17c478bd9Sstevel@tonic-gate /*
27c478bd9Sstevel@tonic-gate  * CDDL HEADER START
37c478bd9Sstevel@tonic-gate  *
47c478bd9Sstevel@tonic-gate  * The contents of this file are subject to the terms of the
5b60f2a0bSfr  * Common Development and Distribution License (the "License").
6b60f2a0bSfr  * You may not use this file except in compliance with the License.
77c478bd9Sstevel@tonic-gate  *
87c478bd9Sstevel@tonic-gate  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
97c478bd9Sstevel@tonic-gate  * or http://www.opensolaris.org/os/licensing.
107c478bd9Sstevel@tonic-gate  * See the License for the specific language governing permissions
117c478bd9Sstevel@tonic-gate  * and limitations under the License.
127c478bd9Sstevel@tonic-gate  *
137c478bd9Sstevel@tonic-gate  * When distributing Covered Code, include this CDDL HEADER in each
147c478bd9Sstevel@tonic-gate  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
157c478bd9Sstevel@tonic-gate  * If applicable, add the following below this CDDL HEADER, with the
167c478bd9Sstevel@tonic-gate  * fields enclosed by brackets "[]" replaced with your own identifying
177c478bd9Sstevel@tonic-gate  * information: Portions Copyright [yyyy] [name of copyright owner]
187c478bd9Sstevel@tonic-gate  *
197c478bd9Sstevel@tonic-gate  * CDDL HEADER END
207c478bd9Sstevel@tonic-gate  */
21726fad2aSDina K Nimeh 
227c478bd9Sstevel@tonic-gate /*
23726fad2aSDina K Nimeh  * Copyright (c) 2003, 2010, Oracle and/or its affiliates. All rights reserved.
247c478bd9Sstevel@tonic-gate  */
257c478bd9Sstevel@tonic-gate 
267c478bd9Sstevel@tonic-gate #include <stdlib.h>
277c478bd9Sstevel@tonic-gate #include <string.h>
287c478bd9Sstevel@tonic-gate #include <strings.h>
297c478bd9Sstevel@tonic-gate #include <sys/types.h>
307c478bd9Sstevel@tonic-gate #include <security/cryptoki.h>
3123c57df7Smcpowers #include <sys/crypto/common.h>
327c478bd9Sstevel@tonic-gate #include <des_impl.h>
33726fad2aSDina K Nimeh #include <cryptoutil.h>
347c478bd9Sstevel@tonic-gate #include "softGlobal.h"
357c478bd9Sstevel@tonic-gate #include "softSession.h"
367c478bd9Sstevel@tonic-gate #include "softObject.h"
377c478bd9Sstevel@tonic-gate #include "softDH.h"
387c478bd9Sstevel@tonic-gate #include "softCrypt.h"
397c478bd9Sstevel@tonic-gate 
407c478bd9Sstevel@tonic-gate 
417c478bd9Sstevel@tonic-gate /*
42726fad2aSDina K Nimeh  * This function takes a converted big integer of the specified attribute
43726fad2aSDina K Nimeh  * as an octet string and stores it in the corresponding key object.
447c478bd9Sstevel@tonic-gate  */
45726fad2aSDina K Nimeh static CK_RV
soft_genDHkey_set_attribute(soft_object_t * key,CK_ATTRIBUTE_TYPE type,uchar_t * buf,uint32_t buflen,boolean_t public)46726fad2aSDina K Nimeh soft_genDHkey_set_attribute(soft_object_t *key, CK_ATTRIBUTE_TYPE type,
47726fad2aSDina K Nimeh     uchar_t *buf, uint32_t buflen, boolean_t public)
487c478bd9Sstevel@tonic-gate {
497c478bd9Sstevel@tonic-gate 
507c478bd9Sstevel@tonic-gate 	CK_RV rv = CKR_OK;
517c478bd9Sstevel@tonic-gate 	biginteger_t *dst = NULL;
527c478bd9Sstevel@tonic-gate 	biginteger_t src;
537c478bd9Sstevel@tonic-gate 
547c478bd9Sstevel@tonic-gate 	switch (type) {
557c478bd9Sstevel@tonic-gate 
567c478bd9Sstevel@tonic-gate 	case CKA_VALUE:
577c478bd9Sstevel@tonic-gate 		if (public)
587c478bd9Sstevel@tonic-gate 			dst = OBJ_PUB_DH_VALUE(key);
597c478bd9Sstevel@tonic-gate 		else
607c478bd9Sstevel@tonic-gate 			dst = OBJ_PRI_DH_VALUE(key);
617c478bd9Sstevel@tonic-gate 		break;
627c478bd9Sstevel@tonic-gate 
637c478bd9Sstevel@tonic-gate 	case CKA_PRIME:
647c478bd9Sstevel@tonic-gate 		dst = OBJ_PRI_DH_PRIME(key);
657c478bd9Sstevel@tonic-gate 		break;
667c478bd9Sstevel@tonic-gate 
677c478bd9Sstevel@tonic-gate 	case CKA_BASE:
687c478bd9Sstevel@tonic-gate 		dst = OBJ_PRI_DH_BASE(key);
697c478bd9Sstevel@tonic-gate 		break;
707c478bd9Sstevel@tonic-gate 	}
717c478bd9Sstevel@tonic-gate 
72726fad2aSDina K Nimeh 	if ((rv = dup_bigint_attr(&src, buf, buflen)) != CKR_OK)
737c478bd9Sstevel@tonic-gate 		goto cleanexit;
747c478bd9Sstevel@tonic-gate 
757c478bd9Sstevel@tonic-gate 	/* Copy the attribute in the key object. */
767c478bd9Sstevel@tonic-gate 	copy_bigint_attr(&src, dst);
777c478bd9Sstevel@tonic-gate 
787c478bd9Sstevel@tonic-gate cleanexit:
79726fad2aSDina K Nimeh 	/* No need to free big_value because dst holds it now after copy. */
807c478bd9Sstevel@tonic-gate 	return (rv);
817c478bd9Sstevel@tonic-gate 
827c478bd9Sstevel@tonic-gate }
837c478bd9Sstevel@tonic-gate 
847c478bd9Sstevel@tonic-gate /*
857c478bd9Sstevel@tonic-gate  * This function covers the DH Key agreement.
867c478bd9Sstevel@tonic-gate  */
877c478bd9Sstevel@tonic-gate CK_RV
soft_dh_genkey_pair(soft_object_t * pubkey,soft_object_t * prikey)887c478bd9Sstevel@tonic-gate soft_dh_genkey_pair(soft_object_t *pubkey, soft_object_t *prikey)
897c478bd9Sstevel@tonic-gate {
907c478bd9Sstevel@tonic-gate 	CK_RV		rv;
91726fad2aSDina K Nimeh 	CK_ATTRIBUTE 	template;
927c478bd9Sstevel@tonic-gate 	uchar_t		prime[MAX_KEY_ATTR_BUFLEN];
937c478bd9Sstevel@tonic-gate 	uint32_t	prime_len = sizeof (prime);
947c478bd9Sstevel@tonic-gate 	uchar_t		base[MAX_KEY_ATTR_BUFLEN];
957c478bd9Sstevel@tonic-gate 	uint32_t	base_len = sizeof (base);
96726fad2aSDina K Nimeh 	uint32_t	value_bits;
97726fad2aSDina K Nimeh 	uchar_t		private_x[MAX_KEY_ATTR_BUFLEN];
98726fad2aSDina K Nimeh 	uchar_t		public_y[MAX_KEY_ATTR_BUFLEN];
99726fad2aSDina K Nimeh 	DHbytekey	k;
1007c478bd9Sstevel@tonic-gate 
1017c478bd9Sstevel@tonic-gate 	if ((pubkey->class != CKO_PUBLIC_KEY) ||
102b60f2a0bSfr 	    (pubkey->key_type != CKK_DH)) {
1037c478bd9Sstevel@tonic-gate 		return (CKR_KEY_TYPE_INCONSISTENT);
104b60f2a0bSfr 	}
1057c478bd9Sstevel@tonic-gate 
1067c478bd9Sstevel@tonic-gate 	if ((prikey->class != CKO_PRIVATE_KEY) ||
107b60f2a0bSfr 	    (prikey->key_type != CKK_DH)) {
1087c478bd9Sstevel@tonic-gate 		return (CKR_KEY_TYPE_INCONSISTENT);
109b60f2a0bSfr 	}
1107c478bd9Sstevel@tonic-gate 
111726fad2aSDina K Nimeh 	/* Get private-value length in bits */
1127c478bd9Sstevel@tonic-gate 	template.pValue = malloc(sizeof (CK_ULONG));
1137c478bd9Sstevel@tonic-gate 	if (template.pValue == NULL) {
114726fad2aSDina K Nimeh 		return (CKR_HOST_MEMORY);
1157c478bd9Sstevel@tonic-gate 	}
1167c478bd9Sstevel@tonic-gate 	template.ulValueLen = sizeof (CK_ULONG);
1177c478bd9Sstevel@tonic-gate 	rv = get_ulong_attr_from_object(OBJ_PRI_DH_VAL_BITS(prikey),
1187c478bd9Sstevel@tonic-gate 	    &template);
1197c478bd9Sstevel@tonic-gate 	if (rv != CKR_OK) {
120726fad2aSDina K Nimeh 		free(template.pValue);
121726fad2aSDina K Nimeh 		return (rv);
1227c478bd9Sstevel@tonic-gate 	}
1237c478bd9Sstevel@tonic-gate 
1247c478bd9Sstevel@tonic-gate #ifdef	__sparcv9
1257c478bd9Sstevel@tonic-gate 	/* LINTED */
1267c478bd9Sstevel@tonic-gate 	value_bits = (uint32_t)(*((CK_ULONG *)(template.pValue)));
1277c478bd9Sstevel@tonic-gate #else	/* !__sparcv9 */
1287c478bd9Sstevel@tonic-gate 	value_bits = *((CK_ULONG *)(template.pValue));
1297c478bd9Sstevel@tonic-gate #endif	/* __sparcv9 */
1307c478bd9Sstevel@tonic-gate 
131726fad2aSDina K Nimeh 	free(template.pValue);
1327c478bd9Sstevel@tonic-gate 
133726fad2aSDina K Nimeh 	/*
134726fad2aSDina K Nimeh 	 * The input to the first phase shall be the Diffie-Hellman
135726fad2aSDina K Nimeh 	 * parameters, which include prime, base, and private-value length.
136726fad2aSDina K Nimeh 	 */
137726fad2aSDina K Nimeh 	rv = soft_get_public_value(pubkey, CKA_PRIME, prime, &prime_len);
138726fad2aSDina K Nimeh 	if (rv != CKR_OK) {
139726fad2aSDina K Nimeh 		return (rv);
1407c478bd9Sstevel@tonic-gate 	}
1417c478bd9Sstevel@tonic-gate 
142726fad2aSDina K Nimeh 	rv = soft_get_public_value(pubkey, CKA_BASE, base, &base_len);
143726fad2aSDina K Nimeh 	if (rv != CKR_OK) {
144726fad2aSDina K Nimeh 		goto ret;
1457c478bd9Sstevel@tonic-gate 	}
1467c478bd9Sstevel@tonic-gate 
147726fad2aSDina K Nimeh 	/* Inputs to DH key pair generation. */
148726fad2aSDina K Nimeh 	k.prime = prime;
149726fad2aSDina K Nimeh 	k.prime_bits = CRYPTO_BYTES2BITS(prime_len);
150726fad2aSDina K Nimeh 	k.base = base;
151726fad2aSDina K Nimeh 	k.base_bytes = base_len;
152726fad2aSDina K Nimeh 	k.value_bits = value_bits;
153726fad2aSDina K Nimeh 	k.rfunc = (IS_TOKEN_OBJECT(pubkey) || IS_TOKEN_OBJECT(prikey)) ?
154726fad2aSDina K Nimeh 	    pkcs11_get_random : pkcs11_get_urandom;
1557c478bd9Sstevel@tonic-gate 
156726fad2aSDina K Nimeh 	/* Outputs from DH key pair generation. */
157726fad2aSDina K Nimeh 	k.private_x = private_x;
158726fad2aSDina K Nimeh 	k.public_y = public_y;
159726fad2aSDina K Nimeh 
160726fad2aSDina K Nimeh 	/* If value_bits is 0, it will return as same size as prime */
161726fad2aSDina K Nimeh 	if ((rv = dh_genkey_pair(&k)) != CKR_OK) {
162726fad2aSDina K Nimeh 		goto ret;
1637c478bd9Sstevel@tonic-gate 	}
1647c478bd9Sstevel@tonic-gate 
1657c478bd9Sstevel@tonic-gate 	/*
1667c478bd9Sstevel@tonic-gate 	 * The integer public value y shall be converted to an octet
1677c478bd9Sstevel@tonic-gate 	 * string PV of length k, the public value.
1687c478bd9Sstevel@tonic-gate 	 */
169726fad2aSDina K Nimeh 	if ((rv = soft_genDHkey_set_attribute(pubkey, CKA_VALUE, public_y,
170*53a3dbbbSJason King 	    prime_len, B_TRUE)) != CKR_OK) {
171726fad2aSDina K Nimeh 		goto ret;
1727c478bd9Sstevel@tonic-gate 	}
1737c478bd9Sstevel@tonic-gate 
1747c478bd9Sstevel@tonic-gate 	/* Convert the big integer private value to an octet string. */
175726fad2aSDina K Nimeh 	if ((rv = soft_genDHkey_set_attribute(prikey, CKA_VALUE, private_x,
176726fad2aSDina K Nimeh 	    CRYPTO_BITS2BYTES(k.value_bits), B_FALSE)) != CKR_OK) {
177726fad2aSDina K Nimeh 		goto ret;
1787c478bd9Sstevel@tonic-gate 	}
1797c478bd9Sstevel@tonic-gate 
1807c478bd9Sstevel@tonic-gate 	/* Convert the big integer prime to an octet string. */
181726fad2aSDina K Nimeh 	if ((rv = soft_genDHkey_set_attribute(prikey, CKA_PRIME, prime,
182726fad2aSDina K Nimeh 	    CRYPTO_BITS2BYTES(k.prime_bits), B_FALSE)) != CKR_OK) {
183726fad2aSDina K Nimeh 		goto ret;
1847c478bd9Sstevel@tonic-gate 	}
1857c478bd9Sstevel@tonic-gate 
1867c478bd9Sstevel@tonic-gate 	/* Convert the big integer base to an octet string. */
187726fad2aSDina K Nimeh 	if ((rv = soft_genDHkey_set_attribute(prikey, CKA_BASE, base,
188726fad2aSDina K Nimeh 	    k.base_bytes, B_FALSE)) != CKR_OK) {
189726fad2aSDina K Nimeh 		goto ret;
1907c478bd9Sstevel@tonic-gate 	}
1917c478bd9Sstevel@tonic-gate 
192726fad2aSDina K Nimeh 	/* Update private-value length in bits; could have been 0 before */
193726fad2aSDina K Nimeh 	OBJ_PRI_DH_VAL_BITS(prikey) = k.value_bits;
1947c478bd9Sstevel@tonic-gate 
195726fad2aSDina K Nimeh ret:
1967c478bd9Sstevel@tonic-gate 	return (rv);
1977c478bd9Sstevel@tonic-gate }
1987c478bd9Sstevel@tonic-gate 
199726fad2aSDina K Nimeh /* ARGSUSED3 */
2007c478bd9Sstevel@tonic-gate CK_RV
soft_dh_key_derive(soft_object_t * basekey,soft_object_t * secretkey,void * publicvalue,size_t publicvaluelen)2017c478bd9Sstevel@tonic-gate soft_dh_key_derive(soft_object_t *basekey, soft_object_t *secretkey,
2027c478bd9Sstevel@tonic-gate     void *publicvalue, size_t publicvaluelen)
2037c478bd9Sstevel@tonic-gate {
204726fad2aSDina K Nimeh 	CK_RV		rv;
2057c478bd9Sstevel@tonic-gate 	uchar_t		privatevalue[MAX_KEY_ATTR_BUFLEN];
2067c478bd9Sstevel@tonic-gate 	uint32_t	privatevaluelen = sizeof (privatevalue);
2077c478bd9Sstevel@tonic-gate 	uchar_t		privateprime[MAX_KEY_ATTR_BUFLEN];
2087c478bd9Sstevel@tonic-gate 	uint32_t	privateprimelen = sizeof (privateprime);
209726fad2aSDina K Nimeh 	uchar_t		key[MAX_KEY_ATTR_BUFLEN];
2107c478bd9Sstevel@tonic-gate 	uint32_t	keylen;
211726fad2aSDina K Nimeh 	DHbytekey	k;
2127c478bd9Sstevel@tonic-gate 
213c64d15a5Smcpowers 	rv = soft_get_private_value(basekey, CKA_VALUE, privatevalue,
2147c478bd9Sstevel@tonic-gate 	    &privatevaluelen);
2157c478bd9Sstevel@tonic-gate 	if (rv != CKR_OK) {
2167c478bd9Sstevel@tonic-gate 		return (rv);
2177c478bd9Sstevel@tonic-gate 	}
2187c478bd9Sstevel@tonic-gate 
219c64d15a5Smcpowers 	rv = soft_get_private_value(basekey, CKA_PRIME, privateprime,
2207c478bd9Sstevel@tonic-gate 	    &privateprimelen);
2217c478bd9Sstevel@tonic-gate 	if (rv != CKR_OK) {
222726fad2aSDina K Nimeh 		goto ret;
2237c478bd9Sstevel@tonic-gate 	}
2247c478bd9Sstevel@tonic-gate 
225726fad2aSDina K Nimeh 	/* keylen may be 0 if CKA_VALUE_LEN did not specify */
226726fad2aSDina K Nimeh 	keylen = OBJ_SEC_VALUE_LEN(secretkey);
227726fad2aSDina K Nimeh 	if (keylen > sizeof (key)) {		/* check for overflow */
228726fad2aSDina K Nimeh 		rv = CKR_ATTRIBUTE_VALUE_INVALID;
229726fad2aSDina K Nimeh 		goto ret;
2307c478bd9Sstevel@tonic-gate 	}
2317c478bd9Sstevel@tonic-gate 
232726fad2aSDina K Nimeh 	k.prime = privateprime;
233726fad2aSDina K Nimeh 	k.prime_bits = CRYPTO_BYTES2BITS(privateprimelen);
234726fad2aSDina K Nimeh 	k.value_bits = CRYPTO_BYTES2BITS(privatevaluelen);
235726fad2aSDina K Nimeh 	k.private_x = privatevalue;
236726fad2aSDina K Nimeh 	k.public_y = publicvalue;
237726fad2aSDina K Nimeh 	k.rfunc = NULL;
2387c478bd9Sstevel@tonic-gate 
239726fad2aSDina K Nimeh 	/* keylen may be modified if it was 0 or conflicts with key type */
240*53a3dbbbSJason King 	rv = dh_key_derive(&k, secretkey->key_type, key, &keylen, 0);
2417c478bd9Sstevel@tonic-gate 
242726fad2aSDina K Nimeh 	if (rv != CKR_OK) {
243726fad2aSDina K Nimeh 		goto ret;
2447c478bd9Sstevel@tonic-gate 	}
2457c478bd9Sstevel@tonic-gate 
2467c478bd9Sstevel@tonic-gate 	if ((OBJ_SEC_VALUE(secretkey) = malloc(keylen)) == NULL) {
2477c478bd9Sstevel@tonic-gate 		rv = CKR_HOST_MEMORY;
248726fad2aSDina K Nimeh 		goto ret;
2497c478bd9Sstevel@tonic-gate 	}
250726fad2aSDina K Nimeh 
2517c478bd9Sstevel@tonic-gate 	OBJ_SEC_VALUE_LEN(secretkey) = keylen;
252726fad2aSDina K Nimeh 	(void) memcpy(OBJ_SEC_VALUE(secretkey), key, keylen);
2537c478bd9Sstevel@tonic-gate 
254726fad2aSDina K Nimeh ret:
2557c478bd9Sstevel@tonic-gate 	return (rv);
2567c478bd9Sstevel@tonic-gate }
257