ech_lib.c revision 280304
1/* crypto/ecdh/ech_lib.c */ 2/* ==================================================================== 3 * Copyright 2002 Sun Microsystems, Inc. ALL RIGHTS RESERVED. 4 * 5 * The Elliptic Curve Public-Key Crypto Library (ECC Code) included 6 * herein is developed by SUN MICROSYSTEMS, INC., and is contributed 7 * to the OpenSSL project. 8 * 9 * The ECC Code is licensed pursuant to the OpenSSL open source 10 * license provided below. 11 * 12 * The ECDH software is originally written by Douglas Stebila of 13 * Sun Microsystems Laboratories. 14 * 15 */ 16/* ==================================================================== 17 * Copyright (c) 1998-2003 The OpenSSL Project. All rights reserved. 18 * 19 * Redistribution and use in source and binary forms, with or without 20 * modification, are permitted provided that the following conditions 21 * are met: 22 * 23 * 1. Redistributions of source code must retain the above copyright 24 * notice, this list of conditions and the following disclaimer. 25 * 26 * 2. Redistributions in binary form must reproduce the above copyright 27 * notice, this list of conditions and the following disclaimer in 28 * the documentation and/or other materials provided with the 29 * distribution. 30 * 31 * 3. All advertising materials mentioning features or use of this 32 * software must display the following acknowledgment: 33 * "This product includes software developed by the OpenSSL Project 34 * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)" 35 * 36 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to 37 * endorse or promote products derived from this software without 38 * prior written permission. For written permission, please contact 39 * openssl-core@OpenSSL.org. 40 * 41 * 5. Products derived from this software may not be called "OpenSSL" 42 * nor may "OpenSSL" appear in their names without prior written 43 * permission of the OpenSSL Project. 44 * 45 * 6. Redistributions of any form whatsoever must retain the following 46 * acknowledgment: 47 * "This product includes software developed by the OpenSSL Project 48 * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)" 49 * 50 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY 51 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 52 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 53 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR 54 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, 55 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 56 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 57 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 58 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, 59 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 60 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED 61 * OF THE POSSIBILITY OF SUCH DAMAGE. 62 * ==================================================================== 63 * 64 * This product includes cryptographic software written by Eric Young 65 * (eay@cryptsoft.com). This product includes software written by Tim 66 * Hudson (tjh@cryptsoft.com). 67 * 68 */ 69 70#include "ech_locl.h" 71#include <string.h> 72#ifndef OPENSSL_NO_ENGINE 73# include <openssl/engine.h> 74#endif 75#include <openssl/err.h> 76#ifdef OPENSSL_FIPS 77# include <openssl/fips.h> 78#endif 79 80const char ECDH_version[] = "ECDH" OPENSSL_VERSION_PTEXT; 81 82static const ECDH_METHOD *default_ECDH_method = NULL; 83 84static void *ecdh_data_new(void); 85static void *ecdh_data_dup(void *); 86static void ecdh_data_free(void *); 87 88void ECDH_set_default_method(const ECDH_METHOD *meth) 89{ 90 default_ECDH_method = meth; 91} 92 93const ECDH_METHOD *ECDH_get_default_method(void) 94{ 95 if (!default_ECDH_method) { 96#ifdef OPENSSL_FIPS 97 if (FIPS_mode()) 98 return FIPS_ecdh_openssl(); 99 else 100 return ECDH_OpenSSL(); 101#else 102 default_ECDH_method = ECDH_OpenSSL(); 103#endif 104 } 105 return default_ECDH_method; 106} 107 108int ECDH_set_method(EC_KEY *eckey, const ECDH_METHOD *meth) 109{ 110 ECDH_DATA *ecdh; 111 112 ecdh = ecdh_check(eckey); 113 114 if (ecdh == NULL) 115 return 0; 116 117#if 0 118 mtmp = ecdh->meth; 119 if (mtmp->finish) 120 mtmp->finish(eckey); 121#endif 122#ifndef OPENSSL_NO_ENGINE 123 if (ecdh->engine) { 124 ENGINE_finish(ecdh->engine); 125 ecdh->engine = NULL; 126 } 127#endif 128 ecdh->meth = meth; 129#if 0 130 if (meth->init) 131 meth->init(eckey); 132#endif 133 return 1; 134} 135 136static ECDH_DATA *ECDH_DATA_new_method(ENGINE *engine) 137{ 138 ECDH_DATA *ret; 139 140 ret = (ECDH_DATA *)OPENSSL_malloc(sizeof(ECDH_DATA)); 141 if (ret == NULL) { 142 ECDHerr(ECDH_F_ECDH_DATA_NEW_METHOD, ERR_R_MALLOC_FAILURE); 143 return (NULL); 144 } 145 146 ret->init = NULL; 147 148 ret->meth = ECDH_get_default_method(); 149 ret->engine = engine; 150#ifndef OPENSSL_NO_ENGINE 151 if (!ret->engine) 152 ret->engine = ENGINE_get_default_ECDH(); 153 if (ret->engine) { 154 ret->meth = ENGINE_get_ECDH(ret->engine); 155 if (!ret->meth) { 156 ECDHerr(ECDH_F_ECDH_DATA_NEW_METHOD, ERR_R_ENGINE_LIB); 157 ENGINE_finish(ret->engine); 158 OPENSSL_free(ret); 159 return NULL; 160 } 161 } 162#endif 163 164 ret->flags = ret->meth->flags; 165 CRYPTO_new_ex_data(CRYPTO_EX_INDEX_ECDH, ret, &ret->ex_data); 166#if 0 167 if ((ret->meth->init != NULL) && !ret->meth->init(ret)) { 168 CRYPTO_free_ex_data(CRYPTO_EX_INDEX_ECDH, ret, &ret->ex_data); 169 OPENSSL_free(ret); 170 ret = NULL; 171 } 172#endif 173 return (ret); 174} 175 176static void *ecdh_data_new(void) 177{ 178 return (void *)ECDH_DATA_new_method(NULL); 179} 180 181static void *ecdh_data_dup(void *data) 182{ 183 ECDH_DATA *r = (ECDH_DATA *)data; 184 185 /* XXX: dummy operation */ 186 if (r == NULL) 187 return NULL; 188 189 return (void *)ecdh_data_new(); 190} 191 192void ecdh_data_free(void *data) 193{ 194 ECDH_DATA *r = (ECDH_DATA *)data; 195 196#ifndef OPENSSL_NO_ENGINE 197 if (r->engine) 198 ENGINE_finish(r->engine); 199#endif 200 201 CRYPTO_free_ex_data(CRYPTO_EX_INDEX_ECDH, r, &r->ex_data); 202 203 OPENSSL_cleanse((void *)r, sizeof(ECDH_DATA)); 204 205 OPENSSL_free(r); 206} 207 208ECDH_DATA *ecdh_check(EC_KEY *key) 209{ 210 ECDH_DATA *ecdh_data; 211 212 void *data = EC_KEY_get_key_method_data(key, ecdh_data_dup, 213 ecdh_data_free, ecdh_data_free); 214 if (data == NULL) { 215 ecdh_data = (ECDH_DATA *)ecdh_data_new(); 216 if (ecdh_data == NULL) 217 return NULL; 218 data = EC_KEY_insert_key_method_data(key, (void *)ecdh_data, 219 ecdh_data_dup, ecdh_data_free, 220 ecdh_data_free); 221 if (data != NULL) { 222 /* 223 * Another thread raced us to install the key_method data and 224 * won. 225 */ 226 ecdh_data_free(ecdh_data); 227 ecdh_data = (ECDH_DATA *)data; 228 } 229 } else 230 ecdh_data = (ECDH_DATA *)data; 231#ifdef OPENSSL_FIPS 232 if (FIPS_mode() && !(ecdh_data->flags & ECDH_FLAG_FIPS_METHOD) 233 && !(EC_KEY_get_flags(key) & EC_FLAG_NON_FIPS_ALLOW)) { 234 ECDHerr(ECDH_F_ECDH_CHECK, ECDH_R_NON_FIPS_METHOD); 235 return NULL; 236 } 237#endif 238 239 return ecdh_data; 240} 241 242int ECDH_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func, 243 CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func) 244{ 245 return CRYPTO_get_ex_new_index(CRYPTO_EX_INDEX_ECDH, argl, argp, 246 new_func, dup_func, free_func); 247} 248 249int ECDH_set_ex_data(EC_KEY *d, int idx, void *arg) 250{ 251 ECDH_DATA *ecdh; 252 ecdh = ecdh_check(d); 253 if (ecdh == NULL) 254 return 0; 255 return (CRYPTO_set_ex_data(&ecdh->ex_data, idx, arg)); 256} 257 258void *ECDH_get_ex_data(EC_KEY *d, int idx) 259{ 260 ECDH_DATA *ecdh; 261 ecdh = ecdh_check(d); 262 if (ecdh == NULL) 263 return NULL; 264 return (CRYPTO_get_ex_data(&ecdh->ex_data, idx)); 265} 266