1e5b75505Sopenharmony_ci/*
2e5b75505Sopenharmony_ci * Crypto wrapper for internal crypto implementation - modexp
3e5b75505Sopenharmony_ci * Copyright (c) 2006-2009, Jouni Malinen <j@w1.fi>
4e5b75505Sopenharmony_ci *
5e5b75505Sopenharmony_ci * This software may be distributed under the terms of the BSD license.
6e5b75505Sopenharmony_ci * See README for more details.
7e5b75505Sopenharmony_ci */
8e5b75505Sopenharmony_ci
9e5b75505Sopenharmony_ci#include "includes.h"
10e5b75505Sopenharmony_ci
11e5b75505Sopenharmony_ci#include "common.h"
12e5b75505Sopenharmony_ci#include "tls/bignum.h"
13e5b75505Sopenharmony_ci#include "crypto.h"
14e5b75505Sopenharmony_ci
15e5b75505Sopenharmony_ci
16e5b75505Sopenharmony_ciint crypto_dh_init(u8 generator, const u8 *prime, size_t prime_len, u8 *privkey,
17e5b75505Sopenharmony_ci		   u8 *pubkey)
18e5b75505Sopenharmony_ci{
19e5b75505Sopenharmony_ci	size_t pubkey_len, pad;
20e5b75505Sopenharmony_ci
21e5b75505Sopenharmony_ci	if (os_get_random(privkey, prime_len) < 0)
22e5b75505Sopenharmony_ci		return -1;
23e5b75505Sopenharmony_ci	if (os_memcmp(privkey, prime, prime_len) > 0) {
24e5b75505Sopenharmony_ci		/* Make sure private value is smaller than prime */
25e5b75505Sopenharmony_ci		privkey[0] = 0;
26e5b75505Sopenharmony_ci	}
27e5b75505Sopenharmony_ci
28e5b75505Sopenharmony_ci	pubkey_len = prime_len;
29e5b75505Sopenharmony_ci	if (crypto_mod_exp(&generator, 1, privkey, prime_len, prime, prime_len,
30e5b75505Sopenharmony_ci			   pubkey, &pubkey_len) < 0)
31e5b75505Sopenharmony_ci		return -1;
32e5b75505Sopenharmony_ci	if (pubkey_len < prime_len) {
33e5b75505Sopenharmony_ci		pad = prime_len - pubkey_len;
34e5b75505Sopenharmony_ci		os_memmove(pubkey + pad, pubkey, pubkey_len);
35e5b75505Sopenharmony_ci		os_memset(pubkey, 0, pad);
36e5b75505Sopenharmony_ci	}
37e5b75505Sopenharmony_ci
38e5b75505Sopenharmony_ci	return 0;
39e5b75505Sopenharmony_ci}
40e5b75505Sopenharmony_ci
41e5b75505Sopenharmony_ci
42e5b75505Sopenharmony_ciint crypto_dh_derive_secret(u8 generator, const u8 *prime, size_t prime_len,
43e5b75505Sopenharmony_ci			    const u8 *order, size_t order_len,
44e5b75505Sopenharmony_ci			    const u8 *privkey, size_t privkey_len,
45e5b75505Sopenharmony_ci			    const u8 *pubkey, size_t pubkey_len,
46e5b75505Sopenharmony_ci			    u8 *secret, size_t *len)
47e5b75505Sopenharmony_ci{
48e5b75505Sopenharmony_ci	struct bignum *pub;
49e5b75505Sopenharmony_ci	int res = -1;
50e5b75505Sopenharmony_ci
51e5b75505Sopenharmony_ci	if (pubkey_len > prime_len ||
52e5b75505Sopenharmony_ci	    (pubkey_len == prime_len &&
53e5b75505Sopenharmony_ci	     os_memcmp(pubkey, prime, prime_len) >= 0))
54e5b75505Sopenharmony_ci		return -1;
55e5b75505Sopenharmony_ci
56e5b75505Sopenharmony_ci	pub = bignum_init();
57e5b75505Sopenharmony_ci	if (!pub || bignum_set_unsigned_bin(pub, pubkey, pubkey_len) < 0 ||
58e5b75505Sopenharmony_ci	    bignum_cmp_d(pub, 1) <= 0)
59e5b75505Sopenharmony_ci		goto fail;
60e5b75505Sopenharmony_ci
61e5b75505Sopenharmony_ci	if (order) {
62e5b75505Sopenharmony_ci		struct bignum *p, *q, *tmp;
63e5b75505Sopenharmony_ci		int failed;
64e5b75505Sopenharmony_ci
65e5b75505Sopenharmony_ci		/* verify: pubkey^q == 1 mod p */
66e5b75505Sopenharmony_ci		p = bignum_init();
67e5b75505Sopenharmony_ci		q = bignum_init();
68e5b75505Sopenharmony_ci		tmp = bignum_init();
69e5b75505Sopenharmony_ci		failed = !p || !q || !tmp ||
70e5b75505Sopenharmony_ci			bignum_set_unsigned_bin(p, prime, prime_len) < 0 ||
71e5b75505Sopenharmony_ci			bignum_set_unsigned_bin(q, order, order_len) < 0 ||
72e5b75505Sopenharmony_ci			bignum_exptmod(pub, q, p, tmp) < 0 ||
73e5b75505Sopenharmony_ci			bignum_cmp_d(tmp, 1) != 0;
74e5b75505Sopenharmony_ci		bignum_deinit(p);
75e5b75505Sopenharmony_ci		bignum_deinit(q);
76e5b75505Sopenharmony_ci		bignum_deinit(tmp);
77e5b75505Sopenharmony_ci		if (failed)
78e5b75505Sopenharmony_ci			goto fail;
79e5b75505Sopenharmony_ci	}
80e5b75505Sopenharmony_ci
81e5b75505Sopenharmony_ci	res = crypto_mod_exp(pubkey, pubkey_len, privkey, privkey_len,
82e5b75505Sopenharmony_ci			     prime, prime_len, secret, len);
83e5b75505Sopenharmony_cifail:
84e5b75505Sopenharmony_ci	bignum_deinit(pub);
85e5b75505Sopenharmony_ci	return res;
86e5b75505Sopenharmony_ci}
87e5b75505Sopenharmony_ci
88e5b75505Sopenharmony_ci
89e5b75505Sopenharmony_ciint crypto_mod_exp(const u8 *base, size_t base_len,
90e5b75505Sopenharmony_ci		   const u8 *power, size_t power_len,
91e5b75505Sopenharmony_ci		   const u8 *modulus, size_t modulus_len,
92e5b75505Sopenharmony_ci		   u8 *result, size_t *result_len)
93e5b75505Sopenharmony_ci{
94e5b75505Sopenharmony_ci	struct bignum *bn_base, *bn_exp, *bn_modulus, *bn_result;
95e5b75505Sopenharmony_ci	int ret = -1;
96e5b75505Sopenharmony_ci
97e5b75505Sopenharmony_ci	bn_base = bignum_init();
98e5b75505Sopenharmony_ci	bn_exp = bignum_init();
99e5b75505Sopenharmony_ci	bn_modulus = bignum_init();
100e5b75505Sopenharmony_ci	bn_result = bignum_init();
101e5b75505Sopenharmony_ci
102e5b75505Sopenharmony_ci	if (bn_base == NULL || bn_exp == NULL || bn_modulus == NULL ||
103e5b75505Sopenharmony_ci	    bn_result == NULL)
104e5b75505Sopenharmony_ci		goto error;
105e5b75505Sopenharmony_ci
106e5b75505Sopenharmony_ci	if (bignum_set_unsigned_bin(bn_base, base, base_len) < 0 ||
107e5b75505Sopenharmony_ci	    bignum_set_unsigned_bin(bn_exp, power, power_len) < 0 ||
108e5b75505Sopenharmony_ci	    bignum_set_unsigned_bin(bn_modulus, modulus, modulus_len) < 0)
109e5b75505Sopenharmony_ci		goto error;
110e5b75505Sopenharmony_ci
111e5b75505Sopenharmony_ci	if (bignum_exptmod(bn_base, bn_exp, bn_modulus, bn_result) < 0)
112e5b75505Sopenharmony_ci		goto error;
113e5b75505Sopenharmony_ci
114e5b75505Sopenharmony_ci	ret = bignum_get_unsigned_bin(bn_result, result, result_len);
115e5b75505Sopenharmony_ci
116e5b75505Sopenharmony_cierror:
117e5b75505Sopenharmony_ci	bignum_deinit(bn_base);
118e5b75505Sopenharmony_ci	bignum_deinit(bn_exp);
119e5b75505Sopenharmony_ci	bignum_deinit(bn_modulus);
120e5b75505Sopenharmony_ci	bignum_deinit(bn_result);
121e5b75505Sopenharmony_ci	return ret;
122e5b75505Sopenharmony_ci}
123