xref: /linux/crypto/ecdsa-x962.c (revision f088104d837a991c65e51fa30bb4196169b3244d)
1d6793ff9SLukas Wunner // SPDX-License-Identifier: GPL-2.0+
2d6793ff9SLukas Wunner /*
3d6793ff9SLukas Wunner  * ECDSA X9.62 signature encoding
4d6793ff9SLukas Wunner  *
5d6793ff9SLukas Wunner  * Copyright (c) 2021 IBM Corporation
6d6793ff9SLukas Wunner  * Copyright (c) 2024 Intel Corporation
7d6793ff9SLukas Wunner  */
8d6793ff9SLukas Wunner 
9d6793ff9SLukas Wunner #include <linux/asn1_decoder.h>
10d6793ff9SLukas Wunner #include <linux/err.h>
11d6793ff9SLukas Wunner #include <linux/module.h>
12d6793ff9SLukas Wunner #include <crypto/algapi.h>
13d6793ff9SLukas Wunner #include <crypto/sig.h>
14d6793ff9SLukas Wunner #include <crypto/internal/ecc.h>
15d6793ff9SLukas Wunner #include <crypto/internal/sig.h>
16d6793ff9SLukas Wunner 
17d6793ff9SLukas Wunner #include "ecdsasignature.asn1.h"
18d6793ff9SLukas Wunner 
19d6793ff9SLukas Wunner struct ecdsa_x962_ctx {
20d6793ff9SLukas Wunner 	struct crypto_sig *child;
21d6793ff9SLukas Wunner };
22d6793ff9SLukas Wunner 
23d6793ff9SLukas Wunner struct ecdsa_x962_signature_ctx {
24d6793ff9SLukas Wunner 	struct ecdsa_raw_sig sig;
25d6793ff9SLukas Wunner 	unsigned int ndigits;
26d6793ff9SLukas Wunner };
27d6793ff9SLukas Wunner 
28d6793ff9SLukas Wunner /* Get the r and s components of a signature from the X.509 certificate. */
ecdsa_get_signature_rs(u64 * dest,size_t hdrlen,unsigned char tag,const void * value,size_t vlen,unsigned int ndigits)29d6793ff9SLukas Wunner static int ecdsa_get_signature_rs(u64 *dest, size_t hdrlen, unsigned char tag,
30d6793ff9SLukas Wunner 				  const void *value, size_t vlen,
31d6793ff9SLukas Wunner 				  unsigned int ndigits)
32d6793ff9SLukas Wunner {
33d6793ff9SLukas Wunner 	size_t bufsize = ndigits * sizeof(u64);
34d6793ff9SLukas Wunner 	const char *d = value;
35d6793ff9SLukas Wunner 
36d6793ff9SLukas Wunner 	if (!value || !vlen || vlen > bufsize + 1)
37d6793ff9SLukas Wunner 		return -EINVAL;
38d6793ff9SLukas Wunner 
39d6793ff9SLukas Wunner 	/*
40d6793ff9SLukas Wunner 	 * vlen may be 1 byte larger than bufsize due to a leading zero byte
41d6793ff9SLukas Wunner 	 * (necessary if the most significant bit of the integer is set).
42d6793ff9SLukas Wunner 	 */
43d6793ff9SLukas Wunner 	if (vlen > bufsize) {
44d6793ff9SLukas Wunner 		/* skip over leading zeros that make 'value' a positive int */
45d6793ff9SLukas Wunner 		if (*d == 0) {
46d6793ff9SLukas Wunner 			vlen -= 1;
47d6793ff9SLukas Wunner 			d++;
48d6793ff9SLukas Wunner 		} else {
49d6793ff9SLukas Wunner 			return -EINVAL;
50d6793ff9SLukas Wunner 		}
51d6793ff9SLukas Wunner 	}
52d6793ff9SLukas Wunner 
53d6793ff9SLukas Wunner 	ecc_digits_from_bytes(d, vlen, dest, ndigits);
54d6793ff9SLukas Wunner 
55d6793ff9SLukas Wunner 	return 0;
56d6793ff9SLukas Wunner }
57d6793ff9SLukas Wunner 
ecdsa_get_signature_r(void * context,size_t hdrlen,unsigned char tag,const void * value,size_t vlen)58d6793ff9SLukas Wunner int ecdsa_get_signature_r(void *context, size_t hdrlen, unsigned char tag,
59d6793ff9SLukas Wunner 			  const void *value, size_t vlen)
60d6793ff9SLukas Wunner {
61d6793ff9SLukas Wunner 	struct ecdsa_x962_signature_ctx *sig_ctx = context;
62d6793ff9SLukas Wunner 
63d6793ff9SLukas Wunner 	return ecdsa_get_signature_rs(sig_ctx->sig.r, hdrlen, tag, value, vlen,
64d6793ff9SLukas Wunner 				      sig_ctx->ndigits);
65d6793ff9SLukas Wunner }
66d6793ff9SLukas Wunner 
ecdsa_get_signature_s(void * context,size_t hdrlen,unsigned char tag,const void * value,size_t vlen)67d6793ff9SLukas Wunner int ecdsa_get_signature_s(void *context, size_t hdrlen, unsigned char tag,
68d6793ff9SLukas Wunner 			  const void *value, size_t vlen)
69d6793ff9SLukas Wunner {
70d6793ff9SLukas Wunner 	struct ecdsa_x962_signature_ctx *sig_ctx = context;
71d6793ff9SLukas Wunner 
72d6793ff9SLukas Wunner 	return ecdsa_get_signature_rs(sig_ctx->sig.s, hdrlen, tag, value, vlen,
73d6793ff9SLukas Wunner 				      sig_ctx->ndigits);
74d6793ff9SLukas Wunner }
75d6793ff9SLukas Wunner 
ecdsa_x962_verify(struct crypto_sig * tfm,const void * src,unsigned int slen,const void * digest,unsigned int dlen)76d6793ff9SLukas Wunner static int ecdsa_x962_verify(struct crypto_sig *tfm,
77d6793ff9SLukas Wunner 			     const void *src, unsigned int slen,
78d6793ff9SLukas Wunner 			     const void *digest, unsigned int dlen)
79d6793ff9SLukas Wunner {
80d6793ff9SLukas Wunner 	struct ecdsa_x962_ctx *ctx = crypto_sig_ctx(tfm);
81d6793ff9SLukas Wunner 	struct ecdsa_x962_signature_ctx sig_ctx;
82d6793ff9SLukas Wunner 	int err;
83d6793ff9SLukas Wunner 
84b16510a5SLukas Wunner 	sig_ctx.ndigits = DIV_ROUND_UP_POW2(crypto_sig_keysize(ctx->child),
85*6b7f9397SLukas Wunner 					    sizeof(u64) * BITS_PER_BYTE);
86d6793ff9SLukas Wunner 
87d6793ff9SLukas Wunner 	err = asn1_ber_decoder(&ecdsasignature_decoder, &sig_ctx, src, slen);
88d6793ff9SLukas Wunner 	if (err < 0)
89d6793ff9SLukas Wunner 		return err;
90d6793ff9SLukas Wunner 
91d6793ff9SLukas Wunner 	return crypto_sig_verify(ctx->child, &sig_ctx.sig, sizeof(sig_ctx.sig),
92d6793ff9SLukas Wunner 				 digest, dlen);
93d6793ff9SLukas Wunner }
94d6793ff9SLukas Wunner 
ecdsa_x962_key_size(struct crypto_sig * tfm)95221f0041SLukas Wunner static unsigned int ecdsa_x962_key_size(struct crypto_sig *tfm)
96d6793ff9SLukas Wunner {
97d6793ff9SLukas Wunner 	struct ecdsa_x962_ctx *ctx = crypto_sig_ctx(tfm);
98d6793ff9SLukas Wunner 
99221f0041SLukas Wunner 	return crypto_sig_keysize(ctx->child);
100d6793ff9SLukas Wunner }
101d6793ff9SLukas Wunner 
ecdsa_x962_max_size(struct crypto_sig * tfm)102a2471684SLukas Wunner static unsigned int ecdsa_x962_max_size(struct crypto_sig *tfm)
103a2471684SLukas Wunner {
104a2471684SLukas Wunner 	struct ecdsa_x962_ctx *ctx = crypto_sig_ctx(tfm);
105a2471684SLukas Wunner 	struct sig_alg *alg = crypto_sig_alg(ctx->child);
106*6b7f9397SLukas Wunner 	int slen = DIV_ROUND_UP_POW2(crypto_sig_keysize(ctx->child),
107*6b7f9397SLukas Wunner 				     BITS_PER_BYTE);
108a2471684SLukas Wunner 
109a2471684SLukas Wunner 	/*
110a2471684SLukas Wunner 	 * Verify takes ECDSA-Sig-Value (described in RFC 5480) as input,
111a2471684SLukas Wunner 	 * which is actually 2 'key_size'-bit integers encoded in ASN.1.
112a2471684SLukas Wunner 	 * Account for the ASN.1 encoding overhead here.
113a2471684SLukas Wunner 	 *
114a2471684SLukas Wunner 	 * NIST P192/256/384 may prepend a '0' to a coordinate to indicate
115a2471684SLukas Wunner 	 * a positive integer. NIST P521 never needs it.
116a2471684SLukas Wunner 	 */
117a2471684SLukas Wunner 	if (strcmp(alg->base.cra_name, "ecdsa-nist-p521") != 0)
118a2471684SLukas Wunner 		slen += 1;
119a2471684SLukas Wunner 
120a2471684SLukas Wunner 	/* Length of encoding the x & y coordinates */
121a2471684SLukas Wunner 	slen = 2 * (slen + 2);
122a2471684SLukas Wunner 
123a2471684SLukas Wunner 	/*
124a2471684SLukas Wunner 	 * If coordinate encoding takes at least 128 bytes then an
125a2471684SLukas Wunner 	 * additional byte for length encoding is needed.
126a2471684SLukas Wunner 	 */
127a2471684SLukas Wunner 	return 1 + (slen >= 128) + 1 + slen;
128a2471684SLukas Wunner }
129a2471684SLukas Wunner 
ecdsa_x962_digest_size(struct crypto_sig * tfm)130a2471684SLukas Wunner static unsigned int ecdsa_x962_digest_size(struct crypto_sig *tfm)
131a2471684SLukas Wunner {
132a2471684SLukas Wunner 	struct ecdsa_x962_ctx *ctx = crypto_sig_ctx(tfm);
133a2471684SLukas Wunner 
134a2471684SLukas Wunner 	return crypto_sig_digestsize(ctx->child);
135a2471684SLukas Wunner }
136a2471684SLukas Wunner 
ecdsa_x962_set_pub_key(struct crypto_sig * tfm,const void * key,unsigned int keylen)137d6793ff9SLukas Wunner static int ecdsa_x962_set_pub_key(struct crypto_sig *tfm,
138d6793ff9SLukas Wunner 				  const void *key, unsigned int keylen)
139d6793ff9SLukas Wunner {
140d6793ff9SLukas Wunner 	struct ecdsa_x962_ctx *ctx = crypto_sig_ctx(tfm);
141d6793ff9SLukas Wunner 
142d6793ff9SLukas Wunner 	return crypto_sig_set_pubkey(ctx->child, key, keylen);
143d6793ff9SLukas Wunner }
144d6793ff9SLukas Wunner 
ecdsa_x962_init_tfm(struct crypto_sig * tfm)145d6793ff9SLukas Wunner static int ecdsa_x962_init_tfm(struct crypto_sig *tfm)
146d6793ff9SLukas Wunner {
147d6793ff9SLukas Wunner 	struct sig_instance *inst = sig_alg_instance(tfm);
148d6793ff9SLukas Wunner 	struct crypto_sig_spawn *spawn = sig_instance_ctx(inst);
149d6793ff9SLukas Wunner 	struct ecdsa_x962_ctx *ctx = crypto_sig_ctx(tfm);
150d6793ff9SLukas Wunner 	struct crypto_sig *child_tfm;
151d6793ff9SLukas Wunner 
152d6793ff9SLukas Wunner 	child_tfm = crypto_spawn_sig(spawn);
153d6793ff9SLukas Wunner 	if (IS_ERR(child_tfm))
154d6793ff9SLukas Wunner 		return PTR_ERR(child_tfm);
155d6793ff9SLukas Wunner 
156d6793ff9SLukas Wunner 	ctx->child = child_tfm;
157d6793ff9SLukas Wunner 
158d6793ff9SLukas Wunner 	return 0;
159d6793ff9SLukas Wunner }
160d6793ff9SLukas Wunner 
ecdsa_x962_exit_tfm(struct crypto_sig * tfm)161d6793ff9SLukas Wunner static void ecdsa_x962_exit_tfm(struct crypto_sig *tfm)
162d6793ff9SLukas Wunner {
163d6793ff9SLukas Wunner 	struct ecdsa_x962_ctx *ctx = crypto_sig_ctx(tfm);
164d6793ff9SLukas Wunner 
165d6793ff9SLukas Wunner 	crypto_free_sig(ctx->child);
166d6793ff9SLukas Wunner }
167d6793ff9SLukas Wunner 
ecdsa_x962_free(struct sig_instance * inst)168d6793ff9SLukas Wunner static void ecdsa_x962_free(struct sig_instance *inst)
169d6793ff9SLukas Wunner {
170d6793ff9SLukas Wunner 	struct crypto_sig_spawn *spawn = sig_instance_ctx(inst);
171d6793ff9SLukas Wunner 
172d6793ff9SLukas Wunner 	crypto_drop_sig(spawn);
173d6793ff9SLukas Wunner 	kfree(inst);
174d6793ff9SLukas Wunner }
175d6793ff9SLukas Wunner 
ecdsa_x962_create(struct crypto_template * tmpl,struct rtattr ** tb)176d6793ff9SLukas Wunner static int ecdsa_x962_create(struct crypto_template *tmpl, struct rtattr **tb)
177d6793ff9SLukas Wunner {
178d6793ff9SLukas Wunner 	struct crypto_sig_spawn *spawn;
179d6793ff9SLukas Wunner 	struct sig_instance *inst;
180d6793ff9SLukas Wunner 	struct sig_alg *ecdsa_alg;
181d6793ff9SLukas Wunner 	u32 mask;
182d6793ff9SLukas Wunner 	int err;
183d6793ff9SLukas Wunner 
184d6793ff9SLukas Wunner 	err = crypto_check_attr_type(tb, CRYPTO_ALG_TYPE_SIG, &mask);
185d6793ff9SLukas Wunner 	if (err)
186d6793ff9SLukas Wunner 		return err;
187d6793ff9SLukas Wunner 
188d6793ff9SLukas Wunner 	inst = kzalloc(sizeof(*inst) + sizeof(*spawn), GFP_KERNEL);
189d6793ff9SLukas Wunner 	if (!inst)
190d6793ff9SLukas Wunner 		return -ENOMEM;
191d6793ff9SLukas Wunner 
192d6793ff9SLukas Wunner 	spawn = sig_instance_ctx(inst);
193d6793ff9SLukas Wunner 
194d6793ff9SLukas Wunner 	err = crypto_grab_sig(spawn, sig_crypto_instance(inst),
195d6793ff9SLukas Wunner 			      crypto_attr_alg_name(tb[1]), 0, mask);
196d6793ff9SLukas Wunner 	if (err)
197d6793ff9SLukas Wunner 		goto err_free_inst;
198d6793ff9SLukas Wunner 
199d6793ff9SLukas Wunner 	ecdsa_alg = crypto_spawn_sig_alg(spawn);
200d6793ff9SLukas Wunner 
201d6793ff9SLukas Wunner 	err = -EINVAL;
202d6793ff9SLukas Wunner 	if (strncmp(ecdsa_alg->base.cra_name, "ecdsa", 5) != 0)
203d6793ff9SLukas Wunner 		goto err_free_inst;
204d6793ff9SLukas Wunner 
205d6793ff9SLukas Wunner 	err = crypto_inst_setname(sig_crypto_instance(inst), tmpl->name,
206d6793ff9SLukas Wunner 				  &ecdsa_alg->base);
207d6793ff9SLukas Wunner 	if (err)
208d6793ff9SLukas Wunner 		goto err_free_inst;
209d6793ff9SLukas Wunner 
210d6793ff9SLukas Wunner 	inst->alg.base.cra_priority = ecdsa_alg->base.cra_priority;
211d6793ff9SLukas Wunner 	inst->alg.base.cra_ctxsize = sizeof(struct ecdsa_x962_ctx);
212d6793ff9SLukas Wunner 
213d6793ff9SLukas Wunner 	inst->alg.init = ecdsa_x962_init_tfm;
214d6793ff9SLukas Wunner 	inst->alg.exit = ecdsa_x962_exit_tfm;
215d6793ff9SLukas Wunner 
216d6793ff9SLukas Wunner 	inst->alg.verify = ecdsa_x962_verify;
217221f0041SLukas Wunner 	inst->alg.key_size = ecdsa_x962_key_size;
218a2471684SLukas Wunner 	inst->alg.max_size = ecdsa_x962_max_size;
219a2471684SLukas Wunner 	inst->alg.digest_size = ecdsa_x962_digest_size;
220d6793ff9SLukas Wunner 	inst->alg.set_pub_key = ecdsa_x962_set_pub_key;
221d6793ff9SLukas Wunner 
222d6793ff9SLukas Wunner 	inst->free = ecdsa_x962_free;
223d6793ff9SLukas Wunner 
224d6793ff9SLukas Wunner 	err = sig_register_instance(tmpl, inst);
225d6793ff9SLukas Wunner 	if (err) {
226d6793ff9SLukas Wunner err_free_inst:
227d6793ff9SLukas Wunner 		ecdsa_x962_free(inst);
228d6793ff9SLukas Wunner 	}
229d6793ff9SLukas Wunner 	return err;
230d6793ff9SLukas Wunner }
231d6793ff9SLukas Wunner 
232d6793ff9SLukas Wunner struct crypto_template ecdsa_x962_tmpl = {
233d6793ff9SLukas Wunner 	.name = "x962",
234d6793ff9SLukas Wunner 	.create = ecdsa_x962_create,
235d6793ff9SLukas Wunner 	.module = THIS_MODULE,
236d6793ff9SLukas Wunner };
237d6793ff9SLukas Wunner 
238d6793ff9SLukas Wunner MODULE_ALIAS_CRYPTO("x962");
239