Update Files
This commit is contained in:
39
Kinc/Sources/kinc/libs/core/cose/CMakeLists.txt
Normal file
39
Kinc/Sources/kinc/libs/core/cose/CMakeLists.txt
Normal file
@ -0,0 +1,39 @@
|
||||
#
|
||||
# libwebsockets - small server side websockets and web server implementation
|
||||
#
|
||||
# Copyright (C) 2010 - 2020 Andy Green <andy@warmcat.com>
|
||||
#
|
||||
# Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
# of this software and associated documentation files (the "Software"), to
|
||||
# deal in the Software without restriction, including without limitation the
|
||||
# rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
|
||||
# sell copies of the Software, and to permit persons to whom the Software is
|
||||
# furnished to do so, subject to the following conditions:
|
||||
#
|
||||
# The above copyright notice and this permission notice shall be included in
|
||||
# all copies or substantial portions of the Software.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
||||
# FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
|
||||
# IN THE SOFTWARE.
|
||||
#
|
||||
|
||||
if (LWS_WITH_COSE)
|
||||
list(APPEND SOURCES
|
||||
cose/cose_key.c
|
||||
cose/cose_validate.c
|
||||
cose/cose_validate_alg.c
|
||||
cose/cose_sign.c
|
||||
cose/cose_sign_alg.c
|
||||
)
|
||||
endif()
|
||||
|
||||
#
|
||||
# Keep explicit parent scope exports at end
|
||||
#
|
||||
|
||||
exports_to_parent_scope()
|
1188
Kinc/Sources/kinc/libs/core/cose/cose_key.c
Normal file
1188
Kinc/Sources/kinc/libs/core/cose/cose_key.c
Normal file
File diff suppressed because it is too large
Load Diff
543
Kinc/Sources/kinc/libs/core/cose/cose_sign.c
Normal file
543
Kinc/Sources/kinc/libs/core/cose/cose_sign.c
Normal file
@ -0,0 +1,543 @@
|
||||
/*
|
||||
* libwebsockets - small server side websockets and web server implementation
|
||||
*
|
||||
* Copyright (C) 2010 - 2021 Andy Green <andy@warmcat.com>
|
||||
*
|
||||
* Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
* of this software and associated documentation files (the "Software"), to
|
||||
* deal in the Software without restriction, including without limitation the
|
||||
* rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
|
||||
* sell copies of the Software, and to permit persons to whom the Software is
|
||||
* furnished to do so, subject to the following conditions:
|
||||
*
|
||||
* The above copyright notice and this permission notice shall be included in
|
||||
* all copies or substantial portions of the Software.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
||||
* FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
|
||||
* IN THE SOFTWARE.
|
||||
*/
|
||||
|
||||
#include "private-lib-core.h"
|
||||
#include "private-lib-cose.h"
|
||||
|
||||
struct lws_cose_sign_context *
|
||||
lws_cose_sign_create(const lws_cose_sign_create_info_t *info)
|
||||
{
|
||||
struct lws_cose_sign_context *csc;
|
||||
|
||||
/* you have to have prepared a cbor output context for us to use */
|
||||
assert(info->lec);
|
||||
/* you have to provide at least one key in a cose_keyset */
|
||||
assert(info->keyset);
|
||||
/* you have to provide an lws_context (for crypto random) */
|
||||
assert(info->cx);
|
||||
|
||||
if (info->sigtype == SIGTYPE_MAC) {
|
||||
lwsl_err("%s: only mac0 supported for signing\n", __func__);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
csc = lws_zalloc(sizeof(*csc), __func__);
|
||||
if (!csc)
|
||||
return NULL;
|
||||
|
||||
csc->info = *info;
|
||||
|
||||
return csc;
|
||||
}
|
||||
|
||||
int
|
||||
lws_cose_sign_add(struct lws_cose_sign_context *csc, cose_param_t alg,
|
||||
const lws_cose_key_t *ck)
|
||||
{
|
||||
lws_cose_sig_alg_t *si = lws_cose_sign_alg_create(csc->info.cx, ck, alg,
|
||||
LWSCOSE_WKKO_SIGN);
|
||||
|
||||
if (!si)
|
||||
return 1;
|
||||
|
||||
lws_dll2_add_tail(&si->list, &csc->algs);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
static signed char cose_tags[] = {
|
||||
0,
|
||||
LWSCOAP_CONTENTFORMAT_COSE_SIGN,
|
||||
LWSCOAP_CONTENTFORMAT_COSE_SIGN1,
|
||||
LWSCOAP_CONTENTFORMAT_COSE_SIGN,
|
||||
LWSCOAP_CONTENTFORMAT_COSE_MAC,
|
||||
LWSCOAP_CONTENTFORMAT_COSE_MAC0
|
||||
};
|
||||
|
||||
static void
|
||||
lws_cose_sign_hashing(struct lws_cose_sign_context *csc,
|
||||
const uint8_t *in, size_t in_len)
|
||||
{
|
||||
//lwsl_hexdump_warn(in, in_len);
|
||||
|
||||
assert(in_len);
|
||||
|
||||
lws_start_foreach_dll_safe(struct lws_dll2 *, p, tp,
|
||||
lws_dll2_get_head(&csc->algs)) {
|
||||
lws_cose_sig_alg_t *alg = lws_container_of(p,
|
||||
lws_cose_sig_alg_t, list);
|
||||
|
||||
if (lws_cose_sign_alg_hash(alg, in, in_len))
|
||||
alg->failed = 1;
|
||||
} lws_end_foreach_dll_safe(p, tp);
|
||||
}
|
||||
|
||||
/*
|
||||
* These chunks may be payload or application AAD being emitted into the
|
||||
* signed object somewhere else. But we do not emit them ourselves here
|
||||
* (since other non-emitted things are also hashed by us) and so can always
|
||||
* deal with the whole in_len in one step.
|
||||
*/
|
||||
|
||||
enum lws_lec_pctx_ret
|
||||
lws_cose_sign_payload_chunk(struct lws_cose_sign_context *csc,
|
||||
const uint8_t *in, size_t in_len)
|
||||
{
|
||||
uint8_t lbuf[MAX_BLOBBED_PARAMS], lb[9];
|
||||
const struct lws_gencrypto_keyelem *ke;
|
||||
enum lws_lec_pctx_ret ret;
|
||||
lws_lec_pctx_t lec, lec1;
|
||||
lws_cose_sig_alg_t *alg;
|
||||
uint8_t c;
|
||||
size_t s;
|
||||
|
||||
switch (csc->tli) {
|
||||
case ST_UNKNOWN:
|
||||
/*
|
||||
* We need to figure out what signing structure we need to use,
|
||||
* given the algorithms that are in it. So let's have a look
|
||||
* and decide.
|
||||
*/
|
||||
|
||||
if (!csc->algs.count) {
|
||||
lwsl_err("%s: must add at least one signature\n", __func__);
|
||||
return 1;
|
||||
}
|
||||
|
||||
csc->type = SIGTYPE_MULTI;
|
||||
alg = lws_container_of(csc->algs.head, lws_cose_sig_alg_t, list);
|
||||
|
||||
switch (alg->cose_alg) {
|
||||
case LWSCOSE_WKAHMAC_256_64:
|
||||
case LWSCOSE_WKAHMAC_256_256:
|
||||
case LWSCOSE_WKAHMAC_384_384:
|
||||
case LWSCOSE_WKAHMAC_512_512:
|
||||
// if (csc->info.sigtype == SIGTYPE_MAC0)
|
||||
csc->type = SIGTYPE_MAC0;
|
||||
// else
|
||||
// csc->type = SIGTYPE_MAC;
|
||||
break;
|
||||
}
|
||||
|
||||
if (csc->algs.count == 1) {
|
||||
if (!csc->info.sigtype && csc->type == SIGTYPE_MAC) {
|
||||
if (csc->info.flags & LCSC_FL_ADD_CBOR_PREFER_MAC0)
|
||||
csc->type = SIGTYPE_MAC0;
|
||||
} else
|
||||
if (!csc->info.sigtype ||
|
||||
csc->info.sigtype == SIGTYPE_SINGLE) /* ie, if no hint */
|
||||
csc->type = SIGTYPE_SINGLE;
|
||||
}
|
||||
|
||||
lwsl_notice("%s: decided on type %d\n", __func__, csc->type);
|
||||
|
||||
/*
|
||||
* Start emitting the appropriate tag if that's requested
|
||||
*/
|
||||
|
||||
if (csc->info.flags & LCSC_FL_ADD_CBOR_TAG) {
|
||||
ret = lws_lec_printf(csc->info.lec, "%t(",
|
||||
cose_tags[csc->type]);
|
||||
|
||||
if (ret != LWS_LECPCTX_RET_FINISHED)
|
||||
return ret;
|
||||
}
|
||||
|
||||
/* The */
|
||||
c = 0;
|
||||
switch (csc->type) {
|
||||
case SIGTYPE_MAC0:
|
||||
case SIGTYPE_MULTI:
|
||||
case SIGTYPE_SINGLE:
|
||||
c = 0x84;
|
||||
break;
|
||||
case SIGTYPE_MAC:
|
||||
c = 0x85;
|
||||
break;
|
||||
default:
|
||||
break;
|
||||
}
|
||||
|
||||
/* The outer array */
|
||||
csc->info.lec->scratch[csc->info.lec->scratch_len++] = c;
|
||||
|
||||
/*
|
||||
* Then, let's start hashing with the sigtype constant part
|
||||
*/
|
||||
|
||||
lws_cose_sign_hashing(csc, sig_mctx[csc->type],
|
||||
sig_mctx_len[csc->type]);
|
||||
|
||||
csc->tli = ST_OUTER_PROTECTED;
|
||||
csc->subsequent = 0;
|
||||
|
||||
/* fallthru */
|
||||
|
||||
case ST_OUTER_PROTECTED:
|
||||
|
||||
/*
|
||||
* We need to list and emit any outer protected data as a map
|
||||
* into its own buffer, then emit that into the output as a bstr
|
||||
*/
|
||||
|
||||
switch (csc->type) {
|
||||
case SIGTYPE_SINGLE:
|
||||
case SIGTYPE_MAC0:
|
||||
alg = lws_container_of(csc->algs.head,
|
||||
lws_cose_sig_alg_t, list);
|
||||
|
||||
lws_lec_init(&lec, lbuf, sizeof(lbuf));
|
||||
|
||||
/* we know it will fit... but coverity doesn't */
|
||||
ret = lws_lec_printf(&lec, "{1:%lld}",
|
||||
(long long)alg->cose_alg);
|
||||
if (ret != LWS_LECPCTX_RET_FINISHED)
|
||||
return ret;
|
||||
|
||||
lws_lec_scratch(&lec);
|
||||
|
||||
if (!csc->subsequent) {
|
||||
lws_lec_init(&lec1, lb, sizeof(lb));
|
||||
lws_lec_int(&lec1, LWS_CBOR_MAJTYP_BSTR, 0,
|
||||
lec.used);
|
||||
lws_cose_sign_hashing(csc, lec1.scratch,
|
||||
lec1.scratch_len);
|
||||
lws_cose_sign_hashing(csc, lec.start, lec.used);
|
||||
ret = lws_lec_printf(csc->info.lec, "%.*b",
|
||||
(int)lec.used, lec.start);
|
||||
|
||||
if (ret != LWS_LECPCTX_RET_FINISHED)
|
||||
return ret;
|
||||
csc->subsequent = 1;
|
||||
}
|
||||
break;
|
||||
case SIGTYPE_MAC:
|
||||
case SIGTYPE_MULTI:
|
||||
lws_lec_init(&lec, lbuf, sizeof(lbuf));
|
||||
lws_lec_int(&lec, LWS_CBOR_MAJTYP_BSTR, 0, 0);
|
||||
lws_lec_int(csc->info.lec, LWS_CBOR_MAJTYP_BSTR, 0, 0);
|
||||
lws_lec_scratch(&lec);
|
||||
lec.used = lws_ptr_diff_size_t(lec.buf, lec.start);
|
||||
lws_cose_sign_hashing(csc, lec.start,
|
||||
lec.used);
|
||||
break;
|
||||
default:
|
||||
lec.used = 0;
|
||||
break;
|
||||
}
|
||||
|
||||
csc->tli = ST_OUTER_UNPROTECTED;
|
||||
|
||||
/* fallthru */
|
||||
|
||||
case ST_OUTER_UNPROTECTED:
|
||||
|
||||
/*
|
||||
* We need to list and emit any outer unprotected data, as
|
||||
* an inline cbor map
|
||||
*/
|
||||
|
||||
switch (csc->type) {
|
||||
case SIGTYPE_SINGLE:
|
||||
case SIGTYPE_MAC0:
|
||||
alg = lws_container_of(csc->algs.head,
|
||||
lws_cose_sig_alg_t, list);
|
||||
ke = &alg->cose_key->meta[COSEKEY_META_KID];
|
||||
if (ke->len) {
|
||||
ret = lws_lec_printf(csc->info.lec, "{%d:%.*b}",
|
||||
LWSCOSE_WKL_KID,
|
||||
(int)ke->len, ke->buf);
|
||||
|
||||
if (ret != LWS_LECPCTX_RET_FINISHED)
|
||||
return ret;
|
||||
}
|
||||
/* hack for no extra data */
|
||||
|
||||
lws_lec_init(&lec1, lb, sizeof(lb));
|
||||
lws_lec_int(&lec1, LWS_CBOR_MAJTYP_BSTR, 0, 0);
|
||||
lws_cose_sign_hashing(csc, lec1.scratch,
|
||||
lec1.scratch_len);
|
||||
break;
|
||||
case SIGTYPE_MAC:
|
||||
case SIGTYPE_MULTI:
|
||||
|
||||
lws_lec_int(csc->info.lec, LWS_CBOR_MAJTYP_BSTR, 0, 0);
|
||||
|
||||
/*
|
||||
* For cose-sign, we need to feed each sig alg its alg-
|
||||
* specific protected data into the hash before letting
|
||||
* all the hashes see the payload
|
||||
*/
|
||||
|
||||
lws_start_foreach_dll_safe(struct lws_dll2 *, p, tp,
|
||||
lws_dll2_get_head(&csc->algs)) {
|
||||
alg = lws_container_of(p, lws_cose_sig_alg_t, list);
|
||||
|
||||
lws_lec_init(&lec, lbuf, sizeof(lbuf));
|
||||
|
||||
/* we know it will fit... but coverity doesn't... */
|
||||
ret = lws_lec_printf(&lec, "{1:%lld}",
|
||||
(long long)alg->cose_alg);
|
||||
if (ret != LWS_LECPCTX_RET_FINISHED)
|
||||
return ret;
|
||||
|
||||
lws_lec_init(&lec1, lb, sizeof(lb));
|
||||
lws_lec_int(&lec1, LWS_CBOR_MAJTYP_BSTR, 0,
|
||||
lec.used);
|
||||
|
||||
// lwsl_hexdump_warn(lec1.scratch, lec1.scratch_len);
|
||||
// lwsl_hexdump_warn(lec.start, lec.used);
|
||||
if (lws_cose_sign_alg_hash(alg, lec1.scratch,
|
||||
lec1.scratch_len))
|
||||
alg->failed = 1;
|
||||
if (lws_cose_sign_alg_hash(alg, lec.start,
|
||||
lec.used))
|
||||
alg->failed = 1;
|
||||
|
||||
} lws_end_foreach_dll_safe(p, tp);
|
||||
|
||||
lws_lec_init(&lec1, lb, sizeof(lb));
|
||||
lws_lec_int(&lec1, LWS_CBOR_MAJTYP_BSTR, 0, 0);
|
||||
lws_cose_sign_hashing(csc, lec1.scratch,
|
||||
lec1.scratch_len);
|
||||
|
||||
break;
|
||||
default:
|
||||
ret = lws_lec_printf(csc->info.lec, "{}");
|
||||
if (ret != LWS_LECPCTX_RET_FINISHED)
|
||||
return ret;
|
||||
break;
|
||||
}
|
||||
|
||||
csc->tli = ST_OUTER_PAYLOAD;
|
||||
csc->subsequent = 0;
|
||||
|
||||
/* Prepare the payload BSTR */
|
||||
|
||||
lws_lec_int(csc->info.lec, LWS_CBOR_MAJTYP_BSTR, 0,
|
||||
csc->info.inline_payload_len);
|
||||
|
||||
lws_lec_init(&lec1, lb, sizeof(lb));
|
||||
lws_lec_int(&lec1, LWS_CBOR_MAJTYP_BSTR, 0,
|
||||
csc->info.inline_payload_len);
|
||||
lws_cose_sign_hashing(csc, lec1.scratch,
|
||||
lec1.scratch_len);
|
||||
|
||||
lws_lec_scratch(csc->info.lec);
|
||||
|
||||
csc->rem_pay = csc->info.inline_payload_len;
|
||||
|
||||
/* fallthru */
|
||||
|
||||
case ST_OUTER_PAYLOAD:
|
||||
|
||||
if (csc->along) {
|
||||
in += csc->along;
|
||||
in_len -= csc->along;
|
||||
}
|
||||
|
||||
lws_lec_scratch(csc->info.lec);
|
||||
|
||||
if (csc->rem_pay) {
|
||||
|
||||
lws_cose_sign_hashing(csc, in, in_len);
|
||||
|
||||
/*
|
||||
* in / in_len is the payload chunk
|
||||
*/
|
||||
|
||||
s = lws_ptr_diff_size_t(csc->info.lec->end,
|
||||
csc->info.lec->buf);
|
||||
if (s > (size_t)csc->rem_pay)
|
||||
s = (size_t)csc->rem_pay;
|
||||
if (s > in_len)
|
||||
s = in_len;
|
||||
|
||||
memcpy(csc->info.lec->buf, in, s);
|
||||
csc->info.lec->buf += s;
|
||||
csc->info.lec->used = lws_ptr_diff_size_t(
|
||||
csc->info.lec->buf,
|
||||
csc->info.lec->start);
|
||||
csc->rem_pay -= s;
|
||||
|
||||
csc->along = s;
|
||||
|
||||
return LWS_LECPCTX_RET_AGAIN;
|
||||
}
|
||||
|
||||
/* finished with rem_pay */
|
||||
|
||||
if (csc->type == SIGTYPE_MULTI) {
|
||||
|
||||
csc->alg = lws_container_of(csc->algs.head,
|
||||
lws_cose_sig_alg_t, list);
|
||||
lws_lec_init(&lec1, lb, sizeof(lb));
|
||||
lws_lec_int(&lec1, LWS_CBOR_MAJTYP_ARRAY, 0,
|
||||
csc->algs.count);
|
||||
lws_lec_int(csc->info.lec, LWS_CBOR_MAJTYP_ARRAY, 0,
|
||||
csc->algs.count);
|
||||
csc->tli = ST_INNER_PROTECTED;
|
||||
goto inner_protected;
|
||||
}
|
||||
csc->tli = ST_OUTER_SIGN1_SIGNATURE;
|
||||
csc->along = 0;
|
||||
|
||||
/* fallthru */
|
||||
|
||||
case ST_OUTER_SIGN1_SIGNATURE:
|
||||
|
||||
alg = lws_container_of(lws_dll2_get_head(&csc->algs),
|
||||
lws_cose_sig_alg_t, list);
|
||||
|
||||
if (!alg->completed)
|
||||
lws_cose_sign_alg_complete(alg);
|
||||
if (alg->failed)
|
||||
return LWS_LECPCTX_RET_FAIL;
|
||||
|
||||
ret = lws_lec_printf(csc->info.lec, "%.*b",
|
||||
(int)alg->rhash_len, alg->rhash);
|
||||
if (ret != LWS_LECPCTX_RET_FINISHED)
|
||||
return ret;
|
||||
|
||||
if (csc->type == SIGTYPE_MAC) {
|
||||
csc->alg = lws_container_of(csc->algs.head,
|
||||
lws_cose_sig_alg_t, list);
|
||||
lws_lec_init(&lec1, lb, sizeof(lb));
|
||||
lws_lec_int(&lec1, LWS_CBOR_MAJTYP_ARRAY, 0,
|
||||
csc->algs.count);
|
||||
lws_lec_int(csc->info.lec, LWS_CBOR_MAJTYP_ARRAY, 0,
|
||||
csc->algs.count);
|
||||
csc->tli = ST_INNER_PROTECTED;
|
||||
goto inner_protected;
|
||||
}
|
||||
|
||||
break;
|
||||
|
||||
case ST_INNER_PROTECTED:
|
||||
inner_protected:
|
||||
|
||||
/*
|
||||
* We need to list and emit any outer protected data as a map
|
||||
* into its own buffer, then emit that into the output as a bstr
|
||||
*/
|
||||
|
||||
switch (csc->type) {
|
||||
case SIGTYPE_MAC:
|
||||
case SIGTYPE_MULTI:
|
||||
lws_lec_init(&lec1, lb, sizeof(lb));
|
||||
lws_lec_int(&lec1, LWS_CBOR_MAJTYP_ARRAY, 0, 3);
|
||||
|
||||
lws_lec_int(csc->info.lec, LWS_CBOR_MAJTYP_ARRAY, 0, 3);
|
||||
|
||||
lws_lec_init(&lec, lbuf, sizeof(lbuf));
|
||||
|
||||
/* we know it will fit */
|
||||
lws_lec_printf(&lec, "{1:%lld}",
|
||||
(long long)csc->alg->cose_alg);
|
||||
|
||||
lws_lec_init(&lec1, lb, sizeof(lb));
|
||||
lws_lec_int(&lec1, LWS_CBOR_MAJTYP_BSTR, 0,
|
||||
lec.used);
|
||||
if (lws_lec_printf(csc->info.lec, "{1:%lld}",
|
||||
(long long)csc->alg->cose_alg) != LWS_LECPCTX_RET_FINISHED)
|
||||
/* coverity */
|
||||
return 0;
|
||||
break;
|
||||
default:
|
||||
lec.used = 0;
|
||||
break;
|
||||
}
|
||||
|
||||
|
||||
csc->tli = ST_INNER_UNPROTECTED;
|
||||
|
||||
/* fallthru */
|
||||
|
||||
case ST_INNER_UNPROTECTED:
|
||||
|
||||
switch (csc->type) {
|
||||
case SIGTYPE_MULTI:
|
||||
alg = lws_container_of(csc->algs.head,
|
||||
lws_cose_sig_alg_t, list);
|
||||
ke = &alg->cose_key->meta[COSEKEY_META_KID];
|
||||
if (ke->len) {
|
||||
ret = lws_lec_printf(csc->info.lec, "{%d:%.*b}",
|
||||
LWSCOSE_WKL_KID,
|
||||
(int)ke->len, ke->buf);
|
||||
|
||||
if (ret != LWS_LECPCTX_RET_FINISHED)
|
||||
return ret;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
ret = lws_lec_printf(csc->info.lec, "{}");
|
||||
if (ret != LWS_LECPCTX_RET_FINISHED)
|
||||
return ret;
|
||||
break;
|
||||
}
|
||||
|
||||
lws_cose_sign_alg_complete(csc->alg);
|
||||
if (csc->alg->failed)
|
||||
return LWS_LECPCTX_RET_FAIL;
|
||||
csc->tli = ST_INNER_SIGNATURE;
|
||||
|
||||
/* fallthru */
|
||||
|
||||
case ST_INNER_SIGNATURE:
|
||||
|
||||
ret = lws_lec_printf(csc->info.lec, "%.*b",
|
||||
(int)csc->alg->rhash_len, csc->alg->rhash);
|
||||
if (ret != LWS_LECPCTX_RET_FINISHED)
|
||||
return ret;
|
||||
|
||||
if (csc->alg->list.next) {
|
||||
csc->alg = (lws_cose_sig_alg_t *)csc->alg->list.next;
|
||||
csc->tli = ST_INNER_PROTECTED;
|
||||
}
|
||||
break;
|
||||
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
void
|
||||
lws_cose_sign_destroy(struct lws_cose_sign_context **_csc)
|
||||
{
|
||||
struct lws_cose_sign_context *csc = *_csc;
|
||||
|
||||
if (!csc)
|
||||
return;
|
||||
|
||||
lws_start_foreach_dll_safe(struct lws_dll2 *, p, tp,
|
||||
lws_dll2_get_head(&csc->algs)) {
|
||||
lws_cose_sig_alg_t *alg = lws_container_of(p,
|
||||
lws_cose_sig_alg_t, list);
|
||||
|
||||
lws_dll2_remove(p);
|
||||
lws_cose_sign_alg_destroy(&alg);
|
||||
} lws_end_foreach_dll_safe(p, tp);
|
||||
|
||||
lws_free_set_NULL(*_csc);
|
||||
}
|
271
Kinc/Sources/kinc/libs/core/cose/cose_sign_alg.c
Normal file
271
Kinc/Sources/kinc/libs/core/cose/cose_sign_alg.c
Normal file
@ -0,0 +1,271 @@
|
||||
/*
|
||||
* libwebsockets - small server side websockets and web server implementation
|
||||
*
|
||||
* Copyright (C) 2010 - 2021 Andy Green <andy@warmcat.com>
|
||||
*
|
||||
* Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
* of this software and associated documentation files (the "Software"), to
|
||||
* deal in the Software without restriction, including without limitation the
|
||||
* rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
|
||||
* sell copies of the Software, and to permit persons to whom the Software is
|
||||
* furnished to do so, subject to the following conditions:
|
||||
*
|
||||
* The above copyright notice and this permission notice shall be included in
|
||||
* all copies or substantial portions of the Software.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
||||
* FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
|
||||
* IN THE SOFTWARE.
|
||||
*/
|
||||
|
||||
#include "private-lib-core.h"
|
||||
#include "private-lib-cose.h"
|
||||
|
||||
lws_cose_sig_alg_t *
|
||||
lws_cose_sign_alg_create(struct lws_context *cx, const lws_cose_key_t *ck,
|
||||
cose_param_t cose_alg, int op)
|
||||
{
|
||||
lws_cose_sig_alg_t *alg = lws_zalloc(sizeof(*alg), __func__);
|
||||
const struct lws_gencrypto_keyelem *ke;
|
||||
enum lws_genhmac_types ghm;
|
||||
enum lws_genhash_types gh;
|
||||
const char *crv;
|
||||
|
||||
if (!alg)
|
||||
return NULL;
|
||||
|
||||
alg->cose_alg = cose_alg;
|
||||
alg->cose_key = ck;
|
||||
|
||||
switch (cose_alg) {
|
||||
|
||||
/* ECDSA algs */
|
||||
|
||||
case LWSCOSE_WKAECDSA_ALG_ES256: /* ECDSA w/ SHA-256 */
|
||||
crv = "P-256";
|
||||
gh = LWS_GENHASH_TYPE_SHA256;
|
||||
alg->keybits = 256;
|
||||
goto ecdsa;
|
||||
case LWSCOSE_WKAECDSA_ALG_ES384: /* ECDSA w/ SHA-384 */
|
||||
crv = "P-384";
|
||||
gh = LWS_GENHASH_TYPE_SHA384;
|
||||
alg->keybits = 384;
|
||||
goto ecdsa;
|
||||
case LWSCOSE_WKAECDSA_ALG_ES512: /* ECDSA w/ SHA-512 */
|
||||
crv = "P-521";
|
||||
gh = LWS_GENHASH_TYPE_SHA512;
|
||||
alg->keybits = 521;
|
||||
ecdsa:
|
||||
|
||||
/* the key is good for this? */
|
||||
|
||||
if (lws_cose_key_checks(ck, LWSCOSE_WKKTV_EC2, cose_alg,
|
||||
op, crv))
|
||||
goto bail_ecdsa;
|
||||
|
||||
if (lws_genhash_init(&alg->hash_ctx, gh))
|
||||
goto bail_ecdsa;
|
||||
|
||||
if (lws_genecdsa_create(&alg->u.ecdsactx, cx, lws_ec_curves)) {
|
||||
lwsl_notice("%s: lws_genrsa_public_decrypt_create\n",
|
||||
__func__);
|
||||
goto bail_ecdsa1;
|
||||
}
|
||||
|
||||
if (lws_genecdsa_set_key(&alg->u.ecdsactx, ck->e)) {
|
||||
lwsl_notice("%s: ec key import fail\n", __func__);
|
||||
goto bail_ecdsa2;
|
||||
}
|
||||
|
||||
break;
|
||||
|
||||
/* HMAC algs */
|
||||
|
||||
case LWSCOSE_WKAHMAC_256_64:
|
||||
ghm = LWS_GENHMAC_TYPE_SHA256;
|
||||
alg->keybits = 64;
|
||||
goto hmac;
|
||||
case LWSCOSE_WKAHMAC_256_256:
|
||||
ghm = LWS_GENHMAC_TYPE_SHA256;
|
||||
alg->keybits = 256;
|
||||
goto hmac;
|
||||
case LWSCOSE_WKAHMAC_384_384:
|
||||
ghm = LWS_GENHMAC_TYPE_SHA384;
|
||||
alg->keybits = 384;
|
||||
goto hmac;
|
||||
case LWSCOSE_WKAHMAC_512_512:
|
||||
ghm = LWS_GENHMAC_TYPE_SHA512;
|
||||
alg->keybits = 512;
|
||||
|
||||
hmac:
|
||||
if (lws_cose_key_checks(ck, LWSCOSE_WKKTV_SYMMETRIC,
|
||||
cose_alg, op, NULL))
|
||||
goto bail_hmac;
|
||||
|
||||
ke = &ck->e[LWS_GENCRYPTO_OCT_KEYEL_K];
|
||||
if (lws_genhmac_init(&alg->u.hmacctx, ghm, ke->buf, ke->len))
|
||||
goto bail_hmac;
|
||||
|
||||
break;
|
||||
|
||||
/* RSASSA algs */
|
||||
|
||||
case LWSCOSE_WKARSA_ALG_RS256:
|
||||
gh = LWS_GENHASH_TYPE_SHA256;
|
||||
goto rsassa;
|
||||
|
||||
case LWSCOSE_WKARSA_ALG_RS384:
|
||||
gh = LWS_GENHASH_TYPE_SHA384;
|
||||
goto rsassa;
|
||||
|
||||
case LWSCOSE_WKARSA_ALG_RS512:
|
||||
gh = LWS_GENHASH_TYPE_SHA512;
|
||||
|
||||
rsassa:
|
||||
if (lws_cose_key_checks(ck, LWSCOSE_WKKTV_RSA, cose_alg,
|
||||
op, NULL))
|
||||
goto bail_hmac;
|
||||
|
||||
alg->keybits = (int)ck->e[LWS_GENCRYPTO_RSA_KEYEL_N].len * 8;
|
||||
|
||||
if (lws_genhash_init(&alg->hash_ctx, gh))
|
||||
goto bail_hmac;
|
||||
|
||||
if (lws_genrsa_create(&alg->u.rsactx, ck->e, cx,
|
||||
LGRSAM_PKCS1_1_5, gh)) {
|
||||
lwsl_notice("%s: lws_genrsa_create fail\n", __func__);
|
||||
goto bail_hmac;
|
||||
}
|
||||
break;
|
||||
|
||||
default:
|
||||
lwsl_warn("%s: unsupported alg %lld\n", __func__,
|
||||
(long long)cose_alg);
|
||||
goto bail_hmac;
|
||||
}
|
||||
|
||||
return alg;
|
||||
|
||||
bail_ecdsa2:
|
||||
lws_genec_destroy(&alg->u.ecdsactx);
|
||||
bail_ecdsa1:
|
||||
lws_genhash_destroy(&alg->hash_ctx, NULL);
|
||||
bail_ecdsa:
|
||||
lws_free(alg);
|
||||
|
||||
return NULL;
|
||||
|
||||
bail_hmac:
|
||||
lws_free(alg);
|
||||
|
||||
return NULL;
|
||||
}
|
||||
|
||||
int
|
||||
lws_cose_sign_alg_hash(lws_cose_sig_alg_t *alg, const uint8_t *in, size_t in_len)
|
||||
{
|
||||
#if defined(VERBOSE)
|
||||
lwsl_hexdump_warn(in, in_len);
|
||||
#endif
|
||||
|
||||
switch (alg->cose_alg) {
|
||||
|
||||
case LWSCOSE_WKAHMAC_256_64:
|
||||
case LWSCOSE_WKAHMAC_256_256:
|
||||
case LWSCOSE_WKAHMAC_384_384:
|
||||
case LWSCOSE_WKAHMAC_512_512:
|
||||
return lws_genhmac_update(&alg->u.hmacctx, in, in_len);
|
||||
}
|
||||
|
||||
/* EC, rsa are just making the hash before signing */
|
||||
|
||||
return lws_genhash_update(&alg->hash_ctx, in, in_len);
|
||||
}
|
||||
|
||||
/*
|
||||
* We fill up alg-> rhash and rhash_len with the results, and destroy the
|
||||
* crypto pieces cleanly. Call lws_cose_sign_alg_destroy() afterwards to
|
||||
* clean up the alg itself.
|
||||
*/
|
||||
|
||||
void
|
||||
lws_cose_sign_alg_complete(lws_cose_sig_alg_t *alg)
|
||||
{
|
||||
uint8_t digest[LWS_GENHASH_LARGEST];
|
||||
unsigned int bytes;
|
||||
uint8_t htype;
|
||||
size_t hs;
|
||||
|
||||
if (alg->completed)
|
||||
return;
|
||||
|
||||
switch (alg->cose_alg) {
|
||||
case LWSCOSE_WKAECDSA_ALG_ES256: /* ECDSA w/ SHA-256 */
|
||||
case LWSCOSE_WKAECDSA_ALG_ES384: /* ECDSA w/ SHA-384 */
|
||||
case LWSCOSE_WKAECDSA_ALG_ES512: /* ECDSA w/ SHA-512 */
|
||||
hs = lws_genhash_size(alg->hash_ctx.type);
|
||||
bytes = (unsigned int)lws_gencrypto_bits_to_bytes(alg->keybits);
|
||||
lws_genhash_destroy(&alg->hash_ctx, digest);
|
||||
alg->rhash_len = 0;
|
||||
lwsl_notice("alg keybits %d hs %d\n", (int)alg->keybits, (int)hs);
|
||||
if (!alg->failed &&
|
||||
lws_genecdsa_hash_sign_jws(&alg->u.ecdsactx, digest,
|
||||
alg->hash_ctx.type,
|
||||
(int)alg->keybits, alg->rhash,
|
||||
2u * bytes) >= 0)
|
||||
alg->rhash_len = (int)(2 * bytes);
|
||||
else
|
||||
alg->failed = 1;
|
||||
|
||||
lws_genec_destroy(&alg->u.ecdsactx);
|
||||
break;
|
||||
|
||||
case LWSCOSE_WKAHMAC_256_64:
|
||||
case LWSCOSE_WKAHMAC_256_256:
|
||||
case LWSCOSE_WKAHMAC_384_384:
|
||||
case LWSCOSE_WKAHMAC_512_512:
|
||||
alg->rhash_len = (int)lws_genhmac_size(alg->u.hmacctx.type);
|
||||
if (alg->cose_alg == LWSCOSE_WKAHMAC_256_64)
|
||||
alg->rhash_len = 8;
|
||||
|
||||
if (lws_genhmac_destroy(&alg->u.hmacctx, alg->rhash)) {
|
||||
lwsl_err("%s: destroy failed\n", __func__);
|
||||
break;
|
||||
}
|
||||
break;
|
||||
|
||||
case LWSCOSE_WKARSA_ALG_RS256:
|
||||
case LWSCOSE_WKARSA_ALG_RS384:
|
||||
case LWSCOSE_WKARSA_ALG_RS512:
|
||||
bytes = (unsigned int)lws_gencrypto_bits_to_bytes(alg->keybits);
|
||||
htype = alg->hash_ctx.type;
|
||||
|
||||
if (!lws_genhash_destroy(&alg->hash_ctx, digest) &&
|
||||
!alg->failed &&
|
||||
lws_genrsa_hash_sign(&alg->u.rsactx, digest, htype,
|
||||
alg->rhash, bytes) >= 0)
|
||||
alg->rhash_len = (int)bytes;
|
||||
else
|
||||
lwsl_err("%s: lws_genrsa_hash_sign\n", __func__);
|
||||
|
||||
lws_genrsa_destroy(&alg->u.rsactx);
|
||||
break;
|
||||
|
||||
default:
|
||||
break;
|
||||
}
|
||||
|
||||
alg->completed = 1;
|
||||
}
|
||||
|
||||
void
|
||||
lws_cose_sign_alg_destroy(lws_cose_sig_alg_t **_alg)
|
||||
{
|
||||
lws_dll2_remove(&(*_alg)->list);
|
||||
lws_cose_sign_alg_complete(*_alg);
|
||||
lws_free_set_NULL(*_alg);
|
||||
}
|
1051
Kinc/Sources/kinc/libs/core/cose/cose_validate.c
Normal file
1051
Kinc/Sources/kinc/libs/core/cose/cose_validate.c
Normal file
File diff suppressed because it is too large
Load Diff
274
Kinc/Sources/kinc/libs/core/cose/cose_validate_alg.c
Normal file
274
Kinc/Sources/kinc/libs/core/cose/cose_validate_alg.c
Normal file
@ -0,0 +1,274 @@
|
||||
/*
|
||||
* libwebsockets - small server side websockets and web server implementation
|
||||
*
|
||||
* Copyright (C) 2010 - 2021 Andy Green <andy@warmcat.com>
|
||||
*
|
||||
* Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
* of this software and associated documentation files (the "Software"), to
|
||||
* deal in the Software without restriction, including without limitation the
|
||||
* rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
|
||||
* sell copies of the Software, and to permit persons to whom the Software is
|
||||
* furnished to do so, subject to the following conditions:
|
||||
*
|
||||
* The above copyright notice and this permission notice shall be included in
|
||||
* all copies or substantial portions of the Software.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
||||
* FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
|
||||
* IN THE SOFTWARE.
|
||||
*/
|
||||
|
||||
#include "private-lib-core.h"
|
||||
#include "private-lib-cose.h"
|
||||
|
||||
lws_cose_sig_alg_t *
|
||||
lws_cose_val_alg_create(struct lws_context *cx, lws_cose_key_t *ck,
|
||||
cose_param_t cose_alg, int op)
|
||||
{
|
||||
lws_cose_sig_alg_t *alg = lws_zalloc(sizeof(*alg), __func__);
|
||||
struct lws_gencrypto_keyelem *ke;
|
||||
enum lws_genhmac_types ghm;
|
||||
enum lws_genhash_types gh;
|
||||
const char *crv;
|
||||
|
||||
if (!alg)
|
||||
return NULL;
|
||||
|
||||
alg->cose_alg = cose_alg;
|
||||
alg->cose_key = ck;
|
||||
|
||||
switch (cose_alg) {
|
||||
|
||||
/* ECDSA algs */
|
||||
|
||||
case LWSCOSE_WKAECDSA_ALG_ES256: /* ECDSA w/ SHA-256 */
|
||||
crv = "P-256";
|
||||
gh = LWS_GENHASH_TYPE_SHA256;
|
||||
alg->keybits = 256;
|
||||
goto ecdsa;
|
||||
case LWSCOSE_WKAECDSA_ALG_ES384: /* ECDSA w/ SHA-384 */
|
||||
crv = "P-384";
|
||||
gh = LWS_GENHASH_TYPE_SHA384;
|
||||
alg->keybits = 384;
|
||||
goto ecdsa;
|
||||
case LWSCOSE_WKAECDSA_ALG_ES512: /* ECDSA w/ SHA-512 */
|
||||
crv = "P-521";
|
||||
gh = LWS_GENHASH_TYPE_SHA512;
|
||||
alg->keybits = 521;
|
||||
ecdsa:
|
||||
|
||||
/* the key is good for this? */
|
||||
|
||||
if (lws_cose_key_checks(ck, LWSCOSE_WKKTV_EC2, cose_alg,
|
||||
op, crv))
|
||||
goto bail_ecdsa;
|
||||
|
||||
if (lws_genhash_init(&alg->hash_ctx, gh))
|
||||
goto bail_ecdsa;
|
||||
|
||||
if (lws_genecdsa_create(&alg->u.ecdsactx, cx, lws_ec_curves)) {
|
||||
lwsl_notice("%s: lws_genrsa_public_decrypt_create\n",
|
||||
__func__);
|
||||
goto bail_ecdsa1;
|
||||
}
|
||||
|
||||
if (lws_genecdsa_set_key(&alg->u.ecdsactx, ck->e)) {
|
||||
lwsl_notice("%s: ec key import fail\n", __func__);
|
||||
goto bail_ecdsa2;
|
||||
}
|
||||
|
||||
break;
|
||||
|
||||
/* HMAC algs */
|
||||
|
||||
case LWSCOSE_WKAHMAC_256_64:
|
||||
ghm = LWS_GENHMAC_TYPE_SHA256;
|
||||
alg->keybits = 64;
|
||||
goto hmac;
|
||||
case LWSCOSE_WKAHMAC_256_256:
|
||||
ghm = LWS_GENHMAC_TYPE_SHA256;
|
||||
alg->keybits = 256;
|
||||
goto hmac;
|
||||
case LWSCOSE_WKAHMAC_384_384:
|
||||
ghm = LWS_GENHMAC_TYPE_SHA384;
|
||||
alg->keybits = 384;
|
||||
goto hmac;
|
||||
case LWSCOSE_WKAHMAC_512_512:
|
||||
ghm = LWS_GENHMAC_TYPE_SHA512;
|
||||
alg->keybits = 512;
|
||||
|
||||
hmac:
|
||||
if (lws_cose_key_checks(ck, LWSCOSE_WKKTV_SYMMETRIC,
|
||||
cose_alg, op, NULL))
|
||||
goto bail_hmac;
|
||||
|
||||
ke = &ck->e[LWS_GENCRYPTO_OCT_KEYEL_K];
|
||||
if (lws_genhmac_init(&alg->u.hmacctx, ghm, ke->buf, ke->len))
|
||||
goto bail_hmac;
|
||||
|
||||
break;
|
||||
|
||||
/* RSASSA algs */
|
||||
|
||||
case LWSCOSE_WKARSA_ALG_RS256:
|
||||
gh = LWS_GENHASH_TYPE_SHA256;
|
||||
goto rsassa;
|
||||
|
||||
case LWSCOSE_WKARSA_ALG_RS384:
|
||||
gh = LWS_GENHASH_TYPE_SHA384;
|
||||
goto rsassa;
|
||||
|
||||
case LWSCOSE_WKARSA_ALG_RS512:
|
||||
gh = LWS_GENHASH_TYPE_SHA512;
|
||||
|
||||
rsassa:
|
||||
if (lws_cose_key_checks(ck, LWSCOSE_WKKTV_RSA, cose_alg,
|
||||
op, NULL))
|
||||
goto bail_hmac;
|
||||
alg->keybits = (int)ck->e[LWS_GENCRYPTO_RSA_KEYEL_N].len * 8;
|
||||
|
||||
if (lws_genhash_init(&alg->hash_ctx, gh))
|
||||
goto bail_ecdsa;
|
||||
|
||||
if (lws_genrsa_create(&alg->u.rsactx, ck->e, cx,
|
||||
LGRSAM_PKCS1_1_5, gh)) {
|
||||
lwsl_notice("%s: lws_genrsa_create fail\n", __func__);
|
||||
goto bail_ecdsa1;
|
||||
}
|
||||
break;
|
||||
|
||||
default:
|
||||
lwsl_warn("%s: unsupported alg %lld\n", __func__,
|
||||
(long long)cose_alg);
|
||||
goto bail_hmac;
|
||||
}
|
||||
|
||||
return alg;
|
||||
|
||||
bail_ecdsa2:
|
||||
lws_genec_destroy(&alg->u.ecdsactx);
|
||||
bail_ecdsa1:
|
||||
lws_genhash_destroy(&alg->hash_ctx, NULL);
|
||||
bail_ecdsa:
|
||||
lws_free(alg);
|
||||
|
||||
lwsl_notice("%s: failed\n", __func__);
|
||||
|
||||
return NULL;
|
||||
|
||||
bail_hmac:
|
||||
lws_free(alg);
|
||||
|
||||
return NULL;
|
||||
}
|
||||
|
||||
int
|
||||
lws_cose_val_alg_hash(lws_cose_sig_alg_t *alg, const uint8_t *in, size_t in_len)
|
||||
{
|
||||
#if defined(VERBOSE)
|
||||
lwsl_hexdump_warn(in, in_len);
|
||||
#endif
|
||||
|
||||
switch (alg->cose_alg) {
|
||||
case LWSCOSE_WKAHMAC_256_64:
|
||||
case LWSCOSE_WKAHMAC_256_256:
|
||||
case LWSCOSE_WKAHMAC_384_384:
|
||||
case LWSCOSE_WKAHMAC_512_512:
|
||||
return lws_genhmac_update(&alg->u.hmacctx, in, in_len);
|
||||
}
|
||||
|
||||
return lws_genhash_update(&alg->hash_ctx, in, in_len);
|
||||
}
|
||||
|
||||
void
|
||||
lws_cose_val_alg_destroy(struct lws_cose_validate_context *cps,
|
||||
lws_cose_sig_alg_t **_alg, const uint8_t *against,
|
||||
size_t against_len)
|
||||
{
|
||||
uint8_t digest[LWS_GENHASH_LARGEST];
|
||||
lws_cose_sig_alg_t *alg = *_alg;
|
||||
lws_cose_validate_res_t *res;
|
||||
size_t hs, shs;
|
||||
int keybits;
|
||||
uint8_t ht;
|
||||
|
||||
lws_dll2_remove(&alg->list);
|
||||
ht = alg->hash_ctx.type;
|
||||
keybits = alg->keybits;
|
||||
|
||||
res = lws_zalloc(sizeof(*res), __func__);
|
||||
if (res) {
|
||||
|
||||
res->cose_key = alg->cose_key;
|
||||
res->cose_alg = alg->cose_alg;
|
||||
res->result = -999;
|
||||
|
||||
lws_dll2_add_tail(&res->list, &cps->results);
|
||||
}
|
||||
|
||||
switch (alg->cose_alg) {
|
||||
case LWSCOSE_WKAECDSA_ALG_ES256: /* ECDSA w/ SHA-256 */
|
||||
case LWSCOSE_WKAECDSA_ALG_ES384: /* ECDSA w/ SHA-384 */
|
||||
case LWSCOSE_WKAECDSA_ALG_ES512: /* ECDSA w/ SHA-512 */
|
||||
hs = lws_genhash_size(alg->hash_ctx.type);
|
||||
lws_genhash_destroy(&alg->hash_ctx, digest);
|
||||
|
||||
lwsl_notice("%d %d %d\n", (int)hs, (int)keybits, (int)against_len);
|
||||
|
||||
if (res && against)
|
||||
res->result = lws_genecdsa_hash_sig_verify_jws(
|
||||
&alg->u.ecdsactx, digest, ht,
|
||||
keybits, against, against_len);
|
||||
lws_genec_destroy(&alg->u.ecdsactx);
|
||||
break;
|
||||
|
||||
case LWSCOSE_WKAHMAC_256_64:
|
||||
case LWSCOSE_WKAHMAC_256_256:
|
||||
case LWSCOSE_WKAHMAC_384_384:
|
||||
case LWSCOSE_WKAHMAC_512_512:
|
||||
shs = hs = lws_genhmac_size(alg->u.hmacctx.type);
|
||||
if (alg->cose_alg == LWSCOSE_WKAHMAC_256_64)
|
||||
shs = 8;
|
||||
|
||||
if (lws_genhmac_destroy(&alg->u.hmacctx, digest)) {
|
||||
lwsl_err("%s: destroy failed\n", __func__);
|
||||
break;
|
||||
}
|
||||
|
||||
if (cps->mac_pos != shs) {
|
||||
lwsl_warn("%s: mac wrong size\n", __func__);
|
||||
/* we can't compare it, leave it at fail */
|
||||
break;
|
||||
}
|
||||
if (res && against) {
|
||||
res->result = lws_timingsafe_bcmp(digest, cps->mac,
|
||||
(uint32_t)shs);
|
||||
if (res->result)
|
||||
lwsl_warn("%s: hash mismatch\n", __func__);
|
||||
}
|
||||
break;
|
||||
|
||||
case LWSCOSE_WKARSA_ALG_RS256:
|
||||
case LWSCOSE_WKARSA_ALG_RS384:
|
||||
case LWSCOSE_WKARSA_ALG_RS512:
|
||||
|
||||
if (!lws_genhash_destroy(&alg->hash_ctx, digest) &&
|
||||
!alg->failed &&
|
||||
lws_genrsa_hash_sig_verify(&alg->u.rsactx, digest,
|
||||
alg->hash_ctx.type,
|
||||
against, against_len) >= 0) {
|
||||
if (res)
|
||||
res->result = 0;
|
||||
} else
|
||||
lwsl_err("%s: lws_genrsa_hash_verify\n", __func__);
|
||||
|
||||
lws_genrsa_destroy(&alg->u.rsactx);
|
||||
break;
|
||||
}
|
||||
|
||||
lws_free_set_NULL(*_alg);
|
||||
}
|
148
Kinc/Sources/kinc/libs/core/cose/private-lib-cose.h
Normal file
148
Kinc/Sources/kinc/libs/core/cose/private-lib-cose.h
Normal file
@ -0,0 +1,148 @@
|
||||
/*
|
||||
* libwebsockets - small server side websockets and web server implementation
|
||||
*
|
||||
* Copyright (C) 2010 - 2021 Andy Green <andy@warmcat.com>
|
||||
*
|
||||
* Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
* of this software and associated documentation files (the "Software"), to
|
||||
* deal in the Software without restriction, including without limitation the
|
||||
* rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
|
||||
* sell copies of the Software, and to permit persons to whom the Software is
|
||||
* furnished to do so, subject to the following conditions:
|
||||
*
|
||||
* The above copyright notice and this permission notice shall be included in
|
||||
* all copies or substantial portions of the Software.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
||||
* FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
|
||||
* IN THE SOFTWARE.
|
||||
*/
|
||||
|
||||
#define VERBOSE
|
||||
|
||||
#define MAX_BLOBBED_PARAMS 96 /* largest bstr-encoded params */
|
||||
|
||||
enum {
|
||||
ST_UNKNOWN,
|
||||
|
||||
ST_OUTER_PROTECTED,
|
||||
ST_OUTER_UNPROTECTED,
|
||||
ST_OUTER_PAYLOAD,
|
||||
ST_OUTER_SIGN1_SIGNATURE,
|
||||
|
||||
ST_OUTER_SIGN_SIGARRAY,
|
||||
|
||||
ST_OUTER_MACTAG,
|
||||
|
||||
ST_INNER_PROTECTED,
|
||||
ST_INNER_UNPROTECTED,
|
||||
ST_INNER_SIGNATURE,
|
||||
|
||||
ST_INNER_EXCESS,
|
||||
};
|
||||
|
||||
typedef struct lws_cose_sig_alg {
|
||||
lws_dll2_t list;
|
||||
uint8_t rhash[512];
|
||||
const lws_cose_key_t *cose_key;
|
||||
struct lws_genhash_ctx hash_ctx;
|
||||
union {
|
||||
struct lws_genec_ctx ecdsactx;
|
||||
struct lws_genrsa_ctx rsactx;
|
||||
struct lws_genhmac_ctx hmacctx;
|
||||
} u;
|
||||
cose_param_t cose_alg;
|
||||
int keybits;
|
||||
int rhash_len;
|
||||
|
||||
char failed;
|
||||
char completed;
|
||||
} lws_cose_sig_alg_t;
|
||||
|
||||
typedef struct lws_cose_validate_param_stack {
|
||||
uint8_t ph[4][MAX_BLOBBED_PARAMS];
|
||||
int ph_pos[4];
|
||||
struct lws_gencrypto_keyelem kid;
|
||||
cose_param_t alg;
|
||||
} lws_cose_validate_param_stack_t;
|
||||
|
||||
struct lws_cose_validate_context {
|
||||
lws_cose_validate_create_info_t info;
|
||||
uint8_t mac[LWS_GENHASH_LARGEST];
|
||||
uint8_t sig_agg[512];
|
||||
lws_cose_validate_param_stack_t st[3];
|
||||
lws_dll2_owner_t algs;
|
||||
lws_dll2_owner_t results;
|
||||
uint8_t *payload_stash;
|
||||
struct lwsac *ac;
|
||||
struct lecp_ctx ctx;
|
||||
void *user;
|
||||
|
||||
size_t payload_pos;
|
||||
size_t payload_stash_size;
|
||||
|
||||
int seen;
|
||||
int depth;
|
||||
|
||||
int outer;
|
||||
size_t mac_pos;
|
||||
size_t sig_agg_pos;
|
||||
|
||||
cose_param_t map_key; /* parsing temp before val */
|
||||
|
||||
int tli; /* toplevel item */
|
||||
int sp;
|
||||
|
||||
uint8_t sub;
|
||||
};
|
||||
|
||||
struct lws_cose_sign_context {
|
||||
lws_cose_sign_create_info_t info;
|
||||
|
||||
lws_dll2_owner_t algs;
|
||||
lws_cose_sig_alg_t *alg;
|
||||
|
||||
size_t rem_pay;
|
||||
enum lws_cose_sig_types type; /* computed */
|
||||
int flags;
|
||||
|
||||
size_t along;
|
||||
|
||||
int tli;
|
||||
|
||||
char subsequent;
|
||||
};
|
||||
|
||||
extern const uint8_t *sig_mctx[];
|
||||
extern uint8_t sig_mctx_len[];
|
||||
extern const char *cose_sections[];
|
||||
|
||||
lws_cose_sig_alg_t *
|
||||
lws_cose_val_alg_create(struct lws_context *cx, lws_cose_key_t *ck,
|
||||
cose_param_t cose_alg, int op);
|
||||
|
||||
int
|
||||
lws_cose_val_alg_hash(lws_cose_sig_alg_t *alg, const uint8_t *in, size_t in_len);
|
||||
|
||||
void
|
||||
lws_cose_val_alg_destroy(struct lws_cose_validate_context *cps,
|
||||
lws_cose_sig_alg_t **_alg, const uint8_t *against,
|
||||
size_t against_len);
|
||||
|
||||
lws_cose_sig_alg_t *
|
||||
lws_cose_sign_alg_create(struct lws_context *cx, const lws_cose_key_t *ck,
|
||||
cose_param_t cose_alg, int op);
|
||||
|
||||
int
|
||||
lws_cose_sign_alg_hash(lws_cose_sig_alg_t *alg, const uint8_t *in, size_t in_len);
|
||||
|
||||
void
|
||||
lws_cose_sign_alg_complete(lws_cose_sig_alg_t *alg);
|
||||
|
||||
void
|
||||
lws_cose_sign_alg_destroy(lws_cose_sig_alg_t **_alg);
|
||||
|
Reference in New Issue
Block a user