x509_sign_verify.c
Go to the documentation of this file.
1 /**
2  * @file x509_sign_verify.c
3  * @brief RSA/DSA/ECDSA/EdDSA signature verification
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2026 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneCRYPTO Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.6.6
29  **/
30 
31 //Switch to the appropriate trace level
32 #define TRACE_LEVEL CRYPTO_TRACE_LEVEL
33 
34 //Dependencies
35 #include "core/crypto.h"
36 #include "pkix/x509_key_parse.h"
37 #include "pkix/x509_sign_verify.h"
38 #include "encoding/oid.h"
39 #include "debug.h"
40 
41 //Check crypto library configuration
42 #if (X509_SUPPORT == ENABLED)
43 
44 //Signature generation/verification callback functions
45 #if (X509_SIGN_CALLBACK_SUPPORT == ENABLED)
46  static X509SignVerifyCallback x509SignVerifyCallback = NULL;
47 #endif
48 
49 
50 /**
51  * @brief Register signature verification callback function
52  * @param[in] callback Signature verification callback function
53  * @return Error code
54  **/
55 
57 {
58 #if (X509_SIGN_CALLBACK_SUPPORT == ENABLED)
59  //Save callback function
60  x509SignVerifyCallback = callback;
61  //Successful processing
62  return NO_ERROR;
63 #else
64  //Not implemented
65  return ERROR_NOT_IMPLEMENTED;
66 #endif
67 }
68 
69 
70 /**
71  * @brief Signature verification
72  * @param[in] tbsData Data whose signature is to be verified
73  * @param[in] signAlgoId Signature algorithm identifier
74  * @param[in] publicKeyInfo Issuer's public key
75  * @param[in] signature Signature to be verified
76  * @return Error code
77  **/
78 
80  const X509SignAlgoId *signAlgoId,
81  const X509SubjectPublicKeyInfo *publicKeyInfo,
82  const X509OctetString *signature)
83 {
84  error_t error;
85  X509SignatureAlgo signAlgo;
86  const HashAlgo *hashAlgo;
87 
88 #if (X509_SIGN_CALLBACK_SUPPORT == ENABLED)
89  //Valid signature verification callback function?
90  if(x509SignVerifyCallback != NULL)
91  {
92  //Invoke user-defined callback
93  error = x509SignVerifyCallback(tbsData, signAlgoId, publicKeyInfo,
94  signature);
95  }
96  else
97 #endif
98  {
99  //No callback function registered
101  }
102 
103  //Check status code
105  {
106  //Retrieve the signature algorithm that was used to sign the certificate
107  error = x509GetSignHashAlgo(signAlgoId, &signAlgo, &hashAlgo);
108 
109  //Check status code
110  if(!error)
111  {
112 #if (X509_RSA_SUPPORT == ENABLED && RSA_SUPPORT == ENABLED)
113  //RSA signature algorithm?
114  if(signAlgo == X509_SIGN_ALGO_RSA)
115  {
116  //Verify RSA signature (RSASSA-PKCS1-v1_5 signature scheme)
117  error = x509VerifyRsaSignature(tbsData, hashAlgo, publicKeyInfo,
118  signature);
119  }
120  else
121 #endif
122 #if (X509_RSA_PSS_SUPPORT == ENABLED && RSA_SUPPORT == ENABLED)
123  //RSA-PSS signature algorithm?
124  if(signAlgo == X509_SIGN_ALGO_RSA_PSS)
125  {
126  size_t oidLen;
127  const uint8_t *oid;
128  const HashAlgo *mgfHashAlgo;
129 
130  //Get the OID of the signature algorithm
131  oid = signAlgoId->oid.value;
132  oidLen = signAlgoId->oid.length;
133 
134  //Check signature algorithm
136  {
137  //The saltLength must be 32 bytes for id-RSASSA-PSS-SHAKE128
138  //(refer to RFC 8692, section 4.1.1)
139  error = x509VerifyRsaPssSignature(tbsData, hashAlgo, hashAlgo,
140  32, publicKeyInfo, signature);
141  }
142  else if(OID_COMP(oid, oidLen, RSASSA_PSS_SHAKE256_OID) == 0)
143  {
144  //The saltLength must be 64 bytes for id-RSASSA-PSS-SHAKE256
145  //(refer to RFC 8692, section 4.1.1)
146  error = x509VerifyRsaPssSignature(tbsData, hashAlgo, hashAlgo,
147  64, publicKeyInfo, signature);
148  }
149  else
150  {
151  //Get the OID of the MGF algorithm
152  oid = signAlgoId->rsaPssParams.maskGenAlgo.value;
153  oidLen = signAlgoId->rsaPssParams.maskGenAlgo.length;
154 
155  //MGF1 mask generation function?
156  if(OID_COMP(oid, oidLen, MGF1_OID) == 0)
157  {
158  //Get the OID of the MGF hash algorithm
159  oid = signAlgoId->rsaPssParams.maskGenHashAlgo.value;
161 
162  //Select the MGF hash algorithm
163  mgfHashAlgo = x509GetHashAlgo(oid, oidLen);
164 
165  //Valid MGF hash algorithm?
166  if(mgfHashAlgo != NULL)
167  {
168  //The saltLength field of the RSASSA-PSS-params is the
169  //octet length of the salt
170  error = x509VerifyRsaPssSignature(tbsData, hashAlgo,
171  mgfHashAlgo, signAlgoId->rsaPssParams.saltLen,
172  publicKeyInfo, signature);
173  }
174  else
175  {
176  //The MGF hash algorithm is not supported
178  }
179  }
180  else
181  {
182  //The MGF algorithm is not supported
184  }
185  }
186  }
187  else
188 #endif
189 #if (X509_DSA_SUPPORT == ENABLED && DSA_SUPPORT == ENABLED)
190  //DSA signature algorithm?
191  if(signAlgo == X509_SIGN_ALGO_DSA)
192  {
193  //Verify DSA signature
194  error = x509VerifyDsaSignature(tbsData, hashAlgo, publicKeyInfo,
195  signature);
196  }
197  else
198 #endif
199 #if (X509_ECDSA_SUPPORT == ENABLED && ECDSA_SUPPORT == ENABLED)
200  //ECDSA signature algorithm?
201  if(signAlgo == X509_SIGN_ALGO_ECDSA)
202  {
203  //Verify ECDSA signature
204  error = x509VerifyEcdsaSignature(tbsData, hashAlgo, publicKeyInfo,
205  signature);
206  }
207  else
208 #endif
209 #if (X509_SM2_SUPPORT == ENABLED && SM2_SUPPORT == ENABLED)
210  //SM2 signature algorithm?
211  if(signAlgo == X509_SIGN_ALGO_SM2)
212  {
213  //Verify SM2 signature
214  error = x509VerifySm2Signature(tbsData, hashAlgo, publicKeyInfo,
215  signature);
216  }
217  else
218 #endif
219 #if (X509_ED25519_SUPPORT == ENABLED && ED25519_SUPPORT == ENABLED)
220  //Ed25519 signature algorithm?
221  if(signAlgo == X509_SIGN_ALGO_ED25519)
222  {
223  //Verify Ed25519 signature (PureEdDSA mode)
224  error = x509VerifyEd25519Signature(tbsData, publicKeyInfo,
225  signature);
226  }
227  else
228 #endif
229 #if (X509_ED448_SUPPORT == ENABLED && ED448_SUPPORT == ENABLED)
230  //Ed448 signature algorithm?
231  if(signAlgo == X509_SIGN_ALGO_ED448)
232  {
233  //Verify Ed448 signature (PureEdDSA mode)
234  error = x509VerifyEd448Signature(tbsData, publicKeyInfo,
235  signature);
236  }
237  else
238 #endif
239 #if (X509_MLDSA44_SUPPORT == ENABLED && MLDSA44_SUPPORT == ENABLED)
240  //ML-DSA-44 signature algorithm?
241  if(signAlgo == X509_SIGN_ALGO_MLDSA44)
242  {
243  //Verify ML-DSA-44 signature
244  error = x509VerifyMldsa44Signature(tbsData, publicKeyInfo,
245  signature);
246  }
247  else
248 #endif
249 #if (X509_MLDSA65_SUPPORT == ENABLED && MLDSA65_SUPPORT == ENABLED)
250  //ML-DSA-65 signature algorithm?
251  if(signAlgo == X509_SIGN_ALGO_MLDSA65)
252  {
253  //Verify ML-DSA-65 signature
254  error = x509VerifyMldsa65Signature(tbsData, publicKeyInfo,
255  signature);
256  }
257  else
258 #endif
259 #if (X509_MLDSA87_SUPPORT == ENABLED && MLDSA87_SUPPORT == ENABLED)
260  //ML-DSA-87 signature algorithm?
261  if(signAlgo == X509_SIGN_ALGO_MLDSA87)
262  {
263  //Verify ML-DSA-87 signature
264  error = x509VerifyMldsa87Signature(tbsData, publicKeyInfo,
265  signature);
266  }
267  else
268 #endif
269  //Invalid signature algorithm?
270  {
271  //Report an error
273  }
274  }
275  }
276 
277  //Return status code
278  return error;
279 }
280 
281 
282 /**
283  * @brief RSA signature verification
284  * @param[in] tbsData Data whose signature is to be verified
285  * @param[in] hashAlgo Underlying hash function
286  * @param[in] publicKeyInfo Issuer's public key
287  * @param[in] signature Signature to be verified
288  * @return Error code
289  **/
290 
292  const HashAlgo *hashAlgo, const X509SubjectPublicKeyInfo *publicKeyInfo,
293  const X509OctetString *signature)
294 {
295 #if (X509_RSA_SUPPORT == ENABLED && RSA_SUPPORT == ENABLED)
296  error_t error;
297  uint_t k;
298  RsaPublicKey rsaPublicKey;
299  uint8_t digest[MAX_HASH_DIGEST_SIZE];
300 
301  //Initialize RSA public key
302  rsaInitPublicKey(&rsaPublicKey);
303 
304  //Check public key identifier
305  if(OID_COMP(publicKeyInfo->oid.value, publicKeyInfo->oid.length,
306  RSA_ENCRYPTION_OID) == 0)
307  {
308  //Digest the TBSCertificate structure using the specified hash algorithm
309  error = hashAlgo->compute(tbsData->value, tbsData->length, digest);
310 
311  //Check status code
312  if(!error)
313  {
314  //Import the RSA public key
315  error = x509ImportRsaPublicKey(&rsaPublicKey, publicKeyInfo);
316  }
317 
318  //Check status code
319  if(!error)
320  {
321  //Get the length of the modulus, in bits
322  k = mpiGetBitLength(&rsaPublicKey.n);
323 
324  //Make sure the modulus is acceptable
325  if(k < X509_MIN_RSA_MODULUS_SIZE || k > X509_MAX_RSA_MODULUS_SIZE)
326  {
327  //Report an error
328  error = ERROR_INVALID_KEY;
329  }
330  }
331 
332  //Check status code
333  if(!error)
334  {
335  //Verify RSA signature (RSASSA-PKCS1-v1_5 signature scheme)
336  error = rsassaPkcs1v15Verify(&rsaPublicKey, hashAlgo, digest,
337  signature->value, signature->length);
338  }
339  }
340  else
341  {
342  //Invalid algorithm identifier
343  error = ERROR_WRONG_IDENTIFIER;
344  }
345 
346  //Release previously allocated resources
347  rsaFreePublicKey(&rsaPublicKey);
348 
349  //Return status code
350  return error;
351 #else
352  //Not implemented
353  return ERROR_NOT_IMPLEMENTED;
354 #endif
355 }
356 
357 
358 /**
359  * @brief RSA-PSS signature verification
360  * @param[in] tbsData Data whose signature is to be verified
361  * @param[in] hashAlgo Hash function
362  * @param[in] mgfHashAlgo MGF hash function
363  * @param[in] saltLen Length of the salt, in bytes
364  * @param[in] publicKeyInfo Issuer's public key
365  * @param[in] signature Signature to be verified
366  * @return Error code
367  **/
368 
370  const HashAlgo *hashAlgo, const HashAlgo *mgfHashAlgo, size_t saltLen,
371  const X509SubjectPublicKeyInfo *publicKeyInfo,
372  const X509OctetString *signature)
373 {
374 #if (X509_RSA_PSS_SUPPORT == ENABLED && RSA_SUPPORT == ENABLED)
375  error_t error;
376  uint_t k;
377  RsaPublicKey rsaPublicKey;
378  uint8_t digest[MAX_HASH_DIGEST_SIZE];
379 
380  //Initialize RSA public key
381  rsaInitPublicKey(&rsaPublicKey);
382 
383  //Check public key identifier
384  if(OID_COMP(publicKeyInfo->oid.value, publicKeyInfo->oid.length,
385  RSASSA_PSS_OID) == 0)
386  {
387  //Digest the TBSCertificate structure using the specified hash algorithm
388  error = hashAlgo->compute(tbsData->value, tbsData->length, digest);
389 
390  //Check status code
391  if(!error)
392  {
393  //Import the RSA public key
394  error = x509ImportRsaPublicKey(&rsaPublicKey, publicKeyInfo);
395  }
396 
397  //Check status code
398  if(!error)
399  {
400  //Get the length of the modulus, in bits
401  k = mpiGetBitLength(&rsaPublicKey.n);
402 
403  //Make sure the modulus is acceptable
404  if(k < X509_MIN_RSA_MODULUS_SIZE || k > X509_MAX_RSA_MODULUS_SIZE)
405  {
406  //Report an error
407  error = ERROR_INVALID_KEY;
408  }
409  }
410 
411  //Check status code
412  if(!error)
413  {
414  //Verify RSA signature (RSASSA-PSS signature scheme)
415  error = rsassaPssVerify(&rsaPublicKey, hashAlgo, mgfHashAlgo, saltLen,
416  digest, signature->value, signature->length);
417  }
418  }
419  else
420  {
421  //Invalid algorithm identifier
422  error = ERROR_WRONG_IDENTIFIER;
423  }
424 
425  //Release previously allocated resources
426  rsaFreePublicKey(&rsaPublicKey);
427 
428  //Return status code
429  return error;
430 #else
431  //Not implemented
432  return ERROR_NOT_IMPLEMENTED;
433 #endif
434 }
435 
436 
437 /**
438  * @brief DSA signature verification
439  * @param[in] tbsData Data whose signature is to be verified
440  * @param[in] hashAlgo Underlying hash function
441  * @param[in] publicKeyInfo Issuer's public key
442  * @param[in] signature Signature to be verified
443  * @return Error code
444  **/
445 
447  const HashAlgo *hashAlgo, const X509SubjectPublicKeyInfo *publicKeyInfo,
448  const X509OctetString *signature)
449 {
450 #if (X509_DSA_SUPPORT == ENABLED && DSA_SUPPORT == ENABLED)
451  error_t error;
452  uint_t k;
453  DsaPublicKey dsaPublicKey;
454  DsaSignature dsaSignature;
455  uint8_t digest[MAX_HASH_DIGEST_SIZE];
456 
457  //Initialize DSA public key
458  dsaInitPublicKey(&dsaPublicKey);
459  //Initialize DSA signature
460  dsaInitSignature(&dsaSignature);
461 
462  //Check public key identifier
463  if(OID_COMP(publicKeyInfo->oid.value, publicKeyInfo->oid.length,
464  DSA_OID) == 0)
465  {
466  //Digest the TBSCertificate structure using the specified hash algorithm
467  error = hashAlgo->compute(tbsData->value, tbsData->length, digest);
468 
469  //Check status code
470  if(!error)
471  {
472  //Import the DSA public key
473  error = x509ImportDsaPublicKey(&dsaPublicKey, publicKeyInfo);
474  }
475 
476  //Check status code
477  if(!error)
478  {
479  //Get the length of the prime modulus, in bits
480  k = mpiGetBitLength(&dsaPublicKey.params.p);
481 
482  //Make sure the prime modulus is acceptable
483  if(k < X509_MIN_DSA_MODULUS_SIZE || k > X509_MAX_DSA_MODULUS_SIZE)
484  {
485  //Report an error
486  error = ERROR_INVALID_KEY;
487  }
488  }
489 
490  //Check status code
491  if(!error)
492  {
493  //Read the ASN.1 encoded signature
494  error = dsaImportSignature(&dsaSignature, signature->value,
495  signature->length);
496  }
497 
498  //Check status code
499  if(!error)
500  {
501  //Verify DSA signature
502  error = dsaVerifySignature(&dsaPublicKey, digest, hashAlgo->digestSize,
503  &dsaSignature);
504  }
505  }
506  else
507  {
508  //Invalid algorithm identifier
509  error = ERROR_WRONG_IDENTIFIER;
510  }
511 
512  //Release previously allocated resources
513  dsaFreePublicKey(&dsaPublicKey);
514  dsaFreeSignature(&dsaSignature);
515 
516  //Return status code
517  return error;
518 #else
519  //Not implemented
520  return ERROR_NOT_IMPLEMENTED;
521 #endif
522 }
523 
524 
525 /**
526  * @brief ECDSA signature verification
527  * @param[in] tbsData Data whose signature is to be verified
528  * @param[in] hashAlgo Underlying hash function
529  * @param[in] publicKeyInfo Issuer's public key
530  * @param[in] signature Signature to be verified
531  * @return Error code
532  **/
533 
535  const HashAlgo *hashAlgo, const X509SubjectPublicKeyInfo *publicKeyInfo,
536  const X509OctetString *signature)
537 {
538 #if (X509_ECDSA_SUPPORT == ENABLED && ECDSA_SUPPORT == ENABLED)
539  error_t error;
540  const EcCurve *curve;
541  EcPublicKey ecPublicKey;
542  EcdsaSignature ecdsaSignature;
543  uint8_t digest[MAX_HASH_DIGEST_SIZE];
544 
545  //Initialize EC public key
546  ecInitPublicKey(&ecPublicKey);
547  //Initialize ECDSA signature
548  ecdsaInitSignature(&ecdsaSignature);
549 
550  //Check public key identifier
551  if(OID_COMP(publicKeyInfo->oid.value, publicKeyInfo->oid.length,
552  EC_PUBLIC_KEY_OID) == 0)
553  {
554  //Get the elliptic curve that matches the OID
555  curve = x509GetCurve(publicKeyInfo->ecParams.namedCurve.value,
556  publicKeyInfo->ecParams.namedCurve.length);
557 
558  //Make sure the specified elliptic curve is supported
559  if(curve != NULL)
560  {
561  //Digest the TBSCertificate structure using the specified hash algorithm
562  error = hashAlgo->compute(tbsData->value, tbsData->length, digest);
563 
564  //Check status code
565  if(!error)
566  {
567  //Import the EC public key
568  error = ecImportPublicKey(&ecPublicKey, curve,
569  publicKeyInfo->ecPublicKey.q.value,
571  }
572 
573  //Check status code
574  if(!error)
575  {
576  //Read the ASN.1 encoded signature
577  error = ecdsaImportSignature(&ecdsaSignature, curve, signature->value,
578  signature->length, ECDSA_SIGNATURE_FORMAT_ASN1);
579  }
580 
581  //Check status code
582  if(!error)
583  {
584  //Verify ECDSA signature
585  error = ecdsaVerifySignature(&ecPublicKey, digest,
586  hashAlgo->digestSize, &ecdsaSignature);
587  }
588  }
589  else
590  {
591  //Invalid elliptic curve
592  error = ERROR_BAD_CERTIFICATE;
593  }
594  }
595  else
596  {
597  //Invalid algorithm identifier
598  error = ERROR_WRONG_IDENTIFIER;
599  }
600 
601  //Release previously allocated resources
602  ecFreePublicKey(&ecPublicKey);
603  ecdsaFreeSignature(&ecdsaSignature);
604 
605  //Return status code
606  return error;
607 #else
608  //Not implemented
609  return ERROR_NOT_IMPLEMENTED;
610 #endif
611 }
612 
613 
614 /**
615  * @brief SM2 signature verification
616  * @param[in] tbsData Data whose signature is to be verified
617  * @param[in] hashAlgo Underlying hash function
618  * @param[in] publicKeyInfo Issuer's public key
619  * @param[in] signature Signature to be verified
620  * @return Error code
621  **/
622 
624  const HashAlgo *hashAlgo, const X509SubjectPublicKeyInfo *publicKeyInfo,
625  const X509OctetString *signature)
626 {
627 #if (X509_SM2_SUPPORT == ENABLED && SM2_SUPPORT == ENABLED)
628  error_t error;
629  EcPublicKey ecPublicKey;
630  EcdsaSignature sm2Signature;
631 
632  //Initialize EC public key
633  ecInitPublicKey(&ecPublicKey);
634  //Initialize SM2 signature
635  ecdsaInitSignature(&sm2Signature);
636 
637  //Check public key identifier
638  if(OID_COMP(publicKeyInfo->oid.value, publicKeyInfo->oid.length,
639  EC_PUBLIC_KEY_OID) == 0)
640  {
641  //SM2 elliptic curve?
642  if(OID_COMP(publicKeyInfo->ecParams.namedCurve.value,
643  publicKeyInfo->ecParams.namedCurve.length, SM2_OID) == 0)
644  {
645  //Import the EC public key
646  error = ecImportPublicKey(&ecPublicKey, SM2_CURVE,
647  publicKeyInfo->ecPublicKey.q.value,
649 
650  //Check status code
651  if(!error)
652  {
653  //Read the ASN.1 encoded signature
654  error = ecdsaImportSignature(&sm2Signature, SM2_CURVE, signature->value,
655  signature->length, ECDSA_SIGNATURE_FORMAT_ASN1);
656  }
657 
658  //Check status code
659  if(!error)
660  {
661  //Verify SM2 signature
662  error = sm2VerifySignature(&ecPublicKey, hashAlgo, SM2_DEFAULT_ID,
663  osStrlen(SM2_DEFAULT_ID), tbsData->value, tbsData->length,
664  &sm2Signature);
665  }
666  }
667  else
668  {
669  //Invalid elliptic curve
670  error = ERROR_BAD_CERTIFICATE;
671  }
672  }
673  else
674  {
675  //Invalid algorithm identifier
676  error = ERROR_WRONG_IDENTIFIER;
677  }
678 
679  //Release previously allocated resources
680  ecFreePublicKey(&ecPublicKey);
681  ecdsaFreeSignature(&sm2Signature);
682 
683  //Return status code
684  return error;
685 #else
686  //Not implemented
687  return ERROR_NOT_IMPLEMENTED;
688 #endif
689 }
690 
691 
692 /**
693  * @brief Ed25519 signature verification
694  * @param[in] tbsData Data whose signature is to be verified
695  * @param[in] publicKeyInfo Issuer's public key
696  * @param[in] signature Signature to be verified
697  * @return Error code
698  **/
699 
701  const X509SubjectPublicKeyInfo *publicKeyInfo,
702  const X509OctetString *signature)
703 {
704 #if (X509_ED25519_SUPPORT == ENABLED && ED25519_SUPPORT == ENABLED)
705  error_t error;
706 
707  //Check public key identifier
708  if(OID_COMP(publicKeyInfo->oid.value, publicKeyInfo->oid.length,
709  ED25519_OID) == 0)
710  {
711  //Check the length of the public key
712  if(publicKeyInfo->ecPublicKey.q.length == ED25519_PUBLIC_KEY_LEN)
713  {
714  //Check the length of the EdDSA signature
715  if(signature->length == ED25519_SIGNATURE_LEN)
716  {
717  //Verify Ed25519 signature (PureEdDSA mode)
718  error = ed25519VerifySignature(publicKeyInfo->ecPublicKey.q.value,
719  tbsData->value, tbsData->length, NULL, 0, 0, signature->value);
720  }
721  else
722  {
723  //The length of the EdDSA signature is not valid
724  error = ERROR_INVALID_SIGNATURE;
725  }
726  }
727  else
728  {
729  //The length of the Ed25519 public key is not valid
730  error = ERROR_ILLEGAL_PARAMETER;
731  }
732  }
733  else
734  {
735  //Invalid algorithm identifier
736  error = ERROR_WRONG_IDENTIFIER;
737  }
738 
739  //Return status code
740  return error;
741 #else
742  //Not implemented
743  return ERROR_NOT_IMPLEMENTED;
744 #endif
745 }
746 
747 
748 /**
749  * @brief Ed448 signature verification
750  * @param[in] tbsData Data whose signature is to be verified
751  * @param[in] publicKeyInfo Issuer's public key
752  * @param[in] signature Signature to be verified
753  * @return Error code
754  **/
755 
757  const X509SubjectPublicKeyInfo *publicKeyInfo,
758  const X509OctetString *signature)
759 {
760 #if (X509_ED448_SUPPORT == ENABLED && ED448_SUPPORT == ENABLED)
761  error_t error;
762 
763  //Check public key identifier
764  if(OID_COMP(publicKeyInfo->oid.value, publicKeyInfo->oid.length,
765  ED448_OID) == 0)
766  {
767  //Check the length of the public key
768  if(publicKeyInfo->ecPublicKey.q.length == ED448_PUBLIC_KEY_LEN)
769  {
770  //Check the length of the EdDSA signature
771  if(signature->length == ED448_SIGNATURE_LEN)
772  {
773  //Verify Ed448 signature (PureEdDSA mode)
774  error = ed448VerifySignature(publicKeyInfo->ecPublicKey.q.value,
775  tbsData->value, tbsData->length, NULL, 0, 0, signature->value);
776  }
777  else
778  {
779  //The length of the EdDSA signature is not valid
780  error = ERROR_INVALID_SIGNATURE;
781  }
782  }
783  else
784  {
785  //The length of the Ed448 public key is not valid
786  error = ERROR_ILLEGAL_PARAMETER;
787  }
788  }
789  else
790  {
791  //Invalid algorithm identifier
792  error = ERROR_WRONG_IDENTIFIER;
793  }
794 
795  //Return status code
796  return error;
797 #else
798  //Not implemented
799  return ERROR_NOT_IMPLEMENTED;
800 #endif
801 }
802 
803 
804 /**
805  * @brief ML-DSA-44 signature verification
806  * @param[in] tbsData Data whose signature is to be verified
807  * @param[in] publicKeyInfo Issuer's public key
808  * @param[in] signature Signature to be verified
809  * @return Error code
810  **/
811 
813  const X509SubjectPublicKeyInfo *publicKeyInfo,
814  const X509OctetString *signature)
815 {
816 #if (X509_MLDSA44_SUPPORT == ENABLED && MLDSA44_SUPPORT == ENABLED)
817  error_t error;
818 
819  //Check public key identifier
820  if(OID_COMP(publicKeyInfo->oid.value, publicKeyInfo->oid.length,
821  MLDSA44_OID) == 0)
822  {
823  //Check the length of the public key
824  if(publicKeyInfo->mldsaPublicKey.pk.length == MLDSA44_PUBLIC_KEY_LEN)
825  {
826  //Check the length of the ML-DSA-44 signature
827  if(signature->length == MLDSA44_SIGNATURE_LEN)
828  {
829  //Verify ML-DSA-44 signature
830  error = mldsa44VerifySignature(publicKeyInfo->mldsaPublicKey.pk.value,
831  tbsData->value, tbsData->length, NULL, 0, signature->value);
832  }
833  else
834  {
835  //The length of the ML-DSA-44 signature is not valid
836  error = ERROR_INVALID_SIGNATURE;
837  }
838  }
839  else
840  {
841  //The length of the ML-DSA-44 public key is not valid
842  error = ERROR_ILLEGAL_PARAMETER;
843  }
844  }
845  else
846  {
847  //Invalid algorithm identifier
848  error = ERROR_WRONG_IDENTIFIER;
849  }
850 
851  //Return status code
852  return error;
853 #else
854  //Not implemented
855  return ERROR_NOT_IMPLEMENTED;
856 #endif
857 }
858 
859 
860 /**
861  * @brief ML-DSA-65 signature verification
862  * @param[in] tbsData Data whose signature is to be verified
863  * @param[in] publicKeyInfo Issuer's public key
864  * @param[in] signature Signature to be verified
865  * @return Error code
866  **/
867 
869  const X509SubjectPublicKeyInfo *publicKeyInfo,
870  const X509OctetString *signature)
871 {
872 #if (X509_MLDSA65_SUPPORT == ENABLED && MLDSA65_SUPPORT == ENABLED)
873  error_t error;
874 
875  //Check public key identifier
876  if(OID_COMP(publicKeyInfo->oid.value, publicKeyInfo->oid.length,
877  MLDSA65_OID) == 0)
878  {
879  //Check the length of the public key
880  if(publicKeyInfo->mldsaPublicKey.pk.length == MLDSA65_PUBLIC_KEY_LEN)
881  {
882  //Check the length of the ML-DSA-65 signature
883  if(signature->length == MLDSA65_SIGNATURE_LEN)
884  {
885  //Verify ML-DSA-65 signature
886  error = mldsa65VerifySignature(publicKeyInfo->mldsaPublicKey.pk.value,
887  tbsData->value, tbsData->length, NULL, 0, signature->value);
888  }
889  else
890  {
891  //The length of the ML-DSA-65 signature is not valid
892  error = ERROR_INVALID_SIGNATURE;
893  }
894  }
895  else
896  {
897  //The length of the ML-DSA-65 public key is not valid
898  error = ERROR_ILLEGAL_PARAMETER;
899  }
900  }
901  else
902  {
903  //Invalid algorithm identifier
904  error = ERROR_WRONG_IDENTIFIER;
905  }
906 
907  //Return status code
908  return error;
909 #else
910  //Not implemented
911  return ERROR_NOT_IMPLEMENTED;
912 #endif
913 }
914 
915 
916 /**
917  * @brief ML-DSA-87 signature verification
918  * @param[in] tbsData Data whose signature is to be verified
919  * @param[in] publicKeyInfo Issuer's public key
920  * @param[in] signature Signature to be verified
921  * @return Error code
922  **/
923 
925  const X509SubjectPublicKeyInfo *publicKeyInfo,
926  const X509OctetString *signature)
927 {
928 #if (X509_MLDSA87_SUPPORT == ENABLED && MLDSA87_SUPPORT == ENABLED)
929  error_t error;
930 
931  //Check public key identifier
932  if(OID_COMP(publicKeyInfo->oid.value, publicKeyInfo->oid.length,
933  MLDSA87_OID) == 0)
934  {
935  //Check the length of the public key
936  if(publicKeyInfo->mldsaPublicKey.pk.length == MLDSA87_PUBLIC_KEY_LEN)
937  {
938  //Check the length of the ML-DSA-87 signature
939  if(signature->length == MLDSA87_SIGNATURE_LEN)
940  {
941  //Verify ML-DSA-87 signature
942  error = mldsa87VerifySignature(publicKeyInfo->mldsaPublicKey.pk.value,
943  tbsData->value, tbsData->length, NULL, 0, signature->value);
944  }
945  else
946  {
947  //The length of the ML-DSA-87 signature is not valid
948  error = ERROR_INVALID_SIGNATURE;
949  }
950  }
951  else
952  {
953  //The length of the ML-DSA-87 public key is not valid
954  error = ERROR_ILLEGAL_PARAMETER;
955  }
956  }
957  else
958  {
959  //Invalid algorithm identifier
960  error = ERROR_WRONG_IDENTIFIER;
961  }
962 
963  //Return status code
964  return error;
965 #else
966  //Not implemented
967  return ERROR_NOT_IMPLEMENTED;
968 #endif
969 }
970 
971 
972 #endif
error_t ecdsaImportSignature(EcdsaSignature *signature, const EcCurve *curve, const uint8_t *input, size_t length, EcdsaSignatureFormat format)
Import an ECDSA signature.
Definition: ecdsa.c:107
const uint8_t MLDSA44_OID[9]
Definition: mldsa.c:47
ECDSA signature.
Definition: ecdsa.h:63
error_t mldsa87VerifySignature(const uint8_t *publicKey, const void *message, size_t messageLen, const void *context, uint8_t contextLen, const uint8_t *signature)
ML-DSA-87 signature verification.
Definition: mldsa.c:700
error_t dsaImportSignature(DsaSignature *signature, const uint8_t *input, size_t length)
Import an ASN.1 encoded DSA signature.
Definition: dsa.c:197
void rsaFreePublicKey(RsaPublicKey *key)
Release an RSA public key.
Definition: rsa.c:113
#define MLDSA65_SIGNATURE_LEN
Definition: mldsa.h:58
@ X509_SIGN_ALGO_MLDSA65
Definition: x509_common.h:717
error_t sm2VerifySignature(const EcPublicKey *publicKey, const HashAlgo *hashAlgo, const char_t *id, size_t idLen, const void *message, size_t messageLen, const EcdsaSignature *signature)
SM2 signature verification.
Definition: sm2.c:274
const uint8_t MLDSA65_OID[9]
Definition: mldsa.c:49
const uint8_t RSASSA_PSS_SHAKE256_OID[8]
Definition: rsa.c:89
@ ERROR_NOT_IMPLEMENTED
Definition: error.h:66
@ ERROR_ILLEGAL_PARAMETER
Definition: error.h:244
#define ED25519_PUBLIC_KEY_LEN
Definition: ed25519.h:42
OID (Object Identifier)
X509OctetString oid
Definition: x509_common.h:910
#define ED448_PUBLIC_KEY_LEN
Definition: ed448.h:42
size_t digestSize
Definition: crypto.h:1249
const uint8_t EC_PUBLIC_KEY_OID[7]
Definition: ec.c:44
error_t ecImportPublicKey(EcPublicKey *key, const EcCurve *curve, const uint8_t *input, size_t length, EcPublicKeyFormat format)
Import an EC public key.
Definition: ec.c:263
X509EcParameters ecParams
Definition: x509_common.h:921
error_t ed448VerifySignature(const uint8_t *publicKey, const void *message, size_t messageLen, const void *context, uint8_t contextLen, uint8_t flag, const uint8_t *signature)
EdDSA signature verification.
Definition: ed448.c:425
#define ED448_SIGNATURE_LEN
Definition: ed448.h:44
X509OctetString maskGenHashAlgo
Definition: x509_common.h:1153
@ EC_PUBLIC_KEY_FORMAT_X963
Definition: ec.h:386
#define ED25519_SIGNATURE_LEN
Definition: ed25519.h:44
error_t x509VerifyRsaPssSignature(const X509OctetString *tbsData, const HashAlgo *hashAlgo, const HashAlgo *mgfHashAlgo, size_t saltLen, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
RSA-PSS signature verification.
error_t x509VerifyEd25519Signature(const X509OctetString *tbsData, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
Ed25519 signature verification.
Mpi p
Prime modulus.
Definition: dsa.h:50
#define osStrlen(s)
Definition: os_port.h:171
const uint8_t RSASSA_PSS_OID[9]
Definition: rsa.c:85
error_t x509ImportDsaPublicKey(DsaPublicKey *publicKey, const X509SubjectPublicKeyInfo *publicKeyInfo)
Import a DSA public key.
error_t mldsa65VerifySignature(const uint8_t *publicKey, const void *message, size_t messageLen, const void *context, uint8_t contextLen, const uint8_t *signature)
ML-DSA-65 signature verification.
Definition: mldsa.c:669
error_t x509VerifySignature(const X509OctetString *tbsData, const X509SignAlgoId *signAlgoId, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
Signature verification.
uint8_t oid[]
Definition: lldp_tlv.h:300
const uint8_t MGF1_OID[9]
Definition: rsa.c:92
Mpi n
Modulus.
Definition: rsa.h:58
const HashAlgo * x509GetHashAlgo(const uint8_t *oid, size_t length)
Get the hash algorithms that match the specified identifier.
Definition: x509_common.c:971
@ X509_SIGN_ALGO_MLDSA44
Definition: x509_common.h:716
const uint8_t DSA_OID[7]
Definition: dsa.c:51
void ecdsaFreeSignature(EcdsaSignature *signature)
Release an ECDSA signature.
Definition: ecdsa.c:90
#define MAX_HASH_DIGEST_SIZE
X509SignatureAlgo
Signature algorithms.
Definition: x509_common.h:707
DSA public key.
Definition: dsa.h:61
error_t x509VerifyEcdsaSignature(const X509OctetString *tbsData, const HashAlgo *hashAlgo, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
ECDSA signature verification.
const EcCurve * x509GetCurve(const uint8_t *oid, size_t length)
Get the elliptic curve that matches the specified OID.
Definition: x509_common.c:1080
error_t
Error codes.
Definition: error.h:43
void dsaInitSignature(DsaSignature *signature)
Initialize a DSA signature.
Definition: dsa.c:168
error_t rsassaPkcs1v15Verify(const RsaPublicKey *key, const HashAlgo *hash, const uint8_t *digest, const uint8_t *signature, size_t signatureLen)
RSASSA-PKCS1-v1_5 signature verification operation.
void ecInitPublicKey(EcPublicKey *key)
Initialize an EC public key.
Definition: ec.c:52
HashAlgoCompute compute
Definition: crypto.h:1252
@ X509_SIGN_ALGO_ECDSA
Definition: x509_common.h:712
RSA public key.
Definition: rsa.h:57
void ecdsaInitSignature(EcdsaSignature *signature)
Initialize an ECDSA signature.
Definition: ecdsa.c:74
X509MldsaPublicKey mldsaPublicKey
Definition: x509_common.h:926
#define MLDSA44_SIGNATURE_LEN
Definition: mldsa.h:47
#define X509_MAX_DSA_MODULUS_SIZE
Definition: x509_common.h:458
error_t x509VerifyEd448Signature(const X509OctetString *tbsData, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
Ed448 signature verification.
General definitions for cryptographic algorithms.
error_t x509GetSignHashAlgo(const X509SignAlgoId *signAlgoId, X509SignatureAlgo *signAlgo, const HashAlgo **hashAlgo)
Get the signature and hash algorithms that match the specified identifier.
Definition: x509_common.c:447
@ ERROR_BAD_CERTIFICATE
Definition: error.h:236
DsaDomainParameters params
DSA domain parameters.
Definition: dsa.h:62
#define MLDSA44_PUBLIC_KEY_LEN
Definition: mldsa.h:45
#define SM2_CURVE
Definition: ec_curves.h:69
@ X509_SIGN_ALGO_MLDSA87
Definition: x509_common.h:718
X509OctetString oid
Definition: x509_common.h:1164
X509OctetString maskGenAlgo
Definition: x509_common.h:1152
error_t x509VerifyRsaSignature(const X509OctetString *tbsData, const HashAlgo *hashAlgo, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
RSA signature verification.
error_t(* X509SignVerifyCallback)(const X509OctetString *tbsData, const X509SignAlgoId *signAlgoId, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
Signature verification callback function.
error_t x509VerifyMldsa44Signature(const X509OctetString *tbsData, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
ML-DSA-44 signature verification.
@ X509_SIGN_ALGO_RSA
Definition: x509_common.h:709
error_t x509VerifyMldsa65Signature(const X509OctetString *tbsData, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
ML-DSA-65 signature verification.
X509OctetString namedCurve
Definition: x509_common.h:879
const uint8_t ED448_OID[3]
Definition: ec_curves.c:114
uint_t mpiGetBitLength(const Mpi *a)
Get the actual length in bits.
Definition: mpi.c:255
const uint8_t ED25519_OID[3]
Definition: ec_curves.c:112
const uint8_t RSA_ENCRYPTION_OID[9]
Definition: rsa.c:54
EC public key.
Definition: ec.h:421
error_t dsaVerifySignature(const DsaPublicKey *key, const uint8_t *digest, size_t digestLen, const DsaSignature *signature)
DSA signature verification.
Definition: dsa.c:571
@ ECDSA_SIGNATURE_FORMAT_ASN1
Definition: ecdsa.h:51
X509OctetString q
Definition: x509_common.h:889
@ X509_SIGN_ALGO_RSA_PSS
Definition: x509_common.h:710
error_t x509RegisterSignVerifyCallback(X509SignVerifyCallback callback)
Register signature verification callback function.
RSA/DSA/ECDSA/EdDSA signature verification.
#define OID_COMP(oid1, oidLen1, oid2)
Definition: oid.h:42
error_t x509VerifySm2Signature(const X509OctetString *tbsData, const HashAlgo *hashAlgo, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
SM2 signature verification.
error_t x509ImportRsaPublicKey(RsaPublicKey *publicKey, const X509SubjectPublicKeyInfo *publicKeyInfo)
Import an RSA public key.
error_t x509VerifyMldsa87Signature(const X509OctetString *tbsData, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
ML-DSA-87 signature verification.
Subject Public Key Information extension.
Definition: x509_common.h:908
__weak_func error_t ecdsaVerifySignature(const EcPublicKey *publicKey, const uint8_t *digest, size_t digestLen, const EcdsaSignature *signature)
ECDSA signature verification.
Definition: ecdsa.c:951
void dsaFreeSignature(DsaSignature *signature)
Release a DSA signature.
Definition: dsa.c:181
__weak_func error_t ed25519VerifySignature(const uint8_t *publicKey, const void *message, size_t messageLen, const void *context, uint8_t contextLen, uint8_t flag, const uint8_t *signature)
EdDSA signature verification.
Definition: ed25519.c:448
#define MLDSA65_PUBLIC_KEY_LEN
Definition: mldsa.h:56
uint8_t oidLen
Definition: lldp_tlv.h:299
@ ERROR_WRONG_IDENTIFIER
Definition: error.h:89
#define X509_MAX_RSA_MODULUS_SIZE
Definition: x509_common.h:444
const uint8_t * value
Definition: x509_common.h:762
Common interface for hash algorithms.
Definition: crypto.h:1243
error_t mldsa44VerifySignature(const uint8_t *publicKey, const void *message, size_t messageLen, const void *context, uint8_t contextLen, const uint8_t *signature)
ML-DSA-44 signature verification.
Definition: mldsa.c:638
error_t rsassaPssVerify(const RsaPublicKey *key, const HashAlgo *hash, const HashAlgo *mgfHash, size_t saltLen, const uint8_t *digest, const uint8_t *signature, size_t signatureLen)
RSASSA-PSS signature verification operation.
DSA signature.
Definition: dsa.h:85
#define EcCurve
Definition: ec.h:346
Parsing of ASN.1 encoded keys.
@ ERROR_UNSUPPORTED_SIGNATURE_ALGO
Definition: error.h:132
@ X509_SIGN_ALGO_SM2
Definition: x509_common.h:713
Octet string.
Definition: x509_common.h:761
#define SM2_DEFAULT_ID
Definition: sm2.h:40
@ X509_SIGN_ALGO_ED25519
Definition: x509_common.h:714
error_t x509VerifyDsaSignature(const X509OctetString *tbsData, const HashAlgo *hashAlgo, const X509SubjectPublicKeyInfo *publicKeyInfo, const X509OctetString *signature)
DSA signature verification.
unsigned int uint_t
Definition: compiler_port.h:57
const uint8_t MLDSA87_OID[9]
Definition: mldsa.c:51
const uint8_t RSASSA_PSS_SHAKE128_OID[8]
Definition: rsa.c:87
X509EcPublicKey ecPublicKey
Definition: x509_common.h:922
@ ERROR_INVALID_SIGNATURE
Definition: error.h:228
X509RsaPssParameters rsaPssParams
Definition: x509_common.h:1166
void dsaFreePublicKey(DsaPublicKey *key)
Release a DSA public key.
Definition: dsa.c:119
#define MLDSA87_PUBLIC_KEY_LEN
Definition: mldsa.h:67
void dsaInitPublicKey(DsaPublicKey *key)
Initialize a DSA public key.
Definition: dsa.c:105
Signature algorithm identifier.
Definition: x509_common.h:1163
@ ERROR_INVALID_KEY
Definition: error.h:106
@ NO_ERROR
Success.
Definition: error.h:44
Debugging facilities.
void rsaInitPublicKey(RsaPublicKey *key)
Initialize an RSA public key.
Definition: rsa.c:100
void ecFreePublicKey(EcPublicKey *key)
Release an EC public key.
Definition: ec.c:68
#define MLDSA87_SIGNATURE_LEN
Definition: mldsa.h:69
@ X509_SIGN_ALGO_DSA
Definition: x509_common.h:711
X509OctetString pk
Definition: x509_common.h:899
@ X509_SIGN_ALGO_ED448
Definition: x509_common.h:715
const uint8_t SM2_OID[8]
Definition: ec_curves.c:106