13ff40c12SJohn Marino /*
23ff40c12SJohn Marino  * Crypto wrapper for internal crypto implementation - modexp
33ff40c12SJohn Marino  * Copyright (c) 2006-2009, Jouni Malinen <j@w1.fi>
43ff40c12SJohn Marino  *
53ff40c12SJohn Marino  * This software may be distributed under the terms of the BSD license.
63ff40c12SJohn Marino  * See README for more details.
73ff40c12SJohn Marino  */
83ff40c12SJohn Marino 
93ff40c12SJohn Marino #include "includes.h"
103ff40c12SJohn Marino 
113ff40c12SJohn Marino #include "common.h"
123ff40c12SJohn Marino #include "tls/bignum.h"
133ff40c12SJohn Marino #include "crypto.h"
143ff40c12SJohn Marino 
153ff40c12SJohn Marino 
crypto_dh_init(u8 generator,const u8 * prime,size_t prime_len,u8 * privkey,u8 * pubkey)16*a1157835SDaniel Fojt int crypto_dh_init(u8 generator, const u8 *prime, size_t prime_len, u8 *privkey,
17*a1157835SDaniel Fojt 		   u8 *pubkey)
18*a1157835SDaniel Fojt {
19*a1157835SDaniel Fojt 	size_t pubkey_len, pad;
20*a1157835SDaniel Fojt 
21*a1157835SDaniel Fojt 	if (os_get_random(privkey, prime_len) < 0)
22*a1157835SDaniel Fojt 		return -1;
23*a1157835SDaniel Fojt 	if (os_memcmp(privkey, prime, prime_len) > 0) {
24*a1157835SDaniel Fojt 		/* Make sure private value is smaller than prime */
25*a1157835SDaniel Fojt 		privkey[0] = 0;
26*a1157835SDaniel Fojt 	}
27*a1157835SDaniel Fojt 
28*a1157835SDaniel Fojt 	pubkey_len = prime_len;
29*a1157835SDaniel Fojt 	if (crypto_mod_exp(&generator, 1, privkey, prime_len, prime, prime_len,
30*a1157835SDaniel Fojt 			   pubkey, &pubkey_len) < 0)
31*a1157835SDaniel Fojt 		return -1;
32*a1157835SDaniel Fojt 	if (pubkey_len < prime_len) {
33*a1157835SDaniel Fojt 		pad = prime_len - pubkey_len;
34*a1157835SDaniel Fojt 		os_memmove(pubkey + pad, pubkey, pubkey_len);
35*a1157835SDaniel Fojt 		os_memset(pubkey, 0, pad);
36*a1157835SDaniel Fojt 	}
37*a1157835SDaniel Fojt 
38*a1157835SDaniel Fojt 	return 0;
39*a1157835SDaniel Fojt }
40*a1157835SDaniel Fojt 
41*a1157835SDaniel Fojt 
crypto_dh_derive_secret(u8 generator,const u8 * prime,size_t prime_len,const u8 * order,size_t order_len,const u8 * privkey,size_t privkey_len,const u8 * pubkey,size_t pubkey_len,u8 * secret,size_t * len)42*a1157835SDaniel Fojt int crypto_dh_derive_secret(u8 generator, const u8 *prime, size_t prime_len,
43*a1157835SDaniel Fojt 			    const u8 *order, size_t order_len,
44*a1157835SDaniel Fojt 			    const u8 *privkey, size_t privkey_len,
45*a1157835SDaniel Fojt 			    const u8 *pubkey, size_t pubkey_len,
46*a1157835SDaniel Fojt 			    u8 *secret, size_t *len)
47*a1157835SDaniel Fojt {
48*a1157835SDaniel Fojt 	struct bignum *pub;
49*a1157835SDaniel Fojt 	int res = -1;
50*a1157835SDaniel Fojt 
51*a1157835SDaniel Fojt 	if (pubkey_len > prime_len ||
52*a1157835SDaniel Fojt 	    (pubkey_len == prime_len &&
53*a1157835SDaniel Fojt 	     os_memcmp(pubkey, prime, prime_len) >= 0))
54*a1157835SDaniel Fojt 		return -1;
55*a1157835SDaniel Fojt 
56*a1157835SDaniel Fojt 	pub = bignum_init();
57*a1157835SDaniel Fojt 	if (!pub || bignum_set_unsigned_bin(pub, pubkey, pubkey_len) < 0 ||
58*a1157835SDaniel Fojt 	    bignum_cmp_d(pub, 1) <= 0)
59*a1157835SDaniel Fojt 		goto fail;
60*a1157835SDaniel Fojt 
61*a1157835SDaniel Fojt 	if (order) {
62*a1157835SDaniel Fojt 		struct bignum *p, *q, *tmp;
63*a1157835SDaniel Fojt 		int failed;
64*a1157835SDaniel Fojt 
65*a1157835SDaniel Fojt 		/* verify: pubkey^q == 1 mod p */
66*a1157835SDaniel Fojt 		p = bignum_init();
67*a1157835SDaniel Fojt 		q = bignum_init();
68*a1157835SDaniel Fojt 		tmp = bignum_init();
69*a1157835SDaniel Fojt 		failed = !p || !q || !tmp ||
70*a1157835SDaniel Fojt 			bignum_set_unsigned_bin(p, prime, prime_len) < 0 ||
71*a1157835SDaniel Fojt 			bignum_set_unsigned_bin(q, order, order_len) < 0 ||
72*a1157835SDaniel Fojt 			bignum_exptmod(pub, q, p, tmp) < 0 ||
73*a1157835SDaniel Fojt 			bignum_cmp_d(tmp, 1) != 0;
74*a1157835SDaniel Fojt 		bignum_deinit(p);
75*a1157835SDaniel Fojt 		bignum_deinit(q);
76*a1157835SDaniel Fojt 		bignum_deinit(tmp);
77*a1157835SDaniel Fojt 		if (failed)
78*a1157835SDaniel Fojt 			goto fail;
79*a1157835SDaniel Fojt 	}
80*a1157835SDaniel Fojt 
81*a1157835SDaniel Fojt 	res = crypto_mod_exp(pubkey, pubkey_len, privkey, privkey_len,
82*a1157835SDaniel Fojt 			     prime, prime_len, secret, len);
83*a1157835SDaniel Fojt fail:
84*a1157835SDaniel Fojt 	bignum_deinit(pub);
85*a1157835SDaniel Fojt 	return res;
86*a1157835SDaniel Fojt }
87*a1157835SDaniel Fojt 
88*a1157835SDaniel Fojt 
crypto_mod_exp(const u8 * base,size_t base_len,const u8 * power,size_t power_len,const u8 * modulus,size_t modulus_len,u8 * result,size_t * result_len)893ff40c12SJohn Marino int crypto_mod_exp(const u8 *base, size_t base_len,
903ff40c12SJohn Marino 		   const u8 *power, size_t power_len,
913ff40c12SJohn Marino 		   const u8 *modulus, size_t modulus_len,
923ff40c12SJohn Marino 		   u8 *result, size_t *result_len)
933ff40c12SJohn Marino {
943ff40c12SJohn Marino 	struct bignum *bn_base, *bn_exp, *bn_modulus, *bn_result;
953ff40c12SJohn Marino 	int ret = -1;
963ff40c12SJohn Marino 
973ff40c12SJohn Marino 	bn_base = bignum_init();
983ff40c12SJohn Marino 	bn_exp = bignum_init();
993ff40c12SJohn Marino 	bn_modulus = bignum_init();
1003ff40c12SJohn Marino 	bn_result = bignum_init();
1013ff40c12SJohn Marino 
1023ff40c12SJohn Marino 	if (bn_base == NULL || bn_exp == NULL || bn_modulus == NULL ||
1033ff40c12SJohn Marino 	    bn_result == NULL)
1043ff40c12SJohn Marino 		goto error;
1053ff40c12SJohn Marino 
1063ff40c12SJohn Marino 	if (bignum_set_unsigned_bin(bn_base, base, base_len) < 0 ||
1073ff40c12SJohn Marino 	    bignum_set_unsigned_bin(bn_exp, power, power_len) < 0 ||
1083ff40c12SJohn Marino 	    bignum_set_unsigned_bin(bn_modulus, modulus, modulus_len) < 0)
1093ff40c12SJohn Marino 		goto error;
1103ff40c12SJohn Marino 
1113ff40c12SJohn Marino 	if (bignum_exptmod(bn_base, bn_exp, bn_modulus, bn_result) < 0)
1123ff40c12SJohn Marino 		goto error;
1133ff40c12SJohn Marino 
1143ff40c12SJohn Marino 	ret = bignum_get_unsigned_bin(bn_result, result, result_len);
1153ff40c12SJohn Marino 
1163ff40c12SJohn Marino error:
1173ff40c12SJohn Marino 	bignum_deinit(bn_base);
1183ff40c12SJohn Marino 	bignum_deinit(bn_exp);
1193ff40c12SJohn Marino 	bignum_deinit(bn_modulus);
1203ff40c12SJohn Marino 	bignum_deinit(bn_result);
1213ff40c12SJohn Marino 	return ret;
1223ff40c12SJohn Marino }
123