aboutsummaryrefslogtreecommitdiffstats
path: root/src/lib/kdf
diff options
context:
space:
mode:
Diffstat (limited to 'src/lib/kdf')
-rw-r--r--src/lib/kdf/kdf.cpp17
-rw-r--r--src/lib/kdf/sp800_108/info.txt6
-rw-r--r--src/lib/kdf/sp800_108/sp800_108.cpp157
-rw-r--r--src/lib/kdf/sp800_108/sp800_108.h81
-rw-r--r--src/lib/kdf/sp800_56c/info.txt6
-rw-r--r--src/lib/kdf/sp800_56c/sp800_56c.cpp45
-rw-r--r--src/lib/kdf/sp800_56c/sp800_56c.h39
7 files changed, 351 insertions, 0 deletions
diff --git a/src/lib/kdf/kdf.cpp b/src/lib/kdf/kdf.cpp
index 45ee165e0..7f4488d32 100644
--- a/src/lib/kdf/kdf.cpp
+++ b/src/lib/kdf/kdf.cpp
@@ -33,6 +33,14 @@
#include <botan/prf_x942.h>
#endif
+#if defined(BOTAN_HAS_SP800_108)
+#include <botan/sp800_108.h>
+#endif
+
+#if defined(BOTAN_HAS_SP800_56C)
+#include <botan/sp800_56c.h>
+#endif
+
#define BOTAN_REGISTER_KDF_NOARGS(type, name) \
BOTAN_REGISTER_NAMED_T(KDF, name, type, (make_new_T<type>))
#define BOTAN_REGISTER_KDF_1HASH(type, name) \
@@ -93,4 +101,13 @@ BOTAN_REGISTER_NAMED_T(KDF, "TLS-12-PRF", TLS_12_PRF, TLS_12_PRF::make);
BOTAN_REGISTER_KDF_NAMED_1STR(X942_PRF, "X9.42-PRF");
#endif
+#if defined(BOTAN_HAS_SP800_108)
+BOTAN_REGISTER_NAMED_T(KDF, "SP800-108-Counter", SP800_108_Counter, SP800_108_Counter::make);
+BOTAN_REGISTER_NAMED_T(KDF, "SP800-108-Feedback", SP800_108_Feedback, SP800_108_Feedback::make);
+BOTAN_REGISTER_NAMED_T(KDF, "SP800-108-Pipeline", SP800_108_Pipeline, SP800_108_Pipeline::make);
+#endif
+
+#if defined(BOTAN_HAS_SP800_56C)
+BOTAN_REGISTER_NAMED_T(KDF, "SP800-56C", SP800_56C, SP800_56C::make);
+#endif
}
diff --git a/src/lib/kdf/sp800_108/info.txt b/src/lib/kdf/sp800_108/info.txt
new file mode 100644
index 000000000..a78531fe7
--- /dev/null
+++ b/src/lib/kdf/sp800_108/info.txt
@@ -0,0 +1,6 @@
+define SP800_108 20160128
+
+<requires>
+mac
+hmac
+</requires>
diff --git a/src/lib/kdf/sp800_108/sp800_108.cpp b/src/lib/kdf/sp800_108/sp800_108.cpp
new file mode 100644
index 000000000..873db814c
--- /dev/null
+++ b/src/lib/kdf/sp800_108/sp800_108.cpp
@@ -0,0 +1,157 @@
+/*
+* KDFs defined in NIST SP 800-108
+* (C) 2016 Kai Michaelis
+*
+* Botan is released under the Simplified BSD License (see license.txt)
+*/
+
+#include <botan/sp800_108.h>
+#include <botan/hmac.h>
+
+namespace Botan {
+
+SP800_108_Counter* SP800_108_Counter::make(const Spec& spec)
+ {
+ if(auto mac = MessageAuthenticationCode::create(spec.arg(0)))
+ return new SP800_108_Counter(mac.release());
+
+ if(auto mac = MessageAuthenticationCode::create("HMAC(" + spec.arg(0) + ")"))
+ return new SP800_108_Counter(mac.release());
+
+ return nullptr;
+ }
+
+size_t SP800_108_Counter::kdf(byte key[], size_t key_len,
+ const byte secret[], size_t secret_len,
+ const byte salt[], size_t salt_len) const
+ {
+ const std::size_t prf_len = m_prf->output_length();
+ byte *p = key;
+ uint32_t counter = 1;
+ secure_vector<byte> tmp;
+
+ m_prf->set_key(secret, secret_len);
+
+ while(p < key + key_len && counter != 0)
+ {
+ const std::size_t to_copy = std::min< std::size_t >(key + key_len - p, prf_len);
+ byte be_cnt[4] = { 0 };
+
+ store_be(counter, be_cnt);
+
+ m_prf->update(be_cnt,4);
+ m_prf->update(salt, salt_len);
+ m_prf->final(tmp);
+
+ std::move(tmp.begin(), tmp.begin() + to_copy, p);
+ ++counter;
+
+ if (counter == 0)
+ throw Invalid_Argument("Can't process more than 4GB");
+
+ p += to_copy;
+ }
+
+ return key_len;
+ }
+
+SP800_108_Feedback* SP800_108_Feedback::make(const Spec& spec)
+ {
+ if(auto mac = MessageAuthenticationCode::create(spec.arg(0)))
+ return new SP800_108_Feedback(mac.release());
+
+ if(auto mac = MessageAuthenticationCode::create("HMAC(" + spec.arg(0) + ")"))
+ return new SP800_108_Feedback(mac.release());
+
+ return nullptr;
+ }
+
+size_t SP800_108_Feedback::kdf(byte key[], size_t key_len,
+ const byte secret[], size_t secret_len,
+ const byte salt[], size_t salt_len) const
+ {
+ const std::size_t prf_len = m_prf->output_length();
+ const std::size_t iv_len = (salt_len >= prf_len ? prf_len : 0);
+
+ byte *p = key;
+ uint32_t counter = 1;
+ secure_vector< byte > prev(salt, salt + iv_len);
+ secure_vector< byte > ctx(salt + iv_len, salt + salt_len);
+
+ m_prf->set_key(secret, secret_len);
+
+ while(p < key + key_len && counter != 0)
+ {
+ const std::size_t to_copy = std::min< std::size_t >(key + key_len - p, prf_len);
+ byte be_cnt[4] = { 0 };
+
+ store_be(counter, be_cnt);
+
+ m_prf->update(prev);
+ m_prf->update(be_cnt,4);
+ m_prf->update(ctx);
+ m_prf->final(prev);
+
+ std::copy(prev.begin(), prev.begin() + to_copy, p);
+ ++counter;
+
+ if (counter == 0)
+ throw Invalid_Argument("Can't process more than 4GB");
+
+ p += to_copy;
+ }
+
+ return key_len;
+ }
+
+SP800_108_Pipeline* SP800_108_Pipeline::make(const Spec& spec)
+ {
+ if(auto mac = MessageAuthenticationCode::create(spec.arg(0)))
+ return new SP800_108_Pipeline(mac.release());
+
+ if(auto mac = MessageAuthenticationCode::create("HMAC(" + spec.arg(0) + ")"))
+ return new SP800_108_Pipeline(mac.release());
+
+ return nullptr;
+ }
+
+size_t SP800_108_Pipeline::kdf(byte key[], size_t key_len,
+ const byte secret[], size_t secret_len,
+ const byte salt[], size_t salt_len) const
+ {
+ const std::size_t prf_len = m_prf->output_length();
+ byte *p = key;
+ uint32_t counter = 1;
+ secure_vector<byte> ai(salt, salt + salt_len), ki;
+
+ m_prf->set_key(secret,secret_len);
+
+ while(p < key + key_len && counter != 0)
+ {
+ // A(i)
+ m_prf->update(ai);
+ m_prf->final(ai);
+
+ // K(i)
+ const std::size_t to_copy = std::min< std::size_t >(key + key_len - p, prf_len);
+ byte be_cnt[4] = { 0 };
+
+ store_be(counter, be_cnt);
+
+ m_prf->update(ai);
+ m_prf->update(be_cnt,4);
+ m_prf->update(salt, salt_len);
+ m_prf->final(ki);
+
+ std::copy(ki.begin(), ki.begin() + to_copy, p);
+ ++counter;
+
+ if (counter == 0)
+ throw Invalid_Argument("Can't process more than 4GB");
+
+ p += to_copy;
+ }
+
+ return key_len;
+ }
+}
diff --git a/src/lib/kdf/sp800_108/sp800_108.h b/src/lib/kdf/sp800_108/sp800_108.h
new file mode 100644
index 000000000..0acdfacf9
--- /dev/null
+++ b/src/lib/kdf/sp800_108/sp800_108.h
@@ -0,0 +1,81 @@
+/*
+* KDFs defined in NIST SP 800-108
+* (C) 2016 Kai Michaelis
+*
+* Botan is released under the Simplified BSD License (see license.txt)
+*/
+
+#ifndef BOTAN_SP800_108_H__
+#define BOTAN_SP800_108_H__
+
+#include <botan/kdf.h>
+#include <botan/mac.h>
+
+namespace Botan {
+
+/**
+ * NIST SP 800-108 KDF in Counter Mode (5.1)
+ */
+class BOTAN_DLL SP800_108_Counter : public KDF
+ {
+ public:
+ std::string name() const override { return "SP800-108-Counter(" + m_prf->name() + ")"; }
+
+ KDF* clone() const override { return new SP800_108_Counter(m_prf->clone()); }
+
+ size_t kdf(byte key[], size_t key_len,
+ const byte secret[], size_t secret_len,
+ const byte salt[], size_t salt_len) const override;
+
+ SP800_108_Counter(MessageAuthenticationCode* mac) : m_prf(mac) {}
+
+ static SP800_108_Counter* make(const Spec& spec);
+ private:
+ std::unique_ptr<MessageAuthenticationCode> m_prf;
+ };
+
+/**
+ * NIST SP 800-108 KDF in Feedback Mode (5.2)
+ */
+class BOTAN_DLL SP800_108_Feedback : public KDF
+ {
+ public:
+ std::string name() const override { return "SP800-108-Feedback(" + m_prf->name() + ")"; }
+
+ KDF* clone() const override { return new SP800_108_Feedback(m_prf->clone()); }
+
+ size_t kdf(byte key[], size_t key_len,
+ const byte secret[], size_t secret_len,
+ const byte salt[], size_t salt_len) const override;
+
+ SP800_108_Feedback(MessageAuthenticationCode* mac) : m_prf(mac) {}
+
+ static SP800_108_Feedback* make(const Spec& spec);
+ private:
+ std::unique_ptr<MessageAuthenticationCode> m_prf;
+ };
+
+/**
+ * NIST SP 800-108 KDF in Double Pipeline Mode (5.3)
+ */
+class BOTAN_DLL SP800_108_Pipeline : public KDF
+ {
+ public:
+ std::string name() const override { return "SP800-108-Pipeline(" + m_prf->name() + ")"; }
+
+ KDF* clone() const override { return new SP800_108_Pipeline(m_prf->clone()); }
+
+ size_t kdf(byte key[], size_t key_len,
+ const byte secret[], size_t secret_len,
+ const byte salt[], size_t salt_len) const override;
+
+ SP800_108_Pipeline(MessageAuthenticationCode* mac) : m_prf(mac) {}
+
+ static SP800_108_Pipeline* make(const Spec& spec);
+ private:
+ std::unique_ptr<MessageAuthenticationCode> m_prf;
+ };
+
+}
+
+#endif
diff --git a/src/lib/kdf/sp800_56c/info.txt b/src/lib/kdf/sp800_56c/info.txt
new file mode 100644
index 000000000..203c05a83
--- /dev/null
+++ b/src/lib/kdf/sp800_56c/info.txt
@@ -0,0 +1,6 @@
+define SP800_56C 20160211
+
+<requires>
+sp800_108
+hmac
+</requires>
diff --git a/src/lib/kdf/sp800_56c/sp800_56c.cpp b/src/lib/kdf/sp800_56c/sp800_56c.cpp
new file mode 100644
index 000000000..664d32b30
--- /dev/null
+++ b/src/lib/kdf/sp800_56c/sp800_56c.cpp
@@ -0,0 +1,45 @@
+/*
+* KDF defined in NIST SP 800-56c
+* (C) 2016 Kai Michaelis
+*
+* Botan is released under the Simplified BSD License (see license.txt)
+*/
+
+#include <botan/sp800_108.h>
+#include <botan/sp800_56c.h>
+#include <botan/hmac.h>
+
+namespace Botan {
+
+SP800_56C* SP800_56C::make(const Spec& spec)
+ {
+ if(auto exp = SP800_108_Feedback::make(spec))
+ {
+ if(auto mac = MessageAuthenticationCode::create(spec.arg(0)))
+ return new SP800_56C(mac.release(), exp);
+
+ if(auto mac = MessageAuthenticationCode::create("HMAC(" + spec.arg(0) + ")"))
+ return new SP800_56C(mac.release(), exp);
+ }
+
+ return nullptr;
+ }
+
+size_t SP800_56C::kdf(byte key[], size_t key_len,
+ const byte secret[], size_t secret_len,
+ const byte salt[], size_t salt_len) const
+ {
+ // Randomness Extraction
+ secure_vector< byte > k_dk, context;
+
+ m_prf->set_key(salt, salt_len);
+ m_prf->update(secret, secret_len);
+ m_prf->final(k_dk);
+
+ // Key Expansion
+ m_exp->kdf(key, key_len, k_dk.data(), k_dk.size(), context.data(), context.size());
+
+ return key_len;
+ }
+
+}
diff --git a/src/lib/kdf/sp800_56c/sp800_56c.h b/src/lib/kdf/sp800_56c/sp800_56c.h
new file mode 100644
index 000000000..d1b6f39b5
--- /dev/null
+++ b/src/lib/kdf/sp800_56c/sp800_56c.h
@@ -0,0 +1,39 @@
+/*
+* KDF defined in NIST SP 800-56c
+* (C) 2016 Kai Michaelis
+*
+* Botan is released under the Simplified BSD License (see license.txt)
+*/
+
+#ifndef BOTAN_SP800_56C_H__
+#define BOTAN_SP800_56C_H__
+
+#include <botan/kdf.h>
+#include <botan/mac.h>
+
+namespace Botan {
+
+/**
+ * NIST SP 800-56C KDF
+ */
+class BOTAN_DLL SP800_56C : public KDF
+ {
+ public:
+ std::string name() const override { return "SP800-56C(" + m_prf->name() + ")"; }
+
+ KDF* clone() const override { return new SP800_56C(m_prf->clone(), m_exp->clone()); }
+
+ size_t kdf(byte key[], size_t key_len,
+ const byte secret[], size_t secret_len,
+ const byte salt[], size_t salt_len) const override;
+
+ SP800_56C(MessageAuthenticationCode* mac, KDF* exp) : m_prf(mac), m_exp(exp) {}
+
+ static SP800_56C* make(const Spec& spec);
+ private:
+ std::unique_ptr<MessageAuthenticationCode> m_prf;
+ std::unique_ptr<KDF> m_exp;
+ };
+}
+
+#endif