/src/open5gs/lib/crypt/ogs-sha2-hmac.c
Line | Count | Source |
1 | | /* |
2 | | * Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved. |
3 | | * |
4 | | * Licensed under the Apache License 2.0 (the "License"). You may not use |
5 | | * this file except in compliance with the License. You can obtain a copy |
6 | | * in the file LICENSE in the source distribution or at |
7 | | * https://www.openssl.org/source/license.html |
8 | | */ |
9 | | |
10 | | /* |
11 | | * Copyright (C) 2019-2020 by Sukchan Lee <acetcom@gmail.com> |
12 | | * |
13 | | * This file is part of Open5GS. |
14 | | * |
15 | | * Licensed under the Apache License, Version 2.0 (the "License"); |
16 | | * you may not use this file except in compliance with the License. |
17 | | * You may obtain a copy of the License at |
18 | | * |
19 | | * http://www.apache.org/licenses/LICENSE-2.0 |
20 | | * |
21 | | * Unless required by applicable law or agreed to in writing, software |
22 | | * distributed under the License is distributed on an "AS IS" BASIS, |
23 | | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
24 | | * See the License for the specific language governing permissions and |
25 | | * limitations under the License. |
26 | | */ |
27 | | |
28 | | /*- |
29 | | * HMAC-SHA-224/256/384/512 implementation |
30 | | * Last update: 06/15/2005 |
31 | | * Issue date: 06/15/2005 |
32 | | * |
33 | | * Copyright (C) 2005 Olivier Gay <olivier.gay@a3.epfl.ch> |
34 | | * All rights reserved. |
35 | | * |
36 | | * Redistribution and use in source and binary forms, with or without |
37 | | * modification, are permitted provided that the following conditions |
38 | | * are met: |
39 | | * 1. Redistributions of source code must retain the above copyright |
40 | | * notice, this list of conditions and the following disclaimer. |
41 | | * 2. Redistributions in binary form must reproduce the above copyright |
42 | | * notice, this list of conditions and the following disclaimer in the |
43 | | * documentation and/or other materials provided with the distribution. |
44 | | * 3. Neither the name of the project nor the names of its contributors |
45 | | * may be used to endorse or promote products derived from this software |
46 | | * without specific prior written permission. |
47 | | * |
48 | | * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND |
49 | | * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
50 | | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
51 | | * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE |
52 | | * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL |
53 | | * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS |
54 | | * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) |
55 | | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT |
56 | | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY |
57 | | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF |
58 | | * SUCH DAMAGE. |
59 | | */ |
60 | | |
61 | | #include "ogs-crypt.h" |
62 | | |
63 | | /* HMAC-SHA-224 functions */ |
64 | | |
65 | | void ogs_hmac_sha224_init(ogs_hmac_sha224_ctx *ctx, const uint8_t *key, |
66 | | uint32_t key_size) |
67 | 0 | { |
68 | 0 | uint32_t fill; |
69 | 0 | uint32_t num; |
70 | |
|
71 | 0 | uint8_t key_temp[OGS_SHA224_BLOCK_SIZE]; |
72 | 0 | int i; |
73 | |
|
74 | 0 | if (key_size > OGS_SHA224_BLOCK_SIZE) { |
75 | 0 | num = OGS_SHA224_DIGEST_SIZE; |
76 | 0 | ogs_sha224(key, key_size, key_temp); |
77 | 0 | } else { |
78 | 0 | if (key_size) |
79 | 0 | memcpy(key_temp, key, key_size); |
80 | 0 | num = key_size; |
81 | 0 | } |
82 | 0 | fill = OGS_SHA224_BLOCK_SIZE - num; |
83 | |
|
84 | 0 | memset(ctx->block_ipad + num, 0x36, fill); |
85 | 0 | memset(ctx->block_opad + num, 0x5c, fill); |
86 | |
|
87 | 0 | for (i = 0; i < num; i++) { |
88 | 0 | ctx->block_ipad[i] = key_temp[i] ^ 0x36; |
89 | 0 | ctx->block_opad[i] = key_temp[i] ^ 0x5c; |
90 | 0 | } |
91 | |
|
92 | 0 | ogs_sha224_init(&ctx->ctx_inside); |
93 | 0 | ogs_sha224_update(&ctx->ctx_inside, ctx->block_ipad, OGS_SHA224_BLOCK_SIZE); |
94 | |
|
95 | 0 | ogs_sha224_init(&ctx->ctx_outside); |
96 | 0 | ogs_sha224_update(&ctx->ctx_outside, ctx->block_opad, |
97 | 0 | OGS_SHA224_BLOCK_SIZE); |
98 | | |
99 | | /* for hmac_reinit */ |
100 | 0 | memcpy(&ctx->ctx_inside_reinit, &ctx->ctx_inside, |
101 | 0 | sizeof(ogs_sha224_ctx)); |
102 | 0 | memcpy(&ctx->ctx_outside_reinit, &ctx->ctx_outside, |
103 | 0 | sizeof(ogs_sha224_ctx)); |
104 | 0 | } |
105 | | |
106 | | void ogs_hmac_sha224_reinit(ogs_hmac_sha224_ctx *ctx) |
107 | 0 | { |
108 | 0 | memcpy(&ctx->ctx_inside, &ctx->ctx_inside_reinit, |
109 | 0 | sizeof(ogs_sha224_ctx)); |
110 | 0 | memcpy(&ctx->ctx_outside, &ctx->ctx_outside_reinit, |
111 | 0 | sizeof(ogs_sha224_ctx)); |
112 | 0 | } |
113 | | |
114 | | void ogs_hmac_sha224_update(ogs_hmac_sha224_ctx *ctx, const uint8_t *message, |
115 | | uint32_t message_len) |
116 | 0 | { |
117 | 0 | ogs_sha224_update(&ctx->ctx_inside, message, message_len); |
118 | 0 | } |
119 | | |
120 | | void ogs_hmac_sha224_final(ogs_hmac_sha224_ctx *ctx, uint8_t *mac, |
121 | | uint32_t mac_size) |
122 | 0 | { |
123 | 0 | uint8_t digest_inside[OGS_SHA224_DIGEST_SIZE]; |
124 | 0 | uint8_t mac_temp[OGS_SHA224_DIGEST_SIZE]; |
125 | |
|
126 | 0 | ogs_sha224_final(&ctx->ctx_inside, digest_inside); |
127 | 0 | ogs_sha224_update(&ctx->ctx_outside, digest_inside, OGS_SHA224_DIGEST_SIZE); |
128 | 0 | ogs_sha224_final(&ctx->ctx_outside, mac_temp); |
129 | 0 | ogs_assert(mac_size <= OGS_SHA224_DIGEST_SIZE); |
130 | 0 | if (mac_size) |
131 | 0 | memcpy(mac, mac_temp, mac_size); |
132 | 0 | } |
133 | | |
134 | | void ogs_hmac_sha224(const uint8_t *key, uint32_t key_size, |
135 | | const uint8_t *message, uint32_t message_len, |
136 | | uint8_t *mac, uint32_t mac_size) |
137 | 0 | { |
138 | 0 | ogs_hmac_sha224_ctx ctx; |
139 | |
|
140 | 0 | ogs_hmac_sha224_init(&ctx, key, key_size); |
141 | 0 | ogs_hmac_sha224_update(&ctx, message, message_len); |
142 | 0 | ogs_hmac_sha224_final(&ctx, mac, mac_size); |
143 | 0 | } |
144 | | |
145 | | /* HMAC-SHA-256 functions */ |
146 | | |
147 | | void ogs_hmac_sha256_init(ogs_hmac_sha256_ctx *ctx, const uint8_t *key, |
148 | | uint32_t key_size) |
149 | 0 | { |
150 | 0 | uint32_t fill; |
151 | 0 | uint32_t num; |
152 | |
|
153 | 0 | uint8_t key_temp[OGS_SHA256_BLOCK_SIZE]; |
154 | 0 | int i; |
155 | |
|
156 | 0 | if (key_size > OGS_SHA256_BLOCK_SIZE) { |
157 | 0 | num = OGS_SHA256_DIGEST_SIZE; |
158 | 0 | ogs_sha256(key, key_size, key_temp); |
159 | 0 | } else { |
160 | 0 | if (key_size) |
161 | 0 | memcpy(key_temp, key, key_size); |
162 | 0 | num = key_size; |
163 | 0 | } |
164 | 0 | fill = OGS_SHA256_BLOCK_SIZE - num; |
165 | |
|
166 | 0 | memset(ctx->block_ipad + num, 0x36, fill); |
167 | 0 | memset(ctx->block_opad + num, 0x5c, fill); |
168 | |
|
169 | 0 | for (i = 0; i < num; i++) { |
170 | 0 | ctx->block_ipad[i] = key_temp[i] ^ 0x36; |
171 | 0 | ctx->block_opad[i] = key_temp[i] ^ 0x5c; |
172 | 0 | } |
173 | |
|
174 | 0 | ogs_sha256_init(&ctx->ctx_inside); |
175 | 0 | ogs_sha256_update(&ctx->ctx_inside, ctx->block_ipad, OGS_SHA256_BLOCK_SIZE); |
176 | |
|
177 | 0 | ogs_sha256_init(&ctx->ctx_outside); |
178 | 0 | ogs_sha256_update(&ctx->ctx_outside, ctx->block_opad, |
179 | 0 | OGS_SHA256_BLOCK_SIZE); |
180 | | |
181 | | /* for hmac_reinit */ |
182 | 0 | memcpy(&ctx->ctx_inside_reinit, &ctx->ctx_inside, |
183 | 0 | sizeof(ogs_sha256_ctx)); |
184 | 0 | memcpy(&ctx->ctx_outside_reinit, &ctx->ctx_outside, |
185 | 0 | sizeof(ogs_sha256_ctx)); |
186 | 0 | } |
187 | | |
188 | | void ogs_hmac_sha256_reinit(ogs_hmac_sha256_ctx *ctx) |
189 | 0 | { |
190 | 0 | memcpy(&ctx->ctx_inside, &ctx->ctx_inside_reinit, |
191 | 0 | sizeof(ogs_sha256_ctx)); |
192 | 0 | memcpy(&ctx->ctx_outside, &ctx->ctx_outside_reinit, |
193 | 0 | sizeof(ogs_sha256_ctx)); |
194 | 0 | } |
195 | | |
196 | | void ogs_hmac_sha256_update(ogs_hmac_sha256_ctx *ctx, const uint8_t *message, |
197 | | uint32_t message_len) |
198 | 0 | { |
199 | 0 | ogs_sha256_update(&ctx->ctx_inside, message, message_len); |
200 | 0 | } |
201 | | |
202 | | void ogs_hmac_sha256_final(ogs_hmac_sha256_ctx *ctx, uint8_t *mac, |
203 | | uint32_t mac_size) |
204 | 0 | { |
205 | 0 | uint8_t digest_inside[OGS_SHA256_DIGEST_SIZE]; |
206 | 0 | uint8_t mac_temp[OGS_SHA256_DIGEST_SIZE]; |
207 | |
|
208 | 0 | ogs_sha256_final(&ctx->ctx_inside, digest_inside); |
209 | 0 | ogs_sha256_update(&ctx->ctx_outside, digest_inside, OGS_SHA256_DIGEST_SIZE); |
210 | 0 | ogs_sha256_final(&ctx->ctx_outside, mac_temp); |
211 | 0 | ogs_assert(mac_size <= OGS_SHA256_DIGEST_SIZE); |
212 | 0 | if (mac_size) |
213 | 0 | memcpy(mac, mac_temp, mac_size); |
214 | 0 | } |
215 | | |
216 | | void ogs_hmac_sha256(const uint8_t *key, uint32_t key_size, |
217 | | const uint8_t *message, uint32_t message_len, |
218 | | uint8_t *mac, uint32_t mac_size) |
219 | 0 | { |
220 | 0 | ogs_hmac_sha256_ctx ctx; |
221 | |
|
222 | 0 | ogs_hmac_sha256_init(&ctx, key, key_size); |
223 | 0 | ogs_hmac_sha256_update(&ctx, message, message_len); |
224 | 0 | ogs_hmac_sha256_final(&ctx, mac, mac_size); |
225 | 0 | } |
226 | | |
227 | | /* HMAC-SHA-384 functions */ |
228 | | |
229 | | void ogs_hmac_sha384_init(ogs_hmac_sha384_ctx *ctx, const uint8_t *key, |
230 | | uint32_t key_size) |
231 | 0 | { |
232 | 0 | uint32_t fill; |
233 | 0 | uint32_t num; |
234 | |
|
235 | 0 | uint8_t key_temp[OGS_SHA384_BLOCK_SIZE]; |
236 | 0 | int i; |
237 | |
|
238 | 0 | if (key_size > OGS_SHA384_BLOCK_SIZE) { |
239 | 0 | num = OGS_SHA384_DIGEST_SIZE; |
240 | 0 | ogs_sha384(key, key_size, key_temp); |
241 | 0 | } else { |
242 | 0 | if (key_size) |
243 | 0 | memcpy(key_temp, key, key_size); |
244 | 0 | num = key_size; |
245 | 0 | } |
246 | 0 | fill = OGS_SHA384_BLOCK_SIZE - num; |
247 | |
|
248 | 0 | memset(ctx->block_ipad + num, 0x36, fill); |
249 | 0 | memset(ctx->block_opad + num, 0x5c, fill); |
250 | |
|
251 | 0 | for (i = 0; i < num; i++) { |
252 | 0 | ctx->block_ipad[i] = key_temp[i] ^ 0x36; |
253 | 0 | ctx->block_opad[i] = key_temp[i] ^ 0x5c; |
254 | 0 | } |
255 | |
|
256 | 0 | ogs_sha384_init(&ctx->ctx_inside); |
257 | 0 | ogs_sha384_update(&ctx->ctx_inside, ctx->block_ipad, OGS_SHA384_BLOCK_SIZE); |
258 | |
|
259 | 0 | ogs_sha384_init(&ctx->ctx_outside); |
260 | 0 | ogs_sha384_update(&ctx->ctx_outside, ctx->block_opad, |
261 | 0 | OGS_SHA384_BLOCK_SIZE); |
262 | | |
263 | | /* for hmac_reinit */ |
264 | 0 | memcpy(&ctx->ctx_inside_reinit, &ctx->ctx_inside, |
265 | 0 | sizeof(ogs_sha384_ctx)); |
266 | 0 | memcpy(&ctx->ctx_outside_reinit, &ctx->ctx_outside, |
267 | 0 | sizeof(ogs_sha384_ctx)); |
268 | 0 | } |
269 | | |
270 | | void ogs_hmac_sha384_reinit(ogs_hmac_sha384_ctx *ctx) |
271 | 0 | { |
272 | 0 | memcpy(&ctx->ctx_inside, &ctx->ctx_inside_reinit, |
273 | 0 | sizeof(ogs_sha384_ctx)); |
274 | 0 | memcpy(&ctx->ctx_outside, &ctx->ctx_outside_reinit, |
275 | 0 | sizeof(ogs_sha384_ctx)); |
276 | 0 | } |
277 | | |
278 | | void ogs_hmac_sha384_update(ogs_hmac_sha384_ctx *ctx, const uint8_t *message, |
279 | | uint32_t message_len) |
280 | 0 | { |
281 | 0 | ogs_sha384_update(&ctx->ctx_inside, message, message_len); |
282 | 0 | } |
283 | | |
284 | | void ogs_hmac_sha384_final(ogs_hmac_sha384_ctx *ctx, uint8_t *mac, |
285 | | uint32_t mac_size) |
286 | 0 | { |
287 | 0 | uint8_t digest_inside[OGS_SHA384_DIGEST_SIZE]; |
288 | 0 | uint8_t mac_temp[OGS_SHA384_DIGEST_SIZE]; |
289 | |
|
290 | 0 | ogs_sha384_final(&ctx->ctx_inside, digest_inside); |
291 | 0 | ogs_sha384_update(&ctx->ctx_outside, digest_inside, OGS_SHA384_DIGEST_SIZE); |
292 | 0 | ogs_sha384_final(&ctx->ctx_outside, mac_temp); |
293 | 0 | ogs_assert(mac_size <= OGS_SHA384_DIGEST_SIZE); |
294 | 0 | if (mac_size) |
295 | 0 | memcpy(mac, mac_temp, mac_size); |
296 | 0 | } |
297 | | |
298 | | void ogs_hmac_sha384(const uint8_t *key, uint32_t key_size, |
299 | | const uint8_t *message, uint32_t message_len, |
300 | | uint8_t *mac, uint32_t mac_size) |
301 | 0 | { |
302 | 0 | ogs_hmac_sha384_ctx ctx; |
303 | |
|
304 | 0 | ogs_hmac_sha384_init(&ctx, key, key_size); |
305 | 0 | ogs_hmac_sha384_update(&ctx, message, message_len); |
306 | 0 | ogs_hmac_sha384_final(&ctx, mac, mac_size); |
307 | 0 | } |
308 | | |
309 | | /* HMAC-SHA-512 functions */ |
310 | | |
311 | | void ogs_hmac_sha512_init(ogs_hmac_sha512_ctx *ctx, const uint8_t *key, |
312 | | uint32_t key_size) |
313 | 0 | { |
314 | 0 | uint32_t fill; |
315 | 0 | uint32_t num; |
316 | |
|
317 | 0 | uint8_t key_temp[OGS_SHA512_BLOCK_SIZE]; |
318 | 0 | int i; |
319 | |
|
320 | 0 | if (key_size > OGS_SHA512_BLOCK_SIZE) { |
321 | 0 | num = OGS_SHA512_DIGEST_SIZE; |
322 | 0 | ogs_sha512(key, key_size, key_temp); |
323 | 0 | } else { |
324 | 0 | if (key_size) |
325 | 0 | memcpy(key_temp, key, key_size); |
326 | 0 | num = key_size; |
327 | 0 | } |
328 | 0 | fill = OGS_SHA512_BLOCK_SIZE - num; |
329 | |
|
330 | 0 | memset(ctx->block_ipad + num, 0x36, fill); |
331 | 0 | memset(ctx->block_opad + num, 0x5c, fill); |
332 | |
|
333 | 0 | for (i = 0; i < num; i++) { |
334 | 0 | ctx->block_ipad[i] = key_temp[i] ^ 0x36; |
335 | 0 | ctx->block_opad[i] = key_temp[i] ^ 0x5c; |
336 | 0 | } |
337 | |
|
338 | 0 | ogs_sha512_init(&ctx->ctx_inside); |
339 | 0 | ogs_sha512_update(&ctx->ctx_inside, ctx->block_ipad, OGS_SHA512_BLOCK_SIZE); |
340 | |
|
341 | 0 | ogs_sha512_init(&ctx->ctx_outside); |
342 | 0 | ogs_sha512_update(&ctx->ctx_outside, ctx->block_opad, |
343 | 0 | OGS_SHA512_BLOCK_SIZE); |
344 | | |
345 | | /* for hmac_reinit */ |
346 | 0 | memcpy(&ctx->ctx_inside_reinit, &ctx->ctx_inside, |
347 | 0 | sizeof(ogs_sha512_ctx)); |
348 | 0 | memcpy(&ctx->ctx_outside_reinit, &ctx->ctx_outside, |
349 | 0 | sizeof(ogs_sha512_ctx)); |
350 | 0 | } |
351 | | |
352 | | void ogs_hmac_sha512_reinit(ogs_hmac_sha512_ctx *ctx) |
353 | 0 | { |
354 | 0 | memcpy(&ctx->ctx_inside, &ctx->ctx_inside_reinit, |
355 | 0 | sizeof(ogs_sha512_ctx)); |
356 | 0 | memcpy(&ctx->ctx_outside, &ctx->ctx_outside_reinit, |
357 | 0 | sizeof(ogs_sha512_ctx)); |
358 | 0 | } |
359 | | |
360 | | void ogs_hmac_sha512_update(ogs_hmac_sha512_ctx *ctx, const uint8_t *message, |
361 | | uint32_t message_len) |
362 | 0 | { |
363 | 0 | ogs_sha512_update(&ctx->ctx_inside, message, message_len); |
364 | 0 | } |
365 | | |
366 | | void ogs_hmac_sha512_final(ogs_hmac_sha512_ctx *ctx, uint8_t *mac, |
367 | | uint32_t mac_size) |
368 | 0 | { |
369 | 0 | uint8_t digest_inside[OGS_SHA512_DIGEST_SIZE]; |
370 | 0 | uint8_t mac_temp[OGS_SHA512_DIGEST_SIZE]; |
371 | |
|
372 | 0 | ogs_sha512_final(&ctx->ctx_inside, digest_inside); |
373 | 0 | ogs_sha512_update(&ctx->ctx_outside, digest_inside, OGS_SHA512_DIGEST_SIZE); |
374 | 0 | ogs_sha512_final(&ctx->ctx_outside, mac_temp); |
375 | 0 | ogs_assert(mac_size <= OGS_SHA512_DIGEST_SIZE); |
376 | 0 | if (mac_size) |
377 | 0 | memcpy(mac, mac_temp, mac_size); |
378 | 0 | } |
379 | | |
380 | | void ogs_hmac_sha512(const uint8_t *key, uint32_t key_size, |
381 | | const uint8_t *message, uint32_t message_len, |
382 | | uint8_t *mac, uint32_t mac_size) |
383 | 0 | { |
384 | 0 | ogs_hmac_sha512_ctx ctx; |
385 | |
|
386 | 0 | ogs_hmac_sha512_init(&ctx, key, key_size); |
387 | 0 | ogs_hmac_sha512_update(&ctx, message, message_len); |
388 | 0 | ogs_hmac_sha512_final(&ctx, mac, mac_size); |
389 | 0 | } |