rsa.h
Go to the documentation of this file.
1 /**
2  * @file rsa.h
3  * @brief RSA public-key cryptography standard
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2023 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneCRYPTO Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.2.4
29  **/
30 
31 #ifndef _RSA_H
32 #define _RSA_H
33 
34 //Dependencies
35 #include "core/crypto.h"
36 #include "hash/hash_algorithms.h"
37 #include "mpi/mpi.h"
38 
39 //C++ guard
40 #ifdef __cplusplus
41 extern "C" {
42 #endif
43 
44 
45 /**
46  * @brief RSA public key
47  **/
48 
49 typedef struct
50 {
51  Mpi n; ///<Modulus
52  Mpi e; ///<Public exponent
53 } RsaPublicKey;
54 
55 
56 /**
57  * @brief RSA private key
58  **/
59 
60 typedef struct
61 {
62  Mpi n; ///<Modulus
63  Mpi e; ///<Public exponent
64  Mpi d; ///<Private exponent
65  Mpi p; ///<First factor
66  Mpi q; ///<Second factor
67  Mpi dp; ///<First factor's CRT exponent
68  Mpi dq; ///<Second factor's CRT exponent
69  Mpi qinv; ///<CRT coefficient
70  int_t slot; ///<Private key slot
72 
73 
74 //RSA related constants
75 extern const uint8_t PKCS1_OID[8];
76 extern const uint8_t RSA_ENCRYPTION_OID[9];
77 extern const uint8_t MD2_WITH_RSA_ENCRYPTION_OID[9];
78 extern const uint8_t MD5_WITH_RSA_ENCRYPTION_OID[9];
79 extern const uint8_t SHA1_WITH_RSA_ENCRYPTION_OID[9];
80 extern const uint8_t SHA224_WITH_RSA_ENCRYPTION_OID[9];
81 extern const uint8_t SHA256_WITH_RSA_ENCRYPTION_OID[9];
82 extern const uint8_t SHA384_WITH_RSA_ENCRYPTION_OID[9];
83 extern const uint8_t SHA512_WITH_RSA_ENCRYPTION_OID[9];
84 extern const uint8_t SHA512_256_WITH_RSA_ENCRYPTION_OID[9];
85 extern const uint8_t SHA512_224_WITH_RSA_ENCRYPTION_OID[9];
86 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_224_OID[9];
87 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_256_OID[9];
88 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_384_OID[9];
89 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_512_OID[9];
90 extern const uint8_t RSASSA_PSS_OID[9];
91 extern const uint8_t MGF1_OID[9];
92 
93 //RSA related functions
98 
99 error_t rsaesPkcs1v15Encrypt(const PrngAlgo *prngAlgo, void *prngContext,
100  const RsaPublicKey *key, const uint8_t *message, size_t messageLen,
101  uint8_t *ciphertext, size_t *ciphertextLen);
102 
104  const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *message,
105  size_t messageSize, size_t *messageLen);
106 
107 error_t rsaesOaepEncrypt(const PrngAlgo *prngAlgo, void *prngContext,
108  const RsaPublicKey *key, const HashAlgo *hash, const char_t *label,
109  const uint8_t *message, size_t messageLen, uint8_t *ciphertext,
110  size_t *ciphertextLen);
111 
113  const char_t *label, const uint8_t *ciphertext, size_t ciphertextLen,
114  uint8_t *message, size_t messageSize, size_t *messageLen);
115 
117  const uint8_t *digest, uint8_t *signature, size_t *signatureLen);
118 
120  const uint8_t *digest, const uint8_t *signature, size_t signatureLen);
121 
122 error_t rsassaPssSign(const PrngAlgo *prngAlgo, void *prngContext,
123  const RsaPrivateKey *key, const HashAlgo *hash, size_t saltLen,
124  const uint8_t *digest, uint8_t *signature, size_t *signatureLen);
125 
127  size_t saltLen, const uint8_t *digest, const uint8_t *signature,
128  size_t signatureLen);
129 
130 error_t rsaep(const RsaPublicKey *key, const Mpi *m, Mpi *c);
131 error_t rsadp(const RsaPrivateKey *key, const Mpi *c, Mpi *m);
132 
133 error_t rsasp1(const RsaPrivateKey *key, const Mpi *m, Mpi *s);
134 error_t rsavp1(const RsaPublicKey *key, const Mpi *s, Mpi *m);
135 
136 error_t emePkcs1v15Encode(const PrngAlgo *prngAlgo, void *prngContext,
137  const uint8_t *message, size_t messageLen, uint8_t *em, size_t k);
138 
139 uint32_t emePkcs1v15Decode(uint8_t *em, size_t k, size_t *messageLen);
140 
141 error_t emeOaepEncode(const PrngAlgo *prngAlgo, void *prngContext,
142  const HashAlgo *hash, const char_t *label, const uint8_t *message,
143  size_t messageLen, uint8_t *em, size_t k);
144 
145 uint32_t emeOaepDecode(const HashAlgo *hash, const char_t *label, uint8_t *em,
146  size_t k, size_t *messageLen);
147 
149  const uint8_t *digest, uint8_t *em, size_t emLen);
150 
151 error_t emsaPkcs1v15Verify(const HashAlgo *hash, const uint8_t *digest,
152  const uint8_t *em, size_t emLen);
153 
154 error_t emsaPssEncode(const PrngAlgo *prngAlgo, void *prngContext,
155  const HashAlgo *hash, size_t saltLen, const uint8_t *digest,
156  uint8_t *em, uint_t emBits);
157 
158 error_t emsaPssVerify(const HashAlgo *hash, size_t saltLen,
159  const uint8_t *digest, uint8_t *em, uint_t emBits);
160 
161 void mgf1(const HashAlgo *hash, HashContext *hashContext, const uint8_t *seed,
162  size_t seedLen, uint8_t *data, size_t dataLen);
163 
164 error_t rsaGenerateKeyPair(const PrngAlgo *prngAlgo, void *prngContext,
165  size_t k, uint_t e, RsaPrivateKey *privateKey, RsaPublicKey *publicKey);
166 
167 error_t rsaGeneratePrivateKey(const PrngAlgo *prngAlgo, void *prngContext,
168  size_t k, uint_t e, RsaPrivateKey *privateKey);
169 
170 error_t rsaGeneratePublicKey(const RsaPrivateKey *privateKey,
171  RsaPublicKey *publicKey);
172 
173 //C++ guard
174 #ifdef __cplusplus
175 }
176 #endif
177 
178 #endif
const uint8_t RSASSA_PSS_OID[9]
Definition: rsa.c:88
error_t emsaPkcs1v15Verify(const HashAlgo *hash, const uint8_t *digest, const uint8_t *em, size_t emLen)
EMSA-PKCS1-v1_5 verification operation.
Definition: rsa.c:1657
const uint8_t MD5_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:62
Generic hash algorithm context.
const uint8_t MGF1_OID[9]
Definition: rsa.c:91
Mpi p
First factor.
Definition: rsa.h:65
uint8_t data[]
Definition: ethernet.h:220
Arbitrary precision integer.
Definition: mpi.h:70
signed int int_t
Definition: compiler_port.h:49
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_512_OID[9]
Definition: rsa.c:85
const uint8_t SHA384_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:70
#define PrngAlgo
Definition: crypto.h:861
error_t rsaesPkcs1v15Decrypt(const RsaPrivateKey *key, const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *message, size_t messageSize, size_t *messageLen)
RSAES-PKCS1-v1_5 decryption operation.
Definition: rsa.c:277
const uint8_t PKCS1_OID[8]
Definition: rsa.c:55
void mgf1(const HashAlgo *hash, HashContext *hashContext, const uint8_t *seed, size_t seedLen, uint8_t *data, size_t dataLen)
MGF1 mask generation function.
Definition: rsa.c:1912
error_t emsaPssEncode(const PrngAlgo *prngAlgo, void *prngContext, const HashAlgo *hash, size_t saltLen, const uint8_t *digest, uint8_t *em, uint_t emBits)
EMSA-PSS encoding operation.
Definition: rsa.c:1733
uint8_t signature
Definition: tls.h:1456
Mpi n
Modulus.
Definition: rsa.h:62
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_224_OID[9]
Definition: rsa.c:79
error_t emsaPkcs1v15Encode(const HashAlgo *hash, const uint8_t *digest, uint8_t *em, size_t emLen)
EMSA-PKCS1-v1_5 encoding operation.
Definition: rsa.c:1593
Mpi e
Public exponent.
Definition: rsa.h:52
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_256_OID[9]
Definition: rsa.c:81
Mpi d
Private exponent.
Definition: rsa.h:64
void rsaFreePublicKey(RsaPublicKey *key)
Release an RSA public key.
Definition: rsa.c:118
Mpi n
Modulus.
Definition: rsa.h:51
error_t rsaGeneratePublicKey(const RsaPrivateKey *privateKey, RsaPublicKey *publicKey)
Derive the public key from an RSA private key.
Definition: rsa.c:2150
int_t slot
Private key slot.
Definition: rsa.h:70
error_t rsaesPkcs1v15Encrypt(const PrngAlgo *prngAlgo, void *prngContext, const RsaPublicKey *key, const uint8_t *message, size_t messageLen, uint8_t *ciphertext, size_t *ciphertextLen)
RSAES-PKCS1-v1_5 encryption operation.
Definition: rsa.c:179
void rsaInitPublicKey(RsaPublicKey *key)
Initialize an RSA public key.
Definition: rsa.c:105
error_t
Error codes.
Definition: error.h:43
const uint8_t SHA512_224_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:74
error_t rsaGenerateKeyPair(const PrngAlgo *prngAlgo, void *prngContext, size_t k, uint_t e, RsaPrivateKey *privateKey, RsaPublicKey *publicKey)
RSA key pair generation.
Definition: rsa.c:1959
Mpi q
Second factor.
Definition: rsa.h:66
RSA public key.
Definition: rsa.h:50
error_t rsavp1(const RsaPublicKey *key, const Mpi *s, Mpi *m)
RSA verification primitive.
Definition: rsa.c:1273
MPI (Multiple Precision Integer Arithmetic)
error_t rsaesOaepDecrypt(const RsaPrivateKey *key, const HashAlgo *hash, const char_t *label, const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *message, size_t messageSize, size_t *messageLen)
RSAES-OAEP decryption operation.
Definition: rsa.c:532
error_t rsaGeneratePrivateKey(const PrngAlgo *prngAlgo, void *prngContext, size_t k, uint_t e, RsaPrivateKey *privateKey)
RSA private key generation.
General definitions for cryptographic algorithms.
void rsaInitPrivateKey(RsaPrivateKey *key)
Initialize an RSA private key.
Definition: rsa.c:131
error_t rsasp1(const RsaPrivateKey *key, const Mpi *m, Mpi *s)
RSA signature primitive.
Definition: rsa.c:1252
error_t emsaPssVerify(const HashAlgo *hash, size_t saltLen, const uint8_t *digest, uint8_t *em, uint_t emBits)
EMSA-PSS verification operation.
Definition: rsa.c:1815
Mpi e
Public exponent.
Definition: rsa.h:63
uint32_t emeOaepDecode(const HashAlgo *hash, const char_t *label, uint8_t *em, size_t k, size_t *messageLen)
EME-OAEP decoding operation.
Definition: rsa.c:1497
const uint8_t SHA512_256_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:76
uint32_t dataLen
Definition: sftp_common.h:227
error_t rsassaPssVerify(const RsaPublicKey *key, const HashAlgo *hash, size_t saltLen, const uint8_t *digest, const uint8_t *signature, size_t signatureLen)
RSASSA-PSS signature verification operation.
Definition: rsa.c:1043
error_t rsassaPkcs1v15Verify(const RsaPublicKey *key, const HashAlgo *hash, const uint8_t *digest, const uint8_t *signature, size_t signatureLen)
RSASSA-PKCS1-v1_5 signature verification operation.
Definition: rsa.c:814
Mpi qinv
CRT coefficient.
Definition: rsa.h:69
Mpi dq
Second factor's CRT exponent.
Definition: rsa.h:68
Collection of hash algorithms.
uint8_t hash
Definition: tls.h:1455
const uint8_t SHA256_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:68
char char_t
Definition: compiler_port.h:48
error_t rsaesOaepEncrypt(const PrngAlgo *prngAlgo, void *prngContext, const RsaPublicKey *key, const HashAlgo *hash, const char_t *label, const uint8_t *message, size_t messageLen, uint8_t *ciphertext, size_t *ciphertextLen)
RSAES-OAEP encryption operation.
Definition: rsa.c:426
uint8_t m
Definition: ndp.h:302
RSA private key.
Definition: rsa.h:61
error_t rsadp(const RsaPrivateKey *key, const Mpi *c, Mpi *m)
RSA decryption primitive.
uint32_t emePkcs1v15Decode(uint8_t *em, size_t k, size_t *messageLen)
EME-PKCS1-v1_5 decoding operation.
Definition: rsa.c:1361
uint8_t s
uint8_t message[]
Definition: chap.h:152
const uint8_t SHA224_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:66
error_t emeOaepEncode(const PrngAlgo *prngAlgo, void *prngContext, const HashAlgo *hash, const char_t *label, const uint8_t *message, size_t messageLen, uint8_t *em, size_t k)
EME-OAEP encoding operation.
Definition: rsa.c:1415
void rsaFreePrivateKey(RsaPrivateKey *key)
Release an RSA private key.
Definition: rsa.c:153
const uint8_t SHA1_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:64
Common interface for hash algorithms.
Definition: crypto.h:958
const uint8_t RSA_ENCRYPTION_OID[9]
Definition: rsa.c:57
const uint8_t SHA512_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:72
error_t rsassaPssSign(const PrngAlgo *prngAlgo, void *prngContext, const RsaPrivateKey *key, const HashAlgo *hash, size_t saltLen, const uint8_t *digest, uint8_t *signature, size_t *signatureLen)
RSASSA-PSS signature generation operation.
Definition: rsa.c:923
Mpi dp
First factor's CRT exponent.
Definition: rsa.h:67
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_384_OID[9]
Definition: rsa.c:83
const uint8_t MD2_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:60
unsigned int uint_t
Definition: compiler_port.h:50
error_t emePkcs1v15Encode(const PrngAlgo *prngAlgo, void *prngContext, const uint8_t *message, size_t messageLen, uint8_t *em, size_t k)
EME-PKCS1-v1_5 encoding operation.
Definition: rsa.c:1293
uint8_t c
Definition: ndp.h:512
error_t rsaep(const RsaPublicKey *key, const Mpi *m, Mpi *c)
RSA encryption primitive.
error_t rsassaPkcs1v15Sign(const RsaPrivateKey *key, const HashAlgo *hash, const uint8_t *digest, uint8_t *signature, size_t *signatureLen)
RSASSA-PKCS1-v1_5 signature generation operation.
Definition: rsa.c:681