psa_crypto.c 190 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139414041414142414341444145414641474148414941504151415241534154415541564157415841594160416141624163416441654166416741684169417041714172417341744175417641774178417941804181418241834184418541864187418841894190419141924193419441954196419741984199420042014202420342044205420642074208420942104211421242134214421542164217421842194220422142224223422442254226422742284229423042314232423342344235423642374238423942404241424242434244424542464247424842494250425142524253425442554256425742584259426042614262426342644265426642674268426942704271427242734274427542764277427842794280428142824283428442854286428742884289429042914292429342944295429642974298429943004301430243034304430543064307430843094310431143124313431443154316431743184319432043214322432343244325432643274328432943304331433243334334433543364337433843394340434143424343434443454346434743484349435043514352435343544355435643574358435943604361436243634364436543664367436843694370437143724373437443754376437743784379438043814382438343844385438643874388438943904391439243934394439543964397439843994400440144024403440444054406440744084409441044114412441344144415441644174418441944204421442244234424442544264427442844294430443144324433443444354436443744384439444044414442444344444445444644474448444944504451445244534454445544564457445844594460446144624463446444654466446744684469447044714472447344744475447644774478447944804481448244834484448544864487448844894490449144924493449444954496449744984499450045014502450345044505450645074508450945104511451245134514451545164517451845194520452145224523452445254526452745284529453045314532453345344535453645374538453945404541454245434544454545464547454845494550455145524553455445554556455745584559456045614562456345644565456645674568456945704571457245734574457545764577457845794580458145824583458445854586458745884589459045914592459345944595459645974598459946004601460246034604460546064607460846094610461146124613461446154616461746184619462046214622462346244625462646274628462946304631463246334634463546364637463846394640464146424643464446454646464746484649465046514652465346544655465646574658465946604661466246634664466546664667466846694670467146724673467446754676467746784679468046814682468346844685468646874688468946904691469246934694469546964697469846994700470147024703470447054706470747084709471047114712471347144715471647174718471947204721472247234724472547264727472847294730473147324733473447354736473747384739474047414742474347444745474647474748474947504751475247534754475547564757475847594760476147624763476447654766476747684769477047714772477347744775477647774778477947804781478247834784478547864787478847894790479147924793479447954796479747984799480048014802480348044805480648074808480948104811481248134814481548164817481848194820482148224823482448254826482748284829483048314832483348344835483648374838483948404841484248434844484548464847484848494850485148524853485448554856485748584859486048614862486348644865486648674868486948704871487248734874487548764877487848794880488148824883488448854886488748884889489048914892489348944895489648974898489949004901490249034904490549064907490849094910491149124913491449154916491749184919492049214922492349244925492649274928492949304931493249334934493549364937493849394940494149424943494449454946494749484949495049514952495349544955495649574958495949604961496249634964496549664967496849694970497149724973497449754976497749784979498049814982498349844985498649874988498949904991499249934994499549964997499849995000500150025003500450055006500750085009501050115012501350145015501650175018501950205021502250235024502550265027502850295030503150325033503450355036503750385039504050415042504350445045504650475048504950505051505250535054505550565057505850595060506150625063506450655066506750685069507050715072507350745075507650775078507950805081508250835084508550865087508850895090509150925093509450955096509750985099510051015102510351045105510651075108510951105111511251135114511551165117511851195120512151225123512451255126512751285129513051315132513351345135513651375138513951405141514251435144514551465147514851495150515151525153515451555156515751585159516051615162516351645165516651675168516951705171517251735174517551765177517851795180518151825183518451855186518751885189519051915192519351945195519651975198519952005201520252035204520552065207520852095210521152125213521452155216521752185219522052215222522352245225522652275228522952305231523252335234523552365237523852395240524152425243524452455246524752485249525052515252525352545255525652575258525952605261526252635264526552665267526852695270527152725273527452755276527752785279528052815282528352845285528652875288528952905291529252935294529552965297529852995300530153025303530453055306530753085309531053115312531353145315531653175318531953205321532253235324532553265327532853295330533153325333533453355336533753385339534053415342534353445345534653475348534953505351535253535354535553565357535853595360536153625363536453655366536753685369537053715372537353745375537653775378537953805381538253835384538553865387538853895390539153925393539453955396539753985399540054015402540354045405540654075408540954105411541254135414541554165417541854195420542154225423542454255426542754285429543054315432543354345435543654375438543954405441
  1. /*
  2. * PSA crypto layer on top of Mbed TLS crypto
  3. */
  4. /*
  5. * Copyright The Mbed TLS Contributors
  6. * SPDX-License-Identifier: Apache-2.0
  7. *
  8. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  9. * not use this file except in compliance with the License.
  10. * You may obtain a copy of the License at
  11. *
  12. * http://www.apache.org/licenses/LICENSE-2.0
  13. *
  14. * Unless required by applicable law or agreed to in writing, software
  15. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  16. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  17. * See the License for the specific language governing permissions and
  18. * limitations under the License.
  19. */
  20. #include "common.h"
  21. #if defined(MBEDTLS_PSA_CRYPTO_C)
  22. #if defined(MBEDTLS_PSA_CRYPTO_CONFIG)
  23. #include "check_crypto_config.h"
  24. #endif
  25. #include "psa/crypto.h"
  26. #include "psa_crypto_cipher.h"
  27. #include "psa_crypto_core.h"
  28. #include "psa_crypto_invasive.h"
  29. #include "psa_crypto_driver_wrappers.h"
  30. #include "psa_crypto_ecp.h"
  31. #include "psa_crypto_hash.h"
  32. #include "psa_crypto_mac.h"
  33. #include "psa_crypto_rsa.h"
  34. #include "psa_crypto_ecp.h"
  35. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  36. #include "psa_crypto_se.h"
  37. #endif
  38. #include "psa_crypto_slot_management.h"
  39. /* Include internal declarations that are useful for implementing persistently
  40. * stored keys. */
  41. #include "psa_crypto_storage.h"
  42. #include "psa_crypto_random_impl.h"
  43. #include <assert.h>
  44. #include <stdlib.h>
  45. #include <string.h>
  46. #include "mbedtls/platform.h"
  47. #if !defined(MBEDTLS_PLATFORM_C)
  48. #define mbedtls_calloc calloc
  49. #define mbedtls_free free
  50. #endif
  51. #include "mbedtls/aes.h"
  52. #include "mbedtls/arc4.h"
  53. #include "mbedtls/asn1.h"
  54. #include "mbedtls/asn1write.h"
  55. #include "mbedtls/bignum.h"
  56. #include "mbedtls/blowfish.h"
  57. #include "mbedtls/camellia.h"
  58. #include "mbedtls/chacha20.h"
  59. #include "mbedtls/chachapoly.h"
  60. #include "mbedtls/cipher.h"
  61. #include "mbedtls/ccm.h"
  62. #include "mbedtls/cmac.h"
  63. #include "mbedtls/des.h"
  64. #include "mbedtls/ecdh.h"
  65. #include "mbedtls/ecp.h"
  66. #include "mbedtls/entropy.h"
  67. #include "mbedtls/error.h"
  68. #include "mbedtls/gcm.h"
  69. #include "mbedtls/md2.h"
  70. #include "mbedtls/md4.h"
  71. #include "mbedtls/md5.h"
  72. #include "mbedtls/md.h"
  73. #include "mbedtls/md_internal.h"
  74. #include "mbedtls/pk.h"
  75. #include "mbedtls/pk_internal.h"
  76. #include "mbedtls/platform_util.h"
  77. #include "mbedtls/error.h"
  78. #include "mbedtls/ripemd160.h"
  79. #include "mbedtls/rsa.h"
  80. #include "mbedtls/sha1.h"
  81. #include "mbedtls/sha256.h"
  82. #include "mbedtls/sha512.h"
  83. #include "mbedtls/xtea.h"
  84. #define ARRAY_LENGTH( array ) ( sizeof( array ) / sizeof( *( array ) ) )
  85. /****************************************************************/
  86. /* Global data, support functions and library management */
  87. /****************************************************************/
  88. static int key_type_is_raw_bytes( psa_key_type_t type )
  89. {
  90. return( PSA_KEY_TYPE_IS_UNSTRUCTURED( type ) );
  91. }
  92. /* Values for psa_global_data_t::rng_state */
  93. #define RNG_NOT_INITIALIZED 0
  94. #define RNG_INITIALIZED 1
  95. #define RNG_SEEDED 2
  96. typedef struct
  97. {
  98. unsigned initialized : 1;
  99. unsigned rng_state : 2;
  100. mbedtls_psa_random_context_t rng;
  101. } psa_global_data_t;
  102. static psa_global_data_t global_data;
  103. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  104. mbedtls_psa_drbg_context_t *const mbedtls_psa_random_state =
  105. &global_data.rng.drbg;
  106. #endif
  107. #define GUARD_MODULE_INITIALIZED \
  108. if( global_data.initialized == 0 ) \
  109. return( PSA_ERROR_BAD_STATE );
  110. psa_status_t mbedtls_to_psa_error( int ret )
  111. {
  112. /* Mbed TLS error codes can combine a high-level error code and a
  113. * low-level error code. The low-level error usually reflects the
  114. * root cause better, so dispatch on that preferably. */
  115. int low_level_ret = - ( -ret & 0x007f );
  116. switch( low_level_ret != 0 ? low_level_ret : ret )
  117. {
  118. case 0:
  119. return( PSA_SUCCESS );
  120. case MBEDTLS_ERR_AES_INVALID_KEY_LENGTH:
  121. case MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH:
  122. case MBEDTLS_ERR_AES_FEATURE_UNAVAILABLE:
  123. return( PSA_ERROR_NOT_SUPPORTED );
  124. case MBEDTLS_ERR_AES_HW_ACCEL_FAILED:
  125. return( PSA_ERROR_HARDWARE_FAILURE );
  126. case MBEDTLS_ERR_ARC4_HW_ACCEL_FAILED:
  127. return( PSA_ERROR_HARDWARE_FAILURE );
  128. case MBEDTLS_ERR_ASN1_OUT_OF_DATA:
  129. case MBEDTLS_ERR_ASN1_UNEXPECTED_TAG:
  130. case MBEDTLS_ERR_ASN1_INVALID_LENGTH:
  131. case MBEDTLS_ERR_ASN1_LENGTH_MISMATCH:
  132. case MBEDTLS_ERR_ASN1_INVALID_DATA:
  133. return( PSA_ERROR_INVALID_ARGUMENT );
  134. case MBEDTLS_ERR_ASN1_ALLOC_FAILED:
  135. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  136. case MBEDTLS_ERR_ASN1_BUF_TOO_SMALL:
  137. return( PSA_ERROR_BUFFER_TOO_SMALL );
  138. #if defined(MBEDTLS_ERR_BLOWFISH_BAD_INPUT_DATA)
  139. case MBEDTLS_ERR_BLOWFISH_BAD_INPUT_DATA:
  140. #elif defined(MBEDTLS_ERR_BLOWFISH_INVALID_KEY_LENGTH)
  141. case MBEDTLS_ERR_BLOWFISH_INVALID_KEY_LENGTH:
  142. #endif
  143. case MBEDTLS_ERR_BLOWFISH_INVALID_INPUT_LENGTH:
  144. return( PSA_ERROR_NOT_SUPPORTED );
  145. case MBEDTLS_ERR_BLOWFISH_HW_ACCEL_FAILED:
  146. return( PSA_ERROR_HARDWARE_FAILURE );
  147. #if defined(MBEDTLS_ERR_CAMELLIA_BAD_INPUT_DATA)
  148. case MBEDTLS_ERR_CAMELLIA_BAD_INPUT_DATA:
  149. #elif defined(MBEDTLS_ERR_CAMELLIA_INVALID_KEY_LENGTH)
  150. case MBEDTLS_ERR_CAMELLIA_INVALID_KEY_LENGTH:
  151. #endif
  152. case MBEDTLS_ERR_CAMELLIA_INVALID_INPUT_LENGTH:
  153. return( PSA_ERROR_NOT_SUPPORTED );
  154. case MBEDTLS_ERR_CAMELLIA_HW_ACCEL_FAILED:
  155. return( PSA_ERROR_HARDWARE_FAILURE );
  156. case MBEDTLS_ERR_CCM_BAD_INPUT:
  157. return( PSA_ERROR_INVALID_ARGUMENT );
  158. case MBEDTLS_ERR_CCM_AUTH_FAILED:
  159. return( PSA_ERROR_INVALID_SIGNATURE );
  160. case MBEDTLS_ERR_CCM_HW_ACCEL_FAILED:
  161. return( PSA_ERROR_HARDWARE_FAILURE );
  162. case MBEDTLS_ERR_CHACHA20_BAD_INPUT_DATA:
  163. return( PSA_ERROR_INVALID_ARGUMENT );
  164. case MBEDTLS_ERR_CHACHAPOLY_BAD_STATE:
  165. return( PSA_ERROR_BAD_STATE );
  166. case MBEDTLS_ERR_CHACHAPOLY_AUTH_FAILED:
  167. return( PSA_ERROR_INVALID_SIGNATURE );
  168. case MBEDTLS_ERR_CIPHER_FEATURE_UNAVAILABLE:
  169. return( PSA_ERROR_NOT_SUPPORTED );
  170. case MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA:
  171. return( PSA_ERROR_INVALID_ARGUMENT );
  172. case MBEDTLS_ERR_CIPHER_ALLOC_FAILED:
  173. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  174. case MBEDTLS_ERR_CIPHER_INVALID_PADDING:
  175. return( PSA_ERROR_INVALID_PADDING );
  176. case MBEDTLS_ERR_CIPHER_FULL_BLOCK_EXPECTED:
  177. return( PSA_ERROR_INVALID_ARGUMENT );
  178. case MBEDTLS_ERR_CIPHER_AUTH_FAILED:
  179. return( PSA_ERROR_INVALID_SIGNATURE );
  180. case MBEDTLS_ERR_CIPHER_INVALID_CONTEXT:
  181. return( PSA_ERROR_CORRUPTION_DETECTED );
  182. case MBEDTLS_ERR_CIPHER_HW_ACCEL_FAILED:
  183. return( PSA_ERROR_HARDWARE_FAILURE );
  184. case MBEDTLS_ERR_CMAC_HW_ACCEL_FAILED:
  185. return( PSA_ERROR_HARDWARE_FAILURE );
  186. #if !( defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) || \
  187. defined(MBEDTLS_PSA_HMAC_DRBG_MD_TYPE) )
  188. /* Only check CTR_DRBG error codes if underlying mbedtls_xxx
  189. * functions are passed a CTR_DRBG instance. */
  190. case MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED:
  191. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  192. case MBEDTLS_ERR_CTR_DRBG_REQUEST_TOO_BIG:
  193. case MBEDTLS_ERR_CTR_DRBG_INPUT_TOO_BIG:
  194. return( PSA_ERROR_NOT_SUPPORTED );
  195. case MBEDTLS_ERR_CTR_DRBG_FILE_IO_ERROR:
  196. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  197. #endif
  198. case MBEDTLS_ERR_DES_INVALID_INPUT_LENGTH:
  199. return( PSA_ERROR_NOT_SUPPORTED );
  200. case MBEDTLS_ERR_DES_HW_ACCEL_FAILED:
  201. return( PSA_ERROR_HARDWARE_FAILURE );
  202. case MBEDTLS_ERR_ENTROPY_NO_SOURCES_DEFINED:
  203. case MBEDTLS_ERR_ENTROPY_NO_STRONG_SOURCE:
  204. case MBEDTLS_ERR_ENTROPY_SOURCE_FAILED:
  205. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  206. case MBEDTLS_ERR_GCM_AUTH_FAILED:
  207. return( PSA_ERROR_INVALID_SIGNATURE );
  208. case MBEDTLS_ERR_GCM_BAD_INPUT:
  209. return( PSA_ERROR_INVALID_ARGUMENT );
  210. case MBEDTLS_ERR_GCM_HW_ACCEL_FAILED:
  211. return( PSA_ERROR_HARDWARE_FAILURE );
  212. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) && \
  213. defined(MBEDTLS_PSA_HMAC_DRBG_MD_TYPE)
  214. /* Only check HMAC_DRBG error codes if underlying mbedtls_xxx
  215. * functions are passed a HMAC_DRBG instance. */
  216. case MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED:
  217. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  218. case MBEDTLS_ERR_HMAC_DRBG_REQUEST_TOO_BIG:
  219. case MBEDTLS_ERR_HMAC_DRBG_INPUT_TOO_BIG:
  220. return( PSA_ERROR_NOT_SUPPORTED );
  221. case MBEDTLS_ERR_HMAC_DRBG_FILE_IO_ERROR:
  222. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  223. #endif
  224. case MBEDTLS_ERR_MD2_HW_ACCEL_FAILED:
  225. case MBEDTLS_ERR_MD4_HW_ACCEL_FAILED:
  226. case MBEDTLS_ERR_MD5_HW_ACCEL_FAILED:
  227. return( PSA_ERROR_HARDWARE_FAILURE );
  228. case MBEDTLS_ERR_MD_FEATURE_UNAVAILABLE:
  229. return( PSA_ERROR_NOT_SUPPORTED );
  230. case MBEDTLS_ERR_MD_BAD_INPUT_DATA:
  231. return( PSA_ERROR_INVALID_ARGUMENT );
  232. case MBEDTLS_ERR_MD_ALLOC_FAILED:
  233. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  234. case MBEDTLS_ERR_MD_FILE_IO_ERROR:
  235. return( PSA_ERROR_STORAGE_FAILURE );
  236. case MBEDTLS_ERR_MD_HW_ACCEL_FAILED:
  237. return( PSA_ERROR_HARDWARE_FAILURE );
  238. case MBEDTLS_ERR_MPI_FILE_IO_ERROR:
  239. return( PSA_ERROR_STORAGE_FAILURE );
  240. case MBEDTLS_ERR_MPI_BAD_INPUT_DATA:
  241. return( PSA_ERROR_INVALID_ARGUMENT );
  242. case MBEDTLS_ERR_MPI_INVALID_CHARACTER:
  243. return( PSA_ERROR_INVALID_ARGUMENT );
  244. case MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL:
  245. return( PSA_ERROR_BUFFER_TOO_SMALL );
  246. case MBEDTLS_ERR_MPI_NEGATIVE_VALUE:
  247. return( PSA_ERROR_INVALID_ARGUMENT );
  248. case MBEDTLS_ERR_MPI_DIVISION_BY_ZERO:
  249. return( PSA_ERROR_INVALID_ARGUMENT );
  250. case MBEDTLS_ERR_MPI_NOT_ACCEPTABLE:
  251. return( PSA_ERROR_INVALID_ARGUMENT );
  252. case MBEDTLS_ERR_MPI_ALLOC_FAILED:
  253. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  254. case MBEDTLS_ERR_PK_ALLOC_FAILED:
  255. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  256. case MBEDTLS_ERR_PK_TYPE_MISMATCH:
  257. case MBEDTLS_ERR_PK_BAD_INPUT_DATA:
  258. return( PSA_ERROR_INVALID_ARGUMENT );
  259. case MBEDTLS_ERR_PK_FILE_IO_ERROR:
  260. return( PSA_ERROR_STORAGE_FAILURE );
  261. case MBEDTLS_ERR_PK_KEY_INVALID_VERSION:
  262. case MBEDTLS_ERR_PK_KEY_INVALID_FORMAT:
  263. return( PSA_ERROR_INVALID_ARGUMENT );
  264. case MBEDTLS_ERR_PK_UNKNOWN_PK_ALG:
  265. return( PSA_ERROR_NOT_SUPPORTED );
  266. case MBEDTLS_ERR_PK_PASSWORD_REQUIRED:
  267. case MBEDTLS_ERR_PK_PASSWORD_MISMATCH:
  268. return( PSA_ERROR_NOT_PERMITTED );
  269. case MBEDTLS_ERR_PK_INVALID_PUBKEY:
  270. return( PSA_ERROR_INVALID_ARGUMENT );
  271. case MBEDTLS_ERR_PK_INVALID_ALG:
  272. case MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE:
  273. case MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE:
  274. return( PSA_ERROR_NOT_SUPPORTED );
  275. case MBEDTLS_ERR_PK_SIG_LEN_MISMATCH:
  276. return( PSA_ERROR_INVALID_SIGNATURE );
  277. case MBEDTLS_ERR_PK_HW_ACCEL_FAILED:
  278. return( PSA_ERROR_HARDWARE_FAILURE );
  279. case MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED:
  280. return( PSA_ERROR_HARDWARE_FAILURE );
  281. case MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED:
  282. return( PSA_ERROR_NOT_SUPPORTED );
  283. case MBEDTLS_ERR_RIPEMD160_HW_ACCEL_FAILED:
  284. return( PSA_ERROR_HARDWARE_FAILURE );
  285. case MBEDTLS_ERR_RSA_BAD_INPUT_DATA:
  286. return( PSA_ERROR_INVALID_ARGUMENT );
  287. case MBEDTLS_ERR_RSA_INVALID_PADDING:
  288. return( PSA_ERROR_INVALID_PADDING );
  289. case MBEDTLS_ERR_RSA_KEY_GEN_FAILED:
  290. return( PSA_ERROR_HARDWARE_FAILURE );
  291. case MBEDTLS_ERR_RSA_KEY_CHECK_FAILED:
  292. return( PSA_ERROR_INVALID_ARGUMENT );
  293. case MBEDTLS_ERR_RSA_PUBLIC_FAILED:
  294. case MBEDTLS_ERR_RSA_PRIVATE_FAILED:
  295. return( PSA_ERROR_CORRUPTION_DETECTED );
  296. case MBEDTLS_ERR_RSA_VERIFY_FAILED:
  297. return( PSA_ERROR_INVALID_SIGNATURE );
  298. case MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE:
  299. return( PSA_ERROR_BUFFER_TOO_SMALL );
  300. case MBEDTLS_ERR_RSA_RNG_FAILED:
  301. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  302. case MBEDTLS_ERR_RSA_UNSUPPORTED_OPERATION:
  303. return( PSA_ERROR_NOT_SUPPORTED );
  304. case MBEDTLS_ERR_RSA_HW_ACCEL_FAILED:
  305. return( PSA_ERROR_HARDWARE_FAILURE );
  306. case MBEDTLS_ERR_SHA1_HW_ACCEL_FAILED:
  307. case MBEDTLS_ERR_SHA256_HW_ACCEL_FAILED:
  308. case MBEDTLS_ERR_SHA512_HW_ACCEL_FAILED:
  309. return( PSA_ERROR_HARDWARE_FAILURE );
  310. case MBEDTLS_ERR_XTEA_INVALID_INPUT_LENGTH:
  311. return( PSA_ERROR_INVALID_ARGUMENT );
  312. case MBEDTLS_ERR_XTEA_HW_ACCEL_FAILED:
  313. return( PSA_ERROR_HARDWARE_FAILURE );
  314. case MBEDTLS_ERR_ECP_BAD_INPUT_DATA:
  315. case MBEDTLS_ERR_ECP_INVALID_KEY:
  316. return( PSA_ERROR_INVALID_ARGUMENT );
  317. case MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL:
  318. return( PSA_ERROR_BUFFER_TOO_SMALL );
  319. case MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE:
  320. return( PSA_ERROR_NOT_SUPPORTED );
  321. case MBEDTLS_ERR_ECP_SIG_LEN_MISMATCH:
  322. case MBEDTLS_ERR_ECP_VERIFY_FAILED:
  323. return( PSA_ERROR_INVALID_SIGNATURE );
  324. case MBEDTLS_ERR_ECP_ALLOC_FAILED:
  325. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  326. case MBEDTLS_ERR_ECP_RANDOM_FAILED:
  327. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  328. case MBEDTLS_ERR_ECP_HW_ACCEL_FAILED:
  329. return( PSA_ERROR_HARDWARE_FAILURE );
  330. case MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED:
  331. return( PSA_ERROR_CORRUPTION_DETECTED );
  332. default:
  333. return( PSA_ERROR_GENERIC_ERROR );
  334. }
  335. }
  336. /****************************************************************/
  337. /* Key management */
  338. /****************************************************************/
  339. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  340. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) || \
  341. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  342. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) || \
  343. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  344. mbedtls_ecp_group_id mbedtls_ecc_group_of_psa( psa_ecc_family_t curve,
  345. size_t bits,
  346. int bits_is_sloppy )
  347. {
  348. switch( curve )
  349. {
  350. case PSA_ECC_FAMILY_SECP_R1:
  351. switch( bits )
  352. {
  353. #if defined(PSA_WANT_ECC_SECP_R1_192)
  354. case 192:
  355. return( MBEDTLS_ECP_DP_SECP192R1 );
  356. #endif
  357. #if defined(PSA_WANT_ECC_SECP_R1_224)
  358. case 224:
  359. return( MBEDTLS_ECP_DP_SECP224R1 );
  360. #endif
  361. #if defined(PSA_WANT_ECC_SECP_R1_256)
  362. case 256:
  363. return( MBEDTLS_ECP_DP_SECP256R1 );
  364. #endif
  365. #if defined(PSA_WANT_ECC_SECP_R1_384)
  366. case 384:
  367. return( MBEDTLS_ECP_DP_SECP384R1 );
  368. #endif
  369. #if defined(PSA_WANT_ECC_SECP_R1_521)
  370. case 521:
  371. return( MBEDTLS_ECP_DP_SECP521R1 );
  372. case 528:
  373. if( bits_is_sloppy )
  374. return( MBEDTLS_ECP_DP_SECP521R1 );
  375. break;
  376. #endif
  377. }
  378. break;
  379. case PSA_ECC_FAMILY_BRAINPOOL_P_R1:
  380. switch( bits )
  381. {
  382. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_256)
  383. case 256:
  384. return( MBEDTLS_ECP_DP_BP256R1 );
  385. #endif
  386. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_384)
  387. case 384:
  388. return( MBEDTLS_ECP_DP_BP384R1 );
  389. #endif
  390. #if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_512)
  391. case 512:
  392. return( MBEDTLS_ECP_DP_BP512R1 );
  393. #endif
  394. }
  395. break;
  396. case PSA_ECC_FAMILY_MONTGOMERY:
  397. switch( bits )
  398. {
  399. #if defined(PSA_WANT_ECC_MONTGOMERY_255)
  400. case 255:
  401. return( MBEDTLS_ECP_DP_CURVE25519 );
  402. case 256:
  403. if( bits_is_sloppy )
  404. return( MBEDTLS_ECP_DP_CURVE25519 );
  405. break;
  406. #endif
  407. #if defined(PSA_WANT_ECC_MONTGOMERY_448)
  408. case 448:
  409. return( MBEDTLS_ECP_DP_CURVE448 );
  410. #endif
  411. }
  412. break;
  413. case PSA_ECC_FAMILY_SECP_K1:
  414. switch( bits )
  415. {
  416. #if defined(PSA_WANT_ECC_SECP_K1_192)
  417. case 192:
  418. return( MBEDTLS_ECP_DP_SECP192K1 );
  419. #endif
  420. #if defined(PSA_WANT_ECC_SECP_K1_224)
  421. case 224:
  422. return( MBEDTLS_ECP_DP_SECP224K1 );
  423. #endif
  424. #if defined(PSA_WANT_ECC_SECP_K1_256)
  425. case 256:
  426. return( MBEDTLS_ECP_DP_SECP256K1 );
  427. #endif
  428. }
  429. break;
  430. }
  431. (void) bits_is_sloppy;
  432. return( MBEDTLS_ECP_DP_NONE );
  433. }
  434. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  435. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) ||
  436. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  437. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) ||
  438. defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH) */
  439. static psa_status_t validate_unstructured_key_bit_size( psa_key_type_t type,
  440. size_t bits )
  441. {
  442. /* Check that the bit size is acceptable for the key type */
  443. switch( type )
  444. {
  445. case PSA_KEY_TYPE_RAW_DATA:
  446. case PSA_KEY_TYPE_HMAC:
  447. case PSA_KEY_TYPE_DERIVE:
  448. break;
  449. #if defined(PSA_WANT_KEY_TYPE_AES)
  450. case PSA_KEY_TYPE_AES:
  451. if( bits != 128 && bits != 192 && bits != 256 )
  452. return( PSA_ERROR_INVALID_ARGUMENT );
  453. break;
  454. #endif
  455. #if defined(PSA_WANT_KEY_TYPE_ARIA)
  456. case PSA_KEY_TYPE_ARIA:
  457. if( bits != 128 && bits != 192 && bits != 256 )
  458. return( PSA_ERROR_INVALID_ARGUMENT );
  459. break;
  460. #endif
  461. #if defined(PSA_WANT_KEY_TYPE_CAMELLIA)
  462. case PSA_KEY_TYPE_CAMELLIA:
  463. if( bits != 128 && bits != 192 && bits != 256 )
  464. return( PSA_ERROR_INVALID_ARGUMENT );
  465. break;
  466. #endif
  467. #if defined(PSA_WANT_KEY_TYPE_DES)
  468. case PSA_KEY_TYPE_DES:
  469. if( bits != 64 && bits != 128 && bits != 192 )
  470. return( PSA_ERROR_INVALID_ARGUMENT );
  471. break;
  472. #endif
  473. #if defined(PSA_WANT_KEY_TYPE_ARC4)
  474. case PSA_KEY_TYPE_ARC4:
  475. if( bits < 8 || bits > 2048 )
  476. return( PSA_ERROR_INVALID_ARGUMENT );
  477. break;
  478. #endif
  479. #if defined(PSA_WANT_KEY_TYPE_CHACHA20)
  480. case PSA_KEY_TYPE_CHACHA20:
  481. if( bits != 256 )
  482. return( PSA_ERROR_INVALID_ARGUMENT );
  483. break;
  484. #endif
  485. default:
  486. return( PSA_ERROR_NOT_SUPPORTED );
  487. }
  488. if( bits % 8 != 0 )
  489. return( PSA_ERROR_INVALID_ARGUMENT );
  490. return( PSA_SUCCESS );
  491. }
  492. /** Check whether a given key type is valid for use with a given MAC algorithm
  493. *
  494. * Upon successful return of this function, the behavior of #PSA_MAC_LENGTH
  495. * when called with the validated \p algorithm and \p key_type is well-defined.
  496. *
  497. * \param[in] algorithm The specific MAC algorithm (can be wildcard).
  498. * \param[in] key_type The key type of the key to be used with the
  499. * \p algorithm.
  500. *
  501. * \retval #PSA_SUCCESS
  502. * The \p key_type is valid for use with the \p algorithm
  503. * \retval #PSA_ERROR_INVALID_ARGUMENT
  504. * The \p key_type is not valid for use with the \p algorithm
  505. */
  506. MBEDTLS_STATIC_TESTABLE psa_status_t psa_mac_key_can_do(
  507. psa_algorithm_t algorithm,
  508. psa_key_type_t key_type )
  509. {
  510. if( PSA_ALG_IS_HMAC( algorithm ) )
  511. {
  512. if( key_type == PSA_KEY_TYPE_HMAC )
  513. return( PSA_SUCCESS );
  514. }
  515. if( PSA_ALG_IS_BLOCK_CIPHER_MAC( algorithm ) )
  516. {
  517. /* Check that we're calling PSA_BLOCK_CIPHER_BLOCK_LENGTH with a cipher
  518. * key. */
  519. if( ( key_type & PSA_KEY_TYPE_CATEGORY_MASK ) ==
  520. PSA_KEY_TYPE_CATEGORY_SYMMETRIC )
  521. {
  522. /* PSA_BLOCK_CIPHER_BLOCK_LENGTH returns 1 for stream ciphers and
  523. * the block length (larger than 1) for block ciphers. */
  524. if( PSA_BLOCK_CIPHER_BLOCK_LENGTH( key_type ) > 1 )
  525. return( PSA_SUCCESS );
  526. }
  527. }
  528. return( PSA_ERROR_INVALID_ARGUMENT );
  529. }
  530. psa_status_t psa_allocate_buffer_to_slot( psa_key_slot_t *slot,
  531. size_t buffer_length )
  532. {
  533. if( slot->key.data != NULL )
  534. return( PSA_ERROR_ALREADY_EXISTS );
  535. slot->key.data = mbedtls_calloc( 1, buffer_length );
  536. if( slot->key.data == NULL )
  537. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  538. slot->key.bytes = buffer_length;
  539. return( PSA_SUCCESS );
  540. }
  541. psa_status_t psa_copy_key_material_into_slot( psa_key_slot_t *slot,
  542. const uint8_t* data,
  543. size_t data_length )
  544. {
  545. psa_status_t status = psa_allocate_buffer_to_slot( slot,
  546. data_length );
  547. if( status != PSA_SUCCESS )
  548. return( status );
  549. memcpy( slot->key.data, data, data_length );
  550. return( PSA_SUCCESS );
  551. }
  552. psa_status_t psa_import_key_into_slot(
  553. const psa_key_attributes_t *attributes,
  554. const uint8_t *data, size_t data_length,
  555. uint8_t *key_buffer, size_t key_buffer_size,
  556. size_t *key_buffer_length, size_t *bits )
  557. {
  558. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  559. psa_key_type_t type = attributes->core.type;
  560. /* zero-length keys are never supported. */
  561. if( data_length == 0 )
  562. return( PSA_ERROR_NOT_SUPPORTED );
  563. if( key_type_is_raw_bytes( type ) )
  564. {
  565. *bits = PSA_BYTES_TO_BITS( data_length );
  566. /* Ensure that the bytes-to-bits conversion hasn't overflown. */
  567. if( data_length > SIZE_MAX / 8 )
  568. return( PSA_ERROR_NOT_SUPPORTED );
  569. /* Enforce a size limit, and in particular ensure that the bit
  570. * size fits in its representation type. */
  571. if( ( *bits ) > PSA_MAX_KEY_BITS )
  572. return( PSA_ERROR_NOT_SUPPORTED );
  573. status = validate_unstructured_key_bit_size( type, *bits );
  574. if( status != PSA_SUCCESS )
  575. return( status );
  576. /* Copy the key material. */
  577. memcpy( key_buffer, data, data_length );
  578. *key_buffer_length = data_length;
  579. (void)key_buffer_size;
  580. return( PSA_SUCCESS );
  581. }
  582. else if( PSA_KEY_TYPE_IS_ASYMMETRIC( type ) )
  583. {
  584. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  585. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY)
  586. if( PSA_KEY_TYPE_IS_ECC( type ) )
  587. {
  588. return( mbedtls_psa_ecp_import_key( attributes,
  589. data, data_length,
  590. key_buffer, key_buffer_size,
  591. key_buffer_length,
  592. bits ) );
  593. }
  594. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  595. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) */
  596. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  597. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  598. if( PSA_KEY_TYPE_IS_RSA( type ) )
  599. {
  600. return( mbedtls_psa_rsa_import_key( attributes,
  601. data, data_length,
  602. key_buffer, key_buffer_size,
  603. key_buffer_length,
  604. bits ) );
  605. }
  606. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  607. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  608. }
  609. return( PSA_ERROR_NOT_SUPPORTED );
  610. }
  611. /** Calculate the intersection of two algorithm usage policies.
  612. *
  613. * Return 0 (which allows no operation) on incompatibility.
  614. */
  615. static psa_algorithm_t psa_key_policy_algorithm_intersection(
  616. psa_key_type_t key_type,
  617. psa_algorithm_t alg1,
  618. psa_algorithm_t alg2 )
  619. {
  620. /* Common case: both sides actually specify the same policy. */
  621. if( alg1 == alg2 )
  622. return( alg1 );
  623. /* If the policies are from the same hash-and-sign family, check
  624. * if one is a wildcard. If so the other has the specific algorithm. */
  625. if( PSA_ALG_IS_SIGN_HASH( alg1 ) &&
  626. PSA_ALG_IS_SIGN_HASH( alg2 ) &&
  627. ( alg1 & ~PSA_ALG_HASH_MASK ) == ( alg2 & ~PSA_ALG_HASH_MASK ) )
  628. {
  629. if( PSA_ALG_SIGN_GET_HASH( alg1 ) == PSA_ALG_ANY_HASH )
  630. return( alg2 );
  631. if( PSA_ALG_SIGN_GET_HASH( alg2 ) == PSA_ALG_ANY_HASH )
  632. return( alg1 );
  633. }
  634. /* If the policies are from the same AEAD family, check whether
  635. * one of them is a minimum-tag-length wildcard. Calculate the most
  636. * restrictive tag length. */
  637. if( PSA_ALG_IS_AEAD( alg1 ) && PSA_ALG_IS_AEAD( alg2 ) &&
  638. ( PSA_ALG_AEAD_WITH_SHORTENED_TAG( alg1, 0 ) ==
  639. PSA_ALG_AEAD_WITH_SHORTENED_TAG( alg2, 0 ) ) )
  640. {
  641. size_t alg1_len = PSA_ALG_AEAD_GET_TAG_LENGTH( alg1 );
  642. size_t alg2_len = PSA_ALG_AEAD_GET_TAG_LENGTH( alg2 );
  643. size_t restricted_len = alg1_len > alg2_len ? alg1_len : alg2_len;
  644. /* If both are wildcards, return most restrictive wildcard */
  645. if( ( ( alg1 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  646. ( ( alg2 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) )
  647. {
  648. return( PSA_ALG_AEAD_WITH_AT_LEAST_THIS_LENGTH_TAG(
  649. alg1, restricted_len ) );
  650. }
  651. /* If only one is a wildcard, return specific algorithm if compatible. */
  652. if( ( ( alg1 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  653. ( alg1_len <= alg2_len ) )
  654. {
  655. return( alg2 );
  656. }
  657. if( ( ( alg2 & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  658. ( alg2_len <= alg1_len ) )
  659. {
  660. return( alg1 );
  661. }
  662. }
  663. /* If the policies are from the same MAC family, check whether one
  664. * of them is a minimum-MAC-length policy. Calculate the most
  665. * restrictive tag length. */
  666. if( PSA_ALG_IS_MAC( alg1 ) && PSA_ALG_IS_MAC( alg2 ) &&
  667. ( PSA_ALG_FULL_LENGTH_MAC( alg1 ) ==
  668. PSA_ALG_FULL_LENGTH_MAC( alg2 ) ) )
  669. {
  670. /* Validate the combination of key type and algorithm. Since the base
  671. * algorithm of alg1 and alg2 are the same, we only need this once. */
  672. if( PSA_SUCCESS != psa_mac_key_can_do( alg1, key_type ) )
  673. return( 0 );
  674. /* Get the (exact or at-least) output lengths for both sides of the
  675. * requested intersection. None of the currently supported algorithms
  676. * have an output length dependent on the actual key size, so setting it
  677. * to a bogus value of 0 is currently OK.
  678. *
  679. * Note that for at-least-this-length wildcard algorithms, the output
  680. * length is set to the shortest allowed length, which allows us to
  681. * calculate the most restrictive tag length for the intersection. */
  682. size_t alg1_len = PSA_MAC_LENGTH( key_type, 0, alg1 );
  683. size_t alg2_len = PSA_MAC_LENGTH( key_type, 0, alg2 );
  684. size_t restricted_len = alg1_len > alg2_len ? alg1_len : alg2_len;
  685. /* If both are wildcards, return most restrictive wildcard */
  686. if( ( ( alg1 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) &&
  687. ( ( alg2 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) )
  688. {
  689. return( PSA_ALG_AT_LEAST_THIS_LENGTH_MAC( alg1, restricted_len ) );
  690. }
  691. /* If only one is an at-least-this-length policy, the intersection would
  692. * be the other (fixed-length) policy as long as said fixed length is
  693. * equal to or larger than the shortest allowed length. */
  694. if( ( alg1 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 )
  695. {
  696. return( ( alg1_len <= alg2_len ) ? alg2 : 0 );
  697. }
  698. if( ( alg2 & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 )
  699. {
  700. return( ( alg2_len <= alg1_len ) ? alg1 : 0 );
  701. }
  702. /* If none of them are wildcards, check whether they define the same tag
  703. * length. This is still possible here when one is default-length and
  704. * the other specific-length. Ensure to always return the
  705. * specific-length version for the intersection. */
  706. if( alg1_len == alg2_len )
  707. return( PSA_ALG_TRUNCATED_MAC( alg1, alg1_len ) );
  708. }
  709. /* If the policies are incompatible, allow nothing. */
  710. return( 0 );
  711. }
  712. static int psa_key_algorithm_permits( psa_key_type_t key_type,
  713. psa_algorithm_t policy_alg,
  714. psa_algorithm_t requested_alg )
  715. {
  716. /* Common case: the policy only allows requested_alg. */
  717. if( requested_alg == policy_alg )
  718. return( 1 );
  719. /* If policy_alg is a hash-and-sign with a wildcard for the hash,
  720. * and requested_alg is the same hash-and-sign family with any hash,
  721. * then requested_alg is compliant with policy_alg. */
  722. if( PSA_ALG_IS_SIGN_HASH( requested_alg ) &&
  723. PSA_ALG_SIGN_GET_HASH( policy_alg ) == PSA_ALG_ANY_HASH )
  724. {
  725. return( ( policy_alg & ~PSA_ALG_HASH_MASK ) ==
  726. ( requested_alg & ~PSA_ALG_HASH_MASK ) );
  727. }
  728. /* If policy_alg is a wildcard AEAD algorithm of the same base as
  729. * the requested algorithm, check the requested tag length to be
  730. * equal-length or longer than the wildcard-specified length. */
  731. if( PSA_ALG_IS_AEAD( policy_alg ) &&
  732. PSA_ALG_IS_AEAD( requested_alg ) &&
  733. ( PSA_ALG_AEAD_WITH_SHORTENED_TAG( policy_alg, 0 ) ==
  734. PSA_ALG_AEAD_WITH_SHORTENED_TAG( requested_alg, 0 ) ) &&
  735. ( ( policy_alg & PSA_ALG_AEAD_AT_LEAST_THIS_LENGTH_FLAG ) != 0 ) )
  736. {
  737. return( PSA_ALG_AEAD_GET_TAG_LENGTH( policy_alg ) <=
  738. PSA_ALG_AEAD_GET_TAG_LENGTH( requested_alg ) );
  739. }
  740. /* If policy_alg is a MAC algorithm of the same base as the requested
  741. * algorithm, check whether their MAC lengths are compatible. */
  742. if( PSA_ALG_IS_MAC( policy_alg ) &&
  743. PSA_ALG_IS_MAC( requested_alg ) &&
  744. ( PSA_ALG_FULL_LENGTH_MAC( policy_alg ) ==
  745. PSA_ALG_FULL_LENGTH_MAC( requested_alg ) ) )
  746. {
  747. /* Validate the combination of key type and algorithm. Since the policy
  748. * and requested algorithms are the same, we only need this once. */
  749. if( PSA_SUCCESS != psa_mac_key_can_do( policy_alg, key_type ) )
  750. return( 0 );
  751. /* Get both the requested output length for the algorithm which is to be
  752. * verified, and the default output length for the base algorithm.
  753. * Note that none of the currently supported algorithms have an output
  754. * length dependent on actual key size, so setting it to a bogus value
  755. * of 0 is currently OK. */
  756. size_t requested_output_length = PSA_MAC_LENGTH(
  757. key_type, 0, requested_alg );
  758. size_t default_output_length = PSA_MAC_LENGTH(
  759. key_type, 0,
  760. PSA_ALG_FULL_LENGTH_MAC( requested_alg ) );
  761. /* If the policy is default-length, only allow an algorithm with
  762. * a declared exact-length matching the default. */
  763. if( PSA_MAC_TRUNCATED_LENGTH( policy_alg ) == 0 )
  764. return( requested_output_length == default_output_length );
  765. /* If the requested algorithm is default-length, allow it if the policy
  766. * length exactly matches the default length. */
  767. if( PSA_MAC_TRUNCATED_LENGTH( requested_alg ) == 0 &&
  768. PSA_MAC_TRUNCATED_LENGTH( policy_alg ) == default_output_length )
  769. {
  770. return( 1 );
  771. }
  772. /* If policy_alg is an at-least-this-length wildcard MAC algorithm,
  773. * check for the requested MAC length to be equal to or longer than the
  774. * minimum allowed length. */
  775. if( ( policy_alg & PSA_ALG_MAC_AT_LEAST_THIS_LENGTH_FLAG ) != 0 )
  776. {
  777. return( PSA_MAC_TRUNCATED_LENGTH( policy_alg ) <=
  778. requested_output_length );
  779. }
  780. }
  781. /* If policy_alg is a generic key agreement operation, then using it for
  782. * a key derivation with that key agreement should also be allowed. This
  783. * behaviour is expected to be defined in a future specification version. */
  784. if( PSA_ALG_IS_RAW_KEY_AGREEMENT( policy_alg ) &&
  785. PSA_ALG_IS_KEY_AGREEMENT( requested_alg ) )
  786. {
  787. return( PSA_ALG_KEY_AGREEMENT_GET_BASE( requested_alg ) ==
  788. policy_alg );
  789. }
  790. /* If it isn't explicitly permitted, it's forbidden. */
  791. return( 0 );
  792. }
  793. /** Test whether a policy permits an algorithm.
  794. *
  795. * The caller must test usage flags separately.
  796. *
  797. * \note This function requires providing the key type for which the policy is
  798. * being validated, since some algorithm policy definitions (e.g. MAC)
  799. * have different properties depending on what kind of cipher it is
  800. * combined with.
  801. *
  802. * \retval PSA_SUCCESS When \p alg is a specific algorithm
  803. * allowed by the \p policy.
  804. * \retval PSA_ERROR_INVALID_ARGUMENT When \p alg is not a specific algorithm
  805. * \retval PSA_ERROR_NOT_PERMITTED When \p alg is a specific algorithm, but
  806. * the \p policy does not allow it.
  807. */
  808. static psa_status_t psa_key_policy_permits( const psa_key_policy_t *policy,
  809. psa_key_type_t key_type,
  810. psa_algorithm_t alg )
  811. {
  812. /* '0' is not a valid algorithm */
  813. if( alg == 0 )
  814. return( PSA_ERROR_INVALID_ARGUMENT );
  815. /* A requested algorithm cannot be a wildcard. */
  816. if( PSA_ALG_IS_WILDCARD( alg ) )
  817. return( PSA_ERROR_INVALID_ARGUMENT );
  818. if( psa_key_algorithm_permits( key_type, policy->alg, alg ) ||
  819. psa_key_algorithm_permits( key_type, policy->alg2, alg ) )
  820. return( PSA_SUCCESS );
  821. else
  822. return( PSA_ERROR_NOT_PERMITTED );
  823. }
  824. /** Restrict a key policy based on a constraint.
  825. *
  826. * \note This function requires providing the key type for which the policy is
  827. * being restricted, since some algorithm policy definitions (e.g. MAC)
  828. * have different properties depending on what kind of cipher it is
  829. * combined with.
  830. *
  831. * \param[in] key_type The key type for which to restrict the policy
  832. * \param[in,out] policy The policy to restrict.
  833. * \param[in] constraint The policy constraint to apply.
  834. *
  835. * \retval #PSA_SUCCESS
  836. * \c *policy contains the intersection of the original value of
  837. * \c *policy and \c *constraint.
  838. * \retval #PSA_ERROR_INVALID_ARGUMENT
  839. * \c key_type, \c *policy and \c *constraint are incompatible.
  840. * \c *policy is unchanged.
  841. */
  842. static psa_status_t psa_restrict_key_policy(
  843. psa_key_type_t key_type,
  844. psa_key_policy_t *policy,
  845. const psa_key_policy_t *constraint )
  846. {
  847. psa_algorithm_t intersection_alg =
  848. psa_key_policy_algorithm_intersection( key_type, policy->alg,
  849. constraint->alg );
  850. psa_algorithm_t intersection_alg2 =
  851. psa_key_policy_algorithm_intersection( key_type, policy->alg2,
  852. constraint->alg2 );
  853. if( intersection_alg == 0 && policy->alg != 0 && constraint->alg != 0 )
  854. return( PSA_ERROR_INVALID_ARGUMENT );
  855. if( intersection_alg2 == 0 && policy->alg2 != 0 && constraint->alg2 != 0 )
  856. return( PSA_ERROR_INVALID_ARGUMENT );
  857. policy->usage &= constraint->usage;
  858. policy->alg = intersection_alg;
  859. policy->alg2 = intersection_alg2;
  860. return( PSA_SUCCESS );
  861. }
  862. /** Get the description of a key given its identifier and policy constraints
  863. * and lock it.
  864. *
  865. * The key must have allow all the usage flags set in \p usage. If \p alg is
  866. * nonzero, the key must allow operations with this algorithm. If \p alg is
  867. * zero, the algorithm is not checked.
  868. *
  869. * In case of a persistent key, the function loads the description of the key
  870. * into a key slot if not already done.
  871. *
  872. * On success, the returned key slot is locked. It is the responsibility of
  873. * the caller to unlock the key slot when it does not access it anymore.
  874. */
  875. static psa_status_t psa_get_and_lock_key_slot_with_policy(
  876. mbedtls_svc_key_id_t key,
  877. psa_key_slot_t **p_slot,
  878. psa_key_usage_t usage,
  879. psa_algorithm_t alg )
  880. {
  881. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  882. psa_key_slot_t *slot;
  883. status = psa_get_and_lock_key_slot( key, p_slot );
  884. if( status != PSA_SUCCESS )
  885. return( status );
  886. slot = *p_slot;
  887. /* Enforce that usage policy for the key slot contains all the flags
  888. * required by the usage parameter. There is one exception: public
  889. * keys can always be exported, so we treat public key objects as
  890. * if they had the export flag. */
  891. if( PSA_KEY_TYPE_IS_PUBLIC_KEY( slot->attr.type ) )
  892. usage &= ~PSA_KEY_USAGE_EXPORT;
  893. if( ( slot->attr.policy.usage & usage ) != usage )
  894. {
  895. status = PSA_ERROR_NOT_PERMITTED;
  896. goto error;
  897. }
  898. /* Enforce that the usage policy permits the requested algortihm. */
  899. if( alg != 0 )
  900. {
  901. status = psa_key_policy_permits( &slot->attr.policy,
  902. slot->attr.type,
  903. alg );
  904. if( status != PSA_SUCCESS )
  905. goto error;
  906. }
  907. return( PSA_SUCCESS );
  908. error:
  909. *p_slot = NULL;
  910. psa_unlock_key_slot( slot );
  911. return( status );
  912. }
  913. /** Get a key slot containing a transparent key and lock it.
  914. *
  915. * A transparent key is a key for which the key material is directly
  916. * available, as opposed to a key in a secure element and/or to be used
  917. * by a secure element.
  918. *
  919. * This is a temporary function that may be used instead of
  920. * psa_get_and_lock_key_slot_with_policy() when there is no opaque key support
  921. * for a cryptographic operation.
  922. *
  923. * On success, the returned key slot is locked. It is the responsibility of the
  924. * caller to unlock the key slot when it does not access it anymore.
  925. */
  926. static psa_status_t psa_get_and_lock_transparent_key_slot_with_policy(
  927. mbedtls_svc_key_id_t key,
  928. psa_key_slot_t **p_slot,
  929. psa_key_usage_t usage,
  930. psa_algorithm_t alg )
  931. {
  932. psa_status_t status = psa_get_and_lock_key_slot_with_policy( key, p_slot,
  933. usage, alg );
  934. if( status != PSA_SUCCESS )
  935. return( status );
  936. if( psa_key_lifetime_is_external( (*p_slot)->attr.lifetime ) )
  937. {
  938. psa_unlock_key_slot( *p_slot );
  939. *p_slot = NULL;
  940. return( PSA_ERROR_NOT_SUPPORTED );
  941. }
  942. return( PSA_SUCCESS );
  943. }
  944. psa_status_t psa_remove_key_data_from_memory( psa_key_slot_t *slot )
  945. {
  946. /* Data pointer will always be either a valid pointer or NULL in an
  947. * initialized slot, so we can just free it. */
  948. if( slot->key.data != NULL )
  949. mbedtls_platform_zeroize( slot->key.data, slot->key.bytes);
  950. mbedtls_free( slot->key.data );
  951. slot->key.data = NULL;
  952. slot->key.bytes = 0;
  953. return( PSA_SUCCESS );
  954. }
  955. /** Completely wipe a slot in memory, including its policy.
  956. * Persistent storage is not affected. */
  957. psa_status_t psa_wipe_key_slot( psa_key_slot_t *slot )
  958. {
  959. psa_status_t status = psa_remove_key_data_from_memory( slot );
  960. /*
  961. * As the return error code may not be handled in case of multiple errors,
  962. * do our best to report an unexpected lock counter: if available
  963. * call MBEDTLS_PARAM_FAILED that may terminate execution (if called as
  964. * part of the execution of a test suite this will stop the test suite
  965. * execution).
  966. */
  967. if( slot->lock_count != 1 )
  968. {
  969. #ifdef MBEDTLS_CHECK_PARAMS
  970. MBEDTLS_PARAM_FAILED( slot->lock_count == 1 );
  971. #endif
  972. status = PSA_ERROR_CORRUPTION_DETECTED;
  973. }
  974. /* Multipart operations may still be using the key. This is safe
  975. * because all multipart operation objects are independent from
  976. * the key slot: if they need to access the key after the setup
  977. * phase, they have a copy of the key. Note that this means that
  978. * key material can linger until all operations are completed. */
  979. /* At this point, key material and other type-specific content has
  980. * been wiped. Clear remaining metadata. We can call memset and not
  981. * zeroize because the metadata is not particularly sensitive. */
  982. memset( slot, 0, sizeof( *slot ) );
  983. return( status );
  984. }
  985. psa_status_t psa_destroy_key( mbedtls_svc_key_id_t key )
  986. {
  987. psa_key_slot_t *slot;
  988. psa_status_t status; /* status of the last operation */
  989. psa_status_t overall_status = PSA_SUCCESS;
  990. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  991. psa_se_drv_table_entry_t *driver;
  992. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  993. if( mbedtls_svc_key_id_is_null( key ) )
  994. return( PSA_SUCCESS );
  995. /*
  996. * Get the description of the key in a key slot. In case of a persistent
  997. * key, this will load the key description from persistent memory if not
  998. * done yet. We cannot avoid this loading as without it we don't know if
  999. * the key is operated by an SE or not and this information is needed by
  1000. * the current implementation.
  1001. */
  1002. status = psa_get_and_lock_key_slot( key, &slot );
  1003. if( status != PSA_SUCCESS )
  1004. return( status );
  1005. /*
  1006. * If the key slot containing the key description is under access by the
  1007. * library (apart from the present access), the key cannot be destroyed
  1008. * yet. For the time being, just return in error. Eventually (to be
  1009. * implemented), the key should be destroyed when all accesses have
  1010. * stopped.
  1011. */
  1012. if( slot->lock_count > 1 )
  1013. {
  1014. psa_unlock_key_slot( slot );
  1015. return( PSA_ERROR_GENERIC_ERROR );
  1016. }
  1017. if( PSA_KEY_LIFETIME_IS_READ_ONLY( slot->attr.lifetime ) )
  1018. {
  1019. /* Refuse the destruction of a read-only key (which may or may not work
  1020. * if we attempt it, depending on whether the key is merely read-only
  1021. * by policy or actually physically read-only).
  1022. * Just do the best we can, which is to wipe the copy in memory
  1023. * (done in this function's cleanup code). */
  1024. overall_status = PSA_ERROR_NOT_PERMITTED;
  1025. goto exit;
  1026. }
  1027. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1028. driver = psa_get_se_driver_entry( slot->attr.lifetime );
  1029. if( driver != NULL )
  1030. {
  1031. /* For a key in a secure element, we need to do three things:
  1032. * remove the key file in internal storage, destroy the
  1033. * key inside the secure element, and update the driver's
  1034. * persistent data. Start a transaction that will encompass these
  1035. * three actions. */
  1036. psa_crypto_prepare_transaction( PSA_CRYPTO_TRANSACTION_DESTROY_KEY );
  1037. psa_crypto_transaction.key.lifetime = slot->attr.lifetime;
  1038. psa_crypto_transaction.key.slot = psa_key_slot_get_slot_number( slot );
  1039. psa_crypto_transaction.key.id = slot->attr.id;
  1040. status = psa_crypto_save_transaction( );
  1041. if( status != PSA_SUCCESS )
  1042. {
  1043. (void) psa_crypto_stop_transaction( );
  1044. /* We should still try to destroy the key in the secure
  1045. * element and the key metadata in storage. This is especially
  1046. * important if the error is that the storage is full.
  1047. * But how to do it exactly without risking an inconsistent
  1048. * state after a reset?
  1049. * https://github.com/ARMmbed/mbed-crypto/issues/215
  1050. */
  1051. overall_status = status;
  1052. goto exit;
  1053. }
  1054. status = psa_destroy_se_key( driver,
  1055. psa_key_slot_get_slot_number( slot ) );
  1056. if( overall_status == PSA_SUCCESS )
  1057. overall_status = status;
  1058. }
  1059. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1060. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C)
  1061. if( ! PSA_KEY_LIFETIME_IS_VOLATILE( slot->attr.lifetime ) )
  1062. {
  1063. status = psa_destroy_persistent_key( slot->attr.id );
  1064. if( overall_status == PSA_SUCCESS )
  1065. overall_status = status;
  1066. /* TODO: other slots may have a copy of the same key. We should
  1067. * invalidate them.
  1068. * https://github.com/ARMmbed/mbed-crypto/issues/214
  1069. */
  1070. }
  1071. #endif /* defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) */
  1072. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1073. if( driver != NULL )
  1074. {
  1075. status = psa_save_se_persistent_data( driver );
  1076. if( overall_status == PSA_SUCCESS )
  1077. overall_status = status;
  1078. status = psa_crypto_stop_transaction( );
  1079. if( overall_status == PSA_SUCCESS )
  1080. overall_status = status;
  1081. }
  1082. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1083. exit:
  1084. status = psa_wipe_key_slot( slot );
  1085. /* Prioritize CORRUPTION_DETECTED from wiping over a storage error */
  1086. if( status != PSA_SUCCESS )
  1087. overall_status = status;
  1088. return( overall_status );
  1089. }
  1090. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1091. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1092. static psa_status_t psa_get_rsa_public_exponent(
  1093. const mbedtls_rsa_context *rsa,
  1094. psa_key_attributes_t *attributes )
  1095. {
  1096. mbedtls_mpi mpi;
  1097. int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
  1098. uint8_t *buffer = NULL;
  1099. size_t buflen;
  1100. mbedtls_mpi_init( &mpi );
  1101. ret = mbedtls_rsa_export( rsa, NULL, NULL, NULL, NULL, &mpi );
  1102. if( ret != 0 )
  1103. goto exit;
  1104. if( mbedtls_mpi_cmp_int( &mpi, 65537 ) == 0 )
  1105. {
  1106. /* It's the default value, which is reported as an empty string,
  1107. * so there's nothing to do. */
  1108. goto exit;
  1109. }
  1110. buflen = mbedtls_mpi_size( &mpi );
  1111. buffer = mbedtls_calloc( 1, buflen );
  1112. if( buffer == NULL )
  1113. {
  1114. ret = MBEDTLS_ERR_MPI_ALLOC_FAILED;
  1115. goto exit;
  1116. }
  1117. ret = mbedtls_mpi_write_binary( &mpi, buffer, buflen );
  1118. if( ret != 0 )
  1119. goto exit;
  1120. attributes->domain_parameters = buffer;
  1121. attributes->domain_parameters_size = buflen;
  1122. exit:
  1123. mbedtls_mpi_free( &mpi );
  1124. if( ret != 0 )
  1125. mbedtls_free( buffer );
  1126. return( mbedtls_to_psa_error( ret ) );
  1127. }
  1128. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1129. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1130. /** Retrieve all the publicly-accessible attributes of a key.
  1131. */
  1132. psa_status_t psa_get_key_attributes( mbedtls_svc_key_id_t key,
  1133. psa_key_attributes_t *attributes )
  1134. {
  1135. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1136. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1137. psa_key_slot_t *slot;
  1138. psa_reset_key_attributes( attributes );
  1139. status = psa_get_and_lock_key_slot_with_policy( key, &slot, 0, 0 );
  1140. if( status != PSA_SUCCESS )
  1141. return( status );
  1142. attributes->core = slot->attr;
  1143. attributes->core.flags &= ( MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY |
  1144. MBEDTLS_PSA_KA_MASK_DUAL_USE );
  1145. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1146. if( psa_get_se_driver_entry( slot->attr.lifetime ) != NULL )
  1147. psa_set_key_slot_number( attributes,
  1148. psa_key_slot_get_slot_number( slot ) );
  1149. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1150. switch( slot->attr.type )
  1151. {
  1152. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1153. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1154. case PSA_KEY_TYPE_RSA_KEY_PAIR:
  1155. case PSA_KEY_TYPE_RSA_PUBLIC_KEY:
  1156. /* TODO: reporting the public exponent for opaque keys
  1157. * is not yet implemented.
  1158. * https://github.com/ARMmbed/mbed-crypto/issues/216
  1159. */
  1160. if( ! psa_key_lifetime_is_external( slot->attr.lifetime ) )
  1161. {
  1162. mbedtls_rsa_context *rsa = NULL;
  1163. status = mbedtls_psa_rsa_load_representation(
  1164. slot->attr.type,
  1165. slot->key.data,
  1166. slot->key.bytes,
  1167. &rsa );
  1168. if( status != PSA_SUCCESS )
  1169. break;
  1170. status = psa_get_rsa_public_exponent( rsa,
  1171. attributes );
  1172. mbedtls_rsa_free( rsa );
  1173. mbedtls_free( rsa );
  1174. }
  1175. break;
  1176. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1177. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1178. default:
  1179. /* Nothing else to do. */
  1180. break;
  1181. }
  1182. if( status != PSA_SUCCESS )
  1183. psa_reset_key_attributes( attributes );
  1184. unlock_status = psa_unlock_key_slot( slot );
  1185. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1186. }
  1187. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1188. psa_status_t psa_get_key_slot_number(
  1189. const psa_key_attributes_t *attributes,
  1190. psa_key_slot_number_t *slot_number )
  1191. {
  1192. if( attributes->core.flags & MBEDTLS_PSA_KA_FLAG_HAS_SLOT_NUMBER )
  1193. {
  1194. *slot_number = attributes->slot_number;
  1195. return( PSA_SUCCESS );
  1196. }
  1197. else
  1198. return( PSA_ERROR_INVALID_ARGUMENT );
  1199. }
  1200. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1201. static psa_status_t psa_export_key_buffer_internal( const uint8_t *key_buffer,
  1202. size_t key_buffer_size,
  1203. uint8_t *data,
  1204. size_t data_size,
  1205. size_t *data_length )
  1206. {
  1207. if( key_buffer_size > data_size )
  1208. return( PSA_ERROR_BUFFER_TOO_SMALL );
  1209. memcpy( data, key_buffer, key_buffer_size );
  1210. memset( data + key_buffer_size, 0,
  1211. data_size - key_buffer_size );
  1212. *data_length = key_buffer_size;
  1213. return( PSA_SUCCESS );
  1214. }
  1215. psa_status_t psa_export_key_internal(
  1216. const psa_key_attributes_t *attributes,
  1217. const uint8_t *key_buffer, size_t key_buffer_size,
  1218. uint8_t *data, size_t data_size, size_t *data_length )
  1219. {
  1220. psa_key_type_t type = attributes->core.type;
  1221. if( key_type_is_raw_bytes( type ) ||
  1222. PSA_KEY_TYPE_IS_RSA( type ) ||
  1223. PSA_KEY_TYPE_IS_ECC( type ) )
  1224. {
  1225. return( psa_export_key_buffer_internal(
  1226. key_buffer, key_buffer_size,
  1227. data, data_size, data_length ) );
  1228. }
  1229. else
  1230. {
  1231. /* This shouldn't happen in the reference implementation, but
  1232. it is valid for a special-purpose implementation to omit
  1233. support for exporting certain key types. */
  1234. return( PSA_ERROR_NOT_SUPPORTED );
  1235. }
  1236. }
  1237. psa_status_t psa_export_key( mbedtls_svc_key_id_t key,
  1238. uint8_t *data,
  1239. size_t data_size,
  1240. size_t *data_length )
  1241. {
  1242. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1243. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1244. psa_key_slot_t *slot;
  1245. /* Reject a zero-length output buffer now, since this can never be a
  1246. * valid key representation. This way we know that data must be a valid
  1247. * pointer and we can do things like memset(data, ..., data_size). */
  1248. if( data_size == 0 )
  1249. return( PSA_ERROR_BUFFER_TOO_SMALL );
  1250. /* Set the key to empty now, so that even when there are errors, we always
  1251. * set data_length to a value between 0 and data_size. On error, setting
  1252. * the key to empty is a good choice because an empty key representation is
  1253. * unlikely to be accepted anywhere. */
  1254. *data_length = 0;
  1255. /* Export requires the EXPORT flag. There is an exception for public keys,
  1256. * which don't require any flag, but
  1257. * psa_get_and_lock_key_slot_with_policy() takes care of this.
  1258. */
  1259. status = psa_get_and_lock_key_slot_with_policy( key, &slot,
  1260. PSA_KEY_USAGE_EXPORT, 0 );
  1261. if( status != PSA_SUCCESS )
  1262. return( status );
  1263. psa_key_attributes_t attributes = {
  1264. .core = slot->attr
  1265. };
  1266. status = psa_driver_wrapper_export_key( &attributes,
  1267. slot->key.data, slot->key.bytes,
  1268. data, data_size, data_length );
  1269. unlock_status = psa_unlock_key_slot( slot );
  1270. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1271. }
  1272. psa_status_t psa_export_public_key_internal(
  1273. const psa_key_attributes_t *attributes,
  1274. const uint8_t *key_buffer,
  1275. size_t key_buffer_size,
  1276. uint8_t *data,
  1277. size_t data_size,
  1278. size_t *data_length )
  1279. {
  1280. psa_key_type_t type = attributes->core.type;
  1281. if( PSA_KEY_TYPE_IS_RSA( type ) || PSA_KEY_TYPE_IS_ECC( type ) )
  1282. {
  1283. if( PSA_KEY_TYPE_IS_PUBLIC_KEY( type ) )
  1284. {
  1285. /* Exporting public -> public */
  1286. return( psa_export_key_buffer_internal(
  1287. key_buffer, key_buffer_size,
  1288. data, data_size, data_length ) );
  1289. }
  1290. if( PSA_KEY_TYPE_IS_RSA( type ) )
  1291. {
  1292. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1293. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1294. return( mbedtls_psa_rsa_export_public_key( attributes,
  1295. key_buffer,
  1296. key_buffer_size,
  1297. data,
  1298. data_size,
  1299. data_length ) );
  1300. #else
  1301. /* We don't know how to convert a private RSA key to public. */
  1302. return( PSA_ERROR_NOT_SUPPORTED );
  1303. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1304. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1305. }
  1306. else
  1307. {
  1308. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) || \
  1309. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY)
  1310. return( mbedtls_psa_ecp_export_public_key( attributes,
  1311. key_buffer,
  1312. key_buffer_size,
  1313. data,
  1314. data_size,
  1315. data_length ) );
  1316. #else
  1317. /* We don't know how to convert a private ECC key to public */
  1318. return( PSA_ERROR_NOT_SUPPORTED );
  1319. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) ||
  1320. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY) */
  1321. }
  1322. }
  1323. else
  1324. {
  1325. /* This shouldn't happen in the reference implementation, but
  1326. it is valid for a special-purpose implementation to omit
  1327. support for exporting certain key types. */
  1328. return( PSA_ERROR_NOT_SUPPORTED );
  1329. }
  1330. }
  1331. psa_status_t psa_export_public_key( mbedtls_svc_key_id_t key,
  1332. uint8_t *data,
  1333. size_t data_size,
  1334. size_t *data_length )
  1335. {
  1336. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1337. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1338. psa_key_slot_t *slot;
  1339. /* Reject a zero-length output buffer now, since this can never be a
  1340. * valid key representation. This way we know that data must be a valid
  1341. * pointer and we can do things like memset(data, ..., data_size). */
  1342. if( data_size == 0 )
  1343. return( PSA_ERROR_BUFFER_TOO_SMALL );
  1344. /* Set the key to empty now, so that even when there are errors, we always
  1345. * set data_length to a value between 0 and data_size. On error, setting
  1346. * the key to empty is a good choice because an empty key representation is
  1347. * unlikely to be accepted anywhere. */
  1348. *data_length = 0;
  1349. /* Exporting a public key doesn't require a usage flag. */
  1350. status = psa_get_and_lock_key_slot_with_policy( key, &slot, 0, 0 );
  1351. if( status != PSA_SUCCESS )
  1352. return( status );
  1353. if( ! PSA_KEY_TYPE_IS_ASYMMETRIC( slot->attr.type ) )
  1354. {
  1355. status = PSA_ERROR_INVALID_ARGUMENT;
  1356. goto exit;
  1357. }
  1358. psa_key_attributes_t attributes = {
  1359. .core = slot->attr
  1360. };
  1361. status = psa_driver_wrapper_export_public_key(
  1362. &attributes, slot->key.data, slot->key.bytes,
  1363. data, data_size, data_length );
  1364. exit:
  1365. unlock_status = psa_unlock_key_slot( slot );
  1366. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1367. }
  1368. #if defined(static_assert)
  1369. static_assert( ( MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_DUAL_USE ) == 0,
  1370. "One or more key attribute flag is listed as both external-only and dual-use" );
  1371. static_assert( ( PSA_KA_MASK_INTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_DUAL_USE ) == 0,
  1372. "One or more key attribute flag is listed as both internal-only and dual-use" );
  1373. static_assert( ( PSA_KA_MASK_INTERNAL_ONLY & MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY ) == 0,
  1374. "One or more key attribute flag is listed as both internal-only and external-only" );
  1375. #endif
  1376. /** Validate that a key policy is internally well-formed.
  1377. *
  1378. * This function only rejects invalid policies. It does not validate the
  1379. * consistency of the policy with respect to other attributes of the key
  1380. * such as the key type.
  1381. */
  1382. static psa_status_t psa_validate_key_policy( const psa_key_policy_t *policy )
  1383. {
  1384. if( ( policy->usage & ~( PSA_KEY_USAGE_EXPORT |
  1385. PSA_KEY_USAGE_COPY |
  1386. PSA_KEY_USAGE_ENCRYPT |
  1387. PSA_KEY_USAGE_DECRYPT |
  1388. PSA_KEY_USAGE_SIGN_MESSAGE |
  1389. PSA_KEY_USAGE_VERIFY_MESSAGE |
  1390. PSA_KEY_USAGE_SIGN_HASH |
  1391. PSA_KEY_USAGE_VERIFY_HASH |
  1392. PSA_KEY_USAGE_DERIVE ) ) != 0 )
  1393. return( PSA_ERROR_INVALID_ARGUMENT );
  1394. return( PSA_SUCCESS );
  1395. }
  1396. /** Validate the internal consistency of key attributes.
  1397. *
  1398. * This function only rejects invalid attribute values. If does not
  1399. * validate the consistency of the attributes with any key data that may
  1400. * be involved in the creation of the key.
  1401. *
  1402. * Call this function early in the key creation process.
  1403. *
  1404. * \param[in] attributes Key attributes for the new key.
  1405. * \param[out] p_drv On any return, the driver for the key, if any.
  1406. * NULL for a transparent key.
  1407. *
  1408. */
  1409. static psa_status_t psa_validate_key_attributes(
  1410. const psa_key_attributes_t *attributes,
  1411. psa_se_drv_table_entry_t **p_drv )
  1412. {
  1413. psa_status_t status = PSA_ERROR_INVALID_ARGUMENT;
  1414. psa_key_lifetime_t lifetime = psa_get_key_lifetime( attributes );
  1415. mbedtls_svc_key_id_t key = psa_get_key_id( attributes );
  1416. status = psa_validate_key_location( lifetime, p_drv );
  1417. if( status != PSA_SUCCESS )
  1418. return( status );
  1419. status = psa_validate_key_persistence( lifetime );
  1420. if( status != PSA_SUCCESS )
  1421. return( status );
  1422. if ( PSA_KEY_LIFETIME_IS_VOLATILE( lifetime ) )
  1423. {
  1424. if( MBEDTLS_SVC_KEY_ID_GET_KEY_ID( key ) != 0 )
  1425. return( PSA_ERROR_INVALID_ARGUMENT );
  1426. }
  1427. else
  1428. {
  1429. if( !psa_is_valid_key_id( psa_get_key_id( attributes ), 0 ) )
  1430. return( PSA_ERROR_INVALID_ARGUMENT );
  1431. }
  1432. status = psa_validate_key_policy( &attributes->core.policy );
  1433. if( status != PSA_SUCCESS )
  1434. return( status );
  1435. /* Refuse to create overly large keys.
  1436. * Note that this doesn't trigger on import if the attributes don't
  1437. * explicitly specify a size (so psa_get_key_bits returns 0), so
  1438. * psa_import_key() needs its own checks. */
  1439. if( psa_get_key_bits( attributes ) > PSA_MAX_KEY_BITS )
  1440. return( PSA_ERROR_NOT_SUPPORTED );
  1441. /* Reject invalid flags. These should not be reachable through the API. */
  1442. if( attributes->core.flags & ~ ( MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY |
  1443. MBEDTLS_PSA_KA_MASK_DUAL_USE ) )
  1444. return( PSA_ERROR_INVALID_ARGUMENT );
  1445. return( PSA_SUCCESS );
  1446. }
  1447. /** Prepare a key slot to receive key material.
  1448. *
  1449. * This function allocates a key slot and sets its metadata.
  1450. *
  1451. * If this function fails, call psa_fail_key_creation().
  1452. *
  1453. * This function is intended to be used as follows:
  1454. * -# Call psa_start_key_creation() to allocate a key slot, prepare
  1455. * it with the specified attributes, and in case of a volatile key assign it
  1456. * a volatile key identifier.
  1457. * -# Populate the slot with the key material.
  1458. * -# Call psa_finish_key_creation() to finalize the creation of the slot.
  1459. * In case of failure at any step, stop the sequence and call
  1460. * psa_fail_key_creation().
  1461. *
  1462. * On success, the key slot is locked. It is the responsibility of the caller
  1463. * to unlock the key slot when it does not access it anymore.
  1464. *
  1465. * \param method An identification of the calling function.
  1466. * \param[in] attributes Key attributes for the new key.
  1467. * \param[out] p_slot On success, a pointer to the prepared slot.
  1468. * \param[out] p_drv On any return, the driver for the key, if any.
  1469. * NULL for a transparent key.
  1470. *
  1471. * \retval #PSA_SUCCESS
  1472. * The key slot is ready to receive key material.
  1473. * \return If this function fails, the key slot is an invalid state.
  1474. * You must call psa_fail_key_creation() to wipe and free the slot.
  1475. */
  1476. static psa_status_t psa_start_key_creation(
  1477. psa_key_creation_method_t method,
  1478. const psa_key_attributes_t *attributes,
  1479. psa_key_slot_t **p_slot,
  1480. psa_se_drv_table_entry_t **p_drv )
  1481. {
  1482. psa_status_t status;
  1483. psa_key_id_t volatile_key_id;
  1484. psa_key_slot_t *slot;
  1485. (void) method;
  1486. *p_drv = NULL;
  1487. status = psa_validate_key_attributes( attributes, p_drv );
  1488. if( status != PSA_SUCCESS )
  1489. return( status );
  1490. status = psa_get_empty_key_slot( &volatile_key_id, p_slot );
  1491. if( status != PSA_SUCCESS )
  1492. return( status );
  1493. slot = *p_slot;
  1494. /* We're storing the declared bit-size of the key. It's up to each
  1495. * creation mechanism to verify that this information is correct.
  1496. * It's automatically correct for mechanisms that use the bit-size as
  1497. * an input (generate, device) but not for those where the bit-size
  1498. * is optional (import, copy). In case of a volatile key, assign it the
  1499. * volatile key identifier associated to the slot returned to contain its
  1500. * definition. */
  1501. slot->attr = attributes->core;
  1502. if( PSA_KEY_LIFETIME_IS_VOLATILE( slot->attr.lifetime ) )
  1503. {
  1504. #if !defined(MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER)
  1505. slot->attr.id = volatile_key_id;
  1506. #else
  1507. slot->attr.id.key_id = volatile_key_id;
  1508. #endif
  1509. }
  1510. /* Erase external-only flags from the internal copy. To access
  1511. * external-only flags, query `attributes`. Thanks to the check
  1512. * in psa_validate_key_attributes(), this leaves the dual-use
  1513. * flags and any internal flag that psa_get_empty_key_slot()
  1514. * may have set. */
  1515. slot->attr.flags &= ~MBEDTLS_PSA_KA_MASK_EXTERNAL_ONLY;
  1516. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1517. /* For a key in a secure element, we need to do three things
  1518. * when creating or registering a persistent key:
  1519. * create the key file in internal storage, create the
  1520. * key inside the secure element, and update the driver's
  1521. * persistent data. This is done by starting a transaction that will
  1522. * encompass these three actions.
  1523. * For registering a volatile key, we just need to find an appropriate
  1524. * slot number inside the SE. Since the key is designated volatile, creating
  1525. * a transaction is not required. */
  1526. /* The first thing to do is to find a slot number for the new key.
  1527. * We save the slot number in persistent storage as part of the
  1528. * transaction data. It will be needed to recover if the power
  1529. * fails during the key creation process, to clean up on the secure
  1530. * element side after restarting. Obtaining a slot number from the
  1531. * secure element driver updates its persistent state, but we do not yet
  1532. * save the driver's persistent state, so that if the power fails,
  1533. * we can roll back to a state where the key doesn't exist. */
  1534. if( *p_drv != NULL )
  1535. {
  1536. psa_key_slot_number_t slot_number;
  1537. status = psa_find_se_slot_for_key( attributes, method, *p_drv,
  1538. &slot_number );
  1539. if( status != PSA_SUCCESS )
  1540. return( status );
  1541. if( ! PSA_KEY_LIFETIME_IS_VOLATILE( attributes->core.lifetime ) )
  1542. {
  1543. psa_crypto_prepare_transaction( PSA_CRYPTO_TRANSACTION_CREATE_KEY );
  1544. psa_crypto_transaction.key.lifetime = slot->attr.lifetime;
  1545. psa_crypto_transaction.key.slot = slot_number;
  1546. psa_crypto_transaction.key.id = slot->attr.id;
  1547. status = psa_crypto_save_transaction( );
  1548. if( status != PSA_SUCCESS )
  1549. {
  1550. (void) psa_crypto_stop_transaction( );
  1551. return( status );
  1552. }
  1553. }
  1554. status = psa_copy_key_material_into_slot(
  1555. slot, (uint8_t *)( &slot_number ), sizeof( slot_number ) );
  1556. }
  1557. if( *p_drv == NULL && method == PSA_KEY_CREATION_REGISTER )
  1558. {
  1559. /* Key registration only makes sense with a secure element. */
  1560. return( PSA_ERROR_INVALID_ARGUMENT );
  1561. }
  1562. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1563. return( PSA_SUCCESS );
  1564. }
  1565. /** Finalize the creation of a key once its key material has been set.
  1566. *
  1567. * This entails writing the key to persistent storage.
  1568. *
  1569. * If this function fails, call psa_fail_key_creation().
  1570. * See the documentation of psa_start_key_creation() for the intended use
  1571. * of this function.
  1572. *
  1573. * If the finalization succeeds, the function unlocks the key slot (it was
  1574. * locked by psa_start_key_creation()) and the key slot cannot be accessed
  1575. * anymore as part of the key creation process.
  1576. *
  1577. * \param[in,out] slot Pointer to the slot with key material.
  1578. * \param[in] driver The secure element driver for the key,
  1579. * or NULL for a transparent key.
  1580. * \param[out] key On success, identifier of the key. Note that the
  1581. * key identifier is also stored in the key slot.
  1582. *
  1583. * \retval #PSA_SUCCESS
  1584. * The key was successfully created.
  1585. * \retval #PSA_ERROR_INSUFFICIENT_MEMORY
  1586. * \retval #PSA_ERROR_INSUFFICIENT_STORAGE
  1587. * \retval #PSA_ERROR_ALREADY_EXISTS
  1588. * \retval #PSA_ERROR_DATA_INVALID
  1589. * \retval #PSA_ERROR_DATA_CORRUPT
  1590. * \retval #PSA_ERROR_STORAGE_FAILURE
  1591. *
  1592. * \return If this function fails, the key slot is an invalid state.
  1593. * You must call psa_fail_key_creation() to wipe and free the slot.
  1594. */
  1595. static psa_status_t psa_finish_key_creation(
  1596. psa_key_slot_t *slot,
  1597. psa_se_drv_table_entry_t *driver,
  1598. mbedtls_svc_key_id_t *key)
  1599. {
  1600. psa_status_t status = PSA_SUCCESS;
  1601. (void) slot;
  1602. (void) driver;
  1603. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C)
  1604. if( ! PSA_KEY_LIFETIME_IS_VOLATILE( slot->attr.lifetime ) )
  1605. {
  1606. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1607. if( driver != NULL )
  1608. {
  1609. psa_se_key_data_storage_t data;
  1610. psa_key_slot_number_t slot_number =
  1611. psa_key_slot_get_slot_number( slot ) ;
  1612. #if defined(static_assert)
  1613. static_assert( sizeof( slot_number ) ==
  1614. sizeof( data.slot_number ),
  1615. "Slot number size does not match psa_se_key_data_storage_t" );
  1616. #endif
  1617. memcpy( &data.slot_number, &slot_number, sizeof( slot_number ) );
  1618. status = psa_save_persistent_key( &slot->attr,
  1619. (uint8_t*) &data,
  1620. sizeof( data ) );
  1621. }
  1622. else
  1623. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1624. {
  1625. /* Key material is saved in export representation in the slot, so
  1626. * just pass the slot buffer for storage. */
  1627. status = psa_save_persistent_key( &slot->attr,
  1628. slot->key.data,
  1629. slot->key.bytes );
  1630. }
  1631. }
  1632. #endif /* defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) */
  1633. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1634. /* Finish the transaction for a key creation. This does not
  1635. * happen when registering an existing key. Detect this case
  1636. * by checking whether a transaction is in progress (actual
  1637. * creation of a persistent key in a secure element requires a transaction,
  1638. * but registration or volatile key creation doesn't use one). */
  1639. if( driver != NULL &&
  1640. psa_crypto_transaction.unknown.type == PSA_CRYPTO_TRANSACTION_CREATE_KEY )
  1641. {
  1642. status = psa_save_se_persistent_data( driver );
  1643. if( status != PSA_SUCCESS )
  1644. {
  1645. psa_destroy_persistent_key( slot->attr.id );
  1646. return( status );
  1647. }
  1648. status = psa_crypto_stop_transaction( );
  1649. }
  1650. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1651. if( status == PSA_SUCCESS )
  1652. {
  1653. *key = slot->attr.id;
  1654. status = psa_unlock_key_slot( slot );
  1655. if( status != PSA_SUCCESS )
  1656. *key = MBEDTLS_SVC_KEY_ID_INIT;
  1657. }
  1658. return( status );
  1659. }
  1660. /** Abort the creation of a key.
  1661. *
  1662. * You may call this function after calling psa_start_key_creation(),
  1663. * or after psa_finish_key_creation() fails. In other circumstances, this
  1664. * function may not clean up persistent storage.
  1665. * See the documentation of psa_start_key_creation() for the intended use
  1666. * of this function.
  1667. *
  1668. * \param[in,out] slot Pointer to the slot with key material.
  1669. * \param[in] driver The secure element driver for the key,
  1670. * or NULL for a transparent key.
  1671. */
  1672. static void psa_fail_key_creation( psa_key_slot_t *slot,
  1673. psa_se_drv_table_entry_t *driver )
  1674. {
  1675. (void) driver;
  1676. if( slot == NULL )
  1677. return;
  1678. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1679. /* TODO: If the key has already been created in the secure
  1680. * element, and the failure happened later (when saving metadata
  1681. * to internal storage), we need to destroy the key in the secure
  1682. * element.
  1683. * https://github.com/ARMmbed/mbed-crypto/issues/217
  1684. */
  1685. /* Abort the ongoing transaction if any (there may not be one if
  1686. * the creation process failed before starting one, or if the
  1687. * key creation is a registration of a key in a secure element).
  1688. * Earlier functions must already have done what it takes to undo any
  1689. * partial creation. All that's left is to update the transaction data
  1690. * itself. */
  1691. (void) psa_crypto_stop_transaction( );
  1692. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1693. psa_wipe_key_slot( slot );
  1694. }
  1695. /** Validate optional attributes during key creation.
  1696. *
  1697. * Some key attributes are optional during key creation. If they are
  1698. * specified in the attributes structure, check that they are consistent
  1699. * with the data in the slot.
  1700. *
  1701. * This function should be called near the end of key creation, after
  1702. * the slot in memory is fully populated but before saving persistent data.
  1703. */
  1704. static psa_status_t psa_validate_optional_attributes(
  1705. const psa_key_slot_t *slot,
  1706. const psa_key_attributes_t *attributes )
  1707. {
  1708. if( attributes->core.type != 0 )
  1709. {
  1710. if( attributes->core.type != slot->attr.type )
  1711. return( PSA_ERROR_INVALID_ARGUMENT );
  1712. }
  1713. if( attributes->domain_parameters_size != 0 )
  1714. {
  1715. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) || \
  1716. defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY)
  1717. if( PSA_KEY_TYPE_IS_RSA( slot->attr.type ) )
  1718. {
  1719. mbedtls_rsa_context *rsa = NULL;
  1720. mbedtls_mpi actual, required;
  1721. int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
  1722. psa_status_t status = mbedtls_psa_rsa_load_representation(
  1723. slot->attr.type,
  1724. slot->key.data,
  1725. slot->key.bytes,
  1726. &rsa );
  1727. if( status != PSA_SUCCESS )
  1728. return( status );
  1729. mbedtls_mpi_init( &actual );
  1730. mbedtls_mpi_init( &required );
  1731. ret = mbedtls_rsa_export( rsa,
  1732. NULL, NULL, NULL, NULL, &actual );
  1733. mbedtls_rsa_free( rsa );
  1734. mbedtls_free( rsa );
  1735. if( ret != 0 )
  1736. goto rsa_exit;
  1737. ret = mbedtls_mpi_read_binary( &required,
  1738. attributes->domain_parameters,
  1739. attributes->domain_parameters_size );
  1740. if( ret != 0 )
  1741. goto rsa_exit;
  1742. if( mbedtls_mpi_cmp_mpi( &actual, &required ) != 0 )
  1743. ret = MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
  1744. rsa_exit:
  1745. mbedtls_mpi_free( &actual );
  1746. mbedtls_mpi_free( &required );
  1747. if( ret != 0)
  1748. return( mbedtls_to_psa_error( ret ) );
  1749. }
  1750. else
  1751. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) ||
  1752. * defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY) */
  1753. {
  1754. return( PSA_ERROR_INVALID_ARGUMENT );
  1755. }
  1756. }
  1757. if( attributes->core.bits != 0 )
  1758. {
  1759. if( attributes->core.bits != slot->attr.bits )
  1760. return( PSA_ERROR_INVALID_ARGUMENT );
  1761. }
  1762. return( PSA_SUCCESS );
  1763. }
  1764. psa_status_t psa_import_key( const psa_key_attributes_t *attributes,
  1765. const uint8_t *data,
  1766. size_t data_length,
  1767. mbedtls_svc_key_id_t *key )
  1768. {
  1769. psa_status_t status;
  1770. psa_key_slot_t *slot = NULL;
  1771. psa_se_drv_table_entry_t *driver = NULL;
  1772. size_t bits;
  1773. *key = MBEDTLS_SVC_KEY_ID_INIT;
  1774. /* Reject zero-length symmetric keys (including raw data key objects).
  1775. * This also rejects any key which might be encoded as an empty string,
  1776. * which is never valid. */
  1777. if( data_length == 0 )
  1778. return( PSA_ERROR_INVALID_ARGUMENT );
  1779. status = psa_start_key_creation( PSA_KEY_CREATION_IMPORT, attributes,
  1780. &slot, &driver );
  1781. if( status != PSA_SUCCESS )
  1782. goto exit;
  1783. /* In the case of a transparent key or an opaque key stored in local
  1784. * storage (thus not in the case of generating a key in a secure element
  1785. * or cryptoprocessor with storage), we have to allocate a buffer to
  1786. * hold the generated key material. */
  1787. if( slot->key.data == NULL )
  1788. {
  1789. status = psa_allocate_buffer_to_slot( slot, data_length );
  1790. if( status != PSA_SUCCESS )
  1791. goto exit;
  1792. }
  1793. bits = slot->attr.bits;
  1794. status = psa_driver_wrapper_import_key( attributes,
  1795. data, data_length,
  1796. slot->key.data,
  1797. slot->key.bytes,
  1798. &slot->key.bytes, &bits );
  1799. if( status != PSA_SUCCESS )
  1800. goto exit;
  1801. if( slot->attr.bits == 0 )
  1802. slot->attr.bits = (psa_key_bits_t) bits;
  1803. else if( bits != slot->attr.bits )
  1804. {
  1805. status = PSA_ERROR_INVALID_ARGUMENT;
  1806. goto exit;
  1807. }
  1808. status = psa_validate_optional_attributes( slot, attributes );
  1809. if( status != PSA_SUCCESS )
  1810. goto exit;
  1811. status = psa_finish_key_creation( slot, driver, key );
  1812. exit:
  1813. if( status != PSA_SUCCESS )
  1814. psa_fail_key_creation( slot, driver );
  1815. return( status );
  1816. }
  1817. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1818. psa_status_t mbedtls_psa_register_se_key(
  1819. const psa_key_attributes_t *attributes )
  1820. {
  1821. psa_status_t status;
  1822. psa_key_slot_t *slot = NULL;
  1823. psa_se_drv_table_entry_t *driver = NULL;
  1824. mbedtls_svc_key_id_t key = MBEDTLS_SVC_KEY_ID_INIT;
  1825. /* Leaving attributes unspecified is not currently supported.
  1826. * It could make sense to query the key type and size from the
  1827. * secure element, but not all secure elements support this
  1828. * and the driver HAL doesn't currently support it. */
  1829. if( psa_get_key_type( attributes ) == PSA_KEY_TYPE_NONE )
  1830. return( PSA_ERROR_NOT_SUPPORTED );
  1831. if( psa_get_key_bits( attributes ) == 0 )
  1832. return( PSA_ERROR_NOT_SUPPORTED );
  1833. status = psa_start_key_creation( PSA_KEY_CREATION_REGISTER, attributes,
  1834. &slot, &driver );
  1835. if( status != PSA_SUCCESS )
  1836. goto exit;
  1837. status = psa_finish_key_creation( slot, driver, &key );
  1838. exit:
  1839. if( status != PSA_SUCCESS )
  1840. psa_fail_key_creation( slot, driver );
  1841. /* Registration doesn't keep the key in RAM. */
  1842. psa_close_key( key );
  1843. return( status );
  1844. }
  1845. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1846. static psa_status_t psa_copy_key_material( const psa_key_slot_t *source,
  1847. psa_key_slot_t *target )
  1848. {
  1849. psa_status_t status = psa_copy_key_material_into_slot( target,
  1850. source->key.data,
  1851. source->key.bytes );
  1852. if( status != PSA_SUCCESS )
  1853. return( status );
  1854. target->attr.type = source->attr.type;
  1855. target->attr.bits = source->attr.bits;
  1856. return( PSA_SUCCESS );
  1857. }
  1858. psa_status_t psa_copy_key( mbedtls_svc_key_id_t source_key,
  1859. const psa_key_attributes_t *specified_attributes,
  1860. mbedtls_svc_key_id_t *target_key )
  1861. {
  1862. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1863. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  1864. psa_key_slot_t *source_slot = NULL;
  1865. psa_key_slot_t *target_slot = NULL;
  1866. psa_key_attributes_t actual_attributes = *specified_attributes;
  1867. psa_se_drv_table_entry_t *driver = NULL;
  1868. *target_key = MBEDTLS_SVC_KEY_ID_INIT;
  1869. status = psa_get_and_lock_transparent_key_slot_with_policy(
  1870. source_key, &source_slot, PSA_KEY_USAGE_COPY, 0 );
  1871. if( status != PSA_SUCCESS )
  1872. goto exit;
  1873. status = psa_validate_optional_attributes( source_slot,
  1874. specified_attributes );
  1875. if( status != PSA_SUCCESS )
  1876. goto exit;
  1877. status = psa_restrict_key_policy( source_slot->attr.type,
  1878. &actual_attributes.core.policy,
  1879. &source_slot->attr.policy );
  1880. if( status != PSA_SUCCESS )
  1881. goto exit;
  1882. status = psa_start_key_creation( PSA_KEY_CREATION_COPY, &actual_attributes,
  1883. &target_slot, &driver );
  1884. if( status != PSA_SUCCESS )
  1885. goto exit;
  1886. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  1887. if( driver != NULL )
  1888. {
  1889. /* Copying to a secure element is not implemented yet. */
  1890. status = PSA_ERROR_NOT_SUPPORTED;
  1891. goto exit;
  1892. }
  1893. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  1894. if( psa_key_lifetime_is_external( actual_attributes.core.lifetime ) )
  1895. {
  1896. /*
  1897. * Copying through an opaque driver is not implemented yet, consider
  1898. * a lifetime with an external location as an invalid parameter for
  1899. * now.
  1900. */
  1901. status = PSA_ERROR_INVALID_ARGUMENT;
  1902. goto exit;
  1903. }
  1904. status = psa_copy_key_material( source_slot, target_slot );
  1905. if( status != PSA_SUCCESS )
  1906. goto exit;
  1907. status = psa_finish_key_creation( target_slot, driver, target_key );
  1908. exit:
  1909. if( status != PSA_SUCCESS )
  1910. psa_fail_key_creation( target_slot, driver );
  1911. unlock_status = psa_unlock_key_slot( source_slot );
  1912. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  1913. }
  1914. /****************************************************************/
  1915. /* Message digests */
  1916. /****************************************************************/
  1917. psa_status_t psa_hash_abort( psa_hash_operation_t *operation )
  1918. {
  1919. /* Aborting a non-active operation is allowed */
  1920. if( operation->id == 0 )
  1921. return( PSA_SUCCESS );
  1922. psa_status_t status = psa_driver_wrapper_hash_abort( operation );
  1923. operation->id = 0;
  1924. return( status );
  1925. }
  1926. psa_status_t psa_hash_setup( psa_hash_operation_t *operation,
  1927. psa_algorithm_t alg )
  1928. {
  1929. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1930. /* A context must be freshly initialized before it can be set up. */
  1931. if( operation->id != 0 )
  1932. {
  1933. status = PSA_ERROR_BAD_STATE;
  1934. goto exit;
  1935. }
  1936. if( !PSA_ALG_IS_HASH( alg ) )
  1937. {
  1938. status = PSA_ERROR_INVALID_ARGUMENT;
  1939. goto exit;
  1940. }
  1941. /* Ensure all of the context is zeroized, since PSA_HASH_OPERATION_INIT only
  1942. * directly zeroes the int-sized dummy member of the context union. */
  1943. memset( &operation->ctx, 0, sizeof( operation->ctx ) );
  1944. status = psa_driver_wrapper_hash_setup( operation, alg );
  1945. exit:
  1946. if( status != PSA_SUCCESS )
  1947. psa_hash_abort( operation );
  1948. return status;
  1949. }
  1950. psa_status_t psa_hash_update( psa_hash_operation_t *operation,
  1951. const uint8_t *input,
  1952. size_t input_length )
  1953. {
  1954. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  1955. if( operation->id == 0 )
  1956. {
  1957. status = PSA_ERROR_BAD_STATE;
  1958. goto exit;
  1959. }
  1960. /* Don't require hash implementations to behave correctly on a
  1961. * zero-length input, which may have an invalid pointer. */
  1962. if( input_length == 0 )
  1963. return( PSA_SUCCESS );
  1964. status = psa_driver_wrapper_hash_update( operation, input, input_length );
  1965. exit:
  1966. if( status != PSA_SUCCESS )
  1967. psa_hash_abort( operation );
  1968. return( status );
  1969. }
  1970. psa_status_t psa_hash_finish( psa_hash_operation_t *operation,
  1971. uint8_t *hash,
  1972. size_t hash_size,
  1973. size_t *hash_length )
  1974. {
  1975. *hash_length = 0;
  1976. if( operation->id == 0 )
  1977. return( PSA_ERROR_BAD_STATE );
  1978. psa_status_t status = psa_driver_wrapper_hash_finish(
  1979. operation, hash, hash_size, hash_length );
  1980. psa_hash_abort( operation );
  1981. return( status );
  1982. }
  1983. psa_status_t psa_hash_verify( psa_hash_operation_t *operation,
  1984. const uint8_t *hash,
  1985. size_t hash_length )
  1986. {
  1987. uint8_t actual_hash[PSA_HASH_MAX_SIZE];
  1988. size_t actual_hash_length;
  1989. psa_status_t status = psa_hash_finish(
  1990. operation,
  1991. actual_hash, sizeof( actual_hash ),
  1992. &actual_hash_length );
  1993. if( status != PSA_SUCCESS )
  1994. goto exit;
  1995. if( actual_hash_length != hash_length )
  1996. {
  1997. status = PSA_ERROR_INVALID_SIGNATURE;
  1998. goto exit;
  1999. }
  2000. if( mbedtls_psa_safer_memcmp( hash, actual_hash, actual_hash_length ) != 0 )
  2001. status = PSA_ERROR_INVALID_SIGNATURE;
  2002. exit:
  2003. mbedtls_platform_zeroize( actual_hash, sizeof( actual_hash ) );
  2004. if( status != PSA_SUCCESS )
  2005. psa_hash_abort(operation);
  2006. return( status );
  2007. }
  2008. psa_status_t psa_hash_compute( psa_algorithm_t alg,
  2009. const uint8_t *input, size_t input_length,
  2010. uint8_t *hash, size_t hash_size,
  2011. size_t *hash_length )
  2012. {
  2013. *hash_length = 0;
  2014. if( !PSA_ALG_IS_HASH( alg ) )
  2015. return( PSA_ERROR_INVALID_ARGUMENT );
  2016. return( psa_driver_wrapper_hash_compute( alg, input, input_length,
  2017. hash, hash_size, hash_length ) );
  2018. }
  2019. psa_status_t psa_hash_compare( psa_algorithm_t alg,
  2020. const uint8_t *input, size_t input_length,
  2021. const uint8_t *hash, size_t hash_length )
  2022. {
  2023. uint8_t actual_hash[PSA_HASH_MAX_SIZE];
  2024. size_t actual_hash_length;
  2025. if( !PSA_ALG_IS_HASH( alg ) )
  2026. return( PSA_ERROR_INVALID_ARGUMENT );
  2027. psa_status_t status = psa_driver_wrapper_hash_compute(
  2028. alg, input, input_length,
  2029. actual_hash, sizeof(actual_hash),
  2030. &actual_hash_length );
  2031. if( status != PSA_SUCCESS )
  2032. goto exit;
  2033. if( actual_hash_length != hash_length )
  2034. {
  2035. status = PSA_ERROR_INVALID_SIGNATURE;
  2036. goto exit;
  2037. }
  2038. if( mbedtls_psa_safer_memcmp( hash, actual_hash, actual_hash_length ) != 0 )
  2039. status = PSA_ERROR_INVALID_SIGNATURE;
  2040. exit:
  2041. mbedtls_platform_zeroize( actual_hash, sizeof( actual_hash ) );
  2042. return( status );
  2043. }
  2044. psa_status_t psa_hash_clone( const psa_hash_operation_t *source_operation,
  2045. psa_hash_operation_t *target_operation )
  2046. {
  2047. if( source_operation->id == 0 ||
  2048. target_operation->id != 0 )
  2049. {
  2050. return( PSA_ERROR_BAD_STATE );
  2051. }
  2052. psa_status_t status = psa_driver_wrapper_hash_clone( source_operation,
  2053. target_operation );
  2054. if( status != PSA_SUCCESS )
  2055. psa_hash_abort( target_operation );
  2056. return( status );
  2057. }
  2058. /****************************************************************/
  2059. /* MAC */
  2060. /****************************************************************/
  2061. psa_status_t psa_mac_abort( psa_mac_operation_t *operation )
  2062. {
  2063. /* Aborting a non-active operation is allowed */
  2064. if( operation->id == 0 )
  2065. return( PSA_SUCCESS );
  2066. psa_status_t status = psa_driver_wrapper_mac_abort( operation );
  2067. operation->mac_size = 0;
  2068. operation->is_sign = 0;
  2069. operation->id = 0;
  2070. return( status );
  2071. }
  2072. static psa_status_t psa_mac_finalize_alg_and_key_validation(
  2073. psa_algorithm_t alg,
  2074. const psa_key_attributes_t *attributes,
  2075. uint8_t *mac_size )
  2076. {
  2077. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2078. psa_key_type_t key_type = psa_get_key_type( attributes );
  2079. size_t key_bits = psa_get_key_bits( attributes );
  2080. if( ! PSA_ALG_IS_MAC( alg ) )
  2081. return( PSA_ERROR_INVALID_ARGUMENT );
  2082. /* Validate the combination of key type and algorithm */
  2083. status = psa_mac_key_can_do( alg, key_type );
  2084. if( status != PSA_SUCCESS )
  2085. return( status );
  2086. /* Get the output length for the algorithm and key combination */
  2087. *mac_size = PSA_MAC_LENGTH( key_type, key_bits, alg );
  2088. if( *mac_size < 4 )
  2089. {
  2090. /* A very short MAC is too short for security since it can be
  2091. * brute-forced. Ancient protocols with 32-bit MACs do exist,
  2092. * so we make this our minimum, even though 32 bits is still
  2093. * too small for security. */
  2094. return( PSA_ERROR_NOT_SUPPORTED );
  2095. }
  2096. if( *mac_size > PSA_MAC_LENGTH( key_type, key_bits,
  2097. PSA_ALG_FULL_LENGTH_MAC( alg ) ) )
  2098. {
  2099. /* It's impossible to "truncate" to a larger length than the full length
  2100. * of the algorithm. */
  2101. return( PSA_ERROR_INVALID_ARGUMENT );
  2102. }
  2103. return( PSA_SUCCESS );
  2104. }
  2105. static psa_status_t psa_mac_setup( psa_mac_operation_t *operation,
  2106. mbedtls_svc_key_id_t key,
  2107. psa_algorithm_t alg,
  2108. int is_sign )
  2109. {
  2110. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2111. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2112. psa_key_slot_t *slot = NULL;
  2113. /* A context must be freshly initialized before it can be set up. */
  2114. if( operation->id != 0 )
  2115. {
  2116. status = PSA_ERROR_BAD_STATE;
  2117. goto exit;
  2118. }
  2119. status = psa_get_and_lock_key_slot_with_policy(
  2120. key,
  2121. &slot,
  2122. is_sign ? PSA_KEY_USAGE_SIGN_MESSAGE : PSA_KEY_USAGE_VERIFY_MESSAGE,
  2123. alg );
  2124. if( status != PSA_SUCCESS )
  2125. goto exit;
  2126. psa_key_attributes_t attributes = {
  2127. .core = slot->attr
  2128. };
  2129. status = psa_mac_finalize_alg_and_key_validation( alg, &attributes,
  2130. &operation->mac_size );
  2131. if( status != PSA_SUCCESS )
  2132. goto exit;
  2133. operation->is_sign = is_sign;
  2134. /* Dispatch the MAC setup call with validated input */
  2135. if( is_sign )
  2136. {
  2137. status = psa_driver_wrapper_mac_sign_setup( operation,
  2138. &attributes,
  2139. slot->key.data,
  2140. slot->key.bytes,
  2141. alg );
  2142. }
  2143. else
  2144. {
  2145. status = psa_driver_wrapper_mac_verify_setup( operation,
  2146. &attributes,
  2147. slot->key.data,
  2148. slot->key.bytes,
  2149. alg );
  2150. }
  2151. exit:
  2152. if( status != PSA_SUCCESS )
  2153. psa_mac_abort( operation );
  2154. unlock_status = psa_unlock_key_slot( slot );
  2155. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2156. }
  2157. psa_status_t psa_mac_sign_setup( psa_mac_operation_t *operation,
  2158. mbedtls_svc_key_id_t key,
  2159. psa_algorithm_t alg )
  2160. {
  2161. return( psa_mac_setup( operation, key, alg, 1 ) );
  2162. }
  2163. psa_status_t psa_mac_verify_setup( psa_mac_operation_t *operation,
  2164. mbedtls_svc_key_id_t key,
  2165. psa_algorithm_t alg )
  2166. {
  2167. return( psa_mac_setup( operation, key, alg, 0 ) );
  2168. }
  2169. psa_status_t psa_mac_update( psa_mac_operation_t *operation,
  2170. const uint8_t *input,
  2171. size_t input_length )
  2172. {
  2173. if( operation->id == 0 )
  2174. return( PSA_ERROR_BAD_STATE );
  2175. /* Don't require hash implementations to behave correctly on a
  2176. * zero-length input, which may have an invalid pointer. */
  2177. if( input_length == 0 )
  2178. return( PSA_SUCCESS );
  2179. psa_status_t status = psa_driver_wrapper_mac_update( operation,
  2180. input, input_length );
  2181. if( status != PSA_SUCCESS )
  2182. psa_mac_abort( operation );
  2183. return( status );
  2184. }
  2185. psa_status_t psa_mac_sign_finish( psa_mac_operation_t *operation,
  2186. uint8_t *mac,
  2187. size_t mac_size,
  2188. size_t *mac_length )
  2189. {
  2190. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2191. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  2192. if( operation->id == 0 )
  2193. {
  2194. status = PSA_ERROR_BAD_STATE;
  2195. goto exit;
  2196. }
  2197. if( ! operation->is_sign )
  2198. {
  2199. status = PSA_ERROR_BAD_STATE;
  2200. goto exit;
  2201. }
  2202. /* Sanity check. This will guarantee that mac_size != 0 (and so mac != NULL)
  2203. * once all the error checks are done. */
  2204. if( operation->mac_size == 0 )
  2205. {
  2206. status = PSA_ERROR_BAD_STATE;
  2207. goto exit;
  2208. }
  2209. if( mac_size < operation->mac_size )
  2210. {
  2211. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2212. goto exit;
  2213. }
  2214. status = psa_driver_wrapper_mac_sign_finish( operation,
  2215. mac, operation->mac_size,
  2216. mac_length );
  2217. exit:
  2218. /* In case of success, set the potential excess room in the output buffer
  2219. * to an invalid value, to avoid potentially leaking a longer MAC.
  2220. * In case of error, set the output length and content to a safe default,
  2221. * such that in case the caller misses an error check, the output would be
  2222. * an unachievable MAC.
  2223. */
  2224. if( status != PSA_SUCCESS )
  2225. {
  2226. *mac_length = mac_size;
  2227. operation->mac_size = 0;
  2228. }
  2229. if( mac_size > operation->mac_size )
  2230. memset( &mac[operation->mac_size], '!',
  2231. mac_size - operation->mac_size );
  2232. abort_status = psa_mac_abort( operation );
  2233. return( status == PSA_SUCCESS ? abort_status : status );
  2234. }
  2235. psa_status_t psa_mac_verify_finish( psa_mac_operation_t *operation,
  2236. const uint8_t *mac,
  2237. size_t mac_length )
  2238. {
  2239. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2240. psa_status_t abort_status = PSA_ERROR_CORRUPTION_DETECTED;
  2241. if( operation->id == 0 )
  2242. {
  2243. status = PSA_ERROR_BAD_STATE;
  2244. goto exit;
  2245. }
  2246. if( operation->is_sign )
  2247. {
  2248. status = PSA_ERROR_BAD_STATE;
  2249. goto exit;
  2250. }
  2251. if( operation->mac_size != mac_length )
  2252. {
  2253. status = PSA_ERROR_INVALID_SIGNATURE;
  2254. goto exit;
  2255. }
  2256. status = psa_driver_wrapper_mac_verify_finish( operation,
  2257. mac, mac_length );
  2258. exit:
  2259. abort_status = psa_mac_abort( operation );
  2260. return( status == PSA_SUCCESS ? abort_status : status );
  2261. }
  2262. static psa_status_t psa_mac_compute_internal( mbedtls_svc_key_id_t key,
  2263. psa_algorithm_t alg,
  2264. const uint8_t *input,
  2265. size_t input_length,
  2266. uint8_t *mac,
  2267. size_t mac_size,
  2268. size_t *mac_length,
  2269. int is_sign )
  2270. {
  2271. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2272. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2273. psa_key_slot_t *slot;
  2274. uint8_t operation_mac_size = 0;
  2275. status = psa_get_and_lock_key_slot_with_policy(
  2276. key,
  2277. &slot,
  2278. is_sign ? PSA_KEY_USAGE_SIGN_MESSAGE : PSA_KEY_USAGE_VERIFY_MESSAGE,
  2279. alg );
  2280. if( status != PSA_SUCCESS )
  2281. goto exit;
  2282. psa_key_attributes_t attributes = {
  2283. .core = slot->attr
  2284. };
  2285. status = psa_mac_finalize_alg_and_key_validation( alg, &attributes,
  2286. &operation_mac_size );
  2287. if( status != PSA_SUCCESS )
  2288. goto exit;
  2289. if( mac_size < operation_mac_size )
  2290. {
  2291. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2292. goto exit;
  2293. }
  2294. status = psa_driver_wrapper_mac_compute(
  2295. &attributes,
  2296. slot->key.data, slot->key.bytes,
  2297. alg,
  2298. input, input_length,
  2299. mac, operation_mac_size, mac_length );
  2300. exit:
  2301. /* In case of success, set the potential excess room in the output buffer
  2302. * to an invalid value, to avoid potentially leaking a longer MAC.
  2303. * In case of error, set the output length and content to a safe default,
  2304. * such that in case the caller misses an error check, the output would be
  2305. * an unachievable MAC.
  2306. */
  2307. if( status != PSA_SUCCESS )
  2308. {
  2309. *mac_length = mac_size;
  2310. operation_mac_size = 0;
  2311. }
  2312. if( mac_size > operation_mac_size )
  2313. memset( &mac[operation_mac_size], '!', mac_size - operation_mac_size );
  2314. unlock_status = psa_unlock_key_slot( slot );
  2315. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2316. }
  2317. psa_status_t psa_mac_compute( mbedtls_svc_key_id_t key,
  2318. psa_algorithm_t alg,
  2319. const uint8_t *input,
  2320. size_t input_length,
  2321. uint8_t *mac,
  2322. size_t mac_size,
  2323. size_t *mac_length)
  2324. {
  2325. return( psa_mac_compute_internal( key, alg,
  2326. input, input_length,
  2327. mac, mac_size, mac_length, 1 ) );
  2328. }
  2329. psa_status_t psa_mac_verify( mbedtls_svc_key_id_t key,
  2330. psa_algorithm_t alg,
  2331. const uint8_t *input,
  2332. size_t input_length,
  2333. const uint8_t *mac,
  2334. size_t mac_length)
  2335. {
  2336. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2337. uint8_t actual_mac[PSA_MAC_MAX_SIZE];
  2338. size_t actual_mac_length;
  2339. status = psa_mac_compute_internal( key, alg,
  2340. input, input_length,
  2341. actual_mac, sizeof( actual_mac ),
  2342. &actual_mac_length, 0 );
  2343. if( status != PSA_SUCCESS )
  2344. goto exit;
  2345. if( mac_length != actual_mac_length )
  2346. {
  2347. status = PSA_ERROR_INVALID_SIGNATURE;
  2348. goto exit;
  2349. }
  2350. if( mbedtls_psa_safer_memcmp( mac, actual_mac, actual_mac_length ) != 0 )
  2351. {
  2352. status = PSA_ERROR_INVALID_SIGNATURE;
  2353. goto exit;
  2354. }
  2355. exit:
  2356. mbedtls_platform_zeroize( actual_mac, sizeof( actual_mac ) );
  2357. return ( status );
  2358. }
  2359. /****************************************************************/
  2360. /* Asymmetric cryptography */
  2361. /****************************************************************/
  2362. static psa_status_t psa_sign_verify_check_alg( int input_is_message,
  2363. psa_algorithm_t alg )
  2364. {
  2365. if( input_is_message )
  2366. {
  2367. if( ! PSA_ALG_IS_SIGN_MESSAGE( alg ) )
  2368. return( PSA_ERROR_INVALID_ARGUMENT );
  2369. if ( PSA_ALG_IS_SIGN_HASH( alg ) )
  2370. {
  2371. if( ! PSA_ALG_IS_HASH( PSA_ALG_SIGN_GET_HASH( alg ) ) )
  2372. return( PSA_ERROR_INVALID_ARGUMENT );
  2373. }
  2374. }
  2375. else
  2376. {
  2377. if( ! PSA_ALG_IS_SIGN_HASH( alg ) )
  2378. return( PSA_ERROR_INVALID_ARGUMENT );
  2379. }
  2380. return( PSA_SUCCESS );
  2381. }
  2382. static psa_status_t psa_sign_internal( mbedtls_svc_key_id_t key,
  2383. int input_is_message,
  2384. psa_algorithm_t alg,
  2385. const uint8_t * input,
  2386. size_t input_length,
  2387. uint8_t * signature,
  2388. size_t signature_size,
  2389. size_t * signature_length )
  2390. {
  2391. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2392. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2393. psa_key_slot_t *slot;
  2394. *signature_length = 0;
  2395. status = psa_sign_verify_check_alg( input_is_message, alg );
  2396. if( status != PSA_SUCCESS )
  2397. return status;
  2398. /* Immediately reject a zero-length signature buffer. This guarantees
  2399. * that signature must be a valid pointer. (On the other hand, the input
  2400. * buffer can in principle be empty since it doesn't actually have
  2401. * to be a hash.) */
  2402. if( signature_size == 0 )
  2403. return( PSA_ERROR_BUFFER_TOO_SMALL );
  2404. status = psa_get_and_lock_key_slot_with_policy(
  2405. key, &slot,
  2406. input_is_message ? PSA_KEY_USAGE_SIGN_MESSAGE :
  2407. PSA_KEY_USAGE_SIGN_HASH,
  2408. alg );
  2409. if( status != PSA_SUCCESS )
  2410. goto exit;
  2411. if( ! PSA_KEY_TYPE_IS_KEY_PAIR( slot->attr.type ) )
  2412. {
  2413. status = PSA_ERROR_INVALID_ARGUMENT;
  2414. goto exit;
  2415. }
  2416. psa_key_attributes_t attributes = {
  2417. .core = slot->attr
  2418. };
  2419. if( input_is_message )
  2420. {
  2421. status = psa_driver_wrapper_sign_message(
  2422. &attributes, slot->key.data, slot->key.bytes,
  2423. alg, input, input_length,
  2424. signature, signature_size, signature_length );
  2425. }
  2426. else
  2427. {
  2428. status = psa_driver_wrapper_sign_hash(
  2429. &attributes, slot->key.data, slot->key.bytes,
  2430. alg, input, input_length,
  2431. signature, signature_size, signature_length );
  2432. }
  2433. exit:
  2434. /* Fill the unused part of the output buffer (the whole buffer on error,
  2435. * the trailing part on success) with something that isn't a valid signature
  2436. * (barring an attack on the signature and deliberately-crafted input),
  2437. * in case the caller doesn't check the return status properly. */
  2438. if( status == PSA_SUCCESS )
  2439. memset( signature + *signature_length, '!',
  2440. signature_size - *signature_length );
  2441. else
  2442. memset( signature, '!', signature_size );
  2443. /* If signature_size is 0 then we have nothing to do. We must not call
  2444. * memset because signature may be NULL in this case. */
  2445. unlock_status = psa_unlock_key_slot( slot );
  2446. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2447. }
  2448. static psa_status_t psa_verify_internal( mbedtls_svc_key_id_t key,
  2449. int input_is_message,
  2450. psa_algorithm_t alg,
  2451. const uint8_t * input,
  2452. size_t input_length,
  2453. const uint8_t * signature,
  2454. size_t signature_length )
  2455. {
  2456. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2457. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2458. psa_key_slot_t *slot;
  2459. status = psa_sign_verify_check_alg( input_is_message, alg );
  2460. if( status != PSA_SUCCESS )
  2461. return status;
  2462. status = psa_get_and_lock_key_slot_with_policy(
  2463. key, &slot,
  2464. input_is_message ? PSA_KEY_USAGE_VERIFY_MESSAGE :
  2465. PSA_KEY_USAGE_VERIFY_HASH,
  2466. alg );
  2467. if( status != PSA_SUCCESS )
  2468. return( status );
  2469. psa_key_attributes_t attributes = {
  2470. .core = slot->attr
  2471. };
  2472. if( input_is_message )
  2473. {
  2474. status = psa_driver_wrapper_verify_message(
  2475. &attributes, slot->key.data, slot->key.bytes,
  2476. alg, input, input_length,
  2477. signature, signature_length );
  2478. }
  2479. else
  2480. {
  2481. status = psa_driver_wrapper_verify_hash(
  2482. &attributes, slot->key.data, slot->key.bytes,
  2483. alg, input, input_length,
  2484. signature, signature_length );
  2485. }
  2486. unlock_status = psa_unlock_key_slot( slot );
  2487. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2488. }
  2489. psa_status_t psa_sign_message_builtin(
  2490. const psa_key_attributes_t *attributes,
  2491. const uint8_t *key_buffer,
  2492. size_t key_buffer_size,
  2493. psa_algorithm_t alg,
  2494. const uint8_t *input,
  2495. size_t input_length,
  2496. uint8_t *signature,
  2497. size_t signature_size,
  2498. size_t *signature_length )
  2499. {
  2500. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2501. if ( PSA_ALG_IS_SIGN_HASH( alg ) )
  2502. {
  2503. size_t hash_length;
  2504. uint8_t hash[PSA_HASH_MAX_SIZE];
  2505. status = psa_driver_wrapper_hash_compute(
  2506. PSA_ALG_SIGN_GET_HASH( alg ),
  2507. input, input_length,
  2508. hash, sizeof( hash ), &hash_length );
  2509. if( status != PSA_SUCCESS )
  2510. return status;
  2511. return psa_driver_wrapper_sign_hash(
  2512. attributes, key_buffer, key_buffer_size,
  2513. alg, hash, hash_length,
  2514. signature, signature_size, signature_length );
  2515. }
  2516. return( PSA_ERROR_NOT_SUPPORTED );
  2517. }
  2518. psa_status_t psa_sign_message( mbedtls_svc_key_id_t key,
  2519. psa_algorithm_t alg,
  2520. const uint8_t * input,
  2521. size_t input_length,
  2522. uint8_t * signature,
  2523. size_t signature_size,
  2524. size_t * signature_length )
  2525. {
  2526. return psa_sign_internal(
  2527. key, 1, alg, input, input_length,
  2528. signature, signature_size, signature_length );
  2529. }
  2530. psa_status_t psa_verify_message_builtin(
  2531. const psa_key_attributes_t *attributes,
  2532. const uint8_t *key_buffer,
  2533. size_t key_buffer_size,
  2534. psa_algorithm_t alg,
  2535. const uint8_t *input,
  2536. size_t input_length,
  2537. const uint8_t *signature,
  2538. size_t signature_length )
  2539. {
  2540. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2541. if ( PSA_ALG_IS_SIGN_HASH( alg ) )
  2542. {
  2543. size_t hash_length;
  2544. uint8_t hash[PSA_HASH_MAX_SIZE];
  2545. status = psa_driver_wrapper_hash_compute(
  2546. PSA_ALG_SIGN_GET_HASH( alg ),
  2547. input, input_length,
  2548. hash, sizeof( hash ), &hash_length );
  2549. if( status != PSA_SUCCESS )
  2550. return status;
  2551. return psa_driver_wrapper_verify_hash(
  2552. attributes, key_buffer, key_buffer_size,
  2553. alg, hash, hash_length,
  2554. signature, signature_length );
  2555. }
  2556. return( PSA_ERROR_NOT_SUPPORTED );
  2557. }
  2558. psa_status_t psa_verify_message( mbedtls_svc_key_id_t key,
  2559. psa_algorithm_t alg,
  2560. const uint8_t * input,
  2561. size_t input_length,
  2562. const uint8_t * signature,
  2563. size_t signature_length )
  2564. {
  2565. return psa_verify_internal(
  2566. key, 1, alg, input, input_length,
  2567. signature, signature_length );
  2568. }
  2569. psa_status_t psa_sign_hash_builtin(
  2570. const psa_key_attributes_t *attributes,
  2571. const uint8_t *key_buffer, size_t key_buffer_size,
  2572. psa_algorithm_t alg, const uint8_t *hash, size_t hash_length,
  2573. uint8_t *signature, size_t signature_size, size_t *signature_length )
  2574. {
  2575. if( attributes->core.type == PSA_KEY_TYPE_RSA_KEY_PAIR )
  2576. {
  2577. if( PSA_ALG_IS_RSA_PKCS1V15_SIGN( alg ) ||
  2578. PSA_ALG_IS_RSA_PSS( alg) )
  2579. {
  2580. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) || \
  2581. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS)
  2582. return( mbedtls_psa_rsa_sign_hash(
  2583. attributes,
  2584. key_buffer, key_buffer_size,
  2585. alg, hash, hash_length,
  2586. signature, signature_size, signature_length ) );
  2587. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) ||
  2588. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS) */
  2589. }
  2590. else
  2591. {
  2592. return( PSA_ERROR_INVALID_ARGUMENT );
  2593. }
  2594. }
  2595. else if( PSA_KEY_TYPE_IS_ECC( attributes->core.type ) )
  2596. {
  2597. if( PSA_ALG_IS_ECDSA( alg ) )
  2598. {
  2599. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  2600. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  2601. return( mbedtls_psa_ecdsa_sign_hash(
  2602. attributes,
  2603. key_buffer, key_buffer_size,
  2604. alg, hash, hash_length,
  2605. signature, signature_size, signature_length ) );
  2606. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  2607. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  2608. }
  2609. else
  2610. {
  2611. return( PSA_ERROR_INVALID_ARGUMENT );
  2612. }
  2613. }
  2614. (void)key_buffer;
  2615. (void)key_buffer_size;
  2616. (void)hash;
  2617. (void)hash_length;
  2618. (void)signature;
  2619. (void)signature_size;
  2620. (void)signature_length;
  2621. return( PSA_ERROR_NOT_SUPPORTED );
  2622. }
  2623. psa_status_t psa_sign_hash( mbedtls_svc_key_id_t key,
  2624. psa_algorithm_t alg,
  2625. const uint8_t *hash,
  2626. size_t hash_length,
  2627. uint8_t *signature,
  2628. size_t signature_size,
  2629. size_t *signature_length )
  2630. {
  2631. return psa_sign_internal(
  2632. key, 0, alg, hash, hash_length,
  2633. signature, signature_size, signature_length );
  2634. }
  2635. psa_status_t psa_verify_hash_builtin(
  2636. const psa_key_attributes_t *attributes,
  2637. const uint8_t *key_buffer, size_t key_buffer_size,
  2638. psa_algorithm_t alg, const uint8_t *hash, size_t hash_length,
  2639. const uint8_t *signature, size_t signature_length )
  2640. {
  2641. if( PSA_KEY_TYPE_IS_RSA( attributes->core.type ) )
  2642. {
  2643. if( PSA_ALG_IS_RSA_PKCS1V15_SIGN( alg ) ||
  2644. PSA_ALG_IS_RSA_PSS( alg) )
  2645. {
  2646. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) || \
  2647. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS)
  2648. return( mbedtls_psa_rsa_verify_hash(
  2649. attributes,
  2650. key_buffer, key_buffer_size,
  2651. alg, hash, hash_length,
  2652. signature, signature_length ) );
  2653. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN) ||
  2654. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS) */
  2655. }
  2656. else
  2657. {
  2658. return( PSA_ERROR_INVALID_ARGUMENT );
  2659. }
  2660. }
  2661. else if( PSA_KEY_TYPE_IS_ECC( attributes->core.type ) )
  2662. {
  2663. if( PSA_ALG_IS_ECDSA( alg ) )
  2664. {
  2665. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) || \
  2666. defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA)
  2667. return( mbedtls_psa_ecdsa_verify_hash(
  2668. attributes,
  2669. key_buffer, key_buffer_size,
  2670. alg, hash, hash_length,
  2671. signature, signature_length ) );
  2672. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_ECDSA) ||
  2673. * defined(MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA) */
  2674. }
  2675. else
  2676. {
  2677. return( PSA_ERROR_INVALID_ARGUMENT );
  2678. }
  2679. }
  2680. (void)key_buffer;
  2681. (void)key_buffer_size;
  2682. (void)hash;
  2683. (void)hash_length;
  2684. (void)signature;
  2685. (void)signature_length;
  2686. return( PSA_ERROR_NOT_SUPPORTED );
  2687. }
  2688. psa_status_t psa_verify_hash( mbedtls_svc_key_id_t key,
  2689. psa_algorithm_t alg,
  2690. const uint8_t *hash,
  2691. size_t hash_length,
  2692. const uint8_t *signature,
  2693. size_t signature_length )
  2694. {
  2695. return psa_verify_internal(
  2696. key, 0, alg, hash, hash_length,
  2697. signature, signature_length );
  2698. }
  2699. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2700. static void psa_rsa_oaep_set_padding_mode( psa_algorithm_t alg,
  2701. mbedtls_rsa_context *rsa )
  2702. {
  2703. psa_algorithm_t hash_alg = PSA_ALG_RSA_OAEP_GET_HASH( alg );
  2704. const mbedtls_md_info_t *md_info = mbedtls_md_info_from_psa( hash_alg );
  2705. mbedtls_md_type_t md_alg = mbedtls_md_get_type( md_info );
  2706. mbedtls_rsa_set_padding( rsa, MBEDTLS_RSA_PKCS_V21, md_alg );
  2707. }
  2708. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2709. psa_status_t psa_asymmetric_encrypt( mbedtls_svc_key_id_t key,
  2710. psa_algorithm_t alg,
  2711. const uint8_t *input,
  2712. size_t input_length,
  2713. const uint8_t *salt,
  2714. size_t salt_length,
  2715. uint8_t *output,
  2716. size_t output_size,
  2717. size_t *output_length )
  2718. {
  2719. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2720. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2721. psa_key_slot_t *slot;
  2722. (void) input;
  2723. (void) input_length;
  2724. (void) salt;
  2725. (void) output;
  2726. (void) output_size;
  2727. *output_length = 0;
  2728. if( ! PSA_ALG_IS_RSA_OAEP( alg ) && salt_length != 0 )
  2729. return( PSA_ERROR_INVALID_ARGUMENT );
  2730. status = psa_get_and_lock_transparent_key_slot_with_policy(
  2731. key, &slot, PSA_KEY_USAGE_ENCRYPT, alg );
  2732. if( status != PSA_SUCCESS )
  2733. return( status );
  2734. if( ! ( PSA_KEY_TYPE_IS_PUBLIC_KEY( slot->attr.type ) ||
  2735. PSA_KEY_TYPE_IS_KEY_PAIR( slot->attr.type ) ) )
  2736. {
  2737. status = PSA_ERROR_INVALID_ARGUMENT;
  2738. goto exit;
  2739. }
  2740. if( PSA_KEY_TYPE_IS_RSA( slot->attr.type ) )
  2741. {
  2742. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) || \
  2743. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2744. mbedtls_rsa_context *rsa = NULL;
  2745. status = mbedtls_psa_rsa_load_representation( slot->attr.type,
  2746. slot->key.data,
  2747. slot->key.bytes,
  2748. &rsa );
  2749. if( status != PSA_SUCCESS )
  2750. goto rsa_exit;
  2751. if( output_size < mbedtls_rsa_get_len( rsa ) )
  2752. {
  2753. status = PSA_ERROR_BUFFER_TOO_SMALL;
  2754. goto rsa_exit;
  2755. }
  2756. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) ||
  2757. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2758. if( alg == PSA_ALG_RSA_PKCS1V15_CRYPT )
  2759. {
  2760. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT)
  2761. status = mbedtls_to_psa_error(
  2762. mbedtls_rsa_pkcs1_encrypt( rsa,
  2763. mbedtls_psa_get_random,
  2764. MBEDTLS_PSA_RANDOM_STATE,
  2765. MBEDTLS_RSA_PUBLIC,
  2766. input_length,
  2767. input,
  2768. output ) );
  2769. #else
  2770. status = PSA_ERROR_NOT_SUPPORTED;
  2771. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT */
  2772. }
  2773. else
  2774. if( PSA_ALG_IS_RSA_OAEP( alg ) )
  2775. {
  2776. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2777. psa_rsa_oaep_set_padding_mode( alg, rsa );
  2778. status = mbedtls_to_psa_error(
  2779. mbedtls_rsa_rsaes_oaep_encrypt( rsa,
  2780. mbedtls_psa_get_random,
  2781. MBEDTLS_PSA_RANDOM_STATE,
  2782. MBEDTLS_RSA_PUBLIC,
  2783. salt, salt_length,
  2784. input_length,
  2785. input,
  2786. output ) );
  2787. #else
  2788. status = PSA_ERROR_NOT_SUPPORTED;
  2789. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP */
  2790. }
  2791. else
  2792. {
  2793. status = PSA_ERROR_INVALID_ARGUMENT;
  2794. }
  2795. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) || \
  2796. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2797. rsa_exit:
  2798. if( status == PSA_SUCCESS )
  2799. *output_length = mbedtls_rsa_get_len( rsa );
  2800. mbedtls_rsa_free( rsa );
  2801. mbedtls_free( rsa );
  2802. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) ||
  2803. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2804. }
  2805. else
  2806. {
  2807. status = PSA_ERROR_NOT_SUPPORTED;
  2808. }
  2809. exit:
  2810. unlock_status = psa_unlock_key_slot( slot );
  2811. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2812. }
  2813. psa_status_t psa_asymmetric_decrypt( mbedtls_svc_key_id_t key,
  2814. psa_algorithm_t alg,
  2815. const uint8_t *input,
  2816. size_t input_length,
  2817. const uint8_t *salt,
  2818. size_t salt_length,
  2819. uint8_t *output,
  2820. size_t output_size,
  2821. size_t *output_length )
  2822. {
  2823. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2824. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2825. psa_key_slot_t *slot;
  2826. (void) input;
  2827. (void) input_length;
  2828. (void) salt;
  2829. (void) output;
  2830. (void) output_size;
  2831. *output_length = 0;
  2832. if( ! PSA_ALG_IS_RSA_OAEP( alg ) && salt_length != 0 )
  2833. return( PSA_ERROR_INVALID_ARGUMENT );
  2834. status = psa_get_and_lock_transparent_key_slot_with_policy(
  2835. key, &slot, PSA_KEY_USAGE_DECRYPT, alg );
  2836. if( status != PSA_SUCCESS )
  2837. return( status );
  2838. if( ! PSA_KEY_TYPE_IS_KEY_PAIR( slot->attr.type ) )
  2839. {
  2840. status = PSA_ERROR_INVALID_ARGUMENT;
  2841. goto exit;
  2842. }
  2843. if( slot->attr.type == PSA_KEY_TYPE_RSA_KEY_PAIR )
  2844. {
  2845. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) || \
  2846. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2847. mbedtls_rsa_context *rsa = NULL;
  2848. status = mbedtls_psa_rsa_load_representation( slot->attr.type,
  2849. slot->key.data,
  2850. slot->key.bytes,
  2851. &rsa );
  2852. if( status != PSA_SUCCESS )
  2853. goto exit;
  2854. if( input_length != mbedtls_rsa_get_len( rsa ) )
  2855. {
  2856. status = PSA_ERROR_INVALID_ARGUMENT;
  2857. goto rsa_exit;
  2858. }
  2859. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) ||
  2860. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2861. if( alg == PSA_ALG_RSA_PKCS1V15_CRYPT )
  2862. {
  2863. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT)
  2864. status = mbedtls_to_psa_error(
  2865. mbedtls_rsa_pkcs1_decrypt( rsa,
  2866. mbedtls_psa_get_random,
  2867. MBEDTLS_PSA_RANDOM_STATE,
  2868. MBEDTLS_RSA_PRIVATE,
  2869. output_length,
  2870. input,
  2871. output,
  2872. output_size ) );
  2873. #else
  2874. status = PSA_ERROR_NOT_SUPPORTED;
  2875. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT */
  2876. }
  2877. else
  2878. if( PSA_ALG_IS_RSA_OAEP( alg ) )
  2879. {
  2880. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2881. psa_rsa_oaep_set_padding_mode( alg, rsa );
  2882. status = mbedtls_to_psa_error(
  2883. mbedtls_rsa_rsaes_oaep_decrypt( rsa,
  2884. mbedtls_psa_get_random,
  2885. MBEDTLS_PSA_RANDOM_STATE,
  2886. MBEDTLS_RSA_PRIVATE,
  2887. salt, salt_length,
  2888. output_length,
  2889. input,
  2890. output,
  2891. output_size ) );
  2892. #else
  2893. status = PSA_ERROR_NOT_SUPPORTED;
  2894. #endif /* MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP */
  2895. }
  2896. else
  2897. {
  2898. status = PSA_ERROR_INVALID_ARGUMENT;
  2899. }
  2900. #if defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) || \
  2901. defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP)
  2902. rsa_exit:
  2903. mbedtls_rsa_free( rsa );
  2904. mbedtls_free( rsa );
  2905. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT) ||
  2906. * defined(MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP) */
  2907. }
  2908. else
  2909. {
  2910. status = PSA_ERROR_NOT_SUPPORTED;
  2911. }
  2912. exit:
  2913. unlock_status = psa_unlock_key_slot( slot );
  2914. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2915. }
  2916. /****************************************************************/
  2917. /* Symmetric cryptography */
  2918. /****************************************************************/
  2919. static psa_status_t psa_cipher_setup( psa_cipher_operation_t *operation,
  2920. mbedtls_svc_key_id_t key,
  2921. psa_algorithm_t alg,
  2922. mbedtls_operation_t cipher_operation )
  2923. {
  2924. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2925. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  2926. psa_key_slot_t *slot = NULL;
  2927. psa_key_usage_t usage = ( cipher_operation == MBEDTLS_ENCRYPT ?
  2928. PSA_KEY_USAGE_ENCRYPT :
  2929. PSA_KEY_USAGE_DECRYPT );
  2930. /* A context must be freshly initialized before it can be set up. */
  2931. if( operation->id != 0 )
  2932. {
  2933. status = PSA_ERROR_BAD_STATE;
  2934. goto exit;
  2935. }
  2936. if( ! PSA_ALG_IS_CIPHER( alg ) )
  2937. {
  2938. status = PSA_ERROR_INVALID_ARGUMENT;
  2939. goto exit;
  2940. }
  2941. status = psa_get_and_lock_key_slot_with_policy( key, &slot, usage, alg );
  2942. if( status != PSA_SUCCESS )
  2943. goto exit;
  2944. /* Initialize the operation struct members, except for id. The id member
  2945. * is used to indicate to psa_cipher_abort that there are resources to free,
  2946. * so we only set it (in the driver wrapper) after resources have been
  2947. * allocated/initialized. */
  2948. operation->iv_set = 0;
  2949. if( alg == PSA_ALG_ECB_NO_PADDING )
  2950. operation->iv_required = 0;
  2951. else
  2952. operation->iv_required = 1;
  2953. operation->default_iv_length = PSA_CIPHER_IV_LENGTH( slot->attr.type, alg );
  2954. psa_key_attributes_t attributes = {
  2955. .core = slot->attr
  2956. };
  2957. /* Try doing the operation through a driver before using software fallback. */
  2958. if( cipher_operation == MBEDTLS_ENCRYPT )
  2959. status = psa_driver_wrapper_cipher_encrypt_setup( operation,
  2960. &attributes,
  2961. slot->key.data,
  2962. slot->key.bytes,
  2963. alg );
  2964. else
  2965. status = psa_driver_wrapper_cipher_decrypt_setup( operation,
  2966. &attributes,
  2967. slot->key.data,
  2968. slot->key.bytes,
  2969. alg );
  2970. exit:
  2971. if( status != PSA_SUCCESS )
  2972. psa_cipher_abort( operation );
  2973. unlock_status = psa_unlock_key_slot( slot );
  2974. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  2975. }
  2976. psa_status_t psa_cipher_encrypt_setup( psa_cipher_operation_t *operation,
  2977. mbedtls_svc_key_id_t key,
  2978. psa_algorithm_t alg )
  2979. {
  2980. return( psa_cipher_setup( operation, key, alg, MBEDTLS_ENCRYPT ) );
  2981. }
  2982. psa_status_t psa_cipher_decrypt_setup( psa_cipher_operation_t *operation,
  2983. mbedtls_svc_key_id_t key,
  2984. psa_algorithm_t alg )
  2985. {
  2986. return( psa_cipher_setup( operation, key, alg, MBEDTLS_DECRYPT ) );
  2987. }
  2988. psa_status_t psa_cipher_generate_iv( psa_cipher_operation_t *operation,
  2989. uint8_t *iv,
  2990. size_t iv_size,
  2991. size_t *iv_length )
  2992. {
  2993. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  2994. uint8_t local_iv[PSA_CIPHER_IV_MAX_SIZE];
  2995. size_t default_iv_length;
  2996. if( operation->id == 0 )
  2997. {
  2998. status = PSA_ERROR_BAD_STATE;
  2999. goto exit;
  3000. }
  3001. if( operation->iv_set || ! operation->iv_required )
  3002. {
  3003. status = PSA_ERROR_BAD_STATE;
  3004. goto exit;
  3005. }
  3006. default_iv_length = operation->default_iv_length;
  3007. if( iv_size < default_iv_length )
  3008. {
  3009. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3010. goto exit;
  3011. }
  3012. if( default_iv_length > PSA_CIPHER_IV_MAX_SIZE )
  3013. {
  3014. status = PSA_ERROR_GENERIC_ERROR;
  3015. goto exit;
  3016. }
  3017. status = psa_generate_random( local_iv, default_iv_length );
  3018. if( status != PSA_SUCCESS )
  3019. goto exit;
  3020. status = psa_driver_wrapper_cipher_set_iv( operation,
  3021. local_iv, default_iv_length );
  3022. exit:
  3023. if( status == PSA_SUCCESS )
  3024. {
  3025. memcpy( iv, local_iv, default_iv_length );
  3026. *iv_length = default_iv_length;
  3027. operation->iv_set = 1;
  3028. }
  3029. else
  3030. {
  3031. *iv_length = 0;
  3032. psa_cipher_abort( operation );
  3033. }
  3034. return( status );
  3035. }
  3036. psa_status_t psa_cipher_set_iv( psa_cipher_operation_t *operation,
  3037. const uint8_t *iv,
  3038. size_t iv_length )
  3039. {
  3040. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3041. if( operation->id == 0 )
  3042. {
  3043. status = PSA_ERROR_BAD_STATE;
  3044. goto exit;
  3045. }
  3046. if( operation->iv_set || ! operation->iv_required )
  3047. {
  3048. status = PSA_ERROR_BAD_STATE;
  3049. goto exit;
  3050. }
  3051. if( iv_length > PSA_CIPHER_IV_MAX_SIZE )
  3052. {
  3053. status = PSA_ERROR_INVALID_ARGUMENT;
  3054. goto exit;
  3055. }
  3056. status = psa_driver_wrapper_cipher_set_iv( operation,
  3057. iv,
  3058. iv_length );
  3059. exit:
  3060. if( status == PSA_SUCCESS )
  3061. operation->iv_set = 1;
  3062. else
  3063. psa_cipher_abort( operation );
  3064. return( status );
  3065. }
  3066. psa_status_t psa_cipher_update( psa_cipher_operation_t *operation,
  3067. const uint8_t *input,
  3068. size_t input_length,
  3069. uint8_t *output,
  3070. size_t output_size,
  3071. size_t *output_length )
  3072. {
  3073. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3074. if( operation->id == 0 )
  3075. {
  3076. status = PSA_ERROR_BAD_STATE;
  3077. goto exit;
  3078. }
  3079. if( operation->iv_required && ! operation->iv_set )
  3080. {
  3081. status = PSA_ERROR_BAD_STATE;
  3082. goto exit;
  3083. }
  3084. status = psa_driver_wrapper_cipher_update( operation,
  3085. input,
  3086. input_length,
  3087. output,
  3088. output_size,
  3089. output_length );
  3090. exit:
  3091. if( status != PSA_SUCCESS )
  3092. psa_cipher_abort( operation );
  3093. return( status );
  3094. }
  3095. psa_status_t psa_cipher_finish( psa_cipher_operation_t *operation,
  3096. uint8_t *output,
  3097. size_t output_size,
  3098. size_t *output_length )
  3099. {
  3100. psa_status_t status = PSA_ERROR_GENERIC_ERROR;
  3101. if( operation->id == 0 )
  3102. {
  3103. status = PSA_ERROR_BAD_STATE;
  3104. goto exit;
  3105. }
  3106. if( operation->iv_required && ! operation->iv_set )
  3107. {
  3108. status = PSA_ERROR_BAD_STATE;
  3109. goto exit;
  3110. }
  3111. status = psa_driver_wrapper_cipher_finish( operation,
  3112. output,
  3113. output_size,
  3114. output_length );
  3115. exit:
  3116. if( status == PSA_SUCCESS )
  3117. return( psa_cipher_abort( operation ) );
  3118. else
  3119. {
  3120. *output_length = 0;
  3121. (void) psa_cipher_abort( operation );
  3122. return( status );
  3123. }
  3124. }
  3125. psa_status_t psa_cipher_abort( psa_cipher_operation_t *operation )
  3126. {
  3127. if( operation->id == 0 )
  3128. {
  3129. /* The object has (apparently) been initialized but it is not (yet)
  3130. * in use. It's ok to call abort on such an object, and there's
  3131. * nothing to do. */
  3132. return( PSA_SUCCESS );
  3133. }
  3134. psa_driver_wrapper_cipher_abort( operation );
  3135. operation->id = 0;
  3136. operation->iv_set = 0;
  3137. operation->iv_required = 0;
  3138. return( PSA_SUCCESS );
  3139. }
  3140. psa_status_t psa_cipher_encrypt( mbedtls_svc_key_id_t key,
  3141. psa_algorithm_t alg,
  3142. const uint8_t *input,
  3143. size_t input_length,
  3144. uint8_t *output,
  3145. size_t output_size,
  3146. size_t *output_length )
  3147. {
  3148. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3149. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3150. psa_key_slot_t *slot = NULL;
  3151. uint8_t local_iv[PSA_CIPHER_IV_MAX_SIZE];
  3152. size_t default_iv_length = 0;
  3153. if( ! PSA_ALG_IS_CIPHER( alg ) )
  3154. {
  3155. status = PSA_ERROR_INVALID_ARGUMENT;
  3156. goto exit;
  3157. }
  3158. status = psa_get_and_lock_key_slot_with_policy( key, &slot,
  3159. PSA_KEY_USAGE_ENCRYPT,
  3160. alg );
  3161. if( status != PSA_SUCCESS )
  3162. goto exit;
  3163. psa_key_attributes_t attributes = {
  3164. .core = slot->attr
  3165. };
  3166. default_iv_length = PSA_CIPHER_IV_LENGTH( slot->attr.type, alg );
  3167. if( default_iv_length > PSA_CIPHER_IV_MAX_SIZE )
  3168. {
  3169. status = PSA_ERROR_GENERIC_ERROR;
  3170. goto exit;
  3171. }
  3172. if( default_iv_length > 0 )
  3173. {
  3174. if( output_size < default_iv_length )
  3175. {
  3176. status = PSA_ERROR_BUFFER_TOO_SMALL;
  3177. goto exit;
  3178. }
  3179. status = psa_generate_random( local_iv, default_iv_length );
  3180. if( status != PSA_SUCCESS )
  3181. goto exit;
  3182. }
  3183. status = psa_driver_wrapper_cipher_encrypt(
  3184. &attributes, slot->key.data, slot->key.bytes,
  3185. alg, local_iv, default_iv_length, input, input_length,
  3186. output + default_iv_length, output_size - default_iv_length,
  3187. output_length );
  3188. exit:
  3189. unlock_status = psa_unlock_key_slot( slot );
  3190. if( status == PSA_SUCCESS )
  3191. status = unlock_status;
  3192. if( status == PSA_SUCCESS )
  3193. {
  3194. if( default_iv_length > 0 )
  3195. memcpy( output, local_iv, default_iv_length );
  3196. *output_length += default_iv_length;
  3197. }
  3198. else
  3199. *output_length = 0;
  3200. return( status );
  3201. }
  3202. psa_status_t psa_cipher_decrypt( mbedtls_svc_key_id_t key,
  3203. psa_algorithm_t alg,
  3204. const uint8_t *input,
  3205. size_t input_length,
  3206. uint8_t *output,
  3207. size_t output_size,
  3208. size_t *output_length )
  3209. {
  3210. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3211. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  3212. psa_key_slot_t *slot = NULL;
  3213. if( ! PSA_ALG_IS_CIPHER( alg ) )
  3214. {
  3215. status = PSA_ERROR_INVALID_ARGUMENT;
  3216. goto exit;
  3217. }
  3218. status = psa_get_and_lock_key_slot_with_policy( key, &slot,
  3219. PSA_KEY_USAGE_DECRYPT,
  3220. alg );
  3221. if( status != PSA_SUCCESS )
  3222. goto exit;
  3223. psa_key_attributes_t attributes = {
  3224. .core = slot->attr
  3225. };
  3226. if( input_length < PSA_CIPHER_IV_LENGTH( slot->attr.type, alg ) )
  3227. {
  3228. status = PSA_ERROR_INVALID_ARGUMENT;
  3229. goto exit;
  3230. }
  3231. status = psa_driver_wrapper_cipher_decrypt(
  3232. &attributes, slot->key.data, slot->key.bytes,
  3233. alg, input, input_length,
  3234. output, output_size, output_length );
  3235. exit:
  3236. unlock_status = psa_unlock_key_slot( slot );
  3237. if( status == PSA_SUCCESS )
  3238. status = unlock_status;
  3239. if( status != PSA_SUCCESS )
  3240. *output_length = 0;
  3241. return( status );
  3242. }
  3243. /****************************************************************/
  3244. /* AEAD */
  3245. /****************************************************************/
  3246. psa_status_t psa_aead_encrypt( mbedtls_svc_key_id_t key,
  3247. psa_algorithm_t alg,
  3248. const uint8_t *nonce,
  3249. size_t nonce_length,
  3250. const uint8_t *additional_data,
  3251. size_t additional_data_length,
  3252. const uint8_t *plaintext,
  3253. size_t plaintext_length,
  3254. uint8_t *ciphertext,
  3255. size_t ciphertext_size,
  3256. size_t *ciphertext_length )
  3257. {
  3258. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3259. psa_key_slot_t *slot;
  3260. *ciphertext_length = 0;
  3261. if( !PSA_ALG_IS_AEAD( alg ) || PSA_ALG_IS_WILDCARD( alg ) )
  3262. return( PSA_ERROR_NOT_SUPPORTED );
  3263. status = psa_get_and_lock_key_slot_with_policy(
  3264. key, &slot, PSA_KEY_USAGE_ENCRYPT, alg );
  3265. if( status != PSA_SUCCESS )
  3266. return( status );
  3267. psa_key_attributes_t attributes = {
  3268. .core = slot->attr
  3269. };
  3270. status = psa_driver_wrapper_aead_encrypt(
  3271. &attributes, slot->key.data, slot->key.bytes,
  3272. alg,
  3273. nonce, nonce_length,
  3274. additional_data, additional_data_length,
  3275. plaintext, plaintext_length,
  3276. ciphertext, ciphertext_size, ciphertext_length );
  3277. if( status != PSA_SUCCESS && ciphertext_size != 0 )
  3278. memset( ciphertext, 0, ciphertext_size );
  3279. psa_unlock_key_slot( slot );
  3280. return( status );
  3281. }
  3282. psa_status_t psa_aead_decrypt( mbedtls_svc_key_id_t key,
  3283. psa_algorithm_t alg,
  3284. const uint8_t *nonce,
  3285. size_t nonce_length,
  3286. const uint8_t *additional_data,
  3287. size_t additional_data_length,
  3288. const uint8_t *ciphertext,
  3289. size_t ciphertext_length,
  3290. uint8_t *plaintext,
  3291. size_t plaintext_size,
  3292. size_t *plaintext_length )
  3293. {
  3294. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3295. psa_key_slot_t *slot;
  3296. *plaintext_length = 0;
  3297. if( !PSA_ALG_IS_AEAD( alg ) || PSA_ALG_IS_WILDCARD( alg ) )
  3298. return( PSA_ERROR_NOT_SUPPORTED );
  3299. status = psa_get_and_lock_key_slot_with_policy(
  3300. key, &slot, PSA_KEY_USAGE_DECRYPT, alg );
  3301. if( status != PSA_SUCCESS )
  3302. return( status );
  3303. psa_key_attributes_t attributes = {
  3304. .core = slot->attr
  3305. };
  3306. status = psa_driver_wrapper_aead_decrypt(
  3307. &attributes, slot->key.data, slot->key.bytes,
  3308. alg,
  3309. nonce, nonce_length,
  3310. additional_data, additional_data_length,
  3311. ciphertext, ciphertext_length,
  3312. plaintext, plaintext_size, plaintext_length );
  3313. if( status != PSA_SUCCESS && plaintext_size != 0 )
  3314. memset( plaintext, 0, plaintext_size );
  3315. psa_unlock_key_slot( slot );
  3316. return( status );
  3317. }
  3318. /****************************************************************/
  3319. /* Generators */
  3320. /****************************************************************/
  3321. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF) || \
  3322. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3323. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3324. #define AT_LEAST_ONE_BUILTIN_KDF
  3325. #endif /* At least one builtin KDF */
  3326. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF) || \
  3327. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3328. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3329. static psa_status_t psa_key_derivation_start_hmac(
  3330. psa_mac_operation_t *operation,
  3331. psa_algorithm_t hash_alg,
  3332. const uint8_t *hmac_key,
  3333. size_t hmac_key_length )
  3334. {
  3335. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  3336. psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
  3337. psa_set_key_type( &attributes, PSA_KEY_TYPE_HMAC );
  3338. psa_set_key_bits( &attributes, PSA_BYTES_TO_BITS( hmac_key_length ) );
  3339. psa_set_key_usage_flags( &attributes, PSA_KEY_USAGE_SIGN_HASH );
  3340. operation->is_sign = 1;
  3341. operation->mac_size = PSA_HASH_LENGTH( hash_alg );
  3342. status = psa_driver_wrapper_mac_sign_setup( operation,
  3343. &attributes,
  3344. hmac_key, hmac_key_length,
  3345. PSA_ALG_HMAC( hash_alg ) );
  3346. psa_reset_key_attributes( &attributes );
  3347. return( status );
  3348. }
  3349. #endif /* KDF algorithms reliant on HMAC */
  3350. #define HKDF_STATE_INIT 0 /* no input yet */
  3351. #define HKDF_STATE_STARTED 1 /* got salt */
  3352. #define HKDF_STATE_KEYED 2 /* got key */
  3353. #define HKDF_STATE_OUTPUT 3 /* output started */
  3354. static psa_algorithm_t psa_key_derivation_get_kdf_alg(
  3355. const psa_key_derivation_operation_t *operation )
  3356. {
  3357. if ( PSA_ALG_IS_KEY_AGREEMENT( operation->alg ) )
  3358. return( PSA_ALG_KEY_AGREEMENT_GET_KDF( operation->alg ) );
  3359. else
  3360. return( operation->alg );
  3361. }
  3362. psa_status_t psa_key_derivation_abort( psa_key_derivation_operation_t *operation )
  3363. {
  3364. psa_status_t status = PSA_SUCCESS;
  3365. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg( operation );
  3366. if( kdf_alg == 0 )
  3367. {
  3368. /* The object has (apparently) been initialized but it is not
  3369. * in use. It's ok to call abort on such an object, and there's
  3370. * nothing to do. */
  3371. }
  3372. else
  3373. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3374. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  3375. {
  3376. mbedtls_free( operation->ctx.hkdf.info );
  3377. status = psa_mac_abort( &operation->ctx.hkdf.hmac );
  3378. }
  3379. else
  3380. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  3381. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3382. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3383. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) ||
  3384. /* TLS-1.2 PSK-to-MS KDF uses the same core as TLS-1.2 PRF */
  3385. PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  3386. {
  3387. if( operation->ctx.tls12_prf.secret != NULL )
  3388. {
  3389. mbedtls_platform_zeroize( operation->ctx.tls12_prf.secret,
  3390. operation->ctx.tls12_prf.secret_length );
  3391. mbedtls_free( operation->ctx.tls12_prf.secret );
  3392. }
  3393. if( operation->ctx.tls12_prf.seed != NULL )
  3394. {
  3395. mbedtls_platform_zeroize( operation->ctx.tls12_prf.seed,
  3396. operation->ctx.tls12_prf.seed_length );
  3397. mbedtls_free( operation->ctx.tls12_prf.seed );
  3398. }
  3399. if( operation->ctx.tls12_prf.label != NULL )
  3400. {
  3401. mbedtls_platform_zeroize( operation->ctx.tls12_prf.label,
  3402. operation->ctx.tls12_prf.label_length );
  3403. mbedtls_free( operation->ctx.tls12_prf.label );
  3404. }
  3405. status = PSA_SUCCESS;
  3406. /* We leave the fields Ai and output_block to be erased safely by the
  3407. * mbedtls_platform_zeroize() in the end of this function. */
  3408. }
  3409. else
  3410. #endif /* defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) ||
  3411. * defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS) */
  3412. {
  3413. status = PSA_ERROR_BAD_STATE;
  3414. }
  3415. mbedtls_platform_zeroize( operation, sizeof( *operation ) );
  3416. return( status );
  3417. }
  3418. psa_status_t psa_key_derivation_get_capacity(const psa_key_derivation_operation_t *operation,
  3419. size_t *capacity)
  3420. {
  3421. if( operation->alg == 0 )
  3422. {
  3423. /* This is a blank key derivation operation. */
  3424. return( PSA_ERROR_BAD_STATE );
  3425. }
  3426. *capacity = operation->capacity;
  3427. return( PSA_SUCCESS );
  3428. }
  3429. psa_status_t psa_key_derivation_set_capacity( psa_key_derivation_operation_t *operation,
  3430. size_t capacity )
  3431. {
  3432. if( operation->alg == 0 )
  3433. return( PSA_ERROR_BAD_STATE );
  3434. if( capacity > operation->capacity )
  3435. return( PSA_ERROR_INVALID_ARGUMENT );
  3436. operation->capacity = capacity;
  3437. return( PSA_SUCCESS );
  3438. }
  3439. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3440. /* Read some bytes from an HKDF-based operation. This performs a chunk
  3441. * of the expand phase of the HKDF algorithm. */
  3442. static psa_status_t psa_key_derivation_hkdf_read( psa_hkdf_key_derivation_t *hkdf,
  3443. psa_algorithm_t hash_alg,
  3444. uint8_t *output,
  3445. size_t output_length )
  3446. {
  3447. uint8_t hash_length = PSA_HASH_LENGTH( hash_alg );
  3448. size_t hmac_output_length;
  3449. psa_status_t status;
  3450. if( hkdf->state < HKDF_STATE_KEYED || ! hkdf->info_set )
  3451. return( PSA_ERROR_BAD_STATE );
  3452. hkdf->state = HKDF_STATE_OUTPUT;
  3453. while( output_length != 0 )
  3454. {
  3455. /* Copy what remains of the current block */
  3456. uint8_t n = hash_length - hkdf->offset_in_block;
  3457. if( n > output_length )
  3458. n = (uint8_t) output_length;
  3459. memcpy( output, hkdf->output_block + hkdf->offset_in_block, n );
  3460. output += n;
  3461. output_length -= n;
  3462. hkdf->offset_in_block += n;
  3463. if( output_length == 0 )
  3464. break;
  3465. /* We can't be wanting more output after block 0xff, otherwise
  3466. * the capacity check in psa_key_derivation_output_bytes() would have
  3467. * prevented this call. It could happen only if the operation
  3468. * object was corrupted or if this function is called directly
  3469. * inside the library. */
  3470. if( hkdf->block_number == 0xff )
  3471. return( PSA_ERROR_BAD_STATE );
  3472. /* We need a new block */
  3473. ++hkdf->block_number;
  3474. hkdf->offset_in_block = 0;
  3475. status = psa_key_derivation_start_hmac( &hkdf->hmac,
  3476. hash_alg,
  3477. hkdf->prk,
  3478. hash_length );
  3479. if( status != PSA_SUCCESS )
  3480. return( status );
  3481. if( hkdf->block_number != 1 )
  3482. {
  3483. status = psa_mac_update( &hkdf->hmac,
  3484. hkdf->output_block,
  3485. hash_length );
  3486. if( status != PSA_SUCCESS )
  3487. return( status );
  3488. }
  3489. status = psa_mac_update( &hkdf->hmac,
  3490. hkdf->info,
  3491. hkdf->info_length );
  3492. if( status != PSA_SUCCESS )
  3493. return( status );
  3494. status = psa_mac_update( &hkdf->hmac,
  3495. &hkdf->block_number, 1 );
  3496. if( status != PSA_SUCCESS )
  3497. return( status );
  3498. status = psa_mac_sign_finish( &hkdf->hmac,
  3499. hkdf->output_block,
  3500. sizeof( hkdf->output_block ),
  3501. &hmac_output_length );
  3502. if( status != PSA_SUCCESS )
  3503. return( status );
  3504. }
  3505. return( PSA_SUCCESS );
  3506. }
  3507. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  3508. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3509. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3510. static psa_status_t psa_key_derivation_tls12_prf_generate_next_block(
  3511. psa_tls12_prf_key_derivation_t *tls12_prf,
  3512. psa_algorithm_t alg )
  3513. {
  3514. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH( alg );
  3515. uint8_t hash_length = PSA_HASH_LENGTH( hash_alg );
  3516. psa_mac_operation_t hmac = PSA_MAC_OPERATION_INIT;
  3517. size_t hmac_output_length;
  3518. psa_status_t status, cleanup_status;
  3519. /* We can't be wanting more output after block 0xff, otherwise
  3520. * the capacity check in psa_key_derivation_output_bytes() would have
  3521. * prevented this call. It could happen only if the operation
  3522. * object was corrupted or if this function is called directly
  3523. * inside the library. */
  3524. if( tls12_prf->block_number == 0xff )
  3525. return( PSA_ERROR_CORRUPTION_DETECTED );
  3526. /* We need a new block */
  3527. ++tls12_prf->block_number;
  3528. tls12_prf->left_in_block = hash_length;
  3529. /* Recall the definition of the TLS-1.2-PRF from RFC 5246:
  3530. *
  3531. * PRF(secret, label, seed) = P_<hash>(secret, label + seed)
  3532. *
  3533. * P_hash(secret, seed) = HMAC_hash(secret, A(1) + seed) +
  3534. * HMAC_hash(secret, A(2) + seed) +
  3535. * HMAC_hash(secret, A(3) + seed) + ...
  3536. *
  3537. * A(0) = seed
  3538. * A(i) = HMAC_hash(secret, A(i-1))
  3539. *
  3540. * The `psa_tls12_prf_key_derivation` structure saves the block
  3541. * `HMAC_hash(secret, A(i) + seed)` from which the output
  3542. * is currently extracted as `output_block` and where i is
  3543. * `block_number`.
  3544. */
  3545. status = psa_key_derivation_start_hmac( &hmac,
  3546. hash_alg,
  3547. tls12_prf->secret,
  3548. tls12_prf->secret_length );
  3549. if( status != PSA_SUCCESS )
  3550. goto cleanup;
  3551. /* Calculate A(i) where i = tls12_prf->block_number. */
  3552. if( tls12_prf->block_number == 1 )
  3553. {
  3554. /* A(1) = HMAC_hash(secret, A(0)), where A(0) = seed. (The RFC overloads
  3555. * the variable seed and in this instance means it in the context of the
  3556. * P_hash function, where seed = label + seed.) */
  3557. status = psa_mac_update( &hmac,
  3558. tls12_prf->label,
  3559. tls12_prf->label_length );
  3560. if( status != PSA_SUCCESS )
  3561. goto cleanup;
  3562. status = psa_mac_update( &hmac,
  3563. tls12_prf->seed,
  3564. tls12_prf->seed_length );
  3565. if( status != PSA_SUCCESS )
  3566. goto cleanup;
  3567. }
  3568. else
  3569. {
  3570. /* A(i) = HMAC_hash(secret, A(i-1)) */
  3571. status = psa_mac_update( &hmac, tls12_prf->Ai, hash_length );
  3572. if( status != PSA_SUCCESS )
  3573. goto cleanup;
  3574. }
  3575. status = psa_mac_sign_finish( &hmac,
  3576. tls12_prf->Ai, hash_length,
  3577. &hmac_output_length );
  3578. if( hmac_output_length != hash_length )
  3579. status = PSA_ERROR_CORRUPTION_DETECTED;
  3580. if( status != PSA_SUCCESS )
  3581. goto cleanup;
  3582. /* Calculate HMAC_hash(secret, A(i) + label + seed). */
  3583. status = psa_key_derivation_start_hmac( &hmac,
  3584. hash_alg,
  3585. tls12_prf->secret,
  3586. tls12_prf->secret_length );
  3587. if( status != PSA_SUCCESS )
  3588. goto cleanup;
  3589. status = psa_mac_update( &hmac, tls12_prf->Ai, hash_length );
  3590. if( status != PSA_SUCCESS )
  3591. goto cleanup;
  3592. status = psa_mac_update( &hmac, tls12_prf->label, tls12_prf->label_length );
  3593. if( status != PSA_SUCCESS )
  3594. goto cleanup;
  3595. status = psa_mac_update( &hmac, tls12_prf->seed, tls12_prf->seed_length );
  3596. if( status != PSA_SUCCESS )
  3597. goto cleanup;
  3598. status = psa_mac_sign_finish( &hmac,
  3599. tls12_prf->output_block, hash_length,
  3600. &hmac_output_length );
  3601. if( status != PSA_SUCCESS )
  3602. goto cleanup;
  3603. cleanup:
  3604. cleanup_status = psa_mac_abort( &hmac );
  3605. if( status == PSA_SUCCESS && cleanup_status != PSA_SUCCESS )
  3606. status = cleanup_status;
  3607. return( status );
  3608. }
  3609. static psa_status_t psa_key_derivation_tls12_prf_read(
  3610. psa_tls12_prf_key_derivation_t *tls12_prf,
  3611. psa_algorithm_t alg,
  3612. uint8_t *output,
  3613. size_t output_length )
  3614. {
  3615. psa_algorithm_t hash_alg = PSA_ALG_TLS12_PRF_GET_HASH( alg );
  3616. uint8_t hash_length = PSA_HASH_LENGTH( hash_alg );
  3617. psa_status_t status;
  3618. uint8_t offset, length;
  3619. switch( tls12_prf->state )
  3620. {
  3621. case PSA_TLS12_PRF_STATE_LABEL_SET:
  3622. tls12_prf->state = PSA_TLS12_PRF_STATE_OUTPUT;
  3623. break;
  3624. case PSA_TLS12_PRF_STATE_OUTPUT:
  3625. break;
  3626. default:
  3627. return( PSA_ERROR_BAD_STATE );
  3628. }
  3629. while( output_length != 0 )
  3630. {
  3631. /* Check if we have fully processed the current block. */
  3632. if( tls12_prf->left_in_block == 0 )
  3633. {
  3634. status = psa_key_derivation_tls12_prf_generate_next_block( tls12_prf,
  3635. alg );
  3636. if( status != PSA_SUCCESS )
  3637. return( status );
  3638. continue;
  3639. }
  3640. if( tls12_prf->left_in_block > output_length )
  3641. length = (uint8_t) output_length;
  3642. else
  3643. length = tls12_prf->left_in_block;
  3644. offset = hash_length - tls12_prf->left_in_block;
  3645. memcpy( output, tls12_prf->output_block + offset, length );
  3646. output += length;
  3647. output_length -= length;
  3648. tls12_prf->left_in_block -= length;
  3649. }
  3650. return( PSA_SUCCESS );
  3651. }
  3652. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF ||
  3653. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  3654. psa_status_t psa_key_derivation_output_bytes(
  3655. psa_key_derivation_operation_t *operation,
  3656. uint8_t *output,
  3657. size_t output_length )
  3658. {
  3659. psa_status_t status;
  3660. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg( operation );
  3661. if( operation->alg == 0 )
  3662. {
  3663. /* This is a blank operation. */
  3664. return( PSA_ERROR_BAD_STATE );
  3665. }
  3666. if( output_length > operation->capacity )
  3667. {
  3668. operation->capacity = 0;
  3669. /* Go through the error path to wipe all confidential data now
  3670. * that the operation object is useless. */
  3671. status = PSA_ERROR_INSUFFICIENT_DATA;
  3672. goto exit;
  3673. }
  3674. if( output_length == 0 && operation->capacity == 0 )
  3675. {
  3676. /* Edge case: this is a finished operation, and 0 bytes
  3677. * were requested. The right error in this case could
  3678. * be either INSUFFICIENT_CAPACITY or BAD_STATE. Return
  3679. * INSUFFICIENT_CAPACITY, which is right for a finished
  3680. * operation, for consistency with the case when
  3681. * output_length > 0. */
  3682. return( PSA_ERROR_INSUFFICIENT_DATA );
  3683. }
  3684. operation->capacity -= output_length;
  3685. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3686. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  3687. {
  3688. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH( kdf_alg );
  3689. status = psa_key_derivation_hkdf_read( &operation->ctx.hkdf, hash_alg,
  3690. output, output_length );
  3691. }
  3692. else
  3693. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  3694. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3695. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3696. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) ||
  3697. PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  3698. {
  3699. status = psa_key_derivation_tls12_prf_read( &operation->ctx.tls12_prf,
  3700. kdf_alg, output,
  3701. output_length );
  3702. }
  3703. else
  3704. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF ||
  3705. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  3706. {
  3707. (void) kdf_alg;
  3708. return( PSA_ERROR_BAD_STATE );
  3709. }
  3710. exit:
  3711. if( status != PSA_SUCCESS )
  3712. {
  3713. /* Preserve the algorithm upon errors, but clear all sensitive state.
  3714. * This allows us to differentiate between exhausted operations and
  3715. * blank operations, so we can return PSA_ERROR_BAD_STATE on blank
  3716. * operations. */
  3717. psa_algorithm_t alg = operation->alg;
  3718. psa_key_derivation_abort( operation );
  3719. operation->alg = alg;
  3720. memset( output, '!', output_length );
  3721. }
  3722. return( status );
  3723. }
  3724. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  3725. static void psa_des_set_key_parity( uint8_t *data, size_t data_size )
  3726. {
  3727. if( data_size >= 8 )
  3728. mbedtls_des_key_set_parity( data );
  3729. if( data_size >= 16 )
  3730. mbedtls_des_key_set_parity( data + 8 );
  3731. if( data_size >= 24 )
  3732. mbedtls_des_key_set_parity( data + 16 );
  3733. }
  3734. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  3735. static psa_status_t psa_generate_derived_key_internal(
  3736. psa_key_slot_t *slot,
  3737. size_t bits,
  3738. psa_key_derivation_operation_t *operation )
  3739. {
  3740. uint8_t *data = NULL;
  3741. size_t bytes = PSA_BITS_TO_BYTES( bits );
  3742. psa_status_t status;
  3743. if( ! key_type_is_raw_bytes( slot->attr.type ) )
  3744. return( PSA_ERROR_INVALID_ARGUMENT );
  3745. if( bits % 8 != 0 )
  3746. return( PSA_ERROR_INVALID_ARGUMENT );
  3747. data = mbedtls_calloc( 1, bytes );
  3748. if( data == NULL )
  3749. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  3750. status = psa_key_derivation_output_bytes( operation, data, bytes );
  3751. if( status != PSA_SUCCESS )
  3752. goto exit;
  3753. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  3754. if( slot->attr.type == PSA_KEY_TYPE_DES )
  3755. psa_des_set_key_parity( data, bytes );
  3756. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  3757. status = psa_allocate_buffer_to_slot( slot, bytes );
  3758. if( status != PSA_SUCCESS )
  3759. goto exit;
  3760. slot->attr.bits = (psa_key_bits_t) bits;
  3761. psa_key_attributes_t attributes = {
  3762. .core = slot->attr
  3763. };
  3764. status = psa_driver_wrapper_import_key( &attributes,
  3765. data, bytes,
  3766. slot->key.data,
  3767. slot->key.bytes,
  3768. &slot->key.bytes, &bits );
  3769. if( bits != slot->attr.bits )
  3770. status = PSA_ERROR_INVALID_ARGUMENT;
  3771. exit:
  3772. mbedtls_free( data );
  3773. return( status );
  3774. }
  3775. psa_status_t psa_key_derivation_output_key( const psa_key_attributes_t *attributes,
  3776. psa_key_derivation_operation_t *operation,
  3777. mbedtls_svc_key_id_t *key )
  3778. {
  3779. psa_status_t status;
  3780. psa_key_slot_t *slot = NULL;
  3781. psa_se_drv_table_entry_t *driver = NULL;
  3782. *key = MBEDTLS_SVC_KEY_ID_INIT;
  3783. /* Reject any attempt to create a zero-length key so that we don't
  3784. * risk tripping up later, e.g. on a malloc(0) that returns NULL. */
  3785. if( psa_get_key_bits( attributes ) == 0 )
  3786. return( PSA_ERROR_INVALID_ARGUMENT );
  3787. if( operation->alg == PSA_ALG_NONE )
  3788. return( PSA_ERROR_BAD_STATE );
  3789. if( ! operation->can_output_key )
  3790. return( PSA_ERROR_NOT_PERMITTED );
  3791. status = psa_start_key_creation( PSA_KEY_CREATION_DERIVE, attributes,
  3792. &slot, &driver );
  3793. #if defined(MBEDTLS_PSA_CRYPTO_SE_C)
  3794. if( driver != NULL )
  3795. {
  3796. /* Deriving a key in a secure element is not implemented yet. */
  3797. status = PSA_ERROR_NOT_SUPPORTED;
  3798. }
  3799. #endif /* MBEDTLS_PSA_CRYPTO_SE_C */
  3800. if( status == PSA_SUCCESS )
  3801. {
  3802. status = psa_generate_derived_key_internal( slot,
  3803. attributes->core.bits,
  3804. operation );
  3805. }
  3806. if( status == PSA_SUCCESS )
  3807. status = psa_finish_key_creation( slot, driver, key );
  3808. if( status != PSA_SUCCESS )
  3809. psa_fail_key_creation( slot, driver );
  3810. return( status );
  3811. }
  3812. /****************************************************************/
  3813. /* Key derivation */
  3814. /****************************************************************/
  3815. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  3816. static psa_status_t psa_key_derivation_setup_kdf(
  3817. psa_key_derivation_operation_t *operation,
  3818. psa_algorithm_t kdf_alg )
  3819. {
  3820. int is_kdf_alg_supported;
  3821. /* Make sure that operation->ctx is properly zero-initialised. (Macro
  3822. * initialisers for this union leave some bytes unspecified.) */
  3823. memset( &operation->ctx, 0, sizeof( operation->ctx ) );
  3824. /* Make sure that kdf_alg is a supported key derivation algorithm. */
  3825. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3826. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  3827. is_kdf_alg_supported = 1;
  3828. else
  3829. #endif
  3830. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF)
  3831. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) )
  3832. is_kdf_alg_supported = 1;
  3833. else
  3834. #endif
  3835. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3836. if( PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  3837. is_kdf_alg_supported = 1;
  3838. else
  3839. #endif
  3840. is_kdf_alg_supported = 0;
  3841. if( is_kdf_alg_supported )
  3842. {
  3843. psa_algorithm_t hash_alg = PSA_ALG_HKDF_GET_HASH( kdf_alg );
  3844. size_t hash_size = PSA_HASH_LENGTH( hash_alg );
  3845. if( hash_size == 0 )
  3846. return( PSA_ERROR_NOT_SUPPORTED );
  3847. if( ( PSA_ALG_IS_TLS12_PRF( kdf_alg ) ||
  3848. PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) ) &&
  3849. ! ( hash_alg == PSA_ALG_SHA_256 || hash_alg == PSA_ALG_SHA_384 ) )
  3850. {
  3851. return( PSA_ERROR_NOT_SUPPORTED );
  3852. }
  3853. operation->capacity = 255 * hash_size;
  3854. return( PSA_SUCCESS );
  3855. }
  3856. return( PSA_ERROR_NOT_SUPPORTED );
  3857. }
  3858. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  3859. psa_status_t psa_key_derivation_setup( psa_key_derivation_operation_t *operation,
  3860. psa_algorithm_t alg )
  3861. {
  3862. psa_status_t status;
  3863. if( operation->alg != 0 )
  3864. return( PSA_ERROR_BAD_STATE );
  3865. if( PSA_ALG_IS_RAW_KEY_AGREEMENT( alg ) )
  3866. return( PSA_ERROR_INVALID_ARGUMENT );
  3867. else if( PSA_ALG_IS_KEY_AGREEMENT( alg ) )
  3868. {
  3869. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  3870. psa_algorithm_t kdf_alg = PSA_ALG_KEY_AGREEMENT_GET_KDF( alg );
  3871. status = psa_key_derivation_setup_kdf( operation, kdf_alg );
  3872. #else
  3873. return( PSA_ERROR_NOT_SUPPORTED );
  3874. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  3875. }
  3876. else if( PSA_ALG_IS_KEY_DERIVATION( alg ) )
  3877. {
  3878. #if defined(AT_LEAST_ONE_BUILTIN_KDF)
  3879. status = psa_key_derivation_setup_kdf( operation, alg );
  3880. #else
  3881. return( PSA_ERROR_NOT_SUPPORTED );
  3882. #endif /* AT_LEAST_ONE_BUILTIN_KDF */
  3883. }
  3884. else
  3885. return( PSA_ERROR_INVALID_ARGUMENT );
  3886. if( status == PSA_SUCCESS )
  3887. operation->alg = alg;
  3888. return( status );
  3889. }
  3890. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  3891. static psa_status_t psa_hkdf_input( psa_hkdf_key_derivation_t *hkdf,
  3892. psa_algorithm_t hash_alg,
  3893. psa_key_derivation_step_t step,
  3894. const uint8_t *data,
  3895. size_t data_length )
  3896. {
  3897. psa_status_t status;
  3898. switch( step )
  3899. {
  3900. case PSA_KEY_DERIVATION_INPUT_SALT:
  3901. if( hkdf->state != HKDF_STATE_INIT )
  3902. return( PSA_ERROR_BAD_STATE );
  3903. else
  3904. {
  3905. status = psa_key_derivation_start_hmac( &hkdf->hmac,
  3906. hash_alg,
  3907. data, data_length );
  3908. if( status != PSA_SUCCESS )
  3909. return( status );
  3910. hkdf->state = HKDF_STATE_STARTED;
  3911. return( PSA_SUCCESS );
  3912. }
  3913. case PSA_KEY_DERIVATION_INPUT_SECRET:
  3914. /* If no salt was provided, use an empty salt. */
  3915. if( hkdf->state == HKDF_STATE_INIT )
  3916. {
  3917. status = psa_key_derivation_start_hmac( &hkdf->hmac,
  3918. hash_alg,
  3919. NULL, 0 );
  3920. if( status != PSA_SUCCESS )
  3921. return( status );
  3922. hkdf->state = HKDF_STATE_STARTED;
  3923. }
  3924. if( hkdf->state != HKDF_STATE_STARTED )
  3925. return( PSA_ERROR_BAD_STATE );
  3926. status = psa_mac_update( &hkdf->hmac,
  3927. data, data_length );
  3928. if( status != PSA_SUCCESS )
  3929. return( status );
  3930. status = psa_mac_sign_finish( &hkdf->hmac,
  3931. hkdf->prk,
  3932. sizeof( hkdf->prk ),
  3933. &data_length );
  3934. if( status != PSA_SUCCESS )
  3935. return( status );
  3936. hkdf->offset_in_block = PSA_HASH_LENGTH( hash_alg );
  3937. hkdf->block_number = 0;
  3938. hkdf->state = HKDF_STATE_KEYED;
  3939. return( PSA_SUCCESS );
  3940. case PSA_KEY_DERIVATION_INPUT_INFO:
  3941. if( hkdf->state == HKDF_STATE_OUTPUT )
  3942. return( PSA_ERROR_BAD_STATE );
  3943. if( hkdf->info_set )
  3944. return( PSA_ERROR_BAD_STATE );
  3945. hkdf->info_length = data_length;
  3946. if( data_length != 0 )
  3947. {
  3948. hkdf->info = mbedtls_calloc( 1, data_length );
  3949. if( hkdf->info == NULL )
  3950. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  3951. memcpy( hkdf->info, data, data_length );
  3952. }
  3953. hkdf->info_set = 1;
  3954. return( PSA_SUCCESS );
  3955. default:
  3956. return( PSA_ERROR_INVALID_ARGUMENT );
  3957. }
  3958. }
  3959. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  3960. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) || \
  3961. defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  3962. static psa_status_t psa_tls12_prf_set_seed( psa_tls12_prf_key_derivation_t *prf,
  3963. const uint8_t *data,
  3964. size_t data_length )
  3965. {
  3966. if( prf->state != PSA_TLS12_PRF_STATE_INIT )
  3967. return( PSA_ERROR_BAD_STATE );
  3968. if( data_length != 0 )
  3969. {
  3970. prf->seed = mbedtls_calloc( 1, data_length );
  3971. if( prf->seed == NULL )
  3972. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  3973. memcpy( prf->seed, data, data_length );
  3974. prf->seed_length = data_length;
  3975. }
  3976. prf->state = PSA_TLS12_PRF_STATE_SEED_SET;
  3977. return( PSA_SUCCESS );
  3978. }
  3979. static psa_status_t psa_tls12_prf_set_key( psa_tls12_prf_key_derivation_t *prf,
  3980. const uint8_t *data,
  3981. size_t data_length )
  3982. {
  3983. if( prf->state != PSA_TLS12_PRF_STATE_SEED_SET )
  3984. return( PSA_ERROR_BAD_STATE );
  3985. if( data_length != 0 )
  3986. {
  3987. prf->secret = mbedtls_calloc( 1, data_length );
  3988. if( prf->secret == NULL )
  3989. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  3990. memcpy( prf->secret, data, data_length );
  3991. prf->secret_length = data_length;
  3992. }
  3993. prf->state = PSA_TLS12_PRF_STATE_KEY_SET;
  3994. return( PSA_SUCCESS );
  3995. }
  3996. static psa_status_t psa_tls12_prf_set_label( psa_tls12_prf_key_derivation_t *prf,
  3997. const uint8_t *data,
  3998. size_t data_length )
  3999. {
  4000. if( prf->state != PSA_TLS12_PRF_STATE_KEY_SET )
  4001. return( PSA_ERROR_BAD_STATE );
  4002. if( data_length != 0 )
  4003. {
  4004. prf->label = mbedtls_calloc( 1, data_length );
  4005. if( prf->label == NULL )
  4006. return( PSA_ERROR_INSUFFICIENT_MEMORY );
  4007. memcpy( prf->label, data, data_length );
  4008. prf->label_length = data_length;
  4009. }
  4010. prf->state = PSA_TLS12_PRF_STATE_LABEL_SET;
  4011. return( PSA_SUCCESS );
  4012. }
  4013. static psa_status_t psa_tls12_prf_input( psa_tls12_prf_key_derivation_t *prf,
  4014. psa_key_derivation_step_t step,
  4015. const uint8_t *data,
  4016. size_t data_length )
  4017. {
  4018. switch( step )
  4019. {
  4020. case PSA_KEY_DERIVATION_INPUT_SEED:
  4021. return( psa_tls12_prf_set_seed( prf, data, data_length ) );
  4022. case PSA_KEY_DERIVATION_INPUT_SECRET:
  4023. return( psa_tls12_prf_set_key( prf, data, data_length ) );
  4024. case PSA_KEY_DERIVATION_INPUT_LABEL:
  4025. return( psa_tls12_prf_set_label( prf, data, data_length ) );
  4026. default:
  4027. return( PSA_ERROR_INVALID_ARGUMENT );
  4028. }
  4029. }
  4030. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF) ||
  4031. * MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4032. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4033. static psa_status_t psa_tls12_prf_psk_to_ms_set_key(
  4034. psa_tls12_prf_key_derivation_t *prf,
  4035. const uint8_t *data,
  4036. size_t data_length )
  4037. {
  4038. psa_status_t status;
  4039. uint8_t pms[ 4 + 2 * PSA_TLS12_PSK_TO_MS_PSK_MAX_SIZE ];
  4040. uint8_t *cur = pms;
  4041. if( data_length > PSA_TLS12_PSK_TO_MS_PSK_MAX_SIZE )
  4042. return( PSA_ERROR_INVALID_ARGUMENT );
  4043. /* Quoting RFC 4279, Section 2:
  4044. *
  4045. * The premaster secret is formed as follows: if the PSK is N octets
  4046. * long, concatenate a uint16 with the value N, N zero octets, a second
  4047. * uint16 with the value N, and the PSK itself.
  4048. */
  4049. *cur++ = MBEDTLS_BYTE_1( data_length );
  4050. *cur++ = MBEDTLS_BYTE_0( data_length );
  4051. memset( cur, 0, data_length );
  4052. cur += data_length;
  4053. *cur++ = pms[0];
  4054. *cur++ = pms[1];
  4055. memcpy( cur, data, data_length );
  4056. cur += data_length;
  4057. status = psa_tls12_prf_set_key( prf, pms, cur - pms );
  4058. mbedtls_platform_zeroize( pms, sizeof( pms ) );
  4059. return( status );
  4060. }
  4061. static psa_status_t psa_tls12_prf_psk_to_ms_input(
  4062. psa_tls12_prf_key_derivation_t *prf,
  4063. psa_key_derivation_step_t step,
  4064. const uint8_t *data,
  4065. size_t data_length )
  4066. {
  4067. if( step == PSA_KEY_DERIVATION_INPUT_SECRET )
  4068. {
  4069. return( psa_tls12_prf_psk_to_ms_set_key( prf,
  4070. data, data_length ) );
  4071. }
  4072. return( psa_tls12_prf_input( prf, step, data, data_length ) );
  4073. }
  4074. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4075. /** Check whether the given key type is acceptable for the given
  4076. * input step of a key derivation.
  4077. *
  4078. * Secret inputs must have the type #PSA_KEY_TYPE_DERIVE.
  4079. * Non-secret inputs must have the type #PSA_KEY_TYPE_RAW_DATA.
  4080. * Both secret and non-secret inputs can alternatively have the type
  4081. * #PSA_KEY_TYPE_NONE, which is never the type of a key object, meaning
  4082. * that the input was passed as a buffer rather than via a key object.
  4083. */
  4084. static int psa_key_derivation_check_input_type(
  4085. psa_key_derivation_step_t step,
  4086. psa_key_type_t key_type )
  4087. {
  4088. switch( step )
  4089. {
  4090. case PSA_KEY_DERIVATION_INPUT_SECRET:
  4091. if( key_type == PSA_KEY_TYPE_DERIVE )
  4092. return( PSA_SUCCESS );
  4093. if( key_type == PSA_KEY_TYPE_NONE )
  4094. return( PSA_SUCCESS );
  4095. break;
  4096. case PSA_KEY_DERIVATION_INPUT_LABEL:
  4097. case PSA_KEY_DERIVATION_INPUT_SALT:
  4098. case PSA_KEY_DERIVATION_INPUT_INFO:
  4099. case PSA_KEY_DERIVATION_INPUT_SEED:
  4100. if( key_type == PSA_KEY_TYPE_RAW_DATA )
  4101. return( PSA_SUCCESS );
  4102. if( key_type == PSA_KEY_TYPE_NONE )
  4103. return( PSA_SUCCESS );
  4104. break;
  4105. }
  4106. return( PSA_ERROR_INVALID_ARGUMENT );
  4107. }
  4108. static psa_status_t psa_key_derivation_input_internal(
  4109. psa_key_derivation_operation_t *operation,
  4110. psa_key_derivation_step_t step,
  4111. psa_key_type_t key_type,
  4112. const uint8_t *data,
  4113. size_t data_length )
  4114. {
  4115. psa_status_t status;
  4116. psa_algorithm_t kdf_alg = psa_key_derivation_get_kdf_alg( operation );
  4117. status = psa_key_derivation_check_input_type( step, key_type );
  4118. if( status != PSA_SUCCESS )
  4119. goto exit;
  4120. #if defined(MBEDTLS_PSA_BUILTIN_ALG_HKDF)
  4121. if( PSA_ALG_IS_HKDF( kdf_alg ) )
  4122. {
  4123. status = psa_hkdf_input( &operation->ctx.hkdf,
  4124. PSA_ALG_HKDF_GET_HASH( kdf_alg ),
  4125. step, data, data_length );
  4126. }
  4127. else
  4128. #endif /* MBEDTLS_PSA_BUILTIN_ALG_HKDF */
  4129. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF)
  4130. if( PSA_ALG_IS_TLS12_PRF( kdf_alg ) )
  4131. {
  4132. status = psa_tls12_prf_input( &operation->ctx.tls12_prf,
  4133. step, data, data_length );
  4134. }
  4135. else
  4136. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF */
  4137. #if defined(MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS)
  4138. if( PSA_ALG_IS_TLS12_PSK_TO_MS( kdf_alg ) )
  4139. {
  4140. status = psa_tls12_prf_psk_to_ms_input( &operation->ctx.tls12_prf,
  4141. step, data, data_length );
  4142. }
  4143. else
  4144. #endif /* MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS */
  4145. {
  4146. /* This can't happen unless the operation object was not initialized */
  4147. (void) data;
  4148. (void) data_length;
  4149. (void) kdf_alg;
  4150. return( PSA_ERROR_BAD_STATE );
  4151. }
  4152. exit:
  4153. if( status != PSA_SUCCESS )
  4154. psa_key_derivation_abort( operation );
  4155. return( status );
  4156. }
  4157. psa_status_t psa_key_derivation_input_bytes(
  4158. psa_key_derivation_operation_t *operation,
  4159. psa_key_derivation_step_t step,
  4160. const uint8_t *data,
  4161. size_t data_length )
  4162. {
  4163. return( psa_key_derivation_input_internal( operation, step,
  4164. PSA_KEY_TYPE_NONE,
  4165. data, data_length ) );
  4166. }
  4167. psa_status_t psa_key_derivation_input_key(
  4168. psa_key_derivation_operation_t *operation,
  4169. psa_key_derivation_step_t step,
  4170. mbedtls_svc_key_id_t key )
  4171. {
  4172. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4173. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  4174. psa_key_slot_t *slot;
  4175. status = psa_get_and_lock_transparent_key_slot_with_policy(
  4176. key, &slot, PSA_KEY_USAGE_DERIVE, operation->alg );
  4177. if( status != PSA_SUCCESS )
  4178. {
  4179. psa_key_derivation_abort( operation );
  4180. return( status );
  4181. }
  4182. /* Passing a key object as a SECRET input unlocks the permission
  4183. * to output to a key object. */
  4184. if( step == PSA_KEY_DERIVATION_INPUT_SECRET )
  4185. operation->can_output_key = 1;
  4186. status = psa_key_derivation_input_internal( operation,
  4187. step, slot->attr.type,
  4188. slot->key.data,
  4189. slot->key.bytes );
  4190. unlock_status = psa_unlock_key_slot( slot );
  4191. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  4192. }
  4193. /****************************************************************/
  4194. /* Key agreement */
  4195. /****************************************************************/
  4196. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  4197. static psa_status_t psa_key_agreement_ecdh( const uint8_t *peer_key,
  4198. size_t peer_key_length,
  4199. const mbedtls_ecp_keypair *our_key,
  4200. uint8_t *shared_secret,
  4201. size_t shared_secret_size,
  4202. size_t *shared_secret_length )
  4203. {
  4204. mbedtls_ecp_keypair *their_key = NULL;
  4205. mbedtls_ecdh_context ecdh;
  4206. psa_status_t status;
  4207. size_t bits = 0;
  4208. psa_ecc_family_t curve = mbedtls_ecc_group_to_psa( our_key->grp.id, &bits );
  4209. mbedtls_ecdh_init( &ecdh );
  4210. status = mbedtls_psa_ecp_load_representation(
  4211. PSA_KEY_TYPE_ECC_PUBLIC_KEY(curve),
  4212. bits,
  4213. peer_key,
  4214. peer_key_length,
  4215. &their_key );
  4216. if( status != PSA_SUCCESS )
  4217. goto exit;
  4218. status = mbedtls_to_psa_error(
  4219. mbedtls_ecdh_get_params( &ecdh, their_key, MBEDTLS_ECDH_THEIRS ) );
  4220. if( status != PSA_SUCCESS )
  4221. goto exit;
  4222. status = mbedtls_to_psa_error(
  4223. mbedtls_ecdh_get_params( &ecdh, our_key, MBEDTLS_ECDH_OURS ) );
  4224. if( status != PSA_SUCCESS )
  4225. goto exit;
  4226. status = mbedtls_to_psa_error(
  4227. mbedtls_ecdh_calc_secret( &ecdh,
  4228. shared_secret_length,
  4229. shared_secret, shared_secret_size,
  4230. mbedtls_psa_get_random,
  4231. MBEDTLS_PSA_RANDOM_STATE ) );
  4232. if( status != PSA_SUCCESS )
  4233. goto exit;
  4234. if( PSA_BITS_TO_BYTES( bits ) != *shared_secret_length )
  4235. status = PSA_ERROR_CORRUPTION_DETECTED;
  4236. exit:
  4237. if( status != PSA_SUCCESS )
  4238. mbedtls_platform_zeroize( shared_secret, shared_secret_size );
  4239. mbedtls_ecdh_free( &ecdh );
  4240. mbedtls_ecp_keypair_free( their_key );
  4241. mbedtls_free( their_key );
  4242. return( status );
  4243. }
  4244. #endif /* MBEDTLS_PSA_BUILTIN_ALG_ECDH */
  4245. #define PSA_KEY_AGREEMENT_MAX_SHARED_SECRET_SIZE MBEDTLS_ECP_MAX_BYTES
  4246. static psa_status_t psa_key_agreement_raw_internal( psa_algorithm_t alg,
  4247. psa_key_slot_t *private_key,
  4248. const uint8_t *peer_key,
  4249. size_t peer_key_length,
  4250. uint8_t *shared_secret,
  4251. size_t shared_secret_size,
  4252. size_t *shared_secret_length )
  4253. {
  4254. switch( alg )
  4255. {
  4256. #if defined(MBEDTLS_PSA_BUILTIN_ALG_ECDH)
  4257. case PSA_ALG_ECDH:
  4258. if( ! PSA_KEY_TYPE_IS_ECC_KEY_PAIR( private_key->attr.type ) )
  4259. return( PSA_ERROR_INVALID_ARGUMENT );
  4260. mbedtls_ecp_keypair *ecp = NULL;
  4261. psa_status_t status = mbedtls_psa_ecp_load_representation(
  4262. private_key->attr.type,
  4263. private_key->attr.bits,
  4264. private_key->key.data,
  4265. private_key->key.bytes,
  4266. &ecp );
  4267. if( status != PSA_SUCCESS )
  4268. return( status );
  4269. status = psa_key_agreement_ecdh( peer_key, peer_key_length,
  4270. ecp,
  4271. shared_secret, shared_secret_size,
  4272. shared_secret_length );
  4273. mbedtls_ecp_keypair_free( ecp );
  4274. mbedtls_free( ecp );
  4275. return( status );
  4276. #endif /* MBEDTLS_PSA_BUILTIN_ALG_ECDH */
  4277. default:
  4278. (void) private_key;
  4279. (void) peer_key;
  4280. (void) peer_key_length;
  4281. (void) shared_secret;
  4282. (void) shared_secret_size;
  4283. (void) shared_secret_length;
  4284. return( PSA_ERROR_NOT_SUPPORTED );
  4285. }
  4286. }
  4287. /* Note that if this function fails, you must call psa_key_derivation_abort()
  4288. * to potentially free embedded data structures and wipe confidential data.
  4289. */
  4290. static psa_status_t psa_key_agreement_internal( psa_key_derivation_operation_t *operation,
  4291. psa_key_derivation_step_t step,
  4292. psa_key_slot_t *private_key,
  4293. const uint8_t *peer_key,
  4294. size_t peer_key_length )
  4295. {
  4296. psa_status_t status;
  4297. uint8_t shared_secret[PSA_KEY_AGREEMENT_MAX_SHARED_SECRET_SIZE];
  4298. size_t shared_secret_length = 0;
  4299. psa_algorithm_t ka_alg = PSA_ALG_KEY_AGREEMENT_GET_BASE( operation->alg );
  4300. /* Step 1: run the secret agreement algorithm to generate the shared
  4301. * secret. */
  4302. status = psa_key_agreement_raw_internal( ka_alg,
  4303. private_key,
  4304. peer_key, peer_key_length,
  4305. shared_secret,
  4306. sizeof( shared_secret ),
  4307. &shared_secret_length );
  4308. if( status != PSA_SUCCESS )
  4309. goto exit;
  4310. /* Step 2: set up the key derivation to generate key material from
  4311. * the shared secret. A shared secret is permitted wherever a key
  4312. * of type DERIVE is permitted. */
  4313. status = psa_key_derivation_input_internal( operation, step,
  4314. PSA_KEY_TYPE_DERIVE,
  4315. shared_secret,
  4316. shared_secret_length );
  4317. exit:
  4318. mbedtls_platform_zeroize( shared_secret, shared_secret_length );
  4319. return( status );
  4320. }
  4321. psa_status_t psa_key_derivation_key_agreement( psa_key_derivation_operation_t *operation,
  4322. psa_key_derivation_step_t step,
  4323. mbedtls_svc_key_id_t private_key,
  4324. const uint8_t *peer_key,
  4325. size_t peer_key_length )
  4326. {
  4327. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4328. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  4329. psa_key_slot_t *slot;
  4330. if( ! PSA_ALG_IS_KEY_AGREEMENT( operation->alg ) )
  4331. return( PSA_ERROR_INVALID_ARGUMENT );
  4332. status = psa_get_and_lock_transparent_key_slot_with_policy(
  4333. private_key, &slot, PSA_KEY_USAGE_DERIVE, operation->alg );
  4334. if( status != PSA_SUCCESS )
  4335. return( status );
  4336. status = psa_key_agreement_internal( operation, step,
  4337. slot,
  4338. peer_key, peer_key_length );
  4339. if( status != PSA_SUCCESS )
  4340. psa_key_derivation_abort( operation );
  4341. else
  4342. {
  4343. /* If a private key has been added as SECRET, we allow the derived
  4344. * key material to be used as a key in PSA Crypto. */
  4345. if( step == PSA_KEY_DERIVATION_INPUT_SECRET )
  4346. operation->can_output_key = 1;
  4347. }
  4348. unlock_status = psa_unlock_key_slot( slot );
  4349. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  4350. }
  4351. psa_status_t psa_raw_key_agreement( psa_algorithm_t alg,
  4352. mbedtls_svc_key_id_t private_key,
  4353. const uint8_t *peer_key,
  4354. size_t peer_key_length,
  4355. uint8_t *output,
  4356. size_t output_size,
  4357. size_t *output_length )
  4358. {
  4359. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4360. psa_status_t unlock_status = PSA_ERROR_CORRUPTION_DETECTED;
  4361. psa_key_slot_t *slot = NULL;
  4362. if( ! PSA_ALG_IS_KEY_AGREEMENT( alg ) )
  4363. {
  4364. status = PSA_ERROR_INVALID_ARGUMENT;
  4365. goto exit;
  4366. }
  4367. status = psa_get_and_lock_transparent_key_slot_with_policy(
  4368. private_key, &slot, PSA_KEY_USAGE_DERIVE, alg );
  4369. if( status != PSA_SUCCESS )
  4370. goto exit;
  4371. status = psa_key_agreement_raw_internal( alg, slot,
  4372. peer_key, peer_key_length,
  4373. output, output_size,
  4374. output_length );
  4375. exit:
  4376. if( status != PSA_SUCCESS )
  4377. {
  4378. /* If an error happens and is not handled properly, the output
  4379. * may be used as a key to protect sensitive data. Arrange for such
  4380. * a key to be random, which is likely to result in decryption or
  4381. * verification errors. This is better than filling the buffer with
  4382. * some constant data such as zeros, which would result in the data
  4383. * being protected with a reproducible, easily knowable key.
  4384. */
  4385. psa_generate_random( output, output_size );
  4386. *output_length = output_size;
  4387. }
  4388. unlock_status = psa_unlock_key_slot( slot );
  4389. return( ( status == PSA_SUCCESS ) ? unlock_status : status );
  4390. }
  4391. /****************************************************************/
  4392. /* Random generation */
  4393. /****************************************************************/
  4394. /** Initialize the PSA random generator.
  4395. */
  4396. static void mbedtls_psa_random_init( mbedtls_psa_random_context_t *rng )
  4397. {
  4398. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4399. memset( rng, 0, sizeof( *rng ) );
  4400. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4401. /* Set default configuration if
  4402. * mbedtls_psa_crypto_configure_entropy_sources() hasn't been called. */
  4403. if( rng->entropy_init == NULL )
  4404. rng->entropy_init = mbedtls_entropy_init;
  4405. if( rng->entropy_free == NULL )
  4406. rng->entropy_free = mbedtls_entropy_free;
  4407. rng->entropy_init( &rng->entropy );
  4408. #if defined(MBEDTLS_PSA_INJECT_ENTROPY) && \
  4409. defined(MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES)
  4410. /* The PSA entropy injection feature depends on using NV seed as an entropy
  4411. * source. Add NV seed as an entropy source for PSA entropy injection. */
  4412. mbedtls_entropy_add_source( &rng->entropy,
  4413. mbedtls_nv_seed_poll, NULL,
  4414. MBEDTLS_ENTROPY_BLOCK_SIZE,
  4415. MBEDTLS_ENTROPY_SOURCE_STRONG );
  4416. #endif
  4417. mbedtls_psa_drbg_init( MBEDTLS_PSA_RANDOM_STATE );
  4418. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4419. }
  4420. /** Deinitialize the PSA random generator.
  4421. */
  4422. static void mbedtls_psa_random_free( mbedtls_psa_random_context_t *rng )
  4423. {
  4424. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4425. memset( rng, 0, sizeof( *rng ) );
  4426. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4427. mbedtls_psa_drbg_free( MBEDTLS_PSA_RANDOM_STATE );
  4428. rng->entropy_free( &rng->entropy );
  4429. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4430. }
  4431. /** Seed the PSA random generator.
  4432. */
  4433. static psa_status_t mbedtls_psa_random_seed( mbedtls_psa_random_context_t *rng )
  4434. {
  4435. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4436. /* Do nothing: the external RNG seeds itself. */
  4437. (void) rng;
  4438. return( PSA_SUCCESS );
  4439. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4440. const unsigned char drbg_seed[] = "PSA";
  4441. int ret = mbedtls_psa_drbg_seed( &rng->entropy,
  4442. drbg_seed, sizeof( drbg_seed ) - 1 );
  4443. return mbedtls_to_psa_error( ret );
  4444. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4445. }
  4446. psa_status_t psa_generate_random( uint8_t *output,
  4447. size_t output_size )
  4448. {
  4449. GUARD_MODULE_INITIALIZED;
  4450. #if defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4451. size_t output_length = 0;
  4452. psa_status_t status = mbedtls_psa_external_get_random( &global_data.rng,
  4453. output, output_size,
  4454. &output_length );
  4455. if( status != PSA_SUCCESS )
  4456. return( status );
  4457. /* Breaking up a request into smaller chunks is currently not supported
  4458. * for the extrernal RNG interface. */
  4459. if( output_length != output_size )
  4460. return( PSA_ERROR_INSUFFICIENT_ENTROPY );
  4461. return( PSA_SUCCESS );
  4462. #else /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4463. while( output_size > 0 )
  4464. {
  4465. size_t request_size =
  4466. ( output_size > MBEDTLS_PSA_RANDOM_MAX_REQUEST ?
  4467. MBEDTLS_PSA_RANDOM_MAX_REQUEST :
  4468. output_size );
  4469. int ret = mbedtls_psa_get_random( MBEDTLS_PSA_RANDOM_STATE,
  4470. output, request_size );
  4471. if( ret != 0 )
  4472. return( mbedtls_to_psa_error( ret ) );
  4473. output_size -= request_size;
  4474. output += request_size;
  4475. }
  4476. return( PSA_SUCCESS );
  4477. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4478. }
  4479. /* Wrapper function allowing the classic API to use the PSA RNG.
  4480. *
  4481. * `mbedtls_psa_get_random(MBEDTLS_PSA_RANDOM_STATE, ...)` calls
  4482. * `psa_generate_random(...)`. The state parameter is ignored since the
  4483. * PSA API doesn't support passing an explicit state.
  4484. *
  4485. * In the non-external case, psa_generate_random() calls an
  4486. * `mbedtls_xxx_drbg_random` function which has exactly the same signature
  4487. * and semantics as mbedtls_psa_get_random(). As an optimization,
  4488. * instead of doing this back-and-forth between the PSA API and the
  4489. * classic API, psa_crypto_random_impl.h defines `mbedtls_psa_get_random`
  4490. * as a constant function pointer to `mbedtls_xxx_drbg_random`.
  4491. */
  4492. #if defined (MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4493. int mbedtls_psa_get_random( void *p_rng,
  4494. unsigned char *output,
  4495. size_t output_size )
  4496. {
  4497. /* This function takes a pointer to the RNG state because that's what
  4498. * classic mbedtls functions using an RNG expect. The PSA RNG manages
  4499. * its own state internally and doesn't let the caller access that state.
  4500. * So we just ignore the state parameter, and in practice we'll pass
  4501. * NULL. */
  4502. (void) p_rng;
  4503. psa_status_t status = psa_generate_random( output, output_size );
  4504. if( status == PSA_SUCCESS )
  4505. return( 0 );
  4506. else
  4507. return( MBEDTLS_ERR_ENTROPY_SOURCE_FAILED );
  4508. }
  4509. #endif /* MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG */
  4510. #if defined(MBEDTLS_PSA_INJECT_ENTROPY)
  4511. #include "mbedtls/entropy_poll.h"
  4512. psa_status_t mbedtls_psa_inject_entropy( const uint8_t *seed,
  4513. size_t seed_size )
  4514. {
  4515. if( global_data.initialized )
  4516. return( PSA_ERROR_NOT_PERMITTED );
  4517. if( ( ( seed_size < MBEDTLS_ENTROPY_MIN_PLATFORM ) ||
  4518. ( seed_size < MBEDTLS_ENTROPY_BLOCK_SIZE ) ) ||
  4519. ( seed_size > MBEDTLS_ENTROPY_MAX_SEED_SIZE ) )
  4520. return( PSA_ERROR_INVALID_ARGUMENT );
  4521. return( mbedtls_psa_storage_inject_entropy( seed, seed_size ) );
  4522. }
  4523. #endif /* MBEDTLS_PSA_INJECT_ENTROPY */
  4524. /** Validate the key type and size for key generation
  4525. *
  4526. * \param type The key type
  4527. * \param bits The number of bits of the key
  4528. *
  4529. * \retval #PSA_SUCCESS
  4530. * The key type and size are valid.
  4531. * \retval #PSA_ERROR_INVALID_ARGUMENT
  4532. * The size in bits of the key is not valid.
  4533. * \retval #PSA_ERROR_NOT_SUPPORTED
  4534. * The type and/or the size in bits of the key or the combination of
  4535. * the two is not supported.
  4536. */
  4537. static psa_status_t psa_validate_key_type_and_size_for_key_generation(
  4538. psa_key_type_t type, size_t bits )
  4539. {
  4540. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4541. if( key_type_is_raw_bytes( type ) )
  4542. {
  4543. status = validate_unstructured_key_bit_size( type, bits );
  4544. if( status != PSA_SUCCESS )
  4545. return( status );
  4546. }
  4547. else
  4548. #if defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR)
  4549. if( PSA_KEY_TYPE_IS_RSA( type ) && PSA_KEY_TYPE_IS_KEY_PAIR( type ) )
  4550. {
  4551. if( bits > PSA_VENDOR_RSA_MAX_KEY_BITS )
  4552. return( PSA_ERROR_NOT_SUPPORTED );
  4553. /* Accept only byte-aligned keys, for the same reasons as
  4554. * in psa_import_rsa_key(). */
  4555. if( bits % 8 != 0 )
  4556. return( PSA_ERROR_NOT_SUPPORTED );
  4557. }
  4558. else
  4559. #endif /* defined(PSA_WANT_KEY_TYPE_RSA_KEY_PAIR) */
  4560. #if defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR)
  4561. if( PSA_KEY_TYPE_IS_ECC( type ) && PSA_KEY_TYPE_IS_KEY_PAIR( type ) )
  4562. {
  4563. /* To avoid empty block, return successfully here. */
  4564. return( PSA_SUCCESS );
  4565. }
  4566. else
  4567. #endif /* defined(PSA_WANT_KEY_TYPE_ECC_KEY_PAIR) */
  4568. {
  4569. return( PSA_ERROR_NOT_SUPPORTED );
  4570. }
  4571. return( PSA_SUCCESS );
  4572. }
  4573. psa_status_t psa_generate_key_internal(
  4574. const psa_key_attributes_t *attributes,
  4575. uint8_t *key_buffer, size_t key_buffer_size, size_t *key_buffer_length )
  4576. {
  4577. psa_status_t status = PSA_ERROR_CORRUPTION_DETECTED;
  4578. psa_key_type_t type = attributes->core.type;
  4579. if( ( attributes->domain_parameters == NULL ) &&
  4580. ( attributes->domain_parameters_size != 0 ) )
  4581. return( PSA_ERROR_INVALID_ARGUMENT );
  4582. if( key_type_is_raw_bytes( type ) )
  4583. {
  4584. status = psa_generate_random( key_buffer, key_buffer_size );
  4585. if( status != PSA_SUCCESS )
  4586. return( status );
  4587. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES)
  4588. if( type == PSA_KEY_TYPE_DES )
  4589. psa_des_set_key_parity( key_buffer, key_buffer_size );
  4590. #endif /* MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES */
  4591. }
  4592. else
  4593. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR) && \
  4594. defined(MBEDTLS_GENPRIME)
  4595. if ( type == PSA_KEY_TYPE_RSA_KEY_PAIR )
  4596. {
  4597. return( mbedtls_psa_rsa_generate_key( attributes,
  4598. key_buffer,
  4599. key_buffer_size,
  4600. key_buffer_length ) );
  4601. }
  4602. else
  4603. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR)
  4604. * defined(MBEDTLS_GENPRIME) */
  4605. #if defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR)
  4606. if ( PSA_KEY_TYPE_IS_ECC( type ) && PSA_KEY_TYPE_IS_KEY_PAIR( type ) )
  4607. {
  4608. return( mbedtls_psa_ecp_generate_key( attributes,
  4609. key_buffer,
  4610. key_buffer_size,
  4611. key_buffer_length ) );
  4612. }
  4613. else
  4614. #endif /* defined(MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR) */
  4615. {
  4616. (void)key_buffer_length;
  4617. return( PSA_ERROR_NOT_SUPPORTED );
  4618. }
  4619. return( PSA_SUCCESS );
  4620. }
  4621. psa_status_t psa_generate_key( const psa_key_attributes_t *attributes,
  4622. mbedtls_svc_key_id_t *key )
  4623. {
  4624. psa_status_t status;
  4625. psa_key_slot_t *slot = NULL;
  4626. psa_se_drv_table_entry_t *driver = NULL;
  4627. size_t key_buffer_size;
  4628. *key = MBEDTLS_SVC_KEY_ID_INIT;
  4629. /* Reject any attempt to create a zero-length key so that we don't
  4630. * risk tripping up later, e.g. on a malloc(0) that returns NULL. */
  4631. if( psa_get_key_bits( attributes ) == 0 )
  4632. return( PSA_ERROR_INVALID_ARGUMENT );
  4633. /* Reject any attempt to create a public key. */
  4634. if( PSA_KEY_TYPE_IS_PUBLIC_KEY(attributes->core.type) )
  4635. return( PSA_ERROR_INVALID_ARGUMENT );
  4636. status = psa_start_key_creation( PSA_KEY_CREATION_GENERATE, attributes,
  4637. &slot, &driver );
  4638. if( status != PSA_SUCCESS )
  4639. goto exit;
  4640. /* In the case of a transparent key or an opaque key stored in local
  4641. * storage (thus not in the case of generating a key in a secure element
  4642. * or cryptoprocessor with storage), we have to allocate a buffer to
  4643. * hold the generated key material. */
  4644. if( slot->key.data == NULL )
  4645. {
  4646. if ( PSA_KEY_LIFETIME_GET_LOCATION( attributes->core.lifetime ) ==
  4647. PSA_KEY_LOCATION_LOCAL_STORAGE )
  4648. {
  4649. status = psa_validate_key_type_and_size_for_key_generation(
  4650. attributes->core.type, attributes->core.bits );
  4651. if( status != PSA_SUCCESS )
  4652. goto exit;
  4653. key_buffer_size = PSA_EXPORT_KEY_OUTPUT_SIZE(
  4654. attributes->core.type,
  4655. attributes->core.bits );
  4656. }
  4657. else
  4658. {
  4659. status = psa_driver_wrapper_get_key_buffer_size(
  4660. attributes, &key_buffer_size );
  4661. if( status != PSA_SUCCESS )
  4662. goto exit;
  4663. }
  4664. status = psa_allocate_buffer_to_slot( slot, key_buffer_size );
  4665. if( status != PSA_SUCCESS )
  4666. goto exit;
  4667. }
  4668. status = psa_driver_wrapper_generate_key( attributes,
  4669. slot->key.data, slot->key.bytes, &slot->key.bytes );
  4670. if( status != PSA_SUCCESS )
  4671. psa_remove_key_data_from_memory( slot );
  4672. exit:
  4673. if( status == PSA_SUCCESS )
  4674. status = psa_finish_key_creation( slot, driver, key );
  4675. if( status != PSA_SUCCESS )
  4676. psa_fail_key_creation( slot, driver );
  4677. return( status );
  4678. }
  4679. /****************************************************************/
  4680. /* Module setup */
  4681. /****************************************************************/
  4682. #if !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4683. psa_status_t mbedtls_psa_crypto_configure_entropy_sources(
  4684. void (* entropy_init )( mbedtls_entropy_context *ctx ),
  4685. void (* entropy_free )( mbedtls_entropy_context *ctx ) )
  4686. {
  4687. if( global_data.rng_state != RNG_NOT_INITIALIZED )
  4688. return( PSA_ERROR_BAD_STATE );
  4689. global_data.rng.entropy_init = entropy_init;
  4690. global_data.rng.entropy_free = entropy_free;
  4691. return( PSA_SUCCESS );
  4692. }
  4693. #endif /* !defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) */
  4694. void mbedtls_psa_crypto_free( void )
  4695. {
  4696. psa_wipe_all_key_slots( );
  4697. if( global_data.rng_state != RNG_NOT_INITIALIZED )
  4698. {
  4699. mbedtls_psa_random_free( &global_data.rng );
  4700. }
  4701. /* Wipe all remaining data, including configuration.
  4702. * In particular, this sets all state indicator to the value
  4703. * indicating "uninitialized". */
  4704. mbedtls_platform_zeroize( &global_data, sizeof( global_data ) );
  4705. /* Terminate drivers */
  4706. psa_driver_wrapper_free( );
  4707. }
  4708. #if defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS)
  4709. /** Recover a transaction that was interrupted by a power failure.
  4710. *
  4711. * This function is called during initialization, before psa_crypto_init()
  4712. * returns. If this function returns a failure status, the initialization
  4713. * fails.
  4714. */
  4715. static psa_status_t psa_crypto_recover_transaction(
  4716. const psa_crypto_transaction_t *transaction )
  4717. {
  4718. switch( transaction->unknown.type )
  4719. {
  4720. case PSA_CRYPTO_TRANSACTION_CREATE_KEY:
  4721. case PSA_CRYPTO_TRANSACTION_DESTROY_KEY:
  4722. /* TODO - fall through to the failure case until this
  4723. * is implemented.
  4724. * https://github.com/ARMmbed/mbed-crypto/issues/218
  4725. */
  4726. default:
  4727. /* We found an unsupported transaction in the storage.
  4728. * We don't know what state the storage is in. Give up. */
  4729. return( PSA_ERROR_DATA_INVALID );
  4730. }
  4731. }
  4732. #endif /* PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS */
  4733. psa_status_t psa_crypto_init( void )
  4734. {
  4735. psa_status_t status;
  4736. /* Double initialization is explicitly allowed. */
  4737. if( global_data.initialized != 0 )
  4738. return( PSA_SUCCESS );
  4739. /* Initialize and seed the random generator. */
  4740. mbedtls_psa_random_init( &global_data.rng );
  4741. global_data.rng_state = RNG_INITIALIZED;
  4742. status = mbedtls_psa_random_seed( &global_data.rng );
  4743. if( status != PSA_SUCCESS )
  4744. goto exit;
  4745. global_data.rng_state = RNG_SEEDED;
  4746. status = psa_initialize_key_slots( );
  4747. if( status != PSA_SUCCESS )
  4748. goto exit;
  4749. /* Init drivers */
  4750. status = psa_driver_wrapper_init( );
  4751. if( status != PSA_SUCCESS )
  4752. goto exit;
  4753. #if defined(PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS)
  4754. status = psa_crypto_load_transaction( );
  4755. if( status == PSA_SUCCESS )
  4756. {
  4757. status = psa_crypto_recover_transaction( &psa_crypto_transaction );
  4758. if( status != PSA_SUCCESS )
  4759. goto exit;
  4760. status = psa_crypto_stop_transaction( );
  4761. }
  4762. else if( status == PSA_ERROR_DOES_NOT_EXIST )
  4763. {
  4764. /* There's no transaction to complete. It's all good. */
  4765. status = PSA_SUCCESS;
  4766. }
  4767. #endif /* PSA_CRYPTO_STORAGE_HAS_TRANSACTIONS */
  4768. /* All done. */
  4769. global_data.initialized = 1;
  4770. exit:
  4771. if( status != PSA_SUCCESS )
  4772. mbedtls_psa_crypto_free( );
  4773. return( status );
  4774. }
  4775. #endif /* MBEDTLS_PSA_CRYPTO_C */