1 /**********************************************************************
3 * Copyright (c) 2005-2006 Cryptocom LTD *
4 * This file is distributed under the same license as OpenSSL *
6 * Implementation of RFC 4357 (GOST R 34.10) Publick key method *
8 * Requires OpenSSL 0.9.9 for compilation *
9 **********************************************************************/
10 #include <openssl/evp.h>
11 #include <openssl/objects.h>
12 #include <openssl/ec.h>
13 #include <openssl/err.h>
14 #include <openssl/x509v3.h> /* For string_to_hex */
19 #include "e_gost_err.h"
20 /* -----init, cleanup, copy - uniform for all algs ---------------*/
21 /* Allocates new gost_pmeth_data structure and assigns it as data */
22 static int pkey_gost_init(EVP_PKEY_CTX *ctx)
24 struct gost_pmeth_data *data;
25 EVP_PKEY *pkey = EVP_PKEY_CTX_get0_pkey(ctx);
27 data = OPENSSL_zalloc(sizeof(*data));
30 if (pkey && EVP_PKEY_get0(pkey)) {
31 switch (EVP_PKEY_base_id(pkey)) {
32 case NID_id_GostR3410_2001:
33 data->sign_param_nid =
34 EC_GROUP_get_curve_name(EC_KEY_get0_group
35 (EVP_PKEY_get0((EVP_PKEY *)pkey)));
41 EVP_PKEY_CTX_set_data(ctx, data);
45 /* Copies contents of gost_pmeth_data structure */
46 static int pkey_gost_copy(EVP_PKEY_CTX *dst, EVP_PKEY_CTX *src)
48 struct gost_pmeth_data *dst_data, *src_data;
49 if (!pkey_gost_init(dst)) {
52 src_data = EVP_PKEY_CTX_get_data(src);
53 dst_data = EVP_PKEY_CTX_get_data(dst);
54 *dst_data = *src_data;
55 if (src_data->shared_ukm) {
56 dst_data->shared_ukm = NULL;
61 /* Frees up gost_pmeth_data structure */
62 static void pkey_gost_cleanup(EVP_PKEY_CTX *ctx)
64 struct gost_pmeth_data *data = EVP_PKEY_CTX_get_data(ctx);
66 OPENSSL_free(data->shared_ukm);
70 /* --------------------- control functions ------------------------------*/
71 static int pkey_gost_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2)
73 struct gost_pmeth_data *pctx =
74 (struct gost_pmeth_data *)EVP_PKEY_CTX_get_data(ctx);
76 case EVP_PKEY_CTRL_MD:
78 if (EVP_MD_type((const EVP_MD *)p2) != NID_id_GostR3411_94) {
79 GOSTerr(GOST_F_PKEY_GOST_CTRL, GOST_R_INVALID_DIGEST_TYPE);
82 pctx->md = (EVP_MD *)p2;
86 case EVP_PKEY_CTRL_GET_MD:
87 *(const EVP_MD **)p2 = pctx->md;
90 case EVP_PKEY_CTRL_PKCS7_ENCRYPT:
91 case EVP_PKEY_CTRL_PKCS7_DECRYPT:
92 case EVP_PKEY_CTRL_PKCS7_SIGN:
93 case EVP_PKEY_CTRL_DIGESTINIT:
94 #ifndef OPENSSL_NO_CMS
95 case EVP_PKEY_CTRL_CMS_ENCRYPT:
96 case EVP_PKEY_CTRL_CMS_DECRYPT:
97 case EVP_PKEY_CTRL_CMS_SIGN:
101 case EVP_PKEY_CTRL_GOST_PARAMSET:
102 pctx->sign_param_nid = (int)p1;
104 case EVP_PKEY_CTRL_SET_IV:
105 pctx->shared_ukm = OPENSSL_malloc((int)p1);
106 if (pctx->shared_ukm == NULL) {
107 GOSTerr(GOST_F_PKEY_GOST_CTRL, ERR_R_MALLOC_FAILURE);
110 memcpy(pctx->shared_ukm, p2, (int)p1);
112 case EVP_PKEY_CTRL_PEER_KEY:
113 if (p1 == 0 || p1 == 1) /* call from EVP_PKEY_derive_set_peer */
115 if (p1 == 2) /* TLS: peer key used? */
116 return pctx->peer_key_used;
117 if (p1 == 3) /* TLS: peer key used! */
118 return (pctx->peer_key_used = 1);
124 static int pkey_gost_ctrl01_str(EVP_PKEY_CTX *ctx,
125 const char *type, const char *value)
129 if (strcmp(type, param_ctrl_string) == 0) {
133 if (strlen(value) == 1) {
134 switch (toupper((unsigned char)value[0])) {
136 param_nid = NID_id_GostR3410_2001_CryptoPro_A_ParamSet;
139 param_nid = NID_id_GostR3410_2001_CryptoPro_B_ParamSet;
142 param_nid = NID_id_GostR3410_2001_CryptoPro_C_ParamSet;
145 param_nid = NID_id_GostR3410_2001_TestParamSet;
150 } else if ((strlen(value) == 2)
151 && (toupper((unsigned char)value[0]) == 'X')) {
152 switch (toupper((unsigned char)value[1])) {
154 param_nid = NID_id_GostR3410_2001_CryptoPro_XchA_ParamSet;
157 param_nid = NID_id_GostR3410_2001_CryptoPro_XchB_ParamSet;
163 R3410_2001_params *p = R3410_2001_paramset;
164 param_nid = OBJ_txt2nid(value);
165 if (param_nid == NID_undef) {
168 for (; p->nid != NID_undef; p++) {
169 if (p->nid == param_nid)
172 if (p->nid == NID_undef) {
173 GOSTerr(GOST_F_PKEY_GOST_CTRL01_STR, GOST_R_INVALID_PARAMSET);
178 return pkey_gost_ctrl(ctx, EVP_PKEY_CTRL_GOST_PARAMSET,
184 /* --------------------- key generation --------------------------------*/
186 static int pkey_gost_paramgen_init(EVP_PKEY_CTX *ctx)
191 static int pkey_gost01_paramgen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
193 struct gost_pmeth_data *data = EVP_PKEY_CTX_get_data(ctx);
196 if (data->sign_param_nid == NID_undef) {
197 GOSTerr(GOST_F_PKEY_GOST01_PARAMGEN, GOST_R_NO_PARAMETERS_SET);
202 if (!fill_GOST2001_params(ec, data->sign_param_nid)) {
206 EVP_PKEY_assign(pkey, NID_id_GostR3410_2001, ec);
210 /* Generates GOST_R3410 2001 key and assigns it using specified type */
211 static int pkey_gost01cp_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
214 if (!pkey_gost01_paramgen(ctx, pkey))
216 ec = EVP_PKEY_get0(pkey);
221 /* ----------- sign callbacks --------------------------------------*/
223 * Packs signature according to Cryptopro rules
224 * and frees up DSA_SIG structure
226 int pack_sign_cp(DSA_SIG *s, int order, unsigned char *sig, size_t *siglen)
229 memset(sig, 0, *siglen);
230 store_bignum(s->s, sig, order);
231 store_bignum(s->r, sig + order, order);
237 static int pkey_gost01_cp_sign(EVP_PKEY_CTX *ctx, unsigned char *sig,
238 size_t *siglen, const unsigned char *tbs,
241 DSA_SIG *unpacked_sig = NULL;
242 EVP_PKEY *pkey = EVP_PKEY_CTX_get0_pkey(ctx);
246 *siglen = 64; /* better to check size of curve order */
249 unpacked_sig = gost2001_do_sign(tbs, tbs_len, EVP_PKEY_get0(pkey));
253 return pack_sign_cp(unpacked_sig, 32, sig, siglen);
256 /* ------------------- verify callbacks ---------------------------*/
257 /* Unpack signature according to cryptopro rules */
258 DSA_SIG *unpack_cp_signature(const unsigned char *sig, size_t siglen)
264 GOSTerr(GOST_F_UNPACK_CP_SIGNATURE, ERR_R_MALLOC_FAILURE);
267 s->s = BN_bin2bn(sig, siglen / 2, NULL);
268 s->r = BN_bin2bn(sig + siglen / 2, siglen / 2, NULL);
273 static int pkey_gost01_cp_verify(EVP_PKEY_CTX *ctx, const unsigned char *sig,
274 size_t siglen, const unsigned char *tbs,
278 EVP_PKEY *pub_key = EVP_PKEY_CTX_get0_pkey(ctx);
279 DSA_SIG *s = unpack_cp_signature(sig, siglen);
283 fprintf(stderr, "R=");
284 BN_print_fp(stderr, s->r);
285 fprintf(stderr, "\nS=");
286 BN_print_fp(stderr, s->s);
287 fprintf(stderr, "\n");
290 ok = gost2001_do_verify(tbs, tbs_len, s, EVP_PKEY_get0(pub_key));
295 /* ------------- encrypt init -------------------------------------*/
296 /* Generates ephermeral key */
297 static int pkey_gost_encrypt_init(EVP_PKEY_CTX *ctx)
302 /* --------------- Derive init ------------------------------------*/
303 static int pkey_gost_derive_init(EVP_PKEY_CTX *ctx)
308 /* -------- PKEY_METHOD for GOST MAC algorithm --------------------*/
309 static int pkey_gost_mac_init(EVP_PKEY_CTX *ctx)
311 struct gost_mac_pmeth_data *data = OPENSSL_zalloc(sizeof(*data));
315 EVP_PKEY_CTX_set_data(ctx, data);
319 static void pkey_gost_mac_cleanup(EVP_PKEY_CTX *ctx)
321 struct gost_mac_pmeth_data *data = EVP_PKEY_CTX_get_data(ctx);
325 static int pkey_gost_mac_copy(EVP_PKEY_CTX *dst, EVP_PKEY_CTX *src)
327 struct gost_mac_pmeth_data *dst_data, *src_data;
328 if (!pkey_gost_mac_init(dst)) {
331 src_data = EVP_PKEY_CTX_get_data(src);
332 dst_data = EVP_PKEY_CTX_get_data(dst);
333 *dst_data = *src_data;
337 static int pkey_gost_mac_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2)
339 struct gost_mac_pmeth_data *data =
340 (struct gost_mac_pmeth_data *)EVP_PKEY_CTX_get_data(ctx);
343 case EVP_PKEY_CTRL_MD:
345 if (EVP_MD_type((const EVP_MD *)p2) != NID_id_Gost28147_89_MAC) {
346 GOSTerr(GOST_F_PKEY_GOST_MAC_CTRL,
347 GOST_R_INVALID_DIGEST_TYPE);
350 data->md = (EVP_MD *)p2;
354 case EVP_PKEY_CTRL_GET_MD:
355 *(const EVP_MD **)p2 = data->md;
358 case EVP_PKEY_CTRL_PKCS7_ENCRYPT:
359 case EVP_PKEY_CTRL_PKCS7_DECRYPT:
360 case EVP_PKEY_CTRL_PKCS7_SIGN:
362 case EVP_PKEY_CTRL_SET_MAC_KEY:
364 GOSTerr(GOST_F_PKEY_GOST_MAC_CTRL, GOST_R_INVALID_MAC_KEY_LENGTH);
368 memcpy(data->key, p2, 32);
371 case EVP_PKEY_CTRL_DIGESTINIT:
373 EVP_MD_CTX *mctx = p2;
375 if (!data->key_set) {
376 EVP_PKEY *pkey = EVP_PKEY_CTX_get0_pkey(ctx);
378 GOSTerr(GOST_F_PKEY_GOST_MAC_CTRL,
379 GOST_R_MAC_KEY_NOT_SET);
382 key = EVP_PKEY_get0(pkey);
384 GOSTerr(GOST_F_PKEY_GOST_MAC_CTRL,
385 GOST_R_MAC_KEY_NOT_SET);
391 return mctx->digest->md_ctrl(mctx, EVP_MD_CTRL_SET_KEY, 32, key);
397 static int pkey_gost_mac_ctrl_str(EVP_PKEY_CTX *ctx,
398 const char *type, const char *value)
400 if (strcmp(type, key_ctrl_string) == 0) {
401 if (strlen(value) != 32) {
402 GOSTerr(GOST_F_PKEY_GOST_MAC_CTRL_STR,
403 GOST_R_INVALID_MAC_KEY_LENGTH);
406 return pkey_gost_mac_ctrl(ctx, EVP_PKEY_CTRL_SET_MAC_KEY,
409 if (strcmp(type, hexkey_ctrl_string) == 0) {
412 unsigned char *keybuf = string_to_hex(value, &keylen);
413 if (!keybuf || keylen != 32) {
414 GOSTerr(GOST_F_PKEY_GOST_MAC_CTRL_STR,
415 GOST_R_INVALID_MAC_KEY_LENGTH);
416 OPENSSL_free(keybuf);
419 ret = pkey_gost_mac_ctrl(ctx, EVP_PKEY_CTRL_SET_MAC_KEY, 32, keybuf);
420 OPENSSL_free(keybuf);
427 static int pkey_gost_mac_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
429 struct gost_mac_pmeth_data *data = EVP_PKEY_CTX_get_data(ctx);
430 unsigned char *keydata;
431 if (!data->key_set) {
432 GOSTerr(GOST_F_PKEY_GOST_MAC_KEYGEN, GOST_R_MAC_KEY_NOT_SET);
435 keydata = OPENSSL_malloc(32);
438 memcpy(keydata, data->key, 32);
439 EVP_PKEY_assign(pkey, NID_id_Gost28147_89_MAC, keydata);
443 static int pkey_gost_mac_signctx_init(EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx)
448 static int pkey_gost_mac_signctx(EVP_PKEY_CTX *ctx, unsigned char *sig,
449 size_t *siglen, EVP_MD_CTX *mctx)
451 unsigned int tmpsiglen = *siglen; /* for platforms where
452 * sizeof(int)!=sizeof(size_t) */
458 ret = EVP_DigestFinal_ex(mctx, sig, &tmpsiglen);
463 /* ----------------------------------------------------------------*/
464 int register_pmeth_gost(int id, EVP_PKEY_METHOD **pmeth, int flags)
466 *pmeth = EVP_PKEY_meth_new(id, flags);
471 case NID_id_GostR3410_2001:
472 EVP_PKEY_meth_set_ctrl(*pmeth, pkey_gost_ctrl, pkey_gost_ctrl01_str);
473 EVP_PKEY_meth_set_sign(*pmeth, NULL, pkey_gost01_cp_sign);
474 EVP_PKEY_meth_set_verify(*pmeth, NULL, pkey_gost01_cp_verify);
476 EVP_PKEY_meth_set_keygen(*pmeth, NULL, pkey_gost01cp_keygen);
478 EVP_PKEY_meth_set_encrypt(*pmeth,
479 pkey_gost_encrypt_init,
480 pkey_GOST01cp_encrypt);
481 EVP_PKEY_meth_set_decrypt(*pmeth, NULL, pkey_GOST01cp_decrypt);
482 EVP_PKEY_meth_set_derive(*pmeth,
483 pkey_gost_derive_init, pkey_gost2001_derive);
484 EVP_PKEY_meth_set_paramgen(*pmeth, pkey_gost_paramgen_init,
485 pkey_gost01_paramgen);
487 case NID_id_Gost28147_89_MAC:
488 EVP_PKEY_meth_set_ctrl(*pmeth, pkey_gost_mac_ctrl,
489 pkey_gost_mac_ctrl_str);
490 EVP_PKEY_meth_set_signctx(*pmeth, pkey_gost_mac_signctx_init,
491 pkey_gost_mac_signctx);
492 EVP_PKEY_meth_set_keygen(*pmeth, NULL, pkey_gost_mac_keygen);
493 EVP_PKEY_meth_set_init(*pmeth, pkey_gost_mac_init);
494 EVP_PKEY_meth_set_cleanup(*pmeth, pkey_gost_mac_cleanup);
495 EVP_PKEY_meth_set_copy(*pmeth, pkey_gost_mac_copy);
497 default: /* Unsupported method */
500 EVP_PKEY_meth_set_init(*pmeth, pkey_gost_init);
501 EVP_PKEY_meth_set_cleanup(*pmeth, pkey_gost_cleanup);
503 EVP_PKEY_meth_set_copy(*pmeth, pkey_gost_copy);
505 * FIXME derive etc...