[crypto/dh] side channel hardening for computing DH shared keys
[openssl.git] / crypto / dh / dh_group_params.c
1 /*
2  * Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved.
3  *
4  * Licensed under the Apache License 2.0 (the "License").  You may not use
5  * this file except in compliance with the License.  You can obtain a copy
6  * in the file LICENSE in the source distribution or at
7  * https://www.openssl.org/source/license.html
8  */
9
10 /* DH parameters from RFC7919 and RFC3526 */
11
12 /*
13  * DH low level APIs are deprecated for public use, but still ok for
14  * internal use.
15  */
16 #include "internal/deprecated.h"
17
18 #include <stdio.h>
19 #include "internal/cryptlib.h"
20 #include "internal/ffc.h"
21 #include "dh_local.h"
22 #include <openssl/bn.h>
23 #include <openssl/objects.h>
24 #include "internal/nelem.h"
25 #include "crypto/dh.h"
26 #include "e_os.h" /* strcasecmp */
27
28 static DH *dh_param_init(OSSL_LIB_CTX *libctx, const DH_NAMED_GROUP *group)
29 {
30     DH *dh = dh_new_ex(libctx);
31
32     if (dh == NULL)
33         return NULL;
34
35     ossl_ffc_named_group_set_pqg(&dh->params, group);
36     dh->params.nid = ossl_ffc_named_group_get_uid(group);
37     dh->length = BN_num_bits(dh->params.q);
38     dh->dirty_cnt++;
39     return dh;
40 }
41
42 DH *dh_new_by_nid_ex(OSSL_LIB_CTX *libctx, int nid)
43 {
44     const DH_NAMED_GROUP *group;
45
46     if ((group = ossl_ffc_uid_to_dh_named_group(nid)) != NULL)
47         return dh_param_init(libctx, group);
48
49     ERR_raise(ERR_LIB_DH, DH_R_INVALID_PARAMETER_NID);
50     return NULL;
51 }
52
53 DH *DH_new_by_nid(int nid)
54 {
55     return dh_new_by_nid_ex(NULL, nid);
56 }
57
58 void dh_cache_named_group(DH *dh)
59 {
60     const DH_NAMED_GROUP *group;
61
62     if (dh == NULL)
63         return;
64
65     dh->params.nid = NID_undef; /* flush cached value */
66
67     /* Exit if p or g is not set */
68     if (dh->params.p == NULL
69         || dh->params.g == NULL)
70         return;
71
72     if ((group = ossl_ffc_numbers_to_dh_named_group(dh->params.p,
73                                                     dh->params.q,
74                                                     dh->params.g)) != NULL) {
75         if (dh->params.q == NULL)
76             dh->params.q = (BIGNUM *)ossl_ffc_named_group_get_q(group);
77         /* cache the nid */
78         dh->params.nid = ossl_ffc_named_group_get_uid(group);
79         dh->length = BN_num_bits(dh->params.q);
80         dh->dirty_cnt++;
81     }
82 }
83
84 int DH_get_nid(const DH *dh)
85 {
86     if (dh == NULL)
87         return NID_undef;
88
89     return dh->params.nid;
90 }