signature.c 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544
  1. /* signature.c
  2. *
  3. * Copyright (C) 2006-2022 wolfSSL Inc.
  4. *
  5. * This file is part of wolfSSL.
  6. *
  7. * wolfSSL is free software; you can redistribute it and/or modify
  8. * it under the terms of the GNU General Public License as published by
  9. * the Free Software Foundation; either version 2 of the License, or
  10. * (at your option) any later version.
  11. *
  12. * wolfSSL is distributed in the hope that it will be useful,
  13. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  14. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  15. * GNU General Public License for more details.
  16. *
  17. * You should have received a copy of the GNU General Public License
  18. * along with this program; if not, write to the Free Software
  19. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA
  20. */
  21. #ifdef HAVE_CONFIG_H
  22. #include <config.h>
  23. #endif
  24. #include <wolfssl/wolfcrypt/settings.h>
  25. #include <wolfssl/wolfcrypt/signature.h>
  26. #include <wolfssl/wolfcrypt/error-crypt.h>
  27. #include <wolfssl/wolfcrypt/logging.h>
  28. #ifndef NO_ASN
  29. #include <wolfssl/wolfcrypt/asn.h>
  30. #endif
  31. #ifdef HAVE_ECC
  32. #include <wolfssl/wolfcrypt/ecc.h>
  33. #endif
  34. #ifndef NO_RSA
  35. #include <wolfssl/wolfcrypt/rsa.h>
  36. #endif
  37. /* If ECC and RSA are disabled then disable signature wrapper */
  38. #if (!defined(HAVE_ECC) || (defined(HAVE_ECC) && !defined(HAVE_ECC_SIGN) \
  39. && !defined(HAVE_ECC_VERIFY))) && defined(NO_RSA)
  40. #undef NO_SIG_WRAPPER
  41. #define NO_SIG_WRAPPER
  42. #endif
  43. /* Signature wrapper disabled check */
  44. #ifndef NO_SIG_WRAPPER
  45. #if !defined(NO_RSA) && defined(WOLFSSL_CRYPTOCELL)
  46. extern int cc310_RsaSSL_Verify(const byte* in, word32 inLen, byte* sig,
  47. RsaKey* key, CRYS_RSA_HASH_OpMode_t mode);
  48. extern int cc310_RsaSSL_Sign(const byte* in, word32 inLen, byte* out,
  49. word32 outLen, RsaKey* key, CRYS_RSA_HASH_OpMode_t mode);
  50. #endif
  51. #if !defined(NO_RSA) && !defined(NO_ASN)
  52. static int wc_SignatureDerEncode(enum wc_HashType hash_type, byte* hash_data,
  53. word32 hash_len, word32* hash_enc_len)
  54. {
  55. int ret, oid;
  56. ret = wc_HashGetOID(hash_type);
  57. if (ret < 0) {
  58. return ret;
  59. }
  60. oid = ret;
  61. ret = wc_EncodeSignature(hash_data, hash_data, hash_len, oid);
  62. if (ret > 0) {
  63. *hash_enc_len = ret;
  64. ret = 0;
  65. }
  66. return ret;
  67. }
  68. #endif /* !NO_RSA && !NO_ASN */
  69. int wc_SignatureGetSize(enum wc_SignatureType sig_type,
  70. const void* key, word32 key_len)
  71. {
  72. int sig_len = BAD_FUNC_ARG;
  73. /* Suppress possible unused args if all signature types are disabled */
  74. (void)key;
  75. (void)key_len;
  76. switch(sig_type) {
  77. case WC_SIGNATURE_TYPE_ECC:
  78. #ifdef HAVE_ECC
  79. /* Sanity check that void* key is at least ecc_key in size */
  80. if (key_len >= sizeof(ecc_key)) {
  81. sig_len = wc_ecc_sig_size((ecc_key*)key);
  82. }
  83. else {
  84. WOLFSSL_MSG("wc_SignatureGetSize: Invalid ECC key size");
  85. }
  86. #else
  87. sig_len = SIG_TYPE_E;
  88. #endif
  89. break;
  90. case WC_SIGNATURE_TYPE_RSA_W_ENC:
  91. case WC_SIGNATURE_TYPE_RSA:
  92. #ifndef NO_RSA
  93. /* Sanity check that void* key is at least RsaKey in size */
  94. if (key_len >= sizeof(RsaKey)) {
  95. sig_len = wc_RsaEncryptSize((RsaKey*)key);
  96. }
  97. else {
  98. WOLFSSL_MSG("wc_SignatureGetSize: Invalid RsaKey key size");
  99. }
  100. #else
  101. sig_len = SIG_TYPE_E;
  102. #endif
  103. break;
  104. case WC_SIGNATURE_TYPE_NONE:
  105. default:
  106. sig_len = BAD_FUNC_ARG;
  107. break;
  108. }
  109. return sig_len;
  110. }
  111. int wc_SignatureVerifyHash(
  112. enum wc_HashType hash_type, enum wc_SignatureType sig_type,
  113. const byte* hash_data, word32 hash_len,
  114. const byte* sig, word32 sig_len,
  115. const void* key, word32 key_len)
  116. {
  117. int ret;
  118. /* Check arguments */
  119. if (hash_data == NULL || hash_len == 0 ||
  120. sig == NULL || sig_len == 0 ||
  121. key == NULL || key_len == 0) {
  122. return BAD_FUNC_ARG;
  123. }
  124. /* Validate signature len (1 to max is okay) */
  125. if ((int)sig_len > wc_SignatureGetSize(sig_type, key, key_len)) {
  126. WOLFSSL_MSG("wc_SignatureVerify: Invalid sig type/len");
  127. return BAD_FUNC_ARG;
  128. }
  129. /* Validate hash size */
  130. ret = wc_HashGetDigestSize(hash_type);
  131. if (ret < 0) {
  132. WOLFSSL_MSG("wc_SignatureVerify: Invalid hash type/len");
  133. return ret;
  134. }
  135. ret = 0;
  136. /* Verify signature using hash */
  137. switch (sig_type) {
  138. case WC_SIGNATURE_TYPE_ECC:
  139. {
  140. #if defined(HAVE_ECC) && defined(HAVE_ECC_VERIFY)
  141. int is_valid_sig = 0;
  142. /* Perform verification of signature using provided ECC key */
  143. do {
  144. #ifdef WOLFSSL_ASYNC_CRYPT
  145. ret = wc_AsyncWait(ret, &((ecc_key*)key)->asyncDev,
  146. WC_ASYNC_FLAG_CALL_AGAIN);
  147. #endif
  148. if (ret >= 0)
  149. ret = wc_ecc_verify_hash(sig, sig_len, hash_data, hash_len,
  150. &is_valid_sig, (ecc_key*)key);
  151. } while (ret == WC_PENDING_E);
  152. if (ret != 0 || is_valid_sig != 1) {
  153. ret = SIG_VERIFY_E;
  154. }
  155. #else
  156. ret = SIG_TYPE_E;
  157. #endif
  158. break;
  159. }
  160. case WC_SIGNATURE_TYPE_RSA_W_ENC:
  161. case WC_SIGNATURE_TYPE_RSA:
  162. {
  163. #ifndef NO_RSA
  164. #ifdef WOLFSSL_CRYPTOCELL
  165. if (sig_type == WC_SIGNATURE_TYPE_RSA_W_ENC) {
  166. ret = cc310_RsaSSL_Verify(hash_data, hash_len, (byte*)sig,
  167. (RsaKey*)key, cc310_hashModeRSA(hash_type, 0));
  168. }
  169. else {
  170. ret = cc310_RsaSSL_Verify(hash_data, hash_len, (byte*)sig,
  171. (RsaKey*)key, cc310_hashModeRSA(hash_type, 1));
  172. }
  173. #else
  174. word32 plain_len = hash_len;
  175. #if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_NO_MALLOC)
  176. byte *plain_data;
  177. #else
  178. byte plain_data[MAX_ENCODED_SIG_SZ];
  179. #endif
  180. /* Make sure the plain text output is at least key size */
  181. if (plain_len < sig_len) {
  182. plain_len = sig_len;
  183. }
  184. #if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_NO_MALLOC)
  185. plain_data = (byte*)XMALLOC(plain_len, NULL, DYNAMIC_TYPE_TMP_BUFFER);
  186. if (plain_data)
  187. #else
  188. if (plain_len <= sizeof(plain_data))
  189. #endif
  190. {
  191. byte* plain_ptr = NULL;
  192. XMEMSET(plain_data, 0, plain_len);
  193. XMEMCPY(plain_data, sig, sig_len);
  194. /* Perform verification of signature using provided RSA key */
  195. do {
  196. #ifdef WOLFSSL_ASYNC_CRYPT
  197. ret = wc_AsyncWait(ret, &((RsaKey*)key)->asyncDev,
  198. WC_ASYNC_FLAG_CALL_AGAIN);
  199. #endif
  200. if (ret >= 0)
  201. ret = wc_RsaSSL_VerifyInline(plain_data, sig_len, &plain_ptr, (RsaKey*)key);
  202. } while (ret == WC_PENDING_E);
  203. if (ret >= 0 && plain_ptr) {
  204. if ((word32)ret == hash_len &&
  205. XMEMCMP(plain_ptr, hash_data, hash_len) == 0) {
  206. ret = 0; /* Success */
  207. }
  208. else {
  209. ret = SIG_VERIFY_E;
  210. }
  211. }
  212. #if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_NO_MALLOC)
  213. XFREE(plain_data, NULL, DYNAMIC_TYPE_TMP_BUFFER);
  214. #endif
  215. }
  216. else {
  217. ret = MEMORY_E;
  218. }
  219. #endif /* WOLFSSL_CRYPTOCELL */
  220. if (ret != 0) {
  221. WOLFSSL_MSG("RSA Signature Verify difference!");
  222. ret = SIG_VERIFY_E;
  223. }
  224. #else
  225. ret = SIG_TYPE_E;
  226. #endif
  227. break;
  228. }
  229. case WC_SIGNATURE_TYPE_NONE:
  230. default:
  231. ret = BAD_FUNC_ARG;
  232. break;
  233. }
  234. return ret;
  235. }
  236. int wc_SignatureVerify(
  237. enum wc_HashType hash_type, enum wc_SignatureType sig_type,
  238. const byte* data, word32 data_len,
  239. const byte* sig, word32 sig_len,
  240. const void* key, word32 key_len)
  241. {
  242. int ret;
  243. word32 hash_len, hash_enc_len;
  244. #if defined(WOLFSSL_SMALL_STACK) || defined(NO_ASN)
  245. byte *hash_data;
  246. #else
  247. byte hash_data[MAX_DER_DIGEST_SZ];
  248. #endif
  249. /* Check arguments */
  250. if (data == NULL || data_len == 0 ||
  251. sig == NULL || sig_len == 0 ||
  252. key == NULL || key_len == 0) {
  253. return BAD_FUNC_ARG;
  254. }
  255. /* Validate signature len (1 to max is okay) */
  256. if ((int)sig_len > wc_SignatureGetSize(sig_type, key, key_len)) {
  257. WOLFSSL_MSG("wc_SignatureVerify: Invalid sig type/len");
  258. return BAD_FUNC_ARG;
  259. }
  260. /* Validate hash size */
  261. ret = wc_HashGetDigestSize(hash_type);
  262. if (ret < 0) {
  263. WOLFSSL_MSG("wc_SignatureVerify: Invalid hash type/len");
  264. return ret;
  265. }
  266. hash_enc_len = hash_len = ret;
  267. #ifndef NO_RSA
  268. if (sig_type == WC_SIGNATURE_TYPE_RSA_W_ENC) {
  269. /* For RSA with ASN.1 encoding include room */
  270. hash_enc_len += MAX_DER_DIGEST_ASN_SZ;
  271. }
  272. #endif
  273. #if defined(WOLFSSL_SMALL_STACK) || defined(NO_ASN)
  274. /* Allocate temporary buffer for hash data */
  275. hash_data = (byte*)XMALLOC(hash_enc_len, NULL, DYNAMIC_TYPE_TMP_BUFFER);
  276. if (hash_data == NULL) {
  277. return MEMORY_E;
  278. }
  279. #endif
  280. /* Perform hash of data */
  281. ret = wc_Hash(hash_type, data, data_len, hash_data, hash_len);
  282. if (ret == 0) {
  283. /* Handle RSA with DER encoding */
  284. if (sig_type == WC_SIGNATURE_TYPE_RSA_W_ENC) {
  285. #if defined(NO_RSA) || defined(NO_ASN)
  286. ret = SIG_TYPE_E;
  287. #else
  288. ret = wc_SignatureDerEncode(hash_type, hash_data, hash_len,
  289. &hash_enc_len);
  290. #endif
  291. }
  292. if (ret == 0) {
  293. /* Verify signature using hash */
  294. ret = wc_SignatureVerifyHash(hash_type, sig_type,
  295. hash_data, hash_enc_len, sig, sig_len, key, key_len);
  296. }
  297. }
  298. #if defined(WOLFSSL_SMALL_STACK) || defined(NO_ASN)
  299. XFREE(hash_data, NULL, DYNAMIC_TYPE_TMP_BUFFER);
  300. #endif
  301. return ret;
  302. }
  303. int wc_SignatureGenerateHash(
  304. enum wc_HashType hash_type, enum wc_SignatureType sig_type,
  305. const byte* hash_data, word32 hash_len,
  306. byte* sig, word32 *sig_len,
  307. const void* key, word32 key_len, WC_RNG* rng)
  308. {
  309. return wc_SignatureGenerateHash_ex(hash_type, sig_type, hash_data, hash_len,
  310. sig, sig_len, key, key_len, rng, 1);
  311. }
  312. int wc_SignatureGenerateHash_ex(
  313. enum wc_HashType hash_type, enum wc_SignatureType sig_type,
  314. const byte* hash_data, word32 hash_len,
  315. byte* sig, word32 *sig_len,
  316. const void* key, word32 key_len, WC_RNG* rng, int verify)
  317. {
  318. int ret;
  319. /* Suppress possible unused arg if all signature types are disabled */
  320. (void)rng;
  321. /* Check arguments */
  322. if (hash_data == NULL || hash_len == 0 ||
  323. sig == NULL || sig_len == NULL || *sig_len == 0 ||
  324. key == NULL || key_len == 0) {
  325. return BAD_FUNC_ARG;
  326. }
  327. /* Validate signature len (needs to be at least max) */
  328. if ((int)*sig_len < wc_SignatureGetSize(sig_type, key, key_len)) {
  329. WOLFSSL_MSG("wc_SignatureGenerate: Invalid sig type/len");
  330. return BAD_FUNC_ARG;
  331. }
  332. /* Validate hash size */
  333. ret = wc_HashGetDigestSize(hash_type);
  334. if (ret < 0) {
  335. WOLFSSL_MSG("wc_SignatureGenerate: Invalid hash type/len");
  336. return ret;
  337. }
  338. ret = 0;
  339. /* Create signature using hash as data */
  340. switch (sig_type) {
  341. case WC_SIGNATURE_TYPE_ECC:
  342. #if defined(HAVE_ECC) && defined(HAVE_ECC_SIGN)
  343. /* Create signature using provided ECC key */
  344. do {
  345. #ifdef WOLFSSL_ASYNC_CRYPT
  346. ret = wc_AsyncWait(ret, &((ecc_key*)key)->asyncDev,
  347. WC_ASYNC_FLAG_CALL_AGAIN);
  348. #endif
  349. if (ret >= 0)
  350. ret = wc_ecc_sign_hash(hash_data, hash_len, sig, sig_len,
  351. rng, (ecc_key*)key);
  352. } while (ret == WC_PENDING_E);
  353. #else
  354. ret = SIG_TYPE_E;
  355. #endif
  356. break;
  357. case WC_SIGNATURE_TYPE_RSA_W_ENC:
  358. case WC_SIGNATURE_TYPE_RSA:
  359. #if !defined(NO_RSA) && !defined(WOLFSSL_RSA_PUBLIC_ONLY) && \
  360. !defined(WOLFSSL_RSA_VERIFY_ONLY)
  361. #ifdef WOLFSSL_CRYPTOCELL
  362. /* use expected signature size (incoming sig_len could be larger buffer */
  363. *sig_len = wc_SignatureGetSize(sig_type, key, key_len);
  364. if (sig_type == WC_SIGNATURE_TYPE_RSA_W_ENC) {
  365. ret = cc310_RsaSSL_Sign(hash_data, hash_len, sig, *sig_len,
  366. (RsaKey*)key, cc310_hashModeRSA(hash_type, 0));
  367. }
  368. else {
  369. ret = cc310_RsaSSL_Sign(hash_data, hash_len, sig, *sig_len,
  370. (RsaKey*)key, cc310_hashModeRSA(hash_type, 1));
  371. }
  372. #else
  373. /* Create signature using provided RSA key */
  374. do {
  375. #ifdef WOLFSSL_ASYNC_CRYPT
  376. ret = wc_AsyncWait(ret, &((RsaKey*)key)->asyncDev,
  377. WC_ASYNC_FLAG_CALL_AGAIN);
  378. #endif
  379. if (ret >= 0)
  380. ret = wc_RsaSSL_Sign(hash_data, hash_len, sig, *sig_len,
  381. (RsaKey*)key, rng);
  382. } while (ret == WC_PENDING_E);
  383. #endif /* WOLFSSL_CRYPTOCELL */
  384. if (ret >= 0) {
  385. *sig_len = ret;
  386. ret = 0; /* Success */
  387. }
  388. #else
  389. ret = SIG_TYPE_E;
  390. #endif
  391. break;
  392. case WC_SIGNATURE_TYPE_NONE:
  393. default:
  394. ret = BAD_FUNC_ARG;
  395. break;
  396. }
  397. if (ret == 0 && verify) {
  398. ret = wc_SignatureVerifyHash(hash_type, sig_type, hash_data, hash_len,
  399. sig, *sig_len, key, key_len);
  400. }
  401. return ret;
  402. }
  403. int wc_SignatureGenerate(
  404. enum wc_HashType hash_type, enum wc_SignatureType sig_type,
  405. const byte* data, word32 data_len,
  406. byte* sig, word32 *sig_len,
  407. const void* key, word32 key_len, WC_RNG* rng)
  408. {
  409. return wc_SignatureGenerate_ex(hash_type, sig_type, data, data_len, sig,
  410. sig_len, key, key_len, rng, 1);
  411. }
  412. int wc_SignatureGenerate_ex(
  413. enum wc_HashType hash_type, enum wc_SignatureType sig_type,
  414. const byte* data, word32 data_len,
  415. byte* sig, word32 *sig_len,
  416. const void* key, word32 key_len, WC_RNG* rng, int verify)
  417. {
  418. int ret;
  419. word32 hash_len, hash_enc_len;
  420. #if defined(WOLFSSL_SMALL_STACK) || defined(NO_ASN)
  421. byte *hash_data;
  422. #else
  423. byte hash_data[MAX_DER_DIGEST_SZ];
  424. #endif
  425. /* Check arguments */
  426. if (data == NULL || data_len == 0 ||
  427. sig == NULL || sig_len == NULL || *sig_len == 0 ||
  428. key == NULL || key_len == 0) {
  429. return BAD_FUNC_ARG;
  430. }
  431. /* Validate signature len (needs to be at least max) */
  432. if ((int)*sig_len < wc_SignatureGetSize(sig_type, key, key_len)) {
  433. WOLFSSL_MSG("wc_SignatureGenerate: Invalid sig type/len");
  434. return BAD_FUNC_ARG;
  435. }
  436. /* Validate hash size */
  437. ret = wc_HashGetDigestSize(hash_type);
  438. if (ret < 0) {
  439. WOLFSSL_MSG("wc_SignatureGenerate: Invalid hash type/len");
  440. return ret;
  441. }
  442. hash_enc_len = hash_len = ret;
  443. #if !defined(NO_RSA) && !defined(WOLFSSL_RSA_PUBLIC_ONLY)
  444. if (sig_type == WC_SIGNATURE_TYPE_RSA_W_ENC) {
  445. /* For RSA with ASN.1 encoding include room */
  446. hash_enc_len += MAX_DER_DIGEST_ASN_SZ;
  447. }
  448. #endif
  449. #if defined(WOLFSSL_SMALL_STACK) || defined(NO_ASN)
  450. /* Allocate temporary buffer for hash data */
  451. hash_data = (byte*)XMALLOC(hash_enc_len, NULL, DYNAMIC_TYPE_TMP_BUFFER);
  452. if (hash_data == NULL) {
  453. return MEMORY_E;
  454. }
  455. #endif
  456. /* Perform hash of data */
  457. ret = wc_Hash(hash_type, data, data_len, hash_data, hash_len);
  458. if (ret == 0) {
  459. /* Handle RSA with DER encoding */
  460. if (sig_type == WC_SIGNATURE_TYPE_RSA_W_ENC) {
  461. #if defined(NO_RSA) || defined(NO_ASN) || \
  462. defined(WOLFSSL_RSA_PUBLIC_ONLY)
  463. ret = SIG_TYPE_E;
  464. #else
  465. ret = wc_SignatureDerEncode(hash_type, hash_data, hash_len,
  466. &hash_enc_len);
  467. #endif
  468. }
  469. if (ret == 0) {
  470. /* Generate signature using hash */
  471. ret = wc_SignatureGenerateHash(hash_type, sig_type,
  472. hash_data, hash_enc_len, sig, sig_len, key, key_len, rng);
  473. }
  474. }
  475. if (ret == 0 && verify) {
  476. ret = wc_SignatureVerifyHash(hash_type, sig_type, hash_data,
  477. hash_enc_len, sig, *sig_len, key, key_len);
  478. }
  479. #if defined(WOLFSSL_SMALL_STACK) || defined(NO_ASN)
  480. XFREE(hash_data, NULL, DYNAMIC_TYPE_TMP_BUFFER);
  481. #endif
  482. return ret;
  483. }
  484. #endif /* NO_SIG_WRAPPER */