diff options
Diffstat (limited to 'src/lib/kdf')
-rw-r--r-- | src/lib/kdf/kdf.cpp | 17 | ||||
-rw-r--r-- | src/lib/kdf/sp800_108/info.txt | 6 | ||||
-rw-r--r-- | src/lib/kdf/sp800_108/sp800_108.cpp | 157 | ||||
-rw-r--r-- | src/lib/kdf/sp800_108/sp800_108.h | 81 | ||||
-rw-r--r-- | src/lib/kdf/sp800_56c/info.txt | 6 | ||||
-rw-r--r-- | src/lib/kdf/sp800_56c/sp800_56c.cpp | 45 | ||||
-rw-r--r-- | src/lib/kdf/sp800_56c/sp800_56c.h | 39 |
7 files changed, 351 insertions, 0 deletions
diff --git a/src/lib/kdf/kdf.cpp b/src/lib/kdf/kdf.cpp index 45ee165e0..7f4488d32 100644 --- a/src/lib/kdf/kdf.cpp +++ b/src/lib/kdf/kdf.cpp @@ -33,6 +33,14 @@ #include <botan/prf_x942.h> #endif +#if defined(BOTAN_HAS_SP800_108) +#include <botan/sp800_108.h> +#endif + +#if defined(BOTAN_HAS_SP800_56C) +#include <botan/sp800_56c.h> +#endif + #define BOTAN_REGISTER_KDF_NOARGS(type, name) \ BOTAN_REGISTER_NAMED_T(KDF, name, type, (make_new_T<type>)) #define BOTAN_REGISTER_KDF_1HASH(type, name) \ @@ -93,4 +101,13 @@ BOTAN_REGISTER_NAMED_T(KDF, "TLS-12-PRF", TLS_12_PRF, TLS_12_PRF::make); BOTAN_REGISTER_KDF_NAMED_1STR(X942_PRF, "X9.42-PRF"); #endif +#if defined(BOTAN_HAS_SP800_108) +BOTAN_REGISTER_NAMED_T(KDF, "SP800-108-Counter", SP800_108_Counter, SP800_108_Counter::make); +BOTAN_REGISTER_NAMED_T(KDF, "SP800-108-Feedback", SP800_108_Feedback, SP800_108_Feedback::make); +BOTAN_REGISTER_NAMED_T(KDF, "SP800-108-Pipeline", SP800_108_Pipeline, SP800_108_Pipeline::make); +#endif + +#if defined(BOTAN_HAS_SP800_56C) +BOTAN_REGISTER_NAMED_T(KDF, "SP800-56C", SP800_56C, SP800_56C::make); +#endif } diff --git a/src/lib/kdf/sp800_108/info.txt b/src/lib/kdf/sp800_108/info.txt new file mode 100644 index 000000000..a78531fe7 --- /dev/null +++ b/src/lib/kdf/sp800_108/info.txt @@ -0,0 +1,6 @@ +define SP800_108 20160128 + +<requires> +mac +hmac +</requires> diff --git a/src/lib/kdf/sp800_108/sp800_108.cpp b/src/lib/kdf/sp800_108/sp800_108.cpp new file mode 100644 index 000000000..873db814c --- /dev/null +++ b/src/lib/kdf/sp800_108/sp800_108.cpp @@ -0,0 +1,157 @@ +/* +* KDFs defined in NIST SP 800-108 +* (C) 2016 Kai Michaelis +* +* Botan is released under the Simplified BSD License (see license.txt) +*/ + +#include <botan/sp800_108.h> +#include <botan/hmac.h> + +namespace Botan { + +SP800_108_Counter* SP800_108_Counter::make(const Spec& spec) + { + if(auto mac = MessageAuthenticationCode::create(spec.arg(0))) + return new SP800_108_Counter(mac.release()); + + if(auto mac = MessageAuthenticationCode::create("HMAC(" + spec.arg(0) + ")")) + return new SP800_108_Counter(mac.release()); + + return nullptr; + } + +size_t SP800_108_Counter::kdf(byte key[], size_t key_len, + const byte secret[], size_t secret_len, + const byte salt[], size_t salt_len) const + { + const std::size_t prf_len = m_prf->output_length(); + byte *p = key; + uint32_t counter = 1; + secure_vector<byte> tmp; + + m_prf->set_key(secret, secret_len); + + while(p < key + key_len && counter != 0) + { + const std::size_t to_copy = std::min< std::size_t >(key + key_len - p, prf_len); + byte be_cnt[4] = { 0 }; + + store_be(counter, be_cnt); + + m_prf->update(be_cnt,4); + m_prf->update(salt, salt_len); + m_prf->final(tmp); + + std::move(tmp.begin(), tmp.begin() + to_copy, p); + ++counter; + + if (counter == 0) + throw Invalid_Argument("Can't process more than 4GB"); + + p += to_copy; + } + + return key_len; + } + +SP800_108_Feedback* SP800_108_Feedback::make(const Spec& spec) + { + if(auto mac = MessageAuthenticationCode::create(spec.arg(0))) + return new SP800_108_Feedback(mac.release()); + + if(auto mac = MessageAuthenticationCode::create("HMAC(" + spec.arg(0) + ")")) + return new SP800_108_Feedback(mac.release()); + + return nullptr; + } + +size_t SP800_108_Feedback::kdf(byte key[], size_t key_len, + const byte secret[], size_t secret_len, + const byte salt[], size_t salt_len) const + { + const std::size_t prf_len = m_prf->output_length(); + const std::size_t iv_len = (salt_len >= prf_len ? prf_len : 0); + + byte *p = key; + uint32_t counter = 1; + secure_vector< byte > prev(salt, salt + iv_len); + secure_vector< byte > ctx(salt + iv_len, salt + salt_len); + + m_prf->set_key(secret, secret_len); + + while(p < key + key_len && counter != 0) + { + const std::size_t to_copy = std::min< std::size_t >(key + key_len - p, prf_len); + byte be_cnt[4] = { 0 }; + + store_be(counter, be_cnt); + + m_prf->update(prev); + m_prf->update(be_cnt,4); + m_prf->update(ctx); + m_prf->final(prev); + + std::copy(prev.begin(), prev.begin() + to_copy, p); + ++counter; + + if (counter == 0) + throw Invalid_Argument("Can't process more than 4GB"); + + p += to_copy; + } + + return key_len; + } + +SP800_108_Pipeline* SP800_108_Pipeline::make(const Spec& spec) + { + if(auto mac = MessageAuthenticationCode::create(spec.arg(0))) + return new SP800_108_Pipeline(mac.release()); + + if(auto mac = MessageAuthenticationCode::create("HMAC(" + spec.arg(0) + ")")) + return new SP800_108_Pipeline(mac.release()); + + return nullptr; + } + +size_t SP800_108_Pipeline::kdf(byte key[], size_t key_len, + const byte secret[], size_t secret_len, + const byte salt[], size_t salt_len) const + { + const std::size_t prf_len = m_prf->output_length(); + byte *p = key; + uint32_t counter = 1; + secure_vector<byte> ai(salt, salt + salt_len), ki; + + m_prf->set_key(secret,secret_len); + + while(p < key + key_len && counter != 0) + { + // A(i) + m_prf->update(ai); + m_prf->final(ai); + + // K(i) + const std::size_t to_copy = std::min< std::size_t >(key + key_len - p, prf_len); + byte be_cnt[4] = { 0 }; + + store_be(counter, be_cnt); + + m_prf->update(ai); + m_prf->update(be_cnt,4); + m_prf->update(salt, salt_len); + m_prf->final(ki); + + std::copy(ki.begin(), ki.begin() + to_copy, p); + ++counter; + + if (counter == 0) + throw Invalid_Argument("Can't process more than 4GB"); + + p += to_copy; + } + + return key_len; + } +} diff --git a/src/lib/kdf/sp800_108/sp800_108.h b/src/lib/kdf/sp800_108/sp800_108.h new file mode 100644 index 000000000..0acdfacf9 --- /dev/null +++ b/src/lib/kdf/sp800_108/sp800_108.h @@ -0,0 +1,81 @@ +/* +* KDFs defined in NIST SP 800-108 +* (C) 2016 Kai Michaelis +* +* Botan is released under the Simplified BSD License (see license.txt) +*/ + +#ifndef BOTAN_SP800_108_H__ +#define BOTAN_SP800_108_H__ + +#include <botan/kdf.h> +#include <botan/mac.h> + +namespace Botan { + +/** + * NIST SP 800-108 KDF in Counter Mode (5.1) + */ +class BOTAN_DLL SP800_108_Counter : public KDF + { + public: + std::string name() const override { return "SP800-108-Counter(" + m_prf->name() + ")"; } + + KDF* clone() const override { return new SP800_108_Counter(m_prf->clone()); } + + size_t kdf(byte key[], size_t key_len, + const byte secret[], size_t secret_len, + const byte salt[], size_t salt_len) const override; + + SP800_108_Counter(MessageAuthenticationCode* mac) : m_prf(mac) {} + + static SP800_108_Counter* make(const Spec& spec); + private: + std::unique_ptr<MessageAuthenticationCode> m_prf; + }; + +/** + * NIST SP 800-108 KDF in Feedback Mode (5.2) + */ +class BOTAN_DLL SP800_108_Feedback : public KDF + { + public: + std::string name() const override { return "SP800-108-Feedback(" + m_prf->name() + ")"; } + + KDF* clone() const override { return new SP800_108_Feedback(m_prf->clone()); } + + size_t kdf(byte key[], size_t key_len, + const byte secret[], size_t secret_len, + const byte salt[], size_t salt_len) const override; + + SP800_108_Feedback(MessageAuthenticationCode* mac) : m_prf(mac) {} + + static SP800_108_Feedback* make(const Spec& spec); + private: + std::unique_ptr<MessageAuthenticationCode> m_prf; + }; + +/** + * NIST SP 800-108 KDF in Double Pipeline Mode (5.3) + */ +class BOTAN_DLL SP800_108_Pipeline : public KDF + { + public: + std::string name() const override { return "SP800-108-Pipeline(" + m_prf->name() + ")"; } + + KDF* clone() const override { return new SP800_108_Pipeline(m_prf->clone()); } + + size_t kdf(byte key[], size_t key_len, + const byte secret[], size_t secret_len, + const byte salt[], size_t salt_len) const override; + + SP800_108_Pipeline(MessageAuthenticationCode* mac) : m_prf(mac) {} + + static SP800_108_Pipeline* make(const Spec& spec); + private: + std::unique_ptr<MessageAuthenticationCode> m_prf; + }; + +} + +#endif diff --git a/src/lib/kdf/sp800_56c/info.txt b/src/lib/kdf/sp800_56c/info.txt new file mode 100644 index 000000000..203c05a83 --- /dev/null +++ b/src/lib/kdf/sp800_56c/info.txt @@ -0,0 +1,6 @@ +define SP800_56C 20160211 + +<requires> +sp800_108 +hmac +</requires> diff --git a/src/lib/kdf/sp800_56c/sp800_56c.cpp b/src/lib/kdf/sp800_56c/sp800_56c.cpp new file mode 100644 index 000000000..664d32b30 --- /dev/null +++ b/src/lib/kdf/sp800_56c/sp800_56c.cpp @@ -0,0 +1,45 @@ +/* +* KDF defined in NIST SP 800-56c +* (C) 2016 Kai Michaelis +* +* Botan is released under the Simplified BSD License (see license.txt) +*/ + +#include <botan/sp800_108.h> +#include <botan/sp800_56c.h> +#include <botan/hmac.h> + +namespace Botan { + +SP800_56C* SP800_56C::make(const Spec& spec) + { + if(auto exp = SP800_108_Feedback::make(spec)) + { + if(auto mac = MessageAuthenticationCode::create(spec.arg(0))) + return new SP800_56C(mac.release(), exp); + + if(auto mac = MessageAuthenticationCode::create("HMAC(" + spec.arg(0) + ")")) + return new SP800_56C(mac.release(), exp); + } + + return nullptr; + } + +size_t SP800_56C::kdf(byte key[], size_t key_len, + const byte secret[], size_t secret_len, + const byte salt[], size_t salt_len) const + { + // Randomness Extraction + secure_vector< byte > k_dk, context; + + m_prf->set_key(salt, salt_len); + m_prf->update(secret, secret_len); + m_prf->final(k_dk); + + // Key Expansion + m_exp->kdf(key, key_len, k_dk.data(), k_dk.size(), context.data(), context.size()); + + return key_len; + } + +} diff --git a/src/lib/kdf/sp800_56c/sp800_56c.h b/src/lib/kdf/sp800_56c/sp800_56c.h new file mode 100644 index 000000000..d1b6f39b5 --- /dev/null +++ b/src/lib/kdf/sp800_56c/sp800_56c.h @@ -0,0 +1,39 @@ +/* +* KDF defined in NIST SP 800-56c +* (C) 2016 Kai Michaelis +* +* Botan is released under the Simplified BSD License (see license.txt) +*/ + +#ifndef BOTAN_SP800_56C_H__ +#define BOTAN_SP800_56C_H__ + +#include <botan/kdf.h> +#include <botan/mac.h> + +namespace Botan { + +/** + * NIST SP 800-56C KDF + */ +class BOTAN_DLL SP800_56C : public KDF + { + public: + std::string name() const override { return "SP800-56C(" + m_prf->name() + ")"; } + + KDF* clone() const override { return new SP800_56C(m_prf->clone(), m_exp->clone()); } + + size_t kdf(byte key[], size_t key_len, + const byte secret[], size_t secret_len, + const byte salt[], size_t salt_len) const override; + + SP800_56C(MessageAuthenticationCode* mac, KDF* exp) : m_prf(mac), m_exp(exp) {} + + static SP800_56C* make(const Spec& spec); + private: + std::unique_ptr<MessageAuthenticationCode> m_prf; + std::unique_ptr<KDF> m_exp; + }; +} + +#endif |