,
  954. constraint->alg);
  955. psa_algorithm_t intersection_alg2 =
  956. psa_key_policy_algorithm_intersection(key_type, policy->alg2,
  957. constraint->alg2);
  958. if (intersection_alg == 0 && policy->alg != 0 && constraint->alg != 0) {
  959. return PSA_ERROR_INVALID_ARGUMENT;
  960. }
  961. if (intersection_alg2 == 0 && policy->alg2 != 0 && constraint->alg2 != 0) {
  962. return PSA_ERROR_INVALID_ARGUMENT;
  963. }
  964. policy->usage &= constraint->usage;
  965. policy->alg = intersection_alg;
  966. policy->alg2 = intersection_alg2;
  967. return PSA_SUCCESS;
  968. }
  969. /** Get the description of a key given its identifier and policy constraints
  970. * and lock it.
  971. *
  972. * The key must have allow all the usage flags set in \p usage. If \p alg is
  973. * nonzero, the key must allow operations with this algorithm. If \p alg is
  974. * zero, the algorithm is not checked.
  975. *
  976. * In case of a persistent key, the function loads the description of the key
  977. * into a key slot if not already done.
  978. *
  979. * On success, the returned key slot has been registered for reading.
  980. * It is the responsibility of the caller to then unregister
  981. * once they have finished reading the contents of the slot.
  982. * The caller unregisters by calling psa_unregister_read() or
  983. * psa_unregister_read_under_mutex(). psa_unregister_read() must be called
  984. * if and only if the caller already holds the global key slot mutex
  985. * (when mutexes are enabled). psa_unregister_read_under_mutex() encapsulates
  986. * the unregister with mutex lock and unlock operations.
  987. */
  988. static psa_status_t psa_get_and_lock_key_slot_with_policy(
  989. mbedtls_svc_key_id_t key,
  990. psa_key_slot_t **p_slot,
  991. psa_key_usage_t usage,
  992. psa_algorithm_t alg)
  993. {
  994. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  995. psa_key_slot_t *slot = NULL;
  996. status = psa_get_and_lock_key_slot(key, p_slot);
  997. if (status != PSA_SUCCESS) {
  998. return status;
  999. }
  1000. slot = *p_slot;
  1001. /* Enforce that usage policy for the key slot contains all the flags
  1002. * required by the usage parameter. There is one exception: public
  1003. * keys can always be exported, so we treat public key objects as
  1004. * if they had the export flag. */
  1005. if (PSA_KEY_TYPE_IS_PUBLIC_KEY(slot->attr.type)) {
  1006. usage &= ~PSA_KEY_USAGE_EXPORT;
  1007. }
  1008. if ((slot->attr.policy.usage & usage) != usage) {
  1009. status = PSA_ERROR_NOT_PERMITTED;
  1010. goto error;
  1011. }
  1012. /* Enforce that the usage policy permits the requested algorithm. */
  1013. if (alg != 0) {
  1014. status = psa_key_policy_permits(&slot->attr.policy,
  1015. slot->attr.type,
  1016. alg);
  1017. if (status != PSA_SUCCESS) {
  1018. goto error;
  1019. }
  1020. }
  1021. return PSA_SUCCESS;
  1022. error:
  1023. *p_slot = NULL;
  1024. psa_unregister_read_under_mutex(slot);
  1025. return status;
  1026. }
  1027. /** Get a key slot containing a transparent key and lock it.
  1028. *
  1029. * A transparent key is a key for which the key material is directly
  1030. * available, as opposed to a key in a secure element and/or to be used
  1031. * by a secure element.
  1032. *
  1033. * This is a temporary function that may be used instead of
  1034. * psa_get_and_lock_key_slot_with_policy() when there is no opaque key support
  1035. * for a cryptographic operation.
  1036. *
  1037. * On success, the returned key slot has been registered for reading.
  1038. * It is the responsibility of the caller to then unregister
  1039. * once they have finished reading the contents of the slot.
  1040. * The caller unregisters by calling psa_unregister_read() or
  1041. * psa_unregister_read_under_mutex(). psa_unregister_read() must be called
  1042. * if and only if the caller already holds the global key slot mutex
  1043. * (when mutexes are enabled). psa_unregister_read_under_mutex() encapsulates
  1044. * psa_unregister_read() with mutex lock and unlock operations.
  1045. */
  1046. static psa_status_t psa_get_and_lock_transparent_key_slot_with_policy(
  1047. mbedtls_svc_key_id_t key,
  1048. psa_key_slot_t **p_slot,
  1049. psa_key_usage_t usage,
  1050. psa_algorithm_t alg)
  1051. {
  1052. psa_status_t status = psa_get_and_lock_key_slot_with_policy(key, p_slot,
  1053. usage, alg);
  1054. if (status != PSA_SUCCESS) {
  1055. return status;
  1056. }
  1057. if (psa_key_lifetime_is_external((*p_slot)->attr.lifetime)) {
  1058. psa_unregister_read_under_mutex(*p_slot);
  1059. *p_slot = NULL;
  1060. return PSA_ERROR_NOT_SUPPORTED;
  1061. }
  1062. return PSA_SUCCESS;
  1063. }
  1064. psa_status_t psa_remove_key_data_from_memory(psa_key_slot_t *slot)
  1065. {
  1066. if (slot->key.data != NULL) {
  1067. mbedtls_zeroize_and_free(slot->key.data, slot->key.bytes);
  1068. }
  1069. slot->key.data = NULL;
  1070. slot->key.bytes = 0;
  1071. return PSA_SUCCESS;
  1072. }
  1073. /** Completely wipe a slot in memory, including its policy.
  1074. * Persistent storage is not affected. */
  1075. psa_status_t psa_wipe_key_slot(psa_key_slot_t *slot)
  1076. {
  1077. psa_status_t status = psa_remove_key_data_from_memory(slot);
  1078. /*
  1079. * As the return error code may not be handled in case of multiple errors,
  1080. * do our best to report an unexpected amount of registered readers or
  1081. * an unexpected state.
  1082. * Assert with MBEDTLS_TEST_HOOK_TEST_ASSERT that the slot is valid for
  1083. * wiping.
  1084. * if the MBEDTLS_TEST_HOOKS configuration option is enabled and the
  1085. * function is called as part of the execution of a test suite, the
  1086. * execution of the test suite is stopped in error if the assertion fails.
  1087. */
  1088. switch (slot->state) {
  1089. case PSA_SLOT_FULL:
  1090. /* In this state psa_wipe_key_slot() must only be called if the
  1091. * caller is the last reader. */
  1092. case PSA_SLOT_PENDING_DELETION:
  1093. /* In this state psa_wipe_key_slot() must only be called if the
  1094. * caller is the last reader. */
  1095. if (slot->var.occupied.registered_readers != 1) {
  1096. MBEDTLS_TEST_HOOK_TEST_ASSERT(slot->var.occupied.registered_readers == 1);
  1097. status = PSA_ERROR_CORRUPTION_DETECTED;
  1098. }
  1099. break;
  1100. case PSA_SLOT_FILLING:
  1101. /* In this state registered_readers must be 0. */
  1102. if (slot->var.occupied.registered_readers != 0) {
  1103. MBEDTLS_TEST_HOOK_TEST_ASSERT(slot->var.occupied.registered_readers == 0);
  1104. status = PSA_ERROR_CORRUPTION_DETECTED;
  1105. }
  1106. break;
  1107. case PSA_SLOT_EMPTY:
  1108. /* The slot is already empty, it cannot be wiped. */
  1109. MBEDTLS_TEST_HOOK_TEST_ASSERT(slot->state != PSA_SLOT_EMPTY);
  1110. status = PSA_ERROR_CORRUPTION_DETECTED;
  1111. break;
  1112. default:
  1113. /* The slot's state is invalid. */
  1114. status = PSA_ERROR_CORRUPTION_DETECTED;
  1115. }
  1116. #if defined(MBEDTLS_PSA_KEY_STORE_DYNAMIC)
  1117. size_t slice_index = slot->slice_index;
  1118. #endif /* MBEDTLS_PSA_KEY_STORE_DYNAMIC */
  1119. /* Multipart operations may still be using the key. This is safe
  1120. * because all multipart operation objects are independent from
  1121. * the key slot: if they need to access the key after the setup
  1122. * phase, they have a copy of the key. Note that this means that
  1123. * key material can linger until all operations are completed. */
  1124. /* At this point, key material and other type-specific content has
  1125. * been wiped. Clear remaining metadata. We can call memset and not
  1126. * zeroize because the metadata is not particularly sensitive.
  1127. * This memset also sets the slot's state to PSA_SLOT_EMPTY. */
  1128. memset(slot, 0, sizeof(*slot));
  1129. #if defined(MBEDTLS_PSA_KEY_STORE_DYNAMIC)
  1130. /* If the slot is already corrupted, something went deeply wrong,
  1131. * like a thread still using the slot or a stray pointer leading
  1132. * to the slot's memory being used for another object. Let the slot
  1133. * leak rather than make the corruption worse. */
  1134. if (status == PSA_SUCCESS) {
  1135. status = psa_free_key_slot(slice_index, slot);
  1136. }
  1137. #endif /* MBEDTLS_PSA_KEY_STORE_DYNAMIC */
  1138. return status;
  1139. }
  1140. psa_status_t psa_destroy_key(mbedtls_svc_key_id_t key)
  1141. {
  1142. psa_key_slot_t *slot;
  1143. psa_status_t status; /* status of the last operation */
  1144. psa_status_t overall_status = PSA_SUCCESS;
  1145. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1146. psa_se_drv_table_entry_t *driver;
  1147. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1148. if (mbedtls_svc_key_id_is_null(key)) {
  1149. return PSA_SUCCESS;
  1150. }
  1151. /*
  1152. * Get the description of the key in a key slot, and register to read it.
  1153. * In the case of a persistent key, this will load the key description
  1154. * from persistent memory if not done yet.
  1155. * We cannot avoid this loading as without it we don't know if
  1156. * the key is operated by an SE or not and this information is needed by
  1157. * the current implementation. */
  1158. status = psa_get_and_lock_key_slot(key, &slot);
  1159. if (status != PSA_SUCCESS) {
  1160. return status;
  1161. }
  1162. #if defined(MBEDTLS_THREADING_C)
  1163. /* We cannot unlock between setting the state to PENDING_DELETION
  1164. * and destroying the key in storage, as otherwise another thread
  1165. * could load the key into a new slot and the key will not be
  1166. * fully destroyed. */
  1167. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_lock(
  1168. &mbedtls_threading_key_slot_mutex));
  1169. if (slot->state == PSA_SLOT_PENDING_DELETION) {
  1170. /* Another thread has destroyed the key between us locking the slot
  1171. * and us gaining the mutex. Unregister from the slot,
  1172. * and report that the key does not exist. */
  1173. status = psa_unregister_read(slot);
  1174. PSA_THREADING_CHK_RET(mbedtls_mutex_unlock(
  1175. &mbedtls_threading_key_slot_mutex));
  1176. return (status == PSA_SUCCESS) ? PSA_ERROR_INVALID_HANDLE : status;
  1177. }
  1178. #endif
  1179. /* Set the key slot containing the key description's state to
  1180. * PENDING_DELETION. This stops new operations from registering
  1181. * to read the slot. Current readers can safely continue to access
  1182. * the key within the slot; the last registered reader will
  1183. * automatically wipe the slot when they call psa_unregister_read().
  1184. * If the key is persistent, we can now delete the copy of the key
  1185. * from memory. If the key is opaque, we require the driver to
  1186. * deal with the deletion. */
  1187. overall_status = psa_key_slot_state_transition(slot, PSA_SLOT_FULL,
  1188. PSA_SLOT_PENDING_DELETION);
  1189. if (overall_status != PSA_SUCCESS) {
  1190. goto exit;
  1191. }
  1192. if (PSA_KEY_LIFETIME_IS_READ_ONLY(slot->attr.lifetime)) {
  1193. /* Refuse the destruction of a read-only key (which may or may not work
  1194. * if we attempt it, depending on whether the key is merely read-only
  1195. * by policy or actually physically read-only).
  1196. * Just do the best we can, which is to wipe the copy in memory
  1197. * (done in this function's cleanup code). */
  1198. overall_status = PSA_ERROR_NOT_PERMITTED;
  1199. goto exit;
  1200. }
  1201. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1202. driver = psa_get_se_driver_entry(slot->attr.lifetime);
  1203. if (driver != NULL) {
  1204. /* For a key in a secure element, we need to do three things:
  1205. * remove the key file in internal storage, destroy the
  1206. * key inside the secure element, and update the driver's
  1207. * persistent data. Start a transaction that will encompass these
  1208. * three actions. */
  1209. psa_crypto_prepare_transaction(PSA_CRYPTO_TRANSACTION_DESTROY_KEY);
  1210. psa_crypto_transaction.key.lifetime = slot->attr.lifetime;
  1211. psa_crypto_transaction.key.slot = psa_key_slot_get_slot_number(slot);
  1212. psa_crypto_transaction.key.id = slot->attr.id;
  1213. status = psa_crypto_save_transaction();
  1214. if (status != PSA_SUCCESS) {
  1215. (void) psa_crypto_stop_transaction();
  1216. /* We should still try to destroy the key in the secure
  1217. * element and the key metadata in storage. This is especially
  1218. * important if the error is that the storage is full.
  1219. * But how to do it exactly without risking an inconsistent
  1220. * state after a reset?
  1221. * https://github.com/ARMmbed/mbed-crypto/issues/215
  1222. */
  1223. overall_status = status;
  1224. goto exit;
  1225. }
  1226. status = psa_destroy_se_key(driver,
  1227. psa_key_slot_get_slot_number(slot));
  1228. if (overall_status == PSA_SUCCESS) {
  1229. overall_status = status;
  1230. }
  1231. }
  1232. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1233. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C)
  1234. if (!PSA_KEY_LIFETIME_IS_VOLATILE(slot->attr.lifetime)) {
  1235. /* Destroy the copy of the persistent key from storage.
  1236. * The slot will still hold a copy of the key until the last reader
  1237. * unregisters. */
  1238. status = psa_destroy_persistent_key(slot->attr.id);
  1239. if (overall_status == PSA_SUCCESS) {
  1240. overall_status = status;
  1241. }
  1242. }
  1243. #endif /* defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) */
  1244. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1245. if (driver != NULL) {
  1246. status = psa_save_se_persistent_data(driver);
  1247. if (overall_status == PSA_SUCCESS) {
  1248. overall_status = status;
  1249. }
  1250. status = psa_crypto_stop_transaction();
  1251. if (overall_status == PSA_SUCCESS) {
  1252. overall_status = status;
  1253. }
  1254. }
  1255. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1256. exit:
  1257. /* Unregister from reading the slot. If we are the last active reader
  1258. * then this will wipe the slot. */
  1259. status = psa_unregister_read(slot);
  1260. /* Prioritize CORRUPTION_DETECTED from unregistering over
  1261. * a storage error. */
  1262. if (status != PSA_SUCCESS) {
  1263. overall_status = status;
  1264. }
  1265. #if defined(MBEDTLS_THREADING_C)
  1266. /* Don't overwrite existing errors if the unlock fails. */
  1267. status = overall_status;
  1268. PSA_THREADING_CHK_RET(mbedtls_mutex_unlock(
  1269. &mbedtls_threading_key_slot_mutex));
  1270. #endif
  1271. return overall_status;
  1272. }
  1273. /** Retrieve all the publicly-accessible attributes of a key.
  1274. */
  1275. psa_status_t psa_get_key_attributes(mbedtls_svc_key_id_t key,
  1276. psa_key_attributes_t *attributes)
  1277. {
  1278. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1279. psa_key_slot_t *slot;
  1280. psa_reset_key_attributes(attributes);
  1281. status = psa_get_and_lock_key_slot_with_policy(key, &slot, 0, 0);
  1282. if (status != PSA_SUCCESS) {
  1283. return status;
  1284. }
  1285. *attributes = slot->attr;
  1286. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1287. if (psa_get_se_driver_entry(slot->attr.lifetime) != NULL) {
  1288. psa_set_key_slot_number(attributes,
  1289. psa_key_slot_get_slot_number(slot));
  1290. }
  1291. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1292. return psa_unregister_read_under_mutex(slot);
  1293. }
  1294. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1295. psa_status_t psa_get_key_slot_number(
  1296. const psa_key_attributes_t *attributes,
  1297. psa_key_slot_number_t *slot_number)
  1298. {
  1299. if (attributes->has_slot_number) {
  1300. *slot_number = attributes->slot_number;
  1301. return PSA_SUCCESS;
  1302. } else {
  1303. return PSA_ERROR_INVALID_ARGUMENT;
  1304. }
  1305. }
  1306. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1307. static psa_status_t psa_export_key_buffer_internal(const uint8_t *key_buffer,
  1308. size_t key_buffer_size,
  1309. uint8_t *data,
  1310. size_t data_size,
  1311. size_t *data_length)
  1312. {
  1313. if (key_buffer_size > data_size) {
  1314. return PSA_ERROR_BUFFER_TOO_SMALL;
  1315. }
  1316. memcpy(data, key_buffer, key_buffer_size);
  1317. memset(data + key_buffer_size, 0,
  1318. data_size - key_buffer_size);
  1319. *data_length = key_buffer_size;
  1320. return PSA_SUCCESS;
  1321. }
  1322. psa_status_t psa_export_key_internal(
  1323. const psa_key_attributes_t *attributes,
  1324. const uint8_t *key_buffer, size_t key_buffer_size,
  1325. uint8_t *data, size_t data_size, size_t *data_length)
  1326. {
  1327. psa_key_type_t type = attributes->type;
  1328. if (key_type_is_raw_bytes(type) ||
  1329. PSA_KEY_TYPE_IS_RSA(type) ||
  1330. PSA_KEY_TYPE_IS_ECC(type) ||
  1331. PSA_KEY_TYPE_IS_DH(type)) {
  1332. return psa_export_key_buffer_internal(
  1333. key_buffer, key_buffer_size,
  1334. data, data_size, data_length);
  1335. } else {
  1336. /* This shouldn't happen in the reference implementation, but
  1337. it is valid for a special-purpose implementation to omit
  1338. support for exporting certain key types. */
  1339. return PSA_ERROR_NOT_SUPPORTED;
  1340. }
  1341. }
  1342. psa_status_t psa_export_key(mbedtls_svc_key_id_t key,
  1343. uint8_t *data_external,
  1344. size_t data_size,
  1345. size_t *data_length)
  1346. {
  1347. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1348. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1349. psa_key_slot_t *slot;
  1350. LOCAL_OUTPUT_DECLARE(data_external, data);
  1351. /* Reject a zero-length output buffer now, since this can never be a
  1352. * valid key representation. This way we know that data must be a valid
  1353. * pointer and we can do things like memset(data, ..., data_size). */
  1354. if (data_size == 0) {
  1355. return PSA_ERROR_BUFFER_TOO_SMALL;
  1356. }
  1357. /* Set the key to empty now, so that even when there are errors, we always
  1358. * set data_length to a value between 0 and data_size. On error, setting
  1359. * the key to empty is a good choice because an empty key representation is
  1360. * unlikely to be accepted anywhere. */
  1361. *data_length = 0;
  1362. /* Export requires the EXPORT flag. There is an exception for public keys,
  1363. * which don't require any flag, but
  1364. * psa_get_and_lock_key_slot_with_policy() takes care of this.
  1365. */
  1366. status = psa_get_and_lock_key_slot_with_policy(key, &slot,
  1367. PSA_KEY_USAGE_EXPORT, 0);
  1368. if (status != PSA_SUCCESS) {
  1369. return status;
  1370. }
  1371. LOCAL_OUTPUT_ALLOC(data_external, data_size, data);
  1372. status = psa_driver_wrapper_export_key(&slot->attr,
  1373. slot->key.data, slot->key.bytes,
  1374. data, data_size, data_length);
  1375. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  1376. exit:
  1377. #endif
  1378. unlock_status = psa_unregister_read_under_mutex(slot);
  1379. LOCAL_OUTPUT_FREE(data_external, data);
  1380. return (status == PSA_SUCCESS) ? unlock_status : status;
  1381. }
  1382. psa_status_t psa_export_public_key_internal(
  1383. const psa_key_attributes_t *attributes,
  1384. const uint8_t *key_buffer,
  1385. size_t key_buffer_size,
  1386. uint8_t *data,
  1387. size_t data_size,
  1388. size_t *data_length)
  1389. {
  1390. psa_key_type_t type = attributes->type;
  1391. if (PSA_KEY_TYPE_IS_PUBLIC_KEY(type) &&
  1392. (PSA_KEY_TYPE_IS_RSA(type) || PSA_KEY_TYPE_IS_ECC(type) ||
  1393. PSA_KEY_TYPE_IS_DH(type))) {
  1394. /* Exporting public -> public */
  1395. return psa_export_key_buffer_internal(
  1396. key_buffer, key_buffer_size,
  1397. data, data_size, data_length);
  1398. } else if (PSA_KEY_TYPE_IS_RSA(type)) {
  1399. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_EXPORT) || \
  1400. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1401. return mbedtls_psa_rsa_export_public_key(attributes,
  1402. key_buffer,
  1403. key_buffer_size,
  1404. data,
  1405. data_size,
  1406. data_length);
  1407. #else
  1408. /* We don't know how to convert a private RSA key to public. */
  1409. return PSA_ERROR_NOT_SUPPORTED;
  1410. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_EXPORT) ||
  1411. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1412. } else if (PSA_KEY_TYPE_IS_ECC(type)) {
  1413. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_EXPORT) || \
  1414. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY)
  1415. return mbedtls_psa_ecp_export_public_key(attributes,
  1416. key_buffer,
  1417. key_buffer_size,
  1418. data,
  1419. data_size,
  1420. data_length);
  1421. #else
  1422. /* We don't know how to convert a private ECC key to public */
  1423. return PSA_ERROR_NOT_SUPPORTED;
  1424. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_EXPORT) ||
  1425. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) */
  1426. } else if (PSA_KEY_TYPE_IS_DH(type)) {
  1427. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_EXPORT) || \
  1428. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_PUBLIC_KEY)
  1429. return mbedtls_psa_ffdh_export_public_key(attributes,
  1430. key_buffer,
  1431. key_buffer_size,
  1432. data, data_size,
  1433. data_length);
  1434. #else
  1435. return PSA_ERROR_NOT_SUPPORTED;
  1436. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_EXPORT) ||
  1437. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_PUBLIC_KEY) */
  1438. } else {
  1439. (void) key_buffer;
  1440. (void) key_buffer_size;
  1441. (void) data;
  1442. (void) data_size;
  1443. (void) data_length;
  1444. return PSA_ERROR_NOT_SUPPORTED;
  1445. }
  1446. }
  1447. psa_status_t psa_export_public_key(mbedtls_svc_key_id_t key,
  1448. uint8_t *data_external,
  1449. size_t data_size,
  1450. size_t *data_length)
  1451. {
  1452. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1453. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1454. psa_key_slot_t *slot;
  1455. LOCAL_OUTPUT_DECLARE(data_external, data);
  1456. /* Reject a zero-length output buffer now, since this can never be a
  1457. * valid key representation. This way we know that data must be a valid
  1458. * pointer and we can do things like memset(data, ..., data_size). */
  1459. if (data_size == 0) {
  1460. return PSA_ERROR_BUFFER_TOO_SMALL;
  1461. }
  1462. /* Set the key to empty now, so that even when there are errors, we always
  1463. * set data_length to a value between 0 and data_size. On error, setting
  1464. * the key to empty is a good choice because an empty key representation is
  1465. * unlikely to be accepted anywhere. */
  1466. *data_length = 0;
  1467. /* Exporting a public key doesn't require a usage flag. */
  1468. status = psa_get_and_lock_key_slot_with_policy(key, &slot, 0, 0);
  1469. if (status != PSA_SUCCESS) {
  1470. return status;
  1471. }
  1472. LOCAL_OUTPUT_ALLOC(data_external, data_size, data);
  1473. if (!PSA_KEY_TYPE_IS_ASYMMETRIC(slot->attr.type)) {
  1474. status = PSA_ERROR_INVALID_ARGUMENT;
  1475. goto exit;
  1476. }
  1477. status = psa_driver_wrapper_export_public_key(
  1478. &slot->attr, slot->key.data, slot->key.bytes,
  1479. data, data_size, data_length);
  1480. exit:
  1481. unlock_status = psa_unregister_read_under_mutex(slot);
  1482. LOCAL_OUTPUT_FREE(data_external, data);
  1483. return (status == PSA_SUCCESS) ? unlock_status : status;
  1484. }
  1485. /** Validate that a key policy is internally well-formed.
  1486. *
  1487. * This function only rejects invalid policies. It does not validate the
  1488. * consistency of the policy with respect to other attributes of the key
  1489. * such as the key type.
  1490. */
  1491. static psa_status_t psa_validate_key_policy(const psa_key_policy_t *policy)
  1492. {
  1493. if ((policy->usage & ~(PSA_KEY_USAGE_EXPORT |
  1494. PSA_KEY_USAGE_COPY |
  1495. PSA_KEY_USAGE_ENCRYPT |
  1496. PSA_KEY_USAGE_DECRYPT |
  1497. PSA_KEY_USAGE_SIGN_MESSAGE |
  1498. PSA_KEY_USAGE_VERIFY_MESSAGE |
  1499. PSA_KEY_USAGE_SIGN_HASH |
  1500. PSA_KEY_USAGE_VERIFY_HASH |
  1501. PSA_KEY_USAGE_VERIFY_DERIVATION |
  1502. PSA_KEY_USAGE_DERIVE)) != 0) {
  1503. return PSA_ERROR_INVALID_ARGUMENT;
  1504. }
  1505. return PSA_SUCCESS;
  1506. }
  1507. /** Validate the internal consistency of key attributes.
  1508. *
  1509. * This function only rejects invalid attribute values. If does not
  1510. * validate the consistency of the attributes with any key data that may
  1511. * be involved in the creation of the key.
  1512. *
  1513. * Call this function early in the key creation process.
  1514. *
  1515. * \param[in] attributes Key attributes for the new key.
  1516. * \param[out] p_drv On any return, the driver for the key, if any.
  1517. * NULL for a transparent key.
  1518. *
  1519. */
  1520. static psa_status_t psa_validate_key_attributes(
  1521. const psa_key_attributes_t *attributes,
  1522. psa_se_drv_table_entry_t **p_drv)
  1523. {
  1524. psa_status_t status = PSA_ERROR_INVALID_ARGUMENT;
  1525. psa_key_lifetime_t lifetime = psa_get_key_lifetime(attributes);
  1526. mbedtls_svc_key_id_t key = psa_get_key_id(attributes);
  1527. status = psa_validate_key_location(lifetime, p_drv);
  1528. if (status != PSA_SUCCESS) {
  1529. return status;
  1530. }
  1531. status = psa_validate_key_persistence(lifetime);
  1532. if (status != PSA_SUCCESS) {
  1533. return status;
  1534. }
  1535. if (PSA_KEY_LIFETIME_IS_VOLATILE(lifetime)) {
  1536. if (MBEDTLS_SVC_KEY_ID_GET_KEY_ID(key) != 0) {
  1537. return PSA_ERROR_INVALID_ARGUMENT;
  1538. }
  1539. } else {
  1540. if (!psa_is_valid_key_id(psa_get_key_id(attributes), 0)) {
  1541. return PSA_ERROR_INVALID_ARGUMENT;
  1542. }
  1543. }
  1544. status = psa_validate_key_policy(&attributes->policy);
  1545. if (status != PSA_SUCCESS) {
  1546. return status;
  1547. }
  1548. /* Refuse to create overly large keys.
  1549. * Note that this doesn't trigger on import if the attributes don't
  1550. * explicitly specify a size (so psa_get_key_bits returns 0), so
  1551. * psa_import_key() needs its own checks. */
  1552. if (psa_get_key_bits(attributes) > PSA_MAX_KEY_BITS) {
  1553. return PSA_ERROR_NOT_SUPPORTED;
  1554. }
  1555. return PSA_SUCCESS;
  1556. }
  1557. /** Prepare a key slot to receive key material.
  1558. *
  1559. * This function allocates a key slot and sets its metadata.
  1560. *
  1561. * If this function fails, call psa_fail_key_creation().
  1562. *
  1563. * This function is intended to be used as follows:
  1564. * -# Call psa_start_key_creation() to allocate a key slot, prepare
  1565. * it with the specified attributes, and in case of a volatile key assign it
  1566. * a volatile key identifier.
  1567. * -# Populate the slot with the key material.
  1568. * -# Call psa_finish_key_creation() to finalize the creation of the slot.
  1569. * In case of failure at any step, stop the sequence and call
  1570. * psa_fail_key_creation().
  1571. *
  1572. * On success, the key slot's state is PSA_SLOT_FILLING.
  1573. * It is the responsibility of the caller to change the slot's state to
  1574. * PSA_SLOT_EMPTY/FULL once key creation has finished.
  1575. *
  1576. * \param method An identification of the calling function.
  1577. * \param[in] attributes Key attributes for the new key.
  1578. * \param[out] p_slot On success, a pointer to the prepared slot.
  1579. * \param[out] p_drv On any return, the driver for the key, if any.
  1580. * NULL for a transparent key.
  1581. *
  1582. * \retval #PSA_SUCCESS
  1583. * The key slot is ready to receive key material.
  1584. * \return If this function fails, the key slot is an invalid state.
  1585. * You must call psa_fail_key_creation() to wipe and free the slot.
  1586. */
  1587. static psa_status_t psa_start_key_creation(
  1588. psa_key_creation_method_t method,
  1589. const psa_key_attributes_t *attributes,
  1590. psa_key_slot_t **p_slot,
  1591. psa_se_drv_table_entry_t **p_drv)
  1592. {
  1593. psa_status_t status;
  1594. (void) method;
  1595. *p_drv = NULL;
  1596. status = psa_validate_key_attributes(attributes, p_drv);
  1597. if (status != PSA_SUCCESS) {
  1598. return status;
  1599. }
  1600. int key_is_volatile = PSA_KEY_LIFETIME_IS_VOLATILE(attributes->lifetime);
  1601. psa_key_id_t volatile_key_id;
  1602. #if defined(MBEDTLS_THREADING_C)
  1603. PSA_THREADING_CHK_RET(mbedtls_mutex_lock(
  1604. &mbedtls_threading_key_slot_mutex));
  1605. #endif
  1606. status = psa_reserve_free_key_slot(
  1607. key_is_volatile ? &volatile_key_id : NULL,
  1608. p_slot);
  1609. #if defined(MBEDTLS_THREADING_C)
  1610. PSA_THREADING_CHK_RET(mbedtls_mutex_unlock(
  1611. &mbedtls_threading_key_slot_mutex));
  1612. #endif
  1613. if (status != PSA_SUCCESS) {
  1614. return status;
  1615. }
  1616. psa_key_slot_t *slot = *p_slot;
  1617. /* We're storing the declared bit-size of the key. It's up to each
  1618. * creation mechanism to verify that this information is correct.
  1619. * It's automatically correct for mechanisms that use the bit-size as
  1620. * an input (generate, device) but not for those where the bit-size
  1621. * is optional (import, copy). In case of a volatile key, assign it the
  1622. * volatile key identifier associated to the slot returned to contain its
  1623. * definition. */
  1624. slot->attr = *attributes;
  1625. if (key_is_volatile) {
  1626. #if !defined(MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER)
  1627. slot->attr.id = volatile_key_id;
  1628. #else
  1629. slot->attr.id.key_id = volatile_key_id;
  1630. #endif
  1631. }
  1632. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1633. /* For a key in a secure element, we need to do three things
  1634. * when creating or registering a persistent key:
  1635. * create the key file in internal storage, create the
  1636. * key inside the secure element, and update the driver's
  1637. * persistent data. This is done by starting a transaction that will
  1638. * encompass these three actions.
  1639. * For registering a volatile key, we just need to find an appropriate
  1640. * slot number inside the SE. Since the key is designated volatile, creating
  1641. * a transaction is not required. */
  1642. /* The first thing to do is to find a slot number for the new key.
  1643. * We save the slot number in persistent storage as part of the
  1644. * transaction data. It will be needed to recover if the power
  1645. * fails during the key creation process, to clean up on the secure
  1646. * element side after restarting. Obtaining a slot number from the
  1647. * secure element driver updates its persistent state, but we do not yet
  1648. * save the driver's persistent state, so that if the power fails,
  1649. * we can roll back to a state where the key doesn't exist. */
  1650. if (*p_drv != NULL) {
  1651. psa_key_slot_number_t slot_number;
  1652. status = psa_find_se_slot_for_key(attributes, method, *p_drv,
  1653. &slot_number);
  1654. if (status != PSA_SUCCESS) {
  1655. return status;
  1656. }
  1657. if (!PSA_KEY_LIFETIME_IS_VOLATILE(attributes->lifetime)) {
  1658. psa_crypto_prepare_transaction(PSA_CRYPTO_TRANSACTION_CREATE_KEY);
  1659. psa_crypto_transaction.key.lifetime = slot->attr.lifetime;
  1660. psa_crypto_transaction.key.slot = slot_number;
  1661. psa_crypto_transaction.key.id = slot->attr.id;
  1662. status = psa_crypto_save_transaction();
  1663. if (status != PSA_SUCCESS) {
  1664. (void) psa_crypto_stop_transaction();
  1665. return status;
  1666. }
  1667. }
  1668. status = psa_copy_key_material_into_slot(
  1669. slot, (uint8_t *) (&slot_number), sizeof(slot_number));
  1670. if (status != PSA_SUCCESS) {
  1671. return status;
  1672. }
  1673. }
  1674. if (*p_drv == NULL && method == PSA_KEY_CREATION_REGISTER) {
  1675. /* Key registration only makes sense with a secure element. */
  1676. return PSA_ERROR_INVALID_ARGUMENT;
  1677. }
  1678. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1679. return PSA_SUCCESS;
  1680. }
  1681. /** Finalize the creation of a key once its key material has been set.
  1682. *
  1683. * This entails writing the key to persistent storage.
  1684. *
  1685. * If this function fails, call psa_fail_key_creation().
  1686. * See the documentation of psa_start_key_creation() for the intended use
  1687. * of this function.
  1688. *
  1689. * If the finalization succeeds, the function sets the key slot's state to
  1690. * PSA_SLOT_FULL, and the key slot can no longer be accessed as part of the
  1691. * key creation process.
  1692. *
  1693. * \param[in,out] slot Pointer to the slot with key material.
  1694. * \param[in] driver The secure element driver for the key,
  1695. * or NULL for a transparent key.
  1696. * \param[out] key On success, identifier of the key. Note that the
  1697. * key identifier is also stored in the key slot.
  1698. *
  1699. * \retval #PSA_SUCCESS
  1700. * The key was successfully created.
  1701. * \retval #PSA_ERROR_INSUFFICIENT_MEMORY \emptydescription
  1702. * \retval #PSA_ERROR_INSUFFICIENT_STORAGE \emptydescription
  1703. * \retval #PSA_ERROR_ALREADY_EXISTS \emptydescription
  1704. * \retval #PSA_ERROR_DATA_INVALID \emptydescription
  1705. * \retval #PSA_ERROR_DATA_CORRUPT \emptydescription
  1706. * \retval #PSA_ERROR_STORAGE_FAILURE \emptydescription
  1707. *
  1708. * \return If this function fails, the key slot is an invalid state.
  1709. * You must call psa_fail_key_creation() to wipe and free the slot.
  1710. */
  1711. static psa_status_t psa_finish_key_creation(
  1712. psa_key_slot_t *slot,
  1713. psa_se_drv_table_entry_t *driver,
  1714. mbedtls_svc_key_id_t *key)
  1715. {
  1716. psa_status_t status = PSA_SUCCESS;
  1717. (void) slot;
  1718. (void) driver;
  1719. #if defined(MBEDTLS_THREADING_C)
  1720. PSA_THREADING_CHK_RET(mbedtls_mutex_lock(
  1721. &mbedtls_threading_key_slot_mutex));
  1722. #endif
  1723. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C)
  1724. if (!PSA_KEY_LIFETIME_IS_VOLATILE(slot->attr.lifetime)) {
  1725. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1726. if (driver != NULL) {
  1727. psa_se_key_data_storage_t data;
  1728. psa_key_slot_number_t slot_number =
  1729. psa_key_slot_get_slot_number(slot);
  1730. MBEDTLS_STATIC_ASSERT(sizeof(slot_number) ==
  1731. sizeof(data.slot_number),
  1732. "Slot number size does not match psa_se_key_data_storage_t");
  1733. memcpy(&data.slot_number, &slot_number, sizeof(slot_number));
  1734. status = psa_save_persistent_key(&slot->attr,
  1735. (uint8_t *) &data,
  1736. sizeof(data));
  1737. } else
  1738. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1739. {
  1740. /* Key material is saved in export representation in the slot, so
  1741. * just pass the slot buffer for storage. */
  1742. status = psa_save_persistent_key(&slot->attr,
  1743. slot->key.data,
  1744. slot->key.bytes);
  1745. }
  1746. }
  1747. #endif /* defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) */
  1748. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1749. /* Finish the transaction for a key creation. This does not
  1750. * happen when registering an existing key. Detect this case
  1751. * by checking whether a transaction is in progress (actual
  1752. * creation of a persistent key in a secure element requires a transaction,
  1753. * but registration or volatile key creation doesn't use one). */
  1754. if (driver != NULL &&
  1755. psa_crypto_transaction.unknown.type == PSA_CRYPTO_TRANSACTION_CREATE_KEY) {
  1756. status = psa_save_se_persistent_data(driver);
  1757. if (status != PSA_SUCCESS) {
  1758. psa_destroy_persistent_key(slot->attr.id);
  1759. #if defined(MBEDTLS_THREADING_C)
  1760. PSA_THREADING_CHK_RET(mbedtls_mutex_unlock(
  1761. &mbedtls_threading_key_slot_mutex));
  1762. #endif
  1763. return status;
  1764. }
  1765. status = psa_crypto_stop_transaction();
  1766. }
  1767. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1768. if (status == PSA_SUCCESS) {
  1769. *key = slot->attr.id;
  1770. status = psa_key_slot_state_transition(slot, PSA_SLOT_FILLING,
  1771. PSA_SLOT_FULL);
  1772. if (status != PSA_SUCCESS) {
  1773. *key = MBEDTLS_SVC_KEY_ID_INIT;
  1774. }
  1775. }
  1776. #if defined(MBEDTLS_THREADING_C)
  1777. PSA_THREADING_CHK_RET(mbedtls_mutex_unlock(
  1778. &mbedtls_threading_key_slot_mutex));
  1779. #endif
  1780. return status;
  1781. }
  1782. /** Abort the creation of a key.
  1783. *
  1784. * You may call this function after calling psa_start_key_creation(),
  1785. * or after psa_finish_key_creation() fails. In other circumstances, this
  1786. * function may not clean up persistent storage.
  1787. * See the documentation of psa_start_key_creation() for the intended use
  1788. * of this function. Sets the slot's state to PSA_SLOT_EMPTY.
  1789. *
  1790. * \param[in,out] slot Pointer to the slot with key material.
  1791. * \param[in] driver The secure element driver for the key,
  1792. * or NULL for a transparent key.
  1793. */
  1794. static void psa_fail_key_creation(psa_key_slot_t *slot,
  1795. psa_se_drv_table_entry_t *driver)
  1796. {
  1797. (void) driver;
  1798. if (slot == NULL) {
  1799. return;
  1800. }
  1801. #if defined(MBEDTLS_THREADING_C)
  1802. /* If the lock operation fails we still wipe the slot.
  1803. * Operations will no longer work after a failed lock,
  1804. * but we still need to wipe the slot of confidential data. */
  1805. mbedtls_mutex_lock(&mbedtls_threading_key_slot_mutex);
  1806. #endif
  1807. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1808. /* TODO: If the key has already been created in the secure
  1809. * element, and the failure happened later (when saving metadata
  1810. * to internal storage), we need to destroy the key in the secure
  1811. * element.
  1812. * https://github.com/ARMmbed/mbed-crypto/issues/217
  1813. */
  1814. /* Abort the ongoing transaction if any (there may not be one if
  1815. * the creation process failed before starting one, or if the
  1816. * key creation is a registration of a key in a secure element).
  1817. * Earlier functions must already have done what it takes to undo any
  1818. * partial creation. All that's left is to update the transaction data
  1819. * itself. */
  1820. (void) psa_crypto_stop_transaction();
  1821. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1822. psa_wipe_key_slot(slot);
  1823. #if defined(MBEDTLS_THREADING_C)
  1824. mbedtls_mutex_unlock(&mbedtls_threading_key_slot_mutex);
  1825. #endif
  1826. }
  1827. /** Validate optional attributes during key creation.
  1828. *
  1829. * Some key attributes are optional during key creation. If they are
  1830. * specified in the attributes structure, check that they are consistent
  1831. * with the data in the slot.
  1832. *
  1833. * This function should be called near the end of key creation, after
  1834. * the slot in memory is fully populated but before saving persistent data.
  1835. */
  1836. static psa_status_t psa_validate_optional_attributes(
  1837. const psa_key_slot_t *slot,
  1838. const psa_key_attributes_t *attributes)
  1839. {
  1840. if (attributes->type != 0) {
  1841. if (attributes->type != slot->attr.type) {
  1842. return PSA_ERROR_INVALID_ARGUMENT;
  1843. }
  1844. }
  1845. if (attributes->bits != 0) {
  1846. if (attributes->bits != slot->attr.bits) {
  1847. return PSA_ERROR_INVALID_ARGUMENT;
  1848. }
  1849. }
  1850. return PSA_SUCCESS;
  1851. }
  1852. psa_status_t psa_import_key(const psa_key_attributes_t *attributes,
  1853. const uint8_t *data_external,
  1854. size_t data_length,
  1855. mbedtls_svc_key_id_t *key)
  1856. {
  1857. psa_status_t status;
  1858. LOCAL_INPUT_DECLARE(data_external, data);
  1859. psa_key_slot_t *slot = NULL;
  1860. psa_se_drv_table_entry_t *driver = NULL;
  1861. size_t bits;
  1862. size_t storage_size = data_length;
  1863. *key = MBEDTLS_SVC_KEY_ID_INIT;
  1864. /* Reject zero-length symmetric keys (including raw data key objects).
  1865. * This also rejects any key which might be encoded as an empty string,
  1866. * which is never valid. */
  1867. if (data_length == 0) {
  1868. return PSA_ERROR_INVALID_ARGUMENT;
  1869. }
  1870. /* Ensure that the bytes-to-bits conversion cannot overflow. */
  1871. if (data_length > SIZE_MAX / 8) {
  1872. return PSA_ERROR_NOT_SUPPORTED;
  1873. }
  1874. LOCAL_INPUT_ALLOC(data_external, data_length, data);
  1875. status = psa_start_key_creation(PSA_KEY_CREATION_IMPORT, attributes,
  1876. &slot, &driver);
  1877. if (status != PSA_SUCCESS) {
  1878. goto exit;
  1879. }
  1880. /* In the case of a transparent key or an opaque key stored in local
  1881. * storage ( thus not in the case of importing a key in a secure element
  1882. * with storage ( MBEDTLS_PSA_CRYPTO_SE_C ) ),we have to allocate a
  1883. * buffer to hold the imported key material. */
  1884. if (slot->key.data == NULL) {
  1885. if (psa_key_lifetime_is_external(attributes->lifetime)) {
  1886. status = psa_driver_wrapper_get_key_buffer_size_from_key_data(
  1887. attributes, data, data_length, &storage_size);
  1888. if (status != PSA_SUCCESS) {
  1889. goto exit;
  1890. }
  1891. }
  1892. status = psa_allocate_buffer_to_slot(slot, storage_size);
  1893. if (status != PSA_SUCCESS) {
  1894. goto exit;
  1895. }
  1896. }
  1897. bits = slot->attr.bits;
  1898. status = psa_driver_wrapper_import_key(attributes,
  1899. data, data_length,
  1900. slot->key.data,
  1901. slot->key.bytes,
  1902. &slot->key.bytes, &bits);
  1903. if (status != PSA_SUCCESS) {
  1904. goto exit;
  1905. }
  1906. if (slot->attr.bits == 0) {
  1907. slot->attr.bits = (psa_key_bits_t) bits;
  1908. } else if (bits != slot->attr.bits) {
  1909. status = PSA_ERROR_INVALID_ARGUMENT;
  1910. goto exit;
  1911. }
  1912. /* Enforce a size limit, and in particular ensure that the bit
  1913. * size fits in its representation type.*/
  1914. if (bits > PSA_MAX_KEY_BITS) {
  1915. status = PSA_ERROR_NOT_SUPPORTED;
  1916. goto exit;
  1917. }
  1918. status = psa_validate_optional_attributes(slot, attributes);
  1919. if (status != PSA_SUCCESS) {
  1920. goto exit;
  1921. }
  1922. status = psa_finish_key_creation(slot, driver, key);
  1923. exit:
  1924. LOCAL_INPUT_FREE(data_external, data);
  1925. if (status != PSA_SUCCESS) {
  1926. psa_fail_key_creation(slot, driver);
  1927. }
  1928. return status;
  1929. }
  1930. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1931. psa_status_t mbedtls_psa_register_se_key(
  1932. const psa_key_attributes_t *attributes)
  1933. {
  1934. psa_status_t status;
  1935. psa_key_slot_t *slot = NULL;
  1936. psa_se_drv_table_entry_t *driver = NULL;
  1937. mbedtls_svc_key_id_t key = MBEDTLS_SVC_KEY_ID_INIT;
  1938. /* Leaving attributes unspecified is not currently supported.
  1939. * It could make sense to query the key type and size from the
  1940. * secure element, but not all secure elements support this
  1941. * and the driver HAL doesn't currently support it. */
  1942. if (psa_get_key_type(attributes) == PSA_KEY_TYPE_NONE) {
  1943. return PSA_ERROR_NOT_SUPPORTED;
  1944. }
  1945. if (psa_get_key_bits(attributes) == 0) {
  1946. return PSA_ERROR_NOT_SUPPORTED;
  1947. }
  1948. /* Not usable with volatile keys, even with an appropriate location,
  1949. * due to the API design.
  1950. * https://github.com/Mbed-TLS/mbedtls/issues/9253
  1951. */
  1952. if (PSA_KEY_LIFETIME_IS_VOLATILE(psa_get_key_lifetime(attributes))) {
  1953. return PSA_ERROR_INVALID_ARGUMENT;
  1954. }
  1955. status = psa_start_key_creation(PSA_KEY_CREATION_REGISTER, attributes,
  1956. &slot, &driver);
  1957. if (status != PSA_SUCCESS) {
  1958. goto exit;
  1959. }
  1960. status = psa_finish_key_creation(slot, driver, &key);
  1961. exit:
  1962. if (status != PSA_SUCCESS) {
  1963. psa_fail_key_creation(slot, driver);
  1964. }
  1965. /* Registration doesn't keep the key in RAM. */
  1966. psa_close_key(key);
  1967. return status;
  1968. }
  1969. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1970. psa_status_t psa_copy_key(mbedtls_svc_key_id_t source_key,
  1971. const psa_key_attributes_t *specified_attributes,
  1972. mbedtls_svc_key_id_t *target_key)
  1973. {
  1974. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1975. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1976. psa_key_slot_t *source_slot = NULL;
  1977. psa_key_slot_t *target_slot = NULL;
  1978. psa_key_attributes_t actual_attributes = *specified_attributes;
  1979. psa_se_drv_table_entry_t *driver = NULL;
  1980. size_t storage_size = 0;
  1981. *target_key = MBEDTLS_SVC_KEY_ID_INIT;
  1982. status = psa_get_and_lock_key_slot_with_policy(
  1983. source_key, &source_slot, PSA_KEY_USAGE_COPY, 0);
  1984. if (status != PSA_SUCCESS) {
  1985. goto exit;
  1986. }
  1987. status = psa_validate_optional_attributes(source_slot,
  1988. specified_attributes);
  1989. if (status != PSA_SUCCESS) {
  1990. goto exit;
  1991. }
  1992. /* The target key type and number of bits have been validated by
  1993. * psa_validate_optional_attributes() to be either equal to zero or
  1994. * equal to the ones of the source key. So it is safe to inherit
  1995. * them from the source key now."
  1996. * */
  1997. actual_attributes.bits = source_slot->attr.bits;
  1998. actual_attributes.type = source_slot->attr.type;
  1999. status = psa_restrict_key_policy(source_slot->attr.type,
  2000. &actual_attributes.policy,
  2001. &source_slot->attr.policy);
  2002. if (status != PSA_SUCCESS) {
  2003. goto exit;
  2004. }
  2005. status = psa_start_key_creation(PSA_KEY_CREATION_COPY, &actual_attributes,
  2006. &target_slot, &driver);
  2007. if (status != PSA_SUCCESS) {
  2008. goto exit;
  2009. }
  2010. if (PSA_KEY_LIFETIME_GET_LOCATION(target_slot->attr.lifetime) !=
  2011. PSA_KEY_LIFETIME_GET_LOCATION(source_slot->attr.lifetime)) {
  2012. /*
  2013. * If the source and target keys are stored in different locations,
  2014. * the source key would need to be exported as plaintext and re-imported
  2015. * in the other location. This has security implications which have not
  2016. * been fully mapped. For now, this can be achieved through
  2017. * appropriate API invocations from the application, if needed.
  2018. * */
  2019. status = PSA_ERROR_NOT_SUPPORTED;
  2020. goto exit;
  2021. }
  2022. /*
  2023. * When the source and target keys are within the same location,
  2024. * - For transparent keys it is a blind copy without any driver invocation,
  2025. * - For opaque keys this translates to an invocation of the drivers'
  2026. * copy_key entry point through the dispatch layer.
  2027. * */
  2028. if (psa_key_lifetime_is_external(actual_attributes.lifetime)) {
  2029. status = psa_driver_wrapper_get_key_buffer_size(&actual_attributes,
  2030. &storage_size);
  2031. if (status != PSA_SUCCESS) {
  2032. goto exit;
  2033. }
  2034. status = psa_allocate_buffer_to_slot(target_slot, storage_size);
  2035. if (status != PSA_SUCCESS) {
  2036. goto exit;
  2037. }
  2038. status = psa_driver_wrapper_copy_key(&actual_attributes,
  2039. source_slot->key.data,
  2040. source_slot->key.bytes,
  2041. target_slot->key.data,
  2042. target_slot->key.bytes,
  2043. &target_slot->key.bytes);
  2044. if (status != PSA_SUCCESS) {
  2045. goto exit;
  2046. }
  2047. } else {
  2048. status = psa_copy_key_material_into_slot(target_slot,
  2049. source_slot->key.data,
  2050. source_slot->key.bytes);
  2051. if (status != PSA_SUCCESS) {
  2052. goto exit;
  2053. }
  2054. }
  2055. status = psa_finish_key_creation(target_slot, driver, target_key);
  2056. exit:
  2057. if (status != PSA_SUCCESS) {
  2058. psa_fail_key_creation(target_slot, driver);
  2059. }
  2060. unlock_status = psa_unregister_read_under_mutex(source_slot);
  2061. return (status == PSA_SUCCESS) ? unlock_status : status;
  2062. }
  2063. /****************************************************************/
  2064. /* Message digests */
  2065. /****************************************************************/
  2066. psa_status_t psa_hash_abort(psa_hash_operation_t *operation)
  2067. {
  2068. /* Aborting a non-active operation is allowed */
  2069. if (operation->id == 0) {
  2070. return PSA_SUCCESS;
  2071. }
  2072. psa_status_t status = psa_driver_wrapper_hash_abort(operation);
  2073. operation->id = 0;
  2074. return status;
  2075. }
  2076. psa_status_t psa_hash_setup(psa_hash_operation_t *operation,
  2077. psa_algorithm_t alg)
  2078. {
  2079. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2080. /* A context must be freshly initialized before it can be set up. */
  2081. if (operation->id != 0) {
  2082. status = PSA_ERROR_BAD_STATE;
  2083. goto exit;
  2084. }
  2085. if (!PSA_ALG_IS_HASH(alg)) {
  2086. status = PSA_ERROR_INVALID_ARGUMENT;
  2087. goto exit;
  2088. }
  2089. /* Ensure all of the context is zeroized, since PSA_HASH_OPERATION_INIT only
  2090. * directly zeroes the int-sized dummy member of the context union. */
  2091. memset(&operation->ctx, 0, sizeof(operation->ctx));
  2092. status = psa_driver_wrapper_hash_setup(operation, alg);
  2093. exit:
  2094. if (status != PSA_SUCCESS) {
  2095. psa_hash_abort(operation);
  2096. }
  2097. return status;
  2098. }
  2099. psa_status_t psa_hash_update(psa_hash_operation_t *operation,
  2100. const uint8_t *input_external,
  2101. size_t input_length)
  2102. {
  2103. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2104. LOCAL_INPUT_DECLARE(input_external, input);
  2105. if (operation->id == 0) {
  2106. status = PSA_ERROR_BAD_STATE;
  2107. goto exit;
  2108. }
  2109. /* Don't require hash implementations to behave correctly on a
  2110. * zero-length input, which may have an invalid pointer. */
  2111. if (input_length == 0) {
  2112. return PSA_SUCCESS;
  2113. }
  2114. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  2115. status = psa_driver_wrapper_hash_update(operation, input, input_length);
  2116. exit:
  2117. if (status != PSA_SUCCESS) {
  2118. psa_hash_abort(operation);
  2119. }
  2120. LOCAL_INPUT_FREE(input_external, input);
  2121. return status;
  2122. }
  2123. static psa_status_t psa_hash_finish_internal(psa_hash_operation_t *operation,
  2124. uint8_t *hash,
  2125. size_t hash_size,
  2126. size_t *hash_length)
  2127. {
  2128. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2129. *hash_length = 0;
  2130. if (operation->id == 0) {
  2131. return PSA_ERROR_BAD_STATE;
  2132. }
  2133. status = psa_driver_wrapper_hash_finish(
  2134. operation, hash, hash_size, hash_length);
  2135. psa_hash_abort(operation);
  2136. return status;
  2137. }
  2138. psa_status_t psa_hash_finish(psa_hash_operation_t *operation,
  2139. uint8_t *hash_external,
  2140. size_t hash_size,
  2141. size_t *hash_length)
  2142. {
  2143. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2144. LOCAL_OUTPUT_DECLARE(hash_external, hash);
  2145. LOCAL_OUTPUT_ALLOC(hash_external, hash_size, hash);
  2146. status = psa_hash_finish_internal(operation, hash, hash_size, hash_length);
  2147. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  2148. exit:
  2149. #endif
  2150. LOCAL_OUTPUT_FREE(hash_external, hash);
  2151. return status;
  2152. }
  2153. psa_status_t psa_hash_verify(psa_hash_operation_t *operation,
  2154. const uint8_t *hash_external,
  2155. size_t hash_length)
  2156. {
  2157. uint8_t actual_hash[PSA_HASH_MAX_SIZE];
  2158. size_t actual_hash_length;
  2159. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2160. LOCAL_INPUT_DECLARE(hash_external, hash);
  2161. status = psa_hash_finish_internal(
  2162. operation,
  2163. actual_hash, sizeof(actual_hash),
  2164. &actual_hash_length);
  2165. if (status != PSA_SUCCESS) {
  2166. goto exit;
  2167. }
  2168. if (actual_hash_length != hash_length) {
  2169. status = PSA_ERROR_INVALID_SIGNATURE;
  2170. goto exit;
  2171. }
  2172. LOCAL_INPUT_ALLOC(hash_external, hash_length, hash);
  2173. if (mbedtls_ct_memcmp(hash, actual_hash, actual_hash_length) != 0) {
  2174. status = PSA_ERROR_INVALID_SIGNATURE;
  2175. }
  2176. exit:
  2177. mbedtls_platform_zeroize(actual_hash, sizeof(actual_hash));
  2178. if (status != PSA_SUCCESS) {
  2179. psa_hash_abort(operation);
  2180. }
  2181. LOCAL_INPUT_FREE(hash_external, hash);
  2182. return status;
  2183. }
  2184. psa_status_t psa_hash_compute(psa_algorithm_t alg,
  2185. const uint8_t *input_external, size_t input_length,
  2186. uint8_t *hash_external, size_t hash_size,
  2187. size_t *hash_length)
  2188. {
  2189. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2190. LOCAL_INPUT_DECLARE(input_external, input);
  2191. LOCAL_OUTPUT_DECLARE(hash_external, hash);
  2192. *hash_length = 0;
  2193. if (!PSA_ALG_IS_HASH(alg)) {
  2194. return PSA_ERROR_INVALID_ARGUMENT;
  2195. }
  2196. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  2197. LOCAL_OUTPUT_ALLOC(hash_external, hash_size, hash);
  2198. status = psa_driver_wrapper_hash_compute(alg, input, input_length,
  2199. hash, hash_size, hash_length);
  2200. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  2201. exit:
  2202. #endif
  2203. LOCAL_INPUT_FREE(input_external, input);
  2204. LOCAL_OUTPUT_FREE(hash_external, hash);
  2205. return status;
  2206. }
  2207. psa_status_t psa_hash_compare(psa_algorithm_t alg,
  2208. const uint8_t *input_external, size_t input_length,
  2209. const uint8_t *hash_external, size_t hash_length)
  2210. {
  2211. uint8_t actual_hash[PSA_HASH_MAX_SIZE];
  2212. size_t actual_hash_length;
  2213. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2214. LOCAL_INPUT_DECLARE(input_external, input);
  2215. LOCAL_INPUT_DECLARE(hash_external, hash);
  2216. if (!PSA_ALG_IS_HASH(alg)) {
  2217. status = PSA_ERROR_INVALID_ARGUMENT;
  2218. return status;
  2219. }
  2220. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  2221. status = psa_driver_wrapper_hash_compute(
  2222. alg, input, input_length,
  2223. actual_hash, sizeof(actual_hash),
  2224. &actual_hash_length);
  2225. if (status != PSA_SUCCESS) {
  2226. goto exit;
  2227. }
  2228. if (actual_hash_length != hash_length) {
  2229. status = PSA_ERROR_INVALID_SIGNATURE;
  2230. goto exit;
  2231. }
  2232. LOCAL_INPUT_ALLOC(hash_external, hash_length, hash);
  2233. if (mbedtls_ct_memcmp(hash, actual_hash, actual_hash_length) != 0) {
  2234. status = PSA_ERROR_INVALID_SIGNATURE;
  2235. }
  2236. exit:
  2237. mbedtls_platform_zeroize(actual_hash, sizeof(actual_hash));
  2238. LOCAL_INPUT_FREE(input_external, input);
  2239. LOCAL_INPUT_FREE(hash_external, hash);
  2240. return status;
  2241. }
  2242. psa_status_t psa_hash_clone(const psa_hash_operation_t *source_operation,
  2243. psa_hash_operation_t *target_operation)
  2244. {
  2245. if (source_operation->id == 0 ||
  2246. target_operation->id != 0) {
  2247. return PSA_ERROR_BAD_STATE;
  2248. }
  2249. psa_status_t status = psa_driver_wrapper_hash_clone(source_operation,
  2250. target_operation);
  2251. if (status != PSA_SUCCESS) {
  2252. psa_hash_abort(target_operation);
  2253. }
  2254. return status;
  2255. }
  2256. /****************************************************************/
  2257. /* MAC */
  2258. /****************************************************************/
  2259. psa_status_t psa_mac_abort(psa_mac_operation_t *operation)
  2260. {
  2261. /* Aborting a non-active operation is allowed */
  2262. if (operation->id == 0) {
  2263. return PSA_SUCCESS;
  2264. }
  2265. psa_status_t status = psa_driver_wrapper_mac_abort(operation);
  2266. operation->mac_size = 0;
  2267. operation->is_sign = 0;
  2268. operation->id = 0;
  2269. return status;
  2270. }
  2271. static psa_status_t psa_mac_finalize_alg_and_key_validation(
  2272. psa_algorithm_t alg,
  2273. const psa_key_attributes_t *attributes,
  2274. uint8_t *mac_size)
  2275. {
  2276. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2277. psa_key_type_t key_type = psa_get_key_type(attributes);
  2278. size_t key_bits = psa_get_key_bits(attributes);
  2279. if (!PSA_ALG_IS_MAC(alg)) {
  2280. return PSA_ERROR_INVALID_ARGUMENT;
  2281. }
  2282. /* Validate the combination of key type and algorithm */
  2283. status = psa_mac_key_can_do(alg, key_type);
  2284. if (status != PSA_SUCCESS) {
  2285. return status;
  2286. }
  2287. /* Get the output length for the algorithm and key combination */
  2288. *mac_size = PSA_MAC_LENGTH(key_type, key_bits, alg);
  2289. if (*mac_size < 4) {
  2290. /* A very short MAC is too short for security since it can be
  2291. * brute-forced. Ancient protocols with 32-bit MACs do exist,
  2292. * so we make this our minimum, even though 32 bits is still
  2293. * too small for security. */
  2294. return PSA_ERROR_NOT_SUPPORTED;
  2295. }
  2296. if (*mac_size > PSA_MAC_LENGTH(key_type, key_bits,
  2297. PSA_ALG_FULL_LENGTH_MAC(alg))) {
  2298. /* It's impossible to "truncate" to a larger length than the full length
  2299. * of the algorithm. */
  2300. return PSA_ERROR_INVALID_ARGUMENT;
  2301. }
  2302. if (*mac_size > PSA_MAC_MAX_SIZE) {
  2303. /* PSA_MAC_LENGTH returns the correct length even for a MAC algorithm
  2304. * that is disabled in the compile-time configuration. The result can
  2305. * therefore be larger than PSA_MAC_MAX_SIZE, which does take the
  2306. * configuration into account. In this case, force a return of
  2307. * PSA_ERROR_NOT_SUPPORTED here. Otherwise psa_mac_verify(), or
  2308. * psa_mac_compute(mac_size=PSA_MAC_MAX_SIZE), would return
  2309. * PSA_ERROR_BUFFER_TOO_SMALL for an unsupported algorithm whose MAC size
  2310. * is larger than PSA_MAC_MAX_SIZE, which is misleading and which breaks
  2311. * systematically generated tests. */
  2312. return PSA_ERROR_NOT_SUPPORTED;
  2313. }
  2314. return PSA_SUCCESS;
  2315. }
  2316. static psa_status_t psa_mac_setup(psa_mac_operation_t *operation,
  2317. mbedtls_svc_key_id_t key,
  2318. psa_algorithm_t alg,
  2319. int is_sign)
  2320. {
  2321. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2322. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2323. psa_key_slot_t *slot = NULL;
  2324. /* A context must be freshly initialized before it can be set up. */
  2325. if (operation->id != 0) {
  2326. status = PSA_ERROR_BAD_STATE;
  2327. goto exit;
  2328. }
  2329. status = psa_get_and_lock_key_slot_with_policy(
  2330. key,
  2331. &slot,
  2332. is_sign ? PSA_KEY_USAGE_SIGN_MESSAGE : PSA_KEY_USAGE_VERIFY_MESSAGE,
  2333. alg);
  2334. if (status != PSA_SUCCESS) {
  2335. goto exit;
  2336. }
  2337. status = psa_mac_finalize_alg_and_key_validation(alg, &slot->attr,
  2338. &operation->mac_size);
  2339. if (status != PSA_SUCCESS) {
  2340. goto exit;
  2341. }
  2342. operation->is_sign = is_sign;
  2343. /* Dispatch the MAC setup call with validated input */
  2344. if (is_sign) {
  2345. status = psa_driver_wrapper_mac_sign_setup(operation,
  2346. &slot->attr,
  2347. slot->key.data,
  2348. slot->key.bytes,
  2349. alg);
  2350. } else {
  2351. status = psa_driver_wrapper_mac_verify_setup(operation,
  2352. &slot->attr,
  2353. slot->key.data,
  2354. slot->key.bytes,
  2355. alg);
  2356. }
  2357. exit:
  2358. if (status != PSA_SUCCESS) {
  2359. psa_mac_abort(operation);
  2360. }
  2361. unlock_status = psa_unregister_read_under_mutex(slot);
  2362. return (status == PSA_SUCCESS) ? unlock_status : status;
  2363. }
  2364. psa_status_t psa_mac_sign_setup(psa_mac_operation_t *operation,
  2365. mbedtls_svc_key_id_t key,
  2366. psa_algorithm_t alg)
  2367. {
  2368. return psa_mac_setup(operation, key, alg, 1);
  2369. }
  2370. psa_status_t psa_mac_verify_setup(psa_mac_operation_t *operation,
  2371. mbedtls_svc_key_id_t key,
  2372. psa_algorithm_t alg)
  2373. {
  2374. return psa_mac_setup(operation, key, alg, 0);
  2375. }
  2376. psa_status_t psa_mac_update(psa_mac_operation_t *operation,
  2377. const uint8_t *input_external,
  2378. size_t input_length)
  2379. {
  2380. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2381. LOCAL_INPUT_DECLARE(input_external, input);
  2382. if (operation->id == 0) {
  2383. status = PSA_ERROR_BAD_STATE;
  2384. return status;
  2385. }
  2386. /* Don't require hash implementations to behave correctly on a
  2387. * zero-length input, which may have an invalid pointer. */
  2388. if (input_length == 0) {
  2389. status = PSA_SUCCESS;
  2390. return status;
  2391. }
  2392. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  2393. status = psa_driver_wrapper_mac_update(operation, input, input_length);
  2394. if (status != PSA_SUCCESS) {
  2395. psa_mac_abort(operation);
  2396. }
  2397. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  2398. exit:
  2399. #endif
  2400. LOCAL_INPUT_FREE(input_external, input);
  2401. return status;
  2402. }
  2403. psa_status_t psa_mac_sign_finish(psa_mac_operation_t *operation,
  2404. uint8_t *mac_external,
  2405. size_t mac_size,
  2406. size_t *mac_length)
  2407. {
  2408. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2409. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  2410. LOCAL_OUTPUT_DECLARE(mac_external, mac);
  2411. LOCAL_OUTPUT_ALLOC(mac_external, mac_size, mac);
  2412. if (operation->id == 0) {
  2413. status = PSA_ERROR_BAD_STATE;
  2414. goto exit;
  2415. }
  2416. if (!operation->is_sign) {
  2417. status = PSA_ERROR_BAD_STATE;
  2418. goto exit;
  2419. }
  2420. /* Sanity check. This will guarantee that mac_size != 0 (and so mac != NULL)
  2421. * once all the error checks are done. */
  2422. if (operation->mac_size == 0) {
  2423. status = PSA_ERROR_BAD_STATE;
  2424. goto exit;
  2425. }
  2426. if (mac_size < operation->mac_size) {
  2427. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2428. goto exit;
  2429. }
  2430. status = psa_driver_wrapper_mac_sign_finish(operation,
  2431. mac, operation->mac_size,
  2432. mac_length);
  2433. exit:
  2434. /* In case of success, set the potential excess room in the output buffer
  2435. * to an invalid value, to avoid potentially leaking a longer MAC.
  2436. * In case of error, set the output length and content to a safe default,
  2437. * such that in case the caller misses an error check, the output would be
  2438. * an unachievable MAC.
  2439. */
  2440. if (status != PSA_SUCCESS) {
  2441. *mac_length = mac_size;
  2442. operation->mac_size = 0;
  2443. }
  2444. if (mac != NULL) {
  2445. psa_wipe_tag_output_buffer(mac, status, mac_size, *mac_length);
  2446. }
  2447. abort_status = psa_mac_abort(operation);
  2448. LOCAL_OUTPUT_FREE(mac_external, mac);
  2449. return status == PSA_SUCCESS ? abort_status : status;
  2450. }
  2451. psa_status_t psa_mac_verify_finish(psa_mac_operation_t *operation,
  2452. const uint8_t *mac_external,
  2453. size_t mac_length)
  2454. {
  2455. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2456. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  2457. LOCAL_INPUT_DECLARE(mac_external, mac);
  2458. if (operation->id == 0) {
  2459. status = PSA_ERROR_BAD_STATE;
  2460. goto exit;
  2461. }
  2462. if (operation->is_sign) {
  2463. status = PSA_ERROR_BAD_STATE;
  2464. goto exit;
  2465. }
  2466. if (operation->mac_size != mac_length) {
  2467. status = PSA_ERROR_INVALID_SIGNATURE;
  2468. goto exit;
  2469. }
  2470. LOCAL_INPUT_ALLOC(mac_external, mac_length, mac);
  2471. status = psa_driver_wrapper_mac_verify_finish(operation,
  2472. mac, mac_length);
  2473. exit:
  2474. abort_status = psa_mac_abort(operation);
  2475. LOCAL_INPUT_FREE(mac_external, mac);
  2476. return status == PSA_SUCCESS ? abort_status : status;
  2477. }
  2478. static psa_status_t psa_mac_compute_internal(mbedtls_svc_key_id_t key,
  2479. psa_algorithm_t alg,
  2480. const uint8_t *input,
  2481. size_t input_length,
  2482. uint8_t *mac,
  2483. size_t mac_size,
  2484. size_t *mac_length,
  2485. int is_sign)
  2486. {
  2487. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2488. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2489. psa_key_slot_t *slot;
  2490. uint8_t operation_mac_size = 0;
  2491. status = psa_get_and_lock_key_slot_with_policy(
  2492. key,
  2493. &slot,
  2494. is_sign ? PSA_KEY_USAGE_SIGN_MESSAGE : PSA_KEY_USAGE_VERIFY_MESSAGE,
  2495. alg);
  2496. if (status != PSA_SUCCESS) {
  2497. goto exit;
  2498. }
  2499. status = psa_mac_finalize_alg_and_key_validation(alg, &slot->attr,
  2500. &operation_mac_size);
  2501. if (status != PSA_SUCCESS) {
  2502. goto exit;
  2503. }
  2504. if (mac_size < operation_mac_size) {
  2505. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2506. goto exit;
  2507. }
  2508. status = psa_driver_wrapper_mac_compute(
  2509. &slot->attr,
  2510. slot->key.data, slot->key.bytes,
  2511. alg,
  2512. input, input_length,
  2513. mac, operation_mac_size, mac_length);
  2514. exit:
  2515. /* In case of success, set the potential excess room in the output buffer
  2516. * to an invalid value, to avoid potentially leaking a longer MAC.
  2517. * In case of error, set the output length and content to a safe default,
  2518. * such that in case the caller misses an error check, the output would be
  2519. * an unachievable MAC.
  2520. */
  2521. if (status != PSA_SUCCESS) {
  2522. *mac_length = mac_size;
  2523. operation_mac_size = 0;
  2524. }
  2525. psa_wipe_tag_output_buffer(mac, status, mac_size, *mac_length);
  2526. unlock_status = psa_unregister_read_under_mutex(slot);
  2527. return (status == PSA_SUCCESS) ? unlock_status : status;
  2528. }
  2529. psa_status_t psa_mac_compute(mbedtls_svc_key_id_t key,
  2530. psa_algorithm_t alg,
  2531. const uint8_t *input_external,
  2532. size_t input_length,
  2533. uint8_t *mac_external,
  2534. size_t mac_size,
  2535. size_t *mac_length)
  2536. {
  2537. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2538. LOCAL_INPUT_DECLARE(input_external, input);
  2539. LOCAL_OUTPUT_DECLARE(mac_external, mac);
  2540. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  2541. LOCAL_OUTPUT_ALLOC(mac_external, mac_size, mac);
  2542. status = psa_mac_compute_internal(key, alg,
  2543. input, input_length,
  2544. mac, mac_size, mac_length, 1);
  2545. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  2546. exit:
  2547. #endif
  2548. LOCAL_INPUT_FREE(input_external, input);
  2549. LOCAL_OUTPUT_FREE(mac_external, mac);
  2550. return status;
  2551. }
  2552. psa_status_t psa_mac_verify(mbedtls_svc_key_id_t key,
  2553. psa_algorithm_t alg,
  2554. const uint8_t *input_external,
  2555. size_t input_length,
  2556. const uint8_t *mac_external,
  2557. size_t mac_length)
  2558. {
  2559. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2560. uint8_t actual_mac[PSA_MAC_MAX_SIZE];
  2561. size_t actual_mac_length;
  2562. LOCAL_INPUT_DECLARE(input_external, input);
  2563. LOCAL_INPUT_DECLARE(mac_external, mac);
  2564. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  2565. status = psa_mac_compute_internal(key, alg,
  2566. input, input_length,
  2567. actual_mac, sizeof(actual_mac),
  2568. &actual_mac_length, 0);
  2569. if (status != PSA_SUCCESS) {
  2570. goto exit;
  2571. }
  2572. if (mac_length != actual_mac_length) {
  2573. status = PSA_ERROR_INVALID_SIGNATURE;
  2574. goto exit;
  2575. }
  2576. LOCAL_INPUT_ALLOC(mac_external, mac_length, mac);
  2577. if (mbedtls_ct_memcmp(mac, actual_mac, actual_mac_length) != 0) {
  2578. status = PSA_ERROR_INVALID_SIGNATURE;
  2579. goto exit;
  2580. }
  2581. exit:
  2582. mbedtls_platform_zeroize(actual_mac, sizeof(actual_mac));
  2583. LOCAL_INPUT_FREE(input_external, input);
  2584. LOCAL_INPUT_FREE(mac_external, mac);
  2585. return status;
  2586. }
  2587. /****************************************************************/
  2588. /* Asymmetric cryptography */
  2589. /****************************************************************/
  2590. static psa_status_t psa_sign_verify_check_alg(int input_is_message,
  2591. psa_algorithm_t alg)
  2592. {
  2593. if (input_is_message) {
  2594. if (!PSA_ALG_IS_SIGN_MESSAGE(alg)) {
  2595. return PSA_ERROR_INVALID_ARGUMENT;
  2596. }
  2597. if (PSA_ALG_IS_SIGN_HASH(alg)) {
  2598. if (!PSA_ALG_IS_HASH(PSA_ALG_SIGN_GET_HASH(alg))) {
  2599. return PSA_ERROR_INVALID_ARGUMENT;
  2600. }
  2601. }
  2602. } else {
  2603. if (!PSA_ALG_IS_SIGN_HASH(alg)) {
  2604. return PSA_ERROR_INVALID_ARGUMENT;
  2605. }
  2606. }
  2607. return PSA_SUCCESS;
  2608. }
  2609. static psa_status_t psa_sign_internal(mbedtls_svc_key_id_t key,
  2610. int input_is_message,
  2611. psa_algorithm_t alg,
  2612. const uint8_t *input,
  2613. size_t input_length,
  2614. uint8_t *signature,
  2615. size_t signature_size,
  2616. size_t *signature_length)
  2617. {
  2618. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2619. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2620. psa_key_slot_t *slot;
  2621. *signature_length = 0;
  2622. status = psa_sign_verify_check_alg(input_is_message, alg);
  2623. if (status != PSA_SUCCESS) {
  2624. return status;
  2625. }
  2626. /* Immediately reject a zero-length signature buffer. This guarantees
  2627. * that signature must be a valid pointer. (On the other hand, the input
  2628. * buffer can in principle be empty since it doesn't actually have
  2629. * to be a hash.) */
  2630. if (signature_size == 0) {
  2631. return PSA_ERROR_BUFFER_TOO_SMALL;
  2632. }
  2633. status = psa_get_and_lock_key_slot_with_policy(
  2634. key, &slot,
  2635. input_is_message ? PSA_KEY_USAGE_SIGN_MESSAGE :
  2636. PSA_KEY_USAGE_SIGN_HASH,
  2637. alg);
  2638. if (status != PSA_SUCCESS) {
  2639. goto exit;
  2640. }
  2641. if (!PSA_KEY_TYPE_IS_KEY_PAIR(slot->attr.type)) {
  2642. status = PSA_ERROR_INVALID_ARGUMENT;
  2643. goto exit;
  2644. }
  2645. if (input_is_message) {
  2646. status = psa_driver_wrapper_sign_message(
  2647. &slot->attr, slot->key.data, slot->key.bytes,
  2648. alg, input, input_length,
  2649. signature, signature_size, signature_length);
  2650. } else {
  2651. status = psa_driver_wrapper_sign_hash(
  2652. &slot->attr, slot->key.data, slot->key.bytes,
  2653. alg, input, input_length,
  2654. signature, signature_size, signature_length);
  2655. }
  2656. exit:
  2657. psa_wipe_tag_output_buffer(signature, status, signature_size,
  2658. *signature_length);
  2659. unlock_status = psa_unregister_read_under_mutex(slot);
  2660. return (status == PSA_SUCCESS) ? unlock_status : status;
  2661. }
  2662. static psa_status_t psa_verify_internal(mbedtls_svc_key_id_t key,
  2663. int input_is_message,
  2664. psa_algorithm_t alg,
  2665. const uint8_t *input,
  2666. size_t input_length,
  2667. const uint8_t *signature,
  2668. size_t signature_length)
  2669. {
  2670. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2671. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2672. psa_key_slot_t *slot;
  2673. status = psa_sign_verify_check_alg(input_is_message, alg);
  2674. if (status != PSA_SUCCESS) {
  2675. return status;
  2676. }
  2677. status = psa_get_and_lock_key_slot_with_policy(
  2678. key, &slot,
  2679. input_is_message ? PSA_KEY_USAGE_VERIFY_MESSAGE :
  2680. PSA_KEY_USAGE_VERIFY_HASH,
  2681. alg);
  2682. if (status != PSA_SUCCESS) {
  2683. return status;
  2684. }
  2685. if (input_is_message) {
  2686. status = psa_driver_wrapper_verify_message(
  2687. &slot->attr, slot->key.data, slot->key.bytes,
  2688. alg, input, input_length,
  2689. signature, signature_length);
  2690. } else {
  2691. status = psa_driver_wrapper_verify_hash(
  2692. &slot->attr, slot->key.data, slot->key.bytes,
  2693. alg, input, input_length,
  2694. signature, signature_length);
  2695. }
  2696. unlock_status = psa_unregister_read_under_mutex(slot);
  2697. return (status == PSA_SUCCESS) ? unlock_status : status;
  2698. }
  2699. psa_status_t psa_sign_message_builtin(
  2700. const psa_key_attributes_t *attributes,
  2701. const uint8_t *key_buffer,
  2702. size_t key_buffer_size,
  2703. psa_algorithm_t alg,
  2704. const uint8_t *input,
  2705. size_t input_length,
  2706. uint8_t *signature,
  2707. size_t signature_size,
  2708. size_t *signature_length)
  2709. {
  2710. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2711. if (PSA_ALG_IS_SIGN_HASH(alg)) {
  2712. size_t hash_length;
  2713. uint8_t hash[PSA_HASH_MAX_SIZE];
  2714. status = psa_driver_wrapper_hash_compute(
  2715. PSA_ALG_SIGN_GET_HASH(alg),
  2716. input, input_length,
  2717. hash, sizeof(hash), &hash_length);
  2718. if (status != PSA_SUCCESS) {
  2719. return status;
  2720. }
  2721. return psa_driver_wrapper_sign_hash(
  2722. attributes, key_buffer, key_buffer_size,
  2723. alg, hash, hash_length,
  2724. signature, signature_size, signature_length);
  2725. }
  2726. return PSA_ERROR_NOT_SUPPORTED;
  2727. }
  2728. psa_status_t psa_sign_message(mbedtls_svc_key_id_t key,
  2729. psa_algorithm_t alg,
  2730. const uint8_t *input_external,
  2731. size_t input_length,
  2732. uint8_t *signature_external,
  2733. size_t signature_size,
  2734. size_t *signature_length)
  2735. {
  2736. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2737. LOCAL_INPUT_DECLARE(input_external, input);
  2738. LOCAL_OUTPUT_DECLARE(signature_external, signature);
  2739. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  2740. LOCAL_OUTPUT_ALLOC(signature_external, signature_size, signature);
  2741. status = psa_sign_internal(key, 1, alg, input, input_length, signature,
  2742. signature_size, signature_length);
  2743. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  2744. exit:
  2745. #endif
  2746. LOCAL_INPUT_FREE(input_external, input);
  2747. LOCAL_OUTPUT_FREE(signature_external, signature);
  2748. return status;
  2749. }
  2750. psa_status_t psa_verify_message_builtin(
  2751. const psa_key_attributes_t *attributes,
  2752. const uint8_t *key_buffer,
  2753. size_t key_buffer_size,
  2754. psa_algorithm_t alg,
  2755. const uint8_t *input,
  2756. size_t input_length,
  2757. const uint8_t *signature,
  2758. size_t signature_length)
  2759. {
  2760. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2761. if (PSA_ALG_IS_SIGN_HASH(alg)) {
  2762. size_t hash_length;
  2763. uint8_t hash[PSA_HASH_MAX_SIZE];
  2764. status = psa_driver_wrapper_hash_compute(
  2765. PSA_ALG_SIGN_GET_HASH(alg),
  2766. input, input_length,
  2767. hash, sizeof(hash), &hash_length);
  2768. if (status != PSA_SUCCESS) {
  2769. return status;
  2770. }
  2771. return psa_driver_wrapper_verify_hash(
  2772. attributes, key_buffer, key_buffer_size,
  2773. alg, hash, hash_length,
  2774. signature, signature_length);
  2775. }
  2776. return PSA_ERROR_NOT_SUPPORTED;
  2777. }
  2778. psa_status_t psa_verify_message(mbedtls_svc_key_id_t key,
  2779. psa_algorithm_t alg,
  2780. const uint8_t *input_external,
  2781. size_t input_length,
  2782. const uint8_t *signature_external,
  2783. size_t signature_length)
  2784. {
  2785. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2786. LOCAL_INPUT_DECLARE(input_external, input);
  2787. LOCAL_INPUT_DECLARE(signature_external, signature);
  2788. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  2789. LOCAL_INPUT_ALLOC(signature_external, signature_length, signature);
  2790. status = psa_verify_internal(key, 1, alg, input, input_length, signature,
  2791. signature_length);
  2792. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  2793. exit:
  2794. #endif
  2795. LOCAL_INPUT_FREE(input_external, input);
  2796. LOCAL_INPUT_FREE(signature_external, signature);
  2797. return status;
  2798. }
  2799. psa_status_t psa_sign_hash_builtin(
  2800. const psa_key_attributes_t *attributes,
  2801. const uint8_t *key_buffer, size_t key_buffer_size,
  2802. psa_algorithm_t alg, const uint8_t *hash, size_t hash_length,
  2803. uint8_t *signature, size_t signature_size, size_t *signature_length)
  2804. {
  2805. if (attributes->type == PSA_KEY_TYPE_RSA_KEY_PAIR) {
  2806. if (PSA_ALG_IS_RSA_PKCS1V15_SIGN(alg) ||
  2807. PSA_ALG_IS_RSA_PSS(alg)) {
  2808. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) || \
  2809. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS)
  2810. return mbedtls_psa_rsa_sign_hash(
  2811. attributes,
  2812. key_buffer, key_buffer_size,
  2813. alg, hash, hash_length,
  2814. signature, signature_size, signature_length);
  2815. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) ||
  2816. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS) */
  2817. } else {
  2818. return PSA_ERROR_INVALID_ARGUMENT;
  2819. }
  2820. } else if (PSA_KEY_TYPE_IS_ECC(attributes->type)) {
  2821. if (PSA_ALG_IS_ECDSA(alg)) {
  2822. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  2823. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  2824. return mbedtls_psa_ecdsa_sign_hash(
  2825. attributes,
  2826. key_buffer, key_buffer_size,
  2827. alg, hash, hash_length,
  2828. signature, signature_size, signature_length);
  2829. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  2830. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  2831. } else {
  2832. return PSA_ERROR_INVALID_ARGUMENT;
  2833. }
  2834. }
  2835. (void) key_buffer;
  2836. (void) key_buffer_size;
  2837. (void) hash;
  2838. (void) hash_length;
  2839. (void) signature;
  2840. (void) signature_size;
  2841. (void) signature_length;
  2842. return PSA_ERROR_NOT_SUPPORTED;
  2843. }
  2844. psa_status_t psa_sign_hash(mbedtls_svc_key_id_t key,
  2845. psa_algorithm_t alg,
  2846. const uint8_t *hash_external,
  2847. size_t hash_length,
  2848. uint8_t *signature_external,
  2849. size_t signature_size,
  2850. size_t *signature_length)
  2851. {
  2852. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2853. LOCAL_INPUT_DECLARE(hash_external, hash);
  2854. LOCAL_OUTPUT_DECLARE(signature_external, signature);
  2855. LOCAL_INPUT_ALLOC(hash_external, hash_length, hash);
  2856. LOCAL_OUTPUT_ALLOC(signature_external, signature_size, signature);
  2857. status = psa_sign_internal(key, 0, alg, hash, hash_length, signature,
  2858. signature_size, signature_length);
  2859. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  2860. exit:
  2861. #endif
  2862. LOCAL_INPUT_FREE(hash_external, hash);
  2863. LOCAL_OUTPUT_FREE(signature_external, signature);
  2864. return status;
  2865. }
  2866. psa_status_t psa_verify_hash_builtin(
  2867. const psa_key_attributes_t *attributes,
  2868. const uint8_t *key_buffer, size_t key_buffer_size,
  2869. psa_algorithm_t alg, const uint8_t *hash, size_t hash_length,
  2870. const uint8_t *signature, size_t signature_length)
  2871. {
  2872. if (PSA_KEY_TYPE_IS_RSA(attributes->type)) {
  2873. if (PSA_ALG_IS_RSA_PKCS1V15_SIGN(alg) ||
  2874. PSA_ALG_IS_RSA_PSS(alg)) {
  2875. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) || \
  2876. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS)
  2877. return mbedtls_psa_rsa_verify_hash(
  2878. attributes,
  2879. key_buffer, key_buffer_size,
  2880. alg, hash, hash_length,
  2881. signature, signature_length);
  2882. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) ||
  2883. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS) */
  2884. } else {
  2885. return PSA_ERROR_INVALID_ARGUMENT;
  2886. }
  2887. } else if (PSA_KEY_TYPE_IS_ECC(attributes->type)) {
  2888. if (PSA_ALG_IS_ECDSA(alg)) {
  2889. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  2890. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  2891. return mbedtls_psa_ecdsa_verify_hash(
  2892. attributes,
  2893. key_buffer, key_buffer_size,
  2894. alg, hash, hash_length,
  2895. signature, signature_length);
  2896. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  2897. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  2898. } else {
  2899. return PSA_ERROR_INVALID_ARGUMENT;
  2900. }
  2901. }
  2902. (void) key_buffer;
  2903. (void) key_buffer_size;
  2904. (void) hash;
  2905. (void) hash_length;
  2906. (void) signature;
  2907. (void) signature_length;
  2908. return PSA_ERROR_NOT_SUPPORTED;
  2909. }
  2910. psa_status_t psa_verify_hash(mbedtls_svc_key_id_t key,
  2911. psa_algorithm_t alg,
  2912. const uint8_t *hash_external,
  2913. size_t hash_length,
  2914. const uint8_t *signature_external,
  2915. size_t signature_length)
  2916. {
  2917. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2918. LOCAL_INPUT_DECLARE(hash_external, hash);
  2919. LOCAL_INPUT_DECLARE(signature_external, signature);
  2920. LOCAL_INPUT_ALLOC(hash_external, hash_length, hash);
  2921. LOCAL_INPUT_ALLOC(signature_external, signature_length, signature);
  2922. status = psa_verify_internal(key, 0, alg, hash, hash_length, signature,
  2923. signature_length);
  2924. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  2925. exit:
  2926. #endif
  2927. LOCAL_INPUT_FREE(hash_external, hash);
  2928. LOCAL_INPUT_FREE(signature_external, signature);
  2929. return status;
  2930. }
  2931. psa_status_t psa_asymmetric_encrypt(mbedtls_svc_key_id_t key,
  2932. psa_algorithm_t alg,
  2933. const uint8_t *input_external,
  2934. size_t input_length,
  2935. const uint8_t *salt_external,
  2936. size_t salt_length,
  2937. uint8_t *output_external,
  2938. size_t output_size,
  2939. size_t *output_length)
  2940. {
  2941. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2942. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2943. psa_key_slot_t *slot;
  2944. LOCAL_INPUT_DECLARE(input_external, input);
  2945. LOCAL_INPUT_DECLARE(salt_external, salt);
  2946. LOCAL_OUTPUT_DECLARE(output_external, output);
  2947. (void) input;
  2948. (void) input_length;
  2949. (void) salt;
  2950. (void) output;
  2951. (void) output_size;
  2952. *output_length = 0;
  2953. if (!PSA_ALG_IS_RSA_OAEP(alg) && salt_length != 0) {
  2954. return PSA_ERROR_INVALID_ARGUMENT;
  2955. }
  2956. status = psa_get_and_lock_key_slot_with_policy(
  2957. key, &slot, PSA_KEY_USAGE_ENCRYPT, alg);
  2958. if (status != PSA_SUCCESS) {
  2959. return status;
  2960. }
  2961. if (!(PSA_KEY_TYPE_IS_PUBLIC_KEY(slot->attr.type) ||
  2962. PSA_KEY_TYPE_IS_KEY_PAIR(slot->attr.type))) {
  2963. status = PSA_ERROR_INVALID_ARGUMENT;
  2964. goto exit;
  2965. }
  2966. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  2967. LOCAL_INPUT_ALLOC(salt_external, salt_length, salt);
  2968. LOCAL_OUTPUT_ALLOC(output_external, output_size, output);
  2969. status = psa_driver_wrapper_asymmetric_encrypt(
  2970. &slot->attr, slot->key.data, slot->key.bytes,
  2971. alg, input, input_length, salt, salt_length,
  2972. output, output_size, output_length);
  2973. exit:
  2974. unlock_status = psa_unregister_read_under_mutex(slot);
  2975. LOCAL_INPUT_FREE(input_external, input);
  2976. LOCAL_INPUT_FREE(salt_external, salt);
  2977. LOCAL_OUTPUT_FREE(output_external, output);
  2978. return (status == PSA_SUCCESS) ? unlock_status : status;
  2979. }
  2980. psa_status_t psa_asymmetric_decrypt(mbedtls_svc_key_id_t key,
  2981. psa_algorithm_t alg,
  2982. const uint8_t *input_external,
  2983. size_t input_length,
  2984. const uint8_t *salt_external,
  2985. size_t salt_length,
  2986. uint8_t *output_external,
  2987. size_t output_size,
  2988. size_t *output_length)
  2989. {
  2990. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2991. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2992. psa_key_slot_t *slot;
  2993. LOCAL_INPUT_DECLARE(input_external, input);
  2994. LOCAL_INPUT_DECLARE(salt_external, salt);
  2995. LOCAL_OUTPUT_DECLARE(output_external, output);
  2996. (void) input;
  2997. (void) input_length;
  2998. (void) salt;
  2999. (void) output;
  3000. (void) output_size;
  3001. *output_length = 0;
  3002. if (!PSA_ALG_IS_RSA_OAEP(alg) && salt_length != 0) {
  3003. return PSA_ERROR_INVALID_ARGUMENT;
  3004. }
  3005. status = psa_get_and_lock_key_slot_with_policy(
  3006. key, &slot, PSA_KEY_USAGE_DECRYPT, alg);
  3007. if (status != PSA_SUCCESS) {
  3008. return status;
  3009. }
  3010. if (!PSA_KEY_TYPE_IS_KEY_PAIR(slot->attr.type)) {
  3011. status = PSA_ERROR_INVALID_ARGUMENT;
  3012. goto exit;
  3013. }
  3014. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  3015. LOCAL_INPUT_ALLOC(salt_external, salt_length, salt);
  3016. LOCAL_OUTPUT_ALLOC(output_external, output_size, output);
  3017. status = psa_driver_wrapper_asymmetric_decrypt(
  3018. &slot->attr, slot->key.data, slot->key.bytes,
  3019. alg, input, input_length, salt, salt_length,
  3020. output, output_size, output_length);
  3021. exit:
  3022. unlock_status = psa_unregister_read_under_mutex(slot);
  3023. LOCAL_INPUT_FREE(input_external, input);
  3024. LOCAL_INPUT_FREE(salt_external, salt);
  3025. LOCAL_OUTPUT_FREE(output_external, output);
  3026. return (status == PSA_SUCCESS) ? unlock_status : status;
  3027. }
  3028. /****************************************************************/
  3029. /* Asymmetric interruptible cryptography */
  3030. /****************************************************************/
  3031. static uint32_t psa_interruptible_max_ops = PSA_INTERRUPTIBLE_MAX_OPS_UNLIMITED;
  3032. void psa_interruptible_set_max_ops(uint32_t max_ops)
  3033. {
  3034. psa_interruptible_max_ops = max_ops;
  3035. }
  3036. uint32_t psa_interruptible_get_max_ops(void)
  3037. {
  3038. return psa_interruptible_max_ops;
  3039. }
  3040. uint32_t psa_sign_hash_get_num_ops(
  3041. const psa_sign_hash_interruptible_operation_t *operation)
  3042. {
  3043. return operation->num_ops;
  3044. }
  3045. uint32_t psa_verify_hash_get_num_ops(
  3046. const psa_verify_hash_interruptible_operation_t *operation)
  3047. {
  3048. return operation->num_ops;
  3049. }
  3050. static psa_status_t psa_sign_hash_abort_internal(
  3051. psa_sign_hash_interruptible_operation_t *operation)
  3052. {
  3053. if (operation->id == 0) {
  3054. /* The object has (apparently) been initialized but it is not (yet)
  3055. * in use. It's ok to call abort on such an object, and there's
  3056. * nothing to do. */
  3057. return PSA_SUCCESS;
  3058. }
  3059. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3060. status = psa_driver_wrapper_sign_hash_abort(operation);
  3061. operation->id = 0;
  3062. /* Do not clear either the error_occurred or num_ops elements here as they
  3063. * only want to be cleared by the application calling abort, not by abort
  3064. * being called at completion of an operation. */
  3065. return status;
  3066. }
  3067. psa_status_t psa_sign_hash_start(
  3068. psa_sign_hash_interruptible_operation_t *operation,
  3069. mbedtls_svc_key_id_t key, psa_algorithm_t alg,
  3070. const uint8_t *hash_external, size_t hash_length)
  3071. {
  3072. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3073. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3074. psa_key_slot_t *slot;
  3075. LOCAL_INPUT_DECLARE(hash_external, hash);
  3076. /* Check that start has not been previously called, or operation has not
  3077. * previously errored. */
  3078. if (operation->id != 0 || operation->error_occurred) {
  3079. return PSA_ERROR_BAD_STATE;
  3080. }
  3081. status = psa_sign_verify_check_alg(0, alg);
  3082. if (status != PSA_SUCCESS) {
  3083. operation->error_occurred = 1;
  3084. return status;
  3085. }
  3086. status = psa_get_and_lock_key_slot_with_policy(key, &slot,
  3087. PSA_KEY_USAGE_SIGN_HASH,
  3088. alg);
  3089. if (status != PSA_SUCCESS) {
  3090. goto exit;
  3091. }
  3092. if (!PSA_KEY_TYPE_IS_KEY_PAIR(slot->attr.type)) {
  3093. status = PSA_ERROR_INVALID_ARGUMENT;
  3094. goto exit;
  3095. }
  3096. LOCAL_INPUT_ALLOC(hash_external, hash_length, hash);
  3097. /* Ensure ops count gets reset, in case of operation re-use. */
  3098. operation->num_ops = 0;
  3099. status = psa_driver_wrapper_sign_hash_start(operation, &slot->attr,
  3100. slot->key.data,
  3101. slot->key.bytes, alg,
  3102. hash, hash_length);
  3103. exit:
  3104. if (status != PSA_SUCCESS) {
  3105. operation->error_occurred = 1;
  3106. psa_sign_hash_abort_internal(operation);
  3107. }
  3108. unlock_status = psa_unregister_read_under_mutex(slot);
  3109. if (unlock_status != PSA_SUCCESS) {
  3110. operation->error_occurred = 1;
  3111. }
  3112. LOCAL_INPUT_FREE(hash_external, hash);
  3113. return (status == PSA_SUCCESS) ? unlock_status : status;
  3114. }
  3115. psa_status_t psa_sign_hash_complete(
  3116. psa_sign_hash_interruptible_operation_t *operation,
  3117. uint8_t *signature_external, size_t signature_size,
  3118. size_t *signature_length)
  3119. {
  3120. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3121. LOCAL_OUTPUT_DECLARE(signature_external, signature);
  3122. *signature_length = 0;
  3123. /* Check that start has been called first, and that operation has not
  3124. * previously errored. */
  3125. if (operation->id == 0 || operation->error_occurred) {
  3126. status = PSA_ERROR_BAD_STATE;
  3127. goto exit;
  3128. }
  3129. /* Immediately reject a zero-length signature buffer. This guarantees that
  3130. * signature must be a valid pointer. */
  3131. if (signature_size == 0) {
  3132. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3133. goto exit;
  3134. }
  3135. LOCAL_OUTPUT_ALLOC(signature_external, signature_size, signature);
  3136. status = psa_driver_wrapper_sign_hash_complete(operation, signature,
  3137. signature_size,
  3138. signature_length);
  3139. /* Update ops count with work done. */
  3140. operation->num_ops = psa_driver_wrapper_sign_hash_get_num_ops(operation);
  3141. exit:
  3142. if (signature != NULL) {
  3143. psa_wipe_tag_output_buffer(signature, status, signature_size,
  3144. *signature_length);
  3145. }
  3146. if (status != PSA_OPERATION_INCOMPLETE) {
  3147. if (status != PSA_SUCCESS) {
  3148. operation->error_occurred = 1;
  3149. }
  3150. psa_sign_hash_abort_internal(operation);
  3151. }
  3152. LOCAL_OUTPUT_FREE(signature_external, signature);
  3153. return status;
  3154. }
  3155. psa_status_t psa_sign_hash_abort(
  3156. psa_sign_hash_interruptible_operation_t *operation)
  3157. {
  3158. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3159. status = psa_sign_hash_abort_internal(operation);
  3160. /* We clear the number of ops done here, so that it is not cleared when
  3161. * the operation fails or succeeds, only on manual abort. */
  3162. operation->num_ops = 0;
  3163. /* Likewise, failure state. */
  3164. operation->error_occurred = 0;
  3165. return status;
  3166. }
  3167. static psa_status_t psa_verify_hash_abort_internal(
  3168. psa_verify_hash_interruptible_operation_t *operation)
  3169. {
  3170. if (operation->id == 0) {
  3171. /* The object has (apparently) been initialized but it is not (yet)
  3172. * in use. It's ok to call abort on such an object, and there's
  3173. * nothing to do. */
  3174. return PSA_SUCCESS;
  3175. }
  3176. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3177. status = psa_driver_wrapper_verify_hash_abort(operation);
  3178. operation->id = 0;
  3179. /* Do not clear either the error_occurred or num_ops elements here as they
  3180. * only want to be cleared by the application calling abort, not by abort
  3181. * being called at completion of an operation. */
  3182. return status;
  3183. }
  3184. psa_status_t psa_verify_hash_start(
  3185. psa_verify_hash_interruptible_operation_t *operation,
  3186. mbedtls_svc_key_id_t key, psa_algorithm_t alg,
  3187. const uint8_t *hash_external, size_t hash_length,
  3188. const uint8_t *signature_external, size_t signature_length)
  3189. {
  3190. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3191. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3192. psa_key_slot_t *slot;
  3193. LOCAL_INPUT_DECLARE(hash_external, hash);
  3194. LOCAL_INPUT_DECLARE(signature_external, signature);
  3195. /* Check that start has not been previously called, or operation has not
  3196. * previously errored. */
  3197. if (operation->id != 0 || operation->error_occurred) {
  3198. return PSA_ERROR_BAD_STATE;
  3199. }
  3200. status = psa_sign_verify_check_alg(0, alg);
  3201. if (status != PSA_SUCCESS) {
  3202. operation->error_occurred = 1;
  3203. return status;
  3204. }
  3205. status = psa_get_and_lock_key_slot_with_policy(key, &slot,
  3206. PSA_KEY_USAGE_VERIFY_HASH,
  3207. alg);
  3208. if (status != PSA_SUCCESS) {
  3209. operation->error_occurred = 1;
  3210. return status;
  3211. }
  3212. LOCAL_INPUT_ALLOC(hash_external, hash_length, hash);
  3213. LOCAL_INPUT_ALLOC(signature_external, signature_length, signature);
  3214. /* Ensure ops count gets reset, in case of operation re-use. */
  3215. operation->num_ops = 0;
  3216. status = psa_driver_wrapper_verify_hash_start(operation, &slot->attr,
  3217. slot->key.data,
  3218. slot->key.bytes,
  3219. alg, hash, hash_length,
  3220. signature, signature_length);
  3221. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  3222. exit:
  3223. #endif
  3224. if (status != PSA_SUCCESS) {
  3225. operation->error_occurred = 1;
  3226. psa_verify_hash_abort_internal(operation);
  3227. }
  3228. unlock_status = psa_unregister_read_under_mutex(slot);
  3229. if (unlock_status != PSA_SUCCESS) {
  3230. operation->error_occurred = 1;
  3231. }
  3232. LOCAL_INPUT_FREE(hash_external, hash);
  3233. LOCAL_INPUT_FREE(signature_external, signature);
  3234. return (status == PSA_SUCCESS) ? unlock_status : status;
  3235. }
  3236. psa_status_t psa_verify_hash_complete(
  3237. psa_verify_hash_interruptible_operation_t *operation)
  3238. {
  3239. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3240. /* Check that start has been called first, and that operation has not
  3241. * previously errored. */
  3242. if (operation->id == 0 || operation->error_occurred) {
  3243. status = PSA_ERROR_BAD_STATE;
  3244. goto exit;
  3245. }
  3246. status = psa_driver_wrapper_verify_hash_complete(operation);
  3247. /* Update ops count with work done. */
  3248. operation->num_ops = psa_driver_wrapper_verify_hash_get_num_ops(
  3249. operation);
  3250. exit:
  3251. if (status != PSA_OPERATION_INCOMPLETE) {
  3252. if (status != PSA_SUCCESS) {
  3253. operation->error_occurred = 1;
  3254. }
  3255. psa_verify_hash_abort_internal(operation);
  3256. }
  3257. return status;
  3258. }
  3259. psa_status_t psa_verify_hash_abort(
  3260. psa_verify_hash_interruptible_operation_t *operation)
  3261. {
  3262. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3263. status = psa_verify_hash_abort_internal(operation);
  3264. /* We clear the number of ops done here, so that it is not cleared when
  3265. * the operation fails or succeeds, only on manual abort. */
  3266. operation->num_ops = 0;
  3267. /* Likewise, failure state. */
  3268. operation->error_occurred = 0;
  3269. return status;
  3270. }
  3271. /****************************************************************/
  3272. /* Asymmetric interruptible cryptography internal */
  3273. /* implementations */
  3274. /****************************************************************/
  3275. void mbedtls_psa_interruptible_set_max_ops(uint32_t max_ops)
  3276. {
  3277. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3278. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3279. defined(MBEDTLS_ECP_RESTARTABLE)
  3280. /* Internal implementation uses zero to indicate infinite number max ops,
  3281. * therefore avoid this value, and set to minimum possible. */
  3282. if (max_ops == 0) {
  3283. max_ops = 1;
  3284. }
  3285. mbedtls_ecp_set_max_ops(max_ops);
  3286. #else
  3287. (void) max_ops;
  3288. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3289. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3290. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3291. }
  3292. uint32_t mbedtls_psa_sign_hash_get_num_ops(
  3293. const mbedtls_psa_sign_hash_interruptible_operation_t *operation)
  3294. {
  3295. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3296. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3297. defined(MBEDTLS_ECP_RESTARTABLE)
  3298. return operation->num_ops;
  3299. #else
  3300. (void) operation;
  3301. return 0;
  3302. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3303. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3304. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3305. }
  3306. uint32_t mbedtls_psa_verify_hash_get_num_ops(
  3307. const mbedtls_psa_verify_hash_interruptible_operation_t *operation)
  3308. {
  3309. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3310. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3311. defined(MBEDTLS_ECP_RESTARTABLE)
  3312. return operation->num_ops;
  3313. #else
  3314. (void) operation;
  3315. return 0;
  3316. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3317. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3318. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3319. }
  3320. psa_status_t mbedtls_psa_sign_hash_start(
  3321. mbedtls_psa_sign_hash_interruptible_operation_t *operation,
  3322. const psa_key_attributes_t *attributes, const uint8_t *key_buffer,
  3323. size_t key_buffer_size, psa_algorithm_t alg,
  3324. const uint8_t *hash, size_t hash_length)
  3325. {
  3326. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3327. size_t required_hash_length;
  3328. if (!PSA_KEY_TYPE_IS_ECC(attributes->type)) {
  3329. return PSA_ERROR_NOT_SUPPORTED;
  3330. }
  3331. if (!PSA_ALG_IS_ECDSA(alg)) {
  3332. return PSA_ERROR_NOT_SUPPORTED;
  3333. }
  3334. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3335. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3336. defined(MBEDTLS_ECP_RESTARTABLE)
  3337. mbedtls_ecdsa_restart_init(&operation->restart_ctx);
  3338. /* Ensure num_ops is zero'ed in case of context re-use. */
  3339. operation->num_ops = 0;
  3340. status = mbedtls_psa_ecp_load_representation(attributes->type,
  3341. attributes->bits,
  3342. key_buffer,
  3343. key_buffer_size,
  3344. &operation->ctx);
  3345. if (status != PSA_SUCCESS) {
  3346. return status;
  3347. }
  3348. operation->coordinate_bytes = PSA_BITS_TO_BYTES(
  3349. operation->ctx->grp.nbits);
  3350. psa_algorithm_t hash_alg = PSA_ALG_SIGN_GET_HASH(alg);
  3351. operation->md_alg = mbedtls_md_type_from_psa_alg(hash_alg);
  3352. operation->alg = alg;
  3353. /* We only need to store the same length of hash as the private key size
  3354. * here, it would be truncated by the internal implementation anyway. */
  3355. required_hash_length = (hash_length < operation->coordinate_bytes ?
  3356. hash_length : operation->coordinate_bytes);
  3357. if (required_hash_length > sizeof(operation->hash)) {
  3358. /* Shouldn't happen, but better safe than sorry. */
  3359. return PSA_ERROR_CORRUPTION_DETECTED;
  3360. }
  3361. memcpy(operation->hash, hash, required_hash_length);
  3362. operation->hash_length = required_hash_length;
  3363. return PSA_SUCCESS;
  3364. #else
  3365. (void) operation;
  3366. (void) key_buffer;
  3367. (void) key_buffer_size;
  3368. (void) alg;
  3369. (void) hash;
  3370. (void) hash_length;
  3371. (void) status;
  3372. (void) required_hash_length;
  3373. return PSA_ERROR_NOT_SUPPORTED;
  3374. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3375. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3376. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3377. }
  3378. psa_status_t mbedtls_psa_sign_hash_complete(
  3379. mbedtls_psa_sign_hash_interruptible_operation_t *operation,
  3380. uint8_t *signature, size_t signature_size,
  3381. size_t *signature_length)
  3382. {
  3383. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3384. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3385. defined(MBEDTLS_ECP_RESTARTABLE)
  3386. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3387. mbedtls_mpi r;
  3388. mbedtls_mpi s;
  3389. mbedtls_mpi_init(&r);
  3390. mbedtls_mpi_init(&s);
  3391. /* Ensure max_ops is set to the current value (or default). */
  3392. mbedtls_psa_interruptible_set_max_ops(psa_interruptible_get_max_ops());
  3393. if (signature_size < 2 * operation->coordinate_bytes) {
  3394. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3395. goto exit;
  3396. }
  3397. if (PSA_ALG_ECDSA_IS_DETERMINISTIC(operation->alg)) {
  3398. #if defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  3399. status = mbedtls_to_psa_error(
  3400. mbedtls_ecdsa_sign_det_restartable(&operation->ctx->grp,
  3401. &r,
  3402. &s,
  3403. &operation->ctx->d,
  3404. operation->hash,
  3405. operation->hash_length,
  3406. operation->md_alg,
  3407. mbedtls_psa_get_random,
  3408. MBEDTLS_PSA_RANDOM_STATE,
  3409. &operation->restart_ctx));
  3410. #else /* defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  3411. status = PSA_ERROR_NOT_SUPPORTED;
  3412. goto exit;
  3413. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  3414. } else {
  3415. status = mbedtls_to_psa_error(
  3416. mbedtls_ecdsa_sign_restartable(&operation->ctx->grp,
  3417. &r,
  3418. &s,
  3419. &operation->ctx->d,
  3420. operation->hash,
  3421. operation->hash_length,
  3422. mbedtls_psa_get_random,
  3423. MBEDTLS_PSA_RANDOM_STATE,
  3424. mbedtls_psa_get_random,
  3425. MBEDTLS_PSA_RANDOM_STATE,
  3426. &operation->restart_ctx));
  3427. }
  3428. /* Hide the fact that the restart context only holds a delta of number of
  3429. * ops done during the last operation, not an absolute value. */
  3430. operation->num_ops += operation->restart_ctx.ecp.ops_done;
  3431. if (status == PSA_SUCCESS) {
  3432. status = mbedtls_to_psa_error(
  3433. mbedtls_mpi_write_binary(&r,
  3434. signature,
  3435. operation->coordinate_bytes)
  3436. );
  3437. if (status != PSA_SUCCESS) {
  3438. goto exit;
  3439. }
  3440. status = mbedtls_to_psa_error(
  3441. mbedtls_mpi_write_binary(&s,
  3442. signature +
  3443. operation->coordinate_bytes,
  3444. operation->coordinate_bytes)
  3445. );
  3446. if (status != PSA_SUCCESS) {
  3447. goto exit;
  3448. }
  3449. *signature_length = operation->coordinate_bytes * 2;
  3450. status = PSA_SUCCESS;
  3451. }
  3452. exit:
  3453. mbedtls_mpi_free(&r);
  3454. mbedtls_mpi_free(&s);
  3455. return status;
  3456. #else
  3457. (void) operation;
  3458. (void) signature;
  3459. (void) signature_size;
  3460. (void) signature_length;
  3461. return PSA_ERROR_NOT_SUPPORTED;
  3462. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3463. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3464. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3465. }
  3466. psa_status_t mbedtls_psa_sign_hash_abort(
  3467. mbedtls_psa_sign_hash_interruptible_operation_t *operation)
  3468. {
  3469. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3470. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3471. defined(MBEDTLS_ECP_RESTARTABLE)
  3472. if (operation->ctx) {
  3473. mbedtls_ecdsa_free(operation->ctx);
  3474. mbedtls_free(operation->ctx);
  3475. operation->ctx = NULL;
  3476. }
  3477. mbedtls_ecdsa_restart_free(&operation->restart_ctx);
  3478. operation->num_ops = 0;
  3479. return PSA_SUCCESS;
  3480. #else
  3481. (void) operation;
  3482. return PSA_ERROR_NOT_SUPPORTED;
  3483. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3484. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3485. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3486. }
  3487. psa_status_t mbedtls_psa_verify_hash_start(
  3488. mbedtls_psa_verify_hash_interruptible_operation_t *operation,
  3489. const psa_key_attributes_t *attributes,
  3490. const uint8_t *key_buffer, size_t key_buffer_size,
  3491. psa_algorithm_t alg,
  3492. const uint8_t *hash, size_t hash_length,
  3493. const uint8_t *signature, size_t signature_length)
  3494. {
  3495. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3496. size_t coordinate_bytes = 0;
  3497. size_t required_hash_length = 0;
  3498. if (!PSA_KEY_TYPE_IS_ECC(attributes->type)) {
  3499. return PSA_ERROR_NOT_SUPPORTED;
  3500. }
  3501. if (!PSA_ALG_IS_ECDSA(alg)) {
  3502. return PSA_ERROR_NOT_SUPPORTED;
  3503. }
  3504. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3505. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3506. defined(MBEDTLS_ECP_RESTARTABLE)
  3507. mbedtls_ecdsa_restart_init(&operation->restart_ctx);
  3508. mbedtls_mpi_init(&operation->r);
  3509. mbedtls_mpi_init(&operation->s);
  3510. /* Ensure num_ops is zero'ed in case of context re-use. */
  3511. operation->num_ops = 0;
  3512. status = mbedtls_psa_ecp_load_representation(attributes->type,
  3513. attributes->bits,
  3514. key_buffer,
  3515. key_buffer_size,
  3516. &operation->ctx);
  3517. if (status != PSA_SUCCESS) {
  3518. return status;
  3519. }
  3520. coordinate_bytes = PSA_BITS_TO_BYTES(operation->ctx->grp.nbits);
  3521. if (signature_length != 2 * coordinate_bytes) {
  3522. return PSA_ERROR_INVALID_SIGNATURE;
  3523. }
  3524. status = mbedtls_to_psa_error(
  3525. mbedtls_mpi_read_binary(&operation->r,
  3526. signature,
  3527. coordinate_bytes));
  3528. if (status != PSA_SUCCESS) {
  3529. return status;
  3530. }
  3531. status = mbedtls_to_psa_error(
  3532. mbedtls_mpi_read_binary(&operation->s,
  3533. signature +
  3534. coordinate_bytes,
  3535. coordinate_bytes));
  3536. if (status != PSA_SUCCESS) {
  3537. return status;
  3538. }
  3539. status = mbedtls_psa_ecp_load_public_part(operation->ctx);
  3540. if (status != PSA_SUCCESS) {
  3541. return status;
  3542. }
  3543. /* We only need to store the same length of hash as the private key size
  3544. * here, it would be truncated by the internal implementation anyway. */
  3545. required_hash_length = (hash_length < coordinate_bytes ? hash_length :
  3546. coordinate_bytes);
  3547. if (required_hash_length > sizeof(operation->hash)) {
  3548. /* Shouldn't happen, but better safe than sorry. */
  3549. return PSA_ERROR_CORRUPTION_DETECTED;
  3550. }
  3551. memcpy(operation->hash, hash, required_hash_length);
  3552. operation->hash_length = required_hash_length;
  3553. return PSA_SUCCESS;
  3554. #else
  3555. (void) operation;
  3556. (void) key_buffer;
  3557. (void) key_buffer_size;
  3558. (void) alg;
  3559. (void) hash;
  3560. (void) hash_length;
  3561. (void) signature;
  3562. (void) signature_length;
  3563. (void) status;
  3564. (void) coordinate_bytes;
  3565. (void) required_hash_length;
  3566. return PSA_ERROR_NOT_SUPPORTED;
  3567. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3568. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3569. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3570. }
  3571. psa_status_t mbedtls_psa_verify_hash_complete(
  3572. mbedtls_psa_verify_hash_interruptible_operation_t *operation)
  3573. {
  3574. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3575. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3576. defined(MBEDTLS_ECP_RESTARTABLE)
  3577. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3578. /* Ensure max_ops is set to the current value (or default). */
  3579. mbedtls_psa_interruptible_set_max_ops(psa_interruptible_get_max_ops());
  3580. status = mbedtls_to_psa_error(
  3581. mbedtls_ecdsa_verify_restartable(&operation->ctx->grp,
  3582. operation->hash,
  3583. operation->hash_length,
  3584. &operation->ctx->Q,
  3585. &operation->r,
  3586. &operation->s,
  3587. &operation->restart_ctx));
  3588. /* Hide the fact that the restart context only holds a delta of number of
  3589. * ops done during the last operation, not an absolute value. */
  3590. operation->num_ops += operation->restart_ctx.ecp.ops_done;
  3591. return status;
  3592. #else
  3593. (void) operation;
  3594. return PSA_ERROR_NOT_SUPPORTED;
  3595. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3596. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3597. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3598. }
  3599. psa_status_t mbedtls_psa_verify_hash_abort(
  3600. mbedtls_psa_verify_hash_interruptible_operation_t *operation)
  3601. {
  3602. #if (defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  3603. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)) && \
  3604. defined(MBEDTLS_ECP_RESTARTABLE)
  3605. if (operation->ctx) {
  3606. mbedtls_ecdsa_free(operation->ctx);
  3607. mbedtls_free(operation->ctx);
  3608. operation->ctx = NULL;
  3609. }
  3610. mbedtls_ecdsa_restart_free(&operation->restart_ctx);
  3611. operation->num_ops = 0;
  3612. mbedtls_mpi_free(&operation->r);
  3613. mbedtls_mpi_free(&operation->s);
  3614. return PSA_SUCCESS;
  3615. #else
  3616. (void) operation;
  3617. return PSA_ERROR_NOT_SUPPORTED;
  3618. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  3619. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) &&
  3620. * defined( MBEDTLS_ECP_RESTARTABLE ) */
  3621. }
  3622. static psa_status_t psa_generate_random_internal(uint8_t *output,
  3623. size_t output_size)
  3624. {
  3625. GUARD_MODULE_INITIALIZED;
  3626. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  3627. psa_status_t status;
  3628. size_t output_length = 0;
  3629. status = mbedtls_psa_external_get_random(&global_data.rng,
  3630. output, output_size,
  3631. &output_length);
  3632. if (status != PSA_SUCCESS) {
  3633. return status;
  3634. }
  3635. /* Breaking up a request into smaller chunks is currently not supported
  3636. * for the external RNG interface. */
  3637. if (output_length != output_size) {
  3638. return PSA_ERROR_INSUFFICIENT_ENTROPY;
  3639. }
  3640. return PSA_SUCCESS;
  3641. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  3642. while (output_size > 0) {
  3643. int ret = MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED;
  3644. size_t request_size =
  3645. (output_size > MBEDTLS_PSA_RANDOM_MAX_REQUEST ?
  3646. MBEDTLS_PSA_RANDOM_MAX_REQUEST :
  3647. output_size);
  3648. #if defined(MBEDTLS_CTR_DRBG_C)
  3649. ret = mbedtls_ctr_drbg_random(&global_data.rng.drbg, output, request_size);
  3650. #elif defined(MBEDTLS_HMAC_DRBG_C)
  3651. ret = mbedtls_hmac_drbg_random(&global_data.rng.drbg, output, request_size);
  3652. #endif /* !MBEDTLS_CTR_DRBG_C && !MBEDTLS_HMAC_DRBG_C */
  3653. if (ret != 0) {
  3654. return mbedtls_to_psa_error(ret);
  3655. }
  3656. output_size -= request_size;
  3657. output += request_size;
  3658. }
  3659. return PSA_SUCCESS;
  3660. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  3661. }
  3662. /****************************************************************/
  3663. /* Symmetric cryptography */
  3664. /****************************************************************/
  3665. static psa_status_t psa_cipher_setup(psa_cipher_operation_t *operation,
  3666. mbedtls_svc_key_id_t key,
  3667. psa_algorithm_t alg,
  3668. mbedtls_operation_t cipher_operation)
  3669. {
  3670. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3671. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3672. psa_key_slot_t *slot = NULL;
  3673. psa_key_usage_t usage = (cipher_operation == MBEDTLS_ENCRYPT ?
  3674. PSA_KEY_USAGE_ENCRYPT :
  3675. PSA_KEY_USAGE_DECRYPT);
  3676. /* A context must be freshly initialized before it can be set up. */
  3677. if (operation->id != 0) {
  3678. status = PSA_ERROR_BAD_STATE;
  3679. goto exit;
  3680. }
  3681. if (!PSA_ALG_IS_CIPHER(alg)) {
  3682. status = PSA_ERROR_INVALID_ARGUMENT;
  3683. goto exit;
  3684. }
  3685. status = psa_get_and_lock_key_slot_with_policy(key, &slot, usage, alg);
  3686. if (status != PSA_SUCCESS) {
  3687. goto exit;
  3688. }
  3689. /* Initialize the operation struct members, except for id. The id member
  3690. * is used to indicate to psa_cipher_abort that there are resources to free,
  3691. * so we only set it (in the driver wrapper) after resources have been
  3692. * allocated/initialized. */
  3693. operation->iv_set = 0;
  3694. if (alg == PSA_ALG_ECB_NO_PADDING) {
  3695. operation->iv_required = 0;
  3696. } else {
  3697. operation->iv_required = 1;
  3698. }
  3699. operation->default_iv_length = PSA_CIPHER_IV_LENGTH(slot->attr.type, alg);
  3700. /* Try doing the operation through a driver before using software fallback. */
  3701. if (cipher_operation == MBEDTLS_ENCRYPT) {
  3702. status = psa_driver_wrapper_cipher_encrypt_setup(operation,
  3703. &slot->attr,
  3704. slot->key.data,
  3705. slot->key.bytes,
  3706. alg);
  3707. } else {
  3708. status = psa_driver_wrapper_cipher_decrypt_setup(operation,
  3709. &slot->attr,
  3710. slot->key.data,
  3711. slot->key.bytes,
  3712. alg);
  3713. }
  3714. exit:
  3715. if (status != PSA_SUCCESS) {
  3716. psa_cipher_abort(operation);
  3717. }
  3718. unlock_status = psa_unregister_read_under_mutex(slot);
  3719. return (status == PSA_SUCCESS) ? unlock_status : status;
  3720. }
  3721. psa_status_t psa_cipher_encrypt_setup(psa_cipher_operation_t *operation,
  3722. mbedtls_svc_key_id_t key,
  3723. psa_algorithm_t alg)
  3724. {
  3725. return psa_cipher_setup(operation, key, alg, MBEDTLS_ENCRYPT);
  3726. }
  3727. psa_status_t psa_cipher_decrypt_setup(psa_cipher_operation_t *operation,
  3728. mbedtls_svc_key_id_t key,
  3729. psa_algorithm_t alg)
  3730. {
  3731. return psa_cipher_setup(operation, key, alg, MBEDTLS_DECRYPT);
  3732. }
  3733. psa_status_t psa_cipher_generate_iv(psa_cipher_operation_t *operation,
  3734. uint8_t *iv_external,
  3735. size_t iv_size,
  3736. size_t *iv_length)
  3737. {
  3738. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3739. size_t default_iv_length = 0;
  3740. LOCAL_OUTPUT_DECLARE(iv_external, iv);
  3741. if (operation->id == 0) {
  3742. status = PSA_ERROR_BAD_STATE;
  3743. goto exit;
  3744. }
  3745. if (operation->iv_set || !operation->iv_required) {
  3746. status = PSA_ERROR_BAD_STATE;
  3747. goto exit;
  3748. }
  3749. default_iv_length = operation->default_iv_length;
  3750. if (iv_size < default_iv_length) {
  3751. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3752. goto exit;
  3753. }
  3754. if (default_iv_length > PSA_CIPHER_IV_MAX_SIZE) {
  3755. status = PSA_ERROR_GENERIC_ERROR;
  3756. goto exit;
  3757. }
  3758. LOCAL_OUTPUT_ALLOC(iv_external, default_iv_length, iv);
  3759. status = psa_generate_random_internal(iv, default_iv_length);
  3760. if (status != PSA_SUCCESS) {
  3761. goto exit;
  3762. }
  3763. status = psa_driver_wrapper_cipher_set_iv(operation,
  3764. iv, default_iv_length);
  3765. exit:
  3766. if (status == PSA_SUCCESS) {
  3767. *iv_length = default_iv_length;
  3768. operation->iv_set = 1;
  3769. } else {
  3770. *iv_length = 0;
  3771. psa_cipher_abort(operation);
  3772. if (iv != NULL) {
  3773. mbedtls_platform_zeroize(iv, default_iv_length);
  3774. }
  3775. }
  3776. LOCAL_OUTPUT_FREE(iv_external, iv);
  3777. return status;
  3778. }
  3779. psa_status_t psa_cipher_set_iv(psa_cipher_operation_t *operation,
  3780. const uint8_t *iv_external,
  3781. size_t iv_length)
  3782. {
  3783. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3784. LOCAL_INPUT_DECLARE(iv_external, iv);
  3785. if (operation->id == 0) {
  3786. status = PSA_ERROR_BAD_STATE;
  3787. goto exit;
  3788. }
  3789. if (operation->iv_set || !operation->iv_required) {
  3790. status = PSA_ERROR_BAD_STATE;
  3791. goto exit;
  3792. }
  3793. if (iv_length > PSA_CIPHER_IV_MAX_SIZE) {
  3794. status = PSA_ERROR_INVALID_ARGUMENT;
  3795. goto exit;
  3796. }
  3797. LOCAL_INPUT_ALLOC(iv_external, iv_length, iv);
  3798. status = psa_driver_wrapper_cipher_set_iv(operation,
  3799. iv,
  3800. iv_length);
  3801. exit:
  3802. if (status == PSA_SUCCESS) {
  3803. operation->iv_set = 1;
  3804. } else {
  3805. psa_cipher_abort(operation);
  3806. }
  3807. LOCAL_INPUT_FREE(iv_external, iv);
  3808. return status;
  3809. }
  3810. psa_status_t psa_cipher_update(psa_cipher_operation_t *operation,
  3811. const uint8_t *input_external,
  3812. size_t input_length,
  3813. uint8_t *output_external,
  3814. size_t output_size,
  3815. size_t *output_length)
  3816. {
  3817. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3818. LOCAL_INPUT_DECLARE(input_external, input);
  3819. LOCAL_OUTPUT_DECLARE(output_external, output);
  3820. if (operation->id == 0) {
  3821. status = PSA_ERROR_BAD_STATE;
  3822. goto exit;
  3823. }
  3824. if (operation->iv_required && !operation->iv_set) {
  3825. status = PSA_ERROR_BAD_STATE;
  3826. goto exit;
  3827. }
  3828. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  3829. LOCAL_OUTPUT_ALLOC(output_external, output_size, output);
  3830. status = psa_driver_wrapper_cipher_update(operation,
  3831. input,
  3832. input_length,
  3833. output,
  3834. output_size,
  3835. output_length);
  3836. exit:
  3837. if (status != PSA_SUCCESS) {
  3838. psa_cipher_abort(operation);
  3839. }
  3840. LOCAL_INPUT_FREE(input_external, input);
  3841. LOCAL_OUTPUT_FREE(output_external, output);
  3842. return status;
  3843. }
  3844. psa_status_t psa_cipher_finish(psa_cipher_operation_t *operation,
  3845. uint8_t *output_external,
  3846. size_t output_size,
  3847. size_t *output_length)
  3848. {
  3849. psa_status_t status = PSA_ERROR_GENERIC_ERROR;
  3850. LOCAL_OUTPUT_DECLARE(output_external, output);
  3851. if (operation->id == 0) {
  3852. status = PSA_ERROR_BAD_STATE;
  3853. goto exit;
  3854. }
  3855. if (operation->iv_required && !operation->iv_set) {
  3856. status = PSA_ERROR_BAD_STATE;
  3857. goto exit;
  3858. }
  3859. LOCAL_OUTPUT_ALLOC(output_external, output_size, output);
  3860. status = psa_driver_wrapper_cipher_finish(operation,
  3861. output,
  3862. output_size,
  3863. output_length);
  3864. exit:
  3865. if (status == PSA_SUCCESS) {
  3866. status = psa_cipher_abort(operation);
  3867. } else {
  3868. *output_length = 0;
  3869. (void) psa_cipher_abort(operation);
  3870. }
  3871. LOCAL_OUTPUT_FREE(output_external, output);
  3872. return status;
  3873. }
  3874. psa_status_t psa_cipher_abort(psa_cipher_operation_t *operation)
  3875. {
  3876. if (operation->id == 0) {
  3877. /* The object has (apparently) been initialized but it is not (yet)
  3878. * in use. It's ok to call abort on such an object, and there's
  3879. * nothing to do. */
  3880. return PSA_SUCCESS;
  3881. }
  3882. psa_driver_wrapper_cipher_abort(operation);
  3883. operation->id = 0;
  3884. operation->iv_set = 0;
  3885. operation->iv_required = 0;
  3886. return PSA_SUCCESS;
  3887. }
  3888. psa_status_t psa_cipher_encrypt(mbedtls_svc_key_id_t key,
  3889. psa_algorithm_t alg,
  3890. const uint8_t *input_external,
  3891. size_t input_length,
  3892. uint8_t *output_external,
  3893. size_t output_size,
  3894. size_t *output_length)
  3895. {
  3896. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3897. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3898. psa_key_slot_t *slot = NULL;
  3899. uint8_t local_iv[PSA_CIPHER_IV_MAX_SIZE];
  3900. size_t default_iv_length = 0;
  3901. LOCAL_INPUT_DECLARE(input_external, input);
  3902. LOCAL_OUTPUT_DECLARE(output_external, output);
  3903. if (!PSA_ALG_IS_CIPHER(alg)) {
  3904. status = PSA_ERROR_INVALID_ARGUMENT;
  3905. goto exit;
  3906. }
  3907. status = psa_get_and_lock_key_slot_with_policy(key, &slot,
  3908. PSA_KEY_USAGE_ENCRYPT,
  3909. alg);
  3910. if (status != PSA_SUCCESS) {
  3911. goto exit;
  3912. }
  3913. default_iv_length = PSA_CIPHER_IV_LENGTH(slot->attr.type, alg);
  3914. if (default_iv_length > PSA_CIPHER_IV_MAX_SIZE) {
  3915. status = PSA_ERROR_GENERIC_ERROR;
  3916. goto exit;
  3917. }
  3918. if (default_iv_length > 0) {
  3919. if (output_size < default_iv_length) {
  3920. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3921. goto exit;
  3922. }
  3923. status = psa_generate_random_internal(local_iv, default_iv_length);
  3924. if (status != PSA_SUCCESS) {
  3925. goto exit;
  3926. }
  3927. }
  3928. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  3929. LOCAL_OUTPUT_ALLOC(output_external, output_size, output);
  3930. status = psa_driver_wrapper_cipher_encrypt(
  3931. &slot->attr, slot->key.data, slot->key.bytes,
  3932. alg, local_iv, default_iv_length, input, input_length,
  3933. psa_crypto_buffer_offset(output, default_iv_length),
  3934. output_size - default_iv_length, output_length);
  3935. exit:
  3936. unlock_status = psa_unregister_read_under_mutex(slot);
  3937. if (status == PSA_SUCCESS) {
  3938. status = unlock_status;
  3939. }
  3940. if (status == PSA_SUCCESS) {
  3941. if (default_iv_length > 0) {
  3942. memcpy(output, local_iv, default_iv_length);
  3943. }
  3944. *output_length += default_iv_length;
  3945. } else {
  3946. *output_length = 0;
  3947. }
  3948. LOCAL_INPUT_FREE(input_external, input);
  3949. LOCAL_OUTPUT_FREE(output_external, output);
  3950. return status;
  3951. }
  3952. psa_status_t psa_cipher_decrypt(mbedtls_svc_key_id_t key,
  3953. psa_algorithm_t alg,
  3954. const uint8_t *input_external,
  3955. size_t input_length,
  3956. uint8_t *output_external,
  3957. size_t output_size,
  3958. size_t *output_length)
  3959. {
  3960. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3961. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3962. psa_key_slot_t *slot = NULL;
  3963. LOCAL_INPUT_DECLARE(input_external, input);
  3964. LOCAL_OUTPUT_DECLARE(output_external, output);
  3965. if (!PSA_ALG_IS_CIPHER(alg)) {
  3966. status = PSA_ERROR_INVALID_ARGUMENT;
  3967. goto exit;
  3968. }
  3969. status = psa_get_and_lock_key_slot_with_policy(key, &slot,
  3970. PSA_KEY_USAGE_DECRYPT,
  3971. alg);
  3972. if (status != PSA_SUCCESS) {
  3973. goto exit;
  3974. }
  3975. if (input_length < PSA_CIPHER_IV_LENGTH(slot->attr.type, alg)) {
  3976. status = PSA_ERROR_INVALID_ARGUMENT;
  3977. goto exit;
  3978. }
  3979. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  3980. LOCAL_OUTPUT_ALLOC(output_external, output_size, output);
  3981. status = psa_driver_wrapper_cipher_decrypt(
  3982. &slot->attr, slot->key.data, slot->key.bytes,
  3983. alg, input, input_length,
  3984. output, output_size, output_length);
  3985. exit:
  3986. unlock_status = psa_unregister_read_under_mutex(slot);
  3987. if (status == PSA_SUCCESS) {
  3988. status = unlock_status;
  3989. }
  3990. if (status != PSA_SUCCESS) {
  3991. *output_length = 0;
  3992. }
  3993. LOCAL_INPUT_FREE(input_external, input);
  3994. LOCAL_OUTPUT_FREE(output_external, output);
  3995. return status;
  3996. }
  3997. /****************************************************************/
  3998. /* AEAD */
  3999. /****************************************************************/
  4000. /* Helper function to get the base algorithm from its variants. */
  4001. static psa_algorithm_t psa_aead_get_base_algorithm(psa_algorithm_t alg)
  4002. {
  4003. return PSA_ALG_AEAD_WITH_DEFAULT_LENGTH_TAG(alg);
  4004. }
  4005. /* Helper function to perform common nonce length checks. */
  4006. static psa_status_t psa_aead_check_nonce_length(psa_algorithm_t alg,
  4007. size_t nonce_length)
  4008. {
  4009. psa_algorithm_t base_alg = psa_aead_get_base_algorithm(alg);
  4010. switch (base_alg) {
  4011. #if defined(PSA_WANT_ALG_GCM)
  4012. case PSA_ALG_GCM:
  4013. /* Not checking max nonce size here as GCM spec allows almost
  4014. * arbitrarily large nonces. Please note that we do not generally
  4015. * recommend the usage of nonces of greater length than
  4016. * PSA_AEAD_NONCE_MAX_SIZE, as large nonces are hashed to a shorter
  4017. * size, which can then lead to collisions if you encrypt a very
  4018. * large number of messages.*/
  4019. if (nonce_length != 0) {
  4020. return PSA_SUCCESS;
  4021. }
  4022. break;
  4023. #endif /* PSA_WANT_ALG_GCM */
  4024. #if defined(PSA_WANT_ALG_CCM)
  4025. case PSA_ALG_CCM:
  4026. if (nonce_length >= 7 && nonce_length <= 13) {
  4027. return PSA_SUCCESS;
  4028. }
  4029. break;
  4030. #endif /* PSA_WANT_ALG_CCM */
  4031. #if defined(PSA_WANT_ALG_CHACHA20_POLY1305)
  4032. case PSA_ALG_CHACHA20_POLY1305:
  4033. if (nonce_length == 12) {
  4034. return PSA_SUCCESS;
  4035. } else if (nonce_length == 8) {
  4036. return PSA_ERROR_NOT_SUPPORTED;
  4037. }
  4038. break;
  4039. #endif /* PSA_WANT_ALG_CHACHA20_POLY1305 */
  4040. default:
  4041. (void) nonce_length;
  4042. return PSA_ERROR_NOT_SUPPORTED;
  4043. }
  4044. return PSA_ERROR_INVALID_ARGUMENT;
  4045. }
  4046. static psa_status_t psa_aead_check_algorithm(psa_algorithm_t alg)
  4047. {
  4048. if (!PSA_ALG_IS_AEAD(alg) || PSA_ALG_IS_WILDCARD(alg)) {
  4049. return PSA_ERROR_INVALID_ARGUMENT;
  4050. }
  4051. return PSA_SUCCESS;
  4052. }
  4053. psa_status_t psa_aead_encrypt(mbedtls_svc_key_id_t key,
  4054. psa_algorithm_t alg,
  4055. const uint8_t *nonce_external,
  4056. size_t nonce_length,
  4057. const uint8_t *additional_data_external,
  4058. size_t additional_data_length,
  4059. const uint8_t *plaintext_external,
  4060. size_t plaintext_length,
  4061. uint8_t *ciphertext_external,
  4062. size_t ciphertext_size,
  4063. size_t *ciphertext_length)
  4064. {
  4065. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4066. psa_key_slot_t *slot;
  4067. LOCAL_INPUT_DECLARE(nonce_external, nonce);
  4068. LOCAL_INPUT_DECLARE(additional_data_external, additional_data);
  4069. LOCAL_INPUT_DECLARE(plaintext_external, plaintext);
  4070. LOCAL_OUTPUT_DECLARE(ciphertext_external, ciphertext);
  4071. *ciphertext_length = 0;
  4072. status = psa_aead_check_algorithm(alg);
  4073. if (status != PSA_SUCCESS) {
  4074. return status;
  4075. }
  4076. status = psa_get_and_lock_key_slot_with_policy(
  4077. key, &slot, PSA_KEY_USAGE_ENCRYPT, alg);
  4078. if (status != PSA_SUCCESS) {
  4079. return status;
  4080. }
  4081. LOCAL_INPUT_ALLOC(nonce_external, nonce_length, nonce);
  4082. LOCAL_INPUT_ALLOC(additional_data_external, additional_data_length, additional_data);
  4083. LOCAL_INPUT_ALLOC(plaintext_external, plaintext_length, plaintext);
  4084. LOCAL_OUTPUT_ALLOC(ciphertext_external, ciphertext_size, ciphertext);
  4085. status = psa_aead_check_nonce_length(alg, nonce_length);
  4086. if (status != PSA_SUCCESS) {
  4087. goto exit;
  4088. }
  4089. status = psa_driver_wrapper_aead_encrypt(
  4090. &slot->attr, slot->key.data, slot->key.bytes,
  4091. alg,
  4092. nonce, nonce_length,
  4093. additional_data, additional_data_length,
  4094. plaintext, plaintext_length,
  4095. ciphertext, ciphertext_size, ciphertext_length);
  4096. if (status != PSA_SUCCESS && ciphertext_size != 0) {
  4097. memset(ciphertext, 0, ciphertext_size);
  4098. }
  4099. exit:
  4100. LOCAL_INPUT_FREE(nonce_external, nonce);
  4101. LOCAL_INPUT_FREE(additional_data_external, additional_data);
  4102. LOCAL_INPUT_FREE(plaintext_external, plaintext);
  4103. LOCAL_OUTPUT_FREE(ciphertext_external, ciphertext);
  4104. psa_unregister_read_under_mutex(slot);
  4105. return status;
  4106. }
  4107. psa_status_t psa_aead_decrypt(mbedtls_svc_key_id_t key,
  4108. psa_algorithm_t alg,
  4109. const uint8_t *nonce_external,
  4110. size_t nonce_length,
  4111. const uint8_t *additional_data_external,
  4112. size_t additional_data_length,
  4113. const uint8_t *ciphertext_external,
  4114. size_t ciphertext_length,
  4115. uint8_t *plaintext_external,
  4116. size_t plaintext_size,
  4117. size_t *plaintext_length)
  4118. {
  4119. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4120. psa_key_slot_t *slot;
  4121. LOCAL_INPUT_DECLARE(nonce_external, nonce);
  4122. LOCAL_INPUT_DECLARE(additional_data_external, additional_data);
  4123. LOCAL_INPUT_DECLARE(ciphertext_external, ciphertext);
  4124. LOCAL_OUTPUT_DECLARE(plaintext_external, plaintext);
  4125. *plaintext_length = 0;
  4126. status = psa_aead_check_algorithm(alg);
  4127. if (status != PSA_SUCCESS) {
  4128. return status;
  4129. }
  4130. status = psa_get_and_lock_key_slot_with_policy(
  4131. key, &slot, PSA_KEY_USAGE_DECRYPT, alg);
  4132. if (status != PSA_SUCCESS) {
  4133. return status;
  4134. }
  4135. LOCAL_INPUT_ALLOC(nonce_external, nonce_length, nonce);
  4136. LOCAL_INPUT_ALLOC(additional_data_external, additional_data_length,
  4137. additional_data);
  4138. LOCAL_INPUT_ALLOC(ciphertext_external, ciphertext_length, ciphertext);
  4139. LOCAL_OUTPUT_ALLOC(plaintext_external, plaintext_size, plaintext);
  4140. status = psa_aead_check_nonce_length(alg, nonce_length);
  4141. if (status != PSA_SUCCESS) {
  4142. goto exit;
  4143. }
  4144. status = psa_driver_wrapper_aead_decrypt(
  4145. &slot->attr, slot->key.data, slot->key.bytes,
  4146. alg,
  4147. nonce, nonce_length,
  4148. additional_data, additional_data_length,
  4149. ciphertext, ciphertext_length,
  4150. plaintext, plaintext_size, plaintext_length);
  4151. if (status != PSA_SUCCESS && plaintext_size != 0) {
  4152. memset(plaintext, 0, plaintext_size);
  4153. }
  4154. exit:
  4155. LOCAL_INPUT_FREE(nonce_external, nonce);
  4156. LOCAL_INPUT_FREE(additional_data_external, additional_data);
  4157. LOCAL_INPUT_FREE(ciphertext_external, ciphertext);
  4158. LOCAL_OUTPUT_FREE(plaintext_external, plaintext);
  4159. psa_unregister_read_under_mutex(slot);
  4160. return status;
  4161. }
  4162. static psa_status_t psa_validate_tag_length(psa_algorithm_t alg)
  4163. {
  4164. const uint8_t tag_len = PSA_ALG_AEAD_GET_TAG_LENGTH(alg);
  4165. switch (PSA_ALG_AEAD_WITH_SHORTENED_TAG(alg, 0)) {
  4166. #if defined(PSA_WANT_ALG_CCM)
  4167. case PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_CCM, 0):
  4168. /* CCM allows the following tag lengths: 4, 6, 8, 10, 12, 14, 16.*/
  4169. if (tag_len < 4 || tag_len > 16 || tag_len % 2) {
  4170. return PSA_ERROR_INVALID_ARGUMENT;
  4171. }
  4172. break;
  4173. #endif /* PSA_WANT_ALG_CCM */
  4174. #if defined(PSA_WANT_ALG_GCM)
  4175. case PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_GCM, 0):
  4176. /* GCM allows the following tag lengths: 4, 8, 12, 13, 14, 15, 16. */
  4177. if (tag_len != 4 && tag_len != 8 && (tag_len < 12 || tag_len > 16)) {
  4178. return PSA_ERROR_INVALID_ARGUMENT;
  4179. }
  4180. break;
  4181. #endif /* PSA_WANT_ALG_GCM */
  4182. #if defined(PSA_WANT_ALG_CHACHA20_POLY1305)
  4183. case PSA_ALG_AEAD_WITH_SHORTENED_TAG(PSA_ALG_CHACHA20_POLY1305, 0):
  4184. /* We only support the default tag length. */
  4185. if (tag_len != 16) {
  4186. return PSA_ERROR_INVALID_ARGUMENT;
  4187. }
  4188. break;
  4189. #endif /* PSA_WANT_ALG_CHACHA20_POLY1305 */
  4190. default:
  4191. (void) tag_len;
  4192. return PSA_ERROR_NOT_SUPPORTED;
  4193. }
  4194. return PSA_SUCCESS;
  4195. }
  4196. /* Set the key for a multipart authenticated operation. */
  4197. static psa_status_t psa_aead_setup(psa_aead_operation_t *operation,
  4198. int is_encrypt,
  4199. mbedtls_svc_key_id_t key,
  4200. psa_algorithm_t alg)
  4201. {
  4202. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4203. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  4204. psa_key_slot_t *slot = NULL;
  4205. psa_key_usage_t key_usage = 0;
  4206. status = psa_aead_check_algorithm(alg);
  4207. if (status != PSA_SUCCESS) {
  4208. goto exit;
  4209. }
  4210. if (operation->id != 0) {
  4211. status = PSA_ERROR_BAD_STATE;
  4212. goto exit;
  4213. }
  4214. if (operation->nonce_set || operation->lengths_set ||
  4215. operation->ad_started || operation->body_started) {
  4216. status = PSA_ERROR_BAD_STATE;
  4217. goto exit;
  4218. }
  4219. if (is_encrypt) {
  4220. key_usage = PSA_KEY_USAGE_ENCRYPT;
  4221. } else {
  4222. key_usage = PSA_KEY_USAGE_DECRYPT;
  4223. }
  4224. status = psa_get_and_lock_key_slot_with_policy(key, &slot, key_usage,
  4225. alg);
  4226. if (status != PSA_SUCCESS) {
  4227. goto exit;
  4228. }
  4229. if ((status = psa_validate_tag_length(alg)) != PSA_SUCCESS) {
  4230. goto exit;
  4231. }
  4232. if (is_encrypt) {
  4233. status = psa_driver_wrapper_aead_encrypt_setup(operation,
  4234. &slot->attr,
  4235. slot->key.data,
  4236. slot->key.bytes,
  4237. alg);
  4238. } else {
  4239. status = psa_driver_wrapper_aead_decrypt_setup(operation,
  4240. &slot->attr,
  4241. slot->key.data,
  4242. slot->key.bytes,
  4243. alg);
  4244. }
  4245. if (status != PSA_SUCCESS) {
  4246. goto exit;
  4247. }
  4248. operation->key_type = psa_get_key_type(&slot->attr);
  4249. exit:
  4250. unlock_status = psa_unregister_read_under_mutex(slot);
  4251. if (status == PSA_SUCCESS) {
  4252. status = unlock_status;
  4253. operation->alg = psa_aead_get_base_algorithm(alg);
  4254. operation->is_encrypt = is_encrypt;
  4255. } else {
  4256. psa_aead_abort(operation);
  4257. }
  4258. return status;
  4259. }
  4260. /* Set the key for a multipart authenticated encryption operation. */
  4261. psa_status_t psa_aead_encrypt_setup(psa_aead_operation_t *operation,
  4262. mbedtls_svc_key_id_t key,
  4263. psa_algorithm_t alg)
  4264. {
  4265. return psa_aead_setup(operation, 1, key, alg);
  4266. }
  4267. /* Set the key for a multipart authenticated decryption operation. */
  4268. psa_status_t psa_aead_decrypt_setup(psa_aead_operation_t *operation,
  4269. mbedtls_svc_key_id_t key,
  4270. psa_algorithm_t alg)
  4271. {
  4272. return psa_aead_setup(operation, 0, key, alg);
  4273. }
  4274. static psa_status_t psa_aead_set_nonce_internal(psa_aead_operation_t *operation,
  4275. const uint8_t *nonce,
  4276. size_t nonce_length)
  4277. {
  4278. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4279. if (operation->id == 0) {
  4280. status = PSA_ERROR_BAD_STATE;
  4281. goto exit;
  4282. }
  4283. if (operation->nonce_set) {
  4284. status = PSA_ERROR_BAD_STATE;
  4285. goto exit;
  4286. }
  4287. status = psa_aead_check_nonce_length(operation->alg, nonce_length);
  4288. if (status != PSA_SUCCESS) {
  4289. status = PSA_ERROR_INVALID_ARGUMENT;
  4290. goto exit;
  4291. }
  4292. status = psa_driver_wrapper_aead_set_nonce(operation, nonce,
  4293. nonce_length);
  4294. exit:
  4295. if (status == PSA_SUCCESS) {
  4296. operation->nonce_set = 1;
  4297. } else {
  4298. psa_aead_abort(operation);
  4299. }
  4300. return status;
  4301. }
  4302. /* Generate a random nonce / IV for multipart AEAD operation */
  4303. psa_status_t psa_aead_generate_nonce(psa_aead_operation_t *operation,
  4304. uint8_t *nonce_external,
  4305. size_t nonce_size,
  4306. size_t *nonce_length)
  4307. {
  4308. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4309. uint8_t local_nonce[PSA_AEAD_NONCE_MAX_SIZE];
  4310. size_t required_nonce_size = 0;
  4311. LOCAL_OUTPUT_DECLARE(nonce_external, nonce);
  4312. LOCAL_OUTPUT_ALLOC(nonce_external, nonce_size, nonce);
  4313. *nonce_length = 0;
  4314. if (operation->id == 0) {
  4315. status = PSA_ERROR_BAD_STATE;
  4316. goto exit;
  4317. }
  4318. if (operation->nonce_set || !operation->is_encrypt) {
  4319. status = PSA_ERROR_BAD_STATE;
  4320. goto exit;
  4321. }
  4322. /* For CCM, this size may not be correct according to the PSA
  4323. * specification. The PSA Crypto 1.0.1 specification states:
  4324. *
  4325. * CCM encodes the plaintext length pLen in L octets, with L the smallest
  4326. * integer >= 2 where pLen < 2^(8L). The nonce length is then 15 - L bytes.
  4327. *
  4328. * However this restriction that L has to be the smallest integer is not
  4329. * applied in practice, and it is not implementable here since the
  4330. * plaintext length may or may not be known at this time. */
  4331. required_nonce_size = PSA_AEAD_NONCE_LENGTH(operation->key_type,
  4332. operation->alg);
  4333. if (nonce_size < required_nonce_size) {
  4334. status = PSA_ERROR_BUFFER_TOO_SMALL;
  4335. goto exit;
  4336. }
  4337. status = psa_generate_random_internal(local_nonce, required_nonce_size);
  4338. if (status != PSA_SUCCESS) {
  4339. goto exit;
  4340. }
  4341. status = psa_aead_set_nonce_internal(operation, local_nonce,
  4342. required_nonce_size);
  4343. exit:
  4344. if (status == PSA_SUCCESS) {
  4345. memcpy(nonce, local_nonce, required_nonce_size);
  4346. *nonce_length = required_nonce_size;
  4347. } else {
  4348. psa_aead_abort(operation);
  4349. }
  4350. LOCAL_OUTPUT_FREE(nonce_external, nonce);
  4351. return status;
  4352. }
  4353. /* Set the nonce for a multipart authenticated encryption or decryption
  4354. operation.*/
  4355. psa_status_t psa_aead_set_nonce(psa_aead_operation_t *operation,
  4356. const uint8_t *nonce_external,
  4357. size_t nonce_length)
  4358. {
  4359. psa_status_t status;
  4360. LOCAL_INPUT_DECLARE(nonce_external, nonce);
  4361. LOCAL_INPUT_ALLOC(nonce_external, nonce_length, nonce);
  4362. status = psa_aead_set_nonce_internal(operation, nonce, nonce_length);
  4363. /* Exit label is only needed for buffer copying, prevent unused warnings. */
  4364. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  4365. exit:
  4366. #endif
  4367. LOCAL_INPUT_FREE(nonce_external, nonce);
  4368. return status;
  4369. }
  4370. /* Declare the lengths of the message and additional data for multipart AEAD. */
  4371. psa_status_t psa_aead_set_lengths(psa_aead_operation_t *operation,
  4372. size_t ad_length,
  4373. size_t plaintext_length)
  4374. {
  4375. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4376. if (operation->id == 0) {
  4377. status = PSA_ERROR_BAD_STATE;
  4378. goto exit;
  4379. }
  4380. if (operation->lengths_set || operation->ad_started ||
  4381. operation->body_started) {
  4382. status = PSA_ERROR_BAD_STATE;
  4383. goto exit;
  4384. }
  4385. switch (operation->alg) {
  4386. #if defined(PSA_WANT_ALG_GCM)
  4387. case PSA_ALG_GCM:
  4388. /* Lengths can only be too large for GCM if size_t is bigger than 32
  4389. * bits. Without the guard this code will generate warnings on 32bit
  4390. * builds. */
  4391. #if SIZE_MAX > UINT32_MAX
  4392. if (((uint64_t) ad_length) >> 61 != 0 ||
  4393. ((uint64_t) plaintext_length) > 0xFFFFFFFE0ull) {
  4394. status = PSA_ERROR_INVALID_ARGUMENT;
  4395. goto exit;
  4396. }
  4397. #endif
  4398. break;
  4399. #endif /* PSA_WANT_ALG_GCM */
  4400. #if defined(PSA_WANT_ALG_CCM)
  4401. case PSA_ALG_CCM:
  4402. if (ad_length > 0xFF00) {
  4403. status = PSA_ERROR_INVALID_ARGUMENT;
  4404. goto exit;
  4405. }
  4406. break;
  4407. #endif /* PSA_WANT_ALG_CCM */
  4408. #if defined(PSA_WANT_ALG_CHACHA20_POLY1305)
  4409. case PSA_ALG_CHACHA20_POLY1305:
  4410. /* No length restrictions for ChaChaPoly. */
  4411. break;
  4412. #endif /* PSA_WANT_ALG_CHACHA20_POLY1305 */
  4413. default:
  4414. break;
  4415. }
  4416. status = psa_driver_wrapper_aead_set_lengths(operation, ad_length,
  4417. plaintext_length);
  4418. exit:
  4419. if (status == PSA_SUCCESS) {
  4420. operation->ad_remaining = ad_length;
  4421. operation->body_remaining = plaintext_length;
  4422. operation->lengths_set = 1;
  4423. } else {
  4424. psa_aead_abort(operation);
  4425. }
  4426. return status;
  4427. }
  4428. /* Pass additional data to an active multipart AEAD operation. */
  4429. psa_status_t psa_aead_update_ad(psa_aead_operation_t *operation,
  4430. const uint8_t *input_external,
  4431. size_t input_length)
  4432. {
  4433. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4434. LOCAL_INPUT_DECLARE(input_external, input);
  4435. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  4436. if (operation->id == 0) {
  4437. status = PSA_ERROR_BAD_STATE;
  4438. goto exit;
  4439. }
  4440. if (!operation->nonce_set || operation->body_started) {
  4441. status = PSA_ERROR_BAD_STATE;
  4442. goto exit;
  4443. }
  4444. /* No input to add (zero length), nothing to do. */
  4445. if (input_length == 0) {
  4446. status = PSA_SUCCESS;
  4447. goto exit;
  4448. }
  4449. if (operation->lengths_set) {
  4450. if (operation->ad_remaining < input_length) {
  4451. status = PSA_ERROR_INVALID_ARGUMENT;
  4452. goto exit;
  4453. }
  4454. operation->ad_remaining -= input_length;
  4455. }
  4456. #if defined(PSA_WANT_ALG_CCM)
  4457. else if (operation->alg == PSA_ALG_CCM) {
  4458. status = PSA_ERROR_BAD_STATE;
  4459. goto exit;
  4460. }
  4461. #endif /* PSA_WANT_ALG_CCM */
  4462. status = psa_driver_wrapper_aead_update_ad(operation, input,
  4463. input_length);
  4464. exit:
  4465. if (status == PSA_SUCCESS) {
  4466. operation->ad_started = 1;
  4467. } else {
  4468. psa_aead_abort(operation);
  4469. }
  4470. LOCAL_INPUT_FREE(input_external, input);
  4471. return status;
  4472. }
  4473. /* Encrypt or decrypt a message fragment in an active multipart AEAD
  4474. operation.*/
  4475. psa_status_t psa_aead_update(psa_aead_operation_t *operation,
  4476. const uint8_t *input_external,
  4477. size_t input_length,
  4478. uint8_t *output_external,
  4479. size_t output_size,
  4480. size_t *output_length)
  4481. {
  4482. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4483. LOCAL_INPUT_DECLARE(input_external, input);
  4484. LOCAL_OUTPUT_DECLARE(output_external, output);
  4485. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  4486. LOCAL_OUTPUT_ALLOC(output_external, output_size, output);
  4487. *output_length = 0;
  4488. if (operation->id == 0) {
  4489. status = PSA_ERROR_BAD_STATE;
  4490. goto exit;
  4491. }
  4492. if (!operation->nonce_set) {
  4493. status = PSA_ERROR_BAD_STATE;
  4494. goto exit;
  4495. }
  4496. if (operation->lengths_set) {
  4497. /* Additional data length was supplied, but not all the additional
  4498. data was supplied.*/
  4499. if (operation->ad_remaining != 0) {
  4500. status = PSA_ERROR_INVALID_ARGUMENT;
  4501. goto exit;
  4502. }
  4503. /* Too much data provided. */
  4504. if (operation->body_remaining < input_length) {
  4505. status = PSA_ERROR_INVALID_ARGUMENT;
  4506. goto exit;
  4507. }
  4508. operation->body_remaining -= input_length;
  4509. }
  4510. #if defined(PSA_WANT_ALG_CCM)
  4511. else if (operation->alg == PSA_ALG_CCM) {
  4512. status = PSA_ERROR_BAD_STATE;
  4513. goto exit;
  4514. }
  4515. #endif /* PSA_WANT_ALG_CCM */
  4516. status = psa_driver_wrapper_aead_update(operation, input, input_length,
  4517. output, output_size,
  4518. output_length);
  4519. exit:
  4520. if (status == PSA_SUCCESS) {
  4521. operation->body_started = 1;
  4522. } else {
  4523. psa_aead_abort(operation);
  4524. }
  4525. LOCAL_INPUT_FREE(input_external, input);
  4526. LOCAL_OUTPUT_FREE(output_external, output);
  4527. return status;
  4528. }
  4529. static psa_status_t psa_aead_final_checks(const psa_aead_operation_t *operation)
  4530. {
  4531. if (operation->id == 0 || !operation->nonce_set) {
  4532. return PSA_ERROR_BAD_STATE;
  4533. }
  4534. if (operation->lengths_set && (operation->ad_remaining != 0 ||
  4535. operation->body_remaining != 0)) {
  4536. return PSA_ERROR_INVALID_ARGUMENT;
  4537. }
  4538. return PSA_SUCCESS;
  4539. }
  4540. /* Finish encrypting a message in a multipart AEAD operation. */
  4541. psa_status_t psa_aead_finish(psa_aead_operation_t *operation,
  4542. uint8_t *ciphertext_external,
  4543. size_t ciphertext_size,
  4544. size_t *ciphertext_length,
  4545. uint8_t *tag_external,
  4546. size_t tag_size,
  4547. size_t *tag_length)
  4548. {
  4549. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4550. LOCAL_OUTPUT_DECLARE(ciphertext_external, ciphertext);
  4551. LOCAL_OUTPUT_DECLARE(tag_external, tag);
  4552. LOCAL_OUTPUT_ALLOC(ciphertext_external, ciphertext_size, ciphertext);
  4553. LOCAL_OUTPUT_ALLOC(tag_external, tag_size, tag);
  4554. *ciphertext_length = 0;
  4555. *tag_length = tag_size;
  4556. status = psa_aead_final_checks(operation);
  4557. if (status != PSA_SUCCESS) {
  4558. goto exit;
  4559. }
  4560. if (!operation->is_encrypt) {
  4561. status = PSA_ERROR_BAD_STATE;
  4562. goto exit;
  4563. }
  4564. status = psa_driver_wrapper_aead_finish(operation, ciphertext,
  4565. ciphertext_size,
  4566. ciphertext_length,
  4567. tag, tag_size, tag_length);
  4568. exit:
  4569. /* In case the operation fails and the user fails to check for failure or
  4570. * the zero tag size, make sure the tag is set to something implausible.
  4571. * Even if the operation succeeds, make sure we clear the rest of the
  4572. * buffer to prevent potential leakage of anything previously placed in
  4573. * the same buffer.*/
  4574. psa_wipe_tag_output_buffer(tag, status, tag_size, *tag_length);
  4575. psa_aead_abort(operation);
  4576. LOCAL_OUTPUT_FREE(ciphertext_external, ciphertext);
  4577. LOCAL_OUTPUT_FREE(tag_external, tag);
  4578. return status;
  4579. }
  4580. /* Finish authenticating and decrypting a message in a multipart AEAD
  4581. operation.*/
  4582. psa_status_t psa_aead_verify(psa_aead_operation_t *operation,
  4583. uint8_t *plaintext_external,
  4584. size_t plaintext_size,
  4585. size_t *plaintext_length,
  4586. const uint8_t *tag_external,
  4587. size_t tag_length)
  4588. {
  4589. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4590. LOCAL_OUTPUT_DECLARE(plaintext_external, plaintext);
  4591. LOCAL_INPUT_DECLARE(tag_external, tag);
  4592. LOCAL_OUTPUT_ALLOC(plaintext_external, plaintext_size, plaintext);
  4593. LOCAL_INPUT_ALLOC(tag_external, tag_length, tag);
  4594. *plaintext_length = 0;
  4595. status = psa_aead_final_checks(operation);
  4596. if (status != PSA_SUCCESS) {
  4597. goto exit;
  4598. }
  4599. if (operation->is_encrypt) {
  4600. status = PSA_ERROR_BAD_STATE;
  4601. goto exit;
  4602. }
  4603. status = psa_driver_wrapper_aead_verify(operation, plaintext,
  4604. plaintext_size,
  4605. plaintext_length,
  4606. tag, tag_length);
  4607. exit:
  4608. psa_aead_abort(operation);
  4609. LOCAL_OUTPUT_FREE(plaintext_external, plaintext);
  4610. LOCAL_INPUT_FREE(tag_external, tag);
  4611. return status;
  4612. }
  4613. /* Abort an AEAD operation. */
  4614. psa_status_t psa_aead_abort(psa_aead_operation_t *operation)
  4615. {
  4616. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4617. if (operation->id == 0) {
  4618. /* The object has (apparently) been initialized but it is not (yet)
  4619. * in use. It's ok to call abort on such an object, and there's
  4620. * nothing to do. */
  4621. return PSA_SUCCESS;
  4622. }
  4623. status = psa_driver_wrapper_aead_abort(operation);
  4624. memset(operation, 0, sizeof(*operation));
  4625. return status;
  4626. }
  4627. /****************************************************************/
  4628. /* Generators */
  4629. /****************************************************************/
  4630. #if defined(BUILTIN_ALG_ANY_HKDF) || \
  4631. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4632. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS) || \
  4633. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS) || \
  4634. defined(PSA_HAVE_SOFT_PBKDF2)
  4635. #define AT_LEAST_ONE_BUILTIN_KDF
  4636. #endif /* At least one builtin KDF */
  4637. #if defined(BUILTIN_ALG_ANY_HKDF) || \
  4638. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4639. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4640. static psa_status_t psa_key_derivation_start_hmac(
  4641. psa_mac_operation_t *operation,
  4642. psa_algorithm_t hash_alg,
  4643. const uint8_t *hmac_key,
  4644. size_t hmac_key_length)
  4645. {
  4646. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4647. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  4648. psa_set_key_type(&attributes, PSA_KEY_TYPE_HMAC);
  4649. psa_set_key_bits(&attributes, PSA_BYTES_TO_BITS(hmac_key_length));
  4650. psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH);
  4651. operation->is_sign = 1;
  4652. operation->mac_size = PSA_HASH_LENGTH(hash_alg);
  4653. status = psa_driver_wrapper_mac_sign_setup(operation,
  4654. &attributes,
  4655. hmac_key, hmac_key_length,
  4656. PSA_ALG_HMAC(hash_alg));
  4657. psa_reset_key_attributes(&attributes);
  4658. return status;
  4659. }
  4660. #endif /* KDF algorithms reliant on HMAC */
  4661. #define HKDF_STATE_INIT 0 /* no input yet */
  4662. #define HKDF_STATE_STARTED 1 /* got salt */
  4663. #define HKDF_STATE_KEYED 2 /* got key */
  4664. #define HKDF_STATE_OUTPUT 3 /* output started */
  4665. static psa_algorithm_t psa_key_derivation_get_kdf_alg(
  4666. const psa_key_derivation_operation_t *operation)
  4667. {
  4668. if (PSA_ALG_IS_KEY_AGREEMENT(operation->alg)) {
  4669. return PSA_ALG_KEY_AGREEMENT_GET_KDF(operation->alg);
  4670. } else {
  4671. return operation->alg;
  4672. }
  4673. }
  4674. psa_status_t psa_key_derivation_abort(psa_key_derivation_operation_t *operation)
  4675. {
  4676. psa_status_t status = PSA_SUCCESS;
  4677. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg(operation);
  4678. if (kdf_alg == 0) {
  4679. /* The object has (apparently) been initialized but it is not
  4680. * in use. It's ok to call abort on such an object, and there's
  4681. * nothing to do. */
  4682. } else
  4683. #if defined(BUILTIN_ALG_ANY_HKDF)
  4684. if (PSA_ALG_IS_ANY_HKDF(kdf_alg)) {
  4685. mbedtls_free(operation->ctx.hkdf.info);
  4686. status = psa_mac_abort(&operation->ctx.hkdf.hmac);
  4687. } else
  4688. #endif /* BUILTIN_ALG_ANY_HKDF */
  4689. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4690. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4691. if (PSA_ALG_IS_TLS12_PRF(kdf_alg) ||
  4692. /* TLS-1.2 PSK-to-MS KDF uses the same core as TLS-1.2 PRF */
  4693. PSA_ALG_IS_TLS12_PSK_TO_MS(kdf_alg)) {
  4694. if (operation->ctx.tls12_prf.secret != NULL) {
  4695. mbedtls_zeroize_and_free(operation->ctx.tls12_prf.secret,
  4696. operation->ctx.tls12_prf.secret_length);
  4697. }
  4698. if (operation->ctx.tls12_prf.seed != NULL) {
  4699. mbedtls_zeroize_and_free(operation->ctx.tls12_prf.seed,
  4700. operation->ctx.tls12_prf.seed_length);
  4701. }
  4702. if (operation->ctx.tls12_prf.label != NULL) {
  4703. mbedtls_zeroize_and_free(operation->ctx.tls12_prf.label,
  4704. operation->ctx.tls12_prf.label_length);
  4705. }
  4706. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4707. if (operation->ctx.tls12_prf.other_secret != NULL) {
  4708. mbedtls_zeroize_and_free(operation->ctx.tls12_prf.other_secret,
  4709. operation->ctx.tls12_prf.other_secret_length);
  4710. }
  4711. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4712. status = PSA_SUCCESS;
  4713. /* We leave the fields Ai and output_block to be erased safely by the
  4714. * mbedtls_platform_zeroize() in the end of this function. */
  4715. } else
  4716. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) ||
  4717. * defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS) */
  4718. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  4719. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  4720. mbedtls_platform_zeroize(operation->ctx.tls12_ecjpake_to_pms.data,
  4721. sizeof(operation->ctx.tls12_ecjpake_to_pms.data));
  4722. } else
  4723. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS) */
  4724. #if defined(PSA_HAVE_SOFT_PBKDF2)
  4725. if (PSA_ALG_IS_PBKDF2(kdf_alg)) {
  4726. if (operation->ctx.pbkdf2.salt != NULL) {
  4727. mbedtls_zeroize_and_free(operation->ctx.pbkdf2.salt,
  4728. operation->ctx.pbkdf2.salt_length);
  4729. }
  4730. status = PSA_SUCCESS;
  4731. } else
  4732. #endif /* defined(PSA_HAVE_SOFT_PBKDF2) */
  4733. {
  4734. status = PSA_ERROR_BAD_STATE;
  4735. }
  4736. mbedtls_platform_zeroize(operation, sizeof(*operation));
  4737. return status;
  4738. }
  4739. psa_status_t psa_key_derivation_get_capacity(const psa_key_derivation_operation_t *operation,
  4740. size_t *capacity)
  4741. {
  4742. if (operation->alg == 0) {
  4743. /* This is a blank key derivation operation. */
  4744. return PSA_ERROR_BAD_STATE;
  4745. }
  4746. *capacity = operation->capacity;
  4747. return PSA_SUCCESS;
  4748. }
  4749. psa_status_t psa_key_derivation_set_capacity(psa_key_derivation_operation_t *operation,
  4750. size_t capacity)
  4751. {
  4752. if (operation->alg == 0) {
  4753. return PSA_ERROR_BAD_STATE;
  4754. }
  4755. if (capacity > operation->capacity) {
  4756. return PSA_ERROR_INVALID_ARGUMENT;
  4757. }
  4758. operation->capacity = capacity;
  4759. return PSA_SUCCESS;
  4760. }
  4761. #if defined(BUILTIN_ALG_ANY_HKDF)
  4762. /* Read some bytes from an HKDF-based operation. */
  4763. static psa_status_t psa_key_derivation_hkdf_read(psa_hkdf_key_derivation_t *hkdf,
  4764. psa_algorithm_t kdf_alg,
  4765. uint8_t *output,
  4766. size_t output_length)
  4767. {
  4768. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH(kdf_alg);
  4769. uint8_t hash_length = PSA_HASH_LENGTH(hash_alg);
  4770. size_t hmac_output_length;
  4771. psa_status_t status;
  4772. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  4773. const uint8_t last_block = PSA_ALG_IS_HKDF_EXTRACT(kdf_alg) ? 0 : 0xff;
  4774. #else
  4775. const uint8_t last_block = 0xff;
  4776. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  4777. if (hkdf->state < HKDF_STATE_KEYED ||
  4778. (!hkdf->info_set
  4779. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  4780. && !PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)
  4781. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  4782. )) {
  4783. return PSA_ERROR_BAD_STATE;
  4784. }
  4785. hkdf->state = HKDF_STATE_OUTPUT;
  4786. while (output_length != 0) {
  4787. /* Copy what remains of the current block */
  4788. uint8_t n = hash_length - hkdf->offset_in_block;
  4789. if (n > output_length) {
  4790. n = (uint8_t) output_length;
  4791. }
  4792. memcpy(output, hkdf->output_block + hkdf->offset_in_block, n);
  4793. output += n;
  4794. output_length -= n;
  4795. hkdf->offset_in_block += n;
  4796. if (output_length == 0) {
  4797. break;
  4798. }
  4799. /* We can't be wanting more output after the last block, otherwise
  4800. * the capacity check in psa_key_derivation_output_bytes() would have
  4801. * prevented this call. It could happen only if the operation
  4802. * object was corrupted or if this function is called directly
  4803. * inside the library. */
  4804. if (hkdf->block_number == last_block) {
  4805. return PSA_ERROR_BAD_STATE;
  4806. }
  4807. /* We need a new block */
  4808. ++hkdf->block_number;
  4809. hkdf->offset_in_block = 0;
  4810. status = psa_key_derivation_start_hmac(&hkdf->hmac,
  4811. hash_alg,
  4812. hkdf->prk,
  4813. hash_length);
  4814. if (status != PSA_SUCCESS) {
  4815. return status;
  4816. }
  4817. if (hkdf->block_number != 1) {
  4818. status = psa_mac_update(&hkdf->hmac,
  4819. hkdf->output_block,
  4820. hash_length);
  4821. if (status != PSA_SUCCESS) {
  4822. return status;
  4823. }
  4824. }
  4825. status = psa_mac_update(&hkdf->hmac,
  4826. hkdf->info,
  4827. hkdf->info_length);
  4828. if (status != PSA_SUCCESS) {
  4829. return status;
  4830. }
  4831. status = psa_mac_update(&hkdf->hmac,
  4832. &hkdf->block_number, 1);
  4833. if (status != PSA_SUCCESS) {
  4834. return status;
  4835. }
  4836. status = psa_mac_sign_finish(&hkdf->hmac,
  4837. hkdf->output_block,
  4838. sizeof(hkdf->output_block),
  4839. &hmac_output_length);
  4840. if (status != PSA_SUCCESS) {
  4841. return status;
  4842. }
  4843. }
  4844. return PSA_SUCCESS;
  4845. }
  4846. #endif /* BUILTIN_ALG_ANY_HKDF */
  4847. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4848. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4849. static psa_status_t psa_key_derivation_tls12_prf_generate_next_block(
  4850. psa_tls12_prf_key_derivation_t *tls12_prf,
  4851. psa_algorithm_t alg)
  4852. {
  4853. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH(alg);
  4854. uint8_t hash_length = PSA_HASH_LENGTH(hash_alg);
  4855. psa_mac_operation_t hmac = PSA_MAC_OPERATION_INIT;
  4856. size_t hmac_output_length;
  4857. psa_status_t status, cleanup_status;
  4858. /* We can't be wanting more output after block 0xff, otherwise
  4859. * the capacity check in psa_key_derivation_output_bytes() would have
  4860. * prevented this call. It could happen only if the operation
  4861. * object was corrupted or if this function is called directly
  4862. * inside the library. */
  4863. if (tls12_prf->block_number == 0xff) {
  4864. return PSA_ERROR_CORRUPTION_DETECTED;
  4865. }
  4866. /* We need a new block */
  4867. ++tls12_prf->block_number;
  4868. tls12_prf->left_in_block = hash_length;
  4869. /* Recall the definition of the TLS-1.2-PRF from RFC 5246:
  4870. *
  4871. * PRF(secret, label, seed) = P_<hash>(secret, label + seed)
  4872. *
  4873. * P_hash(secret, seed) = HMAC_hash(secret, A(1) + seed) +
  4874. * HMAC_hash(secret, A(2) + seed) +
  4875. * HMAC_hash(secret, A(3) + seed) + ...
  4876. *
  4877. * A(0) = seed
  4878. * A(i) = HMAC_hash(secret, A(i-1))
  4879. *
  4880. * The `psa_tls12_prf_key_derivation` structure saves the block
  4881. * `HMAC_hash(secret, A(i) + seed)` from which the output
  4882. * is currently extracted as `output_block` and where i is
  4883. * `block_number`.
  4884. */
  4885. status = psa_key_derivation_start_hmac(&hmac,
  4886. hash_alg,
  4887. tls12_prf->secret,
  4888. tls12_prf->secret_length);
  4889. if (status != PSA_SUCCESS) {
  4890. goto cleanup;
  4891. }
  4892. /* Calculate A(i) where i = tls12_prf->block_number. */
  4893. if (tls12_prf->block_number == 1) {
  4894. /* A(1) = HMAC_hash(secret, A(0)), where A(0) = seed. (The RFC overloads
  4895. * the variable seed and in this instance means it in the context of the
  4896. * P_hash function, where seed = label + seed.) */
  4897. status = psa_mac_update(&hmac,
  4898. tls12_prf->label,
  4899. tls12_prf->label_length);
  4900. if (status != PSA_SUCCESS) {
  4901. goto cleanup;
  4902. }
  4903. status = psa_mac_update(&hmac,
  4904. tls12_prf->seed,
  4905. tls12_prf->seed_length);
  4906. if (status != PSA_SUCCESS) {
  4907. goto cleanup;
  4908. }
  4909. } else {
  4910. /* A(i) = HMAC_hash(secret, A(i-1)) */
  4911. status = psa_mac_update(&hmac, tls12_prf->Ai, hash_length);
  4912. if (status != PSA_SUCCESS) {
  4913. goto cleanup;
  4914. }
  4915. }
  4916. status = psa_mac_sign_finish(&hmac,
  4917. tls12_prf->Ai, hash_length,
  4918. &hmac_output_length);
  4919. if (hmac_output_length != hash_length) {
  4920. status = PSA_ERROR_CORRUPTION_DETECTED;
  4921. }
  4922. if (status != PSA_SUCCESS) {
  4923. goto cleanup;
  4924. }
  4925. /* Calculate HMAC_hash(secret, A(i) + label + seed). */
  4926. status = psa_key_derivation_start_hmac(&hmac,
  4927. hash_alg,
  4928. tls12_prf->secret,
  4929. tls12_prf->secret_length);
  4930. if (status != PSA_SUCCESS) {
  4931. goto cleanup;
  4932. }
  4933. status = psa_mac_update(&hmac, tls12_prf->Ai, hash_length);
  4934. if (status != PSA_SUCCESS) {
  4935. goto cleanup;
  4936. }
  4937. status = psa_mac_update(&hmac, tls12_prf->label, tls12_prf->label_length);
  4938. if (status != PSA_SUCCESS) {
  4939. goto cleanup;
  4940. }
  4941. status = psa_mac_update(&hmac, tls12_prf->seed, tls12_prf->seed_length);
  4942. if (status != PSA_SUCCESS) {
  4943. goto cleanup;
  4944. }
  4945. status = psa_mac_sign_finish(&hmac,
  4946. tls12_prf->output_block, hash_length,
  4947. &hmac_output_length);
  4948. if (status != PSA_SUCCESS) {
  4949. goto cleanup;
  4950. }
  4951. cleanup:
  4952. cleanup_status = psa_mac_abort(&hmac);
  4953. if (status == PSA_SUCCESS && cleanup_status != PSA_SUCCESS) {
  4954. status = cleanup_status;
  4955. }
  4956. return status;
  4957. }
  4958. static psa_status_t psa_key_derivation_tls12_prf_read(
  4959. psa_tls12_prf_key_derivation_t *tls12_prf,
  4960. psa_algorithm_t alg,
  4961. uint8_t *output,
  4962. size_t output_length)
  4963. {
  4964. psa_algorithm_t hash_alg = PSA_ALG_TLS12_PRF_GET_HASH(alg);
  4965. uint8_t hash_length = PSA_HASH_LENGTH(hash_alg);
  4966. psa_status_t status;
  4967. uint8_t offset, length;
  4968. switch (tls12_prf->state) {
  4969. case PSA_TLS12_PRF_STATE_LABEL_SET:
  4970. tls12_prf->state = PSA_TLS12_PRF_STATE_OUTPUT;
  4971. break;
  4972. case PSA_TLS12_PRF_STATE_OUTPUT:
  4973. break;
  4974. default:
  4975. return PSA_ERROR_BAD_STATE;
  4976. }
  4977. while (output_length != 0) {
  4978. /* Check if we have fully processed the current block. */
  4979. if (tls12_prf->left_in_block == 0) {
  4980. status = psa_key_derivation_tls12_prf_generate_next_block(tls12_prf,
  4981. alg);
  4982. if (status != PSA_SUCCESS) {
  4983. return status;
  4984. }
  4985. continue;
  4986. }
  4987. if (tls12_prf->left_in_block > output_length) {
  4988. length = (uint8_t) output_length;
  4989. } else {
  4990. length = tls12_prf->left_in_block;
  4991. }
  4992. offset = hash_length - tls12_prf->left_in_block;
  4993. memcpy(output, tls12_prf->output_block + offset, length);
  4994. output += length;
  4995. output_length -= length;
  4996. tls12_prf->left_in_block -= length;
  4997. }
  4998. return PSA_SUCCESS;
  4999. }
  5000. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF ||
  5001. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  5002. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  5003. static psa_status_t psa_key_derivation_tls12_ecjpake_to_pms_read(
  5004. psa_tls12_ecjpake_to_pms_t *ecjpake,
  5005. uint8_t *output,
  5006. size_t output_length)
  5007. {
  5008. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  5009. size_t output_size = 0;
  5010. if (output_length != 32) {
  5011. return PSA_ERROR_INVALID_ARGUMENT;
  5012. }
  5013. status = psa_hash_compute(PSA_ALG_SHA_256, ecjpake->data,
  5014. PSA_TLS12_ECJPAKE_TO_PMS_DATA_SIZE, output, output_length,
  5015. &output_size);
  5016. if (status != PSA_SUCCESS) {
  5017. return status;
  5018. }
  5019. if (output_size != output_length) {
  5020. return PSA_ERROR_GENERIC_ERROR;
  5021. }
  5022. return PSA_SUCCESS;
  5023. }
  5024. #endif
  5025. #if defined(PSA_HAVE_SOFT_PBKDF2)
  5026. static psa_status_t psa_key_derivation_pbkdf2_generate_block(
  5027. psa_pbkdf2_key_derivation_t *pbkdf2,
  5028. psa_algorithm_t prf_alg,
  5029. uint8_t prf_output_length,
  5030. psa_key_attributes_t *attributes)
  5031. {
  5032. psa_status_t status;
  5033. psa_mac_operation_t mac_operation = PSA_MAC_OPERATION_INIT;
  5034. size_t mac_output_length;
  5035. uint8_t U_i[PSA_MAC_MAX_SIZE];
  5036. uint8_t *U_accumulator = pbkdf2->output_block;
  5037. uint64_t i;
  5038. uint8_t block_counter[4];
  5039. mac_operation.is_sign = 1;
  5040. mac_operation.mac_size = prf_output_length;
  5041. MBEDTLS_PUT_UINT32_BE(pbkdf2->block_number, block_counter, 0);
  5042. status = psa_driver_wrapper_mac_sign_setup(&mac_operation,
  5043. attributes,
  5044. pbkdf2->password,
  5045. pbkdf2->password_length,
  5046. prf_alg);
  5047. if (status != PSA_SUCCESS) {
  5048. goto cleanup;
  5049. }
  5050. status = psa_mac_update(&mac_operation, pbkdf2->salt, pbkdf2->salt_length);
  5051. if (status != PSA_SUCCESS) {
  5052. goto cleanup;
  5053. }
  5054. status = psa_mac_update(&mac_operation, block_counter, sizeof(block_counter));
  5055. if (status != PSA_SUCCESS) {
  5056. goto cleanup;
  5057. }
  5058. status = psa_mac_sign_finish(&mac_operation, U_i, sizeof(U_i),
  5059. &mac_output_length);
  5060. if (status != PSA_SUCCESS) {
  5061. goto cleanup;
  5062. }
  5063. if (mac_output_length != prf_output_length) {
  5064. status = PSA_ERROR_CORRUPTION_DETECTED;
  5065. goto cleanup;
  5066. }
  5067. memcpy(U_accumulator, U_i, prf_output_length);
  5068. for (i = 1; i < pbkdf2->input_cost; i++) {
  5069. /* We are passing prf_output_length as mac_size because the driver
  5070. * function directly sets mac_output_length as mac_size upon success.
  5071. * See https://github.com/Mbed-TLS/mbedtls/issues/7801 */
  5072. status = psa_driver_wrapper_mac_compute(attributes,
  5073. pbkdf2->password,
  5074. pbkdf2->password_length,
  5075. prf_alg, U_i, prf_output_length,
  5076. U_i, prf_output_length,
  5077. &mac_output_length);
  5078. if (status != PSA_SUCCESS) {
  5079. goto cleanup;
  5080. }
  5081. mbedtls_xor(U_accumulator, U_accumulator, U_i, prf_output_length);
  5082. }
  5083. cleanup:
  5084. /* Zeroise buffers to clear sensitive data from memory. */
  5085. mbedtls_platform_zeroize(U_i, PSA_MAC_MAX_SIZE);
  5086. return status;
  5087. }
  5088. static psa_status_t psa_key_derivation_pbkdf2_read(
  5089. psa_pbkdf2_key_derivation_t *pbkdf2,
  5090. psa_algorithm_t kdf_alg,
  5091. uint8_t *output,
  5092. size_t output_length)
  5093. {
  5094. psa_status_t status;
  5095. psa_algorithm_t prf_alg;
  5096. uint8_t prf_output_length;
  5097. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  5098. psa_set_key_bits(&attributes, PSA_BYTES_TO_BITS(pbkdf2->password_length));
  5099. psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE);
  5100. if (PSA_ALG_IS_PBKDF2_HMAC(kdf_alg)) {
  5101. prf_alg = PSA_ALG_HMAC(PSA_ALG_PBKDF2_HMAC_GET_HASH(kdf_alg));
  5102. prf_output_length = PSA_HASH_LENGTH(prf_alg);
  5103. psa_set_key_type(&attributes, PSA_KEY_TYPE_HMAC);
  5104. } else if (kdf_alg == PSA_ALG_PBKDF2_AES_CMAC_PRF_128) {
  5105. prf_alg = PSA_ALG_CMAC;
  5106. prf_output_length = PSA_MAC_LENGTH(PSA_KEY_TYPE_AES, 128U, PSA_ALG_CMAC);
  5107. psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
  5108. } else {
  5109. return PSA_ERROR_INVALID_ARGUMENT;
  5110. }
  5111. switch (pbkdf2->state) {
  5112. case PSA_PBKDF2_STATE_PASSWORD_SET:
  5113. /* Initially we need a new block so bytes_used is equal to block size*/
  5114. pbkdf2->bytes_used = prf_output_length;
  5115. pbkdf2->state = PSA_PBKDF2_STATE_OUTPUT;
  5116. break;
  5117. case PSA_PBKDF2_STATE_OUTPUT:
  5118. break;
  5119. default:
  5120. return PSA_ERROR_BAD_STATE;
  5121. }
  5122. while (output_length != 0) {
  5123. uint8_t n = prf_output_length - pbkdf2->bytes_used;
  5124. if (n > output_length) {
  5125. n = (uint8_t) output_length;
  5126. }
  5127. memcpy(output, pbkdf2->output_block + pbkdf2->bytes_used, n);
  5128. output += n;
  5129. output_length -= n;
  5130. pbkdf2->bytes_used += n;
  5131. if (output_length == 0) {
  5132. break;
  5133. }
  5134. /* We need a new block */
  5135. pbkdf2->bytes_used = 0;
  5136. pbkdf2->block_number++;
  5137. status = psa_key_derivation_pbkdf2_generate_block(pbkdf2, prf_alg,
  5138. prf_output_length,
  5139. &attributes);
  5140. if (status != PSA_SUCCESS) {
  5141. return status;
  5142. }
  5143. }
  5144. return PSA_SUCCESS;
  5145. }
  5146. #endif /* PSA_HAVE_SOFT_PBKDF2 */
  5147. psa_status_t psa_key_derivation_output_bytes(
  5148. psa_key_derivation_operation_t *operation,
  5149. uint8_t *output_external,
  5150. size_t output_length)
  5151. {
  5152. psa_status_t status;
  5153. LOCAL_OUTPUT_DECLARE(output_external, output);
  5154. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg(operation);
  5155. if (operation->alg == 0) {
  5156. /* This is a blank operation. */
  5157. return PSA_ERROR_BAD_STATE;
  5158. }
  5159. if (output_length == 0 && operation->capacity == 0) {
  5160. /* Edge case: this is a finished operation, and 0 bytes
  5161. * were requested. The right error in this case could
  5162. * be either INSUFFICIENT_CAPACITY or BAD_STATE. Return
  5163. * INSUFFICIENT_CAPACITY, which is right for a finished
  5164. * operation, for consistency with the case when
  5165. * output_length > 0. */
  5166. return PSA_ERROR_INSUFFICIENT_DATA;
  5167. }
  5168. LOCAL_OUTPUT_ALLOC(output_external, output_length, output);
  5169. if (output_length > operation->capacity) {
  5170. operation->capacity = 0;
  5171. /* Go through the error path to wipe all confidential data now
  5172. * that the operation object is useless. */
  5173. status = PSA_ERROR_INSUFFICIENT_DATA;
  5174. goto exit;
  5175. }
  5176. operation->capacity -= output_length;
  5177. #if defined(BUILTIN_ALG_ANY_HKDF)
  5178. if (PSA_ALG_IS_ANY_HKDF(kdf_alg)) {
  5179. status = psa_key_derivation_hkdf_read(&operation->ctx.hkdf, kdf_alg,
  5180. output, output_length);
  5181. } else
  5182. #endif /* BUILTIN_ALG_ANY_HKDF */
  5183. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  5184. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  5185. if (PSA_ALG_IS_TLS12_PRF(kdf_alg) ||
  5186. PSA_ALG_IS_TLS12_PSK_TO_MS(kdf_alg)) {
  5187. status = psa_key_derivation_tls12_prf_read(&operation->ctx.tls12_prf,
  5188. kdf_alg, output,
  5189. output_length);
  5190. } else
  5191. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF ||
  5192. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  5193. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  5194. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  5195. status = psa_key_derivation_tls12_ecjpake_to_pms_read(
  5196. &operation->ctx.tls12_ecjpake_to_pms, output, output_length);
  5197. } else
  5198. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS */
  5199. #if defined(PSA_HAVE_SOFT_PBKDF2)
  5200. if (PSA_ALG_IS_PBKDF2(kdf_alg)) {
  5201. status = psa_key_derivation_pbkdf2_read(&operation->ctx.pbkdf2, kdf_alg,
  5202. output, output_length);
  5203. } else
  5204. #endif /* PSA_HAVE_SOFT_PBKDF2 */
  5205. {
  5206. (void) kdf_alg;
  5207. status = PSA_ERROR_BAD_STATE;
  5208. LOCAL_OUTPUT_FREE(output_external, output);
  5209. return status;
  5210. }
  5211. exit:
  5212. if (status != PSA_SUCCESS) {
  5213. /* Preserve the algorithm upon errors, but clear all sensitive state.
  5214. * This allows us to differentiate between exhausted operations and
  5215. * blank operations, so we can return PSA_ERROR_BAD_STATE on blank
  5216. * operations. */
  5217. psa_algorithm_t alg = operation->alg;
  5218. psa_key_derivation_abort(operation);
  5219. operation->alg = alg;
  5220. if (output != NULL) {
  5221. memset(output, '!', output_length);
  5222. }
  5223. }
  5224. LOCAL_OUTPUT_FREE(output_external, output);
  5225. return status;
  5226. }
  5227. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  5228. static void psa_des_set_key_parity(uint8_t *data, size_t data_size)
  5229. {
  5230. if (data_size >= 8) {
  5231. mbedtls_des_key_set_parity(data);
  5232. }
  5233. if (data_size >= 16) {
  5234. mbedtls_des_key_set_parity(data + 8);
  5235. }
  5236. if (data_size >= 24) {
  5237. mbedtls_des_key_set_parity(data + 16);
  5238. }
  5239. }
  5240. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  5241. /*
  5242. * ECC keys on a Weierstrass elliptic curve require the generation
  5243. * of a private key which is an integer
  5244. * in the range [1, N - 1], where N is the boundary of the private key domain:
  5245. * N is the prime p for Diffie-Hellman, or the order of the
  5246. * curve’s base point for ECC.
  5247. *
  5248. * Let m be the bit size of N, such that 2^m > N >= 2^(m-1).
  5249. * This function generates the private key using the following process:
  5250. *
  5251. * 1. Draw a byte string of length ceiling(m/8) bytes.
  5252. * 2. If m is not a multiple of 8, set the most significant
  5253. * (8 * ceiling(m/8) - m) bits of the first byte in the string to zero.
  5254. * 3. Convert the string to integer k by decoding it as a big-endian byte string.
  5255. * 4. If k > N - 2, discard the result and return to step 1.
  5256. * 5. Output k + 1 as the private key.
  5257. *
  5258. * This method allows compliance to NIST standards, specifically the methods titled
  5259. * Key-Pair Generation by Testing Candidates in the following publications:
  5260. * - NIST Special Publication 800-56A: Recommendation for Pair-Wise Key-Establishment
  5261. * Schemes Using Discrete Logarithm Cryptography [SP800-56A] §5.6.1.1.4 for
  5262. * Diffie-Hellman keys.
  5263. *
  5264. * - [SP800-56A] §5.6.1.2.2 or FIPS Publication 186-4: Digital Signature
  5265. * Standard (DSS) [FIPS186-4] §B.4.2 for elliptic curve keys.
  5266. *
  5267. * Note: Function allocates memory for *data buffer, so given *data should be
  5268. * always NULL.
  5269. */
  5270. #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE)
  5271. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_DERIVE)
  5272. static psa_status_t psa_generate_derived_ecc_key_weierstrass_helper(
  5273. psa_key_slot_t *slot,
  5274. size_t bits,
  5275. psa_key_derivation_operation_t *operation,
  5276. uint8_t **data
  5277. )
  5278. {
  5279. unsigned key_out_of_range = 1;
  5280. mbedtls_mpi k;
  5281. mbedtls_mpi diff_N_2;
  5282. int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
  5283. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  5284. size_t m;
  5285. size_t m_bytes;
  5286. mbedtls_mpi_init(&k);
  5287. mbedtls_mpi_init(&diff_N_2);
  5288. psa_ecc_family_t curve = PSA_KEY_TYPE_ECC_GET_FAMILY(
  5289. slot->attr.type);
  5290. mbedtls_ecp_group_id grp_id =
  5291. mbedtls_ecc_group_from_psa(curve, bits);
  5292. if (grp_id == MBEDTLS_ECP_DP_NONE) {
  5293. ret = MBEDTLS_ERR_ASN1_INVALID_DATA;
  5294. goto cleanup;
  5295. }
  5296. mbedtls_ecp_group ecp_group;
  5297. mbedtls_ecp_group_init(&ecp_group);
  5298. MBEDTLS_MPI_CHK(mbedtls_ecp_group_load(&ecp_group, grp_id));
  5299. /* N is the boundary of the private key domain (ecp_group.N). */
  5300. /* Let m be the bit size of N. */
  5301. m = ecp_group.nbits;
  5302. m_bytes = PSA_BITS_TO_BYTES(m);
  5303. /* Calculate N - 2 - it will be needed later. */
  5304. MBEDTLS_MPI_CHK(mbedtls_mpi_sub_int(&diff_N_2, &ecp_group.N, 2));
  5305. /* Note: This function is always called with *data == NULL and it
  5306. * allocates memory for the data buffer. */
  5307. *data = mbedtls_calloc(1, m_bytes);
  5308. if (*data == NULL) {
  5309. ret = MBEDTLS_ERR_ASN1_ALLOC_FAILED;
  5310. goto cleanup;
  5311. }
  5312. while (key_out_of_range) {
  5313. /* 1. Draw a byte string of length ceiling(m/8) bytes. */
  5314. if ((status = psa_key_derivation_output_bytes(operation, *data, m_bytes)) != 0) {
  5315. goto cleanup;
  5316. }
  5317. /* 2. If m is not a multiple of 8 */
  5318. if (m % 8 != 0) {
  5319. /* Set the most significant
  5320. * (8 * ceiling(m/8) - m) bits of the first byte in
  5321. * the string to zero.
  5322. */
  5323. uint8_t clear_bit_mask = (1 << (m % 8)) - 1;
  5324. (*data)[0] &= clear_bit_mask;
  5325. }
  5326. /* 3. Convert the string to integer k by decoding it as a
  5327. * big-endian byte string.
  5328. */
  5329. MBEDTLS_MPI_CHK(mbedtls_mpi_read_binary(&k, *data, m_bytes));
  5330. /* 4. If k > N - 2, discard the result and return to step 1.
  5331. * Result of comparison is returned. When it indicates error
  5332. * then this function is called again.
  5333. */
  5334. MBEDTLS_MPI_CHK(mbedtls_mpi_lt_mpi_ct(&diff_N_2, &k, &key_out_of_range));
  5335. }
  5336. /* 5. Output k + 1 as the private key. */
  5337. MBEDTLS_MPI_CHK(mbedtls_mpi_add_int(&k, &k, 1));
  5338. MBEDTLS_MPI_CHK(mbedtls_mpi_write_binary(&k, *data, m_bytes));
  5339. cleanup:
  5340. if (ret != 0) {
  5341. status = mbedtls_to_psa_error(ret);
  5342. }
  5343. if (status != PSA_SUCCESS) {
  5344. mbedtls_free(*data);
  5345. *data = NULL;
  5346. }
  5347. mbedtls_mpi_free(&k);
  5348. mbedtls_mpi_free(&diff_N_2);
  5349. return status;
  5350. }
  5351. /* ECC keys on a Montgomery elliptic curve draws a byte string whose length
  5352. * is determined by the curve, and sets the mandatory bits accordingly. That is:
  5353. *
  5354. * - Curve25519 (PSA_ECC_FAMILY_MONTGOMERY, 255 bits):
  5355. * draw a 32-byte string and process it as specified in
  5356. * Elliptic Curves for Security [RFC7748] §5.
  5357. *
  5358. * - Curve448 (PSA_ECC_FAMILY_MONTGOMERY, 448 bits):
  5359. * draw a 56-byte string and process it as specified in [RFC7748] §5.
  5360. *
  5361. * Note: Function allocates memory for *data buffer, so given *data should be
  5362. * always NULL.
  5363. */
  5364. static psa_status_t psa_generate_derived_ecc_key_montgomery_helper(
  5365. size_t bits,
  5366. psa_key_derivation_operation_t *operation,
  5367. uint8_t **data
  5368. )
  5369. {
  5370. size_t output_length;
  5371. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  5372. switch (bits) {
  5373. case 255:
  5374. output_length = 32;
  5375. break;
  5376. case 448:
  5377. output_length = 56;
  5378. break;
  5379. default:
  5380. return PSA_ERROR_INVALID_ARGUMENT;
  5381. break;
  5382. }
  5383. *data = mbedtls_calloc(1, output_length);
  5384. if (*data == NULL) {
  5385. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5386. }
  5387. status = psa_key_derivation_output_bytes(operation, *data, output_length);
  5388. if (status != PSA_SUCCESS) {
  5389. return status;
  5390. }
  5391. switch (bits) {
  5392. case 255:
  5393. (*data)[0] &= 248;
  5394. (*data)[31] &= 127;
  5395. (*data)[31] |= 64;
  5396. break;
  5397. case 448:
  5398. (*data)[0] &= 252;
  5399. (*data)[55] |= 128;
  5400. break;
  5401. default:
  5402. return PSA_ERROR_CORRUPTION_DETECTED;
  5403. break;
  5404. }
  5405. return status;
  5406. }
  5407. #else /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_DERIVE */
  5408. static psa_status_t psa_generate_derived_ecc_key_weierstrass_helper(
  5409. psa_key_slot_t *slot, size_t bits,
  5410. psa_key_derivation_operation_t *operation, uint8_t **data)
  5411. {
  5412. (void) slot;
  5413. (void) bits;
  5414. (void) operation;
  5415. (void) data;
  5416. return PSA_ERROR_NOT_SUPPORTED;
  5417. }
  5418. static psa_status_t psa_generate_derived_ecc_key_montgomery_helper(
  5419. size_t bits, psa_key_derivation_operation_t *operation, uint8_t **data)
  5420. {
  5421. (void) bits;
  5422. (void) operation;
  5423. (void) data;
  5424. return PSA_ERROR_NOT_SUPPORTED;
  5425. }
  5426. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_DERIVE */
  5427. #endif /* PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE */
  5428. static psa_status_t psa_generate_derived_key_internal(
  5429. psa_key_slot_t *slot,
  5430. size_t bits,
  5431. psa_key_derivation_operation_t *operation)
  5432. {
  5433. uint8_t *data = NULL;
  5434. size_t bytes = PSA_BITS_TO_BYTES(bits);
  5435. size_t storage_size = bytes;
  5436. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  5437. if (PSA_KEY_TYPE_IS_PUBLIC_KEY(slot->attr.type)) {
  5438. return PSA_ERROR_INVALID_ARGUMENT;
  5439. }
  5440. #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE) || \
  5441. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_DERIVE)
  5442. if (PSA_KEY_TYPE_IS_ECC(slot->attr.type)) {
  5443. psa_ecc_family_t curve = PSA_KEY_TYPE_ECC_GET_FAMILY(slot->attr.type);
  5444. if (PSA_ECC_FAMILY_IS_WEIERSTRASS(curve)) {
  5445. /* Weierstrass elliptic curve */
  5446. status = psa_generate_derived_ecc_key_weierstrass_helper(slot, bits, operation, &data);
  5447. if (status != PSA_SUCCESS) {
  5448. goto exit;
  5449. }
  5450. } else {
  5451. /* Montgomery elliptic curve */
  5452. status = psa_generate_derived_ecc_key_montgomery_helper(bits, operation, &data);
  5453. if (status != PSA_SUCCESS) {
  5454. goto exit;
  5455. }
  5456. }
  5457. } else
  5458. #endif /* defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE) ||
  5459. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_DERIVE) */
  5460. if (key_type_is_raw_bytes(slot->attr.type)) {
  5461. if (bits % 8 != 0) {
  5462. return PSA_ERROR_INVALID_ARGUMENT;
  5463. }
  5464. data = mbedtls_calloc(1, bytes);
  5465. if (data == NULL) {
  5466. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5467. }
  5468. status = psa_key_derivation_output_bytes(operation, data, bytes);
  5469. if (status != PSA_SUCCESS) {
  5470. goto exit;
  5471. }
  5472. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  5473. if (slot->attr.type == PSA_KEY_TYPE_DES) {
  5474. psa_des_set_key_parity(data, bytes);
  5475. }
  5476. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES) */
  5477. } else {
  5478. return PSA_ERROR_NOT_SUPPORTED;
  5479. }
  5480. slot->attr.bits = (psa_key_bits_t) bits;
  5481. if (psa_key_lifetime_is_external(slot->attr.lifetime)) {
  5482. status = psa_driver_wrapper_get_key_buffer_size(&slot->attr,
  5483. &storage_size);
  5484. if (status != PSA_SUCCESS) {
  5485. goto exit;
  5486. }
  5487. }
  5488. status = psa_allocate_buffer_to_slot(slot, storage_size);
  5489. if (status != PSA_SUCCESS) {
  5490. goto exit;
  5491. }
  5492. status = psa_driver_wrapper_import_key(&slot->attr,
  5493. data, bytes,
  5494. slot->key.data,
  5495. slot->key.bytes,
  5496. &slot->key.bytes, &bits);
  5497. if (bits != slot->attr.bits) {
  5498. status = PSA_ERROR_INVALID_ARGUMENT;
  5499. }
  5500. exit:
  5501. mbedtls_free(data);
  5502. return status;
  5503. }
  5504. static const psa_custom_key_parameters_t default_custom_production =
  5505. PSA_CUSTOM_KEY_PARAMETERS_INIT;
  5506. int psa_custom_key_parameters_are_default(
  5507. const psa_custom_key_parameters_t *custom,
  5508. size_t custom_data_length)
  5509. {
  5510. if (custom->flags != 0) {
  5511. return 0;
  5512. }
  5513. if (custom_data_length != 0) {
  5514. return 0;
  5515. }
  5516. return 1;
  5517. }
  5518. psa_status_t psa_key_derivation_output_key_custom(
  5519. const psa_key_attributes_t *attributes,
  5520. psa_key_derivation_operation_t *operation,
  5521. const psa_custom_key_parameters_t *custom,
  5522. const uint8_t *custom_data,
  5523. size_t custom_data_length,
  5524. mbedtls_svc_key_id_t *key)
  5525. {
  5526. psa_status_t status;
  5527. psa_key_slot_t *slot = NULL;
  5528. psa_se_drv_table_entry_t *driver = NULL;
  5529. *key = MBEDTLS_SVC_KEY_ID_INIT;
  5530. /* Reject any attempt to create a zero-length key so that we don't
  5531. * risk tripping up later, e.g. on a malloc(0) that returns NULL. */
  5532. if (psa_get_key_bits(attributes) == 0) {
  5533. return PSA_ERROR_INVALID_ARGUMENT;
  5534. }
  5535. (void) custom_data; /* We only accept 0-length data */
  5536. if (!psa_custom_key_parameters_are_default(custom, custom_data_length)) {
  5537. return PSA_ERROR_INVALID_ARGUMENT;
  5538. }
  5539. if (operation->alg == PSA_ALG_NONE) {
  5540. return PSA_ERROR_BAD_STATE;
  5541. }
  5542. if (!operation->can_output_key) {
  5543. return PSA_ERROR_NOT_PERMITTED;
  5544. }
  5545. status = psa_start_key_creation(PSA_KEY_CREATION_DERIVE, attributes,
  5546. &slot, &driver);
  5547. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  5548. if (driver != NULL) {
  5549. /* Deriving a key in a secure element is not implemented yet. */
  5550. status = PSA_ERROR_NOT_SUPPORTED;
  5551. }
  5552. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  5553. if (status == PSA_SUCCESS) {
  5554. status = psa_generate_derived_key_internal(slot,
  5555. attributes->bits,
  5556. operation);
  5557. }
  5558. if (status == PSA_SUCCESS) {
  5559. status = psa_finish_key_creation(slot, driver, key);
  5560. }
  5561. if (status != PSA_SUCCESS) {
  5562. psa_fail_key_creation(slot, driver);
  5563. }
  5564. return status;
  5565. }
  5566. psa_status_t psa_key_derivation_output_key_ext(
  5567. const psa_key_attributes_t *attributes,
  5568. psa_key_derivation_operation_t *operation,
  5569. const psa_key_production_parameters_t *params,
  5570. size_t params_data_length,
  5571. mbedtls_svc_key_id_t *key)
  5572. {
  5573. return psa_key_derivation_output_key_custom(
  5574. attributes, operation,
  5575. (const psa_custom_key_parameters_t *) params,
  5576. params->data, params_data_length,
  5577. key);
  5578. }
  5579. psa_status_t psa_key_derivation_output_key(
  5580. const psa_key_attributes_t *attributes,
  5581. psa_key_derivation_operation_t *operation,
  5582. mbedtls_svc_key_id_t *key)
  5583. {
  5584. return psa_key_derivation_output_key_custom(attributes, operation,
  5585. &default_custom_production,
  5586. NULL, 0,
  5587. key);
  5588. }
  5589. /****************************************************************/
  5590. /* Key derivation */
  5591. /****************************************************************/
  5592. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  5593. static int is_kdf_alg_supported(psa_algorithm_t kdf_alg)
  5594. {
  5595. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  5596. if (PSA_ALG_IS_HKDF(kdf_alg)) {
  5597. return 1;
  5598. }
  5599. #endif
  5600. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  5601. if (PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)) {
  5602. return 1;
  5603. }
  5604. #endif
  5605. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND)
  5606. if (PSA_ALG_IS_HKDF_EXPAND(kdf_alg)) {
  5607. return 1;
  5608. }
  5609. #endif
  5610. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF)
  5611. if (PSA_ALG_IS_TLS12_PRF(kdf_alg)) {
  5612. return 1;
  5613. }
  5614. #endif
  5615. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  5616. if (PSA_ALG_IS_TLS12_PSK_TO_MS(kdf_alg)) {
  5617. return 1;
  5618. }
  5619. #endif
  5620. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  5621. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  5622. return 1;
  5623. }
  5624. #endif
  5625. #if defined(MBEDTLS_PSA_BUILTIN_ALG_PBKDF2_HMAC)
  5626. if (PSA_ALG_IS_PBKDF2_HMAC(kdf_alg)) {
  5627. return 1;
  5628. }
  5629. #endif
  5630. #if defined(MBEDTLS_PSA_BUILTIN_ALG_PBKDF2_AES_CMAC_PRF_128)
  5631. if (kdf_alg == PSA_ALG_PBKDF2_AES_CMAC_PRF_128) {
  5632. return 1;
  5633. }
  5634. #endif
  5635. return 0;
  5636. }
  5637. static psa_status_t psa_hash_try_support(psa_algorithm_t alg)
  5638. {
  5639. psa_hash_operation_t operation = PSA_HASH_OPERATION_INIT;
  5640. psa_status_t status = psa_hash_setup(&operation, alg);
  5641. psa_hash_abort(&operation);
  5642. return status;
  5643. }
  5644. static psa_status_t psa_key_derivation_set_maximum_capacity(
  5645. psa_key_derivation_operation_t *operation,
  5646. psa_algorithm_t kdf_alg)
  5647. {
  5648. #if defined(PSA_WANT_ALG_TLS12_ECJPAKE_TO_PMS)
  5649. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  5650. operation->capacity = PSA_HASH_LENGTH(PSA_ALG_SHA_256);
  5651. return PSA_SUCCESS;
  5652. }
  5653. #endif
  5654. #if defined(PSA_WANT_ALG_PBKDF2_AES_CMAC_PRF_128)
  5655. if (kdf_alg == PSA_ALG_PBKDF2_AES_CMAC_PRF_128) {
  5656. #if (SIZE_MAX > UINT32_MAX)
  5657. operation->capacity = UINT32_MAX * (size_t) PSA_MAC_LENGTH(
  5658. PSA_KEY_TYPE_AES,
  5659. 128U,
  5660. PSA_ALG_CMAC);
  5661. #else
  5662. operation->capacity = SIZE_MAX;
  5663. #endif
  5664. return PSA_SUCCESS;
  5665. }
  5666. #endif /* PSA_WANT_ALG_PBKDF2_AES_CMAC_PRF_128 */
  5667. /* After this point, if kdf_alg is not valid then value of hash_alg may be
  5668. * invalid or meaningless but it does not affect this function */
  5669. psa_algorithm_t hash_alg = PSA_ALG_GET_HASH(kdf_alg);
  5670. size_t hash_size = PSA_HASH_LENGTH(hash_alg);
  5671. if (hash_size == 0) {
  5672. return PSA_ERROR_NOT_SUPPORTED;
  5673. }
  5674. /* Make sure that hash_alg is a supported hash algorithm. Otherwise
  5675. * we might fail later, which is somewhat unfriendly and potentially
  5676. * risk-prone. */
  5677. psa_status_t status = psa_hash_try_support(hash_alg);
  5678. if (status != PSA_SUCCESS) {
  5679. return status;
  5680. }
  5681. #if defined(PSA_WANT_ALG_HKDF)
  5682. if (PSA_ALG_IS_HKDF(kdf_alg)) {
  5683. operation->capacity = 255 * hash_size;
  5684. } else
  5685. #endif
  5686. #if defined(PSA_WANT_ALG_HKDF_EXTRACT)
  5687. if (PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)) {
  5688. operation->capacity = hash_size;
  5689. } else
  5690. #endif
  5691. #if defined(PSA_WANT_ALG_HKDF_EXPAND)
  5692. if (PSA_ALG_IS_HKDF_EXPAND(kdf_alg)) {
  5693. operation->capacity = 255 * hash_size;
  5694. } else
  5695. #endif
  5696. #if defined(PSA_WANT_ALG_TLS12_PRF)
  5697. if (PSA_ALG_IS_TLS12_PRF(kdf_alg) &&
  5698. (hash_alg == PSA_ALG_SHA_256 || hash_alg == PSA_ALG_SHA_384)) {
  5699. operation->capacity = SIZE_MAX;
  5700. } else
  5701. #endif
  5702. #if defined(PSA_WANT_ALG_TLS12_PSK_TO_MS)
  5703. if (PSA_ALG_IS_TLS12_PSK_TO_MS(kdf_alg) &&
  5704. (hash_alg == PSA_ALG_SHA_256 || hash_alg == PSA_ALG_SHA_384)) {
  5705. /* Master Secret is always 48 bytes
  5706. * https://datatracker.ietf.org/doc/html/rfc5246.html#section-8.1 */
  5707. operation->capacity = 48U;
  5708. } else
  5709. #endif
  5710. #if defined(PSA_WANT_ALG_PBKDF2_HMAC)
  5711. if (PSA_ALG_IS_PBKDF2_HMAC(kdf_alg)) {
  5712. #if (SIZE_MAX > UINT32_MAX)
  5713. operation->capacity = UINT32_MAX * hash_size;
  5714. #else
  5715. operation->capacity = SIZE_MAX;
  5716. #endif
  5717. } else
  5718. #endif /* PSA_WANT_ALG_PBKDF2_HMAC */
  5719. {
  5720. (void) hash_size;
  5721. status = PSA_ERROR_NOT_SUPPORTED;
  5722. }
  5723. return status;
  5724. }
  5725. static psa_status_t psa_key_derivation_setup_kdf(
  5726. psa_key_derivation_operation_t *operation,
  5727. psa_algorithm_t kdf_alg)
  5728. {
  5729. /* Make sure that operation->ctx is properly zero-initialised. (Macro
  5730. * initialisers for this union leave some bytes unspecified.) */
  5731. memset(&operation->ctx, 0, sizeof(operation->ctx));
  5732. /* Make sure that kdf_alg is a supported key derivation algorithm. */
  5733. if (!is_kdf_alg_supported(kdf_alg)) {
  5734. return PSA_ERROR_NOT_SUPPORTED;
  5735. }
  5736. psa_status_t status = psa_key_derivation_set_maximum_capacity(operation,
  5737. kdf_alg);
  5738. return status;
  5739. }
  5740. static psa_status_t psa_key_agreement_try_support(psa_algorithm_t alg)
  5741. {
  5742. #if defined(PSA_WANT_ALG_ECDH)
  5743. if (alg == PSA_ALG_ECDH) {
  5744. return PSA_SUCCESS;
  5745. }
  5746. #endif
  5747. #if defined(PSA_WANT_ALG_FFDH)
  5748. if (alg == PSA_ALG_FFDH) {
  5749. return PSA_SUCCESS;
  5750. }
  5751. #endif
  5752. (void) alg;
  5753. return PSA_ERROR_NOT_SUPPORTED;
  5754. }
  5755. static int psa_key_derivation_allows_free_form_secret_input(
  5756. psa_algorithm_t kdf_alg)
  5757. {
  5758. #if defined(PSA_WANT_ALG_TLS12_ECJPAKE_TO_PMS)
  5759. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  5760. return 0;
  5761. }
  5762. #endif
  5763. (void) kdf_alg;
  5764. return 1;
  5765. }
  5766. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  5767. psa_status_t psa_key_derivation_setup(psa_key_derivation_operation_t *operation,
  5768. psa_algorithm_t alg)
  5769. {
  5770. psa_status_t status;
  5771. if (operation->alg != 0) {
  5772. return PSA_ERROR_BAD_STATE;
  5773. }
  5774. if (PSA_ALG_IS_RAW_KEY_AGREEMENT(alg)) {
  5775. return PSA_ERROR_INVALID_ARGUMENT;
  5776. } else if (PSA_ALG_IS_KEY_AGREEMENT(alg)) {
  5777. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  5778. psa_algorithm_t kdf_alg = PSA_ALG_KEY_AGREEMENT_GET_KDF(alg);
  5779. psa_algorithm_t ka_alg = PSA_ALG_KEY_AGREEMENT_GET_BASE(alg);
  5780. status = psa_key_agreement_try_support(ka_alg);
  5781. if (status != PSA_SUCCESS) {
  5782. return status;
  5783. }
  5784. if (!psa_key_derivation_allows_free_form_secret_input(kdf_alg)) {
  5785. return PSA_ERROR_INVALID_ARGUMENT;
  5786. }
  5787. status = psa_key_derivation_setup_kdf(operation, kdf_alg);
  5788. #else
  5789. return PSA_ERROR_NOT_SUPPORTED;
  5790. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  5791. } else if (PSA_ALG_IS_KEY_DERIVATION(alg)) {
  5792. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  5793. status = psa_key_derivation_setup_kdf(operation, alg);
  5794. #else
  5795. return PSA_ERROR_NOT_SUPPORTED;
  5796. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  5797. } else {
  5798. return PSA_ERROR_INVALID_ARGUMENT;
  5799. }
  5800. if (status == PSA_SUCCESS) {
  5801. operation->alg = alg;
  5802. }
  5803. return status;
  5804. }
  5805. #if defined(BUILTIN_ALG_ANY_HKDF)
  5806. static psa_status_t psa_hkdf_input(psa_hkdf_key_derivation_t *hkdf,
  5807. psa_algorithm_t kdf_alg,
  5808. psa_key_derivation_step_t step,
  5809. const uint8_t *data,
  5810. size_t data_length)
  5811. {
  5812. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH(kdf_alg);
  5813. psa_status_t status;
  5814. switch (step) {
  5815. case PSA_KEY_DERIVATION_INPUT_SALT:
  5816. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND)
  5817. if (PSA_ALG_IS_HKDF_EXPAND(kdf_alg)) {
  5818. return PSA_ERROR_INVALID_ARGUMENT;
  5819. }
  5820. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND */
  5821. if (hkdf->state != HKDF_STATE_INIT) {
  5822. return PSA_ERROR_BAD_STATE;
  5823. } else {
  5824. status = psa_key_derivation_start_hmac(&hkdf->hmac,
  5825. hash_alg,
  5826. data, data_length);
  5827. if (status != PSA_SUCCESS) {
  5828. return status;
  5829. }
  5830. hkdf->state = HKDF_STATE_STARTED;
  5831. return PSA_SUCCESS;
  5832. }
  5833. case PSA_KEY_DERIVATION_INPUT_SECRET:
  5834. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND)
  5835. if (PSA_ALG_IS_HKDF_EXPAND(kdf_alg)) {
  5836. /* We shouldn't be in different state as HKDF_EXPAND only allows
  5837. * two inputs: SECRET (this case) and INFO which does not modify
  5838. * the state. It could happen only if the hkdf
  5839. * object was corrupted. */
  5840. if (hkdf->state != HKDF_STATE_INIT) {
  5841. return PSA_ERROR_BAD_STATE;
  5842. }
  5843. /* Allow only input that fits expected prk size */
  5844. if (data_length != PSA_HASH_LENGTH(hash_alg)) {
  5845. return PSA_ERROR_INVALID_ARGUMENT;
  5846. }
  5847. memcpy(hkdf->prk, data, data_length);
  5848. } else
  5849. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND */
  5850. {
  5851. /* HKDF: If no salt was provided, use an empty salt.
  5852. * HKDF-EXTRACT: salt is mandatory. */
  5853. if (hkdf->state == HKDF_STATE_INIT) {
  5854. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  5855. if (PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)) {
  5856. return PSA_ERROR_BAD_STATE;
  5857. }
  5858. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  5859. status = psa_key_derivation_start_hmac(&hkdf->hmac,
  5860. hash_alg,
  5861. NULL, 0);
  5862. if (status != PSA_SUCCESS) {
  5863. return status;
  5864. }
  5865. hkdf->state = HKDF_STATE_STARTED;
  5866. }
  5867. if (hkdf->state != HKDF_STATE_STARTED) {
  5868. return PSA_ERROR_BAD_STATE;
  5869. }
  5870. status = psa_mac_update(&hkdf->hmac,
  5871. data, data_length);
  5872. if (status != PSA_SUCCESS) {
  5873. return status;
  5874. }
  5875. status = psa_mac_sign_finish(&hkdf->hmac,
  5876. hkdf->prk,
  5877. sizeof(hkdf->prk),
  5878. &data_length);
  5879. if (status != PSA_SUCCESS) {
  5880. return status;
  5881. }
  5882. }
  5883. hkdf->state = HKDF_STATE_KEYED;
  5884. hkdf->block_number = 0;
  5885. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  5886. if (PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)) {
  5887. /* The only block of output is the PRK. */
  5888. memcpy(hkdf->output_block, hkdf->prk, PSA_HASH_LENGTH(hash_alg));
  5889. hkdf->offset_in_block = 0;
  5890. } else
  5891. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  5892. {
  5893. /* Block 0 is empty, and the next block will be
  5894. * generated by psa_key_derivation_hkdf_read(). */
  5895. hkdf->offset_in_block = PSA_HASH_LENGTH(hash_alg);
  5896. }
  5897. return PSA_SUCCESS;
  5898. case PSA_KEY_DERIVATION_INPUT_INFO:
  5899. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT)
  5900. if (PSA_ALG_IS_HKDF_EXTRACT(kdf_alg)) {
  5901. return PSA_ERROR_INVALID_ARGUMENT;
  5902. }
  5903. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  5904. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND)
  5905. if (PSA_ALG_IS_HKDF_EXPAND(kdf_alg) &&
  5906. hkdf->state == HKDF_STATE_INIT) {
  5907. return PSA_ERROR_BAD_STATE;
  5908. }
  5909. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT */
  5910. if (hkdf->state == HKDF_STATE_OUTPUT) {
  5911. return PSA_ERROR_BAD_STATE;
  5912. }
  5913. if (hkdf->info_set) {
  5914. return PSA_ERROR_BAD_STATE;
  5915. }
  5916. hkdf->info_length = data_length;
  5917. if (data_length != 0) {
  5918. hkdf->info = mbedtls_calloc(1, data_length);
  5919. if (hkdf->info == NULL) {
  5920. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5921. }
  5922. memcpy(hkdf->info, data, data_length);
  5923. }
  5924. hkdf->info_set = 1;
  5925. return PSA_SUCCESS;
  5926. default:
  5927. return PSA_ERROR_INVALID_ARGUMENT;
  5928. }
  5929. }
  5930. #endif /* BUILTIN_ALG_ANY_HKDF */
  5931. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  5932. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  5933. static psa_status_t psa_tls12_prf_set_seed(psa_tls12_prf_key_derivation_t *prf,
  5934. const uint8_t *data,
  5935. size_t data_length)
  5936. {
  5937. if (prf->state != PSA_TLS12_PRF_STATE_INIT) {
  5938. return PSA_ERROR_BAD_STATE;
  5939. }
  5940. if (data_length != 0) {
  5941. prf->seed = mbedtls_calloc(1, data_length);
  5942. if (prf->seed == NULL) {
  5943. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5944. }
  5945. memcpy(prf->seed, data, data_length);
  5946. prf->seed_length = data_length;
  5947. }
  5948. prf->state = PSA_TLS12_PRF_STATE_SEED_SET;
  5949. return PSA_SUCCESS;
  5950. }
  5951. static psa_status_t psa_tls12_prf_set_key(psa_tls12_prf_key_derivation_t *prf,
  5952. const uint8_t *data,
  5953. size_t data_length)
  5954. {
  5955. if (prf->state != PSA_TLS12_PRF_STATE_SEED_SET &&
  5956. prf->state != PSA_TLS12_PRF_STATE_OTHER_KEY_SET) {
  5957. return PSA_ERROR_BAD_STATE;
  5958. }
  5959. if (data_length != 0) {
  5960. prf->secret = mbedtls_calloc(1, data_length);
  5961. if (prf->secret == NULL) {
  5962. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5963. }
  5964. memcpy(prf->secret, data, data_length);
  5965. prf->secret_length = data_length;
  5966. }
  5967. prf->state = PSA_TLS12_PRF_STATE_KEY_SET;
  5968. return PSA_SUCCESS;
  5969. }
  5970. static psa_status_t psa_tls12_prf_set_label(psa_tls12_prf_key_derivation_t *prf,
  5971. const uint8_t *data,
  5972. size_t data_length)
  5973. {
  5974. if (prf->state != PSA_TLS12_PRF_STATE_KEY_SET) {
  5975. return PSA_ERROR_BAD_STATE;
  5976. }
  5977. if (data_length != 0) {
  5978. prf->label = mbedtls_calloc(1, data_length);
  5979. if (prf->label == NULL) {
  5980. return PSA_ERROR_INSUFFICIENT_MEMORY;
  5981. }
  5982. memcpy(prf->label, data, data_length);
  5983. prf->label_length = data_length;
  5984. }
  5985. prf->state = PSA_TLS12_PRF_STATE_LABEL_SET;
  5986. return PSA_SUCCESS;
  5987. }
  5988. static psa_status_t psa_tls12_prf_input(psa_tls12_prf_key_derivation_t *prf,
  5989. psa_key_derivation_step_t step,
  5990. const uint8_t *data,
  5991. size_t data_length)
  5992. {
  5993. switch (step) {
  5994. case PSA_KEY_DERIVATION_INPUT_SEED:
  5995. return psa_tls12_prf_set_seed(prf, data, data_length);
  5996. case PSA_KEY_DERIVATION_INPUT_SECRET:
  5997. return psa_tls12_prf_set_key(prf, data, data_length);
  5998. case PSA_KEY_DERIVATION_INPUT_LABEL:
  5999. return psa_tls12_prf_set_label(prf, data, data_length);
  6000. default:
  6001. return PSA_ERROR_INVALID_ARGUMENT;
  6002. }
  6003. }
  6004. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) ||
  6005. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  6006. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  6007. static psa_status_t psa_tls12_prf_psk_to_ms_set_key(
  6008. psa_tls12_prf_key_derivation_t *prf,
  6009. const uint8_t *data,
  6010. size_t data_length)
  6011. {
  6012. psa_status_t status;
  6013. const size_t pms_len = (prf->state == PSA_TLS12_PRF_STATE_OTHER_KEY_SET ?
  6014. 4 + data_length + prf->other_secret_length :
  6015. 4 + 2 * data_length);
  6016. if (data_length > PSA_TLS12_PSK_TO_MS_PSK_MAX_SIZE) {
  6017. return PSA_ERROR_INVALID_ARGUMENT;
  6018. }
  6019. uint8_t *pms = mbedtls_calloc(1, pms_len);
  6020. if (pms == NULL) {
  6021. return PSA_ERROR_INSUFFICIENT_MEMORY;
  6022. }
  6023. uint8_t *cur = pms;
  6024. /* pure-PSK:
  6025. * Quoting RFC 4279, Section 2:
  6026. *
  6027. * The premaster secret is formed as follows: if the PSK is N octets
  6028. * long, concatenate a uint16 with the value N, N zero octets, a second
  6029. * uint16 with the value N, and the PSK itself.
  6030. *
  6031. * mixed-PSK:
  6032. * In a DHE-PSK, RSA-PSK, ECDHE-PSK the premaster secret is formed as
  6033. * follows: concatenate a uint16 with the length of the other secret,
  6034. * the other secret itself, uint16 with the length of PSK, and the
  6035. * PSK itself.
  6036. * For details please check:
  6037. * - RFC 4279, Section 4 for the definition of RSA-PSK,
  6038. * - RFC 4279, Section 3 for the definition of DHE-PSK,
  6039. * - RFC 5489 for the definition of ECDHE-PSK.
  6040. */
  6041. if (prf->state == PSA_TLS12_PRF_STATE_OTHER_KEY_SET) {
  6042. *cur++ = MBEDTLS_BYTE_1(prf->other_secret_length);
  6043. *cur++ = MBEDTLS_BYTE_0(prf->other_secret_length);
  6044. if (prf->other_secret_length != 0) {
  6045. memcpy(cur, prf->other_secret, prf->other_secret_length);
  6046. mbedtls_platform_zeroize(prf->other_secret, prf->other_secret_length);
  6047. cur += prf->other_secret_length;
  6048. }
  6049. } else {
  6050. *cur++ = MBEDTLS_BYTE_1(data_length);
  6051. *cur++ = MBEDTLS_BYTE_0(data_length);
  6052. memset(cur, 0, data_length);
  6053. cur += data_length;
  6054. }
  6055. *cur++ = MBEDTLS_BYTE_1(data_length);
  6056. *cur++ = MBEDTLS_BYTE_0(data_length);
  6057. memcpy(cur, data, data_length);
  6058. cur += data_length;
  6059. status = psa_tls12_prf_set_key(prf, pms, (size_t) (cur - pms));
  6060. mbedtls_zeroize_and_free(pms, pms_len);
  6061. return status;
  6062. }
  6063. static psa_status_t psa_tls12_prf_psk_to_ms_set_other_key(
  6064. psa_tls12_prf_key_derivation_t *prf,
  6065. const uint8_t *data,
  6066. size_t data_length)
  6067. {
  6068. if (prf->state != PSA_TLS12_PRF_STATE_SEED_SET) {
  6069. return PSA_ERROR_BAD_STATE;
  6070. }
  6071. if (data_length != 0) {
  6072. prf->other_secret = mbedtls_calloc(1, data_length);
  6073. if (prf->other_secret == NULL) {
  6074. return PSA_ERROR_INSUFFICIENT_MEMORY;
  6075. }
  6076. memcpy(prf->other_secret, data, data_length);
  6077. prf->other_secret_length = data_length;
  6078. } else {
  6079. prf->other_secret_length = 0;
  6080. }
  6081. prf->state = PSA_TLS12_PRF_STATE_OTHER_KEY_SET;
  6082. return PSA_SUCCESS;
  6083. }
  6084. static psa_status_t psa_tls12_prf_psk_to_ms_input(
  6085. psa_tls12_prf_key_derivation_t *prf,
  6086. psa_key_derivation_step_t step,
  6087. const uint8_t *data,
  6088. size_t data_length)
  6089. {
  6090. switch (step) {
  6091. case PSA_KEY_DERIVATION_INPUT_SECRET:
  6092. return psa_tls12_prf_psk_to_ms_set_key(prf,
  6093. data, data_length);
  6094. break;
  6095. case PSA_KEY_DERIVATION_INPUT_OTHER_SECRET:
  6096. return psa_tls12_prf_psk_to_ms_set_other_key(prf,
  6097. data,
  6098. data_length);
  6099. break;
  6100. default:
  6101. return psa_tls12_prf_input(prf, step, data, data_length);
  6102. break;
  6103. }
  6104. }
  6105. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  6106. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  6107. static psa_status_t psa_tls12_ecjpake_to_pms_input(
  6108. psa_tls12_ecjpake_to_pms_t *ecjpake,
  6109. psa_key_derivation_step_t step,
  6110. const uint8_t *data,
  6111. size_t data_length)
  6112. {
  6113. if (data_length != PSA_TLS12_ECJPAKE_TO_PMS_INPUT_SIZE ||
  6114. step != PSA_KEY_DERIVATION_INPUT_SECRET) {
  6115. return PSA_ERROR_INVALID_ARGUMENT;
  6116. }
  6117. /* Check if the passed point is in an uncompressed form */
  6118. if (data[0] != 0x04) {
  6119. return PSA_ERROR_INVALID_ARGUMENT;
  6120. }
  6121. /* Only K.X has to be extracted - bytes 1 to 32 inclusive. */
  6122. memcpy(ecjpake->data, data + 1, PSA_TLS12_ECJPAKE_TO_PMS_DATA_SIZE);
  6123. return PSA_SUCCESS;
  6124. }
  6125. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS */
  6126. #if defined(PSA_HAVE_SOFT_PBKDF2)
  6127. static psa_status_t psa_pbkdf2_set_input_cost(
  6128. psa_pbkdf2_key_derivation_t *pbkdf2,
  6129. psa_key_derivation_step_t step,
  6130. uint64_t data)
  6131. {
  6132. if (step != PSA_KEY_DERIVATION_INPUT_COST) {
  6133. return PSA_ERROR_INVALID_ARGUMENT;
  6134. }
  6135. if (pbkdf2->state != PSA_PBKDF2_STATE_INIT) {
  6136. return PSA_ERROR_BAD_STATE;
  6137. }
  6138. if (data > PSA_VENDOR_PBKDF2_MAX_ITERATIONS) {
  6139. return PSA_ERROR_NOT_SUPPORTED;
  6140. }
  6141. if (data == 0) {
  6142. return PSA_ERROR_INVALID_ARGUMENT;
  6143. }
  6144. pbkdf2->input_cost = data;
  6145. pbkdf2->state = PSA_PBKDF2_STATE_INPUT_COST_SET;
  6146. return PSA_SUCCESS;
  6147. }
  6148. static psa_status_t psa_pbkdf2_set_salt(psa_pbkdf2_key_derivation_t *pbkdf2,
  6149. const uint8_t *data,
  6150. size_t data_length)
  6151. {
  6152. if (pbkdf2->state == PSA_PBKDF2_STATE_INPUT_COST_SET) {
  6153. pbkdf2->state = PSA_PBKDF2_STATE_SALT_SET;
  6154. } else if (pbkdf2->state == PSA_PBKDF2_STATE_SALT_SET) {
  6155. /* Appending to existing salt. No state change. */
  6156. } else {
  6157. return PSA_ERROR_BAD_STATE;
  6158. }
  6159. if (data_length == 0) {
  6160. /* Appending an empty string, nothing to do. */
  6161. } else {
  6162. uint8_t *next_salt;
  6163. next_salt = mbedtls_calloc(1, data_length + pbkdf2->salt_length);
  6164. if (next_salt == NULL) {
  6165. return PSA_ERROR_INSUFFICIENT_MEMORY;
  6166. }
  6167. if (pbkdf2->salt_length != 0) {
  6168. memcpy(next_salt, pbkdf2->salt, pbkdf2->salt_length);
  6169. }
  6170. memcpy(next_salt + pbkdf2->salt_length, data, data_length);
  6171. pbkdf2->salt_length += data_length;
  6172. mbedtls_free(pbkdf2->salt);
  6173. pbkdf2->salt = next_salt;
  6174. }
  6175. return PSA_SUCCESS;
  6176. }
  6177. #if defined(MBEDTLS_PSA_BUILTIN_ALG_PBKDF2_HMAC)
  6178. static psa_status_t psa_pbkdf2_hmac_set_password(psa_algorithm_t hash_alg,
  6179. const uint8_t *input,
  6180. size_t input_len,
  6181. uint8_t *output,
  6182. size_t *output_len)
  6183. {
  6184. psa_status_t status = PSA_SUCCESS;
  6185. if (input_len > PSA_HASH_BLOCK_LENGTH(hash_alg)) {
  6186. return psa_hash_compute(hash_alg, input, input_len, output,
  6187. PSA_HMAC_MAX_HASH_BLOCK_SIZE, output_len);
  6188. } else if (input_len > 0) {
  6189. memcpy(output, input, input_len);
  6190. }
  6191. *output_len = PSA_HASH_BLOCK_LENGTH(hash_alg);
  6192. return status;
  6193. }
  6194. #endif /* MBEDTLS_PSA_BUILTIN_ALG_PBKDF2_HMAC */
  6195. #if defined(MBEDTLS_PSA_BUILTIN_ALG_PBKDF2_AES_CMAC_PRF_128)
  6196. static psa_status_t psa_pbkdf2_cmac_set_password(const uint8_t *input,
  6197. size_t input_len,
  6198. uint8_t *output,
  6199. size_t *output_len)
  6200. {
  6201. psa_status_t status = PSA_SUCCESS;
  6202. if (input_len != PSA_MAC_LENGTH(PSA_KEY_TYPE_AES, 128U, PSA_ALG_CMAC)) {
  6203. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  6204. uint8_t zeros[16] = { 0 };
  6205. psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
  6206. psa_set_key_bits(&attributes, PSA_BYTES_TO_BITS(sizeof(zeros)));
  6207. psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE);
  6208. /* Passing PSA_MAC_LENGTH(PSA_KEY_TYPE_AES, 128U, PSA_ALG_CMAC) as
  6209. * mac_size as the driver function sets mac_output_length = mac_size
  6210. * on success. See https://github.com/Mbed-TLS/mbedtls/issues/7801 */
  6211. status = psa_driver_wrapper_mac_compute(&attributes,
  6212. zeros, sizeof(zeros),
  6213. PSA_ALG_CMAC, input, input_len,
  6214. output,
  6215. PSA_MAC_LENGTH(PSA_KEY_TYPE_AES,
  6216. 128U,
  6217. PSA_ALG_CMAC),
  6218. output_len);
  6219. } else {
  6220. memcpy(output, input, input_len);
  6221. *output_len = PSA_MAC_LENGTH(PSA_KEY_TYPE_AES, 128U, PSA_ALG_CMAC);
  6222. }
  6223. return status;
  6224. }
  6225. #endif /* MBEDTLS_PSA_BUILTIN_ALG_PBKDF2_AES_CMAC_PRF_128 */
  6226. static psa_status_t psa_pbkdf2_set_password(psa_pbkdf2_key_derivation_t *pbkdf2,
  6227. psa_algorithm_t kdf_alg,
  6228. const uint8_t *data,
  6229. size_t data_length)
  6230. {
  6231. psa_status_t status = PSA_SUCCESS;
  6232. if (pbkdf2->state != PSA_PBKDF2_STATE_SALT_SET) {
  6233. return PSA_ERROR_BAD_STATE;
  6234. }
  6235. #if defined(MBEDTLS_PSA_BUILTIN_ALG_PBKDF2_HMAC)
  6236. if (PSA_ALG_IS_PBKDF2_HMAC(kdf_alg)) {
  6237. psa_algorithm_t hash_alg = PSA_ALG_PBKDF2_HMAC_GET_HASH(kdf_alg);
  6238. status = psa_pbkdf2_hmac_set_password(hash_alg, data, data_length,
  6239. pbkdf2->password,
  6240. &pbkdf2->password_length);
  6241. } else
  6242. #endif /* MBEDTLS_PSA_BUILTIN_ALG_PBKDF2_HMAC */
  6243. #if defined(MBEDTLS_PSA_BUILTIN_ALG_PBKDF2_AES_CMAC_PRF_128)
  6244. if (kdf_alg == PSA_ALG_PBKDF2_AES_CMAC_PRF_128) {
  6245. status = psa_pbkdf2_cmac_set_password(data, data_length,
  6246. pbkdf2->password,
  6247. &pbkdf2->password_length);
  6248. } else
  6249. #endif /* MBEDTLS_PSA_BUILTIN_ALG_PBKDF2_AES_CMAC_PRF_128 */
  6250. {
  6251. return PSA_ERROR_INVALID_ARGUMENT;
  6252. }
  6253. pbkdf2->state = PSA_PBKDF2_STATE_PASSWORD_SET;
  6254. return status;
  6255. }
  6256. static psa_status_t psa_pbkdf2_input(psa_pbkdf2_key_derivation_t *pbkdf2,
  6257. psa_algorithm_t kdf_alg,
  6258. psa_key_derivation_step_t step,
  6259. const uint8_t *data,
  6260. size_t data_length)
  6261. {
  6262. switch (step) {
  6263. case PSA_KEY_DERIVATION_INPUT_SALT:
  6264. return psa_pbkdf2_set_salt(pbkdf2, data, data_length);
  6265. case PSA_KEY_DERIVATION_INPUT_PASSWORD:
  6266. return psa_pbkdf2_set_password(pbkdf2, kdf_alg, data, data_length);
  6267. default:
  6268. return PSA_ERROR_INVALID_ARGUMENT;
  6269. }
  6270. }
  6271. #endif /* PSA_HAVE_SOFT_PBKDF2 */
  6272. /** Check whether the given key type is acceptable for the given
  6273. * input step of a key derivation.
  6274. *
  6275. * Secret inputs must have the type #PSA_KEY_TYPE_DERIVE.
  6276. * Non-secret inputs must have the type #PSA_KEY_TYPE_RAW_DATA.
  6277. * Both secret and non-secret inputs can alternatively have the type
  6278. * #PSA_KEY_TYPE_NONE, which is never the type of a key object, meaning
  6279. * that the input was passed as a buffer rather than via a key object.
  6280. */
  6281. static int psa_key_derivation_check_input_type(
  6282. psa_key_derivation_step_t step,
  6283. psa_key_type_t key_type)
  6284. {
  6285. switch (step) {
  6286. case PSA_KEY_DERIVATION_INPUT_SECRET:
  6287. if (key_type == PSA_KEY_TYPE_DERIVE) {
  6288. return PSA_SUCCESS;
  6289. }
  6290. if (key_type == PSA_KEY_TYPE_NONE) {
  6291. return PSA_SUCCESS;
  6292. }
  6293. break;
  6294. case PSA_KEY_DERIVATION_INPUT_OTHER_SECRET:
  6295. if (key_type == PSA_KEY_TYPE_DERIVE) {
  6296. return PSA_SUCCESS;
  6297. }
  6298. if (key_type == PSA_KEY_TYPE_NONE) {
  6299. return PSA_SUCCESS;
  6300. }
  6301. break;
  6302. case PSA_KEY_DERIVATION_INPUT_LABEL:
  6303. case PSA_KEY_DERIVATION_INPUT_SALT:
  6304. case PSA_KEY_DERIVATION_INPUT_INFO:
  6305. case PSA_KEY_DERIVATION_INPUT_SEED:
  6306. if (key_type == PSA_KEY_TYPE_RAW_DATA) {
  6307. return PSA_SUCCESS;
  6308. }
  6309. if (key_type == PSA_KEY_TYPE_NONE) {
  6310. return PSA_SUCCESS;
  6311. }
  6312. break;
  6313. case PSA_KEY_DERIVATION_INPUT_PASSWORD:
  6314. if (key_type == PSA_KEY_TYPE_PASSWORD) {
  6315. return PSA_SUCCESS;
  6316. }
  6317. if (key_type == PSA_KEY_TYPE_DERIVE) {
  6318. return PSA_SUCCESS;
  6319. }
  6320. if (key_type == PSA_KEY_TYPE_NONE) {
  6321. return PSA_SUCCESS;
  6322. }
  6323. break;
  6324. }
  6325. return PSA_ERROR_INVALID_ARGUMENT;
  6326. }
  6327. static psa_status_t psa_key_derivation_input_internal(
  6328. psa_key_derivation_operation_t *operation,
  6329. psa_key_derivation_step_t step,
  6330. psa_key_type_t key_type,
  6331. const uint8_t *data,
  6332. size_t data_length)
  6333. {
  6334. psa_status_t status;
  6335. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg(operation);
  6336. status = psa_key_derivation_check_input_type(step, key_type);
  6337. if (status != PSA_SUCCESS) {
  6338. goto exit;
  6339. }
  6340. #if defined(BUILTIN_ALG_ANY_HKDF)
  6341. if (PSA_ALG_IS_ANY_HKDF(kdf_alg)) {
  6342. status = psa_hkdf_input(&operation->ctx.hkdf, kdf_alg,
  6343. step, data, data_length);
  6344. } else
  6345. #endif /* BUILTIN_ALG_ANY_HKDF */
  6346. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF)
  6347. if (PSA_ALG_IS_TLS12_PRF(kdf_alg)) {
  6348. status = psa_tls12_prf_input(&operation->ctx.tls12_prf,
  6349. step, data, data_length);
  6350. } else
  6351. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF */
  6352. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  6353. if (PSA_ALG_IS_TLS12_PSK_TO_MS(kdf_alg)) {
  6354. status = psa_tls12_prf_psk_to_ms_input(&operation->ctx.tls12_prf,
  6355. step, data, data_length);
  6356. } else
  6357. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  6358. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS)
  6359. if (kdf_alg == PSA_ALG_TLS12_ECJPAKE_TO_PMS) {
  6360. status = psa_tls12_ecjpake_to_pms_input(
  6361. &operation->ctx.tls12_ecjpake_to_pms, step, data, data_length);
  6362. } else
  6363. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS */
  6364. #if defined(PSA_HAVE_SOFT_PBKDF2)
  6365. if (PSA_ALG_IS_PBKDF2(kdf_alg)) {
  6366. status = psa_pbkdf2_input(&operation->ctx.pbkdf2, kdf_alg,
  6367. step, data, data_length);
  6368. } else
  6369. #endif /* PSA_HAVE_SOFT_PBKDF2 */
  6370. {
  6371. /* This can't happen unless the operation object was not initialized */
  6372. (void) data;
  6373. (void) data_length;
  6374. (void) kdf_alg;
  6375. return PSA_ERROR_BAD_STATE;
  6376. }
  6377. exit:
  6378. if (status != PSA_SUCCESS) {
  6379. psa_key_derivation_abort(operation);
  6380. }
  6381. return status;
  6382. }
  6383. static psa_status_t psa_key_derivation_input_integer_internal(
  6384. psa_key_derivation_operation_t *operation,
  6385. psa_key_derivation_step_t step,
  6386. uint64_t value)
  6387. {
  6388. psa_status_t status;
  6389. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg(operation);
  6390. #if defined(PSA_HAVE_SOFT_PBKDF2)
  6391. if (PSA_ALG_IS_PBKDF2(kdf_alg)) {
  6392. status = psa_pbkdf2_set_input_cost(
  6393. &operation->ctx.pbkdf2, step, value);
  6394. } else
  6395. #endif /* PSA_HAVE_SOFT_PBKDF2 */
  6396. {
  6397. (void) step;
  6398. (void) value;
  6399. (void) kdf_alg;
  6400. status = PSA_ERROR_INVALID_ARGUMENT;
  6401. }
  6402. if (status != PSA_SUCCESS) {
  6403. psa_key_derivation_abort(operation);
  6404. }
  6405. return status;
  6406. }
  6407. psa_status_t psa_key_derivation_input_bytes(
  6408. psa_key_derivation_operation_t *operation,
  6409. psa_key_derivation_step_t step,
  6410. const uint8_t *data_external,
  6411. size_t data_length)
  6412. {
  6413. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6414. LOCAL_INPUT_DECLARE(data_external, data);
  6415. LOCAL_INPUT_ALLOC(data_external, data_length, data);
  6416. status = psa_key_derivation_input_internal(operation, step,
  6417. PSA_KEY_TYPE_NONE,
  6418. data, data_length);
  6419. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  6420. exit:
  6421. #endif
  6422. LOCAL_INPUT_FREE(data_external, data);
  6423. return status;
  6424. }
  6425. psa_status_t psa_key_derivation_input_integer(
  6426. psa_key_derivation_operation_t *operation,
  6427. psa_key_derivation_step_t step,
  6428. uint64_t value)
  6429. {
  6430. return psa_key_derivation_input_integer_internal(operation, step, value);
  6431. }
  6432. psa_status_t psa_key_derivation_input_key(
  6433. psa_key_derivation_operation_t *operation,
  6434. psa_key_derivation_step_t step,
  6435. mbedtls_svc_key_id_t key)
  6436. {
  6437. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6438. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  6439. psa_key_slot_t *slot;
  6440. status = psa_get_and_lock_transparent_key_slot_with_policy(
  6441. key, &slot, PSA_KEY_USAGE_DERIVE, operation->alg);
  6442. if (status != PSA_SUCCESS) {
  6443. psa_key_derivation_abort(operation);
  6444. return status;
  6445. }
  6446. /* Passing a key object as a SECRET or PASSWORD input unlocks the
  6447. * permission to output to a key object. */
  6448. if (step == PSA_KEY_DERIVATION_INPUT_SECRET ||
  6449. step == PSA_KEY_DERIVATION_INPUT_PASSWORD) {
  6450. operation->can_output_key = 1;
  6451. }
  6452. status = psa_key_derivation_input_internal(operation,
  6453. step, slot->attr.type,
  6454. slot->key.data,
  6455. slot->key.bytes);
  6456. unlock_status = psa_unregister_read_under_mutex(slot);
  6457. return (status == PSA_SUCCESS) ? unlock_status : status;
  6458. }
  6459. /****************************************************************/
  6460. /* Key agreement */
  6461. /****************************************************************/
  6462. psa_status_t psa_key_agreement_raw_builtin(const psa_key_attributes_t *attributes,
  6463. const uint8_t *key_buffer,
  6464. size_t key_buffer_size,
  6465. psa_algorithm_t alg,
  6466. const uint8_t *peer_key,
  6467. size_t peer_key_length,
  6468. uint8_t *shared_secret,
  6469. size_t shared_secret_size,
  6470. size_t *shared_secret_length)
  6471. {
  6472. switch (alg) {
  6473. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  6474. case PSA_ALG_ECDH:
  6475. return mbedtls_psa_key_agreement_ecdh(attributes, key_buffer,
  6476. key_buffer_size, alg,
  6477. peer_key, peer_key_length,
  6478. shared_secret,
  6479. shared_secret_size,
  6480. shared_secret_length);
  6481. #endif /* MBEDTLS_PSA_BUILTIN_ALG_ECDH */
  6482. #if defined(MBEDTLS_PSA_BUILTIN_ALG_FFDH)
  6483. case PSA_ALG_FFDH:
  6484. return mbedtls_psa_ffdh_key_agreement(attributes,
  6485. peer_key,
  6486. peer_key_length,
  6487. key_buffer,
  6488. key_buffer_size,
  6489. shared_secret,
  6490. shared_secret_size,
  6491. shared_secret_length);
  6492. #endif /* MBEDTLS_PSA_BUILTIN_ALG_FFDH */
  6493. default:
  6494. (void) attributes;
  6495. (void) key_buffer;
  6496. (void) key_buffer_size;
  6497. (void) peer_key;
  6498. (void) peer_key_length;
  6499. (void) shared_secret;
  6500. (void) shared_secret_size;
  6501. (void) shared_secret_length;
  6502. return PSA_ERROR_NOT_SUPPORTED;
  6503. }
  6504. }
  6505. /** Internal function for raw key agreement
  6506. * Calls the driver wrapper which will hand off key agreement task
  6507. * to the driver's implementation if a driver is present.
  6508. * Fallback specified in the driver wrapper is built-in raw key agreement
  6509. * (psa_key_agreement_raw_builtin).
  6510. */
  6511. static psa_status_t psa_key_agreement_raw_internal(psa_algorithm_t alg,
  6512. psa_key_slot_t *private_key,
  6513. const uint8_t *peer_key,
  6514. size_t peer_key_length,
  6515. uint8_t *shared_secret,
  6516. size_t shared_secret_size,
  6517. size_t *shared_secret_length)
  6518. {
  6519. if (!PSA_ALG_IS_RAW_KEY_AGREEMENT(alg)) {
  6520. return PSA_ERROR_NOT_SUPPORTED;
  6521. }
  6522. return psa_driver_wrapper_key_agreement(&private_key->attr,
  6523. private_key->key.data,
  6524. private_key->key.bytes, alg,
  6525. peer_key, peer_key_length,
  6526. shared_secret,
  6527. shared_secret_size,
  6528. shared_secret_length);
  6529. }
  6530. /* Note that if this function fails, you must call psa_key_derivation_abort()
  6531. * to potentially free embedded data structures and wipe confidential data.
  6532. */
  6533. static psa_status_t psa_key_agreement_internal(psa_key_derivation_operation_t *operation,
  6534. psa_key_derivation_step_t step,
  6535. psa_key_slot_t *private_key,
  6536. const uint8_t *peer_key,
  6537. size_t peer_key_length)
  6538. {
  6539. psa_status_t status;
  6540. uint8_t shared_secret[PSA_RAW_KEY_AGREEMENT_OUTPUT_MAX_SIZE] = { 0 };
  6541. size_t shared_secret_length = 0;
  6542. psa_algorithm_t ka_alg = PSA_ALG_KEY_AGREEMENT_GET_BASE(operation->alg);
  6543. /* Step 1: run the secret agreement algorithm to generate the shared
  6544. * secret. */
  6545. status = psa_key_agreement_raw_internal(ka_alg,
  6546. private_key,
  6547. peer_key, peer_key_length,
  6548. shared_secret,
  6549. sizeof(shared_secret),
  6550. &shared_secret_length);
  6551. if (status != PSA_SUCCESS) {
  6552. goto exit;
  6553. }
  6554. /* Step 2: set up the key derivation to generate key material from
  6555. * the shared secret. A shared secret is permitted wherever a key
  6556. * of type DERIVE is permitted. */
  6557. status = psa_key_derivation_input_internal(operation, step,
  6558. PSA_KEY_TYPE_DERIVE,
  6559. shared_secret,
  6560. shared_secret_length);
  6561. exit:
  6562. mbedtls_platform_zeroize(shared_secret, shared_secret_length);
  6563. return status;
  6564. }
  6565. psa_status_t psa_key_derivation_key_agreement(psa_key_derivation_operation_t *operation,
  6566. psa_key_derivation_step_t step,
  6567. mbedtls_svc_key_id_t private_key,
  6568. const uint8_t *peer_key_external,
  6569. size_t peer_key_length)
  6570. {
  6571. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6572. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  6573. psa_key_slot_t *slot;
  6574. LOCAL_INPUT_DECLARE(peer_key_external, peer_key);
  6575. if (!PSA_ALG_IS_KEY_AGREEMENT(operation->alg)) {
  6576. return PSA_ERROR_INVALID_ARGUMENT;
  6577. }
  6578. status = psa_get_and_lock_transparent_key_slot_with_policy(
  6579. private_key, &slot, PSA_KEY_USAGE_DERIVE, operation->alg);
  6580. if (status != PSA_SUCCESS) {
  6581. return status;
  6582. }
  6583. LOCAL_INPUT_ALLOC(peer_key_external, peer_key_length, peer_key);
  6584. status = psa_key_agreement_internal(operation, step,
  6585. slot,
  6586. peer_key, peer_key_length);
  6587. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  6588. exit:
  6589. #endif
  6590. if (status != PSA_SUCCESS) {
  6591. psa_key_derivation_abort(operation);
  6592. } else {
  6593. /* If a private key has been added as SECRET, we allow the derived
  6594. * key material to be used as a key in PSA Crypto. */
  6595. if (step == PSA_KEY_DERIVATION_INPUT_SECRET) {
  6596. operation->can_output_key = 1;
  6597. }
  6598. }
  6599. unlock_status = psa_unregister_read_under_mutex(slot);
  6600. LOCAL_INPUT_FREE(peer_key_external, peer_key);
  6601. return (status == PSA_SUCCESS) ? unlock_status : status;
  6602. }
  6603. psa_status_t psa_raw_key_agreement(psa_algorithm_t alg,
  6604. mbedtls_svc_key_id_t private_key,
  6605. const uint8_t *peer_key_external,
  6606. size_t peer_key_length,
  6607. uint8_t *output_external,
  6608. size_t output_size,
  6609. size_t *output_length)
  6610. {
  6611. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6612. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  6613. psa_key_slot_t *slot = NULL;
  6614. size_t expected_length;
  6615. LOCAL_INPUT_DECLARE(peer_key_external, peer_key);
  6616. LOCAL_OUTPUT_DECLARE(output_external, output);
  6617. LOCAL_OUTPUT_ALLOC(output_external, output_size, output);
  6618. if (!PSA_ALG_IS_KEY_AGREEMENT(alg)) {
  6619. status = PSA_ERROR_INVALID_ARGUMENT;
  6620. goto exit;
  6621. }
  6622. status = psa_get_and_lock_transparent_key_slot_with_policy(
  6623. private_key, &slot, PSA_KEY_USAGE_DERIVE, alg);
  6624. if (status != PSA_SUCCESS) {
  6625. goto exit;
  6626. }
  6627. /* PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE() is in general an upper bound
  6628. * for the output size. The PSA specification only guarantees that this
  6629. * function works if output_size >= PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE(...),
  6630. * but it might be nice to allow smaller buffers if the output fits.
  6631. * At the time of writing this comment, with only ECDH implemented,
  6632. * PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE() is exact so the point is moot.
  6633. * If FFDH is implemented, PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE() can easily
  6634. * be exact for it as well. */
  6635. expected_length =
  6636. PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE(slot->attr.type, slot->attr.bits);
  6637. if (output_size < expected_length) {
  6638. status = PSA_ERROR_BUFFER_TOO_SMALL;
  6639. goto exit;
  6640. }
  6641. LOCAL_INPUT_ALLOC(peer_key_external, peer_key_length, peer_key);
  6642. status = psa_key_agreement_raw_internal(alg, slot,
  6643. peer_key, peer_key_length,
  6644. output, output_size,
  6645. output_length);
  6646. exit:
  6647. /* Check for successful allocation of output,
  6648. * with an unsuccessful status. */
  6649. if (output != NULL && status != PSA_SUCCESS) {
  6650. /* If an error happens and is not handled properly, the output
  6651. * may be used as a key to protect sensitive data. Arrange for such
  6652. * a key to be random, which is likely to result in decryption or
  6653. * verification errors. This is better than filling the buffer with
  6654. * some constant data such as zeros, which would result in the data
  6655. * being protected with a reproducible, easily knowable key.
  6656. */
  6657. psa_generate_random_internal(output, output_size);
  6658. *output_length = output_size;
  6659. }
  6660. if (output == NULL) {
  6661. /* output allocation failed. */
  6662. *output_length = 0;
  6663. }
  6664. unlock_status = psa_unregister_read_under_mutex(slot);
  6665. LOCAL_INPUT_FREE(peer_key_external, peer_key);
  6666. LOCAL_OUTPUT_FREE(output_external, output);
  6667. return (status == PSA_SUCCESS) ? unlock_status : status;
  6668. }
  6669. /****************************************************************/
  6670. /* Random generation */
  6671. /****************************************************************/
  6672. #if defined(MBEDTLS_PSA_INJECT_ENTROPY)
  6673. #include "entropy_poll.h"
  6674. #endif
  6675. /** Initialize the PSA random generator.
  6676. *
  6677. * Note: the mbedtls_threading_psa_rngdata_mutex should be held when calling
  6678. * this function if mutexes are enabled.
  6679. */
  6680. static void mbedtls_psa_random_init(mbedtls_psa_random_context_t *rng)
  6681. {
  6682. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  6683. memset(rng, 0, sizeof(*rng));
  6684. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  6685. /* Set default configuration if
  6686. * mbedtls_psa_crypto_configure_entropy_sources() hasn't been called. */
  6687. if (rng->entropy_init == NULL) {
  6688. rng->entropy_init = mbedtls_entropy_init;
  6689. }
  6690. if (rng->entropy_free == NULL) {
  6691. rng->entropy_free = mbedtls_entropy_free;
  6692. }
  6693. rng->entropy_init(&rng->entropy);
  6694. #if defined(MBEDTLS_PSA_INJECT_ENTROPY) && \
  6695. defined(MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES)
  6696. /* The PSA entropy injection feature depends on using NV seed as an entropy
  6697. * source. Add NV seed as an entropy source for PSA entropy injection. */
  6698. mbedtls_entropy_add_source(&rng->entropy,
  6699. mbedtls_nv_seed_poll, NULL,
  6700. MBEDTLS_ENTROPY_BLOCK_SIZE,
  6701. MBEDTLS_ENTROPY_SOURCE_STRONG);
  6702. #endif
  6703. mbedtls_psa_drbg_init(&rng->drbg);
  6704. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  6705. }
  6706. /** Deinitialize the PSA random generator.
  6707. *
  6708. * Note: the mbedtls_threading_psa_rngdata_mutex should be held when calling
  6709. * this function if mutexes are enabled.
  6710. */
  6711. static void mbedtls_psa_random_free(mbedtls_psa_random_context_t *rng)
  6712. {
  6713. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  6714. memset(rng, 0, sizeof(*rng));
  6715. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  6716. mbedtls_psa_drbg_free(&rng->drbg);
  6717. rng->entropy_free(&rng->entropy);
  6718. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  6719. }
  6720. /** Seed the PSA random generator.
  6721. */
  6722. static psa_status_t mbedtls_psa_random_seed(mbedtls_psa_random_context_t *rng)
  6723. {
  6724. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  6725. /* Do nothing: the external RNG seeds itself. */
  6726. (void) rng;
  6727. return PSA_SUCCESS;
  6728. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  6729. const unsigned char drbg_seed[] = "PSA";
  6730. int ret = mbedtls_psa_drbg_seed(&rng->drbg, &rng->entropy,
  6731. drbg_seed, sizeof(drbg_seed) - 1);
  6732. return mbedtls_to_psa_error(ret);
  6733. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  6734. }
  6735. psa_status_t psa_generate_random(uint8_t *output_external,
  6736. size_t output_size)
  6737. {
  6738. psa_status_t status;
  6739. LOCAL_OUTPUT_DECLARE(output_external, output);
  6740. LOCAL_OUTPUT_ALLOC(output_external, output_size, output);
  6741. status = psa_generate_random_internal(output, output_size);
  6742. #if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)
  6743. exit:
  6744. #endif
  6745. LOCAL_OUTPUT_FREE(output_external, output);
  6746. return status;
  6747. }
  6748. #if defined(MBEDTLS_PSA_INJECT_ENTROPY)
  6749. psa_status_t mbedtls_psa_inject_entropy(const uint8_t *seed,
  6750. size_t seed_size)
  6751. {
  6752. if (psa_get_initialized()) {
  6753. return PSA_ERROR_NOT_PERMITTED;
  6754. }
  6755. if (((seed_size < MBEDTLS_ENTROPY_MIN_PLATFORM) ||
  6756. (seed_size < MBEDTLS_ENTROPY_BLOCK_SIZE)) ||
  6757. (seed_size > MBEDTLS_ENTROPY_MAX_SEED_SIZE)) {
  6758. return PSA_ERROR_INVALID_ARGUMENT;
  6759. }
  6760. return mbedtls_psa_storage_inject_entropy(seed, seed_size);
  6761. }
  6762. #endif /* MBEDTLS_PSA_INJECT_ENTROPY */
  6763. /** Validate the key type and size for key generation
  6764. *
  6765. * \param type The key type
  6766. * \param bits The number of bits of the key
  6767. *
  6768. * \retval #PSA_SUCCESS
  6769. * The key type and size are valid.
  6770. * \retval #PSA_ERROR_INVALID_ARGUMENT
  6771. * The size in bits of the key is not valid.
  6772. * \retval #PSA_ERROR_NOT_SUPPORTED
  6773. * The type and/or the size in bits of the key or the combination of
  6774. * the two is not supported.
  6775. */
  6776. static psa_status_t psa_validate_key_type_and_size_for_key_generation(
  6777. psa_key_type_t type, size_t bits)
  6778. {
  6779. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6780. if (key_type_is_raw_bytes(type)) {
  6781. status = psa_validate_unstructured_key_bit_size(type, bits);
  6782. if (status != PSA_SUCCESS) {
  6783. return status;
  6784. }
  6785. } else
  6786. #if defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE)
  6787. if (PSA_KEY_TYPE_IS_RSA(type) && PSA_KEY_TYPE_IS_KEY_PAIR(type)) {
  6788. if (bits > PSA_VENDOR_RSA_MAX_KEY_BITS) {
  6789. return PSA_ERROR_NOT_SUPPORTED;
  6790. }
  6791. if (bits < PSA_VENDOR_RSA_GENERATE_MIN_KEY_BITS) {
  6792. return PSA_ERROR_NOT_SUPPORTED;
  6793. }
  6794. /* Accept only byte-aligned keys, for the same reasons as
  6795. * in psa_import_rsa_key(). */
  6796. if (bits % 8 != 0) {
  6797. return PSA_ERROR_NOT_SUPPORTED;
  6798. }
  6799. } else
  6800. #endif /* defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE) */
  6801. #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_GENERATE)
  6802. if (PSA_KEY_TYPE_IS_ECC(type) && PSA_KEY_TYPE_IS_KEY_PAIR(type)) {
  6803. /* To avoid empty block, return successfully here. */
  6804. return PSA_SUCCESS;
  6805. } else
  6806. #endif /* defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_GENERATE) */
  6807. #if defined(PSA_WANT_KEY_TYPE_DH_KEY_PAIR_GENERATE)
  6808. if (PSA_KEY_TYPE_IS_DH(type) && PSA_KEY_TYPE_IS_KEY_PAIR(type)) {
  6809. if (psa_is_dh_key_size_valid(bits) == 0) {
  6810. return PSA_ERROR_NOT_SUPPORTED;
  6811. }
  6812. } else
  6813. #endif /* defined(PSA_WANT_KEY_TYPE_DH_KEY_PAIR_GENERATE) */
  6814. {
  6815. return PSA_ERROR_NOT_SUPPORTED;
  6816. }
  6817. return PSA_SUCCESS;
  6818. }
  6819. psa_status_t psa_generate_key_internal(
  6820. const psa_key_attributes_t *attributes,
  6821. const psa_custom_key_parameters_t *custom,
  6822. const uint8_t *custom_data,
  6823. size_t custom_data_length,
  6824. uint8_t *key_buffer, size_t key_buffer_size, size_t *key_buffer_length)
  6825. {
  6826. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6827. psa_key_type_t type = attributes->type;
  6828. /* Only used for RSA */
  6829. (void) custom;
  6830. (void) custom_data;
  6831. (void) custom_data_length;
  6832. if (key_type_is_raw_bytes(type)) {
  6833. status = psa_generate_random_internal(key_buffer, key_buffer_size);
  6834. if (status != PSA_SUCCESS) {
  6835. return status;
  6836. }
  6837. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  6838. if (type == PSA_KEY_TYPE_DES) {
  6839. psa_des_set_key_parity(key_buffer, key_buffer_size);
  6840. }
  6841. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  6842. } else
  6843. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_GENERATE)
  6844. if (type == PSA_KEY_TYPE_RSA_KEY_PAIR) {
  6845. return mbedtls_psa_rsa_generate_key(attributes,
  6846. custom_data, custom_data_length,
  6847. key_buffer,
  6848. key_buffer_size,
  6849. key_buffer_length);
  6850. } else
  6851. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_GENERATE) */
  6852. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_GENERATE)
  6853. if (PSA_KEY_TYPE_IS_ECC(type) && PSA_KEY_TYPE_IS_KEY_PAIR(type)) {
  6854. return mbedtls_psa_ecp_generate_key(attributes,
  6855. key_buffer,
  6856. key_buffer_size,
  6857. key_buffer_length);
  6858. } else
  6859. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_GENERATE) */
  6860. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_GENERATE)
  6861. if (PSA_KEY_TYPE_IS_DH(type) && PSA_KEY_TYPE_IS_KEY_PAIR(type)) {
  6862. return mbedtls_psa_ffdh_generate_key(attributes,
  6863. key_buffer,
  6864. key_buffer_size,
  6865. key_buffer_length);
  6866. } else
  6867. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_GENERATE) */
  6868. {
  6869. (void) key_buffer_length;
  6870. return PSA_ERROR_NOT_SUPPORTED;
  6871. }
  6872. return PSA_SUCCESS;
  6873. }
  6874. psa_status_t psa_generate_key_custom(const psa_key_attributes_t *attributes,
  6875. const psa_custom_key_parameters_t *custom,
  6876. const uint8_t *custom_data,
  6877. size_t custom_data_length,
  6878. mbedtls_svc_key_id_t *key)
  6879. {
  6880. psa_status_t status;
  6881. psa_key_slot_t *slot = NULL;
  6882. psa_se_drv_table_entry_t *driver = NULL;
  6883. size_t key_buffer_size;
  6884. *key = MBEDTLS_SVC_KEY_ID_INIT;
  6885. /* Reject any attempt to create a zero-length key so that we don't
  6886. * risk tripping up later, e.g. on a malloc(0) that returns NULL. */
  6887. if (psa_get_key_bits(attributes) == 0) {
  6888. return PSA_ERROR_INVALID_ARGUMENT;
  6889. }
  6890. /* Reject any attempt to create a public key. */
  6891. if (PSA_KEY_TYPE_IS_PUBLIC_KEY(attributes->type)) {
  6892. return PSA_ERROR_INVALID_ARGUMENT;
  6893. }
  6894. #if defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE)
  6895. if (attributes->type == PSA_KEY_TYPE_RSA_KEY_PAIR) {
  6896. if (custom->flags != 0) {
  6897. return PSA_ERROR_INVALID_ARGUMENT;
  6898. }
  6899. } else
  6900. #endif
  6901. if (!psa_custom_key_parameters_are_default(custom, custom_data_length)) {
  6902. return PSA_ERROR_INVALID_ARGUMENT;
  6903. }
  6904. status = psa_start_key_creation(PSA_KEY_CREATION_GENERATE, attributes,
  6905. &slot, &driver);
  6906. if (status != PSA_SUCCESS) {
  6907. goto exit;
  6908. }
  6909. /* In the case of a transparent key or an opaque key stored in local
  6910. * storage ( thus not in the case of generating a key in a secure element
  6911. * with storage ( MBEDTLS_PSA_CRYPTO_SE_C ) ),we have to allocate a
  6912. * buffer to hold the generated key material. */
  6913. if (slot->key.data == NULL) {
  6914. if (PSA_KEY_LIFETIME_GET_LOCATION(attributes->lifetime) ==
  6915. PSA_KEY_LOCATION_LOCAL_STORAGE) {
  6916. status = psa_validate_key_type_and_size_for_key_generation(
  6917. attributes->type, attributes->bits);
  6918. if (status != PSA_SUCCESS) {
  6919. goto exit;
  6920. }
  6921. key_buffer_size = PSA_EXPORT_KEY_OUTPUT_SIZE(
  6922. attributes->type,
  6923. attributes->bits);
  6924. } else {
  6925. status = psa_driver_wrapper_get_key_buffer_size(
  6926. attributes, &key_buffer_size);
  6927. if (status != PSA_SUCCESS) {
  6928. goto exit;
  6929. }
  6930. }
  6931. status = psa_allocate_buffer_to_slot(slot, key_buffer_size);
  6932. if (status != PSA_SUCCESS) {
  6933. goto exit;
  6934. }
  6935. }
  6936. status = psa_driver_wrapper_generate_key(attributes,
  6937. custom,
  6938. custom_data, custom_data_length,
  6939. slot->key.data, slot->key.bytes,
  6940. &slot->key.bytes);
  6941. if (status != PSA_SUCCESS) {
  6942. psa_remove_key_data_from_memory(slot);
  6943. }
  6944. exit:
  6945. if (status == PSA_SUCCESS) {
  6946. status = psa_finish_key_creation(slot, driver, key);
  6947. }
  6948. if (status != PSA_SUCCESS) {
  6949. psa_fail_key_creation(slot, driver);
  6950. }
  6951. return status;
  6952. }
  6953. psa_status_t psa_generate_key_ext(const psa_key_attributes_t *attributes,
  6954. const psa_key_production_parameters_t *params,
  6955. size_t params_data_length,
  6956. mbedtls_svc_key_id_t *key)
  6957. {
  6958. return psa_generate_key_custom(
  6959. attributes,
  6960. (const psa_custom_key_parameters_t *) params,
  6961. params->data, params_data_length,
  6962. key);
  6963. }
  6964. psa_status_t psa_generate_key(const psa_key_attributes_t *attributes,
  6965. mbedtls_svc_key_id_t *key)
  6966. {
  6967. return psa_generate_key_custom(attributes,
  6968. &default_custom_production,
  6969. NULL, 0,
  6970. key);
  6971. }
  6972. /****************************************************************/
  6973. /* Module setup */
  6974. /****************************************************************/
  6975. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  6976. psa_status_t mbedtls_psa_crypto_configure_entropy_sources(
  6977. void (* entropy_init)(mbedtls_entropy_context *ctx),
  6978. void (* entropy_free)(mbedtls_entropy_context *ctx))
  6979. {
  6980. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  6981. #if defined(MBEDTLS_THREADING_C)
  6982. mbedtls_mutex_lock(&mbedtls_threading_psa_rngdata_mutex);
  6983. #endif /* defined(MBEDTLS_THREADING_C) */
  6984. if (global_data.rng_state != RNG_NOT_INITIALIZED) {
  6985. status = PSA_ERROR_BAD_STATE;
  6986. } else {
  6987. global_data.rng.entropy_init = entropy_init;
  6988. global_data.rng.entropy_free = entropy_free;
  6989. status = PSA_SUCCESS;
  6990. }
  6991. #if defined(MBEDTLS_THREADING_C)
  6992. mbedtls_mutex_unlock(&mbedtls_threading_psa_rngdata_mutex);
  6993. #endif /* defined(MBEDTLS_THREADING_C) */
  6994. return status;
  6995. }
  6996. #endif /* !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) */
  6997. void mbedtls_psa_crypto_free(void)
  6998. {
  6999. #if defined(MBEDTLS_THREADING_C)
  7000. mbedtls_mutex_lock(&mbedtls_threading_psa_globaldata_mutex);
  7001. #endif /* defined(MBEDTLS_THREADING_C) */
  7002. /* Nothing to do to free transaction. */
  7003. if (global_data.initialized & PSA_CRYPTO_SUBSYSTEM_TRANSACTION_INITIALIZED) {
  7004. global_data.initialized &= ~PSA_CRYPTO_SUBSYSTEM_TRANSACTION_INITIALIZED;
  7005. }
  7006. if (global_data.initialized & PSA_CRYPTO_SUBSYSTEM_KEY_SLOTS_INITIALIZED) {
  7007. psa_wipe_all_key_slots();
  7008. global_data.initialized &= ~PSA_CRYPTO_SUBSYSTEM_KEY_SLOTS_INITIALIZED;
  7009. }
  7010. #if defined(MBEDTLS_THREADING_C)
  7011. mbedtls_mutex_unlock(&mbedtls_threading_psa_globaldata_mutex);
  7012. #endif /* defined(MBEDTLS_THREADING_C) */
  7013. #if defined(MBEDTLS_THREADING_C)
  7014. mbedtls_mutex_lock(&mbedtls_threading_psa_rngdata_mutex);
  7015. #endif /* defined(MBEDTLS_THREADING_C) */
  7016. if (global_data.rng_state != RNG_NOT_INITIALIZED) {
  7017. mbedtls_psa_random_free(&global_data.rng);
  7018. }
  7019. global_data.rng_state = RNG_NOT_INITIALIZED;
  7020. mbedtls_platform_zeroize(&global_data.rng, sizeof(global_data.rng));
  7021. #if defined(MBEDTLS_THREADING_C)
  7022. mbedtls_mutex_unlock(&mbedtls_threading_psa_rngdata_mutex);
  7023. #endif /* defined(MBEDTLS_THREADING_C) */
  7024. #if defined(MBEDTLS_THREADING_C)
  7025. mbedtls_mutex_lock(&mbedtls_threading_psa_globaldata_mutex);
  7026. #endif /* defined(MBEDTLS_THREADING_C) */
  7027. /* Terminate drivers */
  7028. if (global_data.initialized & PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS_INITIALIZED) {
  7029. psa_driver_wrapper_free();
  7030. global_data.initialized &= ~PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS_INITIALIZED;
  7031. }
  7032. #if defined(MBEDTLS_THREADING_C)
  7033. mbedtls_mutex_unlock(&mbedtls_threading_psa_globaldata_mutex);
  7034. #endif /* defined(MBEDTLS_THREADING_C) */
  7035. }
  7036. #if defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS)
  7037. /** Recover a transaction that was interrupted by a power failure.
  7038. *
  7039. * This function is called during initialization, before psa_crypto_init()
  7040. * returns. If this function returns a failure status, the initialization
  7041. * fails.
  7042. */
  7043. static psa_status_t psa_crypto_recover_transaction(
  7044. const psa_crypto_transaction_t *transaction)
  7045. {
  7046. switch (transaction->unknown.type) {
  7047. case PSA_CRYPTO_TRANSACTION_CREATE_KEY:
  7048. case PSA_CRYPTO_TRANSACTION_DESTROY_KEY:
  7049. /* TODO - fall through to the failure case until this
  7050. * is implemented.
  7051. * https://github.com/ARMmbed/mbed-crypto/issues/218
  7052. */
  7053. default:
  7054. /* We found an unsupported transaction in the storage.
  7055. * We don't know what state the storage is in. Give up. */
  7056. return PSA_ERROR_DATA_INVALID;
  7057. }
  7058. }
  7059. #endif /* PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS */
  7060. static psa_status_t mbedtls_psa_crypto_init_subsystem(mbedtls_psa_crypto_subsystem subsystem)
  7061. {
  7062. psa_status_t status = PSA_SUCCESS;
  7063. uint8_t driver_wrappers_initialized = 0;
  7064. switch (subsystem) {
  7065. case PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS:
  7066. #if defined(MBEDTLS_THREADING_C)
  7067. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_lock(&mbedtls_threading_psa_globaldata_mutex));
  7068. #endif /* defined(MBEDTLS_THREADING_C) */
  7069. if (!(global_data.initialized & PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS_INITIALIZED)) {
  7070. /* Init drivers */
  7071. status = psa_driver_wrapper_init();
  7072. /* Drivers need shutdown regardless of startup errors. */
  7073. global_data.initialized |= PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS_INITIALIZED;
  7074. }
  7075. #if defined(MBEDTLS_THREADING_C)
  7076. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_unlock(
  7077. &mbedtls_threading_psa_globaldata_mutex));
  7078. #endif /* defined(MBEDTLS_THREADING_C) */
  7079. break;
  7080. case PSA_CRYPTO_SUBSYSTEM_KEY_SLOTS:
  7081. #if defined(MBEDTLS_THREADING_C)
  7082. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_lock(&mbedtls_threading_psa_globaldata_mutex));
  7083. #endif /* defined(MBEDTLS_THREADING_C) */
  7084. if (!(global_data.initialized & PSA_CRYPTO_SUBSYSTEM_KEY_SLOTS_INITIALIZED)) {
  7085. status = psa_initialize_key_slots();
  7086. /* Need to wipe keys even if initialization fails. */
  7087. global_data.initialized |= PSA_CRYPTO_SUBSYSTEM_KEY_SLOTS_INITIALIZED;
  7088. }
  7089. #if defined(MBEDTLS_THREADING_C)
  7090. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_unlock(
  7091. &mbedtls_threading_psa_globaldata_mutex));
  7092. #endif /* defined(MBEDTLS_THREADING_C) */
  7093. break;
  7094. case PSA_CRYPTO_SUBSYSTEM_RNG:
  7095. #if defined(MBEDTLS_THREADING_C)
  7096. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_lock(&mbedtls_threading_psa_globaldata_mutex));
  7097. #endif /* defined(MBEDTLS_THREADING_C) */
  7098. driver_wrappers_initialized =
  7099. (global_data.initialized & PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS_INITIALIZED);
  7100. #if defined(MBEDTLS_THREADING_C)
  7101. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_unlock(
  7102. &mbedtls_threading_psa_globaldata_mutex));
  7103. #endif /* defined(MBEDTLS_THREADING_C) */
  7104. /* Need to use separate mutex here, as initialisation can require
  7105. * testing of init flags, which requires locking the global data
  7106. * mutex. */
  7107. #if defined(MBEDTLS_THREADING_C)
  7108. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_lock(&mbedtls_threading_psa_rngdata_mutex));
  7109. #endif /* defined(MBEDTLS_THREADING_C) */
  7110. /* Initialize and seed the random generator. */
  7111. if (global_data.rng_state == RNG_NOT_INITIALIZED && driver_wrappers_initialized) {
  7112. mbedtls_psa_random_init(&global_data.rng);
  7113. global_data.rng_state = RNG_INITIALIZED;
  7114. status = mbedtls_psa_random_seed(&global_data.rng);
  7115. if (status == PSA_SUCCESS) {
  7116. global_data.rng_state = RNG_SEEDED;
  7117. }
  7118. }
  7119. #if defined(MBEDTLS_THREADING_C)
  7120. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_unlock(
  7121. &mbedtls_threading_psa_rngdata_mutex));
  7122. #endif /* defined(MBEDTLS_THREADING_C) */
  7123. break;
  7124. case PSA_CRYPTO_SUBSYSTEM_TRANSACTION:
  7125. #if defined(MBEDTLS_THREADING_C)
  7126. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_lock(&mbedtls_threading_psa_globaldata_mutex));
  7127. #endif /* defined(MBEDTLS_THREADING_C) */
  7128. if (!(global_data.initialized & PSA_CRYPTO_SUBSYSTEM_TRANSACTION_INITIALIZED)) {
  7129. #if defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS)
  7130. status = psa_crypto_load_transaction();
  7131. if (status == PSA_SUCCESS) {
  7132. status = psa_crypto_recover_transaction(&psa_crypto_transaction);
  7133. if (status == PSA_SUCCESS) {
  7134. global_data.initialized |= PSA_CRYPTO_SUBSYSTEM_TRANSACTION_INITIALIZED;
  7135. }
  7136. status = psa_crypto_stop_transaction();
  7137. } else if (status == PSA_ERROR_DOES_NOT_EXIST) {
  7138. /* There's no transaction to complete. It's all good. */
  7139. global_data.initialized |= PSA_CRYPTO_SUBSYSTEM_TRANSACTION_INITIALIZED;
  7140. status = PSA_SUCCESS;
  7141. }
  7142. #else /* defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS) */
  7143. global_data.initialized |= PSA_CRYPTO_SUBSYSTEM_TRANSACTION_INITIALIZED;
  7144. status = PSA_SUCCESS;
  7145. #endif /* defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS) */
  7146. }
  7147. #if defined(MBEDTLS_THREADING_C)
  7148. PSA_THREADING_CHK_GOTO_EXIT(mbedtls_mutex_unlock(
  7149. &mbedtls_threading_psa_globaldata_mutex));
  7150. #endif /* defined(MBEDTLS_THREADING_C) */
  7151. break;
  7152. default:
  7153. status = PSA_ERROR_CORRUPTION_DETECTED;
  7154. }
  7155. /* Exit label only required when using threading macros. */
  7156. #if defined(MBEDTLS_THREADING_C)
  7157. exit:
  7158. #endif /* defined(MBEDTLS_THREADING_C) */
  7159. return status;
  7160. }
  7161. psa_status_t psa_crypto_init(void)
  7162. {
  7163. psa_status_t status;
  7164. /* Double initialization is explicitly allowed. Early out if everything is
  7165. * done. */
  7166. if (psa_get_initialized()) {
  7167. return PSA_SUCCESS;
  7168. }
  7169. status = mbedtls_psa_crypto_init_subsystem(PSA_CRYPTO_SUBSYSTEM_DRIVER_WRAPPERS);
  7170. if (status != PSA_SUCCESS) {
  7171. goto exit;
  7172. }
  7173. status = mbedtls_psa_crypto_init_subsystem(PSA_CRYPTO_SUBSYSTEM_KEY_SLOTS);
  7174. if (status != PSA_SUCCESS) {
  7175. goto exit;
  7176. }
  7177. status = mbedtls_psa_crypto_init_subsystem(PSA_CRYPTO_SUBSYSTEM_RNG);
  7178. if (status != PSA_SUCCESS) {
  7179. goto exit;
  7180. }
  7181. status = mbedtls_psa_crypto_init_subsystem(PSA_CRYPTO_SUBSYSTEM_TRANSACTION);
  7182. exit:
  7183. if (status != PSA_SUCCESS) {
  7184. mbedtls_psa_crypto_free();
  7185. }
  7186. return status;
  7187. }
  7188. #if defined(PSA_WANT_ALG_SOME_PAKE)
  7189. psa_status_t psa_crypto_driver_pake_get_password_len(
  7190. const psa_crypto_driver_pake_inputs_t *inputs,
  7191. size_t *password_len)
  7192. {
  7193. if (inputs->password_len == 0) {
  7194. return PSA_ERROR_BAD_STATE;
  7195. }
  7196. *password_len = inputs->password_len;
  7197. return PSA_SUCCESS;
  7198. }
  7199. psa_status_t psa_crypto_driver_pake_get_password(
  7200. const psa_crypto_driver_pake_inputs_t *inputs,
  7201. uint8_t *buffer, size_t buffer_size, size_t *buffer_length)
  7202. {
  7203. if (inputs->password_len == 0) {
  7204. return PSA_ERROR_BAD_STATE;
  7205. }
  7206. if (buffer_size < inputs->password_len) {
  7207. return PSA_ERROR_BUFFER_TOO_SMALL;
  7208. }
  7209. memcpy(buffer, inputs->password, inputs->password_len);
  7210. *buffer_length = inputs->password_len;
  7211. return PSA_SUCCESS;
  7212. }
  7213. psa_status_t psa_crypto_driver_pake_get_user_len(
  7214. const psa_crypto_driver_pake_inputs_t *inputs,
  7215. size_t *user_len)
  7216. {
  7217. if (inputs->user_len == 0) {
  7218. return PSA_ERROR_BAD_STATE;
  7219. }
  7220. *user_len = inputs->user_len;
  7221. return PSA_SUCCESS;
  7222. }
  7223. psa_status_t psa_crypto_driver_pake_get_user(
  7224. const psa_crypto_driver_pake_inputs_t *inputs,
  7225. uint8_t *user_id, size_t user_id_size, size_t *user_id_len)
  7226. {
  7227. if (inputs->user_len == 0) {
  7228. return PSA_ERROR_BAD_STATE;
  7229. }
  7230. if (user_id_size < inputs->user_len) {
  7231. return PSA_ERROR_BUFFER_TOO_SMALL;
  7232. }
  7233. memcpy(user_id, inputs->user, inputs->user_len);
  7234. *user_id_len = inputs->user_len;
  7235. return PSA_SUCCESS;
  7236. }
  7237. psa_status_t psa_crypto_driver_pake_get_peer_len(
  7238. const psa_crypto_driver_pake_inputs_t *inputs,
  7239. size_t *peer_len)
  7240. {
  7241. if (inputs->peer_len == 0) {
  7242. return PSA_ERROR_BAD_STATE;
  7243. }
  7244. *peer_len = inputs->peer_len;
  7245. return PSA_SUCCESS;
  7246. }
  7247. psa_status_t psa_crypto_driver_pake_get_peer(
  7248. const psa_crypto_driver_pake_inputs_t *inputs,
  7249. uint8_t *peer_id, size_t peer_id_size, size_t *peer_id_length)
  7250. {
  7251. if (inputs->peer_len == 0) {
  7252. return PSA_ERROR_BAD_STATE;
  7253. }
  7254. if (peer_id_size < inputs->peer_len) {
  7255. return PSA_ERROR_BUFFER_TOO_SMALL;
  7256. }
  7257. memcpy(peer_id, inputs->peer, inputs->peer_len);
  7258. *peer_id_length = inputs->peer_len;
  7259. return PSA_SUCCESS;
  7260. }
  7261. psa_status_t psa_crypto_driver_pake_get_cipher_suite(
  7262. const psa_crypto_driver_pake_inputs_t *inputs,
  7263. psa_pake_cipher_suite_t *cipher_suite)
  7264. {
  7265. if (inputs->cipher_suite.algorithm == PSA_ALG_NONE) {
  7266. return PSA_ERROR_BAD_STATE;
  7267. }
  7268. *cipher_suite = inputs->cipher_suite;
  7269. return PSA_SUCCESS;
  7270. }
  7271. psa_status_t psa_pake_setup(
  7272. psa_pake_operation_t *operation,
  7273. const psa_pake_cipher_suite_t *cipher_suite)
  7274. {
  7275. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  7276. if (operation->stage != PSA_PAKE_OPERATION_STAGE_SETUP) {
  7277. status = PSA_ERROR_BAD_STATE;
  7278. goto exit;
  7279. }
  7280. if (PSA_ALG_IS_PAKE(cipher_suite->algorithm) == 0 ||
  7281. PSA_ALG_IS_HASH(cipher_suite->hash) == 0) {
  7282. status = PSA_ERROR_INVALID_ARGUMENT;
  7283. goto exit;
  7284. }
  7285. memset(&operation->data.inputs, 0, sizeof(operation->data.inputs));
  7286. operation->alg = cipher_suite->algorithm;
  7287. operation->primitive = PSA_PAKE_PRIMITIVE(cipher_suite->type,
  7288. cipher_suite->family, cipher_suite->bits);
  7289. operation->data.inputs.cipher_suite = *cipher_suite;
  7290. #if defined(PSA_WANT_ALG_JPAKE)
  7291. if (operation->alg == PSA_ALG_JPAKE) {
  7292. psa_jpake_computation_stage_t *computation_stage =
  7293. &operation->computation_stage.jpake;
  7294. memset(computation_stage, 0, sizeof(*computation_stage));
  7295. computation_stage->step = PSA_PAKE_STEP_KEY_SHARE;
  7296. } else
  7297. #endif /* PSA_WANT_ALG_JPAKE */
  7298. {
  7299. status = PSA_ERROR_NOT_SUPPORTED;
  7300. goto exit;
  7301. }
  7302. operation->stage = PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS;
  7303. return PSA_SUCCESS;
  7304. exit:
  7305. psa_pake_abort(operation);
  7306. return status;
  7307. }
  7308. psa_status_t psa_pake_set_password_key(
  7309. psa_pake_operation_t *operation,
  7310. mbedtls_svc_key_id_t password)
  7311. {
  7312. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  7313. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  7314. psa_key_slot_t *slot = NULL;
  7315. psa_key_type_t type;
  7316. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  7317. status = PSA_ERROR_BAD_STATE;
  7318. goto exit;
  7319. }
  7320. status = psa_get_and_lock_key_slot_with_policy(password, &slot,
  7321. PSA_KEY_USAGE_DERIVE,
  7322. operation->alg);
  7323. if (status != PSA_SUCCESS) {
  7324. goto exit;
  7325. }
  7326. type = psa_get_key_type(&slot->attr);
  7327. if (type != PSA_KEY_TYPE_PASSWORD &&
  7328. type != PSA_KEY_TYPE_PASSWORD_HASH) {
  7329. status = PSA_ERROR_INVALID_ARGUMENT;
  7330. goto exit;
  7331. }
  7332. operation->data.inputs.password = mbedtls_calloc(1, slot->key.bytes);
  7333. if (operation->data.inputs.password == NULL) {
  7334. status = PSA_ERROR_INSUFFICIENT_MEMORY;
  7335. goto exit;
  7336. }
  7337. memcpy(operation->data.inputs.password, slot->key.data, slot->key.bytes);
  7338. operation->data.inputs.password_len = slot->key.bytes;
  7339. operation->data.inputs.attributes = slot->attr;
  7340. exit:
  7341. if (status != PSA_SUCCESS) {
  7342. psa_pake_abort(operation);
  7343. }
  7344. unlock_status = psa_unregister_read_under_mutex(slot);
  7345. return (status == PSA_SUCCESS) ? unlock_status : status;
  7346. }
  7347. psa_status_t psa_pake_set_user(
  7348. psa_pake_operation_t *operation,
  7349. const uint8_t *user_id_external,
  7350. size_t user_id_len)
  7351. {
  7352. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  7353. LOCAL_INPUT_DECLARE(user_id_external, user_id);
  7354. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  7355. status = PSA_ERROR_BAD_STATE;
  7356. goto exit;
  7357. }
  7358. if (user_id_len == 0) {
  7359. status = PSA_ERROR_INVALID_ARGUMENT;
  7360. goto exit;
  7361. }
  7362. if (operation->data.inputs.user_len != 0) {
  7363. status = PSA_ERROR_BAD_STATE;
  7364. goto exit;
  7365. }
  7366. operation->data.inputs.user = mbedtls_calloc(1, user_id_len);
  7367. if (operation->data.inputs.user == NULL) {
  7368. status = PSA_ERROR_INSUFFICIENT_MEMORY;
  7369. goto exit;
  7370. }
  7371. LOCAL_INPUT_ALLOC(user_id_external, user_id_len, user_id);
  7372. memcpy(operation->data.inputs.user, user_id, user_id_len);
  7373. operation->data.inputs.user_len = user_id_len;
  7374. status = PSA_SUCCESS;
  7375. exit:
  7376. LOCAL_INPUT_FREE(user_id_external, user_id);
  7377. if (status != PSA_SUCCESS) {
  7378. psa_pake_abort(operation);
  7379. }
  7380. return status;
  7381. }
  7382. psa_status_t psa_pake_set_peer(
  7383. psa_pake_operation_t *operation,
  7384. const uint8_t *peer_id_external,
  7385. size_t peer_id_len)
  7386. {
  7387. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  7388. LOCAL_INPUT_DECLARE(peer_id_external, peer_id);
  7389. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  7390. status = PSA_ERROR_BAD_STATE;
  7391. goto exit;
  7392. }
  7393. if (peer_id_len == 0) {
  7394. status = PSA_ERROR_INVALID_ARGUMENT;
  7395. goto exit;
  7396. }
  7397. if (operation->data.inputs.peer_len != 0) {
  7398. status = PSA_ERROR_BAD_STATE;
  7399. goto exit;
  7400. }
  7401. operation->data.inputs.peer = mbedtls_calloc(1, peer_id_len);
  7402. if (operation->data.inputs.peer == NULL) {
  7403. status = PSA_ERROR_INSUFFICIENT_MEMORY;
  7404. goto exit;
  7405. }
  7406. LOCAL_INPUT_ALLOC(peer_id_external, peer_id_len, peer_id);
  7407. memcpy(operation->data.inputs.peer, peer_id, peer_id_len);
  7408. operation->data.inputs.peer_len = peer_id_len;
  7409. status = PSA_SUCCESS;
  7410. exit:
  7411. LOCAL_INPUT_FREE(peer_id_external, peer_id);
  7412. if (status != PSA_SUCCESS) {
  7413. psa_pake_abort(operation);
  7414. }
  7415. return status;
  7416. }
  7417. psa_status_t psa_pake_set_role(
  7418. psa_pake_operation_t *operation,
  7419. psa_pake_role_t role)
  7420. {
  7421. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  7422. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  7423. status = PSA_ERROR_BAD_STATE;
  7424. goto exit;
  7425. }
  7426. switch (operation->alg) {
  7427. #if defined(PSA_WANT_ALG_JPAKE)
  7428. case PSA_ALG_JPAKE:
  7429. if (role == PSA_PAKE_ROLE_NONE) {
  7430. return PSA_SUCCESS;
  7431. }
  7432. status = PSA_ERROR_INVALID_ARGUMENT;
  7433. break;
  7434. #endif
  7435. default:
  7436. (void) role;
  7437. status = PSA_ERROR_NOT_SUPPORTED;
  7438. goto exit;
  7439. }
  7440. exit:
  7441. psa_pake_abort(operation);
  7442. return status;
  7443. }
  7444. /* Auxiliary function to convert core computation stage to single driver step. */
  7445. #if defined(PSA_WANT_ALG_JPAKE)
  7446. static psa_crypto_driver_pake_step_t convert_jpake_computation_stage_to_driver_step(
  7447. psa_jpake_computation_stage_t *stage)
  7448. {
  7449. psa_crypto_driver_pake_step_t key_share_step;
  7450. if (stage->round == PSA_JPAKE_FIRST) {
  7451. int is_x1;
  7452. if (stage->io_mode == PSA_JPAKE_OUTPUT) {
  7453. is_x1 = (stage->outputs < 1);
  7454. } else {
  7455. is_x1 = (stage->inputs < 1);
  7456. }
  7457. key_share_step = is_x1 ?
  7458. PSA_JPAKE_X1_STEP_KEY_SHARE :
  7459. PSA_JPAKE_X2_STEP_KEY_SHARE;
  7460. } else if (stage->round == PSA_JPAKE_SECOND) {
  7461. key_share_step = (stage->io_mode == PSA_JPAKE_OUTPUT) ?
  7462. PSA_JPAKE_X2S_STEP_KEY_SHARE :
  7463. PSA_JPAKE_X4S_STEP_KEY_SHARE;
  7464. } else {
  7465. return PSA_JPAKE_STEP_INVALID;
  7466. }
  7467. return (psa_crypto_driver_pake_step_t) (key_share_step + stage->step - PSA_PAKE_STEP_KEY_SHARE);
  7468. }
  7469. #endif /* PSA_WANT_ALG_JPAKE */
  7470. static psa_status_t psa_pake_complete_inputs(
  7471. psa_pake_operation_t *operation)
  7472. {
  7473. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  7474. /* Create copy of the inputs on stack as inputs share memory
  7475. with the driver context which will be setup by the driver. */
  7476. psa_crypto_driver_pake_inputs_t inputs = operation->data.inputs;
  7477. if (inputs.password_len == 0) {
  7478. return PSA_ERROR_BAD_STATE;
  7479. }
  7480. if (operation->alg == PSA_ALG_JPAKE) {
  7481. if (inputs.user_len == 0 || inputs.peer_len == 0) {
  7482. return PSA_ERROR_BAD_STATE;
  7483. }
  7484. }
  7485. /* Clear driver context */
  7486. mbedtls_platform_zeroize(&operation->data, sizeof(operation->data));
  7487. status = psa_driver_wrapper_pake_setup(operation, &inputs);
  7488. /* Driver is responsible for creating its own copy of the password. */
  7489. mbedtls_zeroize_and_free(inputs.password, inputs.password_len);
  7490. /* User and peer are translated to role. */
  7491. mbedtls_free(inputs.user);
  7492. mbedtls_free(inputs.peer);
  7493. if (status == PSA_SUCCESS) {
  7494. #if defined(PSA_WANT_ALG_JPAKE)
  7495. if (operation->alg == PSA_ALG_JPAKE) {
  7496. operation->stage = PSA_PAKE_OPERATION_STAGE_COMPUTATION;
  7497. } else
  7498. #endif /* PSA_WANT_ALG_JPAKE */
  7499. {
  7500. status = PSA_ERROR_NOT_SUPPORTED;
  7501. }
  7502. }
  7503. return status;
  7504. }
  7505. #if defined(PSA_WANT_ALG_JPAKE)
  7506. static psa_status_t psa_jpake_prologue(
  7507. psa_pake_operation_t *operation,
  7508. psa_pake_step_t step,
  7509. psa_jpake_io_mode_t io_mode)
  7510. {
  7511. if (step != PSA_PAKE_STEP_KEY_SHARE &&
  7512. step != PSA_PAKE_STEP_ZK_PUBLIC &&
  7513. step != PSA_PAKE_STEP_ZK_PROOF) {
  7514. return PSA_ERROR_INVALID_ARGUMENT;
  7515. }
  7516. psa_jpake_computation_stage_t *computation_stage =
  7517. &operation->computation_stage.jpake;
  7518. if (computation_stage->round != PSA_JPAKE_FIRST &&
  7519. computation_stage->round != PSA_JPAKE_SECOND) {
  7520. return PSA_ERROR_BAD_STATE;
  7521. }
  7522. /* Check that the step we are given is the one we were expecting */
  7523. if (step != computation_stage->step) {
  7524. return PSA_ERROR_BAD_STATE;
  7525. }
  7526. if (step == PSA_PAKE_STEP_KEY_SHARE &&
  7527. computation_stage->inputs == 0 &&
  7528. computation_stage->outputs == 0) {
  7529. /* Start of the round, so function decides whether we are inputting
  7530. * or outputting */
  7531. computation_stage->io_mode = io_mode;
  7532. } else if (computation_stage->io_mode != io_mode) {
  7533. /* Middle of the round so the mode we are in must match the function
  7534. * called by the user */
  7535. return PSA_ERROR_BAD_STATE;
  7536. }
  7537. return PSA_SUCCESS;
  7538. }
  7539. static psa_status_t psa_jpake_epilogue(
  7540. psa_pake_operation_t *operation,
  7541. psa_jpake_io_mode_t io_mode)
  7542. {
  7543. psa_jpake_computation_stage_t *stage =
  7544. &operation->computation_stage.jpake;
  7545. if (stage->step == PSA_PAKE_STEP_ZK_PROOF) {
  7546. /* End of an input/output */
  7547. if (io_mode == PSA_JPAKE_INPUT) {
  7548. stage->inputs++;
  7549. if (stage->inputs == PSA_JPAKE_EXPECTED_INPUTS(stage->round)) {
  7550. stage->io_mode = PSA_JPAKE_OUTPUT;
  7551. }
  7552. }
  7553. if (io_mode == PSA_JPAKE_OUTPUT) {
  7554. stage->outputs++;
  7555. if (stage->outputs == PSA_JPAKE_EXPECTED_OUTPUTS(stage->round)) {
  7556. stage->io_mode = PSA_JPAKE_INPUT;
  7557. }
  7558. }
  7559. if (stage->inputs == PSA_JPAKE_EXPECTED_INPUTS(stage->round) &&
  7560. stage->outputs == PSA_JPAKE_EXPECTED_OUTPUTS(stage->round)) {
  7561. /* End of a round, move to the next round */
  7562. stage->inputs = 0;
  7563. stage->outputs = 0;
  7564. stage->round++;
  7565. }
  7566. stage->step = PSA_PAKE_STEP_KEY_SHARE;
  7567. } else {
  7568. stage->step++;
  7569. }
  7570. return PSA_SUCCESS;
  7571. }
  7572. #endif /* PSA_WANT_ALG_JPAKE */
  7573. psa_status_t psa_pake_output(
  7574. psa_pake_operation_t *operation,
  7575. psa_pake_step_t step,
  7576. uint8_t *output_external,
  7577. size_t output_size,
  7578. size_t *output_length)
  7579. {
  7580. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  7581. psa_crypto_driver_pake_step_t driver_step = PSA_JPAKE_STEP_INVALID;
  7582. LOCAL_OUTPUT_DECLARE(output_external, output);
  7583. *output_length = 0;
  7584. if (operation->stage == PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  7585. status = psa_pake_complete_inputs(operation);
  7586. if (status != PSA_SUCCESS) {
  7587. goto exit;
  7588. }
  7589. }
  7590. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COMPUTATION) {
  7591. status = PSA_ERROR_BAD_STATE;
  7592. goto exit;
  7593. }
  7594. if (output_size == 0) {
  7595. status = PSA_ERROR_INVALID_ARGUMENT;
  7596. goto exit;
  7597. }
  7598. switch (operation->alg) {
  7599. #if defined(PSA_WANT_ALG_JPAKE)
  7600. case PSA_ALG_JPAKE:
  7601. status = psa_jpake_prologue(operation, step, PSA_JPAKE_OUTPUT);
  7602. if (status != PSA_SUCCESS) {
  7603. goto exit;
  7604. }
  7605. driver_step = convert_jpake_computation_stage_to_driver_step(
  7606. &operation->computation_stage.jpake);
  7607. break;
  7608. #endif /* PSA_WANT_ALG_JPAKE */
  7609. default:
  7610. (void) step;
  7611. status = PSA_ERROR_NOT_SUPPORTED;
  7612. goto exit;
  7613. }
  7614. LOCAL_OUTPUT_ALLOC(output_external, output_size, output);
  7615. status = psa_driver_wrapper_pake_output(operation, driver_step,
  7616. output, output_size, output_length);
  7617. if (status != PSA_SUCCESS) {
  7618. goto exit;
  7619. }
  7620. switch (operation->alg) {
  7621. #if defined(PSA_WANT_ALG_JPAKE)
  7622. case PSA_ALG_JPAKE:
  7623. status = psa_jpake_epilogue(operation, PSA_JPAKE_OUTPUT);
  7624. if (status != PSA_SUCCESS) {
  7625. goto exit;
  7626. }
  7627. break;
  7628. #endif /* PSA_WANT_ALG_JPAKE */
  7629. default:
  7630. status = PSA_ERROR_NOT_SUPPORTED;
  7631. goto exit;
  7632. }
  7633. exit:
  7634. LOCAL_OUTPUT_FREE(output_external, output);
  7635. if (status != PSA_SUCCESS) {
  7636. psa_pake_abort(operation);
  7637. }
  7638. return status;
  7639. }
  7640. psa_status_t psa_pake_input(
  7641. psa_pake_operation_t *operation,
  7642. psa_pake_step_t step,
  7643. const uint8_t *input_external,
  7644. size_t input_length)
  7645. {
  7646. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  7647. psa_crypto_driver_pake_step_t driver_step = PSA_JPAKE_STEP_INVALID;
  7648. const size_t max_input_length = (size_t) PSA_PAKE_INPUT_SIZE(operation->alg,
  7649. operation->primitive,
  7650. step);
  7651. LOCAL_INPUT_DECLARE(input_external, input);
  7652. if (operation->stage == PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  7653. status = psa_pake_complete_inputs(operation);
  7654. if (status != PSA_SUCCESS) {
  7655. goto exit;
  7656. }
  7657. }
  7658. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COMPUTATION) {
  7659. status = PSA_ERROR_BAD_STATE;
  7660. goto exit;
  7661. }
  7662. if (input_length == 0 || input_length > max_input_length) {
  7663. status = PSA_ERROR_INVALID_ARGUMENT;
  7664. goto exit;
  7665. }
  7666. switch (operation->alg) {
  7667. #if defined(PSA_WANT_ALG_JPAKE)
  7668. case PSA_ALG_JPAKE:
  7669. status = psa_jpake_prologue(operation, step, PSA_JPAKE_INPUT);
  7670. if (status != PSA_SUCCESS) {
  7671. goto exit;
  7672. }
  7673. driver_step = convert_jpake_computation_stage_to_driver_step(
  7674. &operation->computation_stage.jpake);
  7675. break;
  7676. #endif /* PSA_WANT_ALG_JPAKE */
  7677. default:
  7678. (void) step;
  7679. status = PSA_ERROR_NOT_SUPPORTED;
  7680. goto exit;
  7681. }
  7682. LOCAL_INPUT_ALLOC(input_external, input_length, input);
  7683. status = psa_driver_wrapper_pake_input(operation, driver_step,
  7684. input, input_length);
  7685. if (status != PSA_SUCCESS) {
  7686. goto exit;
  7687. }
  7688. switch (operation->alg) {
  7689. #if defined(PSA_WANT_ALG_JPAKE)
  7690. case PSA_ALG_JPAKE:
  7691. status = psa_jpake_epilogue(operation, PSA_JPAKE_INPUT);
  7692. if (status != PSA_SUCCESS) {
  7693. goto exit;
  7694. }
  7695. break;
  7696. #endif /* PSA_WANT_ALG_JPAKE */
  7697. default:
  7698. status = PSA_ERROR_NOT_SUPPORTED;
  7699. goto exit;
  7700. }
  7701. exit:
  7702. LOCAL_INPUT_FREE(input_external, input);
  7703. if (status != PSA_SUCCESS) {
  7704. psa_pake_abort(operation);
  7705. }
  7706. return status;
  7707. }
  7708. psa_status_t psa_pake_get_implicit_key(
  7709. psa_pake_operation_t *operation,
  7710. psa_key_derivation_operation_t *output)
  7711. {
  7712. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  7713. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  7714. uint8_t shared_key[MBEDTLS_PSA_JPAKE_BUFFER_SIZE];
  7715. size_t shared_key_len = 0;
  7716. if (operation->stage != PSA_PAKE_OPERATION_STAGE_COMPUTATION) {
  7717. status = PSA_ERROR_BAD_STATE;
  7718. goto exit;
  7719. }
  7720. #if defined(PSA_WANT_ALG_JPAKE)
  7721. if (operation->alg == PSA_ALG_JPAKE) {
  7722. psa_jpake_computation_stage_t *computation_stage =
  7723. &operation->computation_stage.jpake;
  7724. if (computation_stage->round != PSA_JPAKE_FINISHED) {
  7725. status = PSA_ERROR_BAD_STATE;
  7726. goto exit;
  7727. }
  7728. } else
  7729. #endif /* PSA_WANT_ALG_JPAKE */
  7730. {
  7731. status = PSA_ERROR_NOT_SUPPORTED;
  7732. goto exit;
  7733. }
  7734. status = psa_driver_wrapper_pake_get_implicit_key(operation,
  7735. shared_key,
  7736. sizeof(shared_key),
  7737. &shared_key_len);
  7738. if (status != PSA_SUCCESS) {
  7739. goto exit;
  7740. }
  7741. status = psa_key_derivation_input_bytes(output,
  7742. PSA_KEY_DERIVATION_INPUT_SECRET,
  7743. shared_key,
  7744. shared_key_len);
  7745. mbedtls_platform_zeroize(shared_key, sizeof(shared_key));
  7746. exit:
  7747. abort_status = psa_pake_abort(operation);
  7748. return status == PSA_SUCCESS ? abort_status : status;
  7749. }
  7750. psa_status_t psa_pake_abort(
  7751. psa_pake_operation_t *operation)
  7752. {
  7753. psa_status_t status = PSA_SUCCESS;
  7754. if (operation->stage == PSA_PAKE_OPERATION_STAGE_COMPUTATION) {
  7755. status = psa_driver_wrapper_pake_abort(operation);
  7756. }
  7757. if (operation->stage == PSA_PAKE_OPERATION_STAGE_COLLECT_INPUTS) {
  7758. if (operation->data.inputs.password != NULL) {
  7759. mbedtls_zeroize_and_free(operation->data.inputs.password,
  7760. operation->data.inputs.password_len);
  7761. }
  7762. if (operation->data.inputs.user != NULL) {
  7763. mbedtls_free(operation->data.inputs.user);
  7764. }
  7765. if (operation->data.inputs.peer != NULL) {
  7766. mbedtls_free(operation->data.inputs.peer);
  7767. }
  7768. }
  7769. memset(operation, 0, sizeof(psa_pake_operation_t));
  7770. return status;
  7771. }
  7772. #endif /* PSA_WANT_ALG_SOME_PAKE */
  7773. /* Memory copying test hooks. These are called before input copy, after input
  7774. * copy, before output copy and after output copy, respectively.
  7775. * They are used by memory-poisoning tests to temporarily unpoison buffers
  7776. * while they are copied. */
  7777. #if defined(MBEDTLS_TEST_HOOKS)
  7778. void (*psa_input_pre_copy_hook)(const uint8_t *input, size_t input_len) = NULL;
  7779. void (*psa_input_post_copy_hook)(const uint8_t *input, size_t input_len) = NULL;
  7780. void (*psa_output_pre_copy_hook)(const uint8_t *output, size_t output_len) = NULL;
  7781. void (*psa_output_post_copy_hook)(const uint8_t *output, size_t output_len) = NULL;
  7782. #endif
  7783. /** Copy from an input buffer to a local copy.
  7784. *
  7785. * \param[in] input Pointer to input buffer.
  7786. * \param[in] input_len Length of the input buffer.
  7787. * \param[out] input_copy Pointer to a local copy in which to store the input data.
  7788. * \param[out] input_copy_len Length of the local copy buffer.
  7789. * \return #PSA_SUCCESS, if the buffer was successfully
  7790. * copied.
  7791. * \return #PSA_ERROR_CORRUPTION_DETECTED, if the local
  7792. * copy is too small to hold contents of the
  7793. * input buffer.
  7794. */
  7795. MBEDTLS_STATIC_TESTABLE
  7796. psa_status_t psa_crypto_copy_input(const uint8_t *input, size_t input_len,
  7797. uint8_t *input_copy, size_t input_copy_len)
  7798. {
  7799. if (input_len > input_copy_len) {
  7800. return PSA_ERROR_CORRUPTION_DETECTED;
  7801. }
  7802. #if defined(MBEDTLS_TEST_HOOKS)
  7803. if (psa_input_pre_copy_hook != NULL) {
  7804. psa_input_pre_copy_hook(input, input_len);
  7805. }
  7806. #endif
  7807. if (input_len > 0) {
  7808. memcpy(input_copy, input, input_len);
  7809. }
  7810. #if defined(MBEDTLS_TEST_HOOKS)
  7811. if (psa_input_post_copy_hook != NULL) {
  7812. psa_input_post_copy_hook(input, input_len);
  7813. }
  7814. #endif
  7815. return PSA_SUCCESS;
  7816. }
  7817. /** Copy from a local output buffer into a user-supplied one.
  7818. *
  7819. * \param[in] output_copy Pointer to a local buffer containing the output.
  7820. * \param[in] output_copy_len Length of the local buffer.
  7821. * \param[out] output Pointer to user-supplied output buffer.
  7822. * \param[out] output_len Length of the user-supplied output buffer.
  7823. * \return #PSA_SUCCESS, if the buffer was successfully
  7824. * copied.
  7825. * \return #PSA_ERROR_BUFFER_TOO_SMALL, if the
  7826. * user-supplied output buffer is too small to
  7827. * hold the contents of the local buffer.
  7828. */
  7829. MBEDTLS_STATIC_TESTABLE
  7830. psa_status_t psa_crypto_copy_output(const uint8_t *output_copy, size_t output_copy_len,
  7831. uint8_t *output, size_t output_len)
  7832. {
  7833. if (output_len < output_copy_len) {
  7834. return PSA_ERROR_BUFFER_TOO_SMALL;
  7835. }
  7836. #if defined(MBEDTLS_TEST_HOOKS)
  7837. if (psa_output_pre_copy_hook != NULL) {
  7838. psa_output_pre_copy_hook(output, output_len);
  7839. }
  7840. #endif
  7841. if (output_copy_len > 0) {
  7842. memcpy(output, output_copy, output_copy_len);
  7843. }
  7844. #if defined(MBEDTLS_TEST_HOOKS)
  7845. if (psa_output_post_copy_hook != NULL) {
  7846. psa_output_post_copy_hook(output, output_len);
  7847. }
  7848. #endif
  7849. return PSA_SUCCESS;
  7850. }
  7851. psa_status_t psa_crypto_local_input_alloc(const uint8_t *input, size_t input_len,
  7852. psa_crypto_local_input_t *local_input)
  7853. {
  7854. psa_status_t status;
  7855. *local_input = PSA_CRYPTO_LOCAL_INPUT_INIT;
  7856. if (input_len == 0) {
  7857. return PSA_SUCCESS;
  7858. }
  7859. local_input->buffer = mbedtls_calloc(input_len, 1);
  7860. if (local_input->buffer == NULL) {
  7861. /* Since we dealt with the zero-length case above, we know that
  7862. * a NULL return value means a failure of allocation. */
  7863. return PSA_ERROR_INSUFFICIENT_MEMORY;
  7864. }
  7865. /* From now on, we must free local_input->buffer on error. */
  7866. local_input->length = input_len;
  7867. status = psa_crypto_copy_input(input, input_len,
  7868. local_input->buffer, local_input->length);
  7869. if (status != PSA_SUCCESS) {
  7870. goto error;
  7871. }
  7872. return PSA_SUCCESS;
  7873. error:
  7874. mbedtls_free(local_input->buffer);
  7875. local_input->buffer = NULL;
  7876. local_input->length = 0;
  7877. return status;
  7878. }
  7879. void psa_crypto_local_input_free(psa_crypto_local_input_t *local_input)
  7880. {
  7881. mbedtls_free(local_input->buffer);
  7882. local_input->buffer = NULL;
  7883. local_input->length = 0;
  7884. }
  7885. psa_status_t psa_crypto_local_output_alloc(uint8_t *output, size_t output_len,
  7886. psa_crypto_local_output_t *local_output)
  7887. {
  7888. *local_output = PSA_CRYPTO_LOCAL_OUTPUT_INIT;
  7889. if (output_len == 0) {
  7890. return PSA_SUCCESS;
  7891. }
  7892. local_output->buffer = mbedtls_calloc(output_len, 1);
  7893. if (local_output->buffer == NULL) {
  7894. /* Since we dealt with the zero-length case above, we know that
  7895. * a NULL return value means a failure of allocation. */
  7896. return PSA_ERROR_INSUFFICIENT_MEMORY;
  7897. }
  7898. local_output->length = output_len;
  7899. local_output->original = output;
  7900. return PSA_SUCCESS;
  7901. }
  7902. psa_status_t psa_crypto_local_output_free(psa_crypto_local_output_t *local_output)
  7903. {
  7904. psa_status_t status;
  7905. if (local_output->buffer == NULL) {
  7906. local_output->length = 0;
  7907. return PSA_SUCCESS;
  7908. }
  7909. if (local_output->original == NULL) {
  7910. /* We have an internal copy but nothing to copy back to. */
  7911. return PSA_ERROR_CORRUPTION_DETECTED;
  7912. }
  7913. status = psa_crypto_copy_output(local_output->buffer, local_output->length,
  7914. local_output->original, local_output->length);
  7915. if (status != PSA_SUCCESS) {
  7916. return status;
  7917. }
  7918. mbedtls_free(local_output->buffer);
  7919. local_output->buffer = NULL;
  7920. local_output->length = 0;
  7921. return PSA_SUCCESS;
  7922. }
  7923. #endif /* MBEDTLS_PSA_CRYPTO_C */