Coverage Report

Created: 2026-09-28 06:22

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/open5gs/lib/crypt/ogs-sha2-hmac.c
Line
Count
Source
1
/*
2
 * Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.
3
 *
4
 * Licensed under the Apache License 2.0 (the "License").  You may not use
5
 * this file except in compliance with the License.  You can obtain a copy
6
 * in the file LICENSE in the source distribution or at
7
 * https://www.openssl.org/source/license.html
8
 */
9
10
/*
11
 * Copyright (C) 2019-2020 by Sukchan Lee <acetcom@gmail.com>
12
 *
13
 * This file is part of Open5GS.
14
 *
15
 * Licensed under the Apache License, Version 2.0 (the "License");
16
 * you may not use this file except in compliance with the License.
17
 * You may obtain a copy of the License at
18
 *
19
 *   http://www.apache.org/licenses/LICENSE-2.0
20
 *
21
 * Unless required by applicable law or agreed to in writing, software
22
 * distributed under the License is distributed on an "AS IS" BASIS,
23
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
24
 * See the License for the specific language governing permissions and
25
 * limitations under the License.
26
 */
27
28
/*-
29
 * HMAC-SHA-224/256/384/512 implementation
30
 * Last update: 06/15/2005
31
 * Issue date:  06/15/2005
32
 *
33
 * Copyright (C) 2005 Olivier Gay <olivier.gay@a3.epfl.ch>
34
 * All rights reserved.
35
 *
36
 * Redistribution and use in source and binary forms, with or without
37
 * modification, are permitted provided that the following conditions
38
 * are met:
39
 * 1. Redistributions of source code must retain the above copyright
40
 *    notice, this list of conditions and the following disclaimer.
41
 * 2. Redistributions in binary form must reproduce the above copyright
42
 *    notice, this list of conditions and the following disclaimer in the
43
 *    documentation and/or other materials provided with the distribution.
44
 * 3. Neither the name of the project nor the names of its contributors
45
 *    may be used to endorse or promote products derived from this software
46
 *    without specific prior written permission.
47
 *
48
 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
49
 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
50
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
51
 * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
52
 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
53
 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
54
 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
55
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
56
 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
57
 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
58
 * SUCH DAMAGE.
59
 */
60
61
#include "ogs-crypt.h"
62
63
/* HMAC-SHA-224 functions */
64
65
void ogs_hmac_sha224_init(ogs_hmac_sha224_ctx *ctx, const uint8_t *key,
66
                      uint32_t key_size)
67
0
{
68
0
    uint32_t fill;
69
0
    uint32_t num;
70
71
0
    uint8_t key_temp[OGS_SHA224_BLOCK_SIZE];
72
0
    int i;
73
74
0
    if (key_size > OGS_SHA224_BLOCK_SIZE) {
75
0
        num = OGS_SHA224_DIGEST_SIZE;
76
0
        ogs_sha224(key, key_size, key_temp);
77
0
    } else {
78
0
        if (key_size)
79
0
            memcpy(key_temp, key, key_size);
80
0
        num = key_size;
81
0
    }
82
0
    fill = OGS_SHA224_BLOCK_SIZE - num;
83
84
0
    memset(ctx->block_ipad + num, 0x36, fill);
85
0
    memset(ctx->block_opad + num, 0x5c, fill);
86
87
0
    for (i = 0; i < num; i++) {
88
0
        ctx->block_ipad[i] = key_temp[i] ^ 0x36;
89
0
        ctx->block_opad[i] = key_temp[i] ^ 0x5c;
90
0
    }
91
92
0
    ogs_sha224_init(&ctx->ctx_inside);
93
0
    ogs_sha224_update(&ctx->ctx_inside, ctx->block_ipad, OGS_SHA224_BLOCK_SIZE);
94
95
0
    ogs_sha224_init(&ctx->ctx_outside);
96
0
    ogs_sha224_update(&ctx->ctx_outside, ctx->block_opad,
97
0
                  OGS_SHA224_BLOCK_SIZE);
98
99
    /* for hmac_reinit */
100
0
    memcpy(&ctx->ctx_inside_reinit, &ctx->ctx_inside,
101
0
           sizeof(ogs_sha224_ctx));
102
0
    memcpy(&ctx->ctx_outside_reinit, &ctx->ctx_outside,
103
0
           sizeof(ogs_sha224_ctx));
104
0
}
105
106
void ogs_hmac_sha224_reinit(ogs_hmac_sha224_ctx *ctx)
107
0
{
108
0
    memcpy(&ctx->ctx_inside, &ctx->ctx_inside_reinit,
109
0
           sizeof(ogs_sha224_ctx));
110
0
    memcpy(&ctx->ctx_outside, &ctx->ctx_outside_reinit,
111
0
           sizeof(ogs_sha224_ctx));
112
0
}
113
114
void ogs_hmac_sha224_update(ogs_hmac_sha224_ctx *ctx, const uint8_t *message,
115
                        uint32_t message_len)
116
0
{
117
0
    ogs_sha224_update(&ctx->ctx_inside, message, message_len);
118
0
}
119
120
void ogs_hmac_sha224_final(ogs_hmac_sha224_ctx *ctx, uint8_t *mac,
121
                       uint32_t mac_size)
122
0
{
123
0
    uint8_t digest_inside[OGS_SHA224_DIGEST_SIZE];
124
0
    uint8_t mac_temp[OGS_SHA224_DIGEST_SIZE];
125
126
0
    ogs_sha224_final(&ctx->ctx_inside, digest_inside);
127
0
    ogs_sha224_update(&ctx->ctx_outside, digest_inside, OGS_SHA224_DIGEST_SIZE);
128
0
    ogs_sha224_final(&ctx->ctx_outside, mac_temp);
129
0
    ogs_assert(mac_size <= OGS_SHA224_DIGEST_SIZE);
130
0
    if (mac_size)
131
0
        memcpy(mac, mac_temp, mac_size);
132
0
}
133
134
void ogs_hmac_sha224(const uint8_t *key, uint32_t key_size,
135
          const uint8_t *message, uint32_t message_len,
136
          uint8_t *mac, uint32_t mac_size)
137
0
{
138
0
    ogs_hmac_sha224_ctx ctx;
139
140
0
    ogs_hmac_sha224_init(&ctx, key, key_size);
141
0
    ogs_hmac_sha224_update(&ctx, message, message_len);
142
0
    ogs_hmac_sha224_final(&ctx, mac, mac_size);
143
0
}
144
145
/* HMAC-SHA-256 functions */
146
147
void ogs_hmac_sha256_init(ogs_hmac_sha256_ctx *ctx, const uint8_t *key,
148
                      uint32_t key_size)
149
0
{
150
0
    uint32_t fill;
151
0
    uint32_t num;
152
153
0
    uint8_t key_temp[OGS_SHA256_BLOCK_SIZE];
154
0
    int i;
155
156
0
    if (key_size > OGS_SHA256_BLOCK_SIZE) {
157
0
        num = OGS_SHA256_DIGEST_SIZE;
158
0
        ogs_sha256(key, key_size, key_temp);
159
0
    } else {
160
0
        if (key_size)
161
0
            memcpy(key_temp, key, key_size);
162
0
        num = key_size;
163
0
    }
164
0
    fill = OGS_SHA256_BLOCK_SIZE - num;
165
166
0
    memset(ctx->block_ipad + num, 0x36, fill);
167
0
    memset(ctx->block_opad + num, 0x5c, fill);
168
169
0
    for (i = 0; i < num; i++) {
170
0
        ctx->block_ipad[i] = key_temp[i] ^ 0x36;
171
0
        ctx->block_opad[i] = key_temp[i] ^ 0x5c;
172
0
    }
173
174
0
    ogs_sha256_init(&ctx->ctx_inside);
175
0
    ogs_sha256_update(&ctx->ctx_inside, ctx->block_ipad, OGS_SHA256_BLOCK_SIZE);
176
177
0
    ogs_sha256_init(&ctx->ctx_outside);
178
0
    ogs_sha256_update(&ctx->ctx_outside, ctx->block_opad,
179
0
                  OGS_SHA256_BLOCK_SIZE);
180
181
    /* for hmac_reinit */
182
0
    memcpy(&ctx->ctx_inside_reinit, &ctx->ctx_inside,
183
0
           sizeof(ogs_sha256_ctx));
184
0
    memcpy(&ctx->ctx_outside_reinit, &ctx->ctx_outside,
185
0
           sizeof(ogs_sha256_ctx));
186
0
}
187
188
void ogs_hmac_sha256_reinit(ogs_hmac_sha256_ctx *ctx)
189
0
{
190
0
    memcpy(&ctx->ctx_inside, &ctx->ctx_inside_reinit,
191
0
           sizeof(ogs_sha256_ctx));
192
0
    memcpy(&ctx->ctx_outside, &ctx->ctx_outside_reinit,
193
0
           sizeof(ogs_sha256_ctx));
194
0
}
195
196
void ogs_hmac_sha256_update(ogs_hmac_sha256_ctx *ctx, const uint8_t *message,
197
                        uint32_t message_len)
198
0
{
199
0
    ogs_sha256_update(&ctx->ctx_inside, message, message_len);
200
0
}
201
202
void ogs_hmac_sha256_final(ogs_hmac_sha256_ctx *ctx, uint8_t *mac,
203
                       uint32_t mac_size)
204
0
{
205
0
    uint8_t digest_inside[OGS_SHA256_DIGEST_SIZE];
206
0
    uint8_t mac_temp[OGS_SHA256_DIGEST_SIZE];
207
208
0
    ogs_sha256_final(&ctx->ctx_inside, digest_inside);
209
0
    ogs_sha256_update(&ctx->ctx_outside, digest_inside, OGS_SHA256_DIGEST_SIZE);
210
0
    ogs_sha256_final(&ctx->ctx_outside, mac_temp);
211
0
    ogs_assert(mac_size <= OGS_SHA256_DIGEST_SIZE);
212
0
    if (mac_size)
213
0
        memcpy(mac, mac_temp, mac_size);
214
0
}
215
216
void ogs_hmac_sha256(const uint8_t *key, uint32_t key_size,
217
          const uint8_t *message, uint32_t message_len,
218
          uint8_t *mac, uint32_t mac_size)
219
0
{
220
0
    ogs_hmac_sha256_ctx ctx;
221
222
0
    ogs_hmac_sha256_init(&ctx, key, key_size);
223
0
    ogs_hmac_sha256_update(&ctx, message, message_len);
224
0
    ogs_hmac_sha256_final(&ctx, mac, mac_size);
225
0
}
226
227
/* HMAC-SHA-384 functions */
228
229
void ogs_hmac_sha384_init(ogs_hmac_sha384_ctx *ctx, const uint8_t *key,
230
                      uint32_t key_size)
231
0
{
232
0
    uint32_t fill;
233
0
    uint32_t num;
234
235
0
    uint8_t key_temp[OGS_SHA384_BLOCK_SIZE];
236
0
    int i;
237
238
0
    if (key_size > OGS_SHA384_BLOCK_SIZE) {
239
0
        num = OGS_SHA384_DIGEST_SIZE;
240
0
        ogs_sha384(key, key_size, key_temp);
241
0
    } else {
242
0
        if (key_size)
243
0
            memcpy(key_temp, key, key_size);
244
0
        num = key_size;
245
0
    }
246
0
    fill = OGS_SHA384_BLOCK_SIZE - num;
247
248
0
    memset(ctx->block_ipad + num, 0x36, fill);
249
0
    memset(ctx->block_opad + num, 0x5c, fill);
250
251
0
    for (i = 0; i < num; i++) {
252
0
        ctx->block_ipad[i] = key_temp[i] ^ 0x36;
253
0
        ctx->block_opad[i] = key_temp[i] ^ 0x5c;
254
0
    }
255
256
0
    ogs_sha384_init(&ctx->ctx_inside);
257
0
    ogs_sha384_update(&ctx->ctx_inside, ctx->block_ipad, OGS_SHA384_BLOCK_SIZE);
258
259
0
    ogs_sha384_init(&ctx->ctx_outside);
260
0
    ogs_sha384_update(&ctx->ctx_outside, ctx->block_opad,
261
0
                  OGS_SHA384_BLOCK_SIZE);
262
263
    /* for hmac_reinit */
264
0
    memcpy(&ctx->ctx_inside_reinit, &ctx->ctx_inside,
265
0
           sizeof(ogs_sha384_ctx));
266
0
    memcpy(&ctx->ctx_outside_reinit, &ctx->ctx_outside,
267
0
           sizeof(ogs_sha384_ctx));
268
0
}
269
270
void ogs_hmac_sha384_reinit(ogs_hmac_sha384_ctx *ctx)
271
0
{
272
0
    memcpy(&ctx->ctx_inside, &ctx->ctx_inside_reinit,
273
0
           sizeof(ogs_sha384_ctx));
274
0
    memcpy(&ctx->ctx_outside, &ctx->ctx_outside_reinit,
275
0
           sizeof(ogs_sha384_ctx));
276
0
}
277
278
void ogs_hmac_sha384_update(ogs_hmac_sha384_ctx *ctx, const uint8_t *message,
279
                        uint32_t message_len)
280
0
{
281
0
    ogs_sha384_update(&ctx->ctx_inside, message, message_len);
282
0
}
283
284
void ogs_hmac_sha384_final(ogs_hmac_sha384_ctx *ctx, uint8_t *mac,
285
                       uint32_t mac_size)
286
0
{
287
0
    uint8_t digest_inside[OGS_SHA384_DIGEST_SIZE];
288
0
    uint8_t mac_temp[OGS_SHA384_DIGEST_SIZE];
289
290
0
    ogs_sha384_final(&ctx->ctx_inside, digest_inside);
291
0
    ogs_sha384_update(&ctx->ctx_outside, digest_inside, OGS_SHA384_DIGEST_SIZE);
292
0
    ogs_sha384_final(&ctx->ctx_outside, mac_temp);
293
0
    ogs_assert(mac_size <= OGS_SHA384_DIGEST_SIZE);
294
0
    if (mac_size)
295
0
        memcpy(mac, mac_temp, mac_size);
296
0
}
297
298
void ogs_hmac_sha384(const uint8_t *key, uint32_t key_size,
299
          const uint8_t *message, uint32_t message_len,
300
          uint8_t *mac, uint32_t mac_size)
301
0
{
302
0
    ogs_hmac_sha384_ctx ctx;
303
304
0
    ogs_hmac_sha384_init(&ctx, key, key_size);
305
0
    ogs_hmac_sha384_update(&ctx, message, message_len);
306
0
    ogs_hmac_sha384_final(&ctx, mac, mac_size);
307
0
}
308
309
/* HMAC-SHA-512 functions */
310
311
void ogs_hmac_sha512_init(ogs_hmac_sha512_ctx *ctx, const uint8_t *key,
312
                      uint32_t key_size)
313
0
{
314
0
    uint32_t fill;
315
0
    uint32_t num;
316
317
0
    uint8_t key_temp[OGS_SHA512_BLOCK_SIZE];
318
0
    int i;
319
320
0
    if (key_size > OGS_SHA512_BLOCK_SIZE) {
321
0
        num = OGS_SHA512_DIGEST_SIZE;
322
0
        ogs_sha512(key, key_size, key_temp);
323
0
    } else {
324
0
        if (key_size)
325
0
            memcpy(key_temp, key, key_size);
326
0
        num = key_size;
327
0
    }
328
0
    fill = OGS_SHA512_BLOCK_SIZE - num;
329
330
0
    memset(ctx->block_ipad + num, 0x36, fill);
331
0
    memset(ctx->block_opad + num, 0x5c, fill);
332
333
0
    for (i = 0; i < num; i++) {
334
0
        ctx->block_ipad[i] = key_temp[i] ^ 0x36;
335
0
        ctx->block_opad[i] = key_temp[i] ^ 0x5c;
336
0
    }
337
338
0
    ogs_sha512_init(&ctx->ctx_inside);
339
0
    ogs_sha512_update(&ctx->ctx_inside, ctx->block_ipad, OGS_SHA512_BLOCK_SIZE);
340
341
0
    ogs_sha512_init(&ctx->ctx_outside);
342
0
    ogs_sha512_update(&ctx->ctx_outside, ctx->block_opad,
343
0
                  OGS_SHA512_BLOCK_SIZE);
344
345
    /* for hmac_reinit */
346
0
    memcpy(&ctx->ctx_inside_reinit, &ctx->ctx_inside,
347
0
           sizeof(ogs_sha512_ctx));
348
0
    memcpy(&ctx->ctx_outside_reinit, &ctx->ctx_outside,
349
0
           sizeof(ogs_sha512_ctx));
350
0
}
351
352
void ogs_hmac_sha512_reinit(ogs_hmac_sha512_ctx *ctx)
353
0
{
354
0
    memcpy(&ctx->ctx_inside, &ctx->ctx_inside_reinit,
355
0
           sizeof(ogs_sha512_ctx));
356
0
    memcpy(&ctx->ctx_outside, &ctx->ctx_outside_reinit,
357
0
           sizeof(ogs_sha512_ctx));
358
0
}
359
360
void ogs_hmac_sha512_update(ogs_hmac_sha512_ctx *ctx, const uint8_t *message,
361
                        uint32_t message_len)
362
0
{
363
0
    ogs_sha512_update(&ctx->ctx_inside, message, message_len);
364
0
}
365
366
void ogs_hmac_sha512_final(ogs_hmac_sha512_ctx *ctx, uint8_t *mac,
367
                       uint32_t mac_size)
368
0
{
369
0
    uint8_t digest_inside[OGS_SHA512_DIGEST_SIZE];
370
0
    uint8_t mac_temp[OGS_SHA512_DIGEST_SIZE];
371
372
0
    ogs_sha512_final(&ctx->ctx_inside, digest_inside);
373
0
    ogs_sha512_update(&ctx->ctx_outside, digest_inside, OGS_SHA512_DIGEST_SIZE);
374
0
    ogs_sha512_final(&ctx->ctx_outside, mac_temp);
375
0
    ogs_assert(mac_size <= OGS_SHA512_DIGEST_SIZE);
376
0
    if (mac_size)
377
0
        memcpy(mac, mac_temp, mac_size);
378
0
}
379
380
void ogs_hmac_sha512(const uint8_t *key, uint32_t key_size,
381
          const uint8_t *message, uint32_t message_len,
382
          uint8_t *mac, uint32_t mac_size)
383
0
{
384
0
    ogs_hmac_sha512_ctx ctx;
385
386
0
    ogs_hmac_sha512_init(&ctx, key, key_size);
387
0
    ogs_hmac_sha512_update(&ctx, message, message_len);
388
0
    ogs_hmac_sha512_final(&ctx, mac, mac_size);
389
0
}