2005-11-18 08:19:12 +00:00
|
|
|
/*
|
2010-03-09 16:15:16 +00:00
|
|
|
* Copyright (C) 2010 Tobias Brunner
|
2007-10-04 15:19:24 +00:00
|
|
|
* Copyright (C) 2005-2007 Martin Willi
|
2006-07-07 08:49:06 +00:00
|
|
|
* Copyright (C) 2005 Jan Hutter
|
2018-05-23 14:04:50 +00:00
|
|
|
* HSR Hochschule fuer Technik Rapperswil
|
2005-11-18 08:19:12 +00:00
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or modify it
|
|
|
|
* under the terms of the GNU General Public License as published by the
|
|
|
|
* Free Software Foundation; either version 2 of the License, or (at your
|
|
|
|
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful, but
|
|
|
|
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
|
|
|
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
|
|
|
* for more details.
|
2008-03-13 14:14:44 +00:00
|
|
|
*/
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2008-03-13 14:14:44 +00:00
|
|
|
/**
|
|
|
|
* @defgroup diffie_hellman diffie_hellman
|
|
|
|
* @{ @ingroup crypto
|
2005-11-18 08:19:12 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef DIFFIE_HELLMAN_H_
|
|
|
|
#define DIFFIE_HELLMAN_H_
|
|
|
|
|
2005-11-24 16:22:04 +00:00
|
|
|
typedef enum diffie_hellman_group_t diffie_hellman_group_t;
|
2006-10-30 14:07:05 +00:00
|
|
|
typedef struct diffie_hellman_t diffie_hellman_t;
|
2010-03-09 16:15:16 +00:00
|
|
|
typedef struct diffie_hellman_params_t diffie_hellman_params_t;
|
2005-11-24 16:22:04 +00:00
|
|
|
|
2006-10-31 12:27:59 +00:00
|
|
|
#include <library.h>
|
2006-10-30 14:07:05 +00:00
|
|
|
|
|
|
|
/**
|
2008-03-13 14:14:44 +00:00
|
|
|
* Diffie-Hellman group.
|
2006-10-30 14:07:05 +00:00
|
|
|
*
|
2005-11-24 16:22:04 +00:00
|
|
|
* The modulus (or group) to use for a Diffie-Hellman calculation.
|
2006-03-07 09:42:15 +00:00
|
|
|
* See IKEv2 RFC 3.3.2 and RFC 3526.
|
2009-09-04 11:46:09 +00:00
|
|
|
*
|
2008-05-22 11:55:05 +00:00
|
|
|
* ECP groups are defined in RFC 4753 and RFC 5114.
|
2013-09-09 07:36:04 +00:00
|
|
|
* ECC Brainpool groups are defined in RFC 6954.
|
2014-08-08 14:20:31 +00:00
|
|
|
* Curve25519 and Curve448 groups are defined in RFC 8031.
|
2005-11-24 16:22:04 +00:00
|
|
|
*/
|
|
|
|
enum diffie_hellman_group_t {
|
2008-05-29 06:55:03 +00:00
|
|
|
MODP_NONE = 0,
|
|
|
|
MODP_768_BIT = 1,
|
|
|
|
MODP_1024_BIT = 2,
|
|
|
|
MODP_1536_BIT = 5,
|
2005-11-24 16:22:04 +00:00
|
|
|
MODP_2048_BIT = 14,
|
|
|
|
MODP_3072_BIT = 15,
|
|
|
|
MODP_4096_BIT = 16,
|
|
|
|
MODP_6144_BIT = 17,
|
2008-05-22 11:39:17 +00:00
|
|
|
MODP_8192_BIT = 18,
|
2008-05-29 06:55:03 +00:00
|
|
|
ECP_256_BIT = 19,
|
|
|
|
ECP_384_BIT = 20,
|
|
|
|
ECP_521_BIT = 21,
|
2010-04-19 12:41:20 +00:00
|
|
|
MODP_1024_160 = 22,
|
|
|
|
MODP_2048_224 = 23,
|
|
|
|
MODP_2048_256 = 24,
|
2008-05-29 06:55:03 +00:00
|
|
|
ECP_192_BIT = 25,
|
|
|
|
ECP_224_BIT = 26,
|
2013-09-09 07:36:04 +00:00
|
|
|
ECP_224_BP = 27,
|
|
|
|
ECP_256_BP = 28,
|
|
|
|
ECP_384_BP = 29,
|
|
|
|
ECP_512_BP = 30,
|
2014-08-08 14:20:31 +00:00
|
|
|
CURVE_25519 = 31,
|
|
|
|
CURVE_448 = 32,
|
2008-11-22 16:14:55 +00:00
|
|
|
/** insecure NULL diffie hellman group for testing, in PRIVATE USE */
|
|
|
|
MODP_NULL = 1024,
|
2011-10-28 18:59:03 +00:00
|
|
|
/** MODP group with custom generator/prime */
|
2013-11-18 20:11:03 +00:00
|
|
|
/** Parameters defined by IEEE 1363.1, in PRIVATE USE */
|
|
|
|
NTRU_112_BIT = 1030,
|
|
|
|
NTRU_128_BIT = 1031,
|
|
|
|
NTRU_192_BIT = 1032,
|
2014-12-01 16:21:59 +00:00
|
|
|
NTRU_256_BIT = 1033,
|
2016-07-26 09:32:22 +00:00
|
|
|
NH_128_BIT = 1040,
|
2014-12-01 16:21:59 +00:00
|
|
|
/** internally used DH group with additional parameters g and p, outside
|
|
|
|
* of PRIVATE USE (i.e. IKEv2 DH group range) so it can't be negotiated */
|
|
|
|
MODP_CUSTOM = 65536,
|
2005-11-24 16:22:04 +00:00
|
|
|
};
|
|
|
|
|
2006-10-18 11:46:13 +00:00
|
|
|
/**
|
|
|
|
* enum name for diffie_hellman_group_t.
|
2005-11-24 16:22:04 +00:00
|
|
|
*/
|
2006-10-18 11:46:13 +00:00
|
|
|
extern enum_name_t *diffie_hellman_group_names;
|
2005-11-24 16:22:04 +00:00
|
|
|
|
2005-11-18 08:19:12 +00:00
|
|
|
/**
|
2008-03-13 14:14:44 +00:00
|
|
|
* Implementation of the Diffie-Hellman algorithm, as in RFC2631.
|
2005-11-18 08:19:12 +00:00
|
|
|
*/
|
2005-11-24 11:30:19 +00:00
|
|
|
struct diffie_hellman_t {
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2005-11-18 08:19:12 +00:00
|
|
|
/**
|
2008-03-13 14:14:44 +00:00
|
|
|
* Returns the shared secret of this diffie hellman exchange.
|
2009-09-04 11:46:09 +00:00
|
|
|
*
|
2012-01-06 16:37:59 +00:00
|
|
|
* Space for returned secret is allocated and must be freed by the caller.
|
2009-09-04 11:46:09 +00:00
|
|
|
*
|
2010-03-09 16:15:16 +00:00
|
|
|
* @param secret shared secret will be written into this chunk
|
2015-03-23 09:54:24 +00:00
|
|
|
* @return TRUE if shared secret computed successfully
|
2005-11-18 08:19:12 +00:00
|
|
|
*/
|
2015-03-23 09:54:24 +00:00
|
|
|
bool (*get_shared_secret)(diffie_hellman_t *this, chunk_t *secret)
|
|
|
|
__attribute__((warn_unused_result));
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2005-11-18 08:19:12 +00:00
|
|
|
/**
|
2008-03-13 14:14:44 +00:00
|
|
|
* Sets the public value of partner.
|
2009-09-04 11:46:09 +00:00
|
|
|
*
|
2007-10-04 15:19:24 +00:00
|
|
|
* Chunk gets cloned and can be destroyed afterwards.
|
2009-09-04 11:46:09 +00:00
|
|
|
*
|
2010-03-09 16:15:16 +00:00
|
|
|
* @param value public value of partner
|
2015-03-23 12:09:32 +00:00
|
|
|
* @return TRUE if other public value verified and set
|
2005-11-18 08:19:12 +00:00
|
|
|
*/
|
2015-03-23 12:09:32 +00:00
|
|
|
bool (*set_other_public_value)(diffie_hellman_t *this, chunk_t value)
|
|
|
|
__attribute__((warn_unused_result));
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2005-11-18 08:19:12 +00:00
|
|
|
/**
|
2008-03-13 14:14:44 +00:00
|
|
|
* Gets the own public value to transmit.
|
2009-09-04 11:46:09 +00:00
|
|
|
*
|
2007-10-04 15:19:24 +00:00
|
|
|
* Space for returned chunk is allocated and must be freed by the caller.
|
2009-09-04 11:46:09 +00:00
|
|
|
*
|
2007-10-04 15:19:24 +00:00
|
|
|
* @param value public value of caller is stored at this location
|
2015-03-23 10:37:27 +00:00
|
|
|
* @return TRUE if public value retrieved
|
2005-11-18 08:19:12 +00:00
|
|
|
*/
|
2015-03-23 10:37:27 +00:00
|
|
|
bool (*get_my_public_value) (diffie_hellman_t *this, chunk_t *value)
|
|
|
|
__attribute__((warn_unused_result));
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2015-04-09 08:02:24 +00:00
|
|
|
/**
|
|
|
|
* Set an explicit own private value to use.
|
|
|
|
*
|
|
|
|
* Calling this method is usually not required, as the DH backend generates
|
|
|
|
* an appropriate private value itself. It is optional to implement, and
|
|
|
|
* used mostly for testing purposes.
|
|
|
|
*
|
|
|
|
* @param value private value to set
|
|
|
|
*/
|
|
|
|
bool (*set_private_value)(diffie_hellman_t *this, chunk_t value)
|
|
|
|
__attribute__((warn_unused_result));
|
|
|
|
|
2006-02-14 14:52:00 +00:00
|
|
|
/**
|
2008-03-13 14:14:44 +00:00
|
|
|
* Get the DH group used.
|
2009-09-04 11:46:09 +00:00
|
|
|
*
|
2007-10-04 15:19:24 +00:00
|
|
|
* @return DH group set in construction
|
2006-02-14 14:52:00 +00:00
|
|
|
*/
|
|
|
|
diffie_hellman_group_t (*get_dh_group) (diffie_hellman_t *this);
|
2005-11-18 08:19:12 +00:00
|
|
|
|
|
|
|
/**
|
2012-01-06 16:37:59 +00:00
|
|
|
* Destroys a diffie_hellman_t object.
|
2005-11-18 08:19:12 +00:00
|
|
|
*/
|
2005-11-28 20:29:47 +00:00
|
|
|
void (*destroy) (diffie_hellman_t *this);
|
2005-11-18 08:19:12 +00:00
|
|
|
};
|
|
|
|
|
2010-03-09 16:15:16 +00:00
|
|
|
/**
|
|
|
|
* Parameters for a specific diffie hellman group.
|
|
|
|
*/
|
|
|
|
struct diffie_hellman_params_t {
|
|
|
|
|
|
|
|
/**
|
2010-04-08 13:08:35 +00:00
|
|
|
* The prime of the group
|
2010-03-09 16:15:16 +00:00
|
|
|
*/
|
2010-04-08 13:08:35 +00:00
|
|
|
const chunk_t prime;
|
2010-03-09 16:15:16 +00:00
|
|
|
|
|
|
|
/**
|
2010-04-08 13:08:35 +00:00
|
|
|
* Generator of the group
|
2010-03-09 16:15:16 +00:00
|
|
|
*/
|
2010-04-08 13:08:35 +00:00
|
|
|
const chunk_t generator;
|
2010-03-09 16:15:16 +00:00
|
|
|
|
|
|
|
/**
|
2010-04-08 13:08:35 +00:00
|
|
|
* Exponent length to use
|
2010-03-09 16:15:16 +00:00
|
|
|
*/
|
|
|
|
size_t exp_len;
|
2010-04-19 12:41:20 +00:00
|
|
|
|
|
|
|
/**
|
|
|
|
* Prime order subgroup; for MODP Groups 22-24
|
|
|
|
*/
|
|
|
|
const chunk_t subgroup;
|
2010-03-09 16:15:16 +00:00
|
|
|
};
|
|
|
|
|
2014-07-16 14:44:24 +00:00
|
|
|
/**
|
|
|
|
* Initialize diffie hellman parameters during startup.
|
|
|
|
*/
|
|
|
|
void diffie_hellman_init();
|
|
|
|
|
2010-03-09 16:15:16 +00:00
|
|
|
/**
|
|
|
|
* Get the parameters associated with the specified diffie hellman group.
|
|
|
|
*
|
2014-07-16 14:44:24 +00:00
|
|
|
* Before calling this method, use diffie_hellman_init() to initialize the
|
|
|
|
* DH group table. This is usually done by library_init().
|
|
|
|
*
|
2010-03-09 16:15:16 +00:00
|
|
|
* @param group DH group
|
|
|
|
* @return The parameters or NULL, if the group is not supported
|
|
|
|
*/
|
|
|
|
diffie_hellman_params_t *diffie_hellman_get_params(diffie_hellman_group_t group);
|
|
|
|
|
2010-09-03 14:22:10 +00:00
|
|
|
/**
|
|
|
|
* Check if a given DH group is an ECDH group
|
|
|
|
*
|
|
|
|
* @param group group to check
|
2015-03-23 13:32:11 +00:00
|
|
|
* @return TRUE if group is an ECP group
|
2010-09-03 14:22:10 +00:00
|
|
|
*/
|
|
|
|
bool diffie_hellman_group_is_ec(diffie_hellman_group_t group);
|
|
|
|
|
2015-03-23 13:32:11 +00:00
|
|
|
/**
|
|
|
|
* Check if a diffie hellman public value is valid for given group.
|
|
|
|
*
|
|
|
|
* @param group group the value is used in
|
|
|
|
* @param value public DH value to check
|
|
|
|
* @return TRUE if value looks valid for group
|
|
|
|
*/
|
|
|
|
bool diffie_hellman_verify_value(diffie_hellman_group_t group, chunk_t value);
|
|
|
|
|
2009-03-24 17:43:01 +00:00
|
|
|
#endif /** DIFFIE_HELLMAN_H_ @}*/
|