17c478bd9Sstevel@tonic-gate /*
27c478bd9Sstevel@tonic-gate * CDDL HEADER START
37c478bd9Sstevel@tonic-gate *
47c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the
5b60f2a0bSfr41279 * Common Development and Distribution License (the "License").
6b60f2a0bSfr41279 * You may not use this file except in compliance with the License.
77c478bd9Sstevel@tonic-gate *
87c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
97c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing.
107c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions
117c478bd9Sstevel@tonic-gate * and limitations under the License.
127c478bd9Sstevel@tonic-gate *
137c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each
147c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
157c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the
167c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying
177c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner]
187c478bd9Sstevel@tonic-gate *
197c478bd9Sstevel@tonic-gate * CDDL HEADER END
207c478bd9Sstevel@tonic-gate */
217c478bd9Sstevel@tonic-gate
22726fad2aSDina K Nimeh /*
23726fad2aSDina K Nimeh * Copyright (c) 2003, 2010, Oracle and/or its affiliates. All rights reserved.
24726fad2aSDina K Nimeh */
257c478bd9Sstevel@tonic-gate
267c478bd9Sstevel@tonic-gate #include <stdlib.h>
277c478bd9Sstevel@tonic-gate #include <string.h>
287c478bd9Sstevel@tonic-gate #include <strings.h>
297c478bd9Sstevel@tonic-gate #include <sys/types.h>
307c478bd9Sstevel@tonic-gate #include <security/cryptoki.h>
3123c57df7Smcpowers #include <sys/crypto/common.h>
327c478bd9Sstevel@tonic-gate #include <des_impl.h>
33726fad2aSDina K Nimeh #include <cryptoutil.h>
347c478bd9Sstevel@tonic-gate #include "softGlobal.h"
357c478bd9Sstevel@tonic-gate #include "softSession.h"
367c478bd9Sstevel@tonic-gate #include "softObject.h"
377c478bd9Sstevel@tonic-gate #include "softDH.h"
387c478bd9Sstevel@tonic-gate #include "softCrypt.h"
397c478bd9Sstevel@tonic-gate
407c478bd9Sstevel@tonic-gate
417c478bd9Sstevel@tonic-gate /*
42726fad2aSDina K Nimeh * This function takes a converted big integer of the specified attribute
43726fad2aSDina K Nimeh * as an octet string and stores it in the corresponding key object.
447c478bd9Sstevel@tonic-gate */
45726fad2aSDina K Nimeh static CK_RV
soft_genDHkey_set_attribute(soft_object_t * key,CK_ATTRIBUTE_TYPE type,uchar_t * buf,uint32_t buflen,boolean_t public)46726fad2aSDina K Nimeh soft_genDHkey_set_attribute(soft_object_t *key, CK_ATTRIBUTE_TYPE type,
47726fad2aSDina K Nimeh uchar_t *buf, uint32_t buflen, boolean_t public)
487c478bd9Sstevel@tonic-gate {
497c478bd9Sstevel@tonic-gate
507c478bd9Sstevel@tonic-gate CK_RV rv = CKR_OK;
517c478bd9Sstevel@tonic-gate biginteger_t *dst = NULL;
527c478bd9Sstevel@tonic-gate biginteger_t src;
537c478bd9Sstevel@tonic-gate
547c478bd9Sstevel@tonic-gate switch (type) {
557c478bd9Sstevel@tonic-gate
567c478bd9Sstevel@tonic-gate case CKA_VALUE:
577c478bd9Sstevel@tonic-gate if (public)
587c478bd9Sstevel@tonic-gate dst = OBJ_PUB_DH_VALUE(key);
597c478bd9Sstevel@tonic-gate else
607c478bd9Sstevel@tonic-gate dst = OBJ_PRI_DH_VALUE(key);
617c478bd9Sstevel@tonic-gate break;
627c478bd9Sstevel@tonic-gate
637c478bd9Sstevel@tonic-gate case CKA_PRIME:
647c478bd9Sstevel@tonic-gate dst = OBJ_PRI_DH_PRIME(key);
657c478bd9Sstevel@tonic-gate break;
667c478bd9Sstevel@tonic-gate
677c478bd9Sstevel@tonic-gate case CKA_BASE:
687c478bd9Sstevel@tonic-gate dst = OBJ_PRI_DH_BASE(key);
697c478bd9Sstevel@tonic-gate break;
707c478bd9Sstevel@tonic-gate }
717c478bd9Sstevel@tonic-gate
72726fad2aSDina K Nimeh if ((rv = dup_bigint_attr(&src, buf, buflen)) != CKR_OK)
737c478bd9Sstevel@tonic-gate goto cleanexit;
747c478bd9Sstevel@tonic-gate
757c478bd9Sstevel@tonic-gate /* Copy the attribute in the key object. */
767c478bd9Sstevel@tonic-gate copy_bigint_attr(&src, dst);
777c478bd9Sstevel@tonic-gate
787c478bd9Sstevel@tonic-gate cleanexit:
79726fad2aSDina K Nimeh /* No need to free big_value because dst holds it now after copy. */
807c478bd9Sstevel@tonic-gate return (rv);
817c478bd9Sstevel@tonic-gate
827c478bd9Sstevel@tonic-gate }
837c478bd9Sstevel@tonic-gate
847c478bd9Sstevel@tonic-gate /*
857c478bd9Sstevel@tonic-gate * This function covers the DH Key agreement.
867c478bd9Sstevel@tonic-gate */
877c478bd9Sstevel@tonic-gate CK_RV
soft_dh_genkey_pair(soft_object_t * pubkey,soft_object_t * prikey)887c478bd9Sstevel@tonic-gate soft_dh_genkey_pair(soft_object_t *pubkey, soft_object_t *prikey)
897c478bd9Sstevel@tonic-gate {
907c478bd9Sstevel@tonic-gate CK_RV rv;
91726fad2aSDina K Nimeh CK_ATTRIBUTE template;
927c478bd9Sstevel@tonic-gate uchar_t prime[MAX_KEY_ATTR_BUFLEN];
937c478bd9Sstevel@tonic-gate uint32_t prime_len = sizeof (prime);
947c478bd9Sstevel@tonic-gate uchar_t base[MAX_KEY_ATTR_BUFLEN];
957c478bd9Sstevel@tonic-gate uint32_t base_len = sizeof (base);
96726fad2aSDina K Nimeh uint32_t value_bits;
97726fad2aSDina K Nimeh uchar_t private_x[MAX_KEY_ATTR_BUFLEN];
98726fad2aSDina K Nimeh uchar_t public_y[MAX_KEY_ATTR_BUFLEN];
99726fad2aSDina K Nimeh DHbytekey k;
1007c478bd9Sstevel@tonic-gate
1017c478bd9Sstevel@tonic-gate if ((pubkey->class != CKO_PUBLIC_KEY) ||
102b60f2a0bSfr41279 (pubkey->key_type != CKK_DH)) {
1037c478bd9Sstevel@tonic-gate return (CKR_KEY_TYPE_INCONSISTENT);
104b60f2a0bSfr41279 }
1057c478bd9Sstevel@tonic-gate
1067c478bd9Sstevel@tonic-gate if ((prikey->class != CKO_PRIVATE_KEY) ||
107b60f2a0bSfr41279 (prikey->key_type != CKK_DH)) {
1087c478bd9Sstevel@tonic-gate return (CKR_KEY_TYPE_INCONSISTENT);
109b60f2a0bSfr41279 }
1107c478bd9Sstevel@tonic-gate
111726fad2aSDina K Nimeh /* Get private-value length in bits */
1127c478bd9Sstevel@tonic-gate template.pValue = malloc(sizeof (CK_ULONG));
1137c478bd9Sstevel@tonic-gate if (template.pValue == NULL) {
114726fad2aSDina K Nimeh return (CKR_HOST_MEMORY);
1157c478bd9Sstevel@tonic-gate }
1167c478bd9Sstevel@tonic-gate template.ulValueLen = sizeof (CK_ULONG);
1177c478bd9Sstevel@tonic-gate rv = get_ulong_attr_from_object(OBJ_PRI_DH_VAL_BITS(prikey),
1187c478bd9Sstevel@tonic-gate &template);
1197c478bd9Sstevel@tonic-gate if (rv != CKR_OK) {
120726fad2aSDina K Nimeh free(template.pValue);
121726fad2aSDina K Nimeh return (rv);
1227c478bd9Sstevel@tonic-gate }
1237c478bd9Sstevel@tonic-gate
1247c478bd9Sstevel@tonic-gate #ifdef __sparcv9
1257c478bd9Sstevel@tonic-gate /* LINTED */
1267c478bd9Sstevel@tonic-gate value_bits = (uint32_t)(*((CK_ULONG *)(template.pValue)));
1277c478bd9Sstevel@tonic-gate #else /* !__sparcv9 */
1287c478bd9Sstevel@tonic-gate value_bits = *((CK_ULONG *)(template.pValue));
1297c478bd9Sstevel@tonic-gate #endif /* __sparcv9 */
1307c478bd9Sstevel@tonic-gate
131726fad2aSDina K Nimeh free(template.pValue);
1327c478bd9Sstevel@tonic-gate
1337c478bd9Sstevel@tonic-gate /*
134726fad2aSDina K Nimeh * The input to the first phase shall be the Diffie-Hellman
135726fad2aSDina K Nimeh * parameters, which include prime, base, and private-value length.
1367c478bd9Sstevel@tonic-gate */
137726fad2aSDina K Nimeh rv = soft_get_public_value(pubkey, CKA_PRIME, prime, &prime_len);
138726fad2aSDina K Nimeh if (rv != CKR_OK) {
139726fad2aSDina K Nimeh return (rv);
1407c478bd9Sstevel@tonic-gate }
1417c478bd9Sstevel@tonic-gate
142726fad2aSDina K Nimeh rv = soft_get_public_value(pubkey, CKA_BASE, base, &base_len);
143726fad2aSDina K Nimeh if (rv != CKR_OK) {
144726fad2aSDina K Nimeh goto ret;
145726fad2aSDina K Nimeh }
146726fad2aSDina K Nimeh
147726fad2aSDina K Nimeh /* Inputs to DH key pair generation. */
148726fad2aSDina K Nimeh k.prime = prime;
149726fad2aSDina K Nimeh k.prime_bits = CRYPTO_BYTES2BITS(prime_len);
150726fad2aSDina K Nimeh k.base = base;
151726fad2aSDina K Nimeh k.base_bytes = base_len;
152726fad2aSDina K Nimeh k.value_bits = value_bits;
153726fad2aSDina K Nimeh k.rfunc = (IS_TOKEN_OBJECT(pubkey) || IS_TOKEN_OBJECT(prikey)) ?
154726fad2aSDina K Nimeh pkcs11_get_random : pkcs11_get_urandom;
155726fad2aSDina K Nimeh
156726fad2aSDina K Nimeh /* Outputs from DH key pair generation. */
157726fad2aSDina K Nimeh k.private_x = private_x;
158726fad2aSDina K Nimeh k.public_y = public_y;
159726fad2aSDina K Nimeh
160726fad2aSDina K Nimeh /* If value_bits is 0, it will return as same size as prime */
161726fad2aSDina K Nimeh if ((rv = dh_genkey_pair(&k)) != CKR_OK) {
162726fad2aSDina K Nimeh goto ret;
1637c478bd9Sstevel@tonic-gate }
1647c478bd9Sstevel@tonic-gate
1657c478bd9Sstevel@tonic-gate /*
1667c478bd9Sstevel@tonic-gate * The integer public value y shall be converted to an octet
1677c478bd9Sstevel@tonic-gate * string PV of length k, the public value.
1687c478bd9Sstevel@tonic-gate */
169726fad2aSDina K Nimeh if ((rv = soft_genDHkey_set_attribute(pubkey, CKA_VALUE, public_y,
170*53a3dbbbSJason King prime_len, B_TRUE)) != CKR_OK) {
171726fad2aSDina K Nimeh goto ret;
1727c478bd9Sstevel@tonic-gate }
1737c478bd9Sstevel@tonic-gate
1747c478bd9Sstevel@tonic-gate /* Convert the big integer private value to an octet string. */
175726fad2aSDina K Nimeh if ((rv = soft_genDHkey_set_attribute(prikey, CKA_VALUE, private_x,
176726fad2aSDina K Nimeh CRYPTO_BITS2BYTES(k.value_bits), B_FALSE)) != CKR_OK) {
177726fad2aSDina K Nimeh goto ret;
1787c478bd9Sstevel@tonic-gate }
1797c478bd9Sstevel@tonic-gate
1807c478bd9Sstevel@tonic-gate /* Convert the big integer prime to an octet string. */
181726fad2aSDina K Nimeh if ((rv = soft_genDHkey_set_attribute(prikey, CKA_PRIME, prime,
182726fad2aSDina K Nimeh CRYPTO_BITS2BYTES(k.prime_bits), B_FALSE)) != CKR_OK) {
183726fad2aSDina K Nimeh goto ret;
1847c478bd9Sstevel@tonic-gate }
1857c478bd9Sstevel@tonic-gate
1867c478bd9Sstevel@tonic-gate /* Convert the big integer base to an octet string. */
187726fad2aSDina K Nimeh if ((rv = soft_genDHkey_set_attribute(prikey, CKA_BASE, base,
188726fad2aSDina K Nimeh k.base_bytes, B_FALSE)) != CKR_OK) {
189726fad2aSDina K Nimeh goto ret;
1907c478bd9Sstevel@tonic-gate }
1917c478bd9Sstevel@tonic-gate
192726fad2aSDina K Nimeh /* Update private-value length in bits; could have been 0 before */
193726fad2aSDina K Nimeh OBJ_PRI_DH_VAL_BITS(prikey) = k.value_bits;
1947c478bd9Sstevel@tonic-gate
195726fad2aSDina K Nimeh ret:
1967c478bd9Sstevel@tonic-gate return (rv);
1977c478bd9Sstevel@tonic-gate }
1987c478bd9Sstevel@tonic-gate
199726fad2aSDina K Nimeh /* ARGSUSED3 */
2007c478bd9Sstevel@tonic-gate CK_RV
soft_dh_key_derive(soft_object_t * basekey,soft_object_t * secretkey,void * publicvalue,size_t publicvaluelen)2017c478bd9Sstevel@tonic-gate soft_dh_key_derive(soft_object_t *basekey, soft_object_t *secretkey,
2027c478bd9Sstevel@tonic-gate void *publicvalue, size_t publicvaluelen)
2037c478bd9Sstevel@tonic-gate {
204726fad2aSDina K Nimeh CK_RV rv;
2057c478bd9Sstevel@tonic-gate uchar_t privatevalue[MAX_KEY_ATTR_BUFLEN];
2067c478bd9Sstevel@tonic-gate uint32_t privatevaluelen = sizeof (privatevalue);
2077c478bd9Sstevel@tonic-gate uchar_t privateprime[MAX_KEY_ATTR_BUFLEN];
2087c478bd9Sstevel@tonic-gate uint32_t privateprimelen = sizeof (privateprime);
209726fad2aSDina K Nimeh uchar_t key[MAX_KEY_ATTR_BUFLEN];
2107c478bd9Sstevel@tonic-gate uint32_t keylen;
211726fad2aSDina K Nimeh DHbytekey k;
2127c478bd9Sstevel@tonic-gate
213c64d15a5Smcpowers rv = soft_get_private_value(basekey, CKA_VALUE, privatevalue,
2147c478bd9Sstevel@tonic-gate &privatevaluelen);
2157c478bd9Sstevel@tonic-gate if (rv != CKR_OK) {
2167c478bd9Sstevel@tonic-gate return (rv);
2177c478bd9Sstevel@tonic-gate }
2187c478bd9Sstevel@tonic-gate
219c64d15a5Smcpowers rv = soft_get_private_value(basekey, CKA_PRIME, privateprime,
2207c478bd9Sstevel@tonic-gate &privateprimelen);
2217c478bd9Sstevel@tonic-gate if (rv != CKR_OK) {
222726fad2aSDina K Nimeh goto ret;
2237c478bd9Sstevel@tonic-gate }
2247c478bd9Sstevel@tonic-gate
225726fad2aSDina K Nimeh /* keylen may be 0 if CKA_VALUE_LEN did not specify */
2267c478bd9Sstevel@tonic-gate keylen = OBJ_SEC_VALUE_LEN(secretkey);
227726fad2aSDina K Nimeh if (keylen > sizeof (key)) { /* check for overflow */
2287c478bd9Sstevel@tonic-gate rv = CKR_ATTRIBUTE_VALUE_INVALID;
229726fad2aSDina K Nimeh goto ret;
230726fad2aSDina K Nimeh }
231726fad2aSDina K Nimeh
232726fad2aSDina K Nimeh k.prime = privateprime;
233726fad2aSDina K Nimeh k.prime_bits = CRYPTO_BYTES2BITS(privateprimelen);
234726fad2aSDina K Nimeh k.value_bits = CRYPTO_BYTES2BITS(privatevaluelen);
235726fad2aSDina K Nimeh k.private_x = privatevalue;
236726fad2aSDina K Nimeh k.public_y = publicvalue;
237726fad2aSDina K Nimeh k.rfunc = NULL;
238726fad2aSDina K Nimeh
239726fad2aSDina K Nimeh /* keylen may be modified if it was 0 or conflicts with key type */
240*53a3dbbbSJason King rv = dh_key_derive(&k, secretkey->key_type, key, &keylen, 0);
241726fad2aSDina K Nimeh
242726fad2aSDina K Nimeh if (rv != CKR_OK) {
243726fad2aSDina K Nimeh goto ret;
2447c478bd9Sstevel@tonic-gate }
2457c478bd9Sstevel@tonic-gate
2467c478bd9Sstevel@tonic-gate if ((OBJ_SEC_VALUE(secretkey) = malloc(keylen)) == NULL) {
2477c478bd9Sstevel@tonic-gate rv = CKR_HOST_MEMORY;
248726fad2aSDina K Nimeh goto ret;
2497c478bd9Sstevel@tonic-gate }
250726fad2aSDina K Nimeh
2517c478bd9Sstevel@tonic-gate OBJ_SEC_VALUE_LEN(secretkey) = keylen;
252726fad2aSDina K Nimeh (void) memcpy(OBJ_SEC_VALUE(secretkey), key, keylen);
2537c478bd9Sstevel@tonic-gate
254726fad2aSDina K Nimeh ret:
2557c478bd9Sstevel@tonic-gate return (rv);
2567c478bd9Sstevel@tonic-gate }
257