psa_crypto.c 192 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502
  1. /*
  2. * PSA crypto layer on top of Mbed TLS crypto
  3. */
  4. /*
  5. * Copyright The Mbed TLS Contributors
  6. * SPDX-License-Identifier: Apache-2.0
  7. *
  8. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  9. * not use this file except in compliance with the License.
  10. * You may obtain a copy of the License at
  11. *
  12. * http://www.apache.org/licenses/LICENSE-2.0
  13. *
  14. * Unless required by applicable law or agreed to in writing, software
  15. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  16. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  17. * See the License for the specific language governing permissions and
  18. * limitations under the License.
  19. */
  20. #include "common.h"
  21. #if defined(MBEDTLS_PSA_CRYPTO_C)
  22. #if defined(MBEDTLS_PSA_CRYPTO_CONFIG)
  23. #include "check_crypto_config.h"
  24. #endif
  25. #include "psa/crypto.h"
  26. #include "psa_crypto_cipher.h"
  27. #include "psa_crypto_core.h"
  28. #include "psa_crypto_invasive.h"
  29. #include "psa_crypto_driver_wrappers.h"
  30. #include "psa_crypto_ecp.h"
  31. #include "psa_crypto_hash.h"
  32. #include "psa_crypto_mac.h"
  33. #include "psa_crypto_rsa.h"
  34. #include "psa_crypto_ecp.h"
  35. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  36. #include "psa_crypto_se.h"
  37. #endif
  38. #include "psa_crypto_slot_management.h"
  39. /* Include internal declarations that are useful for implementing persistently
  40. * stored keys. */
  41. #include "psa_crypto_storage.h"
  42. #include "psa_crypto_random_impl.h"
  43. #include <assert.h>
  44. #include <stdlib.h>
  45. #include <string.h>
  46. #include "mbedtls/platform.h"
  47. #if !defined(MBEDTLS_PLATFORM_C)
  48. #define mbedtls_calloc calloc
  49. #define mbedtls_free free
  50. #endif
  51. #include "mbedtls/aes.h"
  52. #include "mbedtls/arc4.h"
  53. #include "mbedtls/asn1.h"
  54. #include "mbedtls/asn1write.h"
  55. #include "mbedtls/bignum.h"
  56. #include "mbedtls/blowfish.h"
  57. #include "mbedtls/camellia.h"
  58. #include "mbedtls/chacha20.h"
  59. #include "mbedtls/chachapoly.h"
  60. #include "mbedtls/cipher.h"
  61. #include "mbedtls/ccm.h"
  62. #include "mbedtls/cmac.h"
  63. #include "mbedtls/des.h"
  64. #include "mbedtls/ecdh.h"
  65. #include "mbedtls/ecp.h"
  66. #include "mbedtls/entropy.h"
  67. #include "mbedtls/error.h"
  68. #include "mbedtls/gcm.h"
  69. #include "mbedtls/md2.h"
  70. #include "mbedtls/md4.h"
  71. #include "mbedtls/md5.h"
  72. #include "mbedtls/md.h"
  73. #include "mbedtls/md_internal.h"
  74. #include "mbedtls/pk.h"
  75. #include "mbedtls/pk_internal.h"
  76. #include "mbedtls/platform_util.h"
  77. #include "mbedtls/error.h"
  78. #include "mbedtls/ripemd160.h"
  79. #include "mbedtls/rsa.h"
  80. #include "mbedtls/sha1.h"
  81. #include "mbedtls/sha256.h"
  82. #include "mbedtls/sha512.h"
  83. #include "mbedtls/xtea.h"
  84. #define ARRAY_LENGTH( array ) ( sizeof( array ) / sizeof( *( array ) ) )
  85. /****************************************************************/
  86. /* Global data, support functions and library management */
  87. /****************************************************************/
  88. static int key_type_is_raw_bytes( psa_key_type_t type )
  89. {
  90. return( PSA_KEY_TYPE_IS_UNSTRUCTURED( type ) );
  91. }
  92. /* Values for psa_global_data_t::rng_state */
  93. #define RNG_NOT_INITIALIZED 0
  94. #define RNG_INITIALIZED 1
  95. #define RNG_SEEDED 2
  96. typedef struct
  97. {
  98. unsigned initialized : 1;
  99. unsigned rng_state : 2;
  100. mbedtls_psa_random_context_t rng;
  101. } psa_global_data_t;
  102. static psa_global_data_t global_data;
  103. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  104. mbedtls_psa_drbg_context_t *const mbedtls_psa_random_state =
  105. &global_data.rng.drbg;
  106. #endif
  107. #define GUARD_MODULE_INITIALIZED \
  108. if( global_data.initialized == 0 ) \
  109. return( PSA_ERROR_BAD_STATE );
  110. psa_status_t mbedtls_to_psa_error( int ret )
  111. {
  112. /* Mbed TLS error codes can combine a high-level error code and a
  113. * low-level error code. The low-level error usually reflects the
  114. * root cause better, so dispatch on that preferably. */
  115. int low_level_ret = - ( -ret & 0x007f );
  116. switch( low_level_ret != 0 ? low_level_ret : ret )
  117. {
  118. case 0:
  119. return( PSA_SUCCESS );
  120. case MBEDTLS_ERR_AES_INVALID_KEY_LENGTH:
  121. case MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH:
  122. case MBEDTLS_ERR_AES_FEATURE_UNAVAILABLE:
  123. return( PSA_ERROR_NOT_SUPPORTED );
  124. case MBEDTLS_ERR_AES_HW_ACCEL_FAILED:
  125. return( PSA_ERROR_HARDWARE_FAILURE );
  126. case MBEDTLS_ERR_ARC4_HW_ACCEL_FAILED:
  127. return( PSA_ERROR_HARDWARE_FAILURE );
  128. case MBEDTLS_ERR_ASN1_OUT_OF_DATA:
  129. case MBEDTLS_ERR_ASN1_UNEXPECTED_TAG:
  130. case MBEDTLS_ERR_ASN1_INVALID_LENGTH:
  131. case MBEDTLS_ERR_ASN1_LENGTH_MISMATCH:
  132. case MBEDTLS_ERR_ASN1_INVALID_DATA:
  133. return( PSA_ERROR_INVALID_ARGUMENT );
  134. case MBEDTLS_ERR_ASN1_ALLOC_FAILED:
  135. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  136. case MBEDTLS_ERR_ASN1_BUF_TOO_SMALL:
  137. return( PSA_ERROR_BUFFER_TOO_SMALL );
  138. #if defined(MBEDTLS_ERR_BLOWFISH_BAD_INPUT_DATA)
  139. case MBEDTLS_ERR_BLOWFISH_BAD_INPUT_DATA:
  140. #elif defined(MBEDTLS_ERR_BLOWFISH_INVALID_KEY_LENGTH)
  141. case MBEDTLS_ERR_BLOWFISH_INVALID_KEY_LENGTH:
  142. #endif
  143. case MBEDTLS_ERR_BLOWFISH_INVALID_INPUT_LENGTH:
  144. return( PSA_ERROR_NOT_SUPPORTED );
  145. case MBEDTLS_ERR_BLOWFISH_HW_ACCEL_FAILED:
  146. return( PSA_ERROR_HARDWARE_FAILURE );
  147. #if defined(MBEDTLS_ERR_CAMELLIA_BAD_INPUT_DATA)
  148. case MBEDTLS_ERR_CAMELLIA_BAD_INPUT_DATA:
  149. #elif defined(MBEDTLS_ERR_CAMELLIA_INVALID_KEY_LENGTH)
  150. case MBEDTLS_ERR_CAMELLIA_INVALID_KEY_LENGTH:
  151. #endif
  152. case MBEDTLS_ERR_CAMELLIA_INVALID_INPUT_LENGTH:
  153. return( PSA_ERROR_NOT_SUPPORTED );
  154. case MBEDTLS_ERR_CAMELLIA_HW_ACCEL_FAILED:
  155. return( PSA_ERROR_HARDWARE_FAILURE );
  156. case MBEDTLS_ERR_CCM_BAD_INPUT:
  157. return( PSA_ERROR_INVALID_ARGUMENT );
  158. case MBEDTLS_ERR_CCM_AUTH_FAILED:
  159. return( PSA_ERROR_INVALID_SIGNATURE );
  160. case MBEDTLS_ERR_CCM_HW_ACCEL_FAILED:
  161. return( PSA_ERROR_HARDWARE_FAILURE );
  162. case MBEDTLS_ERR_CHACHA20_BAD_INPUT_DATA:
  163. return( PSA_ERROR_INVALID_ARGUMENT );
  164. case MBEDTLS_ERR_CHACHAPOLY_BAD_STATE:
  165. return( PSA_ERROR_BAD_STATE );
  166. case MBEDTLS_ERR_CHACHAPOLY_AUTH_FAILED:
  167. return( PSA_ERROR_INVALID_SIGNATURE );
  168. case MBEDTLS_ERR_CIPHER_FEATURE_UNAVAILABLE:
  169. return( PSA_ERROR_NOT_SUPPORTED );
  170. case MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA:
  171. return( PSA_ERROR_INVALID_ARGUMENT );
  172. case MBEDTLS_ERR_CIPHER_ALLOC_FAILED:
  173. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  174. case MBEDTLS_ERR_CIPHER_INVALID_PADDING:
  175. return( PSA_ERROR_INVALID_PADDING );
  176. case MBEDTLS_ERR_CIPHER_FULL_BLOCK_EXPECTED:
  177. return( PSA_ERROR_INVALID_ARGUMENT );
  178. case MBEDTLS_ERR_CIPHER_AUTH_FAILED:
  179. return( PSA_ERROR_INVALID_SIGNATURE );
  180. case MBEDTLS_ERR_CIPHER_INVALID_CONTEXT:
  181. return( PSA_ERROR_CORRUPTION_DETECTED );
  182. case MBEDTLS_ERR_CIPHER_HW_ACCEL_FAILED:
  183. return( PSA_ERROR_HARDWARE_FAILURE );
  184. case MBEDTLS_ERR_CMAC_HW_ACCEL_FAILED:
  185. return( PSA_ERROR_HARDWARE_FAILURE );
  186. #if !( defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) || \
  187. defined(MBEDTLS_PSA_HMAC_DRBG_MD_TYPE) )
  188. /* Only check CTR_DRBG error codes if underlying mbedtls_xxx
  189. * functions are passed a CTR_DRBG instance. */
  190. case MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED:
  191. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  192. case MBEDTLS_ERR_CTR_DRBG_REQUEST_TOO_BIG:
  193. case MBEDTLS_ERR_CTR_DRBG_INPUT_TOO_BIG:
  194. return( PSA_ERROR_NOT_SUPPORTED );
  195. case MBEDTLS_ERR_CTR_DRBG_FILE_IO_ERROR:
  196. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  197. #endif
  198. case MBEDTLS_ERR_DES_INVALID_INPUT_LENGTH:
  199. return( PSA_ERROR_NOT_SUPPORTED );
  200. case MBEDTLS_ERR_DES_HW_ACCEL_FAILED:
  201. return( PSA_ERROR_HARDWARE_FAILURE );
  202. case MBEDTLS_ERR_ENTROPY_NO_SOURCES_DEFINED:
  203. case MBEDTLS_ERR_ENTROPY_NO_STRONG_SOURCE:
  204. case MBEDTLS_ERR_ENTROPY_SOURCE_FAILED:
  205. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  206. case MBEDTLS_ERR_GCM_AUTH_FAILED:
  207. return( PSA_ERROR_INVALID_SIGNATURE );
  208. case MBEDTLS_ERR_GCM_BAD_INPUT:
  209. return( PSA_ERROR_INVALID_ARGUMENT );
  210. case MBEDTLS_ERR_GCM_HW_ACCEL_FAILED:
  211. return( PSA_ERROR_HARDWARE_FAILURE );
  212. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) && \
  213. defined(MBEDTLS_PSA_HMAC_DRBG_MD_TYPE)
  214. /* Only check HMAC_DRBG error codes if underlying mbedtls_xxx
  215. * functions are passed a HMAC_DRBG instance. */
  216. case MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED:
  217. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  218. case MBEDTLS_ERR_HMAC_DRBG_REQUEST_TOO_BIG:
  219. case MBEDTLS_ERR_HMAC_DRBG_INPUT_TOO_BIG:
  220. return( PSA_ERROR_NOT_SUPPORTED );
  221. case MBEDTLS_ERR_HMAC_DRBG_FILE_IO_ERROR:
  222. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  223. #endif
  224. case MBEDTLS_ERR_MD2_HW_ACCEL_FAILED:
  225. case MBEDTLS_ERR_MD4_HW_ACCEL_FAILED:
  226. case MBEDTLS_ERR_MD5_HW_ACCEL_FAILED:
  227. return( PSA_ERROR_HARDWARE_FAILURE );
  228. case MBEDTLS_ERR_MD_FEATURE_UNAVAILABLE:
  229. return( PSA_ERROR_NOT_SUPPORTED );
  230. case MBEDTLS_ERR_MD_BAD_INPUT_DATA:
  231. return( PSA_ERROR_INVALID_ARGUMENT );
  232. case MBEDTLS_ERR_MD_ALLOC_FAILED:
  233. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  234. case MBEDTLS_ERR_MD_FILE_IO_ERROR:
  235. return( PSA_ERROR_STORAGE_FAILURE );
  236. case MBEDTLS_ERR_MD_HW_ACCEL_FAILED:
  237. return( PSA_ERROR_HARDWARE_FAILURE );
  238. case MBEDTLS_ERR_MPI_FILE_IO_ERROR:
  239. return( PSA_ERROR_STORAGE_FAILURE );
  240. case MBEDTLS_ERR_MPI_BAD_INPUT_DATA:
  241. return( PSA_ERROR_INVALID_ARGUMENT );
  242. case MBEDTLS_ERR_MPI_INVALID_CHARACTER:
  243. return( PSA_ERROR_INVALID_ARGUMENT );
  244. case MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL:
  245. return( PSA_ERROR_BUFFER_TOO_SMALL );
  246. case MBEDTLS_ERR_MPI_NEGATIVE_VALUE:
  247. return( PSA_ERROR_INVALID_ARGUMENT );
  248. case MBEDTLS_ERR_MPI_DIVISION_BY_ZERO:
  249. return( PSA_ERROR_INVALID_ARGUMENT );
  250. case MBEDTLS_ERR_MPI_NOT_ACCEPTABLE:
  251. return( PSA_ERROR_INVALID_ARGUMENT );
  252. case MBEDTLS_ERR_MPI_ALLOC_FAILED:
  253. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  254. case MBEDTLS_ERR_PK_ALLOC_FAILED:
  255. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  256. case MBEDTLS_ERR_PK_TYPE_MISMATCH:
  257. case MBEDTLS_ERR_PK_BAD_INPUT_DATA:
  258. return( PSA_ERROR_INVALID_ARGUMENT );
  259. case MBEDTLS_ERR_PK_FILE_IO_ERROR:
  260. return( PSA_ERROR_STORAGE_FAILURE );
  261. case MBEDTLS_ERR_PK_KEY_INVALID_VERSION:
  262. case MBEDTLS_ERR_PK_KEY_INVALID_FORMAT:
  263. return( PSA_ERROR_INVALID_ARGUMENT );
  264. case MBEDTLS_ERR_PK_UNKNOWN_PK_ALG:
  265. return( PSA_ERROR_NOT_SUPPORTED );
  266. case MBEDTLS_ERR_PK_PASSWORD_REQUIRED:
  267. case MBEDTLS_ERR_PK_PASSWORD_MISMATCH:
  268. return( PSA_ERROR_NOT_PERMITTED );
  269. case MBEDTLS_ERR_PK_INVALID_PUBKEY:
  270. return( PSA_ERROR_INVALID_ARGUMENT );
  271. case MBEDTLS_ERR_PK_INVALID_ALG:
  272. case MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE:
  273. case MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE:
  274. return( PSA_ERROR_NOT_SUPPORTED );
  275. case MBEDTLS_ERR_PK_SIG_LEN_MISMATCH:
  276. return( PSA_ERROR_INVALID_SIGNATURE );
  277. case MBEDTLS_ERR_PK_HW_ACCEL_FAILED:
  278. return( PSA_ERROR_HARDWARE_FAILURE );
  279. case MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED:
  280. return( PSA_ERROR_HARDWARE_FAILURE );
  281. case MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED:
  282. return( PSA_ERROR_NOT_SUPPORTED );
  283. case MBEDTLS_ERR_RIPEMD160_HW_ACCEL_FAILED:
  284. return( PSA_ERROR_HARDWARE_FAILURE );
  285. case MBEDTLS_ERR_RSA_BAD_INPUT_DATA:
  286. return( PSA_ERROR_INVALID_ARGUMENT );
  287. case MBEDTLS_ERR_RSA_INVALID_PADDING:
  288. return( PSA_ERROR_INVALID_PADDING );
  289. case MBEDTLS_ERR_RSA_KEY_GEN_FAILED:
  290. return( PSA_ERROR_HARDWARE_FAILURE );
  291. case MBEDTLS_ERR_RSA_KEY_CHECK_FAILED:
  292. return( PSA_ERROR_INVALID_ARGUMENT );
  293. case MBEDTLS_ERR_RSA_PUBLIC_FAILED:
  294. case MBEDTLS_ERR_RSA_PRIVATE_FAILED:
  295. return( PSA_ERROR_CORRUPTION_DETECTED );
  296. case MBEDTLS_ERR_RSA_VERIFY_FAILED:
  297. return( PSA_ERROR_INVALID_SIGNATURE );
  298. case MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE:
  299. return( PSA_ERROR_BUFFER_TOO_SMALL );
  300. case MBEDTLS_ERR_RSA_RNG_FAILED:
  301. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  302. case MBEDTLS_ERR_RSA_UNSUPPORTED_OPERATION:
  303. return( PSA_ERROR_NOT_SUPPORTED );
  304. case MBEDTLS_ERR_RSA_HW_ACCEL_FAILED:
  305. return( PSA_ERROR_HARDWARE_FAILURE );
  306. case MBEDTLS_ERR_SHA1_HW_ACCEL_FAILED:
  307. case MBEDTLS_ERR_SHA256_HW_ACCEL_FAILED:
  308. case MBEDTLS_ERR_SHA512_HW_ACCEL_FAILED:
  309. return( PSA_ERROR_HARDWARE_FAILURE );
  310. case MBEDTLS_ERR_XTEA_INVALID_INPUT_LENGTH:
  311. return( PSA_ERROR_INVALID_ARGUMENT );
  312. case MBEDTLS_ERR_XTEA_HW_ACCEL_FAILED:
  313. return( PSA_ERROR_HARDWARE_FAILURE );
  314. case MBEDTLS_ERR_ECP_BAD_INPUT_DATA:
  315. case MBEDTLS_ERR_ECP_INVALID_KEY:
  316. return( PSA_ERROR_INVALID_ARGUMENT );
  317. case MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL:
  318. return( PSA_ERROR_BUFFER_TOO_SMALL );
  319. case MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE:
  320. return( PSA_ERROR_NOT_SUPPORTED );
  321. case MBEDTLS_ERR_ECP_SIG_LEN_MISMATCH:
  322. case MBEDTLS_ERR_ECP_VERIFY_FAILED:
  323. return( PSA_ERROR_INVALID_SIGNATURE );
  324. case MBEDTLS_ERR_ECP_ALLOC_FAILED:
  325. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  326. case MBEDTLS_ERR_ECP_RANDOM_FAILED:
  327. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  328. case MBEDTLS_ERR_ECP_HW_ACCEL_FAILED:
  329. return( PSA_ERROR_HARDWARE_FAILURE );
  330. case MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED:
  331. return( PSA_ERROR_CORRUPTION_DETECTED );
  332. default:
  333. return( PSA_ERROR_GENERIC_ERROR );
  334. }
  335. }
  336. /****************************************************************/
  337. /* Key management */
  338. /****************************************************************/
  339. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  340. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) || \
  341. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  342. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) || \
  343. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  344. mbedtls_ecp_group_id mbedtls_ecc_group_of_psa( psa_ecc_family_t curve,
  345. size_t bits,
  346. int bits_is_sloppy )
  347. {
  348. switch( curve )
  349. {
  350. case PSA_ECC_FAMILY_SECP_R1:
  351. switch( bits )
  352. {
  353. #if defined(PSA_WANT_ECC_SECP_R1_192)
  354. case 192:
  355. return( MBEDTLS_ECP_DP_SECP192R1 );
  356. #endif
  357. #if defined(PSA_WANT_ECC_SECP_R1_224)
  358. case 224:
  359. return( MBEDTLS_ECP_DP_SECP224R1 );
  360. #endif
  361. #if defined(PSA_WANT_ECC_SECP_R1_256)
  362. case 256:
  363. return( MBEDTLS_ECP_DP_SECP256R1 );
  364. #endif
  365. #if defined(PSA_WANT_ECC_SECP_R1_384)
  366. case 384:
  367. return( MBEDTLS_ECP_DP_SECP384R1 );
  368. #endif
  369. #if defined(PSA_WANT_ECC_SECP_R1_521)
  370. case 521:
  371. return( MBEDTLS_ECP_DP_SECP521R1 );
  372. case 528:
  373. if( bits_is_sloppy )
  374. return( MBEDTLS_ECP_DP_SECP521R1 );
  375. break;
  376. #endif
  377. }
  378. break;
  379. case PSA_ECC_FAMILY_BRAINPOOL_P_R1:
  380. switch( bits )
  381. {
  382. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_256)
  383. case 256:
  384. return( MBEDTLS_ECP_DP_BP256R1 );
  385. #endif
  386. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_384)
  387. case 384:
  388. return( MBEDTLS_ECP_DP_BP384R1 );
  389. #endif
  390. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_512)
  391. case 512:
  392. return( MBEDTLS_ECP_DP_BP512R1 );
  393. #endif
  394. }
  395. break;
  396. case PSA_ECC_FAMILY_MONTGOMERY:
  397. switch( bits )
  398. {
  399. #if defined(PSA_WANT_ECC_MONTGOMERY_255)
  400. case 255:
  401. return( MBEDTLS_ECP_DP_CURVE25519 );
  402. case 256:
  403. if( bits_is_sloppy )
  404. return( MBEDTLS_ECP_DP_CURVE25519 );
  405. break;
  406. #endif
  407. #if defined(PSA_WANT_ECC_MONTGOMERY_448)
  408. case 448:
  409. return( MBEDTLS_ECP_DP_CURVE448 );
  410. #endif
  411. }
  412. break;
  413. case PSA_ECC_FAMILY_SECP_K1:
  414. switch( bits )
  415. {
  416. #if defined(PSA_WANT_ECC_SECP_K1_192)
  417. case 192:
  418. return( MBEDTLS_ECP_DP_SECP192K1 );
  419. #endif
  420. #if defined(PSA_WANT_ECC_SECP_K1_224)
  421. case 224:
  422. return( MBEDTLS_ECP_DP_SECP224K1 );
  423. #endif
  424. #if defined(PSA_WANT_ECC_SECP_K1_256)
  425. case 256:
  426. return( MBEDTLS_ECP_DP_SECP256K1 );
  427. #endif
  428. }
  429. break;
  430. }
  431. (void) bits_is_sloppy;
  432. return( MBEDTLS_ECP_DP_NONE );
  433. }
  434. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  435. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) ||
  436. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  437. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) ||
  438. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH) */
  439. static psa_status_t validate_unstructured_key_bit_size( psa_key_type_t type,
  440. size_t bits )
  441. {
  442. /* Check that the bit size is acceptable for the key type */
  443. switch( type )
  444. {
  445. case PSA_KEY_TYPE_RAW_DATA:
  446. case PSA_KEY_TYPE_HMAC:
  447. case PSA_KEY_TYPE_DERIVE:
  448. break;
  449. #if defined(PSA_WANT_KEY_TYPE_AES)
  450. case PSA_KEY_TYPE_AES:
  451. if( bits != 128 && bits != 192 && bits != 256 )
  452. return( PSA_ERROR_INVALID_ARGUMENT );
  453. break;
  454. #endif
  455. #if defined(PSA_WANT_KEY_TYPE_ARIA)
  456. case PSA_KEY_TYPE_ARIA:
  457. if( bits != 128 && bits != 192 && bits != 256 )
  458. return( PSA_ERROR_INVALID_ARGUMENT );
  459. break;
  460. #endif
  461. #if defined(PSA_WANT_KEY_TYPE_CAMELLIA)
  462. case PSA_KEY_TYPE_CAMELLIA:
  463. if( bits != 128 && bits != 192 && bits != 256 )
  464. return( PSA_ERROR_INVALID_ARGUMENT );
  465. break;
  466. #endif
  467. #if defined(PSA_WANT_KEY_TYPE_DES)
  468. case PSA_KEY_TYPE_DES:
  469. if( bits != 64 && bits != 128 && bits != 192 )
  470. return( PSA_ERROR_INVALID_ARGUMENT );
  471. break;
  472. #endif
  473. #if defined(PSA_WANT_KEY_TYPE_ARC4)
  474. case PSA_KEY_TYPE_ARC4:
  475. if( bits < 8 || bits > 2048 )
  476. return( PSA_ERROR_INVALID_ARGUMENT );
  477. break;
  478. #endif
  479. #if defined(PSA_WANT_KEY_TYPE_CHACHA20)
  480. case PSA_KEY_TYPE_CHACHA20:
  481. if( bits != 256 )
  482. return( PSA_ERROR_INVALID_ARGUMENT );
  483. break;
  484. #endif
  485. default:
  486. return( PSA_ERROR_NOT_SUPPORTED );
  487. }
  488. if( bits % 8 != 0 )
  489. return( PSA_ERROR_INVALID_ARGUMENT );
  490. return( PSA_SUCCESS );
  491. }
  492. /** Check whether a given key type is valid for use with a given MAC algorithm
  493. *
  494. * Upon successful return of this function, the behavior of #PSA_MAC_LENGTH
  495. * when called with the validated \p algorithm and \p key_type is well-defined.
  496. *
  497. * \param[in] algorithm The specific MAC algorithm (can be wildcard).
  498. * \param[in] key_type The key type of the key to be used with the
  499. * \p algorithm.
  500. *
  501. * \retval #PSA_SUCCESS
  502. * The \p key_type is valid for use with the \p algorithm
  503. * \retval #PSA_ERROR_INVALID_ARGUMENT
  504. * The \p key_type is not valid for use with the \p algorithm
  505. */
  506. MBEDTLS_STATIC_TESTABLE psa_status_t psa_mac_key_can_do(
  507. psa_algorithm_t algorithm,
  508. psa_key_type_t key_type )
  509. {
  510. if( PSA_ALG_IS_HMAC( algorithm ) )
  511. {
  512. if( key_type == PSA_KEY_TYPE_HMAC )
  513. return( PSA_SUCCESS );
  514. }
  515. if( PSA_ALG_IS_BLOCK_CIPHER_MAC( algorithm ) )
  516. {
  517. /* Check that we're calling PSA_BLOCK_CIPHER_BLOCK_LENGTH with a cipher
  518. * key. */
  519. if( ( key_type & PSA_KEY_TYPE_CATEGORY_MASK ) ==
  520. PSA_KEY_TYPE_CATEGORY_SYMMETRIC )
  521. {
  522. /* PSA_BLOCK_CIPHER_BLOCK_LENGTH returns 1 for stream ciphers and
  523. * the block length (larger than 1) for block ciphers. */
  524. if( PSA_BLOCK_CIPHER_BLOCK_LENGTH( key_type ) > 1 )
  525. return( PSA_SUCCESS );
  526. }
  527. }
  528. return( PSA_ERROR_INVALID_ARGUMENT );
  529. }
  530. psa_status_t psa_allocate_buffer_to_slot( psa_key_slot_t *slot,
  531. size_t buffer_length )
  532. {
  533. if( slot->key.data != NULL )
  534. return( PSA_ERROR_ALREADY_EXISTS );
  535. slot->key.data = mbedtls_calloc( 1, buffer_length );
  536. if( slot->key.data == NULL )
  537. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  538. slot->key.bytes = buffer_length;
  539. return( PSA_SUCCESS );
  540. }
  541. psa_status_t psa_copy_key_material_into_slot( psa_key_slot_t *slot,
  542. const uint8_t* data,
  543. size_t data_length )
  544. {
  545. psa_status_t status = psa_allocate_buffer_to_slot( slot,
  546. data_length );
  547. if( status != PSA_SUCCESS )
  548. return( status );
  549. memcpy( slot->key.data, data, data_length );
  550. return( PSA_SUCCESS );
  551. }
  552. psa_status_t psa_import_key_into_slot(
  553. const psa_key_attributes_t *attributes,
  554. const uint8_t *data, size_t data_length,
  555. uint8_t *key_buffer, size_t key_buffer_size,
  556. size_t *key_buffer_length, size_t *bits )
  557. {
  558. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  559. psa_key_type_t type = attributes->core.type;
  560. /* zero-length keys are never supported. */
  561. if( data_length == 0 )
  562. return( PSA_ERROR_NOT_SUPPORTED );
  563. if( key_type_is_raw_bytes( type ) )
  564. {
  565. *bits = PSA_BYTES_TO_BITS( data_length );
  566. /* Ensure that the bytes-to-bits conversion hasn't overflown. */
  567. if( data_length > SIZE_MAX / 8 )
  568. return( PSA_ERROR_NOT_SUPPORTED );
  569. /* Enforce a size limit, and in particular ensure that the bit
  570. * size fits in its representation type. */
  571. if( ( *bits ) > PSA_MAX_KEY_BITS )
  572. return( PSA_ERROR_NOT_SUPPORTED );
  573. status = validate_unstructured_key_bit_size( type, *bits );
  574. if( status != PSA_SUCCESS )
  575. return( status );
  576. /* Copy the key material. */
  577. memcpy( key_buffer, data, data_length );
  578. *key_buffer_length = data_length;
  579. (void)key_buffer_size;
  580. return( PSA_SUCCESS );
  581. }
  582. else if( PSA_KEY_TYPE_IS_ASYMMETRIC( type ) )
  583. {
  584. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  585. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY)
  586. if( PSA_KEY_TYPE_IS_ECC( type ) )
  587. {
  588. return( mbedtls_psa_ecp_import_key( attributes,
  589. data, data_length,
  590. key_buffer, key_buffer_size,
  591. key_buffer_length,
  592. bits ) );
  593. }
  594. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  595. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) */
  596. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  597. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  598. if( PSA_KEY_TYPE_IS_RSA( type ) )
  599. {
  600. return( mbedtls_psa_rsa_import_key( attributes,
  601. data, data_length,
  602. key_buffer, key_buffer_size,
  603. key_buffer_length,
  604. bits ) );
  605. }
  606. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  607. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  608. }
  609. return( PSA_ERROR_NOT_SUPPORTED );
  610. }
  611. /** Calculate the intersection of two algorithm usage policies.
  612. *
  613. * Return 0 (which allows no operation) on incompatibility.
  614. */
  615. static psa_algorithm_t psa_key_policy_algorithm_intersection(
  616. psa_key_type_t key_type,
  617. psa_algorithm_t alg1,
  618. psa_algorithm_t alg2 )
  619. {
  620. /* Common case: both sides actually specify the same policy. */
  621. if( alg1 == alg2 )
  622. return( alg1 );
  623. /* If the policies are from the same hash-and-sign family, check
  624. * if one is a wildcard. If so the other has the specific algorithm. */
  625. if( PSA_ALG_IS_SIGN_HASH( alg1 ) &&
  626. PSA_ALG_IS_SIGN_HASH( alg2 ) &&
  627. ( alg1 & ~PSA_ALG_HASH_MASK ) == ( alg2 & ~PSA_ALG_HASH_MASK ) )
  628. {
  629. if( PSA_ALG_SIGN_GET_HASH( alg1 ) == PSA_ALG_ANY_HASH )
  630. return( alg2 );
  631. if( PSA_ALG_SIGN_GET_HASH( alg2 ) == PSA_ALG_ANY_HASH )
  632. return( alg1 );
  633. }
  634. /* If the policies are from the same AEAD family, check whether
  635. * one of them is a minimum-tag-length wildcard. Calculate the most
  636. * restrictive tag length. */
  637. if( PSA_ALG_IS_AEAD( alg1 ) && PSA_ALG_IS_AEAD( alg2 ) &&
  638. ( PSA_ALG_AEAD_WITH_SHORTENED_TAG( alg1, 0 ) ==
  639. PSA_ALG_AEAD_WITH_SHORTENED_TAG( alg2, 0 ) ) )
  640. {
  641. size_t alg1_len = PSA_ALG_AEAD_GET_TAG_LENGTH( alg1 );
  642. size_t alg2_len = PSA_ALG_AEAD_GET_TAG_LENGTH( alg2 );
  643. size_t restricted_len = alg1_len > alg2_len ? alg1_len : alg2_len;
  644. /* If both are wildcards, return most restrictive wildcard */
  645. if( ( ( alg1 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  646. ( ( alg2 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) )
  647. {
  648. return( PSA_ALG_AEAD_WITH_AT_LEAST_THIS_LENGTH_TAG(
  649. alg1, restricted_len ) );
  650. }
  651. /* If only one is a wildcard, return specific algorithm if compatible. */
  652. if( ( ( alg1 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  653. ( alg1_len <= alg2_len ) )
  654. {
  655. return( alg2 );
  656. }
  657. if( ( ( alg2 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  658. ( alg2_len <= alg1_len ) )
  659. {
  660. return( alg1 );
  661. }
  662. }
  663. /* If the policies are from the same MAC family, check whether one
  664. * of them is a minimum-MAC-length policy. Calculate the most
  665. * restrictive tag length. */
  666. if( PSA_ALG_IS_MAC( alg1 ) && PSA_ALG_IS_MAC( alg2 ) &&
  667. ( PSA_ALG_FULL_LENGTH_MAC( alg1 ) ==
  668. PSA_ALG_FULL_LENGTH_MAC( alg2 ) ) )
  669. {
  670. /* Validate the combination of key type and algorithm. Since the base
  671. * algorithm of alg1 and alg2 are the same, we only need this once. */
  672. if( PSA_SUCCESS != psa_mac_key_can_do( alg1, key_type ) )
  673. return( 0 );
  674. /* Get the (exact or at-least) output lengths for both sides of the
  675. * requested intersection. None of the currently supported algorithms
  676. * have an output length dependent on the actual key size, so setting it
  677. * to a bogus value of 0 is currently OK.
  678. *
  679. * Note that for at-least-this-length wildcard algorithms, the output
  680. * length is set to the shortest allowed length, which allows us to
  681. * calculate the most restrictive tag length for the intersection. */
  682. size_t alg1_len = PSA_MAC_LENGTH( key_type, 0, alg1 );
  683. size_t alg2_len = PSA_MAC_LENGTH( key_type, 0, alg2 );
  684. size_t restricted_len = alg1_len > alg2_len ? alg1_len : alg2_len;
  685. /* If both are wildcards, return most restrictive wildcard */
  686. if( ( ( alg1 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  687. ( ( alg2 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) )
  688. {
  689. return( PSA_ALG_AT_LEAST_THIS_LENGTH_MAC( alg1, restricted_len ) );
  690. }
  691. /* If only one is an at-least-this-length policy, the intersection would
  692. * be the other (fixed-length) policy as long as said fixed length is
  693. * equal to or larger than the shortest allowed length. */
  694. if( ( alg1 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 )
  695. {
  696. return( ( alg1_len <= alg2_len ) ? alg2 : 0 );
  697. }
  698. if( ( alg2 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 )
  699. {
  700. return( ( alg2_len <= alg1_len ) ? alg1 : 0 );
  701. }
  702. /* If none of them are wildcards, check whether they define the same tag
  703. * length. This is still possible here when one is default-length and
  704. * the other specific-length. Ensure to always return the
  705. * specific-length version for the intersection. */
  706. if( alg1_len == alg2_len )
  707. return( PSA_ALG_TRUNCATED_MAC( alg1, alg1_len ) );
  708. }
  709. /* If the policies are incompatible, allow nothing. */
  710. return( 0 );
  711. }
  712. static int psa_key_algorithm_permits( psa_key_type_t key_type,
  713. psa_algorithm_t policy_alg,
  714. psa_algorithm_t requested_alg )
  715. {
  716. /* Common case: the policy only allows requested_alg. */
  717. if( requested_alg == policy_alg )
  718. return( 1 );
  719. /* If policy_alg is a hash-and-sign with a wildcard for the hash,
  720. * and requested_alg is the same hash-and-sign family with any hash,
  721. * then requested_alg is compliant with policy_alg. */
  722. if( PSA_ALG_IS_SIGN_HASH( requested_alg ) &&
  723. PSA_ALG_SIGN_GET_HASH( policy_alg ) == PSA_ALG_ANY_HASH )
  724. {
  725. return( ( policy_alg & ~PSA_ALG_HASH_MASK ) ==
  726. ( requested_alg & ~PSA_ALG_HASH_MASK ) );
  727. }
  728. /* If policy_alg is a wildcard AEAD algorithm of the same base as
  729. * the requested algorithm, check the requested tag length to be
  730. * equal-length or longer than the wildcard-specified length. */
  731. if( PSA_ALG_IS_AEAD( policy_alg ) &&
  732. PSA_ALG_IS_AEAD( requested_alg ) &&
  733. ( PSA_ALG_AEAD_WITH_SHORTENED_TAG( policy_alg, 0 ) ==
  734. PSA_ALG_AEAD_WITH_SHORTENED_TAG( requested_alg, 0 ) ) &&
  735. ( ( policy_alg & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) )
  736. {
  737. return( PSA_ALG_AEAD_GET_TAG_LENGTH( policy_alg ) <=
  738. PSA_ALG_AEAD_GET_TAG_LENGTH( requested_alg ) );
  739. }
  740. /* If policy_alg is a MAC algorithm of the same base as the requested
  741. * algorithm, check whether their MAC lengths are compatible. */
  742. if( PSA_ALG_IS_MAC( policy_alg ) &&
  743. PSA_ALG_IS_MAC( requested_alg ) &&
  744. ( PSA_ALG_FULL_LENGTH_MAC( policy_alg ) ==
  745. PSA_ALG_FULL_LENGTH_MAC( requested_alg ) ) )
  746. {
  747. /* Validate the combination of key type and algorithm. Since the policy
  748. * and requested algorithms are the same, we only need this once. */
  749. if( PSA_SUCCESS != psa_mac_key_can_do( policy_alg, key_type ) )
  750. return( 0 );
  751. /* Get both the requested output length for the algorithm which is to be
  752. * verified, and the default output length for the base algorithm.
  753. * Note that none of the currently supported algorithms have an output
  754. * length dependent on actual key size, so setting it to a bogus value
  755. * of 0 is currently OK. */
  756. size_t requested_output_length = PSA_MAC_LENGTH(
  757. key_type, 0, requested_alg );
  758. size_t default_output_length = PSA_MAC_LENGTH(
  759. key_type, 0,
  760. PSA_ALG_FULL_LENGTH_MAC( requested_alg ) );
  761. /* If the policy is default-length, only allow an algorithm with
  762. * a declared exact-length matching the default. */
  763. if( PSA_MAC_TRUNCATED_LENGTH( policy_alg ) == 0 )
  764. return( requested_output_length == default_output_length );
  765. /* If the requested algorithm is default-length, allow it if the policy
  766. * length exactly matches the default length. */
  767. if( PSA_MAC_TRUNCATED_LENGTH( requested_alg ) == 0 &&
  768. PSA_MAC_TRUNCATED_LENGTH( policy_alg ) == default_output_length )
  769. {
  770. return( 1 );
  771. }
  772. /* If policy_alg is an at-least-this-length wildcard MAC algorithm,
  773. * check for the requested MAC length to be equal to or longer than the
  774. * minimum allowed length. */
  775. if( ( policy_alg & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 )
  776. {
  777. return( PSA_MAC_TRUNCATED_LENGTH( policy_alg ) <=
  778. requested_output_length );
  779. }
  780. }
  781. /* If policy_alg is a generic key agreement operation, then using it for
  782. * a key derivation with that key agreement should also be allowed. This
  783. * behaviour is expected to be defined in a future specification version. */
  784. if( PSA_ALG_IS_RAW_KEY_AGREEMENT( policy_alg ) &&
  785. PSA_ALG_IS_KEY_AGREEMENT( requested_alg ) )
  786. {
  787. return( PSA_ALG_KEY_AGREEMENT_GET_BASE( requested_alg ) ==
  788. policy_alg );
  789. }
  790. /* If it isn't explicitly permitted, it's forbidden. */
  791. return( 0 );
  792. }
  793. /** Test whether a policy permits an algorithm.
  794. *
  795. * The caller must test usage flags separately.
  796. *
  797. * \note This function requires providing the key type for which the policy is
  798. * being validated, since some algorithm policy definitions (e.g. MAC)
  799. * have different properties depending on what kind of cipher it is
  800. * combined with.
  801. *
  802. * \retval PSA_SUCCESS When \p alg is a specific algorithm
  803. * allowed by the \p policy.
  804. * \retval PSA_ERROR_INVALID_ARGUMENT When \p alg is not a specific algorithm
  805. * \retval PSA_ERROR_NOT_PERMITTED When \p alg is a specific algorithm, but
  806. * the \p policy does not allow it.
  807. */
  808. static psa_status_t psa_key_policy_permits( const psa_key_policy_t *policy,
  809. psa_key_type_t key_type,
  810. psa_algorithm_t alg )
  811. {
  812. /* '0' is not a valid algorithm */
  813. if( alg == 0 )
  814. return( PSA_ERROR_INVALID_ARGUMENT );
  815. /* A requested algorithm cannot be a wildcard. */
  816. if( PSA_ALG_IS_WILDCARD( alg ) )
  817. return( PSA_ERROR_INVALID_ARGUMENT );
  818. if( psa_key_algorithm_permits( key_type, policy->alg, alg ) ||
  819. psa_key_algorithm_permits( key_type, policy->alg2, alg ) )
  820. return( PSA_SUCCESS );
  821. else
  822. return( PSA_ERROR_NOT_PERMITTED );
  823. }
  824. /** Restrict a key policy based on a constraint.
  825. *
  826. * \note This function requires providing the key type for which the policy is
  827. * being restricted, since some algorithm policy definitions (e.g. MAC)
  828. * have different properties depending on what kind of cipher it is
  829. * combined with.
  830. *
  831. * \param[in] key_type The key type for which to restrict the policy
  832. * \param[in,out] policy The policy to restrict.
  833. * \param[in] constraint The policy constraint to apply.
  834. *
  835. * \retval #PSA_SUCCESS
  836. * \c *policy contains the intersection of the original value of
  837. * \c *policy and \c *constraint.
  838. * \retval #PSA_ERROR_INVALID_ARGUMENT
  839. * \c key_type, \c *policy and \c *constraint are incompatible.
  840. * \c *policy is unchanged.
  841. */
  842. static psa_status_t psa_restrict_key_policy(
  843. psa_key_type_t key_type,
  844. psa_key_policy_t *policy,
  845. const psa_key_policy_t *constraint )
  846. {
  847. psa_algorithm_t intersection_alg =
  848. psa_key_policy_algorithm_intersection( key_type, policy->alg,
  849. constraint->alg );
  850. psa_algorithm_t intersection_alg2 =
  851. psa_key_policy_algorithm_intersection( key_type, policy->alg2,
  852. constraint->alg2 );
  853. if( intersection_alg == 0 && policy->alg != 0 && constraint->alg != 0 )
  854. return( PSA_ERROR_INVALID_ARGUMENT );
  855. if( intersection_alg2 == 0 && policy->alg2 != 0 && constraint->alg2 != 0 )
  856. return( PSA_ERROR_INVALID_ARGUMENT );
  857. policy->usage &= constraint->usage;
  858. policy->alg = intersection_alg;
  859. policy->alg2 = intersection_alg2;
  860. return( PSA_SUCCESS );
  861. }
  862. /** Get the description of a key given its identifier and policy constraints
  863. * and lock it.
  864. *
  865. * The key must have allow all the usage flags set in \p usage. If \p alg is
  866. * nonzero, the key must allow operations with this algorithm. If \p alg is
  867. * zero, the algorithm is not checked.
  868. *
  869. * In case of a persistent key, the function loads the description of the key
  870. * into a key slot if not already done.
  871. *
  872. * On success, the returned key slot is locked. It is the responsibility of
  873. * the caller to unlock the key slot when it does not access it anymore.
  874. */
  875. static psa_status_t psa_get_and_lock_key_slot_with_policy(
  876. mbedtls_svc_key_id_t key,
  877. psa_key_slot_t **p_slot,
  878. psa_key_usage_t usage,
  879. psa_algorithm_t alg )
  880. {
  881. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  882. psa_key_slot_t *slot;
  883. status = psa_get_and_lock_key_slot( key, p_slot );
  884. if( status != PSA_SUCCESS )
  885. return( status );
  886. slot = *p_slot;
  887. /* Enforce that usage policy for the key slot contains all the flags
  888. * required by the usage parameter. There is one exception: public
  889. * keys can always be exported, so we treat public key objects as
  890. * if they had the export flag. */
  891. if( PSA_KEY_TYPE_IS_PUBLIC_KEY( slot->attr.type ) )
  892. usage &= ~PSA_KEY_USAGE_EXPORT;
  893. if( ( slot->attr.policy.usage & usage ) != usage )
  894. {
  895. status = PSA_ERROR_NOT_PERMITTED;
  896. goto error;
  897. }
  898. /* Enforce that the usage policy permits the requested algorithm. */
  899. if( alg != 0 )
  900. {
  901. status = psa_key_policy_permits( &slot->attr.policy,
  902. slot->attr.type,
  903. alg );
  904. if( status != PSA_SUCCESS )
  905. goto error;
  906. }
  907. return( PSA_SUCCESS );
  908. error:
  909. *p_slot = NULL;
  910. psa_unlock_key_slot( slot );
  911. return( status );
  912. }
  913. /** Get a key slot containing a transparent key and lock it.
  914. *
  915. * A transparent key is a key for which the key material is directly
  916. * available, as opposed to a key in a secure element and/or to be used
  917. * by a secure element.
  918. *
  919. * This is a temporary function that may be used instead of
  920. * psa_get_and_lock_key_slot_with_policy() when there is no opaque key support
  921. * for a cryptographic operation.
  922. *
  923. * On success, the returned key slot is locked. It is the responsibility of the
  924. * caller to unlock the key slot when it does not access it anymore.
  925. */
  926. static psa_status_t psa_get_and_lock_transparent_key_slot_with_policy(
  927. mbedtls_svc_key_id_t key,
  928. psa_key_slot_t **p_slot,
  929. psa_key_usage_t usage,
  930. psa_algorithm_t alg )
  931. {
  932. psa_status_t status = psa_get_and_lock_key_slot_with_policy( key, p_slot,
  933. usage, alg );
  934. if( status != PSA_SUCCESS )
  935. return( status );
  936. if( psa_key_lifetime_is_external( (*p_slot)->attr.lifetime ) )
  937. {
  938. psa_unlock_key_slot( *p_slot );
  939. *p_slot = NULL;
  940. return( PSA_ERROR_NOT_SUPPORTED );
  941. }
  942. return( PSA_SUCCESS );
  943. }
  944. psa_status_t psa_remove_key_data_from_memory( psa_key_slot_t *slot )
  945. {
  946. /* Data pointer will always be either a valid pointer or NULL in an
  947. * initialized slot, so we can just free it. */
  948. if( slot->key.data != NULL )
  949. mbedtls_platform_zeroize( slot->key.data, slot->key.bytes);
  950. mbedtls_free( slot->key.data );
  951. slot->key.data = NULL;
  952. slot->key.bytes = 0;
  953. return( PSA_SUCCESS );
  954. }
  955. /** Completely wipe a slot in memory, including its policy.
  956. * Persistent storage is not affected. */
  957. psa_status_t psa_wipe_key_slot( psa_key_slot_t *slot )
  958. {
  959. psa_status_t status = psa_remove_key_data_from_memory( slot );
  960. /*
  961. * As the return error code may not be handled in case of multiple errors,
  962. * do our best to report an unexpected lock counter: if available
  963. * call MBEDTLS_PARAM_FAILED that may terminate execution (if called as
  964. * part of the execution of a test suite this will stop the test suite
  965. * execution).
  966. */
  967. if( slot->lock_count != 1 )
  968. {
  969. #ifdef MBEDTLS_CHECK_PARAMS
  970. MBEDTLS_PARAM_FAILED( slot->lock_count == 1 );
  971. #endif
  972. status = PSA_ERROR_CORRUPTION_DETECTED;
  973. }
  974. /* Multipart operations may still be using the key. This is safe
  975. * because all multipart operation objects are independent from
  976. * the key slot: if they need to access the key after the setup
  977. * phase, they have a copy of the key. Note that this means that
  978. * key material can linger until all operations are completed. */
  979. /* At this point, key material and other type-specific content has
  980. * been wiped. Clear remaining metadata. We can call memset and not
  981. * zeroize because the metadata is not particularly sensitive. */
  982. memset( slot, 0, sizeof( *slot ) );
  983. return( status );
  984. }
  985. psa_status_t psa_destroy_key( mbedtls_svc_key_id_t key )
  986. {
  987. psa_key_slot_t *slot;
  988. psa_status_t status; /* status of the last operation */
  989. psa_status_t overall_status = PSA_SUCCESS;
  990. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  991. psa_se_drv_table_entry_t *driver;
  992. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  993. if( mbedtls_svc_key_id_is_null( key ) )
  994. return( PSA_SUCCESS );
  995. /*
  996. * Get the description of the key in a key slot. In case of a persistent
  997. * key, this will load the key description from persistent memory if not
  998. * done yet. We cannot avoid this loading as without it we don't know if
  999. * the key is operated by an SE or not and this information is needed by
  1000. * the current implementation.
  1001. */
  1002. status = psa_get_and_lock_key_slot( key, &slot );
  1003. if( status != PSA_SUCCESS )
  1004. return( status );
  1005. /*
  1006. * If the key slot containing the key description is under access by the
  1007. * library (apart from the present access), the key cannot be destroyed
  1008. * yet. For the time being, just return in error. Eventually (to be
  1009. * implemented), the key should be destroyed when all accesses have
  1010. * stopped.
  1011. */
  1012. if( slot->lock_count > 1 )
  1013. {
  1014. psa_unlock_key_slot( slot );
  1015. return( PSA_ERROR_GENERIC_ERROR );
  1016. }
  1017. if( PSA_KEY_LIFETIME_IS_READ_ONLY( slot->attr.lifetime ) )
  1018. {
  1019. /* Refuse the destruction of a read-only key (which may or may not work
  1020. * if we attempt it, depending on whether the key is merely read-only
  1021. * by policy or actually physically read-only).
  1022. * Just do the best we can, which is to wipe the copy in memory
  1023. * (done in this function's cleanup code). */
  1024. overall_status = PSA_ERROR_NOT_PERMITTED;
  1025. goto exit;
  1026. }
  1027. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1028. driver = psa_get_se_driver_entry( slot->attr.lifetime );
  1029. if( driver != NULL )
  1030. {
  1031. /* For a key in a secure element, we need to do three things:
  1032. * remove the key file in internal storage, destroy the
  1033. * key inside the secure element, and update the driver's
  1034. * persistent data. Start a transaction that will encompass these
  1035. * three actions. */
  1036. psa_crypto_prepare_transaction( PSA_CRYPTO_TRANSACTION_DESTROY_KEY );
  1037. psa_crypto_transaction.key.lifetime = slot->attr.lifetime;
  1038. psa_crypto_transaction.key.slot = psa_key_slot_get_slot_number( slot );
  1039. psa_crypto_transaction.key.id = slot->attr.id;
  1040. status = psa_crypto_save_transaction( );
  1041. if( status != PSA_SUCCESS )
  1042. {
  1043. (void) psa_crypto_stop_transaction( );
  1044. /* We should still try to destroy the key in the secure
  1045. * element and the key metadata in storage. This is especially
  1046. * important if the error is that the storage is full.
  1047. * But how to do it exactly without risking an inconsistent
  1048. * state after a reset?
  1049. * https://github.com/ARMmbed/mbed-crypto/issues/215
  1050. */
  1051. overall_status = status;
  1052. goto exit;
  1053. }
  1054. status = psa_destroy_se_key( driver,
  1055. psa_key_slot_get_slot_number( slot ) );
  1056. if( overall_status == PSA_SUCCESS )
  1057. overall_status = status;
  1058. }
  1059. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1060. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C)
  1061. if( ! PSA_KEY_LIFETIME_IS_VOLATILE( slot->attr.lifetime ) )
  1062. {
  1063. status = psa_destroy_persistent_key( slot->attr.id );
  1064. if( overall_status == PSA_SUCCESS )
  1065. overall_status = status;
  1066. /* TODO: other slots may have a copy of the same key. We should
  1067. * invalidate them.
  1068. * https://github.com/ARMmbed/mbed-crypto/issues/214
  1069. */
  1070. }
  1071. #endif /* defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) */
  1072. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1073. if( driver != NULL )
  1074. {
  1075. status = psa_save_se_persistent_data( driver );
  1076. if( overall_status == PSA_SUCCESS )
  1077. overall_status = status;
  1078. status = psa_crypto_stop_transaction( );
  1079. if( overall_status == PSA_SUCCESS )
  1080. overall_status = status;
  1081. }
  1082. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1083. exit:
  1084. status = psa_wipe_key_slot( slot );
  1085. /* Prioritize CORRUPTION_DETECTED from wiping over a storage error */
  1086. if( status != PSA_SUCCESS )
  1087. overall_status = status;
  1088. return( overall_status );
  1089. }
  1090. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1091. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1092. static psa_status_t psa_get_rsa_public_exponent(
  1093. const mbedtls_rsa_context *rsa,
  1094. psa_key_attributes_t *attributes )
  1095. {
  1096. mbedtls_mpi mpi;
  1097. int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
  1098. uint8_t *buffer = NULL;
  1099. size_t buflen;
  1100. mbedtls_mpi_init( &mpi );
  1101. ret = mbedtls_rsa_export( rsa, NULL, NULL, NULL, NULL, &mpi );
  1102. if( ret != 0 )
  1103. goto exit;
  1104. if( mbedtls_mpi_cmp_int( &mpi, 65537 ) == 0 )
  1105. {
  1106. /* It's the default value, which is reported as an empty string,
  1107. * so there's nothing to do. */
  1108. goto exit;
  1109. }
  1110. buflen = mbedtls_mpi_size( &mpi );
  1111. buffer = mbedtls_calloc( 1, buflen );
  1112. if( buffer == NULL )
  1113. {
  1114. ret = MBEDTLS_ERR_MPI_ALLOC_FAILED;
  1115. goto exit;
  1116. }
  1117. ret = mbedtls_mpi_write_binary( &mpi, buffer, buflen );
  1118. if( ret != 0 )
  1119. goto exit;
  1120. attributes->domain_parameters = buffer;
  1121. attributes->domain_parameters_size = buflen;
  1122. exit:
  1123. mbedtls_mpi_free( &mpi );
  1124. if( ret != 0 )
  1125. mbedtls_free( buffer );
  1126. return( mbedtls_to_psa_error( ret ) );
  1127. }
  1128. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1129. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1130. /** Retrieve all the publicly-accessible attributes of a key.
  1131. */
  1132. psa_status_t psa_get_key_attributes( mbedtls_svc_key_id_t key,
  1133. psa_key_attributes_t *attributes )
  1134. {
  1135. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1136. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1137. psa_key_slot_t *slot;
  1138. psa_reset_key_attributes( attributes );
  1139. status = psa_get_and_lock_key_slot_with_policy( key, &slot, 0, 0 );
  1140. if( status != PSA_SUCCESS )
  1141. return( status );
  1142. attributes->core = slot->attr;
  1143. attributes->core.flags &= ( MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY |
  1144. MBEDTLS_PSA_KA_MASK_DUAL_USE );
  1145. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1146. if( psa_get_se_driver_entry( slot->attr.lifetime ) != NULL )
  1147. psa_set_key_slot_number( attributes,
  1148. psa_key_slot_get_slot_number( slot ) );
  1149. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1150. switch( slot->attr.type )
  1151. {
  1152. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1153. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1154. case PSA_KEY_TYPE_RSA_KEY_PAIR:
  1155. case PSA_KEY_TYPE_RSA_PUBLIC_KEY:
  1156. /* TODO: reporting the public exponent for opaque keys
  1157. * is not yet implemented.
  1158. * https://github.com/ARMmbed/mbed-crypto/issues/216
  1159. */
  1160. if( ! psa_key_lifetime_is_external( slot->attr.lifetime ) )
  1161. {
  1162. mbedtls_rsa_context *rsa = NULL;
  1163. status = mbedtls_psa_rsa_load_representation(
  1164. slot->attr.type,
  1165. slot->key.data,
  1166. slot->key.bytes,
  1167. &rsa );
  1168. if( status != PSA_SUCCESS )
  1169. break;
  1170. status = psa_get_rsa_public_exponent( rsa,
  1171. attributes );
  1172. mbedtls_rsa_free( rsa );
  1173. mbedtls_free( rsa );
  1174. }
  1175. break;
  1176. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1177. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1178. default:
  1179. /* Nothing else to do. */
  1180. break;
  1181. }
  1182. if( status != PSA_SUCCESS )
  1183. psa_reset_key_attributes( attributes );
  1184. unlock_status = psa_unlock_key_slot( slot );
  1185. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1186. }
  1187. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1188. psa_status_t psa_get_key_slot_number(
  1189. const psa_key_attributes_t *attributes,
  1190. psa_key_slot_number_t *slot_number )
  1191. {
  1192. if( attributes->core.flags & MBEDTLS_PSA_KA_FLAG_HAS_SLOT_NUMBER )
  1193. {
  1194. *slot_number = attributes->slot_number;
  1195. return( PSA_SUCCESS );
  1196. }
  1197. else
  1198. return( PSA_ERROR_INVALID_ARGUMENT );
  1199. }
  1200. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1201. static psa_status_t psa_export_key_buffer_internal( const uint8_t *key_buffer,
  1202. size_t key_buffer_size,
  1203. uint8_t *data,
  1204. size_t data_size,
  1205. size_t *data_length )
  1206. {
  1207. if( key_buffer_size > data_size )
  1208. return( PSA_ERROR_BUFFER_TOO_SMALL );
  1209. memcpy( data, key_buffer, key_buffer_size );
  1210. memset( data + key_buffer_size, 0,
  1211. data_size - key_buffer_size );
  1212. *data_length = key_buffer_size;
  1213. return( PSA_SUCCESS );
  1214. }
  1215. psa_status_t psa_export_key_internal(
  1216. const psa_key_attributes_t *attributes,
  1217. const uint8_t *key_buffer, size_t key_buffer_size,
  1218. uint8_t *data, size_t data_size, size_t *data_length )
  1219. {
  1220. psa_key_type_t type = attributes->core.type;
  1221. if( key_type_is_raw_bytes( type ) ||
  1222. PSA_KEY_TYPE_IS_RSA( type ) ||
  1223. PSA_KEY_TYPE_IS_ECC( type ) )
  1224. {
  1225. return( psa_export_key_buffer_internal(
  1226. key_buffer, key_buffer_size,
  1227. data, data_size, data_length ) );
  1228. }
  1229. else
  1230. {
  1231. /* This shouldn't happen in the reference implementation, but
  1232. it is valid for a special-purpose implementation to omit
  1233. support for exporting certain key types. */
  1234. return( PSA_ERROR_NOT_SUPPORTED );
  1235. }
  1236. }
  1237. psa_status_t psa_export_key( mbedtls_svc_key_id_t key,
  1238. uint8_t *data,
  1239. size_t data_size,
  1240. size_t *data_length )
  1241. {
  1242. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1243. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1244. psa_key_slot_t *slot;
  1245. /* Reject a zero-length output buffer now, since this can never be a
  1246. * valid key representation. This way we know that data must be a valid
  1247. * pointer and we can do things like memset(data, ..., data_size). */
  1248. if( data_size == 0 )
  1249. return( PSA_ERROR_BUFFER_TOO_SMALL );
  1250. /* Set the key to empty now, so that even when there are errors, we always
  1251. * set data_length to a value between 0 and data_size. On error, setting
  1252. * the key to empty is a good choice because an empty key representation is
  1253. * unlikely to be accepted anywhere. */
  1254. *data_length = 0;
  1255. /* Export requires the EXPORT flag. There is an exception for public keys,
  1256. * which don't require any flag, but
  1257. * psa_get_and_lock_key_slot_with_policy() takes care of this.
  1258. */
  1259. status = psa_get_and_lock_key_slot_with_policy( key, &slot,
  1260. PSA_KEY_USAGE_EXPORT, 0 );
  1261. if( status != PSA_SUCCESS )
  1262. return( status );
  1263. psa_key_attributes_t attributes = {
  1264. .core = slot->attr
  1265. };
  1266. status = psa_driver_wrapper_export_key( &attributes,
  1267. slot->key.data, slot->key.bytes,
  1268. data, data_size, data_length );
  1269. unlock_status = psa_unlock_key_slot( slot );
  1270. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1271. }
  1272. psa_status_t psa_export_public_key_internal(
  1273. const psa_key_attributes_t *attributes,
  1274. const uint8_t *key_buffer,
  1275. size_t key_buffer_size,
  1276. uint8_t *data,
  1277. size_t data_size,
  1278. size_t *data_length )
  1279. {
  1280. psa_key_type_t type = attributes->core.type;
  1281. if( PSA_KEY_TYPE_IS_RSA( type ) || PSA_KEY_TYPE_IS_ECC( type ) )
  1282. {
  1283. if( PSA_KEY_TYPE_IS_PUBLIC_KEY( type ) )
  1284. {
  1285. /* Exporting public -> public */
  1286. return( psa_export_key_buffer_internal(
  1287. key_buffer, key_buffer_size,
  1288. data, data_size, data_length ) );
  1289. }
  1290. if( PSA_KEY_TYPE_IS_RSA( type ) )
  1291. {
  1292. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1293. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1294. return( mbedtls_psa_rsa_export_public_key( attributes,
  1295. key_buffer,
  1296. key_buffer_size,
  1297. data,
  1298. data_size,
  1299. data_length ) );
  1300. #else
  1301. /* We don't know how to convert a private RSA key to public. */
  1302. return( PSA_ERROR_NOT_SUPPORTED );
  1303. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1304. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1305. }
  1306. else
  1307. {
  1308. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  1309. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY)
  1310. return( mbedtls_psa_ecp_export_public_key( attributes,
  1311. key_buffer,
  1312. key_buffer_size,
  1313. data,
  1314. data_size,
  1315. data_length ) );
  1316. #else
  1317. /* We don't know how to convert a private ECC key to public */
  1318. return( PSA_ERROR_NOT_SUPPORTED );
  1319. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  1320. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) */
  1321. }
  1322. }
  1323. else
  1324. {
  1325. /* This shouldn't happen in the reference implementation, but
  1326. it is valid for a special-purpose implementation to omit
  1327. support for exporting certain key types. */
  1328. return( PSA_ERROR_NOT_SUPPORTED );
  1329. }
  1330. }
  1331. psa_status_t psa_export_public_key( mbedtls_svc_key_id_t key,
  1332. uint8_t *data,
  1333. size_t data_size,
  1334. size_t *data_length )
  1335. {
  1336. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1337. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1338. psa_key_slot_t *slot;
  1339. /* Reject a zero-length output buffer now, since this can never be a
  1340. * valid key representation. This way we know that data must be a valid
  1341. * pointer and we can do things like memset(data, ..., data_size). */
  1342. if( data_size == 0 )
  1343. return( PSA_ERROR_BUFFER_TOO_SMALL );
  1344. /* Set the key to empty now, so that even when there are errors, we always
  1345. * set data_length to a value between 0 and data_size. On error, setting
  1346. * the key to empty is a good choice because an empty key representation is
  1347. * unlikely to be accepted anywhere. */
  1348. *data_length = 0;
  1349. /* Exporting a public key doesn't require a usage flag. */
  1350. status = psa_get_and_lock_key_slot_with_policy( key, &slot, 0, 0 );
  1351. if( status != PSA_SUCCESS )
  1352. return( status );
  1353. if( ! PSA_KEY_TYPE_IS_ASYMMETRIC( slot->attr.type ) )
  1354. {
  1355. status = PSA_ERROR_INVALID_ARGUMENT;
  1356. goto exit;
  1357. }
  1358. psa_key_attributes_t attributes = {
  1359. .core = slot->attr
  1360. };
  1361. status = psa_driver_wrapper_export_public_key(
  1362. &attributes, slot->key.data, slot->key.bytes,
  1363. data, data_size, data_length );
  1364. exit:
  1365. unlock_status = psa_unlock_key_slot( slot );
  1366. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1367. }
  1368. #if defined(static_assert)
  1369. static_assert( ( MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_DUAL_USE ) == 0,
  1370. "One or more key attribute flag is listed as both external-only and dual-use" );
  1371. static_assert( ( PSA_KA_MASK_INTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_DUAL_USE ) == 0,
  1372. "One or more key attribute flag is listed as both internal-only and dual-use" );
  1373. static_assert( ( PSA_KA_MASK_INTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY ) == 0,
  1374. "One or more key attribute flag is listed as both internal-only and external-only" );
  1375. #endif
  1376. /** Validate that a key policy is internally well-formed.
  1377. *
  1378. * This function only rejects invalid policies. It does not validate the
  1379. * consistency of the policy with respect to other attributes of the key
  1380. * such as the key type.
  1381. */
  1382. static psa_status_t psa_validate_key_policy( const psa_key_policy_t *policy )
  1383. {
  1384. if( ( policy->usage & ~( PSA_KEY_USAGE_EXPORT |
  1385. PSA_KEY_USAGE_COPY |
  1386. PSA_KEY_USAGE_ENCRYPT |
  1387. PSA_KEY_USAGE_DECRYPT |
  1388. PSA_KEY_USAGE_SIGN_MESSAGE |
  1389. PSA_KEY_USAGE_VERIFY_MESSAGE |
  1390. PSA_KEY_USAGE_SIGN_HASH |
  1391. PSA_KEY_USAGE_VERIFY_HASH |
  1392. PSA_KEY_USAGE_DERIVE ) ) != 0 )
  1393. return( PSA_ERROR_INVALID_ARGUMENT );
  1394. return( PSA_SUCCESS );
  1395. }
  1396. /** Validate the internal consistency of key attributes.
  1397. *
  1398. * This function only rejects invalid attribute values. If does not
  1399. * validate the consistency of the attributes with any key data that may
  1400. * be involved in the creation of the key.
  1401. *
  1402. * Call this function early in the key creation process.
  1403. *
  1404. * \param[in] attributes Key attributes for the new key.
  1405. * \param[out] p_drv On any return, the driver for the key, if any.
  1406. * NULL for a transparent key.
  1407. *
  1408. */
  1409. static psa_status_t psa_validate_key_attributes(
  1410. const psa_key_attributes_t *attributes,
  1411. psa_se_drv_table_entry_t **p_drv )
  1412. {
  1413. psa_status_t status = PSA_ERROR_INVALID_ARGUMENT;
  1414. psa_key_lifetime_t lifetime = psa_get_key_lifetime( attributes );
  1415. mbedtls_svc_key_id_t key = psa_get_key_id( attributes );
  1416. status = psa_validate_key_location( lifetime, p_drv );
  1417. if( status != PSA_SUCCESS )
  1418. return( status );
  1419. status = psa_validate_key_persistence( lifetime );
  1420. if( status != PSA_SUCCESS )
  1421. return( status );
  1422. if ( PSA_KEY_LIFETIME_IS_VOLATILE( lifetime ) )
  1423. {
  1424. if( MBEDTLS_SVC_KEY_ID_GET_KEY_ID( key ) != 0 )
  1425. return( PSA_ERROR_INVALID_ARGUMENT );
  1426. }
  1427. else
  1428. {
  1429. if( !psa_is_valid_key_id( psa_get_key_id( attributes ), 0 ) )
  1430. return( PSA_ERROR_INVALID_ARGUMENT );
  1431. }
  1432. status = psa_validate_key_policy( &attributes->core.policy );
  1433. if( status != PSA_SUCCESS )
  1434. return( status );
  1435. /* Refuse to create overly large keys.
  1436. * Note that this doesn't trigger on import if the attributes don't
  1437. * explicitly specify a size (so psa_get_key_bits returns 0), so
  1438. * psa_import_key() needs its own checks. */
  1439. if( psa_get_key_bits( attributes ) > PSA_MAX_KEY_BITS )
  1440. return( PSA_ERROR_NOT_SUPPORTED );
  1441. /* Reject invalid flags. These should not be reachable through the API. */
  1442. if( attributes->core.flags & ~ ( MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY |
  1443. MBEDTLS_PSA_KA_MASK_DUAL_USE ) )
  1444. return( PSA_ERROR_INVALID_ARGUMENT );
  1445. return( PSA_SUCCESS );
  1446. }
  1447. /** Prepare a key slot to receive key material.
  1448. *
  1449. * This function allocates a key slot and sets its metadata.
  1450. *
  1451. * If this function fails, call psa_fail_key_creation().
  1452. *
  1453. * This function is intended to be used as follows:
  1454. * -# Call psa_start_key_creation() to allocate a key slot, prepare
  1455. * it with the specified attributes, and in case of a volatile key assign it
  1456. * a volatile key identifier.
  1457. * -# Populate the slot with the key material.
  1458. * -# Call psa_finish_key_creation() to finalize the creation of the slot.
  1459. * In case of failure at any step, stop the sequence and call
  1460. * psa_fail_key_creation().
  1461. *
  1462. * On success, the key slot is locked. It is the responsibility of the caller
  1463. * to unlock the key slot when it does not access it anymore.
  1464. *
  1465. * \param method An identification of the calling function.
  1466. * \param[in] attributes Key attributes for the new key.
  1467. * \param[out] p_slot On success, a pointer to the prepared slot.
  1468. * \param[out] p_drv On any return, the driver for the key, if any.
  1469. * NULL for a transparent key.
  1470. *
  1471. * \retval #PSA_SUCCESS
  1472. * The key slot is ready to receive key material.
  1473. * \return If this function fails, the key slot is an invalid state.
  1474. * You must call psa_fail_key_creation() to wipe and free the slot.
  1475. */
  1476. static psa_status_t psa_start_key_creation(
  1477. psa_key_creation_method_t method,
  1478. const psa_key_attributes_t *attributes,
  1479. psa_key_slot_t **p_slot,
  1480. psa_se_drv_table_entry_t **p_drv )
  1481. {
  1482. psa_status_t status;
  1483. psa_key_id_t volatile_key_id;
  1484. psa_key_slot_t *slot;
  1485. (void) method;
  1486. *p_drv = NULL;
  1487. status = psa_validate_key_attributes( attributes, p_drv );
  1488. if( status != PSA_SUCCESS )
  1489. return( status );
  1490. status = psa_get_empty_key_slot( &volatile_key_id, p_slot );
  1491. if( status != PSA_SUCCESS )
  1492. return( status );
  1493. slot = *p_slot;
  1494. /* We're storing the declared bit-size of the key. It's up to each
  1495. * creation mechanism to verify that this information is correct.
  1496. * It's automatically correct for mechanisms that use the bit-size as
  1497. * an input (generate, device) but not for those where the bit-size
  1498. * is optional (import, copy). In case of a volatile key, assign it the
  1499. * volatile key identifier associated to the slot returned to contain its
  1500. * definition. */
  1501. slot->attr = attributes->core;
  1502. if( PSA_KEY_LIFETIME_IS_VOLATILE( slot->attr.lifetime ) )
  1503. {
  1504. #if !defined(MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER)
  1505. slot->attr.id = volatile_key_id;
  1506. #else
  1507. slot->attr.id.key_id = volatile_key_id;
  1508. #endif
  1509. }
  1510. /* Erase external-only flags from the internal copy. To access
  1511. * external-only flags, query `attributes`. Thanks to the check
  1512. * in psa_validate_key_attributes(), this leaves the dual-use
  1513. * flags and any internal flag that psa_get_empty_key_slot()
  1514. * may have set. */
  1515. slot->attr.flags &= ~MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY;
  1516. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1517. /* For a key in a secure element, we need to do three things
  1518. * when creating or registering a persistent key:
  1519. * create the key file in internal storage, create the
  1520. * key inside the secure element, and update the driver's
  1521. * persistent data. This is done by starting a transaction that will
  1522. * encompass these three actions.
  1523. * For registering a volatile key, we just need to find an appropriate
  1524. * slot number inside the SE. Since the key is designated volatile, creating
  1525. * a transaction is not required. */
  1526. /* The first thing to do is to find a slot number for the new key.
  1527. * We save the slot number in persistent storage as part of the
  1528. * transaction data. It will be needed to recover if the power
  1529. * fails during the key creation process, to clean up on the secure
  1530. * element side after restarting. Obtaining a slot number from the
  1531. * secure element driver updates its persistent state, but we do not yet
  1532. * save the driver's persistent state, so that if the power fails,
  1533. * we can roll back to a state where the key doesn't exist. */
  1534. if( *p_drv != NULL )
  1535. {
  1536. psa_key_slot_number_t slot_number;
  1537. status = psa_find_se_slot_for_key( attributes, method, *p_drv,
  1538. &slot_number );
  1539. if( status != PSA_SUCCESS )
  1540. return( status );
  1541. if( ! PSA_KEY_LIFETIME_IS_VOLATILE( attributes->core.lifetime ) )
  1542. {
  1543. psa_crypto_prepare_transaction( PSA_CRYPTO_TRANSACTION_CREATE_KEY );
  1544. psa_crypto_transaction.key.lifetime = slot->attr.lifetime;
  1545. psa_crypto_transaction.key.slot = slot_number;
  1546. psa_crypto_transaction.key.id = slot->attr.id;
  1547. status = psa_crypto_save_transaction( );
  1548. if( status != PSA_SUCCESS )
  1549. {
  1550. (void) psa_crypto_stop_transaction( );
  1551. return( status );
  1552. }
  1553. }
  1554. status = psa_copy_key_material_into_slot(
  1555. slot, (uint8_t *)( &slot_number ), sizeof( slot_number ) );
  1556. }
  1557. if( *p_drv == NULL && method == PSA_KEY_CREATION_REGISTER )
  1558. {
  1559. /* Key registration only makes sense with a secure element. */
  1560. return( PSA_ERROR_INVALID_ARGUMENT );
  1561. }
  1562. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1563. return( PSA_SUCCESS );
  1564. }
  1565. /** Finalize the creation of a key once its key material has been set.
  1566. *
  1567. * This entails writing the key to persistent storage.
  1568. *
  1569. * If this function fails, call psa_fail_key_creation().
  1570. * See the documentation of psa_start_key_creation() for the intended use
  1571. * of this function.
  1572. *
  1573. * If the finalization succeeds, the function unlocks the key slot (it was
  1574. * locked by psa_start_key_creation()) and the key slot cannot be accessed
  1575. * anymore as part of the key creation process.
  1576. *
  1577. * \param[in,out] slot Pointer to the slot with key material.
  1578. * \param[in] driver The secure element driver for the key,
  1579. * or NULL for a transparent key.
  1580. * \param[out] key On success, identifier of the key. Note that the
  1581. * key identifier is also stored in the key slot.
  1582. *
  1583. * \retval #PSA_SUCCESS
  1584. * The key was successfully created.
  1585. * \retval #PSA_ERROR_INSUFFICIENT_MEMORY
  1586. * \retval #PSA_ERROR_INSUFFICIENT_STORAGE
  1587. * \retval #PSA_ERROR_ALREADY_EXISTS
  1588. * \retval #PSA_ERROR_DATA_INVALID
  1589. * \retval #PSA_ERROR_DATA_CORRUPT
  1590. * \retval #PSA_ERROR_STORAGE_FAILURE
  1591. *
  1592. * \return If this function fails, the key slot is an invalid state.
  1593. * You must call psa_fail_key_creation() to wipe and free the slot.
  1594. */
  1595. static psa_status_t psa_finish_key_creation(
  1596. psa_key_slot_t *slot,
  1597. psa_se_drv_table_entry_t *driver,
  1598. mbedtls_svc_key_id_t *key)
  1599. {
  1600. psa_status_t status = PSA_SUCCESS;
  1601. (void) slot;
  1602. (void) driver;
  1603. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C)
  1604. if( ! PSA_KEY_LIFETIME_IS_VOLATILE( slot->attr.lifetime ) )
  1605. {
  1606. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1607. if( driver != NULL )
  1608. {
  1609. psa_se_key_data_storage_t data;
  1610. psa_key_slot_number_t slot_number =
  1611. psa_key_slot_get_slot_number( slot ) ;
  1612. #if defined(static_assert)
  1613. static_assert( sizeof( slot_number ) ==
  1614. sizeof( data.slot_number ),
  1615. "Slot number size does not match psa_se_key_data_storage_t" );
  1616. #endif
  1617. memcpy( &data.slot_number, &slot_number, sizeof( slot_number ) );
  1618. status = psa_save_persistent_key( &slot->attr,
  1619. (uint8_t*) &data,
  1620. sizeof( data ) );
  1621. }
  1622. else
  1623. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1624. {
  1625. /* Key material is saved in export representation in the slot, so
  1626. * just pass the slot buffer for storage. */
  1627. status = psa_save_persistent_key( &slot->attr,
  1628. slot->key.data,
  1629. slot->key.bytes );
  1630. }
  1631. }
  1632. #endif /* defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) */
  1633. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1634. /* Finish the transaction for a key creation. This does not
  1635. * happen when registering an existing key. Detect this case
  1636. * by checking whether a transaction is in progress (actual
  1637. * creation of a persistent key in a secure element requires a transaction,
  1638. * but registration or volatile key creation doesn't use one). */
  1639. if( driver != NULL &&
  1640. psa_crypto_transaction.unknown.type == PSA_CRYPTO_TRANSACTION_CREATE_KEY )
  1641. {
  1642. status = psa_save_se_persistent_data( driver );
  1643. if( status != PSA_SUCCESS )
  1644. {
  1645. psa_destroy_persistent_key( slot->attr.id );
  1646. return( status );
  1647. }
  1648. status = psa_crypto_stop_transaction( );
  1649. }
  1650. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1651. if( status == PSA_SUCCESS )
  1652. {
  1653. *key = slot->attr.id;
  1654. status = psa_unlock_key_slot( slot );
  1655. if( status != PSA_SUCCESS )
  1656. *key = MBEDTLS_SVC_KEY_ID_INIT;
  1657. }
  1658. return( status );
  1659. }
  1660. /** Abort the creation of a key.
  1661. *
  1662. * You may call this function after calling psa_start_key_creation(),
  1663. * or after psa_finish_key_creation() fails. In other circumstances, this
  1664. * function may not clean up persistent storage.
  1665. * See the documentation of psa_start_key_creation() for the intended use
  1666. * of this function.
  1667. *
  1668. * \param[in,out] slot Pointer to the slot with key material.
  1669. * \param[in] driver The secure element driver for the key,
  1670. * or NULL for a transparent key.
  1671. */
  1672. static void psa_fail_key_creation( psa_key_slot_t *slot,
  1673. psa_se_drv_table_entry_t *driver )
  1674. {
  1675. (void) driver;
  1676. if( slot == NULL )
  1677. return;
  1678. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1679. /* TODO: If the key has already been created in the secure
  1680. * element, and the failure happened later (when saving metadata
  1681. * to internal storage), we need to destroy the key in the secure
  1682. * element.
  1683. * https://github.com/ARMmbed/mbed-crypto/issues/217
  1684. */
  1685. /* Abort the ongoing transaction if any (there may not be one if
  1686. * the creation process failed before starting one, or if the
  1687. * key creation is a registration of a key in a secure element).
  1688. * Earlier functions must already have done what it takes to undo any
  1689. * partial creation. All that's left is to update the transaction data
  1690. * itself. */
  1691. (void) psa_crypto_stop_transaction( );
  1692. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1693. psa_wipe_key_slot( slot );
  1694. }
  1695. /** Validate optional attributes during key creation.
  1696. *
  1697. * Some key attributes are optional during key creation. If they are
  1698. * specified in the attributes structure, check that they are consistent
  1699. * with the data in the slot.
  1700. *
  1701. * This function should be called near the end of key creation, after
  1702. * the slot in memory is fully populated but before saving persistent data.
  1703. */
  1704. static psa_status_t psa_validate_optional_attributes(
  1705. const psa_key_slot_t *slot,
  1706. const psa_key_attributes_t *attributes )
  1707. {
  1708. if( attributes->core.type != 0 )
  1709. {
  1710. if( attributes->core.type != slot->attr.type )
  1711. return( PSA_ERROR_INVALID_ARGUMENT );
  1712. }
  1713. if( attributes->domain_parameters_size != 0 )
  1714. {
  1715. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1716. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1717. if( PSA_KEY_TYPE_IS_RSA( slot->attr.type ) )
  1718. {
  1719. mbedtls_rsa_context *rsa = NULL;
  1720. mbedtls_mpi actual, required;
  1721. int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
  1722. psa_status_t status = mbedtls_psa_rsa_load_representation(
  1723. slot->attr.type,
  1724. slot->key.data,
  1725. slot->key.bytes,
  1726. &rsa );
  1727. if( status != PSA_SUCCESS )
  1728. return( status );
  1729. mbedtls_mpi_init( &actual );
  1730. mbedtls_mpi_init( &required );
  1731. ret = mbedtls_rsa_export( rsa,
  1732. NULL, NULL, NULL, NULL, &actual );
  1733. mbedtls_rsa_free( rsa );
  1734. mbedtls_free( rsa );
  1735. if( ret != 0 )
  1736. goto rsa_exit;
  1737. ret = mbedtls_mpi_read_binary( &required,
  1738. attributes->domain_parameters,
  1739. attributes->domain_parameters_size );
  1740. if( ret != 0 )
  1741. goto rsa_exit;
  1742. if( mbedtls_mpi_cmp_mpi( &actual, &required ) != 0 )
  1743. ret = MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
  1744. rsa_exit:
  1745. mbedtls_mpi_free( &actual );
  1746. mbedtls_mpi_free( &required );
  1747. if( ret != 0)
  1748. return( mbedtls_to_psa_error( ret ) );
  1749. }
  1750. else
  1751. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1752. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1753. {
  1754. return( PSA_ERROR_INVALID_ARGUMENT );
  1755. }
  1756. }
  1757. if( attributes->core.bits != 0 )
  1758. {
  1759. if( attributes->core.bits != slot->attr.bits )
  1760. return( PSA_ERROR_INVALID_ARGUMENT );
  1761. }
  1762. return( PSA_SUCCESS );
  1763. }
  1764. psa_status_t psa_import_key( const psa_key_attributes_t *attributes,
  1765. const uint8_t *data,
  1766. size_t data_length,
  1767. mbedtls_svc_key_id_t *key )
  1768. {
  1769. psa_status_t status;
  1770. psa_key_slot_t *slot = NULL;
  1771. psa_se_drv_table_entry_t *driver = NULL;
  1772. size_t bits;
  1773. *key = MBEDTLS_SVC_KEY_ID_INIT;
  1774. /* Reject zero-length symmetric keys (including raw data key objects).
  1775. * This also rejects any key which might be encoded as an empty string,
  1776. * which is never valid. */
  1777. if( data_length == 0 )
  1778. return( PSA_ERROR_INVALID_ARGUMENT );
  1779. status = psa_start_key_creation( PSA_KEY_CREATION_IMPORT, attributes,
  1780. &slot, &driver );
  1781. if( status != PSA_SUCCESS )
  1782. goto exit;
  1783. /* In the case of a transparent key or an opaque key stored in local
  1784. * storage (thus not in the case of generating a key in a secure element
  1785. * or cryptoprocessor with storage), we have to allocate a buffer to
  1786. * hold the generated key material. */
  1787. if( slot->key.data == NULL )
  1788. {
  1789. status = psa_allocate_buffer_to_slot( slot, data_length );
  1790. if( status != PSA_SUCCESS )
  1791. goto exit;
  1792. }
  1793. bits = slot->attr.bits;
  1794. status = psa_driver_wrapper_import_key( attributes,
  1795. data, data_length,
  1796. slot->key.data,
  1797. slot->key.bytes,
  1798. &slot->key.bytes, &bits );
  1799. if( status != PSA_SUCCESS )
  1800. goto exit;
  1801. if( slot->attr.bits == 0 )
  1802. slot->attr.bits = (psa_key_bits_t) bits;
  1803. else if( bits != slot->attr.bits )
  1804. {
  1805. status = PSA_ERROR_INVALID_ARGUMENT;
  1806. goto exit;
  1807. }
  1808. status = psa_validate_optional_attributes( slot, attributes );
  1809. if( status != PSA_SUCCESS )
  1810. goto exit;
  1811. status = psa_finish_key_creation( slot, driver, key );
  1812. exit:
  1813. if( status != PSA_SUCCESS )
  1814. psa_fail_key_creation( slot, driver );
  1815. return( status );
  1816. }
  1817. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1818. psa_status_t mbedtls_psa_register_se_key(
  1819. const psa_key_attributes_t *attributes )
  1820. {
  1821. psa_status_t status;
  1822. psa_key_slot_t *slot = NULL;
  1823. psa_se_drv_table_entry_t *driver = NULL;
  1824. mbedtls_svc_key_id_t key = MBEDTLS_SVC_KEY_ID_INIT;
  1825. /* Leaving attributes unspecified is not currently supported.
  1826. * It could make sense to query the key type and size from the
  1827. * secure element, but not all secure elements support this
  1828. * and the driver HAL doesn't currently support it. */
  1829. if( psa_get_key_type( attributes ) == PSA_KEY_TYPE_NONE )
  1830. return( PSA_ERROR_NOT_SUPPORTED );
  1831. if( psa_get_key_bits( attributes ) == 0 )
  1832. return( PSA_ERROR_NOT_SUPPORTED );
  1833. status = psa_start_key_creation( PSA_KEY_CREATION_REGISTER, attributes,
  1834. &slot, &driver );
  1835. if( status != PSA_SUCCESS )
  1836. goto exit;
  1837. status = psa_finish_key_creation( slot, driver, &key );
  1838. exit:
  1839. if( status != PSA_SUCCESS )
  1840. psa_fail_key_creation( slot, driver );
  1841. /* Registration doesn't keep the key in RAM. */
  1842. psa_close_key( key );
  1843. return( status );
  1844. }
  1845. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1846. static psa_status_t psa_copy_key_material( const psa_key_slot_t *source,
  1847. psa_key_slot_t *target )
  1848. {
  1849. psa_status_t status = psa_copy_key_material_into_slot( target,
  1850. source->key.data,
  1851. source->key.bytes );
  1852. if( status != PSA_SUCCESS )
  1853. return( status );
  1854. target->attr.type = source->attr.type;
  1855. target->attr.bits = source->attr.bits;
  1856. return( PSA_SUCCESS );
  1857. }
  1858. psa_status_t psa_copy_key( mbedtls_svc_key_id_t source_key,
  1859. const psa_key_attributes_t *specified_attributes,
  1860. mbedtls_svc_key_id_t *target_key )
  1861. {
  1862. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1863. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1864. psa_key_slot_t *source_slot = NULL;
  1865. psa_key_slot_t *target_slot = NULL;
  1866. psa_key_attributes_t actual_attributes = *specified_attributes;
  1867. psa_se_drv_table_entry_t *driver = NULL;
  1868. *target_key = MBEDTLS_SVC_KEY_ID_INIT;
  1869. status = psa_get_and_lock_transparent_key_slot_with_policy(
  1870. source_key, &source_slot, PSA_KEY_USAGE_COPY, 0 );
  1871. if( status != PSA_SUCCESS )
  1872. goto exit;
  1873. status = psa_validate_optional_attributes( source_slot,
  1874. specified_attributes );
  1875. if( status != PSA_SUCCESS )
  1876. goto exit;
  1877. status = psa_restrict_key_policy( source_slot->attr.type,
  1878. &actual_attributes.core.policy,
  1879. &source_slot->attr.policy );
  1880. if( status != PSA_SUCCESS )
  1881. goto exit;
  1882. status = psa_start_key_creation( PSA_KEY_CREATION_COPY, &actual_attributes,
  1883. &target_slot, &driver );
  1884. if( status != PSA_SUCCESS )
  1885. goto exit;
  1886. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1887. if( driver != NULL )
  1888. {
  1889. /* Copying to a secure element is not implemented yet. */
  1890. status = PSA_ERROR_NOT_SUPPORTED;
  1891. goto exit;
  1892. }
  1893. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1894. if( psa_key_lifetime_is_external( actual_attributes.core.lifetime ) )
  1895. {
  1896. /*
  1897. * Copying through an opaque driver is not implemented yet, consider
  1898. * a lifetime with an external location as an invalid parameter for
  1899. * now.
  1900. */
  1901. status = PSA_ERROR_INVALID_ARGUMENT;
  1902. goto exit;
  1903. }
  1904. status = psa_copy_key_material( source_slot, target_slot );
  1905. if( status != PSA_SUCCESS )
  1906. goto exit;
  1907. status = psa_finish_key_creation( target_slot, driver, target_key );
  1908. exit:
  1909. if( status != PSA_SUCCESS )
  1910. psa_fail_key_creation( target_slot, driver );
  1911. unlock_status = psa_unlock_key_slot( source_slot );
  1912. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1913. }
  1914. /****************************************************************/
  1915. /* Message digests */
  1916. /****************************************************************/
  1917. psa_status_t psa_hash_abort( psa_hash_operation_t *operation )
  1918. {
  1919. /* Aborting a non-active operation is allowed */
  1920. if( operation->id == 0 )
  1921. return( PSA_SUCCESS );
  1922. psa_status_t status = psa_driver_wrapper_hash_abort( operation );
  1923. operation->id = 0;
  1924. return( status );
  1925. }
  1926. psa_status_t psa_hash_setup( psa_hash_operation_t *operation,
  1927. psa_algorithm_t alg )
  1928. {
  1929. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1930. /* A context must be freshly initialized before it can be set up. */
  1931. if( operation->id != 0 )
  1932. {
  1933. status = PSA_ERROR_BAD_STATE;
  1934. goto exit;
  1935. }
  1936. if( !PSA_ALG_IS_HASH( alg ) )
  1937. {
  1938. status = PSA_ERROR_INVALID_ARGUMENT;
  1939. goto exit;
  1940. }
  1941. /* Ensure all of the context is zeroized, since PSA_HASH_OPERATION_INIT only
  1942. * directly zeroes the int-sized dummy member of the context union. */
  1943. memset( &operation->ctx, 0, sizeof( operation->ctx ) );
  1944. status = psa_driver_wrapper_hash_setup( operation, alg );
  1945. exit:
  1946. if( status != PSA_SUCCESS )
  1947. psa_hash_abort( operation );
  1948. return status;
  1949. }
  1950. psa_status_t psa_hash_update( psa_hash_operation_t *operation,
  1951. const uint8_t *input,
  1952. size_t input_length )
  1953. {
  1954. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1955. if( operation->id == 0 )
  1956. {
  1957. status = PSA_ERROR_BAD_STATE;
  1958. goto exit;
  1959. }
  1960. /* Don't require hash implementations to behave correctly on a
  1961. * zero-length input, which may have an invalid pointer. */
  1962. if( input_length == 0 )
  1963. return( PSA_SUCCESS );
  1964. status = psa_driver_wrapper_hash_update( operation, input, input_length );
  1965. exit:
  1966. if( status != PSA_SUCCESS )
  1967. psa_hash_abort( operation );
  1968. return( status );
  1969. }
  1970. psa_status_t psa_hash_finish( psa_hash_operation_t *operation,
  1971. uint8_t *hash,
  1972. size_t hash_size,
  1973. size_t *hash_length )
  1974. {
  1975. *hash_length = 0;
  1976. if( operation->id == 0 )
  1977. return( PSA_ERROR_BAD_STATE );
  1978. psa_status_t status = psa_driver_wrapper_hash_finish(
  1979. operation, hash, hash_size, hash_length );
  1980. psa_hash_abort( operation );
  1981. return( status );
  1982. }
  1983. psa_status_t psa_hash_verify( psa_hash_operation_t *operation,
  1984. const uint8_t *hash,
  1985. size_t hash_length )
  1986. {
  1987. uint8_t actual_hash[PSA_HASH_MAX_SIZE];
  1988. size_t actual_hash_length;
  1989. psa_status_t status = psa_hash_finish(
  1990. operation,
  1991. actual_hash, sizeof( actual_hash ),
  1992. &actual_hash_length );
  1993. if( status != PSA_SUCCESS )
  1994. goto exit;
  1995. if( actual_hash_length != hash_length )
  1996. {
  1997. status = PSA_ERROR_INVALID_SIGNATURE;
  1998. goto exit;
  1999. }
  2000. if( mbedtls_psa_safer_memcmp( hash, actual_hash, actual_hash_length ) != 0 )
  2001. status = PSA_ERROR_INVALID_SIGNATURE;
  2002. exit:
  2003. mbedtls_platform_zeroize( actual_hash, sizeof( actual_hash ) );
  2004. if( status != PSA_SUCCESS )
  2005. psa_hash_abort(operation);
  2006. return( status );
  2007. }
  2008. psa_status_t psa_hash_compute( psa_algorithm_t alg,
  2009. const uint8_t *input, size_t input_length,
  2010. uint8_t *hash, size_t hash_size,
  2011. size_t *hash_length )
  2012. {
  2013. *hash_length = 0;
  2014. if( !PSA_ALG_IS_HASH( alg ) )
  2015. return( PSA_ERROR_INVALID_ARGUMENT );
  2016. return( psa_driver_wrapper_hash_compute( alg, input, input_length,
  2017. hash, hash_size, hash_length ) );
  2018. }
  2019. psa_status_t psa_hash_compare( psa_algorithm_t alg,
  2020. const uint8_t *input, size_t input_length,
  2021. const uint8_t *hash, size_t hash_length )
  2022. {
  2023. uint8_t actual_hash[PSA_HASH_MAX_SIZE];
  2024. size_t actual_hash_length;
  2025. if( !PSA_ALG_IS_HASH( alg ) )
  2026. return( PSA_ERROR_INVALID_ARGUMENT );
  2027. psa_status_t status = psa_driver_wrapper_hash_compute(
  2028. alg, input, input_length,
  2029. actual_hash, sizeof(actual_hash),
  2030. &actual_hash_length );
  2031. if( status != PSA_SUCCESS )
  2032. goto exit;
  2033. if( actual_hash_length != hash_length )
  2034. {
  2035. status = PSA_ERROR_INVALID_SIGNATURE;
  2036. goto exit;
  2037. }
  2038. if( mbedtls_psa_safer_memcmp( hash, actual_hash, actual_hash_length ) != 0 )
  2039. status = PSA_ERROR_INVALID_SIGNATURE;
  2040. exit:
  2041. mbedtls_platform_zeroize( actual_hash, sizeof( actual_hash ) );
  2042. return( status );
  2043. }
  2044. psa_status_t psa_hash_clone( const psa_hash_operation_t *source_operation,
  2045. psa_hash_operation_t *target_operation )
  2046. {
  2047. if( source_operation->id == 0 ||
  2048. target_operation->id != 0 )
  2049. {
  2050. return( PSA_ERROR_BAD_STATE );
  2051. }
  2052. psa_status_t status = psa_driver_wrapper_hash_clone( source_operation,
  2053. target_operation );
  2054. if( status != PSA_SUCCESS )
  2055. psa_hash_abort( target_operation );
  2056. return( status );
  2057. }
  2058. /****************************************************************/
  2059. /* MAC */
  2060. /****************************************************************/
  2061. psa_status_t psa_mac_abort( psa_mac_operation_t *operation )
  2062. {
  2063. /* Aborting a non-active operation is allowed */
  2064. if( operation->id == 0 )
  2065. return( PSA_SUCCESS );
  2066. psa_status_t status = psa_driver_wrapper_mac_abort( operation );
  2067. operation->mac_size = 0;
  2068. operation->is_sign = 0;
  2069. operation->id = 0;
  2070. return( status );
  2071. }
  2072. static psa_status_t psa_mac_finalize_alg_and_key_validation(
  2073. psa_algorithm_t alg,
  2074. const psa_key_attributes_t *attributes,
  2075. uint8_t *mac_size )
  2076. {
  2077. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2078. psa_key_type_t key_type = psa_get_key_type( attributes );
  2079. size_t key_bits = psa_get_key_bits( attributes );
  2080. if( ! PSA_ALG_IS_MAC( alg ) )
  2081. return( PSA_ERROR_INVALID_ARGUMENT );
  2082. /* Validate the combination of key type and algorithm */
  2083. status = psa_mac_key_can_do( alg, key_type );
  2084. if( status != PSA_SUCCESS )
  2085. return( status );
  2086. /* Get the output length for the algorithm and key combination */
  2087. *mac_size = PSA_MAC_LENGTH( key_type, key_bits, alg );
  2088. if( *mac_size < 4 )
  2089. {
  2090. /* A very short MAC is too short for security since it can be
  2091. * brute-forced. Ancient protocols with 32-bit MACs do exist,
  2092. * so we make this our minimum, even though 32 bits is still
  2093. * too small for security. */
  2094. return( PSA_ERROR_NOT_SUPPORTED );
  2095. }
  2096. if( *mac_size > PSA_MAC_LENGTH( key_type, key_bits,
  2097. PSA_ALG_FULL_LENGTH_MAC( alg ) ) )
  2098. {
  2099. /* It's impossible to "truncate" to a larger length than the full length
  2100. * of the algorithm. */
  2101. return( PSA_ERROR_INVALID_ARGUMENT );
  2102. }
  2103. if( *mac_size > PSA_MAC_MAX_SIZE )
  2104. {
  2105. /* PSA_MAC_LENGTH returns the correct length even for a MAC algorithm
  2106. * that is disabled in the compile-time configuration. The result can
  2107. * therefore be larger than PSA_MAC_MAX_SIZE, which does take the
  2108. * configuration into account. In this case, force a return of
  2109. * PSA_ERROR_NOT_SUPPORTED here. Otherwise psa_mac_verify(), or
  2110. * psa_mac_compute(mac_size=PSA_MAC_MAX_SIZE), would return
  2111. * PSA_ERROR_BUFFER_TOO_SMALL for an unsupported algorithm whose MAC size
  2112. * is larger than PSA_MAC_MAX_SIZE, which is misleading and which breaks
  2113. * systematically generated tests. */
  2114. return( PSA_ERROR_NOT_SUPPORTED );
  2115. }
  2116. return( PSA_SUCCESS );
  2117. }
  2118. static psa_status_t psa_mac_setup( psa_mac_operation_t *operation,
  2119. mbedtls_svc_key_id_t key,
  2120. psa_algorithm_t alg,
  2121. int is_sign )
  2122. {
  2123. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2124. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2125. psa_key_slot_t *slot = NULL;
  2126. /* A context must be freshly initialized before it can be set up. */
  2127. if( operation->id != 0 )
  2128. {
  2129. status = PSA_ERROR_BAD_STATE;
  2130. goto exit;
  2131. }
  2132. status = psa_get_and_lock_key_slot_with_policy(
  2133. key,
  2134. &slot,
  2135. is_sign ? PSA_KEY_USAGE_SIGN_MESSAGE : PSA_KEY_USAGE_VERIFY_MESSAGE,
  2136. alg );
  2137. if( status != PSA_SUCCESS )
  2138. goto exit;
  2139. psa_key_attributes_t attributes = {
  2140. .core = slot->attr
  2141. };
  2142. status = psa_mac_finalize_alg_and_key_validation( alg, &attributes,
  2143. &operation->mac_size );
  2144. if( status != PSA_SUCCESS )
  2145. goto exit;
  2146. operation->is_sign = is_sign;
  2147. /* Dispatch the MAC setup call with validated input */
  2148. if( is_sign )
  2149. {
  2150. status = psa_driver_wrapper_mac_sign_setup( operation,
  2151. &attributes,
  2152. slot->key.data,
  2153. slot->key.bytes,
  2154. alg );
  2155. }
  2156. else
  2157. {
  2158. status = psa_driver_wrapper_mac_verify_setup( operation,
  2159. &attributes,
  2160. slot->key.data,
  2161. slot->key.bytes,
  2162. alg );
  2163. }
  2164. exit:
  2165. if( status != PSA_SUCCESS )
  2166. psa_mac_abort( operation );
  2167. unlock_status = psa_unlock_key_slot( slot );
  2168. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2169. }
  2170. psa_status_t psa_mac_sign_setup( psa_mac_operation_t *operation,
  2171. mbedtls_svc_key_id_t key,
  2172. psa_algorithm_t alg )
  2173. {
  2174. return( psa_mac_setup( operation, key, alg, 1 ) );
  2175. }
  2176. psa_status_t psa_mac_verify_setup( psa_mac_operation_t *operation,
  2177. mbedtls_svc_key_id_t key,
  2178. psa_algorithm_t alg )
  2179. {
  2180. return( psa_mac_setup( operation, key, alg, 0 ) );
  2181. }
  2182. psa_status_t psa_mac_update( psa_mac_operation_t *operation,
  2183. const uint8_t *input,
  2184. size_t input_length )
  2185. {
  2186. if( operation->id == 0 )
  2187. return( PSA_ERROR_BAD_STATE );
  2188. /* Don't require hash implementations to behave correctly on a
  2189. * zero-length input, which may have an invalid pointer. */
  2190. if( input_length == 0 )
  2191. return( PSA_SUCCESS );
  2192. psa_status_t status = psa_driver_wrapper_mac_update( operation,
  2193. input, input_length );
  2194. if( status != PSA_SUCCESS )
  2195. psa_mac_abort( operation );
  2196. return( status );
  2197. }
  2198. psa_status_t psa_mac_sign_finish( psa_mac_operation_t *operation,
  2199. uint8_t *mac,
  2200. size_t mac_size,
  2201. size_t *mac_length )
  2202. {
  2203. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2204. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  2205. if( operation->id == 0 )
  2206. {
  2207. status = PSA_ERROR_BAD_STATE;
  2208. goto exit;
  2209. }
  2210. if( ! operation->is_sign )
  2211. {
  2212. status = PSA_ERROR_BAD_STATE;
  2213. goto exit;
  2214. }
  2215. /* Sanity check. This will guarantee that mac_size != 0 (and so mac != NULL)
  2216. * once all the error checks are done. */
  2217. if( operation->mac_size == 0 )
  2218. {
  2219. status = PSA_ERROR_BAD_STATE;
  2220. goto exit;
  2221. }
  2222. if( mac_size < operation->mac_size )
  2223. {
  2224. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2225. goto exit;
  2226. }
  2227. status = psa_driver_wrapper_mac_sign_finish( operation,
  2228. mac, operation->mac_size,
  2229. mac_length );
  2230. exit:
  2231. /* In case of success, set the potential excess room in the output buffer
  2232. * to an invalid value, to avoid potentially leaking a longer MAC.
  2233. * In case of error, set the output length and content to a safe default,
  2234. * such that in case the caller misses an error check, the output would be
  2235. * an unachievable MAC.
  2236. */
  2237. if( status != PSA_SUCCESS )
  2238. {
  2239. *mac_length = mac_size;
  2240. operation->mac_size = 0;
  2241. }
  2242. if( mac_size > operation->mac_size )
  2243. memset( &mac[operation->mac_size], '!',
  2244. mac_size - operation->mac_size );
  2245. abort_status = psa_mac_abort( operation );
  2246. return( status == PSA_SUCCESS ? abort_status : status );
  2247. }
  2248. psa_status_t psa_mac_verify_finish( psa_mac_operation_t *operation,
  2249. const uint8_t *mac,
  2250. size_t mac_length )
  2251. {
  2252. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2253. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  2254. if( operation->id == 0 )
  2255. {
  2256. status = PSA_ERROR_BAD_STATE;
  2257. goto exit;
  2258. }
  2259. if( operation->is_sign )
  2260. {
  2261. status = PSA_ERROR_BAD_STATE;
  2262. goto exit;
  2263. }
  2264. if( operation->mac_size != mac_length )
  2265. {
  2266. status = PSA_ERROR_INVALID_SIGNATURE;
  2267. goto exit;
  2268. }
  2269. status = psa_driver_wrapper_mac_verify_finish( operation,
  2270. mac, mac_length );
  2271. exit:
  2272. abort_status = psa_mac_abort( operation );
  2273. return( status == PSA_SUCCESS ? abort_status : status );
  2274. }
  2275. static psa_status_t psa_mac_compute_internal( mbedtls_svc_key_id_t key,
  2276. psa_algorithm_t alg,
  2277. const uint8_t *input,
  2278. size_t input_length,
  2279. uint8_t *mac,
  2280. size_t mac_size,
  2281. size_t *mac_length,
  2282. int is_sign )
  2283. {
  2284. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2285. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2286. psa_key_slot_t *slot;
  2287. uint8_t operation_mac_size = 0;
  2288. status = psa_get_and_lock_key_slot_with_policy(
  2289. key,
  2290. &slot,
  2291. is_sign ? PSA_KEY_USAGE_SIGN_MESSAGE : PSA_KEY_USAGE_VERIFY_MESSAGE,
  2292. alg );
  2293. if( status != PSA_SUCCESS )
  2294. goto exit;
  2295. psa_key_attributes_t attributes = {
  2296. .core = slot->attr
  2297. };
  2298. status = psa_mac_finalize_alg_and_key_validation( alg, &attributes,
  2299. &operation_mac_size );
  2300. if( status != PSA_SUCCESS )
  2301. goto exit;
  2302. if( mac_size < operation_mac_size )
  2303. {
  2304. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2305. goto exit;
  2306. }
  2307. status = psa_driver_wrapper_mac_compute(
  2308. &attributes,
  2309. slot->key.data, slot->key.bytes,
  2310. alg,
  2311. input, input_length,
  2312. mac, operation_mac_size, mac_length );
  2313. exit:
  2314. /* In case of success, set the potential excess room in the output buffer
  2315. * to an invalid value, to avoid potentially leaking a longer MAC.
  2316. * In case of error, set the output length and content to a safe default,
  2317. * such that in case the caller misses an error check, the output would be
  2318. * an unachievable MAC.
  2319. */
  2320. if( status != PSA_SUCCESS )
  2321. {
  2322. *mac_length = mac_size;
  2323. operation_mac_size = 0;
  2324. }
  2325. if( mac_size > operation_mac_size )
  2326. memset( &mac[operation_mac_size], '!', mac_size - operation_mac_size );
  2327. unlock_status = psa_unlock_key_slot( slot );
  2328. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2329. }
  2330. psa_status_t psa_mac_compute( mbedtls_svc_key_id_t key,
  2331. psa_algorithm_t alg,
  2332. const uint8_t *input,
  2333. size_t input_length,
  2334. uint8_t *mac,
  2335. size_t mac_size,
  2336. size_t *mac_length)
  2337. {
  2338. return( psa_mac_compute_internal( key, alg,
  2339. input, input_length,
  2340. mac, mac_size, mac_length, 1 ) );
  2341. }
  2342. psa_status_t psa_mac_verify( mbedtls_svc_key_id_t key,
  2343. psa_algorithm_t alg,
  2344. const uint8_t *input,
  2345. size_t input_length,
  2346. const uint8_t *mac,
  2347. size_t mac_length)
  2348. {
  2349. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2350. uint8_t actual_mac[PSA_MAC_MAX_SIZE];
  2351. size_t actual_mac_length;
  2352. status = psa_mac_compute_internal( key, alg,
  2353. input, input_length,
  2354. actual_mac, sizeof( actual_mac ),
  2355. &actual_mac_length, 0 );
  2356. if( status != PSA_SUCCESS )
  2357. goto exit;
  2358. if( mac_length != actual_mac_length )
  2359. {
  2360. status = PSA_ERROR_INVALID_SIGNATURE;
  2361. goto exit;
  2362. }
  2363. if( mbedtls_psa_safer_memcmp( mac, actual_mac, actual_mac_length ) != 0 )
  2364. {
  2365. status = PSA_ERROR_INVALID_SIGNATURE;
  2366. goto exit;
  2367. }
  2368. exit:
  2369. mbedtls_platform_zeroize( actual_mac, sizeof( actual_mac ) );
  2370. return ( status );
  2371. }
  2372. /****************************************************************/
  2373. /* Asymmetric cryptography */
  2374. /****************************************************************/
  2375. static psa_status_t psa_sign_verify_check_alg( int input_is_message,
  2376. psa_algorithm_t alg )
  2377. {
  2378. if( input_is_message )
  2379. {
  2380. if( ! PSA_ALG_IS_SIGN_MESSAGE( alg ) )
  2381. return( PSA_ERROR_INVALID_ARGUMENT );
  2382. if ( PSA_ALG_IS_SIGN_HASH( alg ) )
  2383. {
  2384. if( ! PSA_ALG_IS_HASH( PSA_ALG_SIGN_GET_HASH( alg ) ) )
  2385. return( PSA_ERROR_INVALID_ARGUMENT );
  2386. }
  2387. }
  2388. else
  2389. {
  2390. if( ! PSA_ALG_IS_SIGN_HASH( alg ) )
  2391. return( PSA_ERROR_INVALID_ARGUMENT );
  2392. }
  2393. return( PSA_SUCCESS );
  2394. }
  2395. static psa_status_t psa_sign_internal( mbedtls_svc_key_id_t key,
  2396. int input_is_message,
  2397. psa_algorithm_t alg,
  2398. const uint8_t * input,
  2399. size_t input_length,
  2400. uint8_t * signature,
  2401. size_t signature_size,
  2402. size_t * signature_length )
  2403. {
  2404. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2405. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2406. psa_key_slot_t *slot;
  2407. *signature_length = 0;
  2408. status = psa_sign_verify_check_alg( input_is_message, alg );
  2409. if( status != PSA_SUCCESS )
  2410. return status;
  2411. /* Immediately reject a zero-length signature buffer. This guarantees
  2412. * that signature must be a valid pointer. (On the other hand, the input
  2413. * buffer can in principle be empty since it doesn't actually have
  2414. * to be a hash.) */
  2415. if( signature_size == 0 )
  2416. return( PSA_ERROR_BUFFER_TOO_SMALL );
  2417. status = psa_get_and_lock_key_slot_with_policy(
  2418. key, &slot,
  2419. input_is_message ? PSA_KEY_USAGE_SIGN_MESSAGE :
  2420. PSA_KEY_USAGE_SIGN_HASH,
  2421. alg );
  2422. if( status != PSA_SUCCESS )
  2423. goto exit;
  2424. if( ! PSA_KEY_TYPE_IS_KEY_PAIR( slot->attr.type ) )
  2425. {
  2426. status = PSA_ERROR_INVALID_ARGUMENT;
  2427. goto exit;
  2428. }
  2429. psa_key_attributes_t attributes = {
  2430. .core = slot->attr
  2431. };
  2432. if( input_is_message )
  2433. {
  2434. status = psa_driver_wrapper_sign_message(
  2435. &attributes, slot->key.data, slot->key.bytes,
  2436. alg, input, input_length,
  2437. signature, signature_size, signature_length );
  2438. }
  2439. else
  2440. {
  2441. status = psa_driver_wrapper_sign_hash(
  2442. &attributes, slot->key.data, slot->key.bytes,
  2443. alg, input, input_length,
  2444. signature, signature_size, signature_length );
  2445. }
  2446. exit:
  2447. /* Fill the unused part of the output buffer (the whole buffer on error,
  2448. * the trailing part on success) with something that isn't a valid signature
  2449. * (barring an attack on the signature and deliberately-crafted input),
  2450. * in case the caller doesn't check the return status properly. */
  2451. if( status == PSA_SUCCESS )
  2452. memset( signature + *signature_length, '!',
  2453. signature_size - *signature_length );
  2454. else
  2455. memset( signature, '!', signature_size );
  2456. /* If signature_size is 0 then we have nothing to do. We must not call
  2457. * memset because signature may be NULL in this case. */
  2458. unlock_status = psa_unlock_key_slot( slot );
  2459. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2460. }
  2461. static psa_status_t psa_verify_internal( mbedtls_svc_key_id_t key,
  2462. int input_is_message,
  2463. psa_algorithm_t alg,
  2464. const uint8_t * input,
  2465. size_t input_length,
  2466. const uint8_t * signature,
  2467. size_t signature_length )
  2468. {
  2469. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2470. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2471. psa_key_slot_t *slot;
  2472. status = psa_sign_verify_check_alg( input_is_message, alg );
  2473. if( status != PSA_SUCCESS )
  2474. return status;
  2475. status = psa_get_and_lock_key_slot_with_policy(
  2476. key, &slot,
  2477. input_is_message ? PSA_KEY_USAGE_VERIFY_MESSAGE :
  2478. PSA_KEY_USAGE_VERIFY_HASH,
  2479. alg );
  2480. if( status != PSA_SUCCESS )
  2481. return( status );
  2482. psa_key_attributes_t attributes = {
  2483. .core = slot->attr
  2484. };
  2485. if( input_is_message )
  2486. {
  2487. status = psa_driver_wrapper_verify_message(
  2488. &attributes, slot->key.data, slot->key.bytes,
  2489. alg, input, input_length,
  2490. signature, signature_length );
  2491. }
  2492. else
  2493. {
  2494. status = psa_driver_wrapper_verify_hash(
  2495. &attributes, slot->key.data, slot->key.bytes,
  2496. alg, input, input_length,
  2497. signature, signature_length );
  2498. }
  2499. unlock_status = psa_unlock_key_slot( slot );
  2500. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2501. }
  2502. psa_status_t psa_sign_message_builtin(
  2503. const psa_key_attributes_t *attributes,
  2504. const uint8_t *key_buffer,
  2505. size_t key_buffer_size,
  2506. psa_algorithm_t alg,
  2507. const uint8_t *input,
  2508. size_t input_length,
  2509. uint8_t *signature,
  2510. size_t signature_size,
  2511. size_t *signature_length )
  2512. {
  2513. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2514. if ( PSA_ALG_IS_SIGN_HASH( alg ) )
  2515. {
  2516. size_t hash_length;
  2517. uint8_t hash[PSA_HASH_MAX_SIZE];
  2518. status = psa_driver_wrapper_hash_compute(
  2519. PSA_ALG_SIGN_GET_HASH( alg ),
  2520. input, input_length,
  2521. hash, sizeof( hash ), &hash_length );
  2522. if( status != PSA_SUCCESS )
  2523. return status;
  2524. return psa_driver_wrapper_sign_hash(
  2525. attributes, key_buffer, key_buffer_size,
  2526. alg, hash, hash_length,
  2527. signature, signature_size, signature_length );
  2528. }
  2529. return( PSA_ERROR_NOT_SUPPORTED );
  2530. }
  2531. psa_status_t psa_sign_message( mbedtls_svc_key_id_t key,
  2532. psa_algorithm_t alg,
  2533. const uint8_t * input,
  2534. size_t input_length,
  2535. uint8_t * signature,
  2536. size_t signature_size,
  2537. size_t * signature_length )
  2538. {
  2539. return psa_sign_internal(
  2540. key, 1, alg, input, input_length,
  2541. signature, signature_size, signature_length );
  2542. }
  2543. psa_status_t psa_verify_message_builtin(
  2544. const psa_key_attributes_t *attributes,
  2545. const uint8_t *key_buffer,
  2546. size_t key_buffer_size,
  2547. psa_algorithm_t alg,
  2548. const uint8_t *input,
  2549. size_t input_length,
  2550. const uint8_t *signature,
  2551. size_t signature_length )
  2552. {
  2553. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2554. if ( PSA_ALG_IS_SIGN_HASH( alg ) )
  2555. {
  2556. size_t hash_length;
  2557. uint8_t hash[PSA_HASH_MAX_SIZE];
  2558. status = psa_driver_wrapper_hash_compute(
  2559. PSA_ALG_SIGN_GET_HASH( alg ),
  2560. input, input_length,
  2561. hash, sizeof( hash ), &hash_length );
  2562. if( status != PSA_SUCCESS )
  2563. return status;
  2564. return psa_driver_wrapper_verify_hash(
  2565. attributes, key_buffer, key_buffer_size,
  2566. alg, hash, hash_length,
  2567. signature, signature_length );
  2568. }
  2569. return( PSA_ERROR_NOT_SUPPORTED );
  2570. }
  2571. psa_status_t psa_verify_message( mbedtls_svc_key_id_t key,
  2572. psa_algorithm_t alg,
  2573. const uint8_t * input,
  2574. size_t input_length,
  2575. const uint8_t * signature,
  2576. size_t signature_length )
  2577. {
  2578. return psa_verify_internal(
  2579. key, 1, alg, input, input_length,
  2580. signature, signature_length );
  2581. }
  2582. psa_status_t psa_sign_hash_builtin(
  2583. const psa_key_attributes_t *attributes,
  2584. const uint8_t *key_buffer, size_t key_buffer_size,
  2585. psa_algorithm_t alg, const uint8_t *hash, size_t hash_length,
  2586. uint8_t *signature, size_t signature_size, size_t *signature_length )
  2587. {
  2588. if( attributes->core.type == PSA_KEY_TYPE_RSA_KEY_PAIR )
  2589. {
  2590. if( PSA_ALG_IS_RSA_PKCS1V15_SIGN( alg ) ||
  2591. PSA_ALG_IS_RSA_PSS( alg) )
  2592. {
  2593. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) || \
  2594. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS)
  2595. return( mbedtls_psa_rsa_sign_hash(
  2596. attributes,
  2597. key_buffer, key_buffer_size,
  2598. alg, hash, hash_length,
  2599. signature, signature_size, signature_length ) );
  2600. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) ||
  2601. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS) */
  2602. }
  2603. else
  2604. {
  2605. return( PSA_ERROR_INVALID_ARGUMENT );
  2606. }
  2607. }
  2608. else if( PSA_KEY_TYPE_IS_ECC( attributes->core.type ) )
  2609. {
  2610. if( PSA_ALG_IS_ECDSA( alg ) )
  2611. {
  2612. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  2613. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  2614. return( mbedtls_psa_ecdsa_sign_hash(
  2615. attributes,
  2616. key_buffer, key_buffer_size,
  2617. alg, hash, hash_length,
  2618. signature, signature_size, signature_length ) );
  2619. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  2620. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  2621. }
  2622. else
  2623. {
  2624. return( PSA_ERROR_INVALID_ARGUMENT );
  2625. }
  2626. }
  2627. (void)key_buffer;
  2628. (void)key_buffer_size;
  2629. (void)hash;
  2630. (void)hash_length;
  2631. (void)signature;
  2632. (void)signature_size;
  2633. (void)signature_length;
  2634. return( PSA_ERROR_NOT_SUPPORTED );
  2635. }
  2636. psa_status_t psa_sign_hash( mbedtls_svc_key_id_t key,
  2637. psa_algorithm_t alg,
  2638. const uint8_t *hash,
  2639. size_t hash_length,
  2640. uint8_t *signature,
  2641. size_t signature_size,
  2642. size_t *signature_length )
  2643. {
  2644. return psa_sign_internal(
  2645. key, 0, alg, hash, hash_length,
  2646. signature, signature_size, signature_length );
  2647. }
  2648. psa_status_t psa_verify_hash_builtin(
  2649. const psa_key_attributes_t *attributes,
  2650. const uint8_t *key_buffer, size_t key_buffer_size,
  2651. psa_algorithm_t alg, const uint8_t *hash, size_t hash_length,
  2652. const uint8_t *signature, size_t signature_length )
  2653. {
  2654. if( PSA_KEY_TYPE_IS_RSA( attributes->core.type ) )
  2655. {
  2656. if( PSA_ALG_IS_RSA_PKCS1V15_SIGN( alg ) ||
  2657. PSA_ALG_IS_RSA_PSS( alg) )
  2658. {
  2659. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) || \
  2660. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS)
  2661. return( mbedtls_psa_rsa_verify_hash(
  2662. attributes,
  2663. key_buffer, key_buffer_size,
  2664. alg, hash, hash_length,
  2665. signature, signature_length ) );
  2666. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) ||
  2667. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS) */
  2668. }
  2669. else
  2670. {
  2671. return( PSA_ERROR_INVALID_ARGUMENT );
  2672. }
  2673. }
  2674. else if( PSA_KEY_TYPE_IS_ECC( attributes->core.type ) )
  2675. {
  2676. if( PSA_ALG_IS_ECDSA( alg ) )
  2677. {
  2678. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  2679. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  2680. return( mbedtls_psa_ecdsa_verify_hash(
  2681. attributes,
  2682. key_buffer, key_buffer_size,
  2683. alg, hash, hash_length,
  2684. signature, signature_length ) );
  2685. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  2686. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  2687. }
  2688. else
  2689. {
  2690. return( PSA_ERROR_INVALID_ARGUMENT );
  2691. }
  2692. }
  2693. (void)key_buffer;
  2694. (void)key_buffer_size;
  2695. (void)hash;
  2696. (void)hash_length;
  2697. (void)signature;
  2698. (void)signature_length;
  2699. return( PSA_ERROR_NOT_SUPPORTED );
  2700. }
  2701. psa_status_t psa_verify_hash( mbedtls_svc_key_id_t key,
  2702. psa_algorithm_t alg,
  2703. const uint8_t *hash,
  2704. size_t hash_length,
  2705. const uint8_t *signature,
  2706. size_t signature_length )
  2707. {
  2708. return psa_verify_internal(
  2709. key, 0, alg, hash, hash_length,
  2710. signature, signature_length );
  2711. }
  2712. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2713. static void psa_rsa_oaep_set_padding_mode( psa_algorithm_t alg,
  2714. mbedtls_rsa_context *rsa )
  2715. {
  2716. psa_algorithm_t hash_alg = PSA_ALG_RSA_OAEP_GET_HASH( alg );
  2717. const mbedtls_md_info_t *md_info = mbedtls_md_info_from_psa( hash_alg );
  2718. mbedtls_md_type_t md_alg = mbedtls_md_get_type( md_info );
  2719. mbedtls_rsa_set_padding( rsa, MBEDTLS_RSA_PKCS_V21, md_alg );
  2720. }
  2721. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2722. psa_status_t psa_asymmetric_encrypt( mbedtls_svc_key_id_t key,
  2723. psa_algorithm_t alg,
  2724. const uint8_t *input,
  2725. size_t input_length,
  2726. const uint8_t *salt,
  2727. size_t salt_length,
  2728. uint8_t *output,
  2729. size_t output_size,
  2730. size_t *output_length )
  2731. {
  2732. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2733. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2734. psa_key_slot_t *slot;
  2735. (void) input;
  2736. (void) input_length;
  2737. (void) salt;
  2738. (void) output;
  2739. (void) output_size;
  2740. *output_length = 0;
  2741. if( ! PSA_ALG_IS_RSA_OAEP( alg ) && salt_length != 0 )
  2742. return( PSA_ERROR_INVALID_ARGUMENT );
  2743. status = psa_get_and_lock_transparent_key_slot_with_policy(
  2744. key, &slot, PSA_KEY_USAGE_ENCRYPT, alg );
  2745. if( status != PSA_SUCCESS )
  2746. return( status );
  2747. if( ! ( PSA_KEY_TYPE_IS_PUBLIC_KEY( slot->attr.type ) ||
  2748. PSA_KEY_TYPE_IS_KEY_PAIR( slot->attr.type ) ) )
  2749. {
  2750. status = PSA_ERROR_INVALID_ARGUMENT;
  2751. goto exit;
  2752. }
  2753. if( PSA_KEY_TYPE_IS_RSA( slot->attr.type ) )
  2754. {
  2755. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) || \
  2756. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2757. mbedtls_rsa_context *rsa = NULL;
  2758. status = mbedtls_psa_rsa_load_representation( slot->attr.type,
  2759. slot->key.data,
  2760. slot->key.bytes,
  2761. &rsa );
  2762. if( status != PSA_SUCCESS )
  2763. goto rsa_exit;
  2764. if( output_size < mbedtls_rsa_get_len( rsa ) )
  2765. {
  2766. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2767. goto rsa_exit;
  2768. }
  2769. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) ||
  2770. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2771. if( alg == PSA_ALG_RSA_PKCS1V15_CRYPT )
  2772. {
  2773. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT)
  2774. status = mbedtls_to_psa_error(
  2775. mbedtls_rsa_pkcs1_encrypt( rsa,
  2776. mbedtls_psa_get_random,
  2777. MBEDTLS_PSA_RANDOM_STATE,
  2778. MBEDTLS_RSA_PUBLIC,
  2779. input_length,
  2780. input,
  2781. output ) );
  2782. #else
  2783. status = PSA_ERROR_NOT_SUPPORTED;
  2784. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT */
  2785. }
  2786. else
  2787. if( PSA_ALG_IS_RSA_OAEP( alg ) )
  2788. {
  2789. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2790. psa_rsa_oaep_set_padding_mode( alg, rsa );
  2791. status = mbedtls_to_psa_error(
  2792. mbedtls_rsa_rsaes_oaep_encrypt( rsa,
  2793. mbedtls_psa_get_random,
  2794. MBEDTLS_PSA_RANDOM_STATE,
  2795. MBEDTLS_RSA_PUBLIC,
  2796. salt, salt_length,
  2797. input_length,
  2798. input,
  2799. output ) );
  2800. #else
  2801. status = PSA_ERROR_NOT_SUPPORTED;
  2802. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP */
  2803. }
  2804. else
  2805. {
  2806. status = PSA_ERROR_INVALID_ARGUMENT;
  2807. }
  2808. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) || \
  2809. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2810. rsa_exit:
  2811. if( status == PSA_SUCCESS )
  2812. *output_length = mbedtls_rsa_get_len( rsa );
  2813. mbedtls_rsa_free( rsa );
  2814. mbedtls_free( rsa );
  2815. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) ||
  2816. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2817. }
  2818. else
  2819. {
  2820. status = PSA_ERROR_NOT_SUPPORTED;
  2821. }
  2822. exit:
  2823. unlock_status = psa_unlock_key_slot( slot );
  2824. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2825. }
  2826. psa_status_t psa_asymmetric_decrypt( mbedtls_svc_key_id_t key,
  2827. psa_algorithm_t alg,
  2828. const uint8_t *input,
  2829. size_t input_length,
  2830. const uint8_t *salt,
  2831. size_t salt_length,
  2832. uint8_t *output,
  2833. size_t output_size,
  2834. size_t *output_length )
  2835. {
  2836. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2837. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2838. psa_key_slot_t *slot;
  2839. (void) input;
  2840. (void) input_length;
  2841. (void) salt;
  2842. (void) output;
  2843. (void) output_size;
  2844. *output_length = 0;
  2845. if( ! PSA_ALG_IS_RSA_OAEP( alg ) && salt_length != 0 )
  2846. return( PSA_ERROR_INVALID_ARGUMENT );
  2847. status = psa_get_and_lock_transparent_key_slot_with_policy(
  2848. key, &slot, PSA_KEY_USAGE_DECRYPT, alg );
  2849. if( status != PSA_SUCCESS )
  2850. return( status );
  2851. if( ! PSA_KEY_TYPE_IS_KEY_PAIR( slot->attr.type ) )
  2852. {
  2853. status = PSA_ERROR_INVALID_ARGUMENT;
  2854. goto exit;
  2855. }
  2856. if( slot->attr.type == PSA_KEY_TYPE_RSA_KEY_PAIR )
  2857. {
  2858. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) || \
  2859. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2860. mbedtls_rsa_context *rsa = NULL;
  2861. status = mbedtls_psa_rsa_load_representation( slot->attr.type,
  2862. slot->key.data,
  2863. slot->key.bytes,
  2864. &rsa );
  2865. if( status != PSA_SUCCESS )
  2866. goto exit;
  2867. if( input_length != mbedtls_rsa_get_len( rsa ) )
  2868. {
  2869. status = PSA_ERROR_INVALID_ARGUMENT;
  2870. goto rsa_exit;
  2871. }
  2872. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) ||
  2873. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2874. if( alg == PSA_ALG_RSA_PKCS1V15_CRYPT )
  2875. {
  2876. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT)
  2877. status = mbedtls_to_psa_error(
  2878. mbedtls_rsa_pkcs1_decrypt( rsa,
  2879. mbedtls_psa_get_random,
  2880. MBEDTLS_PSA_RANDOM_STATE,
  2881. MBEDTLS_RSA_PRIVATE,
  2882. output_length,
  2883. input,
  2884. output,
  2885. output_size ) );
  2886. #else
  2887. status = PSA_ERROR_NOT_SUPPORTED;
  2888. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT */
  2889. }
  2890. else
  2891. if( PSA_ALG_IS_RSA_OAEP( alg ) )
  2892. {
  2893. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2894. psa_rsa_oaep_set_padding_mode( alg, rsa );
  2895. status = mbedtls_to_psa_error(
  2896. mbedtls_rsa_rsaes_oaep_decrypt( rsa,
  2897. mbedtls_psa_get_random,
  2898. MBEDTLS_PSA_RANDOM_STATE,
  2899. MBEDTLS_RSA_PRIVATE,
  2900. salt, salt_length,
  2901. output_length,
  2902. input,
  2903. output,
  2904. output_size ) );
  2905. #else
  2906. status = PSA_ERROR_NOT_SUPPORTED;
  2907. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP */
  2908. }
  2909. else
  2910. {
  2911. status = PSA_ERROR_INVALID_ARGUMENT;
  2912. }
  2913. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) || \
  2914. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2915. rsa_exit:
  2916. mbedtls_rsa_free( rsa );
  2917. mbedtls_free( rsa );
  2918. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) ||
  2919. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2920. }
  2921. else
  2922. {
  2923. status = PSA_ERROR_NOT_SUPPORTED;
  2924. }
  2925. exit:
  2926. unlock_status = psa_unlock_key_slot( slot );
  2927. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2928. }
  2929. /****************************************************************/
  2930. /* Symmetric cryptography */
  2931. /****************************************************************/
  2932. static psa_status_t psa_cipher_setup( psa_cipher_operation_t *operation,
  2933. mbedtls_svc_key_id_t key,
  2934. psa_algorithm_t alg,
  2935. mbedtls_operation_t cipher_operation )
  2936. {
  2937. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2938. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2939. psa_key_slot_t *slot = NULL;
  2940. psa_key_usage_t usage = ( cipher_operation == MBEDTLS_ENCRYPT ?
  2941. PSA_KEY_USAGE_ENCRYPT :
  2942. PSA_KEY_USAGE_DECRYPT );
  2943. /* A context must be freshly initialized before it can be set up. */
  2944. if( operation->id != 0 )
  2945. {
  2946. status = PSA_ERROR_BAD_STATE;
  2947. goto exit;
  2948. }
  2949. if( ! PSA_ALG_IS_CIPHER( alg ) )
  2950. {
  2951. status = PSA_ERROR_INVALID_ARGUMENT;
  2952. goto exit;
  2953. }
  2954. status = psa_get_and_lock_key_slot_with_policy( key, &slot, usage, alg );
  2955. if( status != PSA_SUCCESS )
  2956. goto exit;
  2957. /* Initialize the operation struct members, except for id. The id member
  2958. * is used to indicate to psa_cipher_abort that there are resources to free,
  2959. * so we only set it (in the driver wrapper) after resources have been
  2960. * allocated/initialized. */
  2961. operation->iv_set = 0;
  2962. if( alg == PSA_ALG_ECB_NO_PADDING )
  2963. operation->iv_required = 0;
  2964. else if( slot->attr.type == PSA_KEY_TYPE_ARC4 )
  2965. operation->iv_required = 0;
  2966. else
  2967. operation->iv_required = 1;
  2968. operation->default_iv_length = PSA_CIPHER_IV_LENGTH( slot->attr.type, alg );
  2969. psa_key_attributes_t attributes = {
  2970. .core = slot->attr
  2971. };
  2972. /* Try doing the operation through a driver before using software fallback. */
  2973. if( cipher_operation == MBEDTLS_ENCRYPT )
  2974. status = psa_driver_wrapper_cipher_encrypt_setup( operation,
  2975. &attributes,
  2976. slot->key.data,
  2977. slot->key.bytes,
  2978. alg );
  2979. else
  2980. status = psa_driver_wrapper_cipher_decrypt_setup( operation,
  2981. &attributes,
  2982. slot->key.data,
  2983. slot->key.bytes,
  2984. alg );
  2985. exit:
  2986. if( status != PSA_SUCCESS )
  2987. psa_cipher_abort( operation );
  2988. unlock_status = psa_unlock_key_slot( slot );
  2989. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2990. }
  2991. psa_status_t psa_cipher_encrypt_setup( psa_cipher_operation_t *operation,
  2992. mbedtls_svc_key_id_t key,
  2993. psa_algorithm_t alg )
  2994. {
  2995. return( psa_cipher_setup( operation, key, alg, MBEDTLS_ENCRYPT ) );
  2996. }
  2997. psa_status_t psa_cipher_decrypt_setup( psa_cipher_operation_t *operation,
  2998. mbedtls_svc_key_id_t key,
  2999. psa_algorithm_t alg )
  3000. {
  3001. return( psa_cipher_setup( operation, key, alg, MBEDTLS_DECRYPT ) );
  3002. }
  3003. psa_status_t psa_cipher_generate_iv( psa_cipher_operation_t *operation,
  3004. uint8_t *iv,
  3005. size_t iv_size,
  3006. size_t *iv_length )
  3007. {
  3008. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3009. uint8_t local_iv[PSA_CIPHER_IV_MAX_SIZE];
  3010. size_t default_iv_length;
  3011. if( operation->id == 0 )
  3012. {
  3013. status = PSA_ERROR_BAD_STATE;
  3014. goto exit;
  3015. }
  3016. if( operation->iv_set || ! operation->iv_required )
  3017. {
  3018. status = PSA_ERROR_BAD_STATE;
  3019. goto exit;
  3020. }
  3021. default_iv_length = operation->default_iv_length;
  3022. if( iv_size < default_iv_length )
  3023. {
  3024. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3025. goto exit;
  3026. }
  3027. if( default_iv_length > PSA_CIPHER_IV_MAX_SIZE )
  3028. {
  3029. status = PSA_ERROR_GENERIC_ERROR;
  3030. goto exit;
  3031. }
  3032. status = psa_generate_random( local_iv, default_iv_length );
  3033. if( status != PSA_SUCCESS )
  3034. goto exit;
  3035. status = psa_driver_wrapper_cipher_set_iv( operation,
  3036. local_iv, default_iv_length );
  3037. exit:
  3038. if( status == PSA_SUCCESS )
  3039. {
  3040. memcpy( iv, local_iv, default_iv_length );
  3041. *iv_length = default_iv_length;
  3042. operation->iv_set = 1;
  3043. }
  3044. else
  3045. {
  3046. *iv_length = 0;
  3047. psa_cipher_abort( operation );
  3048. }
  3049. return( status );
  3050. }
  3051. psa_status_t psa_cipher_set_iv( psa_cipher_operation_t *operation,
  3052. const uint8_t *iv,
  3053. size_t iv_length )
  3054. {
  3055. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3056. if( operation->id == 0 )
  3057. {
  3058. status = PSA_ERROR_BAD_STATE;
  3059. goto exit;
  3060. }
  3061. if( operation->iv_set || ! operation->iv_required )
  3062. {
  3063. status = PSA_ERROR_BAD_STATE;
  3064. goto exit;
  3065. }
  3066. if( iv_length > PSA_CIPHER_IV_MAX_SIZE )
  3067. {
  3068. status = PSA_ERROR_INVALID_ARGUMENT;
  3069. goto exit;
  3070. }
  3071. status = psa_driver_wrapper_cipher_set_iv( operation,
  3072. iv,
  3073. iv_length );
  3074. exit:
  3075. if( status == PSA_SUCCESS )
  3076. operation->iv_set = 1;
  3077. else
  3078. psa_cipher_abort( operation );
  3079. return( status );
  3080. }
  3081. psa_status_t psa_cipher_update( psa_cipher_operation_t *operation,
  3082. const uint8_t *input,
  3083. size_t input_length,
  3084. uint8_t *output,
  3085. size_t output_size,
  3086. size_t *output_length )
  3087. {
  3088. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3089. if( operation->id == 0 )
  3090. {
  3091. status = PSA_ERROR_BAD_STATE;
  3092. goto exit;
  3093. }
  3094. if( operation->iv_required && ! operation->iv_set )
  3095. {
  3096. status = PSA_ERROR_BAD_STATE;
  3097. goto exit;
  3098. }
  3099. status = psa_driver_wrapper_cipher_update( operation,
  3100. input,
  3101. input_length,
  3102. output,
  3103. output_size,
  3104. output_length );
  3105. exit:
  3106. if( status != PSA_SUCCESS )
  3107. psa_cipher_abort( operation );
  3108. return( status );
  3109. }
  3110. psa_status_t psa_cipher_finish( psa_cipher_operation_t *operation,
  3111. uint8_t *output,
  3112. size_t output_size,
  3113. size_t *output_length )
  3114. {
  3115. psa_status_t status = PSA_ERROR_GENERIC_ERROR;
  3116. if( operation->id == 0 )
  3117. {
  3118. status = PSA_ERROR_BAD_STATE;
  3119. goto exit;
  3120. }
  3121. if( operation->iv_required && ! operation->iv_set )
  3122. {
  3123. status = PSA_ERROR_BAD_STATE;
  3124. goto exit;
  3125. }
  3126. status = psa_driver_wrapper_cipher_finish( operation,
  3127. output,
  3128. output_size,
  3129. output_length );
  3130. exit:
  3131. if( status == PSA_SUCCESS )
  3132. return( psa_cipher_abort( operation ) );
  3133. else
  3134. {
  3135. *output_length = 0;
  3136. (void) psa_cipher_abort( operation );
  3137. return( status );
  3138. }
  3139. }
  3140. psa_status_t psa_cipher_abort( psa_cipher_operation_t *operation )
  3141. {
  3142. if( operation->id == 0 )
  3143. {
  3144. /* The object has (apparently) been initialized but it is not (yet)
  3145. * in use. It's ok to call abort on such an object, and there's
  3146. * nothing to do. */
  3147. return( PSA_SUCCESS );
  3148. }
  3149. psa_driver_wrapper_cipher_abort( operation );
  3150. operation->id = 0;
  3151. operation->iv_set = 0;
  3152. operation->iv_required = 0;
  3153. return( PSA_SUCCESS );
  3154. }
  3155. psa_status_t psa_cipher_encrypt( mbedtls_svc_key_id_t key,
  3156. psa_algorithm_t alg,
  3157. const uint8_t *input,
  3158. size_t input_length,
  3159. uint8_t *output,
  3160. size_t output_size,
  3161. size_t *output_length )
  3162. {
  3163. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3164. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3165. psa_key_slot_t *slot = NULL;
  3166. uint8_t local_iv[PSA_CIPHER_IV_MAX_SIZE];
  3167. size_t default_iv_length = 0;
  3168. if( ! PSA_ALG_IS_CIPHER( alg ) )
  3169. {
  3170. status = PSA_ERROR_INVALID_ARGUMENT;
  3171. goto exit;
  3172. }
  3173. status = psa_get_and_lock_key_slot_with_policy( key, &slot,
  3174. PSA_KEY_USAGE_ENCRYPT,
  3175. alg );
  3176. if( status != PSA_SUCCESS )
  3177. goto exit;
  3178. psa_key_attributes_t attributes = {
  3179. .core = slot->attr
  3180. };
  3181. default_iv_length = PSA_CIPHER_IV_LENGTH( slot->attr.type, alg );
  3182. if( default_iv_length > PSA_CIPHER_IV_MAX_SIZE )
  3183. {
  3184. status = PSA_ERROR_GENERIC_ERROR;
  3185. goto exit;
  3186. }
  3187. if( default_iv_length > 0 )
  3188. {
  3189. if( output_size < default_iv_length )
  3190. {
  3191. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3192. goto exit;
  3193. }
  3194. status = psa_generate_random( local_iv, default_iv_length );
  3195. if( status != PSA_SUCCESS )
  3196. goto exit;
  3197. }
  3198. status = psa_driver_wrapper_cipher_encrypt(
  3199. &attributes, slot->key.data, slot->key.bytes,
  3200. alg, local_iv, default_iv_length, input, input_length,
  3201. output + default_iv_length, output_size - default_iv_length,
  3202. output_length );
  3203. exit:
  3204. unlock_status = psa_unlock_key_slot( slot );
  3205. if( status == PSA_SUCCESS )
  3206. status = unlock_status;
  3207. if( status == PSA_SUCCESS )
  3208. {
  3209. if( default_iv_length > 0 )
  3210. memcpy( output, local_iv, default_iv_length );
  3211. *output_length += default_iv_length;
  3212. }
  3213. else
  3214. *output_length = 0;
  3215. return( status );
  3216. }
  3217. psa_status_t psa_cipher_decrypt( mbedtls_svc_key_id_t key,
  3218. psa_algorithm_t alg,
  3219. const uint8_t *input,
  3220. size_t input_length,
  3221. uint8_t *output,
  3222. size_t output_size,
  3223. size_t *output_length )
  3224. {
  3225. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3226. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3227. psa_key_slot_t *slot = NULL;
  3228. if( ! PSA_ALG_IS_CIPHER( alg ) )
  3229. {
  3230. status = PSA_ERROR_INVALID_ARGUMENT;
  3231. goto exit;
  3232. }
  3233. status = psa_get_and_lock_key_slot_with_policy( key, &slot,
  3234. PSA_KEY_USAGE_DECRYPT,
  3235. alg );
  3236. if( status != PSA_SUCCESS )
  3237. goto exit;
  3238. psa_key_attributes_t attributes = {
  3239. .core = slot->attr
  3240. };
  3241. if( input_length < PSA_CIPHER_IV_LENGTH( slot->attr.type, alg ) )
  3242. {
  3243. status = PSA_ERROR_INVALID_ARGUMENT;
  3244. goto exit;
  3245. }
  3246. status = psa_driver_wrapper_cipher_decrypt(
  3247. &attributes, slot->key.data, slot->key.bytes,
  3248. alg, input, input_length,
  3249. output, output_size, output_length );
  3250. exit:
  3251. unlock_status = psa_unlock_key_slot( slot );
  3252. if( status == PSA_SUCCESS )
  3253. status = unlock_status;
  3254. if( status != PSA_SUCCESS )
  3255. *output_length = 0;
  3256. return( status );
  3257. }
  3258. /****************************************************************/
  3259. /* AEAD */
  3260. /****************************************************************/
  3261. psa_status_t psa_aead_encrypt( mbedtls_svc_key_id_t key,
  3262. psa_algorithm_t alg,
  3263. const uint8_t *nonce,
  3264. size_t nonce_length,
  3265. const uint8_t *additional_data,
  3266. size_t additional_data_length,
  3267. const uint8_t *plaintext,
  3268. size_t plaintext_length,
  3269. uint8_t *ciphertext,
  3270. size_t ciphertext_size,
  3271. size_t *ciphertext_length )
  3272. {
  3273. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3274. psa_key_slot_t *slot;
  3275. *ciphertext_length = 0;
  3276. if( !PSA_ALG_IS_AEAD( alg ) || PSA_ALG_IS_WILDCARD( alg ) )
  3277. return( PSA_ERROR_NOT_SUPPORTED );
  3278. status = psa_get_and_lock_key_slot_with_policy(
  3279. key, &slot, PSA_KEY_USAGE_ENCRYPT, alg );
  3280. if( status != PSA_SUCCESS )
  3281. return( status );
  3282. psa_key_attributes_t attributes = {
  3283. .core = slot->attr
  3284. };
  3285. status = psa_driver_wrapper_aead_encrypt(
  3286. &attributes, slot->key.data, slot->key.bytes,
  3287. alg,
  3288. nonce, nonce_length,
  3289. additional_data, additional_data_length,
  3290. plaintext, plaintext_length,
  3291. ciphertext, ciphertext_size, ciphertext_length );
  3292. if( status != PSA_SUCCESS && ciphertext_size != 0 )
  3293. memset( ciphertext, 0, ciphertext_size );
  3294. psa_unlock_key_slot( slot );
  3295. return( status );
  3296. }
  3297. psa_status_t psa_aead_decrypt( mbedtls_svc_key_id_t key,
  3298. psa_algorithm_t alg,
  3299. const uint8_t *nonce,
  3300. size_t nonce_length,
  3301. const uint8_t *additional_data,
  3302. size_t additional_data_length,
  3303. const uint8_t *ciphertext,
  3304. size_t ciphertext_length,
  3305. uint8_t *plaintext,
  3306. size_t plaintext_size,
  3307. size_t *plaintext_length )
  3308. {
  3309. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3310. psa_key_slot_t *slot;
  3311. *plaintext_length = 0;
  3312. if( !PSA_ALG_IS_AEAD( alg ) || PSA_ALG_IS_WILDCARD( alg ) )
  3313. return( PSA_ERROR_NOT_SUPPORTED );
  3314. status = psa_get_and_lock_key_slot_with_policy(
  3315. key, &slot, PSA_KEY_USAGE_DECRYPT, alg );
  3316. if( status != PSA_SUCCESS )
  3317. return( status );
  3318. psa_key_attributes_t attributes = {
  3319. .core = slot->attr
  3320. };
  3321. status = psa_driver_wrapper_aead_decrypt(
  3322. &attributes, slot->key.data, slot->key.bytes,
  3323. alg,
  3324. nonce, nonce_length,
  3325. additional_data, additional_data_length,
  3326. ciphertext, ciphertext_length,
  3327. plaintext, plaintext_size, plaintext_length );
  3328. if( status != PSA_SUCCESS && plaintext_size != 0 )
  3329. memset( plaintext, 0, plaintext_size );
  3330. psa_unlock_key_slot( slot );
  3331. return( status );
  3332. }
  3333. /****************************************************************/
  3334. /* Generators */
  3335. /****************************************************************/
  3336. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF) || \
  3337. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3338. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3339. #define AT_LEAST_ONE_BUILTIN_KDF
  3340. #endif /* At least one builtin KDF */
  3341. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF) || \
  3342. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3343. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3344. static psa_status_t psa_key_derivation_start_hmac(
  3345. psa_mac_operation_t *operation,
  3346. psa_algorithm_t hash_alg,
  3347. const uint8_t *hmac_key,
  3348. size_t hmac_key_length )
  3349. {
  3350. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3351. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  3352. psa_set_key_type( &attributes, PSA_KEY_TYPE_HMAC );
  3353. psa_set_key_bits( &attributes, PSA_BYTES_TO_BITS( hmac_key_length ) );
  3354. psa_set_key_usage_flags( &attributes, PSA_KEY_USAGE_SIGN_HASH );
  3355. operation->is_sign = 1;
  3356. operation->mac_size = PSA_HASH_LENGTH( hash_alg );
  3357. status = psa_driver_wrapper_mac_sign_setup( operation,
  3358. &attributes,
  3359. hmac_key, hmac_key_length,
  3360. PSA_ALG_HMAC( hash_alg ) );
  3361. psa_reset_key_attributes( &attributes );
  3362. return( status );
  3363. }
  3364. #endif /* KDF algorithms reliant on HMAC */
  3365. #define HKDF_STATE_INIT 0 /* no input yet */
  3366. #define HKDF_STATE_STARTED 1 /* got salt */
  3367. #define HKDF_STATE_KEYED 2 /* got key */
  3368. #define HKDF_STATE_OUTPUT 3 /* output started */
  3369. static psa_algorithm_t psa_key_derivation_get_kdf_alg(
  3370. const psa_key_derivation_operation_t *operation )
  3371. {
  3372. if ( PSA_ALG_IS_KEY_AGREEMENT( operation->alg ) )
  3373. return( PSA_ALG_KEY_AGREEMENT_GET_KDF( operation->alg ) );
  3374. else
  3375. return( operation->alg );
  3376. }
  3377. psa_status_t psa_key_derivation_abort( psa_key_derivation_operation_t *operation )
  3378. {
  3379. psa_status_t status = PSA_SUCCESS;
  3380. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg( operation );
  3381. if( kdf_alg == 0 )
  3382. {
  3383. /* The object has (apparently) been initialized but it is not
  3384. * in use. It's ok to call abort on such an object, and there's
  3385. * nothing to do. */
  3386. }
  3387. else
  3388. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3389. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  3390. {
  3391. mbedtls_free( operation->ctx.hkdf.info );
  3392. status = psa_mac_abort( &operation->ctx.hkdf.hmac );
  3393. }
  3394. else
  3395. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  3396. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3397. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3398. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) ||
  3399. /* TLS-1.2 PSK-to-MS KDF uses the same core as TLS-1.2 PRF */
  3400. PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  3401. {
  3402. if( operation->ctx.tls12_prf.secret != NULL )
  3403. {
  3404. mbedtls_platform_zeroize( operation->ctx.tls12_prf.secret,
  3405. operation->ctx.tls12_prf.secret_length );
  3406. mbedtls_free( operation->ctx.tls12_prf.secret );
  3407. }
  3408. if( operation->ctx.tls12_prf.seed != NULL )
  3409. {
  3410. mbedtls_platform_zeroize( operation->ctx.tls12_prf.seed,
  3411. operation->ctx.tls12_prf.seed_length );
  3412. mbedtls_free( operation->ctx.tls12_prf.seed );
  3413. }
  3414. if( operation->ctx.tls12_prf.label != NULL )
  3415. {
  3416. mbedtls_platform_zeroize( operation->ctx.tls12_prf.label,
  3417. operation->ctx.tls12_prf.label_length );
  3418. mbedtls_free( operation->ctx.tls12_prf.label );
  3419. }
  3420. status = PSA_SUCCESS;
  3421. /* We leave the fields Ai and output_block to be erased safely by the
  3422. * mbedtls_platform_zeroize() in the end of this function. */
  3423. }
  3424. else
  3425. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) ||
  3426. * defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS) */
  3427. {
  3428. status = PSA_ERROR_BAD_STATE;
  3429. }
  3430. mbedtls_platform_zeroize( operation, sizeof( *operation ) );
  3431. return( status );
  3432. }
  3433. psa_status_t psa_key_derivation_get_capacity(const psa_key_derivation_operation_t *operation,
  3434. size_t *capacity)
  3435. {
  3436. if( operation->alg == 0 )
  3437. {
  3438. /* This is a blank key derivation operation. */
  3439. return( PSA_ERROR_BAD_STATE );
  3440. }
  3441. *capacity = operation->capacity;
  3442. return( PSA_SUCCESS );
  3443. }
  3444. psa_status_t psa_key_derivation_set_capacity( psa_key_derivation_operation_t *operation,
  3445. size_t capacity )
  3446. {
  3447. if( operation->alg == 0 )
  3448. return( PSA_ERROR_BAD_STATE );
  3449. if( capacity > operation->capacity )
  3450. return( PSA_ERROR_INVALID_ARGUMENT );
  3451. operation->capacity = capacity;
  3452. return( PSA_SUCCESS );
  3453. }
  3454. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3455. /* Read some bytes from an HKDF-based operation. This performs a chunk
  3456. * of the expand phase of the HKDF algorithm. */
  3457. static psa_status_t psa_key_derivation_hkdf_read( psa_hkdf_key_derivation_t *hkdf,
  3458. psa_algorithm_t hash_alg,
  3459. uint8_t *output,
  3460. size_t output_length )
  3461. {
  3462. uint8_t hash_length = PSA_HASH_LENGTH( hash_alg );
  3463. size_t hmac_output_length;
  3464. psa_status_t status;
  3465. if( hkdf->state < HKDF_STATE_KEYED || ! hkdf->info_set )
  3466. return( PSA_ERROR_BAD_STATE );
  3467. hkdf->state = HKDF_STATE_OUTPUT;
  3468. while( output_length != 0 )
  3469. {
  3470. /* Copy what remains of the current block */
  3471. uint8_t n = hash_length - hkdf->offset_in_block;
  3472. if( n > output_length )
  3473. n = (uint8_t) output_length;
  3474. memcpy( output, hkdf->output_block + hkdf->offset_in_block, n );
  3475. output += n;
  3476. output_length -= n;
  3477. hkdf->offset_in_block += n;
  3478. if( output_length == 0 )
  3479. break;
  3480. /* We can't be wanting more output after block 0xff, otherwise
  3481. * the capacity check in psa_key_derivation_output_bytes() would have
  3482. * prevented this call. It could happen only if the operation
  3483. * object was corrupted or if this function is called directly
  3484. * inside the library. */
  3485. if( hkdf->block_number == 0xff )
  3486. return( PSA_ERROR_BAD_STATE );
  3487. /* We need a new block */
  3488. ++hkdf->block_number;
  3489. hkdf->offset_in_block = 0;
  3490. status = psa_key_derivation_start_hmac( &hkdf->hmac,
  3491. hash_alg,
  3492. hkdf->prk,
  3493. hash_length );
  3494. if( status != PSA_SUCCESS )
  3495. return( status );
  3496. if( hkdf->block_number != 1 )
  3497. {
  3498. status = psa_mac_update( &hkdf->hmac,
  3499. hkdf->output_block,
  3500. hash_length );
  3501. if( status != PSA_SUCCESS )
  3502. return( status );
  3503. }
  3504. status = psa_mac_update( &hkdf->hmac,
  3505. hkdf->info,
  3506. hkdf->info_length );
  3507. if( status != PSA_SUCCESS )
  3508. return( status );
  3509. status = psa_mac_update( &hkdf->hmac,
  3510. &hkdf->block_number, 1 );
  3511. if( status != PSA_SUCCESS )
  3512. return( status );
  3513. status = psa_mac_sign_finish( &hkdf->hmac,
  3514. hkdf->output_block,
  3515. sizeof( hkdf->output_block ),
  3516. &hmac_output_length );
  3517. if( status != PSA_SUCCESS )
  3518. return( status );
  3519. }
  3520. return( PSA_SUCCESS );
  3521. }
  3522. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  3523. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3524. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3525. static psa_status_t psa_key_derivation_tls12_prf_generate_next_block(
  3526. psa_tls12_prf_key_derivation_t *tls12_prf,
  3527. psa_algorithm_t alg )
  3528. {
  3529. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH( alg );
  3530. uint8_t hash_length = PSA_HASH_LENGTH( hash_alg );
  3531. psa_mac_operation_t hmac = PSA_MAC_OPERATION_INIT;
  3532. size_t hmac_output_length;
  3533. psa_status_t status, cleanup_status;
  3534. /* We can't be wanting more output after block 0xff, otherwise
  3535. * the capacity check in psa_key_derivation_output_bytes() would have
  3536. * prevented this call. It could happen only if the operation
  3537. * object was corrupted or if this function is called directly
  3538. * inside the library. */
  3539. if( tls12_prf->block_number == 0xff )
  3540. return( PSA_ERROR_CORRUPTION_DETECTED );
  3541. /* We need a new block */
  3542. ++tls12_prf->block_number;
  3543. tls12_prf->left_in_block = hash_length;
  3544. /* Recall the definition of the TLS-1.2-PRF from RFC 5246:
  3545. *
  3546. * PRF(secret, label, seed) = P_<hash>(secret, label + seed)
  3547. *
  3548. * P_hash(secret, seed) = HMAC_hash(secret, A(1) + seed) +
  3549. * HMAC_hash(secret, A(2) + seed) +
  3550. * HMAC_hash(secret, A(3) + seed) + ...
  3551. *
  3552. * A(0) = seed
  3553. * A(i) = HMAC_hash(secret, A(i-1))
  3554. *
  3555. * The `psa_tls12_prf_key_derivation` structure saves the block
  3556. * `HMAC_hash(secret, A(i) + seed)` from which the output
  3557. * is currently extracted as `output_block` and where i is
  3558. * `block_number`.
  3559. */
  3560. status = psa_key_derivation_start_hmac( &hmac,
  3561. hash_alg,
  3562. tls12_prf->secret,
  3563. tls12_prf->secret_length );
  3564. if( status != PSA_SUCCESS )
  3565. goto cleanup;
  3566. /* Calculate A(i) where i = tls12_prf->block_number. */
  3567. if( tls12_prf->block_number == 1 )
  3568. {
  3569. /* A(1) = HMAC_hash(secret, A(0)), where A(0) = seed. (The RFC overloads
  3570. * the variable seed and in this instance means it in the context of the
  3571. * P_hash function, where seed = label + seed.) */
  3572. status = psa_mac_update( &hmac,
  3573. tls12_prf->label,
  3574. tls12_prf->label_length );
  3575. if( status != PSA_SUCCESS )
  3576. goto cleanup;
  3577. status = psa_mac_update( &hmac,
  3578. tls12_prf->seed,
  3579. tls12_prf->seed_length );
  3580. if( status != PSA_SUCCESS )
  3581. goto cleanup;
  3582. }
  3583. else
  3584. {
  3585. /* A(i) = HMAC_hash(secret, A(i-1)) */
  3586. status = psa_mac_update( &hmac, tls12_prf->Ai, hash_length );
  3587. if( status != PSA_SUCCESS )
  3588. goto cleanup;
  3589. }
  3590. status = psa_mac_sign_finish( &hmac,
  3591. tls12_prf->Ai, hash_length,
  3592. &hmac_output_length );
  3593. if( hmac_output_length != hash_length )
  3594. status = PSA_ERROR_CORRUPTION_DETECTED;
  3595. if( status != PSA_SUCCESS )
  3596. goto cleanup;
  3597. /* Calculate HMAC_hash(secret, A(i) + label + seed). */
  3598. status = psa_key_derivation_start_hmac( &hmac,
  3599. hash_alg,
  3600. tls12_prf->secret,
  3601. tls12_prf->secret_length );
  3602. if( status != PSA_SUCCESS )
  3603. goto cleanup;
  3604. status = psa_mac_update( &hmac, tls12_prf->Ai, hash_length );
  3605. if( status != PSA_SUCCESS )
  3606. goto cleanup;
  3607. status = psa_mac_update( &hmac, tls12_prf->label, tls12_prf->label_length );
  3608. if( status != PSA_SUCCESS )
  3609. goto cleanup;
  3610. status = psa_mac_update( &hmac, tls12_prf->seed, tls12_prf->seed_length );
  3611. if( status != PSA_SUCCESS )
  3612. goto cleanup;
  3613. status = psa_mac_sign_finish( &hmac,
  3614. tls12_prf->output_block, hash_length,
  3615. &hmac_output_length );
  3616. if( status != PSA_SUCCESS )
  3617. goto cleanup;
  3618. cleanup:
  3619. cleanup_status = psa_mac_abort( &hmac );
  3620. if( status == PSA_SUCCESS && cleanup_status != PSA_SUCCESS )
  3621. status = cleanup_status;
  3622. return( status );
  3623. }
  3624. static psa_status_t psa_key_derivation_tls12_prf_read(
  3625. psa_tls12_prf_key_derivation_t *tls12_prf,
  3626. psa_algorithm_t alg,
  3627. uint8_t *output,
  3628. size_t output_length )
  3629. {
  3630. psa_algorithm_t hash_alg = PSA_ALG_TLS12_PRF_GET_HASH( alg );
  3631. uint8_t hash_length = PSA_HASH_LENGTH( hash_alg );
  3632. psa_status_t status;
  3633. uint8_t offset, length;
  3634. switch( tls12_prf->state )
  3635. {
  3636. case PSA_TLS12_PRF_STATE_LABEL_SET:
  3637. tls12_prf->state = PSA_TLS12_PRF_STATE_OUTPUT;
  3638. break;
  3639. case PSA_TLS12_PRF_STATE_OUTPUT:
  3640. break;
  3641. default:
  3642. return( PSA_ERROR_BAD_STATE );
  3643. }
  3644. while( output_length != 0 )
  3645. {
  3646. /* Check if we have fully processed the current block. */
  3647. if( tls12_prf->left_in_block == 0 )
  3648. {
  3649. status = psa_key_derivation_tls12_prf_generate_next_block( tls12_prf,
  3650. alg );
  3651. if( status != PSA_SUCCESS )
  3652. return( status );
  3653. continue;
  3654. }
  3655. if( tls12_prf->left_in_block > output_length )
  3656. length = (uint8_t) output_length;
  3657. else
  3658. length = tls12_prf->left_in_block;
  3659. offset = hash_length - tls12_prf->left_in_block;
  3660. memcpy( output, tls12_prf->output_block + offset, length );
  3661. output += length;
  3662. output_length -= length;
  3663. tls12_prf->left_in_block -= length;
  3664. }
  3665. return( PSA_SUCCESS );
  3666. }
  3667. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF ||
  3668. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  3669. psa_status_t psa_key_derivation_output_bytes(
  3670. psa_key_derivation_operation_t *operation,
  3671. uint8_t *output,
  3672. size_t output_length )
  3673. {
  3674. psa_status_t status;
  3675. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg( operation );
  3676. if( operation->alg == 0 )
  3677. {
  3678. /* This is a blank operation. */
  3679. return( PSA_ERROR_BAD_STATE );
  3680. }
  3681. if( output_length > operation->capacity )
  3682. {
  3683. operation->capacity = 0;
  3684. /* Go through the error path to wipe all confidential data now
  3685. * that the operation object is useless. */
  3686. status = PSA_ERROR_INSUFFICIENT_DATA;
  3687. goto exit;
  3688. }
  3689. if( output_length == 0 && operation->capacity == 0 )
  3690. {
  3691. /* Edge case: this is a finished operation, and 0 bytes
  3692. * were requested. The right error in this case could
  3693. * be either INSUFFICIENT_CAPACITY or BAD_STATE. Return
  3694. * INSUFFICIENT_CAPACITY, which is right for a finished
  3695. * operation, for consistency with the case when
  3696. * output_length > 0. */
  3697. return( PSA_ERROR_INSUFFICIENT_DATA );
  3698. }
  3699. operation->capacity -= output_length;
  3700. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3701. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  3702. {
  3703. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH( kdf_alg );
  3704. status = psa_key_derivation_hkdf_read( &operation->ctx.hkdf, hash_alg,
  3705. output, output_length );
  3706. }
  3707. else
  3708. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  3709. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3710. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3711. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) ||
  3712. PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  3713. {
  3714. status = psa_key_derivation_tls12_prf_read( &operation->ctx.tls12_prf,
  3715. kdf_alg, output,
  3716. output_length );
  3717. }
  3718. else
  3719. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF ||
  3720. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  3721. {
  3722. (void) kdf_alg;
  3723. return( PSA_ERROR_BAD_STATE );
  3724. }
  3725. exit:
  3726. if( status != PSA_SUCCESS )
  3727. {
  3728. /* Preserve the algorithm upon errors, but clear all sensitive state.
  3729. * This allows us to differentiate between exhausted operations and
  3730. * blank operations, so we can return PSA_ERROR_BAD_STATE on blank
  3731. * operations. */
  3732. psa_algorithm_t alg = operation->alg;
  3733. psa_key_derivation_abort( operation );
  3734. operation->alg = alg;
  3735. memset( output, '!', output_length );
  3736. }
  3737. return( status );
  3738. }
  3739. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  3740. static void psa_des_set_key_parity( uint8_t *data, size_t data_size )
  3741. {
  3742. if( data_size >= 8 )
  3743. mbedtls_des_key_set_parity( data );
  3744. if( data_size >= 16 )
  3745. mbedtls_des_key_set_parity( data + 8 );
  3746. if( data_size >= 24 )
  3747. mbedtls_des_key_set_parity( data + 16 );
  3748. }
  3749. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  3750. static psa_status_t psa_generate_derived_key_internal(
  3751. psa_key_slot_t *slot,
  3752. size_t bits,
  3753. psa_key_derivation_operation_t *operation )
  3754. {
  3755. uint8_t *data = NULL;
  3756. size_t bytes = PSA_BITS_TO_BYTES( bits );
  3757. psa_status_t status;
  3758. if( ! key_type_is_raw_bytes( slot->attr.type ) )
  3759. return( PSA_ERROR_INVALID_ARGUMENT );
  3760. if( bits % 8 != 0 )
  3761. return( PSA_ERROR_INVALID_ARGUMENT );
  3762. data = mbedtls_calloc( 1, bytes );
  3763. if( data == NULL )
  3764. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  3765. status = psa_key_derivation_output_bytes( operation, data, bytes );
  3766. if( status != PSA_SUCCESS )
  3767. goto exit;
  3768. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  3769. if( slot->attr.type == PSA_KEY_TYPE_DES )
  3770. psa_des_set_key_parity( data, bytes );
  3771. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  3772. status = psa_allocate_buffer_to_slot( slot, bytes );
  3773. if( status != PSA_SUCCESS )
  3774. goto exit;
  3775. slot->attr.bits = (psa_key_bits_t) bits;
  3776. psa_key_attributes_t attributes = {
  3777. .core = slot->attr
  3778. };
  3779. status = psa_driver_wrapper_import_key( &attributes,
  3780. data, bytes,
  3781. slot->key.data,
  3782. slot->key.bytes,
  3783. &slot->key.bytes, &bits );
  3784. if( bits != slot->attr.bits )
  3785. status = PSA_ERROR_INVALID_ARGUMENT;
  3786. exit:
  3787. mbedtls_free( data );
  3788. return( status );
  3789. }
  3790. psa_status_t psa_key_derivation_output_key( const psa_key_attributes_t *attributes,
  3791. psa_key_derivation_operation_t *operation,
  3792. mbedtls_svc_key_id_t *key )
  3793. {
  3794. psa_status_t status;
  3795. psa_key_slot_t *slot = NULL;
  3796. psa_se_drv_table_entry_t *driver = NULL;
  3797. *key = MBEDTLS_SVC_KEY_ID_INIT;
  3798. /* Reject any attempt to create a zero-length key so that we don't
  3799. * risk tripping up later, e.g. on a malloc(0) that returns NULL. */
  3800. if( psa_get_key_bits( attributes ) == 0 )
  3801. return( PSA_ERROR_INVALID_ARGUMENT );
  3802. if( operation->alg == PSA_ALG_NONE )
  3803. return( PSA_ERROR_BAD_STATE );
  3804. if( ! operation->can_output_key )
  3805. return( PSA_ERROR_NOT_PERMITTED );
  3806. status = psa_start_key_creation( PSA_KEY_CREATION_DERIVE, attributes,
  3807. &slot, &driver );
  3808. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  3809. if( driver != NULL )
  3810. {
  3811. /* Deriving a key in a secure element is not implemented yet. */
  3812. status = PSA_ERROR_NOT_SUPPORTED;
  3813. }
  3814. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  3815. if( status == PSA_SUCCESS )
  3816. {
  3817. status = psa_generate_derived_key_internal( slot,
  3818. attributes->core.bits,
  3819. operation );
  3820. }
  3821. if( status == PSA_SUCCESS )
  3822. status = psa_finish_key_creation( slot, driver, key );
  3823. if( status != PSA_SUCCESS )
  3824. psa_fail_key_creation( slot, driver );
  3825. return( status );
  3826. }
  3827. /****************************************************************/
  3828. /* Key derivation */
  3829. /****************************************************************/
  3830. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  3831. static int is_kdf_alg_supported( psa_algorithm_t kdf_alg )
  3832. {
  3833. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3834. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  3835. return( 1 );
  3836. #endif
  3837. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF)
  3838. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) )
  3839. return( 1 );
  3840. #endif
  3841. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3842. if( PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  3843. return( 1 );
  3844. #endif
  3845. return( 0 );
  3846. }
  3847. static psa_status_t psa_hash_try_support( psa_algorithm_t alg )
  3848. {
  3849. psa_hash_operation_t operation = PSA_HASH_OPERATION_INIT;
  3850. psa_status_t status = psa_hash_setup( &operation, alg );
  3851. psa_hash_abort( &operation );
  3852. return( status );
  3853. }
  3854. static psa_status_t psa_key_derivation_setup_kdf(
  3855. psa_key_derivation_operation_t *operation,
  3856. psa_algorithm_t kdf_alg )
  3857. {
  3858. /* Make sure that operation->ctx is properly zero-initialised. (Macro
  3859. * initialisers for this union leave some bytes unspecified.) */
  3860. memset( &operation->ctx, 0, sizeof( operation->ctx ) );
  3861. /* Make sure that kdf_alg is a supported key derivation algorithm. */
  3862. if( ! is_kdf_alg_supported( kdf_alg ) )
  3863. return( PSA_ERROR_NOT_SUPPORTED );
  3864. /* All currently supported key derivation algorithms are based on a
  3865. * hash algorithm. */
  3866. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH( kdf_alg );
  3867. size_t hash_size = PSA_HASH_LENGTH( hash_alg );
  3868. if( hash_size == 0 )
  3869. return( PSA_ERROR_NOT_SUPPORTED );
  3870. /* Make sure that hash_alg is a supported hash algorithm. Otherwise
  3871. * we might fail later, which is somewhat unfriendly and potentially
  3872. * risk-prone. */
  3873. psa_status_t status = psa_hash_try_support( hash_alg );
  3874. if( status != PSA_SUCCESS )
  3875. return( status );
  3876. if( ( PSA_ALG_IS_TLS12_PRF( kdf_alg ) ||
  3877. PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) ) &&
  3878. ! ( hash_alg == PSA_ALG_SHA_256 || hash_alg == PSA_ALG_SHA_384 ) )
  3879. {
  3880. return( PSA_ERROR_NOT_SUPPORTED );
  3881. }
  3882. operation->capacity = 255 * hash_size;
  3883. return( PSA_SUCCESS );
  3884. }
  3885. static psa_status_t psa_key_agreement_try_support( psa_algorithm_t alg )
  3886. {
  3887. #if defined(PSA_WANT_ALG_ECDH)
  3888. if( alg == PSA_ALG_ECDH )
  3889. return( PSA_SUCCESS );
  3890. #endif
  3891. (void) alg;
  3892. return( PSA_ERROR_NOT_SUPPORTED );
  3893. }
  3894. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  3895. psa_status_t psa_key_derivation_setup( psa_key_derivation_operation_t *operation,
  3896. psa_algorithm_t alg )
  3897. {
  3898. psa_status_t status;
  3899. if( operation->alg != 0 )
  3900. return( PSA_ERROR_BAD_STATE );
  3901. if( PSA_ALG_IS_RAW_KEY_AGREEMENT( alg ) )
  3902. return( PSA_ERROR_INVALID_ARGUMENT );
  3903. else if( PSA_ALG_IS_KEY_AGREEMENT( alg ) )
  3904. {
  3905. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  3906. psa_algorithm_t kdf_alg = PSA_ALG_KEY_AGREEMENT_GET_KDF( alg );
  3907. psa_algorithm_t ka_alg = PSA_ALG_KEY_AGREEMENT_GET_BASE( alg );
  3908. status = psa_key_agreement_try_support( ka_alg );
  3909. if( status != PSA_SUCCESS )
  3910. return( status );
  3911. status = psa_key_derivation_setup_kdf( operation, kdf_alg );
  3912. #else
  3913. return( PSA_ERROR_NOT_SUPPORTED );
  3914. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  3915. }
  3916. else if( PSA_ALG_IS_KEY_DERIVATION( alg ) )
  3917. {
  3918. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  3919. status = psa_key_derivation_setup_kdf( operation, alg );
  3920. #else
  3921. return( PSA_ERROR_NOT_SUPPORTED );
  3922. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  3923. }
  3924. else
  3925. return( PSA_ERROR_INVALID_ARGUMENT );
  3926. if( status == PSA_SUCCESS )
  3927. operation->alg = alg;
  3928. return( status );
  3929. }
  3930. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3931. static psa_status_t psa_hkdf_input( psa_hkdf_key_derivation_t *hkdf,
  3932. psa_algorithm_t hash_alg,
  3933. psa_key_derivation_step_t step,
  3934. const uint8_t *data,
  3935. size_t data_length )
  3936. {
  3937. psa_status_t status;
  3938. switch( step )
  3939. {
  3940. case PSA_KEY_DERIVATION_INPUT_SALT:
  3941. if( hkdf->state != HKDF_STATE_INIT )
  3942. return( PSA_ERROR_BAD_STATE );
  3943. else
  3944. {
  3945. status = psa_key_derivation_start_hmac( &hkdf->hmac,
  3946. hash_alg,
  3947. data, data_length );
  3948. if( status != PSA_SUCCESS )
  3949. return( status );
  3950. hkdf->state = HKDF_STATE_STARTED;
  3951. return( PSA_SUCCESS );
  3952. }
  3953. case PSA_KEY_DERIVATION_INPUT_SECRET:
  3954. /* If no salt was provided, use an empty salt. */
  3955. if( hkdf->state == HKDF_STATE_INIT )
  3956. {
  3957. status = psa_key_derivation_start_hmac( &hkdf->hmac,
  3958. hash_alg,
  3959. NULL, 0 );
  3960. if( status != PSA_SUCCESS )
  3961. return( status );
  3962. hkdf->state = HKDF_STATE_STARTED;
  3963. }
  3964. if( hkdf->state != HKDF_STATE_STARTED )
  3965. return( PSA_ERROR_BAD_STATE );
  3966. status = psa_mac_update( &hkdf->hmac,
  3967. data, data_length );
  3968. if( status != PSA_SUCCESS )
  3969. return( status );
  3970. status = psa_mac_sign_finish( &hkdf->hmac,
  3971. hkdf->prk,
  3972. sizeof( hkdf->prk ),
  3973. &data_length );
  3974. if( status != PSA_SUCCESS )
  3975. return( status );
  3976. hkdf->offset_in_block = PSA_HASH_LENGTH( hash_alg );
  3977. hkdf->block_number = 0;
  3978. hkdf->state = HKDF_STATE_KEYED;
  3979. return( PSA_SUCCESS );
  3980. case PSA_KEY_DERIVATION_INPUT_INFO:
  3981. if( hkdf->state == HKDF_STATE_OUTPUT )
  3982. return( PSA_ERROR_BAD_STATE );
  3983. if( hkdf->info_set )
  3984. return( PSA_ERROR_BAD_STATE );
  3985. hkdf->info_length = data_length;
  3986. if( data_length != 0 )
  3987. {
  3988. hkdf->info = mbedtls_calloc( 1, data_length );
  3989. if( hkdf->info == NULL )
  3990. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  3991. memcpy( hkdf->info, data, data_length );
  3992. }
  3993. hkdf->info_set = 1;
  3994. return( PSA_SUCCESS );
  3995. default:
  3996. return( PSA_ERROR_INVALID_ARGUMENT );
  3997. }
  3998. }
  3999. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  4000. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  4001. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4002. static psa_status_t psa_tls12_prf_set_seed( psa_tls12_prf_key_derivation_t *prf,
  4003. const uint8_t *data,
  4004. size_t data_length )
  4005. {
  4006. if( prf->state != PSA_TLS12_PRF_STATE_INIT )
  4007. return( PSA_ERROR_BAD_STATE );
  4008. if( data_length != 0 )
  4009. {
  4010. prf->seed = mbedtls_calloc( 1, data_length );
  4011. if( prf->seed == NULL )
  4012. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  4013. memcpy( prf->seed, data, data_length );
  4014. prf->seed_length = data_length;
  4015. }
  4016. prf->state = PSA_TLS12_PRF_STATE_SEED_SET;
  4017. return( PSA_SUCCESS );
  4018. }
  4019. static psa_status_t psa_tls12_prf_set_key( psa_tls12_prf_key_derivation_t *prf,
  4020. const uint8_t *data,
  4021. size_t data_length )
  4022. {
  4023. if( prf->state != PSA_TLS12_PRF_STATE_SEED_SET )
  4024. return( PSA_ERROR_BAD_STATE );
  4025. if( data_length != 0 )
  4026. {
  4027. prf->secret = mbedtls_calloc( 1, data_length );
  4028. if( prf->secret == NULL )
  4029. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  4030. memcpy( prf->secret, data, data_length );
  4031. prf->secret_length = data_length;
  4032. }
  4033. prf->state = PSA_TLS12_PRF_STATE_KEY_SET;
  4034. return( PSA_SUCCESS );
  4035. }
  4036. static psa_status_t psa_tls12_prf_set_label( psa_tls12_prf_key_derivation_t *prf,
  4037. const uint8_t *data,
  4038. size_t data_length )
  4039. {
  4040. if( prf->state != PSA_TLS12_PRF_STATE_KEY_SET )
  4041. return( PSA_ERROR_BAD_STATE );
  4042. if( data_length != 0 )
  4043. {
  4044. prf->label = mbedtls_calloc( 1, data_length );
  4045. if( prf->label == NULL )
  4046. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  4047. memcpy( prf->label, data, data_length );
  4048. prf->label_length = data_length;
  4049. }
  4050. prf->state = PSA_TLS12_PRF_STATE_LABEL_SET;
  4051. return( PSA_SUCCESS );
  4052. }
  4053. static psa_status_t psa_tls12_prf_input( psa_tls12_prf_key_derivation_t *prf,
  4054. psa_key_derivation_step_t step,
  4055. const uint8_t *data,
  4056. size_t data_length )
  4057. {
  4058. switch( step )
  4059. {
  4060. case PSA_KEY_DERIVATION_INPUT_SEED:
  4061. return( psa_tls12_prf_set_seed( prf, data, data_length ) );
  4062. case PSA_KEY_DERIVATION_INPUT_SECRET:
  4063. return( psa_tls12_prf_set_key( prf, data, data_length ) );
  4064. case PSA_KEY_DERIVATION_INPUT_LABEL:
  4065. return( psa_tls12_prf_set_label( prf, data, data_length ) );
  4066. default:
  4067. return( PSA_ERROR_INVALID_ARGUMENT );
  4068. }
  4069. }
  4070. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) ||
  4071. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4072. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4073. static psa_status_t psa_tls12_prf_psk_to_ms_set_key(
  4074. psa_tls12_prf_key_derivation_t *prf,
  4075. const uint8_t *data,
  4076. size_t data_length )
  4077. {
  4078. psa_status_t status;
  4079. uint8_t pms[ 4 + 2 * PSA_TLS12_PSK_TO_MS_PSK_MAX_SIZE ];
  4080. uint8_t *cur = pms;
  4081. if( data_length > PSA_TLS12_PSK_TO_MS_PSK_MAX_SIZE )
  4082. return( PSA_ERROR_INVALID_ARGUMENT );
  4083. /* Quoting RFC 4279, Section 2:
  4084. *
  4085. * The premaster secret is formed as follows: if the PSK is N octets
  4086. * long, concatenate a uint16 with the value N, N zero octets, a second
  4087. * uint16 with the value N, and the PSK itself.
  4088. */
  4089. *cur++ = MBEDTLS_BYTE_1( data_length );
  4090. *cur++ = MBEDTLS_BYTE_0( data_length );
  4091. memset( cur, 0, data_length );
  4092. cur += data_length;
  4093. *cur++ = pms[0];
  4094. *cur++ = pms[1];
  4095. memcpy( cur, data, data_length );
  4096. cur += data_length;
  4097. status = psa_tls12_prf_set_key( prf, pms, cur - pms );
  4098. mbedtls_platform_zeroize( pms, sizeof( pms ) );
  4099. return( status );
  4100. }
  4101. static psa_status_t psa_tls12_prf_psk_to_ms_input(
  4102. psa_tls12_prf_key_derivation_t *prf,
  4103. psa_key_derivation_step_t step,
  4104. const uint8_t *data,
  4105. size_t data_length )
  4106. {
  4107. if( step == PSA_KEY_DERIVATION_INPUT_SECRET )
  4108. {
  4109. return( psa_tls12_prf_psk_to_ms_set_key( prf,
  4110. data, data_length ) );
  4111. }
  4112. return( psa_tls12_prf_input( prf, step, data, data_length ) );
  4113. }
  4114. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4115. /** Check whether the given key type is acceptable for the given
  4116. * input step of a key derivation.
  4117. *
  4118. * Secret inputs must have the type #PSA_KEY_TYPE_DERIVE.
  4119. * Non-secret inputs must have the type #PSA_KEY_TYPE_RAW_DATA.
  4120. * Both secret and non-secret inputs can alternatively have the type
  4121. * #PSA_KEY_TYPE_NONE, which is never the type of a key object, meaning
  4122. * that the input was passed as a buffer rather than via a key object.
  4123. */
  4124. static int psa_key_derivation_check_input_type(
  4125. psa_key_derivation_step_t step,
  4126. psa_key_type_t key_type )
  4127. {
  4128. switch( step )
  4129. {
  4130. case PSA_KEY_DERIVATION_INPUT_SECRET:
  4131. if( key_type == PSA_KEY_TYPE_DERIVE )
  4132. return( PSA_SUCCESS );
  4133. if( key_type == PSA_KEY_TYPE_NONE )
  4134. return( PSA_SUCCESS );
  4135. break;
  4136. case PSA_KEY_DERIVATION_INPUT_LABEL:
  4137. case PSA_KEY_DERIVATION_INPUT_SALT:
  4138. case PSA_KEY_DERIVATION_INPUT_INFO:
  4139. case PSA_KEY_DERIVATION_INPUT_SEED:
  4140. if( key_type == PSA_KEY_TYPE_RAW_DATA )
  4141. return( PSA_SUCCESS );
  4142. if( key_type == PSA_KEY_TYPE_NONE )
  4143. return( PSA_SUCCESS );
  4144. break;
  4145. }
  4146. return( PSA_ERROR_INVALID_ARGUMENT );
  4147. }
  4148. static psa_status_t psa_key_derivation_input_internal(
  4149. psa_key_derivation_operation_t *operation,
  4150. psa_key_derivation_step_t step,
  4151. psa_key_type_t key_type,
  4152. const uint8_t *data,
  4153. size_t data_length )
  4154. {
  4155. psa_status_t status;
  4156. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg( operation );
  4157. status = psa_key_derivation_check_input_type( step, key_type );
  4158. if( status != PSA_SUCCESS )
  4159. goto exit;
  4160. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  4161. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  4162. {
  4163. status = psa_hkdf_input( &operation->ctx.hkdf,
  4164. PSA_ALG_HKDF_GET_HASH( kdf_alg ),
  4165. step, data, data_length );
  4166. }
  4167. else
  4168. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  4169. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF)
  4170. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) )
  4171. {
  4172. status = psa_tls12_prf_input( &operation->ctx.tls12_prf,
  4173. step, data, data_length );
  4174. }
  4175. else
  4176. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF */
  4177. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4178. if( PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  4179. {
  4180. status = psa_tls12_prf_psk_to_ms_input( &operation->ctx.tls12_prf,
  4181. step, data, data_length );
  4182. }
  4183. else
  4184. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4185. {
  4186. /* This can't happen unless the operation object was not initialized */
  4187. (void) data;
  4188. (void) data_length;
  4189. (void) kdf_alg;
  4190. return( PSA_ERROR_BAD_STATE );
  4191. }
  4192. exit:
  4193. if( status != PSA_SUCCESS )
  4194. psa_key_derivation_abort( operation );
  4195. return( status );
  4196. }
  4197. psa_status_t psa_key_derivation_input_bytes(
  4198. psa_key_derivation_operation_t *operation,
  4199. psa_key_derivation_step_t step,
  4200. const uint8_t *data,
  4201. size_t data_length )
  4202. {
  4203. return( psa_key_derivation_input_internal( operation, step,
  4204. PSA_KEY_TYPE_NONE,
  4205. data, data_length ) );
  4206. }
  4207. psa_status_t psa_key_derivation_input_key(
  4208. psa_key_derivation_operation_t *operation,
  4209. psa_key_derivation_step_t step,
  4210. mbedtls_svc_key_id_t key )
  4211. {
  4212. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4213. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  4214. psa_key_slot_t *slot;
  4215. status = psa_get_and_lock_transparent_key_slot_with_policy(
  4216. key, &slot, PSA_KEY_USAGE_DERIVE, operation->alg );
  4217. if( status != PSA_SUCCESS )
  4218. {
  4219. psa_key_derivation_abort( operation );
  4220. return( status );
  4221. }
  4222. /* Passing a key object as a SECRET input unlocks the permission
  4223. * to output to a key object. */
  4224. if( step == PSA_KEY_DERIVATION_INPUT_SECRET )
  4225. operation->can_output_key = 1;
  4226. status = psa_key_derivation_input_internal( operation,
  4227. step, slot->attr.type,
  4228. slot->key.data,
  4229. slot->key.bytes );
  4230. unlock_status = psa_unlock_key_slot( slot );
  4231. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  4232. }
  4233. /****************************************************************/
  4234. /* Key agreement */
  4235. /****************************************************************/
  4236. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  4237. static psa_status_t psa_key_agreement_ecdh( const uint8_t *peer_key,
  4238. size_t peer_key_length,
  4239. const mbedtls_ecp_keypair *our_key,
  4240. uint8_t *shared_secret,
  4241. size_t shared_secret_size,
  4242. size_t *shared_secret_length )
  4243. {
  4244. mbedtls_ecp_keypair *their_key = NULL;
  4245. mbedtls_ecdh_context ecdh;
  4246. psa_status_t status;
  4247. size_t bits = 0;
  4248. psa_ecc_family_t curve = mbedtls_ecc_group_to_psa( our_key->grp.id, &bits );
  4249. mbedtls_ecdh_init( &ecdh );
  4250. status = mbedtls_psa_ecp_load_representation(
  4251. PSA_KEY_TYPE_ECC_PUBLIC_KEY(curve),
  4252. bits,
  4253. peer_key,
  4254. peer_key_length,
  4255. &their_key );
  4256. if( status != PSA_SUCCESS )
  4257. goto exit;
  4258. status = mbedtls_to_psa_error(
  4259. mbedtls_ecdh_get_params( &ecdh, their_key, MBEDTLS_ECDH_THEIRS ) );
  4260. if( status != PSA_SUCCESS )
  4261. goto exit;
  4262. status = mbedtls_to_psa_error(
  4263. mbedtls_ecdh_get_params( &ecdh, our_key, MBEDTLS_ECDH_OURS ) );
  4264. if( status != PSA_SUCCESS )
  4265. goto exit;
  4266. status = mbedtls_to_psa_error(
  4267. mbedtls_ecdh_calc_secret( &ecdh,
  4268. shared_secret_length,
  4269. shared_secret, shared_secret_size,
  4270. mbedtls_psa_get_random,
  4271. MBEDTLS_PSA_RANDOM_STATE ) );
  4272. if( status != PSA_SUCCESS )
  4273. goto exit;
  4274. if( PSA_BITS_TO_BYTES( bits ) != *shared_secret_length )
  4275. status = PSA_ERROR_CORRUPTION_DETECTED;
  4276. exit:
  4277. if( status != PSA_SUCCESS )
  4278. mbedtls_platform_zeroize( shared_secret, shared_secret_size );
  4279. mbedtls_ecdh_free( &ecdh );
  4280. mbedtls_ecp_keypair_free( their_key );
  4281. mbedtls_free( their_key );
  4282. return( status );
  4283. }
  4284. #endif /* MBEDTLS_PSA_BUILTIN_ALG_ECDH */
  4285. #define PSA_KEY_AGREEMENT_MAX_SHARED_SECRET_SIZE MBEDTLS_ECP_MAX_BYTES
  4286. static psa_status_t psa_key_agreement_raw_internal( psa_algorithm_t alg,
  4287. psa_key_slot_t *private_key,
  4288. const uint8_t *peer_key,
  4289. size_t peer_key_length,
  4290. uint8_t *shared_secret,
  4291. size_t shared_secret_size,
  4292. size_t *shared_secret_length )
  4293. {
  4294. switch( alg )
  4295. {
  4296. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  4297. case PSA_ALG_ECDH:
  4298. if( ! PSA_KEY_TYPE_IS_ECC_KEY_PAIR( private_key->attr.type ) )
  4299. return( PSA_ERROR_INVALID_ARGUMENT );
  4300. mbedtls_ecp_keypair *ecp = NULL;
  4301. psa_status_t status = mbedtls_psa_ecp_load_representation(
  4302. private_key->attr.type,
  4303. private_key->attr.bits,
  4304. private_key->key.data,
  4305. private_key->key.bytes,
  4306. &ecp );
  4307. if( status != PSA_SUCCESS )
  4308. return( status );
  4309. status = psa_key_agreement_ecdh( peer_key, peer_key_length,
  4310. ecp,
  4311. shared_secret, shared_secret_size,
  4312. shared_secret_length );
  4313. mbedtls_ecp_keypair_free( ecp );
  4314. mbedtls_free( ecp );
  4315. return( status );
  4316. #endif /* MBEDTLS_PSA_BUILTIN_ALG_ECDH */
  4317. default:
  4318. (void) private_key;
  4319. (void) peer_key;
  4320. (void) peer_key_length;
  4321. (void) shared_secret;
  4322. (void) shared_secret_size;
  4323. (void) shared_secret_length;
  4324. return( PSA_ERROR_NOT_SUPPORTED );
  4325. }
  4326. }
  4327. /* Note that if this function fails, you must call psa_key_derivation_abort()
  4328. * to potentially free embedded data structures and wipe confidential data.
  4329. */
  4330. static psa_status_t psa_key_agreement_internal( psa_key_derivation_operation_t *operation,
  4331. psa_key_derivation_step_t step,
  4332. psa_key_slot_t *private_key,
  4333. const uint8_t *peer_key,
  4334. size_t peer_key_length )
  4335. {
  4336. psa_status_t status;
  4337. uint8_t shared_secret[PSA_KEY_AGREEMENT_MAX_SHARED_SECRET_SIZE];
  4338. size_t shared_secret_length = 0;
  4339. psa_algorithm_t ka_alg = PSA_ALG_KEY_AGREEMENT_GET_BASE( operation->alg );
  4340. /* Step 1: run the secret agreement algorithm to generate the shared
  4341. * secret. */
  4342. status = psa_key_agreement_raw_internal( ka_alg,
  4343. private_key,
  4344. peer_key, peer_key_length,
  4345. shared_secret,
  4346. sizeof( shared_secret ),
  4347. &shared_secret_length );
  4348. if( status != PSA_SUCCESS )
  4349. goto exit;
  4350. /* Step 2: set up the key derivation to generate key material from
  4351. * the shared secret. A shared secret is permitted wherever a key
  4352. * of type DERIVE is permitted. */
  4353. status = psa_key_derivation_input_internal( operation, step,
  4354. PSA_KEY_TYPE_DERIVE,
  4355. shared_secret,
  4356. shared_secret_length );
  4357. exit:
  4358. mbedtls_platform_zeroize( shared_secret, shared_secret_length );
  4359. return( status );
  4360. }
  4361. psa_status_t psa_key_derivation_key_agreement( psa_key_derivation_operation_t *operation,
  4362. psa_key_derivation_step_t step,
  4363. mbedtls_svc_key_id_t private_key,
  4364. const uint8_t *peer_key,
  4365. size_t peer_key_length )
  4366. {
  4367. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4368. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  4369. psa_key_slot_t *slot;
  4370. if( ! PSA_ALG_IS_KEY_AGREEMENT( operation->alg ) )
  4371. return( PSA_ERROR_INVALID_ARGUMENT );
  4372. status = psa_get_and_lock_transparent_key_slot_with_policy(
  4373. private_key, &slot, PSA_KEY_USAGE_DERIVE, operation->alg );
  4374. if( status != PSA_SUCCESS )
  4375. return( status );
  4376. status = psa_key_agreement_internal( operation, step,
  4377. slot,
  4378. peer_key, peer_key_length );
  4379. if( status != PSA_SUCCESS )
  4380. psa_key_derivation_abort( operation );
  4381. else
  4382. {
  4383. /* If a private key has been added as SECRET, we allow the derived
  4384. * key material to be used as a key in PSA Crypto. */
  4385. if( step == PSA_KEY_DERIVATION_INPUT_SECRET )
  4386. operation->can_output_key = 1;
  4387. }
  4388. unlock_status = psa_unlock_key_slot( slot );
  4389. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  4390. }
  4391. psa_status_t psa_raw_key_agreement( psa_algorithm_t alg,
  4392. mbedtls_svc_key_id_t private_key,
  4393. const uint8_t *peer_key,
  4394. size_t peer_key_length,
  4395. uint8_t *output,
  4396. size_t output_size,
  4397. size_t *output_length )
  4398. {
  4399. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4400. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  4401. psa_key_slot_t *slot = NULL;
  4402. if( ! PSA_ALG_IS_KEY_AGREEMENT( alg ) )
  4403. {
  4404. status = PSA_ERROR_INVALID_ARGUMENT;
  4405. goto exit;
  4406. }
  4407. status = psa_get_and_lock_transparent_key_slot_with_policy(
  4408. private_key, &slot, PSA_KEY_USAGE_DERIVE, alg );
  4409. if( status != PSA_SUCCESS )
  4410. goto exit;
  4411. /* PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE() is in general an upper bound
  4412. * for the output size. The PSA specification only guarantees that this
  4413. * function works if output_size >= PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE(...),
  4414. * but it might be nice to allow smaller buffers if the output fits.
  4415. * At the time of writing this comment, with only ECDH implemented,
  4416. * PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE() is exact so the point is moot.
  4417. * If FFDH is implemented, PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE() can easily
  4418. * be exact for it as well. */
  4419. size_t expected_length =
  4420. PSA_RAW_KEY_AGREEMENT_OUTPUT_SIZE( slot->attr.type, slot->attr.bits );
  4421. if( output_size < expected_length )
  4422. {
  4423. status = PSA_ERROR_BUFFER_TOO_SMALL;
  4424. goto exit;
  4425. }
  4426. status = psa_key_agreement_raw_internal( alg, slot,
  4427. peer_key, peer_key_length,
  4428. output, output_size,
  4429. output_length );
  4430. exit:
  4431. if( status != PSA_SUCCESS )
  4432. {
  4433. /* If an error happens and is not handled properly, the output
  4434. * may be used as a key to protect sensitive data. Arrange for such
  4435. * a key to be random, which is likely to result in decryption or
  4436. * verification errors. This is better than filling the buffer with
  4437. * some constant data such as zeros, which would result in the data
  4438. * being protected with a reproducible, easily knowable key.
  4439. */
  4440. psa_generate_random( output, output_size );
  4441. *output_length = output_size;
  4442. }
  4443. unlock_status = psa_unlock_key_slot( slot );
  4444. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  4445. }
  4446. /****************************************************************/
  4447. /* Random generation */
  4448. /****************************************************************/
  4449. /** Initialize the PSA random generator.
  4450. */
  4451. static void mbedtls_psa_random_init( mbedtls_psa_random_context_t *rng )
  4452. {
  4453. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4454. memset( rng, 0, sizeof( *rng ) );
  4455. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4456. /* Set default configuration if
  4457. * mbedtls_psa_crypto_configure_entropy_sources() hasn't been called. */
  4458. if( rng->entropy_init == NULL )
  4459. rng->entropy_init = mbedtls_entropy_init;
  4460. if( rng->entropy_free == NULL )
  4461. rng->entropy_free = mbedtls_entropy_free;
  4462. rng->entropy_init( &rng->entropy );
  4463. #if defined(MBEDTLS_PSA_INJECT_ENTROPY) && \
  4464. defined(MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES)
  4465. /* The PSA entropy injection feature depends on using NV seed as an entropy
  4466. * source. Add NV seed as an entropy source for PSA entropy injection. */
  4467. mbedtls_entropy_add_source( &rng->entropy,
  4468. mbedtls_nv_seed_poll, NULL,
  4469. MBEDTLS_ENTROPY_BLOCK_SIZE,
  4470. MBEDTLS_ENTROPY_SOURCE_STRONG );
  4471. #endif
  4472. mbedtls_psa_drbg_init( MBEDTLS_PSA_RANDOM_STATE );
  4473. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4474. }
  4475. /** Deinitialize the PSA random generator.
  4476. */
  4477. static void mbedtls_psa_random_free( mbedtls_psa_random_context_t *rng )
  4478. {
  4479. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4480. memset( rng, 0, sizeof( *rng ) );
  4481. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4482. mbedtls_psa_drbg_free( MBEDTLS_PSA_RANDOM_STATE );
  4483. rng->entropy_free( &rng->entropy );
  4484. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4485. }
  4486. /** Seed the PSA random generator.
  4487. */
  4488. static psa_status_t mbedtls_psa_random_seed( mbedtls_psa_random_context_t *rng )
  4489. {
  4490. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4491. /* Do nothing: the external RNG seeds itself. */
  4492. (void) rng;
  4493. return( PSA_SUCCESS );
  4494. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4495. const unsigned char drbg_seed[] = "PSA";
  4496. int ret = mbedtls_psa_drbg_seed( &rng->entropy,
  4497. drbg_seed, sizeof( drbg_seed ) - 1 );
  4498. return mbedtls_to_psa_error( ret );
  4499. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4500. }
  4501. psa_status_t psa_generate_random( uint8_t *output,
  4502. size_t output_size )
  4503. {
  4504. GUARD_MODULE_INITIALIZED;
  4505. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4506. size_t output_length = 0;
  4507. psa_status_t status = mbedtls_psa_external_get_random( &global_data.rng,
  4508. output, output_size,
  4509. &output_length );
  4510. if( status != PSA_SUCCESS )
  4511. return( status );
  4512. /* Breaking up a request into smaller chunks is currently not supported
  4513. * for the extrernal RNG interface. */
  4514. if( output_length != output_size )
  4515. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  4516. return( PSA_SUCCESS );
  4517. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4518. while( output_size > 0 )
  4519. {
  4520. size_t request_size =
  4521. ( output_size > MBEDTLS_PSA_RANDOM_MAX_REQUEST ?
  4522. MBEDTLS_PSA_RANDOM_MAX_REQUEST :
  4523. output_size );
  4524. int ret = mbedtls_psa_get_random( MBEDTLS_PSA_RANDOM_STATE,
  4525. output, request_size );
  4526. if( ret != 0 )
  4527. return( mbedtls_to_psa_error( ret ) );
  4528. output_size -= request_size;
  4529. output += request_size;
  4530. }
  4531. return( PSA_SUCCESS );
  4532. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4533. }
  4534. /* Wrapper function allowing the classic API to use the PSA RNG.
  4535. *
  4536. * `mbedtls_psa_get_random(MBEDTLS_PSA_RANDOM_STATE, ...)` calls
  4537. * `psa_generate_random(...)`. The state parameter is ignored since the
  4538. * PSA API doesn't support passing an explicit state.
  4539. *
  4540. * In the non-external case, psa_generate_random() calls an
  4541. * `mbedtls_xxx_drbg_random` function which has exactly the same signature
  4542. * and semantics as mbedtls_psa_get_random(). As an optimization,
  4543. * instead of doing this back-and-forth between the PSA API and the
  4544. * classic API, psa_crypto_random_impl.h defines `mbedtls_psa_get_random`
  4545. * as a constant function pointer to `mbedtls_xxx_drbg_random`.
  4546. */
  4547. #if defined (MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4548. int mbedtls_psa_get_random( void *p_rng,
  4549. unsigned char *output,
  4550. size_t output_size )
  4551. {
  4552. /* This function takes a pointer to the RNG state because that's what
  4553. * classic mbedtls functions using an RNG expect. The PSA RNG manages
  4554. * its own state internally and doesn't let the caller access that state.
  4555. * So we just ignore the state parameter, and in practice we'll pass
  4556. * NULL. */
  4557. (void) p_rng;
  4558. psa_status_t status = psa_generate_random( output, output_size );
  4559. if( status == PSA_SUCCESS )
  4560. return( 0 );
  4561. else
  4562. return( MBEDTLS_ERR_ENTROPY_SOURCE_FAILED );
  4563. }
  4564. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4565. #if defined(MBEDTLS_PSA_INJECT_ENTROPY)
  4566. #include "mbedtls/entropy_poll.h"
  4567. psa_status_t mbedtls_psa_inject_entropy( const uint8_t *seed,
  4568. size_t seed_size )
  4569. {
  4570. if( global_data.initialized )
  4571. return( PSA_ERROR_NOT_PERMITTED );
  4572. if( ( ( seed_size < MBEDTLS_ENTROPY_MIN_PLATFORM ) ||
  4573. ( seed_size < MBEDTLS_ENTROPY_BLOCK_SIZE ) ) ||
  4574. ( seed_size > MBEDTLS_ENTROPY_MAX_SEED_SIZE ) )
  4575. return( PSA_ERROR_INVALID_ARGUMENT );
  4576. return( mbedtls_psa_storage_inject_entropy( seed, seed_size ) );
  4577. }
  4578. #endif /* MBEDTLS_PSA_INJECT_ENTROPY */
  4579. /** Validate the key type and size for key generation
  4580. *
  4581. * \param type The key type
  4582. * \param bits The number of bits of the key
  4583. *
  4584. * \retval #PSA_SUCCESS
  4585. * The key type and size are valid.
  4586. * \retval #PSA_ERROR_INVALID_ARGUMENT
  4587. * The size in bits of the key is not valid.
  4588. * \retval #PSA_ERROR_NOT_SUPPORTED
  4589. * The type and/or the size in bits of the key or the combination of
  4590. * the two is not supported.
  4591. */
  4592. static psa_status_t psa_validate_key_type_and_size_for_key_generation(
  4593. psa_key_type_t type, size_t bits )
  4594. {
  4595. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4596. if( key_type_is_raw_bytes( type ) )
  4597. {
  4598. status = validate_unstructured_key_bit_size( type, bits );
  4599. if( status != PSA_SUCCESS )
  4600. return( status );
  4601. }
  4602. else
  4603. #if defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR)
  4604. if( PSA_KEY_TYPE_IS_RSA( type ) && PSA_KEY_TYPE_IS_KEY_PAIR( type ) )
  4605. {
  4606. if( bits > PSA_VENDOR_RSA_MAX_KEY_BITS )
  4607. return( PSA_ERROR_NOT_SUPPORTED );
  4608. /* Accept only byte-aligned keys, for the same reasons as
  4609. * in psa_import_rsa_key(). */
  4610. if( bits % 8 != 0 )
  4611. return( PSA_ERROR_NOT_SUPPORTED );
  4612. }
  4613. else
  4614. #endif /* defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR) */
  4615. #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR)
  4616. if( PSA_KEY_TYPE_IS_ECC( type ) && PSA_KEY_TYPE_IS_KEY_PAIR( type ) )
  4617. {
  4618. /* To avoid empty block, return successfully here. */
  4619. return( PSA_SUCCESS );
  4620. }
  4621. else
  4622. #endif /* defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR) */
  4623. {
  4624. return( PSA_ERROR_NOT_SUPPORTED );
  4625. }
  4626. return( PSA_SUCCESS );
  4627. }
  4628. psa_status_t psa_generate_key_internal(
  4629. const psa_key_attributes_t *attributes,
  4630. uint8_t *key_buffer, size_t key_buffer_size, size_t *key_buffer_length )
  4631. {
  4632. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4633. psa_key_type_t type = attributes->core.type;
  4634. if( ( attributes->domain_parameters == NULL ) &&
  4635. ( attributes->domain_parameters_size != 0 ) )
  4636. return( PSA_ERROR_INVALID_ARGUMENT );
  4637. if( key_type_is_raw_bytes( type ) )
  4638. {
  4639. status = psa_generate_random( key_buffer, key_buffer_size );
  4640. if( status != PSA_SUCCESS )
  4641. return( status );
  4642. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  4643. if( type == PSA_KEY_TYPE_DES )
  4644. psa_des_set_key_parity( key_buffer, key_buffer_size );
  4645. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  4646. }
  4647. else
  4648. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) && \
  4649. defined(MBEDTLS_GENPRIME)
  4650. if ( type == PSA_KEY_TYPE_RSA_KEY_PAIR )
  4651. {
  4652. return( mbedtls_psa_rsa_generate_key( attributes,
  4653. key_buffer,
  4654. key_buffer_size,
  4655. key_buffer_length ) );
  4656. }
  4657. else
  4658. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR)
  4659. * defined(MBEDTLS_GENPRIME) */
  4660. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR)
  4661. if ( PSA_KEY_TYPE_IS_ECC( type ) && PSA_KEY_TYPE_IS_KEY_PAIR( type ) )
  4662. {
  4663. return( mbedtls_psa_ecp_generate_key( attributes,
  4664. key_buffer,
  4665. key_buffer_size,
  4666. key_buffer_length ) );
  4667. }
  4668. else
  4669. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) */
  4670. {
  4671. (void)key_buffer_length;
  4672. return( PSA_ERROR_NOT_SUPPORTED );
  4673. }
  4674. return( PSA_SUCCESS );
  4675. }
  4676. psa_status_t psa_generate_key( const psa_key_attributes_t *attributes,
  4677. mbedtls_svc_key_id_t *key )
  4678. {
  4679. psa_status_t status;
  4680. psa_key_slot_t *slot = NULL;
  4681. psa_se_drv_table_entry_t *driver = NULL;
  4682. size_t key_buffer_size;
  4683. *key = MBEDTLS_SVC_KEY_ID_INIT;
  4684. /* Reject any attempt to create a zero-length key so that we don't
  4685. * risk tripping up later, e.g. on a malloc(0) that returns NULL. */
  4686. if( psa_get_key_bits( attributes ) == 0 )
  4687. return( PSA_ERROR_INVALID_ARGUMENT );
  4688. /* Reject any attempt to create a public key. */
  4689. if( PSA_KEY_TYPE_IS_PUBLIC_KEY(attributes->core.type) )
  4690. return( PSA_ERROR_INVALID_ARGUMENT );
  4691. status = psa_start_key_creation( PSA_KEY_CREATION_GENERATE, attributes,
  4692. &slot, &driver );
  4693. if( status != PSA_SUCCESS )
  4694. goto exit;
  4695. /* In the case of a transparent key or an opaque key stored in local
  4696. * storage (thus not in the case of generating a key in a secure element
  4697. * or cryptoprocessor with storage), we have to allocate a buffer to
  4698. * hold the generated key material. */
  4699. if( slot->key.data == NULL )
  4700. {
  4701. if ( PSA_KEY_LIFETIME_GET_LOCATION( attributes->core.lifetime ) ==
  4702. PSA_KEY_LOCATION_LOCAL_STORAGE )
  4703. {
  4704. status = psa_validate_key_type_and_size_for_key_generation(
  4705. attributes->core.type, attributes->core.bits );
  4706. if( status != PSA_SUCCESS )
  4707. goto exit;
  4708. key_buffer_size = PSA_EXPORT_KEY_OUTPUT_SIZE(
  4709. attributes->core.type,
  4710. attributes->core.bits );
  4711. }
  4712. else
  4713. {
  4714. status = psa_driver_wrapper_get_key_buffer_size(
  4715. attributes, &key_buffer_size );
  4716. if( status != PSA_SUCCESS )
  4717. goto exit;
  4718. }
  4719. status = psa_allocate_buffer_to_slot( slot, key_buffer_size );
  4720. if( status != PSA_SUCCESS )
  4721. goto exit;
  4722. }
  4723. status = psa_driver_wrapper_generate_key( attributes,
  4724. slot->key.data, slot->key.bytes, &slot->key.bytes );
  4725. if( status != PSA_SUCCESS )
  4726. psa_remove_key_data_from_memory( slot );
  4727. exit:
  4728. if( status == PSA_SUCCESS )
  4729. status = psa_finish_key_creation( slot, driver, key );
  4730. if( status != PSA_SUCCESS )
  4731. psa_fail_key_creation( slot, driver );
  4732. return( status );
  4733. }
  4734. /****************************************************************/
  4735. /* Module setup */
  4736. /****************************************************************/
  4737. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4738. psa_status_t mbedtls_psa_crypto_configure_entropy_sources(
  4739. void (* entropy_init )( mbedtls_entropy_context *ctx ),
  4740. void (* entropy_free )( mbedtls_entropy_context *ctx ) )
  4741. {
  4742. if( global_data.rng_state != RNG_NOT_INITIALIZED )
  4743. return( PSA_ERROR_BAD_STATE );
  4744. global_data.rng.entropy_init = entropy_init;
  4745. global_data.rng.entropy_free = entropy_free;
  4746. return( PSA_SUCCESS );
  4747. }
  4748. #endif /* !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) */
  4749. void mbedtls_psa_crypto_free( void )
  4750. {
  4751. psa_wipe_all_key_slots( );
  4752. if( global_data.rng_state != RNG_NOT_INITIALIZED )
  4753. {
  4754. mbedtls_psa_random_free( &global_data.rng );
  4755. }
  4756. /* Wipe all remaining data, including configuration.
  4757. * In particular, this sets all state indicator to the value
  4758. * indicating "uninitialized". */
  4759. mbedtls_platform_zeroize( &global_data, sizeof( global_data ) );
  4760. /* Terminate drivers */
  4761. psa_driver_wrapper_free( );
  4762. }
  4763. #if defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS)
  4764. /** Recover a transaction that was interrupted by a power failure.
  4765. *
  4766. * This function is called during initialization, before psa_crypto_init()
  4767. * returns. If this function returns a failure status, the initialization
  4768. * fails.
  4769. */
  4770. static psa_status_t psa_crypto_recover_transaction(
  4771. const psa_crypto_transaction_t *transaction )
  4772. {
  4773. switch( transaction->unknown.type )
  4774. {
  4775. case PSA_CRYPTO_TRANSACTION_CREATE_KEY:
  4776. case PSA_CRYPTO_TRANSACTION_DESTROY_KEY:
  4777. /* TODO - fall through to the failure case until this
  4778. * is implemented.
  4779. * https://github.com/ARMmbed/mbed-crypto/issues/218
  4780. */
  4781. default:
  4782. /* We found an unsupported transaction in the storage.
  4783. * We don't know what state the storage is in. Give up. */
  4784. return( PSA_ERROR_DATA_INVALID );
  4785. }
  4786. }
  4787. #endif /* PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS */
  4788. psa_status_t psa_crypto_init( void )
  4789. {
  4790. psa_status_t status;
  4791. /* Double initialization is explicitly allowed. */
  4792. if( global_data.initialized != 0 )
  4793. return( PSA_SUCCESS );
  4794. /* Initialize and seed the random generator. */
  4795. mbedtls_psa_random_init( &global_data.rng );
  4796. global_data.rng_state = RNG_INITIALIZED;
  4797. status = mbedtls_psa_random_seed( &global_data.rng );
  4798. if( status != PSA_SUCCESS )
  4799. goto exit;
  4800. global_data.rng_state = RNG_SEEDED;
  4801. status = psa_initialize_key_slots( );
  4802. if( status != PSA_SUCCESS )
  4803. goto exit;
  4804. /* Init drivers */
  4805. status = psa_driver_wrapper_init( );
  4806. if( status != PSA_SUCCESS )
  4807. goto exit;
  4808. #if defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS)
  4809. status = psa_crypto_load_transaction( );
  4810. if( status == PSA_SUCCESS )
  4811. {
  4812. status = psa_crypto_recover_transaction( &psa_crypto_transaction );
  4813. if( status != PSA_SUCCESS )
  4814. goto exit;
  4815. status = psa_crypto_stop_transaction( );
  4816. }
  4817. else if( status == PSA_ERROR_DOES_NOT_EXIST )
  4818. {
  4819. /* There's no transaction to complete. It's all good. */
  4820. status = PSA_SUCCESS;
  4821. }
  4822. #endif /* PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS */
  4823. /* All done. */
  4824. global_data.initialized = 1;
  4825. exit:
  4826. if( status != PSA_SUCCESS )
  4827. mbedtls_psa_crypto_free( );
  4828. return( status );
  4829. }
  4830. #endif /* MBEDTLS_PSA_CRYPTO_C */