xref: /freebsd/crypto/libecc/src/sig/decdsa.c (revision f0865ec9906d5a18fa2a3b61381f22ce16e606ad)
1*f0865ec9SKyle Evans /*
2*f0865ec9SKyle Evans  *  Copyright (C) 2017 - This file is part of libecc project
3*f0865ec9SKyle Evans  *
4*f0865ec9SKyle Evans  *  Authors:
5*f0865ec9SKyle Evans  *      Ryad BENADJILA <ryadbenadjila@gmail.com>
6*f0865ec9SKyle Evans  *      Arnaud EBALARD <arnaud.ebalard@ssi.gouv.fr>
7*f0865ec9SKyle Evans  *      Jean-Pierre FLORI <jean-pierre.flori@ssi.gouv.fr>
8*f0865ec9SKyle Evans  *
9*f0865ec9SKyle Evans  *  Contributors:
10*f0865ec9SKyle Evans  *      Nicolas VIVET <nicolas.vivet@ssi.gouv.fr>
11*f0865ec9SKyle Evans  *      Karim KHALFALLAH <karim.khalfallah@ssi.gouv.fr>
12*f0865ec9SKyle Evans  *
13*f0865ec9SKyle Evans  *  This software is licensed under a dual BSD and GPL v2 license.
14*f0865ec9SKyle Evans  *  See LICENSE file at the root folder of the project.
15*f0865ec9SKyle Evans  */
16*f0865ec9SKyle Evans #include <libecc/lib_ecc_config.h>
17*f0865ec9SKyle Evans #ifdef WITH_SIG_DECDSA
18*f0865ec9SKyle Evans 
19*f0865ec9SKyle Evans #if !defined(WITH_HMAC)
20*f0865ec9SKyle Evans #error "DECDSA signature needs HMAC, please activate it!"
21*f0865ec9SKyle Evans #endif
22*f0865ec9SKyle Evans #include <libecc/hash/hmac.h>
23*f0865ec9SKyle Evans 
24*f0865ec9SKyle Evans #include <libecc/nn/nn_rand.h>
25*f0865ec9SKyle Evans #include <libecc/nn/nn_mul_public.h>
26*f0865ec9SKyle Evans #include <libecc/nn/nn_logical.h>
27*f0865ec9SKyle Evans 
28*f0865ec9SKyle Evans #include <libecc/sig/sig_algs_internal.h>
29*f0865ec9SKyle Evans #include <libecc/sig/ec_key.h>
30*f0865ec9SKyle Evans #include <libecc/utils/utils.h>
31*f0865ec9SKyle Evans #ifdef VERBOSE_INNER_VALUES
32*f0865ec9SKyle Evans #define EC_SIG_ALG "DECDSA"
33*f0865ec9SKyle Evans #endif
34*f0865ec9SKyle Evans #include <libecc/utils/dbg_sig.h>
35*f0865ec9SKyle Evans 
decdsa_init_pub_key(ec_pub_key * out_pub,const ec_priv_key * in_priv)36*f0865ec9SKyle Evans int decdsa_init_pub_key(ec_pub_key *out_pub, const ec_priv_key *in_priv)
37*f0865ec9SKyle Evans {
38*f0865ec9SKyle Evans 	return __ecdsa_init_pub_key(out_pub, in_priv, DECDSA);
39*f0865ec9SKyle Evans }
40*f0865ec9SKyle Evans 
decdsa_siglen(u16 p_bit_len,u16 q_bit_len,u8 hsize,u8 blocksize,u8 * siglen)41*f0865ec9SKyle Evans int decdsa_siglen(u16 p_bit_len, u16 q_bit_len, u8 hsize, u8 blocksize, u8 *siglen)
42*f0865ec9SKyle Evans {
43*f0865ec9SKyle Evans 	return __ecdsa_siglen(p_bit_len, q_bit_len, hsize, blocksize, siglen);
44*f0865ec9SKyle Evans }
45*f0865ec9SKyle Evans 
_decdsa_sign_init(struct ec_sign_context * ctx)46*f0865ec9SKyle Evans int _decdsa_sign_init(struct ec_sign_context *ctx)
47*f0865ec9SKyle Evans {
48*f0865ec9SKyle Evans 	int ret;
49*f0865ec9SKyle Evans 
50*f0865ec9SKyle Evans 	/* Override our random source with NULL since we want a deterministic
51*f0865ec9SKyle Evans 	 * generation.
52*f0865ec9SKyle Evans 	 */
53*f0865ec9SKyle Evans 	MUST_HAVE((ctx != NULL), ret, err);
54*f0865ec9SKyle Evans 
55*f0865ec9SKyle Evans 	ctx->rand = NULL;
56*f0865ec9SKyle Evans 	ret =  __ecdsa_sign_init(ctx, DECDSA);
57*f0865ec9SKyle Evans 
58*f0865ec9SKyle Evans err:
59*f0865ec9SKyle Evans 	return ret;
60*f0865ec9SKyle Evans }
61*f0865ec9SKyle Evans 
_decdsa_sign_update(struct ec_sign_context * ctx,const u8 * chunk,u32 chunklen)62*f0865ec9SKyle Evans int _decdsa_sign_update(struct ec_sign_context *ctx,
63*f0865ec9SKyle Evans 		       const u8 *chunk, u32 chunklen)
64*f0865ec9SKyle Evans {
65*f0865ec9SKyle Evans 	int ret;
66*f0865ec9SKyle Evans 
67*f0865ec9SKyle Evans 	/* NOTE: for deterministic ECDSA, the random source MUST be NULL, hence
68*f0865ec9SKyle Evans 	 * the following check.
69*f0865ec9SKyle Evans 	 */
70*f0865ec9SKyle Evans 	MUST_HAVE((ctx != NULL) && (ctx->rand == NULL), ret, err);
71*f0865ec9SKyle Evans 
72*f0865ec9SKyle Evans 	ret = __ecdsa_sign_update(ctx, chunk, chunklen, DECDSA);
73*f0865ec9SKyle Evans 
74*f0865ec9SKyle Evans err:
75*f0865ec9SKyle Evans 	return ret;
76*f0865ec9SKyle Evans }
77*f0865ec9SKyle Evans 
_decdsa_sign_finalize(struct ec_sign_context * ctx,u8 * sig,u8 siglen)78*f0865ec9SKyle Evans int _decdsa_sign_finalize(struct ec_sign_context *ctx, u8 *sig, u8 siglen)
79*f0865ec9SKyle Evans {
80*f0865ec9SKyle Evans 	int ret;
81*f0865ec9SKyle Evans 
82*f0865ec9SKyle Evans 	/* NOTE: for deterministic ECDSA, the random source MUST be NULL, hence
83*f0865ec9SKyle Evans 	 * the following check.
84*f0865ec9SKyle Evans 	 */
85*f0865ec9SKyle Evans 	MUST_HAVE((ctx != NULL) && (ctx->rand == NULL), ret, err);
86*f0865ec9SKyle Evans 
87*f0865ec9SKyle Evans 	ret =  __ecdsa_sign_finalize(ctx, sig, siglen, DECDSA);
88*f0865ec9SKyle Evans 
89*f0865ec9SKyle Evans err:
90*f0865ec9SKyle Evans 	return ret;
91*f0865ec9SKyle Evans }
92*f0865ec9SKyle Evans 
_decdsa_verify_init(struct ec_verify_context * ctx,const u8 * sig,u8 siglen)93*f0865ec9SKyle Evans int _decdsa_verify_init(struct ec_verify_context *ctx, const u8 *sig, u8 siglen)
94*f0865ec9SKyle Evans {
95*f0865ec9SKyle Evans 	return __ecdsa_verify_init(ctx, sig, siglen, DECDSA);
96*f0865ec9SKyle Evans }
97*f0865ec9SKyle Evans 
_decdsa_verify_update(struct ec_verify_context * ctx,const u8 * chunk,u32 chunklen)98*f0865ec9SKyle Evans int _decdsa_verify_update(struct ec_verify_context *ctx,
99*f0865ec9SKyle Evans 			 const u8 *chunk, u32 chunklen)
100*f0865ec9SKyle Evans {
101*f0865ec9SKyle Evans 	return __ecdsa_verify_update(ctx, chunk, chunklen, DECDSA);
102*f0865ec9SKyle Evans }
103*f0865ec9SKyle Evans 
_decdsa_verify_finalize(struct ec_verify_context * ctx)104*f0865ec9SKyle Evans int _decdsa_verify_finalize(struct ec_verify_context *ctx)
105*f0865ec9SKyle Evans {
106*f0865ec9SKyle Evans 	return __ecdsa_verify_finalize(ctx, DECDSA);
107*f0865ec9SKyle Evans }
108*f0865ec9SKyle Evans 
decdsa_public_key_from_sig(ec_pub_key * out_pub1,ec_pub_key * out_pub2,const ec_params * params,const u8 * sig,u8 siglen,const u8 * hash,u8 hsize)109*f0865ec9SKyle Evans int decdsa_public_key_from_sig(ec_pub_key *out_pub1, ec_pub_key *out_pub2, const ec_params *params,
110*f0865ec9SKyle Evans                               const u8 *sig, u8 siglen, const u8 *hash, u8 hsize)
111*f0865ec9SKyle Evans {
112*f0865ec9SKyle Evans 	return __ecdsa_public_key_from_sig(out_pub1, out_pub2, params, sig, siglen, hash, hsize, DECDSA);
113*f0865ec9SKyle Evans }
114*f0865ec9SKyle Evans 
115*f0865ec9SKyle Evans #else /* WITH_SIG_DECDSA */
116*f0865ec9SKyle Evans 
117*f0865ec9SKyle Evans /*
118*f0865ec9SKyle Evans  * Dummy definition to avoid the empty translation unit ISO C warning
119*f0865ec9SKyle Evans  */
120*f0865ec9SKyle Evans typedef int dummy;
121*f0865ec9SKyle Evans #endif /* WITH_SIG_DECDSA */
122