rsa.h
Go to the documentation of this file.
1 /**
2  * @file rsa.h
3  * @brief RSA public-key cryptography standard
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2024 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneCRYPTO Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.4.4
29  **/
30 
31 #ifndef _RSA_H
32 #define _RSA_H
33 
34 //Dependencies
35 #include "core/crypto.h"
36 #include "hash/hash_algorithms.h"
37 #include "mpi/mpi.h"
38 
39 //Maximum acceptable size for RSA modulus
40 #ifndef RSA_MAX_MODULUS_SIZE
41  #define RSA_MAX_MODULUS_SIZE 4096
42 #elif (RSA_MAX_MODULUS_SIZE < 0)
43  #error RSA_MAX_MODULUS_SIZE parameter is not valid
44 #endif
45 
46 //C++ guard
47 #ifdef __cplusplus
48 extern "C" {
49 #endif
50 
51 
52 /**
53  * @brief RSA public key
54  **/
55 
56 typedef struct
57 {
58  Mpi n; ///<Modulus
59  Mpi e; ///<Public exponent
60 } RsaPublicKey;
61 
62 
63 /**
64  * @brief RSA private key
65  **/
66 
67 typedef struct
68 {
69  Mpi n; ///<Modulus
70  Mpi e; ///<Public exponent
71  Mpi d; ///<Private exponent
72  Mpi p; ///<First factor
73  Mpi q; ///<Second factor
74  Mpi dp; ///<First factor's CRT exponent
75  Mpi dq; ///<Second factor's CRT exponent
76  Mpi qinv; ///<CRT coefficient
77  int_t slot; ///<Private key slot
79 
80 
81 //RSA related constants
82 extern const uint8_t PKCS1_OID[8];
83 extern const uint8_t RSA_ENCRYPTION_OID[9];
84 extern const uint8_t MD2_WITH_RSA_ENCRYPTION_OID[9];
85 extern const uint8_t MD5_WITH_RSA_ENCRYPTION_OID[9];
86 extern const uint8_t SHA1_WITH_RSA_ENCRYPTION_OID[9];
87 extern const uint8_t SHA224_WITH_RSA_ENCRYPTION_OID[9];
88 extern const uint8_t SHA256_WITH_RSA_ENCRYPTION_OID[9];
89 extern const uint8_t SHA384_WITH_RSA_ENCRYPTION_OID[9];
90 extern const uint8_t SHA512_WITH_RSA_ENCRYPTION_OID[9];
91 extern const uint8_t SHA512_256_WITH_RSA_ENCRYPTION_OID[9];
92 extern const uint8_t SHA512_224_WITH_RSA_ENCRYPTION_OID[9];
93 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_224_OID[9];
94 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_256_OID[9];
95 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_384_OID[9];
96 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_512_OID[9];
97 extern const uint8_t RSASSA_PSS_OID[9];
98 extern const uint8_t MGF1_OID[9];
99 
100 //RSA related functions
101 void rsaInitPublicKey(RsaPublicKey *key);
102 void rsaFreePublicKey(RsaPublicKey *key);
105 
106 error_t rsaesPkcs1v15Encrypt(const PrngAlgo *prngAlgo, void *prngContext,
107  const RsaPublicKey *key, const uint8_t *message, size_t messageLen,
108  uint8_t *ciphertext, size_t *ciphertextLen);
109 
111  const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *message,
112  size_t messageSize, size_t *messageLen);
113 
114 error_t rsaesOaepEncrypt(const PrngAlgo *prngAlgo, void *prngContext,
115  const RsaPublicKey *key, const HashAlgo *hash, const char_t *label,
116  const uint8_t *message, size_t messageLen, uint8_t *ciphertext,
117  size_t *ciphertextLen);
118 
119 error_t rsaesOaepDecrypt(const RsaPrivateKey *key, const HashAlgo *hash,
120  const char_t *label, const uint8_t *ciphertext, size_t ciphertextLen,
121  uint8_t *message, size_t messageSize, size_t *messageLen);
122 
123 error_t rsassaPkcs1v15Sign(const RsaPrivateKey *key, const HashAlgo *hash,
124  const uint8_t *digest, uint8_t *signature, size_t *signatureLen);
125 
126 error_t rsassaPkcs1v15Verify(const RsaPublicKey *key, const HashAlgo *hash,
127  const uint8_t *digest, const uint8_t *signature, size_t signatureLen);
128 
129 error_t rsassaPssSign(const PrngAlgo *prngAlgo, void *prngContext,
130  const RsaPrivateKey *key, const HashAlgo *hash, size_t saltLen,
131  const uint8_t *digest, uint8_t *signature, size_t *signatureLen);
132 
133 error_t rsassaPssVerify(const RsaPublicKey *key, const HashAlgo *hash,
134  size_t saltLen, const uint8_t *digest, const uint8_t *signature,
135  size_t signatureLen);
136 
137 error_t rsaep(const RsaPublicKey *key, const Mpi *m, Mpi *c);
138 error_t rsadp(const RsaPrivateKey *key, const Mpi *c, Mpi *m);
139 
140 error_t rsasp1(const RsaPrivateKey *key, const Mpi *m, Mpi *s);
141 error_t rsavp1(const RsaPublicKey *key, const Mpi *s, Mpi *m);
142 
143 error_t emePkcs1v15Encode(const PrngAlgo *prngAlgo, void *prngContext,
144  const uint8_t *message, size_t messageLen, uint8_t *em, size_t k);
145 
146 uint32_t emePkcs1v15Decode(uint8_t *em, size_t k, size_t *messageLen);
147 
148 error_t emeOaepEncode(const PrngAlgo *prngAlgo, void *prngContext,
149  const HashAlgo *hash, const char_t *label, const uint8_t *message,
150  size_t messageLen, uint8_t *em, size_t k);
151 
152 uint32_t emeOaepDecode(const HashAlgo *hash, const char_t *label, uint8_t *em,
153  size_t k, size_t *messageLen);
154 
156  const uint8_t *digest, uint8_t *em, size_t emLen);
157 
158 error_t emsaPkcs1v15Verify(const HashAlgo *hash, const uint8_t *digest,
159  const uint8_t *em, size_t emLen);
160 
161 error_t emsaPssEncode(const PrngAlgo *prngAlgo, void *prngContext,
162  const HashAlgo *hash, size_t saltLen, const uint8_t *digest,
163  uint8_t *em, uint_t emBits);
164 
165 error_t emsaPssVerify(const HashAlgo *hash, size_t saltLen,
166  const uint8_t *digest, uint8_t *em, uint_t emBits);
167 
168 void mgf1(const HashAlgo *hash, HashContext *hashContext, const uint8_t *seed,
169  size_t seedLen, uint8_t *data, size_t dataLen);
170 
171 error_t rsaGenerateKeyPair(const PrngAlgo *prngAlgo, void *prngContext,
172  size_t k, uint_t e, RsaPrivateKey *privateKey, RsaPublicKey *publicKey);
173 
174 error_t rsaGeneratePrivateKey(const PrngAlgo *prngAlgo, void *prngContext,
175  size_t k, uint_t e, RsaPrivateKey *privateKey);
176 
177 error_t rsaGeneratePublicKey(const RsaPrivateKey *privateKey,
178  RsaPublicKey *publicKey);
179 
180 //C++ guard
181 #ifdef __cplusplus
182 }
183 #endif
184 
185 #endif
const uint8_t RSASSA_PSS_OID[9]
Definition: rsa.c:88
error_t emsaPkcs1v15Verify(const HashAlgo *hash, const uint8_t *digest, const uint8_t *em, size_t emLen)
EMSA-PKCS1-v1_5 verification operation.
Definition: rsa.c:1717
const uint8_t MD5_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:62
Generic hash algorithm context.
const uint8_t MGF1_OID[9]
Definition: rsa.c:91
Mpi p
First factor.
Definition: rsa.h:72
Arbitrary precision integer.
Definition: mpi.h:80
signed int int_t
Definition: compiler_port.h:49
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_512_OID[9]
Definition: rsa.c:85
const uint8_t SHA384_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:70
#define PrngAlgo
Definition: crypto.h:938
error_t rsaesPkcs1v15Decrypt(const RsaPrivateKey *key, const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *message, size_t messageSize, size_t *messageLen)
RSAES-PKCS1-v1_5 decryption operation.
Definition: rsa.c:277
uint8_t message[]
Definition: chap.h:154
const uint8_t PKCS1_OID[8]
Definition: rsa.c:55
void mgf1(const HashAlgo *hash, HashContext *hashContext, const uint8_t *seed, size_t seedLen, uint8_t *data, size_t dataLen)
MGF1 mask generation function.
Definition: rsa.c:1988
uint8_t data[]
Definition: ethernet.h:222
error_t emsaPssEncode(const PrngAlgo *prngAlgo, void *prngContext, const HashAlgo *hash, size_t saltLen, const uint8_t *digest, uint8_t *em, uint_t emBits)
EMSA-PSS encoding operation.
Definition: rsa.c:1793
Mpi n
Modulus.
Definition: rsa.h:69
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_224_OID[9]
Definition: rsa.c:79
error_t emsaPkcs1v15Encode(const HashAlgo *hash, const uint8_t *digest, uint8_t *em, size_t emLen)
EMSA-PKCS1-v1_5 encoding operation.
Definition: rsa.c:1653
Mpi e
Public exponent.
Definition: rsa.h:59
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_256_OID[9]
Definition: rsa.c:81
Mpi d
Private exponent.
Definition: rsa.h:71
void rsaFreePublicKey(RsaPublicKey *key)
Release an RSA public key.
Definition: rsa.c:118
Mpi n
Modulus.
Definition: rsa.h:58
error_t rsaGeneratePublicKey(const RsaPrivateKey *privateKey, RsaPublicKey *publicKey)
Derive the public key from an RSA private key.
Definition: rsa.c:2226
int_t slot
Private key slot.
Definition: rsa.h:77
error_t rsaesPkcs1v15Encrypt(const PrngAlgo *prngAlgo, void *prngContext, const RsaPublicKey *key, const uint8_t *message, size_t messageLen, uint8_t *ciphertext, size_t *ciphertextLen)
RSAES-PKCS1-v1_5 encryption operation.
Definition: rsa.c:179
void rsaInitPublicKey(RsaPublicKey *key)
Initialize an RSA public key.
Definition: rsa.c:105
error_t
Error codes.
Definition: error.h:43
const uint8_t SHA512_224_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:74
error_t rsaGenerateKeyPair(const PrngAlgo *prngAlgo, void *prngContext, size_t k, uint_t e, RsaPrivateKey *privateKey, RsaPublicKey *publicKey)
RSA key pair generation.
Definition: rsa.c:2035
Mpi q
Second factor.
Definition: rsa.h:73
RSA public key.
Definition: rsa.h:57
error_t rsavp1(const RsaPublicKey *key, const Mpi *s, Mpi *m)
RSA verification primitive.
Definition: rsa.c:1323
MPI (Multiple Precision Integer Arithmetic)
error_t rsaesOaepDecrypt(const RsaPrivateKey *key, const HashAlgo *hash, const char_t *label, const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *message, size_t messageSize, size_t *messageLen)
RSAES-OAEP decryption operation.
Definition: rsa.c:544
error_t rsaGeneratePrivateKey(const PrngAlgo *prngAlgo, void *prngContext, size_t k, uint_t e, RsaPrivateKey *privateKey)
RSA private key generation.
General definitions for cryptographic algorithms.
void rsaInitPrivateKey(RsaPrivateKey *key)
Initialize an RSA private key.
Definition: rsa.c:131
error_t rsasp1(const RsaPrivateKey *key, const Mpi *m, Mpi *s)
RSA signature primitive.
Definition: rsa.c:1302
error_t emsaPssVerify(const HashAlgo *hash, size_t saltLen, const uint8_t *digest, uint8_t *em, uint_t emBits)
EMSA-PSS verification operation.
Definition: rsa.c:1883
Mpi e
Public exponent.
Definition: rsa.h:70
uint32_t emeOaepDecode(const HashAlgo *hash, const char_t *label, uint8_t *em, size_t k, size_t *messageLen)
EME-OAEP decoding operation.
Definition: rsa.c:1555
const uint8_t SHA512_256_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:76
uint32_t dataLen
Definition: sftp_common.h:229
error_t rsassaPssVerify(const RsaPublicKey *key, const HashAlgo *hash, size_t saltLen, const uint8_t *digest, const uint8_t *signature, size_t signatureLen)
RSASSA-PSS signature verification operation.
Definition: rsa.c:1079
error_t rsassaPkcs1v15Verify(const RsaPublicKey *key, const HashAlgo *hash, const uint8_t *digest, const uint8_t *signature, size_t signatureLen)
RSASSA-PKCS1-v1_5 signature verification operation.
Definition: rsa.c:838
Mpi qinv
CRT coefficient.
Definition: rsa.h:76
Mpi dq
Second factor's CRT exponent.
Definition: rsa.h:75
Collection of hash algorithms.
const uint8_t SHA256_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:68
char char_t
Definition: compiler_port.h:48
error_t rsaesOaepEncrypt(const PrngAlgo *prngAlgo, void *prngContext, const RsaPublicKey *key, const HashAlgo *hash, const char_t *label, const uint8_t *message, size_t messageLen, uint8_t *ciphertext, size_t *ciphertextLen)
RSAES-OAEP encryption operation.
Definition: rsa.c:438
uint8_t m
Definition: ndp.h:304
RSA private key.
Definition: rsa.h:68
error_t rsadp(const RsaPrivateKey *key, const Mpi *c, Mpi *m)
RSA decryption primitive.
uint32_t emePkcs1v15Decode(uint8_t *em, size_t k, size_t *messageLen)
EME-PKCS1-v1_5 decoding operation.
Definition: rsa.c:1411
const uint8_t SHA224_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:66
error_t emeOaepEncode(const PrngAlgo *prngAlgo, void *prngContext, const HashAlgo *hash, const char_t *label, const uint8_t *message, size_t messageLen, uint8_t *em, size_t k)
EME-OAEP encoding operation.
Definition: rsa.c:1465
uint8_t s
Definition: igmp_common.h:234
void rsaFreePrivateKey(RsaPrivateKey *key)
Release an RSA private key.
Definition: rsa.c:153
const uint8_t SHA1_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:64
Common interface for hash algorithms.
Definition: crypto.h:1046
const uint8_t RSA_ENCRYPTION_OID[9]
Definition: rsa.c:57
const uint8_t SHA512_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:72
error_t rsassaPssSign(const PrngAlgo *prngAlgo, void *prngContext, const RsaPrivateKey *key, const HashAlgo *hash, size_t saltLen, const uint8_t *digest, uint8_t *signature, size_t *signatureLen)
RSASSA-PSS signature generation operation.
Definition: rsa.c:959
Mpi dp
First factor's CRT exponent.
Definition: rsa.h:74
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_384_OID[9]
Definition: rsa.c:83
const uint8_t MD2_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:60
unsigned int uint_t
Definition: compiler_port.h:50
error_t emePkcs1v15Encode(const PrngAlgo *prngAlgo, void *prngContext, const uint8_t *message, size_t messageLen, uint8_t *em, size_t k)
EME-PKCS1-v1_5 encoding operation.
Definition: rsa.c:1343
uint8_t c
Definition: ndp.h:514
error_t rsaep(const RsaPublicKey *key, const Mpi *m, Mpi *c)
RSA encryption primitive.
error_t rsassaPkcs1v15Sign(const RsaPrivateKey *key, const HashAlgo *hash, const uint8_t *digest, uint8_t *signature, size_t *signatureLen)
RSASSA-PKCS1-v1_5 signature generation operation.
Definition: rsa.c:705