rsa.h
Go to the documentation of this file.
1 /**
2  * @file rsa.h
3  * @brief RSA public-key cryptography standard
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2020 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneCRYPTO Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 1.9.8
29  **/
30 
31 #ifndef _RSA_H
32 #define _RSA_H
33 
34 //Dependencies
35 #include "core/crypto.h"
36 #include "mpi/mpi.h"
37 
38 //C++ guard
39 #ifdef __cplusplus
40 extern "C" {
41 #endif
42 
43 
44 /**
45  * @brief RSA public key
46  **/
47 
48 typedef struct
49 {
50  Mpi n; ///<Modulus
51  Mpi e; ///<Public exponent
52 } RsaPublicKey;
53 
54 
55 /**
56  * @brief RSA private key
57  **/
58 
59 typedef struct
60 {
61  Mpi n; ///<Modulus
62  Mpi e; ///<Public exponent
63  Mpi d; ///<Private exponent
64  Mpi p; ///<First factor
65  Mpi q; ///<Second factor
66  Mpi dp; ///<First factor's CRT exponent
67  Mpi dq; ///<second factor's CRT exponent
68  Mpi qinv; ///<CRT coefficient
70 
71 
72 //RSA related constants
73 extern const uint8_t PKCS1_OID[8];
74 extern const uint8_t RSA_ENCRYPTION_OID[9];
75 extern const uint8_t MD2_WITH_RSA_ENCRYPTION_OID[9];
76 extern const uint8_t MD5_WITH_RSA_ENCRYPTION_OID[9];
77 extern const uint8_t SHA1_WITH_RSA_ENCRYPTION_OID[9];
78 extern const uint8_t SHA224_WITH_RSA_ENCRYPTION_OID[9];
79 extern const uint8_t SHA256_WITH_RSA_ENCRYPTION_OID[9];
80 extern const uint8_t SHA384_WITH_RSA_ENCRYPTION_OID[9];
81 extern const uint8_t SHA512_WITH_RSA_ENCRYPTION_OID[9];
82 extern const uint8_t SHA512_256_WITH_RSA_ENCRYPTION_OID[9];
83 extern const uint8_t SHA512_224_WITH_RSA_ENCRYPTION_OID[9];
84 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_224_OID[9];
85 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_256_OID[9];
86 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_384_OID[9];
87 extern const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_512_OID[9];
88 extern const uint8_t RSASSA_PSS_OID[9];
89 extern const uint8_t MGF1_OID[9];
90 
91 //RSA related functions
96 
97 error_t rsaesPkcs1v15Encrypt(const PrngAlgo *prngAlgo, void *prngContext,
98  const RsaPublicKey *key, const uint8_t *message, size_t messageLen,
99  uint8_t *ciphertext, size_t *ciphertextLen);
100 
102  const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *message,
103  size_t messageSize, size_t *messageLen);
104 
105 error_t rsaesOaepEncrypt(const PrngAlgo *prngAlgo, void *prngContext,
106  const RsaPublicKey *key, const HashAlgo *hash, const char_t *label,
107  const uint8_t *message, size_t messageLen, uint8_t *ciphertext,
108  size_t *ciphertextLen);
109 
111  const char_t *label, const uint8_t *ciphertext, size_t ciphertextLen,
112  uint8_t *message, size_t messageSize, size_t *messageLen);
113 
115  const uint8_t *digest, uint8_t *signature, size_t *signatureLen);
116 
118  const uint8_t *digest, const uint8_t *signature, size_t signatureLen);
119 
120 error_t rsassaPssSign(const PrngAlgo *prngAlgo, void *prngContext,
121  const RsaPrivateKey *key, const HashAlgo *hash, size_t saltLen,
122  const uint8_t *digest, uint8_t *signature, size_t *signatureLen);
123 
125  size_t saltLen, const uint8_t *digest, const uint8_t *signature,
126  size_t signatureLen);
127 
128 error_t rsaep(const RsaPublicKey *key, const Mpi *m, Mpi *c);
129 error_t rsadp(const RsaPrivateKey *key, const Mpi *c, Mpi *m);
130 
131 error_t rsasp1(const RsaPrivateKey *key, const Mpi *m, Mpi *s);
132 error_t rsavp1(const RsaPublicKey *key, const Mpi *s, Mpi *m);
133 
134 error_t emePkcs1v15Encode(const PrngAlgo *prngAlgo, void *prngContext,
135  const uint8_t *message, size_t messageLen, uint8_t *em, size_t k);
136 
137 uint32_t emePkcs1v15Decode(uint8_t *em, size_t k, size_t *messageLen);
138 
139 error_t emeOaepEncode(const PrngAlgo *prngAlgo, void *prngContext,
140  const HashAlgo *hash, const char_t *label, const uint8_t *message,
141  size_t messageLen, uint8_t *em, size_t k);
142 
143 uint32_t emeOaepDecode(const HashAlgo *hash, const char_t *label, uint8_t *em,
144  size_t k, size_t *messageLen);
145 
147  const uint8_t *digest, uint8_t *em, size_t emLen);
148 
149 error_t emsaPkcs1v15Verify(const HashAlgo *hash, const uint8_t *digest,
150  const uint8_t *em, size_t emLen);
151 
152 error_t emsaPssEncode(const PrngAlgo *prngAlgo, void *prngContext,
153  const HashAlgo *hash, size_t saltLen, const uint8_t *digest,
154  uint8_t *em, uint_t emBits);
155 
156 error_t emsaPssVerify(const HashAlgo *hash, size_t saltLen,
157  const uint8_t *digest, uint8_t *em, uint_t emBits);
158 
159 void mgf1(const HashAlgo *hash, HashContext *hashContext, const uint8_t *seed,
160  size_t seedLen, uint8_t *data, size_t dataLen);
161 
162 error_t rsaGenerateKeyPair(const PrngAlgo *prngAlgo, void *prngContext,
163  size_t k, uint_t e, RsaPrivateKey *privateKey, RsaPublicKey *publicKey);
164 
165 //C++ guard
166 #ifdef __cplusplus
167 }
168 #endif
169 
170 #endif
const uint8_t RSASSA_PSS_OID[9]
Definition: rsa.c:88
error_t emsaPkcs1v15Verify(const HashAlgo *hash, const uint8_t *digest, const uint8_t *em, size_t emLen)
EMSA-PKCS1-v1_5 verification operation.
Definition: rsa.c:1649
const uint8_t MD5_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:62
const uint8_t MGF1_OID[9]
Definition: rsa.c:91
Mpi p
First factor.
Definition: rsa.h:64
uint8_t data[]
Definition: ethernet.h:209
Arbitrary precision integer.
Definition: mpi.h:69
Common interface for pseudo-random number generators.
Definition: crypto.h:1102
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_512_OID[9]
Definition: rsa.c:85
const uint8_t SHA384_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:70
error_t rsaesPkcs1v15Decrypt(const RsaPrivateKey *key, const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *message, size_t messageSize, size_t *messageLen)
RSAES-PKCS1-v1_5 decryption operation.
Definition: rsa.c:274
const uint8_t PKCS1_OID[8]
Definition: rsa.c:55
void mgf1(const HashAlgo *hash, HashContext *hashContext, const uint8_t *seed, size_t seedLen, uint8_t *data, size_t dataLen)
MGF1 mask generation function.
Definition: rsa.c:1904
error_t emsaPssEncode(const PrngAlgo *prngAlgo, void *prngContext, const HashAlgo *hash, size_t saltLen, const uint8_t *digest, uint8_t *em, uint_t emBits)
EMSA-PSS encoding operation.
Definition: rsa.c:1725
uint8_t signature
Definition: tls.h:1381
Mpi n
Modulus.
Definition: rsa.h:61
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_224_OID[9]
Definition: rsa.c:79
error_t emsaPkcs1v15Encode(const HashAlgo *hash, const uint8_t *digest, uint8_t *em, size_t emLen)
EMSA-PKCS1-v1_5 encoding operation.
Definition: rsa.c:1585
Mpi e
Public exponent.
Definition: rsa.h:51
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_256_OID[9]
Definition: rsa.c:81
Mpi d
Private exponent.
Definition: rsa.h:63
void rsaFreePublicKey(RsaPublicKey *key)
Release an RSA public key.
Definition: rsa.c:118
Mpi n
Modulus.
Definition: rsa.h:50
error_t rsaesPkcs1v15Encrypt(const PrngAlgo *prngAlgo, void *prngContext, const RsaPublicKey *key, const uint8_t *message, size_t messageLen, uint8_t *ciphertext, size_t *ciphertextLen)
RSAES-PKCS1-v1_5 encryption operation.
Definition: rsa.c:176
void rsaInitPublicKey(RsaPublicKey *key)
Initialize an RSA public key.
Definition: rsa.c:105
error_t
Error codes.
Definition: error.h:42
const uint8_t SHA512_224_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:74
error_t rsaGenerateKeyPair(const PrngAlgo *prngAlgo, void *prngContext, size_t k, uint_t e, RsaPrivateKey *privateKey, RsaPublicKey *publicKey)
RSA key pair generation.
Definition: rsa.c:1951
Mpi q
Second factor.
Definition: rsa.h:65
RSA public key.
Definition: rsa.h:48
error_t rsavp1(const RsaPublicKey *key, const Mpi *s, Mpi *m)
RSA verification primitive.
Definition: rsa.c:1269
MPI (Multiple Precision Integer Arithmetic)
error_t rsaesOaepDecrypt(const RsaPrivateKey *key, const HashAlgo *hash, const char_t *label, const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *message, size_t messageSize, size_t *messageLen)
RSAES-OAEP decryption operation.
Definition: rsa.c:529
General definitions for cryptographic algorithms.
void rsaInitPrivateKey(RsaPrivateKey *key)
Initialize an RSA private key.
Definition: rsa.c:131
error_t rsasp1(const RsaPrivateKey *key, const Mpi *m, Mpi *s)
RSA signature primitive.
Definition: rsa.c:1248
error_t emsaPssVerify(const HashAlgo *hash, size_t saltLen, const uint8_t *digest, uint8_t *em, uint_t emBits)
EMSA-PSS verification operation.
Definition: rsa.c:1807
Mpi e
Public exponent.
Definition: rsa.h:62
uint32_t emeOaepDecode(const HashAlgo *hash, const char_t *label, uint8_t *em, size_t k, size_t *messageLen)
EME-OAEP decoding operation.
Definition: rsa.c:1491
const uint8_t SHA512_256_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:76
error_t rsassaPssVerify(const RsaPublicKey *key, const HashAlgo *hash, size_t saltLen, const uint8_t *digest, const uint8_t *signature, size_t signatureLen)
RSASSA-PSS signature verification operation.
Definition: rsa.c:1040
error_t rsassaPkcs1v15Verify(const RsaPublicKey *key, const HashAlgo *hash, const uint8_t *digest, const uint8_t *signature, size_t signatureLen)
RSASSA-PKCS1-v1_5 signature verification operation.
Definition: rsa.c:811
Mpi qinv
CRT coefficient.
Definition: rsa.h:68
Mpi dq
second factor's CRT exponent
Definition: rsa.h:67
uint8_t hash
Definition: tls.h:1380
const uint8_t SHA256_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:68
char char_t
Definition: compiler_port.h:43
error_t rsaesOaepEncrypt(const PrngAlgo *prngAlgo, void *prngContext, const RsaPublicKey *key, const HashAlgo *hash, const char_t *label, const uint8_t *message, size_t messageLen, uint8_t *ciphertext, size_t *ciphertextLen)
RSAES-OAEP encryption operation.
Definition: rsa.c:423
uint8_t m
Definition: ndp.h:302
RSA private key.
Definition: rsa.h:59
error_t rsadp(const RsaPrivateKey *key, const Mpi *c, Mpi *m)
RSA decryption primitive.
uint32_t emePkcs1v15Decode(uint8_t *em, size_t k, size_t *messageLen)
EME-PKCS1-v1_5 decoding operation.
Definition: rsa.c:1357
uint8_t s
uint8_t message[]
Definition: chap.h:152
const uint8_t SHA224_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:66
error_t emeOaepEncode(const PrngAlgo *prngAlgo, void *prngContext, const HashAlgo *hash, const char_t *label, const uint8_t *message, size_t messageLen, uint8_t *em, size_t k)
EME-OAEP encoding operation.
Definition: rsa.c:1411
void rsaFreePrivateKey(RsaPrivateKey *key)
Release an RSA private key.
Definition: rsa.c:150
const uint8_t SHA1_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:64
Common interface for hash algorithms.
Definition: crypto.h:1062
const uint8_t RSA_ENCRYPTION_OID[9]
Definition: rsa.c:57
const uint8_t SHA512_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:72
error_t rsassaPssSign(const PrngAlgo *prngAlgo, void *prngContext, const RsaPrivateKey *key, const HashAlgo *hash, size_t saltLen, const uint8_t *digest, uint8_t *signature, size_t *signatureLen)
RSASSA-PSS signature generation operation.
Definition: rsa.c:920
Mpi dp
First factor's CRT exponent.
Definition: rsa.h:66
const uint8_t RSASSA_PKCS1_V1_5_WITH_SHA3_384_OID[9]
Definition: rsa.c:83
const uint8_t MD2_WITH_RSA_ENCRYPTION_OID[9]
Definition: rsa.c:60
unsigned int uint_t
Definition: compiler_port.h:45
error_t emePkcs1v15Encode(const PrngAlgo *prngAlgo, void *prngContext, const uint8_t *message, size_t messageLen, uint8_t *em, size_t k)
EME-PKCS1-v1_5 encoding operation.
Definition: rsa.c:1289
Generic hash algorithm context.
Definition: crypto.h:1052
uint8_t c
Definition: ndp.h:513
error_t rsaep(const RsaPublicKey *key, const Mpi *m, Mpi *c)
RSA encryption primitive.
Definition: rsa.c:1154
error_t rsassaPkcs1v15Sign(const RsaPrivateKey *key, const HashAlgo *hash, const uint8_t *digest, uint8_t *signature, size_t *signatureLen)
RSASSA-PKCS1-v1_5 signature generation operation.
Definition: rsa.c:678