mirror of
https://github.com/espressif/openthread.git
synced 2026-09-16 06:00:13 +00:00
[crypto] add ECDSA API (#8273)
- remove ecdsa tinycrypt implementation - add crypto API, move default implementation in crypto_platform.c - define crypto ecdsa structures and format
This commit is contained in:
@@ -55,25 +55,13 @@ extern "C" {
|
||||
*
|
||||
*/
|
||||
|
||||
#define OT_CRYPTO_SHA256_HASH_SIZE 32 ///< Length of SHA256 hash (in bytes).
|
||||
|
||||
/**
|
||||
* @struct otCryptoSha256Hash
|
||||
*
|
||||
* This structure represents a SHA-256 hash.
|
||||
*
|
||||
*/
|
||||
OT_TOOL_PACKED_BEGIN
|
||||
struct otCryptoSha256Hash
|
||||
{
|
||||
uint8_t m8[OT_CRYPTO_SHA256_HASH_SIZE]; ///< Hash bytes.
|
||||
} OT_TOOL_PACKED_END;
|
||||
|
||||
/**
|
||||
* This structure represents a SHA-256 hash.
|
||||
*
|
||||
*/
|
||||
typedef struct otCryptoSha256Hash otCryptoSha256Hash;
|
||||
typedef otPlatCryptoSha256Hash otCryptoSha256Hash;
|
||||
|
||||
/**
|
||||
* This function performs HMAC computation.
|
||||
|
||||
@@ -53,7 +53,7 @@ extern "C" {
|
||||
* @note This number versions both OpenThread platform and user APIs.
|
||||
*
|
||||
*/
|
||||
#define OPENTHREAD_API_VERSION (258)
|
||||
#define OPENTHREAD_API_VERSION (259)
|
||||
|
||||
/**
|
||||
* @addtogroup api-instance
|
||||
|
||||
@@ -130,6 +130,95 @@ typedef struct otCryptoContext
|
||||
uint16_t mContextSize; ///< The length of the context in bytes.
|
||||
} otCryptoContext;
|
||||
|
||||
/**
|
||||
* Length of SHA256 hash (in bytes).
|
||||
*
|
||||
*/
|
||||
#define OT_CRYPTO_SHA256_HASH_SIZE 32
|
||||
|
||||
/**
|
||||
* @struct otPlatCryptoSha256Hash
|
||||
*
|
||||
* This structure represents a SHA-256 hash.
|
||||
*
|
||||
*/
|
||||
OT_TOOL_PACKED_BEGIN
|
||||
struct otPlatCryptoSha256Hash
|
||||
{
|
||||
uint8_t m8[OT_CRYPTO_SHA256_HASH_SIZE]; ///< Hash bytes.
|
||||
} OT_TOOL_PACKED_END;
|
||||
|
||||
/**
|
||||
* This structure represents a SHA-256 hash.
|
||||
*
|
||||
*/
|
||||
typedef struct otPlatCryptoSha256Hash otPlatCryptoSha256Hash;
|
||||
|
||||
/**
|
||||
* Max buffer size (in bytes) for representing the EDCSA key-pair in DER format.
|
||||
*
|
||||
*/
|
||||
#define OT_CRYPTO_ECDSA_MAX_DER_SIZE 125
|
||||
|
||||
/**
|
||||
* @struct otPlatCryptoEcdsaKeyPair
|
||||
*
|
||||
* This structure represents an ECDSA key pair (public and private keys).
|
||||
*
|
||||
* The key pair is stored using Distinguished Encoding Rules (DER) format (per RFC 5915).
|
||||
*
|
||||
*/
|
||||
typedef struct otPlatCryptoEcdsaKeyPair
|
||||
{
|
||||
uint8_t mDerBytes[OT_CRYPTO_ECDSA_MAX_DER_SIZE];
|
||||
uint8_t mDerLength;
|
||||
} otPlatCryptoEcdsaKeyPair;
|
||||
|
||||
/**
|
||||
* Buffer size (in bytes) for representing the EDCSA public key.
|
||||
*
|
||||
*/
|
||||
#define OT_CRYPTO_ECDSA_PUBLIC_KEY_SIZE 64
|
||||
|
||||
/**
|
||||
* @struct otPlatCryptoEcdsaPublicKey
|
||||
*
|
||||
* This struct represents a ECDSA public key.
|
||||
*
|
||||
* The public key is stored as a byte sequence representation of an uncompressed curve point (RFC 6605 - sec 4).
|
||||
*
|
||||
*/
|
||||
OT_TOOL_PACKED_BEGIN
|
||||
struct otPlatCryptoEcdsaPublicKey
|
||||
{
|
||||
uint8_t m8[OT_CRYPTO_ECDSA_PUBLIC_KEY_SIZE];
|
||||
} OT_TOOL_PACKED_END;
|
||||
|
||||
typedef struct otPlatCryptoEcdsaPublicKey otPlatCryptoEcdsaPublicKey;
|
||||
|
||||
/**
|
||||
* Buffer size (in bytes) for representing the EDCSA signature.
|
||||
*
|
||||
*/
|
||||
#define OT_CRYPTO_ECDSA_SIGNATURE_SIZE 64
|
||||
|
||||
/**
|
||||
* @struct otPlatCryptoEcdsaSignature
|
||||
*
|
||||
* This struct represents an ECDSA signature.
|
||||
*
|
||||
* The signature is encoded as the concatenated binary representation of two MPIs `r` and `s` which are calculated
|
||||
* during signing (RFC 6605 - section 4).
|
||||
*
|
||||
*/
|
||||
OT_TOOL_PACKED_BEGIN
|
||||
struct otPlatCryptoEcdsaSignature
|
||||
{
|
||||
uint8_t m8[OT_CRYPTO_ECDSA_SIGNATURE_SIZE];
|
||||
} OT_TOOL_PACKED_END;
|
||||
|
||||
typedef struct otPlatCryptoEcdsaSignature otPlatCryptoEcdsaSignature;
|
||||
|
||||
/**
|
||||
* Initialize the Crypto module.
|
||||
*
|
||||
@@ -480,15 +569,81 @@ void otPlatCryptoRandomDeinit(void);
|
||||
/**
|
||||
* Fills a given buffer with cryptographically secure random bytes.
|
||||
*
|
||||
* @param[out] aBuffer A pointer to a buffer to fill with the random bytes.
|
||||
* @param[in] aSize Size of buffer (number of bytes to fill).
|
||||
* @param[out] aBuffer A pointer to a buffer to fill with the random bytes.
|
||||
* @param[in] aSize Size of buffer (number of bytes to fill).
|
||||
*
|
||||
* @retval OT_ERROR_NONE Successfully filled buffer with random values.
|
||||
* @retval OT_ERROR_FAILED Operation failed.
|
||||
* @retval OT_ERROR_NONE Successfully filled buffer with random values.
|
||||
* @retval OT_ERROR_FAILED Operation failed.
|
||||
*
|
||||
*/
|
||||
otError otPlatCryptoRandomGet(uint8_t *aBuffer, uint16_t aSize);
|
||||
|
||||
/**
|
||||
* Generate and populate the output buffer with a new ECDSA key-pair.
|
||||
*
|
||||
* @param[out] aKeyPair A pointer to an ECDSA key-pair structure to store the generated key-pair.
|
||||
*
|
||||
* @retval OT_ERROR_NONE A new key-pair was generated successfully.
|
||||
* @retval OT_ERROR_NO_BUFS Failed to allocate buffer for key generation.
|
||||
* @retval OT_ERROR_NOT_CAPABLE Feature not supported.
|
||||
* @retval OT_ERROR_FAILED Failed to generate key-pair.
|
||||
*
|
||||
*/
|
||||
otError otPlatCryptoEcdsaGenerateKey(otPlatCryptoEcdsaKeyPair *aKeyPair);
|
||||
|
||||
/**
|
||||
* Get the associated public key from the input context.
|
||||
*
|
||||
* @param[in] aKeyPair A pointer to an ECDSA key-pair structure where the key-pair is stored.
|
||||
* @param[out] aPublicKey A pointer to an ECDSA public key structure to store the public key.
|
||||
*
|
||||
* @retval OT_ERROR_NONE Public key was retrieved successfully, and @p aBuffer is updated.
|
||||
* @retval OT_ERROR_PARSE The key-pair DER format could not be parsed (invalid format).
|
||||
* @retval OT_ERROR_INVALID_ARGS The @p aContext is NULL.
|
||||
*
|
||||
*/
|
||||
otError otPlatCryptoEcdsaGetPublicKey(const otPlatCryptoEcdsaKeyPair *aKeyPair, otPlatCryptoEcdsaPublicKey *aPublicKey);
|
||||
|
||||
/**
|
||||
* Calculate the ECDSA signature for a hashed message using the private key from the input context.
|
||||
*
|
||||
* This method uses the deterministic digital signature generation procedure from RFC 6979.
|
||||
*
|
||||
* @param[in] aKeyPair A pointer to an ECDSA key-pair structure where the key-pair is stored.
|
||||
* @param[in] aHash A pointer to a SHA-256 hash structure where the hash value for signature calculation
|
||||
* is stored.
|
||||
* @param[out] aSignature A pointer to an ECDSA signature structure to output the calculated signature.
|
||||
*
|
||||
* @retval OT_ERROR_NONE The signature was calculated successfully, @p aSignature was updated.
|
||||
* @retval OT_ERROR_PARSE The key-pair DER format could not be parsed (invalid format).
|
||||
* @retval OT_ERROR_NO_BUFS Failed to allocate buffer for signature calculation.
|
||||
* @retval OT_ERROR_INVALID_ARGS The @p aContext is NULL.
|
||||
*
|
||||
*/
|
||||
otError otPlatCryptoEcdsaSign(const otPlatCryptoEcdsaKeyPair *aKeyPair,
|
||||
const otPlatCryptoSha256Hash * aHash,
|
||||
otPlatCryptoEcdsaSignature * aSignature);
|
||||
|
||||
/**
|
||||
* Use the key from the input context to verify the ECDSA signature of a hashed message.
|
||||
*
|
||||
* @param[in] aPublicKey A pointer to an ECDSA public key structure where the public key for signature
|
||||
* verification is stored.
|
||||
* @param[in] aHash A pointer to a SHA-256 hash structure where the hash value for signature verification
|
||||
* is stored.
|
||||
* @param[in] aSignature A pointer to an ECDSA signature structure where the signature value to be verified is
|
||||
* stored.
|
||||
*
|
||||
* @retval OT_ERROR_NONE The signature was verified successfully.
|
||||
* @retval OT_ERROR_SECURITY The signature is invalid.
|
||||
* @retval OT_ERROR_INVALID_ARGS The key or hash is invalid.
|
||||
* @retval OT_ERROR_NO_BUFS Failed to allocate buffer for signature verification.
|
||||
*
|
||||
*/
|
||||
otError otPlatCryptoEcdsaVerify(const otPlatCryptoEcdsaPublicKey *aPublicKey,
|
||||
const otPlatCryptoSha256Hash * aHash,
|
||||
const otPlatCryptoEcdsaSignature *aSignature);
|
||||
|
||||
/**
|
||||
* @}
|
||||
*
|
||||
|
||||
Reference in New Issue
Block a user