1*0957b409SSimon J. Gerraty /* 2*0957b409SSimon J. Gerraty * Copyright (c) 2016 Thomas Pornin <pornin@bolet.org> 3*0957b409SSimon J. Gerraty * 4*0957b409SSimon J. Gerraty * Permission is hereby granted, free of charge, to any person obtaining 5*0957b409SSimon J. Gerraty * a copy of this software and associated documentation files (the 6*0957b409SSimon J. Gerraty * "Software"), to deal in the Software without restriction, including 7*0957b409SSimon J. Gerraty * without limitation the rights to use, copy, modify, merge, publish, 8*0957b409SSimon J. Gerraty * distribute, sublicense, and/or sell copies of the Software, and to 9*0957b409SSimon J. Gerraty * permit persons to whom the Software is furnished to do so, subject to 10*0957b409SSimon J. Gerraty * the following conditions: 11*0957b409SSimon J. Gerraty * 12*0957b409SSimon J. Gerraty * The above copyright notice and this permission notice shall be 13*0957b409SSimon J. Gerraty * included in all copies or substantial portions of the Software. 14*0957b409SSimon J. Gerraty * 15*0957b409SSimon J. Gerraty * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, 16*0957b409SSimon J. Gerraty * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF 17*0957b409SSimon J. Gerraty * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND 18*0957b409SSimon J. Gerraty * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS 19*0957b409SSimon J. Gerraty * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN 20*0957b409SSimon J. Gerraty * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN 21*0957b409SSimon J. Gerraty * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE 22*0957b409SSimon J. Gerraty * SOFTWARE. 23*0957b409SSimon J. Gerraty */ 24*0957b409SSimon J. Gerraty 25*0957b409SSimon J. Gerraty #include "inner.h" 26*0957b409SSimon J. Gerraty 27*0957b409SSimon J. Gerraty /* 28*0957b409SSimon J. Gerraty * Compute ASN.1 encoded length for the provided integer. The ASN.1 29*0957b409SSimon J. Gerraty * encoding is signed, so its leading bit must have value 0; it must 30*0957b409SSimon J. Gerraty * also be of minimal length (so leading bytes of value 0 must be 31*0957b409SSimon J. Gerraty * removed, except if that would contradict the rule about the sign 32*0957b409SSimon J. Gerraty * bit). 33*0957b409SSimon J. Gerraty */ 34*0957b409SSimon J. Gerraty static size_t 35*0957b409SSimon J. Gerraty asn1_int_length(const unsigned char *x, size_t xlen) 36*0957b409SSimon J. Gerraty { 37*0957b409SSimon J. Gerraty while (xlen > 0 && *x == 0) { 38*0957b409SSimon J. Gerraty x ++; 39*0957b409SSimon J. Gerraty xlen --; 40*0957b409SSimon J. Gerraty } 41*0957b409SSimon J. Gerraty if (xlen == 0 || *x >= 0x80) { 42*0957b409SSimon J. Gerraty xlen ++; 43*0957b409SSimon J. Gerraty } 44*0957b409SSimon J. Gerraty return xlen; 45*0957b409SSimon J. Gerraty } 46*0957b409SSimon J. Gerraty 47*0957b409SSimon J. Gerraty /* see bearssl_ec.h */ 48*0957b409SSimon J. Gerraty size_t 49*0957b409SSimon J. Gerraty br_ecdsa_raw_to_asn1(void *sig, size_t sig_len) 50*0957b409SSimon J. Gerraty { 51*0957b409SSimon J. Gerraty /* 52*0957b409SSimon J. Gerraty * Internal buffer is large enough to accommodate a signature 53*0957b409SSimon J. Gerraty * such that r and s fit on 125 bytes each (signed encoding), 54*0957b409SSimon J. Gerraty * meaning a curve order of up to 999 bits. This is the limit 55*0957b409SSimon J. Gerraty * that ensures "simple" length encodings. 56*0957b409SSimon J. Gerraty */ 57*0957b409SSimon J. Gerraty unsigned char *buf; 58*0957b409SSimon J. Gerraty size_t hlen, rlen, slen, zlen, off; 59*0957b409SSimon J. Gerraty unsigned char tmp[257]; 60*0957b409SSimon J. Gerraty 61*0957b409SSimon J. Gerraty buf = sig; 62*0957b409SSimon J. Gerraty if ((sig_len & 1) != 0) { 63*0957b409SSimon J. Gerraty return 0; 64*0957b409SSimon J. Gerraty } 65*0957b409SSimon J. Gerraty 66*0957b409SSimon J. Gerraty /* 67*0957b409SSimon J. Gerraty * Compute lengths for the two integers. 68*0957b409SSimon J. Gerraty */ 69*0957b409SSimon J. Gerraty hlen = sig_len >> 1; 70*0957b409SSimon J. Gerraty rlen = asn1_int_length(buf, hlen); 71*0957b409SSimon J. Gerraty slen = asn1_int_length(buf + hlen, hlen); 72*0957b409SSimon J. Gerraty if (rlen > 125 || slen > 125) { 73*0957b409SSimon J. Gerraty return 0; 74*0957b409SSimon J. Gerraty } 75*0957b409SSimon J. Gerraty 76*0957b409SSimon J. Gerraty /* 77*0957b409SSimon J. Gerraty * SEQUENCE header. 78*0957b409SSimon J. Gerraty */ 79*0957b409SSimon J. Gerraty tmp[0] = 0x30; 80*0957b409SSimon J. Gerraty zlen = rlen + slen + 4; 81*0957b409SSimon J. Gerraty if (zlen >= 0x80) { 82*0957b409SSimon J. Gerraty tmp[1] = 0x81; 83*0957b409SSimon J. Gerraty tmp[2] = zlen; 84*0957b409SSimon J. Gerraty off = 3; 85*0957b409SSimon J. Gerraty } else { 86*0957b409SSimon J. Gerraty tmp[1] = zlen; 87*0957b409SSimon J. Gerraty off = 2; 88*0957b409SSimon J. Gerraty } 89*0957b409SSimon J. Gerraty 90*0957b409SSimon J. Gerraty /* 91*0957b409SSimon J. Gerraty * First INTEGER (r). 92*0957b409SSimon J. Gerraty */ 93*0957b409SSimon J. Gerraty tmp[off ++] = 0x02; 94*0957b409SSimon J. Gerraty tmp[off ++] = rlen; 95*0957b409SSimon J. Gerraty if (rlen > hlen) { 96*0957b409SSimon J. Gerraty tmp[off] = 0x00; 97*0957b409SSimon J. Gerraty memcpy(tmp + off + 1, buf, hlen); 98*0957b409SSimon J. Gerraty } else { 99*0957b409SSimon J. Gerraty memcpy(tmp + off, buf + hlen - rlen, rlen); 100*0957b409SSimon J. Gerraty } 101*0957b409SSimon J. Gerraty off += rlen; 102*0957b409SSimon J. Gerraty 103*0957b409SSimon J. Gerraty /* 104*0957b409SSimon J. Gerraty * Second INTEGER (s). 105*0957b409SSimon J. Gerraty */ 106*0957b409SSimon J. Gerraty tmp[off ++] = 0x02; 107*0957b409SSimon J. Gerraty tmp[off ++] = slen; 108*0957b409SSimon J. Gerraty if (slen > hlen) { 109*0957b409SSimon J. Gerraty tmp[off] = 0x00; 110*0957b409SSimon J. Gerraty memcpy(tmp + off + 1, buf + hlen, hlen); 111*0957b409SSimon J. Gerraty } else { 112*0957b409SSimon J. Gerraty memcpy(tmp + off, buf + sig_len - slen, slen); 113*0957b409SSimon J. Gerraty } 114*0957b409SSimon J. Gerraty off += slen; 115*0957b409SSimon J. Gerraty 116*0957b409SSimon J. Gerraty /* 117*0957b409SSimon J. Gerraty * Return ASN.1 signature. 118*0957b409SSimon J. Gerraty */ 119*0957b409SSimon J. Gerraty memcpy(sig, tmp, off); 120*0957b409SSimon J. Gerraty return off; 121*0957b409SSimon J. Gerraty } 122