ike_sign_verify.h
Go to the documentation of this file.
1 /**
2  * @file ike_sign_verify.h
3  * @brief RSA/DSA/ECDSA/EdDSA signature verification
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2022-2024 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneIPSEC Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.4.0
29  **/
30 
31 #ifndef _IKE_SIGN_VERIFY_H
32 #define _IKE_SIGN_VERIFY_H
33 
34 //Dependencies
35 #include "ike/ike.h"
36 #include "ike/ike_sign_misc.h"
37 #include "pkix/x509_common.h"
38 
39 //C++ guard
40 #ifdef __cplusplus
41 extern "C" {
42 #endif
43 
44 //IKEv2 related functions
45 error_t ikeVerifySignature(IkeSaEntry *sa, const uint8_t *id, size_t idLen,
46  uint8_t authMethod, const X509SubjectPublicKeyInfo *publicKeyInfo,
47  const uint8_t *signature, size_t signatureLen);
48 
49 error_t ikeVerifyDigitalSignature(IkeSaEntry *sa, const uint8_t *id,
50  size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo,
51  const IkeAuthData *authData, size_t authDataLen);
52 
53 error_t ikeVerifyRsaSignature(IkeSaEntry *sa, const uint8_t *id,
54  size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo,
55  const HashAlgo *hashAlgo, const uint8_t *signature, size_t signatureLen);
56 
57 error_t ikeVerifyRsaPssSignature(IkeSaEntry *sa, const uint8_t *id,
58  size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo,
59  const HashAlgo *hashAlgo, size_t saltLen, const uint8_t *signature,
60  size_t signatureLen);
61 
62 error_t ikeVerifyDsaSignature(IkeSaEntry *sa, const uint8_t *id,
63  size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo,
64  const HashAlgo *hashAlgo, const uint8_t *signature, size_t signatureLen,
65  IkeSignFormat format);
66 
67 error_t ikeVerifyEcdsaSignature(IkeSaEntry *sa, const uint8_t *id,
68  size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo,
69  const EcCurveInfo *group, const HashAlgo *hashAlgo,
70  const uint8_t *signature, size_t signatureLen, IkeSignFormat format);
71 
72 error_t ikeVerifyEd25519Signature(IkeSaEntry *sa, const uint8_t *id,
73  size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo,
74  const uint8_t *signature, size_t signatureLen);
75 
76 error_t ikeVerifyEd448Signature(IkeSaEntry *sa, const uint8_t *id,
77  size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo,
78  const uint8_t *signature, size_t signatureLen);
79 
80 //C++ guard
81 #ifdef __cplusplus
82 }
83 #endif
84 
85 #endif
error_t
Error codes.
Definition: error.h:43
IKEv2 (Internet Key Exchange Protocol)
#define IkeSaEntry
Definition: ike.h:682
IkeAuthData
Definition: ike.h:1414
uint8_t authMethod
Definition: ike.h:1400
Helper functions for signature generation and verification.
IkeSignFormat
Signature format.
Definition: ike_sign_misc.h:48
error_t ikeVerifyEd25519Signature(IkeSaEntry *sa, const uint8_t *id, size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo, const uint8_t *signature, size_t signatureLen)
Ed25519 signature verification.
error_t ikeVerifyRsaSignature(IkeSaEntry *sa, const uint8_t *id, size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo, const HashAlgo *hashAlgo, const uint8_t *signature, size_t signatureLen)
RSA signature verification.
error_t ikeVerifyDsaSignature(IkeSaEntry *sa, const uint8_t *id, size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo, const HashAlgo *hashAlgo, const uint8_t *signature, size_t signatureLen, IkeSignFormat format)
DSA signature verification.
error_t ikeVerifyEd448Signature(IkeSaEntry *sa, const uint8_t *id, size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo, const uint8_t *signature, size_t signatureLen)
Ed448 signature verification.
error_t ikeVerifyEcdsaSignature(IkeSaEntry *sa, const uint8_t *id, size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo, const EcCurveInfo *group, const HashAlgo *hashAlgo, const uint8_t *signature, size_t signatureLen, IkeSignFormat format)
ECDSA signature verification.
error_t ikeVerifyRsaPssSignature(IkeSaEntry *sa, const uint8_t *id, size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo, const HashAlgo *hashAlgo, size_t saltLen, const uint8_t *signature, size_t signatureLen)
RSA-PSS signature verification.
error_t ikeVerifySignature(IkeSaEntry *sa, const uint8_t *id, size_t idLen, uint8_t authMethod, const X509SubjectPublicKeyInfo *publicKeyInfo, const uint8_t *signature, size_t signatureLen)
Signature verification.
error_t ikeVerifyDigitalSignature(IkeSaEntry *sa, const uint8_t *id, size_t idLen, const X509SubjectPublicKeyInfo *publicKeyInfo, const IkeAuthData *authData, size_t authDataLen)
Digital signature verification.
uint8_t authData[]
Definition: ipv6.h:344
Elliptic curve parameters.
Definition: ec_curves.h:295
Common interface for hash algorithms.
Definition: crypto.h:1014
Subject Public Key Information extension.
Definition: x509_common.h:783
X.509 common definitions.