ssh_kdf.c
Go to the documentation of this file.
1 /**
2  * @file ssh_kdf.c
3  * @brief SSH key derivation function
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2026 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneCRYPTO Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.6.6
29  **/
30 
31 //Switch to the appropriate trace level
32 #define TRACE_LEVEL CRYPTO_TRACE_LEVEL
33 
34 //Dependencies
35 #include "core/crypto.h"
36 #include "kdf/ssh_kdf.h"
37 #include "hash/hash_algorithms.h"
38 
39 //Check crypto library configuration
40 #if (SSH_KDF_SUPPORT == ENABLED)
41 
42 
43 /**
44  * @brief SSH key derivation function
45  * @param[in] hashAlgo Underlying hash function
46  * @param[in] k Shared secret K (encoded as an SSH mpint)
47  * @param[in] kLen Length of the shared secret, in bytes
48  * @param[in] h Exchange hash H
49  * @param[in] hLen Length of the exchange hash, in bytes
50  * @param[in] sessionId Session identifier
51  * @param[in] sessionIdLen Length of the session identifier, in bytes
52  * @param[in] x A single byte ('A' to 'F') selecting the derived key
53  * @param[out] output Pointer to the derived key
54  * @param[in] outputLen Desired output length, in bytes
55  * @return Error code
56  **/
57 
58 error_t sshKdf(const HashAlgo *hashAlgo, const uint8_t *k, size_t kLen,
59  const uint8_t *h, size_t hLen, const uint8_t *sessionId,
60  size_t sessionIdLen, uint8_t x, uint8_t *output, size_t outputLen)
61 {
62  size_t i;
63  size_t n;
64  uint8_t digest[MAX_HASH_DIGEST_SIZE];
65 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
66  HashContext *hashContext;
67 #else
68  HashContext hashContext[1];
69 #endif
70 
71  //Check parameters
72  if(hashAlgo == NULL || k == NULL || h == NULL || sessionId == NULL ||
73  output == NULL)
74  {
76  }
77 
78 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
79  //Allocate a memory buffer to hold the hash context
80  hashContext = cryptoAllocMem(hashAlgo->contextSize);
81  //Failed to allocate memory?
82  if(hashContext == NULL)
83  return ERROR_OUT_OF_MEMORY;
84 #endif
85 
86  //Compute K(1) = HASH(K || H || X || session_id)
87  hashAlgo->init(hashContext);
88  hashAlgo->update(hashContext, k, kLen);
89  hashAlgo->update(hashContext, h, hLen);
90  hashAlgo->update(hashContext, &x, sizeof(x));
91  hashAlgo->update(hashContext, sessionId, sessionIdLen);
92  hashAlgo->final(hashContext, digest);
93 
94  //Key data must be taken from the beginning of the hash output
95  for(n = 0; n < hashAlgo->digestSize && n < outputLen; n++)
96  {
97  output[n] = digest[n];
98  }
99 
100  //If the key length needed is longer than the output of the HASH, the key
101  //is extended by computing HASH of the concatenation of K and H and the
102  //entire key so far, and appending the resulting bytes to the key
103  while(n < outputLen)
104  {
105  //Compute K(n + 1) = HASH(K || H || K(1) || ... || K(n))
106  hashAlgo->init(hashContext);
107  hashAlgo->update(hashContext, k, kLen);
108  hashAlgo->update(hashContext, h, hLen);
109  hashAlgo->update(hashContext, output, n);
110  hashAlgo->final(hashContext, digest);
111 
112  //This process is repeated until enough key material is available
113  for(i = 0; i < hashAlgo->digestSize && n < outputLen; i++, n++)
114  {
115  output[n] = digest[i];
116  }
117  }
118 
119 #if (CRYPTO_STATIC_MEM_SUPPORT == DISABLED)
120  //Free previously allocated memory
121  cryptoFreeMem(hashContext);
122 #endif
123 
124  //Successful processing
125  return NO_ERROR;
126 }
127 
128 #endif
error_t sshKdf(const HashAlgo *hashAlgo, const uint8_t *k, size_t kLen, const uint8_t *h, size_t hLen, const uint8_t *sessionId, size_t sessionIdLen, uint8_t x, uint8_t *output, size_t outputLen)
SSH key derivation function.
Definition: ssh_kdf.c:58
HashAlgoInit init
Definition: crypto.h:1253
Generic hash algorithm context.
uint8_t sessionId[]
Definition: tls.h:1942
uint8_t x
Definition: lldp_ext_med.h:211
size_t digestSize
Definition: crypto.h:1249
HashAlgoUpdate update
Definition: crypto.h:1254
@ ERROR_OUT_OF_MEMORY
Definition: error.h:63
size_t contextSize
Definition: crypto.h:1247
uint8_t sessionIdLen
Definition: tls.h:1941
#define MAX_HASH_DIGEST_SIZE
uint8_t h
Definition: ndp.h:302
@ ERROR_INVALID_PARAMETER
Invalid parameter.
Definition: error.h:47
error_t
Error codes.
Definition: error.h:43
General definitions for cryptographic algorithms.
Collection of hash algorithms.
HashAlgoFinal final
Definition: crypto.h:1255
uint8_t n
#define cryptoFreeMem(p)
Definition: crypto.h:966
#define cryptoAllocMem(size)
Definition: crypto.h:961
Common interface for hash algorithms.
Definition: crypto.h:1243
SSH key derivation function.
@ NO_ERROR
Success.
Definition: error.h:44